¹¥»÷ÕßÀûÓûªË¶ÖÐÑëÈ˹¥»÷·Ö·¢PleadºóÃÅ£»È«ÇòÍþвָÊý£¬ÒøÐÐľÂíTrickbot³Á·µÇ°Ê®

°ä²¼¹¦·ò 2019-05-16
1¡¢Adobe°ä²¼5Ô°²È«¸üУ¬½¨¸´87¸ö·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
AdobeµÄ5Ô°²È«¸üн¨¸´Á˶à¸ö²úÆ·ÖеÄ87¸ö·ì϶ ¡£ÓëAdobe AcrobatºÍReaderÓйصķì϶ÊýΪ84¸ö£¬ÆäÖÐ42¸ö±»ÏóÕ÷ΪÑϳÁ£¨Critical£©·ì϶£¬ÕâЩ·ì϶¾ù¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐкÍϵͳÊÕÊÜ ¡£Flash PlayerÖн¨¸´ÁËÑϳÁ·ì϶£¨CVE-2019-7837£©£¬¸Ã·ì϶ÊÇÒ»¸öUse-After-Free·ì϶£¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐУ¬Ó°ÏìÁËWindows¡¢macOS¡¢Linux¼°Chrome OSƽ̨µÄFlash Player ¡£Media Encoderа汾13.1Öн¨¸´Á˿ɵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеÄÑϳÁ·ì϶£¨CVE-2019-7842£©ºÍ¿Éµ¼ÖÂÐÅϢй¶µÄ·ì϶£¨CVE-2019-7844£© ¡£±¾Ô½¨¸´µÄ·ì϶¾ùûÓÐÔÚÒ°±í±»ÀûÓà ¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/05/adobe-software-updates.html

2¡¢Twitter bugµ¼ÖÂÏòµÚÈý·½¹²ÏíiOSÓû§µÄλÏàÐÅÏ¢

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
TwitterÅû¶Æäƽ̨ÖеÄÒ»¸ö·ì϶£¬¸Ã·ì϶¿ÉÍøÂçiOSÓû§µÄµØÎ»Êý¾Ý²¢ÏòµÚÈý·½ºÏ×÷ͬ°é¹²ÏíÕâЩÊý¾Ý ¡£·ì϶µÄ¾ßÌåϸ½ÚΪ£¬µ±Óû§ÔÚiOSÉ豸ÉÏʹÓÃÁ½¸öTwitterÕÊ»§Ê±£¬¼´±ã½öÔÚÒ»¸öÕÊ»§ÖÐÆôÓÃÁ˶¨Î»Ö°ÄÜ£¬Ò²»á½«ÍøÂçµ½µÄµØÎ»Êý¾ÝÀûÓÃÓÚÁíÒ»¸öÕË»§ ¡£Twitter³ÆÒѾ­½¨¸´ÁËÕâ¸öÎÊÌ⣬²¢È·ÈϺÏ×÷ͬ°éÔÚÆäÕý³£Á÷³ÌÖÐɾ³ýÁ˹²ÏíµÄÊý¾Ý ¡£Twitter»¹°µÊ¾ÒѾ­Í¨ÖªÁËÕË»§¿ÉÄÜÊܵ½Ó°ÏìµÄÓû§ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/bug-in-twitter-led-to-collection-and-sharing-of-users-geolocation-data-with-its-partner-f2ebc19c

3¡¢¹¥»÷ÕßÀûÓûªË¶ÖÐÑëÈ˹¥»÷·Ö·¢PleadºóÃÅ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
4Ôµ×ESET×êÑÐÈËÔ±¹Û²ìµ½ÀûÓá°AsusWSPanel.exe¡±·Ö·¢PleadºóÃŵĹ¥»÷»î¶¯ ¡£AsusWSPanel.exeÊÇ»ªË¶ÔÆ´æ´¢·þÎñWebStorageµÄWindows¿Í»§¶Ë ¡£×êÑÐÈËÔ±¸ø³öÁËÁ½ÖÖ¿ÉÄܵĹ¥»÷³¡¾°£¬Ò»ÖÖÊÇ»ªË¶Ôâµ½¹©¸øÁ´¹¥»÷£¬ÁíÒ»ÖÖÊǹ¥»÷ÕßÀûÓÃÖÐÑëÈ˹¥»÷ºÍÒ×Êܹ¥»÷µÄ·ÓÉÆ÷À´´«²¼¶ñÒâÈí¼þ ¡£½øÒ»²½µÄ·ÖÎöºó×êÑÐÈËÔ±ÒÔΪºóÒ»ÖÖ¹¥»÷³¡¾°µÄ¿ÉÄÜÐÔ¸ü´ó ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.tripwire.com/state-of-security/security-data-protection/bad-actors-using-mitm-attacks-against-asus-to-distribute-plead-backdoor/

4¡¢Check Point×îÐÂÈ«ÇòÍþвָÊý£¬ÒøÐÐľÂíTrickbot³Á·µÇ°Ê®

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
Check Point°ä²¼4ÔÂÈ«ÇòÍþвָÊý£¬ÒøÐÐľÂíTrickbotÔÚʱ¸ôÁ½Äêºó³Á·µÇ°Ê®£¬Î»ÓÚµÚ°ËÃû ¡£4Ô·ÝTrickbot¹¥»÷»î¶¯µÄÉÏÉýÇ÷Ïò¿ÉÄÜÓëÃÀ¹úÄÉ˰Èյĵ½À´ÓйØ ¡£Ö»¹Ü°ñµ¥Ç°ÈýÃûÒÀÈ»±»¶ñÒâ¿ó¹¤Õ¼¾Ý£¬µ«ÆäÓàÆßÃû¶¼ÊǶàÖ°ÄÜľÂí£¬ÕâЩľÂí²»½öÄܹ»ÇÔÈ¡Êý¾Ý£¬»¹Äܹ»´«²¼ÆäËüÀÕË÷Èí¼þ ¡£4Ô·Ý×î³£±»ÀûÓõķì϶ÊÇOpenSSL TLS DTLSÐÄÌø°üÐÅϢй¶·ì϶£¨CVE-2014-0160¡¢CVE-2014-0346£© ¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.checkpoint.com/2019/05/14/april-2019s-most-wanted-malware-cybercriminals-up-to-old-trickbots-crypto-cryptomining-security-ryuk/

5¡¢ºÚ¿ÍÔÚ¸£²¼Ë¹¶©ÔÄÍøÕ¾×¢ÈëMagecart¾ç±¾

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
¸£²¼Ë¹¶©ÔÄÍøÕ¾±»ºÚ¿Í×¢Èë¶ñÒâMagecart¾ç±¾£¬¸Ã¾ç±¾ÓÃÓÚÍøÂçÓû§ÔÚÖ§¸¶Ò³ÃæÉÏÊäÈëµÄÖ§¸¶ÐÅÏ¢²¢·¢ËÍÖÁ¹¥»÷Õß½ÚÔìµÄÔ¶³Ì·þÎñÆ÷ ¡£ÇÔÈ¡µÄÐÅÏ¢Ô̺¬ÐÅÓþ¿¨ºÅ¡¢µ½ÆÚÈÕÆÚ¡¢CVV/CVCÂë¡¢ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂëºÍÓÊÏ䵨ַ ¡£×êÑÐÈËÔ±Troy Mursch·¢ÏÖÁËÕâÒ»¹¥»÷ÊÂÎñ£¬¹ÌÈ»forbesmagazine.comÉÏÒÀÈ»´æÔÚ¸ÃMagecart¾ç±¾£¬µ«¹¥»÷ÕßÓÃÓÚÍøÂçÐÅÏ¢µÄ·þÎñÆ÷ÓòÃûÒѱ»ÓòÃû·þÎñÉÌFreenomɾ³ý£¬Ê¹µÃ¹¥»÷ÒѾ­ÎÞЧ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-inject-magecart-card-skimmer-in-forbes-subscription-site/

6¡¢¶íÂÞ˹µ±¾ÖÍøÕ¾Ð¹Â¶225Íò¹«ÃñµÄÃô¸ÐÐÅÏ¢

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
¶íÂÞ˹×êÑÐÈËÔ±Begtinµ÷²é·¢ÏÖ23¸öµ±¾ÖÍøÕ¾Ð¹Â¶Á˹«ÃñµÄSNILSºÅÂ루Ï൱ÓÚÉç±£ºÅÂ룩£¬14¸öµ±¾ÖÍøÕ¾Ð¹Â¶Á˹«ÃñµÄ»¤ÕÕÐÅÏ¢ ¡£×ܹ²Äܹ»ÔÚÏß»ñµÃ³¬¹ý225Íò¶íÂÞ˹¹«ÃñµÄÊý¾Ý£¬Ô̺¬ÐÕÃû¡¢Ö°Î»¡¢¹¤×÷µØÖ·¡¢µç×ÓÓʼþ¡¢ÄÉ˰ºÅÂëµÈ£¬ÒÔ¼°Ä³Ð©Çé¿öÏµĻ¤ÕÕÐÅÏ¢ ¡£BegtinÂÅ´Î֪ͨµ±¾ÐÄà¹Ü»ú¹¹£¬µ«ÎÊÌⲢδµÃµ½½â¾ö ¡£Æ¾¾Ý±¾µØÃ½ÌåµÄ±¨Â·£¬Ò»Ð©¶íÂÞ˹µ±¾Ö¸ß¹ÙµÄÐÅÏ¢Ò²Ôâй¶£¬Ô̺¬Òé»á¸±Ö÷ϯAlexander ZhukovµÈ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/russian-government-sites-leak-passport-and-personal-data-for-2-25-million-users/