¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180710
Ðû²¼Ê±¼ä 2018-07-10¡¾Êý¾Ýй¶¡¿TimehopÔâºÚ¿ÍÈëÇÖ£¬Áè¼Ý2100ÍòÓû§µÄÊý¾Ýй¶
7ÔÂ4ÈÕÊ¢ÐеÄÉ罻ýÌåÓ¦ÓÃTimehopÔâºÚ¿ÍÈëÇÖ£¬Áè¼Ý2100ÍòÓû§µÄСÎÒ˽¼ÒÊý¾Ýй¶£¬°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµãÒÔ¼°Ô¼470Íò¸öµç»°ºÅÂë¡£TimehopÓÃÓÚ×ÊÖúÓû§´ÓiPhone¡¢Facebook¡¢InstagramºÍTwitterµÈÍøÂç¾ÉÕÕÆ¬ºÍÌû×Ó£¬ÒÔ³äÆäʱ¼ä»úеµÄ¹¦Ð§¡£¹¥»÷Õß»¹»ñÈ¡ÁËÆäËüÉç½»ÍøÕ¾ÌṩӦTimehopµÄÊÚȨÁîÅÆ£¬¿ÉÔÚδ¾ÔÊÐíµÄÇéÐÎÏ»á¼ûÓû§ÔÚÆäËüÉç½»ÍøÕ¾ÉϵÄÌû×Ó¡£Õâ´ÎÊÂÎñµÄÔµ¹ÊÔÓÉÊÇTimehopδ½ÓÄÉË«ÒòËØÈÏÖ¤À´ÖÎÀíÆäÔÆÅÌËãÇéÐÎµÄÆ¾Ö¤¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/timehop-data-breach.html
¡¾Êý¾Ýй¶¡¿Domain FactoryÈ·ÈÏÔÚ1Ô·ÝÔâºÚ¿ÍÈëÇÖ£¬²¿·ÖÓû§µÄÊý¾Ýй¶
µÂ¹úÍйܷþÎñÌṩÉÌDomainFactoryÈ·ÈÏÔÚ1Ô·ݱ¬·¢Êý¾Ýй¶ÊÂÎñ£¬²¿·ÖÓû§µÄСÎÒ˽¼ÒÊý¾Ýй¶£¬µ«¸Ã¹«Ë¾Î´Åû¶ÏêϸµÄÊý×Ö¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨Óû§µÄÐÕÃû¡¢¹«Ë¾Ãû¡¢ÕË»§ID¡¢µØµã¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢³öÉúÈÕÆÚ¡¢ÒøÐп¨Õ˺ŵÈÐÅÏ¢£¬ÍøÂç·¸·¨·Ö×Ó¿ÉʹÓÃÕâЩÊý¾Ý¾ÙÐÐÓÐÕë¶ÔÐÔµÄÉç»á¹¤³Ì¹¥»÷¡£DomainFactory½¨ÒéËùÓÐÓû§ÐÞ¸ÄÆäÃÜÂë¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/web-hosting-server-hack.html
¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷Õë¶Ô°ÍÀÕ˹̹Õþ¸®»ú¹¹µÄAPT¹¥»÷¾íÍÁÖØÀ´
Check PointÑо¿ÍŶӷ¢Ã÷Õë¶Ô°ÍÀÕ˹̹Õþ¸®»ú¹¹µÄAPT¹¥»÷¾íÍÁÖØÀ´¡£ÕâЩ¹¥»÷×îÏÈÓÚ2018Äê3Ô£¬¹¥»÷Õßͨ¹ý°üÀ¨¶ñÒâÈí¼þµÄ´¹ÂÚÓʼþѬȾĿµÄ£¬¸Ã¶ñÒâÈí¼þ¿ÉÒÔÍøÂçÓû§µÄ.doc¡¢.odt¡¢.xls¡¢.pptºÍ.pdfÎļþ²¢·¢ËÍÖÁÔ¶³Ì·þÎñÆ÷¡£Ñо¿Ö°Ô±³Æ¸Ã¶ñÒâÈí¼þ¹²°üÀ¨13¸öÄ£¿é£¬µ«ÏÖÔÚÖ»ÄÜÈ·ÈÏÆäÖÐ5¸öÄ£¿éµÄ¹¦Ð§¡£Check PointÒÔΪ¸ÃAPT¹¥»÷±³ºóµÄ×éÖ¯ÊÇGaza Cybergang¡£
ÔÎÄÁ´½Ó£ºhttps://research.checkpoint.com/apt-attack-middle-east-big-bang/
¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷ÌØ¹¤Èí¼þʹÓñ»ÇÔµÄD-LinkÊý×ÖÖ¤Êé¾ÙÐÐÊðÃû
ESETÑо¿ÍŶӷ¢Ã÷ʹÓñ»ÇÔÊý×ÖÖ¤Êé¾ÙÐÐÊðÃûµÄжñÒâÈí¼þÔ˶¯¡£µÚÒ»¸ö¶ñÒâÈí¼þÊÇPlead£¬Ö÷ÒªÓÃÓÚÇÔÈ¡Óû§µÄÃô¸ÐÐÅÏ¢£¬ÆäʹÓÃÁĘ̈Íå¿Æ¼¼¹«Ë¾D-LinkµÄÓÐÓÃÊý×ÖÖ¤Êé¾ÙÐÐÊðÃû¡£µÚ¶þ¸ö¶ñÒâÈí¼þÊÇÒ»¸öÃÜÂëÇÔÈ¡³ÌÐò£¬Ö÷ÒªÓÃÓÚ´ÓChrome¡¢IE¡¢OutlookºÍFirefoxµÈÇÔÈ¡Óû§µÄÃÜÂ룬ÆäʹÓÃÁËChanging Information Technology¹«Ë¾µÄÓÐÓÃÖ¤ÊéÊðÃû¡£ÕâÁ½¼Ò¹«Ë¾ÔÚ½Óµ½±¨¸æºóÒÑ»®·ÖÔÚ7ÔÂ3ÈÕºÍ4ÈÕ×÷·ÏÁ˱»ÇÔµÄÖ¤Êé¡£
ÔÎÄÁ´½Ó£ºhttps://www.welivesecurity.com/2018/07/09/certificates-stolen-taiwanese-tech-companies-plead-malware-campaign/
¡¾Îó²î²¹¶¡¡¿AppleÐû²¼Boot CampÇå¾²¸üУ¬ÐÞ¸´3¸öWi-Fi KRACKÏà¹ØµÄÎó²î
AppleÐû²¼Boot Camp 6.4.0µÄÇå¾²¸üУ¬ÐÞ¸´ÓëÈ¥ÄêÄêµ×Åû¶µÄWi-Fi KRACK¹¥»÷Ïà¹ØµÄ3¸öÇå¾²Îó²î£¨CVE-2017-13077¡¢CVE-2017-13078ºÍCVE-2017-13080£©¡£Boot CampÊÇmacOSÖÐµÄÆô¶¯¹¤¾ß£¬¿ÉÔÊÐíÓû§ÔÚ»ùÓÚIntel CPUµÄMacÉÏ×°ÖÃWindows²Ù×÷ϵͳ¡£¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÇ¿ÖÆÔÚWPAµ¥²¥/PTK¿Í»§¶Ë»òWPA¶à²¥/GTK¿Í»§¶ËÖÐÖØ¸´Ê¹ÓÃnonce£¬½¨ÒéÓû§¾¡¿ì¾ÙÐиüС£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/apple-patches-krack-flaws-boot-camp
¡¾¶ñÒâÈí¼þ¡¿Ñо¿Ö°Ô±·¢Ã÷ÀÕË÷Èí¼þKingOuroborosµÄбäÖÖ
Ñо¿Ö°Ô±ÔÚ2018Äê6ÔÂÏÂÑ®·¢Ã÷ÀÕË÷Èí¼þKingOuroborosµÄбäÖÖ£¬¸Ã±äÖÖαװ³ÉJava Update Scheduler³ÌÐò£¨jusched.exe£©¾ÙÐÐÈö²¥£¬Í¨¹ýAES¼ÓÃÜÓû§µÄÊý¾Ý£¬²¢ÔÚ¼ÓÃܵÄÎļþµÄÔÎļþÃûºÍÀ©Õ¹ÃûÖ®¼äÌí¼Ó.king_ouroborosÀ©Õ¹Ãû¡£¸Ã±äÖÖµÄÊê½ðΪ¼ÛÖµ50-80ÃÀÔªµÄ±ÈÌØ±Ò£¬ÆäÀÕË÷ÐÅÏ¢ÖаüÀ¨12ÖÖÓïÑԵķÒë¡£
ÔÎÄÁ´½Ó£ºhttps://id-ransomware.blogspot.com/2018/06/kingouroboros-ransomware.html


¾©¹«Íø°²±¸11010802024551ºÅ