¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180905

Ðû²¼Ê±¼ä 2018-09-05

¡¾Õþ²ß¹æÔò¡¿¹¤ÐŲ¿Ðû²¼2018ÄêµÚ¶þ¼¾¶ÈÍøÂçÇå¾²ÍþÐ²Ì¬ÊÆÆÊÎöÓëÊÂÇé×ÛÊö


¹¤ÐŲ¿Ðû²¼µÄµÚ¶þ¼¾¶ÈÍøÂçÇå¾²ÍþÐ²Ì¬ÊÆÈçÏ£ºµÚ¶þ¼¾¶È¹²¼à²âÍøÂçÇå¾²ÍþвԼ1841Íò¸ö£¬£¬ÆäÖлù´¡µçÐÅÆóÒµ¼à²âÔ¼1683Íò¸ö£¬£¬ÍøÂçÇ徲רҵ»ú¹¹¼à²âÔ¼3Íò¸ö£¬£¬Öص㻥ÁªÍøÆóÒµ¡¢ÓòÃû»ú¹¹ºÍÍøÂçÇå¾²ÆóÒµ¼à²âÔ¼155Íò¸ö¡£¡£¡£ÍøÂçÇå¾²ÍþÐ²Ì¬ÊÆ·ºÆðÒÔϼ¸¸öÌØµã£º£¨Ò»£©²¿·Ö»¥ÁªÍøÓû§ÓÊÏäÒÉËÆ±»¿Ø£¬£¬ÑÏÖØÎ£º¦Óû§Ð¡ÎÒ˽¼ÒÐÅÏ¢Çå¾²¡£¡£¡££¨¶þ£©¹¤Òµ»¥ÁªÍøÆ½Ì¨ºÍÖÇÄÜ×°±¸³ÉÎªÍøÂçÍþвµÄÖ÷ҪĿµÄ¡£¡£¡££¨Èý£©²»·¨¡°ÍÚ¿ó¡±ÑÏÖØÍþв»¥ÁªÍøÍøÂçÇå¾²¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttp://www.miit.gov.cn/n1146285/n1146352/n3054355/n3057724/n3057728/c6363487/content.html


¡¾Êý¾Ýй¶¡¿Ñо¿Ö°Ô±·¢Ã÷Ô¼57ÍòMortal OnlineÓÎÏ·Íæ¼ÒµÄƾ֤ÔÚÂÛ̳³öÊÛ


Çå¾²Ñо¿Ö°Ô±Adam Davies·¢Ã÷ÊôÓÚÔ¼57ÍòMortal OnlineÓÎÏ·Íæ¼ÒµÄÕË»§ÐÅÏ¢ÔÚÂÛ̳ÉϳöÊÛ¡£¡£¡£2018Äê6ÔÂ17ÈÕδ¾­ÊÚȨµÄµÚÈý·½»á¼ûÁ˸ÃÓÎÏ·µÄÂÛ̳ºÍÊÐËÁÊý¾Ý¿âµÄЧÀÍÆ÷²¢ÇÔÈ¡ÁËÓû§µÄÊý¾Ý¡£¡£¡£¹¥»÷Õß»¹»ñÈ¡ÁËÓû§ÃÜÂëµÄMD5¹þÏ£Öµ£¬£¬ÕâЩ¹þÏ£ÖµËÆºõÒѱ»ÆÆ½â¡£¡£¡£¸ÃÊý¾Ý¿âÏÖÔÚÒѱ»Ìí¼Óµ½Have I Been PwnedÍøÕ¾ÖС£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cracked-logins-of-570-000-mortal-online-players-sold-on-forums/


¡¾Êý¾Ýй¶¡¿¼Ò³¤¼à¿ØÈí¼þFamily OrbitÔâºÚ¿ÍÈëÇÖ£¬£¬Êý°ÙÃû¶ùͯµÄÕÕÆ¬¿ÉÄÜй¶


¼Ò³¤¼à¿ØÓ¦ÓÃFamily OrbitµÄÔÆÐ§ÀÍÆ÷Ôâµ½ºÚ¿Í¹¥»÷£¬£¬Ô¼281GBÊý¾ÝÒÉÔâй¶¡£¡£¡£¹¥»÷Õß·¢Ã÷¸ÃÔÆÐ§ÀÍÆ÷±£´æÈõÃÜÂëÎó²î£¬£¬Ê¹ÓøÃÎó²î¿É»ñÈ¡Êý°ÙÃû¶ùͯµÄÕÕÆ¬µÄ»á¼ûȨÏÞ¡£¡£¡£Family Orbit¹«Ë¾È·ÈÏÁ˸ÃÊý¾Ýй¶ÊÂÎñ£¬£¬²¢Á¬Ã¦¸ü¸ÄÁËAPIÃÜÔ¿ºÍµÇ¼ƾ֤¡£¡£¡£¸Ã¹«Ë¾³ÆÒÑ×èÖ¹ÏúÊÛºÍЧÀÍ£¬£¬Ö±µ½È·±£ËùÓеÄÎó²î¶¼»ñµÃÐÞ¸´¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75888/data-breach/family-orbit-hacked.html


¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷Ö÷ÒªÕë¶Ô°ÍÎ÷ÒøÐеĶñÒâÈí¼þCamuBot


IBM X-ForceÑо¿ÍŶÓÊӲ쵽һ¸öÖ÷ÒªÕë¶Ô°ÍÎ÷ÒøÐеÄжñÒâÈí¼þCamuBot¡£¡£¡£CamuBotÓÚ2018Äê8Ô·ºÆð£¬£¬Ö÷ÒªÕë¶Ô°ÍÎ÷µÄÆóÒµºÍ¹«¹²²¿·Ö£¬£¬Æäαװ³ÉÄ¿µÄÒøÐеÄÇ徲ģ¿£¿£¿£¿é¾ÙÐÐÈö²¥¡£¡£¡£¹¥»÷Õßαװ³ÉÒøÐеÄÔ±¹¤£¬£¬Í¨¹ýµç»°Ö¸Ê¾Êܺ¦Õßä¯ÀÀÒ»¸öURLÒÔ¼ì²éÆäÇ徲ģ¿£¿£¿£¿éÊÇ·ñÊÇ×îеÄ¡£¡£¡£CamuBotµÄ¹¥»÷»î¶¯ÊÇÓÐÕë¶ÔÐԵġ£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://securityintelligence.com/camubot-new-financial-malware-targets-brazilian-banking-customers/


¡¾Çå¾²²¥±¨¡¿¾Ý±¨µÀ¹È¸èÓëÍòÊ´ïÉñÃØÏàÖúÒÔ¸ú×ÙÓû§µÄÏûºÄ¼Í¼


¾ÝÅí²©É籨µÀ£¬£¬¹È¸èÏòÍòÊ´│¹«Ë¾Ö§¸¶ÁËÊý°ÙÍòÃÀÔªÒÔ»ñÈ¡Óû§¹ºÎïµÄÊý¾Ý¡£¡£¡£Á½¼Ò¹«Ë¾¾­ÓÉ4ÄêµÄ̸ÅУ¬£¬¸æ¿¢ÁËÒ»±Ê·Ç¹ûÕæµÄÉúÒâ¡£¡£¡£¹È¸èʹÓÃÕâЩÓû§µÄÏßϹºÎïÊý¾ÝΪ¹ã¸æÖ÷¿ª·¢¹¤¾ß£¬£¬Ï¸·Ö³öÄÇЩµã»÷¹ýÔÚÏß¹ã¸æ£¬£¬ËæºóÔÚÏßÏÂʵÌåµê¹ºÖÃÉÌÆ·µÄÖ÷¹Ë¡£¡£¡£¹È¸è¾Ü¾øÖ¤ÊµÓëÍòÊ´│¹«Ë¾µÄÏàÖú¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/09/google-mastercard-advertising.html


¡¾Îó²î²¹¶¡¡¿¼à¿ØÈí¼þOpsview MonitorÐû²¼Çå¾²¸üУ¬£¬ÐÞ¸´5¸öÎó²î


SecureAuthºÍCoreSecurityÅû¶¼à¿ØÈí¼þOpsview MonitorÖеÄ5¸öÇå¾²Îó²î£¬£¬°üÀ¨XSSÎó²î£¨CVE-2018-16147ºÍCVE-2018-16148£©¡¢¿Éµ¼ÖÂÏÂÁîÖ´ÐеÄÎó²î£¨CVE-2018-16146ºÍCVE-2018-16144£©ÒÔ¼°ÍâµØÌáȨÎó²î£¨CVE-2018-16145£©¡£¡£¡£Opsview Monitor°æ±¾4.2¡¢5.3ºÍ5.4Êܵ½Ó°Ï죬£¬½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/multiple-remote-code-execution-flaws-patched-in-opsview-monitor/137170/