ÆôÓÃHyper-VµÄWin10ϵͳÖб£´æ0day£¬£¬£¬£¬£¬£¬£¬£¬¿É½¨ÉèÎļþ£»£»£»£»£»£»ÍøÂçÑо¿Ð¡×éÐû²¼½üÊ®ÄêÍøÂçÇå¾²ÊÂÎñµÄÑо¿±¨¸æ
Ðû²¼Ê±¼ä 2020-09-081.ÆôÓÃHyper-VµÄWin10ϵͳÖб£´æ0day£¬£¬£¬£¬£¬£¬£¬£¬¿É½¨ÉèÎļþ

ÄæÏò¹¤³ÌʦJonas LykkegaardÔÚÆôÓÃÁËHyper-VµÄWindows 10ϵͳÖз¢Ã÷ÁËÒ»¸öеÄ0day£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿É±»Ê¹ÓÃÔÚÊÜÓ°ÏìµÄ²Ù×÷ϵͳÖн¨ÉèÎļþ¡£¡£¡£¡£¡£¡£¡£ÔÚHyper-V´¦Óڻ״̬ʱ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚ\ system32Öн¨ÉèÎļþ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ²»ÐèÒª¾ÙÐÐÌáȨ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÎļþµÄ½¨ÉèÕßÒ²ÊÇËùÓÐÕߣ¬£¬£¬£¬£¬£¬£¬£¬Òò´Ë¹¥»÷Õß¿ÉÒÔʹÓøÃÎļþ½«¶ñÒâ´úÂë×¢ÈëϵͳÄÚ²¿£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚÐèҪʱʹÓÃÌáÉýµÄȨÏÞÖ´ÐиöñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£CERT/CCÎó²îÆÊÎöʦWill Dormann ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÏÕЩ²»ÐèÒª×öÈÎºÎÆð¾¢±ã¿ÉÒÔʹÓøÃÎó²î¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/windows-10-sandbox-activation-enables-zero-day-vulnerability/
2.ÍøÂçÑо¿Ð¡×éÐû²¼½üÊ®ÄêÍøÂçÇå¾²ÊÂÎñµÄÑо¿±¨¸æ

ÓÉÍøÂçÇå¾²ºÍ»¥ÁªÍøÑо¿ÁìÓòµÄר¼Ò×é³ÉµÄѧÊõÍŶӯÊÎöÁËÒÑÍùÊ®Ä꣨2009ÄêÖÁ2019Ä꣩Ðû²¼µÄ700ÆªÍøÂçÇå¾²±¨¸æ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨629·ÝÉÌÒµÍþвÇ鱨¹©Ó¦É̱¨¸æºÍ71×ÔÁ¦Ñо¿ÖÐÐı¨¸æ¡£¡£¡£¡£¡£¡£¡£×¨¼Ò·¢Ã÷£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÉÌÒµ±¨¸æÖÐÖ»ÓÐ82·Ý£¨13£¥£©ÌÖÂÛÁËÕë¶ÔÃñÉúºÍÉç»áµÄÍþв£¬£¬£¬£¬£¬£¬£¬£¬ÆäÓà607·Ý±¨¸æµÄÖØµãÊÇÍøÂç·¸·¨ÍÅ»ïºÍAPT×éÖ¯¡£¡£¡£¡£¡£¡£¡£Ïà·´£¬£¬£¬£¬£¬£¬£¬£¬×ÔÁ¦Ñо¿ÖÐÐĵĴó´ó¶¼±¨¸æ¶¼¼¯ÖÐÔÚ¶ÔÃñ¼äÉç»áµÄÍþвÉÏ¡£¡£¡£¡£¡£¡£¡£×¨¼ÒÒÔΪ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÓÉÓÚÇå¾²±¨¸æÊÜÀûÈóÇý¶¯£¬£¬£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²¹«Ë¾Ðû²¼µÄ±¨¸æÓëÍþвÇ鱨һÑù£¬£¬£¬£¬£¬£¬£¬£¬¾ßÓÐ¹ã¸æ×÷Óᣡ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/most-cyber-security-reports-only-focus-on-the-cool-threats/
3.BancoEstadoÒøÐмì²âµ½Æä²Ù×÷ϵͳÖб£´æ¶ñÒâÈí¼þ

BancoEstadoÒøÐÐÓÚ±¾ÖÜÈÕÐû²¼ÁËÒ»·ÝÐÂΟ壬£¬£¬£¬£¬£¬£¬£¬ÈÏ¿ÉÆäÒÑÔÚÆä²Ù×÷ϵͳÖмì²âµ½¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎÊÌâÔÚ±»ÒøÐеÄÍøÂçÇå¾²ÍŶӼì²âµ½ºó½â¾ö¡£¡£¡£¡£¡£¡£¡£¸ÃÒøÐÐÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬Ö»¹ÜËûÃǵÄijЩƽ̨¿ÉÄÜ»áÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬£¬µ«µ½ÏÖÔÚΪֹ£¬£¬£¬£¬£¬£¬£¬£¬ËûÃÇÃæÏò¿Í»§µÄϵͳ£¬£¬£¬£¬£¬£¬£¬£¬Èç×Ô¶¯¹ñÔ±»ú¡¢CajaVecina¡¢ÍøÕ¾ºÍÓ¦ÓóÌÐò²¢Î´Êܵ½Ó°Ïì²¢ÇÒÕýÔÚÔËÐС£¡£¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬£¬£¬£¬Óм¸Î»Óû§ÔÚBanco EstadoµÄÔÚÏ߯½Ì¨Éϱ¨¸æ£¬£¬£¬£¬£¬£¬£¬£¬Ó¦ÓóÌÐòºÍÍøÕ¾µÄÔËÐж¼·ºÆðÁ˼äЪÐÔµÄÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.biobiochile.cl/noticias/economia/actualidad-economica//09/06/banco-estado-detecto-software-malicioso-en-sus-sistemas-no-ha2020bria-afectado-a-clientes.shtml
4.VisaÖÒÑÔÐÂÐÅÓÿ¨ÇÔÈ¡¾ç±¾Baka¿É×ÔÎÒɾ³ýÒÔÈÆ¹ý¼ì²â

VisaÖÒÑÔÐÂÐÅÓÿ¨ÇÔÈ¡¾ç±¾Baka£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÔÚÇÔÈ¡Êý¾Ýºó×ÔÎÒɾ³ýÒÔÈÆ¹ý¼ì²â¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Í¨Ì«¹ýÎö¸Ã¾ç±¾µÄÑù±¾£¬£¬£¬£¬£¬£¬£¬£¬·¢Ã÷Baka³ýÁ˾ßÓÐͨÀýµÄÇÔÈ¡Êý¾ÝµÄ¹¦Ð§Í⣬£¬£¬£¬£¬£¬£¬£¬»¹¾ßÓÐÆæÒìµÄ»ìÏýÒªÁìºÍ¼ÓÔØ³ÌÐò¡£¡£¡£¡£¡£¡£¡£Ëü¶¯Ì¬¼ÓÔØskimmerÒÔÈÆ¹ý¾²Ì¬µÄ¶ñÒâÈí¼þɨÃèÆ÷£¬£¬£¬£¬£¬£¬£¬£¬²¢ÎªÃ¿¸öÊܺ¦ÕßʹÓÃΨһµÄ¼ÓÃܲÎÊýÀ´»ìÏý¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£µ±Ëü¼ì²âµ½Ê¹Óÿª·¢¹¤¾ß¾ÙÐеĶ¯Ì¬ÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬»òÕßÒѾÀÖ³ÉÇÔÈ¡Êý¾Ýʱ£¬£¬£¬£¬£¬£¬£¬£¬±ã»á´ÓÄÚ´æÖÐ×ÔÎÒɾ³ý£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÈÆ¹ý¼ì²âºÍÆÊÎö¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬BakaÒ²ÊÇVisa·¢Ã÷µÄµÚÒ»¸öʹÓÃXORÃÜÂë»ìÏý´úÂëºÍÓ²±àÂëµÄÐÅÓÿ¨ÇÔÈ¡¾ç±¾¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/visa-warns-of-new-baka-credit-card-javascript-skimmer/
5.LloydsÒøÐÐÓû§Ôâµ½´¹ÂÚÓʼþºÍSMS´¹ÂÚ¶ÌÐŹ¥»÷

Griffin LawÂÉËù·¢Ã÷£¬£¬£¬£¬£¬£¬£¬£¬LloydsÒøÐеÄÓû§Ôâµ½ÁËÖØ´óµÄ´¹ÂÚÓʼþºÍSMS´¹ÂÚ¶ÌÐŹ¥»÷¡£¡£¡£¡£¡£¡£¡£ÔÚ´¹ÂÚÓʼþÖУ¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍαÔìÀ´×ÔLloydsµÄÓʼþ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÒÔ¡°ÖÒÑÔ£ºÎĵµ±¨¸æ-ÎÒÃÇ×¢ÖØµ½ÓйØÇ徲ά»¤µÄÐÅÏ¢¡±ÎªÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬Éù³ÆÊÕ¼þÈ˵ÄÒøÐÐÕÊ»§Òѱ»µÁÓ㬣¬£¬£¬£¬£¬£¬£¬ÒªÇóÆäÑéÖ¤ÕÊ»§¡£¡£¡£¡£¡£¡£¡£Ö®ºóÓû§»á±»Öض¨Ïòµ½´¹ÂÚÍøÒ³£¬£¬£¬£¬£¬£¬£¬£¬²¢±»ÒªÇóÊäÈëÃÜÂë¡¢ÕÊ»§ÐÅÏ¢ºÍÇå¾²´úÂëµÈÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÔÚSMS´¹ÂÚ¶ÌÐÅÖУ¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í»á·¢ËÍÒ»ÌõαÔì³ÆÀ´×ÔLloydsµÄ¶ÌÐÅ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÓÕʹÓû§·¿ªÒÔÇÔÈ¡ÆäÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/phishing-scam-lloyds-bank-customers/
6.TelmateÀÎÓüͨѶƽ̨й¶Êý°ÙÍòÃûÇô·¸µÄСÎÒ˽¼ÒÐÅÏ¢

רÃÅÓÃÓÚÇô·¸½»Á÷µÄTelmateƽ̨й¶ÁËÊý°ÙÍòÇô·¸µÄСÎÒ˽¼ÒÏêϸÐÅÏ¢ÒÔ¼°ËûÃÇÓëÍâ½çµÄÁªÏµµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨¶ÌÐÅÄÚÈÝ¡¢Ê±¼ä´Á¼Ç¡¢¼à·¸DoB¡¢ÉèÊ©ID¡¢È«ÃûºÍÐÔ±ð¡¢ÊÕ¼þÈËÈ«Ãû¡¢µç×ÓÓʼþµØµã¡¢½ÖµÀµØµã¡¢IPµØµãºÍ¼ÝʻִÕÕºÅÂë¡¢Çô·¸µÄÈ«Ãû¡¢×ïÐС¢ºÍÕÊ»§Óà¶î¡¢Í¨»°ÏêϸÐÅÏ¢¡¢Çô·¸Ìá³öµÄÉêËßµÈÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£TelmateµÄÉú²úÉÌGlobal Tel LinkÔÚÊÕµ½±¨¸æµÄ¼¸¸öСʱÄÚ¶Ô¸ÃÊÂÎñ×ö³öÁË»ØÓ¦£¬£¬£¬£¬£¬£¬£¬£¬²¢½«Ì»Â¶µÄÊý¾Ý¿âµÄ¾ÙÐÐÁËÐÞ¸´£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÊǸÃÊý¾Ý¿âµÄ̻¶×Üʱ¼äÈÔȻδ֪¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.technadu.com/telmate-prison-communications-exposes-personal-data-millions/194733/


¾©¹«Íø°²±¸11010802024551ºÅ