¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181114
Ðû²¼Ê±¼ä 2018-11-14
1¡¢Ñо¿»ú¹¹Ðû²¼ÃÀ¹úÐÅÓÿ¨Ú²Æ±¨¸æ£¬ÒÑÍù1ÄêÄÚÒÑÓÐ6000ÍòÐÅÓÿ¨ÐÅÏ¢±»ÇÔ
ƾ֤Gemini AdvisoryÐû²¼µÄÃÀ¹úÐÅÓÿ¨Ú²Æ±¨¸æ£¬Ö»¹Ü2015ÄêÃÀ¹ú½ðÈÚÒµ¾ÍÒÑ´ó¹æÄ£Ç¨áãµ½EMVоƬ¿¨±ê×¼£¬µ«ÔÚÒÑÍù12¸öÔÂÄÚÈÔÓÐ6000ÍòÕÅÐÅÓÿ¨µÄÐÅÏ¢±»ÇÔ¡£ÆäÖÐ4580Íò£¨75%£©µÄÐÅÓÿ¨ÐÅÏ¢ÊÇͨ¹ýPoS»úÉϵÄʵ¿¨ÉúÒâ±»ÇԵģ¬Ö»ÓÐ25%µÄÐÅÓÿ¨ÐÅÏ¢±»ÔÚÏßÇÔÈ¡¡£ÕâЩʵ¿¨ÖÐ90%ÊÇEMV¿¨¡£ÒÑÍù12¸öÔÂÄÚÔÚµç×ÓÉÌÎñÖб»ÇÔµÄÐÅÓÿ¨ÊýÄ¿ÔöÌíÁË14%£¬ÕâÒâζÕß·¸·¨·Ö×ÓÕýÔÚ´Óʵ¿¨ÉúÒâתÏòÎÞ¿¨Ú²Æ¡£
2¡¢RiskIQºÍFlashpointÍŽáÐû²¼¹ØÓÚMagecart¹¥»÷µÄÆÊÎö±¨¸æ
ƾ֤RiskIQºÍFlashpointÍŽáÐû²¼µÄ¡¶Magecart¹¥»÷¶´²ì¡·±¨¸æ£¬MagecartÊÇÖÁÉÙ7¸öÍøÂç·¸·¨ÍÅ»ïµÄ×ܳơ£Magecart¹¥»÷ͨ¹ýÔÚµç×ÓÉÌÎñÍøÕ¾ÉÏÖ²Èë¶ñÒâ½ÅÔÀ´ÇÔÈ¡Óû§µÄÐÅÓÿ¨ÐÅÏ¢£¬ÊýÊ®¸öÈ«ÇòÖøÃûÆ·ÅÆµÄµç×ÓÉÌÎñÍøÕ¾¶¼ÊÇËüµÄÊܺ¦Õߣ¬°üÀ¨Ticketmaster¡¢British AirwaysÒÔ¼°Ðµ°µÈ¡£Ñо¿Ö°Ô±ÔÚ±¨¸æÖй¹½¨ÁËMagecart¹¥»÷µÄʱ¼äÏߣ¬²¢ÖصãÏÈÈÝÁËËüÃǵĶñÒâ¾ç±¾¡¢¹¥»÷Õ½ÂÔÒÔ¼°Ä¿µÄÑ¡ÔñµÈÐÅÏ¢¡£
3¡¢Ñо¿ÍŶӷ¢Ã÷Õë¶Ô°Í»ù˹̹µÄÐÂAPT×éÖ¯The White Company
CylanceÑо¿ÍŶӷ¢Ã÷Ò»¸öÖ÷ÒªÕë¶Ô°Í»ù˹̹Õþ¸®ºÍ¾ü¶ÓµÄÐÂAPT×éÖ¯The White Company£¨°×É«¹«Ë¾£©¡£¸ÃAPT×éÖ¯ËÆºõÊÇÓɹú¼Ò×ÊÖúµÄ£¬Æä´ó¹æÄ£Ìع¤Ô˶¯±»³ÆÎªOperation Shaheen£¨É³ÐÀÐж¯£©¡£The White CompanyʹÓÃÁ˶àÖÖÖØ´óµÄÒªÁìÀ´ÌӱܹéÒò£¬ÀýÈçÌӱܷÀ²¡¶¾Èí¼þ¼ì²â¡¢×ÔÎÒɱ¾øºÍɨ³ýºÛ¼£ÒÔ¼°¾ÓÐÄÁôÏÂÏ໥ì¶ÜµÄÖ¤¾ÝµÈ¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/the-white-company-a-new-state-sponsored-apt-discovered-by-cylance-523745.shtml
4¡¢Ñо¿ÍŶÓÐû²¼¹ØÓÚжñÒâÍÚ¿óÈí¼þWebCobraµÄÆÊÎö±¨¸æ
McAfeeʵÑéÊÒµÄÑо¿Ö°Ô±·¢Ã÷Ò»¸öжíÂÞ˹¶ñÒâÈí¼þWebCobra£¬WebCobra»áƾ֤ËùѬȾµÄϵͳ¼Ü¹¹µÄ²î±ð×°Öòî±ðµÄ¶ñÒâÍÚ¿óÈí¼þ£¬°üÀ¨Cryptonight£¨x86£©ºÍClaymore Zcash£¨x64£©¡£Ñо¿Ö°Ô±ÒÔΪÕâÖÖ¶ñÒâÈí¼þÊÇͨ¹ýDZÔÚÓк¦µÄ³ÌÐò£¨PUP£©·Ö·¢µÄ£¬ÆäѬȾ¹æÄ£±é²¼È«Çò£¬µ«Ö÷ÒªÊÇÔÚ°ÍÎ÷¡¢ÄϷǺÍÃÀ¹ú¡£
5¡¢Ñо¿Ö°Ô±ÔÚGoogle PlayÉÏ·¢Ã÷Òþ²ØÒ»ÄêÖ®¾ÃµÄ¶ñÒâͨ»°Â¼Òôapp
Çå¾²Ñо¿Ö°Ô±Lukas StefankoÔÚGoogle PlayÉÏ·¢Ã÷Ò»¸ö¶ñÒâµÄͨ»°Â¼Òôapp£¬¸Ãapp×Ô2017Äê11ÔÂ30ÈÕÆðÔÚGoogle PlayÉÏ¿ÉÓã¬ÒÑÒþ²ØÁËÔ¼Ò»ÄêµÄʱ¼ä£¬ÆäÏÂÔØ´ÎÊýÁè¼Ý5000´Î¡£¸Ã¶ñÒâapp»á´Óhttp://adsmserver[.]club/up/update.apk£¨¸ÃÁ´½ÓÏÖÔÚÒѱ»É¾³ý£©ÏÂÔØÒ»¸öÐéαµÄFlash Player¸üУ¬²¢ÓÕÆÓû§¾ÙÐÐ×°Öá£ÓÉÓÚÓÐÓúÉÔØÒѲ»¿ÉÓã¬Ñо¿Ö°Ô±Î´ÄܾÙÐнøÒ»²½µÄÆÊÎö¡£
6¡¢Î¢ÈíÐû²¼11ÔÂÇå¾²¸üУ¬ÐÞ¸´64¸öÎó²î
΢ÈíÐû²¼11Ô·ݵÄÇå¾²¸üУ¬¹²ÐÞ¸´64¸öÎó²î£¬ÆäÖаüÀ¨12¸ö¸ßΣÎó²î¡£ÆäÖÐÓÉ¿¨°Í˹»ùʵÑéÊÒ±¨¸æµÄÁãÈÕÎó²î£¨CVE-2018-8589£©Òѱ»¹¥»÷ÕßÔÚÒ°ÍâÆð¾¢Ê¹Ó᣸ÃÎó²îÊÇÒ»¸öÌáȨÎó²î£¬ÓëWindows×°±¸Çý¶¯³ÌÐòWin32k.sysÓйء£¿¨°Í˹»ùÍýÏëÓÚÖÜÈýÐû²¼¹ØÓÚ¸ÃÎó²î±»APT×éÖ¯Æð¾¢Ê¹Óõĸü¶àÐÅÏ¢¡£ÏêϸÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£
ÉùÃ÷£º±¾×ÊѶÓÉ×ðÁú¿Ê±Î¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí
ƾ֤Gemini AdvisoryÐû²¼µÄÃÀ¹úÐÅÓÿ¨Ú²Æ±¨¸æ£¬Ö»¹Ü2015ÄêÃÀ¹ú½ðÈÚÒµ¾ÍÒÑ´ó¹æÄ£Ç¨áãµ½EMVоƬ¿¨±ê×¼£¬µ«ÔÚÒÑÍù12¸öÔÂÄÚÈÔÓÐ6000ÍòÕÅÐÅÓÿ¨µÄÐÅÏ¢±»ÇÔ¡£ÆäÖÐ4580Íò£¨75%£©µÄÐÅÓÿ¨ÐÅÏ¢ÊÇͨ¹ýPoS»úÉϵÄʵ¿¨ÉúÒâ±»ÇԵģ¬Ö»ÓÐ25%µÄÐÅÓÿ¨ÐÅÏ¢±»ÔÚÏßÇÔÈ¡¡£ÕâЩʵ¿¨ÖÐ90%ÊÇEMV¿¨¡£ÒÑÍù12¸öÔÂÄÚÔÚµç×ÓÉÌÎñÖб»ÇÔµÄÐÅÓÿ¨ÊýÄ¿ÔöÌíÁË14%£¬ÕâÒâζÕß·¸·¨·Ö×ÓÕýÔÚ´Óʵ¿¨ÉúÒâתÏòÎÞ¿¨Ú²Æ¡£
ÔÎÄÁ´½Ó£º
https://geminiadvisory.io/card-fraud-on-the-rise/2¡¢RiskIQºÍFlashpointÍŽáÐû²¼¹ØÓÚMagecart¹¥»÷µÄÆÊÎö±¨¸æ
ƾ֤RiskIQºÍFlashpointÍŽáÐû²¼µÄ¡¶Magecart¹¥»÷¶´²ì¡·±¨¸æ£¬MagecartÊÇÖÁÉÙ7¸öÍøÂç·¸·¨ÍÅ»ïµÄ×ܳơ£Magecart¹¥»÷ͨ¹ýÔÚµç×ÓÉÌÎñÍøÕ¾ÉÏÖ²Èë¶ñÒâ½ÅÔÀ´ÇÔÈ¡Óû§µÄÐÅÓÿ¨ÐÅÏ¢£¬ÊýÊ®¸öÈ«ÇòÖøÃûÆ·ÅÆµÄµç×ÓÉÌÎñÍøÕ¾¶¼ÊÇËüµÄÊܺ¦Õߣ¬°üÀ¨Ticketmaster¡¢British AirwaysÒÔ¼°Ðµ°µÈ¡£Ñо¿Ö°Ô±ÔÚ±¨¸æÖй¹½¨ÁËMagecart¹¥»÷µÄʱ¼äÏߣ¬²¢ÖصãÏÈÈÝÁËËüÃǵĶñÒâ¾ç±¾¡¢¹¥»÷Õ½ÂÔÒÔ¼°Ä¿µÄÑ¡ÔñµÈÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.riskiq.com/blog/external-threat-management/inside-magecart/3¡¢Ñо¿ÍŶӷ¢Ã÷Õë¶Ô°Í»ù˹̹µÄÐÂAPT×éÖ¯The White Company
CylanceÑо¿ÍŶӷ¢Ã÷Ò»¸öÖ÷ÒªÕë¶Ô°Í»ù˹̹Õþ¸®ºÍ¾ü¶ÓµÄÐÂAPT×éÖ¯The White Company£¨°×É«¹«Ë¾£©¡£¸ÃAPT×éÖ¯ËÆºõÊÇÓɹú¼Ò×ÊÖúµÄ£¬Æä´ó¹æÄ£Ìع¤Ô˶¯±»³ÆÎªOperation Shaheen£¨É³ÐÀÐж¯£©¡£The White CompanyʹÓÃÁ˶àÖÖÖØ´óµÄÒªÁìÀ´ÌӱܹéÒò£¬ÀýÈçÌӱܷÀ²¡¶¾Èí¼þ¼ì²â¡¢×ÔÎÒɱ¾øºÍɨ³ýºÛ¼£ÒÔ¼°¾ÓÐÄÁôÏÂÏ໥ì¶ÜµÄÖ¤¾ÝµÈ¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/the-white-company-a-new-state-sponsored-apt-discovered-by-cylance-523745.shtml
4¡¢Ñо¿ÍŶÓÐû²¼¹ØÓÚжñÒâÍÚ¿óÈí¼þWebCobraµÄÆÊÎö±¨¸æ
McAfeeʵÑéÊÒµÄÑо¿Ö°Ô±·¢Ã÷Ò»¸öжíÂÞ˹¶ñÒâÈí¼þWebCobra£¬WebCobra»áƾ֤ËùѬȾµÄϵͳ¼Ü¹¹µÄ²î±ð×°Öòî±ðµÄ¶ñÒâÍÚ¿óÈí¼þ£¬°üÀ¨Cryptonight£¨x86£©ºÍClaymore Zcash£¨x64£©¡£Ñо¿Ö°Ô±ÒÔΪÕâÖÖ¶ñÒâÈí¼þÊÇͨ¹ýDZÔÚÓк¦µÄ³ÌÐò£¨PUP£©·Ö·¢µÄ£¬ÆäѬȾ¹æÄ£±é²¼È«Çò£¬µ«Ö÷ÒªÊÇÔÚ°ÍÎ÷¡¢ÄϷǺÍÃÀ¹ú¡£
ÔÎÄÁ´½Ó£º
https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/webcobra-malware-uses-victims-computers-to-mine-cryptocurrency/5¡¢Ñо¿Ö°Ô±ÔÚGoogle PlayÉÏ·¢Ã÷Òþ²ØÒ»ÄêÖ®¾ÃµÄ¶ñÒâͨ»°Â¼Òôapp
Çå¾²Ñо¿Ö°Ô±Lukas StefankoÔÚGoogle PlayÉÏ·¢Ã÷Ò»¸ö¶ñÒâµÄͨ»°Â¼Òôapp£¬¸Ãapp×Ô2017Äê11ÔÂ30ÈÕÆðÔÚGoogle PlayÉÏ¿ÉÓã¬ÒÑÒþ²ØÁËÔ¼Ò»ÄêµÄʱ¼ä£¬ÆäÏÂÔØ´ÎÊýÁè¼Ý5000´Î¡£¸Ã¶ñÒâapp»á´Óhttp://adsmserver[.]club/up/update.apk£¨¸ÃÁ´½ÓÏÖÔÚÒѱ»É¾³ý£©ÏÂÔØÒ»¸öÐéαµÄFlash Player¸üУ¬²¢ÓÕÆÓû§¾ÙÐÐ×°Öá£ÓÉÓÚÓÐÓúÉÔØÒѲ»¿ÉÓã¬Ñо¿Ö°Ô±Î´ÄܾÙÐнøÒ»²½µÄÆÊÎö¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/trojanized-android-app-found-on-google-play-with-more-than-5-000-installs-523743.shtml6¡¢Î¢ÈíÐû²¼11ÔÂÇå¾²¸üУ¬ÐÞ¸´64¸öÎó²î
΢ÈíÐû²¼11Ô·ݵÄÇå¾²¸üУ¬¹²ÐÞ¸´64¸öÎó²î£¬ÆäÖаüÀ¨12¸ö¸ßΣÎó²î¡£ÆäÖÐÓÉ¿¨°Í˹»ùʵÑéÊÒ±¨¸æµÄÁãÈÕÎó²î£¨CVE-2018-8589£©Òѱ»¹¥»÷ÕßÔÚÒ°ÍâÆð¾¢Ê¹Ó᣸ÃÎó²îÊÇÒ»¸öÌáȨÎó²î£¬ÓëWindows×°±¸Çý¶¯³ÌÐòWin32k.sysÓйء£¿¨°Í˹»ùÍýÏëÓÚÖÜÈýÐû²¼¹ØÓÚ¸ÃÎó²î±»APT×éÖ¯Æð¾¢Ê¹Óõĸü¶àÐÅÏ¢¡£ÏêϸÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-november-2018-patch-tuesday-fixes-12-critical-vulnerabilities/ÉùÃ÷£º±¾×ÊѶÓÉ×ðÁú¿Ê±Î¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ