¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180614

°ä²¼¹¦·ò 2018-06-14
¡¾Êý¾Ýй¶¡¿ÁãÊÛ¹«Ë¾Dixons CarphoneÔâºÚ¿ÍÈëÇÖ£¬Ô¼590ÍòÓû§µÄÐÅÓþ¿¨ÐÅϢй¶


ÁãÊÛ¹«Ë¾Dixons CarphoneÅû¶һ¸öÉæ¼°Ô¼590ÍòÕÅÐÅÓþ¿¨ºÍ120ÍòÌõÓ×ÎÒÊý¾Ý¼Í¼µÄ°²È«ÊÂÎñ ¡£¸Ã¹«Ë¾³ÆºÚ¿Í½Ó¼ûÁË´æ´¢ÔÚÆäCurrys PC WorldºÍDixons TravelÉ̵êµÄϵͳÖеÄÔ¼590ÍòÕÅÐÅÓþ¿¨Êý¾Ý£¬ÆäÖÐ580ÍòÕÅÐÅÓþ¿¨ÓµÓÐоƬºÍPINÂë± £»¤£¬ÕâÒâζןڿͻñÈ¡µÄÊý¾Ý¼ÈûÓÐÔ̺¬PINÂë¡¢CVV£¬Ò²Ã»ÓÐÔ̺¬ÈκÎÄܹ»½øÐгֿ¨È˼ø±ðºÍ²É°ìÐÐΪµÄÑéÖ¤Êý¾Ý ¡£¸Ã¹«Ë¾ÔÚÁªÏµÊÜÓ°ÏìµÄÓû§£¬²¢ÏòËûÃÇ´ÍÓ뽨Òé ¡£


Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/73479/data-breach/dixons-carphone-hacked.html





¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±·¢ÏÖMacµÄ°²È«¹¤¾ß´æÔÚbug£¬¿ÉÔÊÐí¶ñÒâÈí¼þ¼Ù×°³ÉºÏ·¨µÄAppleÈí¼þ


ƾ¾ÝOkta°²È«×êÑÐÈËÔ±Josh Pitts°ä²¼µÄ×êÑл㱨£¬µÚÈý·½ÀûÓ÷¨Ê½Öеķì϶¿Éµ¼Ö¶ñÒâÈí¼þ¼Ù×°³ÉÓÉAppleÊðÃûµÄºÏ·¨·¨Ê½£¬À´×ÔFacebook¡¢Google¡¢VirusTotalµÈµÄµÚÈý·½Mac°²È«·¨Ê½¶¼ÊÜÓ°Ïì ¡£¸Ã·ì϶ÊÇÓÉÓÚÀûÓ÷¨Ê½Ã»ÓÐÕýÈ·µØ²é³­¿ÉÖ´ÐÐÎļþ£¨FatÎļþ£©µÄÊðÃûµ¼ÖµÄ£¬Apple³ÆÕâÊÇÒ»¸öÓëµÚÈý·½¿ª·¢ÈËÔ±Óйصķì϶ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/mac-security-tool-bugs-allow-malware-to-appear-as-apple-software/





¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖAPT27Õë¶ÔÖÐÑǵØÓòµÄ¹ú¶ÈÊý¾ÝÖÐÐÄÌáÒé¹¥»÷»î¶¯


¿¨°Í˹»ù³¢ÊÔÊÒ·¢ÏÖÒ»¸öÕë¶ÔÖÐÑǹú¶ÈÊý¾ÝÖÐÐĵĹ¥»÷»î¶¯£¬¸Ã»î¶¯×Ô2017ÄêÇï¼¾ÒÔÀ´Ò»Ïò»îÔ¾£¬×êÑÐÈËÔ±ÒÔΪ¹¥»÷ÕßÊÇ·¸×ïÍÅ»ïLuckyMouse£¨Ò²±»³ÆÎªAPT27£© ¡£³õʼ¹¥»÷ÏòÁ¿Éв»Ã÷ÏÔ£¬µ«¹¥»÷ÕßʹÓÃľÂíHyperBro×÷ΪÆä×îÖս׶εÄRAT¹¤¾ß£¬²¢¿ÉÄÜÀûÓÃÕâЩµ±¾ÖÍøÕ¾×ÊÔ´ÌáÒéË®¿Ó¹¥»÷ ¡£×êÑÐÈËÔ±Åû¶Á˸ù¥»÷»î¶¯ÓйصÄIoC ¡£


Ô­ÎÄÁ´½Ó£ºhttps://securelist.com/luckymouse-hits-national-data-center/86083/





¡¾·ì϶²¹¶¡¡¿Î¢Èí°ä²¼6Եݲȫ¸üУ¬¹²½¨¸´50¸ö°²È«·ì϶


±¾Öܶþ΢Èí°ä²¼2018Äê6Եݲȫ¸üУ¬¹²½¨¸´ÁË50¸ö°²È«·ì϶£¬ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬Windowsϵͳ¡¢IE¡¢Edge¡¢JSÒýÇæChakraCore¡¢OfficeºÍWeb Apps ¡£±¾´Î²¹¶¡°üÖв»Ô̺¬ÈκÎWindows 0day£¬µ«Î¢Èí½¨¸´ÁËÉÏÖÜÅû¶µÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-8267£© ¡£¾ßÌå·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/microsoft/microsoft-june-2018-patch-tuesday-fixes-50-security-issues/





¡¾·ì϶²¹¶¡¡¿×êÑÐÈËÔ±·¢ÏÖCortanaÌáȨ·ì϶¿ÉÔÊÐí¹¥»÷Õß½Ó¼ûËø¶¨µÄµçÄÔ


McAfee°²È«×êÑÐÈËÔ±Cedric Cochin·¢ÏÖ΢ÈíµÄCortanaÖÇÄܸ±ÊÖ´æÔÚÒ»¸ö°²È«·ì϶£¬¸ÃÌáȨ·ì϶£¨CVE-2018-8140£©¿ÉÔÊÐí¹¥»÷Õß½Ó¼ûËø¶¨µÄÍÆËã»úÒÔʹÓÃCortanaºÍ½Ó¼ûÉ豸ÉϵÄÊý¾Ý¡¢Ö´ÐжñÒâ´úÂëÉõÖÁÅú¸ÄÃÜÂëÒÔÆëÈ«ÊÕÊÜÉ豸 ¡£½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾µÄWindows£¬»òÕßÔÚËø¶¨ÆÁĻʱ½ûÓÃCortana ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cortana-hack-lets-you-change-passwords-on-locked-pcs/





¡¾¶ñÒâÈí¼þ¡¿×êÑÐÍŶӷ¢ÏÖͨ¹ýNSA EternalRomance·ì϶ÀûÓô«²¼µÄ¶ñÒâÈí¼þPyRoMineIoT


Fortinet×êÑÐÍŶӷ¢ÏÖÀûÓÃÓëNSAÓйصÄEternalRomance·ì϶ÀûÓýøÐд«²¼µÄ¶ñÒâÍÚ¿óÈí¼þPyRoMineIoT£¬PyRoMineIoTÊÇPyRoMineµÄÒ»¸öбäÖÖ£¬ÆäÀûÓÃÊÜϰȾµÄÉ豸À´É¨ÃèÒ×Êܹ¥»÷µÄIoTÉ豸£¬ÖØÒªÕë¶ÔÒÁÀʺÍÉ³ÌØ°¢À­²® ¡£PyRoMineIoTÒÀȻʹÓÃÁËIPµØÖ·212.83.190.122£¬Æä»áÔÚÊÜϰȾµÄÉ豸ÉÏÊÔͼɾ³ýÆäËüPyRoMine±äÖÖ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/73472/malware/pyromineiot-iot-miner.html