2019ÄêÕë¶ÔMacÓû§µÄ´¹µö¹¥»÷Ôö³¤ÖÁ160Íò´Î£»ÃÀ¹ú²ÆÕþ²¿°ä·¢¶ÔÈý¸ö³¯ÏʺڿÍ×éÖ¯Ö´ÐÐÔì²Ã
°ä²¼¹¦·ò 2019-09-161.2019ÄêÕë¶ÔMacÓû§µÄ´¹µö¹¥»÷Ôö³¤ÖÁ160Íò´Î
¿¨°Í˹»ùÔÚ2019ÄêµÄǰÁù¸öÔÂÖй²²¶»ñµ½160Íò´ÎÕë¶ÔMacÓû§µÄ´¹µö¹¥»÷¡£2018ÄêÕûÄêÀûÓÃAppleÆ·ÅÆµÄ´¹µö¹¥»÷´ÎÊýΪ150Íò´Î£¬½ñÄêÉϰëÄêÒѾ³¬¹ýÁËÕâÒ»Êý×Ö¡£¿¨°Í˹»ù°µÊ¾´ËÀ๥»÷ͨ³£Ã¿ÄêÔö³¤30-40%¡£°ÍÎ÷µÄmacOSÓû§ÖÐÊÜ´¹µö¹¥»÷µÄ±ÈÀý×î´ó£¬Îª30%£¬¶ø·¨¹úºÍÓ¡¶ÈµÄ±ÈÀýԼΪ22%¡£¿¨°Í˹»ùÇ¿µ÷³Æ¹¥»÷ÕßÔ½À´Ô½¶àµØÀûÓÃAppleͼ±êÀ´ÓÕÆÓû§µÄApple IDºÍÍ´´¦¡£´Ë±í£¬¿¨°Í˹»ù°µÊ¾×Ô2015ÄêÒÔÀ´ÍøÂç´¹µö¹¥»÷µÄ×ÜÊýÔøÖ¸Êý¼¶Ôö³¤£¬ÆäʱµÄÊý×ÖΪԼ85Íò´Î¹¥»÷£¬¶øÔÚ½ñÄêÉϰëÄê´¹µö¹¥»÷µÄ×ÜÊýΪ½ü600Íò´Î¡£
ÔÎÄÁ´½Ó£º
https://www.techrepublic.com/article/phishing-scams-targeting-mac-users-on-the-rise-with-1-6-million-attacks-in-2019/
2.ÃÀ¹ú²ÆÕþ²¿°ä·¢¶ÔÈý¸ö³¯ÏʺڿÍ×éÖ¯Ö´ÐÐÔì²Ã
ÃÀ¹ú²ÆÕþ²¿°ä·¢¶ÔÈý¸öÓɹú¶ÈÖ§³ÖµÄ³¯ÏʺڿÍ×éÖ¯Ö´ÐÐÔì²Ã£¬Ô̺¬·¸×ïÍÅ»ïLazarus Group¼°Æä×Ó¼¯ÍÅBluenoroffºÍAndariel¡£ÕâЩºÚ¿Í×éÖ¯±»Ö¸¿Ø¶ÔÃÀ¹ú¹Ø¼ü»ù´¡ÉèʩִÐÐÁËÂŴηÛËéÐÔÍøÂç¹¥»÷ÒÔ¼°´ÓÈ«Çò½ðÈÚ»ú¹¹ÇÔÈ¡ÊýÒÚÃÀÔª²¢Îª³¯Ïʵ±¾ÖµÄ·¸·¨±øÆ÷ºÍµ¼µ¯´òËãÌṩ×ʽ𡣲ÆÕþ²¿±í¹ú×ʲú½ÚÔì°ì¹«ÊÒ£¨OFAC£©°µÊ¾Ôì²ÃµÄÖ÷ÕÅÊÇËø¶¨ÈκÎÓÐÒâΪÕâЩºÚ¿Í×éÖ¯Ìṩ³Á´óÂòÂô»ò·þÎñµÄ±í¹ú½ðÈÚ»ú¹¹£¬²¢¶³½áÓëÕâÈý¸ö×éÖ¯ÓйصÄÈκÎ×ʲú¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/09/north-korea-cyber-attack.html
3.ÓŲ½½¨¸´¿Éµ¼ÖÂÓû§ÕË»§±»ÊÕÊܵÄAPI·ì϶
Anand Prakash·¢ÏÖÓŲ½µÄÒ»¸öAPI·ì϶¿ÉÓÃÓÚÊÕÊÜÓû§ÕË»§ºÍ¸ú×ÙÓû§¡£¹¥»÷Õß¿ÉÊ×ÏÈͨ¹ý·¢ËÍÔ̺¬Óû§µç»°ºÅÂë»òµç×ÓÓʼþµØÖ·µÄAPIÒªÇóÀ´»ñÈ¡ÈκÎÓû§µÄΨһ±êʶ·û£¨UUID£©£¬¶øºóÀûÓøÃUUID³Áз¢ËÍÒªÇ󣬴ӶøÄܹ»»ñÈ¡ÒÆ¶¯APPµÄ½Ó¼ûÁîÅÆ¡¢µØÎ»ºÍµØÖ·µÈ¸öÈËÐÅÏ¢¡£Prakash°µÊ¾Í¨¹ý½Ó¼ûÁîÅÆ£¬Ëû¿ÉÄÜÆëÈ«ÊÕÊܲâÊÔÕË»§¡¢·¢Ëͳ˳µÒªÇóÒÔ¼°»ñÈ¡¸¶¿îÐÅÏ¢µÈ¡£¸ÃÎÊÌâͬʱӰÏìÁËÓŲ½Óû§ºÍ˾»ú¡£ÓŲ½ÔÚÈ·ÈÏÁ˸ÃÎÊÌâºóѸ¿ì½¨¸´ÁËÓйطì϶¡£
ÔÎÄÁ´½Ó£º
https://www.forbes.com/sites/daveywinder/2019/09/12/uber-confirms-account-takeover-vulnerability-found-by-forbes-30-under-30-honoree/
4.Instagram½¨¸´¿Éµ¼ÖÂÕË»§ÐÅϢй¶µÄ·ì϶
Facebook½¨¸´ÁËInstagramÖпɵ¼Ö¹¥»÷Õß»ñÈ¡Óû§¸öÈËÐÅÏ¢µÄ·ì϶¡£°²È«×êÑÐÔ±@ZHacker13°µÊ¾¿É±»»ñÈ¡µÄÓû§Êý¾ÝÔ̺¬ÕæÊµÐÕÃû¡¢ÆëÈ«µç»°ºÅÂëÒÔ¼°InstagramÕʺÅÐÅÏ¢µÈ¡£¸Ãר¼Ò»¹ÖÒ¸æ³Æ¹¥»÷ÕßÄܹ»Ê¹ÓÃ×Ô¶¯¾ç±¾ºÍ»úеÈË´ÓÆ½Ì¨ÍøÂçÓû§Êý¾Ý£¬²¢½«Óû§ÓëÆäÁªÏµÈËÐÅÏ¢¹ØÁªÆðÀ´¡£¹¥»÷³¡¾°Ô̺¬Á½¸ö²½Ö裺Ê×ÏÈÊÇÔÚInstagramµÄµÇ¼±íµ¥ÉϽøÐб©Á¦¹¥»÷£¬Ò»´Î²é³Ò»¸öµç»°ºÅÂ룬ÒÔ±ãÁ´½Óµ½Ò»¸öÕæÊµµÄInstagramÕÊ»§£»¶øºóÀûÓÃInstagramµÄͬ²½ÁªÏµÈËÖ°ÄÜÕÒµ½Óëµç»°ºÅÂëÓйØÁªµÄÕÊ»§Ãû³ÆºÍºÅÂë¡£Facebook½²»°È˰µÊ¾¸Ã¹«Ë¾Í¨¹ýÅú¸ÄInstagramÁªÏµÈ˵¼È뷽ʽ½¨¸´Á˸ÃÎÊÌâ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/91253/hacking/instagram-bug-data-exposure.html
5.NemtyбäÌå¿ÉɱËÀVirtualBox¡¢SQLµÈ¹ý³Ì
ÀÕË÷Èí¼þNemtyÔÚ»ý¼«¿ª·¢ÖУ¬Æä×÷ÕßÏÔÈ»ÔÚÖÂÁ¦Ê¹Æä³ÉΪһÖÖ¸ü¸ßЧ¡¢¸´ÔӵĶñÒâÈí¼þ£¬²¢ÆðÍ·¸ü¿í·ºµÄ·Ö·¢¡£°²È«×êÑÐÔ±Vitali Kremez·ÖÎö·¢ÏÖÖ»¹ÜNemty×÷Õß¶Ô´úÂë½øÐÐÁ˸ü¸Ä£¬µ«Ëü±£ÁôÁËÒ»ÑùµÄ°æ±¾ºÅ¡£×îеÄÑù±¾Ô̺¬ÓÃÓÚɱËÀ¹ý³ÌºÍ·þÎñµÄ´úÂ룬ָ±ê¹ý³ÌÔ̺¬WordPad¡¢Microsoft Word¡¢Excel¡¢Outlook¡¢µç×ÓÓʼþ¿Í»§¶ËThunderbird¡¢SQL¡¢oracle¡¢onenoteºÍÓÃÓÚÔËÐÐÐé¹¹»úµÄVirtualBoxÈí¼þ¡£ÕâÒâζ×ÅNemtyÔÚÕë¶ÔÆóÒµÊܺ¦Õß¡£Nemty×î³õͨ¹ýRIG EK·Ö·¢£¬¶ø×îа汾1.4Ôòͨ¹ýÐéαµÄPayPalÍøÕ¾´«²¼£¬ËæºóÓÖÐÂÔöÁËRadio EK´«²¼Çþ·¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/nemty-ransomware-update-lets-it-kill-processes-and-services/
6.д¹µöȦÌ×ÖØÒªÇÔÈ¡ÑÇÂíÑ·Óû§µÄÐÅÓþ¿¨Êý¾Ý
×êÑÐÈËÔ±·¢ÏÖÒ»¸öеĴ¹µöÓʼþȦÌ×ÔÚ´«²¼£¬¹¥»÷ÕßÖØÒªÊÔͼÇÔÈ¡ÑÇÂíÑ·Óû§µÄÐÅÓþ¿¨Êý¾Ý¡£¸ÃȦÌ׵Ť×÷µÀÀíÈçÏ£ºÊܺ¦Õ߽ӹܵ½Ò»·â¼Ù×°³ÉÀ´×ÔÑÇÂíÑ·µÄµç×ÓÓʼþ£¬Í¨ÖªÓÐ¹ØÆäÕË»§µÄ¿ÉÒɻ£¬¸ÃÓʼþʹÓûìºÏÁËÓ¢ÓïºÍ·¨ÓïµÄÖ÷Ì⣬ҪÇóÊܺ¦Õßµã»÷Á´½ÓÀ´¸üÐÂÕË»§ÐÅÏ¢£¬Ô̺¬ÊäÈë½Ó¼ûÍ´´¦¡¢Õ˵¥µØÖ·¡¢²ÆÕþÐÅÏ¢µÈ¡£¸Ã´¹µöÍøÕ¾ÍйÜÔÚwadwa-wmdw(dot)comÓòÃûÉÏ£¬´ËÓòÃûÊÇ8ÔÂ22ÈÕÔÚÒ»¸ö¶àÂ×¶àµØÖ·×¢²áµÄ£¬¸ÃµØÖ·ºÜ¿ÉÄÜÖ»ÊÇÒ»¸öÐéαµØÖ·¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/new-amazon-phishing-scam-stealing-credit-card-data/


¾©¹«Íø°²±¸11010802024551ºÅ