¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180925
°ä²¼¹¦·ò 2018-09-25¡¾·ÖÎö»ã±¨¡¿¿¨°Í˹»ù°ä²¼¹ØÓÚICSϵͳÖеÄRAT·çÏյķÖÎö»ã±¨
¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼¹ØÓÚICSÖеÄRAT·çÏյķÖÎö»ã±¨¡£Ô¶³ÌÖÎÀí¹¤¾ß£¨RAT£©±»¿í·ºÓÃÓÚ¹¤ÒµÍøÂçÖ®ÖУ¬ÓÃÓÚ½øÐÐICS¼à²â¡¢½ÚÔìºÍÊØ»¤¡£Ô¶³Ì²Ù×÷ICSµÄÄÜÁ¦Äܹ»´ó´ó½µµÍÊØ»¤³É±¾£¬µ«²»ÊܽÚÔìµÄÔ¶³Ì½Ó¼û¡¢ÎÞ·¨100%µØÌṩԶ³Ì¿Í»§¶ËµÄºÏ·¨ÐÔÑéÖ¤ÒÔ¼°RAT´úÂëºÍÅäÖÃÖеķì϶¶¼´ó´óÔö³¤Á˹¥»÷Ãæ¡£Óë´Ëͬʱ£¬¹¥»÷ÕßÔ½À´Ô½¶àµØÊ¹ÓÃRATºÍÆäËüºÏ·¨¹¤¾ßÀ´¸²¸ÇÆä¶ñÒâ»î¶¯£¬Ê¹µÃ¶Ô¶ñÒâ»î¶¯½øÐйéÒòÔ½·¢ÄÑÌâ¡£
https://securelist.com/threats-posed-by-using-rats-in-ics/88011/
¡¾·ì϶²¹¶¡¡¿Î÷Êý°ä²¼NASÉ豸µÄ°²È«¸üУ¬½¨¸´Ò»¸öÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶
Î÷Êý°ä²¼My Cloud NASÉ豸µÄ¹Ì¼þ¸üУ¬½¨¸´Éí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2018-17153£©¡£¸Ã·ì϶ÔÊÐí¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤²¢»ñµÃÉ豸µÄÖÎÀíԱȨÏÞ¡£¸Ã·ì϶ÓÉSecurifyµÄ×êÑÐÈËÔ±·¢ÏÖ£¬²¢ÓÚ2017Äê4Ô»㱨¸øÎ÷Êý£¬µ«Î÷ÊýÔÚ³¤´ïÒ»Äê¶àµÄ¹¦·òÀïÒ»ÏòûÓнøÐÐÈκλظ´¡£ÔÚ¾¹ý¿í·ºµÄýÌ屨·ºó£¬Î÷Êý°ä²¼Á˸÷ì϶µÄÓйؽ¨¸´²¹¶¡¡£
https://www.bleepingcomputer.com/news/security/western-digital-releases-hotfix-for-my-cloud-auth-bypass-vulnerability/
¡¾°²È«·ì϶¡¿×êÑÐÈËÔ±·¢ÏÖFireFox´æÔÚÐÂbug£¬¿Éµ¼ÖÂä¯ÀÀÆ÷ºÍ²Ù×÷ϵͳ±ÀÀ£
Wire°²È«×êÑÐÈËÔ±Sabri Haddouche·¢ÏÖFirefoxÖеÄÒ»¸öÐÂbug£¬¿Éµ¼ÖÂä¯ÀÀÆ÷±ÀÀ££¬ÔÚijЩÇé¿öÏÂÉõÖÁ»áµ¼Öµײã²Ù×÷ϵͳ±ÀÀ£¡£ÆäÔÒòÊǶñÒâJavaScript¾ç±¾»áÌìÉúÒ»¸öÎļþ£¨blob£©£¬ÆäÖÐÔ̺¬Ò»¸ö¼«¶È³¤µÄÎļþÃû£¬²¢ÌáÐÑÓû§Ã¿¸ôÒ»ºÁÃëÏÂÔØÒ»´Î¡£Òò¶ø£¬Ëü»áÔÚFirefoxµÄ×Ó½ÚµãºÍÖ÷½ÚµãÖ®¼ä³äÒçIPC£¨¹ý³Ì¼äͨѶ£©Í¨Â·¹ý³Ì£¬Ê¹ÏµÍ³±ÀÀ£¡£Mac¡¢LinuxºÍWindowsƽ̨ÉϵÄFirefox¶¼ÊÜÓ°Ïì¡£×êÑÐÈËÔ±ÒÑÓÚ9ÔÂ23ÈÕÏòMozilla»ã±¨Á˸÷ì϶£¬²¢ÔÚGitHubÉϰ䲼ÁËÓйØPoC¡£
https://www.bleepingcomputer.com/news/security/new-mozilla-firefox-attack-causes-desktop-client-to-crash/
¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖÀûÓÃ×ÔÓÉÖ°ÒµÍøÕ¾fiverrºÍFreelancerµÄ¹¥»÷»î¶¯
MalwareHunterTeam×êÑÐÍŶӷ¢ÏÖÀûÓÃ×ÔÓÉÖ°ÒµÍøÕ¾£¨Ô̺¬fiverrºÍFreelancer£©À´·Ö·¢¶ñÒâÈí¼þµÄ¹¥»÷»î¶¯¡£ÕâЩ¶ñÒâÈí¼þ¼Ù×°³É¹¤×÷¼ò½éµÄ¸½¼þ£¬µ«ÏÖʵÉÏÓÃÓÚ×°ÖüüÅ̼ͼÆ÷£¨ÈçAgent Tesla£©ºÍÔ¶¿ØÄ¾ÂíµÈ¡£µ±Êܺ¦ÕßÔÚ´ò¿ª¸Ã¶ñÒ⸽¼þÓöµ½ÎÊÌâʱ£¬¹¥»÷Õß»¹»á»Ø¸´ËûÃÇÒÔÌṩԮÊÖ£¬ÀýÈçÒ»ÃûÓû§³ÆÎÞ·¨ÔÚÒÆ¶¯É豸ÉÏ´ò¿ª¸ÃÎļþ£¬¶ø¹¥»÷Õ߻ظ´³Æ±ØÒªÔÚPCÉÏ´ò¿ªËü¡£
https://www.bleepingcomputer.com/news/security/malware-disguised-as-job-offers-distributed-on-freelance-sites/
¡¾¶ñÒâÈí¼þ¡¿×êÑÐÍŶӰ䲼¹ØÓÚmacOS¶ñÒâÈí¼þOSX.FairyTaleµÄ·ÖÎö»ã±¨
SentinelOne×êÑÐÍŶӰ䲼¹ØÓÚmacOS¶ñÒâÈí¼þOSX.FairyTaleµÄ·ÖÎö»ã±¨¡£½üÄêÀ´£¬macOSƽ̨ÉÏ×îÆÕ±éµÄ°²È«ÍþвһÏòÊÇÓÃÓÚ·Ö·¢¸æ°×Èí¼þºÍDZÔÚÓк¦Èí¼þ£¨PUP£©µÄ¶ñÒⷨʽ¡£OSX.FairyTaleÊÇÒ»¸ö¸æ°×Èí¼þµÄ±äÖÖ£¬×î³õÓÉMalwarebytesµÄ×êÑÐÈËÔ±Thomas ReedÓÚ2018ËêÊ×·¢ÏÖ¡£OSX.FairyTaleʹÓÃÁË´óÁ¿µÄ»ìºÏºÍ·´ÄæÏò¼¼Êõ£¬Õâ¶ÔÓÚ¸æ°×Èí¼þÀ´ËµÊDz»³£¼ûµÄ¡£
https://www.sentinelone.com/blog/trail-osx-fairytale-adware-playing-malware/
¡¾Êý¾Ýй¶¡¿Ê±×°ÁãÊÛÉÌSHEINÔâºÚ¿ÍÈëÇÖ£¬Ô¼642ÍòÓû§µÄÐÅÏ¢¿ÉÄÜй¶
ʱװÁãÊÛÉÌSHEINÉÏÖÜÎå°ä·¢ÆäÔâµ½ºÚ¿Í¹¥»÷£¬Ô¼642ÍòÓû§µÄÐÅÏ¢¿ÉÄÜй¶¡£¹¥»÷ÊÂÎñ²úÉúÔÚÏÄÌ죬¼´6ÔµÄij¸öʱ³½£¬¹¥»÷Õß½Ó¼ûÁËÓû§µÄµç×ÓÓʼþµØÖ·ºÍ¼ÓÃܵÄÃÜÂë¡£¸Ã¹«Ë¾ÓÚ8ÔÂ22ÈÕ·¢ÏÖÁËÕâÒ»ÊÂÎñ£¬²¢ÔÚÁªÏµÊÜÓ°ÏìµÄÓû§Åú¸ÄÆäÃÜÂ롣й¶µÄÊý¾ÝÖв»Ô̺¬ÈκÎÐÅÓþ¿¨ÐÅÏ¢¡£¸Ã¹«Ë¾ÔÚ½øÇ°½øÒ»²½µÄµ÷²é¡£
https://www.zdnet.com/article/shein-fashion-retailer-announces-breach-affecting-6-42-million-users/


¾©¹«Íø°²±¸11010802024551ºÅ