¹È¸èÐû²¼ÁËÕë¶ÔAndroid OSµÄÇå¾²¸üУ¬ £¬£¬£¬£¬ÐÞ¸´¶à¸öÎó²î£»£»£»Ô¼¿Ë´óѧÔâºÚ¿Í¹¥»÷£¬ £¬£¬£¬£¬¶à¸öЧÀÍÆ÷ºÍÊÂÇéÕ¾±»ÆÆËð

Ðû²¼Ê±¼ä 2020-05-06

1.¹È¸èÐû²¼ÁËÕë¶ÔAndroid OSµÄÇå¾²¸üУ¬ £¬£¬£¬£¬ÐÞ¸´¶à¸öÎó²î


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


¹È¸èÓÚ±¾ÖÜÐû²¼ÁË2020Äê5ÔÂÕë¶ÔAndroid²Ù×÷ϵͳµÄÇå¾²²¹¶¡£¬ £¬£¬£¬£¬×ܹ²ÐÞ¸´ÁË39¸öÎó²î£¬ £¬£¬£¬£¬¸ÃÇå¾²¸üÐÂ×ܹ²°üÀ¨Á½²¿·Ö£¬ £¬£¬£¬£¬ÆäÖÐ2020-05-01Çå¾²²¹¶¡³ÌÐòÐÞ¸´ÁË15¸öÎó²î£¬ £¬£¬£¬£¬¶ø2020-05-05Çå¾²²¹¶¡³ÌÐòÐÞ¸´ÁË24¸öÎó²î¡£¡£¡£¡£´Ë´ÎÐÞ²¹µÄÎó²îÖÐ×îÑÏÖØµÄÒ»¸öÎó²î±»×·×ÙΪCVE-2020-0103£¬ £¬£¬£¬£¬ÆäÓ°ÏìÁËAndroid 9ºÍAndroid 10£¬ £¬£¬£¬£¬ËüÄÜʹԶ³Ì¹¥»÷ÕßÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£  


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/androids-may-2020-patches-fix-critical-system-vulnerability


2.ºÚ¿Íαװ³ÉFINRA¹ÙÔ±Ìᳫ´¹ÂÚ¹¥»÷ÒÔÇÔÈ¡Óû§ÐÅÏ¢


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÃÀ¹ú½ðÈÚÒµî¿Ïµ¾Ö£¨FINRA£©ÖÒÑÔ˵£¬ £¬£¬£¬£¬ÏÖÔÚÓкڿÍÕýÔÚð³äî¿Ïµ¾ÖµÄ¹ÙÔ±£¬ £¬£¬£¬£¬Ðû²¼ÍøÂç´¹ÂÚµç×ÓÓʼþ¡£¡£¡£¡£ÕâЩÓʼþÓòÃû¾ùΪ¡°broker-finra[.]org,¡± £¬ £¬£¬£¬£¬²¢ÇÒÓʼþÖÐÒªÇóÊÕ¼þÈ˵ã»÷¡°Á¬Ã¦¹Ø×¢¡±µÄÁ´½Ó£¬ £¬£¬£¬£¬ÒÔ½«Êܺ¦ÕßÖØ¶¨Ïòµ½ÍøÂç´¹ÂÚÍøÕ¾£¬ £¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡ÆäMicrosoft Office»òSharePointÃÜÂë¡£¡£¡£¡£FINRAÃ÷È·ÌåÏÖËûÃÇÕýÔÚ¹¥»÷´Ë´Î´¹Âڻ£¬ £¬£¬£¬£¬²¢ÖÒÑÔÓû§broker-finra[.]orgÓëî¿Ïµ¾Ö²¢ÎÞ¹ØÏµ£¬ £¬£¬£¬£¬¹«Ë¾Ó¦Á¬Ã¦É¾³ý´ËÓòÃûµÄËùÓеç×ÓÓʼþ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.tripwire.com/state-of-security/security-data-protection/digital-fraudsters-masquerading-as-finra-in-phishing-emails/


3.¶ñÒâÈí¼þKaijiͨ¹ýSSH±©Á¦¹¥»÷Õë¶ÔLinuxЧÀÍÆ÷ºÍIoT×°±¸


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Çå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖеĶñÒâÈí¼þKaiji£¬ £¬£¬£¬£¬¸Ã¶ñÒâÈí¼þͨ¹ýSSH±©Á¦¹¥»÷£¬ £¬£¬£¬£¬×¨ÃÅѬȾ»ùÓÚLinuxµÄЧÀÍÆ÷ºÍÖÇÄÜÎïÁªÍø£¨IoT£©×°±¸£¬ £¬£¬£¬£¬È»ºóʹÓÃÕâЩװ±¸ÌᳫDDoS¹¥»÷¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÓëÆäËûIoT¶ñÒâÈí¼þµÄÀàÐÍÓкܴó²î±ð£¬ £¬£¬£¬£¬ËüÊÇʹÓÃGo±àдµÄ¶ø²»ÊÇC»òC ++¡£¡£¡£¡£IntezerÑо¿Ö°Ô±Ñо¿·¢Ã÷£¬ £¬£¬£¬£¬¸ÃÈí¼þÊÇͨ¹ýSSH±©Á¦¹¥»÷¾ÙÐÐÈö²¥µÄ£¬ £¬£¬£¬£¬¶Ô±©Â©ÁËSSHµÄIoT×°±¸ºÍLinuxЧÀÍÆ÷Ö´Ðб©Á¦¹¥»÷²¢ÇÒÖ»Õë¶ÔrootÓû§¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬KaijiÒѾ­ÔÚÒ°ÍⱻʹÓ㬠£¬£¬£¬£¬²¢ÔÚÌìϹæÄ£ÄÚ»ºÂýÈö²¥£¬ £¬£¬£¬£¬¸ÃÈí¼þ»¹ÔÚÒ»Ö±¿ª·¢ÖС£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-kaiji-malware-targets-iot-devices-via-ssh-brute-force-attacks/


4.ÐÂÀÕË÷Èí¼þVCryptͨ¹ý7zip¼ÓÃÜÎļþ£¬ £¬£¬£¬£¬Õë¶Ô·¨¹úÓû§


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


BleepingComputer·¢Ã÷ÁËÒ»ÖÖеÄÃûΪVCryptµÄÀÕË÷Èí¼þ£¬ £¬£¬£¬£¬Ëüͨ¹ýʹÓÃ7zipÏÂÁîÐгÌÐòÀ´¼ÓÃÜÎļþ£¬ £¬£¬£¬£¬²¢ÇÒÕë¶ÔµÄÊÇ·¨¹úÊܺ¦Õß¡£¡£¡£¡£¸ÃÀÕË÷Èí¼þ½«É¾³ýÊܺ¦ÕßWindowsÎļþ¼ÐÖÐËùÓеÄÎļþ£¬ £¬£¬£¬£¬È»ºó½¨ÉèÒÔ¸ÃÎļþ¼ÐÃûÃüÃûµÄ¼ÓÃÜÎļþ£¬ £¬£¬£¬£¬ÕâЩ¼ÓÃܵÄÎļþÊÇÒÔusername_foldername.vxcryptµÄÃûÌÃÃüÃûµÄ¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬ÀÕË÷Èí¼þÆô¶¯ºó£¬ £¬£¬£¬£¬Internet ExplorerÖлáÏÔʾÓ÷¨Óï±àдµÄÃûΪhelp.htmlµÄÀÕË÷ÐÅÏ¢¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬Éв»ÇåÎú´Ë´Î¹¥»÷ÊÇÔõÑù·Ö·¢¸ÃÀÕË÷Èí¼þ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-vcrypt-ransomware-locks-files-in-password-protected-7zips/


5.Florentine BankerÍÅ»ïʹÓô¹ÂÚ¹¥»÷͵ȡÁË50¶àÍòÓ¢°÷


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


·ðÂÞÂ×ÈøÒøÐмҼ¯ÍÅ£¨Florentine Banker£©ÒÔÓ¢¹úºÍÒÔÉ«ÁнðÈÚÒµµÄÈý¸ö´óÐÍ×éÖ¯×÷ΪĿµÄ£¬ £¬£¬£¬£¬Ê¹ÓÃÁËÆóÒµµç×ÓÓʼþÍ×Э£¨BEC£©Ú²Æ­µÄ·½·¨£¬ £¬£¬£¬£¬ÍµÈ¡ÁËÁè¼Ý50ÍòÓ¢°÷¡£¡£¡£¡£Ê×ÏÈ£¬ £¬£¬£¬£¬¸Ã´¹ÂڻÕë¶ÔµÄÊÇÄ¿µÄ»ú¹¹ÖеÄÊ×ϯִÐй١¢Ê×ϯ²ÆÎñ¹ÙºÍÆäËûÓÐȨ´ú±í¸Ã×éÖ¯¾ÙÐÐ×ʽð×ªÒÆµÄСÎÒ˽¼Ò¡£¡£¡£¡£È»ºó¹¥»÷Õßͨ¹ýÑо¿Êܺ¦Õߵĵç×ÓÓʼþ£¬ £¬£¬£¬£¬ÒÔÏàʶÕâЩ×éÖ¯ÖеĻã¿îÁ÷³Ì¡£¡£¡£¡£×îºó£¬ £¬£¬£¬£¬¸ÃÍÅ»ï¾ÙÐÐÁËËÄ´ÎÉúÒâʵÑ飬 £¬£¬£¬£¬ÊÔͼ½«110ÍòÓ¢°÷תÈëËûÃǵÄÒøÐÐÕÊ»§¡£¡£¡£¡£×îÖÕ£¬ £¬£¬£¬£¬±»µÁ½ð¶îÖÐÖ»ÓÐ57ÍòÓ¢°÷±»×·»Ø£¬ £¬£¬£¬£¬´Ë´Î¹¥»÷¸øÕâЩ×éÖ¯Ôì³ÉÔ¼60ÍòÓ¢°÷µÄËðʧ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/the-florentine-banker-group-tricks-banks-in-a-half-million-gbp-heist-01a5ba79/?web_view=true


6.Ô¼¿Ë´óѧÔâºÚ¿Í¹¥»÷£¬ £¬£¬£¬£¬¶à¸öЧÀÍÆ÷ºÍÊÂÇéÕ¾±»ÆÆËð


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Ô¼¿Ë´óѧÔÚÒ»·ÝÉùÃ÷ÖÐ˵£¬ £¬£¬£¬£¬ÆäѧУÓÚÉÏÖÜÎåÍíÉÏÔâµ½Á˺ڿ͵Ĺ¥»÷£¬ £¬£¬£¬£¬ÆäÐí¶àЧÀÍÆ÷ºÍÊÂÇéÕ¾±»ÆÆË𡣡£¡£¡£¶ø¸Ã´óѧÔÚ¹¥»÷×îÏȺó£¬ £¬£¬£¬£¬Ñ¸ËÙÇжÏÁËѧУµÄ»¥ÁªÍø²¢¹Ø±ÕÁËÐí¶àÔÚÏß³ÌÐò£¬ £¬£¬£¬£¬ÒÔ¼õÇá¹¥»÷µÄ¹æÄ£ºÍÑÏÖØÐÔ¡£¡£¡£¡£×èÖ¹±¾ÖÜÒ»ÏÂÖ磬 £¬£¬£¬£¬ÆäÖÐһЩϵͳÈÔ´¦ÓÚÀëÏß״̬£¬ £¬£¬£¬£¬°üÀ¨Ñ§Ð£µÄÃÅ»§ÍøÕ¾¡£¡£¡£¡£Ô¼¿Ë´óѧÌåÏÖ£¬ £¬£¬£¬£¬ÕýÔÚÊÓ²ì´ËÊÂÎñ£¬ £¬£¬£¬£¬Ò²ÔÚÆð¾¢ÒÔ¾¡¿ì»Ö¸´Ô¼¿Ë´óѧµÄÔÚÏßϵͳ£¬ £¬£¬£¬£¬²¢½¨ÒéϵͳÓû§ÖØÐÂÉèÖÃÃÜÂë¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cbc.ca/news/canada/toronto/york-university-cyber-attack-1.5555106