2019ÄêÕë¶ÔMacÓû§µÄ´¹ÂÚ¹¥»÷ÔöÌíÖÁ160Íò´Î £»£»£»£»ÃÀ¹ú²ÆÎñ²¿Ðû²¼¶ÔÈý¸ö³¯ÏʺڿÍ×é֯ʵÑéÖÆ²Ã

Ðû²¼Ê±¼ä 2019-09-16

1.2019ÄêÕë¶ÔMacÓû§µÄ´¹ÂÚ¹¥»÷ÔöÌíÖÁ160Íò´Î


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


¿¨°Í˹»ùÔÚ2019ÄêµÄǰÁù¸öÔÂÖй²²¶»ñµ½160Íò´ÎÕë¶ÔMacÓû§µÄ´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£2018ÄêÕûÄêʹÓÃAppleÆ·ÅÆµÄ´¹ÂÚ¹¥»÷´ÎÊýΪ150Íò´Î£¬£¬£¬£¬ £¬£¬£¬½ñÄêÉϰëÄêÒѾ­Áè¼ÝÁËÕâÒ»Êý×Ö¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿¨°Í˹»ùÌåÏÖ´ËÀ๥»÷ͨ³£Ã¿ÄêÔöÌí30-40%¡£¡£¡£¡£¡£°ÍÎ÷µÄmacOSÓû§ÖÐÊÜ´¹ÂÚ¹¥»÷µÄ±ÈÀý×î´ó£¬£¬£¬£¬ £¬£¬£¬Îª30%£¬£¬£¬£¬ £¬£¬£¬¶ø·¨¹úºÍÓ¡¶ÈµÄ±ÈÀýԼΪ22%¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿¨°Í˹»ùÇ¿µ÷³Æ¹¥»÷ÕßÔ½À´Ô½¶àµØÊ¹ÓÃAppleͼ±êÀ´ÓÕÆ­Óû§µÄApple IDºÍƾ֤¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬£¬¿¨°Í˹»ùÌåÏÖ×Ô2015ÄêÒÔÀ´ÍøÂç´¹ÂÚ¹¥»÷µÄ×ÜÊýÔøÖ¸Êý¼¶ÔöÌí£¬£¬£¬£¬ £¬£¬£¬ÆäʱµÄÊý×ÖΪԼ85Íò´Î¹¥»÷£¬£¬£¬£¬ £¬£¬£¬¶øÔÚ½ñÄêÉϰëÄê´¹ÂÚ¹¥»÷µÄ×ÜÊýΪ½ü600Íò´Î¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.techrepublic.com/article/phishing-scams-targeting-mac-users-on-the-rise-with-1-6-million-attacks-in-2019/


2.ÃÀ¹ú²ÆÎñ²¿Ðû²¼¶ÔÈý¸ö³¯ÏʺڿÍ×é֯ʵÑéÖÆ²Ã


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÃÀ¹ú²ÆÎñ²¿Ðû²¼¶ÔÈý¸öÓɹú¼ÒÖ§³ÖµÄ³¯ÏʺڿÍ×é֯ʵÑéÖÆ²Ã£¬£¬£¬£¬ £¬£¬£¬°üÀ¨·¸·¨ÍÅ»ïLazarus Group¼°Æä×Ó¼¯ÍÅBluenoroffºÍAndariel¡£¡£¡£¡£¡£ÕâЩºÚ¿Í×éÖ¯±»Ö¸¿Ø¶ÔÃÀ¹úÒªº¦»ù´¡ÉèʩʵÑéÁ˶à´ÎÆÆËðÐÔÍøÂç¹¥»÷ÒÔ¼°´ÓÈ«Çò½ðÈÚ»ú¹¹ÇÔÈ¡ÊýÒÚÃÀÔª²¢Îª³¯ÏÊÕþ¸®µÄ²»·¨ÎäÆ÷ºÍµ¼µ¯ÍýÏëÌṩ×ʽ𡣡£¡£¡£¡£²ÆÎñ²¿Íâ¹ú×ʲú¿ØÖư칫ÊÒ£¨OFAC£©ÌåÏÖÖÆ²ÃµÄÄ¿µÄÊÇËø¶¨ÈκÎÓÐÒâΪÕâЩºÚ¿Í×éÖ¯Ìá¹©ÖØ´óÉúÒâ»òЧÀ͵ÄÍâ¹ú½ðÈÚ»ú¹¹£¬£¬£¬£¬ £¬£¬£¬²¢¶³½áÓëÕâÈý¸ö×éÖ¯Ïà¹ØµÄÈκÎ×ʲú¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/09/north-korea-cyber-attack.html


3.ÓŲ½ÐÞ¸´¿Éµ¼ÖÂÓû§ÕË»§±»½ÓÊܵÄAPIÎó²î


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Anand Prakash·¢Ã÷ÓŲ½µÄÒ»¸öAPIÎó²î¿ÉÓÃÓÚ½ÓÊÜÓû§ÕË»§ºÍ¸ú×ÙÓû§¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÊ×ÏÈͨ¹ý·¢ËͰüÀ¨Óû§µç»°ºÅÂë»òµç×ÓÓʼþµØµãµÄAPIÇëÇóÀ´»ñÈ¡ÈκÎÓû§µÄΨһ±êʶ·û£¨UUID£©£¬£¬£¬£¬ £¬£¬£¬È»ºóʹÓøÃUUIDÖØÐ·¢ËÍÇëÇ󣬣¬£¬£¬ £¬£¬£¬´Ó¶ø¿ÉÒÔ»ñÈ¡ÒÆ¶¯APPµÄ»á¼ûÁîÅÆ¡¢Î»Öú͵صãµÈ˽ÈËÐÅÏ¢¡£¡£¡£¡£¡£PrakashÌåÏÖͨ¹ý»á¼ûÁîÅÆ£¬£¬£¬£¬ £¬£¬£¬ËûÄܹ»ÍêÈ«½ÓÊܲâÊÔÕË»§¡¢·¢Ëͳ˳µÇëÇóÒÔ¼°»ñÈ¡¸¶¿îÐÅÏ¢µÈ¡£¡£¡£¡£¡£¸ÃÎÊÌâͬʱӰÏìÁËÓŲ½Óû§ºÍ˾»ú¡£¡£¡£¡£¡£ÓŲ½ÔÚÈ·ÈÏÁ˸ÃÎÊÌâºóѸËÙÐÞ¸´ÁËÏà¹ØÎó²î¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.forbes.com/sites/daveywinder/2019/09/12/uber-confirms-account-takeover-vulnerability-found-by-forbes-30-under-30-honoree/


4.InstagramÐÞ¸´¿Éµ¼ÖÂÕË»§ÐÅϢй¶µÄÎó²î


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


FacebookÐÞ¸´ÁËInstagramÖпɵ¼Ö¹¥»÷Õß»ñÈ¡Óû§Ë½ÈËÐÅÏ¢µÄÎó²î¡£¡£¡£¡£¡£Çå¾²Ñо¿Ô±@ZHacker13ÌåÏֿɱ»»ñÈ¡µÄÓû§Êý¾Ý°üÀ¨ÕæÊµÐÕÃû¡¢ÍêÕûµç»°ºÅÂëÒÔ¼°InstagramÕʺÅÐÅÏ¢µÈ¡£¡£¡£¡£¡£¸Ãר¼Ò»¹ÖÒÑԳƹ¥»÷Õß¿ÉÒÔʹÓÃ×Ô¶¯¾ç±¾ºÍ»úеÈË´ÓÆ½Ì¨ÍøÂçÓû§Êý¾Ý£¬£¬£¬£¬ £¬£¬£¬²¢½«Óû§ÓëÆäÁªÏµÈËÐÅÏ¢¹ØÁªÆðÀ´¡£¡£¡£¡£¡£¹¥»÷³¡¾°°üÀ¨Á½¸ö°ì·¨£ºÊ×ÏÈÊÇÔÚInstagramµÄµÇ¼±íµ¥ÉϾÙÐб©Á¦¹¥»÷£¬£¬£¬£¬ £¬£¬£¬Ò»´Î¼ì²éÒ»¸öµç»°ºÅÂ룬£¬£¬£¬ £¬£¬£¬ÒÔ±ãÁ´½Óµ½Ò»¸öÕæÊµµÄInstagramÕÊ»§ £»£»£»£»È»ºóʹÓÃInstagramµÄͬ²½ÁªÏµÈ˹¦Ð§ÕÒµ½Óëµç»°ºÅÂëÏà¹ØÁªµÄÕÊ»§Ãû³ÆºÍºÅÂë¡£¡£¡£¡£¡£Facebook½²»°ÈËÌåÏָù«Ë¾Í¨¹ýÐÞ¸ÄInstagramÁªÏµÈ˵¼Èë·½·¨ÐÞ¸´Á˸ÃÎÊÌâ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/91253/hacking/instagram-bug-data-exposure.html


5.NemtyбäÌå¿ÉɱËÀVirtualBox¡¢SQLµÈÀú³Ì


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÀÕË÷Èí¼þNemtyÕýÔÚÆð¾¢¿ª·¢ÖУ¬£¬£¬£¬ £¬£¬£¬Æä×÷ÕßÏÔÈ»ÕýÔÚÆð¾¢Ê¹Æä³ÉΪһÖÖ¸ü¸ßЧ¡¢ÖØ´óµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬ £¬£¬£¬²¢×îÏȸüÆÕ±éµÄ·Ö·¢¡£¡£¡£¡£¡£Çå¾²Ñо¿Ô±Vitali KremezÆÊÎö·¢Ã÷Ö»¹ÜNemty×÷Õß¶Ô´úÂë¾ÙÐÐÁ˸ü¸Ä£¬£¬£¬£¬ £¬£¬£¬µ«Ëü±£´æÁËÏàͬµÄ°æ±¾ºÅ¡£¡£¡£¡£¡£×îеÄÑù±¾°üÀ¨ÓÃÓÚɱËÀÀú³ÌºÍЧÀ͵ĴúÂ룬£¬£¬£¬ £¬£¬£¬Ä¿µÄÀú³Ì°üÀ¨WordPad¡¢Microsoft Word¡¢Excel¡¢Outlook¡¢µç×ÓÓʼþ¿Í»§¶ËThunderbird¡¢SQL¡¢oracle¡¢onenoteºÍÓÃÓÚÔËÐÐÐéÄâ»úµÄVirtualBoxÈí¼þ¡£¡£¡£¡£¡£ÕâÒâζ×ÅNemtyÕýÔÚÕë¶ÔÆóÒµÊܺ¦Õß¡£¡£¡£¡£¡£Nemty×î³õͨ¹ýRIG EK·Ö·¢£¬£¬£¬£¬ £¬£¬£¬¶ø×îа汾1.4Ôòͨ¹ýÐéαµÄPayPalÍøÕ¾Èö²¥£¬£¬£¬£¬ £¬£¬£¬ËæºóÓÖÐÂÔöÁËRadio EKÈö²¥ÇþµÀ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nemty-ransomware-update-lets-it-kill-processes-and-services/


6.д¹ÂÚȦÌ×Ö÷ÒªÇÔÈ¡ÑÇÂíÑ·Óû§µÄÐÅÓÿ¨Êý¾Ý


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ñо¿Ö°Ô±·¢Ã÷Ò»¸öеĴ¹ÂÚÓʼþȦÌ×ÕýÔÚÈö²¥£¬£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßÖ÷ÒªÊÔͼÇÔÈ¡ÑÇÂíÑ·Óû§µÄÐÅÓÿ¨Êý¾Ý¡£¡£¡£¡£¡£¸ÃȦÌ×µÄÊÂÇéÔ­ÀíÈçÏ£ºÊܺ¦ÕßÎüÊÕµ½Ò»·âαװ³ÉÀ´×ÔÑÇÂíÑ·µÄµç×ÓÓʼþ£¬£¬£¬£¬ £¬£¬£¬Í¨ÖªÓÐ¹ØÆäÕË»§µÄ¿ÉÒɻ£¬£¬£¬£¬ £¬£¬£¬¸ÃÓʼþʹÓûìÏýÁËÓ¢ÓïºÍ·¨ÓïµÄÖ÷Ì⣬£¬£¬£¬ £¬£¬£¬ÒªÇóÊܺ¦Õßµã»÷Á´½ÓÀ´¸üÐÂÕË»§ÐÅÏ¢£¬£¬£¬£¬ £¬£¬£¬°üÀ¨ÊäÈë»á¼ûƾ֤¡¢Õ˵¥µØµã¡¢²ÆÎñÐÅÏ¢µÈ¡£¡£¡£¡£¡£¸Ã´¹ÂÚÍøÕ¾ÍйÜÔÚwadwa-wmdw(dot)comÓòÃûÉÏ£¬£¬£¬£¬ £¬£¬£¬´ËÓòÃûÊÇ8ÔÂ22ÈÕÔÚÒ»¸ö¶àÂ×¶àµØµã×¢²áµÄ£¬£¬£¬£¬ £¬£¬£¬¸ÃµØµãºÜ¿ÉÄÜÖ»ÊÇÒ»¸öÐéαµØµã¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/new-amazon-phishing-scam-stealing-credit-card-data/