2018ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö£»Chrome 0dayÐ®ÖÆ5ÒÚiOSÓû§»á»°£»JustDialй¶1ÒÚÓû§ÐÅÏ¢

Ðû²¼Ê±¼ä 2019-04-18
1¡¢¹ú¼Ò»¥ÁªÍøÓ¦¼±ÖÐÐÄÐû²¼¡¶2018ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


4ÔÂ16ÈÕCNCERT/CCÐû²¼¡¶2018ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡· £¬¸Ã±¨¸æ×ܽáÁË2018ÄêÎÒ¹ú»¥ÁªÍøµÄÍøÂçÇ徲״̬ £¬²¢¶Ô2019ÄêÍøÂçÇå¾²Ç÷ÊÆ¾ÙÐÐÁËÕ¹Íû¡£±¨¸æÖеÄÊý¾Ýº­¸ÇÁË2018ÄêµÄ¶ñÒâ³ÌÐò¡¢Çå¾²Îó²î¡¢¾Ü¾ø·þÎñ¹¥»÷¡¢ÍøÕ¾Çå¾²¡¢¹¤Òµ»¥ÁªÍøÇå¾²¡¢»¥ÁªÍø½ðÈÚÇå¾²Áù¸ö·½ÃæµÄͳ¼ÆÊý¾Ý¡£ÍêÕû±¨¸æÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£


Ô­ÎÄÁ´½Ó£º
http://www.cert.org.cn/publish/main/upload/File/2018situation.pdf

2¡¢³¬´ó¹æÄ£¶ñÒâ¹ã¸æÔ˶¯ £¬Ð®ÖÆ5ÒÚiOSÓû§»á»°


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


Çå¾²³§ÉÌConfiant·¢Ã÷·¸·¨ÍÅ»ïeGobblerÌᳫÕë¶ÔiOSÓû§µÄ³¬´ó¹æÄ£¶ñÒâ¹ã¸æÔ˶¯ £¬ÒÑÐ®ÖÆ5ÒÚiOSÓû§µÄ»á»°¡£¸Ã¹¥»÷Ô˶¯´Ó4ÔÂ6ÈÕ×îÏÈ £¬Ò»Á¬ÁË6ÌìµÄʱ¼ä £¬¹¥»÷ÕßʹÓÃÁË8¸ö²î±ðµÄ¶ñÒâ¹ã¸æÏµÁкÍ30¶à¸öÐéα¹ã¸æ £¬Ã¿¸öÐéα¹ã¸æÏµÁеÄÉúÃüÖÜÆÚΪ24-48Сʱ֮¼ä¡£¹¥»÷ÕßÖ÷ÒªÕë¶ÔÃÀ¹úºÍÅ·Ã˵ÄiOSÓû§ £¬²¢ÔÚ¹¥»÷ÖÐʹÓÃÁËChromeä¯ÀÀÆ÷ÖеÄÎó²îÒÔÈÆ¹ýɳºÐ¼ì²â¡£¹¥»÷ÕßʹÓÃÁË.worldÓòÃûÍйܵĴ¹ÂÚÍøÕ¾ £¬¾­ÓɶÌÔݵÄÍ£ÁôÖ®ºó £¬ÓÖתÏò.siteÓòÃûµÄ´¹ÂÚÍøÕ¾¡£×Ô4ÔÂ14ÈÕÒÔÀ´ £¬ÕâЩ´¹ÂÚÍøÕ¾Ò»Ö±´¦ÓÚ»îԾ״̬¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/malvertising-campaign-abused-chrome-to-hijack-500-million-ios-user-sessions/

3¡¢JustDial APIй¶Áè¼Ý1ÒÚÓ¡¶ÈÓû§µÄСÎÒ˽¼ÒÐÅÏ¢

×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!

Çå¾²Ñо¿Ô±Rajshekhar Rajaharia·¢Ã÷Ó¡¶ÈÍâµØËÑË÷·þÎñ¹«Ë¾JustDialµÄÒ»¸öAPIδÊܱ£»¤ £¬¿É±»ÈκÎÈËʹÓÃÒÔ¼ìË÷Áè¼Ý100ÍòÓû§µÄСÎÒ˽¼ÒÐÅÏ¢¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨Óû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢ÊÖ»úºÅÂë¡¢ÆÜÉíµØÖ·¡¢ÐԱ𡢳öÉúÈÕÆÚ¡¢ÕÕÆ¬¡¢¾ÍÖ°¹«Ë¾µÈ¡£ËäÈ»¸ÃAPIÖÁÉÙ´Ó2015ÄêÆð¾Í¿É¹ûÕæ»á¼û £¬µ«Éв»ÇåÎúÊÇ·ñÒÑÓÐÈËʹÓÃËüÀ´ÍøÂçJustDialÓû§µÄСÎÒ˽¼ÒÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/04/justdial-hacked-data-breach.html

4¡¢Navicent HealthÈ·ÈÏÔâºÚ¿ÍÈëÇÖ £¬27Íò»¼ÕßÐÅϢй¶


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


Navicent HealthÐû²¼ÉùÃ÷³ÆÆäµç×ÓÓʼþϵͳÔâºÚ¿ÍÈëÇÖ £¬Ô¼27Íò»¼ÕßµÄÐÅϢй¶ £¬ÆäÖаüÀ¨Ò»Ð©»¼ÕßµÄÉç»áÇå¾²ºÅÂë¡£¸ÃÊý¾Ýй¶ÊÂÎñ±¬·¢ÔÚ2018Äê7Ô £¬NavicentÊÓ²ìÈ·ÈÏÖ»Óеç×ÓÓʼþϵͳÔâµ½ÈëÇÖ £¬Ð¹Â¶µÄÐÅÏ¢°üÀ¨»¼ÕßµÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µØÖ·ÒÔ¼°Õ˵¥ºÍÔ¤Ô¼ÐÅÏ¢¡£Navicent½«ÎªÉç»áÇå¾²ºÅÂëÔ⵽й¶µÄ»¼ÕßÌṩһÄêµÄÃâ·ÑÐÅÓÃ¼à¿Ø·þÎñ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/navicent-health-data-breach-exposes-patients-personal-info/

5¡¢ÐÂÀÕË÷Èí¼þNamPoHyu Virus £¬Ö÷ÒªÕë¶ÔSamba·þÎñÆ÷


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


ÐÂÀÕË÷Èí¼þNamPoHyu VirusÕýÔÚÆð¾¢¾ÙÐÐÈö²¥ £¬ÓëÆäËüÀÕË÷Èí¼þ²î±ðµÄÊÇ £¬¸ÃÀÕË÷Èí¼þ²»ÊÇÍâµØ¾ÙÐмÓÃÜ £¬¶øÊÇÔ¶³Ì¼ÓÃܿɻá¼ûµÄSamba·þÎñÆ÷¡£NamPoHyu»áËÑË÷¿É»á¼ûµÄÔ¶³ÌSamba·þÎñÆ÷ £¬±©Á¦ÆÆ½âÆäÃÜÂë £¬È»ºóÔ¶³Ì¼ÓÃÜÆäÎļþ²¢ÊÍ·ÅÊê½ðƱ¾Ý¡£ShodanÏÔʾÓнü50Íò¸ö¿É»á¼ûµÄSamba·þÎñÆ÷¿ÉÄܳÉΪĿµÄ¡£¸ÃÀÕË÷²¡¶¾Ê״ηºÆðÓÚ3Ô·Ý £¬ÆäÃû³ÆÎªMegaLocker £¬È»ºóÔÚ4Ô³õ¸üÃûΪNamPoHyu £¬²¢½«.NamPoHyuÀ©Õ¹Ãû¸½¼Óµ½¼ÓÃÜÎļþºó¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nampohyu-virus-ransomware-targets-remote-samba-servers/

6¡¢HawkeyeбäÖÖReborn v9 £¬¿É¼Í¼¼üÅ̼°ÇÔÊØÐÅÏ¢


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


˼¿ÆTalos·¢Ã÷ÕýÔÚ·Ö·¢HawkEyeбäÖÖReborn v9µÄ´¹ÂÚ¹¥»÷Ô˶¯¡£ÕâЩ´¹ÂÚÓʼþαװ³É·¢Æ±¡¢ÎïÁÏÇåµ¥¡¢¶©µ¥È·ÈϵÈÓªÒµÓʼþ £¬Ê¹ÓÃOffice´úÂëÖ´ÐÐÎó²îCVE-2017-11882À´ÏÂÔØ²¢ÔËÐÐHawkeye Reborn v9¡£¸ÃбäÖÖ¿ÉÒԼͼ¼üÅ̲¢ÇÔÈ¡ä¯ÀÀÆ÷¡¢¼ôÌù°åÖеÄÐÅÏ¢ºÍƾ֤ £¬»¹¿ÉÒÔ½ØÈ¡×ÀÃæ¼°´ÓÉãÏñÍ·ÅÄÉãÕÕÆ¬¡£¸ÃбäÖÖÕýÔÚ×÷Ϊ¡°¸ß¼¶¼à¿Ø½â¾ö¼Æ»®¡±¾ÙÐгöÊÛ £¬»¹°üÀ¨¡°·þÎñÌõ¿îЭÒ顱 £¬Õ¥È¡Âò¼ÒÔÚδ¾­ÔÊÐíµÄÇéÐÎÏÂʹÓøÃÈí¼þ £¬²¢Õ¥È¡Ê¹Ó÷À²¡¶¾Èí¼þɨÃèÆä¿ÉÖ´ÐÐÎļþ¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/a-new-variant-of-hawkeye-keylogger-reborn-v9-arises-821b972a

ÉùÃ÷£º±¾×ÊѶÓÉ×ðÁú¿­¹ÙÍøÈë¿ÚάËûÃüÇ徲С×é·­ÒëºÍÕûÀí