¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181106

°ä²¼¹¦·ò 2018-11-06
1¡¢»ôÄáΤ¶û°ä²¼¹ØÓÚ¹¤ÒµÉèÊ©ÖеÄUSBÍþвµÄ·ÖÎö»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾Ý»ôÄáΤ¶û°ä²¼µÄÒ»·Ýл㱨£¬USBÉ豸ÊÇÕë¶Ô¹¤ÒµÉèÊ©µÄ¶ñÒâÈí¼þ¹¥»÷µÄÖØÒªÃ½½é ¡£¸Ã»ã±¨ÊÇ»ùÓÚ»ôÄáΤ¶ûµÄ°²È«Ã½Ì廥»»£¨SMX£©¼¼ÊõÍøÂçµÄÊý¾Ý£¬º­¸ÇÁËÄÜÔ´¡¢Ê¯ÓͺÍÌìÈ»Æø¡¢»¯Ñ§¡¢Ö½ÕÅÔì×÷µÈÐÐÒµ ¡£Êý¾ÝÅú×¢£¬26%µÄÍþв¿ÉÄܵ¼Ö¹¤ÒµÆóҵʧȥICS»·¾³µÄ¿É¼ûÐÔ»ò½ÚÔìȨ£¬´Ó¶øÔì³É³Á´óÖжÏ ¡£16%µÄÍþвרÃÅÕë¶ÔICSºÍIoTϵͳ£¬ÆäÖÐÔ̺¬¶ñÒâÈí¼þMirai£¨6£¥£©¡¢Stuxnet£¨2£¥£©¡¢Triton£¨2£¥£©ºÍWannaCry£¨1£¥£© ¡£

   

Ô­ÎÄÁ´½Ó£º

https://honeywellprocess.blob.core.windows.net/public/Support/Customer/Honeywell-USB-Threat-Report.pdf


2¡¢ÃÀ»ã·áÒøÐÐÔâµ½ºÚ¿Í¹¥»÷£¬²¿Ãſͻ§×ÊÁϱ»ÇÔ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÃÀ¹ú»ã·áÒøÐÐ11ÔÂ2ÈÕÏò¿Í»§·¢Ë͵ÄÊý¾Ýй¶֪ͨ£¬²¿Ãſͻ§µÄÔÚÏßÕË»§ÓÚ2018Äê10ÔÂ4ÈÕÖÁ14ÈÕÆÚ¼äÔ⵽δÊÚȨ½Ó¼û£¬±»ÇÔµÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢×¡Ö·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Õ˺š¢ÕË»§ÀàÐÍ¡¢ÕË»§Óà¶î¡¢º¹ÇàÂòÂô¼Í¼¡¢ÊÕ¿îÈËÕË»§ÐÅÏ¢µÈ ¡ £»ã·áÒøÐаµÊ¾ËùÓÐÊÜÓ°ÏìµÄ¿Í»§¶¼½«»ñµÃÃâ·ÑµÄÐÅÓþ¼à¿ØºÍÉí·Ý͵ÇÔ± £»¤·þÎñ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/hsbc-bank-breached-again-suspends-online-access-to-affected-accounts-523620.shtml


3¡¢×êÑÐÈËÔ±ÖÒ¸æ³ÆICSÉ豸Ò×ÊܱßÐÅ·¹¥»÷µÄÓ°Ïì

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÈËÔ±Demos AndreouÔÚICSÍøÂ簲ȫ´ó»áÉÏÖÒ¸æ³Æ±ßÐÅ·¹¥»÷¿ÉÄܶÔICSϵͳ×é³ÉÑϳÁµÄÍþв ¡£Æ¾¾ÝAndreou¶ÔÅäµçϵͳ³£Óõı £»¤É豸µÄ×êÑУ¬ÓµÓÐÎïÀí½Ó¼ûȨÏ޵Ĺ¥»÷ÕßÄܹ»Í¨¹ýʾ²¨Æ÷ºÍÔËÐпªÔ´Èí¼þµÄרÓÃÓ²¼þÉ豸À´»ñÈ¡¼ÓÃÜÃÜÔ¿£¬´ËÀ๥»÷ËùÐèµÄÓ²¼þ³É±¾Ô¼Îª300ÃÀÔª ¡£×êÑÐÈËÔ±·¢ÏÖÈý¼ÒÖØÒª¹©¸øÉ̵ÄÉ豸¶¼´æÔÚ·çÏÕ£¬ÓÉÓÚÕâЩÉ豸ÓÃÓÚ± £»¤µçÍø£¬Òò¶øÕâÖÖ¹¥»÷¿ÉÄÜ»áÔì³ÉÑϳÁµÄºó¹û ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/ics-devices-vulnerable-side-channel-attacks-researcher


4¡¢×êÑÐÈËÔ±ÖÒ¸æ·ÂÕÕÑ¡¾ÙÐÅÏ¢ÍøÕ¾µÄ´¹µöÍøÕ¾VOTE411.com

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



×êÑÐÈËÔ±Amanda RousseauºÍLukas Stefanko·¢ÏÖÓÃÓÚ·ÂÕÕÑ¡¾ÙÐÅÏ¢ÍøÕ¾VOTE411.orgµÄ´¹µöÚ¿Æ­ÍøÕ¾vote411[.]com ¡£Ëæ×ÅÃÀ¹úÖÐÆÚÑ¡¾ÙµÄÁÚ½ü£¬·¸×ï·Ö×ÓÔ½À´Ô½¶àµØÕë¶ÔÑ¡Ãñ½øÐд¹µö¹¥»÷ ¡£¸Ã´¹µöÍøÕ¾»á½«macOSºÍiOSƽ̨µÄÓû§³Á¶¨ÏòÖÁÒ»¸öÐéαµÄ¶ñÒâÈí¼þϰȾ¾¯±¨Ò³Ã棬ÕâÊÇÒ»¸öµäÐ͵ļ¼ÊõÖ§³ÖȦÌ×£¬ÖØÒªÓÃÓÚÓÕʹÓû§¶©ÔĶÌÕÛ·þÎñ»òÆ­ÊØÐÅÓþ¿¨ÐÅÏ¢ ¡£ÈôÊÇ´ÓWindows»òAndroid½Ó¼û¸ÃÍøÕ¾£¬Ôò»á±»³Á¶¨ÏòÖÁ·ÖÆçµÄ´¹µöÍøÕ¾ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/scammers-ride-on-voter-info-website-popularity-to-push-scareware-alerts/


5¡¢¿ªÔ´Á÷ýÌå·þÎñÆ÷Icecast°ä²¼°²È«¸üУ¬½¨¸´Ò»¸öRCE·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÈËÔ±·¢ÏÖ¿ªÔ´Á÷ýÌå·þÎñÆ÷Icecast´æÔÚÒ»¸ö·ì϶£¬¿ÉÄܵ¼Ö»ùÓÚ¸ÃÈí¼þµÄÍøÂç¹ã²¥µç̨±ÀÀ£ ¡£¸Ã·ì϶£¨CVE-2018-18820£©ÊÇÒ»¸öÓësprintfº¯ÊýÓйصĻº³åÇøÒç¶Âí½Å£¬¹¥»÷Õß¿ÉÄÜÀûÓöñÒâµÄ³¬³¤HTTPÍ·´¥·¢¸Ã·ì϶£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´Ðлò»Ø¾ø·þÎñ ¡£IcecastÔÚ11ÔÂ1ÈÕ°ä²¼µÄа汾2.4.4Öн¨¸´Á˸÷ì϶ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/security-bug-puts-online-radio-stations-at-risk/


6¡¢×êÑÐÍŶÓÅû¶Sophos HitmanPro.AlertÖеĶà¸ö°²È«·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


˼¿ÆTalosÍŶÓÅû¶Sophos HitmanPro.AlertÖеĶà¸ö°²È«·ì϶ ¡£HitmanPro.AlertÊÇÒ»¸ö¶ñÒâÈí¼þ¼ì²âºÍ·À»¤¹¤¾ß£¬×êÑÐÈËÔ±·¢Ïֵķì϶ÓëÊäÈëÊä³ö½ÚÔ죨IOCTL£©ÐÂÎÅ´¦Öùý³ÌÓйØ£¬·ì϶£¨CVE-2018-3970£©¿ÉÔÊÐí¹¥»÷Õß¶ÁÈ¡ÄÚºËÄÚ´æÖеÄÄÚÈÝ£¬·ì϶£¨CVE-2018-3971£©¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐкÍÌáȨ ¡£×êÑÐÈËÔ±»¹ÑÝʾÁËÈôºÎÀûÓø÷ì϶¹¹½¨exploitÀ´»ñÈ¡±¾µØSYSTEMȨÏÞ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2018/11/TALOS-2018-0636.html


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù