¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190107
°ä²¼¹¦·ò 2019-01-07
ÃÀ¹ú¹ú¶È°²È«¾Ö£¨NSA£©½«ÔÚ2019Äê3Ô·ݵÄRSA´ó»áÉÏÃâ·Ñ°ä²¼ÄæÏò¹¤³Ì¹¤¾ßGHIDRA¡£Æ¾¾Ýά»ù½âÃÜÅû¶µÄCIA Vault 7ϵÁÐÎĵµ£¬GHIDRAÊÇÓÉNSA»ùÓÚJava˵»°¿ª·¢µÄÄæÏò¹¤³Ì¹¤¾ß¡£NSA°µÊ¾GHIDRAÓµÓн»»¥Ê½GUI£¬²¢ÇÒºÏÓÃÓÚ¶àÖÔì½Ì¨£¬Ô̺¬Windows¡¢LinuxºÍMac OS£¬»¹Ö§³Ö¶àÖÖоƬָÁ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/nsa-releasing-the-ghidra-reverse-engineering-tool-at-rsaconference/2¡¢Town of SalemÊý¾Ýй¶ÊÂÎñ³¬¹ý27%µÄÃÜÂëÒѱ»ÆÆ½â
2018Äê12ÔÂ28ÈÕ£¬ÐÅϢй¶²éÎÊÍøÕ¾DeHashed½Ó¹Üµ½Ò»·âÓʼþ£¬ÆäÖÐÔ̺¬Town of SalemÓÎÏ··þÎñÆ÷±»ºÚ¿ÍÈëÇÖµÄÖ¤¾ÝÒÔ¼°¸ÃÓÎÏ·Êý¾Ý¿âµÄ¸±±¾¡£Æ¾¾ÝDeHashed£¬¸ÃÊý¾Ý¿âÔ̺¬³¬¹ý760Íò¸öΨһµç×ÓÓʼþµØÖ·£¬»¹Ô̺¬Óû§Ãû¡¢¹þÏ£ÃÜÂë¡¢IPµØÖ·µÅ×û§Êý¾Ý¡£ÃÜÂ븴ÔÍøÕ¾Hashes.orgÒÑ¾ÆÆ½âÁËÕâЩй¶µÄÊý¾ÝÖеÄ210Íò¸ö¹þÏ£ÃÜÂ루Լ27%£©£¬½¨ÒéSalemÓû§¾¡¿ìÔÚʹÓÃÁËÒ»ÑùÃÜÂëµÄÍøÕ¾Éϸü¸ÄÆäÃÜÂë¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/27-percent-of-passwords-from-town-of-salem-breach-already-cracked/3¡¢IBM TWCÆøÏóÀûÓÃÒòÏúÊÛÓû§Êý¾ÝÔâµ½¸æ×´
Âåɼí¶ÊÐÏò¼ÓÀû¸£ÄáÑÇÖÝ·¨ÔºÌá¸æ×´ËÏ£¬¿ØËßIBM×Ó¹«Ë¾TWCµÄÆøÏóÀûÓã¨Weather Channel£©ÍÚ¾òÓû§µÄÒþÖÔÊý¾Ý²¢½«ÕâЩÐÅÏ¢ÏúÊÛ¸øµÚÈý·½£¬Ô̺¬¸æ°×¹«Ë¾¡£Âåɼí¶Êз½Ã氵ʾ£¬Weather ChannelÔںܶàÓû§²»ÖªÇéµÄÇé¿öϸú×ÙÓû§µÄµØÀíµØÎ»Êý¾Ý£¬²¢½«ÕâЩÊý¾ÝÓÃÓÚÓëÆøÏóÔ¤±¨ÆëÈ«Î޹صĸæ°×µÈóÒ×Óô¦¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/city-of-la-sues-weather-channel-app-for-sharing-location-data-with-advertisers/4¡¢Bobby YeeÔâÀÕË÷Èí¼þ¹¥»÷£¬²¨¼°2.4Íò»¼ÕßÐÅÏ¢
¼ÓÖÝ×ã¿ÆÒ½ÔºBobby Yee D.P.M.°ä·¢Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬ËûÃǵÄÒ½ÁƼͼ£¨Ô̺¬»¼ÕßµÄÓ×ÎÒÐÅÏ¢£©Ô⵽δÊÚȨ¸ü¸Ä¡£Éæ¼°µ½µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢´ºÇï¡¢ÐԱ𡢵®ÉúÈÕÆÚ¡¢Éç±£ºÅÂë¡¢±£ÏÕµ¥ºÅÂëÒÔ¼°²¡Àú¡£¸Ã°ì¹«ÊÒÒÑ֪ͨÁËÊÜÓ°ÏìµÄ2.4ÍòÃû»¼Õߣ¬µ«°µÊ¾Ã»ÓÐÖ¤¾ÝÅú×¢Ó×ÎÒÐÅÏ¢»òÒ½ÁÆÐÅÏ¢Ô⵽й¶¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/bobby-yee-d-p-m-notified-24000-patients-after-ransomware-attack/5¡¢ÀÕË÷Èí¼þ¼Ò×åAuroraµÄÃâ·Ñ½âÃÜÆ÷Òѱ»°ä²¼
Michael Gillespie´´½¨ÁËÀÕË÷Èí¼þ¼Ò×åAuroraµÄÃâ·Ñ½âÃܹ¤¾ß¡£¸Ã½âÃÜÆ÷¿É½âÃÜÀ©´óÃûΪ.Nano¡¢.animus¡¢.Aurora¡¢.desu¡¢.ONIºÍ.auroraµÄ±äÌ壬ÆäÖÐ.Nano±äÌåÊǵ±Ç°×îΪ»îÔ¾µÄAurora±äÌå¡£Auroraͨ³£Í¨¹ýRDP·þÎñÈëÇÖÊܺ¦ÕßµÄÍÆËã»ú£¬²¢ÔÚ¼ÓÃÜÎļþÖ®ºóÒªÇóÒÔ±ÈÌØ±ÒÖ§¸¶Êê½ð¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/how-to-decrypt-the-aurora-ransomware-with-auroradecrypter/6¡¢ÐÂ¼ÓÆÂº½¿Õ¹«Ë¾Èí¼þbugµ¼ÖÂ284ÃûÓû§ÐÅϢй¶
ÐÂ¼ÓÆÂº½¿Õ¹«Ë¾Èí¼þ³öÏÖbug£¬µ¼Ö³¬¹ý280ÃûKrisFlyerÓû§µÄÓ×ÎÒÐÅϢй¶¡£Æ¾¾Ý¸Ã¹«Ë¾µÄµ÷²é£¬¹²ÓÐ284¸öKrisFlyerÕÊ»§Êܵ½Ó°Ï죬ÕâЩÕË»§µÄÐÕÃû¡¢º½°àº¹Çà¡¢×î½üÀï³ÌºÍ¼Î½±¿É±»ÆäËüÓû§½Ó¼û¡£´Ë±í£¬7ÃûÓû§µÄ»¤ÕÕºÅÂëÒ²±»Ð¹Â¶¡£ÕâÒ»ÊÂÎñ²úÉúÔÚ1ÔÂ5ºÅ£¬¸Ã¹«Ë¾°µÊ¾²¢Ã»ÓÐÊܵ½±í²¿¹¥»÷¡£
ÔÎÄÁ´½Ó£º
http://theindependent.sg/singapore-airlines-experiences-security-breach-personal-information-of-more-than-280-krisflyer-members-disclosed/ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ