¹È¸è±»Å·ÃË·£¿£¿£¿£¿î17ÒÚÃÀÔª£»£»£»£»Ê±¸ôÁ½ÄêPuTTYÐû²¼0.71°æ±¾£»£»£»£»¹¥»÷»î¶¯Bad Tidings

Ðû²¼Ê±¼ä 2019-03-21
1¡¢Ê±¸ôÁ½ÄêPuTTYÐû²¼0.71°æ±¾£¬£¬£¬£¬£¬£¬ÐÞ¸´8¸öÇå¾²Îó²î


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


±¾ÖÜPuTTYÐû²¼ÁËÊÊÓÃÓÚWindowsºÍUnixƽ̨µÄа汾0.71£¬£¬£¬£¬£¬£¬Õâ¾àÀëÆäÉÏÒ»¸ö°æ±¾µÄÐû²¼ÒÑÓнüÁ½ÄêµÄʱ¼ä¡£¡£¡£¡£¡£¡£¸Ãа汾ÐÞ¸´ÁË8¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬Îó²î¹æÄ£°üÀ¨Éí·ÝÑéÖ¤ÌáÐÑÐÅϢαÔì¡¢CHMÐ®ÖÆµ¼ÖµĴúÂëÖ´ÐС¢»º³åÇøÒç³ö¡¢¼ÓÃÜËæ»úÊýÖØÓá¢ÕûÊýÒç³öÒÔ¼°¾Ü¾øÐ§ÀÍ¡£¡£¡£¡£¡£¡£½¨ÒéÓû§´Ó¹ÙÍøÏÂÔØ¸Ãа汾¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/03/putty-software-hacking.html

2¡¢Google PhotosÎó²î¿Éµ¼ÖÂÓû§Î»ÖÃÐÅϢй¶


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ImpervaÇå¾²Ñо¿Ô±Ron Masas·¢Ã÷web°æGoogle Photos±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¶ñÒâÍøÕ¾Æ¾Ö¤Óû§ÕË»§Öд洢µÄÕÕÆ¬À´¸ú×ÙÓû§µÄλÖÃÐÅÏ¢¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬£¬Ê¹ÓûùÓÚä¯ÀÀÆ÷µÄʱÐò¹¥»÷£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÍÆ¶Ï³öÀ´×ÔÌØ¶¨µØÀíλÖõÄÕÕÆ¬ÊÇ·ñ±£´æÓÚÓû§µÄÕË»§ÖУ¬£¬£¬£¬£¬£¬¼´Óû§ÊÇ·ñ»á¼ûÁËÕâ¸ö¹ú¼Ò¡£¡£¡£¡£¡£¡£Í¨¹ýÈÕÏÞÆÚ¶¨£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÉõÖÁÄܹ»È·¶¨Óû§»á¼û¸Ã¹ú¼ÒµÄ´óÖÂʱ¼ä¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-photos-bug-exposed-the-location-and-time-of-your-pictures/

3¡¢¹È¸èÒò¹ã¸æÂ¢¶ÏÔÙ±»Å·ÃË·£¿£¿£¿£¿î17ÒÚÃÀÔª

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

3ÔÂ20ÈÕÅ·ÃËίԱ»áÐû²¼ÉùÃ÷¶Ô¹È¸èµÄ¹ã¸æÂ¢¶ÏÐÐΪ·£¿£¿£¿£¿î14.9ÒÚÅ·Ôª£¨Ô¼17ÒÚÃÀÔª£©£¬£¬£¬£¬£¬£¬ÕâÊÇÁ½ÄêÄÚÅ·Ã˶Թȸ迪³öµÄµÚÈýÕÅ´ó¶î·´Â¢¶Ï·£µ¥¡£¡£¡£¡£¡£¡£Å·ÃËίԱ»áÌåÏÖÕâÒ»·£¿£¿£¿£¿îµÄÔµ¹ÊÔ­ÓÉÊǹȸèÀÄÓÃÆäÊг¡Ö÷µ¼Ö°Î»£¬£¬£¬£¬£¬£¬×èÖ¹ÍøÒ³Ê¹ÓÃAdSenseƽ̨ÒÔÍâµÄ¹ã¸æÐ§ÀÍ£¬£¬£¬£¬£¬£¬ÕâÒ»·£½ðÏ൱Óڹȸè2018ÄêÓªÒµ¶îµÄ1.29%¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-fined-17-billion-for-anti-competitive-practices-in-online-advertising/

4¡¢MyPillowºÍAmerisleep³ÉΪMagecart¹¥»÷µÄ×îÐÂÊܺ¦Õß


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Çå¾²Ñо¿Ö°Ô±·¢Ã÷´²ÉÏÓÃÆ·ÁãÊÛÉÌMyPillowºÍAmerisleep³ÉΪMagecart¹¥»÷µÄ×îÐÂÊܺ¦Õß¡£¡£¡£¡£¡£¡£Í¬Ö®Ç°µÄ¹¥»÷Ò»Ñù£¬£¬£¬£¬£¬£¬Magecart¹¥»÷ÕßÔÚÕâÁ½¸ö¹ºÎïÍøÕ¾ÉÏÖ²ÈëÁËÓÃÓÚÇÔȡ֧¸¶ÐÅÏ¢µÄ¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£MyPillowÓÚ2018Äê10ÔÂÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬¶øAmerisleepÔòÔÚ2017Äê¡¢2018Äê12Ô¼°2019Äê1Ô¶¼Ôâµ½¹¥»÷¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬MyPillowºÍAmerisleep¶¼Ã»ÓÐÕë¶ÔÕâÒ»ÊÂÎñÏòÓû§·¢³öÈκÎÖÒÑÔ»ò¹Ù·½ÉùÃ÷¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/03/magecart-ecommerce-hackers.html

5¡¢Ð´¹ÂÚ¹¥»÷»î¶¯Bad Tidings£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÉ³ÌØ°¢À­²®


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


1Ô·ÝAnomali·¢Ã÷ð³äÉ³ÌØ°¢À­²®ÄÚÕþ²¿¹ÙÍøAbsherµÄ´¹ÂÚÍøÕ¾ÊýÄ¿¼¤Ôö¡£¡£¡£¡£¡£¡£½øÒ»²½Ñо¿Åú×¢ÕâÊÇÒ»¸öÕë¶ÔÉ³ÌØ°¢À­²®Ëĸö²î±ðµÄÕþ¸®»ú¹¹£¨ÄÚÕþ²¿¡¢Íâ½»²¿¡¢ÀͶ¯¼°Éç»áÉú³¤²¿¡¢Õþ¸®¹ÙÍø£©ÒÔ¼°Ò»¸ö½ðÈÚ»ú¹¹£¨É³µØÓ¢¹úÒøÐУ©µÄ¸üÆÕ±éµÄ´¹ÂÚ¹¥»÷»î¶¯Bad Tidings£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷»î¶¯¿É×·ËÝÖÁ2016Äê11ÔÂ⣬£¬£¬£¬£¬£¬¹²½¨ÉèÁËÁè¼Ý90¸ö´¹ÂÚÖ÷»úÃû£¨ÊôÓÚ46¸öÓòÃû£©¡£¡£¡£¡£¡£¡£ÕâЩÐéαÓòÃû´ó¶àÒÔ.cc¡¢.xyz¡¢.club¡¢.siteºÍ.services×îºó¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.anomali.com/blog/bad-tidings-phishing-campaign-impersonates-saudi-government-agencies-and-a-saudi-financial-institution

6¡¢Cardinal RATбäÖÖ£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÒÔÉ«ÁнðÈÚ¹«Ë¾


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Palo Alto NetworksµÄUnit 42ÍŶӷ¢Ã÷Cardinal RATµÄбäÖÖÕýÔÚÕë¶ÔÒÔÉ«ÁеĽðÈÚ¹«Ë¾¡£¡£¡£¡£¡£¡£¸Ã±äÖְ汾Ϊ1.7.2£¬£¬£¬£¬£¬£¬Æä½ÓÄÉÁ˶àÖÖ»ìÏýÊÖÒÕ£¬£¬£¬£¬£¬£¬°üÀ¨ÒþдÊõºÍXOR¼ÓÃܵÈ¡£¡£¡£¡£¡£¡£¸Ã±äÖֵĹ¦Ð§°üÀ¨ÍøÂçÐÅÏ¢¡¢¼üÅ̼ͼ¡¢ÆÁÄ»½ØÍ¼¡¢Ö´ÐжñÒâÏÂÁî¼°×ÔÎÒÐ¶ÔØµÈ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷¸Ã±äÖÖÓëÁíÒ»¸ö¶ñÒâÈí¼þ¼Ò×åEVILNUM±£´æ¹ØÁª¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/a-new-variant-of-cardinal-rat-employs-bmp-trick-to-target-israeli-financial-firms-e0cefbb0

ÉùÃ÷£º±¾×ÊѶÓÉÄϹ¬NGÓéÀÖάËûÃüÇ徲С×é·­ÒëºÍÕûÀí