Ñо¿ÍŶӳÆ1.28ÒÚiOSÓû§ÒÑѬȾ¶ñÒâÈí¼þXcodeGhost£»TorÍøÂçÐÂÔöÊýǧ¸ö¶ñÒâ½Ó¿Ú£¬¼àÌý¼ÓÃÜ»õ±ÒÏà¹ØµÄÁ÷Á¿

Ðû²¼Ê±¼ä 2021-05-11

1.Ñо¿ÍŶӳÆ1.28ÒÚiOSÓû§ÒÑѬȾ¶ñÒâÈí¼þXcodeGhost


1.jpg


Ñо¿ÍŶӳÆ£¬ÔÚ×î½üµÄ¶ñÒâÈí¼þ¹¥»÷ÖУ¬Áè¼Ý1.28ÒÚiOSÓû§³ÉΪ¹¥»÷Ä¿±ê¡£¹¥»÷ÕßÔڴ˴λÖÐʹÓÃÁËXcodeGhost£¬¸Ã¶ñÒâÈí¼þÓÚ2015ÄêÊ״ηºÆð¡£Apple¾¯¸æ³Æ£¬Ô¼Äª2500¸öÓ¦ÓÃѬȾÁ˶ñÒâXcode´úÂë¡£¾Ý±¨µÀ£¬ÆäÖÐÔ¼55%µÄÓû§ÊÇÖйúÈË£¬¶ø66%µÄÏÂÔØÁ¿ÓëÖйúÓйØ¡£ÌرðÊÇ£¬Ò»Ð©¹ãÊÜ»¶Ó­µÄÓ¦ÓÃÒ²ÒÑѬȾÁ˸öñÒâÈí¼þ£¬°üÂÞÓÎÏ·¡°ÄÕÅ­µÄСÄñ2¡±¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/05/xcodeghost-malware-infected-around-128m.html


2.TorÍøÂçÐÂÔöÊýǧ¸ö¶ñÒâ½Ó¿Ú£¬¼àÌý¼ÓÃÜ»õ±ÒÏà¹ØµÄÁ÷Á¿


2.jpg


The Record³Æ£¬×Ô2020ÄêÒÔÀ´TorÍøÂçÐÂÔöÊýǧ¸ö¶ñÒâ½Ó¿Ú£¬¼àÌý¼ÓÃÜ»õ±ÒÏà¹ØÍøÕ¾µÄÁ÷Á¿¡£ÔÚÕë¶ÔTorÍøÂçµÄ¹¥»÷ÖУ¬¹¥»÷Õß¿ÉÀûÓÃÆä¿ØÖÆµÄÇ®°üÌæ»»ºÏ·¨Ç®°üµÄµØÖ·À´½Ù³Ö½»Òס£´ËÍ⣬Nusenu·¢ÏÖºÚ¿ÍÒѾ­Á½´Î´òÆÆÁËÆä×Ô2020Äê5ÔÂÒÔÀ´µÄ¼Ç¼(¶ñÒâ½Ó¿Ú±ÈÀýΪ23%):2020Äê10ÔÂ30ÈÕ£¬ºÚ¿ÍÍÅ»ïÀûÓÃÁËÁè¼Ý26%µÄtorÍøÂç½Ó¿Ú£¬µ½2021Äê02ÔÂ02ÈÕ£¬ÆäÒѾ­¹ÜÀíÁËÁè¼Ý27%µÄ½Ó¿Ú¡£Ä¿Ç°£¬¶ñÒâ½Ó¿Ú¾ùÒÑ´ÓTorÍøÂçÖÐÒÆ³ý¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/117749/deep-web/tor-exit-nodes-ssl-stripping.html


3.ÃÀ¹úËþ¶ûÈøÊÐÍøÂçѬȾÀÕË÷Èí¼þ£¬ÊÐÕþϵͳȫ²¿¹Ø±Õ


3.jpg


ÉÏÖÜÄ©£¬ÃÀ¹úËþ¶ûÈøÊеÄÍøÂçѬȾÀÕË÷Èí¼þ£¬ÊÐÕþϵͳȫ²¿¹Ø±Õ¡£Ëþ¶ûÈø£¨Tulsa£©ÊÇÃÀ¹ú¶í¿ËÀ­ºÉÂíÖݵĵڶþ¶àÊý»á£¬ÈË¿ÚÔ¼40ÍòÈË¡£¸ÃÊÐÊг¤³ÆÆäÔÚ·þÎñÆ÷ÉÏ·¢ÏÖÁ˶ñÒâÈí¼þ£¬²¢Á¢¿Ì¹Ø±ÕÁËËùÓÐϵͳ¡£Æä911·þÎñ»ò½ô¼±ÏìÓ¦²¢Î´Êܵ½Ó°Ï죬µ«ÊÇÔÚÏßÕ˵¥Ö§¸¶ÏµÍ³¡¢¹«¹²ÊÂÎñ·þÎñ¡¢Ëþ¶ûÈøÊÐÒé»á¡¢¾¯²ì¾ÖºÍËþ¶ûÈøµÈ311¸öÍøÕ¾ÈÔÔÚά»¤ÖС£¸ÃÊгƴ˴ι¥»÷²¢Î´Ð¹Â¶¹«ÃñµÄÐÅÏ¢£¬µ«²¿ÃÅÎļþÒѾ­±»ÇÔ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/city-of-tulsas-online-services-disrupted-in-ransomware-incident/


4.°Ä´óÀûÑǹúÁ¢´óѧÔâµ½¹¥»÷£¬Ô±¹¤ºÍѧÉúµÄÐÅϢй¶


4.jpg


°Ä´óÀûÑǹúÁ¢´óѧ(ANU)½üÆÚ·¢ÏÖÆäÔøÔâµ½¹¥»÷£¬Ô±¹¤ºÍѧÉúµÄÐÅϢй¶¡£ANUÓÚÁ½ÖÜǰ·¢ÏÖÆäÔÚ2018Äêµ×Ôâµ½ÁËÍøÂç¹¥»÷£¬±»µÁÊý¾Ý¿É×·Ëݵ½19ÄêÒÔǰ£¬Éæ¼°Ô±¹¤¡¢Ñ§ÉúºÍ·Ã¿Í£¬Ä¿Ç°Éв»Çå³þºÚ¿ÍÔÚANUµÄϵͳÖÐÒþ²ØÁ˶೤ʱ¼ä¡£´Ë´Îй¶µÄÐÅÏ¢°üÂÞÐÕÃû¡¢µØÖ·¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢ÓʼþµØÖ·¡¢½ô¼±ÁªÏµ·½Ê½¡¢Ë°ÎñÎļþ±àºÅ¡¢ÈËΪµ¥ÐÅÏ¢¡¢ÒøÐÐÕÊ»§ÏêϸÐÅÏ¢¡¢»¤ÕÕÏêϸÐÅÏ¢ºÍѧÊõ¼Ç¼µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/au-19-years-of-personal-data-was-stolen-from-anu-it-could-show-up-on-the-dark-web/


5.Ñо¿ÈËÔ±ÑÝʾ¿ÉÈÆ¹ýSpectre·À»¤´ëÊ©µÄй¥»÷·½Ê½


5.jpg


Ñо¿ÈËÔ±ÑÝʾÁËÒ»ÖÖÐµĹ¥»÷·½Ê½£¬¿ÉÈÆ¹ýоƬÖÐÄÚÖõÄËùÓÐSpectre·À»¤´ëÊ©¡£SpectreÓÚ2018Äê1Ô¹ûÈ»£¬ËüµÄºËÐÄÊǶ¨Ê±²àÐŵÀ¹¥»÷£¬ÀûÓÃÁËCPUÓ²¼þʵÏÖÖеÄÍÆ²âÖ´ÐÐÓÅ»¯ÒªÁ죬ÓÕʹ·¨Ê½·ÃÎÊÄÚ´æÖеÄÈÎÒâλÖôӶøÐ¹Â©ÐÅÏ¢¡£ÕâÖÖÐµĹ¥»÷·½Ê½Ê¹ÓÃÁË΢²Ù×÷£¨micro-ops£©»º´æ£¬ÕâÊÇ¿ÉÒÔ½«»úÆ÷Ö¸ÁîÆÊÎöΪ¸ü¼òµ¥µÄÃüÁîµÄ×é¼þ£¬¿É×÷Ϊй¶»úÃÜÐÅÏ¢µÄ¸¨ÖúÇþµÀ£¬×Ô2011ÄêÒÔÀ´±ãÒѱ»ÄÚÖõ½»ùÓÚIntelµÄ¼ÆËã»úÖС£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/05/new-spectre-flaws-in-intel-and-amd-cpus.html


6.Alien Labs·¢ÏÖQBotÀûÓÃÏÖÓкϷ¨ÓʼþµÄ¹¥»÷»î¶¯


6.jpg


Alien LabsµÄÑо¿ÈËÔ±·¢ÏÖÁËÐÂÒ»ÂÖµÄQBot¹¥»÷»î¶¯¡£QBot×Ô2007Ä꿪ʼ»îÔ¾£¬×î³õÖ»ÊÇ´¦ÓÚ²ÆÕþÄ¿µÄµÄÒøÐÐľÂí¡£Ôڴ˴ι¥»÷ÖУ¬¹¥»÷ÕßÀûÓÃÁËÄ¿±êÖ®¼äºÏ·¨µÄÉÌҵͨÐÅ£¬²¢¶ÔÆä½øÐÐÁËÐ޸ģ¬Ê¹µÃÓÕ¶üÓʼþ¿´ÉÏÈ¥¸üÓÐ˵·þÁ¦¡£´ËÍ⣬ΪÁËÔö¼Ó¼ì²âºÍ·ÖÎöµÄÄѶÈ£¬QBot»á¶ÔÆä×Ö·û´®½øÐмÓÃܲ¢ÔÚÔËÐÐʱ¶ÔÆä½øÐнâÃÜ£¬Ò»µ©QBotµÄÖ´ÐÐÂß¼­Ê¹ÓÃÍê×Ö·û´®£¬Ëü½«Á¢¼´´ÓÄÚ´æÖÐɾ³ý¸Ã×Ö·û´®¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/05/qakbot-malware-is-targeting-users-via.html