¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190130

Ðû²¼Ê±¼ä 2019-01-30
1¡¢FaceTimeÆØÖØ´óÇÔÌýÎó²î£¬£¬£¬£¬£¬£¬AppleÌåÏÖ½«ÔÚ±¾ÖÜÐÞ¸´

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


¾ÝÍâý±¨µÀ£¬£¬£¬£¬£¬£¬Apple FaceTime±£´æÖØ´óÇå¾²Îó²î£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÄ¿µÄ½ÓÌý»ò¾Ü¾øFaceTimeͨ»°Ö®Ç°¼àÌý¶Ô·½µÄÉùÒô¡£¡£¡£¡£ÈôÊǶԷ½°´ÏÂÒôÁ¿½µµÍ°´Å¥»òµçÔ´°´Å¥À´¾²Òô»ò×÷·Ïͨ»°£¬£¬£¬£¬£¬£¬ÔòÆäǰÖÃÉãÏñÍ·Ò²»á·­¿ª£¬£¬£¬£¬£¬£¬²¢½«ÊÓÆµÐźŷ¢Ë͸ø¹¥»÷Õß¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬¸ÃÎó²î»á·ºÆðÔÚiOS 12.1»ò¸ü¸ß°æ±¾µÄiOS×°±¸ÖС£¡£¡£¡£AppleÒѾ­ÔÝʱ½ûÓÃÁËFaceTimeÖеÄȺ×éͨ»°¹¦Ð§£¬£¬£¬£¬£¬£¬²¢ÌåÏÖ½«ÔÚ±¾ÖÜÍíЩʱ¼äÐû²¼ÐÞ¸´²¹¶¡¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/apple-facetime-privacy-hack.html


2¡¢°Ä´óÀûÑÇ8¼ÒÍйÜЧÀÍÉÌÔâÓö¹¥»÷»î¶¯Manic Menagerie

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø



ƾ֤°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄ£¨ACSC£©Ðû²¼µÄÒ»·Ý±¨¸æ£¬£¬£¬£¬£¬£¬8¸öÍйÜЧÀÍÉÌÔÚ2018ÄêÔâÓö¶ñÒâ¹¥»÷»î¶¯Manic Menagerie¡£¡£¡£¡£¹¥»÷ÕßʹÓÃWebÓ¦ÓÃÖеÄÎó²îÀ´»ñÈ¡WebЧÀÍÆ÷µÄrootȨÏÞ£¬£¬£¬£¬£¬£¬²¢×°ÖÃÃÜÂëÇÔÈ¡¹¤¾ßºÍGh0st RAT¡£¡£¡£¡£ÆäÖÐÒ»¸ö±»Ê¹ÓõÄÎó²îÊÇ2018Äê4Ô¹ûÕæµÄÌáȨÎó²îTotalMeltdown£¨CVE-2018-1038£©¡£¡£¡£¡£ACSCÒѽ¨ÒéÕâЩÍйÜЧÀÍÉ̸øWebÓ¦ÓúÍCMS´ò²¹¶¡ºÍ½ûÓöñÒâ²å¼þ£¬£¬£¬£¬£¬£¬²¢ÖØÖÃÓû§µÄƾ֤¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/eight-australian-web-hosting-providers-compromised-in-manic-menagerie-attack-campaign-8ee4259a 


3¡¢AZORultľÂíαװ³É¹È¸è¸üгÌÐò£¬£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡Óû§Æ¾Ö¤

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


À´×ÔMinerva Labs¡¢Asaf AprozperºÍGal BitenskyµÄÑо¿Ö°Ô±ÊӲ쵽AZORultľÂíͨ¹ýαװ³ÉGoogle Updater³ÌÐòÀ´ÊµÏÖ³¤ÆÚÐÔ¡£¡£¡£¡£AZORultľÂíÖ÷ÒªÓÃÓÚÇÔÈ¡Óû§µÄÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬°üÀ¨Îļþ¡¢ÃÜÂë¡¢cookie¡¢ä¯ÀÀÆ÷ÀúÊ·¼Í¼¡¢ÒøÐÐÆ¾Ö¤ºÍ¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡£¡£¡£¡£ÓÉÓÚAZORultαװ³ÉGoogle Updater³ÌÐò£¬£¬£¬£¬£¬£¬Ëü½«ÒÔÖÎÀíԱȨÏÞÔËÐС£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÕâЩ¶ñÒâµÄGoogleUpdate.exeÎļþʹÓÃÁËÓÐÓõÄÖ¤Êé¾ÙÐÐÊðÃû£¬£¬£¬£¬£¬£¬µ«¸ÃÖ¤ÊéÏÖʵÉϱ»½ÒÏþ¸ø¡°Singh Agile Content Design Limited¡±£¬£¬£¬£¬£¬£¬¶ø²»ÊÇGoogle¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/azorult-trojan-disguised-as-google-update-installer-steals-credentials-6e225ab6


4¡¢¶ñÒâÈí¼þFormBook»Ø¹é£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹úÁãÊÛºÍÂùÝÒµ

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ƾ֤Deep InstinctµÄ±¨¸æ£¬£¬£¬£¬£¬£¬FormBookÕýÔÚʹÓÃÒ»¸öеÄÎļþÍйÜЧÀÍÈö²¥£¬£¬£¬£¬£¬£¬Ö÷Òª¹¥»÷ÃÀ¹úµÄÁãÊÛºÍÂùÝÒµ¡£¡£¡£¡£FormBook×îÔç·ºÆðÓÚ2016Ä꣬£¬£¬£¬£¬£¬¿ÉÒÔÇÔÈ¡Óû§µÄƾ֤¡¢½ØÈ¡×ÀÃæÆÁÄ»ÒÔ¼°¼Í¼¼üÅ̵ȡ£¡£¡£¡£ÔÚÕâ¸öеĶñÒâ»î¶¯ÖУ¬£¬£¬£¬£¬£¬FormBookͨ¹ý´¹ÂÚÓʼþÖеÄRTF¸½¼þÈö²¥£¬£¬£¬£¬£¬£¬¸Ã¸½¼þʹÓÃÁËCVE-2012-0158¡¢CVE-2017-11882µÈOfficeÎó²î¡£¡£¡£¡£FormBook»¹Ê¹ÓÃÁËÒ»¸öеÄÎļþÍйÜЧÀÍDropMyBin£¬£¬£¬£¬£¬£¬¸ÃÎļþÍйÜЧÀÍÒ²±»ÆäËü¶ñÒâÈí¼þʹÓ㬣¬£¬£¬£¬£¬ÀýÈçLokibotºÍAzorult¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.deepinstinct.com/2019/01/27/info-stealer-formbook-continues-activity-and-uses-a-new-malware-friendly-file-hosting-service/


5¡¢·ÆÂɱöµçÐŹ«Ë¾GlobeÒâÍâй¶8851Ãû¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ƾ֤BestVPN.comµÄ±¨¸æ£¬£¬£¬£¬£¬£¬·ÆÂɱöµçÐŹ«Ë¾GlobeÔÚ½üÆÚµÄÍÆ¹ã×¢²á»î¶¯ÖУ¬£¬£¬£¬£¬£¬ÒâÍâÏòÐÂ×¢²áµÄÓû§ÓÊÏä·¢ËÍÁËÆäËüÓû§¼òÖ±ÈÏÓʼþ£¬£¬£¬£¬£¬£¬µ¼Ö²¿·Ö¿Í»§µÄÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£ÕâЩÊý¾Ý°üÀ¨¿Í»§µÄÐÕÃû¡¢µç×ÓÓÊÏ䵨µãºÍÍêÕûµÄÓÊÕþµØµã£¬£¬£¬£¬£¬£¬¹²ÓÐ8851Ãû¿Í»§Êܵ½Ó°Ïì¡£¡£¡£¡£¸Ã¹«Ë¾ÒѾ­Ö¤ÊµÁËÕâÒ»ÊÂÎñ£¬£¬£¬£¬£¬£¬²¢Æ¾Ö¤î¿ÏµÒªÇó֪ͨÁ˹ú¼ÒÒþ˽±£»£»¤Î¯Ô±»á£¨NPC£©¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/filipino-telecom-giant-globe-inadvertently-leaks-personal-data-of-8851-subscribers-e87bb87b


6¡¢ÐÂ¼ÓÆÂÔ¼1.4Íò°¬×̲¡»¼ÕßÐÅϢй¶£¬£¬£¬£¬£¬£¬ÏÓ·¸ÎªÃÀ¼®ÄÐ×Ó

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

2019Äê1ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬ÐÂ¼ÓÆÂÎÀÉú²¿ÔÚÒ»·ÝÉùÃ÷ÖÐ֤ʵÃÀ¹úÄÐ×ÓMikhy K Farrera Brochez²»·¨»ñÈ¡²¢Ð¹Â¶ÁËÔ¼1.42Íò°¬×̲¡»¼ÕßµÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£ÆäÖÐ5400Ãû»¼ÕßÊÇÐÂ¼ÓÆÂÈË£¬£¬£¬£¬£¬£¬8800Ãû»¼ÕßÊÇÍâ¹úÈË¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨»¼ÕßµÄÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢µç»°ºÅÂë¡¢µØµã¡¢HIV¼ì²âЧ¹ûºÍÏà¹ØÒ½ÁÆÐÅÏ¢µÈ¡£¡£¡£¡£ÕâЩÊý¾ÝÊÇBrochezÖØÐÂ¼ÓÆÂµÄ°¬×̲¡¹ÒºÅ´¦ÇÔÈ¡µÄ¡£¡£¡£¡£2017Äê3Ô£¬£¬£¬£¬£¬£¬BrochezÔÚÐÂ¼ÓÆÂ±»¿ØÚ²Æ­µÈ¶àÏî×ïÃû£¬£¬£¬£¬£¬£¬²¢ÔÚ·þÐ̺ó±»ÇýÖð³ö¾³¡£¡£¡£¡£2019Äê1ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬ÐÂ¼ÓÆÂÎÀÉú²¿·¢Ã÷ÉÏÊö»¼Õß×ÊÁÏÔÚÍøÉϱ»Ð¹Â¶ºó±¨¾¯¡£¡£¡£¡£ÏÖÔÚÍâµØ¾¯ÆÓÖ±ÔÚ×·Çó¶Ô´Ë°¸¾ÙÐйú¼ÊÊӲ졣¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/private-data-of-almost-14200-patients-diagnosed-with-hiv-leaked-online-de45a837


ÉùÃ÷£º±¾×ÊѶÓÉÈËÉú¾ÍÊDz©Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí