¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181214

Ðû²¼Ê±¼ä 2018-12-14
1¡¢·¨¹úÂÃÓξ¯Ê¾ÍøÕ¾±»ºÚ£¬ £¬²¿·Ö¹«ÃñµÄСÎÒ˽¼ÒÊý¾Ý±»µÁ

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


·¨ÍâÑó½»²¿ÖÜËÄÌåÏÖ£¬ £¬ÆäÂÃÓξ¯Ê¾ÍøÕ¾±»ºÚ£¬ £¬Ô¼54Íò¹«ÃñµÄСÎÒ˽¼ÒÐÅÏ¢±»µÁ¡£¡£Æ¾Ö¤ÆäÐû²¼µÄ¹ûÕæÉùÃ÷£¬ £¬Arianeƽ̨µÄ½ôÆÈÁªÏµÈËÊý¾Ý¿âÔâδÊÚȨ»á¼û£¬ £¬±»µÁµÄÊý¾Ý°üÀ¨ÐÕÃû¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµØµã£¬ £¬µ«²»°üÀ¨Ãô¸ÐÐÅÏ¢¡¢²ÆÎñÐÅÏ¢»òÂÃÐÐÄ¿µÄµØµÈÐÅÏ¢¡£¡£¸Ã²¿·ÖÔÚ2018Äê12ÔÂ5ÈÕ·¢Ã÷Á˴˴ι¥»÷£¬ £¬²¢ÔÚ72СʱÄÚ֪ͨÁËÒþ˽î¿Ïµ»ú¹¹CNIL¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/personal-info-of-540k-people-exposed-in-french-ministry-website-breach-524270.shtml


2¡¢Òâ´óÀûʯÓͺÍ×ÔÈ»Æø¹«Ë¾SaipemÔâµ½ºÚ¿ÍÍøÂç¹¥»÷

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø



±¾ÖÜÒ»Òâ´óÀûʯÓͺÍ×ÔÈ»Æø¹«Ë¾SaipemÔâµ½ÍøÂç¹¥»÷¡£¡£Saipem¹«Ë¾µÄ¿Í»§±é²¼ÔÚ60¶à¸ö¹ú¼ÒÄÚ£¬ £¬´Ë´Î¹¥»÷ȪԴÓÚÓ¡¶È£¬ £¬Ö÷ÒªÓ°ÏìÁ˸ù«Ë¾ÔÚÖж«µØÇøµÄЧÀÍÆ÷£¬ £¬°üÀ¨É³Ìذ¢À­²®¡¢°¢ÁªÇõºÍ¿ÆÍþÌØ£¬ £¬ÆäÔÚÒâ´óÀû¡¢·¨¹úºÍÓ¢¹úµÄÖ÷ÒªÔËÓªÖÐÐÄûÓÐÊܵ½Ó°Ïì¡£¡£Saipem¶Ô·͸ÉçÌåÏÖ¹¥»÷ȪԴÓÚÓ¡¶È½ðÄΣ¬ £¬µ«¹¥»÷ÕßµÄÉí·Ý²»Ã÷£¬ £¬ÓÉÓÚϵͳ¶¼Óб¸·Ý£¬ £¬Òò´ËûÓÐÊý¾ÝÊܵ½Ëðʧ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/78859/hacking/saipem-cyber-attack.html


3¡¢AndroidľÂíαװ³ÉµçÁ¿ÓÅ»¯Ó¦Ó㬠£¬ÊÔͼÇÔÈ¡PayPalÕË»§×ʽð

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ESETÑо¿Ö°Ô±·¢Ã÷Ò»¸öαװ³ÉµçÁ¿ÓÅ»¯appµÄAndroidľÂí£¬ £¬¸ÃľÂíÊÔͼ´ÓÓû§µÄPayPalÕÊ»§ÇÔÈ¡1000Å·ÔªµÄ×ʽ𡣡£¸ÃľÂíαװ³ÉOptimization AndroidÓ¦Ó㬠£¬¿ÉÒÔ´ÓµÚÈý·½Ó¦ÓÃÊÐËÁ»ñµÃ¡£¡£ÔÚ¶ñÒâ³ÌÐòÊ×´ÎÆô¶¯Ê±£¬ £¬Ëü»á¸ü¸Ä¸¨Öú¹¦Ð§ÉèÖÃÒÔÆôÓõþ¼Ó²ã£¬ £¬²¢ÒªÇóÓû§·­¿ªPayPalÒÔÈ·ÈÏÓû§µÄÕË»§¡£¡£Ò»µ©Óû§·­¿ªPayPal£¬ £¬¶ñÒâ³ÌÐò¾Í»áÄ£ÄâÓû§µÄµã»÷²Ù×÷£¬ £¬Ïò¹¥»÷Õß»ã¿î1000Å·Ôª£¬ £¬Õû¸öÀú³Ì»òÐíÐèÒª5ÃëÖÓ¡£¡£¸ÃľÂí»¹¿ÉÒÔ×èµ²¡¢·¢ËÍ»òɾ³ýÓû§µÄ¶ÌÐÅ£¬ £¬»ñÈ¡ÁªÏµÈËÁбíÒÔ¼°²¦´òµç»°¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/android-trojan-targets-paypal-users/139872/


4¡¢ÕÝ·ü½üÁ½Äêºó£¬ £¬Shamoon²¡¶¾ÐÂÑù±¾ÔÙÏÖÒâ´óÀû

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Êý¾Ý²Á³ý²¡¶¾ShamoonÊ״ηºÆðÓÚ2012Ä꣬ £¬Æäɾ³ýÁËÉ³ÌØ°¢ÃÀʯÓ͹«Ë¾µÄ3.5ÍòÅÌËã»úϵͳµÄÊý¾Ý¡£¡£Æä4ÄêÖ®ºóÔٴηºÆð£¬ £¬²¢Ò»Ö±Ò»Á¬µ½2017Äê1Ô¡£¡£ÕâÒ»´ÎÔÚÕÝ·ü½üÁ½Äêºó£¬ £¬Çå¾²³§ÉÌChronicle·¢Ã÷¸Ã²¡¶¾µÄÐÂÑù±¾ÔÚÒâ´óÀû±»ÉÏ´«ÖÁVirusTotal¡£¡£±¾ÖÜÒâ´óÀûʯÓͺÍ×ÔÈ»Æø¹«Ë¾SaipemÔâµ½ÍøÂç¹¥»÷£¬ £¬ÆäÖÐÒ»¸öÑù±¾ÊÇÓɸù«Ë¾ÉÏ´«µÄ¡£¡£ÐÂÑù±¾°üÀ¨dropperÒÔ¼°Á½¸öÄ£¿£¿£¿£¿£¿£¿é£¨WiperºÍNetwork£©£¬ £¬ÕâÁ½¸öÄ£¿£¿£¿£¿£¿£¿é»®·ÖÈÏÕæ²Á³ý´ÅÅÌÒÔ¼°ÓëC&CͨѶ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/shamoon-disk-wiping-malware-re-emerges-with-two-new-variants/


5¡¢macOS¶ñÒâÈí¼þÔÙÌíгÉÔ±£¬ £¬OSX.LamePyreºóÃſɽØÈ¡ÆÁÄ»ÐÅÏ¢

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


MalwarebytesÑо¿Ö°Ô±Adam Thomas·¢Ã÷Ò»¸öеÄmacOS¶ñÒâÈí¼þOSX.LamePyre¡£¡£¸Ã¶ñÒâÈí¼þµÄ¹¦Ð§½ö°üÀ¨ÆÁÄ»½ØÍ¼ºÍºóÃųÌÐò£¬ £¬¿´ÆðÀ´¸Ã¶ñÒâÈí¼þÈÔ´¦ÓÚ¿ª·¢Àú³ÌÖС£¡£OSX.LamePyreαװ³ÉÐÂÎÅÓ¦ÓÃDiscord¾ÙÐÐÈö²¥£¬ £¬ÆäʹÓÃÁ˵䷶µÄAutomatorͼ±ê£¬ £¬²¢ÊÍ·Åpython±àдµÄpayload£¬ £¬È»ºó½ØÈ¡ÆÁÄ»ÐÅÏ¢²¢ÉÏ´«ÖÁC&CЧÀÍÆ÷¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-lamepyre-macos-malware-sends-screenshots-to-attacker/


6¡¢Õ¨µ¯À´Ï®£¬ £¬ÐµçÓÊȦÌ×ÔÚÃÀ¹úÒýÆð¿Ö»Å

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÐÂÒ»ÂÖµç×ÓÓʼþÕ©Æ­»î¶¯ÔÚÃÀ¹úÒýÆðÁ˿ֻÅÇéÐ÷£¬ £¬ÓÉÓÚÕâЩÓʼþÉù³ÆÔÚÊÕ¼þÈ˵ÄÐÞ½¨ÎïÖа²ÅÅÁËÕ¨µ¯£¬ £¬ÈôÊDz»Ö§¸¶¼ÛÖµ2ÍòÃÀÔªµÄ±ÈÌØ±Ò£¬ £¬¸ÃÕ¨µ¯½«ÔÚµ±Ìì¿¢ÊÂʱÒý±¬¡£¡£Å¦Ô¼¾¯Ô±¾ÖÒÑ×îÏÈÊÓ²ìÕâЩÍþв£¬ £¬µ«µ½ÏÖÔÚΪֹÕâЩÍþв¶¼²»ÊÇÕæµÄ¡£¡£TwitterÉϵÄÇå¾²Ñо¿Ö°Ô±DefenderÌåÏÖ£¬ £¬×Ô12ÔÂ13ÈÕÃÀ¹ú¶«²¿Ê±¼äÏÂÖç12:48×îÏÈ£¬ £¬ËûÃÇÒѾ­²¶»ñµ½ÁËÁè¼Ý1.5Íò·âÕ©Æ­Óʼþ£¬ £¬ÕâЩÓʼþÀ´×ÔÓÚ¶íÂÞ˹µÄIPµØµã¡£¡£Defender»¹ÌåÏÖÕâЩթƭÓʼþ²»µ«±»·¢ËÍÖÁÃÀ¹ú£¬ £¬»¹±»·¢ËÍÖÁ¼ÓÄôó¡¢Ó¢¹ú¡¢ºÉÀ¼¡¢ÈðÊ¿ºÍÈðµä¡£¡£ÏÖÔÚÒÑÓв¿·ÖÊܺ¦ÕßÖ§¸¶Á˼ÛÖµ18ÃÀÔªµÄ±ÈÌØ±Ò£¬ £¬Õâ¿ÉÄÜÊÇÓÉÓÚÊܺ¦Õ߸ã´íÁËСÊýµãµÄλÖ㬠£¬ÊµÑéÖ§¸¶20ÃÀÔªµÄÊê½ð¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-bomb-threat-email-scam-campaign-demanding-20k-in-bitcoin/


ÉùÃ÷£º±¾×ÊѶÓÉÈËÉú¾ÍÊDz©Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí