¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180905

°ä²¼¹¦·ò 2018-09-05

¡¾Õþ²ßÂÉÀý¡¿¹¤ÐŲ¿°ä²¼2018ÄêµÚ¶þ¼¾¶ÈÍøÂ簲ȫÍþÐ²Ì¬ÊÆ·ÖÎöÓ빤×÷×ÛÊö


¹¤ÐŲ¿°ä²¼µÄµÚ¶þ¼¾¶ÈÍøÂ簲ȫÍþÐ²Ì¬ÊÆÈçÏ£ºµÚ¶þ¼¾¶È¹²¼à²âÍøÂ簲ȫÍþвԼ1841Íò¸ö £¬ÆäÖлù´¡µçÐÅÆóÒµ¼à²âÔ¼1683Íò¸ö £¬ÍøÂ簲ȫרҵ»ú¹¹¼à²âÔ¼3Íò¸ö £¬³Áµã»¥ÁªÍøÆóÒµ¡¢ÓòÃû»ú¹¹ºÍÍøÂ簲ȫÆóÒµ¼à²âÔ¼155Íò¸ö¡£ÍøÂ簲ȫÍþÐ²Ì¬ÊÆ³öÏÖÒÔϼ¸¸öÌØµã£º£¨Ò»£©²¿ÃÅ»¥ÁªÍøÓû§ÓÊÏäÒÉËÆ±»¿Ø £¬ÑϳÁ·çÏÕÓû§Ó×ÎÒÐÅÏ¢°²È«¡££¨¶þ£©¹¤Òµ»¥ÁªÍøÆ½Ì¨ºÍÖÇÄÜÉ豸³ÉÎªÍøÂçÍþвµÄ³ÁÒªÖ¸±ê¡££¨Èý£©·¸·¨¡°ÍÚ¿ó¡±ÑϳÁÍþв»¥ÁªÍøÍøÂ簲ȫ¡£


Ô­ÎÄÁ´½Ó£ºhttp://www.miit.gov.cn/n1146285/n1146352/n3054355/n3057724/n3057728/c6363487/content.html


¡¾Êý¾Ýй¶¡¿×êÑÐÈËÔ±·¢ÏÖÔ¼57ÍòMortal OnlineÓÎÏ·Íæ¼ÒµÄÍ´´¦ÔÚÂÛ̳ÏúÊÛ


°²È«×êÑÐÈËÔ±Adam Davies·¢ÏÖÊôÓÚÔ¼57ÍòMortal OnlineÓÎÏ·Íæ¼ÒµÄÕË»§ÐÅÏ¢ÔÚÂÛ̳ÉÏÏúÊÛ¡£2018Äê6ÔÂ17ÈÕδ¾­ÊÚȨµÄµÚÈý·½½Ó¼ûÁ˸ÃÓÎÏ·µÄÂÛ̳ºÍÉ̵êÊý¾Ý¿âµÄ·þÎñÆ÷²¢ÇÔÈ¡ÁËÓû§µÄÊý¾Ý¡£¹¥»÷Õß»¹»ñÈ¡ÁËÓû§ÃÜÂëµÄMD5¹þÏ£Öµ £¬ÕâЩ¹þÏ£ÖµËÆºõÒѱ»ÆÆ½â¡£¸ÃÊý¾Ý¿âĿǰÒѱ»Ôö³¤µ½Have I Been PwnedÍøÕ¾ÖС£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cracked-logins-of-570-000-mortal-online-players-sold-on-forums/


¡¾Êý¾Ýй¶¡¿¼Ò³¤¼à¿ØÈí¼þFamily OrbitÔâºÚ¿ÍÈëÇÖ £¬Êý°ÙÃû¶ùͯµÄÕÕÆ¬¿ÉÄÜй¶


¼Ò³¤¼à¿ØÀûÓÃFamily OrbitµÄÔÆ·þÎñÆ÷Ôâµ½ºÚ¿Í¹¥»÷ £¬Ô¼281GBÊý¾ÝÒÉÔâй¶¡£¹¥»÷Õß·¢ÏÖ¸ÃÔÆ·þÎñÆ÷´æÔÚÈõÃÜÂë·ì϶ £¬ÀûÓø÷ì϶¿É»ñÈ¡Êý°ÙÃû¶ùͯµÄÕÕÆ¬µÄ½Ó¼ûȨÏÞ¡£Family Orbit¹«Ë¾È·ÈÏÁ˸ÃÊý¾Ýй¶ÊÂÎñ £¬²¢ÂíÉϸü¸ÄÁËAPIÃÜÔ¿ºÍµÇ¼ʹ´¦¡£¸Ã¹«Ë¾³ÆÒÑÖÕ³¡ÏúÊۺͷþÎñ £¬Ö±µ½È·±£ËùÓеķì϶¶¼µÃµ½½¨¸´¡£


Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75888/data-breach/family-orbit-hacked.html


¡¾¶ñÒâÈí¼þ¡¿×êÑÐÍŶӷ¢ÏÖÖØÒªÕë¶Ô°ÍÎ÷ÒøÐеĶñÒâÈí¼þCamuBot


IBM X-Force×êÑÐÍŶӹ۲쵽һ¸öÖØÒªÕë¶Ô°ÍÎ÷ÒøÐеÄжñÒâÈí¼þCamuBot¡£CamuBotÓÚ2018Äê8Ô³öÏÖ £¬ÖØÒªÕë¶Ô°ÍÎ÷µÄÆóÒµºÍ¹«¹²²¿ÃÅ £¬Æä¼Ù×°³ÉÖ¸±êÒøÐеݲȫÄ£¿é½øÐд«²¼¡£¹¥»÷Õß¼Ù×°³ÉÒøÐеÄÔ±¹¤ £¬Í¨¹ýµç»°ÅúʾÊܺ¦Õßä¯ÀÀÒ»¸öURLÒԲ鳭Æä°²È«Ä£¿éÊÇ·ñÊÇ×îеÄ¡£CamuBotµÄ¹¥»÷»î¶¯ÊÇÓÐÕë¶ÔÐԵġ£


Ô­ÎÄÁ´½Ó£ºhttps://securityintelligence.com/camubot-new-financial-malware-targets-brazilian-banking-customers/


¡¾°²È«²¥±¨¡¿¾Ý±¨Â·¹È¸èÓëÍòÊ´ï°ÂÃØºÏ×÷ÒÔ¸ú×ÙÓû§µÄÏû·Ñ¼Í¼


¾ÝÅí²©É籨· £¬¹È¸èÏòÍòÊ´│¹«Ë¾Ö§¸¶ÁËÊý°ÙÍòÃÀÔªÒÔ»ñÈ¡Óû§¹ºÎïµÄÊý¾Ý¡£Á½¼Ò¹«Ë¾¾­¹ý4ÄêµÄ½»Éæ £¬´ï³ÉÁËÒ»±Ê·Ç¹«¿ªµÄÂòÂô¡£¹È¸èʹÓÃÕâЩÓû§µÄÏßϹºÎïÊý¾ÝΪ¸æ°×Ö÷¿ª·¢¹¤¾ß £¬Ï¸·Ö³öÄÇЩµã»÷¹ýÔÚÏ߸æ°× £¬ËæºóÔÚÏßÏÂʵÌåµê²É°ìÉÌÆ·µÄ¹Ë¿Í¡£¹È¸è»Ø¾øÖ¤ÊµÓëÍòÊ´│¹«Ë¾µÄºÏ×÷¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/09/google-mastercard-advertising.html


¡¾·ì϶²¹¶¡¡¿¼à¿ØÈí¼þOpsview Monitor°ä²¼°²È«¸üР£¬½¨¸´5¸ö·ì϶


SecureAuthºÍCoreSecurityÅû¶¼à¿ØÈí¼þOpsview MonitorÖеÄ5¸ö°²È«·ì϶ £¬Ô̺¬XSS·ì϶£¨CVE-2018-16147ºÍCVE-2018-16148£©¡¢¿Éµ¼ÖºÅÁîÖ´Ðеķì϶£¨CVE-2018-16146ºÍCVE-2018-16144£©ÒÔ¼°±¾µØÌáȨ·ì϶£¨CVE-2018-16145£©¡£Opsview Monitor°æ±¾4.2¡¢5.3ºÍ5.4Êܵ½Ó°Ïì £¬½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾¡£


Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/multiple-remote-code-execution-flaws-patched-in-opsview-monitor/137170/