Ñо¿ÍŶӳÆ1.28ÒÚiOSÓû§ÒÑѬȾ¶ñÒâÈí¼þXcodeGhost£»TorÍøÂçÐÂÔöÊýǧ¸ö¶ñÒâ½Ó¿Ú£¬¼àÌý¼ÓÃÜÇ®±ÒÏà¹ØµÄÁ÷Á¿

Ðû²¼Ê±¼ä 2021-05-11

1.Ñо¿ÍŶӳÆ1.28ÒÚiOSÓû§ÒÑѬȾ¶ñÒâÈí¼þXcodeGhost


1.jpg


Ñо¿ÍŶӳÆ£¬ÔÚ×î½üµÄ¶ñÒâÈí¼þ¹¥»÷ÖУ¬Áè¼Ý1.28ÒÚiOSÓû§³ÉΪ¹¥»÷Ä¿µÄ¡£¹¥»÷ÕßÔÚ´Ë´ÎÔ˶¯ÖÐʹÓÃÁËXcodeGhost£¬¸Ã¶ñÒâÈí¼þÓÚ2015ÄêÊ״ηºÆð¡£AppleÖÒÑԳƣ¬Ô¼Äª2500¸öÓ¦ÓÃѬȾÁ˶ñÒâXcode´úÂë¡£¾Ý±¨µÀ£¬ÆäÖÐÔ¼55%µÄÓû§ÊÇÖйúÈË£¬¶ø66%µÄÏÂÔØÁ¿ÓëÖйúÓйØ¡£ÌØÊâÊÇ£¬Ò»Ð©¹ãÊܽӴýµÄÓ¦ÓÃÒ²ÒÑѬȾÁ˸öñÒâÈí¼þ£¬°üÀ¨ÓÎÏ·¡°ÄÕÅ­µÄСÄñ2¡±¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/05/xcodeghost-malware-infected-around-128m.html


2.TorÍøÂçÐÂÔöÊýǧ¸ö¶ñÒâ½Ó¿Ú£¬¼àÌý¼ÓÃÜÇ®±ÒÏà¹ØµÄÁ÷Á¿


2.jpg


The Record³Æ£¬×Ô2020ÄêÒÔÀ´TorÍøÂçÐÂÔöÊýǧ¸ö¶ñÒâ½Ó¿Ú£¬¼àÌý¼ÓÃÜÇ®±ÒÏà¹ØÍøÕ¾µÄÁ÷Á¿¡£ÔÚÕë¶ÔTorÍøÂçµÄ¹¥»÷ÖУ¬¹¥»÷Õß¿ÉʹÓÃÆä¿ØÖÆµÄÇ®°üÌæ»»Õýµ±Ç®°üµÄµØµãÀ´Ð®ÖÆÉúÒâ¡£±ðµÄ£¬Nusenu·¢Ã÷ºÚ¿ÍÒѾ­Á½´ÎÍ»ÆÆÁËÆä×Ô2020Äê5ÔÂÒÔÀ´µÄ¼Í¼(¶ñÒâ½Ó¿Ú±ÈÀýΪ23%):2020Äê10ÔÂ30ÈÕ£¬ºÚ¿ÍÍÅ»ïʹÓÃÁËÁè¼Ý26%µÄtorÍøÂç½Ó¿Ú£¬µ½2021Äê02ÔÂ02ÈÕ£¬ÆäÒѾ­ÖÎÀíÁËÁè¼Ý27%µÄ½Ó¿Ú¡£ÏÖÔÚ£¬¶ñÒâ½Ó¿Ú¾ùÒÑ´ÓTorÍøÂçÖÐÒÆ³ý¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/117749/deep-web/tor-exit-nodes-ssl-stripping.html


3.ÃÀ¹úËþ¶ûÈøÊÐÍøÂçѬȾÀÕË÷Èí¼þ£¬ÊÐÕþϵͳËùÓйرÕ


3.jpg


ÉÏÖÜÄ©£¬ÃÀ¹úËþ¶ûÈøÊеÄÍøÂçѬȾÀÕË÷Èí¼þ£¬ÊÐÕþϵͳËùÓйرÕ¡£Ëþ¶ûÈø£¨Tulsa£©ÊÇÃÀ¹ú¶í¿ËÀ­ºÉÂíÖݵĵڶþ´ó¶¼»á£¬Éú³ÝÔ¼40ÍòÈË¡£¸ÃÊÐÊг¤³ÆÆäÔÚ·þÎñÆ÷ÉÏ·¢Ã÷Á˶ñÒâÈí¼þ£¬²¢Á¬Ã¦¹Ø±ÕÁËËùÓÐϵͳ¡£Æä911·þÎñ»ò½ôÆÈÏìÓ¦²¢Î´Êܵ½Ó°Ï죬¿ÉÊÇÔÚÏßÕ˵¥Ö§¸¶ÏµÍ³¡¢¹«¹²ÊÂÎñ·þÎñ¡¢Ëþ¶ûÈøÊÐÒé»á¡¢¾¯Ô±¾ÖºÍËþ¶ûÈøµÈ311¸öÍøÕ¾ÈÔÔÚά»¤ÖС£¸ÃÊгƴ˴ι¥»÷²¢Î´Ð¹Â¶¹«ÃñµÄÐÅÏ¢£¬µ«²¿·ÖÎļþÒѾ­±»ÇÔ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/city-of-tulsas-online-services-disrupted-in-ransomware-incident/


4.°Ä´óÀûÑǹúÁ¢´óѧÔâµ½¹¥»÷£¬Ô±¹¤ºÍѧÉúµÄÐÅϢй¶


4.jpg


°Ä´óÀûÑǹúÁ¢´óѧ(ANU)½üÆÚ·¢Ã÷ÆäÔøÔâµ½¹¥»÷£¬Ô±¹¤ºÍѧÉúµÄÐÅϢй¶¡£ANUÓÚÁ½ÖÜǰ·¢Ã÷ÆäÔÚ2018Äêµ×Ôâµ½ÁËÍøÂç¹¥»÷£¬±»µÁÊý¾Ý¿É×·Ëݵ½19ÄêÒÔǰ£¬Éæ¼°Ô±¹¤¡¢Ñ§ÉúºÍ·Ã¿Í£¬ÏÖÔÚÉв»ÇåÎúºÚ¿ÍÔÚANUµÄϵͳÖÐÒþ²ØÁ˶೤ʱ¼ä¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢ÓʼþµØµã¡¢½ôÆÈÁªÏµ·½·¨¡¢Ë°ÎñÎļþ±àºÅ¡¢ÈËΪµ¥ÐÅÏ¢¡¢ÒøÐÐÕÊ»§ÏêϸÐÅÏ¢¡¢»¤ÕÕÏêϸÐÅÏ¢ºÍѧÊõ¼Í¼µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/au-19-years-of-personal-data-was-stolen-from-anu-it-could-show-up-on-the-dark-web/


5.Ñо¿Ö°Ô±ÑÝʾ¿ÉÈÆ¹ýSpectre·À»¤²½·¥µÄй¥»÷·½·¨


5.jpg


Ñо¿Ö°Ô±ÑÝʾÁËÒ»ÖÖÐµĹ¥»÷·½·¨£¬¿ÉÈÆ¹ýоƬÖÐÄÚÖõÄËùÓÐSpectre·À»¤²½·¥¡£SpectreÓÚ2018Äê1Ô¹ûÕæ£¬ËüµÄ½¹µãÊÇ׼ʱ²àÐŵÀ¹¥»÷£¬Ê¹ÓÃÁËCPUÓ²¼þʵÏÖÖеÄÍÆ²âÖ´ÐÐÓÅ»¯ÒªÁ죬ÓÕʹ³ÌÐò»á¼ûÄÚ´æÖеÄí§ÒâλÖôӶø×ß©ÐÅÏ¢¡£ÕâÖÖÐµĹ¥»÷·½·¨Ê¹ÓÃÁË΢²Ù×÷£¨micro-ops£©»º´æ£¬ÕâÊÇ¿ÉÒÔ½«»úеָÁîÆÊÎöΪ¸ü¼òÆÓµÄÏÂÁîµÄ×é¼þ£¬¿É×÷Ϊй¶ÉñÃØÐÅÏ¢µÄ¸¨ÖúÇþµÀ£¬×Ô2011ÄêÒÔÀ´±ãÒѱ»ÄÚÖõ½»ùÓÚIntelµÄÅÌËã»úÖС£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/05/new-spectre-flaws-in-intel-and-amd-cpus.html


6.Alien Labs·¢Ã÷QBotʹÓÃÏÖÓÐÕýµ±ÓʼþµÄ¹¥»÷Ô˶¯


6.jpg


Alien LabsµÄÑо¿Ö°Ô±·¢Ã÷ÁËÐÂÒ»ÂÖµÄQBot¹¥»÷Ô˶¯¡£QBot×Ô2007Äê×îÏÈ»îÔ¾£¬×î³õÖ»ÊÇ´¦ÓÚ²ÆÎñÄ¿µÄµÄÒøÐÐľÂí¡£Ôڴ˴ι¥»÷ÖУ¬¹¥»÷ÕßʹÓÃÁËÄ¿µÄÖ®¼äÕýµ±µÄÉÌҵͨѶ£¬²¢¶ÔÆä¾ÙÐÐÁËÐ޸ģ¬Ê¹µÃÓÕ¶üÓʼþ¿´ÉÏÈ¥¸üÓÐ˵·þÁ¦¡£±ðµÄ£¬ÎªÁËÔöÌí¼ì²âºÍÆÊÎöµÄÄѶÈ£¬QBot»á¶ÔÆä×Ö·û´®¾ÙÐмÓÃܲ¢ÔÚÔËÐÐʱ¶ÔÆä¾ÙÐнâÃÜ£¬Ò»µ©QBotµÄÖ´ÐÐÂß¼­Ê¹ÓÃÍê×Ö·û´®£¬Ëü½«Á¬Ã¦´ÓÄÚ´æÖÐɾ³ý¸Ã×Ö·û´®¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/05/qakbot-malware-is-targeting-users-via.html