¹ØÓÚÓ¡·¢¡¶AppÎ¥·¨Î¥¹æÍøÂçʹÓÃÓ×ÎÒÐÅÏ¢ÐÐΪÈ϶¨²½Öè¡·µÄ֪ͨ£»×êÑÐÈËÔ±Åû¶RuckusÎÞÏß·ÓÉÆ÷ÖеĶà¸ö·ì϶
°ä²¼¹¦·ò 2019-12-30
1.¹ØÓÚÓ¡·¢¡¶AppÎ¥·¨Î¥¹æÍøÂçʹÓÃÓ×ÎÒÐÅÏ¢ÐÐΪÈ϶¨²½Öè¡·µÄ֪ͨ
ƾ¾Ý¡¶¹ØÓÚ·¢Õ¹AppÎ¥·¨Î¥¹æÍøÂçʹÓÃÓ×ÎÒÐÅϢרÏîÖÎÀíµÄ²¼¸æ¡·£¬Îª¼à¶½ÖÎÀí²¿ÃÅÈ϶¨AppÎ¥·¨Î¥¹æÍøÂçʹÓÃÓ×ÎÒÐÅÏ¢ÐÐΪÌṩ²Î¿¼£¬ÎªAppÔËÓªÕß×Ô²é×Ô¾ÀºÍÍøÃñÉç»á¼à¶½ÌṩָÒý£¬Âäʵ¡¶ÍøÂ簲ȫ·¨¡·µÈ˾·¨Âɹ棬¹ú¶È»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒ¡¢¹¤ÒµºÍÐÅÏ¢»¯²¿¡¢¹«°²²¿¡¢Êг¡¼à¹Ü×ֽܾáºÏÔì¶©ÁË¡¶AppÎ¥·¨Î¥¹æÍøÂçʹÓÃÓ×ÎÒÐÅÏ¢ÐÐΪÈ϶¨²½Öè¡·¡£
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2019-12/27/c_1578986455686625.htm?scene=2&clicktime=1577670801&enterid=1577670801&from=timeline&isappinstalled=0
2.ÎïÁªÍø¹©¸øÉÌWyzeÒâ±íй¶Լ240Íò¿Í»§ÐÅÏ¢
ÎïÁªÍø¹©¸øÉÌWyzeÈ·ÈÏÆäÒ»¸öElasticsearch·þÎñÆ÷й¶ÁËÔ¼240ÍòÓû§µÄ¾ßÌåÐÅÏ¢¡£¸ÃÊý¾Ý¿â²¢²»Êdzö²úϵͳ£¬µ«´æ´¢ÁËÓÐЧµÄÓû§Êý¾Ý£¬Ô̺¬ÓÃÓÚ´´½¨WyzeÕÊ»§µÄµç×ÓÓʼþµØÖ·¡¢·ÖÅ䏸ÆäWyze°²È«ÉãÏñ»úµÄÓû§êdzơ¢WiFiÍøÂç±êʶ·ûSSIDÒÔ¼°2.4ÍòÓû§µÄAlexaÁîÅÆµÈ¡£¸ÃÊý¾Ý¿âÓÚ12ÔÂ4ÈÕ±»ÃýÎóµØÂ¶³öÔÚ¹«ÍøÉÏ£¬°²È«¹«Ë¾Twelve SecurityÓÚ12ÔÂ26ÈÕ·¢ÏÖÁ˸ÃÊý¾Ý¿â²¢Í¨ÖªÁËWyze£¬WyzeËæºó¶ÔÊý¾Ý¿â½øÐÐÁ˱£»¤¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/iot-vendor-wyze-confirms-server-leak/
3.±ÈÀûʱAllianz Partners¹«Ë¾16Íò¿Í»§Êý¾Ý±»µÁ
±ÈÀûʱ±£ÏÕºÍÔöÔ®¹«Ë¾Allianz Partners³ÆÆäÒ»¸ö±£ÏÕÏäÓÚ8Ô·ÝÔÚºÉÀ¼±»µÁ£¬ÆäÖÐÔ̺¬Óë16Íò¸ö¿Í»§ÓйصĿàÄÑË÷ÅâÓйØÊý¾Ý±¸·Ý¡£Æ¾¾Ý¶ÔÓйØÎļþµÄÉó¼ÆºÍ·ÖÎö£¬ÓйØÎļþÊǿͻ§Æ¾¾ÝÆäÔöÔ®ºÏͬ»ò¹Û¹â±£ÏÕÌá³ö¿àÄÑ»ò¹ÊÕÏË÷ÅâµÄÎļþ±¸·Ý£¬¸Ã¹«Ë¾ÒÑÏòºÉÀ¼¾¯·½Ìá³öÁËÉêÊö£¬Ë¾·¨µ÷²éÔÚ½øÐÐÖС£¸Ã¹«Ë¾»¹Í¨ÖªÁ˱ÈÀûʱµÄÊý¾Ý±£»¤»ú¹¹£¬Ä¿Ç°ÎªÖ¹Ã»Óм£ÏóÅú×¢¹¥»÷ÕßÄܹ»½Ó¼ûÕâЩ±¸·ÝÎļþÖÐÔ̺¬µÄÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://www.brusselstimes.com/all-news/business/86376/about-160000-belgian-clients-of-allianz-partners-affected-by-strongbox-theft-in-the-netherlands/
4.³¬¹ý100¸öAndroid APPÀûÓÃSoraka¿â½øÐиæ°×Ú²Æ
Íþвµý±¨×êÑÐÓ××éWhite Ops·¢ÏÖ100¶à¸öAPPʹÓÃSoraka¿âÔÚÓû§µÄAndroidÉ豸ÉϽøÐиæ°×ڲƣ¬Õâ100¶à¸ö¶ñÒâAndroid APPµÄ×ÜÏÂÔØÁ¿´ï460Íò´Î¡£×êÑÐÍŶÓÔÚ·ÖÎöÖз¢ÏÖ£¬ÕâЩAPPÒÀÀµÓÚÃûΪAppsFlyerµÄ¿ò¼ÜÀ´¼à¶½ÊÇ·ñΪڲÆÕߵķַ¢Çþ·װÖã¬ËüÃǽöÔÚÕâÖÖÇé¿öϲÅÏÔʾڲÆÐÔ¸æ°×¡£ÕâЩAPPʹÓöàÖÖ»ùÓÚJavaµÄÓÆ¾ÃÐÔ»úÔ죨Ô̺¬ÉèÖþ¯±¨£©À´±£ÁôÔÚÊÜϰȾµÄÉ豸ÉÏ¡£AndroidÓû§Ó¦Ð¶ÔØ×êÑÐÍŶӼì²âµ½µÄËùÓжñÒâAPP¡£
ÔÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/over-100-android-apps-used-soraka-package-to-perform-ad-fraud/
5.×êÑÐÈËÔ±Åû¶RuckusÎÞÏß·ÓÉÆ÷ÖеĶà¸ö·ì϶
°²È«×êÑÐÔ±Gal Zror·¢ÏÖRuckusÎÞÏß·ÓÉÆ÷´æÔÚ3¸öRCE·ì϶£¬²¢Ôڵ¹úÄê¶È»ìãçͨѶ´ó»áÉÏÅû¶ÁËÕâЩ·¢ÏÖ¡£Zror³ÆÕâЩ·ì϶´æÔÚÓÚUnleashedϵÁзÓÉÆ÷ÔËÐеÄWebÓû§½çÃæÈí¼þÖУ¬ÎÞÐè·ÓÉÆ÷ÃÜÂë¼´¿ÉÀûÓÃÕâЩ·ì϶£¬²¢¿É´ÓInternetÉÏÆëÈ«½ÚÔìÊÜÓ°ÏìµÄ·ÓÉÆ÷¡£ÕâÈý¸ö·ì϶¾ù¿ÉÓÃÓÚ»ñȡ·ÓÉÆ÷rootÌØÈ¨£¬´Ó¶øÊ¹¹¥»÷ÕßÄܹ»²»ÊÜÏ޶ȵؽӼûÉ豸ºÍÍøÂç¡£RuckusÔÚ²¹¶¡°ü200.7.10.202.92Öн¨¸´ÁËÕâЩ·ì϶£¬µ«Óû§±ØÐë×Ô¼º¸üÐÂÒ×Êܹ¥»÷µÄÉ豸¡£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2019/12/28/ruckus-wireless-routers-flaws/
6.LampionľÂíй¥»÷»î¶¯ÖØÒªÕë¶ÔÆÏÌÑÑÀ
SI-LAB¼ì²âµ½¼Ù×°³ÉÆÏÌÑÑÀµ±¾Ö²ÆÕþºÍ˰ÊÕµç×ÓÓʼþ´«²¼µÄÐÂľÂíLampion¡£¸ÃľÂí¿´ÆðÀ´ÀàËÆÓÚTrojan-Banker.Win32.ChePro¼Ò×壬µ«½øÐÐÁ˸Ľø£¬Ê¹ÆäÄÑÒÔ±»¼ì²âºÍ·ÖÎö¡£LampionÄܹ»ÍøÂçÍÆËã»úÓ²ÅÌ¡¢µ±Ç°´ò¿ªµÄ´°¿Ú¡¢¼ôÌù°åºÍÒøÐÐÍ´´¦µÈÐÅÏ¢²¢·¢ËÍÖÁC2·þÎñÆ÷¡£¸ÃľÂí£¨P-19-2.dll£©ÔÚVirusTotalÉϵļì²âÁ˾ÖΪ12/71£¬ÕâÅú×¢´óÎÞÊý·À²¡¶¾ÒýÇæÉÐδ¼ì²âµ½¸Ã¶ñÒâÈí¼þµÄÊðÃû¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/95731/malware/lampion-malware-targets-portugal.html


¾©¹«Íø°²±¸11010802024551ºÅ