¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181101

°ä²¼¹¦·ò 2018-11-01
1¡¢¹«°²»ú¹Ø»¥ÁªÍø°²È«¼à¶½²é³­»®¶¨½ñÈÕÆðÍ·Ö´ÐÐ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¡¶¹«°²»ú¹Ø»¥ÁªÍø°²È«¼à¶½²é³­»®¶¨¡·ÒѾ­ÓÚ2018Äê9ÔÂ5ÈÕ¹«°²²¿²¿³¤°ì¹«»áÒéͨ¹ý£¬×Ô2018Äê11ÔÂ1ÈÕÆðÖ´ÐС£±¾»®¶¨ºÏÓÃÓÚ¹«°²»ú¹ØÒÀ·¨¶Ô»¥ÁªÍø·þÎñÌṩÕߺÍÁªÍøÊ¹Óõ¥ÔªÍƹã˾·¨¡¢ÐÐÕþÂÉÀý»®¶¨µÄÍøÂ簲ȫʹÃüÇé¿ö½øÐеݲȫ¼à¶½²é³­¡ £»¥ÁªÍø°²È«¼à¶½²é³­¹¤×÷ÓÉÏØ¼¶ÒÔÉÏ´¦ËùÈËÃñµ±¾Ö¹«°²»ú¹ØÍøÂ簲ȫ±£ÎÀ²¿ÃÅ×éÖ¯Ö´ÐС£¹«°²»ú¹Ø¶Ô»¥ÁªÍø°²È«¼à¶½²é³­¹¤×÷Öз¢ÏֵĿÉÄÜ·çÏÕ¹ú¶È°²È«¡¢¹«¹²°²È«¡¢Éç»áÖÈÐòµÄÍøÂ簲ȫ·çÏÕ£¬¸Ãµ±ÊµÊ±´«µÝÓйØÖ÷¹Ü²¿Ãź͵¥Ôª¡£

   

Ô­ÎÄÁ´½Ó£º

http://www.mps.gov.cn/n2254314/n2254409/n4904353/c6263180/content.html


2¡¢×êÑÐÍŶӰ䲼2018ÄêµÚÈý¼¾¶ÈDDoS¹¥»÷Ç÷ÏòµÄ·ÖÎö»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ù°ä²¼2018ÄêµÚÈý¼¾¶ÈDDoS¹¥»÷Ç÷ÏòµÄ·ÖÎö»ã±¨£¬»ã±¨µÄÖØÒª·¢ÏÖÔ̺¬£ºÍ¨¹ý½©Ê¬ÍøÂçÌáÒéµÄDDoS¹¥»÷ÊýÁ¿ÔÚ8Ô·ݴﵽ¶¥·å£¬×îµÍ¹È³Ê´Ë¿Ì7Ô³õ £»³ÖÐøÐÔDDoS¹¥»÷µÄÊýÁ¿ÓÐËù½µÂ䣬Ȼ¶ø³ÖÐø¹¦·ò¶ÌÓÚ4Ó×ʱµÄ¹¥»÷Ôö³¤ÁË17.5¸ö°Ù·Öµã£¬´ï86.94% £»SYN·ººé¹¥»÷ÒÀÈ»ÅÅÔÚµÚһ루83.2%£© £»ÖйúÒÀÈ»Êǹ¥»÷ÊýÁ¿×î¶àµÄµØÓò£¨78%£©¡£

 

 Ô­ÎÄÁ´½Ó£º

https://securelist.com/ddos-report-in-q3-2018/88617/


3¡¢Windows 10зì϶ÔÊÐíUWPÀûÓýӼûÈ«ÊýÎļþϵͳ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͨÓÃWindowsƽ̨£¨UWP£©ÀûÓÃÔÊÐíÀûÓ÷¨Ê½ÔÚÖ°ºÎWindows 10É豸ÉÏÔËÐУ¬Ô̺¬Ì¨Ê½»ú¡¢Xbox¡¢ÎïÁªÍøÉ豸ºÍSurface HubµÈ¡£Î¢ÈíΪUWPÀûÓÃÌṩÁËÒ»¸öAPIÀ´½Ó¼ûÎļþϵͳ£¬Õý³£Çé¿öϸÃAPI»áµ¯³ö¶Ô»°¿òÉêÇëÓû§µÄȨÏÞÐí¿É£¬µ«×êÑÐÈËÔ±·¢ÏÖ¸ÃAPI´æÔÚÖÂÃü·ì϶£¬¶ñÒâµÄUWPÀûÓÿÉÈÆ¹ýÓû§µÄȨÏÞÒªÇó½Ó¼ûÆëÈ«µÄÎļþϵͳ¡£Î¢ÈíÒѾ­ÔÚWindows 10°æ±¾1809Öн¨¸´Á˸÷ì϶¡£

  

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/10/windows10-uwp-apps.html


4¡¢×êÑÐÈËÔ±ÔÚа䲼µÄiOS 12.1Öз¢ÏÖÃÜÂëÈÆ¹ý·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÔÚApple°ä²¼iOS 12.1µÄ¼¸¸öÓ×ʱÄÚ£¬Î÷°àÑÀ×êÑÐÈËÔ±Jose Rodriguez·¢ÏÖÁËÒ»¸öеÄÃÜÂëÈÆ¹ý·ì϶¡£¸Ã·ì϶ÓëiOS 12.1ÖеÄÐÂÖ°ÄÜGroup FaceTimeÓйØ£¬×êÑÐÈËÔ±Åû¶ÁËÓйØPoCÊÓÆµ¡£¸Ã·ìÏ¶ËÆºõºÏÓÃÓÚËùÓеÄiPhoneÐͺÅ£¬Ô̺¬iPhone XºÍXS¡£ÓÉÓÚĿǰûÓÐһʱ½â¾ö¸ÃÎÊÌâµÄworkaround£¬½¨ÒéÓû§ÆÚ´ýAppleµÄ¸üС£ÕâÒѾ­ÊÇRodriguez½üÆÚµÚÈý´ÎѸ¿ì·¢ÏÖiOS 12ÖеÄÃÜÂëÈÆ¹ý·ì϶ÁË¡£

  

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/10/iphone-ios-passcode-bypass.html


5¡¢Ë¼¿ÆÅû¶ASAºÍFTD²úÆ·ÖеÄÐÂ0day£¬¿Éµ¼Ö»ؾø·þÎñ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


˼¿Æ°²È«ÍŶÓÅû¶Æä×ÔÊÊÓ¦°²È«É豸£¨ASA£©ºÍFirepowerÍþв·ÀÓùÈí¼þ£¨FTD£©ÖеĻỰ³õʼ»¯ºÍ̸£¨SIP£©²é³­ÒýÇæ´æÔÚÒ»¸ö¿Éµ¼Ö»ؾø·þÎñµÄÁãÈÕ·ì϶¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâSIPÒªÇóÀ´´¥·¢¸Ã·ì϶£¬µ¼ÖÂDoS¡£¸Ã·ì϶£¨CVE-2018-15454£©Ó°ÏìÔËÐÐASA 9.4+ºÍFTD 6.0+µÄÉ豸£¬Ô̺¬¶à¸öÐͺŵĹ¤Òµ°²È«É豸ºÍ·À»ðǽµÈ²úÆ·¡£Ä¿Ç°»¹Ã»Óи÷ì϶µÄ½¨¸´²¹¶¡ºÍworkaround£¬µ«Äܹ»²ÉȡһЩ»º½â´ëÊ©×èÖ¹Ô¶³Ì¹¥»÷Õß·ÛËéÆäÉ豸¡£

  

Ô­ÎÄÁ´½Ó£º

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181031-asaftd-sip-dos


6¡¢×êÑлú¹¹°ä²¼¹ØÓÚÀÕË÷Èí¼þ¼´·þÎñKraken CryptorµÄ·ÖÎö»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Insikt GroupÓëMcAfee¹²Í¬°ä²¼¹ØÓÚÀÕË÷Èí¼þKraken CryptorµÄ·ÖÎö»ã±¨¡£KrakenÓÚ2018Äê8Ô³õ´ÎÔÚÒ°±í³öÏÖ£¬ÓÉ»îÔ¾ÔÚ¶íÂÞ˹·¸×ïÂÛ̳ÉϵÄÍÅ»ïThisWasKraken½øÐзַ¢¡£KrakenÊÇÒ»¸öÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©µÄ»áÔ±ÔìÏúÊÛ´òË㣬ÓÉThisWasKrakenÕÆ¹Ü¾­Óª£¬ÆäÖØÒª·Ö·¢·½Ê½ÊÇFallout EK¡£×êÑÐÈËÔ±»¹·¢ÏÖThisWasKrakenÀûÓÃÔÚÏ߶ij¡BitcoinPenguinÀ´Ï´Ç®¡£Insikt GroupÐÅÄîÊ®×ãµØÒÔΪThisWasKrakenÍŶӵijÉÔ±¾ÓסÔÚÒÁÀÊ¡¢°ÍÎ÷»òǰËÕÁª¹ú¶È¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.recordedfuture.com/kraken-cryptor-ransomware/


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù