¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180802

°ä²¼¹¦·ò 2018-08-02

¡¾Íþвµý±¨¡¿ÃÀ¹úÉÌÎñ²¿Ôì²ÃÃûµ¥ÐÂÔö44¼ÒÖйú¸ß¿Æ¼¼ÆóÒµ


ƾ¾ÝÃÀ¹úÁª¹ú¹«±¨£¨FederalRegister£¬ÃÀ¹úÁª¹úµ±¾ÖÈ·µ±¾Ö¹«±¨£©ÍøÕ¾°ä²¼µÄ×îÐÂÐÅÏ¢ÏÔʾ£¬ÃÀ¹úBIS½«ÓÚÃÀ¶«¹¦·ò8ÔÂ1ÈÕÕýʽÒÔ¹ú¶È°²È«ºÍ±í½»ÀûÒæÎªÓÉ£¬½«44¼ÒÖйúÆóÒµ£¨8¸öʵÌåºÍ36¸ö´ÓÊô»ú¹¹£©ÁÐÈë³ö¿Ú¹ÜÔìʵÌåÇåµ¥£¬ÆäÖÐÔ̺¬ºÃ¶à×êÑлú¹¹¡£ÃÀ¹úÕýʽÆðÍ·¶ÔÖйú½øÐм¼Êõ¹Ø±Õ¡£Õâ44¼ÒÆóҵȫÊý¶¼ÊÇÖйú¸ß¿Æ¼¼ÆóÒµ£¬ÒÔº½¿Õº½Ìì¡¢¾ü¹¤ÀàÆóҵΪÖ÷¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://weibo.com/ttarticle/p/show?id=2309614268300610741920


¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±·¢ÏÖÀûÓÃNSO¼äµýÈí¼þÕë¶ÔÉ³ÌØ°¢À­²®ÈËȨ×éÖ¯µÄ¹¥»÷»î¶¯

2018Äê6Ô¹ú¼ÊÌØÉâ×éÖ¯µÄÒ»Ãû¹¤×÷ÈËÔ±ÊÕµ½¶ñÒâµÄWhatsAppÐÂÎÅ£¬ÆäÖÐÔ̺¬ÓëÉ³ÌØ°¢À­²®ÓйصĴ¹µöÁ´½Ó¡£×êÑÐÈËÔ±»¹·¢ÏÖÁíÒ»Î»É³ÌØÈËȨÖ÷ÒåÕßÒ²ÊÕµ½ÁËÀàËÆµÄÐÂÎÅ¡£·ÖÎöÅú×¢ÕâЩ¶ñÒâÐÂÎŽ«»áµ¼ÖÂϰȾÒÔÉ«ÁÐ¼à¿Ø¹©¸øÉÌNSO¼¯ÍÅÏúÊÛµÄóÒ×¼äµýÈí¼þPegasus¡£PegasusÖ¼ÔÚÔÊÐí¹¥»÷Õß½Ó¼ûÖ¸±êµÄÊý¾Ý£¬Ô̺¬¶ÌÐÅ¡¢µç×ÓÓʼþ¡¢WhatsAppÐÂÎÅ¡¢Óû§µÄµØÎ»¡¢Âó¿Ë·çºÍÉãÏñÍ·¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/iphone-hacking-spyware.html


¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖÀûÓÃRMSºÍTeamViewerÕë¶Ô¶í¹¤ÒµÆóÒµµÄ´¹µö¹¥»÷


¿¨°Í˹»ù³¢ÊÔÊÒICS CERT·¢ÏÖÖØÒªÕë¶Ô¶íÂÞ˹¹¤ÒµÆóÒµµÄÍøÂç´¹µö»î¶¯£¬¸Ã¹¥»÷»î¶¯ÀûÓúϷ¨µÄÔ¶³ÌÖÎÀíÈí¼þTeamViewerºÍRMSÀ´Ô¶³Ì½ÚÔìÊÜϰȾµÄϵͳ¡£Æ¾¾ÝÏÖÓеķ¢ÏÖ£¬¹¥»÷ÕßµÄÖØÒªÖ¸±êÊÇ´ÓÖ¸±êÆóÒµµÄÕË»§ÖÐÇÔÈ¡×ʽ𣬵«³ýÁ˾­¼ÃËðʧ֮±í£¬ÕâЩ¹¥»÷»¹»áµ¼ÖÂÖ¸±êÆóÒµµÄÃô¸ÐÊý¾Ýй¶¡£¸Ã¹¥»÷»î¶¯ÓÚ2017Äê11ÔÂÆðÍ·£¬Ä¿Ç°»¹ÔÚ³ÖÐø½øÐÐÖС£

 

Ô­ÎÄÁ´½Ó£ºhttps://securelist.com/attacks-on-industrial-enterprises-using-rms-and-teamviewer/87104/


¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖÓÃÓÚ·Ö·¢FlawedAmmyy RATµÄÀ¬»øÓʼþ»î¶¯


Ç÷Ïò¿Æ¼¼×êÑÐÍŶӼì²âµ½ÓÃÓÚ·Ö·¢Ô¶¿ØÄ¾ÂíFlawedAmmyy RATµÄÀ¬»øÓʼþ»î¶¯¡£¸Ã¹¥»÷»î¶¯»¹ÔÚ¶ñÒâPDFÎĵµÖÐÀûÓÃ.SettingContent-msÎļþÀàÐÍÒÔÌӱܼì²â¡£×êÑÐÍŶӳÆÊÕµ½¸ÃÀ¬»øÓʼþµÄµç×ÓÓʼþÕË»§ÖÐÓг¬¹ý50%ÊôÓÚÂíÀ´Î÷ÑÇ¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢¿ÏÄáÑÇ¡¢ÂÞÂíÄáÑÇ¡¢²¨À¼ºÍ°ÂµØÀûµÈ¹ú¶ÈµÄÒøÐС£¸ÃFlawedAmmyy RAT±äÌåÓë½©Ê¬ÍøÂçNecurs·Ö·¢µÄÕë¶ÔÒøÐкÍPoS»úÓû§µÄ±äÌåÒ»Ñù¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/spam-campaign-abusing-settingcontent-ms-found-dropping-same-flawedammy-rat-distributed-by-necurs/


¡¾Íþвµý±¨¡¿×êÑÐÅú×¢ÎåÖÖÎļþÀàÐÍռȫÊýÀ¬»øÓʼþ¶ñÒ⸽¼þµÄ85%


ƾ¾Ý·ÒÀ¼ÍøÂ簲ȫ¹«Ë¾F-SecureµÄ»ã±¨£¬Ö»¹ÜµÁ°æ×ÊÔ´ÊǶñÒâÈí¼þµÄÖØÒªÆðÔ´£¬µ«À¬»øÓʼþÒÀÈ»ÊǽñÌìµÄÖØÒªÏ°È¾Ã½½éºÍ·¸×ï·Ö×ÓµÄÊ×Ñ¡¹¤¾ß¡£À¬»øÓʼþÒÀÈ»ÓÐЧµÄÖØÒªÔ­ÒòÖ®Ò»ÊÇÓû§ÎÞ·¨¼ø±ðÀ¬»øÓʼþ¡£À¬»øÓʼþµÄµã»÷ÂÊÒѾ­´Ó2017ÄêϰëÄêµÄ13.4£¥ÉÏÉýÖÁ2018ÄêÉϰëÄêµÄ14.2£¥¡£ÎåÖÖÎļþÀàÐÍ×é³ÉÁË85£¥µÄ¶ñÒ⸽¼þ£¬±ðÀëÊÇ.ZIP¡¢.DOC¡¢.XLS¡¢.PDFºÍ.7Z¡£2018Äê´º¼¾µÄÀ¬»øÓʼþÑù±¾ÖУ¬46%ÊÇÔ¼»áÚ¿Æ­»î¶¯£¬23%ÊÇЯ´ø¶ñÒ⸽¼þµÄÓʼþ£¬31%Ô̺¬¶ñÒâÍøÕ¾µÄÁ´½Ó¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/just-five-file-types-make-up-85-percent-of-all-spam-malicious-attachments/


¡¾Êý¾Ýй¶¡¿RedditÔâºÚ¿ÍÈëÇÖ£¬²¿ÃÅÓû§µÄÊý¾Ýй¶


Reddit°ä·¢ÆäÔâºÚ¿ÍÈëÇÖ£¬²¿ÃÅÓû§µÄÊý¾Ýй¶¡£¹¥»÷ÕßÈÆ¹ýË«³É·ÖÈÏÖ¤£¨2FA£©½øÈëÁ˼¸ÃûÔ±¹¤µÄÕË»§£¬²¢ÇÔÈ¡Á˲¿Ãŵç×ÓÓʼþµØÖ·¡¢ÈÕÖ¾¼Í¼ÒÔ¼°Ô̺¬¼ÓÑιþÏ£ÃÜÂëµÄÒ»¸ö2007ÄêµÄÊý¾Ý¿â±¸·Ý¡£¸Ã¹¥»÷ÊÂÎñ²úÉúÔÚ6ÔÂ14ÈÕÖÁ6ÔÂ18ÈÕÖ®¼ä£¬¹¥»÷ÕßÇÔÈ¡µÄÊý¾Ý¿â±¸·ÝÔ̺¬2005ÄêÖÁ2007Äê5ÔÂÆÚ¼äµÄÓû§Êý¾Ý£¬ÈçÕË»§Í´´¦£¨Óû§ÃûºÍ¼ÓÑιþÏ£ÃÜÂ룩¡¢µç×ÓÓʼþµØÖ·ºÍ¹«¿ª/¸öÈËÐÂÎÅ¡£ÔÚ2007Äê5ÔÂÖ®ºó×¢²áµÄÓû§ºÍ°ä²¼µÄÌû×Ó±»ÒÔΪÊǰ²È«µÄ¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/reddit-announces-security-breach-after-hackers-bypassed-staffs-2fa/