ÆôÓÃHyper-VµÄWin10ϵͳÖдæÔÚ0day£¬£¬£¬£¬£¬£¬£¬¿É´´½¨Îļþ£»£»£»£»£»£»£»ÍøÂç×êÑÐÓ××é°ä²¼½üÊ®ÄêÍøÂ簲ȫÊÂÎñµÄ×êÑл㱨
°ä²¼¹¦·ò 2020-09-081.ÆôÓÃHyper-VµÄWin10ϵͳÖдæÔÚ0day£¬£¬£¬£¬£¬£¬£¬¿É´´½¨Îļþ

ÄæÏò¹¤³ÌʦJonas LykkegaardÔÚÆôÓÃÁËHyper-VµÄWindows 10ϵͳÖз¢ÏÖÁËÒ»¸öеÄ0day£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿É±»ÀûÓÃÔÚÊÜÓ°ÏìµÄ²Ù×÷ϵͳÖд´½¨Îļþ¡£¡£¡£¡£¡£¡£ÔÚHyper-V´¦Óڻ״̬ʱ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚ\ system32Öд´½¨Îļþ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ²»±ØÒª½øÐÐÌáȨ¡£¡£¡£¡£¡£¡£ÓÉÓÚÎļþµÄ´´½¨ÕßÒ²ÊÇËùÓÐÕߣ¬£¬£¬£¬£¬£¬£¬Òò¶ø¹¥»÷ÕßÄܹ»Ê¹ÓøÃÎļþ½«¶ñÒâ´úÂë×¢ÈëϵͳÄÚ²¿£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ±ØÒªÊ±Ê¹ÓÃÌáÉýµÄȨÏÞÖ´ÐиöñÒâ´úÂë¡£¡£¡£¡£¡£¡£CERT/CC·ì϶·ÖÎöʦWill Dormann °µÊ¾£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÏÕЩ²»±ØÒª×öÈκÎÖÂÁ¦±ãÄܹ»ÀûÓø÷ì϶¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/windows-10-sandbox-activation-enables-zero-day-vulnerability/
2.ÍøÂç×êÑÐÓ××é°ä²¼½üÊ®ÄêÍøÂ簲ȫÊÂÎñµÄ×êÑл㱨

ÓÉÍøÂ簲ȫºÍ»¥ÁªÍø×êÑÐÁìÓòµÄר¼Ò×é³ÉµÄѧÊõÍŶӷÖÎöÁË´ÓǰʮÄ꣨2009ÄêÖÁ2019Ä꣩°ä²¼µÄ700ÆªÍøÂ簲ȫ»ã±¨£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬629·ÝóÒ×Íþвµý±¨¹©¸øÉ̻㱨ºÍ71¶ÀÁ¢×êÑÐÖÐÐĻ㱨¡£¡£¡£¡£¡£¡£×¨¼Ò·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬ÔÚóÒ׻㱨ÖÐÖ»ÓÐ82·Ý£¨13£¥£©»áÉÌÁËÕë¶ÔÃñÉúºÍÉç»áµÄÍþв£¬£¬£¬£¬£¬£¬£¬ÆäÓà607·Ý»ã±¨µÄ³ÁµãÊÇÍøÂç·¸×ïÍÅ»ïºÍAPT×éÖ¯¡£¡£¡£¡£¡£¡£Ïà·´£¬£¬£¬£¬£¬£¬£¬¶ÀÁ¢×êÑÐÖÐÐĵĴóÎÞÊý»ã±¨¶¼¼¯ÖÐÔÚ¶ÔÃñ¼äÉç»áµÄÍþвÉÏ¡£¡£¡£¡£¡£¡£×¨¼ÒÒÔΪ£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÓÉÓÚ°²È«»ã±¨ÊÜÀûÈóÇý¶¯£¬£¬£¬£¬£¬£¬£¬ÍøÂ簲ȫ¹«Ë¾°ä²¼µÄ»ã±¨ÓëÍþвµý±¨Ò»Ñù£¬£¬£¬£¬£¬£¬£¬ÓµÓиæ°××÷Óᣡ£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/most-cyber-security-reports-only-focus-on-the-cool-threats/
3.BancoEstadoÒøÐмì²âµ½Æä²Ù×÷ϵͳÖдæÔÚ¶ñÒâÈí¼þ

BancoEstadoÒøÐÐÓÚ±¾ÖÜÈÕ°ä²¼ÁËÒ»·ÝÐÂΟ壬£¬£¬£¬£¬£¬£¬ÈÏ¿ÉÆäÒÑÔÚÆä²Ù×÷ϵͳÖмì²âµ½¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬¸ÃÎÊÌâÔÚ±»ÒøÐеÄÍøÂ簲ȫÍŶӼì²âµ½ºó½â¾ö¡£¡£¡£¡£¡£¡£¸ÃÒøÐаµÊ¾£¬£¬£¬£¬£¬£¬£¬Ö»¹ÜËûÃǵÄijЩƽ̨¿ÉÄÜ»áÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬µ«µ½Ä¿Ç°ÎªÖ¹£¬£¬£¬£¬£¬£¬£¬ËûÃÇÃæÏò¿Í»§µÄϵͳ£¬£¬£¬£¬£¬£¬£¬Èç×Ô¶¯¹ñÔ±»ú¡¢CajaVecina¡¢ÍøÕ¾ºÍÀûÓ÷¨Ê½²¢Î´Êܵ½Ó°Ïì²¢ÇÒÔÚÔËÐС£¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬£¬£¬£¬£¬£¬Óм¸Î»Óû§ÔÚBanco EstadoµÄÔÚÏ߯½Ì¨Éϻ㱨£¬£¬£¬£¬£¬£¬£¬ÀûÓ÷¨Ê½ºÍÍøÕ¾µÄÔËÐж¼³öÏÖÁ˼äЪÐÔµÄÖжϡ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.biobiochile.cl/noticias/economia/actualidad-economica//09/06/banco-estado-detecto-software-malicioso-en-sus-sistemas-no-ha2020bria-afectado-a-clientes.shtml
4.VisaÖÒ¸æÐÂÐÅÓþ¿¨ÇÔÈ¡¾ç±¾Baka¿É×ÔÎÒɾ³ýÒÔÈÆ¹ý¼ì²â

VisaÖÒ¸æÐÂÐÅÓþ¿¨ÇÔÈ¡¾ç±¾Baka£¬£¬£¬£¬£¬£¬£¬¿ÉÔÚÇÔÈ¡Êý¾Ýºó×ÔÎÒɾ³ýÒÔÈÆ¹ý¼ì²â¡£¡£¡£¡£¡£¡£×êÑÐÈËԱͨ¹ý¶ÈÎö¸Ã¾ç±¾µÄÑù±¾£¬£¬£¬£¬£¬£¬£¬·¢ÏÖBaka³ýÁËÓµÓÐͨÀýµÄÇÔÈ¡Êý¾ÝµÄÖ°ÄÜ±í£¬£¬£¬£¬£¬£¬£¬»¹ÓµÓйÖÒìµÄ»ìºÏ²½ÖèºÍ¼ÓÔØ·¨Ê½¡£¡£¡£¡£¡£¡£Ëü¶¯Ì¬¼ÓÔØskimmerÒÔÈÆ¹ý¾²Ì¬µÄ¶ñÒâÈí¼þɨÃèÆ÷£¬£¬£¬£¬£¬£¬£¬²¢ÎªÃ¿¸öÊܺ¦ÕßʹÓÃΨһµÄ¼ÓÃܲÎÊýÀ´»ìºÏ¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£µ±Ëü¼ì²âµ½Ê¹Óÿª·¢¹¤¾ß½øÐеĶ¯Ì¬·ÖÎö£¬£¬£¬£¬£¬£¬£¬»òÕßÒѾ³É¹¦ÇÔÈ¡Êý¾Ýʱ£¬£¬£¬£¬£¬£¬£¬±ã»á´ÓÄÚ´æÖÐ×ÔÎÒɾ³ý£¬£¬£¬£¬£¬£¬£¬ÒÔÈÆ¹ý¼ì²âºÍ·ÖÎö¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬BakaÒ²ÊÇVisa·¢ÏֵĵÚÒ»¸öʹÓÃXORÃÜÂë»ìºÏ´úÂëºÍÓ²±àÂëµÄÐÅÓþ¿¨ÇÔÈ¡¾ç±¾¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/visa-warns-of-new-baka-credit-card-javascript-skimmer/
5.LloydsÒøÐÐÓû§Ôâµ½´¹µöÓʼþºÍSMS´¹µö¶ÌÐŹ¥»÷

Griffin LawÂÉËù·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬LloydsÒøÐеÄÓû§Ôâµ½Á˸´ÔӵĴ¹µöÓʼþºÍSMS´¹µö¶ÌÐŹ¥»÷¡£¡£¡£¡£¡£¡£ÔÚ´¹µöÓʼþÖУ¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍαÔìÀ´×ÔLloydsµÄÓʼþ£¬£¬£¬£¬£¬£¬£¬²¢ÒÔ¡°ÖҸ棺Îĵµ»ã±¨-ÎÒÃǰÑÎȵ½Óйذ²È«ÊØ»¤µÄÐÅÏ¢¡±Îª±êÌ⣬£¬£¬£¬£¬£¬£¬Ðû³ÆÊÕ¼þÈ˵ÄÒøÐÐÕÊ»§Òѱ»µÁÓ㬣¬£¬£¬£¬£¬£¬ÒªÇóÆäÑéÖ¤ÕÊ»§¡£¡£¡£¡£¡£¡£Ö®ºóÓû§»á±»³Á¶¨Ïòµ½´¹µöÍøÒ³£¬£¬£¬£¬£¬£¬£¬²¢±»ÒªÇóÊäÈëÃÜÂë¡¢ÕÊ»§ÐÅÏ¢ºÍ°²È«´úÂëµÈÊý¾Ý¡£¡£¡£¡£¡£¡£ÔÚSMS´¹µö¶ÌÐÅÖУ¬£¬£¬£¬£¬£¬£¬ºÚ¿Í»á·¢ËÍÒ»ÌõαÔì³ÆÀ´×ÔLloydsµÄ¶ÌÐÅ£¬£¬£¬£¬£¬£¬£¬²¢ÓÕʹÓû§´ò¿ªÒÔÇÔÈ¡ÆäÐÅÏ¢¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/phishing-scam-lloyds-bank-customers/
6.Telmate¼àÓüͨѶƽ̨й¶Êý°ÙÍòÃûÇô·¸µÄÓ×ÎÒÐÅÏ¢

רÃÅÓÃÓÚÇô·¸»¥»»µÄTelmateƽ̨й¶ÁËÊý°ÙÍòÇô·¸µÄÓ×ÎÒ¾ßÌåÐÅÏ¢ÒÔ¼°ËûÃÇÓë±í½çµÄÁªÏµµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬¶ÌÐÅÄÚÈÝ¡¢¹¦·ò´Á¼Ç¡¢ÇôͽDoB¡¢ÉèÊ©ID¡¢È«ÃûºÍÐÔ±ð¡¢ÊÕ¼þÈËÈ«Ãû¡¢µç×ÓÓʼþµØÖ·¡¢½Ö·µØÖ·¡¢IPµØÖ·ºÍ¼ÝÊ»ÅÆÕÕºÅÂë¡¢Çô·¸µÄÈ«Ãû¡¢×ï×´¡¢ºÍÕÊ»§Óà¶î¡¢Í¨»°¾ßÌåÐÅÏ¢¡¢Çô·¸Ìá³öµÄÉêÊöµÈÄÚÈÝ¡£¡£¡£¡£¡£¡£TelmateµÄ³ö²úÉÌGlobal Tel LinkÔÚÊÕµ½»ã±¨µÄ¼¸¸öÓ×ʱÄÚ¶Ô¸ÃÊÂÎñ×ö³öÁË»ØÓ¦£¬£¬£¬£¬£¬£¬£¬²¢½«Â¶³öµÄÊý¾Ý¿âµÄ½øÐÐÁ˽¨¸´£¬£¬£¬£¬£¬£¬£¬µ«ÊǸÃÊý¾Ý¿âµÄ¶³ö×ܹ¦·òÒÀȻδ֪¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.technadu.com/telmate-prison-communications-exposes-personal-data-millions/194733/


¾©¹«Íø°²±¸11010802024551ºÅ