¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180930
°ä²¼¹¦·ò 2018-09-30¡¾Íþвµý±¨¡¿IC3¡¢DHSºÍFBI½áºÏ°ä²¼ÓйØÔ¶³Ì×ÀÃæºÍ̸RDP¹¥»÷µÄÔ¤¾¯
ÃÀ¹ú»¥ÁªÍø·¸×ïͶËßÖÐÐÄ£¨IC3£©¡¢ºÓɽ°²È«Êý£¨DHS£©ºÍÁª¹úµ÷²é¾Ö£¨FBI£©½áºÏ°ä²¼Á˹ØÓÚRDP¹¥»÷µÄ¾¯±¨¡£¹¥»÷Õßͨ¹ýÈëÇÖ¶³öÔÚ»¥ÁªÍøÉϵÄRDP·þÎñÒÔ½øÐÐ͵ÇÔ¡¢ºóÃÅ×°ÖÃÒÔ¼°×÷ΪÆäËü¹¥»÷µÄÌáÒéµã¡£US-CERT³Æ×Ô2016ÄêÒÔÀ´Ëæ×ŰµÍøÊг¡É϶ÔRDP½Ó¼ûȨÏÞµÄÏúÊÛµÄÔö¶à£¬ÀûÓÃÔ¶³ÌÖÎÀí¹¤¾ß£¨ÈçRDP£©µÄ¹¥»÷Ò²Ô½À´Ô½¶à¡£
https://www.bleepingcomputer.com/news/security/ic3-issues-alert-regarding-remote-desktop-protocol-rdp-attacks/
¡¾°²È«·ì϶¡¿×êÑÐÈËÔ±·¢ÏÖiPhone XS´æÔÚÃÜÂëÈÆ¹ý·ì϶£¬¿ÉÓÃÓÚÇÔÈ¡ÁªÏµÈ˺ÍÕÕÆ¬ÐÅÏ¢
×êÑÐÈËÔ±Jose Rodriguez·¢ÏÖiOS 12´æÔÚÃÜÂëÈÆ¹ý·ì϶£¬¿ÉÔÊÐí¹¥»÷Õß½Ó¼ûÉ豸ÉϵÄÕÕÆ¬ºÍÁªÏµÈËÐÅÏ¢£¨Ô̺¬µç»°ºÅÂëºÍµç×ÓÓʼþµÈ£©¡£ThreatpostÈ·Èϸ÷ì϶ºÏÓÃÓÚ¶à¸öiPhoneÐͺţ¬Ô̺¬×îеÄiPhone XS¡£¸Ã·ìÏ¶Éæ¼°µ½ºýŪSiriºÍVoiceOverÖ°ÄÜÀ´ÈƹýÉ豸µÄÃÜÂë¡£¹¥»÷µÄǰÌáÊÇÄܹ»ÎïÀí½Ó¼ûÆôÓÃÁËSiriÇÒFaceID±»¹Ø¹Ø»òÕÚµ²µÄÉ豸¡£
https://threatpost.com/iphone-xs-passcode-bypass-hack-exposes-contacts-photos/137790/
¡¾¶ñÒâÈí¼þ¡¿×êÑÐÍŶÓÔÚGoogle PlayÉÏ·¢ÏÖ25¸öÀûÓÃϰȾ¶ñÒâÍÚ¿óÈí¼þ
SophosLabsÔÚGoogle PlayÖз¢ÏÖ25¸öÀûÓÃϰȾ¶ñÒâÍÚ¿óÈí¼þ£¬ÕâЩÀûÓüÙ×°³ÉÓÎÏ·¡¢Ó×¹¤¾ß»ò½ÌÓýÀûÓõȣ¬µ«¶¼Ç¶ÈëÁËCoinhiveÍÚ¿ó´úÂ루ÓÃÓÚÍÚ¾òÃÅÂÞ±ÒµÄJavaScript´úÂ룩¡£ÕâЩÀûÓõÄ×ÜÏÂÔØ´ÎÊý³¬¹ýÁË12Íò´Î¡£SophosLabsÔÚ°ËÔ·ÝÏò¹È¸è»ã±¨ÁËÕâЩ¶ñÒâÀûÓ㬹ÌÈ»²¿ÃÅÀûÓÃÒѱ»É¾³ý£¬µ«ÈÔÓв¿ÃÅÀûÓÃÒÀÈ»¿ÉÓá£
https://news.sophos.com/en-us/2018/09/24/cryptojacking-apps-return-to-google-play-market/
¡¾·ì϶²¹¶¡¡¿Cisco TalosÅû¶Epee¿âÖеķ´ÐòÁл¯·ì϶£¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ
Cisco TalosÅû¶Epee¿âÖеÄÒ»¸ö·´ÐòÁл¯·ì϶¡£Epee¿âÊǼÓÃÜÇ®±ÒµÄ¶ÔµÈͨѶ£¨P2P£©ÍøÂçºÍ̸LevinµÄÒ»¸öʵÏÖ£¬Æä±»ÀûÓÃÓÚ´óÁ¿¼ÓÃÜÇ®±Ò£¬Ô̺¬ÃÅÂÞ±Ò¡£×êÑÐÈËÔ±·¢ÏָÿâÖеÄLevin·´ÐòÁл¯Ö°ÄÜ´æÔÚ·ì϶£¬¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâÊý¾Ý°ü´¥·¢¸Ã·ì϶µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¸Ã·ì϶µÄ±àºÅΪTALOS-2018-0637/CVE-2018-3972£¬½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾¡£
https://blog.talosintelligence.com/2018/09/epee-levin-vuln.html
¡¾·ì϶²¹¶¡¡¿Trustwave·¢ÏÖWindows PureVPN¿Í»§¶ËÖдæÔÚÁ½¸öÍ´´¦Ð¹Â¶·ì϶
Trustwave×êÑÐÈËÔ±Manuel Nader·¢ÏÖWindows PureVPN¿Í»§¶Ë´æÔÚÁ½¸ö¿Éµ¼ÖÂÍ´´¦Ð¹Â¶µÄ°²È«·ì϶¡£±¾µØ¹¥»÷Õß¿ÉÀûÓø÷ì϶½Ó¼û³É¹¦µÇ¼PureVPN·þÎñµÄ×îºóÒ»¸öÓû§µÄÃÜÂë¡£¸Ã¹¥»÷Æëȫͨ¹ýGUIʵÏÖ£¬²»±ØÒªÊ¹ÓÃÈÎºÎ±í²¿¹¤¾ß¡£PureVPN°æ±¾5.18.2.0Êܵ½Ó°Ï죬½¨ÒéÓû§¸üÐÂÖÁ6.1.0»òÖ®ºóµÄ°æ±¾¡£
https://securityaffairs.co/wordpress/76660/hacking/windows-purevpn-client-flaws.html
¡¾·ì϶²¹¶¡¡¿×êÑÐÈËÔ±·¢ÏÖTelegramĬÈÏ»áй¶Óû§µÄIPµØÖ·
×êÑÐÈËÔ±Dhiraj Mishra·¢ÏÖTelegramÔÚĬÈÏÉèÖÃÏ»áÔÚ½ÚÔį̀ÈÕÖ¾ÖÐй¶Óû§µÄIPµØÖ·¡£ÔÚijЩÇé¿öÏ£¬¼´±ã¿Í»§¶ËÅäÖÃΪ±£»¤ÓйØÐÅÏ¢£¬Windows¡¢MacºÍLinux°æ±¾µÄTelegram×ÀÃæ¿Í»§¶ËÒ²»áй¶Óû§µÄIPµØÖ·¡£×êÑÐÈËÔ±Åû¶Á˸÷ì϶£¨CVE-2018-17780£©µÄPoCÊÓÆµ¡£TelegramÒÑÔÚ×ÀÃæ¿Í»§¶ËµÄv1.4.0ºÍv1.3.17 betaÖн¨¸´ÁË´Ë·ì϶¡£
https://www.bleepingcomputer.com/news/security/telegram-leaks-ip-addresses-by-default-when-initiating-calls/


¾©¹«Íø°²±¸11010802024551ºÅ