¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180926

°ä²¼¹¦·ò 2018-09-26

¡¾·ÖÎö»ã±¨¡¿°²È«×êÑÐÍŶӰ䲼¹ØÓÚUSBÍþв½ü¿öµÄ·ÖÎö»ã±¨


¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼¹ØÓÚUSBÍþвÇé¿öµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£»ã±¨µÄÖØÒª·¢ÏÖÔ̺¬£ºÖÁÉÙ´Ó2015ÄêÆðÍ· £¬£¬£¬£¬£¬£¬£¬£¬USBÉ豸ºÍÆäËü¿ÉÒÆ¶¯Ã½Ìå±»ÓÃÓÚ´«²¼¶ñÒâÍÚ¿óÈí¼þ£» £» £»£»£»Í¨¹ýUSBÉ豸/¿ÉÒÆ¶¯Ã½Ìå´«²¼µÄÆäËü¶ñÒâÈí¼þ»¹Ô̺¬WindowsľÂí¼Ò×åLNK£» £» £»£»£»ÑÇÖÞ¡¢·ÇÖÞºÍÄÏÃÀÖÞµÈÐÂÐËÊг¡×îÈÝÒ×Êܵ½¿ÉÒÆ¶¯Ã½ÌåÍþвµÄϰȾ £¬£¬£¬£¬£¬£¬£¬£¬µ«ÔÚÅ·Ö޺ͱ±ÃÀÒ²´æÔÚһЩ¹ÂÁ¢µÄ¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£


https://securelist.com/usb-threats-from-malware-to-miners/87989/


¡¾°²È«²¥±¨¡¿ÔÆÍÆË㹫˾ZohoµÄÓòÃû±»½ûÓýüÁ½Ó×ʱ £¬£¬£¬£¬£¬£¬£¬£¬Ô¼3000ÍòÓû§ÊÜÓ°Ïì


Ó¡¶È³ÛÃûÔÆÍÆËã¿Æ¼¼¹«Ë¾ZohoµÄÓòÃû£¨zoho.com£©±»ÆäÓòÃû×¢²áÉÌTierraNet½ûÓýüÁ½¸öÓ×ʱ £¬£¬£¬£¬£¬£¬£¬£¬ÔÚ´ËÆÚ¼äÓû§±»³Á¶¨ÏòÖÁÒ»¸ö¿ÕÈ±Ò³Ãæ £¬£¬£¬£¬£¬£¬£¬£¬Ô¼3000ÍòÓû§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£Æ¾¾ÝTierraNetµÄ˵·¨ £¬£¬£¬£¬£¬£¬£¬£¬ÆäÂÅ´ÎÊÕµ½¹ØÓÚÀûÓÃZohoÓʼþ·þÎñ·¢ËÍ´¹µöÓʼþµÄͶËß £¬£¬£¬£¬£¬£¬£¬£¬µ«ÔÚÊý´ÎÓëZoho¹µÍ¨ºó¸ÃÎÊÌâûÓеõ½½â¾ö £¬£¬£¬£¬£¬£¬£¬£¬×îÖÕÒ»Ì××Ô¶¯»¯ÏµÍ³µ¼ÖÂÁË´ËÊÂÎñµÄ²úÉú¡£¡£¡£¡£¡£


https://www.zdnet.com/article/domain-registrar-oversteps-taking-down-zoho-domain-impacts-over-30mil-users/


¡¾°²È«²¥±¨¡¿×êÑÐÈËÔ±ÑÝʾÈôºÎÈÆ¹ýmacOS MojaveÖеݲȫ´ëÊ©²¢½Ó¼ûÓû§µÄÃô¸ÐÊý¾Ý


°²È«×êÑÐÈËÔ±Patrick Wardle³ÆÆäÄܹ»ÈƹýmacOS Mojave Öеݲȫ´ëÊ©²¢½Ó¼ûÓû§µÄÃô¸ÐÊý¾Ý £¬£¬£¬£¬£¬£¬£¬£¬ÈçͨѶ¼ÖеÄÐÅÏ¢µÈ¡£¡£¡£¡£¡£Wardle°µÊ¾¸Ã·ì϶ÓëAppleµÄÒþÖÔ±£» £» £»£»£»¤´ëÊ©µÄʵÏÖÓйء£¡£¡£¡£¡£¸Ã·ì϶100%¿¿µÃס £¬£¬£¬£¬£¬£¬£¬£¬¶ñÒâ»ò²»ÊÜÐÅÀµµÄÀûÓÿÉÀûÓø÷ìÏ¶ÈÆ¹ýÐµİ²È«»úÔì²¢ÔÚδ¾­ÊÚȨµÄÇé¿öϽӼûÓû§µÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ½«ÔÚ11Ô·ݵÄMac°²È«´ó»áÉÏÅû¶¸ü¶à¼¼Êõϸ½Ú¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/macos-mojave-privacy-bypass-flaw-allows-access-to-protected-files/


¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖAdwind RATÕë¶ÔÍÁ¶úÆäµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯


Cisco TalosºÍReversingLabsµÄ×êÑÐÈËÔ±·¢ÏÖ¶ñÒâÈí¼þAdwindµÄÒ»¸öбäÌå £¬£¬£¬£¬£¬£¬£¬£¬¸Ã±äÌå¿ÉÕë¶ÔLinux¡¢WindowsºÍmacOSƽ̨¡£¡£¡£¡£¡£AdwindÊÇÒ»ÖÖÔ¶¿ØÄ¾Âí£¨RAT£© £¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖµÄÐÂÑù±¾ÊÇAdwind RAT 3.0 £¬£¬£¬£¬£¬£¬£¬£¬¸Ã±äÌåÀûÓÃÁËMicrosoft ExcelÖеĶ¯Ì¬Êý¾Ý»¥»»£¨DDE£©´úÂë×¢Èë¹¥»÷¡£¡£¡£¡£¡£¸Ã±äÌåµÄ¹¥»÷»î¶¯ÓÚ2018Äê8ÔÂ26ÈÕÆðÍ· £¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÍÁ¶úÆäµÄÓû§£¨75£¥£© £¬£¬£¬£¬£¬£¬£¬£¬Ò²ÓÐһЩÊܺ¦ÕßλÓڵ¹ú¡£¡£¡£¡£¡£Æä·Ö·¢·½Ê½ÊÇÍÁ¶úÆäÓïµÄÀ¬»øÓʼþ¡£¡£¡£¡£¡£


https://blog.talosintelligence.com/2018/09/adwind-dodgesav-dde.html


¡¾·ì϶²¹¶¡¡¿±ÈÌØ±ÒÖ÷ÌâÍŶӰ䲼³ÁÒª¸üР£¬£¬£¬£¬£¬£¬£¬£¬½¨¸´µ×²ãÈí¼þÖеÄÒ»¸öDDoS·ì϶


±ÈÌØ±ÒÖ÷Ì⿪·¢ÍŶӰ䲼°²È«¸üР£¬£¬£¬£¬£¬£¬£¬£¬½¨¸´±ÈÌØ±Òµ×²ãÈí¼þÖеÄÒ»¸ö³ÁÒªµÄDDoS·ì϶¡£¡£¡£¡£¡£¸Ã·ì϶£¨CVE-2018-17144£©¿ÉÔÊÐíÈκαÈÌØ±Ò¿ó¹¤Ôì³É±ÈÌØ±ÒÖ÷Ìâ½ÚµãµÄ±ÀÀ£ £¬£¬£¬£¬£¬£¬£¬£¬¾ßÌåÀ´Ëµ £¬£¬£¬£¬£¬£¬£¬£¬¿ó¹¤¿Éͨ¹ýÏòÇø¿éºé·º³Á¸´ÂòÂôÀ´µ¼ÖÂÆäËüÈ˵ÄÂòÂôÈ·ÈÏÅö±Ú»òͨ¹ýºé·º±ÈÌØ±ÒP2PÍøÂçµÄ½Úµãµ¼Ö´ø¿íºÄ¾¡¡£¡£¡£¡£¡£±ÈÌØ±ÒÖ÷Ìâ°æ±¾0.14.0µ½0.16.2Êܵ½Ó°Ïì £¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§ÊµÊ±¸üÐÂÖÁ×îа汾0.16.3¡£¡£¡£¡£¡£


https://thehackernews.com/2018/09/bitcoin-core-software.html

¡¾Êý¾Ýй¶¡¿½áºÏ¹úÒ»WordPressÍøÕ¾´æÔÚ°²È«·ì϶ £¬£¬£¬£¬£¬£¬£¬£¬Êýǧ·ÝÇóÖ°¼òÀúÒÉй¶


Seekurity°²È«×êÑÐÈËÔ±Mohamed Baset·¢ÏÖ½áºÏ¹úµÄÒ»¸öWordPressÍøÕ¾´æÔÚõ辶й¶·ì϶ºÍÐÅϢй¶·ì϶ £¬£¬£¬£¬£¬£¬£¬£¬Êýǧ·ÝÇóÖ°¼òÀúÒÉй¶¡£¡£¡£¡£¡£ÕâЩÇóÖ°¼òÀúµÄÈÕÆÚ×îÔç¿É×·ÒäÖÁ2016Äê¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÓÚ8ÔÂ6ÈÕÏò½áºÏ¹ú»ã±¨ÁË´ËÎÊÌâ £¬£¬£¬£¬£¬£¬£¬£¬µ«Ö±ÖÁ9ÔÂ5ÈÕ²ÅÊÕµ½»Ø¸´³Æ¸Ã·ì϶Óë½áºÏ¹ú¿ª·¢´òËãÊð£¨UNDP £©Óйء£¡£¡£¡£¡£Ä¿Ç°¸Ã·ì϶»¹Î´±»½¨¸´¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/united-nations-wordpress-site-exposes-thousands-of-resumes/



¡¾8827Ì«Ñô¼¯Íż¯ÍÅADLabÕû¶Ù°ä²¼¡¿