¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190306
°ä²¼¹¦·ò 2019-03-06
ƾ¾Ý΢ÈíµÄ°²È«µý±¨»ã±¨£¨SIR£©Volume 24£¬ÔÚ2018Äê1ÔÂÖÁ12ÔÂÆÚ¼ä£¬ÍøÂç´¹µö¹¥»÷Ôö³¤ÁË250%¡£¹¥»÷ÕßÔÚÔËÓªÍøÂç´¹µö»î¶¯Ê±Ñ¡È¡¶àÑù»¯µÄ»ù´¡ÉèÊ©£¬Ô̺¬ÍйܷþÎñÆ÷ºÍ¹«¹²ÔƵȡ£ÁíÒ»·½Ã棬2018ÄêÆÚ¼ä¶ñÒâÈí¼þµÄÊýÁ¿½µÂäÁËÔ¼34%¡£´Ë±í£¬Ëæ×Å2018ÄêËêĺ¼ÓÃÜÇ®±Ò¼ÛÖµµÄ×ÅÂ䣬¶ñÒâÍÚ¿ó»î¶¯Ò²½µÂäÁË36%¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-sees-250-percent-phishing-increase-malware-decline-by-34-percent/2¡¢APWG°ä²¼´¹µö¹¥»÷»ã±¨£¬¹¥»÷ÕßתÏòÕë¶ÔSaaSºÍÓÊÏä·þÎñ
ƾ¾ÝAPWGµÄд¹µö¹¥»÷»ã±¨£¬2018ÄêÍøÂç´¹µöÕ¾µãµÄÊýÁ¿²»ÐݽµÂ䣬Q4¼ì²âµ½µÄ´¹µöÕ¾µãÊýÁ¿Îª138328£¬±ÈQ3µÄ151014ÒªµÍ£¬¶øQ2ÊÇ233040£¬Q1ÊÇ263538¡£Õë¶ÔSaaSºÍWebmail·þÎñµÄ´¹µö¹¥»÷´ÓQ3µÄ20.1£¥Ôö³¤ÖÁQ4µÄ½ü30£¥£¬¶øÕë¶ÔÔÆ´æ´¢ºÍÎļþÍйÜÕ¾µãµÄ¹¥»÷Ôò³ÖÐø½µÂ䣬´ÓQ1µÄ11.3£¥½µÂäÖÁQ4µÄ4%¡£´Ë±í£¬Ê¹ÓÃSSLµÄ´¹µöÕ¾µãÔÚQ4ÂÔÓнµÂ䣬µ«ÈÔÓÐ47%¡£
ÔÎÄÁ´½Ó£º
https://www.marketwatch.com/press-release/apwg-report-phishers-shift-efforts-to-attack-saas-and-webmail-services-2019-03-043¡¢2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾ÖУ¬WordPressÕ¼90%
ƾ¾ÝSucuriµÄÒ»·Ýµ÷²é»ã±¨£¬ÔÚ2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾µÄCMSÉ¢²¼ÖУ¬WordPressÒ£Ò£µ±ÏÈ£¬Õ¼90%£¬¶þÈýËÄÃû±ðÀëÊÇMagento£¨4.6£¥£©¡¢Joomla£¨4.3£¥£©ºÍDrupal£¨3.7£¥£©¡£68%µÄÊÜÏ°È¾ÍøÕ¾±»Ö²ÈëÁ˺óÃÅ£¬56%µÄÊÜÏ°È¾ÍøÕ¾ÍйÜÁËÆäËü¶ñÒâÈí¼þ¡£´Ë±í£¬51%µÄÊÜÏ°È¾ÍøÕ¾±»²¿ÊðÁËSEOÀ¬»øÐÅÏ¢Ò³Ãæ£¬2017ÄêÕâÒ»Êý×ÖÊÇ44%¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/wordpress-accounted-for-90-percent-of-all-hacked-cms-sites-in-2018/4¡¢ÐÂÀÕË÷Èí¼þ¼´·þÎñJokerooÔÚ°µÍøÊг¡ÉÏÍÆ¹ã
×êÑÐÈËÔ±Damian·¢ÏÖJokeroo RaaSÔÚ°µÍøÂÛ̳Exploit.inºÍTwitterÉϽøÐÐÍÆ¹ã¡£·¸×ï·Ö×Ó±ØÐëÏÈÖ§¸¶¿Ï¶¨µÄ½ð¶îÄÜÁ¦³ÉΪ»áÔ±£¬ÕâЩ»áÔ±µÄÌײͼÛÖµ´Ó90ÃÀÔªµ½300¡¢600ÃÀÔª²»µÈ¡£ÆäÒDZíÅÌÒ³ÃæµÄÊý¾ÝÏÔʾ¸ÃRaaSÒѾϰȾÁË923¸öÊܺ¦Õß²¢ÇÒ»ñµÃÁË7.13¸ö±ÈÌØ±ÒµÄÊê½ð£¬µ«BleepingComputerÒÔΪÕâЩֻÊDzâÊÔÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/jokeroo-ransomware-as-a-service-offers-multiple-membership-packages/5¡¢Outdoor Tech»¬Ñ©Í·¿ø¶à¸ö·ì϶£¬¿Éµ¼ÖÂÓû§ÐÅϢй¶

Pen Test PartnersµÄ×êÑÐÈËÔ±ÔÚOutdoor Tech CHIPS»¬Ñ©Í·¿øµÄÖÇÄܶú»úÖз¢ÏÖ¶à¸ö°²È«·ì϶£¬¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶ÇÔȡָ±êÓû§µÄÓ×ÎÒÐÅÏ¢£¬Ô̺¬ËûÃǵĵç×ÓÓʼþ¡¢ÃÜÂë¡¢GPSµØÎ»Êý¾ÝµÈ£¬ÉõÖÁÄܹ»ÇÔÌýËûÃǵĸöÈË·¢ÑÔ¡£Outdoor Tech¹«Ë¾²¢Î´¶ÔÓйØÎÊÌâ×÷³ö»ØÓ¦¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/smart-ski-helmet-headphone-flaws-leak-personal-gps-data/142456/6¡¢×êÑÐÈËÔ±Åû¶ÂÞ¼¼Harmony HubÖеÄ4¸ö°²È«·ì϶
Tenable Network SecurityµÄ×êÑÐÈËÔ±Joseph BinghamÔÚBSides SF 2019°²È«»áÒéÉÏÅû¶ÁËÂÞ¼¼Harmony HubÖеÄ4¸ö·ì϶µÄÓйؼ¼Êõϸ½Ú¡£Harmony HubÊÇÒ»¸öÖÇÄܼҾÓÉ豸£¬¿É×÷Ϊ¼ÒÍ¥Éú̬ϵͳµÄÖÐÐÄÀ´ÏνÓÉãÏñÍ·¡¢ÕÕÃ÷¡¢¹©Å¯¡¢ÃÅËøµÈÆäËüÉ豸¡£ÕâЩ·ì϶Ô̺¬Ä¬ÈÏÍ´´¦·ì϶£¨CVE-2018-15720£©¡¢Éí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2018-15721£©ÒÔ¼°ºÅÁî×¢Èë·ì϶£¨CVE-2018-15722ºÍCVE-2018-15722£©£¬¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶»ñµÃLogitechÉ豸µÄÆëÈ«½ÚÔìȨ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/remote-root-bug-logitech-harmony-hub/142488/ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ