¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181225
Ðû²¼Ê±¼ä 2018-12-25
12ÔÂ21ÈÕά»ù½âÃÜÅû¶1.6Íò·ÝÎļþ£¬£¬£¬£¬£¬ÕâЩÎļþÊÇÃÀ¹ú´óʹ¹ÝµÄ¹ºÎïÇåµ¥¡£¡£¡£¡£Æ¾Ö¤ÕâЩÎļþ£¬£¬£¬£¬£¬ÃÀ¹úפ¶à¹ú´óʹ¹Ý¶¼Ôø¹ºÖÃÌØ¹¤×°±¸¡£¡£¡£¡£ÀýÈç2018Äê8Ô£¬£¬£¬£¬£¬ÃÀ¹ú×¤Èø¶ûÍß¶àʹ¹ÝÐû²¼Ò»·Ý²É¹ºÐèÇ󣬣¬£¬£¬£¬ÆäÖаüÀ¨94¼þÌØ¹¤×°±¸£¬£¬£¬£¬£¬°üÀ¨ÄÜ×°ÖÃÔÚÆû³µÀïµÄÒ¹ÊÓÉãÏñÍ·ÒÔ¼°Î±×°Ôڸֱʡ¢´ò»ð»ú¡¢³ÄÉÀŦ¿Û¡¢ÑÛ¾µµÈÒ»Ñùƽ³£ÓÃÆ·ÖеÄÉãÏñÍ·¡£¡£¡£¡£ÃÀ¹úפÎÚ¿ËÀ¼Ê¹¹ÝÔò²É¹ºÁ˼Òô»úºÍÒþ²ØÎÞÏßµç×°±¸µÈ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://shoppinglist.wikileaks.org/2¡¢Îó²îʹÓù¤¾ß°üUnderminerÔÚ12ÔÂÍÆ³öˢа汾

Malwarebytes Labs·¢Ã÷Îó²îʹÓù¤¾ß°üUnderminerÔÚ12Ô·ÝÍÆ³öÁËˢеİ汾¡£¡£¡£¡£ÔÚ2018ÄêÇï¼¾£¬£¬£¬£¬£¬UnderminerÖ÷ҪʹÓÃIEÖеÄÎó²î£¨CVE-2018-8174£©ºÍFlash PlayerÖеÄÎó²î£¨CVE-2018-4878£©¡£¡£¡£¡£µ«ÔÚ12Ô·ݣ¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÒÔΪа汾µÄUnderminerʵÏÖÁË×î½üµÄFlash PlayerÎó²îʹÓã¨CVE-2018-15982£©¡£¡£¡£¡£Æä×îÖÕpayloadµÄ´ò°üºÍÖ´Ðеķ½·¨ÈÔÊÇUnderminer¶ÀÍ̵쬣¬£¬£¬£¬ÆäpayloadΪHidden Bee¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/threat-analysis/2018/12/underminer-exploit-kit-improves-latest-iteration/3¡¢Ó¢¹úÕþ¸®ÍƳö¹ú¼ÒÍøÂçÇå¾²ÊÖÒÕÆðÔ´Õ½ÂÔÕ÷¼¯Òâ¼û¸å

Ó¢¹úÕþ¸®ÍƳö¹ú¼ÒÍøÂçÇå¾²ÊÖÒÕÆðÔ´Õ½ÂÔµÄÕ÷¼¯Òâ¼û¸å£¬£¬£¬£¬£¬ÕâÒ»ÆðÔ´Õ½ÂÔµÄÄ¿µÄÊǽâ¾ö¸üÆÕ±éµÄÍøÂçÇå¾²ÄÜÁ¦²î±ð¡£¡£¡£¡£±¨¸æÖжÔÍøÂçÇå¾²ÊÖÒÕ¾ÙÐÐÁËÃ÷È·½ç˵£¬£¬£¬£¬£¬²¢½«ÔÚ2019ÄêÐû²¼ÍêÕûµÄÍøÂçÇ徲֪ʶϵͳ£¨CyBoK£©¡£¡£¡£¡£ÆðÔ´Õ½ÂÔ»¹½«½¨ÉèÒ»¸öеġ¢×ÔÁ¦µÄÓ¢¹úÍøÂçÇ徲ίԱ»á£¬£¬£¬£¬£¬¸ÃίԱ»á½«ÈÏÕæÖÆ¶©º¸Ç²î±ðרҵµÄ¿ò¼Ü£¬£¬£¬£¬£¬µÓÚ¨ÍøÂçÇ徲רҵµÄ½á¹¹»ù´¡¡£¡£¡£¡£Õþ¸®»¹½«¼ÌÐøÖ§³ÖÉú³¤ÐÐÒµÖ÷µ¼µÄÅàѵÉú̬ϵͳ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.gov.uk/government/publications/cyber-security-skills-strategy/initial-national-cyber-security-skills-strategy-increasing-the-uks-cyber-security-capability-a-call-for-views-executive-summary4¡¢Ñо¿ÍŶÓÅû¶»ªÎªÂ·ÓÉÆ÷ÖеÄÐÅϢй¶Îó²î

NewSky SecurityÅû¶»ªÎªÂ·ÓÉÆ÷ÖеÄÒ»¸öÐÅϢй¶Îó²î£¬£¬£¬£¬£¬¸ÃÎó²î£¨CVE-2018-7900£©Ê¹µÃ¹¥»÷·ÓÉÆ÷µÄÀú³ÌÔ½·¢¼ò»¯¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÅжÏ·ÓÉÆ÷ÊÇ·ñ¾ßÓÐĬÈÏÆ¾Ö¤£¬£¬£¬£¬£¬¶øÎÞÐèÅþÁ¬µ½×°±¸¡£¡£¡£¡£¸ÃÎó²îµÄÔÀíÊÇ·ÓÉÆ÷Ãæ°åµÄµÇÂ¼Ò³ÃæµÄhtmlÔ´ÂëÖаüÀ¨Ò»¸öÌØ¶¨µÄ±äÁ¿£¬£¬£¬£¬£¬¸Ã±äÁ¿µÄÌØ¶¨ÖµÕ¹ÏÖÁË·ÓÉÆ÷ÊÇ·ñ¾ßÓÐĬÈÏÃÜÂ룬£¬£¬£¬£¬Òò´Ë¹¥»÷Õß¿ÉÒÔÔÚZoomEye/ShodanÉÏÒþʽµØ»ñÈ¡¾ßÓÐĬÈÏÃÜÂëµÄ×°±¸ÁÐ±í¡£¡£¡£¡£ÔÚ½Óµ½±¨¸æºó£¬£¬£¬£¬£¬»ªÎªÒѾÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.newskysecurity.com/information-disclosure-vulnerability-cve-2018-7900-makes-it-easy-for-attackers-to-find-huawei-3e7039b6f44f5¡¢Ê©ÄÍµÂµçÆøÐÞ¸´EVLinkµç¶¯Æû³µ³äµçÕ¾ÖеĶà¸öÇå¾²Îó²î

Ê©ÄÍµÂµçÆøÌåÏÖÆäEVLinkµç¶¯Æû³µ³äµçÕ¾µÄParkingÂäµØÊ½µ¥Î»£¨v3.2.0-12_v1¼°¸üÔç°æ±¾£©±£´æÈý¸öÇå¾²Îó²î£¬£¬£¬£¬£¬°üÀ¨Ó²±àÂëÆ¾Ö¤Îó²î£¨CVE-2018-7800£©¡¢´úÂë×¢ÈëÎó²î£¨CVE-2018-7801£©ºÍSQL×¢ÈëÎó²î£¨CVE-2018-7802£©¡£¡£¡£¡£EVLinkͨ³£ÓÃÓڰ칫ÊÒ¡¢Âùݺͳ¬Êеȵط½£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒѾΪÕâЩÎó²îÌṩÁËÐÞ¸´²¹¶¡¡£¡£¡£¡£±¾ÔÂÔçЩʱ¼ä¿¨°Í˹»ùʵÑéÊÒÅû¶ChargePoint HomeµÄ³äµç×®±£´æ¶à¸öÎó²î£¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹Ö¸³öEVͨѶÐÒé¡¢EVÖ§¸¶ÏµÍ³ºÍºó¶ËͨѶµÄÇå¾²ÐÔ¶¼Ò×Êܹ¥»÷¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/critical-bug-patched-in-schneider-electric-vehicle-charging-station/140370/6¡¢AkamaiÐû²¼Ð´¹ÂÚÕ½ÂÔÑо¿±¨¸æ£¬£¬£¬£¬£¬ÖØµã¹Ø×¢ÓÎÏ·¡¢Éç½»¼°Öн±

ƾ֤AkamaiµÄд¹ÂÚÕ½ÂÔÑо¿±¨¸æ£¬£¬£¬£¬£¬Ê¢Ðеġ°Èý¸öÎÊÌ⡱ÔÚÏßС¿¼ÊÔ±»·¢Ã÷ÊÇÒ»¸ö´óÐ͵ÄÍøÂç´¹ÂÚթƻ¡£¡£¡£¡£¸Ã´¹ÂڻģÄâÁËËĸöÐÐÒµ£¨°üÀ¨º½¿Õ¡¢ÁãÊÛ¡¢ÓéÀÖºÍʳÎµÄ78¸öÆ·ÅÆ£¬£¬£¬£¬£¬ÀýÈçµÏÊ¿ÄáÀÖÔ°¡¢Dunkin'DonutsºÍTargetµÈ¡£¡£¡£¡£¸ÃȦÌ×ͨ³£ÔÊÐí¿¼ÊÔÖ®ºó¸øÓè½±Àø£¬£¬£¬£¬£¬µ«ÏÖʵÉÏ»áÒªÇóÓû§ÔÚ½ÓÊܽ±Æ·Ö®Ìõ¼þ¹©Ð¡ÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬²¢ÔÚÉ罻ýÌåÉÏÈö²¥Á´½Ó¡£¡£¡£¡£AkamaiµÄ±¨¸æ»¹¹Ø×¢ÁËÓÎÏ·¡¢Éç½»¼°Öн±µÈ´¹ÂÚÕ½ÂÔ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.akamai.com/us/en/multimedia/documents/report/a-new-era-in-phishing-research-paper.pdfÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí