¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190107
Ðû²¼Ê±¼ä 2019-01-07
ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©½«ÔÚ2019Äê3Ô·ݵÄRSA´ó»áÉÏÃâ·ÑÐû²¼ÄæÏò¹¤³Ì¹¤¾ßGHIDRA¡£¡£¡£¡£Æ¾Ö¤Î¬»ù½âÃÜÅû¶µÄCIA Vault 7ϵÁÐÎĵµ£¬£¬£¬GHIDRAÊÇÓÉNSA»ùÓÚJavaÓïÑÔ¿ª·¢µÄÄæÏò¹¤³Ì¹¤¾ß¡£¡£¡£¡£NSAÌåÏÖGHIDRA¾ßÓн»»¥Ê½GUI£¬£¬£¬²¢ÇÒÊÊÓÃÓÚ¶àÖÖÆ½Ì¨£¬£¬£¬°üÀ¨Windows¡¢LinuxºÍMac OS£¬£¬£¬»¹Ö§³Ö¶àÖÖоƬָÁ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/nsa-releasing-the-ghidra-reverse-engineering-tool-at-rsaconference/2¡¢Town of SalemÊý¾Ýй¶ÊÂÎñÁè¼Ý27%µÄÃÜÂëÒѱ»ÆÆ½â
2018Äê12ÔÂ28ÈÕ£¬£¬£¬ÐÅϢй¶ÅÌÎÊÍøÕ¾DeHashedÎüÊÕµ½Ò»·âÓʼþ£¬£¬£¬ÆäÖаüÀ¨Town of SalemÓÎϷЧÀÍÆ÷±»ºÚ¿ÍÈëÇÖµÄÖ¤¾ÝÒÔ¼°¸ÃÓÎÏ·Êý¾Ý¿âµÄ¸±±¾¡£¡£¡£¡£Æ¾Ö¤DeHashed£¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨Áè¼Ý760Íò¸öΨһµç×ÓÓʼþµØµã£¬£¬£¬»¹°üÀ¨Óû§Ãû¡¢¹þÏ£ÃÜÂë¡¢IPµØµãµÈÓû§Êý¾Ý¡£¡£¡£¡£ÃÜÂë»Ö¸´ÍøÕ¾Hashes.orgÒÑ¾ÆÆ½âÁËÕâЩй¶µÄÊý¾ÝÖеÄ210Íò¸ö¹þÏ£ÃÜÂ루Լ27%£©£¬£¬£¬½¨ÒéSalemÓû§¾¡¿ìÔÚʹÓÃÁËÏàͬÃÜÂëµÄÍøÕ¾Éϸü¸ÄÆäÃÜÂë¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/27-percent-of-passwords-from-town-of-salem-breach-already-cracked/3¡¢IBM TWCÌìÆøÓ¦ÓÃÒò³öÊÛÓû§Êý¾ÝÔâµ½ÆðËß
Âåɼí¶ÊÐÏò¼ÓÀû¸£ÄáÑÇÖÝ·¨ÔºÌáÆðËßËÏ£¬£¬£¬¿ØËßIBM×Ó¹«Ë¾TWCµÄÌìÆøÓ¦Óã¨Weather Channel£©ÍÚ¾òÓû§µÄÒþ˽Êý¾Ý²¢½«ÕâЩÐÅÏ¢³öÊÛ¸øµÚÈý·½£¬£¬£¬°üÀ¨¹ã¸æ¹«Ë¾¡£¡£¡£¡£Âåɼí¶Êз½ÃæÌåÏÖ£¬£¬£¬Weather ChannelÔÚÐí¶àÓû§²»ÖªÇéµÄÇéÐÎϸú×ÙÓû§µÄµØÀíλÖÃÊý¾Ý£¬£¬£¬²¢½«ÕâЩÊý¾ÝÓÃÓÚÓëÌìÆøÔ¤¸æÍêÈ«ÎÞ¹ØµÄ¹ã¸æµÈÉÌÒµÓÃ;¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/city-of-la-sues-weather-channel-app-for-sharing-location-data-with-advertisers/4¡¢Bobby YeeÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬²¨¼°2.4Íò»¼ÕßÐÅÏ¢
¼ÓÖÝ×ã¿ÆÒ½ÔºBobby Yee D.P.M.Ðû²¼Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ËûÃǵÄÒ½ÁƼͼ£¨°üÀ¨»¼ÕßµÄСÎÒ˽¼ÒÐÅÏ¢£©Ô⵽δÊÚȨ¸ü¸Ä¡£¡£¡£¡£Éæ¼°µ½µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¡¢ÄêËê¡¢ÐԱ𡢳öÉúÈÕÆÚ¡¢Éç±£ºÅÂë¡¢°ü¹Üµ¥ºÅÂëÒÔ¼°²¡Àú¡£¡£¡£¡£¸Ã°ì¹«ÊÒÒÑ֪ͨÁËÊÜÓ°ÏìµÄ2.4ÍòÃû»¼Õߣ¬£¬£¬µ«ÌåÏÖûÓÐÖ¤¾ÝÅúעСÎÒ˽¼ÒÐÅÏ¢»òÒ½ÁÆÐÅÏ¢Ô⵽й¶¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/bobby-yee-d-p-m-notified-24000-patients-after-ransomware-attack/5¡¢ÀÕË÷Èí¼þ¼Ò×åAuroraµÄÃ⺬»ìÃÜÆ÷Òѱ»Ðû²¼
Michael Gillespie½¨ÉèÁËÀÕË÷Èí¼þ¼Ò×åAuroraµÄÃ⺬»ìÃܹ¤¾ß¡£¡£¡£¡£¸Ã½âÃÜÆ÷¿É½âÃÜÀ©Õ¹ÃûΪ.Nano¡¢.animus¡¢.Aurora¡¢.desu¡¢.ONIºÍ.auroraµÄ±äÌ壬£¬£¬ÆäÖÐ.Nano±äÌåÊÇÄ¿½ñ×îΪ»îÔ¾µÄAurora±äÌå¡£¡£¡£¡£Auroraͨ³£Í¨¹ýRDPЧÀÍÈëÇÖÊܺ¦ÕßµÄÅÌËã»ú£¬£¬£¬²¢ÔÚ¼ÓÃÜÎļþÖ®ºóÒªÇóÒÔ±ÈÌØ±ÒÖ§¸¶Êê½ð¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/how-to-decrypt-the-aurora-ransomware-with-auroradecrypter/6¡¢ÐÂ¼ÓÆÂº½¿Õ¹«Ë¾Èí¼þbugµ¼ÖÂ284ÃûÓû§ÐÅϢй¶
ÐÂ¼ÓÆÂº½¿Õ¹«Ë¾Èí¼þ·ºÆðbug£¬£¬£¬µ¼ÖÂÁè¼Ý280ÃûKrisFlyerÓû§µÄСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£¡£Æ¾Ö¤¸Ã¹«Ë¾µÄÊӲ죬£¬£¬¹²ÓÐ284¸öKrisFlyerÕÊ»§Êܵ½Ó°Ï죬£¬£¬ÕâЩÕË»§µÄÐÕÃû¡¢º½°àÀúÊ·¡¢×î½üÀï³ÌºÍ½±Àø¿É±»ÆäËüÓû§»á¼û¡£¡£¡£¡£±ðµÄ£¬£¬£¬7ÃûÓû§µÄ»¤ÕÕºÅÂëÒ²±»Ð¹Â¶¡£¡£¡£¡£ÕâÒ»ÊÂÎñ±¬·¢ÔÚ1ÔÂ5ºÅ£¬£¬£¬¸Ã¹«Ë¾ÌåÏÖ²¢Ã»ÓÐÊܵ½Íⲿ¹¥»÷¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
http://theindependent.sg/singapore-airlines-experiences-security-breach-personal-information-of-more-than-280-krisflyer-members-disclosed/ÉùÃ÷£º±¾×ÊѶÓÉ¿·¢k8άËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ