¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190130

°ä²¼¹¦·ò 2019-01-30
1¡¢FaceTimeÆØ³Á´óÇÔÌý·ì϶£¬Apple°µÊ¾½«ÔÚ±¾Öܽ¨¸´

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¾Ý±íý±¨Â·£¬Apple FaceTime´æÔÚ³Á´ó°²È«·ì϶£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÖ¸±ê½ÓÌý»ò»Ø¾øFaceTimeͨ»°Ö®Ç°¼àÌý¶Ô·½µÄÉùÒô ¡£ÈôÊǶԷ½°´ÏÂÒôÁ¿½µµÍ°´Å¥»òµçÔ´°´Å¥À´¾²Òô»òÈ¡µÞͨ»°£¬ÔòÆäǰÖÃÉãÏñÍ·Ò²»á´ò¿ª£¬²¢½«ÊÓÆµÐźŷ¢Ë͸ø¹¥»÷Õß ¡£¾ÝϤ£¬¸Ã·ì϶»á³Ê´Ë¿ÌiOS 12.1»ò¸ü¸ß°æ±¾µÄiOSÉ豸ÖÐ ¡£AppleÒѾ­Ò»Ê±½ûÓÃÁËFaceTimeÖеÄȺ×éͨ»°Ö°ÄÜ£¬²¢°µÊ¾½«ÔÚ±¾ÖÜÍíЩʱ³½°ä²¼½¨¸´²¹¶¡ ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/apple-facetime-privacy-hack.html


2¡¢°Ä´óÀûÑÇ8¼ÒÍйܷþÎñÉÌÔâ·ê¹¥»÷»î¶¯Manic Menagerie

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



ƾ¾Ý°Ä´óÀûÑÇÍøÂ簲ȫÖÐÐÄ£¨ACSC£©°ä²¼µÄÒ»·Ý»ã±¨£¬8¸öÍйܷþÎñÉÌÔÚ2018ÄêÔâ·ê¶ñÒâ¹¥»÷»î¶¯Manic Menagerie ¡£¹¥»÷ÕßÀûÓÃWebÀûÓÃÖеķì϶À´»ñÈ¡Web·þÎñÆ÷µÄrootȨÏÞ£¬²¢×°ÖÃÃÜÂëÇÔÈ¡¹¤¾ßºÍGh0st RAT ¡£ÆäÖÐÒ»¸ö±»ÀûÓõķì϶ÊÇ2018Äê4Ô¹«¿ªµÄÌáȨ·ì϶TotalMeltdown£¨CVE-2018-1038£© ¡£ACSCÒѽ¨ÒéÕâЩÍйܷþÎñÉ̸øWebÀûÓúÍCMS´ò²¹¶¡ºÍ½ûÓöñÒâ²å¼þ£¬²¢³ÁÖÃÓû§µÄÍ´´¦ ¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/eight-australian-web-hosting-providers-compromised-in-manic-menagerie-attack-campaign-8ee4259a 


3¡¢AZORultľÂí¼Ù×°³É¹È¸è¸üз¨Ê½£¬Ö¼ÔÚÇÔÈ¡Óû§Í´´¦

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


À´×ÔMinerva Labs¡¢Asaf AprozperºÍGal BitenskyµÄ×êÑÐÈËÔ±¹Û²ìµ½AZORultľÂíͨ¹ý¼Ù×°³ÉGoogle Updater·¨Ê½À´ÊµÏÖÓÆ¾ÃÐÔ ¡£AZORultľÂíÖØÒªÓÃÓÚÇÔÈ¡Óû§µÄÃô¸ÐÊý¾Ý£¬Ô̺¬Îļþ¡¢ÃÜÂë¡¢cookie¡¢ä¯ÀÀÆ÷º¹Çà¼Í¼¡¢ÒøÐÐÍ´´¦ºÍ¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢ ¡£ÓÉÓÚAZORult¼Ù×°³ÉGoogle Updater·¨Ê½£¬Ëü½«ÒÔÖÎÀíԱȨÏÞÔËÐÐ ¡£×êÑÐÈËÔ±·¢ÏÖÕâЩ¶ñÒâµÄGoogleUpdate.exeÎļþʹÓÃÁËÓÐЧµÄÖ¤Êé½øÐÐÊðÃû£¬µ«¸ÃÖ¤ÊéÏÖʵÉϱ»Ðû¸æ¸ø¡°Singh Agile Content Design Limited¡±£¬¶ø²»ÊÇGoogle ¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/azorult-trojan-disguised-as-google-update-installer-steals-credentials-6e225ab6


4¡¢¶ñÒâÈí¼þFormBook»Ø¹é£¬ÖØÒªÕë¶ÔÃÀ¹úÁãÊۺ;ƵêÒµ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ƾ¾ÝDeep InstinctµÄ»ã±¨£¬FormBookÔÚʹÓÃÒ»¸öеÄÎļþÍйܷþÎñ´«²¼£¬ÖØÒª¹¥»÷ÃÀ¹úµÄÁãÊۺ;ƵêÒµ ¡£FormBook×îÔç³öÏÖÓÚ2016Ä꣬Äܹ»ÇÔÈ¡Óû§µÄÍ´´¦¡¢½ØÈ¡×ÀÃæÆÁÄ»ÒÔ¼°¼Í¼¼üÅ̵È ¡£ÔÚÕâ¸öеĶñÒâ»î¶¯ÖУ¬FormBookͨ¹ý´¹µöÓʼþÖеÄRTF¸½¼þ´«²¼£¬¸Ã¸½¼þÀûÓÃÁËCVE-2012-0158¡¢CVE-2017-11882µÈOffice·ì϶ ¡£FormBook»¹ÀûÓÃÁËÒ»¸öеÄÎļþÍйܷþÎñDropMyBin£¬¸ÃÎļþÍйܷþÎñÒ²±»ÆäËü¶ñÒâÈí¼þʹÓã¬ÀýÈçLokibotºÍAzorult ¡£


Ô­ÎÄÁ´½Ó£º

https://www.deepinstinct.com/2019/01/27/info-stealer-formbook-continues-activity-and-uses-a-new-malware-friendly-file-hosting-service/


5¡¢·ÆÂɱöµçÐŹ«Ë¾GlobeÒâ±íй¶8851Ãû¿Í»§µÄÓ×ÎÒÐÅÏ¢

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ƾ¾ÝBestVPN.comµÄ»ã±¨£¬·ÆÂɱöµçÐŹ«Ë¾GlobeÔÚ½üÆÚµÄÍÆ¹ã×¢²á»î¶¯ÖУ¬Òâ±íÏòÐÂ×¢²áµÄÓû§ÓÊÏä·¢ËÍÁËÆäËüÓû§¼òÖ±ÈÏÓʼþ£¬µ¼Ö²¿Ãſͻ§µÄÃô¸ÐÊý¾Ýй¶ ¡£ÕâЩÊý¾ÝÔ̺¬¿Í»§µÄÐÕÃû¡¢µç×ÓÓÊÏ䵨ַºÍÆëÈ«µÄÓÊÕþµØÖ·£¬¹²ÓÐ8851Ãû¿Í»§Êܵ½Ó°Ïì ¡£¸Ã¹«Ë¾ÒѾ­Ö¤ÊµÁËÕâÒ»ÊÂÎñ£¬²¢Æ¾¾Ý¼à¹ÜÒªÇó֪ͨÁ˹ú¶ÈÒþÖÔ±£»¤Î¯Ô±»á£¨NPC£© ¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/filipino-telecom-giant-globe-inadvertently-leaks-personal-data-of-8851-subscribers-e87bb87b


6¡¢ÐÂ¼ÓÆÂÔ¼1.4Íò°¬×̲¡»¼ÕßÐÅϢй¶£¬ÏÓ·¸ÎªÃÀ¼®ÄÐ×Ó

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

2019Äê1ÔÂ28ÈÕ£¬ÐÂ¼ÓÆÂÎÀÉú²¿ÔÚÒ»·ÝÉêÃ÷ÖÐ֤ʵÃÀ¹úÄÐ×ÓMikhy K Farrera Brochez·¸·¨»ñÈ¡²¢Ð¹Â¶ÁËÔ¼1.42Íò°¬×̲¡»¼ÕßµÄÓ×ÎÒÐÅÏ¢ ¡£ÆäÖÐ5400Ãû»¼ÕßÊÇÐÂ¼ÓÆÂÈË£¬8800Ãû»¼ÕßÊDZí¹úÈË ¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬»¼ÕßµÄÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢µç»°ºÅÂë¡¢µØÖ·¡¢HIV¼ì²âÁ˾ֺÍÓйØÒ½ÁÆÐÅÏ¢µÈ ¡£ÕâЩÊý¾ÝÊÇBrochez´ÓÐÂ¼ÓÆÂµÄ°¬×̲¡µÇ¼Ç´¦ÇÔÈ¡µÄ ¡£2017Äê3Ô£¬BrochezÔÚÐÂ¼ÓÆÂ±»¿ØÚ²Æ­µÈ¶àÏî×ïÃû£¬²¢ÔÚ·þÐ̺󱻱÷³ý³ö¾³ ¡£2019Äê1ÔÂ22ÈÕ£¬ÐÂ¼ÓÆÂÎÀÉú²¿·¢ÏÖÉÏÊö»¼Õß×ÊÁÏÔÚÍøÉϱ»Ð¹Â¶ºó±¨¾¯ ¡£Ä¿Ç°±¾µØ¾¯·½ÔÚ×·Çó¶Ô´Ë°¸½øÐйú¼Êµ÷²é ¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/private-data-of-almost-14200-patients-diagnosed-with-hiv-leaked-online-de45a837


ÉêÃ÷£º±¾×ÊѶÓɱ¦ÔËÀ³¹Ù·½ÍøÕ¾Î¬ËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù