220Íò¸öÓëÓ¢¹ú100Ëù¶¥¼â´óѧÏà¹ØµÄƾ֤ÔÚ°µÍøÉÏй¶

Ðû²¼Ê±¼ä 2023-06-21

1¡¢220Íò¸öÓëÓ¢¹ú100Ëù¶¥¼â´óѧÏà¹ØµÄƾ֤ÔÚ°µÍøÉÏй¶


¾Ý6ÔÂ19ÈÕ±¨µÀ£¬CrosswordÔÚ°µÍøÉÏ·¢ÏÖÁ˽ü220Íò¸öÓëÓ¢¹ú100Ëù¶¥¼â´óѧÏà¹ØµÄƾ֤£¬ÆäÖÐ57%ÊôÓÚ24ËùÂÞËØ¼¯ÍÅ´óѧ ¡£´óѧµÄλÖú͹æÄ£¶Ôй¶µÄˮƽҲÓÐÓ°Ï죬Â׶صķçÏÕÒª´óµÃ¶à£¬ÓÐ506330(20%)¸öÖ¤Ê鱻й¶£¬Æä´ÎÊǶ«Äϲ¿(334251£¬Õ¼±È13%)ºÍËÕ¸ñÀ¼(306873£¬12%) ¡£Ñо¿ÈËÔ±»¹Í¸Â¶£¬Áè¼ÝÒ»°ë£¨54%£©µÄй¿à´×ÔÓµÓÐÑо¿ÉèÊ©µÄÓ¢¹ú´óѧ£¬Õþ¸®×ÊÖúµÄºËÄܺ͹ú·ÀµÈÁìÓòµÄÏîÄ¿¿ÉÄÜÃæÁÙ·çÏÕ ¡£


https://www.infosecurity-magazine.com/news/millions-uk-university-credentials/


2¡¢Cyfirma·¢ÏÖDoNotαװ³ÉVPNºÍÁÄÌìÓ¦ÓõļäµýÈí¼þ


¾Ý6ÔÂ19ÈÕ±¨µÀ£¬Cyfirma³ÆÆäÔÚGoogle PlayÉÏ·¢ÏÖÁË¿ÉÒɵÄÓ¦ÓÃnSure ChatºÍiKHfaa VPN£¬ËüÃǶ¼ÊÇ´ÓSecurITY IndustryÉÏ´«µÄ ¡£½øÒ»²½µÄ·ÖÎöÖ¤Ã÷ËüÃǾßÓжñÒâÈí¼þÌØÕ÷£¬²¢±»¹éÒòÓÚÓ¡¶ÈÏà¹ØºÚ¿ÍÍÅ»ïDoNot ¡£´Ë´Î¹¥»÷»î¶¯Ö÷ÒªÕë¶Ô°Í»ù˹̹£¬Ö¼ÔÚ´ÓÄ¿±êÉ豸ÊÕ¼¯Ç鱨£¬ÀýÈçλÖÃÊý¾ÝºÍÁªÏµÈËÁбí ¡£´ËÍ⣬ÓëÕâÁ½¿îÓ¦ÓÃÀ´×Ôͬһ¿¯ÐÐÉ̵ĵÚÈý¿îÓ¦ÓÃËÆºõûÓжñÒ⣬µ«ÈÔ¿ÉÔÚGoogle PlayÉÏʹÓà ¡£


https://www.cyfirma.com/outofband/donot-apt-elevates-its-tactics-by-deploying-malicious-android-apps-on-google-play-store/


3¡¢BitdefenderÅû¶Õë¶ÔmacOSµÄ¹¤¾ß°üµÄ×é¼þµÄϸ½Ú


BitdefenderÔÚ6ÔÂ16ÈÕ͸¶Æä·¢ÏÖÁËÒ»×é¾ßÓкóÃŹ¦Ð§µÄ¶ñÒâÎļþ£¬²¢ÍƶÏÊÇÕë¶ÔApple macOSϵͳµÄÅӴ󹤾߰üµÄÒ»²¿ÃÅ ¡£Ä¿Ç°ÊÓ²ìÈÔÔÚ½øÐÐÖУ¬Ñù±¾µÄ´ó²¿ÃÅÈÔδ±»·¢ÏÖ ¡£Ñо¿ÈËÔ±¹²·ÖÎöÁËÉÏ´«µ½VirusTotalµÄËĸöÑù±¾£¬ÆäÖÐ×îÔçµÄÓÚ4ÔÂ18ÈÕÓÉÄäÃûÓû§ÉÏ´« ¡£Ñо¿ÈËÔ±·¢ÏֵĶñÒâÎļþ·Ö±ðÊÇÒ»¸öͨÓõÄPythonºóÃÅshared.dat£¬Ò»¸öÇ¿´óµÄºóÃÅsh.py£¬ÒÔ¼°Ò»¸öFAT¶þ½øÖÆÎļþxcc ¡£Bitdefender½«Python×é¼þ¸ú×ÙΪJokerSpy ¡£


https://www.bitdefender.com/blog/labs/fragments-of-cross-platform-backdoor-hint-at-larger-mac-os-attack/


4¡¢eSentire¼ì²âµ½ÀûÓÃOnlyFansÒ³Ãæ·Ö·¢DcRATµÄ»î¶¯


6ÔÂ15ÈÕ£¬eSentire³ÆÆä¼ì²âµ½ÁËÀûÓÃαÔìµÄOnlyFansµÈÓÕ¶ü·Ö·¢DcRATµÄ»î¶¯ ¡£¸Ã»î¶¯×Ô1ÔÂÒÔÀ´Ò»Ö±ÔÚ»îÔ¾£¬Á÷´«°üÂÞVBScript¼ÓÔØ·¨Ê½µÄZIPÎļþ£¬È»ºóÓÕʹĿ±êÊÖ¶¯Ö´ÐÐ ¡£VBScript¼ÓÔØ·¨Ê½Æô¶¯Ê±£¬»áʹÓÃWMI¼ì²é²Ù×÷ϵͳ¼Ü¹¹²¢Éú³É32λ½ø³Ì ¡£Õâʹ¶ñÒâÈí¼þÄܹ»·ÃÎÊDynamicWrapperX ¡£×îÖÕ£¬ÃûΪBinaryDataµÄpayload»á±»¼ÓÔØµ½Äڴ棬²¢×¢ÈëRegAsm.exe½ø³Ì ¡£×¢ÈëµÄpayloadÊÇDcRAT£¬ËüÊÇAsyncRATµÄÐ޸İ汾£¬¿ÉÔÚGitHubÉÏÃâ·Ñ»ñµÃ ¡£


https://www.esentire.com/blog/onlydcratfans-malware-distributed-using-explicit-lures-of-onlyfans-pages-and-other-adult-content


5¡¢Ñо¿ÈËÔ±Åû¶΢ÈíAzure ADÉí·ÝÑé֤©¶´nOAuth


¾ÝýÌå6ÔÂ20ÈÕ±¨µÀ£¬DescopeÅû¶ÁËMicrosoft Azure AD OAuthÓ¦Ó÷¨Ê½ÖеÄÒ»¸öÑÏÖØµÄ´íÎóÅäÖà ¡£Ëü±»³ÆÎªnOAuth£¬ÊÇÒ»¸öÉí·ÝÑé֤©¶´ ¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄAzure ADÕÊ»§Öеĵç×ÓÓʼþÊôÐÔ£¬²¢Ê¹ÓÃËûÃÇÏëҪð³äµÄÄ¿±êµÄµç×ÓÓʼþµØÖ·À´ÀûÓÃÒ»¼üʽµÄ¡°Ê¹ÓÃMicrosoftµÇ¼¡±¹¦Ð§£¬´Ó¶øÍêÈ«½Ó¹ÜÕÊ»§ ¡£Microsoft½«¸ÃÎÊÌâÃèÊöΪ"Azure ADÓ¦Ó÷¨Ê½ÖÐʹÓõIJ»Äþ¾²µÄ·´Ä£Ê½"£¬ÒÑͨ¹ýÐû²¼»º½â´ëÊ©½â¾öÁËÕâÒ»ÎÊÌâ ¡£


https://www.securityweek.com/researchers-flag-account-takeover-flaw-in-microsoft-azure-ad-oauth-apps/


6¡¢Check PointÐû²¼Ä¿Ç°ÈÔÔÚ½øÐеĵöÓã»î¶¯µÄ³ÂËß


6ÔÂ19ÈÕ£¬Check Point Research(CPR)Ðû²¼³ÂË߳Ƽì²âµ½ÁËÒ»¸öÕýÔÚ½øÐеĵöÓã»î¶¯ ¡£¸Ã»î¶¯Ê¹ÓÃÁ˶à¸ö°æ±¾µÄÓʼþºÍһЩ²îÒìµÄHTMLÄ£°å ¡£ÎªÁËʹµÇÂ¼Ò³Ãæ¿´ÆðÀ´¸üºÏ·¨£¬¹¥»÷ÕßÒѾ­ÔÚ±íµ¥ÖÐÌîдÁËÄ¿±êµÄµç×ÓÓʼþµØÖ·£¬ÕâÊÇÓ²±àÂëÔÚHTMLÎļþÖÐµÄ ¡£Ò»µ©Ä¿±êÊäÈëÁËÆ¾Ö¤²¢ÊÔͼµÇ¼£¬ÕâЩÐÅÏ¢¾Í»áÖ±½Ó·¢Ë͵½¹¥»÷ÕßµÄÓÊÏäÀï ¡£´ËÍ⣬¹¥»÷Õ߶ԺϷ¨·þÎñµÄʹÓÃÓÐËùÔö¼Ó£¬ÕâÔö¼ÓÁ˵ÖÓù´ËÀ๥»÷µÄÀ§ÄÑ ¡£


https://blog.checkpoint.com/security/sign-in-to-continue-and-suffer-attackers-abusing-legitimate-services-for-credential-theft/