¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190107

Ðû²¼Ê±¼ä 2019-01-07
1¡¢NSA½«ÔÚRSA 2019ÉϹûտĿÏò¹¤¾ßGHIDRA

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©½«ÔÚ2019Äê3Ô·ݵÄRSA´ó»áÉÏÃâ·ÑÐû²¼ÄæÏò¹¤³Ì¹¤¾ßGHIDRA¡£¡£¡£Æ¾Ö¤Î¬»ù½âÃÜÅû¶µÄCIA Vault 7ϵÁÐÎĵµ £¬£¬£¬£¬GHIDRAÊÇÓÉNSA»ùÓÚJavaÓïÑÔ¿ª·¢µÄÄæÏò¹¤³Ì¹¤¾ß¡£¡£¡£NSAÌåÏÖGHIDRA¾ßÓн»»¥Ê½GUI £¬£¬£¬£¬²¢ÇÒÊÊÓÃÓÚ¶àÖÖÆ½Ì¨ £¬£¬£¬£¬°üÀ¨Windows¡¢LinuxºÍMac OS £¬£¬£¬£¬»¹Ö§³Ö¶àÖÖоƬָÁ¡£¡£¡£

  

 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nsa-releasing-the-ghidra-reverse-engineering-tool-at-rsaconference/


2¡¢Town of SalemÊý¾Ýй¶ÊÂÎñÁè¼Ý27%µÄÃÜÂëÒѱ»ÆÆ½â

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


2018Äê12ÔÂ28ÈÕ £¬£¬£¬£¬ÐÅϢй¶ÅÌÎÊÍøÕ¾DeHashedÎüÊÕµ½Ò»·âÓʼþ £¬£¬£¬£¬ÆäÖаüÀ¨Town of SalemÓÎϷЧÀÍÆ÷±»ºÚ¿ÍÈëÇÖµÄÖ¤¾ÝÒÔ¼°¸ÃÓÎÏ·Êý¾Ý¿âµÄ¸±±¾¡£¡£¡£Æ¾Ö¤DeHashed £¬£¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨Áè¼Ý760Íò¸öΨһµç×ÓÓʼþµØµã £¬£¬£¬£¬»¹°üÀ¨Óû§Ãû¡¢¹þÏ£ÃÜÂë¡¢IPµØµãµÈÓû§Êý¾Ý¡£¡£¡£ÃÜÂë»Ö¸´ÍøÕ¾Hashes.orgÒѾ­ÆÆ½âÁËÕâЩй¶µÄÊý¾ÝÖеÄ210Íò¸ö¹þÏ£ÃÜÂ루Լ27%£© £¬£¬£¬£¬½¨ÒéSalemÓû§¾¡¿ìÔÚʹÓÃÁËÏàͬÃÜÂëµÄÍøÕ¾Éϸü¸ÄÆäÃÜÂë¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/27-percent-of-passwords-from-town-of-salem-breach-already-cracked/


3¡¢IBM TWCÌìÆøÓ¦ÓÃÒò³öÊÛÓû§Êý¾ÝÔâµ½ÆðËß

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

Âåɼí¶ÊÐÏò¼ÓÀû¸£ÄáÑÇÖÝ·¨ÔºÌáÆðËßËÏ £¬£¬£¬£¬¿ØËßIBM×Ó¹«Ë¾TWCµÄÌìÆøÓ¦Óã¨Weather Channel£©ÍÚ¾òÓû§µÄÒþ˽Êý¾Ý²¢½«ÕâЩÐÅÏ¢³öÊÛ¸øµÚÈý·½ £¬£¬£¬£¬°üÀ¨¹ã¸æ¹«Ë¾¡£¡£¡£Âåɼí¶Êз½ÃæÌåÏÖ £¬£¬£¬£¬Weather ChannelÔÚÐí¶àÓû§²»ÖªÇéµÄÇéÐÎϸú×ÙÓû§µÄµØÀíλÖÃÊý¾Ý £¬£¬£¬£¬²¢½«ÕâЩÊý¾ÝÓÃÓÚÓëÌìÆøÔ¤¸æÍêÈ«ÎÞ¹ØµÄ¹ã¸æµÈÉÌÒµÓÃ;¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/city-of-la-sues-weather-channel-app-for-sharing-location-data-with-advertisers/


4¡¢Bobby YeeÔâÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬£¬²¨¼°2.4Íò»¼ÕßÐÅÏ¢

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

¼ÓÖÝ×ã¿ÆÒ½ÔºBobby Yee D.P.M.Ðû²¼Ôâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬£¬ËûÃǵÄÒ½ÁƼͼ£¨°üÀ¨»¼ÕßµÄСÎÒ˽¼ÒÐÅÏ¢£©Ô⵽δÊÚȨ¸ü¸Ä¡£¡£¡£Éæ¼°µ½µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¡¢ÄêËê¡¢ÐԱ𡢳öÉúÈÕÆÚ¡¢Éç±£ºÅÂë¡¢°ü¹Üµ¥ºÅÂëÒÔ¼°²¡Àú¡£¡£¡£¸Ã°ì¹«ÊÒÒÑ֪ͨÁËÊÜÓ°ÏìµÄ2.4ÍòÃû»¼Õß £¬£¬£¬£¬µ«ÌåÏÖûÓÐÖ¤¾ÝÅúעСÎÒ˽¼ÒÐÅÏ¢»òÒ½ÁÆÐÅÏ¢Ô⵽й¶¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/bobby-yee-d-p-m-notified-24000-patients-after-ransomware-attack/


5¡¢ÀÕË÷Èí¼þ¼Ò×åAuroraµÄÃ⺬»ìÃÜÆ÷Òѱ»Ðû²¼

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

Michael Gillespie½¨ÉèÁËÀÕË÷Èí¼þ¼Ò×åAuroraµÄÃ⺬»ìÃܹ¤¾ß¡£¡£¡£¸Ã½âÃÜÆ÷¿É½âÃÜÀ©Õ¹ÃûΪ.Nano¡¢.animus¡¢.Aurora¡¢.desu¡¢.ONIºÍ.auroraµÄ±äÌå £¬£¬£¬£¬ÆäÖÐ.Nano±äÌåÊÇÄ¿½ñ×îΪ»îÔ¾µÄAurora±äÌå¡£¡£¡£Auroraͨ³£Í¨¹ýRDPЧÀÍÈëÇÖÊܺ¦ÕßµÄÅÌËã»ú £¬£¬£¬£¬²¢ÔÚ¼ÓÃÜÎļþÖ®ºóÒªÇóÒÔ±ÈÌØ±ÒÖ§¸¶Êê½ð¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/how-to-decrypt-the-aurora-ransomware-with-auroradecrypter/


6¡¢ÐÂ¼ÓÆÂº½¿Õ¹«Ë¾Èí¼þbugµ¼ÖÂ284ÃûÓû§ÐÅϢй¶

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÐÂ¼ÓÆÂº½¿Õ¹«Ë¾Èí¼þ·ºÆðbug £¬£¬£¬£¬µ¼ÖÂÁè¼Ý280ÃûKrisFlyerÓû§µÄСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£Æ¾Ö¤¸Ã¹«Ë¾µÄÊÓ²ì £¬£¬£¬£¬¹²ÓÐ284¸öKrisFlyerÕÊ»§Êܵ½Ó°Ïì £¬£¬£¬£¬ÕâЩÕË»§µÄÐÕÃû¡¢º½°àÀúÊ·¡¢×î½üÀï³ÌºÍ½±Àø¿É±»ÆäËüÓû§»á¼û¡£¡£¡£±ðµÄ £¬£¬£¬£¬7ÃûÓû§µÄ»¤ÕÕºÅÂëÒ²±»Ð¹Â¶¡£¡£¡£ÕâÒ»ÊÂÎñ±¬·¢ÔÚ1ÔÂ5ºÅ £¬£¬£¬£¬¸Ã¹«Ë¾ÌåÏÖ²¢Ã»ÓÐÊܵ½Íⲿ¹¥»÷¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

http://theindependent.sg/singapore-airlines-experiences-security-breach-personal-information-of-more-than-280-krisflyer-members-disclosed/


ÉùÃ÷£º±¾×ÊѶÓÉÈËÉú¾ÍÊDz©Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí