¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190213

°ä²¼¹¦·ò 2019-02-13
1¡¢6.2ÒÚÕË»§ÐÅÏ¢ÔÚ°µÍøÏúÊÛ£¬ÊÛ¼ÛÔ¼2ÍòÃÀÔª

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

°µÍøÊг¡Dream MarketÉÏÔÚÏúÊÛ6.2ÒÚÕË»§ÐÅÏ¢£¬ÕâЩÐÅÏ¢µÁ×Ô16¸öÍøÕ¾£¬ÊÛ¼ÛÔ¼2ÍòÃÀÔª£¨ÒÔ±ÈÌØ±ÒÖ§¸¶£© ¡£ÕâЩ±»µÁÊý¾ÝÉæ¼°µÄÍøÕ¾Ô̺¬Dubsmash£¨1.62ÒÚ£©¡¢MyFitnessPal£¨1.51ÒÚ£©¡¢MyHeritage£¨9200Íò£©¡¢ShareThis£¨4100Íò£©¡¢HauteLook£¨2800Íò£©¡¢Animoto£¨2500Íò£©¡¢EyeEm£¨2200Íò£©¡¢8fit£¨2000Íò£©¡¢Whitepages£¨1800Íò£©¡¢Fotolog£¨1600Íò£©¡¢500px£¨1500Íò£©¡¢Armor Games£¨1100Íò£©¡¢BookMate£¨800Íò£©¡¢CoffeeMeetsBagel£¨600Íò£©¡¢Artsy£¨100Íò£©ºÍDataCamp£¨70Íò£© ¡£´ÓÑù±¾Êý¾ÝÀ´¿´£¬ÕâЩÊý¾ÝÖØÒªÔ̺¬ÕË»§³ÖÓÐÈ˵ÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍ¹þÏ£ÃÜÂ룬µ«²»Ô̺¬ÒøÐп¨ÐÅÏ¢ ¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2019/02/11/620_million_hacked_accounts_dark_web/

2¡¢LandMark While¿Í»§Êý¾Ýй¶£¬³¬¹ý10ÍòÈËÊÜÓ°Ïì

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


°Ä´óÀûÑÇ·¿²ú¹ÀÖµ¹«Ë¾LandMark WhiteÓÚ2ÔÂ8ÈÕÅû¶Êý¾Ýй¶ÊÂÎñ£¬³¬¹ý10ÍòÃû¿Í»§Êܵ½Ó°Ïì ¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢ÁªÏµ·½Ê½¡¢µç»°»òµç×ÓÓʼþµØÖ·¡¢·¿²ú¹ÀÖµÐÅÏ¢¡¢¾­¼ÍÈËÁªÏµ·½Ê½µÈ ¡£ÊÂÎñ²úÉúºó£¬°Ä´óÀûÑÇÁª¹úÒøÐУ¨CBA£©ºÍ°ÄÐÂÒøÐÐÔÝÍ£ÁËLandMark WhiteµÄÆÀ¹À¹¤×÷£¬²¢¶ÔÊÂÎñ½øÇ°½øÒ»²½µÄµ÷²é ¡£CBAÒÑÈ·ÈÏûÓÐÒøÐÐÕË»§ÐÅÏ¢Êܵ½ÇÖº¦ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/landmark-white-hit-by-data-breach-impacting-the-personal-information-of-up-to-100000-customers-3203577c

3¡¢VFEmail.netÔâºÚ¿ÍÈëÇÖ£¬ËùÓÐÃÀ¹ú¿Í»§µÄÊý¾Ý±»É¾³ý

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

2ÔÂ11ÈÕ£¬µç×ÓÓʼþ·þÎñÉÌVFEmail.netÔâµ½ºÚ¿Í¹¥»÷£¬ËùÓÐÃÀ¹ú·þÎñÆ÷ÉϵÄÊý¾Ý±»É¾³ý£¬Õâµ¼ÖÂËùÓÐÃÀ¹ú¿Í»§µÄÊý¾Ý±»É¾ ¡£¸Ã¹«Ë¾°µÊ¾£¬¹¥»÷ÕßÌåʽ»¯ÁËÿһ̨·þÎñÆ÷ÉϵÄÓ²ÅÌ£¬ËùÓеÄÐé¹¹»ú¡¢Îļþ·þÎñÆ÷Ô̺¬±¸·Ý·þÎñÆ÷¶¼ÒÑÃÔʧ ¡£ºÚ¿Í²¢Ã»ÓÐÒªÇóÊê½ð£¬VFEmail½«´ËÊÂÎñÃèÊöΪ¹¥»÷ºÍ·ÛËéÊÂÎñ ¡£Ä¿Ç°¸Ã¹«Ë¾µÄÍøÕ¾ÒѾ­³ÁÐÂÉÏÏߣ¬µ«´Î¼¶ÓòÃûÈÔÎÞ·¨½Ó¼û ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hackers-wipe-us-servers-of-email-provider-vfemail/

4¡¢Dunkin'DonutsÔÚÈý¸öÔÂÄÚµÚ¶þ´ÎÔ⵽ײ¿â¹¥»÷

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

Dunkin'DonutsÔÚÈý¸öÔÂÄÚµÚ¶þ´ÎÔ⵽ײ¿â¹¥»÷£¬²¿ÃÅÓû§ÕË»§ÊÜËð ¡£Dunkin'DonutsÔÚ2018Äê11Ôµ×Åû¶Á˵ÚÒ»´Îײ¿â¹¥»÷£¬¸Ã¹¥»÷²úÉúÔÚ2018Äê10ÔÂ31ÈÕ£¬´Ë¿Ì£¬¸Ã¹«Ë¾Åû¶Á˵ڶþ´Îײ¿â¹¥»÷£¨¹¥»÷ÏÖʵ²úÉúÔÚ2019Äê1ÔÂ10ÈÕ£© ¡£¹¥»÷ÕßÀûÓÃÓû§ÔÚÆäËüÍøÕ¾ÉÏй¶µÄÍ´´¦µÇ¼DD PerksµÄ¼Î½±ÕË»§£¬²¢ÀûÓÃÕË»§»ý·ÖÀ´¶Ò»»Ãâ·ÑÒûÁÏ»òÕÛ¿Û ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/dunkin-donuts-accounts-compromised-in-second-credential-stuffing-attack-in-three-months/

5¡¢Î¢Èí°ä²¼2019Äê2Ô°²È«¸üУ¬½¨¸´70¸ö·ì϶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

΢ÈíÔÚ2019Äê2Եݲȫ¸üÐÂÖн¨¸´ÁË70¸ö·ì϶£¬½ÏΪÑϳÁµÄ·ì϶Ô̺¬Microsoft ExchangeÖеÄÌáȨ·ì϶£¨PrivExchange£¬CVE-2019-0686£©¡¢IEÖеÄÐÅϢй¶·ì϶£¨CVE-2019-0676£¬¸Ã·ì϶ÒÑÔÚÒ°±í±»»ý¼«ÀûÓã©¡¢SMBv2ÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-0630£©ÒÔ¼°DHCPÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-0626£© ¡£¾ßÌå·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó ¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2019-patch-tuesday-includes-fixes-for-70-vulnerabilities/

6¡¢Windows EXEÀàÐ͵ÄжñÒâÎļþ£¬¿ÉϰȾmacOSϵͳ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ç÷Ïò¿Æ¼¼×êÑÐÈËÔ±·¢ÏÖÒ»¸öWindows EXEÀàÐ͵ÄжñÒâÎļþ¿ÉÈÆ¹ýmacOSµÄ°²È«±£»¤Ö°ÄÜ ¡£¸Ã¶ñÒâÎļþÊÇͨ¹ýMono¿ò¼Ü±àÒëµÄEXEÀûÓ÷¨Ê½£¬ÒÔ±ãÓëmacOS¼æÈÝ ¡£Í¨³£Çé¿öÏ£¬macOSÔÚÔËÐÐWindows exeÎļþʱ»á·¸´í£¬µ«ÆäÄÚÖõı£»¤»úÔ죨ÈçGatekeeper£©»áÌø¹ý¶ÔexeµÄɨÃè ¡£¸Ã¶ñÒâÈí¼þ¼Ù×°³ÉLittle Snitch·À»ðǽµÄ×°ÖÃÎļþ£¬ÆäpayloadÖ¼ÔÚÍøÂçºÍ·¢ËÍÖ¸±êMacµÄϵͳÐÅÏ¢µ½C&C·þÎñÆ÷ ¡£¸Ã¶ñÒâÈí¼þ»¹»áÏÂÔØ²¢ÌáÐÑÓû§×°Öø÷Àà¸æ°×Èí¼þ ¡£ÓÐȤµÄÊÇ£¬¸Ã¶ñÒâexeÎļþÎÞ·¨ÔÚWindowsÉÏÔËÐУ¬ÕâÒâζ×ÅÆäÖ»Õë¶ÔmacOSÓû§ ¡£

 

 Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/02/macos-windows-exe-malware.html


ÉêÃ÷£º±¾×ÊѶÓɱ¦ÔËÀ³¹Ù·½ÍøÕ¾Î¬ËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù