Ñо¿Ö°Ô±Ò»Á¬µÚÈýÌìÐû²¼Windows 0day¼°PoC£»£»£»£»£»2019ÄêQ1ڲƹ¥»÷Ì¬ÊÆ±¨¸æ£¬£¬£¬£¬Òƶ¯Ú²ÆìÉý300%
Ðû²¼Ê±¼ä 2019-05-24
SandboxEscaperÒ»Á¬µÚÈýÌìÐû²¼ÁËеÄWindows 0day£¬£¬£¬£¬²¢ÔÚGitHubÉÏÐû²¼ÁËPoC´úÂë¡£¡£¡£¡£¡£×òÌìËýÐû²¼µÄWindows¹ýʧ±¨¸æÐ§ÀÍÖеÄLPE´ÓÊÖÒÕÉÏÀ´Ëµ²¢²»ÊÇ0day£¨Î¢ÈíµÄ5ÔÂÇå¾²¸üÐÂÒѾÐÞ¸´ÁËÕâ¸öÎÊÌ⣩£¬£¬£¬£¬Òò´Ë½ñÌìµÄÁ½¸ö0dayÊÇËýÐû²¼µÄµÚÆßºÍµÚ°Ë¸ö0day¡£¡£¡£¡£¡£µÚÆß¸ö0dayÊÇÕë¶ÔCVE-2019-0841ÐÞ¸´²¹¶¡µÄÈÆ¹ý£¬£¬£¬£¬ÕâÊÇÒ»¸öLPEÎó²î¡£¡£¡£¡£¡£µÚ°Ë¸öÔòÊÇÓëWindows³ÌÐòÐÞ¸´×°ÖÃÀú³ÌÖеĶÌʱ¼ä¾ºÕùÌõ¼þÓйأ¬£¬£¬£¬Ê¹ÓÃmsiexec /fa£¨ÐÞ¸´×°Ö㩲Ù×÷ÖеÄÎó²î£¬£¬£¬£¬µÍȨÏ޵Ĺ¥»÷Õß¿ÉÖ²Èë¶ñÒâÈí¼þ²¢½ÓÊÜÅÌËã»ú¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/researcher-publishes-windows-zero-days-for-the-third-day-in-a-row/
2¡¢RSAÐû²¼2019ÄêQ1ڲƹ¥»÷Ì¬ÊÆ±¨¸æ£¬£¬£¬£¬Òƶ¯Ú²ÆìÉý300%
ƾ֤RSAÐû²¼µÄ2019ÄêQ1ڲƹ¥»÷Ì¬ÊÆ±¨¸æ£¬£¬£¬£¬Òƶ¯APPڲƹ¥»÷ÔÚµÚÒ»¼¾¶ÈìÉý300%£¬£¬£¬£¬2019Äê1ÔÂ1ÈÕÒÆ¶¯Ú²Æ¹¥»÷×ÜÊýΪ10390£¬£¬£¬£¬µ«×èÖ¹3ÔÂ31ÈÕ¸ÃÊý×ÖÒÑìÉýÖÁ41313¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬¸Ã±¨¸æ»¹·¢Ã÷Óë½ðÈÚÓйصÄڲƹ¥»÷ÔöÌíÁË56%£¬£¬£¬£¬´Ó2018ÄêQ4µÄ6603ÆðÔöÌíÖÁ2019ÄêQ1µÄ10331Æð¡£¡£¡£¡£¡£ÍøÂç´¹ÂÚÕ¼µÚÒ»¼¾¶ÈËùÓÐڲƹ¥»÷µÄ29%¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/fraud-attacks-from-mobile-spiked-1/
3¡¢4545ÃûTalkTalk¿Í»§µÄ²ÆÎñÐÅÏ¢ÔÚGoogleÉÏй¶
ƾ֤BBC WatchdogµÄÊӲ죬£¬£¬£¬4545ÃûTalkTalk¿Í»§µÄÃô¸ÐÐÅÏ¢¿ÉÔÚGoogleËÑË÷ÖÐÕÒµ½£¬£¬£¬£¬ÕâЩÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Õ˺š¢µç»°ºÅÂëºÍ²ÆÎñÐÅÏ¢¡£¡£¡£¡£¡£Õâ²¢²»ÁÏζ×ÅеÄÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬¶øÊÇÓë2015ÄêµÄÇå¾²ÊÂÎñÓйء£¡£¡£¡£¡£¼òÆÓÀ´Ëµ£¬£¬£¬£¬ÔÚÆäʱµÄÊÂÎñÖУ¬£¬£¬£¬TalkTalkûÄÜ׼ȷµØÍ¨ÖªÕâЩ¿Í»§ËûÃǵÄÊý¾ÝÔ⵽й¶£¬£¬£¬£¬µ¼ÖÂÕâ4545Ãû¿Í»§µÄÐÅÏ¢×Ô2015ÄêÒÔÀ´Ò»Ö±ÔÚÍøÉÏй¶¶ø²»×ÔÖª¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/talktalk-customer-financial-details-found-through-google-search/
4¡¢ºÉÀ¼¾¯·½È¡µÞ¼ÓÃÜÇ®±ÒϴǮЧÀÍBestMixer.io
ºÉÀ¼¾¯·½È¡µÞ¼ÓÃÜÇ®±ÒϴǮЧÀÍBestMixer.io¡£¡£¡£¡£¡£BestmixerÓÚ2018Äê5ÔÂÍÆ³ö£¬£¬£¬£¬ÔÚÒ»ÄêµÄʱ¼äÀïÒѾ×ÊÖú¿Í»§Ï´Ç®ÖÁÉÙ2ÒÚÃÀÔª¡£¡£¡£¡£¡£¸ÃЧÀÍ¿ÉÒÔ»ìÏý±ÈÌØ±Ò£¨BTC£©¡¢±ÈÌØ±ÒÏÖ½ð£¨BCH£©ºÍÀ³Ìرң¨LTC£©£¬£¬£¬£¬Í¨¹ý´ó×Ú»ìÏýÉúÒâʹµÃ¿î×ÓµÄȪԴ²»¿É×·×Ù¡£¡£¡£¡£¡£ºÉÀ¼FIODºÍÅ·ÖÞÐ̾¯×éÖ¯²é»ñÁË6̨ÓÃÓÚÌṩ¸ÃЧÀ͵ÄЧÀÍÆ÷£¬£¬£¬£¬²¢½«¶ÔÆäÊý¾Ý¾ÙÐнøÒ»²½µÄÆÊÎö¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/crypto-currency-laundering-service-bestmixer-io-taken-down-by-law-enforcement/
5¡¢Ñо¿ÍŶÓÐû²¼ÀÕË÷Èí¼þShadeй¥»÷»î¶¯µÄÆÊÎö±¨¸æ
ƾ֤palo alto networksµÄunit42ÍŶӵÄÒ»ÏîÐÂÑо¿£¬£¬£¬£¬2019Äê1Ôµ½3ÔÂʱ´úÀÕË÷Èí¼þShadeÖ÷ÒªÕë¶ÔµÄ¹ú¼ÒÓÐÃÀ¹ú¡¢ÈÕ±¾¡¢Ó¡¶È¡¢Ì©¹úºÍ¼ÓÄô󣬣¬£¬£¬Ö÷ÒªÕë¶ÔµÄÐÐÒµ°üÀ¨¸ß¿Æ¼¼ÐÐÒµ¡¢Åú·¢ÒµºÍ½ÌÓýÁìÓò¡£¡£¡£¡£¡£ShadeÊ״ηºÆðÓÚ2014Ä꣬£¬£¬£¬Ö÷ÒªÕë¶ÔÔËÐÐWindowsµÄÖ÷»ú£¬£¬£¬£¬Í¨¹ýÀ¬»øÓʼþºÍÎó²îʹÓù¤¾ß°ü¾ÙÐзַ¢¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://unit42.paloaltonetworks.com/shade-ransomware-hits-high-tech-wholesale-education-sectors-in-u-s-japan-india-thailand-canada/
6¡¢Ñо¿ÍŶÓÐû²¼ÀÕË÷Èí¼þGetCryptµÄ½âÃܹ¤¾ß
EmsisoftÒѾÐû²¼ÁËÀÕË÷Èí¼þGetCryptµÄÃ⺬»ìÃÜÆ÷¡£¡£¡£¡£¡£GetCryptÊÇÒ»ÖÖͨ¹ýRIG EK·Ö·¢µÄÐÂÀÕË÷Èí¼þ£¬£¬£¬£¬¸ÃÀÕË÷Èí¼þ»áÊ×Ïȼì²éWindowsÊÇ·ñÉèÖÃΪÎÚ¿ËÀ¼Óï¡¢°×¶íÂÞ˹Óï¡¢¶íÓï»ò¹þÈø¿ËÓ£¬£¬£¬ÈôÊÇÊÇÕâЩÓïÑÔ£¬£¬£¬£¬Ôò×èÖ¹ÔËÐУ¬£¬£¬£¬²»È»½«Ê¹ÓÃSalsa20ºÍRSA-4096Ëã·¨µÄ×éºÏÀ´¼ÓÃÜÎļþ£¬£¬£¬£¬²¢ÔÚÎļþºó¸½¼ÓËæ»ú4¸ö×Ö·ûµÄÀ©Õ¹Ãû¡£¡£¡£¡£¡£ÆäÀÕË÷ÐÅÏ¢ÒªÇóÓû§ÁªÏµgetcrypt@cock[.]li¾ÙÐи¶¿î¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/free-decryptor-released-for-getcrypt-ransomware-that-spreads-through-rig-exploit-kit-f4b5a4b2


¾©¹«Íø°²±¸11010802024551ºÅ