¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181112

Ðû²¼Ê±¼ä 2018-11-12
1¡¢FIAÌåÏÖ×î½üµÄÊý¾Ýй¶ÊÂÎñÓ°ÏìÁËÏÕЩËùÓеİͻùË¹Ì¹ÒøÐÐ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤°Í»ù˹̹Áª°îÊÓ²ì¾ÖFIAµÄ˵·¨£¬£¬ £¬£¬ÏÕЩËùÓеİͻùË¹Ì¹ÒøÐж¼Êܵ½×î½üµÄÊý¾Ýй¶ÊÂÎñµÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¾Ý³Æ¸ÃÊÂÎñÓëÔÚ°µÍøÊг¡ÉÏ·ºÆðµÄÔ¼2ÍòÕŰͻùË¹Ì¹ÒøÐнè¼Ç¿¨ÐÅÏ¢ÓйØ¡£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹ÕýÔÚÊÓ²ìÓë¸ÃÊÂÎñÓйصÄ100¶àÆðÍøÂç¹¥»÷£¬£¬ £¬£¬ÏÖÔÚÉв»ÇåÎúÊý¾Ýй¶ÊÂÎñ±¬·¢µÄÏêϸʱ¼ä£¬£¬ £¬£¬Ò²²»ÖªµÀ¹¥»÷ÕßÔõÑù½øÈëÕâЩ°Í»ùË¹Ì¹ÒøÐеÄϵͳ¡£¡£¡£¡£¡£¡£¡£×èÖ¹ÉÏÖÜÄ©£¬£¬ £¬£¬Ò»Ð©°Í»ùË¹Ì¹ÒøÐÐÒѾ­ÔÝÍ£ÔÚÍâÑóʹÓÃËüÃǵĽè¼Ç¿¨£¬£¬ £¬£¬²¢½ûÓÃÁËÕâЩ¿¨µÄËùÓйú¼ÊÉúÒâ¡£¡£¡£¡£¡£¡£¡£PakCERTͬÑùÐû²¼ÁËÒ»·Ý¹ØÓÚÊý¾Ýй¶µÄʱ¼ä±íºÍ¹æÄ£µÄ±¨¸æ¡£¡£¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/77847/cyber-crime/pakistani-banks-data-breach.html


2¡¢ÈüÃÅÌú¿ËÐû²¼¹ØÓÚLazarusµÄATM¹¥»÷¹¤¾ßFastcashµÄÆÊÎö±¨¸æ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÈüÃÅÌú¿ËÐû²¼¹ØÓÚLazarusÓÃÓÚ¹¥»÷ATMµÄ¹¤¾ßFastCashµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£ÖÁÉÙ×Ô2016ÄêÒÔÀ´£¬£¬ £¬£¬¸ÃAPT×éÖ¯Ò»Ö±ÔÚʹÓÃÕâÖÖ¶ñÒâÈí¼þ£¬£¬ £¬£¬´ÓÑÇÖ޺ͷÇÖÞµÄÖÐСÐÍÒøÐÐATMÖÐÇÔÈ¡ÁËÁè¼ÝÊý°ÙÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£FastCashľÂí×÷ÓÃÓÚÒøÐÐÄÚ²¿ÍøÂçÖеÄÓÃÓÚ´¦Öóͷ£ATMÉúÒâÇëÇóµÄ½»Á÷»úÓ¦ÓÃЧÀÍÆ÷ÖУ¬£¬ £¬£¬Ö¼ÔÚ×èµ²ºÍÅú׼ڲƭÐÔµÄATMÌáÈ¡ÏÖ½ðÇëÇ󣬣¬ £¬£¬²¢·¢ËÍÐéαµÄÅú×¼ÏìÓ¦¡£¡£¡£¡£¡£¡£¡£¸ÃľÂíרÃÅÕë¶ÔÔËÐÐIBM AIXϵͳµÄ½»Á÷»úÓ¦ÓÃЧÀÍÆ÷£¬£¬ £¬£¬ÈüÃÅÌú¿Ë·¢Ã÷¸Ã×éÖ¯¹¥»÷µÄËùÓÐЧÀÍÆ÷¶¼ÔËÐÐÒÑÓâÆÚµÄAIX OS°æ±¾¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.symantec.com/blogs/threat-intelligence/fastcash-lazarus-atm-malware


3¡¢Ñо¿ÍŶӷ¢Ã÷Ö÷ÒªÕë¶Ô°ÍÎ÷½ðÈÚ»ú¹¹µÄ¶ñÒâÈí¼þ·Ö·¢»î¶¯

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


˼¿ÆTalosÍŶӷ¢Ã÷Á½¸öÕýÔÚ¾ÙÐÐÖеĶñÒâÈí¼þ·Ö·¢»î¶¯£¬£¬ £¬£¬ÕâЩ»î¶¯ÓÃÓÚÏò°ÍÎ÷µÄ½ðÈÚ»ú¹¹Óû§Èö²¥ÒøÐÐľÂí¡£¡£¡£¡£¡£¡£¡£¹¥»÷»î¶¯±¬·¢ÔÚ10ÔÂβºÍ11Ô³õ£¬£¬ £¬£¬ÕâÁ½¸ö¹¥»÷»î¶¯Ê¹ÓÃÁ˲î±ðµÄ³õʼѬȾÎļþÀàÐͺÍÁ½¸ö²î±ðµÄÒøÐÐľÂí£¬£¬ £¬£¬µ«ÔÚѬȾÀú³ÌÖжÔÖÖÖÖÎļþʹÓÃÁËÏàͬµÄÃüÃû¹æÔò£¬£¬ £¬£¬²¢¶¼Ê¹ÓÃÁ˶ÌÁ´½ÓÀ´Òþ²ØÏÖʵµÄ·Ö·¢Ð§ÀÍÆ÷µØµã¡£¡£¡£¡£¡£¡£¡£ÔÚÆÊÎöÕâЩ»î¶¯Ê±£¬£¬ £¬£¬Talos»¹·¢Ã÷ÁËÒ»¸öеÄÀ¬»øÓʼþ½©Ê¬ÍøÂç¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2018/11/metamorfo-brazilian-campaigns.html


4¡¢¼ÓÄôóÓÊÕþй¶Լ4500ÃûOCS¿Í»§µÄ´óÂé¶©µ¥ÐÅÏ¢

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÉÏÖÜÈý°²Ê¡´óÂéÍøµê£¨OCS£©ÔÚTwitterÉÏ͸¶³Æ£¬£¬ £¬£¬Î´Öª¹¥»÷Õß´Ó¼ÓÄôóÓÊÕþ»á¼ûÁËÔ¼4500Ãû¿Í»§µÄ¶©µ¥¼Í¼£¬£¬ £¬£¬Ô¼Õ¼¸Ã¹«Ë¾¿Í»§ÈºµÄ2%¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨Ç©ÊÕÈ˵ÄÐÕÃû»òËõд¡¢ÓÊÕþ±àÂë¡¢½»¸¶ÈÕÆÚ¡¢OCS±àºÅ¡¢ÓÊÕþ°ü¹üºÅÒÔ¼°OCS¹«Ë¾µÄÃû³ÆºÍÓªÒµµØµãµÈ¡£¡£¡£¡£¡£¡£¡£µ«OCS¼á³ÆÍêÕûµÄ¿Í»§µØµã¡¢¶©µ¥ÄÚÈݺ͸¶¿îÐÅϢûÓÐÊܵ½Ë𺦡£¡£¡£¡£¡£¡£¡£¸Ãй¶ÊÂÎñÓÚ11ÔÂ1ÈÕ±»·¢Ã÷£¬£¬ £¬£¬¼ÓÄôóÓÊÕþºÍOCSÕýÔÚÏàÖúÊÓ²ìÊÂÎñµÄÒòÓÉ¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/canada-post-leaked-personal-data-orders-of-thousands-of-cannabis-smokers/


5¡¢·ðÂÞÀï´ïÖÝÎÀÉúÊ𱻺ڿÍÈëÇÖ£¬£¬ £¬£¬²¿·ÖµØÇøµÄ»¼ÕßÐÅϢй¶

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¾Ý±¨µÀ·ðÂÞÀï´ïÖÝÎÀÉúÊðµÄÒ»ÃûCMSÔ±¹¤µÄOutlook 365ÕË»§±»ºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬Escambia¡¢Santa Rosa¡¢OkaloosaºÍWaltonµØÇøµÄ»¼ÕßÐÅÏ¢±»ÇÔ¡£¡£¡£¡£¡£¡£¡£¸ÃÕË»§µÄδÊÚȨ»á¼û±¬·¢ÔÚ10ÔÂ8ÈÕÖÁ10ÔÂ16ÈÕÖ®¼ä£¬£¬ £¬£¬²¿·ÖÓû§µÄÐÕÃû¡¢Ò½ÁÆ×´Ì¬µÈÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤¸ÃÎÀÉúÊðµÄÉùÃ÷£¬£¬ £¬£¬Ã»ÓÐÖ¤¾ÝÅú×¢»¼ÕßµÄÉç±£ºÅÂë¡¢ÒøÐÐÕË»§»òÐÅÓÿ¨ÐÅÏ¢±»ÇÔ¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/florida-department-of-health-breached-patients-private-information-exposed-523724.shtml


6¡¢ICS-CERTÖÒÑÔ³ÆÈðÊ¿ÂÞÊÏÒ½ÁÆÆ÷е±£´æ¶à¸öÇå¾²Îó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²³§ÉÌMedigate·¢Ã÷ÈðʿҽÁƱ£½¡¹«Ë¾ÂÞÊÏÖÆÔìµÄÈýÖÖÒ½ÁÆÆ÷еÖб£´æÎå¸öÇå¾²Îó²î£¬£¬ £¬£¬¿ÉÄܵ¼Ö»¼ÕßÃæÁÙΣº¦¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨Accu-ChekѪÌÇÒÇ¡¢CoaguChek×°±¸ºÍCobas±ãЯʽ´²±ßÕչ˻¤Ê¿ÏµÍ³¡£¡£¡£¡£¡£¡£¡£ICS-CERTÒ²ÔÚÏà¹Ø±¨¸æÖÐÁгöÁËÊÜÓ°Ïì²úÆ·ºÍ°æ±¾µÄÏêϸÇåµ¥¡£¡£¡£¡£¡£¡£¡£ÈðÊ¿ÂÞÊÏÕýÔÚÐÞ¸´ÕâЩÎó²î£¬£¬ £¬£¬Ô¤¼Æ±¾Ô½«Ðû²¼Ïà¹ØÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/flaws-roche-medical-devices-can-put-patients-risk


ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí