¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181015
°ä²¼¹¦·ò 2018-10-15
ƾ¾ÝÍþвµý±¨ÉÌBlueliv×îÐÂµÄÆ¾Ö¤ÇÔÈ¡Ì¬ÊÆ·ÖÎö»ã±¨£¬Óë2018Äê3ÔÂÖÁ5ÔÂÏà±È£¬6ÔÂÖÁ8ÔÂÆÚ¼äÔÚ±±ÃÀ½©Ê¬ÍøÂçÖмì²âµ½µÄ±»ÇÔÍ´´¦µÄÊýÁ¿ìÉý141%¡£Óë´Ëͬʱ£¬ÆäËüµØÓòµÄ±»ÇÔÍ´´¦µÄÊýÁ¿ÔòÓÐËù½µÂ䣬ŷÖ޺ͶíÂÞ˹µØÓò½µÂäÁË22%£¬¶øÑÇÖÞµØÓòÔò½µÂäÁË36%¡£ÔÚÓÃÓÚÇÔÈ¡Óû§Í´´¦µÄ¶ñÒâÈí¼þ·½Ã棬Pony¡¢KeyBaseºÍLokiPWSÊÇ×îÊÜӽӵĶñÒâÈí¼þ¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/stolen-credentials-soars-141-north/2¡¢ÃÀ¹ú·À²¿£¨Îå½Ç´óÂ¥£©Ô¼3ÍòÃûÔ±¹¤µÄ¹Û¹â¼Í¼й¶
ÃÀ¹ú¹ú·À²¿£¨Îå½Ç´óÂ¥£©µÄ²¿Ãžü·½ºÍÎÄÖ°ÈËÔ±µÄÓ×ÎÒÐÅÏ¢ºÍÐÅÓþ¿¨Êý¾Ýй¶£¬Ô¼3ÍòÈËÊܵ½Ó°Ïì¡£ÕâÒ»Êý¾Ýй¶ÊÂÎñ¿ÉÄܲúÉúÔÚ¼¸¸öÔÂǰ£¬µ«Ö±µ½×î½ü²Å±»·¢ÏÖ¡£¸ÃÊÂÎñÉæ¼°µ½Ò»¼ÒΪ¹ú·À²¿Ìṩ·þÎñµÄµÚÈý·½¹©¸øÉÌ£¬Ä¿Ç°¸Ã¹©¸øÉ̵ÄÉí·ÝÒÀÈ»²»Ã÷È·¡£ÕâÒ»ÊÂÎñÒÀÈ»ÔÚ½øÒ»²½µÄµ÷²éÖ®ÖУ¬µ«Ã»ÓÐÈκλúÃÜÐÅÏ¢Ô⵽й¶¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/77097/data-breach/pentagon-travel-records-data-breach.html3¡¢×êÑÐÍŶӷ¢ÏÖÀûÓÃÐéαFlash¸üÐÂÀ´´«²¼µÄ¶ñÒâÍÚ¿óÈí¼þ
ƾ¾ÝPalo Alto NetworksµÄUnit 42ÍŶӵÄ×îÐÂ×êÑУ¬Ò»¸ö¶ñÒâÈí¼þ·¨Ê½Í¨¹ýÐéαµÄFlash¸üÐÂÀ´´«²¼£¬²¢×°ÖöñÒâ¿ó¹¤XMRigÒÔÍÚÈ¡ÃÅÂÞ±Ò¡£ÓÉÓڸöñÒâÈí¼þ·¨Ê½µÄÈ·»áÔÚÖ¸±êÍÆËã»ú¸ßµÍÔØ²¢×°ÖÃ×îа汾µÄFlash£¬Õâ½øÒ»²½Ôö³¤ÁËÆä±í±íÉϵĺϷ¨ÐÔ¡£×êÑÐÍŶÓÁгöÁË2018Äê3ÔÂ25ÈÕÖÁ9ÔÂ10ÈÕÆÚ¼ä¸ÃÐéαFlash¸üеÄ473¸öÎļþÃûºÍURL¡£
ÔÎÄÁ´½Ó£º
https://researchcenter.paloaltonetworks.com/2018/10/unit42-fake-flash-updaters-push-cryptocurrency-miners/4¡¢×êÑÐÍŶӷ¢ÏÖMagecart¹¥»÷µÄбäÖÖCartThief
The Media Trust×êÑÐÍŶӷ¢ÏÖMagecart¹¥»÷µÄÒ»¸öбäÖÖCartThief¡£Æ¾¾Ý¸Ã×êÑÐÍŶӵÄ˵·¨£¬CartThiefÒ»ÏòÔÚÕë¶Ô½ÏÓ×¹æÄ£µÄµç×ÓÉÌÎñ¹«Ë¾¡£CartThiefÀàËÆÓÚMagecartµÄÐÐΪ£¬ÓÃÓÚÍøÂçÖ§¸¶Ò³ÃæÉϵÄÓ×ÎÒÐÅÏ¢ºÍ²ÆÕþÐÅÏ¢¡£µ«CartThiefÓëÆäËüMagecart±äÖÖ·ÖÆçµÄÊÇ£¬CartThiefûÓÐʹÓÃcookieÀ´¼ø±ðÓû§£¬Õâ¿ÉÄÜÊÇΪÁËÔ¤·ÀÒýÆðÒÉ»óºÍÌӱܼì²â¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/no-cookies-for-cartthief-a-new/5¡¢×êÑÐÈËÔ±ÔÚ΢Èí¹Ù·½É̳ÇÖз¢ÏÖÒ»¸ö¶ñÒâµÄ¸æ°×µã»÷Æ÷
×êÑÐÈËÔ±ÔÚ΢Èí¹Ù·½É̳ÇÖз¢ÏÖÒ»¸öÃûΪAlbum by Google Photos£¨¹È¸èÏà²á£©µÄ¶ñÒⷨʽ£¬¸Ã¶ñÒâÈí¼þ¼Ù×°³ÉÀ´×Թȸ裬µ«ÏÖʵÉÏÓÃÓÚÔÚWindows 10Öв»ÐÝ´ò¿ª°µ²ØµÄ¸æ°×¡£¸Ã¶ñÒâÈí¼þÔ̺¬Èý¸öÎļþ£ºBlock Craft 3D.dll¡¢Block Craft 3D.exeºÍBlock Craft 3D.xr£¬Ëü½«ÔÚºó¶ÜÏνӵ½¸÷Àà¸æ°×URL²¢´ò¿ªËüÃÇ¡£ÓÉÓÚ¸æ°×²»»áÔÚǰ̨ÏÔʾ£¬Òò¶øÈôÊǸæ°×Ô̺¬ÒôƵ£¬Óû§¿ÉÄÜ»áÌýµ½Ææ¹ÖµÄÉùÒô¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ad-clicker-hiding-as-google-photos-app-found-in-microsoft-store/6¡¢Juniper Networks°ä²¼Junos OSµÄ°²È«¸üУ¬½¨¸´30¶à¸ö·ì϶
Juniper Networks°ä²¼Junos OSµÄ°²È«¸üУ¬¹²½¨¸´30¶à¸ö·ì϶£¬ÆäÖнÏΪÑϳÁµÄ·ì϶Ô̺¬¿Éµ¼ÖÂδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì½Ó¼ûµÄ·ì϶£¨CVE-2018-0044£©¡¢¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐеĻº³åÇøÒç¶Âí½Å£¨CVE-2018-7183£©¡¢¿Éµ¼ÖÂÄں˱ÀÀ£ºÍDoSµÄ·ì϶£¨CVE-2018-0049£©ÒÔ¼°XSS·ì϶£¨CVE-2018-0047£©µÈ¡£½¨ÒéÓû§¾¡¿ì×°ÖÃÕâЩ¸üС£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/77047/hacking/juniper-networks-junos-flaws.htmlÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ