《维他命》逐日清静简讯20190315
宣布时间 2019-03-15
原文链接:
https://thehackernews.com/2019/03/hack-wordpress-websites.html2、思科宣布清静更新,修复CSPC软件中的后门账户误差
原文链接:
https://securityaffairs.co/wordpress/82391/security/common-services-platform-collector-flaw.html3、巴基斯坦移民局官网遭黑客入侵,被植入键盘纪录木马
巴基斯坦移民与护照局的官网tracking.dgip.gov[.]pk遭黑客入侵,攻击者在网站上植入了恶意代码以跟踪用户。被植入的payload是ScanBox,该变种可以网络网站会见者的系统信息并举行键盘纪录。别的,该变种还试图检测会见者是否装置了特定的清静产品、解压缩工具和虚拟机工具等,这个列表长达77项,该行为可能是针对特定目的群体的水坑攻击的一部分。
原文链接:
https://www.bleepingcomputer.com/news/security/pakistani-government-site-compromised-logs-visitor-keystrokes/4、Steam上39%的CS 1.6服务器向玩家分发Belonard木马
原文链接:
https://www.bleepingcomputer.com/news/security/39-percent-of-all-counter-strike-16-servers-used-to-infect-players/5、新CryptoSink挖矿攻击,主要针对Elasticsearch服务器
原文链接:
https://www.f5.com/labs/articles/threat-intelligence/-cryptosink--campaign-deploys-a-new-miner-malware6、PoS恶意软件DMSniff,自2016年来一直针对中小型企业
原文链接:
https://www.bleepingcomputer.com/news/security/dmsniff-point-of-sale-malware-silently-attacked-smbs-for-years/声明:本资讯由尊龙凯官网入口维他命清静小组翻译和整理


京公网安备11010802024551号