AndroidÎó²îStrandHogg 2.0Ó°ÏìÁè¼Ý10ÒŲ́װ±¸ £»£»£»£»£»£»£»2600ÍòLiveJournalÕÊ»§Êý¾ÝÔÚ¶à¸öºÚ¿ÍÂÛ̳Èö²¥

Ðû²¼Ê±¼ä 2020-05-28

1.AndroidÎó²îStrandHogg 2.0±»Åû¶ £¬£¬£¬£¬ £¬£¬£¬Ó°ÏìÁè¼Ý10ÒŲ́װ±¸


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


5ÔÂ26ÈÕ £¬£¬£¬£¬ £¬£¬£¬PromonÇå¾²Ñо¿Ö°Ô±Åû¶ÁËÒ»¸öÑÏÖØµÄAndroidÇå¾²Îó²îStrandHogg 2.0£¨CVE-2020-0096£© £¬£¬£¬£¬ £¬£¬£¬Ëü¿ÉÒÔ½«¶ñÒâÓ¦ÓÃαװ³ÉÕýµ±Ó¦Óà £¬£¬£¬£¬ £¬£¬£¬ÇÔÈ¡AndroidÓû§µÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËËùÓÐÔËÐÐAndroid 9.0¼°¸üµÍ°æ±¾µÄ×°±¸£¨Googleͳ¼ÆÓÐ91.8£¥µÄAndroidÓû§Ê¹Óøð汾£© £¬£¬£¬£¬ £¬£¬£¬»ò½«¸ß´ï10ÒŲ́װ±¸¡£¡£¡£¡£¡£Í¨¹ý´ËÎó²î £¬£¬£¬£¬ £¬£¬£¬ºÚ¿Í¿ÉÒÔÖ´ÐÐÖÖÖÖʹÃü £¬£¬£¬£¬ £¬£¬£¬ÀýÈçͨ¹ýÂó¿Ë·çÇÔÊØÐÅÏ¢¡¢Í¨¹ýÏà»úÕÕÏà¡¢ÔĶÁºÍ·¢ËÍSMSÐÂÎÅ¡¢¾ÙÐкͼͼµç»°¶Ô»°¡¢ÍøÂç´¹ÂڵǼƾ֤¡¢»á¼û×°±¸ÉÏËùÓÐ˽ÈËÕÕÆ¬ºÍÎļþ¡¢»ñȡλÖúÍGPSÐÅÏ¢¡¢»á¼ûÁªÏµÈËÁÐ±í¡¢»á¼ûµç»°ÈÕÖ¾¡£¡£¡£¡£¡£GoogleÓÚ2020Äê4ÔÂΪAndroid 8.0¡¢8.1ºÍ9Ðû²¼ÁËÇå¾²²¹¶¡³ÌÐò £¬£¬£¬£¬ £¬£¬£¬ÏÖÔÚΪֹ £¬£¬£¬£¬ £¬£¬£¬¸ÃÎó²î»¹Î´±»ÔÚҰʹÓᣡ£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-android-bug-lets-malicious-apps-hide-in-plain-sight/


2.2600Íò¸öLiveJournalÕÊ»§Êý¾ÝÔÚ¶à¸öºÚ¿ÍÂÛ̳Èö²¥


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


¿ËÈÕ £¬£¬£¬£¬ £¬£¬£¬2600Íò¸öLiveJournalÕÊ»§Êý¾ÝÔÚ¶à¸öºÚ¿ÍÂÛ̳ÉÏÈö²¥ £¬£¬£¬£¬ £¬£¬£¬´Ë´Îй¶Êý¾Ý°üÀ¨µç×ÓÓʼþµØµã¡¢Óû§Ãû¡¢ÉèÖÃÎļþURLºÍ´¿Îı¾ÃÜÂë¡£¡£¡£¡£¡£Óд«ÑÔ³ÆLiveJournalÔÚ2014Äê±»ÈëÇÖ £¬£¬£¬£¬ £¬£¬£¬²¢ÇÒÆäÁè¼Ý3300ÍòÓû§µÄÕË»§ÐÅÏ¢±»µÁ¡£¡£¡£¡£¡£µ«Æ¾Ö¤bleepingcomputerµÄÊÓ²ì £¬£¬£¬£¬ £¬£¬£¬ÆäÖÐÓÐЩÎļþÃûÏÔʾÊý¾Ýй¶ÊDZ¬·¢ÔÚ2017Äê £¬£¬£¬£¬ £¬£¬£¬Óë2014Äêй¶ÊÇÏàì¶ÜµÄ¡£¡£¡£¡£¡£LiveJournalÔòÐû²¼Í¨¸æ £¬£¬£¬£¬ £¬£¬£¬·ñ¶¨ÆäÔâµ½Á˹¥»÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/26-million-livejournal-accounts-being-shared-on-hacker-forums/


3.¿¨Ëþ¶ûCOVID-19×·×ÙÓ¦Óñ£´æÎó²î £¬£¬£¬£¬ £¬£¬£¬Ð¹Â¶100ÍòÓû§Êý¾Ý


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


´óÉâ¹ú¼ÊÈËȨ×éÖ¯ÓÚÉÏÖܶþÖÒÑÔ¿¨Ëþ¶û £¬£¬£¬£¬ £¬£¬£¬ÆäCOVID-19×·×ÙÓ¦Óñ£´æÎó²î £¬£¬£¬£¬ £¬£¬£¬Ð¹Â¶ÁËÁè¼Ý100ÍòÓû§µÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¸ÃÓ¦ÓÃÆôÓÃÁËÐí¶àȨÏÞ £¬£¬£¬£¬ £¬£¬£¬Èç»á¼ûAndroidÉè±¹ØÁ¬ÄÎļþÒÔ¼°ÔÊÐí¸ÃÈí¼þ²¦´òµç»°¡£¡£¡£¡£¡£´óÉâ¹ú¼ÊµÄÇ徲ʵÑéÊÒ·¢Ã÷ £¬£¬£¬£¬ £¬£¬£¬ÓÉÓÚ¸ÃÓ¦ÓÃûÓнÓÄÉÊʵ±µÄÇå¾²²½·¥À´± £»£»£»£»£»£»£»¤ÕâЩÊý¾Ý £¬£¬£¬£¬ £¬£¬£¬Ê¹µÃËûÃÇÄܹ»»á¼ûһЩÃô¸ÐÐÅÏ¢ £¬£¬£¬£¬ £¬£¬£¬°üÀ¨ÐÕÃû¡¢¿µ½¡×´Ì¬ºÍÓû§Ö¸¶¨¸ôÀëËùÔÚµÄGPS×ø±ê¡£¡£¡£¡£¡£ÏÖÔÚ £¬£¬£¬£¬ £¬£¬£¬¸ÃÎó²îÒѾ­±»ÐÞ¸´¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/qatar-tracing-app-flaw-exposed-1-mn-users-data-amnesty


4.ºÚ¿ÍÒÔ7.5Íò¬±È³öÊÛ475ÍòÓ¡¶ÈTruecallerÓû§Êý¾Ý


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


¾ÝÔÚÏßÇ鱨¹«Ë¾Cyble³Æ £¬£¬£¬£¬ £¬£¬£¬5ÔÂ26ÈÕ£¨PTI£© £¬£¬£¬£¬ £¬£¬£¬Ò»ÃûºÚ¿Í³öÊÛÁË475ÍòÀ´×ÔÓ¡¶ÈÔÚÏßĿ¼TruecallerµÄÊý¾Ý £¬£¬£¬£¬ £¬£¬£¬ÊÛ¼ÛԼΪ75000¬±È¡£¡£¡£¡£¡£³öÊÛµÄÊý¾Ý°üÀ¨µç»°ºÅÂë¡¢ÐԱ𡢶¼»á¡¢Òƶ¯ÍøÂç¡¢Facebook IDµÈ¡£¡£¡£¡£¡£CybleµÄÑо¿Ö°Ô±ÆÊÎöÌåÏÖ £¬£¬£¬£¬ £¬£¬£¬ÕâÖÖ×ß©¿ÉÄÜ»á¶ÔÓ¡¶ÈµÄ¿í´óÓû§Ôì³ÉÓ°Ïì £¬£¬£¬£¬ £¬£¬£¬ÀýÈçÀ¬»øÓʼþ¡¢Õ©Æ­¡¢Éí·Ý͵ÇԵȡ£¡£¡£¡£¡£Truecaller½²»°ÈËÔò·ñ¶¨ÆäÊý¾Ý¿âÔâµ½Á˹¥»÷ £¬£¬£¬£¬ £¬£¬£¬²¢ÌåÏÖÕâ¿ÉÄÜÊÇÒѾ­Ð¹Â¶µÄÊý¾Ý¿â £¬£¬£¬£¬ £¬£¬£¬¸Ã¹«Ë¾ÓÚ2019Äê5Ô±¬·¢¹ýÀàËÆÊý¾Ý³öÊÛµÄÎÊÌâ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://in.finance.yahoo.com/news/cyber-criminal-put-truecaller-records-134149107.html


5.ÐÂÀÕË÷²¡¶¾[F]UnicornʹÓÃCOVID-19Ö÷Ìâ £¬£¬£¬£¬ £¬£¬£¬Õë¶ÔÒâ´óÀû


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


±¾ÖÜÒ» £¬£¬£¬£¬ £¬£¬£¬Òâ´óÀûÊý×ÖÒâ´óÀû¾Ö£¨AgID£©µÄÅÌËã»ú½ôÆÈÏìӦС×飨CERT£©Ðû²¼Á˹ØÓÚÒ»ÖÖÃûΪ[F]UnicornµÄÀÕË÷Èí¼þµÄͨ¸æ £¬£¬£¬£¬ £¬£¬£¬²¢Í¨Öª¸Ã²¡¶¾ÒÑÔÚÌìϹæÄ£ÄÚÈö²¥¡£¡£¡£¡£¡£[F]UnicornÒÔCOVID-19֪ͨ¸üÐÂΪÓÕ¶ü £¬£¬£¬£¬ £¬£¬£¬ÓÕʹÓû§ÏÂÔØÎ±ÔìµÄÁªÏµÈ˸ú×ÙÓ¦ÓÃImmuni£¨Òâ´óÀûÕþ¸®½«ÔÚ±¾ÔÂβÐû²¼£© £¬£¬£¬£¬ £¬£¬£¬²¢Í¨¹ýÉç»á¹¤³Ìʹ¸ÃÓ¦Óÿ´ÆðÀ´À´×ÔÒâ´óÀûÒ©¼ÁʦÁªºÏ»á£¨FOFI£©¡£¡£¡£¡£¡£ºÚ¿ÍÊ×ÏÈͨ¹ýÓʼþÓÕʹÓû§ÏÂÔØPC¶ËµÄBeta°æImmuni £¬£¬£¬£¬ £¬£¬£¬»¹¿Ë¡ÁËFOFIÍøÕ¾²¢×¢²áÁËÓëԭʼÓòÃûÏàËÆµÄÓòÃû £¬£¬£¬£¬ £¬£¬£¬ÔÚÖ´ÐиöñÒâÈí¼þºó»á»¹»áÏÔʾ´øÓÐCOVID-19ÐÅÏ¢µÄ½çÃæ¡£¡£¡£¡£¡£µ±Óû§Ô¢Ä¿½çÃæÐÅϢʱ £¬£¬£¬£¬ £¬£¬£¬[F]Unicorn±ã×îÏÈÔÚϵͳÉϼÓÃÜÊý¾Ý¡£¡£¡£¡£¡£Êê½ð֪ͨҪÇóÊܺ¦ÕßÔÚÈýÌìÄÚÖ§¸¶300Å·Ôª £¬£¬£¬£¬ £¬£¬£¬²»È»Êý¾Ý½«É¥Ê§¡£¡£¡£¡£¡£CERT-AgIDÑо¿Ö°Ô±ÌåÏָò¡¶¾ºÜºéÁ÷ƽÉÏÊÇ»ùÓÚHidden TearµÄ £¬£¬£¬£¬ £¬£¬£¬Ö»ÊÇ×öÁËЩÐí¸Ä±ä¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-f-unicorn-ransomware-hits-italy-via-fake-covid-19-infection-map/


6.΢ÈíÐû²¼ÖÒÑÔ £¬£¬£¬£¬ £¬£¬£¬°²ÅÅ·ÀÓùÒÔ¶Ô¿¹ÐÂÀÕË÷Èí¼þPonyFinal


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


΢ÈíÍŶÓÓÚÐû²¼ÁËÒ»·ÝÖÒÑÔ £¬£¬£¬£¬ £¬£¬£¬Í¨ÖªÈ«Çò¸÷µØµÄ×éÖ¯°²ÅÅ·ÀÓù²½·¥ £¬£¬£¬£¬ £¬£¬£¬ÒÔ±ÜÃâ×î½üÊ¢ÐеÄÐÂÐÍÀÕË÷Èí¼þPonyFinal¡£¡£¡£¡£¡£ºÚ¿Íͨ³£ÊÇÕë¶ÔÄ¿µÄ¹«Ë¾µÄÒ»¸öÕË»§ £¬£¬£¬£¬ £¬£¬£¬Ê¹ÓÃÈõÃÜÂ뱩Á¦ÆÆ½â¸ÃÕË»§½øÈëÍøÂç £¬£¬£¬£¬ £¬£¬£¬Ö®ºó°²ÅÅÒ»¸öVisual Basic¾ç±¾ÒÔÔËÐÐPowerShell·´ÏòÍâ¿Ç³ÌÐò £¬£¬£¬£¬ £¬£¬£¬ÓÃÀ´×ª´¢ºÍÇÔÈ¡ÍâµØÊý¾Ý¡£¡£¡£¡£¡£ÓÐʱ¼ä¹¥»÷Õß»¹»áÔÚÄ¿µÄÖ÷»ú×°ÖÃJRE £¬£¬£¬£¬ £¬£¬£¬ÓÉÓÚPonyFinaÊÇlÓÃJava±àдµÄ¡£¡£¡£¡£¡£ºÚ¿ÍÒ»µ©ÕÆÎÕÁËÄ¿µÄÍøÂç £¬£¬£¬£¬ £¬£¬£¬±ã»á°²ÅÅPonyFinal²¢ÔÚÆäËûϵͳÖÐÈö²¥ £¬£¬£¬£¬ £¬£¬£¬ÕâÓëÒÔÍùµÄͨ¹ýÀ¬»øÓʼþ»òÎó²î¹¤¾ß°ü·Ö·¢ÀÕË÷Èí¼þµÄ·½·¨²î±ð¡£¡£¡£¡£¡£¾Ý±¨µÀ £¬£¬£¬£¬ £¬£¬£¬Ó¡¶È¡¢ÒÁÀʺÍÃÀ¹úÒÑÓдËÀÕË÷Èí¼þµÄÊܺ¦Õß¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsoft-warns-about-attacks-with-the-ponyfinal-ransomware/