¡¾·ÖÎö»ã±¨¡¿SANS×êÑÐËù°ä²¼2018ÄêIIOT°²È«ÐԵĵ÷Ñл㱨
SANS×êÑÐËù°ä²¼¹ØÓÚ¹¤ÒµÎïÁªÍø£¨IIoT£©°²È«ÐԵĵ÷Ñл㱨£¬¸Ã×êÑÐËù¶ÔÀ´×ÔÄÜÔ´¡¢¹«ÓÃÊÂÒµ¡¢Ê¯ÓͺÍÌìÈ»ÆøÒÔ¼°Ôì×÷ÒµµÄ200¶àÃû°²È«ÈËÔ±½øÐÐÁ˵÷²é£¬Ö»Óв»µ½5%µÄOTÈËÔ±°µÊ¾¶ÔËûÃǹ«Ë¾µÄлù´¡ÉèÊ©µÄ°²È«·À»¤³ä³âÐÅÄî¡£32%µÄÊÜ·ÃÆóÒµÖеÄIIoTÉ豸ֱ½ÓÏνӵ½»¥ÁªÍø£¬ÈƹýÁË´«Í³µÄICS°²È«²ã¡£´Ë±í£¬Ö»ÓÐ40%µÄÊÜ·ÃÕß°µÊ¾ËûÃÇʵʱΪÉ豸װÖò¹¶¡ºÍ¸üС£
ÔÎÄÁ´½Ó£ºhttps://cdn2.hubspot.net/hubfs/2755567/White%20Papers%20and%20Briefs/Sans%20IIOT%20Survey.pdf
¡¾¹¥»÷ÊÂÎñ¡¿Chrome²å¼þMEGAÔâºÚ¿Í½Ù³Ö£¬ÓÃÓÚÇÔÈ¡Óû§µÄÃÜÂë
ÔÆ´æ´¢·þÎñMEGA.nzµÄ¹Ù·½Chrome²å¼þÔâµ½ºÚ¿Í½Ù³Ö£¬ÓÃÓÚÇÔÈ¡Óû§µÄÃÜÂ롣ƾ¾Ý¸Ã¹«Ë¾µÄ²©¿Í£¬¹¥»÷ÕßÔÚ9ÔÂ4ÈÕ14:30 UTCÈëÇÖMEGAµÄChrome web storeÕÊ»§£¬²¢ÉÏ´«ÁËÒ»¸ö¶ñÒâ°æ±¾3.39.4¡£¸Ã°æ±¾ÓÃÓÚÇÔÈ¡Óû§µÄÑÇÂíÑ·¡¢Î¢Èí¡¢GithubºÍ¹È¸èµÈÊ¢ÐÐÍøÕ¾µÄÍ´´¦£¬ÒÔ¼°MyEtherWalletºÍMyMoneroµÈÔÚÏß¼ÓÃÜÇ®±ÒÇ®°üºÍ¼ÓÃÜÇ®±ÒÂòÂôƽ̨Idex.marketµÄÍ´´¦¡£±»µÁµÄÐÅÏ¢½«±»·¢ËÍÖÁλÓÚÎÚ¿ËÀ¼µÄmegaopac[.]host·þÎñÆ÷¡£¸Ã¹«Ë¾ÔÚÊÂÎñ²úÉúËÄÓ×ʱ֮ºó¸üÐÂÁËÒ»¸ö¸É¾»µÄ°æ±¾3.39.5¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/09/mega-file-upload-chrome-extension.html
¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖÀûÓÃ.tkÓòÃûµÄ´ó¹æÄ£¸æ°×ڿƻ
ZscalerµÄ×êÑÐÈËÔ±·¢ÏÖÀûÓÃ.tkÓòÃûµÄ´ó¹æÄ£¸æ°×ڿƻ¡£×Ô2018Äê5ÔÂÒÔÀ´£¬¸Ã¶ñÒâ»î¶¯Ò»Ïò´¦ÓÚ»îԾ״̬¡£¹¥»÷Õß½«Óû§³Á¶¨ÏòÖÁÐéαµÄ²©¿ÍÍøÕ¾£¬ÕâÐ©ÍøÕ¾Éϵĸæ°×ÊÕÈëÿÔ´ï2ÍòÃÀÔªÒÔÉÏ¡£²¿ÃÅ.tkÓòÃû»¹±»ÓÃÓÚ¼¼ÊõÖ§³¶à¿Æ¡£.tkÓòÃûÊÇÒ»¸ö¹ú¶È/µØÓò¼¶µÄ¶¥¼¶ÓòÃû£¬Ëü´ú±íÁË´ÓÊôÓÚÐÂÎ÷À¼µÄµº¹úTokelau¡£¸ÃÓòÃûÊÇÃâ·ÑµÄ£¬ÕâÒýÆðÁ˹¥»÷ÕßµÄÐËÖ¡£×êÑÐÈËÔ±×ܹ²·¢ÏÖÁËÓë¸Ã¶ñÒâ»î¶¯ÓйصÄ3804¸ö.tkÓòÃû¡£
ÔÎÄÁ´½Ó£ºhttps://www.zscaler.com/blogs/research/spam-campaigns-leveraging-tk-domains
¡¾Íþвµý±¨¡¿Group-IB·¢ÏÖÖØÒªÕë¶Ô¶íÂÞ˹ºÍ¶«Å·ÒøÐеÄз¸×ïÍÅ»ïSilence
Group-IB°ä²¼¹ØÓÚз¸×ïÍÅ»ïSilenceµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬SilenceÖÁÉÙÓë¶íÂÞ˹ºÍ¶«Å·µÄÒøÐкͽðÈÚ»ú¹¹µÄ80ÍòÃÀԪ͵ÇÔ°¸Óйء£¾ÝGroup-IB³Æ£¬¸Ã×éÖ¯ÔÚ´ÓǰÈýÄêÖÐÒ»Ö¹Øë¶Ô¶íÂÞ˹ºÍ¶«Å·µÄ½ðÈÚ»ú¹¹ÌáÒé¹¥»÷¡£Silence¿ª·¢ÁËһЩ×Ô¼ºµÄ¹¤¾ß£¬Ô̺¬»ù´¡ÉèÊ©¹¥»÷¿ò¼ÜSilence¡¢ATM¹¥»÷¹¤¾ßÏäAtmosphere¡¢ÃÜÂë»ñÈ¡¹¤¾ßFarseÒÔ¼°ÈÕÖ¾ÒÆ³ý¹¤¾ßCleaner¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/new-silence-hacking-group-suspected-of-having-ties-to-cyber-security-industry/
¡¾Íþвµý±¨¡¿·¸×ïÍÅ»ïFIN6¾íÍÁ³ÁÀ´£¬ÖØÒªÕë¶ÔÃÀ¹úºÍÅ·ÖÞµÄPoSϵͳ
IBM X-Force IRIS×êÑÐÍŶӷ¢ÏÖ·¸×ïÍÅ»ïFIN6µÄй¥»÷»î¶¯¡£¸Ã¹¥»÷»î¶¯ÖØÒªÕë¶ÔÃÀ¹úºÍÅ·ÖÞµÄÁãÊÛÉ̵ÄPoSϵͳ¡£Ä¿Ç°Éв»Ã÷ÏÔ¼¸¶àÆóÒµÔâµ½Á˹¥»÷¡£FIN6ͨ¹ýºóÃÅÈí¼þGrabnewÀ´ÍøÂçÓû§µÄÍ´´¦ÐÅÏ¢£¬¶øºóʹÓöñÒâÈí¼þTrinity£¨ÓÖ½ÐFrameworkPOS£©²éÕÒºÍÉøÈëPoSÉ豸¡£×êÑÐÈËÔ±°µÊ¾90%µÄй¥»÷»î¶¯¶¼Ê¹ÓÃÁËÓë֮ǰFIN6¹¥»÷Ò»ÑùµÄÕ½ÊõºÍ¹¤¾ß¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/fin6-returns-to-attack-retailers-in-us-europe/
¡¾·ì϶²¹¶¡¡¿Ë¼¿Æ°ä²¼¶à¿î²úÆ·µÄ°²È«¸üУ¬½¨¸´16¸ö°²È«·ì϶
±¾ÖÜÈý˼¿Æ°ä²¼ÁËRVϵÁÓ×¢SD-WANºÍUmbrellaµÈ²úÆ·µÄ°²È«¸üУ¬¹²½¨¸´ÁË16¸ö°²È«·ì϶¡£ÆäÖÐÔ̺¬RVϵÁзÀ»ðǽºÍ·ÓÉÆ÷µÄwebÖÎÀí½çÃæÖеĻº³åÇøÒç¶Âí½Å£¨CVE-2018-0423£©£¬¸Ã·ì϶¿ÉÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë»ò´¥·¢»Ø¾ø·þÎñ£»Umbrella APIÖеĸßΣ·ì϶£¨CVE-2018-0435£©£¬¸Ã·ì϶¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õ߲鿴ºÍÅú¸ÄÆäËü×éÖ¯µÄÊý¾Ý¡£½¨ÒéÓû§¾¡¿ì×°ÖÃÕâЩ¸üС£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cisco-releases-16-security-alerts-rated-critical-and-high/