¹¥»÷ÕßÀûÓûªË¶ÖÐÑëÈ˹¥»÷·Ö·¢PleadºóÃÅ£»£»£»£»£»£»È«ÇòÍþвָÊý£¬£¬£¬£¬£¬£¬ÒøÐÐľÂíTrickbot³Á·µÇ°Ê®
°ä²¼¹¦·ò 2019-05-16
AdobeµÄ5Ô°²È«¸üн¨¸´Á˶à¸ö²úÆ·ÖеÄ87¸ö·ì϶¡£¡£¡£¡£¡£ÓëAdobe AcrobatºÍReaderÓйصķì϶ÊýΪ84¸ö£¬£¬£¬£¬£¬£¬ÆäÖÐ42¸ö±»ÏóÕ÷ΪÑϳÁ£¨Critical£©·ì϶£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶¾ù¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐкÍϵͳÊÕÊÜ¡£¡£¡£¡£¡£Flash PlayerÖн¨¸´ÁËÑϳÁ·ì϶£¨CVE-2019-7837£©£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÊÇÒ»¸öUse-After-Free·ì϶£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬Ó°ÏìÁËWindows¡¢macOS¡¢Linux¼°Chrome OSƽ̨µÄFlash Player¡£¡£¡£¡£¡£Media Encoderа汾13.1Öн¨¸´Á˿ɵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеÄÑϳÁ·ì϶£¨CVE-2019-7842£©ºÍ¿Éµ¼ÖÂÐÅϢй¶µÄ·ì϶£¨CVE-2019-7844£©¡£¡£¡£¡£¡£±¾Ô½¨¸´µÄ·ì϶¾ùûÓÐÔÚÒ°±í±»ÀûÓᣡ£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/05/adobe-software-updates.html
2¡¢Twitter bugµ¼ÖÂÏòµÚÈý·½¹²ÏíiOSÓû§µÄλÏàÐÅÏ¢
TwitterÅû¶Æäƽ̨ÖеÄÒ»¸ö·ì϶£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÍøÂçiOSÓû§µÄµØÎ»Êý¾Ý²¢ÏòµÚÈý·½ºÏ×÷ͬ°é¹²ÏíÕâЩÊý¾Ý¡£¡£¡£¡£¡£·ì϶µÄ¾ßÌåϸ½ÚΪ£¬£¬£¬£¬£¬£¬µ±Óû§ÔÚiOSÉ豸ÉÏʹÓÃÁ½¸öTwitterÕÊ»§Ê±£¬£¬£¬£¬£¬£¬¼´±ã½öÔÚÒ»¸öÕÊ»§ÖÐÆôÓÃÁ˶¨Î»Ö°ÄÜ£¬£¬£¬£¬£¬£¬Ò²»á½«ÍøÂçµ½µÄµØÎ»Êý¾ÝÀûÓÃÓÚÁíÒ»¸öÕË»§¡£¡£¡£¡£¡£Twitter³ÆÒѾ½¨¸´ÁËÕâ¸öÎÊÌ⣬£¬£¬£¬£¬£¬²¢È·ÈϺÏ×÷ͬ°éÔÚÆäÕý³£Á÷³ÌÖÐɾ³ýÁ˹²ÏíµÄÊý¾Ý¡£¡£¡£¡£¡£Twitter»¹°µÊ¾ÒѾ֪ͨÁËÕË»§¿ÉÄÜÊܵ½Ó°ÏìµÄÓû§¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/bug-in-twitter-led-to-collection-and-sharing-of-users-geolocation-data-with-its-partner-f2ebc19c
3¡¢¹¥»÷ÕßÀûÓûªË¶ÖÐÑëÈ˹¥»÷·Ö·¢PleadºóÃÅ
4Ôµ×ESET×êÑÐÈËÔ±¹Û²ìµ½ÀûÓá°AsusWSPanel.exe¡±·Ö·¢PleadºóÃŵĹ¥»÷»î¶¯¡£¡£¡£¡£¡£AsusWSPanel.exeÊÇ»ªË¶ÔÆ´æ´¢·þÎñWebStorageµÄWindows¿Í»§¶Ë¡£¡£¡£¡£¡£×êÑÐÈËÔ±¸ø³öÁËÁ½ÖÖ¿ÉÄܵĹ¥»÷³¡¾°£¬£¬£¬£¬£¬£¬Ò»ÖÖÊÇ»ªË¶Ôâµ½¹©¸øÁ´¹¥»÷£¬£¬£¬£¬£¬£¬ÁíÒ»ÖÖÊǹ¥»÷ÕßÀûÓÃÖÐÑëÈ˹¥»÷ºÍÒ×Êܹ¥»÷µÄ·ÓÉÆ÷À´´«²¼¶ñÒâÈí¼þ¡£¡£¡£¡£¡£½øÒ»²½µÄ·ÖÎöºó×êÑÐÈËÔ±ÒÔΪºóÒ»ÖÖ¹¥»÷³¡¾°µÄ¿ÉÄÜÐÔ¸ü´ó¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.tripwire.com/state-of-security/security-data-protection/bad-actors-using-mitm-attacks-against-asus-to-distribute-plead-backdoor/
4¡¢Check Point×îÐÂÈ«ÇòÍþвָÊý£¬£¬£¬£¬£¬£¬ÒøÐÐľÂíTrickbot³Á·µÇ°Ê®
Check Point°ä²¼4ÔÂÈ«ÇòÍþвָÊý£¬£¬£¬£¬£¬£¬ÒøÐÐľÂíTrickbotÔÚʱ¸ôÁ½Äêºó³Á·µÇ°Ê®£¬£¬£¬£¬£¬£¬Î»ÓÚµÚ°ËÃû¡£¡£¡£¡£¡£4Ô·ÝTrickbot¹¥»÷»î¶¯µÄÉÏÉýÇ÷Ïò¿ÉÄÜÓëÃÀ¹úÄÉ˰Èյĵ½À´Óйء£¡£¡£¡£¡£Ö»¹Ü°ñµ¥Ç°ÈýÃûÒÀÈ»±»¶ñÒâ¿ó¹¤Õ¼¾Ý£¬£¬£¬£¬£¬£¬µ«ÆäÓàÆßÃû¶¼ÊǶàÖ°ÄÜľÂí£¬£¬£¬£¬£¬£¬ÕâЩľÂí²»½öÄܹ»ÇÔÈ¡Êý¾Ý£¬£¬£¬£¬£¬£¬»¹Äܹ»´«²¼ÆäËüÀÕË÷Èí¼þ¡£¡£¡£¡£¡£4Ô·Ý×î³£±»ÀûÓõķì϶ÊÇOpenSSL TLS DTLSÐÄÌø°üÐÅϢй¶·ì϶£¨CVE-2014-0160¡¢CVE-2014-0346£©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://blog.checkpoint.com/2019/05/14/april-2019s-most-wanted-malware-cybercriminals-up-to-old-trickbots-crypto-cryptomining-security-ryuk/
5¡¢ºÚ¿ÍÔÚ¸£²¼Ë¹¶©ÔÄÍøÕ¾×¢ÈëMagecart¾ç±¾
¸£²¼Ë¹¶©ÔÄÍøÕ¾±»ºÚ¿Í×¢Èë¶ñÒâMagecart¾ç±¾£¬£¬£¬£¬£¬£¬¸Ã¾ç±¾ÓÃÓÚÍøÂçÓû§ÔÚÖ§¸¶Ò³ÃæÉÏÊäÈëµÄÖ§¸¶ÐÅÏ¢²¢·¢ËÍÖÁ¹¥»÷Õß½ÚÔìµÄÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£ÇÔÈ¡µÄÐÅÏ¢Ô̺¬ÐÅÓþ¿¨ºÅ¡¢µ½ÆÚÈÕÆÚ¡¢CVV/CVCÂë¡¢ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂëºÍÓÊÏ䵨ַ¡£¡£¡£¡£¡£×êÑÐÈËÔ±Troy Mursch·¢ÏÖÁËÕâÒ»¹¥»÷ÊÂÎñ£¬£¬£¬£¬£¬£¬¹ÌÈ»forbesmagazine.comÉÏÒÀÈ»´æÔÚ¸ÃMagecart¾ç±¾£¬£¬£¬£¬£¬£¬µ«¹¥»÷ÕßÓÃÓÚÍøÂçÐÅÏ¢µÄ·þÎñÆ÷ÓòÃûÒѱ»ÓòÃû·þÎñÉÌFreenomɾ³ý£¬£¬£¬£¬£¬£¬Ê¹µÃ¹¥»÷ÒѾÎÞЧ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-inject-magecart-card-skimmer-in-forbes-subscription-site/
6¡¢¶íÂÞ˹µ±¾ÖÍøÕ¾Ð¹Â¶225Íò¹«ÃñµÄÃô¸ÐÐÅÏ¢
¶íÂÞ˹×êÑÐÈËÔ±Begtinµ÷²é·¢ÏÖ23¸öµ±¾ÖÍøÕ¾Ð¹Â¶Á˹«ÃñµÄSNILSºÅÂ루Ï൱ÓÚÉç±£ºÅÂ룩£¬£¬£¬£¬£¬£¬14¸öµ±¾ÖÍøÕ¾Ð¹Â¶Á˹«ÃñµÄ»¤ÕÕÐÅÏ¢¡£¡£¡£¡£¡£×ܹ²Äܹ»ÔÚÏß»ñµÃ³¬¹ý225Íò¶íÂÞ˹¹«ÃñµÄÊý¾Ý£¬£¬£¬£¬£¬£¬Ô̺¬ÐÕÃû¡¢Ö°Î»¡¢¹¤×÷µØÖ·¡¢µç×ÓÓʼþ¡¢ÄÉ˰ºÅÂëµÈ£¬£¬£¬£¬£¬£¬ÒÔ¼°Ä³Ð©Çé¿öÏµĻ¤ÕÕÐÅÏ¢¡£¡£¡£¡£¡£BegtinÂÅ´Î֪ͨµ±¾ÐÄà¹Ü»ú¹¹£¬£¬£¬£¬£¬£¬µ«ÎÊÌⲢδµÃµ½½â¾ö¡£¡£¡£¡£¡£Æ¾¾Ý±¾µØÃ½ÌåµÄ±¨Â·£¬£¬£¬£¬£¬£¬Ò»Ð©¶íÂÞ˹µ±¾Ö¸ß¹ÙµÄÐÅÏ¢Ò²Ôâй¶£¬£¬£¬£¬£¬£¬Ô̺¬Òé»á¸±Ö÷ϯAlexander ZhukovµÈ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/russian-government-sites-leak-passport-and-personal-data-for-2-25-million-users/


¾©¹«Íø°²±¸11010802024551ºÅ