¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181228

Ðû²¼Ê±¼ä 2018-12-28
1¡¢Exchange ServerºáÏòÉøÍ¸ºÍÌáȨ£¬£¬£¬£¬£¬£¬£¬EXPÒÑÐû²¼

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ZDIÅû¶Exchange ServerÖеÄÒ»¸öÇå¾²Îó²î£¨CVE-2018-8581£©µÄÊÖÒÕϸ½Ú¡£¡£ ¡£¡£¡£¡£¸ÃÎó²îÔÊÐíÈκξ­ÓÉÉí·ÝÑéÖ¤µÄÓû§Ã°³äExchange ServerÉÏµÄÆäËüÓû§£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚ´¹Âڻ¡¢Êý¾Ýй¶µÈ¹¥»÷»î¶¯ÖС£¡£ ¡£¡£¡£¡£¸ÃÎó²îÊÇÒ»¸öЧÀÍÆ÷¶ËÇëÇóαÔ죨SSRF£©Îó²î£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÑÝʾÁËÔõÑùʹÓøÃÎó²îÐÞ¸ÄÊܺ¦ÕßÓÊÏäµÄÈëÕ¾¹æÔò£¬£¬£¬£¬£¬£¬£¬²¢½«ËùÓеÄÈëÕ¾µç×ÓÓʼþ¶¼×ª·¢¸ø¹¥»÷Õߣ¬£¬£¬£¬£¬£¬£¬Æäexp¾ç±¾¿ÉÒÔ´ÓgithubÉÏÏÂÔØ¡£¡£ ¡£¡£¡£¡£Î¢ÈíÔÚ11Ô·ݵÄÐÞ¸´²¹¶¡ÖÐͨ¹ýɾ³ýÒ»¸ö×¢²á±íÏîÀ´»º½â¸ÃÎó²î¡£¡£ ¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.zerodayinitiative.com/blog/2018/12/19/an-insincere-form-of-flattery-impersonating-users-on-microsoft-exchange


2¡¢ÀÕË÷Èí¼þCriaklµÄбäÌåͨ¹ýÀ¬»øÓʼþÈö²¥

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾



AnyrunÔÚÊ¥µ®½Úʱ´ú·¢Ã÷Ò»¸öеÄÀÕË÷Èí¼þÑù±¾£¬£¬£¬£¬£¬£¬£¬¸ÃÑù±¾ÊÇcriaklµÄÒ»¸öбäÌå¡£¡£ ¡£¡£¡£¡£Criakl·ºÆðÓÚ2014Äê×óÓÒ£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÓ¢¹ú£¬£¬£¬£¬£¬£¬£¬µ«ËæºóÏÕЩÏûÊÅ¡£¡£ ¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷µÄÑù±¾Í¨¹ý´¹ÂÚÓʼþÈö²¥£¬£¬£¬£¬£¬£¬£¬ÕâЩ´¹ÂÚÓʼþµÄÓ¢ÎIJ¢²»ÊǺܺ㬣¬£¬£¬£¬£¬£¬ºÜ¿ÉÄÜÊÇͨ¹ýÆäËüÓïÑÔ»úе·­ÒëµÃÀ´¡£¡£ ¡£¡£¡£¡£ÕâЩ´¹ÂÚÓʼþ¾ùͨ¹ýSPFºÍDKIMÈÏÖ¤£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÒ»¸ö°üÀ¨.docÎĵµµÄzip¸½¼þ£¬£¬£¬£¬£¬£¬£¬ÁíÒ»¸ö°üÀ¨.exeÎļþµÄrar¸½¼þ¡£¡£ ¡£¡£¡£¡£¸ÃcriaklµÄбäÌåֻѬȾWindowsϵͳµÄÅÌËã»ú¡£¡£ ¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://myonlinesecurity.co.uk/new-ransomware-possibly-criakl-version/


3¡¢Shamoon 3ÐÂÑù±¾±»ÉÏ´«ÖÁVirusTotal£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÓâÆÚµÄ°Ù¶ÈÖ¤Êé

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Êý¾Ý²Á³ýÈí¼þShamoon 3µÄÒ»¸öÐÂÑù±¾ÓÚ12ÔÂ23ÈÕÔÚ·¨¹úÉÏ´«ÖÁVirusTotalƽ̨¡£¡£ ¡£¡£¡£¡£¸ÃÑù±¾Ê¹ÓÃÁËÓâÆÚµÄ°Ù¶ÈÖ¤Ê飨´ËÖ¤ÊéÓÚ2015Äê3ÔÂ25ÈÕÐû²¼£¬£¬£¬£¬£¬£¬£¬²¢ÓÚ2016Äê3ÔÂ26ÈÕÓâÆÚ£©£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÉÌÒµ´ò°ü¹¤¾ßEnigma v4¾ÙÐлìÏý¡£¡£ ¡£¡£¡£¡£Æ¾Ö¤AnomaliʵÑéÊ񵀮ÊÎö£¬£¬£¬£¬£¬£¬£¬¸ÃÐÂÑù±¾Ê¹ÓÃÁËȼÉÕµÄÃÀԪͼ°¸²¢°üÀ¨¡°ÎÒÃǽ«Îªº¢×ÓµÄѪÓëÀḴ³ð¡±×ÖÑù¡£¡£ ¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/79248/malware/shamoon-3-france.html


4¡¢ÃÀÁª°îÉÌҵίԱ»áÖÒÑÔÕë¶ÔNetflixÓû§µÄ´¹ÂÚ¹¥»÷

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÃÀ¹úÁª°îÉÌҵίԱ»á£¨FTC£©ÖÒÑÔÕë¶ÔNetflix¿Í»§µÄÐÂÍøÂç´¹Âڻ¡£¡£ ¡£¡£¡£¡£ÕâЩ´¹ÂڻÖй¥»÷Õßαװ³ÉNetflixÏòÓû§·¢ËÍ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬£¬Éù³ÆÓû§µÄÕË»§ÓÉÓÚ½áËãÎÊÌâ¶ø±»ÔÝÊ±Ëø¶¨£¬£¬£¬£¬£¬£¬£¬ÒªÇóËûÃǸüÐÂ×Ô¼ºµÄ¸¶¿î·½·¨£¬£¬£¬£¬£¬£¬£¬µ«ÏÖʵÉÏÖ»ÊÇΪÁËÇÔÈ¡ÕâЩ¸¶¿îÐÅÏ¢¡£¡£ ¡£¡£¡£¡£NetflixÌåÏָù«Ë¾¾ø²»»áÒªÇóÓû§Í¨¹ýµç×ÓÓʼþ·¢ËÍСÎÒ˽¼ÒÐÅÏ¢¡¢¸¶¿îÐÅÏ¢»òÕË»§ÃÜÂëµÈ¡£¡£ ¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/ftc-warns-of-netflix-phishing-scam-making-rounds/140378/


5¡¢BevMoÍøÕ¾±»×¢Èë¶ñÒâ´úÂ룬£¬£¬£¬£¬£¬£¬Áè¼Ý1.4ÍòÓû§µÄÐÅϢй¶

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÃÀ¹úÆÏÌѾƺÍÁÒ¾ÆÊÐËÁBevMoÏòÆä¿Í»§Í¨Öª³Æ¸Ã¹«Ë¾ÔâÓöÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬Áè¼Ý1.4ÍòÃû¿Í»§µÄÐÅϢй¶¡£¡£ ¡£¡£¡£¡£Æ¾Ö¤¸Ã¹«Ë¾Ìá½»¸ø¼ÓÖÝÉó²é³¤°ì¹«Êҵı¨¸æ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÆäÍøÕ¾µÄ½áÕËÒ³Ãæ×¢ÈëÁ˶ñÒâ´úÂ룬£¬£¬£¬£¬£¬£¬ÓÃÓÚÇÔÈ¡¿Í»§µÄÐÕÃû¡¢µç»°ºÅÂë¡¢µØµã¡¢ÐÅÓÿ¨ºÅÂëºÍÇå¾²ÂëµÈ¡£¡£ ¡£¡£¡£¡£¸ÃÊÂÎñÓ°ÏìÁË2018Äê8ÔÂ2ÈÕÖÁ9ÔÂ26ÈÕʱ´úµÄ¶©µ¥¡£¡£ ¡£¡£¡£¡£BevMoÒÑ´ÓÆäÔÚÏßÊÐËÁÖÐɾ³ýÁ˶ñÒâ´úÂ룬£¬£¬£¬£¬£¬£¬²¢È·ÈÏÕýÔÚ¾ÙÐÐÊӲ졣¡£ ¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/79230/data-breach/bevmo-payment-card-breach.html


6¡¢·¨¹úî¿Ïµ»ú¹¹CNILÒòÊý¾Ýй¶ÊÂÎñ¶ÔµçÐŹ«Ë¾Bouygues·£¿£¿£¿£¿î25ÍòÅ·Ôª

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


¾Ý°ÍÀè·͸É籨µÀ£¬£¬£¬£¬£¬£¬£¬±¾ÖÜËÄ·¨¹úÊý¾ÝÒþ˽î¿Ïµ»ú¹¹CNIL¶ÔµçÐŹ«Ë¾Bouygues´¦ÒÔ25ÍòÅ·ÔªµÄ·£¿£¿£¿£¿î£¨Ô¼28.5ÍòÃÀÔª£©¡£¡£ ¡£¡£¡£¡£CNIL³ÆBouyguesδÄÜÈ·±£ÆäÍøÕ¾ÉÏÊý¾ÝµÄÇå¾²ÐÔ£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÔ¼2°ÙÍòÓû§µÄСÎÒ˽¼ÒÊý¾ÝÊܵ½Êý¾Ýй¶ÊÂÎñµÄÓ°Ïì¡£¡£ ¡£¡£¡£¡£CNIL»¹³Æ¸Ã¹«Ë¾ÒѾ­ÐÞ¸´Á˸ÃÎÊÌâ¡£¡£ ¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.reuters.com/article/us-france-bouygues-fine/french-watchdog-fines-bouygues-for-data-security-breach-idUSKCN1OQ0Q4


ÉùÃ÷£º±¾×ÊѶÓÉ918²©ÌìÌÃάËûÃüÇ徲С×é·­ÒëºÍÕûÀí