腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Attack ] Finnish defense ministry website targeted by cyber attack | Reuters http://ow.ly/ZTrWS
"芬兰国防部网站遭到黑客攻击, 来自路透社报道: https://t.co/NFE6KsPjsk"
-
[ Browser ] Turns out Google Chrome has just fixed the bugs at #Pwn2Own, where are the others? @ MicrosoftEdge @ AdobeSecurity http://googlechromereleases.blogspot.com/2016/03/stable-channel-update_24.html
"Google Chrome 浏览器已经修复了在 Pwn2Own 比赛中使用的漏洞(49.0.2623.108): https://t.co/7jX9YUy7oH"
-
[ Defend ] Protecting targeted individuals and populations at scale is critically important: https://security.googleblog.com/2016/03/more-encryption-more-notifications-more.html
"Google 为 Gmail 增加了一个新的安全特性:提示用户接收/发送的邮件是否是加密传输 ︰ https://t.co/O6HprJs1xj"
-
[ Defend ] Microsoft is hoping to curb malware with a new macro blocking feature in Office - http://ow.ly/ZTXSW
"为了阻断宏恶意代码攻击,微软在 Office 上启用了新的保护特性, 来自 ThreatPost 的报道: https://t.co/xqek5JAsiz 微软的 Blog: https://blogs.technet.microsoft.com/mmpc/2016/03/22/new-feature-in-office-2016-can-block-macros-and-help-prevent-infection/ "
-
[ Defend ] Abusing bugs in the Locky ransomware to create a vaccine. https://www.lexsi.com/securityhub/abusing-bugs-in-the-locky-ransomware-to-create-a-vaccine/?lang=en
"滥用 Locky 勒索软件的 Bug,造个'疫苗': https://t.co/KSiXPCiMtx"
-
[ Forensics ] SDN Forensics Challenge, 2016 - https://www.cmand.org/sdn/sdnf.html
"SDN 取证分析比赛 2016: https://t.co/P3Bb4IN8Fq"
-
[ Linux ] An automated script that download potential exploit for linux kernel from exploitdb, and compile them automatically https://github.com/ngalongc/AutoLocalPrivilegeEscalation
"Linux 内核本地提权自动化脚本,自动探测环境,从 exploitdb 下载 Exploit,编译运行, Github Repo: https://t.co/BqKFd0No23"
-
[ Mac OS X ] Check out our new blog on how to use OS X FSEvents to discover deleted malicious artifacts http://ow.ly/ZUfbN #cybersecurity #infosec
"如何通过 OS X FSEvents 找出恶意软件对目录的修改记录,包括创建的文件、修改的时间、删除的文件等,来自 CrowdStrike Blog: https://t.co/MuT6Ba0XdO "
-
[ Mac OS X ] Slides for "Don't Trust Your Eye: Apple Graphics Is Compromised!" CanSecWest16 by @ chenliang0817 , me, @ flanker_hqd https://speakerdeck.com/marcograss/dont-trust-your-eye-apple-graphics-is-compromised
"别相信你的眼睛︰ Apple 图形处理被攻破了, 来自 KeenLab 的 Chenliang、 Flanker、 MarcoGrass 在 CanSecWest 2016 会议的演讲, 主要介绍了他们在 OS X 图形处理漏洞挖掘方面的方法和思路, 并且也以实际例子谈漏洞利用的细节, 在线浏览: https://t.co/3I4m3QpuY7 PDF 下载: http://tool.flanker017.me/papers/CanSecWest.pdf "
-
[ Malware ] NCC Group @ foxit Blog: Website of security certification provider spreading ransomware - http://blog.fox-it.com/2016/03/24/website-of-security-certification-provider-spreading-ransomware/
"安全认证提供商 EC-COUNCIL 的网站传播勒索软件: https://t.co/yhwZhMl594"
-
[ Malware ] #Unit42 investigates the evolution of #SamSa Malware & discovers new #ransomware tactics in play http://bit.ly/25nAQNB
"SamSa 恶意软件的进化过程表明:攻击者不再倾向于 '广撒网,烧香祈祷',定向勒索攻击的时代已经到来, 来自 Palo Alto Blog: https://t.co/JWrkY2eejN"
-
[ Malware ] New TeslaCrypt Ransomware Spikes on Leap Day, Attempting to Catch Users Off-Guard http://blog.checkpoint.com/2016/03/23/new-teslacrypt-ransomware-spikes-on-leap-day-attempting-to-catch-users-off-guard/
"TeslaCrypt 勒索软件在闰日( 2 月 29 日)出现峰值, 试图给用户来个猝不及防, 来自 CheckPoint Blog: https://t.co/jYzCfClTgy"
-
[ Others ] Internet of Medical Devices - security incidents related to hospitals and medical equipment. https://securelist.com/blog/research/74249/hospitals-are-under-attack-in-2016/
"2016 年,仅这两三个月, 就已经出现了很多的医院、医疗设备被攻击事件, 来自 Kaspersky Blog: https://t.co/YEth7XbWI3"
-
[ Others ] The native Docker apps for Mac & Windows use unikernel tech under the hood. Very excited we can now share this :) https://blog.docker.com/2016/03/docker-for-mac-windows-beta/
"Docker for Mac & Windows Beta 版本发布,底层使用 unikernel 技术, 来自 Docker Blog: https://t.co/NGCkxeUwp3"
-
[ Pentest ] Conducting red team assessments without the use of #malware http://bddy.me/1RnaWQn #DFIR #FEYERedTeam https://t.co/0NA4nsWVv2
"不依赖恶意软件和 Exploit 的渗透测试评估过程, 来自 FireEye Blog: https://t.co/CfgX2JdpPw https://t.co/0NA4nsWVv2"
-
[ Popular Software ] Oracle out-of-band release for Java 0-day https://blog.qualys.com/laws-of-vulnerabilities/2016/03/24/oracle-out-of-band-release-for-java-0-day
"Oracle 发了一个带外补丁,用于修复两周前在 FullDisclosure 上泄漏的 Java 0Day(CVE_2013-5838 的变种): https://t.co/MYMCjY56Ir 两周前 FullDisclosure 的公告: http://seclists.org/fulldisclosure/2016/Mar/31 "
-
[ ThirdParty ] The Six Types of Open-Source Library Vulnerabilities - https://blog.srcclr.com/the-six-types-of-open-source-library-vulnerabilities/
"开源库漏洞的 6 种类型, 不是指漏洞本身的类型(信息泄露、类型混淆, UAF等), 而是指漏洞引入的类型, 包括 0Day, 继承来的、 相似漏洞等: https://t.co/D7PHCwp6zh"
-
[ Tools ] New Pin release !!!!!!! https://software.intel.com/en-us/articles/pintool-downloads
"Intel 发布二进制插桩框架 PIN 新版本: https://t.co/AOFypZJ26u"
-
[ Tools ] I've added the slides from my OWASP Cologne Burp Session Handling Workshop to the NastyWebHackme repo https://github.com/thomaspatzke/NastyWebHackme
"Burp 的 Session 处理, Github Repo: https://t.co/Q3NeaW8Lke"
-
[ Tools ] Based on LLVM, but Keystone is way smaller: LLVM compile in 15 min, but Keystone takes only 30 sec. More comparison: http://keystone-engine.org/docs/beyond_llvm.html
"虽然是基于 LLVM, 但 Keystone 汇编引擎更加小巧。 LLVM 编译 15 分钟的代码, 用 Keystone 仅需 30 秒。 LLVM 和 Keystone 更多的比较 ︰ https://t.co/ox9JyVPm6i"
-
[ Web Security ] Exfiltration at Lightspeed - Faster Blind SQL Injection https://drive.google.com/file/d/0B0tBYiOD2uG7MkpxaFRWTkhOTTA/view
"以光速偷数据 - 更快的 SQL 盲注, PDF: https://t.co/icjKtwDvk6 "
-
[ Windows ] BitLocker : What’s New in Windows 10 November Update, And How To Break It : https://articles.forensicfocus.com/2016/03/23/bitlocker-whats-new-in-windows-10-november-update-and-how-to-break-it/
"BitLocker 在 Windows 10 去年 11 月份的更新中有什么新变化, 如何攻破? ︰ https://t.co/qPGuCTgCLd"
-
[ Windows ] Slides for our talk at #CSW16 (#BadWinmail and Email Security on Outlook) available at https://sites.google.com/site/zerodayresearch/BadWinmail_and_Email_Security_Outlook_final.pdf. Pay attention to slides 40+.
"Haifei Li 在 CanSecWest 2016 会议的演讲: BadWinmail 与 Outlook 邮件安全, Slides: https://t.co/Co4LpCXzak "
-
[ WirelessSecurity ] SDR Radio Academy: Reverse engineering a wireless car key fob. http://phasenoise.livejournal.com/3822.html
"SDR 无线电学院 - 逆向无线车钥匙, Youtube 视频: https://t.co/wZUM769Rqr"