¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180710

Ðû²¼Ê±¼ä 2018-07-10

¡¾Êý¾Ýй¶¡¿TimehopÔâºÚ¿ÍÈëÇÖ£¬ £¬£¬Áè¼Ý2100ÍòÓû§µÄÊý¾Ýй¶


7ÔÂ4ÈÕÊ¢ÐеÄÉ罻ýÌåÓ¦ÓÃTimehopÔâºÚ¿ÍÈëÇÖ£¬ £¬£¬Áè¼Ý2100ÍòÓû§µÄСÎÒ˽¼ÒÊý¾Ýй¶£¬ £¬£¬°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµãÒÔ¼°Ô¼470Íò¸öµç»°ºÅÂë¡£ ¡£¡£¡£¡£TimehopÓÃÓÚ×ÊÖúÓû§´ÓiPhone¡¢Facebook¡¢InstagramºÍTwitterµÈÍøÂç¾ÉÕÕÆ¬ºÍÌû×Ó£¬ £¬£¬ÒÔ³äÆäʱ¼ä»úеµÄ¹¦Ð§¡£ ¡£¡£¡£¡£¹¥»÷Õß»¹»ñÈ¡ÁËÆäËüÉç½»ÍøÕ¾ÌṩӦTimehopµÄÊÚȨÁîÅÆ£¬ £¬£¬¿ÉÔÚδ¾­ÔÊÐíµÄÇéÐÎÏ»á¼ûÓû§ÔÚÆäËüÉç½»ÍøÕ¾ÉϵÄÌû×Ó¡£ ¡£¡£¡£¡£Õâ´ÎÊÂÎñµÄÔµ¹ÊÔ­ÓÉÊÇTimehopδ½ÓÄÉË«ÒòËØÈÏÖ¤À´ÖÎÀíÆäÔÆÅÌËãÇéÐÎµÄÆ¾Ö¤¡£ ¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/timehop-data-breach.html


¡¾Êý¾Ýй¶¡¿Domain FactoryÈ·ÈÏÔÚ1Ô·ÝÔâºÚ¿ÍÈëÇÖ£¬ £¬£¬²¿·ÖÓû§µÄÊý¾Ýй¶


µÂ¹úÍйÜЧÀÍÌṩÉÌDomainFactoryÈ·ÈÏÔÚ1Ô·ݱ¬·¢Êý¾Ýй¶ÊÂÎñ£¬ £¬£¬²¿·ÖÓû§µÄСÎÒ˽¼ÒÊý¾Ýй¶£¬ £¬£¬µ«¸Ã¹«Ë¾Î´Åû¶ÏêϸµÄÊý×Ö¡£ ¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨Óû§µÄÐÕÃû¡¢¹«Ë¾Ãû¡¢ÕË»§ID¡¢µØµã¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢³öÉúÈÕÆÚ¡¢ÒøÐп¨Õ˺ŵÈÐÅÏ¢£¬ £¬£¬ÍøÂç·¸·¨·Ö×Ó¿ÉʹÓÃÕâЩÊý¾Ý¾ÙÐÐÓÐÕë¶ÔÐÔµÄÉç»á¹¤³Ì¹¥»÷¡£ ¡£¡£¡£¡£DomainFactory½¨ÒéËùÓÐÓû§ÐÞ¸ÄÆäÃÜÂë¡£ ¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/web-hosting-server-hack.html


¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷Õë¶Ô°ÍÀÕ˹̹Õþ¸®»ú¹¹µÄAPT¹¥»÷¾íÍÁÖØÀ´


Check PointÑо¿ÍŶӷ¢Ã÷Õë¶Ô°ÍÀÕ˹̹Õþ¸®»ú¹¹µÄAPT¹¥»÷¾íÍÁÖØÀ´¡£ ¡£¡£¡£¡£ÕâЩ¹¥»÷×îÏÈÓÚ2018Äê3Ô£¬ £¬£¬¹¥»÷Õßͨ¹ý°üÀ¨¶ñÒâÈí¼þµÄ´¹ÂÚÓʼþѬȾĿµÄ£¬ £¬£¬¸Ã¶ñÒâÈí¼þ¿ÉÒÔÍøÂçÓû§µÄ.doc¡¢.odt¡¢.xls¡¢.pptºÍ.pdfÎļþ²¢·¢ËÍÖÁÔ¶³ÌЧÀÍÆ÷¡£ ¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ¸Ã¶ñÒâÈí¼þ¹²°üÀ¨13¸öÄ£¿£¿£¿ £¿£¿£¿£¿é£¬ £¬£¬µ«ÏÖÔÚÖ»ÄÜÈ·ÈÏÆäÖÐ5¸öÄ£¿£¿£¿ £¿£¿£¿£¿éµÄ¹¦Ð§¡£ ¡£¡£¡£¡£Check PointÒÔΪ¸ÃAPT¹¥»÷±³ºóµÄ×éÖ¯ÊÇGaza Cybergang¡£ ¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://research.checkpoint.com/apt-attack-middle-east-big-bang/


¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷ÌØ¹¤Èí¼þʹÓñ»ÇÔµÄD-LinkÊý×ÖÖ¤Êé¾ÙÐÐÊðÃû


ESETÑо¿ÍŶӷ¢Ã÷ʹÓñ»ÇÔÊý×ÖÖ¤Êé¾ÙÐÐÊðÃûµÄжñÒâÈí¼þ»î¶¯¡£ ¡£¡£¡£¡£µÚÒ»¸ö¶ñÒâÈí¼þÊÇPlead£¬ £¬£¬Ö÷ÒªÓÃÓÚÇÔÈ¡Óû§µÄÃô¸ÐÐÅÏ¢£¬ £¬£¬ÆäʹÓÃÁĘ̈Íå¿Æ¼¼¹«Ë¾D-LinkµÄÓÐÓÃÊý×ÖÖ¤Êé¾ÙÐÐÊðÃû¡£ ¡£¡£¡£¡£µÚ¶þ¸ö¶ñÒâÈí¼þÊÇÒ»¸öÃÜÂëÇÔÈ¡³ÌÐò£¬ £¬£¬Ö÷ÒªÓÃÓÚ´ÓChrome¡¢IE¡¢OutlookºÍFirefoxµÈÇÔÈ¡Óû§µÄÃÜÂ룬 £¬£¬ÆäʹÓÃÁËChanging Information Technology¹«Ë¾µÄÓÐÓÃÖ¤ÊéÊðÃû¡£ ¡£¡£¡£¡£ÕâÁ½¼Ò¹«Ë¾ÔÚ½Óµ½±¨¸æºóÒÑ»®·ÖÔÚ7ÔÂ3ÈÕºÍ4ÈÕ×÷·ÏÁ˱»ÇÔµÄÖ¤Êé¡£ ¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.welivesecurity.com/2018/07/09/certificates-stolen-taiwanese-tech-companies-plead-malware-campaign/


¡¾Îó²î²¹¶¡¡¿AppleÐû²¼Boot CampÇå¾²¸üУ¬ £¬£¬ÐÞ¸´3¸öWi-Fi KRACKÏà¹ØµÄÎó²î


AppleÐû²¼Boot Camp 6.4.0µÄÇå¾²¸üУ¬ £¬£¬ÐÞ¸´ÓëÈ¥ÄêÄêµ×Åû¶µÄWi-Fi KRACK¹¥»÷Ïà¹ØµÄ3¸öÇå¾²Îó²î£¨CVE-2017-13077¡¢CVE-2017-13078ºÍCVE-2017-13080£©¡£ ¡£¡£¡£¡£Boot CampÊÇmacOSÖÐµÄÆô¶¯¹¤¾ß£¬ £¬£¬¿ÉÔÊÐíÓû§ÔÚ»ùÓÚIntel CPUµÄMacÉÏ×°ÖÃWindows²Ù×÷ϵͳ¡£ ¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÇ¿ÖÆÔÚWPAµ¥²¥/PTK¿Í»§¶Ë»òWPA¶à²¥/GTK¿Í»§¶ËÖÐÖØ¸´Ê¹ÓÃnonce£¬ £¬£¬½¨ÒéÓû§¾¡¿ì¾ÙÐиüС£ ¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/apple-patches-krack-flaws-boot-camp


¡¾¶ñÒâÈí¼þ¡¿Ñо¿Ö°Ô±·¢Ã÷ÀÕË÷Èí¼þKingOuroborosµÄбäÖÖ


Ñо¿Ö°Ô±ÔÚ2018Äê6ÔÂÏÂÑ®·¢Ã÷ÀÕË÷Èí¼þKingOuroborosµÄбäÖÖ£¬ £¬£¬¸Ã±äÖÖαװ³ÉJava Update Scheduler³ÌÐò£¨jusched.exe£©¾ÙÐÐÈö²¥£¬ £¬£¬Í¨¹ýAES¼ÓÃÜÓû§µÄÊý¾Ý£¬ £¬£¬²¢ÔÚ¼ÓÃܵÄÎļþµÄÔ­ÎļþÃûºÍÀ©Õ¹ÃûÖ®¼äÌí¼Ó.king_ouroborosÀ©Õ¹Ãû¡£ ¡£¡£¡£¡£¸Ã±äÖÖµÄÊê½ðΪ¼ÛÖµ50-80ÃÀÔªµÄ±ÈÌØ±Ò£¬ £¬£¬ÆäÀÕË÷ÐÅÏ¢ÖаüÀ¨12ÖÖÓïÑԵķ­Òë¡£ ¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://id-ransomware.blogspot.com/2018/06/kingouroboros-ransomware.html