¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180925
Ðû²¼Ê±¼ä 2018-09-25¡¾ÆÊÎö±¨¸æ¡¿¿¨°Í˹»ùÐû²¼¹ØÓÚICSϵͳÖеÄRATΣº¦µÄÆÊÎö±¨¸æ
¿¨°Í˹»ùʵÑéÊÒÐû²¼¹ØÓÚICSÖеÄRATΣº¦µÄÆÊÎö±¨¸æ¡£¡£¡£Ô¶³ÌÖÎÀí¹¤¾ß£¨RAT£©±»ÆÕ±éÓÃÓÚ¹¤ÒµÍøÂçÖ®ÖУ¬£¬£¬£¬£¬£¬ÓÃÓÚ¾ÙÐÐICS¼à²â¡¢¿ØÖƺÍά»¤¡£¡£¡£Ô¶³Ì²Ù×÷ICSµÄÄÜÁ¦¿ÉÒÔ´ó´ó½µµÍά»¤±¾Ç®£¬£¬£¬£¬£¬£¬µ«²»ÊÜ¿ØÖƵÄÔ¶³Ì»á¼û¡¢ÎÞ·¨100%µØÌṩԶ³Ì¿Í»§¶ËµÄÕýµ±ÐÔÑéÖ¤ÒÔ¼°RAT´úÂëºÍÉèÖÃÖеÄÎó²î¶¼´ó´óÔöÌíÁ˹¥»÷Ãæ¡£¡£¡£Óë´Ëͬʱ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔ½À´Ô½¶àµØÊ¹ÓÃRATºÍÆäËüÕýµ±¹¤¾ßÀ´ÑÚÊÎÆä¶ñÒâ»î¶¯£¬£¬£¬£¬£¬£¬Ê¹µÃ¶Ô¶ñÒâ»î¶¯¾ÙÐйéÒòÔ½·¢ÄÑÌâ¡£¡£¡£
https://securelist.com/threats-posed-by-using-rats-in-ics/88011/
¡¾Îó²î²¹¶¡¡¿Î÷ÊýÐû²¼NAS×°±¸µÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´Ò»¸öÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î
Î÷ÊýÐû²¼My Cloud NAS×°±¸µÄ¹Ì¼þ¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´Éí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2018-17153£©¡£¡£¡£¸ÃÎó²îÔÊÐí¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤²¢»ñµÃ×°±¸µÄÖÎÀíԱȨÏÞ¡£¡£¡£¸ÃÎó²îÓÉSecurifyµÄÑо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬²¢ÓÚ2017Äê4Ô±¨¸æ¸øÎ÷Êý£¬£¬£¬£¬£¬£¬µ«Î÷ÊýÔÚ³¤´ïÒ»Äê¶àµÄʱ¼äÀïһֱûÓоÙÐÐÈκλظ´¡£¡£¡£ÔÚ¾ÓÉÆÕ±éµÄýÌ屨µÀºó£¬£¬£¬£¬£¬£¬Î÷ÊýÐû²¼Á˸ÃÎó²îµÄÏà¹ØÐÞ¸´²¹¶¡¡£¡£¡£
https://www.bleepingcomputer.com/news/security/western-digital-releases-hotfix-for-my-cloud-auth-bypass-vulnerability/
¡¾Çå¾²Îó²î¡¿Ñо¿Ö°Ô±·¢Ã÷FireFox±£´æÐÂbug£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂä¯ÀÀÆ÷ºÍ²Ù×÷ϵͳÍß½â
WireÇå¾²Ñо¿Ö°Ô±Sabri Haddouche·¢Ã÷FirefoxÖеÄÒ»¸öÐÂbug£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂä¯ÀÀÆ÷Í߽⣬£¬£¬£¬£¬£¬ÔÚijЩÇéÐÎÏÂÉõÖÁ»áµ¼Öµײã²Ù×÷ϵͳÍ߽⡣¡£¡£ÆäÔµ¹ÊÔÓÉÊǶñÒâJavaScript¾ç±¾»áÌìÉúÒ»¸öÎļþ£¨blob£©£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Ò»¸öºÜÊdz¤µÄÎļþÃû£¬£¬£¬£¬£¬£¬²¢ÌáÐÑÓû§Ã¿¸ôÒ»ºÁÃëÏÂÔØÒ»´Î¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬Ëü»áÔÚFirefoxµÄ×Ó½ÚµãºÍÖ÷½ÚµãÖ®¼ä³äÂúIPC£¨Àú³Ì¼äͨѶ£©Í¨µÀÀú³Ì£¬£¬£¬£¬£¬£¬Ê¹ÏµÍ³Í߽⡣¡£¡£Mac¡¢LinuxºÍWindowsƽ̨ÉϵÄFirefox¶¼ÊÜÓ°Ïì¡£¡£¡£Ñо¿Ö°Ô±ÒÑÓÚ9ÔÂ23ÈÕÏòMozilla±¨¸æÁ˸ÃÎó²î£¬£¬£¬£¬£¬£¬²¢ÔÚGitHubÉÏÐû²¼ÁËÏà¹ØPoC¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-mozilla-firefox-attack-causes-desktop-client-to-crash/
¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷ʹÓÃ×ÔÓÉÖ°ÒµÍøÕ¾fiverrºÍFreelancerµÄ¹¥»÷»î¶¯
MalwareHunterTeamÑо¿ÍŶӷ¢Ã÷ʹÓÃ×ÔÓÉÖ°ÒµÍøÕ¾£¨°üÀ¨fiverrºÍFreelancer£©À´·Ö·¢¶ñÒâÈí¼þµÄ¹¥»÷»î¶¯¡£¡£¡£ÕâЩ¶ñÒâÈí¼þαװ³ÉÊÂÇé¼ò½éµÄ¸½¼þ£¬£¬£¬£¬£¬£¬µ«ÏÖʵÉÏÓÃÓÚ×°ÖüüÅ̼ͼÆ÷£¨ÈçAgent Tesla£©ºÍÔ¶¿ØÄ¾ÂíµÈ¡£¡£¡£µ±Êܺ¦ÕßÔÚ·¿ª¸Ã¶ñÒ⸽¼þÓöµ½ÎÊÌâʱ£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹»á»Ø¸´ËûÃÇÒÔÌṩ×ÊÖú£¬£¬£¬£¬£¬£¬ÀýÈçÒ»ÃûÓû§³ÆÎÞ·¨ÔÚÒÆ¶¯×°±¸ÉÏ·¿ª¸ÃÎļþ£¬£¬£¬£¬£¬£¬¶ø¹¥»÷Õ߻ظ´³ÆÐèÒªÔÚPCÉÏ·¿ªËü¡£¡£¡£
https://www.bleepingcomputer.com/news/security/malware-disguised-as-job-offers-distributed-on-freelance-sites/
¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶÓÐû²¼¹ØÓÚmacOS¶ñÒâÈí¼þOSX.FairyTaleµÄÆÊÎö±¨¸æ
SentinelOneÑо¿ÍŶÓÐû²¼¹ØÓÚmacOS¶ñÒâÈí¼þOSX.FairyTaleµÄÆÊÎö±¨¸æ¡£¡£¡£½üÄêÀ´£¬£¬£¬£¬£¬£¬macOSƽ̨ÉÏ×îÆÕ±éµÄÇå¾²ÍþвһֱÊÇÓÃÓÚ·Ö·¢¹ã¸æÈí¼þºÍDZÔÚÓк¦Èí¼þ£¨PUP£©µÄ¶ñÒâ³ÌÐò¡£¡£¡£OSX.FairyTaleÊÇÒ»¸ö¹ã¸æÈí¼þµÄ±äÖÖ£¬£¬£¬£¬£¬£¬×î³õÓÉMalwarebytesµÄÑо¿Ö°Ô±Thomas ReedÓÚ2018ÄêÍ··¢Ã÷¡£¡£¡£OSX.FairyTaleʹÓÃÁË´ó×ڵĻìÏýºÍ·´ÄæÏòÊÖÒÕ£¬£¬£¬£¬£¬£¬Õâ¹ØÓÚ¹ã¸æÈí¼þÀ´ËµÊDz»³£¼ûµÄ¡£¡£¡£
https://www.sentinelone.com/blog/trail-osx-fairytale-adware-playing-malware/
¡¾Êý¾Ýй¶¡¿Ê±×°ÁãÊÛÉÌSHEINÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬Ô¼642ÍòÓû§µÄÐÅÏ¢¿ÉÄÜй¶
ʱװÁãÊÛÉÌSHEINÉÏÖÜÎåÐû²¼ÆäÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬Ô¼642ÍòÓû§µÄÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£¹¥»÷ÊÂÎñ±¬·¢ÔÚÑ×Ì죬£¬£¬£¬£¬£¬¼´6ÔµÄij¸öʱ¼ä£¬£¬£¬£¬£¬£¬¹¥»÷Õß»á¼ûÁËÓû§µÄµç×ÓÓʼþµØµãºÍ¼ÓÃܵÄÃÜÂë¡£¡£¡£¸Ã¹«Ë¾ÓÚ8ÔÂ22ÈÕ·¢Ã÷ÁËÕâÒ»ÊÂÎñ£¬£¬£¬£¬£¬£¬²¢ÕýÔÚÁªÏµÊÜÓ°ÏìµÄÓû§ÐÞ¸ÄÆäÃÜÂë¡£¡£¡£Ð¹Â¶µÄÊý¾ÝÖв»°üÀ¨ÈκÎÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¸Ã¹«Ë¾ÕýÔÚ¾ÙÐнøÒ»²½µÄÊӲ졣¡£¡£
https://www.zdnet.com/article/shein-fashion-retailer-announces-breach-affecting-6-42-million-users/


¾©¹«Íø°²±¸11010802024551ºÅ