¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181128
Ðû²¼Ê±¼ä 2018-11-28
Ò»¸öÆÕ±éʹÓõÄNodeJSÄ£¿éEvent-Stream±»·¢Ã÷ѬȾÁ˶ñÒâ´úÂ룬¿ÉÇÔÈ¡±ÈÌØ±ÒÇ®°üÖеÄ×ʽð¡£Event-StreamÊÇÒ»¸öµÚÈý·½¿â£¬ÓÃÓÚ´¦Öóͷ£Node.jsÁ÷Êý¾Ý£¬ÆäÒ»ÖܵÄÏÂÔØÁ¿¾Í¿¿½ü200Íò´Î¡£¸Ã¶ñÒâ´úÂë±£´æÓÚEvent-Stream°æ±¾3.3.6ÖУ¬ÏÖÔڸð汾Òѱ»É¾³ý£¬Óû§¿É¸üÐÂÖÁ×îа汾4.0.1¡£ÊÂÎñµÄÒòÓÉÊÇEvent-StreamµÄÔ×÷ÕßDominic Tarr½«ÏîÄ¿µÄ¿ª·¢ºÍά»¤½»¸øÁËÁíÒ»Ãû×÷Õßright9ctrl£¬µ«right9ctrlËæºóÐû²¼Á˰üÀ¨¶ñÒâ´úÂëµÄ°æ±¾¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/11/nodejs-event-stream-module.html2¡¢Ñо¿Ö°Ô±·¢Ã÷Õë¶ÔÒâ´óÀûµÄÐÂÀ¬»øÓʼþÔ˶¯sLoad
CERT-Yoroi·¢Ã÷Ò»¸öÕë¶ÔÒâ´óÀûµÄÐÂÀ¬»øÓʼþÔ˶¯£¬¸ÃÔ˶¯Ö÷Òª·Ö·¢sLoadµÄбäÖÖ¡£sLoadµÄ¹¦Ð§Ç¿Ê¢£¬Ëü¿ÉÒÔ½ØÈ¡ÆÁÄ»¡¢¶ÁÈ¡Àú³ÌÁÐ±í¡¢»ñÈ¡DNS»º´æ¡¢ÇÔÈ¡outlookÓʼþÄÚÈݵȡ£¸ÃÔ˶¯ÖÐsLoadͨ¹ýÀ¬»øÓʼþÖеÄzip¸½¼þ¾ÙÐзַ¢¡£ÏÖÔÚ»¹²»ÇåÎú¸ÃÔ˶¯ÊÇÒ»¸öÐµķ¸·¨ÍÅ»ïËùΪÕÕ¾ÉÒÑÖªµÄ·¸·¨ÍÅ»ï¸Ä±äÁËËüÃǵÄTTP¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/78468/malware/sload-malspam-hit-italy.html3¡¢Ñо¿ÍŶӷ¢Ã÷Õë¶ÔÖж«µØÇøµÄ¶ñÒâÔ˶¯DNSpionage
˼¿ÆTalos·¢Ã÷Õë¶ÔÀè°ÍÄۺͰ¢ÁªÇõÕþ¸®ÍøÕ¾ÒÔ¼°Ò»¼ÒÀè°ÍÄÛº½¿Õ¹«Ë¾µÄжñÒâÔ˶¯¡£Æ¾Ö¤Talos¶ÔÆä»ù´¡ÉèÊ©ºÍTTPµÄÊÓ²ìЧ¹û£¬¸Ã¶ñÒâÔ˶¯ÎÞ·¨ÓëÈκÎÒÑÖªµÄ¹¥»÷Õß¾ÙÐйØÁª¡£ÏÖÔÚ»¹²»¿ÉÈ·¶¨¹¥»÷ÕßµÄÄ¿µÄ£¬Ò²²»ÇåÎú¹¥»÷ÕßÓÃÓÚ·Ö·¢¶ñÒâÎĵµµÄÒªÁ죬µ«×îÓпÉÄܵÄÊÇͨ¹ýÓã²æÊ½´¹ÂÚÔ˶¯»òÉ罻ýÌåÆ½Ì¨¾ÙÐзַ¢¡£Ñо¿Ö°Ô±ÔÚ±¨¸æÖÐÅû¶Á˸ü¶àµÄÊÖÒÕϸ½ÚºÍ¹¥»÷ʱ¼äÖá¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2018/11/dnspionage-campaign-targets-middle-east.html4¡¢ÃÀ¹úiOSÓû§Ôâ´ó¹æÄ£¶ñÒâ¹ã¸æÔ˶¯¹¥»÷
Çå¾²³§ÉÌConfiant·¢Ã÷Ò»¸öÕë¶ÔÃÀ¹úiOSÓû§µÄ´ó¹æÄ£¶ñÒâ¹ã¸æÔ˶¯¡£11ÔÂ12ÈոöñÒâÔ˶¯²þâ±ìÉý£¬·¸·¨·Ö×ÓÔÚ48СʱÄÚÐ®ÖÆÁËÁè¼Ý3ÒÚ¸öä¯ÀÀÆ÷»á»°¡£¸Ã¶ñÒâÔ˶¯Í¨¹ýÕýµ±ÍøÕ¾ÉϵĶñÒâ¹ã¸æ½«Óû§Öض¨ÏòÖÁһϵÁеÄÔÝÊ±ÍøÕ¾£¬²¢ÏòÓû§ÍÆËͳÉÈËÍøÕ¾»òÀñÎ│Ö÷ÌâµÄÕ©ÆÔ˶¯¡£Ñо¿Ö°Ô±½«¸Ã¶ñÒâÔ˶¯¹ØÁªÖÁ·¸·¨ÍÅ»ïScamClub¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/us-ios-users-targeted-by-massive-malvertising-campaign/5¡¢¶íº¥¶íÖÝÒ½ÔºÔâÀÕË÷Èí¼þ¹¥»÷£¬¼±Õï·þÎñ±»ÆÈÖÐÖ¹
¾ÝThe Times Leader±¨µÀ£¬11ÔÂ23ÈÕÐÇÆÚÎåÍíÉ϶«¶íº¥¶íµØÇøÒ½ÔººÍ¶íº¥¶í¹ÈÒ½ÁÆÖÐÐĵÄÅÌËã»úϵͳÔâÀÕË÷Èí¼þ¹¥»÷£¬ÖÂʹҽԺµÄ¼±Õï·þÎñ±»ÆÈÖÐÖ¹¡£¸ÃµØÇøµÄ¼±Õï²½¶ÓÒѽ«²¡ÈË×ªÒÆÖÁÆäËüµØÇøµÄÒ½Ôº¡£ºÃÐÂÎÅÊÇ£¬Ã»Óл¼ÕßµÄÊý¾ÝÔڴ˴ι¥»÷ÊÂÎñÖÐй¶¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/78441/breaking-news/ohio-hospital-system-ransomware.html6¡¢UberÒò2016ÄêÊý¾Ýй¶±»ºÉÀ¼ºÍÓ¢¹ú·£¿î120ÍòÃÀÔª
Ó¢¹úµÄÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©ÒÔ¼°ºÉÀ¼µÄÊý¾Ý±£»¤»ú¹¹Autoriteit Persoonsgegevens»®·ÖÒò2016Äê10ÔµÄÊý¾Ýй¶ÊÂÎñ¶ÔUber´¦ÒÔ38.5ÍòÓ¢°÷ºÍ60ÍòÅ·ÔªµÄ·£¿î¡£ICOÌåÏÖ¸ÃÊÂÎñÓ°ÏìÁËÓ¢¹úµÄ270ÍòUberÓû§ÒÔ¼°8.2Íò˾»ú¡£ºÉÀ¼DPA³ÆÓÐ17.4ÍòºÉÀ¼¹«ÃñÊܵ½Ó°Ïì¡£·£¿îµÄÖ÷ÒªÔµ¹ÊÔÓÉÊÇUberÑÓ³ÙÁ˽üÒ»Äê²Å±¨¸æ´Ë´Îй¶ÊÂÎñ£¬ÕâÑÏÖØÎ¥·´ÁËÏà¹ØÖ´·¨ÌõÀý£¬²¢ÇÒʹÊÜÓ°ÏìµÄÓû§ºÍ˾»úÃæÁÙ¸ü¸ßµÄÚ²ÆÎ£º¦¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/uber-fined-for-covering-up-2016-data-breach/
ÉùÃ÷£º±¾×ÊѶÓÉ×ðÁú¿Ê±Î¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ