¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190130

Ðû²¼Ê±¼ä 2019-01-30
1¡¢FaceTimeÆØÖØ´óÇÔÌýÎó²î£¬£¬£¬£¬£¬AppleÌåÏÖ½«ÔÚ±¾ÖÜÐÞ¸´

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


¾ÝÍâý±¨µÀ£¬£¬£¬£¬£¬Apple FaceTime±£´æÖØ´óÇå¾²Îó²î£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÄ¿µÄ½ÓÌý»ò¾Ü¾øFaceTimeͨ»°Ö®Ç°¼àÌý¶Ô·½µÄÉùÒô¡£¡£¡£ÈôÊǶԷ½°´ÏÂÒôÁ¿½µµÍ°´Å¥»òµçÔ´°´Å¥À´¾²Òô»ò×÷·Ïͨ»°£¬£¬£¬£¬£¬ÔòÆäǰÖÃÉãÏñÍ·Ò²»á·­¿ª£¬£¬£¬£¬£¬²¢½«ÊÓÆµÐźŷ¢Ë͸ø¹¥»÷Õß¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬¸ÃÎó²î»á·ºÆðÔÚiOS 12.1»ò¸ü¸ß°æ±¾µÄiOS×°±¸ÖС£¡£¡£AppleÒѾ­ÔÝʱ½ûÓÃÁËFaceTimeÖеÄȺ×éͨ»°¹¦Ð§£¬£¬£¬£¬£¬²¢ÌåÏÖ½«ÔÚ±¾ÖÜÍíЩʱ¼äÐû²¼ÐÞ¸´²¹¶¡¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/apple-facetime-privacy-hack.html


2¡¢°Ä´óÀûÑÇ8¼ÒÍйÜЧÀÍÉÌÔâÓö¹¥»÷»î¶¯Manic Menagerie

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾



ƾ֤°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄ£¨ACSC£©Ðû²¼µÄÒ»·Ý±¨¸æ£¬£¬£¬£¬£¬8¸öÍйÜЧÀÍÉÌÔÚ2018ÄêÔâÓö¶ñÒâ¹¥»÷»î¶¯Manic Menagerie¡£¡£¡£¹¥»÷ÕßʹÓÃWebÓ¦ÓÃÖеÄÎó²îÀ´»ñÈ¡WebЧÀÍÆ÷µÄrootȨÏÞ£¬£¬£¬£¬£¬²¢×°ÖÃÃÜÂëÇÔÈ¡¹¤¾ßºÍGh0st RAT¡£¡£¡£ÆäÖÐÒ»¸ö±»Ê¹ÓõÄÎó²îÊÇ2018Äê4Ô¹ûÕæµÄÌáȨÎó²îTotalMeltdown£¨CVE-2018-1038£©¡£¡£¡£ACSCÒѽ¨ÒéÕâЩÍйÜЧÀÍÉ̸øWebÓ¦ÓúÍCMS´ò²¹¶¡ºÍ½ûÓöñÒâ²å¼þ£¬£¬£¬£¬£¬²¢ÖØÖÃÓû§µÄƾ֤¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/eight-australian-web-hosting-providers-compromised-in-manic-menagerie-attack-campaign-8ee4259a 


3¡¢AZORultľÂíαװ³É¹È¸è¸üгÌÐò£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡Óû§Æ¾Ö¤

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


À´×ÔMinerva Labs¡¢Asaf AprozperºÍGal BitenskyµÄÑо¿Ö°Ô±ÊӲ쵽AZORultľÂíͨ¹ýαװ³ÉGoogle Updater³ÌÐòÀ´ÊµÏÖ³¤ÆÚÐÔ¡£¡£¡£AZORultľÂíÖ÷ÒªÓÃÓÚÇÔÈ¡Óû§µÄÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬°üÀ¨Îļþ¡¢ÃÜÂë¡¢cookie¡¢ä¯ÀÀÆ÷ÀúÊ·¼Í¼¡¢ÒøÐÐÆ¾Ö¤ºÍ¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡£¡£¡£ÓÉÓÚAZORultαװ³ÉGoogle Updater³ÌÐò£¬£¬£¬£¬£¬Ëü½«ÒÔÖÎÀíԱȨÏÞÔËÐС£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÕâЩ¶ñÒâµÄGoogleUpdate.exeÎļþʹÓÃÁËÓÐÓõÄÖ¤Êé¾ÙÐÐÊðÃû£¬£¬£¬£¬£¬µ«¸ÃÖ¤ÊéÏÖʵÉϱ»½ÒÏþ¸ø¡°Singh Agile Content Design Limited¡±£¬£¬£¬£¬£¬¶ø²»ÊÇGoogle¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/azorult-trojan-disguised-as-google-update-installer-steals-credentials-6e225ab6


4¡¢¶ñÒâÈí¼þFormBook»Ø¹é£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹úÁãÊÛºÍÂùÝÒµ

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ƾ֤Deep InstinctµÄ±¨¸æ£¬£¬£¬£¬£¬FormBookÕýÔÚʹÓÃÒ»¸öеÄÎļþÍйÜЧÀÍÈö²¥£¬£¬£¬£¬£¬Ö÷Òª¹¥»÷ÃÀ¹úµÄÁãÊÛºÍÂùÝÒµ¡£¡£¡£FormBook×îÔç·ºÆðÓÚ2016Ä꣬£¬£¬£¬£¬¿ÉÒÔÇÔÈ¡Óû§µÄƾ֤¡¢½ØÈ¡×ÀÃæÆÁÄ»ÒÔ¼°¼Í¼¼üÅ̵ȡ£¡£¡£ÔÚÕâ¸öеĶñÒâ»î¶¯ÖУ¬£¬£¬£¬£¬FormBookͨ¹ý´¹ÂÚÓʼþÖеÄRTF¸½¼þÈö²¥£¬£¬£¬£¬£¬¸Ã¸½¼þʹÓÃÁËCVE-2012-0158¡¢CVE-2017-11882µÈOfficeÎó²î¡£¡£¡£FormBook»¹Ê¹ÓÃÁËÒ»¸öеÄÎļþÍйÜЧÀÍDropMyBin£¬£¬£¬£¬£¬¸ÃÎļþÍйÜЧÀÍÒ²±»ÆäËü¶ñÒâÈí¼þʹÓ㬣¬£¬£¬£¬ÀýÈçLokibotºÍAzorult¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.deepinstinct.com/2019/01/27/info-stealer-formbook-continues-activity-and-uses-a-new-malware-friendly-file-hosting-service/


5¡¢·ÆÂɱöµçÐŹ«Ë¾GlobeÒâÍâй¶8851Ãû¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ƾ֤BestVPN.comµÄ±¨¸æ£¬£¬£¬£¬£¬·ÆÂɱöµçÐŹ«Ë¾GlobeÔÚ½üÆÚµÄÍÆ¹ã×¢²á»î¶¯ÖУ¬£¬£¬£¬£¬ÒâÍâÏòÐÂ×¢²áµÄÓû§ÓÊÏä·¢ËÍÁËÆäËüÓû§¼òÖ±ÈÏÓʼþ£¬£¬£¬£¬£¬µ¼Ö²¿·Ö¿Í»§µÄÃô¸ÐÊý¾Ýй¶¡£¡£¡£ÕâЩÊý¾Ý°üÀ¨¿Í»§µÄÐÕÃû¡¢µç×ÓÓÊÏ䵨µãºÍÍêÕûµÄÓÊÕþµØµã£¬£¬£¬£¬£¬¹²ÓÐ8851Ãû¿Í»§Êܵ½Ó°Ïì¡£¡£¡£¸Ã¹«Ë¾ÒѾ­Ö¤ÊµÁËÕâÒ»ÊÂÎñ£¬£¬£¬£¬£¬²¢Æ¾Ö¤î¿ÏµÒªÇó֪ͨÁ˹ú¼ÒÒþ˽±£»£»£»¤Î¯Ô±»á£¨NPC£©¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/filipino-telecom-giant-globe-inadvertently-leaks-personal-data-of-8851-subscribers-e87bb87b


6¡¢ÐÂ¼ÓÆÂÔ¼1.4Íò°¬×̲¡»¼ÕßÐÅϢй¶£¬£¬£¬£¬£¬ÏÓ·¸ÎªÃÀ¼®ÄÐ×Ó

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

2019Äê1ÔÂ28ÈÕ£¬£¬£¬£¬£¬ÐÂ¼ÓÆÂÎÀÉú²¿ÔÚÒ»·ÝÉùÃ÷ÖÐ֤ʵÃÀ¹úÄÐ×ÓMikhy K Farrera Brochez²»·¨»ñÈ¡²¢Ð¹Â¶ÁËÔ¼1.42Íò°¬×̲¡»¼ÕßµÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£ÆäÖÐ5400Ãû»¼ÕßÊÇÐÂ¼ÓÆÂÈË£¬£¬£¬£¬£¬8800Ãû»¼ÕßÊÇÍâ¹úÈË¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨»¼ÕßµÄÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢µç»°ºÅÂë¡¢µØµã¡¢HIV¼ì²âЧ¹ûºÍÏà¹ØÒ½ÁÆÐÅÏ¢µÈ¡£¡£¡£ÕâЩÊý¾ÝÊÇBrochezÖØÐÂ¼ÓÆÂµÄ°¬×̲¡¹ÒºÅ´¦ÇÔÈ¡µÄ¡£¡£¡£2017Äê3Ô£¬£¬£¬£¬£¬BrochezÔÚÐÂ¼ÓÆÂ±»¿ØÚ²Æ­µÈ¶àÏî×ïÃû£¬£¬£¬£¬£¬²¢ÔÚ·þÐ̺ó±»ÇýÖð³ö¾³¡£¡£¡£2019Äê1ÔÂ22ÈÕ£¬£¬£¬£¬£¬ÐÂ¼ÓÆÂÎÀÉú²¿·¢Ã÷ÉÏÊö»¼Õß×ÊÁÏÔÚÍøÉϱ»Ð¹Â¶ºó±¨¾¯¡£¡£¡£ÏÖÔÚÍâµØ¾¯ÆÓÖ±ÔÚ×·Çó¶Ô´Ë°¸¾ÙÐйú¼ÊÊӲ졣¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/private-data-of-almost-14200-patients-diagnosed-with-hiv-leaked-online-de45a837


ÉùÃ÷£º±¾×ÊѶÓÉÄϹ¬NGÓéÀÖάËûÃüÇ徲С×é·­ÒëºÍÕûÀí