¹¥»÷ÕßÀûÓûªË¶ÖÐÑëÈ˹¥»÷·Ö·¢PleadºóÃÅ£»£»£»£»£»£»È«ÇòÍþвָÊý£¬ £¬ £¬£¬£¬£¬ÒøÐÐľÂíTrickbot³Á·µÇ°Ê®

°ä²¼¹¦·ò 2019-05-16
1¡¢Adobe°ä²¼5Ô°²È«¸üУ¬ £¬ £¬£¬£¬£¬½¨¸´87¸ö·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
AdobeµÄ5Ô°²È«¸üн¨¸´Á˶à¸ö²úÆ·ÖеÄ87¸ö·ì϶¡£¡£¡£¡£¡£ÓëAdobe AcrobatºÍReaderÓйصķì϶ÊýΪ84¸ö£¬ £¬ £¬£¬£¬£¬ÆäÖÐ42¸ö±»ÏóÕ÷ΪÑϳÁ£¨Critical£©·ì϶£¬ £¬ £¬£¬£¬£¬ÕâЩ·ì϶¾ù¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐкÍϵͳÊÕÊÜ¡£¡£¡£¡£¡£Flash PlayerÖн¨¸´ÁËÑϳÁ·ì϶£¨CVE-2019-7837£©£¬ £¬ £¬£¬£¬£¬¸Ã·ì϶ÊÇÒ»¸öUse-After-Free·ì϶£¬ £¬ £¬£¬£¬£¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐУ¬ £¬ £¬£¬£¬£¬Ó°ÏìÁËWindows¡¢macOS¡¢Linux¼°Chrome OSƽ̨µÄFlash Player¡£¡£¡£¡£¡£Media Encoderа汾13.1Öн¨¸´Á˿ɵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеÄÑϳÁ·ì϶£¨CVE-2019-7842£©ºÍ¿Éµ¼ÖÂÐÅϢй¶µÄ·ì϶£¨CVE-2019-7844£©¡£¡£¡£¡£¡£±¾Ô½¨¸´µÄ·ì϶¾ùûÓÐÔÚÒ°±í±»ÀûÓᣡ£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/05/adobe-software-updates.html

2¡¢Twitter bugµ¼ÖÂÏòµÚÈý·½¹²ÏíiOSÓû§µÄλÏàÐÅÏ¢

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
TwitterÅû¶Æäƽ̨ÖеÄÒ»¸ö·ì϶£¬ £¬ £¬£¬£¬£¬¸Ã·ì϶¿ÉÍøÂçiOSÓû§µÄµØÎ»Êý¾Ý²¢ÏòµÚÈý·½ºÏ×÷ͬ°é¹²ÏíÕâЩÊý¾Ý¡£¡£¡£¡£¡£·ì϶µÄ¾ßÌåϸ½ÚΪ£¬ £¬ £¬£¬£¬£¬µ±Óû§ÔÚiOSÉ豸ÉÏʹÓÃÁ½¸öTwitterÕÊ»§Ê±£¬ £¬ £¬£¬£¬£¬¼´±ã½öÔÚÒ»¸öÕÊ»§ÖÐÆôÓÃÁ˶¨Î»Ö°ÄÜ£¬ £¬ £¬£¬£¬£¬Ò²»á½«ÍøÂçµ½µÄµØÎ»Êý¾ÝÀûÓÃÓÚÁíÒ»¸öÕË»§¡£¡£¡£¡£¡£Twitter³ÆÒѾ­½¨¸´ÁËÕâ¸öÎÊÌ⣬ £¬ £¬£¬£¬£¬²¢È·ÈϺÏ×÷ͬ°éÔÚÆäÕý³£Á÷³ÌÖÐɾ³ýÁ˹²ÏíµÄÊý¾Ý¡£¡£¡£¡£¡£Twitter»¹°µÊ¾ÒѾ­Í¨ÖªÁËÕË»§¿ÉÄÜÊܵ½Ó°ÏìµÄÓû§¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/bug-in-twitter-led-to-collection-and-sharing-of-users-geolocation-data-with-its-partner-f2ebc19c

3¡¢¹¥»÷ÕßÀûÓûªË¶ÖÐÑëÈ˹¥»÷·Ö·¢PleadºóÃÅ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
4Ôµ×ESET×êÑÐÈËÔ±¹Û²ìµ½ÀûÓá°AsusWSPanel.exe¡±·Ö·¢PleadºóÃŵĹ¥»÷»î¶¯¡£¡£¡£¡£¡£AsusWSPanel.exeÊÇ»ªË¶ÔÆ´æ´¢·þÎñWebStorageµÄWindows¿Í»§¶Ë¡£¡£¡£¡£¡£×êÑÐÈËÔ±¸ø³öÁËÁ½ÖÖ¿ÉÄܵĹ¥»÷³¡¾°£¬ £¬ £¬£¬£¬£¬Ò»ÖÖÊÇ»ªË¶Ôâµ½¹©¸øÁ´¹¥»÷£¬ £¬ £¬£¬£¬£¬ÁíÒ»ÖÖÊǹ¥»÷ÕßÀûÓÃÖÐÑëÈ˹¥»÷ºÍÒ×Êܹ¥»÷µÄ·ÓÉÆ÷À´´«²¼¶ñÒâÈí¼þ¡£¡£¡£¡£¡£½øÒ»²½µÄ·ÖÎöºó×êÑÐÈËÔ±ÒÔΪºóÒ»ÖÖ¹¥»÷³¡¾°µÄ¿ÉÄÜÐÔ¸ü´ó¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.tripwire.com/state-of-security/security-data-protection/bad-actors-using-mitm-attacks-against-asus-to-distribute-plead-backdoor/

4¡¢Check Point×îÐÂÈ«ÇòÍþвָÊý£¬ £¬ £¬£¬£¬£¬ÒøÐÐľÂíTrickbot³Á·µÇ°Ê®

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
Check Point°ä²¼4ÔÂÈ«ÇòÍþвָÊý£¬ £¬ £¬£¬£¬£¬ÒøÐÐľÂíTrickbotÔÚʱ¸ôÁ½Äêºó³Á·µÇ°Ê®£¬ £¬ £¬£¬£¬£¬Î»ÓÚµÚ°ËÃû¡£¡£¡£¡£¡£4Ô·ÝTrickbot¹¥»÷»î¶¯µÄÉÏÉýÇ÷Ïò¿ÉÄÜÓëÃÀ¹úÄÉ˰Èյĵ½À´ÓйØ¡£¡£¡£¡£¡£Ö»¹Ü°ñµ¥Ç°ÈýÃûÒÀÈ»±»¶ñÒâ¿ó¹¤Õ¼¾Ý£¬ £¬ £¬£¬£¬£¬µ«ÆäÓàÆßÃû¶¼ÊǶàÖ°ÄÜľÂí£¬ £¬ £¬£¬£¬£¬ÕâЩľÂí²»½öÄܹ»ÇÔÈ¡Êý¾Ý£¬ £¬ £¬£¬£¬£¬»¹Äܹ»´«²¼ÆäËüÀÕË÷Èí¼þ¡£¡£¡£¡£¡£4Ô·Ý×î³£±»ÀûÓõķì϶ÊÇOpenSSL TLS DTLSÐÄÌø°üÐÅϢй¶·ì϶£¨CVE-2014-0160¡¢CVE-2014-0346£©¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.checkpoint.com/2019/05/14/april-2019s-most-wanted-malware-cybercriminals-up-to-old-trickbots-crypto-cryptomining-security-ryuk/

5¡¢ºÚ¿ÍÔÚ¸£²¼Ë¹¶©ÔÄÍøÕ¾×¢ÈëMagecart¾ç±¾

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
¸£²¼Ë¹¶©ÔÄÍøÕ¾±»ºÚ¿Í×¢Èë¶ñÒâMagecart¾ç±¾£¬ £¬ £¬£¬£¬£¬¸Ã¾ç±¾ÓÃÓÚÍøÂçÓû§ÔÚÖ§¸¶Ò³ÃæÉÏÊäÈëµÄÖ§¸¶ÐÅÏ¢²¢·¢ËÍÖÁ¹¥»÷Õß½ÚÔìµÄÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£ÇÔÈ¡µÄÐÅÏ¢Ô̺¬ÐÅÓþ¿¨ºÅ¡¢µ½ÆÚÈÕÆÚ¡¢CVV/CVCÂë¡¢ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂëºÍÓÊÏ䵨ַ¡£¡£¡£¡£¡£×êÑÐÈËÔ±Troy Mursch·¢ÏÖÁËÕâÒ»¹¥»÷ÊÂÎñ£¬ £¬ £¬£¬£¬£¬¹ÌÈ»forbesmagazine.comÉÏÒÀÈ»´æÔÚ¸ÃMagecart¾ç±¾£¬ £¬ £¬£¬£¬£¬µ«¹¥»÷ÕßÓÃÓÚÍøÂçÐÅÏ¢µÄ·þÎñÆ÷ÓòÃûÒѱ»ÓòÃû·þÎñÉÌFreenomɾ³ý£¬ £¬ £¬£¬£¬£¬Ê¹µÃ¹¥»÷ÒѾ­ÎÞЧ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-inject-magecart-card-skimmer-in-forbes-subscription-site/

6¡¢¶íÂÞ˹µ±¾ÖÍøÕ¾Ð¹Â¶225Íò¹«ÃñµÄÃô¸ÐÐÅÏ¢

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
¶íÂÞ˹×êÑÐÈËÔ±Begtinµ÷²é·¢ÏÖ23¸öµ±¾ÖÍøÕ¾Ð¹Â¶Á˹«ÃñµÄSNILSºÅÂ루Ï൱ÓÚÉç±£ºÅÂ룩£¬ £¬ £¬£¬£¬£¬14¸öµ±¾ÖÍøÕ¾Ð¹Â¶Á˹«ÃñµÄ»¤ÕÕÐÅÏ¢¡£¡£¡£¡£¡£×ܹ²Äܹ»ÔÚÏß»ñµÃ³¬¹ý225Íò¶íÂÞ˹¹«ÃñµÄÊý¾Ý£¬ £¬ £¬£¬£¬£¬Ô̺¬ÐÕÃû¡¢Ö°Î»¡¢¹¤×÷µØÖ·¡¢µç×ÓÓʼþ¡¢ÄÉ˰ºÅÂëµÈ£¬ £¬ £¬£¬£¬£¬ÒÔ¼°Ä³Ð©Çé¿öÏµĻ¤ÕÕÐÅÏ¢¡£¡£¡£¡£¡£BegtinÂÅ´Î֪ͨµ±¾ÐÄà¹Ü»ú¹¹£¬ £¬ £¬£¬£¬£¬µ«ÎÊÌⲢδµÃµ½½â¾ö¡£¡£¡£¡£¡£Æ¾¾Ý±¾µØÃ½ÌåµÄ±¨Â·£¬ £¬ £¬£¬£¬£¬Ò»Ð©¶íÂÞ˹µ±¾Ö¸ß¹ÙµÄÐÅÏ¢Ò²Ôâй¶£¬ £¬ £¬£¬£¬£¬Ô̺¬Òé»á¸±Ö÷ϯAlexander ZhukovµÈ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/russian-government-sites-leak-passport-and-personal-data-for-2-25-million-users/