¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180711
°ä²¼¹¦·ò 2018-07-11¡¾·ÖÎö»ã±¨¡¿°²È«×êÑлú¹¹°ä²¼2018ÄêµÚ¶þ¼¾¶ÈAPTÇ÷Ïò»ã±¨
¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼2018ÄêµÚ¶þ¼¾¶ÈµÄAPTÇ÷Ïò»ã±¨£¬£¬£¬£¬£¬£¬£¬ÑÇÖÞ¹¥»÷Õß×îΪ»îÔ¾£¬£¬£¬£¬£¬£¬£¬Ô̺¬Lazarus/BlueNoroff¡¢Reaper¡¢DarkHotelºÍLuckyMouseµÈ¡£¡£¡£¡£¡£¡£±¾¼¾¶È×îÒýÈËÖõÖ÷ÕŹ¥»÷»î¶¯ÊÇAPT×éÖ¯SofacyºÍSandwormµÄVPNFilter»î¶¯¡£¡£¡£¡£¡£¡£Ëƺõ´Óǰ¼¸ÄêÖÐ×îΪ»îÔ¾µÄһЩ×éÖ¯ÒѾÏ÷¼õÁËËüÃǵĻ£¬£¬£¬£¬£¬£¬£¬µ«Õâ²¢²»ÁÏζ×ÅËüÃǵÄΣÏÕÐÔ±äÓס£¡£¡£¡£¡£¡£ÀýÈçSofacyÔö³¤ÁËÓÃGo˵»°±àдµÄÐÂÏÂÔØÆ÷ÒÔ·Ö·¢Zebrocy¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±»¹¹Û²ìµ½ÐµÄAPT×éÖ¯PerfanlyÒÔ¼°²¿ÃÅÕÝ·üÊýÔÂÉõÖÁÊýÄêµÄAPT×éÖ¯³ÁгöÏÖ£¨ÈçWhiteWhale£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securelist.com/apt-trends-report-q2-2018/86487/
¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖ·¸×ïÍÅ»ïMagecartµÄ´ó¹æÄ£ÐÅÓþ¿¨ÐÅϢ͵ÇԻ
RiskIQ×êÑÐÍŶӷ¢ÏÖTicketmasterµÄÊý¾Ýй¶ÊÂÎñÖ»ÊǸü´ó¹æÄ£µÄÐÅÓþ¿¨ÐÅϢ͵ÇԻµÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±½øÒ»²½Ö¸³öÆä×ï¿ý»öÊ×ÊÇ·¸×ïÍÅ»ïMagecart£¬£¬£¬£¬£¬£¬£¬ÆäÕë¶ÔÐÅÓþ¿¨ÐÅÏ¢µÄ͵ÇԻӰÏìÁËÈ«Çò800¶à¸öµç×ÓÉÌÎñÍøÕ¾¡£¡£¡£¡£¡£¡£Magecartͨ¹ý×¢ÈëÍøÕ¾µÄ½ÅÕý±¾ÇÔÈ¡µç×ÓÉÌÎñÍøÕ¾µÄÔÚÏßÖ§¸¶ÐÅÏ¢¡£¡£¡£¡£¡£¡£²»½ö½öÊÇTicketmasterµÄµÚÈý·½²å¼þÌṩÉÌInbentaÔâµ½ÉøÈ룬£¬£¬£¬£¬£¬£¬PushAssist¡¢Clarity ConnectÒÔ¼°Annex CloudµÈÒ²±»ÉøÈë¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.riskiq.com/blog/labs/magecart-ticketmaster-breach/
¡¾¹¥»÷ÊÂÎñ¡¿¼ÓÃÜÇ®±ÒÂòÂôËùBancorÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬¼ÛÖµÔ¼1250ÍòÃÀÔªµÄÒÔÌ«±Ò±»ÇÔ
7ÔÂ9ÈÕÒÔÉ«ÁмÓÃÜÇ®±ÒÂòÂôËùBancorÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß´ÓBancorÖÇÄܺÏÔ¼ÖÐÇÔÈ¡ÁË24984¸öÒÔÌ«±Ò£¨¼ÛÖµÔ¼1250ÍòÃÀÔª£©£¬£¬£¬£¬£¬£¬£¬Í¬Ê±»¹ÇÔÈ¡ÁË229356645¸öNPXS±Ò£¨¼ÛÖµÔ¼100ÍòÃÀÔª£©¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹ÇÔÈ¡ÁË320Íò¸öBancorÁîÅÆ£¨BNT£©£¬£¬£¬£¬£¬£¬£¬¼ÛÖµÔ¼1000ÍòÃÀÔª£¬£¬£¬£¬£¬£¬£¬µ«Bancor³ÆÆä°²È«Ö°Äܶ³½áÁ˸ñÊ×ʽ𡣡£¡£¡£¡£¡£Bancor°µÊ¾¹¥»÷Õß²¢Î´Õë¶ÔÈκÎÓû§Ç®°ü£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐй©¹¥»÷ÕßµÄÈëÇÖ·½Ê½¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hacker-steals-135-million-from-bancor-cryptocurrency-exchange/
¡¾·ì϶²¹¶¡¡¿Apple°ä²¼¶à¿î²úÆ·µÄ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬µ«ÐÂÍÆ³öµÄusbÏÞ¶ÈģʽÒѱ»Èƹý
Apple°ä²¼Õë¶ÔmacOS¡¢iOS¡¢watchOs¡¢tvOS¡¢Safari¡¢iCloud for WindowsºÍiTunes for WindowsµÈ²úÆ·µÄ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´¶à¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£Apple»¹ÔÚiOS 11.4.1ÖÐÍÆ³öÁËеÄusbÏÞ¶Èģʽ£¬£¬£¬£¬£¬£¬£¬¸Ãģʽ¿ÉÔÚÒ»Ó×ʱºó½ûÓÃiOSÉ豸ÉϵÄUSB¶Ë¿Ú£¬£¬£¬£¬£¬£¬£¬ÒÔÔ¤·ÀһЩÈí¼þ¹«Ë¾µÄiPhone½âËø¼¼Êõ¡£¡£¡£¡£¡£¡£µ«Èí¼þ¹«Ë¾Elcomsoft³Æ¿Éͨ¹ý²åÈëÈκÎUSBÉ豸À´Èƹý¸Ãģʽ¡£¡£¡£¡£¡£¡£¾ßÌå¸üÐÂÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/apple/apple-releases-security-updates-for-ios-macos-and-more/
¡¾·ì϶²¹¶¡¡¿Î¢Èí°ä²¼2018Äê7Ô°²È«¸üУ¬£¬£¬£¬£¬£¬£¬¹²½¨¸´15¸ö²úÆ·ÖеÄ53¸ö°²È«·ì϶
΢ÈíµÄ7Ô°²È«¸üй²½¨¸´ÁË53¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬17¸ö¸ßΣ·ì϶¡£¡£¡£¡£¡£¡£ÑϳÁÐÔ×î¸ßµÄä¯ÀÀÆ÷·ì϶ÊÇÓëJScriptÒýÇæChakraÓйصÄËĸöÄÚ´æ°Ü»µ·ì϶£¨CVE-2018-8280¡¢CVE-2018-8286¡¢CVE-2018-8290¡¢CVE-2018-8294£©£¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶¶¼¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£ÁíÒ»¸ö½ÏΪÑϳÁµÄ·ì϶ÊÇWindows DNSAPIÖеĻؾø·þÎñ·ì϶£¨CVE-2018-8304£©¡£¡£¡£¡£¡£¡£¾ßÌå·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/microsoft/microsoft-july-2018-patch-tuesday-fixes-53-security-bugs-across-15-products/
¡¾Êý¾Ýй¶¡¿Ã·Î÷°Ù»õ²¿ÃÅÓû§µÄµÇ¼ʹ´¦Ôâй£¬£¬£¬£¬£¬£¬£¬Òì³£ÕË»§Òѱ»¶³½á
÷Î÷°Ù»õ³ÆÔÚ2018Äê4ÔÂ26ÈÕÖÁ6ÔÂ12ÈÕÆÚ¼ä£¬£¬£¬£¬£¬£¬£¬Î´¾ÊÚȨµÄµÚÈý·½Ê¹ÓÃÓÐЧµÄµÇ¼ʹ´¦½Ó¼ûÁËÓû§µÄÔÚÏß×ÊÁÏ£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜй¶µÄÐÅÏ¢Ô̺¬Óû§µÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢ÉúÈÕÒÔ¼°½è¼Ç¿¨»òÐÅÓþ¿¨µÄºÅÂë¼°ÓÐЧÆÚ¡£¡£¡£¡£¡£¡£Óû§µÄÉç±£ºÅÂë¼°ÒøÐп¨CVVºÅÂ벢δй¶¡£¡£¡£¡£¡£¡£Ã·Î÷°Ù»õµÄ½²»°È˳ÆÊÜÓ°ÏìµÄÓû§Ö»Õ¼ÆäÓû§µÄ1%¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÒѾ¶³½áÁËÕâЩÒì³£ÕË»§¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/macy-s-locks-small-number-of-accounts-following-suspicious-logins-fraud-reports/


¾©¹«Íø°²±¸11010802024551ºÅ