¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180711

Ðû²¼Ê±¼ä 2018-07-11

 ¡¾ÆÊÎö±¨¸æ¡¿Çå¾²Ñо¿»ú¹¹Ðû²¼2018ÄêµÚ¶þ¼¾¶ÈAPTÇ÷ÊÆ±¨¸æ


¿¨°Í˹»ùʵÑéÊÒÐû²¼2018ÄêµÚ¶þ¼¾¶ÈµÄAPTÇ÷ÊÆ±¨¸æ£¬£¬£¬ÑÇÖÞ¹¥»÷Õß×îΪ»îÔ¾£¬£¬£¬°üÀ¨Lazarus/BlueNoroff¡¢Reaper¡¢DarkHotelºÍLuckyMouseµÈ¡£¡£¡£¡£¡£ ¡£¡£±¾¼¾¶È×îÒýÈËעĿµÄ¹¥»÷»î¶¯ÊÇAPT×éÖ¯SofacyºÍSandwormµÄVPNFilter»î¶¯¡£¡£¡£¡£¡£ ¡£¡£ËƺõÒÑÍù¼¸ÄêÖÐ×îΪ»îÔ¾µÄһЩ×éÖ¯ÒѾ­ïÔÌ­ÁËËüÃǵĻ£¬£¬£¬µ«Õâ²¢²»ÁÏζ×ÅËüÃǵÄΣÏÕÐÔ±äС¡£¡£¡£¡£¡£ ¡£¡£ÀýÈçSofacyÔöÌíÁËÓÃGoÓïÑÔ±àдµÄÐÂÏÂÔØÆ÷ÒÔ·Ö·¢Zebrocy¡£¡£¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±»¹ÊӲ쵽еÄAPT×éÖ¯PerfanlyÒÔ¼°²¿·ÖÕÝ·üÊýÔÂÉõÖÁÊýÄêµÄAPT×éÖ¯ÖØÐ·ºÆð£¨ÈçWhiteWhale£©¡£¡£¡£¡£¡£ ¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://securelist.com/apt-trends-report-q2-2018/86487/


¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷·¸·¨ÍÅ»ïMagecartµÄ´ó¹æÄ£ÐÅÓÿ¨ÐÅϢ͵ÇԻ

RiskIQÑо¿ÍŶӷ¢Ã÷TicketmasterµÄÊý¾Ýй¶ÊÂÎñÖ»ÊǸü´ó¹æÄ£µÄÐÅÓÿ¨ÐÅϢ͵ÇԻµÄÒ»²¿·Ö¡£¡£¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±½øÒ»²½Ö¸³öÆä×ï¿ý×ï¿ýÊÇ·¸·¨ÍÅ»ïMagecart£¬£¬£¬ÆäÕë¶ÔÐÅÓÿ¨ÐÅÏ¢µÄ͵ÇԻӰÏìÁËÈ«Çò800¶à¸öµç×ÓÉÌÎñÍøÕ¾¡£¡£¡£¡£¡£ ¡£¡£Magecartͨ¹ý×¢ÈëÍøÕ¾µÄ½ÅÔ­À´ÇÔÈ¡µç×ÓÉÌÎñÍøÕ¾µÄÔÚÏßÖ§¸¶ÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£²»µ«½öÊÇTicketmasterµÄµÚÈý·½²å¼þÌṩÉÌInbentaÔâµ½ÉøÍ¸£¬£¬£¬PushAssist¡¢Clarity ConnectÒÔ¼°Annex CloudµÈÒ²±»ÉøÍ¸¡£¡£¡£¡£¡£ ¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.riskiq.com/blog/labs/magecart-ticketmaster-breach/


¡¾¹¥»÷ÊÂÎñ¡¿¼ÓÃÜÇ®±ÒÉúÒâËùBancorÔâºÚ¿ÍÈëÇÖ£¬£¬£¬¼ÛÖµÔ¼1250ÍòÃÀÔªµÄÒÔÌ«±Ò±»ÇÔ


7ÔÂ9ÈÕÒÔÉ«ÁмÓÃÜÇ®±ÒÉúÒâËùBancorÔâºÚ¿ÍÈëÇÖ£¬£¬£¬¹¥»÷Õß´ÓBancorÖÇÄܺÏÔ¼ÖÐÇÔÈ¡ÁË24984¸öÒÔÌ«±Ò£¨¼ÛÖµÔ¼1250ÍòÃÀÔª£©£¬£¬£¬Í¬Ê±»¹ÇÔÈ¡ÁË229356645¸öNPXS±Ò£¨¼ÛÖµÔ¼100ÍòÃÀÔª£©¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷Õß»¹ÇÔÈ¡ÁË320Íò¸öBancorÁîÅÆ£¨BNT£©£¬£¬£¬¼ÛÖµÔ¼1000ÍòÃÀÔª£¬£¬£¬µ«Bancor³ÆÆäÇå¾²¹¦Ð§¶³½áÁ˸ñÊ×ʽ𡣡£¡£¡£¡£ ¡£¡£BancorÌåÏÖ¹¥»÷Õß²¢Î´Õë¶ÔÈκÎÓû§Ç®°ü£¬£¬£¬µ«Ã»ÓÐ͸¶¹¥»÷ÕßµÄÈëÇÖ·½·¨¡£¡£¡£¡£¡£ ¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hacker-steals-135-million-from-bancor-cryptocurrency-exchange/


¡¾Îó²î²¹¶¡¡¿AppleÐû²¼¶à¿î²úÆ·µÄÇå¾²¸üУ¬£¬£¬µ«ÐÂÍÆ³öµÄusbÏÞÖÆÄ£Ê½Òѱ»Èƹý


AppleÐû²¼Õë¶ÔmacOS¡¢iOS¡¢watchOs¡¢tvOS¡¢Safari¡¢iCloud for WindowsºÍiTunes for WindowsµÈ²úÆ·µÄÇå¾²¸üУ¬£¬£¬ÐÞ¸´¶à¸öÇå¾²Îó²î¡£¡£¡£¡£¡£ ¡£¡£Apple»¹ÔÚiOS 11.4.1ÖÐÍÆ³öÁËеÄusbÏÞÖÆÄ£Ê½£¬£¬£¬¸Ãģʽ¿ÉÔÚһСʱºó½ûÓÃiOSÉè±¹ØÁ¬ÄUSB¶Ë¿Ú£¬£¬£¬ÒÔ±ÜÃâһЩÈí¼þ¹«Ë¾µÄiPhone½âËøÊÖÒÕ¡£¡£¡£¡£¡£ ¡£¡£µ«Èí¼þ¹«Ë¾Elcomsoft³Æ¿Éͨ¹ý²åÈëÈκÎUSB×°±¸À´Èƹý¸Ãģʽ¡£¡£¡£¡£¡£ ¡£¡£Ïêϸ¸üÐÂÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£ ¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/apple/apple-releases-security-updates-for-ios-macos-and-more/


¡¾Îó²î²¹¶¡¡¿Î¢ÈíÐû²¼2018Äê7ÔÂÇå¾²¸üУ¬£¬£¬¹²ÐÞ¸´15¸ö²úÆ·ÖеÄ53¸öÇå¾²Îó²î


΢ÈíµÄ7ÔÂÇå¾²¸üй²ÐÞ¸´ÁË53¸öÇå¾²Îó²î£¬£¬£¬ÆäÖаüÀ¨17¸ö¸ßΣÎó²î¡£¡£¡£¡£¡£ ¡£¡£ÑÏÖØÐÔ×î¸ßµÄä¯ÀÀÆ÷Îó²îÊÇÓëJScriptÒýÇæChakraÓйصÄËĸöÄÚ´æËð»µÎó²î£¨CVE-2018-8280¡¢CVE-2018-8286¡¢CVE-2018-8290¡¢CVE-2018-8294£©£¬£¬£¬ÕâЩÎó²î¶¼¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£ ¡£¡£ÁíÒ»¸ö½ÏΪÑÏÖØµÄÎó²îÊÇWindows DNSAPIÖеľܾøÐ§ÀÍÎó²î£¨CVE-2018-8304£©¡£¡£¡£¡£¡£ ¡£¡£ÏêϸÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£ ¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/microsoft/microsoft-july-2018-patch-tuesday-fixes-53-security-bugs-across-15-products/


¡¾Êý¾Ýй¶¡¿Ã·Î÷°Ù»õ²¿·ÖÓû§µÄµÇ¼ƾ֤Ôâй£¬£¬£¬Òì³£ÕË»§Òѱ»¶³½á


÷Î÷°Ù»õ³ÆÔÚ2018Äê4ÔÂ26ÈÕÖÁ6ÔÂ12ÈÕʱ´ú£¬£¬£¬Î´¾­ÊÚȨµÄµÚÈý·½Ê¹ÓÃÓÐÓõĵǼƾ֤»á¼ûÁËÓû§µÄÔÚÏß×ÊÁÏ£¬£¬£¬¿ÉÄÜй¶µÄÐÅÏ¢°üÀ¨Óû§µÄÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢ÉúÈÕÒÔ¼°½è¼Ç¿¨»òÐÅÓÿ¨µÄºÅÂë¼°ÓÐÓÃÆÚ¡£¡£¡£¡£¡£ ¡£¡£Óû§µÄÉç±£ºÅÂë¼°ÒøÐп¨CVVºÅÂ벢δй¶¡£¡£¡£¡£¡£ ¡£¡£Ã·Î÷°Ù»õµÄ½²»°È˳ÆÊÜÓ°ÏìµÄÓû§Ö»Õ¼ÆäÓû§µÄ1%¡£¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾ÒѾ­¶³½áÁËÕâЩÒì³£ÕË»§¡£¡£¡£¡£¡£ ¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/macy-s-locks-small-number-of-accounts-following-suspicious-logins-fraud-reports/