¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181109
°ä²¼¹¦·ò 2018-11-09
±¾ÖÜÒ»ÃÀ¹úÍøÂç˾Á£¨USCYBERCOM£©µÄÏÂÊôµ¥Ôª¹ú¶ÈÍøÂ繤×÷¶ÓÁУ¨CNMF£©°ä·¢Æô¶¯Ò»¸öÐÂÏîÄ¿£¬ÃÀ¹ú¹ú·À²¿½«Í¨¹ý¸ÃÏîÄ¿Ïò¸ü¿í·ºµÄÍøÂ簲ȫÉçÇø¹²ÏíÆä·¢ÏֵĶñÒâÈí¼þÑù±¾¡£¸ÃÏîĿͨ¹ýÔÚÏßɨÃè·þÎñVirusTotal½øÐУ¬´Ë±íUSCYBERCOM»¹´´½¨ÁËÒ»¸öеÄTwitterÕÊ»§£¨@CNMF_VirusAlert£©£¬ÓÃÓڰ䲼жñÒâÈí¼þÑù±¾µÄVirusTotalÁ´½Ó¡£´Ë¾ÙµÃµ½ÁËÍøÂ簲ȫ½ìµÄÒ»ÖÂºÃÆÀ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/us-cyber-command-starts-uploading-foreign-apt-malware-to-virustotal/2¡¢¾Ýͳ¼Æ2018ÄêǰÈý¼¾¶ÈÒÆ¶¯¶ñÒâÈí¼þ×ÜÊýͬ±ÈÔö³¤40%
ƾ¾Ý°²È«³§ÉÌG DATAµÄͳ¼Æ£¬½ØÖÁ2018ÄêµÚÈý¼¾¶ÈÄ©£¬G DATAµÄ·ÖÎöʦÒѾ·¢ÏÖÁËÔ¼320Íò¸öÒÆ¶¯¶ñÒâÈí¼þÑù±¾£¬ÓëÈ¥ÄêͬÆÚÏà±È£¨2017ÄêǰÈý¼¾¶ÈµÄÊý¾ÝÊÇÔ¼220Íò¸öÒÆ¶¯¶ñÒâÈí¼þÑù±¾£©£¬Ôö³¤ÁË40%¡£ÍøÂç·¸×ï·Ö×ÓÔ½À´Ô½¹Ø×¢Òƶ¯É豸£¬ÓÈÆäÊÇAndroidÉ豸£¬ÆäÔÒòÊÇÈ«Çò¼«¶ÈÖ®°ËµÄÈ˶¡¶¼ÔÚʹÓøÃϵͳ¡£ÕâҲʹµÃÒÆ¶¯É豸ÉϵݲȫԽÀ´Ô½³ÁÒª¡£
ÔÎÄÁ´½Ó£º
https://www.gdatasoftware.com/blog/2018/11/31255-cyber-attacks-on-android-devices-on-the-rise
3¡¢×êÑÐÍŶӷ¢ÏÖ2018Äê9Ô·ÝÀÕË÷Èí¼þ¹¥»÷ÊýÁ¿ìÉý
BBR¹«Ë¾µÄ×êÑÐÍŶӷ¢ÏÖ2018Äê9Ô·ÝÀÕË÷Èí¼þ¹¥»÷µÄÊýÁ¿ÔÙ´ÎìÉý£¬Ïà±È8Ô·ÝÔö³¤ÁËÒ»±¶ÒÔÉÏ¡£Ä¿Ç°Éв»Ã÷ÏÔÕâÒ»Ç÷ÏòÊÇ·ñ»áÒ»Á¬ÏÂÈ¥¡£ÔÚ9Ô·Ý֮ǰ£¬2018ÄêµÄÀÕË÷Èí¼þ¹¥»÷Óë2017Äêά³ÖÏà¶Ô²»±ä£¬Ò½ÁƱ£½¡ÐÐÒµÈÔ¾ÉÊÇ×î±»Õë¶ÔµÄÐÐÒµ£¨37%£©¡£ÔÚµÚÈý¼¾¶È£¬½ðÈÚÐÐÒµÔâµ½µÄÀÕË÷Èí¼þ¹¥»÷Ïà±ÈÉÏÒ»¼¾¶ÈÔö³¤ÁË18¸ö°Ù·Öµã¡£ÀÕË÷Êê½ð×î¸ßµÄÀÕË÷Èí¼þÊÇRyukºÍBitPaymer¡£Æ¾¾Ý¸Ã¹«Ë¾µÄÊý¾Ý£¬ÔÚ2018ÄêµÄǰ9¸öÔ£¬71%µÄÀÕË÷Èí¼þ¹¥»÷ÖØÒªÕë¶ÔÖÐÓ×ÐÍÆóÒµ¡£
ÔÎÄÁ´½Ó£º
https://www.beazley.com/news/2018/beazley_breach_insights_october_2018.html4¡¢nginx¿ª·¢ÍŶӰ䲼°²È«¸üУ¬½¨¸´¶à¸ö·ì϶
¿ªÔ´Web·þÎñÆ÷nginxÔÚ11ÔÂ6Èհ䲼а汾1.15.6ºÍ1.14.1£¬½¨¸´Ö®Ç°°æ±¾ÖеĶà¸ö°²È«·ì϶¡£ÆäÖÐÔ̺¬ÄÚ´æºÄ¾¡·ì϶£¨CVE-2018-16843£©ºÍCPUºÄ¾¡·ì϶£¨CVE-2018-16844£©£¬¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÔìµÄHTTP/2ÒªÇóµ¼Ö»ؾø·þÎñÇé¿ö¡£´Ë±í£¬¿ª·¢ÍŶӻ¹½¨¸´ÁËMP4Ä£¿éÖеÄÄÚ´æÐ¹Â©·ì϶£¨CVE-2018-16845£©¡£Æ¾¾ÝNetcraftµÄͳ¼Æ£¬½ØÖÁ2018Äê10Ô·ÝÔ¼ÓÐ25.28%µÄ´óÐÍÍøÕ¾ÊÇ»ùÓÚnginxµÄ¡£½¨ÒéÍøÕ¾ÖÎÀíÔ±¾¡¿ì½øÐиüС£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/nginx-security-issues-expose-more-than-14-million-servers-to-dos-attacks-523659.shtml5¡¢¼íÆÒÕ¯¶à¼ÒISPÔâµ½¸Ã¹úº¹ÇàÉÏ×î´ó¹æÄ£µÄDDoS¹¥»÷
±¾ÖܼíÆÒÕ¯×î´óµÄ¼¸¼Ò»¥ÁªÍø·þÎñÌṩÉÌ£¨ISP£©Ôâµ½ÁË´ó¹æÄ£µÄDDoS¹¥»÷£¬Ô̺¬EZECOM¡¢SINET¡¢TelcotechºÍDigi¡£¾Ý±¾µØÃ½Ì屨·£¬Õâ´ÎDDoS¹¥»÷ÊǸùúº¹ÇàÉÏ×î´ó¹æÄ£µÄ¹¥»÷Ö®Ò»£¬±¾ÖÜÒ»µÄDDoS¹¥»÷Á÷Á¿´ï½ü150Gbps¡£¹ØÓÚÕâ´Î¹¥»÷µÄÔÒòºÍ¶¯»úÉв»Ã÷ÏÔ£¬Ò²Ã»Óй¥»÷ÕßÐû³Æ¶Ô´ËÕÆ¹Ü¡£Ò»ÖÖ¿ÉÄܵÄÇé¿öÊÇISP¾ºÕùµÐÊÖÖ®¼äµÄÏ໥¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/cambodias-isps-hit-by-some-of-the-biggest-ddos-attacks-in-the-countrys-history/6¡¢×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓÃcookie½Ù³Ö´ó½®ÎÞÈË»úÕË»§
Check Point×êÑÐÈËÔ±·¢ÏÖ´ó½®ÎÞÈË»ú´æÔÚ°²È«·ì϶£¬¿Éµ¼ÖÂÓû§ÕÊ»§±»½Ù³Ö£¬½ø¶øµ¼ÖÂÎÞÈË»ú·ÉÐÐ×ÊÁϵÈÐÅÏ¢¿É±»¹¥»÷Õß½Ó¼û¡£¸Ã·ì϶µÄÔÒòÊÇ´ó½®ÔÚ¶à¸öƽ̨ÉÏʹÓÃÁËÒ»ÑùµÄcookie£¬Ô̺¬ÔÚÏßÂÛ̳¡¢Òƶ¯APPºÍWeb app DJI FlightHub¡£×êÑÐÈËԱͨ¹ýÔÚ´ó½®ÂÛ̳ÉÏÖ´ÐÐXSS¹¥»÷£¬³É¹¦µØÇÔÈ¡ÁËÓû§µÄcookie£¬½ø¶øÄܹ»Í¨¹ý¸ÃcookieµÇ¼ÆäËüƽ̨½Ó¼ûÓû§µÄ×ÊÁÏ¡£´ó½®°µÊ¾ÒѾ½¨¸´Á˸÷ì϶¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/dji-drone-flight-logs-photos-and-videos-exposed-to-unauthorized-access/ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ