¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180619

°ä²¼¹¦·ò 2018-06-19

¡¾·ÖÎö»ã±¨¡¿×êÑÐÍŶӰ䲼2018ÄêQ1ÍøÂç´¹µö¹¥»÷Ç÷ÏòµÄ·ÖÎö»ã±¨

Palo Alto NetworksµÄUnit42×êÑÐÍŶÓͳ¼ÆÁË2018ÄêµÚÒ»¼¾¶È£¨1ÔÂÖÁ3ÔÂÆÚ¼ä£©µÄÍøÂç´¹µö¹¥»÷ £¬¹²·¢ÏÖÁËÀ´×Ô262¸ö·ÖÆçÓòÃûµÄ4213¸ö´¹µöURL £¬¾ùÔÈÒ»¸öÓòÃû¹ØÁª16¸ö·ÖÆçµÄ´¹µöURL¡£Ô¼150¸ö´¹µöÓòÃûÍйÜÔÚÃÀ¹ú £¬Æä´ÎÊǵ¹ú£¨28¸ö£©ºÍ²¨À¼£¨13¸ö£©¡£ÓÐ2066¸ö´¹µöURLʹÓÃͨÓô¹µöÄ£°å £¬Ê¹ÆäÄܹ»Õë¶Ô¶à¸ö·ÖÆçµÄ¹«Ë¾»ò×éÖ¯¡£À´×ÔÓÚ46¸ö·ÖÆçÓòÃûµÄ1010¸ö´¹µöURLÊÇ»ùÓÚHTTPSµÄ¡£

Ô­ÎÄÁ´½Ó£ºhttps://researchcenter.paloaltonetworks.com/2018/06/unit42-phishing-nutshell-january-march-2018/

rightrightright¡¾¶ñÒâÈí¼þ¡¿×êÑÐÈËÔ±·¢ÏÖÖØÒªÕë¶ÔÃÀ¹úWin10Óû§µÄ¸æ°×Èí¼þZacinlo

BitdefenderµÄ°²È«×êÑÐÈËÔ±·¢ÏÖÖØÒªÕë¶ÔÃÀ¹úWin10Óû§µÄ¸æ°×Èí¼þZacinlo¡£ZacinloÔ̺¬Ò»¸örootkitÄ£¿é £¬¸ÃÄ£¿é¿É×èÖ¹¶Ô¸æ°×Èí¼þÖ°ÄÜÔì³ÉΣÏյĹý³Ì £¬Í¬Ê±± £»¤¸æ°×Èí¼þ²»±»À¹½Ø»òɾ³ý¡£Zacinlo´Ó2012ÄêÆðÆðÍ·»îÔ¾ £¬ËüÄܹ»Ö´ÐÐÖÐÑëÈ˹¥»÷ £¬½«¸æ°××¢Èëµ½Óû§½Ó¼ûµÄÍøÒ³ÖÐ £¬ÉõÖÁ»¹Äܹ»½øÐÐ½ØÆÁ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/rootkit-based-adware-wreaks-havoc-among-windows-10-users-in-the-us/

rightrightright¡¾·ì϶²¹¶¡¡¿ÈðµäAxis Communications AB½¨¸´392¸öÉãÏñ»úÐͺÅÖеÄ7¸ö°²È«·ì϶

Èðµä³§ÉÌAxis Communications AB½¨¸´ÁË392¸öÉãÏñ»úÐͺÅÖеÄ7¸ö°²È«·ì϶ £¬Ô̺¬¿Éµ¼ÖÂ/bin/ssid¹ý³Ì±ÀÀ£µÄ·ì϶£¨CVE-2018-10658ºÍCVE-2018-10659£©¡¢ShellºÅÁî×¢Èë·ì϶£¨CVE-2018-10660£©¡¢È¨ÏÞÈÆ¹ý·ì϶£¨CVE-2018-10661£©¡¢dbus½Ó¼û²»ÊÜÏÞ·ì϶£¨CVE-2018-10662£©¡¢ÐÅϢй¶·ì϶£¨CVE-2018-10663£©ºÍ¿Éµ¼ÖÂhttpd¹ý³Ì±ÀÀ£µÄ·ì϶£¨CVE-2018-10664£©¡£°²È«³§ÉÌVDOO·¢ÏÖÁËÕâЩ·ì϶ £¬²¢Åû¶ÁËÓйØPoC¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/vendor-patches-seven-vulnerabilities-across-392-camera-models/

rightrightright¡¾Íþвµý±¨¡¿US-CERTÕë¶Ô³¯ÏʶñÒâÈí¼þTypeframe°ä²¼ÖÒ¸æ

US-CERTÕë¶Ô³¯ÏʵÄжñÒâÈí¼þTypeframe°ä²¼ÖÒ¸æ £¬¸Ã¶ñÒâÈí¼þÓ볯ÏÊAPT×éÖ¯Hidden CobraÓйØ¡£Õâ·Ý¶ñÒâÈí¼þ·ÖÎö»ã±¨£¨MAR£©ÓÉÃÀ¹úºÓɽ°²È«Êý£¨DHS£©ºÍÁª¹úµ÷²é¾Ö£¨FBI£©¹²Í¬±àд £¬»ã±¨ÖзÖÎöÁ˶ñÒâÈí¼þµÄ11¸öÑù±¾ £¬ÆäÖ°ÄÜÔ̺¬ÏÂÔØºÍ×°ÖöñÒâÈí¼þ¡¢×°ÖôúÀíºÍRAT¡¢ÏνÓC2·þÎñÆ÷²¢½ÓÊÜÖ¸ÁîÒÔ¼°Åú¸Ä·À»ðǽµÈ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/uscert-uncovers-north-korean/

rightrightright¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±ÖÒ¸æ³Æ¶ñÒâÈí¼þͨ¹ý¼Ù×°³Éµï±¤Ö®Ò¹°²×¿°æ½øÐд«²¼

ESETµÄ¶ñÒâÈí¼þ×êÑÐÈËÔ±Lukas Stefanko·¢ÏÖ²¿ÃŶñÒâÈí¼þͨ¹ý¼Ù×°³Éµï±¤Ö®Ò¹µÄ°²×¿°æ½øÐд«²¼¡£µï±¤Ö®Ò¹ÔÚÈ«ÇòÕ¼Óг¬¹ý1.25ÒÚÍæ¼Ò £¬µ«Æä¹Ù·½°²×¿°æ±¾ÉÐδ°ä²¼¡£×êÑÐÈËÔ±·¢ÏÖGoogleºÍYouTubeÉϵÄһЩÊÓÆµºÍÁ´½ÓÐû³ÆÆäÔ̺¬µï±¤Ö®Ò¹µÄAPKÎļþ £¬»òÊÇÊèµ¼Óû§×°ÖÃһЩÆäËüÀûÓÃÒÔ½âËø¸ÃÓÎÏ· £¬Õ⽫¸ø¶ñÒâÈí¼þ¿ª·¢ÈËÔ±´øÀ´ÊÕÈë»òÇÖº¦Óû§µÄ°²×¿É豸¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/fortnite-for-android-apk.html

rightrightright¡¾Íþвµý±¨¡¿°²µÏAndroid·ÂÕÕÆ÷±»ÆØÔÚÓû§µÄ»úеÉÏ×°ÖÃGPUÍÚ¿óÈí¼þ

RedditÓû§TopWireÔÚһƪÎÄÕÂÖгư²µÏAndroid·ÂÕÕÆ÷ÔÚÓû§²»ÖªÇéµÄÇé¿öÏÂ×°ÖÃÁËÒ»¸öGPUÍÚ¿óÈí¼þ £¬¸Ã¿ó¹¤ÔÚÔËÐÐʱ»áºÄ¾¡Óû§µÄGPU×ÊÔ´¡£¸Ã¶ñÒâÎļþÊǰ²µÏAndroid·ÂÕÕÆ÷ÔÚ×°ÖÃʱ´´½¨µÄÒ»¸öupdater.exe £¬VirusTotalµÄɨÃèÁ˾ÖÏÔʾÕâÊÇÒ»¸ö¶ñÒâ¿ó¹¤¡£°²µÏ¿ª·¢ÈËÔ±ÉÐδ½øÐлØÓ¦¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/andy-os-android-emulator-reportedly-installing-a-gpu-miner/