¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180608

Ðû²¼Ê±¼ä 2018-06-08
¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý4Íò¸ö×°±¸Ñ¬È¾½©Ê¬ÍøÂçProwli


GuardiCoreÇå¾²Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý4Íò¸ö×°±¸Ñ¬È¾Á˽©Ê¬ÍøÂçProwli£¬£¬£¬ £¬£¬£¬£¬ÕâЩװ±¸ÈªÔ´ÓÚ½ðÈÚ¡¢½ÌÓýºÍÕþ¸®»ú¹¹µÄ9000¶à¸ö×éÖ¯£¬£¬£¬ £¬£¬£¬£¬°üÀ¨Ð§ÀÍÆ÷¡¢Â·ÓÉÆ÷ºÍIoT×°±¸µÈ¡£¡£¡£¡£¡£ÓÉÓÚ¹¥»÷ÕßÊÔͼͨ¹ý¸Ã½©Ê¬ÍøÂç¾ÙÐжñÒâÍÚ¿ó»î¶¯ÒÔ¼°½«Óû§Öض¨ÏòÖÁ¶ñÒâÍøÕ¾£¬£¬£¬ £¬£¬£¬£¬Ñо¿Ö°Ô±ÒÔΪProwliµÄÖ÷ÒªÄîÍ·ÊǾ­¼ÃÀûÒæ£¬£¬£¬ £¬£¬£¬£¬¶ø²»ÊÇÍøÂçÌØ¹¤»î¶¯¡£¡£¡£¡£¡£Prowli»áÔÚÊÜѬȾµÄ×°±¸ÉÏ×°ÖÃÃÅÂޱҿ󹤺Ír2r2È䳿£¬£¬£¬ £¬£¬£¬£¬»¹»á½«ÍøÕ¾µÄ»á¼ûÕßÖØ¶¨Ïòµ½ÓÃÓÚÈö²¥¶ñÒâä¯ÀÀÆ÷²å¼þµÄ´¹ÂÚÍøÕ¾¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/prowli-malware-botnet.html


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±³ÆAuth0±£´æÇ徲Σº¦£¬£¬£¬ £¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÌᳫ´¹ÂÚ¹¥»÷


ImpervaµÄÑо¿Ö°Ô±ÖÒÑÔ³ÆAuth0µÄ×ÓÓòÃûϵͳ±£´æÇ±ÔÚµÄÇ徲Σº¦£¬£¬£¬ £¬£¬£¬£¬¿É±»¹¥»÷ÕßʹÓÃÒÔÌᳫ´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£Auth0ÊÇÒ»¸öÉí·Ý¼´Ð§ÀÍµÄÆ½Ì¨£¬£¬£¬ £¬£¬£¬£¬ÆäÔÚ70¶à¸ö¹ú¼ÒÓµÓÐÔ¼2000¼ÒÆóÒµ¿Í»§¡£¡£¡£¡£¡£Auth0ÓµÓÐ3¸ö×ÓÓòÃû£¬£¬£¬ £¬£¬£¬£¬»®·ÖÓÃÓÚÃÀÖÞ¡¢Å·ÖÞºÍÑÇÌ«µØÇøµÄ¿Í»§¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ¹¥»÷Õß¿ÉÒÔʹÓòî±ðµØÇøµÄ×ÓÓòÃûÀ´¹¹½¨´¹ÂÚÍøÕ¾£¬£¬£¬ £¬£¬£¬£¬ÒÔαװ³ÉÆäËû×ÓÓòÃûϵÄÕýµ±ÍøÕ¾£¬£¬£¬ £¬£¬£¬£¬ÕâÖÖ¹¥»÷ÄÑÒÔ±»Ê¶±ð¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/auth0-glitch-allows-attackers-to-launch-phishing-attacks/132554/


¡¾Îó²î²¹¶¡¡¿Ñо¿Ö°Ô±·¢Ã÷Chrome±£´æÑÏÖØÎó²î£¬£¬£¬ £¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üÐÂ


Çå¾²Ñо¿Ö°Ô±Micha?Bentkowski·¢Ã÷²¢±¨¸æÁËChromeÖеÄÒ»¸öÑÏÖØÎó²î£¬£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËËùÓÐÆ½Ì¨£¨°üÀ¨Windows¡¢MacºÍLinux£©µÄChrome°æ±¾¡£¡£¡£¡£¡£ChromeÇå¾²ÍŶÓûÓÐÅû¶¹ØÓÚ¸ÃÎó²îµÄÈκÎÊÖÒÕϸ½Ú£¬£¬£¬ £¬£¬£¬£¬Ö»Êǽ«¸ÃÎó²îÐÎòΪ²»×¼È·µÄCSPÍ·£¨Content Security Policy£¬£¬£¬ £¬£¬£¬£¬ÄÚÈÝÇå¾²Õ½ÂÔ£©´¦Öóͷ£Îó²î£¨CVE-2018-6148£©¡£¡£¡£¡£¡£ChromeÒÑÔÚ¸üÐÂ67.0.3396.79ÖÐÐÞ¸´Á˸ÃÎó²î£¬£¬£¬ £¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¾ÙÐиüС£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/google-chrome-csp.html


¡¾Îó²î²¹¶¡¡¿AdobeÐû²¼Flash PlayerµÄÇå¾²¸üУ¬£¬£¬ £¬£¬£¬£¬ÐÞ¸´4¸öÇå¾²Îó²î


±¾ÖÜËÄAdob??eÐû²¼Flash PlayerµÄÇå¾²¸üУ¬£¬£¬ £¬£¬£¬£¬¹²ÐÞ¸´4¸öÇå¾²Îó²î¡£¡£¡£¡£¡£ÆäÖÐÎó²î£¨CVE-2018-5002£©ÊÇ»ùÓÚÕ»µÄ»º³åÇøÒç³öµ¼ÖµÄí§Òâ´úÂëÖ´ÐÐÎó²î£¬£¬£¬ £¬£¬£¬£¬ÒÑÓй¥»÷ÕßʹÓøÃÎó²îÕë¶ÔÖж«µÄÆóÒµÌᳫ¹¥»÷¡£¡£¡£¡£¡£ÁíÍâ3¸öÎó²î°üÀ¨¿Éµ¼Ö´úÂëÖ´ÐеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2018-4945£©¡¢¿Éµ¼ÖÂÐÅϢй¶µÄÕûÊýÒç³öÎó²î£¨CVE-2018- 5000£©ºÍ¿Éµ¼ÖÂÐÅϢй¶µÄÔ½½ç¶ÁÎó²î£¨CVE-2018-5001£©¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁFlash Player 30.0.0.113¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/adobe-patches-flash-zero-day-exploited-targeted-attacks-1


¡¾¶ñÒâÈí¼þ¡¿Ñо¿Ö°Ô±·¢Ã÷αװ³ÉÀÕË÷Èí¼þµÄÊý¾Ý²Á³ýÈí¼þRedEye


Ñо¿Ö°Ô±Bart Blaze·¢Ã÷ÐÂÀÕË÷Èí¼þRedEyeÏÖʵÉϲ¢Î´¼ÓÃÜÓû§µÄÎļþ£¬£¬£¬ £¬£¬£¬£¬¶øÊÇÓÃ0×Ö½ÚÁýÕÖÁËÎļþ£¬£¬£¬ £¬£¬£¬£¬Õ⽫µ¼ÖÂÓû§µÄÊý¾Ý±»³¹µ×ÆÆË𡣡£¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄ¿ª·¢ÕßËÆºõͬʱҲÊÇÀÕË÷Èí¼þAnnabelleµÄ¿ª·¢Õß¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷µÄ¶ñÒâÈí¼þÑù±¾¾ÞϸΪ35.0MB£¬£¬£¬ £¬£¬£¬£¬ÆäÖаüÀ¨ÓÃÓÚ·¢³ö¿Ö²ÀÉùÒôÏÅ»£Óû§µÄÈý¸ö.wavÎļþ£¨child.wav¡¢redeye.wavºÍsuicide.wav£©£¬£¬£¬ £¬£¬£¬£¬RedEyeѬȾϵͳºó»¹½«½ûÓÃʹÃüÖÎÀíÆ÷ÒÔ¼°Òþ²ØÇý¶¯Æ÷£¬£¬£¬ £¬£¬£¬£¬²¢Ìæ»»MBR¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/redeye-ransomware-destroys-files-rewrites-mbr


¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷ÔÙ´ÎÏ®»÷À­¶¡ÃÀÖÞ½ðÈÚ»ú¹¹µÄÐÂKillDisk±äÖÖ


Ç÷ÊÆ¿Æ¼¼Ñо¿ÍŶӷ¢Ã÷Ò»¸öеÄKillDisk±äÖÖ£¬£¬£¬ £¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÖ÷ÒªÕë¶ÔÀ­¶¡ÃÀÖ޵ĽðÈÚ»ú¹¹¡£¡£¡£¡£¡£¸Ã±äÖÖ»áÆÆËðϵͳµÄMBR£¬£¬£¬ £¬£¬£¬£¬¼´ÓÃ0x00ÁýÕÖÿһ¸öÎïÀí´ÅÅ̵ĵÚÒ»¸öÉÈÇø£¨512×Ö½Ú£©¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ã»Óз¢Ã÷¸Ã±äÖÖµÄC&CͨѶ£¬£¬£¬ £¬£¬£¬£¬Ò²Ã»Óз¢Ã÷ÀàËÆÀÕË÷Èí¼þµÄÐÐΪ£¬£¬£¬ £¬£¬£¬£¬¸Ã±äÖÖ²»ÐèÒª¾ÙÐÐÍøÂçͨѶ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/new-killdisk-variant-hits-latin-american-financial-organizations-again/