2018ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö£»£»£»£»Chrome 0dayÐ®ÖÆ5ÒÚiOSÓû§»á»°£»£»£»£»JustDialй¶1ÒÚÓû§ÐÅÏ¢

Ðû²¼Ê±¼ä 2019-04-18
1¡¢¹ú¼Ò»¥ÁªÍøÓ¦¼±ÖÐÐÄÐû²¼¡¶2018ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


4ÔÂ16ÈÕCNCERT/CCÐû²¼¡¶2018ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·£¬£¬£¬¸Ã±¨¸æ×ܽáÁË2018ÄêÎÒ¹ú»¥ÁªÍøµÄÍøÂçÇ徲״̬£¬£¬£¬²¢¶Ô2019ÄêÍøÂçÇå¾²Ç÷ÊÆ¾ÙÐÐÁËÕ¹Íû ¡£¡£¡£±¨¸æÖеÄÊý¾Ýº­¸ÇÁË2018ÄêµÄ¶ñÒâ³ÌÐò¡¢Çå¾²Îó²î¡¢¾Ü¾øÐ§À͹¥»÷¡¢ÍøÕ¾Çå¾²¡¢¹¤Òµ»¥ÁªÍøÇå¾²¡¢»¥ÁªÍø½ðÈÚÇå¾²Áù¸ö·½ÃæµÄͳ¼ÆÊý¾Ý ¡£¡£¡£ÍêÕû±¨¸æÇë²Î¿¼ÒÔÏÂÁ´½Ó ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
http://www.cert.org.cn/publish/main/upload/File/2018situation.pdf

2¡¢³¬´ó¹æÄ£¶ñÒâ¹ã¸æ»î¶¯£¬£¬£¬Ð®ÖÆ5ÒÚiOSÓû§»á»°


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²³§ÉÌConfiant·¢Ã÷·¸·¨ÍÅ»ïeGobblerÌᳫÕë¶ÔiOSÓû§µÄ³¬´ó¹æÄ£¶ñÒâ¹ã¸æ»î¶¯£¬£¬£¬ÒÑÐ®ÖÆ5ÒÚiOSÓû§µÄ»á»° ¡£¡£¡£¸Ã¹¥»÷»î¶¯´Ó4ÔÂ6ÈÕ×îÏÈ£¬£¬£¬Ò»Á¬ÁË6ÌìµÄʱ¼ä£¬£¬£¬¹¥»÷ÕßʹÓÃÁË8¸ö²î±ðµÄ¶ñÒâ¹ã¸æÏµÁкÍ30¶à¸öÐéα¹ã¸æ£¬£¬£¬Ã¿¸öÐéα¹ã¸æÏµÁеÄÉúÃüÖÜÆÚΪ24-48Сʱ֮¼ä ¡£¡£¡£¹¥»÷ÕßÖ÷ÒªÕë¶ÔÃÀ¹úºÍÅ·Ã˵ÄiOSÓû§£¬£¬£¬²¢ÔÚ¹¥»÷ÖÐʹÓÃÁËChromeä¯ÀÀÆ÷ÖеÄÎó²îÒÔÈÆ¹ýɳºÐ¼ì²â ¡£¡£¡£¹¥»÷ÕßʹÓÃÁË.worldÓòÃûÍйܵĴ¹ÂÚÍøÕ¾£¬£¬£¬¾­ÓɶÌÔݵÄÍ£ÁôÖ®ºó£¬£¬£¬ÓÖתÏò.siteÓòÃûµÄ´¹ÂÚÍøÕ¾ ¡£¡£¡£×Ô4ÔÂ14ÈÕÒÔÀ´£¬£¬£¬ÕâЩ´¹ÂÚÍøÕ¾Ò»Ö±´¦ÓÚ»îԾ״̬ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/malvertising-campaign-abused-chrome-to-hijack-500-million-ios-user-sessions/

3¡¢JustDial APIй¶Áè¼Ý1ÒÚÓ¡¶ÈÓû§µÄСÎÒ˽¼ÒÐÅÏ¢

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Çå¾²Ñо¿Ô±Rajshekhar Rajaharia·¢Ã÷Ó¡¶ÈÍâµØËÑË÷ЧÀ͹«Ë¾JustDialµÄÒ»¸öAPIδÊܱ£»£»£»£»¤£¬£¬£¬¿É±»ÈκÎÈËʹÓÃÒÔ¼ìË÷Áè¼Ý100ÍòÓû§µÄСÎÒ˽¼ÒÐÅÏ¢ ¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨Óû§µÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢ÊÖ»úºÅÂë¡¢ÆÜÉíµØµã¡¢ÐԱ𡢳öÉúÈÕÆÚ¡¢ÕÕÆ¬¡¢¾ÍÖ°¹«Ë¾µÈ ¡£¡£¡£ËäÈ»¸ÃAPIÖÁÉÙ´Ó2015ÄêÆð¾Í¿É¹ûÕæ»á¼û£¬£¬£¬µ«Éв»ÇåÎúÊÇ·ñÒÑÓÐÈËʹÓÃËüÀ´ÍøÂçJustDialÓû§µÄСÎÒ˽¼ÒÐÅÏ¢ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/04/justdial-hacked-data-breach.html

4¡¢Navicent HealthÈ·ÈÏÔâºÚ¿ÍÈëÇÖ£¬£¬£¬27Íò»¼ÕßÐÅϢй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Navicent HealthÐû²¼ÉùÃ÷³ÆÆäµç×ÓÓʼþϵͳÔâºÚ¿ÍÈëÇÖ£¬£¬£¬Ô¼27Íò»¼ÕßµÄÐÅϢй¶£¬£¬£¬ÆäÖаüÀ¨Ò»Ð©»¼ÕßµÄÉç»áÇå¾²ºÅÂë ¡£¡£¡£¸ÃÊý¾Ýй¶ÊÂÎñ±¬·¢ÔÚ2018Äê7Ô£¬£¬£¬NavicentÊÓ²ìÈ·ÈÏÖ»Óеç×ÓÓʼþϵͳÔâµ½ÈëÇÖ£¬£¬£¬Ð¹Â¶µÄÐÅÏ¢°üÀ¨»¼ÕßµÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µØµãÒÔ¼°Õ˵¥ºÍÔ¤Ô¼ÐÅÏ¢ ¡£¡£¡£Navicent½«ÎªÉç»áÇå¾²ºÅÂëÔ⵽й¶µÄ»¼ÕßÌṩһÄêµÄÃâ·ÑÐÅÓÃ¼à¿ØÐ§ÀÍ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/navicent-health-data-breach-exposes-patients-personal-info/

5¡¢ÐÂÀÕË÷Èí¼þNamPoHyu Virus£¬£¬£¬Ö÷ÒªÕë¶ÔSambaЧÀÍÆ÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÐÂÀÕË÷Èí¼þNamPoHyu VirusÕýÔÚÆð¾¢¾ÙÐÐÈö²¥£¬£¬£¬ÓëÆäËüÀÕË÷Èí¼þ²î±ðµÄÊÇ£¬£¬£¬¸ÃÀÕË÷Èí¼þ²»ÊÇÍâµØ¾ÙÐмÓÃÜ£¬£¬£¬¶øÊÇÔ¶³Ì¼ÓÃܿɻá¼ûµÄSambaЧÀÍÆ÷ ¡£¡£¡£NamPoHyu»áËÑË÷¿É»á¼ûµÄÔ¶³ÌSambaЧÀÍÆ÷£¬£¬£¬±©Á¦ÆÆ½âÆäÃÜÂ룬£¬£¬È»ºóÔ¶³Ì¼ÓÃÜÆäÎļþ²¢ÊÍ·ÅÊê½ðƱ¾Ý ¡£¡£¡£ShodanÏÔʾÓнü50Íò¸ö¿É»á¼ûµÄSambaЧÀÍÆ÷¿ÉÄܳÉΪĿµÄ ¡£¡£¡£¸ÃÀÕË÷²¡¶¾Ê״ηºÆðÓÚ3Ô·Ý£¬£¬£¬ÆäÃû³ÆÎªMegaLocker£¬£¬£¬È»ºóÔÚ4Ô³õ¸üÃûΪNamPoHyu£¬£¬£¬²¢½«.NamPoHyuÀ©Õ¹Ãû¸½¼Óµ½¼ÓÃÜÎļþºó ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nampohyu-virus-ransomware-targets-remote-samba-servers/

6¡¢HawkeyeбäÖÖReborn v9£¬£¬£¬¿É¼Í¼¼üÅ̼°ÇÔÊØÐÅÏ¢


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


˼¿ÆTalos·¢Ã÷ÕýÔÚ·Ö·¢HawkEyeбäÖÖReborn v9µÄ´¹ÂÚ¹¥»÷»î¶¯ ¡£¡£¡£ÕâЩ´¹ÂÚÓʼþαװ³É·¢Æ±¡¢ÎïÁÏÇåµ¥¡¢¶©µ¥È·ÈϵÈÓªÒµÓʼþ£¬£¬£¬Ê¹ÓÃOffice´úÂëÖ´ÐÐÎó²îCVE-2017-11882À´ÏÂÔØ²¢ÔËÐÐHawkeye Reborn v9 ¡£¡£¡£¸ÃбäÖÖ¿ÉÒԼͼ¼üÅ̲¢ÇÔÈ¡ä¯ÀÀÆ÷¡¢¼ôÌù°åÖеÄÐÅÏ¢ºÍƾ֤£¬£¬£¬»¹¿ÉÒÔ½ØÈ¡×ÀÃæ¼°´ÓÉãÏñÍ·ÅÄÉãÕÕÆ¬ ¡£¡£¡£¸ÃбäÖÖÕýÔÚ×÷Ϊ¡°¸ß¼¶¼à¿Ø½â¾ö¼Æ»®¡±¾ÙÐгöÊÛ£¬£¬£¬»¹°üÀ¨¡°Ð§ÀÍÌõ¿îЭÒ顱£¬£¬£¬Õ¥È¡Âò¼ÒÔÚδ¾­ÔÊÐíµÄÇéÐÎÏÂʹÓøÃÈí¼þ£¬£¬£¬²¢Õ¥È¡Ê¹Ó÷À²¡¶¾Èí¼þɨÃèÆä¿ÉÖ´ÐÐÎļþ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/a-new-variant-of-hawkeye-keylogger-reborn-v9-arises-821b972a

ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí