Adobe´øÍâ¸üÐÂÐÞ¸´82¸öÎó²î£»£»£» £»£»£»£»½©Ê¬ÍøÂçPhorpiexÿСʱ¿É·¢ËÍ3Íò·âÕ©Æ­Óʼþ£»£»£» £»£»£»£»ÐéαCheckra1n iOSÔ½Óü

Ðû²¼Ê±¼ä 2019-10-17
1¡¢AdobeÐû²¼´øÍâÇå¾²¸üУ¬ £¬£¬ £¬ÐÞ¸´82¸öÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

AdobeÐû²¼´øÍâÇå¾²¸üУ¬ £¬£¬ £¬ÐÞ¸´AcrobatºÍReader¡¢Experience Manager¡¢Experience Manager FormsºÍDownload ManagerÖÐµÄ 82¸öÎó²î¡£¡£¡£ÆäÖÐ45¸öÎó²î±»ÆÀΪÑÏÖØ¼¶±ð£¬ £¬£¬ £¬ËüÃǶ¼±£´æÓÚAdobe AcrobatºÍReaderÖУ¬ £¬£¬ £¬²¢ÇÒÔÚÀÖ³ÉʹÓÃʱ¿Éµ¼ÖÂÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ÏêϸÀ´Ëµ£¬ £¬£¬ £¬ÓÐ26¸öÎó²îΪuse-after-freeÎó²î£¬ £¬£¬ £¬6¸öÎó²îÊÇÔ½½çд£¬ £¬£¬ £¬4¸öÎó²îÊÇÀàÐÍ»ìÏý¹ýʧ£¬ £¬£¬ £¬4¸öÎó²îÊDz»¿ÉÐŵÄÖ¸Õë½âÒýÓ㬠£¬£¬ £¬3¸öÊǶÑÒç³ö£¬ £¬£¬ £¬1¸öÊÇ»º³åÇøÒç³ö£¬ £¬£¬ £¬1¸öÊǾºÕùÌõ¼þÎÊÌâ¡£¡£¡£Adobe Flash PlayerÕâ´ÎûÓÐÊÕµ½Çå¾²²¹¶¡£¬ £¬£¬ £¬Ó¦¸Ã×¢ÖØµÄÊÇ£¬ £¬£¬ £¬Adobe½«ÔÚ2020Äêµ××èÖ¹Ìṩ¶ÔFlash PlayerµÄ¸üС£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/10/adobe-software-patches.html


2¡¢ÈüÃÅÌú¿ËÖÕ¶ËÇå¾²²úÆ·µÄ¸üе¼ÖÂÓû§×°±¸À¶ÆÁ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ÈüÃÅÌú¿ËΪÆäEndpoint Protection²úÆ·ÍÆ³öµÄÈëÇÖ¼ì²âÊðÃû¸üе¼ÖÂÓû§×°±¸·ºÆðÍ߽ⲢÏÔʾÀ¶ÆÁ£¨BSOD£©¡£¡£¡£¸ÃÎÊÌâÓ°ÏìÁËWin 7¡¢Win8¼°Win 10£¬ £¬£¬ £¬Æ¾Ö¤ÈüÃÅÌú¿ËµÄ±íÊö£¬ £¬£¬ £¬ÔÚÔËÐÐLiveUpdateʱEndpoint Protection Client»áÏÔʾéæÃüÀ¶ÆÁ£¬ £¬£¬ £¬²¢ÏÔʾIDSvix86.sys/IDSvia64.sys·ºÆðÎÊÌ⣬ £¬£¬ £¬µ¼ÖÂBAD_POOL_CALLER (c2)»òKERNEL_MODE_HEAP_CORRUPTION (13A)Òì³£¡£¡£¡£¸Ã¹«Ë¾»¹Ôö²¹³ÆÊÜÓ°ÏìµÄÈëÇÖ¼ì²âµÄÊðÃû°æ±¾Îª2019/10/14 r61£¬ £¬£¬ £¬¸ÃÎÊÌâÒÑÔÚа汾2019/10/14 r62Öнâ¾ö¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/symantec-fixes-bad-ips-definitions-that-cause-a-windows-bsod/

3¡¢·ðÂÞÀï´ïÖÝÒ»¼ÒÅ®ÐÔÕïËù½ü52Íò»¼ÕßÐÅÏ¢¿ÉÄÜй¶

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

·ðÂÞÀï´ïÖÝÒ»¼ÒרΪŮÐÔÌṩҽÁÆÐ§À͵ÄÕïËùÖÒÑÔÆä52.8Íò»¼ÕßËýÃǵÄСÎÒ˽¼ÒÊý¾ÝºÍÒ½ÁƼͼ¿ÉÄÜÒѾ­Ð¹Â¶¡£¡£¡£±±·ðÂÞÀï´ïÖÝOB-GYNÔÚ7ÔÂ27ÈÕÒâʶµ½ÍøÂç¹¥»÷µÄ±¬·¢£¬ £¬£¬ £¬²¢ÓëµÚÈý·½ÊÖÒÕÕÕÁÏÏàÖúÍê³ÉÁËÆðԴϵͳÆÀ¹À¡£¡£¡£ÆÀ¹ÀÅú×¢Æä²¿·ÖÅÌËã»úϵͳÔâµ½²»µ±»á¼û²¢ÇÒijЩÎļþÒѱ»²¡¶¾¼ÓÃÜ¡£¡£¡£ÆÀ¹ÀÒÔΪ¸Ã¹¥»÷ÊÂÎñ±¬·¢ÔÚ2019Äê4ÔÂ29ÈÕ֮ǰ¡£¡£¡£¸ÃÕïËù¹Ø±ÕÁËϵͳ²¢Æô¶¯ÁËÊÂÎñÏìÓ¦ºÍ»Ö¸´³ÌÐò¡£¡£¡£ÊÜÊÂÎñÓ°ÏìµÄÐÅÏ¢°üÀ¨»¼ÕßµÄÐÕÃû¡¢ÈºÌåÌØÕ÷¡¢³öÉúÈÕÆÚ¡¢Éç»áÇå¾²ºÅÂë¡¢¼ÝÕÕ¼°Éí·ÝID¡¢¾ÍÒµÐÅÏ¢¡¢Ò½Áưü¹ÜÐÅÏ¢¼°ÖÎÁÆ¡¢Õï¶Ï¡¢Ò½Ñ§Í¼ÏñµÈÒ½ÁÆÐÅÏ¢£¬ £¬£¬ £¬µ«²»°üÀ¨ÈκÎÐÅÓÿ¨»òÒøÐп¨ÐÅÏ¢¡£¡£¡£ÏÖÔÚÏÕЩËùÓмÓÃܵÄÎļþ¶¼Òѻָ´¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/florida-womens-clinic-data-breach/

4¡¢½©Ê¬ÍøÂçPhorpiexÿСʱ¿É·¢ËÍ3Íò·âÕ©Æ­Óʼþ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ÔÚCheck PointµÄÒ»·Ýб¨¸æÖУ¬ £¬£¬ £¬Ñо¿Ö°Ô±ÆÊÎöÁ˽©Ê¬ÍøÂçPhorpiex̫ͨ¹ý·¢ÊýÒÔ°ÙÍò¼ÆµÄsextortionÕ©Æ­ÓʼþÀ´±¬·¢¿É¹ÛµÄÊÕÈë¡£¡£¡£PhorpiexÒÑÓнüÊ®ÄêµÄÀúÊ·£¬ £¬£¬ £¬ËüÒ²±»³ÆÎªTrik£¬ £¬£¬ £¬ÊÇÒ»ÖÖͨ¹ýµç×ÓÓʼþÈö²¥µÄÈ䳿¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷¸Ã½©Ê¬ÍøÂçÔÚ2019ÄêÌí¼ÓÁËÒ»¸öеÄÓÐÓøºÔØ-À¬»øÓʼþ»úеÈË¡£¡£¡£ÔÚ×°Öúó£¬ £¬£¬ £¬¸ÃbotÄ£¿ £¿ £¿£¿é½«ÅþÁ¬µ½C2ЧÀÍÆ÷£¬ £¬£¬ £¬ÏÂÔØ°üÀ¨´ó×Úµç×ÓÓʼþµØµãµÄÊý¾Ý¿â£¬ £¬£¬ £¬ÏòÊý°ÙÍòDZÔÚÊܺ¦Õß·¢ËÍÓʼþ¡£¡£¡£ÆäÖÐһЩC2¾ßÓÐ325µ½1363¸öÊý¾Ý¿â£¬ £¬£¬ £¬Ã¿¸öÊý¾Ý¿â°üÀ¨×î¶à2Íò¸öµç×ÓÓʼþµØµã¡£¡£¡£·¢ËÍÀ¬»øÓʼþʱ£¬ £¬£¬ £¬Phorpiex½«½¨Éè1.5Íò¸öỊ̈߳¬ £¬£¬ £¬Check PointÔ¤¼Æµ¥¸öÊÜѬȾµÄ×°±¸Ã¿Ð¡Ê±¿ÉÒÔ·¢ËͶà´ï3Íò·âÓʼþ¡£¡£¡£×Ô2019Äê4ÔÂÒÔÀ´£¬ £¬£¬ £¬Ñо¿Ö°Ô±¼à¿ØÁ˹¥»÷ÕßµÄ74¸ö±ÈÌØ±ÒµØµã£¬ £¬£¬ £¬·¢Ã÷¹¥»÷Õß¹²¼Æ»ñµÃ157±Ê¸¶¿î£¬ £¬£¬ £¬×ܼÆ11.99545¸ö±ÈÌØ±Ò¡£¡£¡£ÒÔ½ñÌìµÄ¼ÛÇ®ÅÌË㣬 £¬£¬ £¬ÆäÊÕÈëÔÚ6¸öÔÂÄÚԼεִï9.5ÍòÃÀÔª£¬ £¬£¬ £¬¼´Ã¿ÔÂÊÕÈë1.6ÍòÃÀÔª¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/malware-uses-your-pc-to-send-30k-sextortion-emails-per-hour/

5¡¢TA505ÔÚй¥»÷»î¶¯Öзַ¢ÏÂÔØÆ÷Get2¼°SDBbot RAT

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ProofpointÑо¿Ö°Ô±·¢Ã÷£¬ £¬£¬ £¬´Ó2019Äê9ÔÂ×îÏȺڿÍ×éÖ¯TA505ÔÚÆä´¹ÂÚ¹¥»÷»î¶¯Öзַ¢ÁËÁ½ÖÖеĶñÒâÈí¼þ£¬ £¬£¬ £¬°üÀ¨ÏÂÔØÆ÷Get2ºÍÔ¶¿ØÄ¾ÂíSDBbot¡£¡£¡£ÐµÄGet2»ùÓÚC++£¬ £¬£¬ £¬¹¥»÷Õßͨ¹ýËü·Ö·¢FlawedGrace¡¢FlawedAmmyy¡¢SnatchºÍеÄSDBbot RATÆ·¼¶¶þ½×¶Îpayload¡£¡£¡£9Ô³õ¸Ã¹¥»÷»î¶¯Ö÷ÒªÕë¶ÔÏ£À°¡¢ÐÂ¼ÓÆÂ¡¢°¢ÁªÇõ¡¢¸ñ³¼ªÑÇ¡¢ÈðµäºÍÁ¢ÌÕÍðµÈ¹ú¼ÒµÄ½ðÈÚ»ú¹¹£¬ £¬£¬ £¬9ÔÂ20ºÅ×îÏȳÉǧÉÏÍò·âÓ¢ÓïºÍ·¨Óï´¹ÂÚÓʼþ±»·¢Ë͸øÃÀ¹úºÍ¼ÓÄôó¶à¸öÐÐÒµµÄÆóÒµ£¬ £¬£¬ £¬10ÔÂ7ºÅ×îÏȹ¥»÷ÕßʹÓöÌÁ´½ÓÀ´¾ÙÐÐÌø×ª£¬ £¬£¬ £¬²¢Çл»µ½ÐµÄSDBbot RAT¡£¡£¡£SDBbotҲʹÓÃC++¿ª·¢£¬ £¬£¬ £¬ËüÊÇÒ»¸öÄ£¿ £¿ £¿£¿é»¯µÄ¶ñÒâÈí¼þ£¬ £¬£¬ £¬¾ßÓÐÏÂÁîÐÐshell¡¢ÆÁÄ»Â¼ÖÆ¡¢Ô¶³Ì×ÀÃæ¡¢¶Ë¿Úת·¢ºÍÎļþ»á¼ûµÈµä·¶RAT¹¦Ð§£¬ £¬£¬ £¬²¢Í¨¹ýTCP¶Ë¿Ú443¾ÙÐÐͨѶ¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-sdbot-remote-access-trojan-used-in-ta505-malspam-campaigns/

6¡¢¹¥»÷ÕßʹÓÃÐéαCheckra1n iOSÔ½ÓüÌᳫµã»÷ڲƭ¹¥»÷

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

˼¿ÆTalosµÄÑо¿Ö°Ô±·¢Ã÷£¬ £¬£¬ £¬¹¥»÷ÕßÕýÔÚʹÓÃÐéαµÄCheckra1n iOSÔ½ÓüÀ´Ìᳫµã»÷ڲƭ»î¶¯¡£¡£¡£checkra1nÉù³ÆÊ¹ÓÃÁËÑо¿Ö°Ô±×î½üÅû¶µÄiOSÔ½ÓüÎó²îbootrom¡£¡£¡£¹¥»÷Õß½¨ÉèÁËÒ»¸öÐéαµÄcheckrain[.]comÍøÕ¾£¬ £¬£¬ £¬Éù³Æ¿ÉÒÔ×ÊÖúiPhoneÓû§Ô½Óü£¬ £¬£¬ £¬µ«ÏÖʵÉÏÒªÇóÓû§ÏÂÔØ¶ñÒâµÄ¡°mobileconfig¡±ÉèÖÃÎļþ£¬ £¬£¬ £¬×îÖÕÔÊÐí¹¥»÷Õß¾ÙÐеã»÷ڲƭ¹¥»÷¡£¡£¡£¸Ã¹¥»÷Ö÷Ҫͨ¹ýÔÚÓû§µÄiOS×°±¸ÉϾÙÐжà´ÎÖØ¶¨ÏòÀ´¾ÙÐУ¬ £¬£¬ £¬ÔÚÕâ¸öÀú³ÌÖУ¬ £¬£¬ £¬Óû§½«ÂÄÀúÖÖÖÖ¹ã¸æ¸ú×Ù¡¢ÑéÖ¤ºÍÌṩµØÀíλÖõÄÑ­»·£¬ £¬£¬ £¬×îÖÕ×°ÖÃÒ»¸öÓÐÄÚ¹º¹¦Ð§µÄiOSÀÏ»¢»úÓÎÏ·¡£¡£¡£´Ë´Î¹¥»÷µÄÄ¿µÄÖ÷ÒªÊÇÃÀ¹ú£¬ £¬£¬ £¬Æä´ÎÊÇÓ¢¹ú¡¢·¨¹ú¡¢ÄáÈÕÀûÑǵȡ£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/scammers-use-fake-checkra1n-ios-jailbreak-in-click-fraud-campaign/