¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180730
°ä²¼¹¦·ò 2018-07-30
×êÑÐÈËÔ±Nathan Reese·¢ÏÖÉí·Ý͵ÇÔ±£»¤¹«Ë¾LifeLockµÄÍøÕ¾´æÔÚ°²È«·ì϶£¬¿Éµ¼ÖÂÊý°ÙÍòÓû§µÄµç×ÓÓʼþµØÖ·Ð¹Â¶¡£Reese³Æ¿Éͨ¹ýÅú¸ÄURLµØÖ·ÖеÄÂ½ÐøÊý×Ö²ÎÊýsubscriberkeyµÄ·½Ê½£¬±àд¾ç±¾»ñȡÿһ¸öLifeLockÓû§µÄµç×ÓÓʼþµØÖ·¡£Æ¾¾Ý2017Äê1ÔµÄÊý¾Ý£¬LifeLockµÄÓû§ÊýÁ¿³¬¹ýÁË450Íò¡£¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩÐÅÏ¢ÌáÒéÓÐÕë¶ÔÐÔµÄÍøÂç´¹µö¹¥»÷¡£LifeLockÒѾÔÚ¸ÃÍøÕ¾ÉϽ¨¸´ÁË´Ë·ì϶¡£
ÔÎÄÁ´½Ó£ºhttps://krebsonsecurity.com/2018/07/lifelock-bug-exposed-millions-of-customer-email-addresses/
¡¾·ì϶²¹¶¡¡¿°²È«×êÑÐÈËÔ±·¢ÏÖSwann¼ÒÓÃÉãÏñ»ú´æÔÚ°²È«·ì϶
×êÑÐÈËÔ±·¢ÏÖSwann IoTÉãÏñÍ·´æÔÚ°²È«·ì϶£¬¿ÉÔÊÐí¹¥»÷Õ߲鿴ºÍ½Ó¼ûÆäËüÓû§µÄÊÓÆµÁ÷¡£¸ÃÉãÏñÍ·µÄÔÆ·þÎñÊÇÓÉOzvisionÌṩµÄ£¬µ±Óû§Í¨¹ýSafe by SwannµÇ¼ϵͳʱ£¬»áÏò·þÎñÆ÷·¢³öÒªÇó£¨userListAssets£©£¬·þÎñÆ÷½«·µ»ØÓëÕË»§ÓйØÁªµÄÉ豸ÁÐ±í¡£×êÑÐÈËÔ±·¢ÏÖͨ¹ýÅú¸ÄÐòÁкŲÎÊýÄܹ»½Ó¼ûÆäËüÓû§µÄÊÓÆµÁ÷¡£SwannÒѾ½¨¸´Á˸÷ì϶¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74868/hacking/swann-camera-hacking.html
¡¾Íþвµý±¨¡¿°²È«×êÑÐÈËÔ±·¢ÏÖ¶à¸öÓÃÓÚÍÆË͸æ°×Èí¼þµÄ¶ñÒâÍøÕ¾
·¨¹ú×êÑÐÈËÔ±Ivan Kwiatkowski·¢ÏÖ¶à¸ö¼Ù×°³ÉºÏ·¨ÍøÕ¾µÄ´¹µöÍøÕ¾£¬ÕâЩ´¹µöÍøÕ¾ÊÔͼÏòÓû§ÍÆË͸æ°×Èí¼þInstallCore¡£ÀýÈ磬¶ñÒâÍøÕ¾keepass.fr£¨ºÏ·¨ÍøÕ¾µÄÓòÃûÊÇkeepass.info£©ÉÏÌṩµÄKeePass°æ±¾°ó¸¿Á˸æ°×Èí¼þInstallCore¡£×êÑÐÈËÔ±¹²·¢ÏÖÁËÊýÊ®¸ö´ËÀàÍøÕ¾£¬Ô̺¬7Zip¡¢FilezillaºÍAdBlock´¹µöÍøÕ¾µÈ¡£ËùÓеÄÓòÃû¶¼ÊÇÓÉͳһ¸öµç×ÓÓʼþµØÖ·×¢²áµÄ¡£´óÎÞÊýÓòÃû¶¼×¢²áÔÚ.fr»ò.es TLDÏ¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/fake-websites-for-keepass-7zip-audacity-others-found-pushing-adware/
¡¾Íþвµý±¨¡¿Google´ÓChromeÉ̵êÖÐÃýÎóɾ³ýMetamask¹Ù·½²å¼þ£¬»òµ¼Ö´¹µö·çÏÕ
Google´ÓChromeÉ̵êÖÐÃýÎóµØÉ¾³ýÁËÒÔÌ«·»Ç®°üMetamaskµÄ¹Ù·½²å¼þ£¬µ«±£ÁôÁËÒ»¸öÐéα²å¼þ¡£¸ÃÐéα²å¼þÊÔIJÀûÓÃMetamaskµÄÃû³ÆºÍÆ·ÅÆÀ´Íƹã×Ô¼º£¬Æ¾¾ÝBraveä¯ÀÀÆ÷¿ª·¢ÈËÔ±Jonathan SampsonµÄ˵·¨£¬¸Ã²å¼þʹÓÃÁË֮ǰÔÚÍøÂç´¹µö»î¶¯ÖÐʹÓõĵç×ÓÓʼþµØÖ·£¬Òò¶øÕâºÜ¿ÉÄÜÊÇÒ»¸ö¶ñÒâ²å¼þ¡£¼¸¸öÓ×ʱ֮ºóGoogle½¨¸ÄÁËÆäÐÐΪ£¬É¾³ýÁ˸ÃÐéα²å¼þ²¢¸´ÔÁ˹ٷ½µÄ²å¼þ¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/cryptocurrency/google-removes-real-ethereum-wallet-from-web-store-but-leaves-fake-one-alone/
¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖ¶íAPT28ÊÔͼÕë¶ÔÃÀ²ÎÒéÔ±µÄ´¹µö¹¥»÷»î¶¯
×êÑÐÈËÔ±·¢ÏÖ¶íÂÞ˹APT×éÖ¯Fancy Bear£¨ÓÖ±»³ÆÎªAPT28£©ÊÔͼÕë¶ÔÃÀ²ÎÒéÔ±Claire McCaskill¼°Æä¹¤×÷ÈËÔ±µÄ´¹µö¹¥»÷»î¶¯¡£McCaskillÔÚΪÆä2018ÄêµÄ²õÁª¾ºÑ¡×ö³ï±¸¡£Æ¾¾ÝThe Daily BeastµÄ±¨Â·£¬¹¥»÷Õßͨ¹ýÖ÷ÌâΪÅú¸ÄMicrosoft ExchangeÃÜÂëµÄÍøÂç´¹µöÓʼþ£¬ÊÔͼÇÔÈ¡¸ÃÒéÔ±¼°Æä¹¤×÷ÈËÔ±µÄÍ´´¦¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74843/cyber-warfare-2/apt28-targeted-senator-mccaskill.html
¡¾¹¥»÷ÊÂÎñ¡¿°®´ïºÉÖÝ364ÃûÇô·¸ÈëÇÖJPayƽ°åµçÄÔ£¬¹²ÇÔȡԼ22.5ÍòÃÀÔªµÄÊý×ÖÐÅ´û
ƾ¾ÝÃÀ¹ú°®´ïºÉÖݱ¾µØ¹ÙÔ±µÄ˵·¨£¬¹²ÓÐ364ÃûÇô·¸ÈëÇÖÁ˼àÓüJPayƽ°åµçÄÔµÄϵͳ£¬Îª¸÷×ÔµÄÕË»§³äÈëÁË´óÁ¿µÄÐÅÓþ¶î¶È£¬¼ÆË㽫½ü22.5ÍòÃÀÔª¡£ÔÚÕâЩÇô·¸ÖУ¬ÓÐ50±¨´ð×Ô¼º³äÖµµÄ½ð¶î³¬¹ý1000ÃÀÔª£¬×î¸ßµÄһλ³äÈëÁ˽«½ü1ÍòÃÀÔª¡£Çô·¸ÀûÓÃÕâЩÐÅÓþ¶î¶ÈÀ´²É°ìÓÎÏ·¡¢ÒôÀֺ͵ç×ÓÓÊÏä·þÎñ¡£Ä¿Ç°¸Ã¹«Ë¾Òѽ¨¸´ÁËÆ½°åµçÄÔÉϵķì϶¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/364-idaho-inmates-hacked-their-prison-tablets-for-free-credits/


¾©¹«Íø°²±¸11010802024551ºÅ