¹¥»÷ÕßÀûÓûªË¶ÖÐÑëÈ˹¥»÷·Ö·¢PleadºóÃÅ£»È«ÇòÍþвָÊý£¬ÒøÐÐľÂíTrickbot³Á·µÇ°Ê®
°ä²¼¹¦·ò 2019-05-16
AdobeµÄ5Ô°²È«¸üн¨¸´Á˶à¸ö²úÆ·ÖеÄ87¸ö·ì϶¡£ÓëAdobe AcrobatºÍReaderÓйصķì϶ÊýΪ84¸ö£¬ÆäÖÐ42¸ö±»ÏóÕ÷ΪÑϳÁ£¨Critical£©·ì϶£¬ÕâЩ·ì϶¾ù¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐкÍϵͳÊÕÊÜ¡£Flash PlayerÖн¨¸´ÁËÑϳÁ·ì϶£¨CVE-2019-7837£©£¬¸Ã·ì϶ÊÇÒ»¸öUse-After-Free·ì϶£¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐУ¬Ó°ÏìÁËWindows¡¢macOS¡¢Linux¼°Chrome OSƽ̨µÄFlash Player¡£Media Encoderа汾13.1Öн¨¸´Á˿ɵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеÄÑϳÁ·ì϶£¨CVE-2019-7842£©ºÍ¿Éµ¼ÖÂÐÅϢй¶µÄ·ì϶£¨CVE-2019-7844£©¡£±¾Ô½¨¸´µÄ·ì϶¾ùûÓÐÔÚÒ°±í±»ÀûÓá£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/05/adobe-software-updates.html
2¡¢Twitter bugµ¼ÖÂÏòµÚÈý·½¹²ÏíiOSÓû§µÄλÏàÐÅÏ¢
TwitterÅû¶Æäƽ̨ÖеÄÒ»¸ö·ì϶£¬¸Ã·ì϶¿ÉÍøÂçiOSÓû§µÄµØÎ»Êý¾Ý²¢ÏòµÚÈý·½ºÏ×÷ͬ°é¹²ÏíÕâЩÊý¾Ý¡£·ì϶µÄ¾ßÌåϸ½ÚΪ£¬µ±Óû§ÔÚiOSÉ豸ÉÏʹÓÃÁ½¸öTwitterÕÊ»§Ê±£¬¼´±ã½öÔÚÒ»¸öÕÊ»§ÖÐÆôÓÃÁ˶¨Î»Ö°ÄÜ£¬Ò²»á½«ÍøÂçµ½µÄµØÎ»Êý¾ÝÀûÓÃÓÚÁíÒ»¸öÕË»§¡£Twitter³ÆÒѾ½¨¸´ÁËÕâ¸öÎÊÌ⣬²¢È·ÈϺÏ×÷ͬ°éÔÚÆäÕý³£Á÷³ÌÖÐɾ³ýÁ˹²ÏíµÄÊý¾Ý¡£Twitter»¹°µÊ¾ÒѾ֪ͨÁËÕË»§¿ÉÄÜÊܵ½Ó°ÏìµÄÓû§¡£
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/bug-in-twitter-led-to-collection-and-sharing-of-users-geolocation-data-with-its-partner-f2ebc19c
3¡¢¹¥»÷ÕßÀûÓûªË¶ÖÐÑëÈ˹¥»÷·Ö·¢PleadºóÃÅ
4Ôµ×ESET×êÑÐÈËÔ±¹Û²ìµ½ÀûÓá°AsusWSPanel.exe¡±·Ö·¢PleadºóÃŵĹ¥»÷»î¶¯¡£AsusWSPanel.exeÊÇ»ªË¶ÔÆ´æ´¢·þÎñWebStorageµÄWindows¿Í»§¶Ë¡£×êÑÐÈËÔ±¸ø³öÁËÁ½ÖÖ¿ÉÄܵĹ¥»÷³¡¾°£¬Ò»ÖÖÊÇ»ªË¶Ôâµ½¹©¸øÁ´¹¥»÷£¬ÁíÒ»ÖÖÊǹ¥»÷ÕßÀûÓÃÖÐÑëÈ˹¥»÷ºÍÒ×Êܹ¥»÷µÄ·ÓÉÆ÷À´´«²¼¶ñÒâÈí¼þ¡£½øÒ»²½µÄ·ÖÎöºó×êÑÐÈËÔ±ÒÔΪºóÒ»ÖÖ¹¥»÷³¡¾°µÄ¿ÉÄÜÐÔ¸ü´ó¡£
ÔÎÄÁ´½Ó£ºhttps://www.tripwire.com/state-of-security/security-data-protection/bad-actors-using-mitm-attacks-against-asus-to-distribute-plead-backdoor/
4¡¢Check Point×îÐÂÈ«ÇòÍþвָÊý£¬ÒøÐÐľÂíTrickbot³Á·µÇ°Ê®
Check Point°ä²¼4ÔÂÈ«ÇòÍþвָÊý£¬ÒøÐÐľÂíTrickbotÔÚʱ¸ôÁ½Äêºó³Á·µÇ°Ê®£¬Î»ÓÚµÚ°ËÃû¡£4Ô·ÝTrickbot¹¥»÷»î¶¯µÄÉÏÉýÇ÷Ïò¿ÉÄÜÓëÃÀ¹úÄÉ˰Èյĵ½À´Óйء£Ö»¹Ü°ñµ¥Ç°ÈýÃûÒÀÈ»±»¶ñÒâ¿ó¹¤Õ¼¾Ý£¬µ«ÆäÓàÆßÃû¶¼ÊǶàÖ°ÄÜľÂí£¬ÕâЩľÂí²»½öÄܹ»ÇÔÈ¡Êý¾Ý£¬»¹Äܹ»´«²¼ÆäËüÀÕË÷Èí¼þ¡£4Ô·Ý×î³£±»ÀûÓõķì϶ÊÇOpenSSL TLS DTLSÐÄÌø°üÐÅϢй¶·ì϶£¨CVE-2014-0160¡¢CVE-2014-0346£©¡£
ÔÎÄÁ´½Ó£ºhttps://blog.checkpoint.com/2019/05/14/april-2019s-most-wanted-malware-cybercriminals-up-to-old-trickbots-crypto-cryptomining-security-ryuk/
5¡¢ºÚ¿ÍÔÚ¸£²¼Ë¹¶©ÔÄÍøÕ¾×¢ÈëMagecart¾ç±¾
¸£²¼Ë¹¶©ÔÄÍøÕ¾±»ºÚ¿Í×¢Èë¶ñÒâMagecart¾ç±¾£¬¸Ã¾ç±¾ÓÃÓÚÍøÂçÓû§ÔÚÖ§¸¶Ò³ÃæÉÏÊäÈëµÄÖ§¸¶ÐÅÏ¢²¢·¢ËÍÖÁ¹¥»÷Õß½ÚÔìµÄÔ¶³Ì·þÎñÆ÷¡£ÇÔÈ¡µÄÐÅÏ¢Ô̺¬ÐÅÓþ¿¨ºÅ¡¢µ½ÆÚÈÕÆÚ¡¢CVV/CVCÂë¡¢ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂëºÍÓÊÏ䵨ַ¡£×êÑÐÈËÔ±Troy Mursch·¢ÏÖÁËÕâÒ»¹¥»÷ÊÂÎñ£¬¹ÌÈ»forbesmagazine.comÉÏÒÀÈ»´æÔÚ¸ÃMagecart¾ç±¾£¬µ«¹¥»÷ÕßÓÃÓÚÍøÂçÐÅÏ¢µÄ·þÎñÆ÷ÓòÃûÒѱ»ÓòÃû·þÎñÉÌFreenomɾ³ý£¬Ê¹µÃ¹¥»÷ÒѾÎÞЧ¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-inject-magecart-card-skimmer-in-forbes-subscription-site/
6¡¢¶íÂÞ˹µ±¾ÖÍøÕ¾Ð¹Â¶225Íò¹«ÃñµÄÃô¸ÐÐÅÏ¢
¶íÂÞ˹×êÑÐÈËÔ±Begtinµ÷²é·¢ÏÖ23¸öµ±¾ÖÍøÕ¾Ð¹Â¶Á˹«ÃñµÄSNILSºÅÂ루Ï൱ÓÚÉç±£ºÅÂ룩£¬14¸öµ±¾ÖÍøÕ¾Ð¹Â¶Á˹«ÃñµÄ»¤ÕÕÐÅÏ¢¡£×ܹ²Äܹ»ÔÚÏß»ñµÃ³¬¹ý225Íò¶íÂÞ˹¹«ÃñµÄÊý¾Ý£¬Ô̺¬ÐÕÃû¡¢Ö°Î»¡¢¹¤×÷µØÖ·¡¢µç×ÓÓʼþ¡¢ÄÉ˰ºÅÂëµÈ£¬ÒÔ¼°Ä³Ð©Çé¿öÏµĻ¤ÕÕÐÅÏ¢¡£BegtinÂÅ´Î֪ͨµ±¾ÐÄà¹Ü»ú¹¹£¬µ«ÎÊÌⲢδµÃµ½½â¾ö¡£Æ¾¾Ý±¾µØÃ½ÌåµÄ±¨Â·£¬Ò»Ð©¶íÂÞ˹µ±¾Ö¸ß¹ÙµÄÐÅÏ¢Ò²Ôâй¶£¬Ô̺¬Òé»á¸±Ö÷ϯAlexander ZhukovµÈ¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/russian-government-sites-leak-passport-and-personal-data-for-2-25-million-users/


¾©¹«Íø°²±¸11010802024551ºÅ