¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181015
°ä²¼¹¦·ò 2018-10-15
ƾ¾ÝÍþвµý±¨ÉÌBlueliv×îÐÂµÄÆ¾Ö¤ÇÔÈ¡Ì¬ÊÆ·ÖÎö»ã±¨£¬£¬£¬£¬£¬Óë2018Äê3ÔÂÖÁ5ÔÂÏà±È£¬£¬£¬£¬£¬6ÔÂÖÁ8ÔÂÆÚ¼äÔÚ±±ÃÀ½©Ê¬ÍøÂçÖмì²âµ½µÄ±»ÇÔÍ´´¦µÄÊýÁ¿ìÉý141%¡£¡£¡£¡£¡£Óë´Ëͬʱ£¬£¬£¬£¬£¬ÆäËüµØÓòµÄ±»ÇÔÍ´´¦µÄÊýÁ¿ÔòÓÐËù½µÂ䣬£¬£¬£¬£¬Å·Ö޺ͶíÂÞ˹µØÓò½µÂäÁË22%£¬£¬£¬£¬£¬¶øÑÇÖÞµØÓòÔò½µÂäÁË36%¡£¡£¡£¡£¡£ÔÚÓÃÓÚÇÔÈ¡Óû§Í´´¦µÄ¶ñÒâÈí¼þ·½Ã棬£¬£¬£¬£¬Pony¡¢KeyBaseºÍLokiPWSÊÇ×îÊÜ»¶ÓµÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/stolen-credentials-soars-141-north/2¡¢ÃÀ¹ú·À²¿£¨Îå½Ç´óÂ¥£©Ô¼3ÍòÃûÔ±¹¤µÄ¹Û¹â¼Í¼й¶
ÃÀ¹ú¹ú·À²¿£¨Îå½Ç´óÂ¥£©µÄ²¿Ãžü·½ºÍÎÄÖ°ÈËÔ±µÄÓ×ÎÒÐÅÏ¢ºÍÐÅÓþ¿¨Êý¾Ýй¶£¬£¬£¬£¬£¬Ô¼3ÍòÈËÊܵ½Ó°Ïì¡£¡£¡£¡£¡£ÕâÒ»Êý¾Ýй¶ÊÂÎñ¿ÉÄܲúÉúÔÚ¼¸¸öÔÂǰ£¬£¬£¬£¬£¬µ«Ö±µ½×î½ü²Å±»·¢ÏÖ¡£¡£¡£¡£¡£¸ÃÊÂÎñÉæ¼°µ½Ò»¼ÒΪ¹ú·À²¿Ìṩ·þÎñµÄµÚÈý·½¹©¸øÉÌ£¬£¬£¬£¬£¬Ä¿Ç°¸Ã¹©¸øÉ̵ÄÉí·ÝÒÀÈ»²»Ã÷È·¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñÒÀÈ»ÔÚ½øÒ»²½µÄµ÷²éÖ®ÖУ¬£¬£¬£¬£¬µ«Ã»ÓÐÈκλúÃÜÐÅÏ¢Ô⵽й¶¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/77097/data-breach/pentagon-travel-records-data-breach.html3¡¢×êÑÐÍŶӷ¢ÏÖÀûÓÃÐéαFlash¸üÐÂÀ´´«²¼µÄ¶ñÒâÍÚ¿óÈí¼þ
ƾ¾ÝPalo Alto NetworksµÄUnit 42ÍŶӵÄ×îÐÂ×êÑУ¬£¬£¬£¬£¬Ò»¸ö¶ñÒâÈí¼þ·¨Ê½Í¨¹ýÐéαµÄFlash¸üÐÂÀ´´«²¼£¬£¬£¬£¬£¬²¢×°ÖöñÒâ¿ó¹¤XMRigÒÔÍÚÈ¡ÃÅÂÞ±Ò¡£¡£¡£¡£¡£ÓÉÓڸöñÒâÈí¼þ·¨Ê½µÄÈ·»áÔÚÖ¸±êÍÆËã»ú¸ßµÍÔØ²¢×°ÖÃ×îа汾µÄFlash£¬£¬£¬£¬£¬Õâ½øÒ»²½Ôö³¤ÁËÆä±í±íÉϵĺϷ¨ÐÔ¡£¡£¡£¡£¡£×êÑÐÍŶÓÁгöÁË2018Äê3ÔÂ25ÈÕÖÁ9ÔÂ10ÈÕÆÚ¼ä¸ÃÐéαFlash¸üеÄ473¸öÎļþÃûºÍURL¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://researchcenter.paloaltonetworks.com/2018/10/unit42-fake-flash-updaters-push-cryptocurrency-miners/4¡¢×êÑÐÍŶӷ¢ÏÖMagecart¹¥»÷µÄбäÖÖCartThief
The Media Trust×êÑÐÍŶӷ¢ÏÖMagecart¹¥»÷µÄÒ»¸öбäÖÖCartThief¡£¡£¡£¡£¡£Æ¾¾Ý¸Ã×êÑÐÍŶӵÄ˵·¨£¬£¬£¬£¬£¬CartThiefÒ»ÏòÔÚÕë¶Ô½ÏÓ×¹æÄ£µÄµç×ÓÉÌÎñ¹«Ë¾¡£¡£¡£¡£¡£CartThiefÀàËÆÓÚMagecartµÄÐÐΪ£¬£¬£¬£¬£¬ÓÃÓÚÍøÂçÖ§¸¶Ò³ÃæÉϵÄÓ×ÎÒÐÅÏ¢ºÍ²ÆÕþÐÅÏ¢¡£¡£¡£¡£¡£µ«CartThiefÓëÆäËüMagecart±äÖÖ·ÖÆçµÄÊÇ£¬£¬£¬£¬£¬CartThiefûÓÐʹÓÃcookieÀ´¼ø±ðÓû§£¬£¬£¬£¬£¬Õâ¿ÉÄÜÊÇΪÁËÔ¤·ÀÒýÆðÒÉ»óºÍÌӱܼì²â¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/no-cookies-for-cartthief-a-new/5¡¢×êÑÐÈËÔ±ÔÚ΢Èí¹Ù·½É̳ÇÖз¢ÏÖÒ»¸ö¶ñÒâµÄ¸æ°×µã»÷Æ÷
×êÑÐÈËÔ±ÔÚ΢Èí¹Ù·½É̳ÇÖз¢ÏÖÒ»¸öÃûΪAlbum by Google Photos£¨¹È¸èÏà²á£©µÄ¶ñÒⷨʽ£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ¼Ù×°³ÉÀ´×Թȸ裬£¬£¬£¬£¬µ«ÏÖʵÉÏÓÃÓÚÔÚWindows 10Öв»ÐÝ´ò¿ª°µ²ØµÄ¸æ°×¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÔ̺¬Èý¸öÎļþ£ºBlock Craft 3D.dll¡¢Block Craft 3D.exeºÍBlock Craft 3D.xr£¬£¬£¬£¬£¬Ëü½«ÔÚºó¶ÜÏνӵ½¸÷Àà¸æ°×URL²¢´ò¿ªËüÃÇ¡£¡£¡£¡£¡£ÓÉÓÚ¸æ°×²»»áÔÚǰ̨ÏÔʾ£¬£¬£¬£¬£¬Òò¶øÈôÊǸæ°×Ô̺¬ÒôƵ£¬£¬£¬£¬£¬Óû§¿ÉÄÜ»áÌýµ½Ææ¹ÖµÄÉùÒô¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ad-clicker-hiding-as-google-photos-app-found-in-microsoft-store/6¡¢Juniper Networks°ä²¼Junos OSµÄ°²È«¸üУ¬£¬£¬£¬£¬½¨¸´30¶à¸ö·ì϶
Juniper Networks°ä²¼Junos OSµÄ°²È«¸üУ¬£¬£¬£¬£¬¹²½¨¸´30¶à¸ö·ì϶£¬£¬£¬£¬£¬ÆäÖнÏΪÑϳÁµÄ·ì϶Ô̺¬¿Éµ¼ÖÂδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì½Ó¼ûµÄ·ì϶£¨CVE-2018-0044£©¡¢¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐеĻº³åÇøÒç¶Âí½Å£¨CVE-2018-7183£©¡¢¿Éµ¼ÖÂÄں˱ÀÀ£ºÍDoSµÄ·ì϶£¨CVE-2018-0049£©ÒÔ¼°XSS·ì϶£¨CVE-2018-0047£©µÈ¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì×°ÖÃÕâЩ¸üС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/77047/hacking/juniper-networks-junos-flaws.htmlÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ