¡¾Õþ²ß¹æÔò¡¿¹¤ÐŲ¿Ðû²¼2018ÄêµÚ¶þ¼¾¶ÈÍøÂçÇå¾²ÍþÐ²Ì¬ÊÆÆÊÎöÓëÊÂÇé×ÛÊö
¹¤ÐŲ¿Ðû²¼µÄµÚ¶þ¼¾¶ÈÍøÂçÇå¾²ÍþÐ²Ì¬ÊÆÈçÏ£ºµÚ¶þ¼¾¶È¹²¼à²âÍøÂçÇå¾²ÍþвԼ1841Íò¸ö£¬ÆäÖлù´¡µçÐÅÆóÒµ¼à²âÔ¼1683Íò¸ö£¬ÍøÂçÇ徲רҵ»ú¹¹¼à²âÔ¼3Íò¸ö£¬Öص㻥ÁªÍøÆóÒµ¡¢ÓòÃû»ú¹¹ºÍÍøÂçÇå¾²ÆóÒµ¼à²âÔ¼155Íò¸ö¡£ÍøÂçÇå¾²ÍþÐ²Ì¬ÊÆ·ºÆðÒÔϼ¸¸öÌØµã£º£¨Ò»£©²¿·Ö»¥ÁªÍøÓû§ÓÊÏäÒÉËÆ±»¿Ø£¬ÑÏÖØÎ£º¦Óû§Ð¡ÎÒ˽¼ÒÐÅÏ¢Çå¾²¡££¨¶þ£©¹¤Òµ»¥ÁªÍøÆ½Ì¨ºÍÖÇÄÜ×°±¸³ÉÎªÍøÂçÍþвµÄÖ÷ҪĿµÄ¡££¨Èý£©²»·¨¡°ÍÚ¿ó¡±ÑÏÖØÍþв»¥ÁªÍøÍøÂçÇå¾²¡£
ÔÎÄÁ´½Ó£ºhttp://www.miit.gov.cn/n1146285/n1146352/n3054355/n3057724/n3057728/c6363487/content.html
¡¾Êý¾Ýй¶¡¿Ñо¿Ö°Ô±·¢Ã÷Ô¼57ÍòMortal OnlineÓÎÏ·Íæ¼ÒµÄƾ֤ÔÚÂÛ̳³öÊÛ
Çå¾²Ñо¿Ö°Ô±Adam Davies·¢Ã÷ÊôÓÚÔ¼57ÍòMortal OnlineÓÎÏ·Íæ¼ÒµÄÕË»§ÐÅÏ¢ÔÚÂÛ̳ÉϳöÊÛ¡£2018Äê6ÔÂ17ÈÕδ¾ÊÚȨµÄµÚÈý·½»á¼ûÁ˸ÃÓÎÏ·µÄÂÛ̳ºÍÊÐËÁÊý¾Ý¿âµÄ·þÎñÆ÷²¢ÇÔÈ¡ÁËÓû§µÄÊý¾Ý¡£¹¥»÷Õß»¹»ñÈ¡ÁËÓû§ÃÜÂëµÄMD5¹þÏ£Öµ£¬ÕâЩ¹þÏ£ÖµËÆºõÒѱ»ÆÆ½â¡£¸ÃÊý¾Ý¿âÏÖÔÚÒѱ»Ìí¼Óµ½Have I Been PwnedÍøÕ¾ÖС£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cracked-logins-of-570-000-mortal-online-players-sold-on-forums/
¡¾Êý¾Ýй¶¡¿¼Ò³¤¼à¿ØÈí¼þFamily OrbitÔâºÚ¿ÍÈëÇÖ£¬Êý°ÙÃû¶ùͯµÄÕÕÆ¬¿ÉÄÜй¶
¼Ò³¤¼à¿ØÓ¦ÓÃFamily OrbitµÄÔÆ·þÎñÆ÷Ôâµ½ºÚ¿Í¹¥»÷£¬Ô¼281GBÊý¾ÝÒÉÔâй¶¡£¹¥»÷Õß·¢Ã÷¸ÃÔÆ·þÎñÆ÷±£´æÈõÃÜÂëÎó²î£¬Ê¹ÓøÃÎó²î¿É»ñÈ¡Êý°ÙÃû¶ùͯµÄÕÕÆ¬µÄ»á¼ûȨÏÞ¡£Family Orbit¹«Ë¾È·ÈÏÁ˸ÃÊý¾Ýй¶ÊÂÎñ£¬²¢Á¬Ã¦¸ü¸ÄÁËAPIÃÜÔ¿ºÍµÇ¼ƾ֤¡£¸Ã¹«Ë¾³ÆÒÑ×èÖ¹ÏúÊۺͷþÎñ£¬Ö±µ½È·±£ËùÓеÄÎó²î¶¼»ñµÃÐÞ¸´¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75888/data-breach/family-orbit-hacked.html
¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷Ö÷ÒªÕë¶Ô°ÍÎ÷ÒøÐеĶñÒâÈí¼þCamuBot
IBM X-ForceÑо¿ÍŶÓÊӲ쵽һ¸öÖ÷ÒªÕë¶Ô°ÍÎ÷ÒøÐеÄжñÒâÈí¼þCamuBot¡£CamuBotÓÚ2018Äê8Ô·ºÆð£¬Ö÷ÒªÕë¶Ô°ÍÎ÷µÄÆóÒµºÍ¹«¹²²¿·Ö£¬Æäαװ³ÉÄ¿µÄÒøÐеÄÇ徲ģ¿é¾ÙÐÐÈö²¥¡£¹¥»÷Õßαװ³ÉÒøÐеÄÔ±¹¤£¬Í¨¹ýµç»°Ö¸Ê¾Êܺ¦Õßä¯ÀÀÒ»¸öURLÒÔ¼ì²éÆäÇ徲ģ¿éÊÇ·ñÊÇ×îеġ£CamuBotµÄ¹¥»÷Ô˶¯ÊÇÓÐÕë¶ÔÐԵġ£
ÔÎÄÁ´½Ó£ºhttps://securityintelligence.com/camubot-new-financial-malware-targets-brazilian-banking-customers/
¡¾Çå¾²²¥±¨¡¿¾Ý±¨µÀ¹È¸èÓëÍòÊ´ïÉñÃØÏàÖúÒÔ¸ú×ÙÓû§µÄÏûºÄ¼Í¼
¾ÝÅí²©É籨µÀ£¬¹È¸èÏòÍòÊ´│¹«Ë¾Ö§¸¶ÁËÊý°ÙÍòÃÀÔªÒÔ»ñÈ¡Óû§¹ºÎïµÄÊý¾Ý¡£Á½¼Ò¹«Ë¾¾ÓÉ4ÄêµÄ̸ÅУ¬¸æ¿¢ÁËÒ»±Ê·Ç¹ûÕæµÄÉúÒâ¡£¹È¸èʹÓÃÕâЩÓû§µÄÏßϹºÎïÊý¾ÝΪ¹ã¸æÖ÷¿ª·¢¹¤¾ß£¬Ï¸·Ö³öÄÇЩµã»÷¹ýÔÚÏß¹ã¸æ£¬ËæºóÔÚÏßÏÂʵÌåµê¹ºÖÃÉÌÆ·µÄÖ÷¹Ë¡£¹È¸è¾Ü¾øÖ¤ÊµÓëÍòÊ´│¹«Ë¾µÄÏàÖú¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/09/google-mastercard-advertising.html
¡¾Îó²î²¹¶¡¡¿¼à¿ØÈí¼þOpsview MonitorÐû²¼Çå¾²¸üУ¬ÐÞ¸´5¸öÎó²î
SecureAuthºÍCoreSecurityÅû¶¼à¿ØÈí¼þOpsview MonitorÖеÄ5¸öÇå¾²Îó²î£¬°üÀ¨XSSÎó²î£¨CVE-2018-16147ºÍCVE-2018-16148£©¡¢¿Éµ¼ÖÂÏÂÁîÖ´ÐеÄÎó²î£¨CVE-2018-16146ºÍCVE-2018-16144£©ÒÔ¼°ÍâµØÌáȨÎó²î£¨CVE-2018-16145£©¡£Opsview Monitor°æ±¾4.2¡¢5.3ºÍ5.4Êܵ½Ó°Ï죬½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/multiple-remote-code-execution-flaws-patched-in-opsview-monitor/137170/