2018ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö£»£»£»£»£»Chrome 0dayÐ®ÖÆ5ÒÚiOSÓû§»á»°£»£»£»£»£»JustDialй¶1ÒÚÓû§ÐÅÏ¢

Ðû²¼Ê±¼ä 2019-04-18
1¡¢¹ú¼Ò»¥ÁªÍøÓ¦¼±ÖÐÐÄÐû²¼¡¶2018ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


4ÔÂ16ÈÕCNCERT/CCÐû²¼¡¶2018ÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ×ÛÊö¡·£¬ £¬£¬£¬¸Ã±¨¸æ×ܽáÁË2018ÄêÎÒ¹ú»¥ÁªÍøµÄÍøÂçÇ徲״̬£¬ £¬£¬£¬²¢¶Ô2019ÄêÍøÂçÇå¾²Ç÷ÊÆ¾ÙÐÐÁËÕ¹Íû¡£¡£¡£±¨¸æÖеÄÊý¾Ýº­¸ÇÁË2018ÄêµÄ¶ñÒâ³ÌÐò¡¢Çå¾²Îó²î¡¢¾Ü¾øÐ§À͹¥»÷¡¢ÍøÕ¾Çå¾²¡¢¹¤Òµ»¥ÁªÍøÇå¾²¡¢»¥ÁªÍø½ðÈÚÇå¾²Áù¸ö·½ÃæµÄͳ¼ÆÊý¾Ý¡£¡£¡£ÍêÕû±¨¸æÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
http://www.cert.org.cn/publish/main/upload/File/2018situation.pdf

2¡¢³¬´ó¹æÄ£¶ñÒâ¹ã¸æ»î¶¯£¬ £¬£¬£¬Ð®ÖÆ5ÒÚiOSÓû§»á»°


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Çå¾²³§ÉÌConfiant·¢Ã÷·¸·¨ÍÅ»ïeGobblerÌᳫÕë¶ÔiOSÓû§µÄ³¬´ó¹æÄ£¶ñÒâ¹ã¸æ»î¶¯£¬ £¬£¬£¬ÒÑÐ®ÖÆ5ÒÚiOSÓû§µÄ»á»°¡£¡£¡£¸Ã¹¥»÷»î¶¯´Ó4ÔÂ6ÈÕ×îÏÈ£¬ £¬£¬£¬Ò»Á¬ÁË6ÌìµÄʱ¼ä£¬ £¬£¬£¬¹¥»÷ÕßʹÓÃÁË8¸ö²î±ðµÄ¶ñÒâ¹ã¸æÏµÁкÍ30¶à¸öÐéα¹ã¸æ£¬ £¬£¬£¬Ã¿¸öÐéα¹ã¸æÏµÁеÄÉúÃüÖÜÆÚΪ24-48Сʱ֮¼ä¡£¡£¡£¹¥»÷ÕßÖ÷ÒªÕë¶ÔÃÀ¹úºÍÅ·Ã˵ÄiOSÓû§£¬ £¬£¬£¬²¢ÔÚ¹¥»÷ÖÐʹÓÃÁËChromeä¯ÀÀÆ÷ÖеÄÎó²îÒÔÈÆ¹ýɳºÐ¼ì²â¡£¡£¡£¹¥»÷ÕßʹÓÃÁË.worldÓòÃûÍйܵĴ¹ÂÚÍøÕ¾£¬ £¬£¬£¬¾­ÓɶÌÔݵÄÍ£ÁôÖ®ºó£¬ £¬£¬£¬ÓÖתÏò.siteÓòÃûµÄ´¹ÂÚÍøÕ¾¡£¡£¡£×Ô4ÔÂ14ÈÕÒÔÀ´£¬ £¬£¬£¬ÕâЩ´¹ÂÚÍøÕ¾Ò»Ö±´¦ÓÚ»îԾ״̬¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/malvertising-campaign-abused-chrome-to-hijack-500-million-ios-user-sessions/

3¡¢JustDial APIй¶Áè¼Ý1ÒÚÓ¡¶ÈÓû§µÄСÎÒ˽¼ÒÐÅÏ¢

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

Çå¾²Ñо¿Ô±Rajshekhar Rajaharia·¢Ã÷Ó¡¶ÈÍâµØËÑË÷ЧÀ͹«Ë¾JustDialµÄÒ»¸öAPIδÊܱ£»£»£»£»£»¤£¬ £¬£¬£¬¿É±»ÈκÎÈËʹÓÃÒÔ¼ìË÷Áè¼Ý100ÍòÓû§µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨Óû§µÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢ÊÖ»úºÅÂë¡¢ÆÜÉíµØµã¡¢ÐԱ𡢳öÉúÈÕÆÚ¡¢ÕÕÆ¬¡¢¾ÍÖ°¹«Ë¾µÈ¡£¡£¡£ËäÈ»¸ÃAPIÖÁÉÙ´Ó2015ÄêÆð¾Í¿É¹ûÕæ»á¼û£¬ £¬£¬£¬µ«Éв»ÇåÎúÊÇ·ñÒÑÓÐÈËʹÓÃËüÀ´ÍøÂçJustDialÓû§µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/04/justdial-hacked-data-breach.html

4¡¢Navicent HealthÈ·ÈÏÔâºÚ¿ÍÈëÇÖ£¬ £¬£¬£¬27Íò»¼ÕßÐÅϢй¶


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Navicent HealthÐû²¼ÉùÃ÷³ÆÆäµç×ÓÓʼþϵͳÔâºÚ¿ÍÈëÇÖ£¬ £¬£¬£¬Ô¼27Íò»¼ÕßµÄÐÅϢй¶£¬ £¬£¬£¬ÆäÖаüÀ¨Ò»Ð©»¼ÕßµÄÉç»áÇå¾²ºÅÂë¡£¡£¡£¸ÃÊý¾Ýй¶ÊÂÎñ±¬·¢ÔÚ2018Äê7Ô£¬ £¬£¬£¬NavicentÊÓ²ìÈ·ÈÏÖ»Óеç×ÓÓʼþϵͳÔâµ½ÈëÇÖ£¬ £¬£¬£¬Ð¹Â¶µÄÐÅÏ¢°üÀ¨»¼ÕßµÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µØµãÒÔ¼°Õ˵¥ºÍÔ¤Ô¼ÐÅÏ¢¡£¡£¡£Navicent½«ÎªÉç»áÇå¾²ºÅÂëÔ⵽й¶µÄ»¼ÕßÌṩһÄêµÄÃâ·ÑÐÅÓÃ¼à¿ØÐ§ÀÍ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/navicent-health-data-breach-exposes-patients-personal-info/

5¡¢ÐÂÀÕË÷Èí¼þNamPoHyu Virus£¬ £¬£¬£¬Ö÷ÒªÕë¶ÔSambaЧÀÍÆ÷


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÐÂÀÕË÷Èí¼þNamPoHyu VirusÕýÔÚÆð¾¢¾ÙÐÐÈö²¥£¬ £¬£¬£¬ÓëÆäËüÀÕË÷Èí¼þ²î±ðµÄÊÇ£¬ £¬£¬£¬¸ÃÀÕË÷Èí¼þ²»ÊÇÍâµØ¾ÙÐмÓÃÜ£¬ £¬£¬£¬¶øÊÇÔ¶³Ì¼ÓÃܿɻá¼ûµÄSambaЧÀÍÆ÷¡£¡£¡£NamPoHyu»áËÑË÷¿É»á¼ûµÄÔ¶³ÌSambaЧÀÍÆ÷£¬ £¬£¬£¬±©Á¦ÆÆ½âÆäÃÜÂ룬 £¬£¬£¬È»ºóÔ¶³Ì¼ÓÃÜÆäÎļþ²¢ÊÍ·ÅÊê½ðƱ¾Ý¡£¡£¡£ShodanÏÔʾÓнü50Íò¸ö¿É»á¼ûµÄSambaЧÀÍÆ÷¿ÉÄܳÉΪĿµÄ¡£¡£¡£¸ÃÀÕË÷²¡¶¾Ê״ηºÆðÓÚ3Ô·ݣ¬ £¬£¬£¬ÆäÃû³ÆÎªMegaLocker£¬ £¬£¬£¬È»ºóÔÚ4Ô³õ¸üÃûΪNamPoHyu£¬ £¬£¬£¬²¢½«.NamPoHyuÀ©Õ¹Ãû¸½¼Óµ½¼ÓÃÜÎļþºó¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nampohyu-virus-ransomware-targets-remote-samba-servers/

6¡¢HawkeyeбäÖÖReborn v9£¬ £¬£¬£¬¿É¼Í¼¼üÅ̼°ÇÔÊØÐÅÏ¢


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


˼¿ÆTalos·¢Ã÷ÕýÔÚ·Ö·¢HawkEyeбäÖÖReborn v9µÄ´¹ÂÚ¹¥»÷»î¶¯¡£¡£¡£ÕâЩ´¹ÂÚÓʼþαװ³É·¢Æ±¡¢ÎïÁÏÇåµ¥¡¢¶©µ¥È·ÈϵÈÓªÒµÓʼþ£¬ £¬£¬£¬Ê¹ÓÃOffice´úÂëÖ´ÐÐÎó²îCVE-2017-11882À´ÏÂÔØ²¢ÔËÐÐHawkeye Reborn v9¡£¡£¡£¸ÃбäÖÖ¿ÉÒԼͼ¼üÅ̲¢ÇÔÈ¡ä¯ÀÀÆ÷¡¢¼ôÌù°åÖеÄÐÅÏ¢ºÍƾ֤£¬ £¬£¬£¬»¹¿ÉÒÔ½ØÈ¡×ÀÃæ¼°´ÓÉãÏñÍ·ÅÄÉãÕÕÆ¬¡£¡£¡£¸ÃбäÖÖÕýÔÚ×÷Ϊ¡°¸ß¼¶¼à¿Ø½â¾ö¼Æ»®¡±¾ÙÐгöÊÛ£¬ £¬£¬£¬»¹°üÀ¨¡°Ð§ÀÍÌõ¿îЭÒ顱£¬ £¬£¬£¬Õ¥È¡Âò¼ÒÔÚδ¾­ÔÊÐíµÄÇéÐÎÏÂʹÓøÃÈí¼þ£¬ £¬£¬£¬²¢Õ¥È¡Ê¹Ó÷À²¡¶¾Èí¼þɨÃèÆä¿ÉÖ´ÐÐÎļþ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/a-new-variant-of-hawkeye-keylogger-reborn-v9-arises-821b972a

ÉùÃ÷£º±¾×ÊѶÓÉÈËÉú¾ÍÊDz©Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí