¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190130

Ðû²¼Ê±¼ä 2019-01-30
1¡¢FaceTimeÆØÖØ´óÇÔÌýÎó²î£¬£¬£¬AppleÌåÏÖ½«ÔÚ±¾ÖÜÐÞ¸´

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¾ÝÍâý±¨µÀ£¬£¬£¬Apple FaceTime±£´æÖØ´óÇå¾²Îó²î£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÄ¿µÄ½ÓÌý»ò¾Ü¾øFaceTimeͨ»°Ö®Ç°¼àÌý¶Ô·½µÄÉùÒô¡£¡£¡£¡£¡£¡£¡£ÈôÊǶԷ½°´ÏÂÒôÁ¿½µµÍ°´Å¥»òµçÔ´°´Å¥À´¾²Òô»ò×÷·Ïͨ»°£¬£¬£¬ÔòÆäǰÖÃÉãÏñÍ·Ò²»á·­¿ª£¬£¬£¬²¢½«ÊÓÆµÐźŷ¢Ë͸ø¹¥»÷Õß¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬¸ÃÎó²î»á·ºÆðÔÚiOS 12.1»ò¸ü¸ß°æ±¾µÄiOS×°±¸ÖС£¡£¡£¡£¡£¡£¡£AppleÒѾ­ÔÝʱ½ûÓÃÁËFaceTimeÖеÄȺ×éͨ»°¹¦Ð§£¬£¬£¬²¢ÌåÏÖ½«ÔÚ±¾ÖÜÍíЩʱ¼äÐû²¼ÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/apple-facetime-privacy-hack.html


2¡¢°Ä´óÀûÑÇ8¼ÒÍйÜЧÀÍÉÌÔâÓö¹¥»÷»î¶¯Manic Menagerie

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾



ƾ֤°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄ£¨ACSC£©Ðû²¼µÄÒ»·Ý±¨¸æ£¬£¬£¬8¸öÍйÜЧÀÍÉÌÔÚ2018ÄêÔâÓö¶ñÒâ¹¥»÷»î¶¯Manic Menagerie¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃWebÓ¦ÓÃÖеÄÎó²îÀ´»ñÈ¡WebЧÀÍÆ÷µÄrootȨÏÞ£¬£¬£¬²¢×°ÖÃÃÜÂëÇÔÈ¡¹¤¾ßºÍGh0st RAT¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÒ»¸ö±»Ê¹ÓõÄÎó²îÊÇ2018Äê4Ô¹ûÕæµÄÌáȨÎó²îTotalMeltdown£¨CVE-2018-1038£©¡£¡£¡£¡£¡£¡£¡£ACSCÒѽ¨ÒéÕâЩÍйÜЧÀÍÉ̸øWebÓ¦ÓúÍCMS´ò²¹¶¡ºÍ½ûÓöñÒâ²å¼þ£¬£¬£¬²¢ÖØÖÃÓû§µÄƾ֤¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/eight-australian-web-hosting-providers-compromised-in-manic-menagerie-attack-campaign-8ee4259a 


3¡¢AZORultľÂíαװ³É¹È¸è¸üгÌÐò£¬£¬£¬Ö¼ÔÚÇÔÈ¡Óû§Æ¾Ö¤

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


À´×ÔMinerva Labs¡¢Asaf AprozperºÍGal BitenskyµÄÑо¿Ö°Ô±ÊӲ쵽AZORultľÂíͨ¹ýαװ³ÉGoogle Updater³ÌÐòÀ´ÊµÏÖ³¤ÆÚÐÔ¡£¡£¡£¡£¡£¡£¡£AZORultľÂíÖ÷ÒªÓÃÓÚÇÔÈ¡Óû§µÄÃô¸ÐÊý¾Ý£¬£¬£¬°üÀ¨Îļþ¡¢ÃÜÂë¡¢cookie¡¢ä¯ÀÀÆ÷ÀúÊ·¼Í¼¡¢ÒøÐÐÆ¾Ö¤ºÍ¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚAZORultαװ³ÉGoogle Updater³ÌÐò£¬£¬£¬Ëü½«ÒÔÖÎÀíԱȨÏÞÔËÐС£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÕâЩ¶ñÒâµÄGoogleUpdate.exeÎļþʹÓÃÁËÓÐÓõÄÖ¤Êé¾ÙÐÐÊðÃû£¬£¬£¬µ«¸ÃÖ¤ÊéÏÖʵÉϱ»½ÒÏþ¸ø¡°Singh Agile Content Design Limited¡±£¬£¬£¬¶ø²»ÊÇGoogle¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/azorult-trojan-disguised-as-google-update-installer-steals-credentials-6e225ab6


4¡¢¶ñÒâÈí¼þFormBook»Ø¹é£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹úÁãÊÛºÍÂùÝÒµ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ƾ֤Deep InstinctµÄ±¨¸æ£¬£¬£¬FormBookÕýÔÚʹÓÃÒ»¸öеÄÎļþÍйÜЧÀÍÈö²¥£¬£¬£¬Ö÷Òª¹¥»÷ÃÀ¹úµÄÁãÊÛºÍÂùÝÒµ¡£¡£¡£¡£¡£¡£¡£FormBook×îÔç·ºÆðÓÚ2016Ä꣬£¬£¬¿ÉÒÔÇÔÈ¡Óû§µÄƾ֤¡¢½ØÈ¡×ÀÃæÆÁÄ»ÒÔ¼°¼Í¼¼üÅ̵È¡£¡£¡£¡£¡£¡£¡£ÔÚÕâ¸öеĶñÒâ»î¶¯ÖУ¬£¬£¬FormBookͨ¹ý´¹ÂÚÓʼþÖеÄRTF¸½¼þÈö²¥£¬£¬£¬¸Ã¸½¼þʹÓÃÁËCVE-2012-0158¡¢CVE-2017-11882µÈOfficeÎó²î¡£¡£¡£¡£¡£¡£¡£FormBook»¹Ê¹ÓÃÁËÒ»¸öеÄÎļþÍйÜЧÀÍDropMyBin£¬£¬£¬¸ÃÎļþÍйÜЧÀÍÒ²±»ÆäËü¶ñÒâÈí¼þʹÓ㬣¬£¬ÀýÈçLokibotºÍAzorult¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.deepinstinct.com/2019/01/27/info-stealer-formbook-continues-activity-and-uses-a-new-malware-friendly-file-hosting-service/


5¡¢·ÆÂɱöµçÐŹ«Ë¾GlobeÒâÍâй¶8851Ãû¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ƾ֤BestVPN.comµÄ±¨¸æ£¬£¬£¬·ÆÂɱöµçÐŹ«Ë¾GlobeÔÚ½üÆÚµÄÍÆ¹ã×¢²á»î¶¯ÖУ¬£¬£¬ÒâÍâÏòÐÂ×¢²áµÄÓû§ÓÊÏä·¢ËÍÁËÆäËüÓû§¼òÖ±ÈÏÓʼþ£¬£¬£¬µ¼Ö²¿·Ö¿Í»§µÄÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£ÕâЩÊý¾Ý°üÀ¨¿Í»§µÄÐÕÃû¡¢µç×ÓÓÊÏ䵨µãºÍÍêÕûµÄÓÊÕþµØµã£¬£¬£¬¹²ÓÐ8851Ãû¿Í»§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÒѾ­Ö¤ÊµÁËÕâÒ»ÊÂÎñ£¬£¬£¬²¢Æ¾Ö¤î¿ÏµÒªÇó֪ͨÁ˹ú¼ÒÒþ˽±£»£»£»£»£»¤Î¯Ô±»á£¨NPC£©¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/filipino-telecom-giant-globe-inadvertently-leaks-personal-data-of-8851-subscribers-e87bb87b


6¡¢ÐÂ¼ÓÆÂÔ¼1.4Íò°¬×̲¡»¼ÕßÐÅϢй¶£¬£¬£¬ÏÓ·¸ÎªÃÀ¼®ÄÐ×Ó

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

2019Äê1ÔÂ28ÈÕ£¬£¬£¬ÐÂ¼ÓÆÂÎÀÉú²¿ÔÚÒ»·ÝÉùÃ÷ÖÐ֤ʵÃÀ¹úÄÐ×ÓMikhy K Farrera Brochez²»·¨»ñÈ¡²¢Ð¹Â¶ÁËÔ¼1.42Íò°¬×̲¡»¼ÕßµÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ5400Ãû»¼ÕßÊÇÐÂ¼ÓÆÂÈË£¬£¬£¬8800Ãû»¼ÕßÊÇÍâ¹úÈË¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨»¼ÕßµÄÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢µç»°ºÅÂë¡¢µØµã¡¢HIV¼ì²âЧ¹ûºÍÏà¹ØÒ½ÁÆÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£ÕâЩÊý¾ÝÊÇBrochezÖØÐÂ¼ÓÆÂµÄ°¬×̲¡¹ÒºÅ´¦ÇÔÈ¡µÄ¡£¡£¡£¡£¡£¡£¡£2017Äê3Ô£¬£¬£¬BrochezÔÚÐÂ¼ÓÆÂ±»¿ØÚ²Æ­µÈ¶àÏî×ïÃû£¬£¬£¬²¢ÔÚ·þÐ̺ó±»ÇýÖð³ö¾³¡£¡£¡£¡£¡£¡£¡£2019Äê1ÔÂ22ÈÕ£¬£¬£¬ÐÂ¼ÓÆÂÎÀÉú²¿·¢Ã÷ÉÏÊö»¼Õß×ÊÁÏÔÚÍøÉϱ»Ð¹Â¶ºó±¨¾¯¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚÍâµØ¾¯ÆÓÖ±ÔÚ×·Çó¶Ô´Ë°¸¾ÙÐйú¼ÊÊӲ졣¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/private-data-of-almost-14200-patients-diagnosed-with-hiv-leaked-online-de45a837


ÉùÃ÷£º±¾×ÊѶÓÉ¿­·¢k8άËûÃüÇ徲С×é·­ÒëºÍÕûÀí