¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190104
Ðû²¼Ê±¼ä 2019-01-04
1ÔÂ3ÈÕAdobeÐû²¼Ç徲ͨ¸æAPSB19-02£¬£¬£¬ÐÞ¸´ÁËAdobe AcrobatºÍReaderÖеÄÁ½¸ö¸ßΣÎó²î¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸öÎó²î£¨CVE-2018-16011£©¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐУ¬£¬£¬µÚ¶þ¸öÎó²î£¨CVE-2018-19725£©ÔòÊÇÒ»¸öÌáȨÎó²î¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸öÎó²îÊÇÓÉÇ÷ÊÆ¿Æ¼¼µÄZDIÌá½»µÄ£¬£¬£¬½¨ÒéÓû§¾¡¿ìÉý¼¶ÖÁAcrobat DC/Acrobat ReaderµÄ×îа汾2019.010.20069¡¢2017.011.30113ºÍ2015.006.30464¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/adobe-acrobat-and-reader-security-updates-released-for-critical-bugs/2¡¢¹È¸èÐÞ¸´Android°æChromeÖб£´æ3ÄêµÄÒþ˽й¶Îó²î

¹È¸è×îÖÕÐÞ¸´ÁËÊÊÓÃÓÚAndroidµÄChromeä¯ÀÀÆ÷ÖеÄÒ»¸öÒþ˽й¶Îó²î¡£¡£¡£¡£¡£¡£¡£Nightwatch Cybersecurity¹«Ë¾µÄYakov ShafranovichÔøÔÚ2015ÄêÏò¹È¸è±¨¸æ¹ý´ËÎÊÌ⣬£¬£¬µ«¹È¸èÆäʱ³ÆÕâ²»ÊÇÒ»¸öÎó²î¡£¡£¡£¡£¡£¡£¡£ÔÚ2018Äê7Ô·ÝChromiumÂÛ̳ÉÏÒ»¸öÓû§ÔÙ´ÎÅû¶´ËÎó²îºó£¬£¬£¬¹È¸èÔÚChrome 70ÖÐÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓëChromeÌìÉúµÄUser Agent×Ö·û´®°üÀ¨Android°æ±¾ºÅ¡¢×°±¸Ãû³Æ¼°¹Ì¼þ°æ±¾ÐÅÏ¢Óйأ¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÈ·¶¨×°±¸µÄÇå¾²²¹¶¡¼¶±ð£¬£¬£¬´Ó¶øÌᳫÕë¶ÔÐԵĹ¥»÷¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/google-chrome-android-privacy.html3¡¢¶¼°ØÁÖÓйìµç³µÏµÍ³Luas¹ÙÍø±»ºÚ£¬£¬£¬ºÚ¿ÍÀÕË÷3800ÃÀÔª

°®¶ûÀ¼Ê×¶¼¶¼°ØÁÖµÄÓйìµç³µÏµÍ³LuasµÄ¹ÙÍøÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬¹¥»÷ÕßÉù³Æ´ÓLuasµÄÔËÓªÉÌTransdev Ireland´¦ÇÔÈ¡ÁËÊý¾Ý£¬£¬£¬²¢ÒªÇóÔÚÎåÌìÄÚÖ§¸¶Ò»¸ö±ÈÌØ±Ò£¨¼ÛÖµÔ¼3800ÃÀÔª£©µÄÊê½ð¡£¡£¡£¡£¡£¡£¡£LuasÒѽ«¹ÙÍøÀëÏß²¢¾ÙÐÐÇå¾²¼ì²é¡£¡£¡£¡£¡£¡£¡£ºÃÐÂÎÅÊÇLuasµÄÔËӪЧÀͲ¢Î´Êܵ½Ó°Ï죬£¬£¬ÓοÍÖ»ÊÇÎÞ·¨´Ó¹ÙÍøÉÏÅÌÎʵ糵µÄʱ¿Ì±í¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/hackers-demand-ransom-luas-website-defaced/4¡¢NRSMinerбäÌåÏ®»÷ÑÇÖÞ£¬£¬£¬Ê¹ÓÃEternalBlueÎó²îÈö²¥

F-SecureµÄÇå¾²Ñо¿Ö°Ô±·¢Ã÷NRSMinerµÄбäÌåʹÓÃEternalBlueÎó²î¹¥»÷ÑÇÖÞµØÇøµÄ¹ú¼Ò¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯´Ó2018Äê11ÔÂÖÐÑ®×îÏÈ£¬£¬£¬Ö÷ÒªÕë¶ÔÔ½ÄÏ¡¢Öйú¡¢ÈÕ±¾ºÍ¶ò¹Ï¶à¶ûµÈ¡£¡£¡£¡£¡£¡£¡£NRSMinerʹÓÃÃÅÂÞ±Ò¿ó¹¤XMRig¾ÙÐÐÍڿ󣬣¬£¬»¹¿ÉÒÔÏÂÔØ¸üеÄÄ£¿£¿£¿£¿£¿£¿£¿é²¢Ìæ»»¾É°æ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃEternalBlueÈö²¥µÄÍÚ¿óľÂí»¹°üÀ¨WannamineºÍRedisWannaMineµÈ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/revamped-cryptominer-is-striking-asia-through-eternal-blue-exploit/5¡¢ÀÕË÷Èí¼þFilesLockerÖ÷½âÃÜÃÜÔ¿±»·Å³ö£¬£¬£¬Ñо¿Ö°Ô±ÒÑ¿ª·¢³ö½âÃÜÆ÷

2018Äê12ÔÂ29ÈÕ£¬£¬£¬Î´ÖªÓû§ÔÚPastbinÉÏ·¢Ìû·Å³öÁËÀÕË÷Èí¼þFilesLockerµÄÖ÷½âÃÜÃÜÔ¿£¬£¬£¬ËæºóÑо¿Ö°Ô±Michael GillespieʹÓøÃÃÜÔ¿½¨ÉèÁËFilesLockerµÄ½âÃÜÆ÷¡£¡£¡£¡£¡£¡£¡£¸Ã½âÃÜÆ÷¿É½âÃÜFilesLocker v1ºÍv2¼ÓÃܵÄÎļþ£¨Îļþºó׺ÃûΪ.[fileslocker@pm.me]£©¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎú¸Ã½âÃÜÃÜԿΪʲô±»ÊÍ·Å£¬£¬£¬µ«ÓпÉÄÜÊÇÀÕË÷Èí¼þ¿ª·¢Õß¾öÒé¿¢ÊÂÏîÄ¿»òÖØÐÂ×îÏÈеÄÏîÄ¿¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/master-decryption-key-released-for-fileslocker-ransomware/6¡¢ÃÜÂëÖÎÀíÆ÷BlurÓû§Êý¾Ýй¶£¬£¬£¬240ÍòÈËÊܵ½Ó°Ïì

±¾ÖÜÒ»Abine¹«Ë¾ÌåÏÖÆäÃÜÂëÖÎÀíÆ÷²úÆ·BlurµÄÓû§Êý¾ÝÔÚЧÀÍÆ÷ÉÏ̻¶£¬£¬£¬ÕâЩÊý¾Ý°üÀ¨2018Äê1ÔÂ6ÈÕ֮ǰע²áµÄBlurÓû§µÄÐÅÏ¢£¬£¬£¬Èçµç×ÓÓʼþµØµã¡¢ÐÕÃû¡¢ÃÜÂëÌáÐÑÓï¡¢×îºóµÇ¼IPºÍ¼ÓÑÎÃÜÂë¹þÏ£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ç¿µ÷³ÆÓû§µÄÃÜÂë¡¢ÐÅÓÿ¨ÐÅÏ¢ºÍµç»°ºÅÂëûÓÐй¶¡£¡£¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñÓ°ÏìÁËÔ¼240ÍòBlurÓû§¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/data-of-2-4-million-blur-password-manager-users-left-exposed-online/ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí