¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181229
°ä²¼¹¦·ò 2018-12-29
½üÆÚ£¬£¬£¬£¬£¬£¬£¬£¬¹ú¶ÈÍøÐŰì»áͬÓйز¿ÃÅÕë¶ÔÍøÃñ·´Ó³Ç¿ÁÒµÄÎ¥·¨Î¥¹æ¡¢µÍËײ»Á¼Òƶ¯ÀûÓ÷¨Ê½£¨APP£©ÂÒÏ󣬣¬£¬£¬£¬£¬£¬£¬¼¯Öз¢Õ¹ËãÕÊÕûÖÎרÏîÐж¯£¬£¬£¬£¬£¬£¬£¬£¬ÒÀ·¨¹ØÍ£Ï¼ܡ°³ÉÈËÔ¼ÁÄ¡±¡°Á½ÐÔ˽ÃÜȦ¡±¡°°ÄÃŽðɳ¡±¡°Ò¹É«µÄ¼Åᡱ¡°È«ÃñÉäË®¹û¡±µÈ3469¿îÉæ»ÆÉæ¶Ä¡¢¶ñÒâ¿Û·Ñ¡¢ÇÔÈ¡ÒþÖÔ¡¢ÓÕÆÚ¿Æ¡¢Î¥¹æÓÎÏ·¡¢²»Á¼½ø½¨ÀàAPP¡£¡£¡£¡£¡£¡£¡£¾Ýͳ¼Æ£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ÔÚ¹úÄÚÀûÓÃÉ̵êÉϼܵÄAPPÒѾ³¬¹ý480Íò¿î£¬£¬£¬£¬£¬£¬£¬£¬º¸ÇÁËÈËÃñÉúÑĵĸ÷¸ö·½Ãæ¡£¡£¡£¡£¡£¡£¡£½üÈÕ£¬£¬£¬£¬£¬£¬£¬£¬¹ú¶ÈÍøÐŰ켯ÌåԼ̸28¼ÒÀûÓÃÉ̵ꡢÉ罻ƽ̨ºÍÔÆ·þÎñÆóÒµ£¬£¬£¬£¬£¬£¬£¬£¬¶ÔÆäÍÆ¹ãÖ÷ÌåÔðÈβ»Á¦¡¢¿Í¹ÛÉÏΪΥ·¨Î¥¹æAPPÌṩ½ÓÈëͨ·¡¢À©É¢Çþ·Ìá³öÖҸ棬£¬£¬£¬£¬£¬£¬£¬ÒªÇóÁ¢¼´¶Ô¸÷×ÔÆ½Ì¨½øÐÐÈ«ÃæÅŲ飬£¬£¬£¬£¬£¬£¬£¬µ±Õæ·¢Õ¹×Ô²é×Ô¾À£¬£¬£¬£¬£¬£¬£¬£¬»ý¼«×Ô¶¯²Î¼ÓÎ¥·¨Î¥¹æAPPÂÒÏóרÏîÕûÖÎÐж¯£¬£¬£¬£¬£¬£¬£¬£¬ËãÕʵ±ÓÃÉ̵꣬£¬£¬£¬£¬£¬£¬£¬ÆÁ±Î¶ñÒâÁ´½Ó£¬£¬£¬£¬£¬£¬£¬£¬²é¾¿½ÓÈë·þÎñ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2018-12/28/c_1123919199.htm2¡¢×êÑÐÈËÔ±Åû¶Edgeä¯ÀÀÆ÷ÖÐRCE·ì϶µÄPoC´úÂë
Phoenhexgroup°²È«×êÑÐÔ±Bruno Keith°ä²¼Î¢ÈíEdgeä¯ÀÀÆ÷ÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-8629£©µÄPoC´úÂë¡£¡£¡£¡£¡£¡£¡£¸ÃPoC´úÂëÓÐ71ÐУ¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ½½ç£¨OOB£©ÄÚ´æ¶ÁÈ¡£¬£¬£¬£¬£¬£¬£¬£¬µ«¹¥»÷ÕßÄܹ»Í¨¹ý¶Ô´úÂë½øÐе¥Ò»µÄ³ÁÐÂÉè¼ÆÀ´ÊµÏÖ¸üÓꦵÄÁ˾֡£¡£¡£¡£¡£¡£¡£Î¢ÈíÔÚ12Ô·ݵݲȫ¸üÐÂÖн¨¸´ÁËÕâÒ»·ì϶£¬£¬£¬£¬£¬£¬£¬£¬Æ¾¾Ý΢ÈíµÄÃèÊö£¬£¬£¬£¬£¬£¬£¬£¬Chakra¾ç±¾ÒýÇæ´¦ÖÃMicrosoft EdgeÄÚ´æ¶ÔÏóµÄ·½Ê½ÖдæÔÚÒ»¸öÔ¶³ÌÖ´ÐдúÂë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÔÊÐí¹¥»÷ÕßÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/79264/hacking/microsoft-edge-poc-exploit.html3¡¢ºÚ¿Í¹¥»÷ElectrumÇ®°ü»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡200¶à±ÈÌØ±Ò
ºÚ¿Í»òºÚ¿Í×é֯ͨ¹ý¹¥»÷Electrum±ÈÌØ±ÒÇ®°üµÄ»ù´¡ÉèÊ©ÇÔÈ¡ÁË200¶à±ÈÌØ±Ò£¬£¬£¬£¬£¬£¬£¬£¬¼ÛֵԼĪ75ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈÏòElectrumÇ®°üÍøÂçÔö³¤Êýʮ̨¶ñÒâ·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬£¬µ±Óû§µÄºÏ·¨±ÈÌØ±ÒÂòÂôͨ¹ý¶ñÒâ·þÎñÆ÷ʱ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·þÎñÆ÷½«ÏòÓû§µ¯³öÃýÎóÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬£¬²¢¶½´ÙÓû§´Ó¹¥»÷ÕßµÄGitHub¿âÖÐÏÂÔØ¶ñÒâµÄÇ®°ü¸üС£¡£¡£¡£¡£¡£¡£Ò»µ©Óû§´ò¿ª¶ñÒâÇ®°ü²¢Ìṩ2FA´úÂ룬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß½«×ª×ßÓû§Ç®°üÀïµÄ±ÈÌØ±Ò¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ʼÓÚ12ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚGithubɾ³ýÁ˶ñÒâµÄ¿âºóÖÕ³¡£¬£¬£¬£¬£¬£¬£¬£¬µ«ÓÉÓÚÖ÷Ìâ·ì϶ÉÐ佨¸´£¬£¬£¬£¬£¬£¬£¬£¬ElectrumÖÒ¸æ³ÆÀàËÆµÄ¹¥»÷¿ÉÄÜ»áÔٴβúÉú¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/users-report-losing-bitcoin-in-clever-hack-of-electrum-wallets/4¡¢Nova EntertainmentÌý¶àÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬25Íò°Ä´óÀûÑÇÈËÊܵ½Ó°Ïì
Nova EntertainmentµÄÊ×ϯִÐйÙCathy O'Connor±¾ÖÜËÄÔÚÒ»·ÝÉêÃ÷ÖаµÊ¾£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄÒ»¸ö¡°ÒÅÁôÊý¾Ý¼¯¡±²úÉúй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬³¬¹ý25Íò°Ä´óÀûÑÇÌý¶àÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£ÕâЩÊý¾ÝÊÇ2009Äê5ÔÂÖÁ2011Äê10ÔÂÆÚ¼äµÄÓû§ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬Óû§ÃûºÍ¹þÏ£ÃÜÂë¡¢¼Òͥסַ¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢ÐÔ±ðºÍµ®ÉúÈÕÆÚ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾Ã»ÓвÆÕþÐÅÏ¢»òÉí·ÝIDÐÅϢй¶£¬£¬£¬£¬£¬£¬£¬£¬ÆäÏÖÓÐϵͳҲûÓÐÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£NovaÒѾ֪ͨ°Ä´óÀûÑÇÐÅϢרԱ°ì¹«ÊÒ£¨OAIC£©£¬£¬£¬£¬£¬£¬£¬£¬²¢ÁªÏµ·¨ÂÉ»ú¹¹½øÐе÷²é¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.smh.com.au/business/companies/nova-warns-listeners-of-major-data-breach-affecting-250-000-listeners-20181228-p50omw.html5¡¢º«¹ú°²ÉèÖÐÐÄÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬½ü1000ÃûÍѱ¹ØßÓ×ÎÒÐÅϢй¶
º«¹úµ±¾Öй©£¬£¬£¬£¬£¬£¬£¬£¬Æä25¸ö°²ÉèÖÐÐÄÖеÄÒ»¸öÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬½ü1000ÃûÍѱ¹ØßµÄÓ×ÎÒÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£¸Ã°²ÉèÖÐÐĵÄÒ»ÃûÔ±¹¤ÔÚ2018Äê12ÔÂ19ÈÕÔâµ½´¹µöÓʼþ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÁËÕâ´Îй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍµÄÉí·ÝºÍÍøÂç¹¥»÷µÄÆðÔ´ÉÐδµÃµ½Ö¤Êµ¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬Íѱ¹ØßµÄÐÕÃû¡¢µ®ÉúÈÕÆÚºÍ¼ÒͥסַµÈÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£º«¹úµ±¾ÖÈÔÔÚ¶ÔÕâÒ»ÊÂÎñ½øÐе÷²é¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hackers-steal-personal-info-of-1000-north-korean-defectors/6¡¢ESET°ä²¼¹ØÓÚEmotet×îй¥»÷»î¶¯µÄ·ÖÎö»ã±¨
ESET×êÑÐÈËÔ±°ä²¼¹ØÓÚEmotet×îй¥»÷»î¶¯µÄ·ÖÎö»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬¸Ã»î¶¯ÖØÒªÕë¶ÔÀ¶¡ÃÀÖÞ¹ú¶È¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯ÖÐEmotetͨ¹ýÀ¬»øÓʼþ´«²¼£¬£¬£¬£¬£¬£¬£¬£¬Æä¶ñÒ⸽¼þÊÇOffice WordÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÎļþÖеĶñÒâºê½«Æô¶¯PowerShell¾ç±¾²¢³¢ÊÔ´Ó5¸ö¶ñÒâÕ¾µãÏÂÔØÓÐЧºÉÔØ£¨¾¹ý»ìºÏµÄEmotet£©¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯ÆðÍ·ÓÚ11Ô·ݣ¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¼«¶È»îÔ¾¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.welivesecurity.com/2018/12/28/analysis-latest-emotet-propagation-campaign/ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ