¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180710

°ä²¼¹¦·ò 2018-07-10

¡¾Êý¾Ýй¶¡¿TimehopÔâºÚ¿ÍÈëÇÖ£¬³¬¹ý2100ÍòÓû§µÄÊý¾Ýй¶


7ÔÂ4ÈÕÊ¢ÐеÄÉ罻ýÌåÀûÓÃTimehopÔâºÚ¿ÍÈëÇÖ£¬³¬¹ý2100ÍòÓû§µÄÓ×ÎÒÊý¾Ýй¶£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·ÒÔ¼°Ô¼470Íò¸öµç»°ºÅÂë¡£TimehopÓÃÓÚÔ®ÊÖÓû§´ÓiPhone¡¢Facebook¡¢InstagramºÍTwitterµÈÍøÂç¾ÉÕÕÆ¬ºÍÌû×Ó£¬ÒÔ³äÈι¦·ò»úеµÄÖ°ÄÜ¡£¹¥»÷Õß»¹»ñÈ¡ÁËÆäËüÉç½»ÍøÕ¾Ìṩ¸øTimehopµÄÊÚȨÁîÅÆ£¬¿ÉÔÚδ¾­Ðí¿ÉµÄÇé¿öϽӼûÓû§ÔÚÆäËüÉç½»ÍøÕ¾ÉϵÄÌû×Ó¡£Õâ´ÎÊÂÎñµÄÔ­ÒòÊÇTimehopδѡȡ˫³É·ÖÈÏÖ¤À´ÖÎÀíÆäÔÆÍÆËã»·¾³µÄÍ´´¦¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/timehop-data-breach.html


¡¾Êý¾Ýй¶¡¿Domain FactoryÈ·ÈÏÔÚ1Ô·ÝÔâºÚ¿ÍÈëÇÖ£¬²¿ÃÅÓû§µÄÊý¾Ýй¶


µÂ¹úÍйܷþÎñÌṩÉÌDomainFactoryÈ·ÈÏÔÚ1Ô·ݲúÉúÊý¾Ýй¶ÊÂÎñ£¬²¿ÃÅÓû§µÄÓ×ÎÒÊý¾Ýй¶£¬µ«¸Ã¹«Ë¾Î´Åû¶¾ßÌåµÄÊý×Ö¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬Óû§µÄÐÕÃû¡¢¹«Ë¾Ãû¡¢ÕË»§ID¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢ÒøÐп¨Õ˺ŵÈÐÅÏ¢£¬ÍøÂç·¸×ï·Ö×Ó¿ÉÀûÓÃÕâЩÊý¾Ý½øÐÐÓÐÕë¶ÔÐÔµÄÉç»á¹¤³Ì¹¥»÷¡£DomainFactory½¨ÒéËùÓÐЧ»§Åú¸ÄÆäÃÜÂë¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/web-hosting-server-hack.html


¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖÕë¶Ô°ÍÀÕ˹̹µ±¾Ö»ú¹¹µÄAPT¹¥»÷¾íÍÁ³ÁÀ´


Check Point×êÑÐÍŶӷ¢ÏÖÕë¶Ô°ÍÀÕ˹̹µ±¾Ö»ú¹¹µÄAPT¹¥»÷¾íÍÁ³ÁÀ´¡£ÕâЩ¹¥»÷ÆðÍ·ÓÚ2018Äê3Ô£¬¹¥»÷Õßͨ¹ýÔ̺¬¶ñÒâÈí¼þµÄ´¹µöÓʼþϰȾָ±ê£¬¸Ã¶ñÒâÈí¼þÄܹ»ÍøÂçÓû§µÄ.doc¡¢.odt¡¢.xls¡¢.pptºÍ.pdfÎļþ²¢·¢ËÍÖÁÔ¶³Ì·þÎñÆ÷¡£×êÑÐÈËÔ±³Æ¸Ã¶ñÒâÈí¼þ¹²Ô̺¬13¸öÄ£¿é£¬µ«Ä¿Ç°Ö»ÄÜÈ·ÈÏÆäÖÐ5¸öÄ£¿éµÄÖ°ÄÜ¡£Check PointÒÔΪ¸ÃAPT¹¥»÷±³ºóµÄ×éÖ¯ÊÇGaza Cybergang¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://research.checkpoint.com/apt-attack-middle-east-big-bang/


¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖ¼äµýÈí¼þÀûÓñ»ÇÔµÄD-LinkÊý×ÖÖ¤Êé½øÐÐÊðÃû


ESET×êÑÐÍŶӷ¢ÏÖÀûÓñ»ÇÔÊý×ÖÖ¤Êé½øÐÐÊðÃûµÄжñÒâÈí¼þ»î¶¯¡£µÚÒ»¸ö¶ñÒâÈí¼þÊÇPlead£¬ÖØÒªÓÃÓÚÇÔÈ¡Óû§µÄÃô¸ÐÐÅÏ¢£¬ÆäʹÓÃÁĘ̈Íå¿Æ¼¼¹«Ë¾D-LinkµÄÓÐЧÊý×ÖÖ¤Êé½øÐÐÊðÃû¡£µÚ¶þ¸ö¶ñÒâÈí¼þÊÇÒ»¸öÃÜÂëÇÔÈ¡·¨Ê½£¬ÖØÒªÓÃÓÚ´ÓChrome¡¢IE¡¢OutlookºÍFirefoxµÈÇÔÈ¡Óû§µÄÃÜÂ룬ÆäʹÓÃÁËChanging Information Technology¹«Ë¾µÄÓÐЧ֤ÊéÊðÃû¡£ÕâÁ½¼Ò¹«Ë¾ÔÚ½Óµ½»ã±¨ºóÒѱðÀëÔÚ7ÔÂ3ÈÕºÍ4ÈÕ³·ÏúÁ˱»ÇÔµÄÖ¤Êé¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.welivesecurity.com/2018/07/09/certificates-stolen-taiwanese-tech-companies-plead-malware-campaign/


¡¾·ì϶²¹¶¡¡¿Apple°ä²¼Boot Camp°²È«¸üУ¬½¨¸´3¸öWi-Fi KRACKÓйصķì϶


Apple°ä²¼Boot Camp 6.4.0µÄ°²È«¸üУ¬½¨¸´ÓëÈ¥ÄêÄêµ×Åû¶µÄWi-Fi KRACK¹¥»÷ÓйصÄ3¸ö°²È«·ì϶£¨CVE-2017-13077¡¢CVE-2017-13078ºÍCVE-2017-13080£©¡£Boot CampÊÇmacOSÖÐµÄÆô¶¯¹¤¾ß£¬¿ÉÔÊÐíÓû§ÔÚ»ùÓÚIntel CPUµÄMacÉÏ×°ÖÃWindows²Ù×÷ϵͳ¡£¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶ǿÔìÔÚWPAµ¥²¥/PTK¿Í»§¶Ë»òWPA¶à²¥/GTK¿Í»§¶ËÖгÁ¸´Ê¹ÓÃnonce£¬½¨ÒéÓû§¾¡¿ì½øÐиüС£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/apple-patches-krack-flaws-boot-camp


¡¾¶ñÒâÈí¼þ¡¿×êÑÐÈËÔ±·¢ÏÖÀÕË÷Èí¼þKingOuroborosµÄбäÖÖ


×êÑÐÈËÔ±ÔÚ2018Äê6ÔÂÏÂÑ®·¢ÏÖÀÕË÷Èí¼þKingOuroborosµÄбäÖÖ£¬¸Ã±äÖÖ¼Ù×°³ÉJava Update Scheduler·¨Ê½£¨jusched.exe£©½øÐд«²¼£¬Í¨¹ýAES¼ÓÃÜÓû§µÄÊý¾Ý£¬²¢ÔÚ¼ÓÃܵÄÎļþµÄÔ­ÎļþÃûºÍÀ©´óÃûÖ®¼äÔö³¤.king_ouroborosÀ©´óÃû¡£¸Ã±äÖÖµÄÊê½ðΪ¼ÛÖµ50-80ÃÀÔªµÄ±ÈÌØ±Ò£¬ÆäÀÕË÷ÐÅÏ¢ÖÐÔ̺¬12ÖÖ˵»°µÄ·­Òë¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://id-ransomware.blogspot.com/2018/06/kingouroboros-ransomware.html