FireEye 2019 Q1µç×ÓÓʼþÍþв»ã±¨£¬´¹µö¹¥»÷Ôö³¤17%£»Silex¿ÉÈÃIoTÉ豸±äש£¬ÒÑϰȾ2000¶ą̀É豸
°ä²¼¹¦·ò 2019-06-26
ƾ¾Ý±¾ÖܶþFireEye°ä²¼µÄ2019ÄêµÚÒ»¼¾¶Èµç×ÓÓʼþÍþв»ã±¨£¬Ê¹ÓÃHTTPSµÄ¶ñÒâURL±ÈÀýÔö³¤ÁË26%£¬¶ø´«Í³µÄ¸½¼þΪ¶ñÒâÈí¼þµÄµç×ÓÓʼþÔÚÎȲ½½µÂä¡£»ùÓÚ¶Ô13ÒÚ·âµç×ÓÓʼþµÄ·ÖÎö£¬¸Ã»ã±¨Ö¸³ö2019ÄêµÚÒ»¼¾¶ÈµÄÍøÂç´¹µö¹¥»÷±ÈÉÏÒ»¼¾¶ÈÔö³¤ÁË17%£¬×ܹ²Óнü30%µÄ¹¥»÷ÊÇ·ÂÕÕMicrosoft¡¢OneDrive¡¢Apple¡¢AmazonºÍPayPalµÈ³ÛÃûÆ·ÅÆ¡£´Ë±í£¬Îļþ¹²Ïí·þÎñÔÚÕë¶ÔÆóÒµµÄÍøÂç¹¥»÷Öб»¸üƵÈÔµØÊ¹Óã¬Ô̺¬Google DriveºÍDropbox¡£
ÔÎÄÁ´½Ó£ºhttps://www.fireeye.com/offers/rpt-email-threat.html
2¡¢¶ñÒâÈí¼þOSX/Linker£¬ÀûÓÃmacOSÖÐ佨²¹µÄGatekeeperÈÆ¹ý·ì϶
Intego°²È«×êÑÐÈËÔ±ÖÒ¸æ³ÆÐµĶñÒâÈí¼þOSX/LinkerÔÚÀûÓÃmacOSÖÐ佨¸´µÄGatekeeperÈÆ¹ý·ì϶¡£¸Ã·ì϶¿ÉÔÚ²»ÏòÓû§ÏÔʾÈκÎÖÒ¸æÐÅÏ¢»òÒªÇó»ñµÃÐí¿ÉµÄÇé¿öÏÂÖ´Ðв»ÊÜÐÅÀµµÄ´úÂë¡£OSX/LinkerÉÐδÔÚÒ°±í³öÏÖ£¬×êÑÐÈËÔ±Joshua Long°µÊ¾¸Ã¶ñÒâÈí¼þËÆºõ»¹ÔÚ¿ª·¢ÖУ¬¹ÌÈ»¶ñÒâÑù±¾ÀûÓÃÁË佨²¹µÄGatekeeperÈÆ¹ý·ì϶£¬µ«Ã»Óдӹ¥»÷ÕߵķþÎñÆ÷¸ßµÍÔØÈκζñÒâÀûÓ÷¨Ê½¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/06/macos-malware-gatekeeper.html
3¡¢Ð¶ñÒâÈí¼þSilex¿ÉÈÃIoTÉ豸±äש£¬ÒÑϰȾ2000¶ą̀É豸
Akamai×êÑÐÔ±Larry Cashdollar·¢ÏÖжñÒâÈí¼þSilexÔÚ½øÐй¥»÷£¬¸Ã¶ñÒâÈí¼þ»á²Á³ýIoTÉ豸µÄ¹Ì¼þ£¬É¾³ýÆä´æ´¢¡¢·À»ðǽ¹æ¶¨ÒÔ¼°ÍøÂçÅäÖã¬×îÖÕµ¼ÖÂÉ豸ÖÕ³¡ÔËÐС£ÒªÏ븴ÔÉ豸µÄÔËÐУ¬Êܺ¦Õß±ØÐëÊÖ¶¯³ÁÐÂ×°ÖÃÉ豸¹Ì¼þ¡£¿ÉÄÜ»áÓÐһЩÊܺ¦ÕßÒÔΪÓöµ½ÁËÓ²¼þ¹ÊÕ϶øÅׯúÉ豸¡£¹¥»÷ÆðÔ´ÊÇλÓÚÒÁÀʵķþÎñÆ÷£¬¹¥»÷ÕßÖØÒªÍ¨¹ýÒÑÖªµÄIoTÉ豸ĬÈϵǼʹ´¦»ñµÃ¶ÔÉ豸µÄ½Ó¼û¡£¸Ã¹¥»÷»î¶¯ÈÔÔÚ½øÐÐÖУ¬ÒÑÓг¬¹ý2000̨É豸±»±äש¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/new-silex-malware-is-bricking-iot-devices-has-scary-plans/
4¡¢ÐÂÀ¬»øÓʼþ»î¶¯£¬ÀûÓÃISOÎļþ´«²¼LokiBotºÍNanocore
Netskope×êÑÐÈËÔ±ÔÚ4Ô·ݹ۲쵽¶à¸ö¶ñÒâ¹¥»÷»î¶¯ÀûÓÃISO¾µÏñÎļþ´«²¼LokiBotºÍNanocore£¬ÕâЩISOÎļþ×ã¹»Ó×£¬ÒÔÖÁÓÚÄܹ»·ÅÈëµç×ÓÓʼþµÄ¸½¼þÖС£Í¨³£Çé¿öÏÂISOÎļþÒª´óÓÚ100MB£¬µ«¹¥»÷»î¶¯ÖеÄISOÎļþµÄ´óÓ×´Ó1MBµ½2MB²»µÈ¡£´Ó¹¥»÷ÕߵĽǶÈÀ´¿´£¬Ê¹ÓÃISOÎļþºÜÓÐÒâ˼£¬ÓÉÓÚ´óÎÞÊýÏÖ´ú²Ù×÷ϵͳÄܹ»ÔÚÓû§½Ó¼û¾µÏñʱ×Ô¶¯¹ÒÔØ¾µÏñ²¢ÏÔʾÆäÄÚÈÝ¡£´Ë±í£¬³öÓÚ»úÄÜÔÒò£¬Ò»Ð©°²È«½â¾ö¹æ»®Æ«²îÓÚ½«ISOÎļþÁÐÈë°×Ãûµ¥£¬´Ó¶øÊ¹ËüÃDz»Ò×±»¼ì²â¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/malspam-campaigns-hide-infostealers-in-iso-image-files/
5¡¢·ÆÄá¿Ë˹µçÆø½¨¸´AutomationworxÌ×¼þÖеĶà¸ö·ì϶
µÂ¹ú·ÆÄá¿Ë˹µçÆø£¨Phoenix Contact£©½¨¸´Automationworx×Ô¶¯»¯Ì×¼þÖеĶà¸ö·ì϶£¬Ô̺¬Ö¸Õëδ³õʼ»¯·ì϶£¨CVE-2019-12870£©¡¢use-after-free·ì϶£¨CVE-2019-12871£©ºÍÔ½½ç¶Á·ì϶£¨CVE-2019-12869£©¡£ÊÜÓ°ÏìµÄ°æ±¾Ô̺¬PC Worx 1.86¼°Ö®Ç°°æ±¾¡¢PC Worx Express 1.86¼°Ö®Ç°°æ±¾ºÍConfig+ 1.86 ¼°Ö®Ç°°æ±¾¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/flaws-phoenix-contact-automationworx-allow-code-execution-malicious-files
6¡¢ABB½¨¸´×Ô¶¯»¯ÏµÍ³HMIÖеÄÊ®¶à¸ö·ì϶
DarkMatter xen1thLabs×êÑÐÍŶӷ¢ÏÖÈðÊ¿¹¤Òµ¼¼Êõ¹«Ë¾ABBµÄHMI²úÆ·ÖеÄ12¸ö·ì϶£¬ÕâЩ·ì϶¿Éµ¼ÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡¢ËÁÒâ´úÂëÖ´ÐкÍÐÅϢй¶µÈ¡£·ì϶ÁìÓòº¸Ç¹ýÆÚµÄÈí¼þ×é¼þ¡¢Ó²±àÂëµÄÖÎÀíԱʹ´¦¡¢²»°²È«µÄÈí¼þ¸üлúÔì¡¢FTP·þÎñÆ÷ÖеÄõè¾¶±éÀú¡¢»Ø¾ø·þÎñÒÔ¼°´úÂëÖ´Ðеȣ¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâÒªÇóÀ´ÀûÓÃÕâЩ·ì϶¡£³É¹¦ÀûÓ÷ì϶µÄ¹¥»÷Õß¿ÉÄÜ»á×èÖ¹¶ÔÊÜÓ°Ïìϵͳ½ÚµãµÄºÏ·¨½Ó¼û¡¢Ô¶³ÌÖÕ³¡ÏµÍ³½Úµã¡¢½ÚÔìϵͳ½Úµã»òÔÚϵͳ½ÚµãÖвåÈëºÍÔËÐÐËÁÒâ´úÂë¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/abb-patches-many-vulnerabilities-hmi-products


¾©¹«Íø°²±¸11010802024551ºÅ