¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180726

°ä²¼¹¦·ò 2018-07-26

¡¾·ÖÎö»ã±¨¡¿×êÑÐÍŶӰ䲼¹ØÓÚ¹²ÏíÆû³µAPPµÄ°²È«ÐԵĵ÷Ñл㱨


¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼¹ØÓÚ¹²ÏíÆû³µAPPµÄ°²È«ÐԵĵ÷Ñл㱨¡£2017ÄêĪ˹¿ÆµÄ¹²ÏíÆû³µµÄ»îÔ¾Óû§ÊýÁ¿ºÍ³öÐдÎÊý¶¼ÏÕЩ·­·¬ £¬ÕâÒý·¢Á˰²È«×¨¼Ò¶ÔÆä·þÎñµÄ°²È«ÐÔµÄÓÇÓô¡£×êÑÐÈËÔ±²âÊÔÁË13¸öÒÆ¶¯APP £¬Ö»ÓÐ1¸öAPPÓµÓзÀÄæÏò± £»¤²¢ÇÒ¶ÔÊý¾Ý½øÐÐÁ˼ÓÃÜ¡£Ò»°ëµÄAPP²»ÔÊÐíÓû§´´½¨×Ô¼ºµÄÃÜÂë £¬¶øÊÇÇ¿ÔìÓû§Ê¹Óõ绰ºÅÂëºÍͨ¹ý¶ÌÐÅ·¢Ë͵ÄPINÂëµÇ¼¡£ËùÓеÄAPP¶¼Ò×ÊÜMITM¹¥»÷¡£

Ô­ÎÄÁ´½Ó£ºhttps://securelist.com/a-study-of-car-sharing-apps/86948/


¡¾¹¥»÷ÊÂÎñ¡¿¸¥¼ªÄáÑÇÒøÐÐ8¸öÔÂÄÚ2´ÎÔâºÚ¿ÍÈëÇÖ £¬¹²ËðʧԼ240ÍòÃÀÔª


¾Ý¼ÇÕßBrian Krebs±¨Â· £¬ÃÀ¸¥¼ªÄáÑǹú¶ÈÒøÐÐÓÚ2016Äê5ÔÂÏÂÑ®ºÍ2017Äê1ÔÂÁ½´ÎÔâµ½´¹µöÓʼþµÄ¹¥»÷ £¬¹²ËðʧԼ240ÍòÃÀÔª¡£µÚÒ»´Î¹¥»÷Öй¥»÷Õßͨ¹ý¶ñÒâÈí¼þϰȾÁËÒ»Ì¨ÍÆËã»ú £¬²¢¿ÉÄܽӼûÒøÐÐÄÚÍøºÍÈÆ¹ýPINÂë¡¢ÖðÈÕÈ¡¿îÏÞ¶ÈÒÔ¼°·´Ú²Æ­´ëÊ©µÈ¡£µÚ¶þ´Î¹¥»÷µÄģʽÓëµÚÒ»´Î¹¥»÷ÀàËÆ¡£SynopsysÊ×ϯÕÕ·÷Chandu KetkarÒÔΪ £¬ÕâЩÊÂÎñÊÇÆä°²È«ÒâʶÅàѵ¡¢¼à¿ØºÍÓ¦¼±ÏìÓ¦µÈÕ½ÊõµÄʧ°Ü¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/virginian-bank-robbed-twice-in/


¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖÓ¡¶È¶ñÒâÈí¼þMDMµÄ¸ü¿í·ºµÄ¹¥»÷»î¶¯


˼¿ÆTalos×êÑÐÍŶӷ¢ÏÖÓ¡¶ÈÒÆ¶¯¶ñÒâÈí¼þMDMµÄ¹¥»÷»î¶¯ÊÇÕë¶Ô¶àƽ̨£¨WindowsÉ豸ÒÔ¼°¿ÉÄܵÄAndroidÉ豸£©µÄ¿í·º¹¥»÷»î¶¯µÄÒ»²¿ÃÅ¡£¹¥»÷Õßͨ¹ý¶ñÒâÈí¼þ°µÖмලÓû§ £¬²¢´ÓµÚÈý·½Ì¸ÌìÀûÓÃÖÐÇÔÈ¡Óû§µÄʵʱµØÎ»¡¢¶ÌÐÅ¡¢ÁªÏµÈ˺ÍÕÕÆ¬µÈÐÅÏ¢¡£×êÑÐÈËÔ±·¢ÏÖÁËеÄMDM»ù´¡ÉèÊ©¼°ÆäÍйܵÄÕë¶ÔWindowsÓû§µÄ¶ñÒâ¶þ½øÔìÎļþ¡£×êÑÐÈËÔ±»¹·¢Ïָù¥»÷»î¶¯ÓëºÚ¿Í×éÖ¯Bahamut´æÔÚ¹ØÁª¡£


Ô­ÎÄÁ´½Ó£ºhttps://blog.talosintelligence.com/2018/07/Mobile-Malware-Campaign-uses-Malicious-MDM-Part2.html


¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±·¢ÏÖÖØÒªÕë¶ÔAVTechÉ豸µÄн©Ê¬ÍøÂçDeath


NewSky Security°²È«×êÑÐÈËÔ±Ankit Anubhav³Æ½©Ê¬ÍøÂçDeathÔÚͨ¹ýAVTechÉ豸Öеķì϶½øÐд«²¼¡£ÕâЩ·ì϶ÓÚ2016Äêµ×±»¹«¿ª £¬Ô̺¬14¸ö°²È«·ì϶ £¬Ó°ÏìDVR¡¢NVR¡¢IPÉãÏñÓŵÈAVTechÉ豸¡£AVTechÓÚ2017ËêÊ×½¨¸´ÁËÕâЩ·ì϶ £¬µ«ÈÔÓв¿ÃÅÓû§Ã»ÓнøÐиüС£Ä¿Ç°¸Ã½©Ê¬ÍøÂçµÄ´óÓ×»¹Î´Öª¡£³ýÁËDeathÖ®±í £¬½©Ê¬ÍøÂçHide'N Seek£¨HNS£©Ò²ÔÚÕë¶ÔÕâЩ·ì϶ÌáÒé¹¥»÷¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/malware-author-building-death-botnet-using-old-avtech-flaw/


¡¾Íþвµý±¨¡¿×êÑлú¹¹°ä²¼ÀÕË÷Èí¼þLockCryptµÄ.1btc±äÌåµÄ½âÃܹ¤¾ß


ÂÞÂíÄáÑǰ²È«³§ÉÌBitdefender°ä²¼ÀÕË÷Èí¼þLockCryptµÄÒ»¸ö±äÌåµÄ½âÃܹ¤¾ß £¬¸Ã±äÌåÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.1btcÀ©´óÃû¡£¸Ã±äÌåÔÚ2018Äê2ÔÂÖÁ5Ôµ×Ö®¼ä»îÔ¾ £¬ËæºóÀÕË÷Èí¼þµÄ×÷Õß¿ª·¢Á˸üеİ汾.BI_D¡£Bitdefender°ä²¼µÄ½âÃܹ¤¾ßʹÓü«¶Èµ¥Ò»¡£°²È«×êÑÐÔ±Michael GillespieÕû¶ÙÁËLockCryptµÄ·ÖÆç±äÌåµÄ½âÃܹ¤¾ß £¬Ä¿Ç°Ö»ÓÐ×îеÄ.BI_D±äÌå²»³É½âÃÜ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/bitdefender-releases-decryption-tool-for-older-version-of-lockcrypt-ransomware/


¡¾¶ñÒâÈí¼þ¡¿×êÑÐÈËÔ±·¢ÏÖÊôÓÚÒøÐÐľÂíKronosµÄбäÌåµÄ¹¥»÷»î¶¯


Proofpoint×êÑÐÈËÔ±·¢ÏÖÒøÐÐľÂíKronosµÄбäÌåµÄ¹¥»÷»î¶¯ £¬ÕâЩ¹¥»÷»î¶¯´Ó2018Äê6ÔÂÏÂÑ®ÆðÍ· £¬ÖØÒªÕë¶Ô5¼ÒµÂ¹ú½ðÈÚ»ú¹¹ÒÔ¼°13¼ÒÈÕ±¾½ðÈÚ»ú¹¹ºÍ²¨À¼µÄ²¿ÃÅÓû§¡£Ð±äÌåͨ¹ýÀ¬»øÓʼþ½øÐзַ¢¡£×êÑÐÈËÔ±·ÖÎöÁ˸ñäÌåÓë2014ÄêµÄ°æ±¾Ö®¼äµÄÇø±ð £¬·¢ÏÖËüÃÇ´æÔÚ¿í·ºµÄ´úÂë³ÁÓÃÒÔ¼°Ò»ÑùµÄ×Ö·û´®¼ÓÃܼ¼Êõ¡¢C&C¼ÓÃÜ»úÔìºÍÀàËÆµÄC&CÃæ°å²¼¾ÖµÈ¡£×êÑÐÈËÔ±³Æ¸ÃбäÌå¿ÉÄܾÍÊÇÐµÄľÂíOsiris¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-version-of-the-kronos-banking-trojan-discovered/