¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190130

Ðû²¼Ê±¼ä 2019-01-30
1¡¢FaceTimeÆØÖØ´óÇÔÌýÎó²î£¬£¬£¬£¬£¬AppleÌåÏÖ½«ÔÚ±¾ÖÜÐÞ¸´

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¾ÝÍâý±¨µÀ£¬£¬£¬£¬£¬Apple FaceTime±£´æÖØ´óÇå¾²Îó²î£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÄ¿µÄ½ÓÌý»ò¾Ü¾øFaceTimeͨ»°Ö®Ç°¼àÌý¶Ô·½µÄÉùÒô¡£¡£¡£¡£¡£¡£ÈôÊǶԷ½°´ÏÂÒôÁ¿½µµÍ°´Å¥»òµçÔ´°´Å¥À´¾²Òô»ò×÷·Ïͨ»°£¬£¬£¬£¬£¬ÔòÆäǰÖÃÉãÏñÍ·Ò²»á·­¿ª£¬£¬£¬£¬£¬²¢½«ÊÓÆµÐźŷ¢Ë͸ø¹¥»÷Õß¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬¸ÃÎó²î»á·ºÆðÔÚiOS 12.1»ò¸ü¸ß°æ±¾µÄiOS×°±¸ÖС£¡£¡£¡£¡£¡£AppleÒѾ­ÔÝʱ½ûÓÃÁËFaceTimeÖеÄȺ×éͨ»°¹¦Ð§£¬£¬£¬£¬£¬²¢ÌåÏÖ½«ÔÚ±¾ÖÜÍíЩʱ¼äÐû²¼ÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/apple-facetime-privacy-hack.html


2¡¢°Ä´óÀûÑÇ8¼ÒÍйÜЧÀÍÉÌÔâÓö¹¥»÷»î¶¯Manic Menagerie

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



ƾ֤°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄ£¨ACSC£©Ðû²¼µÄÒ»·Ý±¨¸æ£¬£¬£¬£¬£¬8¸öÍйÜЧÀÍÉÌÔÚ2018ÄêÔâÓö¶ñÒâ¹¥»÷»î¶¯Manic Menagerie¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃWebÓ¦ÓÃÖеÄÎó²îÀ´»ñÈ¡WebЧÀÍÆ÷µÄrootȨÏÞ£¬£¬£¬£¬£¬²¢×°ÖÃÃÜÂëÇÔÈ¡¹¤¾ßºÍGh0st RAT¡£¡£¡£¡£¡£¡£ÆäÖÐÒ»¸ö±»Ê¹ÓõÄÎó²îÊÇ2018Äê4Ô¹ûÕæµÄÌáȨÎó²îTotalMeltdown£¨CVE-2018-1038£©¡£¡£¡£¡£¡£¡£ACSCÒѽ¨ÒéÕâЩÍйÜЧÀÍÉ̸øWebÓ¦ÓúÍCMS´ò²¹¶¡ºÍ½ûÓöñÒâ²å¼þ£¬£¬£¬£¬£¬²¢ÖØÖÃÓû§µÄƾ֤¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/eight-australian-web-hosting-providers-compromised-in-manic-menagerie-attack-campaign-8ee4259a 


3¡¢AZORultľÂíαװ³É¹È¸è¸üгÌÐò£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡Óû§Æ¾Ö¤

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


À´×ÔMinerva Labs¡¢Asaf AprozperºÍGal BitenskyµÄÑо¿Ö°Ô±ÊӲ쵽AZORultľÂíͨ¹ýαװ³ÉGoogle Updater³ÌÐòÀ´ÊµÏÖ³¤ÆÚÐÔ¡£¡£¡£¡£¡£¡£AZORultľÂíÖ÷ÒªÓÃÓÚÇÔÈ¡Óû§µÄÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬°üÀ¨Îļþ¡¢ÃÜÂë¡¢cookie¡¢ä¯ÀÀÆ÷ÀúÊ·¼Í¼¡¢ÒøÐÐÆ¾Ö¤ºÍ¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡£¡£¡£¡£¡£¡£ÓÉÓÚAZORultαװ³ÉGoogle Updater³ÌÐò£¬£¬£¬£¬£¬Ëü½«ÒÔÖÎÀíԱȨÏÞÔËÐС£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÕâЩ¶ñÒâµÄGoogleUpdate.exeÎļþʹÓÃÁËÓÐÓõÄÖ¤Êé¾ÙÐÐÊðÃû£¬£¬£¬£¬£¬µ«¸ÃÖ¤ÊéÏÖʵÉϱ»½ÒÏþ¸ø¡°Singh Agile Content Design Limited¡±£¬£¬£¬£¬£¬¶ø²»ÊÇGoogle¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/azorult-trojan-disguised-as-google-update-installer-steals-credentials-6e225ab6


4¡¢¶ñÒâÈí¼þFormBook»Ø¹é£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹úÁãÊÛºÍÂùÝÒµ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤Deep InstinctµÄ±¨¸æ£¬£¬£¬£¬£¬FormBookÕýÔÚʹÓÃÒ»¸öеÄÎļþÍйÜЧÀÍÈö²¥£¬£¬£¬£¬£¬Ö÷Òª¹¥»÷ÃÀ¹úµÄÁãÊÛºÍÂùÝÒµ¡£¡£¡£¡£¡£¡£FormBook×îÔç·ºÆðÓÚ2016Ä꣬£¬£¬£¬£¬¿ÉÒÔÇÔÈ¡Óû§µÄƾ֤¡¢½ØÈ¡×ÀÃæÆÁÄ»ÒÔ¼°¼Í¼¼üÅ̵È¡£¡£¡£¡£¡£¡£ÔÚÕâ¸öеĶñÒâ»î¶¯ÖУ¬£¬£¬£¬£¬FormBookͨ¹ý´¹ÂÚÓʼþÖеÄRTF¸½¼þÈö²¥£¬£¬£¬£¬£¬¸Ã¸½¼þʹÓÃÁËCVE-2012-0158¡¢CVE-2017-11882µÈOfficeÎó²î¡£¡£¡£¡£¡£¡£FormBook»¹Ê¹ÓÃÁËÒ»¸öеÄÎļþÍйÜЧÀÍDropMyBin£¬£¬£¬£¬£¬¸ÃÎļþÍйÜЧÀÍÒ²±»ÆäËü¶ñÒâÈí¼þʹÓ㬣¬£¬£¬£¬ÀýÈçLokibotºÍAzorult¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.deepinstinct.com/2019/01/27/info-stealer-formbook-continues-activity-and-uses-a-new-malware-friendly-file-hosting-service/


5¡¢·ÆÂɱöµçÐŹ«Ë¾GlobeÒâÍâй¶8851Ãû¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤BestVPN.comµÄ±¨¸æ£¬£¬£¬£¬£¬·ÆÂɱöµçÐŹ«Ë¾GlobeÔÚ½üÆÚµÄÍÆ¹ã×¢²á»î¶¯ÖУ¬£¬£¬£¬£¬ÒâÍâÏòÐÂ×¢²áµÄÓû§ÓÊÏä·¢ËÍÁËÆäËüÓû§¼òÖ±ÈÏÓʼþ£¬£¬£¬£¬£¬µ¼Ö²¿·Ö¿Í»§µÄÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£¡£¡£ÕâЩÊý¾Ý°üÀ¨¿Í»§µÄÐÕÃû¡¢µç×ÓÓÊÏ䵨µãºÍÍêÕûµÄÓÊÕþµØµã£¬£¬£¬£¬£¬¹²ÓÐ8851Ãû¿Í»§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÒѾ­Ö¤ÊµÁËÕâÒ»ÊÂÎñ£¬£¬£¬£¬£¬²¢Æ¾Ö¤î¿ÏµÒªÇó֪ͨÁ˹ú¼ÒÒþ˽±£»£»£»£» £»£»£»¤Î¯Ô±»á£¨NPC£©¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/filipino-telecom-giant-globe-inadvertently-leaks-personal-data-of-8851-subscribers-e87bb87b


6¡¢ÐÂ¼ÓÆÂÔ¼1.4Íò°¬×̲¡»¼ÕßÐÅϢй¶£¬£¬£¬£¬£¬ÏÓ·¸ÎªÃÀ¼®ÄÐ×Ó

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

2019Äê1ÔÂ28ÈÕ£¬£¬£¬£¬£¬ÐÂ¼ÓÆÂÎÀÉú²¿ÔÚÒ»·ÝÉùÃ÷ÖÐ֤ʵÃÀ¹úÄÐ×ÓMikhy K Farrera Brochez²»·¨»ñÈ¡²¢Ð¹Â¶ÁËÔ¼1.42Íò°¬×̲¡»¼ÕßµÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£ÆäÖÐ5400Ãû»¼ÕßÊÇÐÂ¼ÓÆÂÈË£¬£¬£¬£¬£¬8800Ãû»¼ÕßÊÇÍâ¹úÈË¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨»¼ÕßµÄÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢µç»°ºÅÂë¡¢µØµã¡¢HIV¼ì²âЧ¹ûºÍÏà¹ØÒ½ÁÆÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£ÕâЩÊý¾ÝÊÇBrochezÖØÐÂ¼ÓÆÂµÄ°¬×̲¡¹ÒºÅ´¦ÇÔÈ¡µÄ¡£¡£¡£¡£¡£¡£2017Äê3Ô£¬£¬£¬£¬£¬BrochezÔÚÐÂ¼ÓÆÂ±»¿ØÚ²Æ­µÈ¶àÏî×ïÃû£¬£¬£¬£¬£¬²¢ÔÚ·þÐ̺ó±»ÇýÖð³ö¾³¡£¡£¡£¡£¡£¡£2019Äê1ÔÂ22ÈÕ£¬£¬£¬£¬£¬ÐÂ¼ÓÆÂÎÀÉú²¿·¢Ã÷ÉÏÊö»¼Õß×ÊÁÏÔÚÍøÉϱ»Ð¹Â¶ºó±¨¾¯¡£¡£¡£¡£¡£¡£ÏÖÔÚÍâµØ¾¯ÆÓÖ±ÔÚ×·Çó¶Ô´Ë°¸¾ÙÐйú¼ÊÊӲ졣¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/private-data-of-almost-14200-patients-diagnosed-with-hiv-leaked-online-de45a837


ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí