¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180710
Ðû²¼Ê±¼ä 2018-07-10¡¾Êý¾Ýй¶¡¿TimehopÔâºÚ¿ÍÈëÇÖ£¬£¬£¬Áè¼Ý2100ÍòÓû§µÄÊý¾Ýй¶
7ÔÂ4ÈÕÊ¢ÐеÄÉ罻ýÌåÓ¦ÓÃTimehopÔâºÚ¿ÍÈëÇÖ£¬£¬£¬Áè¼Ý2100ÍòÓû§µÄСÎÒ˽¼ÒÊý¾Ýй¶£¬£¬£¬°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµãÒÔ¼°Ô¼470Íò¸öµç»°ºÅÂë¡£¡£¡£¡£¡£TimehopÓÃÓÚ×ÊÖúÓû§´ÓiPhone¡¢Facebook¡¢InstagramºÍTwitterµÈÍøÂç¾ÉÕÕÆ¬ºÍÌû×Ó£¬£¬£¬ÒÔ³äÆäʱ¼ä»úеµÄ¹¦Ð§¡£¡£¡£¡£¡£¹¥»÷Õß»¹»ñÈ¡ÁËÆäËüÉç½»ÍøÕ¾ÌṩӦTimehopµÄÊÚȨÁîÅÆ£¬£¬£¬¿ÉÔÚδ¾ÔÊÐíµÄÇéÐÎÏ»á¼ûÓû§ÔÚÆäËüÉç½»ÍøÕ¾ÉϵÄÌû×Ó¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñµÄÔµ¹ÊÔÓÉÊÇTimehopδ½ÓÄÉË«ÒòËØÈÏÖ¤À´ÖÎÀíÆäÔÆÅÌËãÇéÐÎµÄÆ¾Ö¤¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/timehop-data-breach.html
¡¾Êý¾Ýй¶¡¿Domain FactoryÈ·ÈÏÔÚ1Ô·ÝÔâºÚ¿ÍÈëÇÖ£¬£¬£¬²¿·ÖÓû§µÄÊý¾Ýй¶
µÂ¹úÍйÜЧÀÍÌṩÉÌDomainFactoryÈ·ÈÏÔÚ1Ô·ݱ¬·¢Êý¾Ýй¶ÊÂÎñ£¬£¬£¬²¿·ÖÓû§µÄСÎÒ˽¼ÒÊý¾Ýй¶£¬£¬£¬µ«¸Ã¹«Ë¾Î´Åû¶ÏêϸµÄÊý×Ö¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨Óû§µÄÐÕÃû¡¢¹«Ë¾Ãû¡¢ÕË»§ID¡¢µØµã¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢³öÉúÈÕÆÚ¡¢ÒøÐп¨Õ˺ŵÈÐÅÏ¢£¬£¬£¬ÍøÂç·¸·¨·Ö×Ó¿ÉʹÓÃÕâЩÊý¾Ý¾ÙÐÐÓÐÕë¶ÔÐÔµÄÉç»á¹¤³Ì¹¥»÷¡£¡£¡£¡£¡£DomainFactory½¨ÒéËùÓÐÓû§ÐÞ¸ÄÆäÃÜÂë¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/web-hosting-server-hack.html
¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷Õë¶Ô°ÍÀÕ˹̹Õþ¸®»ú¹¹µÄAPT¹¥»÷¾íÍÁÖØÀ´
Check PointÑо¿ÍŶӷ¢Ã÷Õë¶Ô°ÍÀÕ˹̹Õþ¸®»ú¹¹µÄAPT¹¥»÷¾íÍÁÖØÀ´¡£¡£¡£¡£¡£ÕâЩ¹¥»÷×îÏÈÓÚ2018Äê3Ô£¬£¬£¬¹¥»÷Õßͨ¹ý°üÀ¨¶ñÒâÈí¼þµÄ´¹ÂÚÓʼþѬȾĿµÄ£¬£¬£¬¸Ã¶ñÒâÈí¼þ¿ÉÒÔÍøÂçÓû§µÄ.doc¡¢.odt¡¢.xls¡¢.pptºÍ.pdfÎļþ²¢·¢ËÍÖÁÔ¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ¸Ã¶ñÒâÈí¼þ¹²°üÀ¨13¸öÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬µ«ÏÖÔÚÖ»ÄÜÈ·ÈÏÆäÖÐ5¸öÄ£¿£¿£¿£¿£¿£¿£¿éµÄ¹¦Ð§¡£¡£¡£¡£¡£Check PointÒÔΪ¸ÃAPT¹¥»÷±³ºóµÄ×éÖ¯ÊÇGaza Cybergang¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://research.checkpoint.com/apt-attack-middle-east-big-bang/
¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷ÌØ¹¤Èí¼þʹÓñ»ÇÔµÄD-LinkÊý×ÖÖ¤Êé¾ÙÐÐÊðÃû
ESETÑо¿ÍŶӷ¢Ã÷ʹÓñ»ÇÔÊý×ÖÖ¤Êé¾ÙÐÐÊðÃûµÄжñÒâÈí¼þ»î¶¯¡£¡£¡£¡£¡£µÚÒ»¸ö¶ñÒâÈí¼þÊÇPlead£¬£¬£¬Ö÷ÒªÓÃÓÚÇÔÈ¡Óû§µÄÃô¸ÐÐÅÏ¢£¬£¬£¬ÆäʹÓÃÁĘ̈Íå¿Æ¼¼¹«Ë¾D-LinkµÄÓÐÓÃÊý×ÖÖ¤Êé¾ÙÐÐÊðÃû¡£¡£¡£¡£¡£µÚ¶þ¸ö¶ñÒâÈí¼þÊÇÒ»¸öÃÜÂëÇÔÈ¡³ÌÐò£¬£¬£¬Ö÷ÒªÓÃÓÚ´ÓChrome¡¢IE¡¢OutlookºÍFirefoxµÈÇÔÈ¡Óû§µÄÃÜÂ룬£¬£¬ÆäʹÓÃÁËChanging Information Technology¹«Ë¾µÄÓÐÓÃÖ¤ÊéÊðÃû¡£¡£¡£¡£¡£ÕâÁ½¼Ò¹«Ë¾ÔÚ½Óµ½±¨¸æºóÒÑ»®·ÖÔÚ7ÔÂ3ÈÕºÍ4ÈÕ×÷·ÏÁ˱»ÇÔµÄÖ¤Êé¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.welivesecurity.com/2018/07/09/certificates-stolen-taiwanese-tech-companies-plead-malware-campaign/
¡¾Îó²î²¹¶¡¡¿AppleÐû²¼Boot CampÇå¾²¸üУ¬£¬£¬ÐÞ¸´3¸öWi-Fi KRACKÏà¹ØµÄÎó²î
AppleÐû²¼Boot Camp 6.4.0µÄÇå¾²¸üУ¬£¬£¬ÐÞ¸´ÓëÈ¥ÄêÄêµ×Åû¶µÄWi-Fi KRACK¹¥»÷Ïà¹ØµÄ3¸öÇå¾²Îó²î£¨CVE-2017-13077¡¢CVE-2017-13078ºÍCVE-2017-13080£©¡£¡£¡£¡£¡£Boot CampÊÇmacOSÖÐµÄÆô¶¯¹¤¾ß£¬£¬£¬¿ÉÔÊÐíÓû§ÔÚ»ùÓÚIntel CPUµÄMacÉÏ×°ÖÃWindows²Ù×÷ϵͳ¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÇ¿ÖÆÔÚWPAµ¥²¥/PTK¿Í»§¶Ë»òWPA¶à²¥/GTK¿Í»§¶ËÖÐÖØ¸´Ê¹ÓÃnonce£¬£¬£¬½¨ÒéÓû§¾¡¿ì¾ÙÐиüС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/apple-patches-krack-flaws-boot-camp
¡¾¶ñÒâÈí¼þ¡¿Ñо¿Ö°Ô±·¢Ã÷ÀÕË÷Èí¼þKingOuroborosµÄбäÖÖ
Ñо¿Ö°Ô±ÔÚ2018Äê6ÔÂÏÂÑ®·¢Ã÷ÀÕË÷Èí¼þKingOuroborosµÄбäÖÖ£¬£¬£¬¸Ã±äÖÖαװ³ÉJava Update Scheduler³ÌÐò£¨jusched.exe£©¾ÙÐÐÈö²¥£¬£¬£¬Í¨¹ýAES¼ÓÃÜÓû§µÄÊý¾Ý£¬£¬£¬²¢ÔÚ¼ÓÃܵÄÎļþµÄÔÎļþÃûºÍÀ©Õ¹ÃûÖ®¼äÌí¼Ó.king_ouroborosÀ©Õ¹Ãû¡£¡£¡£¡£¡£¸Ã±äÖÖµÄÊê½ðΪ¼ÛÖµ50-80ÃÀÔªµÄ±ÈÌØ±Ò£¬£¬£¬ÆäÀÕË÷ÐÅÏ¢ÖаüÀ¨12ÖÖÓïÑԵķÒë¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://id-ransomware.blogspot.com/2018/06/kingouroboros-ransomware.html