¶íÂÞ˹з¨°¸Ç¿ÔìÊÖ»úºÍPCԤװÖñ¾¹úÈí¼þ£»¿¨°Í˹»ù°ä²¼2019ÄêQ3 DDoS¹¥»÷»ã±¨

°ä²¼¹¦·ò 2019-11-12

1¡¢¶íÂÞ˹з¨°¸Ç¿ÔìÊÖ»úºÍPCԤװÖñ¾¹úÈí¼þ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶íÂÞ˹Òé»áÔÚÍÆ¶¯Ò»ÏîÁ¢·¨£¬¸Ã·¨°¸½«Ç¿ÔìÒªÇóËùÓÐÔÚ¶íÂÞ˹ÏúÊ۵ĵç×ÓÉ豸£¨Ô̺¬ÖÇÄÜÊÖ»ú¡¢PCºÍÖÇÄܵçÊӵȣ©Ô¤×°Öñ¾¹ú¿Æ¼¼¹«Ë¾µÄÀûÓá£Õâ¿ÉÄÜ»á´øÀ´°²È«Òþ»¼¡£Á¢·¨Õß°µÊ¾¸Ã·¨°¸ÊÇΪÁ˱£»¤±¾µØµÄ¼¼ÊõÊг¡ÃâÊܱí¹ú£¨¿ÉÄÜÊÇÖ¸ÃÀ¹ú£©µÄ¾ºÕù¡£µ±¾Ö½«Õë¶ÔÿÖÖÉ豸ÀàÐͰ䲼һ·ÝÈí¼þÁбí£¬É豸¹©¸øÉ̱ØÒªÔÚ¶íÂÞ˹ÏúÊÛµÄÉ豸ÉÏԤװÖÃÕâЩÈí¼þ¡£ÈôÊǹ©¸øÉ̲»×ñÊØ»®¶¨£¬½«±»´¦ÒÔ×î¸ß20Íò¬²¼£¨Ô¼ºÏ3100ÃÀÔª£©µÄ·£¿î¡£¸Ã·¨°¸µÃµ½ÁËËùÓÐÖØÒªÕþµ³µÄÖ§³Ö£¬ÕâÒâζ×ÅËüºÜÓпÉÄܽ«ÔÚ2020Äê7ÔÂ1ÈÕÉúЧ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/phones-and-pcs-sold-in-russia-will-have-to-come-pre-installed-with-russian-apps/


2¡¢¿¨°Í˹»ù°ä²¼2019ÄêQ3 DDoS¹¥»÷»ã±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼2019ÄêµÚÈý¼¾¶ÈµÄDDoS¹¥»÷¶¯Ì¬»ã±¨¡£Æ¾¾Ý¸Ã»ã±¨£¬DDoS¹¥»÷ÔÚ½ñÄê³ÖÐøÎ¬³ÖÔö³¤Ì¬ÊÆ£¬µ«¼¼Êõ¸üÏȽøµÄÖÇÄÜÐ͹¥»÷·´¶øÓÐËù½µÂä¡£¿¨°Í˹»ùÔ¤²âDDoSÊг¡½«±äµÃ¹ÄºÍ²¢ÖÕ³¡Ôö³¤£¬ÈôÊǸýáÂÛÕýÈ·£¬µÚËÄʱ¶ÈµÄ¹Ø¼üÖ¸±êÔö³¤½«²»»áÄÇô¿É¹Û¡£ÆßÔ·ÝÊDZ¾¼¾¶ÈDDoS»î¶¯µÄ¶¥·åʱÆÚ£¬×î³£¼ûµÄ¹¥»÷ÀàÐÍÒÀÈ»ÊÇSYN·ººé£¨79.7%£©£¬Linux½©Ê¬ÍøÂçÒÀȻռ¹¥»÷»î¶¯µÄ¾ø´óÎÞÊý£¨97.75%£©¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/ddos-report-q3-2019/94958/


3¡¢ÀÕË÷Èí¼þ¼´·þÎñBuran»ý¼«ÔÚ°µÍøÂÛ̳´«²¼


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝMcAfee×êÑÐÈËÔ±Alexandre MundoºÍMarc RiveroµÄ·¢ÏÖ£¬ÐµÄÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©BuranÔÚ°µÍøÂÛ̳ÉÏ»ý¼«´«²¼¡£BuranÔËÓªÕßËÆºõÕýÖÂÁ¦Óë·¸×ï¿Í»§³ÉÁ¢Ó×ÎÒ¹ØÏµ£¬ËüÃÇÔÚ´òÕÛÏúÊÛÒÔÎüÒý¸ü¶à·¸×ï·Ö×Ó¡£×ÜÌå¶øÑÔ£¬Buran×÷ÕßÖ»Õ¼¾ÝϰȾÊÕÈëÖеÄ25£¥£¬Õâ±ÈRaaSÔËÓªÕßͨ³£ÒªÇóµÄ30%-40%ÒªµÍµÄ¶à¡£¸ÃRaaSÊÔͼͨ¹ýÕâÖÖ·½Ê½ÓëÆäËüµÐÊÖ½øÐоºÕù¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/vegalocker-evolves-into-buran-ransomware-as-a-service/


4¡¢´¹µö»î¶¯¼Ù×°³ÉÓ¢¹ú˾·¨²¿´«²¼Predator the Thief


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Cofense×êÑÐÈËÔ±·¢ÏÖÒ»¸öеÄÍøÂç´¹µö»î¶¯¼Ù×°³ÉÓ¢¹ú˾·¨²¿´«²¼¶ñÒâÈí¼þPredator the Thief¡£¸Ã´¹µöÓʼþÖÐÔ̺¬Î±ÔìµÄ·¨Ôº´«Æ±²¢´øÓÐÓ¢¹ú˾·¨²¿»Õ±ê£¬ÒªÇóÊܺ¦Õßµã»÷Á´½ÓÒÔÏàʶ°¸¼þÐÅÏ¢¡£µ±Êܺ¦Õßµã»÷Á´½Óºó£¬½«»á´ÓÔÆ·þÎñÉÌ´¦ÏÂÔØÔ̺¬Predator the ThiefµÄÎĵµ¡£Predator the ThiefÊÇÔÚ°µÍøÂÛ̳ÉÏÏúÊÛµÄÒ»ÖÖ¶ñÒâÈí¼þ£¬ËüÄܹ»ÇÔÈ¡Óû§Ãû¡¢ÃÜÂë¡¢ä¯ÀÀÆ÷Êý¾ÝºÍ¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢µÈ£¬»¹Äܹ»Ê¹ÓÃÉãÏñÍ·½øÐÐÅÄÕÕ¡£¸Ã¶ñÒâÈí¼þÓÚ2018Äê7Ô³õ´Î³öÏÖ¡£¸Ã´¹µö»î¶¯ÖØÒªÕë¶Ô±£ÏÕÒµºÍÁãÊÛÒµµÄÔ±¹¤¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/phishing-campaign-delivers-data-stealing-malware-via-fake-court-summons-emails/


5¡¢AdobeÒÆ¶¯SDKÖеÄĬÈÏÅäÖôæÔÚ°²È«·çÏÕ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Nightwatch Cybersecurity·¢ÏÖAdobeµÄÒÆ¶¯Èí¼þ¿ª·¢Ì×¼þ£¨SDK£©¸½´øµÄʾÀýÅäÖÃÎļþ´æÔÚ°²È«·çÏÕ£¬Adobe×î½ü°ä²¼ÁËSDKµÄ¸üа汾½¨¸´¸ÃÎÊÌâ¡£¸Ã¹«Ë¾ÌṩµÄSDK×÷Ϊģ°å£¬¿É¹©¿ª·¢ÈËÔ±ÔÚ¸÷ÀàÆ½Ì¨´ó½«ÆäÀûÓ÷¨Ê½ÓëAdobeµÄÔÆ·þÎñ¼¯³ÉÔÚһ·¡£×êÑÐÈËÔ±·¢ÏÔìäÖ÷ÀûÓ÷¨Ê½ÅäÖÃÎļþADBMobileConfig.jsonÔ̺¬¿ÉÄܵ¼Ö°²È«ÎÊÌâµÄÉèÖã¬ÕâЩÎÊÌâÖØÒªÓëSSL/HTTPSÉèÖÃÓйØ£¬Ô̺¬Ä¬ÈϹعطÖÎöÉèÖá¢Ïνӵ½mediaHeartbeat¶ÔÏóµÄÊý¾Ý´«Êä´¦ÓÚÒ»ÑùµÄ²»°²È«×´Ì¬¡¢Ä¬Èϲ»Ê¹ÓÃSSLÏνӵÈ¡£×êÑÐÈËÔ±×ܹ²ÔÚ·ÖÆçµÄƽ̨ÉÏ·¢ÏÖÁË28¸öÄ£°å£¬Ò»Ð©¿ª·¢ÈËÔ±Ò»ÏòÔÚ×Ô¼ºµÄÀûÓ÷¨Ê½ÖÐʹÓÃÕâЩÅäÖÃÎļþ£¬µ¼Ö¹¥»÷ÕßÄܹ»²é¿´»òÅú¸ÄÓÉÀûÓ÷¨Ê½´«Ê仨AdobeÔÆ·þÎñµÄÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://nakedsecurity.sophos.com/2019/11/11/adobe-fixes-sdk-weakness-affecting-mobile-apps/


6¡¢Check Point ZoneAlarm²úÆ·ÂÛ̳Óû§Êý¾Ýй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÒÔÉ«Áа²È«³§ÉÌCheck PointÆìϵÄZoneAlarmÂÛ̳Óû§Êý¾Ýй¶¡£Ö»¹ÜZoneAlarm¼°Check PointÉÐδ¹«¿ªÅû¶´ËÊÂÎñ£¬µ«¸Ã¹«Ë¾ÒѾ­Í¨¹ýµç×ÓÓʼþÏòÓû§·¢ËÍÁ˾¯±¨¡£Óʼþ֪ͨÖаµÊ¾ºÚ¿Íδ¾­ÊÚȨ»ñÈ¡ÁËÂÛ̳Óû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢¹þÏ£ÃÜÂëºÍÉúÈյĽӼûȨÏÞ£¬½¨ÒéÓû§ÂíÉϸü¸ÄÆäÃÜÂë¡£¸Ã¹«Ë¾»¹³ÎÇå˵ֻÓÐÔÚ¡°forums.zonealarm.com¡±ÓòÖÐ×¢²áµÄÓû§£¨Ô¼Îª4500ÈË£©Êܵ½Ó°Ï죬¸ÃÂÛ̳ÊÇÒ»¸öµ¥¶ÀµÄÍøÕ¾£¬²»»áÓ°ÏìCheck PointµÄÈÎºÎÆäËüÍøÕ¾¡£¸ÃÊÂÎñµÄÔ­ÒòÓëvBulletin֮ǰ½¨¸´µÄRCE 0day£¨CVE-2019-16759£©ÓйØ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/11/zonealarm-forum-data-breach.html