¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180906

Ðû²¼Ê±¼ä 2018-09-06

¡¾ÆÊÎö±¨¸æ¡¿SANSÑо¿ËùÐû²¼2018ÄêIIOTÇå¾²ÐԵĵ÷Ñб¨¸æ


SANSÑо¿ËùÐû²¼¹ØÓÚ¹¤ÒµÎïÁªÍø£¨IIoT£©Çå¾²ÐԵĵ÷Ñб¨¸æ  £¬¸ÃÑо¿Ëù¶ÔÀ´×ÔÄÜÔ´¡¢¹«ÓÃÊÂÒµ¡¢Ê¯ÓͺÍ×ÔÈ»ÆøÒÔ¼°ÖÆÔìÒµµÄ200¶àÃûÇå¾²Ö°Ô±¾ÙÐÐÁËÊÓ²ì  £¬Ö»Óв»µ½5%µÄOTÖ°Ô±ÌåÏÖ¶ÔËûÃǹ«Ë¾µÄлù´¡ÉèÊ©µÄÇå¾²·À»¤³äÂúÐÅÐÄ¡£32%µÄÊÜ·ÃÆóÒµÖеÄIIoT×°±¸Ö±½ÓÅþÁ¬µ½»¥ÁªÍø  £¬ÈƹýÁ˹ŰåµÄICSÇå¾²²ã¡£±ðµÄ  £¬Ö»ÓÐ40%µÄÊÜ·ÃÕßÌåÏÖËûÃÇʵʱΪװ±¸×°Öò¹¶¡ºÍ¸üС£


Ô­ÎÄÁ´½Ó£ºhttps://cdn2.hubspot.net/hubfs/2755567/White%20Papers%20and%20Briefs/Sans%20IIOT%20Survey.pdf


¡¾¹¥»÷ÊÂÎñ¡¿Chrome²å¼þMEGAÔâºÚ¿ÍÐ®ÖÆ  £¬ÓÃÓÚÇÔÈ¡Óû§µÄÃÜÂë


ÔÆ´æ´¢·þÎñMEGA.nzµÄ¹Ù·½Chrome²å¼þÔâµ½ºÚ¿ÍÐ®ÖÆ  £¬ÓÃÓÚÇÔÈ¡Óû§µÄÃÜÂ롣ƾ֤¸Ã¹«Ë¾µÄ²©¿Í  £¬¹¥»÷ÕßÔÚ9ÔÂ4ÈÕ14:30 UTCÈëÇÖMEGAµÄChrome web storeÕÊ»§  £¬²¢ÉÏ´«ÁËÒ»¸ö¶ñÒâ°æ±¾3.39.4¡£¸Ã°æ±¾ÓÃÓÚÇÔÈ¡Óû§µÄÑÇÂíÑ·¡¢Î¢Èí¡¢GithubºÍ¹È¸èµÈÊ¢ÐÐÍøÕ¾µÄƾ֤  £¬ÒÔ¼°MyEtherWalletºÍMyMoneroµÈÔÚÏß¼ÓÃÜÇ®±ÒÇ®°üºÍ¼ÓÃÜÇ®±ÒÉúÒâÆ½Ì¨Idex.marketµÄƾ֤¡£±»µÁµÄÐÅÏ¢½«±»·¢ËÍÖÁλÓÚÎÚ¿ËÀ¼µÄmegaopac[.]host·þÎñÆ÷¡£¸Ã¹«Ë¾ÔÚÊÂÎñ±¬·¢ËÄСʱ֮ºó¸üÐÂÁËÒ»¸öÇå½àµÄ°æ±¾3.39.5¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/09/mega-file-upload-chrome-extension.html


¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷ʹÓÃ.tkÓòÃûµÄ´ó¹æÄ£¹ã¸æÕ©Æ­Ô˶¯


ZscalerµÄÑо¿Ö°Ô±·¢Ã÷ʹÓÃ.tkÓòÃûµÄ´ó¹æÄ£¹ã¸æÕ©Æ­Ô˶¯¡£×Ô2018Äê5ÔÂÒÔÀ´  £¬¸Ã¶ñÒâÔ˶¯Ò»Ö±´¦ÓÚ»îԾ״̬¡£¹¥»÷Õß½«Óû§Öض¨ÏòÖÁÐéαµÄ²©¿ÍÍøÕ¾  £¬ÕâÐ©ÍøÕ¾ÉÏµÄ¹ã¸æÊÕÈëÿÔ´ï2ÍòÃÀÔªÒÔÉÏ¡£²¿·Ö.tkÓòÃû»¹±»ÓÃÓÚÊÖÒÕÖ§³ÖÕ©Æ­¡£.tkÓòÃûÊÇÒ»¸ö¹ú¼Ò/µØÇø¼¶µÄ¶¥¼¶ÓòÃû  £¬Ëü´ú±íÁËÁ¥ÊôÓÚÐÂÎ÷À¼µÄµº¹úTokelau¡£¸ÃÓòÃûÊÇÃâ·ÑµÄ  £¬ÕâÒýÆðÁ˹¥»÷ÕßµÄÐËȤ¡£Ñо¿Ö°Ô±×ܹ²·¢Ã÷ÁËÓë¸Ã¶ñÒâÔ˶¯ÓйصÄ3804¸ö.tkÓòÃû¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zscaler.com/blogs/research/spam-campaigns-leveraging-tk-domains


¡¾ÍþвÇ鱨¡¿Group-IB·¢Ã÷Ö÷ÒªÕë¶Ô¶íÂÞ˹ºÍ¶«Å·ÒøÐеÄз¸·¨ÍÅ»ïSilence


Group-IBÐû²¼¹ØÓÚз¸·¨ÍÅ»ïSilenceµÄÆÊÎö±¨¸æ¡£±¨¸æÖ¸³ö  £¬SilenceÖÁÉÙÓë¶íÂÞ˹ºÍ¶«Å·µÄÒøÐкͽðÈÚ»ú¹¹µÄ80ÍòÃÀԪ͵ÇÔ°¸ÓйØ¡£¾ÝGroup-IB³Æ  £¬¸Ã×éÖ¯ÔÚÒÑÍùÈýÄêÖÐÒ»Ö±Õë¶Ô¶íÂÞ˹ºÍ¶«Å·µÄ½ðÈÚ»ú¹¹Ìᳫ¹¥»÷¡£Silence¿ª·¢ÁËһЩ×Ô¼ºµÄ¹¤¾ß  £¬°üÀ¨»ù´¡ÉèÊ©¹¥»÷¿ò¼ÜSilence¡¢ATM¹¥»÷¹¤¾ßÏäAtmosphere¡¢ÃÜÂë»ñÈ¡¹¤¾ßFarseÒÔ¼°ÈÕÖ¾ÒÆ³ý¹¤¾ßCleaner¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/new-silence-hacking-group-suspected-of-having-ties-to-cyber-security-industry/


¡¾ÍþвÇ鱨¡¿·¸·¨ÍÅ»ïFIN6¾íÍÁÖØÀ´  £¬Ö÷ÒªÕë¶ÔÃÀ¹úºÍÅ·ÖÞµÄPoSϵͳ


IBM X-Force IRISÑо¿ÍŶӷ¢Ã÷·¸·¨ÍÅ»ïFIN6µÄй¥»÷Ô˶¯¡£¸Ã¹¥»÷Ô˶¯Ö÷ÒªÕë¶ÔÃÀ¹úºÍÅ·ÖÞµÄÁãÊÛÉ̵ÄPoSϵͳ¡£ÏÖÔÚÉв»ÇåÎú¼¸¶àÆóÒµÔâµ½Á˹¥»÷¡£FIN6ͨʺóÃÅÈí¼þGrabnewÀ´ÍøÂçÓû§µÄƾ֤ÐÅÏ¢  £¬È»ºóʹÓöñÒâÈí¼þTrinity£¨ÓÖ½ÐFrameworkPOS£©²éÕÒºÍÉøÍ¸PoS×°±¸¡£Ñо¿Ö°Ô±ÌåÏÖ90%µÄй¥»÷Ô˶¯¶¼Ê¹ÓÃÁËÓë֮ǰFIN6¹¥»÷ÏàͬµÄÕ½ÂԺ͹¤¾ß¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/fin6-returns-to-attack-retailers-in-us-europe/


¡¾Îó²î²¹¶¡¡¿Ë¼¿ÆÐû²¼¶à¿î²úÆ·µÄÇå¾²¸üР £¬ÐÞ¸´16¸öÇå¾²Îó²î


±¾ÖÜÈý˼¿ÆÐû²¼ÁËRVϵÁС¢SD-WANºÍUmbrellaµÈ²úÆ·µÄÇå¾²¸üР £¬¹²ÐÞ¸´ÁË16¸öÇå¾²Îó²î¡£ÆäÖаüÀ¨RVϵÁзÀ»ðǽºÍ·ÓÉÆ÷µÄwebÖÎÀí½çÃæÖеĻº³åÇøÒç³öÎó²î£¨CVE-2018-0423£©  £¬¸ÃÎó²î¿ÉÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐÐí§Òâ´úÂë»ò´¥·¢¾Ü¾ø·þÎñ£»Umbrella APIÖеĸßΣÎó²î£¨CVE-2018-0435£©  £¬¸ÃÎó²î¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßÉó²éºÍÐÞ¸ÄÆäËü×éÖ¯µÄÊý¾Ý¡£½¨ÒéÓû§¾¡¿ì×°ÖÃÕâЩ¸üС£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cisco-releases-16-security-alerts-rated-critical-and-high/