¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180830

Ðû²¼Ê±¼ä 2018-08-30
¡¾ÆÊÎö±¨¸æ¡¿Ñо¿»ú¹¹Ðû²¼2018ÄêÖÐÇå¾²×ÛÊö£¬£¬£¬£¬£¬¶ñÒâÍÚ¿ó¹¥»÷ͬ±ÈÔöÌí956£¥
Ç÷ÊÆ¿Æ¼¼Ðû²¼2018ÄêÖÐÇå¾²×ÛÊö±¨¸æ£¬£¬£¬£¬£¬±¨¸æÖ¸³öÓë2017ÄêÕûÄêÏà±È£¬£¬£¬£¬£¬2018ÄêÉϰëÄê¶ñÒâÍÚ¿ó¹¥»÷µÄ¼ì²âÊýÄ¿ÔöÌíÁË96%£»£»£»£»¶øÓë2017ÄêÉϰëÄêÏà±È£¬£¬£¬£¬£¬ÔòÔöÌíÁË956%£¨½ü10±¶£© ¡£¡£¡£¡£¡£±¨¸æ»¹Ö¸³ö£¬£¬£¬£¬£¬Ç÷ÊÆ¿Æ¼¼ÔÚ2018ÄêÉϰëÄê×èÖ¹ÁË200¶àÒÚ´ÎÍþв£¬£¬£¬£¬£¬¹¥»÷Õߵ폷¨Õ½ÂÔÒѾ­±¬·¢ÁËת±ä£¬£¬£¬£¬£¬´Ó°²ÅÅ¿ìËÙÖ§¸¶µÄÀÕË÷Èí¼þתÏòÇÔÈ¡Óû§µÄ×ʽðºÍÅÌËã»úËãÁ¦µÈÒþÄäµÄÊÖ¶Î ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.trendmicro.com/vinfo/us/security/research-and-analysis/threat-reports/roundup/unseen-threats-imminent-losses


¡¾¹¥»÷ÊÂÎñ¡¿Î÷°àÑÀÒøÐйÙÍøÔâµ½DDoS¹¥»÷£¬£¬£¬£¬£¬ÍøÕ¾ÔÝʱÎÞ·¨»á¼û


ƾ֤·͸ÉçµÄ±¨µÀ£¬£¬£¬£¬£¬´Ó8ÔÂ26ÈÕÐÇÆÚÈÕ×îÏÈÎ÷°àÑÀÒøÐеĹÙÍøÔâµ½ÁËÂþÑÜʽ¾Ü¾øÐ§À͹¥»÷£¨DDoS£©£¬£¬£¬£¬£¬ÆäÍøÕ¾ÔÝʱÎÞ·¨»á¼û ¡£¡£¡£¡£¡£¸ÃÒøÐеĽ²»°ÈËÌåÏÖ£¬£¬£¬£¬£¬´Ë´Î¹¥»÷¶Ô¸ÃÒøÐеÄЧÀÍ»ò¸ÃÒøÐÐÓëÅ·ÖÞÖÐÑëÒøÐлòÆäËü»ú¹¹µÄͨѶûÓÐÔì³ÉÈκÎÓ°Ï죬£¬£¬£¬£¬²¢ÇÒûÓÐÈκÎÊý¾Ýй¶µÄΣº¦ ¡£¡£¡£¡£¡£×èÖ¹ÖܶþÏÂÖ磬£¬£¬£¬£¬¸ÃÒøÐеÄÍøÕ¾ÈÔ´¦ÓÚÀëÏß״̬ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://uk.reuters.com/article/us-spain-cyber-cenbank/bank-of-spains-website-hit-by-cyber-attack-idUKKCN1LC23B


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷ÓÃÓÚ·Ö·¢DarkComet RATµÄÀ¬»øÓʼþ»î¶¯


Çå¾²Ñо¿Ô±Vishal Thakur·¢Ã÷Ò»¸öÓÃÓÚ·Ö·¢DarkComet RATµÄÀ¬»øÓʼþ»î¶¯ ¡£¡£¡£¡£¡£¸ÃÀ¬»øÓʼþÖаüÀ¨Ãû³ÆÎªDOC000YUT600.pdf.zµÄ¸½¼þ£¬£¬£¬£¬£¬Æä»á½«DarkComet RAT×°Öõ½Óû§µÄÅÌËã»úÉÏ ¡£¡£¡£¡£¡£DarkComet¿ÉÒÔ¼ÍÈÎÃü»§µÄÓ¦ÓóÌÐòʹÓÃÇéÐκͼüÅÌÇû÷¼Í¼£¬£¬£¬£¬£¬²¢½«ÕâЩÊý¾ÝÉúÑÄÔÚ£¥UserProfile£¥\AppData\Roaming\dclogs\Îļþ¼ÐϵÄÈÕÖ¾ÎļþÖÐ ¡£¡£¡£¡£¡£ÕâЩÎļþ»áÒÔ²î±ðµÄ¾àÀëÉÏ´«ÖÁ¹¥»÷Õß ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/beware-of-fake-shipping-docs-malspam-pushing-the-darkcomet-rat/


¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶÓÐû²¼¹ØÓÚAndroidÌØ¹¤Èí¼þBusyGasperµÄÆÊÎö±¨¸æ


¿¨°Í˹»ùʵÑéÊÒÔÚ2018ÄêÍ·¼ì²âµ½Ò»¸öеÄAndroidÌØ¹¤Èí¼þBusyGasper ¡£¡£¡£¡£¡£BusyGasperµÄÖØ´óÐÔ²»¸ß£¬£¬£¬£¬£¬µ«¾ßÓÐÒ»Ð©ÌØÊâµÄ¹¦Ð§£¬£¬£¬£¬£¬ÀýÈç¼àÌý×°±¸µÄ´«¸ÐÆ÷£¨Ô˶¯´«¸ÐÆ÷µÈ£© ¡£¡£¡£¡£¡£ÆäЭÒé¾ßÓÐÔ¼100¸öÏÂÁ£¬£¬£¬£¬»¹¿ÉÒÔÈÆ¹ý½ÚµçÓÅ»¯¹¦Ð§Doze ¡£¡£¡£¡£¡£BusyGasper¿ÉÒÔÇÔÈ¡ÐÂÎÅÓ¦Óã¨ÈçWhatsApp¡¢ViberºÍFacebook£©µÄÊý¾Ý£¬£¬£¬£¬£¬²¢¾ßÓмüÅ̼ͼ¹¦Ð§ ¡£¡£¡£¡£¡£BusyGasperͨ¹ýÊÖ¶¯×°Ö㬣¬£¬£¬£¬Ö÷ÒªÕë¶Ô¶íÂÞ˹£¬£¬£¬£¬£¬ÆäC&CЧÀÍÆ÷µÄIPÊôÓÚ¶íÂÞ˹µÄÒ»¸öÃâ·ÑµÄÍøÂçÍйÜЧÀÍUcoz ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://securelist.com/busygasper-the-unfriendly-spy/87627/


¡¾Îó²î²¹¶¡¡¿PHPÈí¼þ°ü¿âPackagistµÄ¹ÙÍøÐÞ¸´Ò»¸ö¿É±»Ð®ÖƵÄÇå¾²Îó²î


PackagistÍŶÓÔÚÆä¹Ù·½ÍøÕ¾ÉÏÐÞ¸´ÁËÒ»¸ö¿Éµ¼ÖÂÆäЧÀͱ»Ð®ÖƵÄÇå¾²Îó²î ¡£¡£¡£¡£¡£PackagistÊÇPHP×î´óµÄÈí¼þ°ü´æ´¢¿â£¬£¬£¬£¬£¬ÆäÿÔµÄ×°ÖðüÏÂÔØ´ÎÊýÁè¼Ý4ÒÚ´Î ¡£¡£¡£¡£¡£Çå¾²Ñо¿Ô±Max Justicz·¢Ã÷²¢±¨¸æÁËÕâ¸öÎó²î£¬£¬£¬£¬£¬Æ¾Ö¤JusticzµÄ˵·¨£¬£¬£¬£¬£¬PackagistÖ÷Ò³ÉÏÌá½»ÐÂPHP°üµÄ°´Å¥µÄÊäÈë×Ö¶ÎÔÊÐí¹¥»÷ÕßÒÔ$(MALICIOUS_COMMANDS)µÄÃûÌÃÔËÐжñÒâÏÂÁî ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/critical-flaw-fixed-in-packagist-phps-largest-package-repository/


¡¾Îó²î²¹¶¡¡¿Çå¾²Ñо¿Ö°Ô±·¢Ã÷OpenSSH±£´æÁíÒ»¸öÓû§Ãûö¾ÙÎó²î


QualysµÄÇå¾²Ñо¿Ö°Ô±ÔÚ×îа汾µÄOpenSSHÖз¢Ã÷ÁËÒ»¸öеÄÓû§Ãûö¾ÙÎó²î£¨CVE-2018-15919£© ¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁË2011Äê9ÔÂÖ®ºóµÄËùÓÐOpenSSH°æ±¾ ¡£¡£¡£¡£¡£¸ÃÎó²îÓëÑо¿Ö°Ô±ÉÏÖÜ·¢Ã÷µÄÎó²î£¨CVE-2018-15473£©ÀàËÆ£¬£¬£¬£¬£¬¶¼ÔÊÐí¹¥»÷ÕßÍÆ²âЧÀÍÆ÷ÉϵÄÓÐÓÃÓû§Ãû ¡£¡£¡£¡£¡£OpenSSHµÄ¿ª·¢Ö°Ô±³Æ¸ÃÎó²îµÄÑÏÖØÐԽϵÍ£¬£¬£¬£¬£¬Òò´Ë²¢²»»áÓÅÏÈÐÞ¸´¸ÃÎó²î ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/openssh-versions-since-2011-vulnerable-to-oracle-attack/