¹È¸è±»Å·ÃË·£¿£¿£¿£¿î17ÒÚÃÀÔª£» £»£»£»£»£»Ê±¸ôÁ½ÄêPuTTYÐû²¼0.71°æ±¾£» £»£»£»£»£»¹¥»÷»î¶¯Bad Tidings

Ðû²¼Ê±¼ä 2019-03-21
1¡¢Ê±¸ôÁ½ÄêPuTTYÐû²¼0.71°æ±¾£¬£¬£¬ £¬£¬£¬ÐÞ¸´8¸öÇå¾²Îó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


±¾ÖÜPuTTYÐû²¼ÁËÊÊÓÃÓÚWindowsºÍUnixƽ̨µÄа汾0.71£¬£¬£¬ £¬£¬£¬Õâ¾àÀëÆäÉÏÒ»¸ö°æ±¾µÄÐû²¼ÒÑÓнüÁ½ÄêµÄʱ¼ä¡£¡£ ¡£¡£¸Ãа汾ÐÞ¸´ÁË8¸öÇå¾²Îó²î£¬£¬£¬ £¬£¬£¬Îó²î¹æÄ£°üÀ¨Éí·ÝÑéÖ¤ÌáÐÑÐÅϢαÔì¡¢CHMÐ®ÖÆµ¼ÖµĴúÂëÖ´ÐС¢»º³åÇøÒç³ö¡¢¼ÓÃÜËæ»úÊýÖØÓá¢ÕûÊýÒç³öÒÔ¼°¾Ü¾øÐ§ÀÍ¡£¡£ ¡£¡£½¨ÒéÓû§´Ó¹ÙÍøÏÂÔØ¸Ãа汾¡£¡£ ¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/03/putty-software-hacking.html

2¡¢Google PhotosÎó²î¿Éµ¼ÖÂÓû§Î»ÖÃÐÅϢй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ImpervaÇå¾²Ñо¿Ô±Ron Masas·¢Ã÷web°æGoogle Photos±£´æÇå¾²Îó²î£¬£¬£¬ £¬£¬£¬¿ÉÔÊÐí¶ñÒâÍøÕ¾Æ¾Ö¤Óû§ÕË»§Öд洢µÄÕÕÆ¬À´¸ú×ÙÓû§µÄλÖÃÐÅÏ¢¡£¡£ ¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬ £¬£¬£¬Ê¹ÓûùÓÚä¯ÀÀÆ÷µÄʱÐò¹¥»÷£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉÍÆ¶Ï³öÀ´×ÔÌØ¶¨µØÀíλÖõÄÕÕÆ¬ÊÇ·ñ±£´æÓÚÓû§µÄÕË»§ÖУ¬£¬£¬ £¬£¬£¬¼´Óû§ÊÇ·ñ»á¼ûÁËÕâ¸ö¹ú¼Ò¡£¡£ ¡£¡£Í¨¹ýÈÕÏÞÆÚ¶¨£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßÉõÖÁÄܹ»È·¶¨Óû§»á¼û¸Ã¹ú¼ÒµÄ´óÖÂʱ¼ä¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-photos-bug-exposed-the-location-and-time-of-your-pictures/

3¡¢¹È¸èÒò¹ã¸æÂ¢¶ÏÔÙ±»Å·ÃË·£¿£¿£¿£¿î17ÒÚÃÀÔª

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

3ÔÂ20ÈÕÅ·ÃËίԱ»áÐû²¼ÉùÃ÷¶Ô¹È¸èµÄ¹ã¸æÂ¢¶ÏÐÐΪ·£¿£¿£¿£¿î14.9ÒÚÅ·Ôª£¨Ô¼17ÒÚÃÀÔª£©£¬£¬£¬ £¬£¬£¬ÕâÊÇÁ½ÄêÄÚÅ·Ã˶Թȸ迪³öµÄµÚÈýÕÅ´ó¶î·´Â¢¶Ï·£µ¥¡£¡£ ¡£¡£Å·ÃËίԱ»áÌåÏÖÕâÒ»·£¿£¿£¿£¿îµÄÔµ¹ÊÔ­ÓÉÊǹȸèÀÄÓÃÆäÊг¡Ö÷µ¼Ö°Î»£¬£¬£¬ £¬£¬£¬×èÖ¹ÍøÒ³Ê¹ÓÃAdSenseƽ̨ÒÔÍâµÄ¹ã¸æÐ§ÀÍ£¬£¬£¬ £¬£¬£¬ÕâÒ»·£½ðÏ൱Óڹȸè2018ÄêÓªÒµ¶îµÄ1.29%¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-fined-17-billion-for-anti-competitive-practices-in-online-advertising/

4¡¢MyPillowºÍAmerisleep³ÉΪMagecart¹¥»÷µÄ×îÐÂÊܺ¦Õß


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²Ñо¿Ö°Ô±·¢Ã÷´²ÉÏÓÃÆ·ÁãÊÛÉÌMyPillowºÍAmerisleep³ÉΪMagecart¹¥»÷µÄ×îÐÂÊܺ¦Õß¡£¡£ ¡£¡£Í¬Ö®Ç°µÄ¹¥»÷Ò»Ñù£¬£¬£¬ £¬£¬£¬Magecart¹¥»÷ÕßÔÚÕâÁ½¸ö¹ºÎïÍøÕ¾ÉÏÖ²ÈëÁËÓÃÓÚÇÔȡ֧¸¶ÐÅÏ¢µÄ¶ñÒâ´úÂë¡£¡£ ¡£¡£MyPillowÓÚ2018Äê10ÔÂÔâµ½¹¥»÷£¬£¬£¬ £¬£¬£¬¶øAmerisleepÔòÔÚ2017Äê¡¢2018Äê12Ô¼°2019Äê1Ô¶¼Ôâµ½¹¥»÷¡£¡£ ¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬MyPillowºÍAmerisleep¶¼Ã»ÓÐÕë¶ÔÕâÒ»ÊÂÎñÏòÓû§·¢³öÈκÎÖÒÑÔ»ò¹Ù·½ÉùÃ÷¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/03/magecart-ecommerce-hackers.html

5¡¢Ð´¹ÂÚ¹¥»÷»î¶¯Bad Tidings£¬£¬£¬ £¬£¬£¬Ö÷ÒªÕë¶ÔÉ³ÌØ°¢À­²®


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


1Ô·ÝAnomali·¢Ã÷ð³äÉ³ÌØ°¢À­²®ÄÚÕþ²¿¹ÙÍøAbsherµÄ´¹ÂÚÍøÕ¾ÊýÄ¿¼¤Ôö¡£¡£ ¡£¡£½øÒ»²½Ñо¿Åú×¢ÕâÊÇÒ»¸öÕë¶ÔÉ³ÌØ°¢À­²®Ëĸö²î±ðµÄÕþ¸®»ú¹¹£¨ÄÚÕþ²¿¡¢Íâ½»²¿¡¢ÀͶ¯¼°Éç»áÉú³¤²¿¡¢Õþ¸®¹ÙÍø£©ÒÔ¼°Ò»¸ö½ðÈÚ»ú¹¹£¨É³µØÓ¢¹úÒøÐУ©µÄ¸üÆÕ±éµÄ´¹ÂÚ¹¥»÷»î¶¯Bad Tidings£¬£¬£¬ £¬£¬£¬¸Ã¹¥»÷»î¶¯¿É×·ËÝÖÁ2016Äê11ÔÂ⣬£¬£¬ £¬£¬£¬¹²½¨ÉèÁËÁè¼Ý90¸ö´¹ÂÚÖ÷»úÃû£¨ÊôÓÚ46¸öÓòÃû£©¡£¡£ ¡£¡£ÕâЩÐéαÓòÃû´ó¶àÒÔ.cc¡¢.xyz¡¢.club¡¢.siteºÍ.services×îºó¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.anomali.com/blog/bad-tidings-phishing-campaign-impersonates-saudi-government-agencies-and-a-saudi-financial-institution

6¡¢Cardinal RATбäÖÖ£¬£¬£¬ £¬£¬£¬Ö÷ÒªÕë¶ÔÒÔÉ«ÁнðÈÚ¹«Ë¾


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Palo Alto NetworksµÄUnit 42ÍŶӷ¢Ã÷Cardinal RATµÄбäÖÖÕýÔÚÕë¶ÔÒÔÉ«ÁеĽðÈÚ¹«Ë¾¡£¡£ ¡£¡£¸Ã±äÖְ汾Ϊ1.7.2£¬£¬£¬ £¬£¬£¬Æä½ÓÄÉÁ˶àÖÖ»ìÏýÊÖÒÕ£¬£¬£¬ £¬£¬£¬°üÀ¨ÒþдÊõºÍXOR¼ÓÃܵÈ¡£¡£ ¡£¡£¸Ã±äÖֵĹ¦Ð§°üÀ¨ÍøÂçÐÅÏ¢¡¢¼üÅ̼ͼ¡¢ÆÁÄ»½ØÍ¼¡¢Ö´ÐжñÒâÏÂÁî¼°×ÔÎÒÐ¶ÔØµÈ¡£¡£ ¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷¸Ã±äÖÖÓëÁíÒ»¸ö¶ñÒâÈí¼þ¼Ò×åEVILNUM±£´æ¹ØÁª¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/a-new-variant-of-cardinal-rat-employs-bmp-trick-to-target-israeli-financial-firms-e0cefbb0

ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí