¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180613

°ä²¼¹¦·ò 2018-06-13

¡¾Íþвµý±¨¡¿×êÑÐÅú×¢¶ñÒâÍÚ¿ó»î¶¯³ÖÐøì­Éý£¬Ô¼5%µÄÃÅÂÞ±ÒΪ¶ñÒâÍÚ¿ó»ñµÃ


Palo Alto NetworksµÄUnit42×êÑÐÍŶӷÖÎöÁË629126¸ö¶ñÒâÍÚ¿óÈí¼þÑù±¾£¨²»Ô̺¬ä¯ÀÀÆ÷ÍÚ¿ó¾ç±¾£©£¬·¢ÏÖ84%µÄ¶ñÒâÍÚ¿óÈí¼þÓÃÓÚÍÚÈ¡ÃÅÂÞ±Ò¡£×êÑÐÈËÔ±³Æ·¸×ï·Ö×Óͨ¹ýÕâЩ¶ñÒâÍÚ¿óÈí¼þÍÚÈ¡ÁËÔ¼798613.33¸öÃÅÂÞ±Ò£¬Õ¼µ±Ç°Á÷ͨµÄÃÅÂÞ±Ò×ÜÊýµÄÔ¼5%¡£×Ô2017Äê6ÔÂÒÔÀ´£¬¶ñÒâÍÚ¿ó»î¶¯µÄÔö³¤ÔøÏÖ³ö¼¤½øµÄÉÏÉýÇ÷Ïò¡£

Ô­ÎÄÁ´½Ó£ºhttps://researchcenter.paloaltonetworks.com/2018/06/unit42-rise-cryptocurrency-miners/


¡¾Íþвµý±¨¡¿App StoreÃ÷È·²»ÈÝÀûÓÃAppleÉ豸½øÐÐÍÚ¿óµÄÀûÓÃ


Apple¸üÐÂÁËÆäAPP StoreÖ¸ÄϵÄÓ²¼þ¼æÈÝÐÔ²¿ÃÅ£¬´Ë¿ÌÃ÷È·²»ÈÝiOSºÍMacÀûÓü°¸æ°×ÔÚºó¶Ü½øÐÐÍÚ¿ó¡£ÕâÒ»ÐÐΪÊÇΪÁ˱£»¤Óû§µÄAppleÉ豸£¬¸ÃÖ¸ÄÏÖ¸³öÍÚ¿ó»î¶¯½«Ñ¸¿ìºÄ¾¡É豸µÄµç³Ø¡¢²úÉú¹ý¶àµÄÈÈÁ¿ÒÔ¼°¸øÉ豸×ÊÔ´´øÀ´²»ÓÃÒªµÄѹÁ¦¡£µ«ÈôÊÇÍÚ¿óÐÐΪÊÇÔÚÉ豸֮±íµÄ´¦Ëù½øÐУ¬ÈçÔ¶³Ì·þÎñÆ÷»òÔÆ£¬¸ÃÀûÓý«²»»á±»²»ÈÝ¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/cryptocurrency-mining-apps.html


¡¾·ì϶²¹¶¡¡¿VMware°ä²¼AirWatch AgentµÄ°²È«¸üУ¬½¨¸´¿Éµ¼ÖÂRCEµÄ°²È«·ì϶


VMware½¨¸´ÁËAirWatch AgentÀûÓÃÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-6968£©¡£¸Ã·ì϶¿ÉÔÊÐíδ¾­ÊÚȨµÄ¹¥»÷Õß´´½¨ºÍÖ´ÐÐAgentɳºÐºÍÆäËü¿É¹«¿ª½Ó¼ûµÄĿ¼£¨ÈçSD¿¨£©ÖеÄÎļþ¡£VMwareÔÚAndroidƽ̨µÄAirWatch Agent°æ±¾8.2ºÍWindows Mobileƽ̨µÄ°æ±¾6.5.2Öн¨¸´Á˸÷ì϶£¬iOS°æ±¾²»ÊÜÓ°Ïì¡£


Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/73452/hacking/airwatch-agent-rce.html


¡¾Êý¾Ýй¶¡¿Weight Watchers¹«Ë¾µÄKubernetes·þÎñÆ÷δÉèÖÃÃÜÂ룬²¿ÃÅ»ù´¡ÉèÊ©µÄÍ´´¦Ð¹Â¶


µÂ¹ú°²È«³§ÉÌKromtechµÄ×êÑÐÈËÔ±·¢ÏÖWeight Watchers¹«Ë¾µÄKubernetes·þÎñÆ÷δÉèÖÃÃÜÂ룬ÕâʹµÃÈκÎÈ˶¼Äܹ»Í¨¹ý¶Ë¿Ú10250½Ó¼û¸Ã·þÎñÆ÷¡£×êÑÐÈËÔ±Ôڸ÷þÎñÆ÷ÉÏ·¢ÏÖÁËWeight Watchers¹«Ë¾µÄIT»ù´¡ÉèÊ©µÄÅäÏàÐÅÏ¢£¬Ô̺¬ÖÎÀíԱʹ´¦¡¢102¸öÓòµÄ½Ó¼ûÃÜÔ¿¡¢AWS½Ó¼ûÃÜÔ¿µÈ¡£Weight Watchers³ÆÕâ²»ÊÇÒ»¸ö³ö²úÍøÂç¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/weight-watchers-it-infrastructure-exposed-via-no-password-kubernetes-server/


¡¾Êý¾Ýй¶¡¿AÕ¾ÔâºÚ¿Í¹¥»÷£¬½üǧÍòÓû§µÄÊý¾Ýй¶


½ñÈÕÁ賿AcFun°ä²¼²¼¸æ³ÆÆäÔâºÚ¿Í¹¥»÷£¬½üǧÍòÓû§µÄÊý¾Ýй¶£¬Ô̺¬Óû§ID¡¢êdzơ¢¼ÓÃÜ´æ´¢µÄÃÜÂëµÈ¡£ÔÚ2017Äê7ÔÂ7ÈÕ֮ǰµÇ¼¹ýAcFunµÄÓû§ÊÜÓ°Ï죬µ«Ò²½¨ÒéÃÜÂë¹ýÓÚµ¥Ò»µÄÆäËüÓû§Åú¸ÄÃÜÂë¡£AcFun³ÆÒѾ­½áºÏÄÚ²¿ºÍ±í²¿µÄ¼¼Êõר¼Ò¶ÔÎÊÌâ½øÐÐÅŲ飬²¢Éý¼¶ÏµÍ³µÄ°²È«µÈ¼¶¡£


Ô­ÎÄÁ´½Ó£ºhttp://www.sohu.com/a/235455264_250147


¡¾°²È«²¥±¨¡¿FBI¿ÛÁô74ÃûÉæ¼°ÄáÈÕÀûÑÇBECÚ¿Æ­»î¶¯µÄ·¸×ï·Ö×Ó


FBIºÍ¹ú¼Ê·¨ÂÉ»ú¹¹½áºÏ¿ÛÁôÁËÉæ¼°ÄáÈÕÀûÑÇBECÚ¿Æ­ÍÅ»ïµÄ74Ãû·¸×ï·Ö×Ó£¬ÆäÖÐÔÚÃÀ¹ú¿ÛÁôÁË42Ãû£¬ÔÚÄáÈÕÀûÑÇ¿ÛÁôÁË29Ãû£¬ÔÚ¼ÓÄôó¡¢Ã«ÀïÇó˹ºÍ²¨À¼±ðÀë¿ÛÁôÁË1Ãû¡£Õâ´Î·¨ÂÉÐж¯ÊÇFBIÖ÷µ¼µÄóÒ×ڲƭµ÷²éÐж¯Operation Wire WireµÄÒ»²¿ÃÅ£¬µ±¾Ö¹²½É»ñÁËÔ¼240ÍòÃÀÔª£¬²¢×·»ØÁËÔ¼1400ÍòÃÀÔªµÄڲƭÂòÂô×ʽð¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/email-phishing-nigerian-scams.html