¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180926

Ðû²¼Ê±¼ä 2018-09-26

¡¾ÆÊÎö±¨¸æ¡¿Çå¾²Ñо¿ÍŶÓÐû²¼¹ØÓÚUSBÍþвÏÖ×´µÄÆÊÎö±¨¸æ


¿¨°Í˹»ùʵÑéÊÒÐû²¼¹ØÓÚUSBÍþв״̬µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£±¨¸æµÄÖ÷Òª·¢Ã÷°üÀ¨£ºÖÁÉÙ´Ó2015Äê×îÏÈ£¬£¬£¬ £¬£¬£¬£¬USB×°±¸ºÍÆäËü¿ÉÒÆ¶¯Ã½Ìå±»ÓÃÓÚÈö²¥¶ñÒâÍÚ¿óÈí¼þ£»£»£»£»£»£»Í¨¹ýUSB×°±¸/¿ÉÒÆ¶¯Ã½ÌåÈö²¥µÄÆäËü¶ñÒâÈí¼þ»¹°üÀ¨WindowsľÂí¼Ò×åLNK£»£»£»£»£»£»ÑÇÖÞ¡¢·ÇÖÞºÍÄÏÃÀÖÞµÈÐÂÐËÊг¡×îÈÝÒ×Êܵ½¿ÉÒÆ¶¯Ã½ÌåÍþвµÄѬȾ£¬£¬£¬ £¬£¬£¬£¬µ«ÔÚÅ·Ö޺ͱ±ÃÀÒ²±£´æÒ»Ð©ÁæØêµÄ¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£


https://securelist.com/usb-threats-from-malware-to-miners/87989/


¡¾Çå¾²²¥±¨¡¿ÔÆÅÌË㹫˾ZohoµÄÓòÃû±»½ûÓýüÁ½Ð¡Ê±£¬£¬£¬ £¬£¬£¬£¬Ô¼3000ÍòÓû§ÊÜÓ°Ïì


Ó¡¶È×ÅÃûÔÆÅÌËã¿Æ¼¼¹«Ë¾ZohoµÄÓòÃû£¨zoho.com£©±»ÆäÓòÃû×¢²áÉÌTierraNet½ûÓýüÁ½¸öСʱ£¬£¬£¬ £¬£¬£¬£¬ÔÚ´Ëʱ´úÓû§±»Öض¨ÏòÖÁÒ»¸ö¿ÕÈ±Ò³Ãæ£¬£¬£¬ £¬£¬£¬£¬Ô¼3000ÍòÓû§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£Æ¾Ö¤TierraNetµÄ˵·¨£¬£¬£¬ £¬£¬£¬£¬Æä¶à´ÎÊÕµ½¹ØÓÚʹÓÃZohoÓʼþЧÀÍ·¢ËÍ´¹ÂÚÓʼþµÄͶËߣ¬£¬£¬ £¬£¬£¬£¬µ«ÔÚÊý´ÎÓëZohoÏàͬºó¸ÃÎÊÌâûÓлñµÃ½â¾ö£¬£¬£¬ £¬£¬£¬£¬×îÖÕÒ»Ì××Ô¶¯»¯ÏµÍ³µ¼ÖÂÁË´ËÊÂÎñµÄ±¬·¢¡£¡£¡£¡£¡£


https://www.zdnet.com/article/domain-registrar-oversteps-taking-down-zoho-domain-impacts-over-30mil-users/


¡¾Çå¾²²¥±¨¡¿Ñо¿Ö°Ô±ÑÝʾÔõÑùÈÆ¹ýmacOS MojaveÖеÄÇå¾²²½·¥²¢»á¼ûÓû§µÄÃô¸ÐÊý¾Ý


Çå¾²Ñо¿Ö°Ô±Patrick Wardle³ÆÆä¿ÉÒÔÈÆ¹ýmacOS Mojave ÖеÄÇå¾²²½·¥²¢»á¼ûÓû§µÄÃô¸ÐÊý¾Ý£¬£¬£¬ £¬£¬£¬£¬ÈçͨѶ¼ÖеÄÐÅÏ¢µÈ¡£¡£¡£¡£¡£WardleÌåÏÖ¸ÃÎó²îÓëAppleµÄÒþ˽±£»£»£»£»£»£»¤²½·¥µÄʵÏÖÓйØ¡£¡£¡£¡£¡£¸ÃÎó²î100%¿É¿¿£¬£¬£¬ £¬£¬£¬£¬¶ñÒâ»ò²»ÊÜÐÅÈεÄÓ¦ÓÿÉʹÓøÃÎó²îÈÆ¹ýеÄÇå¾²»úÖÆ²¢ÔÚδ¾­ÊÚȨµÄÇéÐÎÏ»á¼ûÓû§µÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ½«ÔÚ11Ô·ݵÄMacÇå¾²´ó»áÉÏÅû¶¸ü¶àÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/macos-mojave-privacy-bypass-flaw-allows-access-to-protected-files/


¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷Adwind RATÕë¶ÔÍÁ¶úÆäµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯


Cisco TalosºÍReversingLabsµÄÑо¿Ö°Ô±·¢Ã÷¶ñÒâÈí¼þAdwindµÄÒ»¸öбäÌ壬£¬£¬ £¬£¬£¬£¬¸Ã±äÌå¿ÉÕë¶ÔLinux¡¢WindowsºÍmacOSƽ̨¡£¡£¡£¡£¡£AdwindÊÇÒ»ÖÖÔ¶¿ØÄ¾Âí£¨RAT£©£¬£¬£¬ £¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷µÄÐÂÑù±¾ÊÇAdwind RAT 3.0£¬£¬£¬ £¬£¬£¬£¬¸Ã±äÌåʹÓÃÁËMicrosoft ExcelÖеĶ¯Ì¬Êý¾Ý½»Á÷£¨DDE£©´úÂë×¢Èë¹¥»÷¡£¡£¡£¡£¡£¸Ã±äÌåµÄ¹¥»÷»î¶¯ÓÚ2018Äê8ÔÂ26ÈÕ×îÏÈ£¬£¬£¬ £¬£¬£¬£¬Ö÷ÒªÕë¶ÔÍÁ¶úÆäµÄÓû§£¨75£¥£©£¬£¬£¬ £¬£¬£¬£¬Ò²ÓÐһЩÊܺ¦ÕßλÓڵ¹ú¡£¡£¡£¡£¡£Æä·Ö·¢·½·¨ÊÇÍÁ¶úÆäÓïµÄÀ¬»øÓʼþ¡£¡£¡£¡£¡£


https://blog.talosintelligence.com/2018/09/adwind-dodgesav-dde.html


¡¾Îó²î²¹¶¡¡¿±ÈÌØ±Ò½¹µãÍŶÓÐû²¼Ö÷Òª¸üУ¬£¬£¬ £¬£¬£¬£¬ÐÞ¸´µ×²ãÈí¼þÖеÄÒ»¸öDDoSÎó²î


±ÈÌØ±Ò½¹µã¿ª·¢ÍŶÓÐû²¼Çå¾²¸üУ¬£¬£¬ £¬£¬£¬£¬ÐÞ¸´±ÈÌØ±Òµ×²ãÈí¼þÖеÄÒ»¸öÖ÷ÒªµÄDDoSÎó²î¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2018-17144£©¿ÉÔÊÐíÈκαÈÌØ±Ò¿ó¹¤Ôì³É±ÈÌØ±Ò½¹µã½ÚµãµÄÍ߽⣬£¬£¬ £¬£¬£¬£¬ÏêϸÀ´Ëµ£¬£¬£¬ £¬£¬£¬£¬¿ó¹¤¿Éͨ¹ýÏòÇø¿éºé·ºÖظ´ÉúÒâÀ´µ¼ÖÂÆäËüÈ˵ÄÉúÒâÈ·ÈÏÊÜ×è»òͨ¹ýºé·º±ÈÌØ±ÒP2PÍøÂçµÄ½Úµãµ¼Ö´ø¿íºÄ¾¡¡£¡£¡£¡£¡£±ÈÌØ±Ò½¹µã°æ±¾0.14.0µ½0.16.2Êܵ½Ó°Ï죬£¬£¬ £¬£¬£¬£¬½¨ÒéÓû§ÊµÊ±¸üÐÂÖÁ×îа汾0.16.3¡£¡£¡£¡£¡£


https://thehackernews.com/2018/09/bitcoin-core-software.html

¡¾Êý¾Ýй¶¡¿ÁªºÏ¹úÒ»WordPressÍøÕ¾±£´æÇå¾²Îó²î£¬£¬£¬ £¬£¬£¬£¬Êýǧ·ÝÇóÖ°¼òÀúÒÉй¶


SeekurityÇå¾²Ñо¿Ö°Ô±Mohamed Baset·¢Ã÷ÁªºÏ¹úµÄÒ»¸öWordPressÍøÕ¾±£´æÂ·¾¶Ð¹Â¶Îó²îºÍÐÅϢй¶Îó²î£¬£¬£¬ £¬£¬£¬£¬Êýǧ·ÝÇóÖ°¼òÀúÒÉй¶¡£¡£¡£¡£¡£ÕâЩÇóÖ°¼òÀúµÄÈÕÆÚ×îÔç¿É×·ËÝÖÁ2016Äê¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÓÚ8ÔÂ6ÈÕÏòÁªºÏ¹ú±¨¸æÁË´ËÎÊÌ⣬£¬£¬ £¬£¬£¬£¬µ«Ö±ÖÁ9ÔÂ5ÈÕ²ÅÊÕµ½»Ø¸´³Æ¸ÃÎó²îÓëÁªºÏ¹ú¿ª·¢ÍýÏëÊð£¨UNDP £©Ïà¹Ø¡£¡£¡£¡£¡£ÏÖÔÚ¸ÃÎó²î»¹Î´±»ÐÞ¸´¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/united-nations-wordpress-site-exposes-thousands-of-resumes/



¡¾¿­·¢k8¼¯ÍÅADLabÕûÀíÐû²¼¡¿