¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180730

°ä²¼¹¦·ò 2018-07-30
¡¾·ì϶²¹¶¡¡¿LifeLock¹ÙÍø´æÔÚ·ì϶ £¬¿Éµ¼ÖÂÊý°ÙÍòÓû§µÄµç×ÓÓʼþµØÖ·Ð¹Â¶


×êÑÐÈËÔ±Nathan Reese·¢ÏÖÉí·Ý͵ÇÔ±£»¤¹«Ë¾LifeLockµÄÍøÕ¾´æÔÚ°²È«·ì϶ £¬¿Éµ¼ÖÂÊý°ÙÍòÓû§µÄµç×ÓÓʼþµØÖ·Ð¹Â¶¡£Reese³Æ¿Éͨ¹ýÅú¸ÄURLµØÖ·ÖеÄÂ½ÐøÊý×Ö²ÎÊýsubscriberkeyµÄ·½Ê½ £¬±àд¾ç±¾»ñȡÿһ¸öLifeLockÓû§µÄµç×ÓÓʼþµØÖ·¡£Æ¾¾Ý2017Äê1ÔµÄÊý¾Ý £¬LifeLockµÄÓû§ÊýÁ¿³¬¹ýÁË450Íò¡£¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩÐÅÏ¢ÌáÒéÓÐÕë¶ÔÐÔµÄÍøÂç´¹µö¹¥»÷¡£LifeLockÒѾ­ÔÚ¸ÃÍøÕ¾ÉϽ¨¸´ÁË´Ë·ì϶¡£


Ô­ÎÄÁ´½Ó£ºhttps://krebsonsecurity.com/2018/07/lifelock-bug-exposed-millions-of-customer-email-addresses/


¡¾·ì϶²¹¶¡¡¿°²È«×êÑÐÈËÔ±·¢ÏÖSwann¼ÒÓÃÉãÏñ»ú´æÔÚ°²È«·ì϶


×êÑÐÈËÔ±·¢ÏÖSwann IoTÉãÏñÍ·´æÔÚ°²È«·ì϶ £¬¿ÉÔÊÐí¹¥»÷Õ߲鿴ºÍ½Ó¼ûÆäËüÓû§µÄÊÓÆµÁ÷¡£¸ÃÉãÏñÍ·µÄÔÆ·þÎñÊÇÓÉOzvisionÌṩµÄ £¬µ±Óû§Í¨¹ýSafe by SwannµÇ¼ϵͳʱ £¬»áÏò·þÎñÆ÷·¢³öÒªÇó£¨userListAssets£© £¬·þÎñÆ÷½«·µ»ØÓëÕË»§ÓйØÁªµÄÉ豸Áбí¡£×êÑÐÈËÔ±·¢ÏÖͨ¹ýÅú¸ÄÐòÁкŲÎÊýÄܹ»½Ó¼ûÆäËüÓû§µÄÊÓÆµÁ÷¡£SwannÒѾ­½¨¸´Á˸÷ì϶¡£


Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74868/hacking/swann-camera-hacking.html


¡¾Íþвµý±¨¡¿°²È«×êÑÐÈËÔ±·¢ÏÖ¶à¸öÓÃÓÚÍÆË͸æ°×Èí¼þµÄ¶ñÒâÍøÕ¾


·¨¹ú×êÑÐÈËÔ±Ivan Kwiatkowski·¢ÏÖ¶à¸ö¼Ù×°³ÉºÏ·¨ÍøÕ¾µÄ´¹µöÍøÕ¾ £¬ÕâЩ´¹µöÍøÕ¾ÊÔͼÏòÓû§ÍÆË͸æ°×Èí¼þInstallCore¡£ÀýÈç £¬¶ñÒâÍøÕ¾keepass.fr£¨ºÏ·¨ÍøÕ¾µÄÓòÃûÊÇkeepass.info£©ÉÏÌṩµÄKeePass°æ±¾°ó¸¿Á˸æ°×Èí¼þInstallCore¡£×êÑÐÈËÔ±¹²·¢ÏÖÁËÊýÊ®¸ö´ËÀàÍøÕ¾ £¬Ô̺¬7Zip¡¢FilezillaºÍAdBlock´¹µöÍøÕ¾µÈ¡£ËùÓеÄÓòÃû¶¼ÊÇÓÉͳһ¸öµç×ÓÓʼþµØÖ·×¢²áµÄ¡£´óÎÞÊýÓòÃû¶¼×¢²áÔÚ.fr»ò.es TLDÏ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/fake-websites-for-keepass-7zip-audacity-others-found-pushing-adware/


¡¾Íþвµý±¨¡¿Google´ÓChromeÉ̵êÖÐÃýÎóɾ³ýMetamask¹Ù·½²å¼þ £¬»òµ¼Ö´¹µö·çÏÕ


Google´ÓChromeÉ̵êÖÐÃýÎóµØÉ¾³ýÁËÒÔÌ«·»Ç®°üMetamaskµÄ¹Ù·½²å¼þ £¬µ«±£ÁôÁËÒ»¸öÐéα²å¼þ¡£¸ÃÐéα²å¼þÊÔIJÀûÓÃMetamaskµÄÃû³ÆºÍÆ·ÅÆÀ´Íƹã×Ô¼º £¬Æ¾¾ÝBraveä¯ÀÀÆ÷¿ª·¢ÈËÔ±Jonathan SampsonµÄ˵·¨ £¬¸Ã²å¼þʹÓÃÁË֮ǰÔÚÍøÂç´¹µö»î¶¯ÖÐʹÓõĵç×ÓÓʼþµØÖ· £¬Òò¶øÕâºÜ¿ÉÄÜÊÇÒ»¸ö¶ñÒâ²å¼þ¡£¼¸¸öÓ×ʱ֮ºóGoogle½¨¸ÄÁËÆäÐÐΪ £¬É¾³ýÁ˸ÃÐéα²å¼þ²¢¸´Ô­Á˹ٷ½µÄ²å¼þ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/cryptocurrency/google-removes-real-ethereum-wallet-from-web-store-but-leaves-fake-one-alone/


¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖ¶íAPT28ÊÔͼÕë¶ÔÃÀ²ÎÒéÔ±µÄ´¹µö¹¥»÷»î¶¯


×êÑÐÈËÔ±·¢ÏÖ¶íÂÞ˹APT×éÖ¯Fancy Bear£¨ÓÖ±»³ÆÎªAPT28£©ÊÔͼÕë¶ÔÃÀ²ÎÒéÔ±Claire McCaskill¼°Æä¹¤×÷ÈËÔ±µÄ´¹µö¹¥»÷»î¶¯¡£McCaskillÔÚΪÆä2018ÄêµÄ²õÁª¾ºÑ¡×ö³ï±¸¡£Æ¾¾ÝThe Daily BeastµÄ±¨Â· £¬¹¥»÷Õßͨ¹ýÖ÷ÌâΪÅú¸ÄMicrosoft ExchangeÃÜÂëµÄÍøÂç´¹µöÓʼþ £¬ÊÔͼÇÔÈ¡¸ÃÒéÔ±¼°Æä¹¤×÷ÈËÔ±µÄÍ´´¦¡£

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74843/cyber-warfare-2/apt28-targeted-senator-mccaskill.html


¡¾¹¥»÷ÊÂÎñ¡¿°®´ïºÉÖÝ364ÃûÇô·¸ÈëÇÖJPayƽ°åµçÄÔ £¬¹²ÇÔȡԼ22.5ÍòÃÀÔªµÄÊý×ÖÐÅ´û


ƾ¾ÝÃÀ¹ú°®´ïºÉÖݱ¾µØ¹ÙÔ±µÄ˵·¨ £¬¹²ÓÐ364ÃûÇô·¸ÈëÇÖÁ˼àÓüJPayƽ°åµçÄÔµÄϵͳ £¬Îª¸÷×ÔµÄÕË»§³äÈëÁË´óÁ¿µÄÐÅÓþ¶î¶È £¬¼ÆË㽫½ü22.5ÍòÃÀÔª¡£ÔÚÕâЩÇô·¸ÖÐ £¬ÓÐ50±¨´ð×Ô¼º³äÖµµÄ½ð¶î³¬¹ý1000ÃÀÔª £¬×î¸ßµÄһλ³äÈëÁ˽«½ü1ÍòÃÀÔª¡£Çô·¸ÀûÓÃÕâЩÐÅÓþ¶î¶ÈÀ´²É°ìÓÎÏ·¡¢ÒôÀֺ͵ç×ÓÓÊÏä·þÎñ¡£Ä¿Ç°¸Ã¹«Ë¾Òѽ¨¸´ÁËÆ½°åµçÄÔÉϵķì϶¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/364-idaho-inmates-hacked-their-prison-tablets-for-free-credits/