¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180608

°ä²¼¹¦·ò 2018-06-08
¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±·¢ÏÖ³¬¹ý4Íò¸öÉ豸ϰȾ½©Ê¬ÍøÂçProwli


GuardiCore°²È«×êÑÐÈËÔ±·¢ÏÖ³¬¹ý4Íò¸öÉ豸ϰȾÁ˽©Ê¬ÍøÂçProwli £¬ÕâЩÉ豸ÆðÔ´ÓÚ½ðÈÚ¡¢½ÌÓýºÍµ±¾Ö»ú¹¹µÄ9000¶à¸ö×éÖ¯ £¬Ô̺¬·þÎñÆ÷¡¢Â·ÓÉÆ÷ºÍIoTÉ豸µÈ¡£ÓÉÓÚ¹¥»÷ÕßÊÔͼͨ¹ý¸Ã½©Ê¬ÍøÂç½øÐжñÒâÍÚ¿ó»î¶¯ÒÔ¼°½«Óû§³Á¶¨ÏòÖÁ¶ñÒâÍøÕ¾ £¬×êÑÐÈËÔ±ÒÔΪProwliµÄÖØÒª¶¯»úÊǾ­¼ÃÀûÒæ £¬¶ø²»ÊÇÍøÂç¼äµý»î¶¯¡£Prowli»áÔÚÊÜϰȾµÄÉ豸ÉÏ×°ÖÃÃÅÂޱҿ󹤺Ír2r2È䳿 £¬»¹»á½«ÍøÕ¾µÄ½Ó¼ûÕß³Á¶¨Ïòµ½ÓÃÓÚ´«²¼¶ñÒâä¯ÀÀÆ÷²å¼þµÄ´¹µöÍøÕ¾¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/prowli-malware-botnet.html


¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±³ÆAuth0´æÔÚ°²È«·çÏÕ £¬¿ÉÔÊÐí¹¥»÷ÕßÌáÒé´¹µö¹¥»÷


ImpervaµÄ×êÑÐÈËÔ±ÖÒ¸æ³ÆAuth0µÄ×ÓÓòÃûϵͳ´æÔÚDZÔڵݲȫ·çÏÕ £¬¿É±»¹¥»÷ÕßÀûÓÃÒÔÌáÒé´¹µö¹¥»÷¡£Auth0ÊÇÒ»¸öÉí·Ý¼´·þÎñµÄƽ̨ £¬ÆäÔÚ70¶à¸ö¹ú¶ÈÕ¼ÓÐÔ¼2000¼ÒÆóÒµ¿Í»§¡£Auth0Õ¼ÓÐ3¸ö×ÓÓòÃû £¬±ðÀëÓÃÓÚÃÀÖÞ¡¢Å·ÖÞºÍÑÇÌ«µØÓòµÄ¿Í»§¡£×êÑÐÈËÔ±³Æ¹¥»÷ÕßÄܹ»ÀûÓÃ·ÖÆçµØÓòµÄ×ÓÓòÃûÀ´¹¹½¨´¹µöÍøÕ¾ £¬ÒÔ¼Ù×°³ÉÆäËû×ÓÓòÃûϵĺϷ¨ÍøÕ¾ £¬ÕâÖÖ¹¥»÷ÄÑÒÔ±»¼ø±ð¡£


Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/auth0-glitch-allows-attackers-to-launch-phishing-attacks/132554/


¡¾·ì϶²¹¶¡¡¿×êÑÐÈËÔ±·¢ÏÖChrome´æÔÚÑϳÁ·ì϶ £¬½¨ÒéÓû§¾¡¿ì¸üÐÂ


°²È«×êÑÐÈËÔ±Micha?Bentkowski·¢ÏÖ²¢»ã±¨ÁËChromeÖеÄÒ»¸öÑϳÁ·ì϶ £¬¸Ã·ì϶ӰÏìÁËËùÓÐÆ½Ì¨£¨Ô̺¬Windows¡¢MacºÍLinux£©µÄChrome°æ±¾¡£Chrome°²È«ÍŶÓûÓÐÅû¶¹ØÓڸ÷ì϶µÄÈκμ¼Êõϸ½Ú £¬Ö»Êǽ«¸Ã·ìϼûèÊöΪ²»ÕýÈ·µÄCSPÍ·£¨Content Security Policy £¬ÄÚÈݰ²È«Õ½Êõ£©´¦Ö÷ì϶£¨CVE-2018-6148£©¡£ChromeÒÑÔÚ¸üÐÂ67.0.3396.79Öн¨¸´Á˸÷ì϶ £¬½¨ÒéÓû§¾¡¿ì½øÐиüС£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/google-chrome-csp.html


¡¾·ì϶²¹¶¡¡¿Adobe°ä²¼Flash PlayerµÄ°²È«¸üР£¬½¨¸´4¸ö°²È«·ì϶


±¾ÖÜËÄAdob??e°ä²¼Flash PlayerµÄ°²È«¸üР£¬¹²½¨¸´4¸ö°²È«·ì϶¡£ÆäÖзì϶£¨CVE-2018-5002£©ÊÇ»ùÓÚÕ»µÄ»º³åÇøÒç³öµ¼ÖµÄËÁÒâ´úÂëÖ´Ðзì϶ £¬ÒÑÓй¥»÷ÕßÀûÓø÷ì϶Õë¶ÔÖж«µÄÆóÒµÌáÒé¹¥»÷¡£Áí±í3¸ö·ì϶Ô̺¬¿Éµ¼Ö´úÂëÖ´ÐеÄÀàÐÍ»ìºÏ·ì϶£¨CVE-2018-4945£©¡¢¿Éµ¼ÖÂÐÅϢй¶µÄÕûÊýÒç¶Âí½Å£¨CVE-2018- 5000£©ºÍ¿Éµ¼ÖÂÐÅϢй¶µÄÔ½½ç¶Á·ì϶£¨CVE-2018-5001£©¡£½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁFlash Player 30.0.0.113¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/adobe-patches-flash-zero-day-exploited-targeted-attacks-1


¡¾¶ñÒâÈí¼þ¡¿×êÑÐÈËÔ±·¢ÏÖ¼Ù×°³ÉÀÕË÷Èí¼þµÄÊý¾Ý²Á³ýÈí¼þRedEye


×êÑÐÈËÔ±Bart Blaze·¢ÏÖÐÂÀÕË÷Èí¼þRedEyeÏÖʵÉϲ¢Î´¼ÓÃÜÓû§µÄÎļþ £¬¶øÊÇÓÃ0×Ö½Ú¸²¸ÇÁËÎļþ £¬Õ⽫µ¼ÖÂÓû§µÄÊý¾Ý±»³¹µ×·ÛËé¡£¸Ã¶ñÒâÈí¼þµÄ¿ª·¢ÕßËÆºõͬʱҲÊÇÀÕË÷Èí¼þAnnabelleµÄ¿ª·¢Õß¡£×êÑÐÈËÔ±·¢ÏֵĶñÒâÈí¼þÑù±¾´óÓ×Ϊ35.0MB £¬ÆäÖÐÔ̺¬ÓÃÓÚ·¢³ö¿Ö²ÀÉùÒôÏÅ»£Óû§µÄÈý¸ö.wavÎļþ£¨child.wav¡¢redeye.wavºÍsuicide.wav£© £¬RedEyeϰȾϵͳºó»¹½«½ûÓù¤×÷ÖÎÀíÆ÷ÒÔ¼°°µ²ØÇý¶¯Æ÷ £¬²¢´úÌæMBR¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/redeye-ransomware-destroys-files-rewrites-mbr


¡¾¶ñÒâÈí¼þ¡¿×êÑÐÍŶӷ¢ÏÖÔÙ´ÎÏ®»÷À­¶¡ÃÀÖÞ½ðÈÚ»ú¹¹µÄÐÂKillDisk±äÖÖ


Ç÷Ïò¿Æ¼¼×êÑÐÍŶӷ¢ÏÖÒ»¸öеÄKillDisk±äÖÖ £¬¸Ã¶ñÒâÈí¼þÖØÒªÕë¶ÔÀ­¶¡ÃÀÖ޵ĽðÈÚ»ú¹¹¡£¸Ã±äÖÖ»á·ÛËéϵͳµÄMBR £¬¼´ÓÃ0x00¸²¸Çÿһ¸öÎïÀí´ÅÅ̵ĵÚÒ»¸öÉÈÇø£¨512×Ö½Ú£©¡£×êÑÐÈËԱûÓз¢ÏָñäÖÖµÄC&CͨѶ £¬Ò²Ã»Óз¢ÏÖÀàËÆÀÕË÷Èí¼þµÄÐÐΪ £¬¸Ã±äÖÖ²»±ØÒª½øÐÐÍøÂçͨѶ¡£


Ô­ÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/new-killdisk-variant-hits-latin-american-financial-organizations-again/