¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181114
°ä²¼¹¦·ò 2018-11-14
ƾ¾ÝGemini Advisory°ä²¼µÄÃÀ¹úÐÅÓþ¿¨Ú²Æ»ã±¨£¬Ö»¹Ü2015ÄêÃÀ¹ú½ðÈÚÒµ¾ÍÒÑ´ó¹æÄ£Ç¨áãµ½EMVоƬ¿¨³ß¶È£¬µ«ÔÚ´Óǰ12¸öÔÂÄÚÈÔÓÐ6000ÍòÕÅÐÅÓþ¿¨µÄÐÅÏ¢±»ÇÔ¡£ÆäÖÐ4580Íò£¨75%£©µÄÐÅÓþ¿¨ÐÅÏ¢ÊÇͨ¹ýPoS»úÉϵÄʵ¿¨ÂòÂô±»ÇԵģ¬Ö»ÓÐ25%µÄÐÅÓþ¿¨ÐÅÏ¢±»ÔÚÏßÇÔÈ¡¡£ÕâЩʵ¿¨ÖÐ90%ÊÇEMV¿¨¡£´Óǰ12¸öÔÂÄÚºµç×ÓÉÌÎñÖб»ÇÔµÄÐÅÓþ¿¨ÊýÁ¿Ôö³¤ÁË14%£¬ÕâÒâζÕß·¸×ï·Ö×ÓÔÚ´Óʵ¿¨ÂòÂôתÏòÎÞ¿¨Ú²Æ¡£
ÔÎÄÁ´½Ó£º
https://geminiadvisory.io/card-fraud-on-the-rise/2¡¢RiskIQºÍFlashpoint½áºÏ°ä²¼¹ØÓÚMagecart¹¥»÷µÄ·ÖÎö»ã±¨
ƾ¾ÝRiskIQºÍFlashpoint½áºÏ°ä²¼µÄ¡¶Magecart¹¥»÷¶´²ì¡·»ã±¨£¬MagecartÊÇÖÁÉÙ7¸öÍøÂç·¸×ïÍÅ»ïµÄ×ܳơ£Magecart¹¥»÷ͨ¹ýÔÚµç×ÓÉÌÎñÍøÕ¾ÉÏÖ²Èë¶ñÒâ½ÅÕý±¾ÇÔÈ¡Óû§µÄÐÅÓþ¿¨ÐÅÏ¢£¬ÊýÊ®¸öÈ«Çò³ÛÃûÆ·ÅÆµÄµç×ÓÉÌÎñÍøÕ¾¶¼ÊÇËüµÄÊܺ¦Õߣ¬Ô̺¬Ticketmaster¡¢British AirwaysÒÔ¼°Ðµ°µÈ¡£×êÑÐÈËÔ±Ôڻ㱨Öй¹½¨ÁËMagecart¹¥»÷µÄ¹¦·òÏߣ¬²¢³Áµã½éÉÜÁËËüÃǵĶñÒâ¾ç±¾¡¢¹¥»÷Õ½ÊõÒÔ¼°Ö¸±êÑ¡ÔñµÈÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.riskiq.com/blog/external-threat-management/inside-magecart/3¡¢×êÑÐÍŶӷ¢ÏÖÕë¶Ô°Í»ù˹̹µÄÐÂAPT×éÖ¯The White Company
Cylance×êÑÐÍŶӷ¢ÏÖÒ»¸öÖØÒªÕë¶Ô°Í»ù˹̹µ±¾ÖºÍ¾ü¶ÓµÄÐÂAPT×éÖ¯The White Company£¨°×É«¹«Ë¾£©¡£¸ÃAPT×éÖ¯ËÆºõÊÇÓɹú¶ÈÔÞÖúµÄ£¬Æä´ó¹æÄ£¼äµý»î¶¯±»³ÆÎªOperation Shaheen£¨É³ÐÀÐж¯£©¡£The White CompanyʹÓÃÁ˶àÖÖ¸´ÔӵIJ½ÖèÀ´ÌӱܹéÒò£¬ÀýÈçÌӱܷÀ²¡¶¾Èí¼þ¼ì²â¡¢×ÔÎÒ¸²ÃðºÍ¶Ï¸ùºÛ¼£ÒÔ¼°ÓÐÒâÁôÏÂÏ໥ì¶ÜµÄÖ¤¾ÝµÈ¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/the-white-company-a-new-state-sponsored-apt-discovered-by-cylance-523745.shtml
4¡¢×êÑÐÍŶӰ䲼¹ØÓÚжñÒâÍÚ¿óÈí¼þWebCobraµÄ·ÖÎö»ã±¨
McAfee³¢ÊÔÊÒµÄ×êÑÐÈËÔ±·¢ÏÖÒ»¸öжíÂÞ˹¶ñÒâÈí¼þWebCobra£¬WebCobra»áƾ¾ÝËùϰȾµÄϵͳ¼Ü¹¹µÄ·ÖÆç×°ÖÃ·ÖÆçµÄ¶ñÒâÍÚ¿óÈí¼þ£¬Ô̺¬Cryptonight£¨x86£©ºÍClaymore Zcash£¨x64£©¡£×êÑÐÈËÔ±ÒÔΪÕâÖÖ¶ñÒâÈí¼þÊÇͨ¹ýDZÔÚÓк¦µÄ·¨Ê½£¨PUP£©·Ö·¢µÄ£¬ÆäϰȾÁìÓò±é²¼È«Çò£¬µ«ÖØÒªÊÇÔÚ°ÍÎ÷¡¢ÄϷǺÍÃÀ¹ú¡£
ÔÎÄÁ´½Ó£º
https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/webcobra-malware-uses-victims-computers-to-mine-cryptocurrency/5¡¢×êÑÐÈËÔ±ÔÚGoogle PlayÉÏ·¢ÏÖ°µ²ØÒ»ÄêÖ®¾ÃµÄ¶ñÒâͨ»°¹àÒôapp
°²È«×êÑÐÈËÔ±Lukas StefankoÔÚGoogle PlayÉÏ·¢ÏÖÒ»¸ö¶ñÒâµÄͨ»°¹àÒôapp£¬¸Ãapp×Ô2017Äê11ÔÂ30ÈÕÆðÔÚGoogle PlayÉÏ¿ÉÓã¬ÒѰµ²ØÁËÔ¼Ò»ÄêµÄ¹¦·ò£¬ÆäÏÂÔØ´ÎÊý³¬¹ý5000´Î¡£¸Ã¶ñÒâapp»á´Óhttp://adsmserver[.]club/up/update.apk£¨¸ÃÁ´½ÓĿǰÒѱ»É¾³ý£©ÏÂÔØÒ»¸öÐéαµÄFlash Player¸üУ¬²¢ºýŪÓû§½øÐÐ×°Öá£ÓÉÓÚÓÐЧºÉÔØÒѲ»³ÉÓã¬×êÑÐÈËԱδÄܽøÇ°½øÒ»²½µÄ·ÖÎö¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/trojanized-android-app-found-on-google-play-with-more-than-5-000-installs-523743.shtml6¡¢Î¢Èí°ä²¼11Ô°²È«¸üУ¬½¨¸´64¸ö·ì϶
΢Èí°ä²¼11Ô·ݵݲȫ¸üУ¬¹²½¨¸´64¸ö·ì϶£¬ÆäÖÐÔ̺¬12¸ö¸ßΣ·ì϶¡£ÆäÖÐÓÉ¿¨°Í˹»ù³¢ÊÔÊһ㱨µÄÁãÈÕ·ì϶£¨CVE-2018-8589£©Òѱ»¹¥»÷ÕßÔÚÒ°±í»ý¼«ÀûÓ᣸÷ì϶ÊÇÒ»¸öÌáȨ·ì϶£¬ÓëWindowsÉ豸Çý¶¯·¨Ê½Win32k.sysÓйء£¿¨°Í˹»ù´òËãÓÚÖÜÈý°ä²¼¹ØÓڸ÷ì϶±»APT×éÖ¯»ý¼«ÀûÓõĸü¶àÐÅÏ¢¡£¾ßÌå·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-november-2018-patch-tuesday-fixes-12-critical-vulnerabilities/ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ