¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181107
°ä²¼¹¦·ò 2018-11-07
¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼2018ÄêµÚÈý¼¾¶ÈÀ¬»øÓʼþºÍÍøÂç´¹µö»î¶¯µÄÇ÷Ïò·ÖÎö»ã±¨¡£ÔÚ2018ÄêQ3£¬À¬»øÓʼþռȫÇòÓʼþ×ÜÁ¿ÖеıÈÀýÔö³¤ÁË2.88¸ö°Ù·Öµã£¬´ï52.54%¡£·´´¹µöϵͳ¹²×èÖ¹Á˳¬¹ý1.37ÒÚ¸öÌø×ªÖÁ´¹µöÍøÕ¾µÄ³Á¶¨Ïò£¬±ÈÉÏÒ»¼¾¶ÈÔö³¤ÁË3000Íò¡£À¬»øÓʼþºÍ´¹µö»î¶¯³ÖÐøÀûÓñ¾¼¾¶ÈµÄ³Á´óÐÂÎű¨Â·À´´«²¼£¬ÀýÈçÐÂiPhoneµÄ°ä²¼¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/spam-and-phishing-in-q3-2018/88686/2¡¢×êÑÐÍŶӷ¢ÏÖÀûÓÃÐéαTelegram¼à¶½ÒÁÀÊÓû§µÄ¶ñÒâ»î¶¯
˼¿ÆTalosÅû¶ÁËÒÁÀʵÄһЩÓɹú¶ÈÔÞÖúµÄ¶ñÒâ»î¶¯£¬ÕâЩ»î¶¯×Ô2017ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬ÖØÒªÓÃÓڼලÒÁÀʵÄÔ¼4000ÍòTelegramÓû§£¨¹ÌÈ»¸ÃÀûÓÃÏÖʵÉÏÔڸùú±»²»ÈÝʹÓã©¡£Talos³ÆÕâЩ»î¶¯µÄ¸´ÔÓÐÔ¡¢×ÊÔ´ÐèÒªºÍ²½Öè¸÷²»Ò»Ñù£¬µ«ÖØÒªÊ¹ÓÃÁËÈý¸öÔØÌ壺ÐéαÀûÓᢴ¹µöµÇÂ¼Ò³ÃæºÍBGP½Ù³Ö¡£ÕâЩÐéαTelegram¡°¿Ë¡Ì塱Ӧ¸Ã±»¹éÀàΪ»ÒÉ«Èí¼þ»òDZÔÚÓꦵÄÈí¼þ£¨PUP£©¡£¹ÌÈ»ÕâЩ¶ñÒâ»î¶¯¶¼Õë¶ÔÒÁÀÊ£¬µ«×êÑÐÈËÔ±²¢Î´·¢ÏÖËüÃÇÖ®¼ä´æÔÚÁªÏµ¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2018/11/persian-stalker.html3¡¢·¸×ïÍÅ»ïInceptionÀûÓÃÐÂPowerShellºóÃŶÔ׼ŷÖÞ
Palo Alto NetworksµÄUnit42°ä²¼¹ØÓÚ·¸×ïÍÅ»ïInceptionµÄй¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£InceptionÖÁÉÙ×Ô2014ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬¸Ã×éÖ¯ÔøÔÚ2017ÄêÕë¶ÔÅ·ÖÞ¡¢¶íÂÞ˹ºÍÖÐÑǵØÓòÈ·µ±¾Ö»ú¹¹ÌáÒé¹¥»÷¡£Unit42¹Û²ìµ½¸Ã×éÖ¯ÔÚ2018Äê10ÔÂʹÓÃOffice·ì϶CVE-2017-11882ºÍÒ»¸öеÄPowerShellºóÃÅÕë¶ÔÅ·ÖÞµÄÖ¸±êÌáÒé¹¥»÷¡£¸ÃºóÃű»³ÆÎªPOWERSHOWER£¬¿ÉÓÃÓÚÍøÂçϵͳÐÅÏ¢²¢ÉÏ´«ÖÁC2·þÎñÆ÷ÒÔ¼°¶Ï¸ùÖ¤¾Ý£¬»¹¿ÉÓÃÓÚÖ´ÐÐÆäËüpayload¡£
ÔÎÄÁ´½Ó£º
https://researchcenter.paloaltonetworks.com/2018/11/unit42-inception-attackers-target-europe-year-old-office-vulnerability/4¡¢×êÑÐÈËÔ±·¢ÏÖ¶à¿î×Ô¼ÓÃÜSSD´æÔÚ·ì϶£¬¿ÉÔÊÐí¹¥»÷Õß½âÃÜÓû§Êý¾Ý
ºÉÀ¼Radboud´óѧµÄ×êÑÐÈËÔ±Carlo MeijerºÍBernard van Gastel·¢ÏÖ¶à¿îÊ¢ÐеÄ×Ô¼ÓÃÜSSD´æÔÚ°²È«·ì϶£¬¿ÉÔÊÐí¹¥»÷Õß½âÃÜ´ÅÅ̺ͻñÈ¡Óû§Êý¾Ý¡£ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬CrucialµÄCruces MX100ºÍÈýÐǵÄ850 EVOµÈ¡£CrucialÒѾΪÆäËùÓÐÊÜÓ°ÏìµÄSSD°ä²¼Á˹̼þ²¹¶¡£¬µ«ÈýÐÇֻΪT3ºÍT5±ãЯʽSSD°ä²¼Á˽¨¸´²¹¶¡£¬²¢½¨ÒéEVOÓû§Ê¹ÓÃÓëϵͳ¼æÈݵļÓÃÜÈí¼þ¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/11/self-encrypting-ssd-hacking.html5¡¢Google°ä²¼11ÔÂAndroid°²È«¸üУ¬½¨¸´¶à¸ö·ì϶
GoogleÔÚ11Ô·ݵÄAndroid°²È«¸üÐÂÖн¨¸´ÁË36¸ö°²È«·ì϶£¬´Ë±í»¹ÓÐ17¸ö·ì϶ÓëQualcomm×é¼þÓйء£½ÏÑϳÁµÄ·ì϶Ô̺¬Ó°ÏìAndroid 7.0+µÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-9527£©ºÍÓ°Ïì9.0µÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-9531ºÍCVE-2018-9521£©¡£ÓÉÓÚÔÚLibxaac¿âÖз¢ÏÖ´óÁ¿°²È«·ì϶£¬Òò¶øGoogleÒѽ«¸Ã¿âÏóÕ÷Ϊ³¢ÊÔÐÔ²¢ÇÒ²»»á½«¸Ã¿âÔ̺¬ÔÚÖ°ºÎAndroid³ö²ú°æ±¾ÖС£´Ë±í£¬11Եݲȫ¸üнöºÏÓÃÓÚAndroid7.0+µÄ°æ±¾£¬»»¾ä»°Ëµ£¬Android 6.x½«²»Ôٵõ½GoogleµÄÖ§³Ö¡£
ÔÎÄÁ´½Ó£º
https://source.android.com/security/bulletin/2018-11-01.html6¡¢Akado TelecomÒâ±íй¶ÊýǧÃû¿Í»§µÄÓ×ÎÒÐÅÏ¢
¾Ý·͸É籨·£¬¶íÂÞ˹ISP Akado TelecomÒâ±íµØ½«ÊýǧÃû¿Í»§µÄÓ×ÎÒÐÅÏ¢ÉÏ´«ÖÁRIPE NCCµÄ·þÎñÆ÷£¬ÕâЩй¶µÄÓ×ÎÒÐÅÏ¢£¨PII£©Öл¹Ô̺¬Ò»Ð©¶íÂÞ˹µ±¾Ö¹ÙÔ±ºÍ¶íÂÞ˹ÃûÈË¡¢ÒøÐй¤×÷ÈËÔ±µÄµØÖ·ºÍµç»°ºÅÂëµÈ¡£RIPE NCCÊÇÅ·ÖÞ¡¢Öж«ºÍÖÐÑDz¿ÃŵØÓòµÄ·ÇͶ»úÐÔÇøÓò»¥ÁªÍø×¢²á»ú¹¹£¬ÆäÊý¾Ý¿âÊǿɹ«¿ª½Ó¼ûµÄ¡£Akado Telecom°µÊ¾ÒѾÆô¶¯ÁËÒ»Ïî¹ØÓÚ´ËÊÂÎñµÄÄÚ²¿µ÷²é¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/akado-telecom-accidentally-leaks-customers-names-phone-numbers-and-addresses-523617.shtmlÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ