¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181031

°ä²¼¹¦·ò 2018-10-31
1¡¢µÚ¶þ¸ö¡°ÖÐÐË¡±³öÏÖ£¬¸£½¨½ú»ª±»ÃÀÉÌÎñ²¿ÁÐÈë½ûÊÛÃûµ¥

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úÉÌÎñ²¿ÖÜÒ»°ä·¢¶Ô¸£½¨½ú»ª¼¯³Éµç·ÓÐÏÞ¹«Ë¾Ö´ÐнûÊÛÁ²»ÈÝÃÀ¹úÆóÒµÏòÆäÏúÊÛ¼¼ÊõºÍ²úÆ·¡£ÕâÊǼÌÖÐÐËÖ®ºó£¬ÃÀ¹úµ±¾ÖÔٴζÔÖйú¿Æ¼¼ÆóÒµÖ´ÐнûÊÛÁî¡£±»´¦·£µÄ¸£½¨½ú»ªÍ¬ÑùÊôÓÚ¡°ÖйúÔì×÷2025´òË㡱£¬ÕâÊǶÔÖйú´æ´¢Ð¾Æ¬Ôì×÷ÒµµÄ³ÁÃͽø¹¥¡£ÃÀ¹úµ±¾Ö³Æ¸£½¨½ú»ªÉæ¼°Î¥·´ÃÀ¹ú¹ú¶È°²È«ÀûÒæµÄÐÐΪ£¬¸øÃÀ¹ú´øÀ´ÁËÑϳÁµÄ·çÏÕ¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/us-bans-exports-to-chinese/


2¡¢Apple°ä²¼°²È«¸üУ¬½¨¸´iOS¡¢macOSÖеĶà¸ö·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


AppleÕë¶ÔÖ÷Ìâ²úÆ·°ä²¼°²È«¸üУ¬Ô̺¬iOS 12.1¡¢Safari 12.0.1¡¢watchOS 5.1¡¢tvOS 12.1ºÍmacOS¸üеÈ£¬½¨¸´Á˶à¸ö¿Éµ¼Ö´úÂëÖ´ÐÓעȨÏÞÌáÉýºÍÐÅϢй¶µÄ·ì϶¡£½ÏÑϳÁµÄ·ì϶Ô̺¬iOSÖеÄFaceTime·ì϶£¨CVE-2018-4367£©£¬¸Ã·ì϶¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õß´ÓÖ¸±êÉ豸ÌáÒéFaceTimeºô½Ð £»macOSÖеĿɵ¼ÖÂÉ豸±ÀÀ£µÄ·ì϶£¨CVE-2018-4407£©£¬¸Ã·ì϶¿ÉÔÊÐíͳһ¸öWiFiÄڵĹ¥»÷Õßͨ¹ý·¢ËͶñÒâÊý¾Ý°üÀ´µ¼ÖÂÖ¸±êÉ豸±ÀÀ£¡£½¨ÒéÓû§¾¡¿ì½øÐÐÉý¼¶¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/apple-fixes-creepy-facetime-vulnerability-crash-bug-in-macos-and-more/


3¡¢¿¨°Í˹»ù°ä²¼2018Äê¹¤ÒµÍøÂ簲ȫÇé¿ö°×ƤÊé

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ù×î½ü°ä²¼µÄ2018Äê¹¤ÒµÍøÂ簲ȫÇé¿ö°×ƤÊéÖ¸³ö£¬Ëæ×ÅÓë±í²¿ÊÀ½çµÄÏνӲ»ÐÝÔö¶à£¬ÔÚ¹¤ÒµITºÍOTÍøÂçÖа²È«ÐÔÔÚ³ÉΪ×î³ÁÒªµÄÖ÷ÌâÖ®Ò»¡£77%µÄ¹¤Òµ°²È«ÈËÊ¿ÒÔΪËûÃÇµÄÆóÒµºÜ¿ÉÄܳÉÎªÍøÂ簲ȫÊÂÎñµÄÖ¸±ê£¬Í¬Ê±48%µÄÊÜ·ÃÕß°µÊ¾ËûÃÇûÓÐרÃŵÄOT/ICSÊÂÎñÏìÓ¦´òËã¡£´Óǰ12¸öÔÂÄÚ³¬¹ýÒ»°ëµÄÆóÒµ°µÊ¾ËûÃÇûÓо­Àú¹ýÈκΰ²È«ÊÂÎñ£¬µ«ºÜ¶àÆóÒµÊÂʵÉϵ××ÓûÓмì²â»ò¸ú×Ù¹ýÈκι¥»÷¡£

  

Ô­ÎÄÁ´½Ó£º

https://ics.kaspersky.com/media/2018-Kaspersky-ICS-Whitepaper.pdf


4¡¢Ç÷Ïò¿Æ¼¼°ä²¼Ë®ÎñºÍÄÜÔ´¹Ø¼ü»ù´¡ÉèÊ©·çÏջ㱨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ç÷Ïò¿Æ¼¼°ä²¼Ë®ÎñºÍÄÜÔ´¹Ø¼ü»ù´¡ÉèÊ©£¨CI£©µÄ·çÏÕµ÷²é»ã±¨¡£Í¨¹ý»¥ÁªÍøÉ¨Ãè£¨ÖØÒªÊÇShodan£©ºÍÎïÀíµØÎ»Ó³É䣬×êÑÐÈËÔ±·¢Ïֺܶà¶³öºÍÒ×Êܹ¥»÷µÄHMIϵͳ¡£ÕâЩϵͳ¶¼ÊÇÖÐÓ×ÐÍÆóÒµµÄϵͳ¡£¶ÔÓÚË®Îñϵͳ£¬Â¶³öµÄϵͳÔ̺¬¼ÓÈÈ¡¢µØÈÈ¡¢Ë®±Ã¡¢¹ýÂË¡¢º£Ë®·´ÉøÈëºÍÃð¾úϵͳµÄ¼à²âºÍ½ÚÔì½Ó¿ÚµÈ¡£¶ÔÓÚÄÜԴϵͳ£¬Ô̺¬Ê¯ÓÍ¡¢ÌìÈ»Æø¡¢ÕÓÆøºÍµçÁ¦µÈϵͳ¡£ÕâЩ¶³öµÄHMIʹµÃ¹¥»÷ÕßÄܹ»ÊµÊ±²é¿´³ö²úˮƽµÈÐÅÏ¢£¬ÉõÖÁÄܹ»Ö±½ÓÓëϵͳºÍÉ豸½øÐн»»¥¡£
  Ô­ÎÄÁ´½Ó£º
https://documents.trendmicro.com/assets/white_papers/wp-exposed-and-vulnerable-critical-infrastructure-the-water-energy-industries.pdf


5¡¢McAfee°ä²¼ÔÆ·þÎñ·çÏջ㱨£¬21%µÄÔÆÎļþÔ̺¬Ãô¸ÐÊý¾Ý

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


McAfee°ä²¼ÔÆÑ¡È¡Î¢·çÏջ㱨£¨2019°æ£©£¬»ã±¨µÄÖØÒª·¢ÏÖÔ̺¬£º21%µÄÔÆÎļþÔ̺¬Ãô¸ÐÊý¾Ý£¬ÀàÐÍÔ̺¬»úÃÜÎļþ¡¢µç×ÓÓʼþ¡¢¼ÓÃܵÄÃÜÂë¡¢PII¡¢Ö§¸¶ÐÅÏ¢ÒÔ¼°PHIÐÅÏ¢ £»8%µÄ¹²ÏíÎļþÔ̺¬Ãô¸ÐÊý¾Ý£¬Ô̺¬Í¨¹ýÊ¢¿ªÁ´½Ó¹²ÏíºÍÓëÓ×ÎÒÓʼþµØÖ·¹²ÏíµÄÎļþ £»¶àIaaSÕ½ÊõÊdz߶È £»ÔÆÍþв³ÖÐøÔö³¤£¬¾ùÔÈÿ¸ö×é֯ÿÔ¾­Àú31.3´ÎÔÆ°²È«ÊÂÎñ£¬±ÈÈ¥ÄêͬÆÚÔö³¤27.7% £»ÏÕЩËùÓеÄ×éÖ¯³ÇÊÐÓöµ½Íþв¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.skyhighnetworks.com/cloud-computing-trends-2019/


6¡¢×êÑÐÍŶӷ¢ÏÖÕë¶Ô¶íÂÞ˹Áª¹ú´¢ÐîÒøÐеÄľÂíGPlayed Banking

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


˼¿ÆTalosÍŶӷ¢ÏÖÖØÒªÕë¶Ô¶íÂÞ˹Áª¹ú´¢ÐîÒøÐУ¨Sberbank£©µÄÒøÐÐľÂíGPlayed Banking¡£GPlayed BankingÊÇÒøÐÐľÂíGPlayedµÄǰÉí£¬ËüÖ»Õë¶ÔSberbankµÄAutoPay·þÎñµÄÓû§¡£¸ÃľÂíµÄ´«²¼·½Ê½ÓëGPlayedÀàËÆ£¬¶¼ÊǼÙ×°³ÉÐéαµÄGoogle app store½øÐд«²¼¡£¸ÃľÂíÊÇͨ¹ý.NET±àдµÄ£¬¶ñÒâ´úÂëÔ̺¬ÔÚPlayMarket.dllÖС£

  

Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2018/10/gplayerbanker.html


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù