¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180917

°ä²¼¹¦·ò 2018-09-17
1¡¢Î¢Èí½¨¸´¶à¸öWindows°æ±¾Öпɵ¼ÖÂDoSµÄFragmentSmack·ì϶



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


΢Èí°ä²¼¹ØÓڿɵ¼ÖÂDoSµÄ°²È«·ì϶FragmentSmackµÄ°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶£¨CVE-2018-5391£©ÊÇÒ»ÖÖIPË鯬¹¥»÷£¨Teardrop¹¥»÷£©£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÍÆËã»úµÄCPU´ïµ½×î´óÀûÓÃÂʲ¢ÇÒ²Ù×÷ϵͳÎÞÏìÓ¦ ¡£¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁËWindows 7¡¢8ºÍ10ÒÔ¼°Server 2008¡¢2012ºÍ2016ϵͳ ¡£¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì×°ÖÃÏàÓ¦µÄ¸üР¡£¡£¡£¡£¡£¡£


   Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/windows-systems-vulnerable-to-fragmentsmack-90s-like-dos-bug/


2¡¢×êÑÐÈËÔ±·¢ÏÖmacOS°²È«Èí¼þWebroot SecureAnywhere´æÔÚÄں˼¶·ì϶



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


TrustwaveµÄ×êÑÐÈËÔ±·¢ÏÖmacOS°²È«Èí¼þWebroot SecureAnywhereÖдæÔÚÒ»¸ö¿É±»±¾µØÀûÓõÄÄں˼¶·ì϶ ¡£¡£¡£¡£¡£¡£¸Ã·ì϶£¨CVE-2018-16962£©ÊÇÓɶÌȱ¶ÔÓû§Ö¸ÕëµÄÑéÖ¤¶øµ¼Öµģ¬£¬£¬£¬£¬£¬£¬£¬ÔÚijЩÇé¿öÏ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÄÜÓëÆäËü·ì϶½áºÏÒÔ½øÐб¾µØÌáȨ£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÒÔÄں˼¶È¨ÏÞÖ´ÐжñÒâÈí¼þ ¡£¡£¡£¡£¡£¡£Webroot SecureAnywhere°æ±¾9.0.8.34Öн¨¸´Á˸ÃÎÊÌâ ¡£¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/76220/hacking/webroot-secureanywhere-flaw.html


3¡¢×êÑÐÈËÔ±ÑÝʾͨ¹ýCSSºÍHTMLÍøÒ³µ¼ÖÂiPhone³ÁÆôºÍMac¿¨ËÀµÄй¥»÷²½Öè



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Wire°²È«×êÑÐÈËÔ±Sabri HaddoucheÉè¼Æ³öÒ»ÖÖͨ¹ýCSS&HTMLÍøÒ³¼±¾çºÄ¾¡Æ»¹ûÉ豸×ÊÔ´µÄ¹¥»÷²½Öè ¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷¿É¼±¾ç¿÷ËðËùÓеÄͼÐÎ×ÊÔ´²¢µ¼Ö²Ù×÷ϵͳ±ÀÀ£»£»£»£»£»£»£»ò¿¨ËÀ£¬£¬£¬£¬£¬£¬£¬£¬ËùÓÐʹÓÃWebKitäÖȾÒýÇæµÄiOSä¯ÀÀÆ÷ÒÔ¼°macOSÖеÄSafariºÍMail¶¼Êܵ½Ó°Ïì ¡£¡£¡£¡£¡£¡£¶ÔÓÚiOS£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷½«µ¼ÖÂÄں˱ÀÀ£²¢³ÁÆô£»£»£»£»£»£»£»¶ÔÓÚmacOS£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷½«µ¼ÖÂSafari»á»°³ÁÆô¼°É豸¿¨ËÀ ¡£¡£¡£¡£¡£¡£Ä¿Ç°»¹Ã»Óз¨×Ó·À»¤´ËÀ๥»÷ ¡£¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-css-attack-restarts-an-iphone-or-freezes-a-mac/


4¡¢×êÑÐÍŶӷ¢ÏÖ¼Ù×°³ÉÓ¢¹ú˰Îñ¾ÖHMRCµÄ´¹µöÓʼþ¹¥»÷



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Malwarebytes Labs×êÑÐÍŶӷ¢ÏÖ¼Ù×°³ÉÓ¢¹ú˰Îñ¾ÖHMRCµÄÍøÂç´¹µö»î¶¯ ¡£¡£¡£¡£¡£¡£¸Ã´¹µöÓʼþµÄÖ÷ÌâÊÇ542.94Ó¢°÷µÄÍË˰£¬£¬£¬£¬£¬£¬£¬£¬ÓʼþÕýÎÄÖÐÔ̺¬ÓÃÓÚÍË˰µÄÍøÕ¾Á´½Ó ¡£¡£¡£¡£¡£¡£¸Ã´¹µöÍøÕ¾µÄµÚÒ»¸öÈë¿ÚµãÊÇÐéαµÄOutlookµÇÂ¼Ò³Ãæ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÍøÖ·ÊÇonlinehmrevnue(.)from-tx(.)com/webGBTxid/checkValidation(.)php£¬£¬£¬£¬£¬£¬£¬£¬Ò»µ©Óû§ÊäÈëÓйØÍ´´¦£¬£¬£¬£¬£¬£¬£¬£¬¾Í»áÌø×ªµ½Ò»¸öÓÃÓÚÍøÂçÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂëµÈÐÅÏ¢µÄÍøÒ³ ¡£¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º
https://blog.malwarebytes.com/cybercrime/2018/09/hmrc-phish-swipes-email-login-payment-details/


5¡¢°²È«×êÑÐÈËÔ±·¢ÏÖÀÕË÷Èí¼þDharmaµÄбäÌåBrrr



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×êÑÐÈËÔ±Jakub Kroustek·¢ÏÖÀÕË÷Èí¼þDharma¼Ò×åµÄÒ»¸öбäÌ壬£¬£¬£¬£¬£¬£¬£¬¸Ã±äÌåÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.brrrÀ©´óÃû ¡£¡£¡£¡£¡£¡£Dharmaͨ¹ýRDPÏνӰ춯½øÐзַ¢£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýɨÃèÊ¢¿ªµÄTCP3389¶Ë¿Ú£¬£¬£¬£¬£¬£¬£¬£¬¶ÔÆä½øÐб©Á¦ÆÆ½âÒÔ»ñµÃµÇ¼ʹ´¦ ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÒ²¿ÉÄÜ´ÓµØÏÂÂÛ̳²É°ì¿É½Ó¼ûµÄRDPµÇ¼ʹ´¦ ¡£¡£¡£¡£¡£¡£Brrr»áÔÚ¼ÓÃܵÄÎļþºóÔö³¤.id-[id].[email].brrrÀ©´óÃû ¡£¡£¡£¡£¡£¡£Ä¿Ç°»¹Ã»Óз¨×ÓÃâ·Ñ½âÃܸñäÌå¼ÓÃܵÄÎļþ ¡£¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-brrr-dharma-ransomware-variant-released/


6¡¢Ó¢¹ú²¼Àï˹Íжû»ú³¡Ôâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬º½°àÐÅÏ¢ÏÔʾÆÁÒÑÖÕ³¡·þÎñÁ½Ìì



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ó¢¹ú²¼Àï˹Íжû»ú³¡Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Æäº½°àÐÅÏ¢ÏÔʾÆÁÒÑÖÕ³¡·þÎñÁ½Ìì ¡£¡£¡£¡£¡£¡£¸Ã»ú³¡µÄ½²»°È˰µÊ¾º½°à²»ÊÜÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬µ«±ØÐëʹÓÃÓ¦¼±´ëÊ©ºÍÊÖ¶¯µÄÁ÷³Ì£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬°×°åºÍ¼ÇºÅ±ÊµÈÀ´°ü°ìÏÔʾÆÁ ¡£¡£¡£¡£¡£¡£¸Ã»ú³¡Ã»ÓÐÏò¹¥»÷ÕßÖ§¸¶Êê½ð ¡£¡£¡£¡£¡£¡£Õâ²»ÊÇÒ»´ÎÕë¶ÔÐԵĹ¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¶øÊÇËæ»úµÄ¹¥»÷ ¡£¡£¡£¡£¡£¡£¸Ã»ú³¡ÔÚÈ·±£Æäº½°àÐÅϢϵͳÔÚ³ÁÐÂÉÏÏß֮ǰÊǰ²È«µÄ ¡£¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/76248/breaking-news/bristol-airport-cyber-attack.html


ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù