¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190104
°ä²¼¹¦·ò 2019-01-04
1ÔÂ3ÈÕAdobe°ä²¼°²È«²¼¸æAPSB19-02£¬½¨¸´ÁËAdobe AcrobatºÍReaderÖеÄÁ½¸ö¸ßΣ·ì϶¡£µÚÒ»¸ö·ì϶£¨CVE-2018-16011£©¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐУ¬µÚ¶þ¸ö·ì϶£¨CVE-2018-19725£©ÔòÊÇÒ»¸öÌáȨ·ì϶¡£ÕâÁ½¸ö·ì϶ÊÇÓÉÇ÷Ïò¿Æ¼¼µÄZDIÌá½»µÄ£¬½¨ÒéÓû§¾¡¿ìÉý¼¶ÖÁAcrobat DC/Acrobat ReaderµÄ×îа汾2019.010.20069¡¢2017.011.30113ºÍ2015.006.30464¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/adobe-acrobat-and-reader-security-updates-released-for-critical-bugs/2¡¢¹È¸è½¨¸´Android°æChromeÖдæÔÚ3ÄêµÄÒþÖÔй¶·ì϶
¹È¸è×îÖÕ½¨¸´Á˺ÏÓÃÓÚAndroidµÄChromeä¯ÀÀÆ÷ÖеÄÒ»¸öÒþÖÔй¶·ì϶¡£Nightwatch Cybersecurity¹«Ë¾µÄYakov ShafranovichÔøÔÚ2015ÄêÏò¹È¸è»ã±¨¹ý´ËÎÊÌ⣬µ«¹È¸èÆäʱ³ÆÕâ²»ÊÇÒ»¸ö·ì϶¡£ÔÚ2018Äê7Ô·ÝChromiumÂÛ̳ÉÏÒ»¸öÓû§ÔÙ´ÎÅû¶´Ë·ì϶ºó£¬¹È¸èÔÚChrome 70Öн¨¸´Á˸÷ì϶¡£¸Ã·ì϶ÓëChromeÌìÉúµÄUser Agent×Ö·û´®Ô̺¬Android°æ±¾ºÅ¡¢É豸Ãû³Æ¼°¹Ì¼þ°æ±¾ÐÅÏ¢Óйأ¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ȷ¶¨É豸µÄ°²È«²¹¶¡¼¶±ð£¬´Ó¶øÌáÒéÕë¶ÔÐԵĹ¥»÷¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/google-chrome-android-privacy.html3¡¢¶¼°ØÁÖÓйìµç³µÏµÍ³Luas¹ÙÍø±»ºÚ£¬ºÚ¿ÍÀÕË÷3800ÃÀÔª
°®¶ûÀ¼Ê×¶¼¶¼°ØÁÖµÄÓйìµç³µÏµÍ³LuasµÄ¹ÙÍøÔâµ½ºÚ¿Í¹¥»÷£¬¹¥»÷ÕßÐû³Æ´ÓLuasµÄÔËÓªÉÌTransdev Ireland´¦ÇÔÈ¡ÁËÊý¾Ý£¬²¢ÒªÇóÔÚÎåÌìÄÚÖ§¸¶Ò»¸ö±ÈÌØ±Ò£¨¼ÛÖµÔ¼3800ÃÀÔª£©µÄÊê½ð¡£LuasÒѽ«¹ÙÍøÀëÏß²¢½øÐа²È«²é³¡£ºÃÐÂÎÅÊÇLuasµÄÔËÓª·þÎñ²¢Î´Êܵ½Ó°Ï죬´î¿ÍÖ»ÊÇÎÞ·¨´Ó¹ÙÍøÉϲéÎʵ糵µÄʱ¿Ì±í¡£
ÔÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/hackers-demand-ransom-luas-website-defaced/4¡¢NRSMinerбäÌåÏ®»÷ÑÇÖÞ£¬ÀûÓÃEternalBlue·ì϶´«²¼
F-SecureµÄ°²È«×êÑÐÈËÔ±·¢ÏÖNRSMinerµÄбäÌåÀûÓÃEternalBlue·ì϶¹¥»÷ÑÇÖÞµØÓòµÄ¹ú¶È¡£¸Ã¹¥»÷»î¶¯´Ó2018Äê11ÔÂÖÐÑ®ÆðÍ·£¬ÖØÒªÕë¶ÔÔ½ÄÏ¡¢Öйú¡¢ÈÕ±¾ºÍ¶ò¹Ï¶à¶ûµÈ¡£NRSMinerÀûÓÃÃÅÂÞ±Ò¿ó¹¤XMRig½øÐÐÍڿ󣬻¹Äܹ»ÏÂÔØ¸üеÄÄ£¿é²¢´úÌæ¾É°æ¶ñÒâÈí¼þ¡£ÀûÓÃEternalBlue´«²¼µÄÍÚ¿óľÂí»¹Ô̺¬WannamineºÍRedisWannaMineµÈ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/revamped-cryptominer-is-striking-asia-through-eternal-blue-exploit/5¡¢ÀÕË÷Èí¼þFilesLockerÖ÷½âÃÜÃÜÔ¿±»·Å³ö£¬×êÑÐÈËÔ±ÒÑ¿ª·¢³ö½âÃÜÆ÷
2018Äê12ÔÂ29ÈÕ£¬Î´ÖªÓû§ÔÚPastbinÉÏ·¢Ìû·Å³öÁËÀÕË÷Èí¼þFilesLockerµÄÖ÷½âÃÜÃÜÔ¿£¬Ëæºó×êÑÐÈËÔ±Michael GillespieÀûÓøÃÃÜÔ¿´´½¨ÁËFilesLockerµÄ½âÃÜÆ÷¡£¸Ã½âÃÜÆ÷¿É½âÃÜFilesLocker v1ºÍv2¼ÓÃܵÄÎļþ£¨Îļþºó׺ÃûΪ.[fileslocker@pm.me]£©¡£Ä¿Ç°Éв»Ã÷ÏԸýâÃÜÃÜԿΪʲô±»¿ªÊÍ£¬µ«ÓпÉÄÜÊÇÀÕË÷Èí¼þ¿ª·¢Õß¾ö¶¨ÊµÏÖÏîÄ¿»ò³ÁÐÂÆðͷеÄÏîÄ¿¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/master-decryption-key-released-for-fileslocker-ransomware/6¡¢ÃÜÂëÖÎÀíÆ÷BlurÓû§Êý¾Ýй¶£¬240ÍòÈËÊܵ½Ó°Ïì
±¾ÖÜÒ»Abine¹«Ë¾°µÊ¾ÆäÃÜÂëÖÎÀíÆ÷²úÆ·BlurµÄÓû§Êý¾ÝÔÚ·þÎñÆ÷É϶³ö£¬ÕâЩÊý¾ÝÔ̺¬2018Äê1ÔÂ6ÈÕ֮ǰע²áµÄBlurÓû§µÄÐÅÏ¢£¬Èçµç×ÓÓʼþµØÖ·¡¢ÐÕÃû¡¢ÃÜÂëÌáÐÑÓï¡¢×îºóµÇ¼IPºÍ¼ÓÑÎÃÜÂë¹þÏ£¡£¸Ã¹«Ë¾Ç¿µ÷³ÆÓû§µÄÃÜÂë¡¢ÐÅÓþ¿¨ÐÅÏ¢ºÍµç»°ºÅÂëûÓÐй¶¡£ÕâÒ»ÊÂÎñÓ°ÏìÁËÔ¼240ÍòBlurÓû§¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/data-of-2-4-million-blur-password-manager-users-left-exposed-online/ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ