2019ÄêÕë¶ÔMacÓû§µÄ´¹ÂÚ¹¥»÷ÔöÌíÖÁ160Íò´Î£»£»£»ÃÀ¹ú²ÆÎñ²¿Ðû²¼¶ÔÈý¸ö³¯ÏʺڿÍ×é֯ʵÑéÖÆ²Ã

Ðû²¼Ê±¼ä 2019-09-16

1.2019ÄêÕë¶ÔMacÓû§µÄ´¹ÂÚ¹¥»÷ÔöÌíÖÁ160Íò´Î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¿¨°Í˹»ùÔÚ2019ÄêµÄǰÁù¸öÔÂÖй²²¶»ñµ½160Íò´ÎÕë¶ÔMacÓû§µÄ´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£2018ÄêÕûÄêʹÓÃAppleÆ·ÅÆµÄ´¹ÂÚ¹¥»÷´ÎÊýΪ150Íò´Î£¬£¬£¬£¬£¬½ñÄêÉϰëÄêÒѾ­Áè¼ÝÁËÕâÒ»Êý×Ö¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿¨°Í˹»ùÌåÏÖ´ËÀ๥»÷ͨ³£Ã¿ÄêÔöÌí30-40%¡£¡£¡£¡£¡£¡£°ÍÎ÷µÄmacOSÓû§ÖÐÊÜ´¹ÂÚ¹¥»÷µÄ±ÈÀý×î´ó£¬£¬£¬£¬£¬Îª30%£¬£¬£¬£¬£¬¶ø·¨¹úºÍÓ¡¶ÈµÄ±ÈÀýԼΪ22%¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿¨°Í˹»ùÇ¿µ÷³Æ¹¥»÷ÕßÔ½À´Ô½¶àµØÊ¹ÓÃAppleͼ±êÀ´ÓÕÆ­Óû§µÄApple IDºÍƾ֤¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¿¨°Í˹»ùÌåÏÖ×Ô2015ÄêÒÔÀ´ÍøÂç´¹ÂÚ¹¥»÷µÄ×ÜÊýÔøÖ¸Êý¼¶ÔöÌí£¬£¬£¬£¬£¬ÆäʱµÄÊý×ÖΪԼ85Íò´Î¹¥»÷£¬£¬£¬£¬£¬¶øÔÚ½ñÄêÉϰëÄê´¹ÂÚ¹¥»÷µÄ×ÜÊýΪ½ü600Íò´Î¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.techrepublic.com/article/phishing-scams-targeting-mac-users-on-the-rise-with-1-6-million-attacks-in-2019/


2.ÃÀ¹ú²ÆÎñ²¿Ðû²¼¶ÔÈý¸ö³¯ÏʺڿÍ×é֯ʵÑéÖÆ²Ã


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÃÀ¹ú²ÆÎñ²¿Ðû²¼¶ÔÈý¸öÓɹú¼ÒÖ§³ÖµÄ³¯ÏʺڿÍ×é֯ʵÑéÖÆ²Ã£¬£¬£¬£¬£¬°üÀ¨·¸·¨ÍÅ»ïLazarus Group¼°Æä×Ó¼¯ÍÅBluenoroffºÍAndariel¡£¡£¡£¡£¡£¡£ÕâЩºÚ¿Í×éÖ¯±»Ö¸¿Ø¶ÔÃÀ¹úÒªº¦»ù´¡ÉèʩʵÑéÁ˶à´ÎÆÆËðÐÔÍøÂç¹¥»÷ÒÔ¼°´ÓÈ«Çò½ðÈÚ»ú¹¹ÇÔÈ¡ÊýÒÚÃÀÔª²¢Îª³¯ÏÊÕþ¸®µÄ²»·¨ÎäÆ÷ºÍµ¼µ¯ÍýÏëÌṩ×ʽ𡣡£¡£¡£¡£¡£²ÆÎñ²¿Íâ¹ú×ʲú¿ØÖư칫ÊÒ£¨OFAC£©ÌåÏÖÖÆ²ÃµÄÄ¿µÄÊÇËø¶¨ÈκÎÓÐÒâΪÕâЩºÚ¿Í×éÖ¯Ìá¹©ÖØ´óÉúÒâ»òЧÀ͵ÄÍâ¹ú½ðÈÚ»ú¹¹£¬£¬£¬£¬£¬²¢¶³½áÓëÕâÈý¸ö×éÖ¯Ïà¹ØµÄÈκÎ×ʲú¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/09/north-korea-cyber-attack.html


3.ÓŲ½ÐÞ¸´¿Éµ¼ÖÂÓû§ÕË»§±»½ÓÊܵÄAPIÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Anand Prakash·¢Ã÷ÓŲ½µÄÒ»¸öAPIÎó²î¿ÉÓÃÓÚ½ÓÊÜÓû§ÕË»§ºÍ¸ú×ÙÓû§¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÊ×ÏÈͨ¹ý·¢ËͰüÀ¨Óû§µç»°ºÅÂë»òµç×ÓÓʼþµØµãµÄAPIÇëÇóÀ´»ñÈ¡ÈκÎÓû§µÄΨһ±êʶ·û£¨UUID£©£¬£¬£¬£¬£¬È»ºóʹÓøÃUUIDÖØÐ·¢ËÍÇëÇ󣬣¬£¬£¬£¬´Ó¶ø¿ÉÒÔ»ñÈ¡ÒÆ¶¯APPµÄ»á¼ûÁîÅÆ¡¢Î»Öú͵صãµÈ˽ÈËÐÅÏ¢¡£¡£¡£¡£¡£¡£PrakashÌåÏÖͨ¹ý»á¼ûÁîÅÆ£¬£¬£¬£¬£¬ËûÄܹ»ÍêÈ«½ÓÊܲâÊÔÕË»§¡¢·¢Ëͳ˳µÇëÇóÒÔ¼°»ñÈ¡¸¶¿îÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¸ÃÎÊÌâͬʱӰÏìÁËÓŲ½Óû§ºÍ˾»ú¡£¡£¡£¡£¡£¡£ÓŲ½ÔÚÈ·ÈÏÁ˸ÃÎÊÌâºóѸËÙÐÞ¸´ÁËÏà¹ØÎó²î¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.forbes.com/sites/daveywinder/2019/09/12/uber-confirms-account-takeover-vulnerability-found-by-forbes-30-under-30-honoree/


4.InstagramÐÞ¸´¿Éµ¼ÖÂÕË»§ÐÅϢй¶µÄÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


FacebookÐÞ¸´ÁËInstagramÖпɵ¼Ö¹¥»÷Õß»ñÈ¡Óû§Ë½ÈËÐÅÏ¢µÄÎó²î¡£¡£¡£¡£¡£¡£Çå¾²Ñо¿Ô±@ZHacker13ÌåÏֿɱ»»ñÈ¡µÄÓû§Êý¾Ý°üÀ¨ÕæÊµÐÕÃû¡¢ÍêÕûµç»°ºÅÂëÒÔ¼°InstagramÕʺÅÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¸Ãר¼Ò»¹ÖÒÑԳƹ¥»÷Õß¿ÉÒÔʹÓÃ×Ô¶¯¾ç±¾ºÍ»úеÈË´ÓÆ½Ì¨ÍøÂçÓû§Êý¾Ý£¬£¬£¬£¬£¬²¢½«Óû§ÓëÆäÁªÏµÈËÐÅÏ¢¹ØÁªÆðÀ´¡£¡£¡£¡£¡£¡£¹¥»÷³¡¾°°üÀ¨Á½¸ö°ì·¨£ºÊ×ÏÈÊÇÔÚInstagramµÄµÇ¼±íµ¥ÉϾÙÐб©Á¦¹¥»÷£¬£¬£¬£¬£¬Ò»´Î¼ì²éÒ»¸öµç»°ºÅÂ룬£¬£¬£¬£¬ÒÔ±ãÁ´½Óµ½Ò»¸öÕæÊµµÄInstagramÕÊ»§£»£»£»È»ºóʹÓÃInstagramµÄͬ²½ÁªÏµÈ˹¦Ð§ÕÒµ½Óëµç»°ºÅÂëÏà¹ØÁªµÄÕÊ»§Ãû³ÆºÍºÅÂë¡£¡£¡£¡£¡£¡£Facebook½²»°ÈËÌåÏָù«Ë¾Í¨¹ýÐÞ¸ÄInstagramÁªÏµÈ˵¼Èë·½·¨ÐÞ¸´Á˸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/91253/hacking/instagram-bug-data-exposure.html


5.NemtyбäÌå¿ÉɱËÀVirtualBox¡¢SQLµÈÀú³Ì


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÀÕË÷Èí¼þNemtyÕýÔÚÆð¾¢¿ª·¢ÖУ¬£¬£¬£¬£¬Æä×÷ÕßÏÔÈ»ÕýÔÚÆð¾¢Ê¹Æä³ÉΪһÖÖ¸ü¸ßЧ¡¢ÖØ´óµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬²¢×îÏȸüÆÕ±éµÄ·Ö·¢¡£¡£¡£¡£¡£¡£Çå¾²Ñо¿Ô±Vitali KremezÆÊÎö·¢Ã÷Ö»¹ÜNemty×÷Õß¶Ô´úÂë¾ÙÐÐÁ˸ü¸Ä£¬£¬£¬£¬£¬µ«Ëü±£´æÁËÏàͬµÄ°æ±¾ºÅ¡£¡£¡£¡£¡£¡£×îеÄÑù±¾°üÀ¨ÓÃÓÚɱËÀÀú³ÌºÍЧÀ͵ĴúÂ룬£¬£¬£¬£¬Ä¿µÄÀú³Ì°üÀ¨WordPad¡¢Microsoft Word¡¢Excel¡¢Outlook¡¢µç×ÓÓʼþ¿Í»§¶ËThunderbird¡¢SQL¡¢oracle¡¢onenoteºÍÓÃÓÚÔËÐÐÐéÄâ»úµÄVirtualBoxÈí¼þ¡£¡£¡£¡£¡£¡£ÕâÒâζ×ÅNemtyÕýÔÚÕë¶ÔÆóÒµÊܺ¦Õß¡£¡£¡£¡£¡£¡£Nemty×î³õͨ¹ýRIG EK·Ö·¢£¬£¬£¬£¬£¬¶ø×îа汾1.4Ôòͨ¹ýÐéαµÄPayPalÍøÕ¾Èö²¥£¬£¬£¬£¬£¬ËæºóÓÖÐÂÔöÁËRadio EKÈö²¥ÇþµÀ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nemty-ransomware-update-lets-it-kill-processes-and-services/


6.д¹ÂÚȦÌ×Ö÷ÒªÇÔÈ¡ÑÇÂíÑ·Óû§µÄÐÅÓÿ¨Êý¾Ý


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Ñо¿Ö°Ô±·¢Ã÷Ò»¸öеĴ¹ÂÚÓʼþȦÌ×ÕýÔÚÈö²¥£¬£¬£¬£¬£¬¹¥»÷ÕßÖ÷ÒªÊÔͼÇÔÈ¡ÑÇÂíÑ·Óû§µÄÐÅÓÿ¨Êý¾Ý¡£¡£¡£¡£¡£¡£¸ÃȦÌ×µÄÊÂÇéÔ­ÀíÈçÏ£ºÊܺ¦ÕßÎüÊÕµ½Ò»·âαװ³ÉÀ´×ÔÑÇÂíÑ·µÄµç×ÓÓʼþ£¬£¬£¬£¬£¬Í¨ÖªÓÐ¹ØÆäÕË»§µÄ¿ÉÒɻ£¬£¬£¬£¬£¬¸ÃÓʼþʹÓûìÏýÁËÓ¢ÓïºÍ·¨ÓïµÄÖ÷Ì⣬£¬£¬£¬£¬ÒªÇóÊܺ¦Õßµã»÷Á´½ÓÀ´¸üÐÂÕË»§ÐÅÏ¢£¬£¬£¬£¬£¬°üÀ¨ÊäÈë»á¼ûƾ֤¡¢Õ˵¥µØµã¡¢²ÆÎñÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¸Ã´¹ÂÚÍøÕ¾ÍйÜÔÚwadwa-wmdw(dot)comÓòÃûÉÏ£¬£¬£¬£¬£¬´ËÓòÃûÊÇ8ÔÂ22ÈÕÔÚÒ»¸ö¶àÂ×¶àµØµã×¢²áµÄ£¬£¬£¬£¬£¬¸ÃµØµãºÜ¿ÉÄÜÖ»ÊÇÒ»¸öÐéαµØµã¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/new-amazon-phishing-scam-stealing-credit-card-data/