¹È¸è±»Å·ÃË·£¿î17ÒÚÃÀÔª £»Ê±¸ôÁ½ÄêPuTTY°ä²¼0.71°æ±¾ £»¹¥»÷»î¶¯Bad Tidings

°ä²¼¹¦·ò 2019-03-21
1¡¢Ê±¸ôÁ½ÄêPuTTY°ä²¼0.71°æ±¾£¬½¨¸´8¸ö°²È«·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±¾ÖÜPuTTY°ä²¼Á˺ÏÓÃÓÚWindowsºÍUnixƽ̨µÄа汾0.71£¬Õâ¾àÀëÆäÉÏÒ»¸ö°æ±¾µÄ°ä²¼ÒÑÓнüÁ½ÄêµÄ¹¦·ò¡£¸Ãа汾½¨¸´ÁË8¸ö°²È«·ì϶£¬·ì϶ÁìÓòÔ̺¬Éí·ÝÑéÖ¤ÌáÐÑÐÅϢαÔì¡¢CHM½Ù³Öµ¼ÖµĴúÂëÖ´ÐÓ×¢»º³åÇøÒç³ö¡¢¼ÓÃÜËæ»úÊý³ÁÓá¢ÕûÊýÒç³öÒÔ¼°»Ø¾ø·þÎñ¡£½¨ÒéÓû§´Ó¹ÙÍøÏÂÔØ¸Ãа汾¡£


 Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/03/putty-software-hacking.html

2¡¢Google Photos·ì϶¿Éµ¼ÖÂÓû§Î»ÏàÐÅϢй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Imperva°²È«×êÑÐÔ±Ron Masas·¢ÏÖweb°æGoogle Photos´æÔÚ°²È«·ì϶£¬¿ÉÔÊÐí¶ñÒâÍøÕ¾Æ¾¾ÝÓû§ÕË»§Öд洢µÄÕÕÆ¬À´¸ú×ÙÓû§µÄλÏàÐÅÏ¢¡£×êÑÐÈËÔ±³Æ£¬ÀûÓûùÓÚä¯ÀÀÆ÷µÄʱÐò¹¥»÷£¬¹¥»÷Õ߿ɴ§¶È³öÀ´×ÔÌØ¶¨µØÀíµØÎ»µÄÕÕÆ¬ÊÇ·ñ´æÔÚÓÚÓû§µÄÕË»§ÖУ¬¼´Óû§ÊÇ·ñ½Ó¼ûÁËÕâ¸ö¹ú¶È¡£Í¨¹ýÈÕÆÚÏÞÔ죬¹¥»÷ÕßÉõÖÁ¿ÉÄÜÈ·¶¨Óû§½Ó¼û¸Ã¹ú¶ÈµÄ´óÌ幦·ò¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-photos-bug-exposed-the-location-and-time-of-your-pictures/

3¡¢¹È¸èÒò¸æ°×¢¶ÏÔÙ±»Å·ÃË·£¿î17ÒÚÃÀÔª

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

3ÔÂ20ÈÕÅ·ÃËίԱ»á°ä²¼ÉêÃ÷¶Ô¹È¸èµÄ¸æ°×¢¶ÏÐÐΪ·£¿î14.9ÒÚÅ·Ôª£¨Ô¼17ÒÚÃÀÔª£©£¬ÕâÊÇÁ½ÄêÄÚÅ·Ã˶Թȸ迪³öµÄµÚÈýÕÅ´ó¶î·´Â¢¶Ï·£µ¥¡£Å·ÃËίԱ»á°µÊ¾ÕâÒ»·£¿îµÄÔ­ÒòÊǹȸèÀÄÓÃÆäÊг¡Ö÷µ¼Ö°Î»£¬×èÖ¹ÍøÒ³Ê¹ÓÃAdSenseƽ̨ÒÔ±íµÄ¸æ°×·þÎñ£¬ÕâÒ»·£½ðÏ൱Óڹȸè2018Äê½»Ò×¶îµÄ1.29%¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-fined-17-billion-for-anti-competitive-practices-in-online-advertising/

4¡¢MyPillowºÍAmerisleep³ÉΪMagecart¹¥»÷µÄ×îÐÂÊܺ¦Õß


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÈËÔ±·¢ÏÖ´²ÉÏÓÃÆ·ÁãÊÛÉÌMyPillowºÍAmerisleep³ÉΪMagecart¹¥»÷µÄ×îÐÂÊܺ¦Õß¡£Í¬Ö®Ç°µÄ¹¥»÷Ò»Ñù£¬Magecart¹¥»÷ÕßÔÚÕâÁ½¸ö¹ºÎïÍøÕ¾ÉÏÖ²ÈëÁËÓÃÓÚÇÔȡ֧¸¶ÐÅÏ¢µÄ¶ñÒâ´úÂë¡£MyPillowÓÚ2018Äê10ÔÂÔâµ½¹¥»÷£¬¶øAmerisleepÔòÔÚ2017Äê¡¢2018Äê12Ô¼°2019Äê1Ô¶¼Ôâµ½¹¥»÷¡£´Ë±í£¬MyPillowºÍAmerisleep¶¼Ã»ÓÐÕë¶ÔÕâÒ»ÊÂÎñÏòÓû§·¢³öÈκÎÖÒ¸æ»ò¹Ù·½ÉêÃ÷¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/03/magecart-ecommerce-hackers.html

5¡¢Ð´¹µö¹¥»÷»î¶¯Bad Tidings£¬ÖØÒªÕë¶ÔÉ³ÌØ°¢À­²®


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


1Ô·ÝAnomali·¢ÏÖ¼ÙÒâÉ³ÌØ°¢À­²®ÄÚÕþ²¿¹ÙÍøAbsherµÄ´¹µöÍøÕ¾ÊýÁ¿¼¤Ôö¡£½øÒ»²½×êÑÐÅú×¢ÕâÊÇÒ»¸öÕë¶ÔÉ³ÌØ°¢À­²®Ëĸö·ÖÆçÈ·µ±¾Ö»ú¹¹£¨ÄÚÕþ²¿¡¢±í½»²¿¡¢ÀͶ¯¼°Éç»á·¢Õ¹²¿¡¢µ±¾Ö¹ÙÍø£©ÒÔ¼°Ò»¸ö½ðÈÚ»ú¹¹£¨É³µØÓ¢¹úÒøÐУ©µÄ¸ü¿í·ºµÄ´¹µö¹¥»÷»î¶¯Bad Tidings£¬¸Ã¹¥»÷»î¶¯¿É×·ÒäÖÁ2016Äê11Ôµ×£¬¹²´´½¨Á˳¬¹ý90¸ö´¹µöÖ÷»úÃû£¨ÊôÓÚ46¸öÓòÃû£©¡£ÕâЩÐéαÓòÃû´ó¶àÒÔ.cc¡¢.xyz¡¢.club¡¢.siteºÍ.services½áβ¡£


Ô­ÎÄÁ´½Ó£º

https://www.anomali.com/blog/bad-tidings-phishing-campaign-impersonates-saudi-government-agencies-and-a-saudi-financial-institution

6¡¢Cardinal RATбäÖÖ£¬ÖØÒªÕë¶ÔÒÔÉ«ÁнðÈÚ¹«Ë¾


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Palo Alto NetworksµÄUnit 42ÍŶӷ¢ÏÖCardinal RATµÄбäÖÖÔÚÕë¶ÔÒÔÉ«ÁеĽðÈÚ¹«Ë¾¡£¸Ã±äÖְ汾Ϊ1.7.2£¬ÆäѡȡÁ˶àÖÖ»ìºÏ¼¼Êõ£¬Ô̺¬ÒþдÊõºÍXOR¼ÓÃܵÈ¡£¸Ã±äÖÖµÄÖ°ÄÜÔ̺¬ÍøÂçÐÅÏ¢¡¢¼üÅ̼ͼ¡¢ÆÁÄ»½ØÍ¼¡¢Ö´ÐжñÒâºÅÁî¼°×ÔÎÒÐ¶ÔØµÈ¡£×êÑÐÈËÔ±»¹·¢ÏָñäÖÖÓëÁíÒ»¸ö¶ñÒâÈí¼þ¼Ò×åEVILNUM´æÔÚ¹ØÁª¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/a-new-variant-of-cardinal-rat-employs-bmp-trick-to-target-israeli-financial-firms-e0cefbb0

ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù