¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181214

°ä²¼¹¦·ò 2018-12-14
1¡¢·¨¹úÓÎÀÀ¾¯Ê¾ÍøÕ¾±»ºÚ£¬²¿ÃŹ«ÃñµÄÓ×ÎÒÊý¾Ý±»µÁ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


·¨¹ú±í½»²¿ÖÜËݵʾ£¬ÆäÓÎÀÀ¾¯Ê¾ÍøÕ¾±»ºÚ£¬Ô¼54Íò¹«ÃñµÄÓ×ÎÒÐÅÏ¢±»µÁ¡£Æ¾¾ÝÆä°ä²¼µÄ¹«¿ªÉêÃ÷£¬Arianeƽ̨µÄ´¹Î£ÁªÏµÈËÊý¾Ý¿âÔâδÊÚȨ½Ó¼û£¬±»µÁµÄÊý¾ÝÔ̺¬ÐÕÃû¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµØÖ·£¬µ«²»Ô̺¬Ãô¸ÐÐÅÏ¢¡¢²ÆÕþÐÅÏ¢»ò¹Û¹âÖ÷ÕŵصÈÐÅÏ¢¡£¸Ã²¿ÃÅÔÚ2018Äê12ÔÂ5ÈÕ·¢ÏÖÁËÕâ´Î¹¥»÷£¬²¢ÔÚ72Ó×ʱÄÚ֪ͨÁËÒþÖÔ¼à¹Ü»ú¹¹CNIL¡£

   

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/personal-info-of-540k-people-exposed-in-french-ministry-website-breach-524270.shtml


2¡¢Òâ´óÀûʯÓͺÍÌìÈ»Æø¹«Ë¾SaipemÔâµ½ºÚ¿ÍÍøÂç¹¥»÷

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



±¾ÖÜÒ»Òâ´óÀûʯÓͺÍÌìÈ»Æø¹«Ë¾SaipemÔâµ½ÍøÂç¹¥»÷¡£Saipem¹«Ë¾µÄ¿Í»§±é²¼ÔÚ60¶à¸ö¹ú¶ÈÄÚ£¬Õâ´Î¹¥»÷ÆðÔ´ÓÚÓ¡¶È£¬ÖØÒªÓ°ÏìÁ˸ù«Ë¾ÔÚÖж«µØÓòµÄ·þÎñÆ÷£¬Ô̺¬É³Ìذ¢À­²®¡¢°¢ÁªÇõºÍ¿ÆÍþÌØ£¬ÆäÔÚÒâ´óÀû¡¢·¨¹úºÍÓ¢¹úµÄÖØÒªÔËÓªÖÐÐÄûÓÐÊܵ½Ó°Ïì¡£Saipem¶Ô·͸É簵ʾ¹¥»÷ÆðÔ´ÓÚÓ¡¶È½ðÄΣ¬µ«¹¥»÷ÕßµÄÉí·Ý²»Ã÷£¬ÓÉÓÚϵͳ¶¼Óб¸·Ý£¬Òò¶øÃ»º±¼û¾ÝÊܵ½Ëðʧ¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/78859/hacking/saipem-cyber-attack.html


3¡¢AndroidľÂí¼Ù×°³ÉµçÁ¿ÓÅ»¯ÀûÓã¬ÊÔͼÇÔÈ¡PayPalÕË»§×ʽð

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ESET×êÑÐÈËÔ±·¢ÏÖÒ»¸ö¼Ù×°³ÉµçÁ¿ÓÅ»¯appµÄAndroidľÂí£¬¸ÃľÂíÊÔͼ´ÓÓû§µÄPayPalÕÊ»§ÇÔÈ¡1000Å·ÔªµÄ×ʽð¡£¸ÃľÂí¼Ù×°³ÉOptimization AndroidÀûÓã¬Äܹ»´ÓµÚÈý·½ÀûÓÃÉ̵ê»ñµÃ¡£ÔÚ¶ñÒⷨʽ³õ´ÎÆô¶¯Ê±£¬Ëü»á¸ü¸Ä¸¨ÖúÖ°ÄÜÉèÖÃÒÔÆôÓõþ¼Ó²ã£¬²¢ÒªÇóÓû§´ò¿ªPayPalÒÔÈ·ÈÏÓû§µÄÕË»§¡£Ò»µ©Óû§´ò¿ªPayPal£¬¶ñÒⷨʽ¾Í»á·ÂÕÕÓû§µÄµã»÷²Ù×÷£¬Ïò¹¥»÷Õß»ã¿î1000Å·Ôª£¬Õû¸ö¹ý³Ì»òÐí±ØÒª5ÃëÖÓ¡£¸ÃľÂí»¹Äܹ»À¹½Ø¡¢·¢ËÍ»òɾ³ýÓû§µÄ¶ÌÐÅ£¬»ñÈ¡ÁªÏµÈËÁбíÒÔ¼°²¦´òµç»°¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/android-trojan-targets-paypal-users/139872/


4¡¢ÕÝ·ü½üÁ½Äêºó£¬Shamoon²¡¶¾ÐÂÑù±¾ÔÙÏÖÒâ´óÀû

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Êý¾Ý²Á³ý²¡¶¾Shamoon³õ´Î³öÏÖÓÚ2012Ä꣬Æäɾ³ýÁËÉ³ÌØ°¢ÃÀʯÓ͹«Ë¾µÄ3.5ÍòÍÆËã»úϵͳµÄÊý¾Ý¡£Æä4ÄêÖ®ºóÔٴγöÏÖ£¬²¢Ò»Ïò³ÖÐøµ½2017Äê1Ô¡£ÕâÒ»´ÎÔÚÕÝ·ü½üÁ½Äêºó£¬°²È«³§ÉÌChronicle·¢Ïָò¡¶¾µÄÐÂÑù±¾ÔÚÒâ´óÀû±»ÉÏ´«ÖÁVirusTotal¡£±¾ÖÜÒâ´óÀûʯÓͺÍÌìÈ»Æø¹«Ë¾SaipemÔâµ½ÍøÂç¹¥»÷£¬ÆäÖÐÒ»¸öÑù±¾ÊÇÓɸù«Ë¾ÉÏ´«µÄ¡£ÐÂÑù±¾Ô̺¬dropperÒÔ¼°Á½¸öÄ£¿é£¨WiperºÍNetwork£©£¬ÕâÁ½¸öÄ£¿é±ðÀëÕÆ¹Ü²Á³ý´ÅÅÌÒÔ¼°ÓëC&CͨѶ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/shamoon-disk-wiping-malware-re-emerges-with-two-new-variants/


5¡¢macOS¶ñÒâÈí¼þÔÙÌíгÉÔ±£¬OSX.LamePyreºóÃſɽØÈ¡ÆÁÄ»ÐÅÏ¢

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Malwarebytes×êÑÐÈËÔ±Adam Thomas·¢ÏÖÒ»¸öеÄmacOS¶ñÒâÈí¼þOSX.LamePyre¡£¸Ã¶ñÒâÈí¼þµÄÖ°ÄܽöÔ̺¬ÆÁÄ»½ØÍ¼ºÍºóÃÅ·¨Ê½£¬¿´ÆðÀ´¸Ã¶ñÒâÈí¼þÈÔ´¦ÓÚ¿ª·¢¹ý³ÌÖС£OSX.LamePyre¼Ù×°³ÉÐÂÎÅÀûÓÃDiscord½øÐд«²¼£¬ÆäʹÓÃÁ˵äÐ͵ÄAutomatorͼ±ê£¬²¢¿ªÊÍpython±àдµÄpayload£¬¶øºó½ØÈ¡ÆÁÄ»ÐÅÏ¢²¢ÉÏ´«ÖÁC&C·þÎñÆ÷¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-lamepyre-macos-malware-sends-screenshots-to-attacker/


6¡¢Õ¨µ¯À´Ï®£¬ÐµçÓÊȦÌ×ÔÚÃÀ¹úÒýÆð·¢¼±

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÐÂÒ»ÂÖµç×ÓÓʼþÚ¿Æ­»î¶¯ÔÚÃÀ¹úÒýÆðÁË·¢¼±¸ÐÇ飬ÓÉÓÚÕâЩÓʼþÐû³ÆÔÚÊÕ¼þÈ˵Ĺ¹ÖþÎïÖиéÖÃÁËÕ¨µ¯£¬ÈôÊDz»Ö§¸¶¼ÛÖµ2ÍòÃÀÔªµÄ±ÈÌØ±Ò£¬¸ÃÕ¨µ¯½«ÔÚµ±ÌìʵÏÖʱÒý±¬¡£Å¦Ô¼¾¯Ô±¾ÖÒÑÆðÍ·µ÷²éÕâЩÍþв£¬µ«µ½Ä¿Ç°ÎªÖ¹ÕâЩÍþв¶¼²»ÊÇÕæµÄ¡£TwitterÉϵݲȫ×êÑÐÈËÔ±Defender°µÊ¾£¬×Ô12ÔÂ13ÈÕÃÀ¹ú¶«²¿¹¦·òÏÂÎç12:48ÆðÍ·£¬ËûÃÇÒѾ­²¶»ñµ½Á˳¬¹ý1.5Íò·âÚ¿Æ­Óʼþ£¬ÕâЩÓʼþÀ´×ÔÓÚ¶íÂÞ˹µÄIPµØÖ·¡£Defender»¹°µÊ¾ÕâЩڿƭÓʼþ²»½ö±»·¢ËÍÖÁÃÀ¹ú£¬»¹±»·¢ËÍÖÁ¼ÓÄôó¡¢Ó¢¹ú¡¢ºÉÀ¼¡¢ÈðÊ¿ºÍÈðµä¡£Ä¿Ç°ÒÑÓв¿ÃÅÊܺ¦ÕßÖ§¸¶Á˼ÛÖµ18ÃÀÔªµÄ±ÈÌØ±Ò£¬Õâ¿ÉÄÜÊÇÓÉÓÚÊܺ¦Õ߸ã´íÁËÓ×ÊýµãµÄµØÎ»£¬³¢ÊÔÖ§¸¶20ÃÀÔªµÄÊê½ð¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-bomb-threat-email-scam-campaign-demanding-20k-in-bitcoin/


ÉêÃ÷£º±¾×ÊѶÓɱ¦ÔËÀ³¹Ù·½ÍøÕ¾Î¬ËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù