2019ÄêÕë¶ÔMacÓû§µÄ´¹ÂÚ¹¥»÷ÔöÌíÖÁ160Íò´Î£»ÃÀ¹ú²ÆÎñ²¿Ðû²¼¶ÔÈý¸ö³¯ÏʺڿÍ×é֯ʵÑéÖÆ²Ã

Ðû²¼Ê±¼ä 2019-09-16

1.2019ÄêÕë¶ÔMacÓû§µÄ´¹ÂÚ¹¥»÷ÔöÌíÖÁ160Íò´Î


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


¿¨°Í˹»ùÔÚ2019ÄêµÄǰÁù¸öÔÂÖй²²¶»ñµ½160Íò´ÎÕë¶ÔMacÓû§µÄ´¹ÂÚ¹¥»÷¡£2018ÄêÕûÄêʹÓÃAppleÆ·ÅÆµÄ´¹ÂÚ¹¥»÷´ÎÊýΪ150Íò´Î£¬½ñÄêÉϰëÄêÒѾ­Áè¼ÝÁËÕâÒ»Êý×Ö¡£¿¨°Í˹»ùÌåÏÖ´ËÀ๥»÷ͨ³£Ã¿ÄêÔöÌí30-40%¡£°ÍÎ÷µÄmacOSÓû§ÖÐÊÜ´¹ÂÚ¹¥»÷µÄ±ÈÀý×î´ó£¬Îª30%£¬¶ø·¨¹úºÍÓ¡¶ÈµÄ±ÈÀýԼΪ22%¡£¿¨°Í˹»ùÇ¿µ÷³Æ¹¥»÷ÕßÔ½À´Ô½¶àµØÊ¹ÓÃAppleͼ±êÀ´ÓÕÆ­Óû§µÄApple IDºÍƾ֤¡£±ðµÄ£¬¿¨°Í˹»ùÌåÏÖ×Ô2015ÄêÒÔÀ´ÍøÂç´¹ÂÚ¹¥»÷µÄ×ÜÊýÔøÖ¸Êý¼¶ÔöÌí£¬ÆäʱµÄÊý×ÖΪԼ85Íò´Î¹¥»÷£¬¶øÔÚ½ñÄêÉϰëÄê´¹ÂÚ¹¥»÷µÄ×ÜÊýΪ½ü600Íò´Î¡£


Ô­ÎÄÁ´½Ó£º

https://www.techrepublic.com/article/phishing-scams-targeting-mac-users-on-the-rise-with-1-6-million-attacks-in-2019/


2.ÃÀ¹ú²ÆÎñ²¿Ðû²¼¶ÔÈý¸ö³¯ÏʺڿÍ×é֯ʵÑéÖÆ²Ã


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÃÀ¹ú²ÆÎñ²¿Ðû²¼¶ÔÈý¸öÓɹú¼ÒÖ§³ÖµÄ³¯ÏʺڿÍ×é֯ʵÑéÖÆ²Ã£¬°üÀ¨·¸·¨ÍÅ»ïLazarus Group¼°Æä×Ó¼¯ÍÅBluenoroffºÍAndariel¡£ÕâЩºÚ¿Í×éÖ¯±»Ö¸¿Ø¶ÔÃÀ¹úÒªº¦»ù´¡ÉèʩʵÑéÁ˶à´ÎÆÆËðÐÔÍøÂç¹¥»÷ÒÔ¼°´ÓÈ«Çò½ðÈÚ»ú¹¹ÇÔÈ¡ÊýÒÚÃÀÔª²¢Îª³¯ÏÊÕþ¸®µÄ²»·¨ÎäÆ÷ºÍµ¼µ¯ÍýÏëÌṩ×ʽð¡£²ÆÎñ²¿Íâ¹ú×ʲú¿ØÖư칫ÊÒ£¨OFAC£©ÌåÏÖÖÆ²ÃµÄÄ¿µÄÊÇËø¶¨ÈκÎÓÐÒâΪÕâЩºÚ¿Í×éÖ¯Ìá¹©ÖØ´óÉúÒâ»ò·þÎñµÄÍâ¹ú½ðÈÚ»ú¹¹£¬²¢¶³½áÓëÕâÈý¸ö×éÖ¯Ïà¹ØµÄÈκÎ×ʲú¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/09/north-korea-cyber-attack.html


3.ÓŲ½ÐÞ¸´¿Éµ¼ÖÂÓû§ÕË»§±»½ÓÊܵÄAPIÎó²î


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Anand Prakash·¢Ã÷ÓŲ½µÄÒ»¸öAPIÎó²î¿ÉÓÃÓÚ½ÓÊÜÓû§ÕË»§ºÍ¸ú×ÙÓû§¡£¹¥»÷Õß¿ÉÊ×ÏÈͨ¹ý·¢ËͰüÀ¨Óû§µç»°ºÅÂë»òµç×ÓÓʼþµØµãµÄAPIÇëÇóÀ´»ñÈ¡ÈκÎÓû§µÄΨһ±êʶ·û£¨UUID£©£¬È»ºóʹÓøÃUUIDÖØÐ·¢ËÍÇëÇ󣬴Ӷø¿ÉÒÔ»ñÈ¡ÒÆ¶¯APPµÄ»á¼ûÁîÅÆ¡¢Î»Öú͵صãµÈ˽ÈËÐÅÏ¢¡£PrakashÌåÏÖͨ¹ý»á¼ûÁîÅÆ£¬ËûÄܹ»ÍêÈ«½ÓÊܲâÊÔÕË»§¡¢·¢Ëͳ˳µÇëÇóÒÔ¼°»ñÈ¡¸¶¿îÐÅÏ¢µÈ¡£¸ÃÎÊÌâͬʱӰÏìÁËÓŲ½Óû§ºÍ˾»ú¡£ÓŲ½ÔÚÈ·ÈÏÁ˸ÃÎÊÌâºóѸËÙÐÞ¸´ÁËÏà¹ØÎó²î¡£


Ô­ÎÄÁ´½Ó£º

https://www.forbes.com/sites/daveywinder/2019/09/12/uber-confirms-account-takeover-vulnerability-found-by-forbes-30-under-30-honoree/


4.InstagramÐÞ¸´¿Éµ¼ÖÂÕË»§ÐÅϢй¶µÄÎó²î


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


FacebookÐÞ¸´ÁËInstagramÖпɵ¼Ö¹¥»÷Õß»ñÈ¡Óû§Ë½ÈËÐÅÏ¢µÄÎó²î¡£Çå¾²Ñо¿Ô±@ZHacker13ÌåÏֿɱ»»ñÈ¡µÄÓû§Êý¾Ý°üÀ¨ÕæÊµÐÕÃû¡¢ÍêÕûµç»°ºÅÂëÒÔ¼°InstagramÕʺÅÐÅÏ¢µÈ¡£¸Ãר¼Ò»¹ÖÒÑԳƹ¥»÷Õß¿ÉÒÔʹÓÃ×Ô¶¯¾ç±¾ºÍ»úеÈË´ÓÆ½Ì¨ÍøÂçÓû§Êý¾Ý£¬²¢½«Óû§ÓëÆäÁªÏµÈËÐÅÏ¢¹ØÁªÆðÀ´¡£¹¥»÷³¡¾°°üÀ¨Á½¸ö°ì·¨£ºÊ×ÏÈÊÇÔÚInstagramµÄµÇ¼±íµ¥ÉϾÙÐб©Á¦¹¥»÷£¬Ò»´Î¼ì²éÒ»¸öµç»°ºÅÂ룬ÒÔ±ãÁ´½Óµ½Ò»¸öÕæÊµµÄInstagramÕÊ»§£»È»ºóʹÓÃInstagramµÄͬ²½ÁªÏµÈ˹¦Ð§ÕÒµ½Óëµç»°ºÅÂëÏà¹ØÁªµÄÕÊ»§Ãû³ÆºÍºÅÂë¡£Facebook½²»°ÈËÌåÏָù«Ë¾Í¨¹ýÐÞ¸ÄInstagramÁªÏµÈ˵¼Èë·½·¨ÐÞ¸´Á˸ÃÎÊÌâ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/91253/hacking/instagram-bug-data-exposure.html


5.NemtyбäÌå¿ÉɱËÀVirtualBox¡¢SQLµÈÀú³Ì


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÀÕË÷Èí¼þNemtyÕýÔÚÆð¾¢¿ª·¢ÖУ¬Æä×÷ÕßÏÔÈ»ÕýÔÚÆð¾¢Ê¹Æä³ÉΪһÖÖ¸ü¸ßЧ¡¢ÖØ´óµÄ¶ñÒâÈí¼þ£¬²¢×îÏȸüÆÕ±éµÄ·Ö·¢¡£Çå¾²Ñо¿Ô±Vitali KremezÆÊÎö·¢Ã÷Ö»¹ÜNemty×÷Õß¶Ô´úÂë¾ÙÐÐÁ˸ü¸Ä£¬µ«Ëü±£´æÁËÏàͬµÄ°æ±¾ºÅ¡£×îеÄÑù±¾°üÀ¨ÓÃÓÚɱËÀÀú³ÌºÍ·þÎñµÄ´úÂ룬ĿµÄÀú³Ì°üÀ¨WordPad¡¢Microsoft Word¡¢Excel¡¢Outlook¡¢µç×ÓÓʼþ¿Í»§¶ËThunderbird¡¢SQL¡¢oracle¡¢onenoteºÍÓÃÓÚÔËÐÐÐéÄâ»úµÄVirtualBoxÈí¼þ¡£ÕâÒâζ×ÅNemtyÕýÔÚÕë¶ÔÆóÒµÊܺ¦Õß¡£Nemty×î³õͨ¹ýRIG EK·Ö·¢£¬¶ø×îа汾1.4Ôòͨ¹ýÐéαµÄPayPalÍøÕ¾Èö²¥£¬ËæºóÓÖÐÂÔöÁËRadio EKÈö²¥ÇþµÀ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nemty-ransomware-update-lets-it-kill-processes-and-services/


6.д¹ÂÚȦÌ×Ö÷ÒªÇÔÈ¡ÑÇÂíÑ·Óû§µÄÐÅÓÿ¨Êý¾Ý


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Ñо¿Ö°Ô±·¢Ã÷Ò»¸öеĴ¹ÂÚÓʼþȦÌ×ÕýÔÚÈö²¥£¬¹¥»÷ÕßÖ÷ÒªÊÔͼÇÔÈ¡ÑÇÂíÑ·Óû§µÄÐÅÓÿ¨Êý¾Ý¡£¸ÃȦÌ×µÄÊÂÇéÔ­ÀíÈçÏ£ºÊܺ¦ÕßÎüÊÕµ½Ò»·âαװ³ÉÀ´×ÔÑÇÂíÑ·µÄµç×ÓÓʼþ£¬Í¨ÖªÓÐ¹ØÆäÕË»§µÄ¿ÉÒÉÔ˶¯£¬¸ÃÓʼþʹÓûìÏýÁËÓ¢ÓïºÍ·¨ÓïµÄÖ÷Ì⣬ҪÇóÊܺ¦Õßµã»÷Á´½ÓÀ´¸üÐÂÕË»§ÐÅÏ¢£¬°üÀ¨ÊäÈë»á¼ûƾ֤¡¢Õ˵¥µØµã¡¢²ÆÎñÐÅÏ¢µÈ¡£¸Ã´¹ÂÚÍøÕ¾ÍйÜÔÚwadwa-wmdw(dot)comÓòÃûÉÏ£¬´ËÓòÃûÊÇ8ÔÂ22ÈÕÔÚÒ»¸ö¶àÂ×¶àµØµã×¢²áµÄ£¬¸ÃµØµãºÜ¿ÉÄÜÖ»ÊÇÒ»¸öÐéαµØµã¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/new-amazon-phishing-scam-stealing-credit-card-data/