¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190213

Ðû²¼Ê±¼ä 2019-02-13
1¡¢6.2ÒÚÕË»§ÐÅÏ¢ÔÚ°µÍø³öÊÛ£¬£¬ £¬£¬ÊÛ¼ÛÔ¼2ÍòÃÀÔª

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

°µÍøÊг¡Dream MarketÉÏÕýÔÚ³öÊÛ6.2ÒÚÕË»§ÐÅÏ¢£¬£¬ £¬£¬ÕâЩÐÅÏ¢µÁ×Ô16¸öÍøÕ¾£¬£¬ £¬£¬ÊÛ¼ÛÔ¼2ÍòÃÀÔª£¨ÒÔ±ÈÌØ±ÒÖ§¸¶£©¡£¡£¡£ ¡£¡£ÕâЩ±»µÁÊý¾ÝÉæ¼°µÄÍøÕ¾°üÀ¨Dubsmash£¨1.62ÒÚ£©¡¢MyFitnessPal£¨1.51ÒÚ£©¡¢MyHeritage£¨9200Íò£©¡¢ShareThis£¨4100Íò£©¡¢HauteLook£¨2800Íò£©¡¢Animoto£¨2500Íò£©¡¢EyeEm£¨2200Íò£©¡¢8fit£¨2000Íò£©¡¢Whitepages£¨1800Íò£©¡¢Fotolog£¨1600Íò£©¡¢500px£¨1500Íò£©¡¢Armor Games£¨1100Íò£©¡¢BookMate£¨800Íò£©¡¢CoffeeMeetsBagel£¨600Íò£©¡¢Artsy£¨100Íò£©ºÍDataCamp£¨70Íò£©¡£¡£¡£ ¡£¡£´ÓÑù±¾Êý¾ÝÀ´¿´£¬£¬ £¬£¬ÕâЩÊý¾ÝÖ÷Òª°üÀ¨ÕË»§³ÖÓÐÈ˵ÄÐÕÃû¡¢µç×ÓÓʼþµØµãºÍ¹þÏ£ÃÜÂ룬£¬ £¬£¬µ«²»°üÀ¨ÒøÐп¨ÐÅÏ¢¡£¡£¡£ ¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2019/02/11/620_million_hacked_accounts_dark_web/

2¡¢LandMark While¿Í»§Êý¾Ýй¶£¬£¬ £¬£¬Áè¼Ý10ÍòÈËÊÜÓ°Ïì

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


°Ä´óÀûÑÇ·¿²ú¹ÀÖµ¹«Ë¾LandMark WhiteÓÚ2ÔÂ8ÈÕÅû¶Êý¾Ýй¶ÊÂÎñ£¬£¬ £¬£¬Áè¼Ý10ÍòÃû¿Í»§Êܵ½Ó°Ïì¡£¡£¡£ ¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢ÁªÏµ·½·¨¡¢µç»°»òµç×ÓÓʼþµØµã¡¢·¿²ú¹ÀÖµÐÅÏ¢¡¢¾­¼ÍÈËÁªÏµ·½·¨µÈ¡£¡£¡£ ¡£¡£ÊÂÎñ±¬·¢ºó£¬£¬ £¬£¬°Ä´óÀûÑÇÁª°îÒøÐУ¨CBA£©ºÍ°ÄÐÂÒøÐÐÔÝÍ£ÁËLandMark WhiteµÄÆÀ¹ÀÊÂÇ飬£¬ £¬£¬²¢¶ÔÊÂÎñ¾ÙÐнøÒ»²½µÄÊӲ졣¡£¡£ ¡£¡£CBAÒÑÈ·ÈÏûÓÐÒøÐÐÕË»§ÐÅÏ¢Êܵ½Ë𺦡£¡£¡£ ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/landmark-white-hit-by-data-breach-impacting-the-personal-information-of-up-to-100000-customers-3203577c

3¡¢VFEmail.netÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬ËùÓÐÃÀ¹ú¿Í»§µÄÊý¾Ý±»É¾³ý

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

2ÔÂ11ÈÕ£¬£¬ £¬£¬µç×ÓÓʼþЧÀÍÉÌVFEmail.netÔâµ½ºÚ¿Í¹¥»÷£¬£¬ £¬£¬ËùÓÐÃÀ¹úЧÀÍÆ÷ÉϵÄÊý¾Ý±»É¾³ý£¬£¬ £¬£¬Õâµ¼ÖÂËùÓÐÃÀ¹ú¿Í»§µÄÊý¾Ý±»É¾¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬ £¬£¬¹¥»÷ÕßÃûÌû¯ÁËÿһ̨ЧÀÍÆ÷ÉϵÄÓ²ÅÌ£¬£¬ £¬£¬ËùÓеÄÐéÄâ»ú¡¢ÎļþЧÀÍÆ÷°üÀ¨±¸·ÝЧÀÍÆ÷¶¼ÒÑɥʧ¡£¡£¡£ ¡£¡£ºÚ¿Í²¢Ã»ÓÐÒªÇóÊê½ð£¬£¬ £¬£¬VFEmail½«´ËÊÂÎñÐÎòΪ¹¥»÷ºÍÆÆËðÊÂÎñ¡£¡£¡£ ¡£¡£ÏÖÔڸù«Ë¾µÄÍøÕ¾ÒѾ­ÖØÐÂÉÏÏߣ¬£¬ £¬£¬µ«´Î¼¶ÓòÃûÈÔÎÞ·¨»á¼û¡£¡£¡£ ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hackers-wipe-us-servers-of-email-provider-vfemail/

4¡¢Dunkin'DonutsÔÚÈý¸öÔÂÄÚµÚ¶þ´ÎÔ⵽ײ¿â¹¥»÷

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

Dunkin'DonutsÔÚÈý¸öÔÂÄÚµÚ¶þ´ÎÔ⵽ײ¿â¹¥»÷£¬£¬ £¬£¬²¿·ÖÓû§ÕË»§ÊÜË𡣡£¡£ ¡£¡£Dunkin'DonutsÔÚ2018Äê11ÔÂβÅû¶Á˵ÚÒ»´Îײ¿â¹¥»÷£¬£¬ £¬£¬¸Ã¹¥»÷±¬·¢ÔÚ2018Äê10ÔÂ31ÈÕ£¬£¬ £¬£¬ÏÖÔÚ£¬£¬ £¬£¬¸Ã¹«Ë¾Åû¶Á˵ڶþ´Îײ¿â¹¥»÷£¨¹¥»÷ÏÖʵ±¬·¢ÔÚ2019Äê1ÔÂ10ÈÕ£©¡£¡£¡£ ¡£¡£¹¥»÷ÕßʹÓÃÓû§ÔÚÆäËüÍøÕ¾ÉÏй¶µÄƾ֤µÇ¼DD PerksµÄ½±ÀøÕË»§£¬£¬ £¬£¬²¢Ê¹ÓÃÕË»§»ý·ÖÀ´¶Ò»»Ãâ·ÑÒûÁÏ»òÕÛ¿Û¡£¡£¡£ ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/dunkin-donuts-accounts-compromised-in-second-credential-stuffing-attack-in-three-months/

5¡¢Î¢ÈíÐû²¼2019Äê2ÔÂÇå¾²¸üУ¬£¬ £¬£¬ÐÞ¸´70¸öÎó²î

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

΢ÈíÔÚ2019Äê2ÔµÄÇå¾²¸üÐÂÖÐÐÞ¸´ÁË70¸öÎó²î£¬£¬ £¬£¬½ÏΪÑÏÖØµÄÎó²î°üÀ¨Microsoft ExchangeÖеÄÌáȨÎó²î£¨PrivExchange£¬£¬ £¬£¬CVE-2019-0686£©¡¢IEÖеÄÐÅϢй¶Îó²î£¨CVE-2019-0676£¬£¬ £¬£¬¸ÃÎó²îÒÑÔÚÒ°Íâ±»Æð¾¢Ê¹Óã©¡¢SMBv2ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0630£©ÒÔ¼°DHCPÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-0626£©¡£¡£¡£ ¡£¡£ÏêϸÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£ ¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2019-patch-tuesday-includes-fixes-for-70-vulnerabilities/

6¡¢Windows EXEÀàÐ͵ÄжñÒâÎļþ£¬£¬ £¬£¬¿ÉѬȾmacOSϵͳ

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ç÷ÊÆ¿Æ¼¼Ñо¿Ö°Ô±·¢Ã÷Ò»¸öWindows EXEÀàÐ͵ÄжñÒâÎļþ¿ÉÈÆ¹ýmacOSµÄÇå¾²±£»£» £»£»£»¤¹¦Ð§¡£¡£¡£ ¡£¡£¸Ã¶ñÒâÎļþÊÇͨ¹ýMono¿ò¼Ü±àÒëµÄEXEÓ¦ÓóÌÐò£¬£¬ £¬£¬ÒÔ±ãÓëmacOS¼æÈÝ¡£¡£¡£ ¡£¡£Í¨³£ÇéÐÎÏ£¬£¬ £¬£¬macOSÔÚÔËÐÐWindows exeÎļþʱ»áÍÉ»¯£¬£¬ £¬£¬µ«ÆäÄÚÖõı£»£» £»£»£»¤»úÖÆ£¨ÈçGatekeeper£©»áÌø¹ý¶ÔexeµÄɨÃè¡£¡£¡£ ¡£¡£¸Ã¶ñÒâÈí¼þαװ³ÉLittle Snitch·À»ðǽµÄ×°ÖÃÎļþ£¬£¬ £¬£¬ÆäpayloadÖ¼ÔÚÍøÂçºÍ·¢ËÍÄ¿µÄMacµÄϵͳÐÅÏ¢µ½C&CЧÀÍÆ÷¡£¡£¡£ ¡£¡£¸Ã¶ñÒâÈí¼þ»¹»áÏÂÔØ²¢ÌáÐÑÓû§×°ÖÃÖÖÖÖ¹ã¸æÈí¼þ¡£¡£¡£ ¡£¡£ÓÐȤµÄÊÇ£¬£¬ £¬£¬¸Ã¶ñÒâexeÎļþÎÞ·¨ÔÚWindowsÉÏÔËÐУ¬£¬ £¬£¬ÕâÒâζ×ÅÆäÖ»Õë¶ÔmacOSÓû§¡£¡£¡£ ¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/02/macos-windows-exe-malware.html


ÉùÃ÷£º±¾×ÊѶÓÉ918²©ÌìÌÃάËûÃüÇ徲С×é·­ÒëºÍÕûÀí