¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180906

Ðû²¼Ê±¼ä 2018-09-06

¡¾ÆÊÎö±¨¸æ¡¿SANSÑо¿ËùÐû²¼2018ÄêIIOTÇå¾²ÐԵĵ÷Ñб¨¸æ


SANSÑо¿ËùÐû²¼¹ØÓÚ¹¤ÒµÎïÁªÍø£¨IIoT£©Çå¾²ÐԵĵ÷Ñб¨¸æ£¬£¬ £¬¸ÃÑо¿Ëù¶ÔÀ´×ÔÄÜÔ´¡¢¹«ÓÃÊÂÒµ¡¢Ê¯ÓͺÍ×ÔÈ»ÆøÒÔ¼°ÖÆÔìÒµµÄ200¶àÃûÇå¾²Ö°Ô±¾ÙÐÐÁËÊӲ죬£¬ £¬Ö»Óв»µ½5%µÄOTÖ°Ô±ÌåÏÖ¶ÔËûÃǹ«Ë¾µÄлù´¡ÉèÊ©µÄÇå¾²·À»¤³äÂúÐÅÐÄ¡£¡£¡£¡£¡£¡£32%µÄÊÜ·ÃÆóÒµÖеÄIIoT×°±¸Ö±½ÓÅþÁ¬µ½»¥ÁªÍø£¬£¬ £¬ÈƹýÁ˹ŰåµÄICSÇå¾²²ã¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬Ö»ÓÐ40%µÄÊÜ·ÃÕßÌåÏÖËûÃÇʵʱΪװ±¸×°Öò¹¶¡ºÍ¸üС£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://cdn2.hubspot.net/hubfs/2755567/White%20Papers%20and%20Briefs/Sans%20IIOT%20Survey.pdf


¡¾¹¥»÷ÊÂÎñ¡¿Chrome²å¼þMEGAÔâºÚ¿ÍÐ®ÖÆ£¬£¬ £¬ÓÃÓÚÇÔÈ¡Óû§µÄÃÜÂë


ÔÆ´æ´¢Ð§ÀÍMEGA.nzµÄ¹Ù·½Chrome²å¼þÔâµ½ºÚ¿ÍÐ®ÖÆ£¬£¬ £¬ÓÃÓÚÇÔÈ¡Óû§µÄÃÜÂë¡£¡£¡£¡£¡£¡£Æ¾Ö¤¸Ã¹«Ë¾µÄ²©¿Í£¬£¬ £¬¹¥»÷ÕßÔÚ9ÔÂ4ÈÕ14:30 UTCÈëÇÖMEGAµÄChrome web storeÕÊ»§£¬£¬ £¬²¢ÉÏ´«ÁËÒ»¸ö¶ñÒâ°æ±¾3.39.4¡£¡£¡£¡£¡£¡£¸Ã°æ±¾ÓÃÓÚÇÔÈ¡Óû§µÄÑÇÂíÑ·¡¢Î¢Èí¡¢GithubºÍ¹È¸èµÈÊ¢ÐÐÍøÕ¾µÄƾ֤£¬£¬ £¬ÒÔ¼°MyEtherWalletºÍMyMoneroµÈÔÚÏß¼ÓÃÜÇ®±ÒÇ®°üºÍ¼ÓÃÜÇ®±ÒÉúÒâÆ½Ì¨Idex.marketµÄƾ֤¡£¡£¡£¡£¡£¡£±»µÁµÄÐÅÏ¢½«±»·¢ËÍÖÁλÓÚÎÚ¿ËÀ¼µÄmegaopac[.]hostЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÊÂÎñ±¬·¢ËÄСʱ֮ºó¸üÐÂÁËÒ»¸öÇå½àµÄ°æ±¾3.39.5¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/09/mega-file-upload-chrome-extension.html


¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷ʹÓÃ.tkÓòÃûµÄ´ó¹æÄ£¹ã¸æÕ©Æ­»î¶¯


ZscalerµÄÑо¿Ö°Ô±·¢Ã÷ʹÓÃ.tkÓòÃûµÄ´ó¹æÄ£¹ã¸æÕ©Æ­»î¶¯¡£¡£¡£¡£¡£¡£×Ô2018Äê5ÔÂÒÔÀ´£¬£¬ £¬¸Ã¶ñÒâ»î¶¯Ò»Ö±´¦ÓÚ»îԾ״̬¡£¡£¡£¡£¡£¡£¹¥»÷Õß½«Óû§Öض¨ÏòÖÁÐéαµÄ²©¿ÍÍøÕ¾£¬£¬ £¬ÕâÐ©ÍøÕ¾ÉÏµÄ¹ã¸æÊÕÈëÿÔ´ï2ÍòÃÀÔªÒÔÉÏ¡£¡£¡£¡£¡£¡£²¿·Ö.tkÓòÃû»¹±»ÓÃÓÚÊÖÒÕÖ§³ÖÕ©Æ­¡£¡£¡£¡£¡£¡£.tkÓòÃûÊÇÒ»¸ö¹ú¼Ò/µØÇø¼¶µÄ¶¥¼¶ÓòÃû£¬£¬ £¬Ëü´ú±íÁËÁ¥ÊôÓÚÐÂÎ÷À¼µÄµº¹úTokelau¡£¡£¡£¡£¡£¡£¸ÃÓòÃûÊÇÃâ·ÑµÄ£¬£¬ £¬ÕâÒýÆðÁ˹¥»÷ÕßµÄÐËȤ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±×ܹ²·¢Ã÷ÁËÓë¸Ã¶ñÒâ»î¶¯ÓйصÄ3804¸ö.tkÓòÃû¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zscaler.com/blogs/research/spam-campaigns-leveraging-tk-domains


¡¾ÍþвÇ鱨¡¿Group-IB·¢Ã÷Ö÷ÒªÕë¶Ô¶íÂÞ˹ºÍ¶«Å·ÒøÐеÄз¸·¨ÍÅ»ïSilence


Group-IBÐû²¼¹ØÓÚз¸·¨ÍÅ»ïSilenceµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬ £¬SilenceÖÁÉÙÓë¶íÂÞ˹ºÍ¶«Å·µÄÒøÐкͽðÈÚ»ú¹¹µÄ80ÍòÃÀԪ͵ÇÔ°¸Óйء£¡£¡£¡£¡£¡£¾ÝGroup-IB³Æ£¬£¬ £¬¸Ã×éÖ¯ÔÚÒÑÍùÈýÄêÖÐÒ»Ö±Õë¶Ô¶íÂÞ˹ºÍ¶«Å·µÄ½ðÈÚ»ú¹¹Ìᳫ¹¥»÷¡£¡£¡£¡£¡£¡£Silence¿ª·¢ÁËһЩ×Ô¼ºµÄ¹¤¾ß£¬£¬ £¬°üÀ¨»ù´¡ÉèÊ©¹¥»÷¿ò¼ÜSilence¡¢ATM¹¥»÷¹¤¾ßÏäAtmosphere¡¢ÃÜÂë»ñÈ¡¹¤¾ßFarseÒÔ¼°ÈÕÖ¾ÒÆ³ý¹¤¾ßCleaner¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/new-silence-hacking-group-suspected-of-having-ties-to-cyber-security-industry/


¡¾ÍþвÇ鱨¡¿·¸·¨ÍÅ»ïFIN6¾íÍÁÖØÀ´£¬£¬ £¬Ö÷ÒªÕë¶ÔÃÀ¹úºÍÅ·ÖÞµÄPoSϵͳ


IBM X-Force IRISÑо¿ÍŶӷ¢Ã÷·¸·¨ÍÅ»ïFIN6µÄй¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯Ö÷ÒªÕë¶ÔÃÀ¹úºÍÅ·ÖÞµÄÁãÊÛÉ̵ÄPoSϵͳ¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎú¼¸¶àÆóÒµÔâµ½Á˹¥»÷¡£¡£¡£¡£¡£¡£FIN6ͨʺóÃÅÈí¼þGrabnewÀ´ÍøÂçÓû§µÄƾ֤ÐÅÏ¢£¬£¬ £¬È»ºóʹÓöñÒâÈí¼þTrinity£¨ÓÖ½ÐFrameworkPOS£©²éÕÒºÍÉøÍ¸PoS×°±¸¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ90%µÄй¥»÷»î¶¯¶¼Ê¹ÓÃÁËÓë֮ǰFIN6¹¥»÷ÏàͬµÄÕ½ÂԺ͹¤¾ß¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/fin6-returns-to-attack-retailers-in-us-europe/


¡¾Îó²î²¹¶¡¡¿Ë¼¿ÆÐû²¼¶à¿î²úÆ·µÄÇå¾²¸üУ¬£¬ £¬ÐÞ¸´16¸öÇå¾²Îó²î


±¾ÖÜÈý˼¿ÆÐû²¼ÁËRVϵÁС¢SD-WANºÍUmbrellaµÈ²úÆ·µÄÇå¾²¸üУ¬£¬ £¬¹²ÐÞ¸´ÁË16¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£ÆäÖаüÀ¨RVϵÁзÀ»ðǽºÍ·ÓÉÆ÷µÄwebÖÎÀí½çÃæÖеĻº³åÇøÒç³öÎó²î£¨CVE-2018-0423£©£¬£¬ £¬¸ÃÎó²î¿ÉÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐÐí§Òâ´úÂë»ò´¥·¢¾Ü¾øÐ§ÀÍ£» £» £»£»Umbrella APIÖеĸßΣÎó²î£¨CVE-2018-0435£©£¬£¬ £¬¸ÃÎó²î¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßÉó²éºÍÐÞ¸ÄÆäËü×éÖ¯µÄÊý¾Ý¡£¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì×°ÖÃÕâЩ¸üС£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cisco-releases-16-security-alerts-rated-critical-and-high/