¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180925
Ðû²¼Ê±¼ä 2018-09-25¡¾ÆÊÎö±¨¸æ¡¿¿¨°Í˹»ùÐû²¼¹ØÓÚICSϵͳÖеÄRATΣº¦µÄÆÊÎö±¨¸æ
¿¨°Í˹»ùʵÑéÊÒÐû²¼¹ØÓÚICSÖеÄRATΣº¦µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£Ô¶³ÌÖÎÀí¹¤¾ß£¨RAT£©±»ÆÕ±éÓÃÓÚ¹¤ÒµÍøÂçÖ®ÖУ¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ¾ÙÐÐICS¼à²â¡¢¿ØÖƺÍά»¤¡£¡£¡£¡£¡£Ô¶³Ì²Ù×÷ICSµÄÄÜÁ¦¿ÉÒÔ´ó´ó½µµÍά»¤±¾Ç®£¬£¬£¬£¬£¬£¬£¬µ«²»ÊÜ¿ØÖƵÄÔ¶³Ì»á¼û¡¢ÎÞ·¨100%µØÌṩԶ³Ì¿Í»§¶ËµÄÕýµ±ÐÔÑéÖ¤ÒÔ¼°RAT´úÂëºÍÉèÖÃÖеÄÎó²î¶¼´ó´óÔöÌíÁ˹¥»÷Ãæ¡£¡£¡£¡£¡£Óë´Ëͬʱ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔ½À´Ô½¶àµØÊ¹ÓÃRATºÍÆäËüÕýµ±¹¤¾ßÀ´ÑÚÊÎÆä¶ñÒâ»î¶¯£¬£¬£¬£¬£¬£¬£¬Ê¹µÃ¶Ô¶ñÒâ»î¶¯¾ÙÐйéÒòÔ½·¢ÄÑÌâ¡£¡£¡£¡£¡£
https://securelist.com/threats-posed-by-using-rats-in-ics/88011/
¡¾Îó²î²¹¶¡¡¿Î÷ÊýÐû²¼NAS×°±¸µÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Ò»¸öÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î
Î÷ÊýÐû²¼My Cloud NAS×°±¸µÄ¹Ì¼þ¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Éí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2018-17153£©¡£¡£¡£¡£¡£¸ÃÎó²îÔÊÐí¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤²¢»ñµÃ×°±¸µÄÖÎÀíԱȨÏÞ¡£¡£¡£¡£¡£¸ÃÎó²îÓÉSecurifyµÄÑо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬£¬²¢ÓÚ2017Äê4Ô±¨¸æ¸øÎ÷Êý£¬£¬£¬£¬£¬£¬£¬µ«Î÷ÊýÔÚ³¤´ïÒ»Äê¶àµÄʱ¼äÀïһֱûÓоÙÐÐÈκλظ´¡£¡£¡£¡£¡£ÔÚ¾ÓÉÆÕ±éµÄýÌ屨µÀºó£¬£¬£¬£¬£¬£¬£¬Î÷ÊýÐû²¼Á˸ÃÎó²îµÄÏà¹ØÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/western-digital-releases-hotfix-for-my-cloud-auth-bypass-vulnerability/
¡¾Çå¾²Îó²î¡¿Ñо¿Ö°Ô±·¢Ã÷FireFox±£´æÐÂbug£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂä¯ÀÀÆ÷ºÍ²Ù×÷ϵͳÍß½â
WireÇå¾²Ñо¿Ö°Ô±Sabri Haddouche·¢Ã÷FirefoxÖеÄÒ»¸öÐÂbug£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂä¯ÀÀÆ÷Í߽⣬£¬£¬£¬£¬£¬£¬ÔÚijЩÇéÐÎÏÂÉõÖÁ»áµ¼Öµײã²Ù×÷ϵͳÍ߽⡣¡£¡£¡£¡£ÆäÔµ¹ÊÔÓÉÊǶñÒâJavaScript¾ç±¾»áÌìÉúÒ»¸öÎļþ£¨blob£©£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Ò»¸öºÜÊdz¤µÄÎļþÃû£¬£¬£¬£¬£¬£¬£¬²¢ÌáÐÑÓû§Ã¿¸ôÒ»ºÁÃëÏÂÔØÒ»´Î¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬£¬Ëü»áÔÚFirefoxµÄ×Ó½ÚµãºÍÖ÷½ÚµãÖ®¼ä³äÂúIPC£¨Àú³Ì¼äͨѶ£©Í¨µÀÀú³Ì£¬£¬£¬£¬£¬£¬£¬Ê¹ÏµÍ³Í߽⡣¡£¡£¡£¡£Mac¡¢LinuxºÍWindowsƽ̨ÉϵÄFirefox¶¼ÊÜÓ°Ïì¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÑÓÚ9ÔÂ23ÈÕÏòMozilla±¨¸æÁ˸ÃÎó²î£¬£¬£¬£¬£¬£¬£¬²¢ÔÚGitHubÉÏÐû²¼ÁËÏà¹ØPoC¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-mozilla-firefox-attack-causes-desktop-client-to-crash/
¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷ʹÓÃ×ÔÓÉÖ°ÒµÍøÕ¾fiverrºÍFreelancerµÄ¹¥»÷»î¶¯
MalwareHunterTeamÑо¿ÍŶӷ¢Ã÷ʹÓÃ×ÔÓÉÖ°ÒµÍøÕ¾£¨°üÀ¨fiverrºÍFreelancer£©À´·Ö·¢¶ñÒâÈí¼þµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£ÕâЩ¶ñÒâÈí¼þαװ³ÉÊÂÇé¼ò½éµÄ¸½¼þ£¬£¬£¬£¬£¬£¬£¬µ«ÏÖʵÉÏÓÃÓÚ×°ÖüüÅ̼ͼÆ÷£¨ÈçAgent Tesla£©ºÍÔ¶¿ØÄ¾ÂíµÈ¡£¡£¡£¡£¡£µ±Êܺ¦ÕßÔÚ·¿ª¸Ã¶ñÒ⸽¼þÓöµ½ÎÊÌâʱ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹»á»Ø¸´ËûÃÇÒÔÌṩ×ÊÖú£¬£¬£¬£¬£¬£¬£¬ÀýÈçÒ»ÃûÓû§³ÆÎÞ·¨ÔÚÒÆ¶¯×°±¸ÉÏ·¿ª¸ÃÎļþ£¬£¬£¬£¬£¬£¬£¬¶ø¹¥»÷Õ߻ظ´³ÆÐèÒªÔÚPCÉÏ·¿ªËü¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/malware-disguised-as-job-offers-distributed-on-freelance-sites/
¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶÓÐû²¼¹ØÓÚmacOS¶ñÒâÈí¼þOSX.FairyTaleµÄÆÊÎö±¨¸æ
SentinelOneÑо¿ÍŶÓÐû²¼¹ØÓÚmacOS¶ñÒâÈí¼þOSX.FairyTaleµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£½üÄêÀ´£¬£¬£¬£¬£¬£¬£¬macOSƽ̨ÉÏ×îÆÕ±éµÄÇå¾²ÍþвһֱÊÇÓÃÓÚ·Ö·¢¹ã¸æÈí¼þºÍDZÔÚÓк¦Èí¼þ£¨PUP£©µÄ¶ñÒâ³ÌÐò¡£¡£¡£¡£¡£OSX.FairyTaleÊÇÒ»¸ö¹ã¸æÈí¼þµÄ±äÖÖ£¬£¬£¬£¬£¬£¬£¬×î³õÓÉMalwarebytesµÄÑо¿Ö°Ô±Thomas ReedÓÚ2018ÄêÍ··¢Ã÷¡£¡£¡£¡£¡£OSX.FairyTaleʹÓÃÁË´ó×ڵĻìÏýºÍ·´ÄæÏòÊÖÒÕ£¬£¬£¬£¬£¬£¬£¬Õâ¹ØÓÚ¹ã¸æÈí¼þÀ´ËµÊDz»³£¼ûµÄ¡£¡£¡£¡£¡£
https://www.sentinelone.com/blog/trail-osx-fairytale-adware-playing-malware/
¡¾Êý¾Ýй¶¡¿Ê±×°ÁãÊÛÉÌSHEINÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Ô¼642ÍòÓû§µÄÐÅÏ¢¿ÉÄÜй¶
ʱװÁãÊÛÉÌSHEINÉÏÖÜÎåÐû²¼ÆäÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ô¼642ÍòÓû§µÄÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£¡£¡£¹¥»÷ÊÂÎñ±¬·¢ÔÚÑ×Ì죬£¬£¬£¬£¬£¬£¬¼´6ÔµÄij¸öʱ¼ä£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»á¼ûÁËÓû§µÄµç×ÓÓʼþµØµãºÍ¼ÓÃܵÄÃÜÂë¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ8ÔÂ22ÈÕ·¢Ã÷ÁËÕâÒ»ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬²¢ÕýÔÚÁªÏµÊÜÓ°ÏìµÄÓû§ÐÞ¸ÄÆäÃÜÂë¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾ÝÖв»°üÀ¨ÈκÎÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÕýÔÚ¾ÙÐнøÒ»²½µÄÊӲ졣¡£¡£¡£¡£
https://www.zdnet.com/article/shein-fashion-retailer-announces-breach-affecting-6-42-million-users/


¾©¹«Íø°²±¸11010802024551ºÅ