¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180710
Ðû²¼Ê±¼ä 2018-07-10¡¾Êý¾Ýй¶¡¿TimehopÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Áè¼Ý2100ÍòÓû§µÄÊý¾Ýй¶
7ÔÂ4ÈÕÊ¢ÐеÄÉ罻ýÌåÓ¦ÓÃTimehopÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Áè¼Ý2100ÍòÓû§µÄСÎÒ˽¼ÒÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµãÒÔ¼°Ô¼470Íò¸öµç»°ºÅÂë¡£¡£¡£TimehopÓÃÓÚ×ÊÖúÓû§´ÓiPhone¡¢Facebook¡¢InstagramºÍTwitterµÈÍøÂç¾ÉÕÕÆ¬ºÍÌû×Ó£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ³äÆäʱ¼ä»úеµÄ¹¦Ð§¡£¡£¡£¹¥»÷Õß»¹»ñÈ¡ÁËÆäËüÉç½»ÍøÕ¾ÌṩӦTimehopµÄÊÚȨÁîÅÆ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÔÚδ¾ÔÊÐíµÄÇéÐÎÏ»á¼ûÓû§ÔÚÆäËüÉç½»ÍøÕ¾ÉϵÄÌû×Ó¡£¡£¡£Õâ´ÎÊÂÎñµÄÔµ¹ÊÔÓÉÊÇTimehopδ½ÓÄÉË«ÒòËØÈÏÖ¤À´ÖÎÀíÆäÔÆÅÌËãÇéÐÎµÄÆ¾Ö¤¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/timehop-data-breach.html
¡¾Êý¾Ýй¶¡¿Domain FactoryÈ·ÈÏÔÚ1Ô·ÝÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬²¿·ÖÓû§µÄÊý¾Ýй¶
µÂ¹úÍйÜЧÀÍÌṩÉÌDomainFactoryÈ·ÈÏÔÚ1Ô·ݱ¬·¢Êý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬²¿·ÖÓû§µÄСÎÒ˽¼ÒÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾Î´Åû¶ÏêϸµÄÊý×Ö¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨Óû§µÄÐÕÃû¡¢¹«Ë¾Ãû¡¢ÕË»§ID¡¢µØµã¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢³öÉúÈÕÆÚ¡¢ÒøÐп¨Õ˺ŵÈÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬ÍøÂç·¸·¨·Ö×Ó¿ÉʹÓÃÕâЩÊý¾Ý¾ÙÐÐÓÐÕë¶ÔÐÔµÄÉç»á¹¤³Ì¹¥»÷¡£¡£¡£DomainFactory½¨ÒéËùÓÐÓû§ÐÞ¸ÄÆäÃÜÂë¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/web-hosting-server-hack.html
¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷Õë¶Ô°ÍÀÕ˹̹Õþ¸®»ú¹¹µÄAPT¹¥»÷¾íÍÁÖØÀ´
Check PointÑо¿ÍŶӷ¢Ã÷Õë¶Ô°ÍÀÕ˹̹Õþ¸®»ú¹¹µÄAPT¹¥»÷¾íÍÁÖØÀ´¡£¡£¡£ÕâЩ¹¥»÷×îÏÈÓÚ2018Äê3Ô£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý°üÀ¨¶ñÒâÈí¼þµÄ´¹ÂÚÓʼþѬȾĿµÄ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ¿ÉÒÔÍøÂçÓû§µÄ.doc¡¢.odt¡¢.xls¡¢.pptºÍ.pdfÎļþ²¢·¢ËÍÖÁÔ¶³ÌЧÀÍÆ÷¡£¡£¡£Ñо¿Ö°Ô±³Æ¸Ã¶ñÒâÈí¼þ¹²°üÀ¨13¸öÄ£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬£¬µ«ÏÖÔÚÖ»ÄÜÈ·ÈÏÆäÖÐ5¸öÄ£¿£¿£¿éµÄ¹¦Ð§¡£¡£¡£Check PointÒÔΪ¸ÃAPT¹¥»÷±³ºóµÄ×éÖ¯ÊÇGaza Cybergang¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://research.checkpoint.com/apt-attack-middle-east-big-bang/
¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷ÌØ¹¤Èí¼þʹÓñ»ÇÔµÄD-LinkÊý×ÖÖ¤Êé¾ÙÐÐÊðÃû
ESETÑо¿ÍŶӷ¢Ã÷ʹÓñ»ÇÔÊý×ÖÖ¤Êé¾ÙÐÐÊðÃûµÄжñÒâÈí¼þ»î¶¯¡£¡£¡£µÚÒ»¸ö¶ñÒâÈí¼þÊÇPlead£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚÇÔÈ¡Óû§µÄÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬ÆäʹÓÃÁĘ̈Íå¿Æ¼¼¹«Ë¾D-LinkµÄÓÐÓÃÊý×ÖÖ¤Êé¾ÙÐÐÊðÃû¡£¡£¡£µÚ¶þ¸ö¶ñÒâÈí¼þÊÇÒ»¸öÃÜÂëÇÔÈ¡³ÌÐò£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚ´ÓChrome¡¢IE¡¢OutlookºÍFirefoxµÈÇÔÈ¡Óû§µÄÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬ÆäʹÓÃÁËChanging Information Technology¹«Ë¾µÄÓÐÓÃÖ¤ÊéÊðÃû¡£¡£¡£ÕâÁ½¼Ò¹«Ë¾ÔÚ½Óµ½±¨¸æºóÒÑ»®·ÖÔÚ7ÔÂ3ÈÕºÍ4ÈÕ×÷·ÏÁ˱»ÇÔµÄÖ¤Êé¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.welivesecurity.com/2018/07/09/certificates-stolen-taiwanese-tech-companies-plead-malware-campaign/
¡¾Îó²î²¹¶¡¡¿AppleÐû²¼Boot CampÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´3¸öWi-Fi KRACKÏà¹ØµÄÎó²î
AppleÐû²¼Boot Camp 6.4.0µÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÓëÈ¥ÄêÄêµ×Åû¶µÄWi-Fi KRACK¹¥»÷Ïà¹ØµÄ3¸öÇå¾²Îó²î£¨CVE-2017-13077¡¢CVE-2017-13078ºÍCVE-2017-13080£©¡£¡£¡£Boot CampÊÇmacOSÖÐµÄÆô¶¯¹¤¾ß£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÔÊÐíÓû§ÔÚ»ùÓÚIntel CPUµÄMacÉÏ×°ÖÃWindows²Ù×÷ϵͳ¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÇ¿ÖÆÔÚWPAµ¥²¥/PTK¿Í»§¶Ë»òWPA¶à²¥/GTK¿Í»§¶ËÖÐÖØ¸´Ê¹ÓÃnonce£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¾ÙÐиüС£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/apple-patches-krack-flaws-boot-camp
¡¾¶ñÒâÈí¼þ¡¿Ñо¿Ö°Ô±·¢Ã÷ÀÕË÷Èí¼þKingOuroborosµÄбäÖÖ
Ñо¿Ö°Ô±ÔÚ2018Äê6ÔÂÏÂÑ®·¢Ã÷ÀÕË÷Èí¼þKingOuroborosµÄбäÖÖ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã±äÖÖαװ³ÉJava Update Scheduler³ÌÐò£¨jusched.exe£©¾ÙÐÐÈö²¥£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýAES¼ÓÃÜÓû§µÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ¼ÓÃܵÄÎļþµÄÔÎļþÃûºÍÀ©Õ¹ÃûÖ®¼äÌí¼Ó.king_ouroborosÀ©Õ¹Ãû¡£¡£¡£¸Ã±äÖÖµÄÊê½ðΪ¼ÛÖµ50-80ÃÀÔªµÄ±ÈÌØ±Ò£¬£¬£¬£¬£¬£¬£¬£¬ÆäÀÕË÷ÐÅÏ¢ÖаüÀ¨12ÖÖÓïÑԵķÒë¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://id-ransomware.blogspot.com/2018/06/kingouroboros-ransomware.html


¾©¹«Íø°²±¸11010802024551ºÅ