¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190130

°ä²¼¹¦·ò 2019-01-30
1¡¢FaceTimeÆØ³Á´óÇÔÌý·ì϶£¬Apple°µÊ¾½«ÔÚ±¾Öܽ¨¸´

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾Ý±íý±¨Â·£¬Apple FaceTime´æÔÚ³Á´ó°²È«·ì϶£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÖ¸±ê½ÓÌý»ò»Ø¾øFaceTimeͨ»°Ö®Ç°¼àÌý¶Ô·½µÄÉùÒô¡£ÈôÊǶԷ½°´ÏÂÒôÁ¿½µµÍ°´Å¥»òµçÔ´°´Å¥À´¾²Òô»òÈ¡µÞͨ»°£¬ÔòÆäǰÖÃÉãÏñÍ·Ò²»á´ò¿ª£¬²¢½«ÊÓÆµÐźŷ¢Ë͸ø¹¥»÷Õß¡£¾ÝϤ£¬¸Ã·ì϶»á³Ê´Ë¿ÌiOS 12.1»ò¸ü¸ß°æ±¾µÄiOSÉ豸ÖС£AppleÒѾ­Ò»Ê±½ûÓÃÁËFaceTimeÖеÄȺ×éͨ»°Ö°ÄÜ£¬²¢°µÊ¾½«ÔÚ±¾ÖÜÍíЩʱ³½°ä²¼½¨¸´²¹¶¡¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/apple-facetime-privacy-hack.html


2¡¢°Ä´óÀûÑÇ8¼ÒÍйܷþÎñÉÌÔâ·ê¹¥»÷»î¶¯Manic Menagerie

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



ƾ¾Ý°Ä´óÀûÑÇÍøÂ簲ȫÖÐÐÄ£¨ACSC£©°ä²¼µÄÒ»·Ý»ã±¨£¬8¸öÍйܷþÎñÉÌÔÚ2018ÄêÔâ·ê¶ñÒâ¹¥»÷»î¶¯Manic Menagerie¡£¹¥»÷ÕßÀûÓÃWebÀûÓÃÖеķì϶À´»ñÈ¡Web·þÎñÆ÷µÄrootȨÏÞ£¬²¢×°ÖÃÃÜÂëÇÔÈ¡¹¤¾ßºÍGh0st RAT¡£ÆäÖÐÒ»¸ö±»ÀûÓõķì϶ÊÇ2018Äê4Ô¹«¿ªµÄÌáȨ·ì϶TotalMeltdown£¨CVE-2018-1038£©¡£ACSCÒѽ¨ÒéÕâЩÍйܷþÎñÉ̸øWebÀûÓúÍCMS´ò²¹¶¡ºÍ½ûÓöñÒâ²å¼þ£¬²¢³ÁÖÃÓû§µÄÍ´´¦¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/eight-australian-web-hosting-providers-compromised-in-manic-menagerie-attack-campaign-8ee4259a 


3¡¢AZORultľÂí¼Ù×°³É¹È¸è¸üз¨Ê½£¬Ö¼ÔÚÇÔÈ¡Óû§Í´´¦

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


À´×ÔMinerva Labs¡¢Asaf AprozperºÍGal BitenskyµÄ×êÑÐÈËÔ±¹Û²ìµ½AZORultľÂíͨ¹ý¼Ù×°³ÉGoogle Updater·¨Ê½À´ÊµÏÖÓÆ¾ÃÐÔ¡£AZORultľÂíÖØÒªÓÃÓÚÇÔÈ¡Óû§µÄÃô¸ÐÊý¾Ý£¬Ô̺¬Îļþ¡¢ÃÜÂë¡¢cookie¡¢ä¯ÀÀÆ÷º¹Çà¼Í¼¡¢ÒøÐÐÍ´´¦ºÍ¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡£ÓÉÓÚAZORult¼Ù×°³ÉGoogle Updater·¨Ê½£¬Ëü½«ÒÔÖÎÀíԱȨÏÞÔËÐС£×êÑÐÈËÔ±·¢ÏÖÕâЩ¶ñÒâµÄGoogleUpdate.exeÎļþʹÓÃÁËÓÐЧµÄÖ¤Êé½øÐÐÊðÃû£¬µ«¸ÃÖ¤ÊéÏÖʵÉϱ»Ðû¸æ¸ø¡°Singh Agile Content Design Limited¡±£¬¶ø²»ÊÇGoogle¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/azorult-trojan-disguised-as-google-update-installer-steals-credentials-6e225ab6


4¡¢¶ñÒâÈí¼þFormBook»Ø¹é£¬ÖØÒªÕë¶ÔÃÀ¹úÁãÊۺ;ƵêÒµ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝDeep InstinctµÄ»ã±¨£¬FormBookÔÚʹÓÃÒ»¸öеÄÎļþÍйܷþÎñ´«²¼£¬ÖØÒª¹¥»÷ÃÀ¹úµÄÁãÊۺ;ƵêÒµ¡£FormBook×îÔç³öÏÖÓÚ2016Ä꣬Äܹ»ÇÔÈ¡Óû§µÄÍ´´¦¡¢½ØÈ¡×ÀÃæÆÁÄ»ÒÔ¼°¼Í¼¼üÅ̵È¡£ÔÚÕâ¸öеĶñÒâ»î¶¯ÖУ¬FormBookͨ¹ý´¹µöÓʼþÖеÄRTF¸½¼þ´«²¼£¬¸Ã¸½¼þÀûÓÃÁËCVE-2012-0158¡¢CVE-2017-11882µÈOffice·ì϶¡£FormBook»¹ÀûÓÃÁËÒ»¸öеÄÎļþÍйܷþÎñDropMyBin£¬¸ÃÎļþÍйܷþÎñÒ²±»ÆäËü¶ñÒâÈí¼þʹÓã¬ÀýÈçLokibotºÍAzorult¡£


Ô­ÎÄÁ´½Ó£º

https://www.deepinstinct.com/2019/01/27/info-stealer-formbook-continues-activity-and-uses-a-new-malware-friendly-file-hosting-service/


5¡¢·ÆÂɱöµçÐŹ«Ë¾GlobeÒâ±íй¶8851Ãû¿Í»§µÄÓ×ÎÒÐÅÏ¢

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝBestVPN.comµÄ»ã±¨£¬·ÆÂɱöµçÐŹ«Ë¾GlobeÔÚ½üÆÚµÄÍÆ¹ã×¢²á»î¶¯ÖУ¬Òâ±íÏòÐÂ×¢²áµÄÓû§ÓÊÏä·¢ËÍÁËÆäËüÓû§¼òÖ±ÈÏÓʼþ£¬µ¼Ö²¿Ãſͻ§µÄÃô¸ÐÊý¾Ýй¶¡£ÕâЩÊý¾ÝÔ̺¬¿Í»§µÄÐÕÃû¡¢µç×ÓÓÊÏ䵨ַºÍÆëÈ«µÄÓÊÕþµØÖ·£¬¹²ÓÐ8851Ãû¿Í»§Êܵ½Ó°Ïì¡£¸Ã¹«Ë¾ÒѾ­Ö¤ÊµÁËÕâÒ»ÊÂÎñ£¬²¢Æ¾¾Ý¼à¹ÜÒªÇó֪ͨÁ˹ú¶ÈÒþÖÔ±£»¤Î¯Ô±»á£¨NPC£©¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/filipino-telecom-giant-globe-inadvertently-leaks-personal-data-of-8851-subscribers-e87bb87b


6¡¢ÐÂ¼ÓÆÂÔ¼1.4Íò°¬×̲¡»¼ÕßÐÅϢй¶£¬ÏÓ·¸ÎªÃÀ¼®ÄÐ×Ó

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

2019Äê1ÔÂ28ÈÕ£¬ÐÂ¼ÓÆÂÎÀÉú²¿ÔÚÒ»·ÝÉêÃ÷ÖÐ֤ʵÃÀ¹úÄÐ×ÓMikhy K Farrera Brochez·¸·¨»ñÈ¡²¢Ð¹Â¶ÁËÔ¼1.42Íò°¬×̲¡»¼ÕßµÄÓ×ÎÒÐÅÏ¢¡£ÆäÖÐ5400Ãû»¼ÕßÊÇÐÂ¼ÓÆÂÈË£¬8800Ãû»¼ÕßÊDZí¹úÈË¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬»¼ÕßµÄÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢µç»°ºÅÂë¡¢µØÖ·¡¢HIV¼ì²âÁ˾ֺÍÓйØÒ½ÁÆÐÅÏ¢µÈ¡£ÕâЩÊý¾ÝÊÇBrochez´ÓÐÂ¼ÓÆÂµÄ°¬×̲¡µÇ¼Ç´¦ÇÔÈ¡µÄ¡£2017Äê3Ô£¬BrochezÔÚÐÂ¼ÓÆÂ±»¿ØÚ²Æ­µÈ¶àÏî×ïÃû£¬²¢ÔÚ·þÐ̺󱻱÷³ý³ö¾³¡£2019Äê1ÔÂ22ÈÕ£¬ÐÂ¼ÓÆÂÎÀÉú²¿·¢ÏÖÉÏÊö»¼Õß×ÊÁÏÔÚÍøÉϱ»Ð¹Â¶ºó±¨¾¯¡£Ä¿Ç°±¾µØ¾¯·½ÔÚ×·Çó¶Ô´Ë°¸½øÐйú¼Êµ÷²é¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/private-data-of-almost-14200-patients-diagnosed-with-hiv-leaked-online-de45a837


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù