¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190104

°ä²¼¹¦·ò 2019-01-04
1¡¢Adobe°ä²¼°²È«¸üР£¬½¨¸´Á½¸ö¸ßΣ·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


1ÔÂ3ÈÕAdobe°ä²¼°²È«²¼¸æAPSB19-02 £¬½¨¸´ÁËAdobe AcrobatºÍReaderÖеÄÁ½¸ö¸ßΣ·ì϶¡£µÚÒ»¸ö·ì϶£¨CVE-2018-16011£©¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐÐ £¬µÚ¶þ¸ö·ì϶£¨CVE-2018-19725£©ÔòÊÇÒ»¸öÌáȨ·ì϶¡£ÕâÁ½¸ö·ì϶ÊÇÓÉÇ÷Ïò¿Æ¼¼µÄZDIÌá½»µÄ £¬½¨ÒéÓû§¾¡¿ìÉý¼¶ÖÁAcrobat DC/Acrobat ReaderµÄ×îа汾2019.010.20069¡¢2017.011.30113ºÍ2015.006.30464¡£

  

 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-acrobat-and-reader-security-updates-released-for-critical-bugs/


2¡¢¹È¸è½¨¸´Android°æChromeÖдæÔÚ3ÄêµÄÒþÖÔй¶·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



¹È¸è×îÖÕ½¨¸´Á˺ÏÓÃÓÚAndroidµÄChromeä¯ÀÀÆ÷ÖеÄÒ»¸öÒþÖÔй¶·ì϶¡£Nightwatch Cybersecurity¹«Ë¾µÄYakov ShafranovichÔøÔÚ2015ÄêÏò¹È¸è»ã±¨¹ý´ËÎÊÌâ £¬µ«¹È¸èÆäʱ³ÆÕâ²»ÊÇÒ»¸ö·ì϶¡£ÔÚ2018Äê7Ô·ÝChromiumÂÛ̳ÉÏÒ»¸öÓû§ÔÙ´ÎÅû¶´Ë·ì϶ºó £¬¹È¸èÔÚChrome 70Öн¨¸´Á˸÷ì϶¡£¸Ã·ì϶ÓëChromeÌìÉúµÄUser Agent×Ö·û´®Ô̺¬Android°æ±¾ºÅ¡¢É豸Ãû³Æ¼°¹Ì¼þ°æ±¾ÐÅÏ¢ÓÐ¹Ø £¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ȷ¶¨É豸µÄ°²È«²¹¶¡¼¶±ð £¬´Ó¶øÌáÒéÕë¶ÔÐԵĹ¥»÷¡£

  

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/google-chrome-android-privacy.html


3¡¢¶¼°ØÁÖÓйìµç³µÏµÍ³Luas¹ÙÍø±»ºÚ £¬ºÚ¿ÍÀÕË÷3800ÃÀÔª

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°®¶ûÀ¼Ê×¶¼¶¼°ØÁÖµÄÓйìµç³µÏµÍ³LuasµÄ¹ÙÍøÔâµ½ºÚ¿Í¹¥»÷ £¬¹¥»÷ÕßÐû³Æ´ÓLuasµÄÔËÓªÉÌTransdev Ireland´¦ÇÔÈ¡ÁËÊý¾Ý £¬²¢ÒªÇóÔÚÎåÌìÄÚÖ§¸¶Ò»¸ö±ÈÌØ±Ò£¨¼ÛÖµÔ¼3800ÃÀÔª£©µÄÊê½ð¡£LuasÒѽ«¹ÙÍøÀëÏß²¢½øÐа²È«²é³­¡£ºÃÐÂÎÅÊÇLuasµÄÔËÓª·þÎñ²¢Î´Êܵ½Ó°Ïì £¬´î¿ÍÖ»ÊÇÎÞ·¨´Ó¹ÙÍøÉϲéÎʵ糵µÄʱ¿Ì±í¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.tripwire.com/state-of-security/security-data-protection/hackers-demand-ransom-luas-website-defaced/


4¡¢NRSMinerбäÌåÏ®»÷ÑÇÖÞ £¬ÀûÓÃEternalBlue·ì϶´«²¼

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


F-SecureµÄ°²È«×êÑÐÈËÔ±·¢ÏÖNRSMinerµÄбäÌåÀûÓÃEternalBlue·ì϶¹¥»÷ÑÇÖÞµØÓòµÄ¹ú¶È¡£¸Ã¹¥»÷»î¶¯´Ó2018Äê11ÔÂÖÐÑ®ÆðÍ· £¬ÖØÒªÕë¶ÔÔ½ÄÏ¡¢Öйú¡¢ÈÕ±¾ºÍ¶ò¹Ï¶à¶ûµÈ¡£NRSMinerÀûÓÃÃÅÂÞ±Ò¿ó¹¤XMRig½øÐÐÍÚ¿ó £¬»¹Äܹ»ÏÂÔØ¸üеÄÄ£¿é²¢´úÌæ¾É°æ¶ñÒâÈí¼þ¡£ÀûÓÃEternalBlue´«²¼µÄÍÚ¿óľÂí»¹Ô̺¬WannamineºÍRedisWannaMineµÈ¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/revamped-cryptominer-is-striking-asia-through-eternal-blue-exploit/


5¡¢ÀÕË÷Èí¼þFilesLockerÖ÷½âÃÜÃÜÔ¿±»·Å³ö £¬×êÑÐÈËÔ±ÒÑ¿ª·¢³ö½âÃÜÆ÷

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2018Äê12ÔÂ29ÈÕ £¬Î´ÖªÓû§ÔÚPastbinÉÏ·¢Ìû·Å³öÁËÀÕË÷Èí¼þFilesLockerµÄÖ÷½âÃÜÃÜÔ¿ £¬Ëæºó×êÑÐÈËÔ±Michael GillespieÀûÓøÃÃÜÔ¿´´½¨ÁËFilesLockerµÄ½âÃÜÆ÷¡£¸Ã½âÃÜÆ÷¿É½âÃÜFilesLocker v1ºÍv2¼ÓÃܵÄÎļþ£¨Îļþºó׺ÃûΪ.[fileslocker@pm.me]£©¡£Ä¿Ç°Éв»Ã÷ÏԸýâÃÜÃÜԿΪʲô±»¿ªÊÍ £¬µ«ÓпÉÄÜÊÇÀÕË÷Èí¼þ¿ª·¢Õß¾ö¶¨ÊµÏÖÏîÄ¿»ò³ÁÐÂÆðͷеÄÏîÄ¿¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/master-decryption-key-released-for-fileslocker-ransomware/


6¡¢ÃÜÂëÖÎÀíÆ÷BlurÓû§Êý¾Ýй¶ £¬240ÍòÈËÊܵ½Ó°Ïì

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



±¾ÖÜÒ»Abine¹«Ë¾°µÊ¾ÆäÃÜÂëÖÎÀíÆ÷²úÆ·BlurµÄÓû§Êý¾ÝÔÚ·þÎñÆ÷É϶³ö £¬ÕâЩÊý¾ÝÔ̺¬2018Äê1ÔÂ6ÈÕ֮ǰע²áµÄBlurÓû§µÄÐÅÏ¢ £¬Èçµç×ÓÓʼþµØÖ·¡¢ÐÕÃû¡¢ÃÜÂëÌáÐÑÓï¡¢×îºóµÇ¼IPºÍ¼ÓÑÎÃÜÂë¹þÏ£¡£¸Ã¹«Ë¾Ç¿µ÷³ÆÓû§µÄÃÜÂë¡¢ÐÅÓþ¿¨ÐÅÏ¢ºÍµç»°ºÅÂëûÓÐй¶¡£ÕâÒ»ÊÂÎñÓ°ÏìÁËÔ¼240ÍòBlurÓû§¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/data-of-2-4-million-blur-password-manager-users-left-exposed-online/


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù