¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180906

Ðû²¼Ê±¼ä 2018-09-06

¡¾ÆÊÎö±¨¸æ¡¿SANSÑо¿ËùÐû²¼2018ÄêIIOTÇå¾²ÐԵĵ÷Ñб¨¸æ


SANSÑо¿ËùÐû²¼¹ØÓÚ¹¤ÒµÎïÁªÍø£¨IIoT£©Çå¾²ÐԵĵ÷Ñб¨¸æ£¬£¬ £¬ £¬ £¬¸ÃÑо¿Ëù¶ÔÀ´×ÔÄÜÔ´¡¢¹«ÓÃÊÂÒµ¡¢Ê¯ÓͺÍ×ÔÈ»ÆøÒÔ¼°ÖÆÔìÒµµÄ200¶àÃûÇå¾²Ö°Ô±¾ÙÐÐÁËÊӲ죬£¬ £¬ £¬ £¬Ö»Óв»µ½5%µÄOTÖ°Ô±ÌåÏÖ¶ÔËûÃǹ«Ë¾µÄлù´¡ÉèÊ©µÄÇå¾²·À»¤³äÂúÐÅÐÄ ¡£¡£¡£32%µÄÊÜ·ÃÆóÒµÖеÄIIoT×°±¸Ö±½ÓÅþÁ¬µ½»¥ÁªÍø£¬£¬ £¬ £¬ £¬ÈƹýÁ˹ŰåµÄICSÇå¾²²ã ¡£¡£¡£±ðµÄ£¬£¬ £¬ £¬ £¬Ö»ÓÐ40%µÄÊÜ·ÃÕßÌåÏÖËûÃÇʵʱΪװ±¸×°Öò¹¶¡ºÍ¸üР¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://cdn2.hubspot.net/hubfs/2755567/White%20Papers%20and%20Briefs/Sans%20IIOT%20Survey.pdf


¡¾¹¥»÷ÊÂÎñ¡¿Chrome²å¼þMEGAÔâºÚ¿ÍÐ®ÖÆ£¬£¬ £¬ £¬ £¬ÓÃÓÚÇÔÈ¡Óû§µÄÃÜÂë


ÔÆ´æ´¢Ð§ÀÍMEGA.nzµÄ¹Ù·½Chrome²å¼þÔâµ½ºÚ¿ÍÐ®ÖÆ£¬£¬ £¬ £¬ £¬ÓÃÓÚÇÔÈ¡Óû§µÄÃÜÂë ¡£¡£¡£Æ¾Ö¤¸Ã¹«Ë¾µÄ²©¿Í£¬£¬ £¬ £¬ £¬¹¥»÷ÕßÔÚ9ÔÂ4ÈÕ14:30 UTCÈëÇÖMEGAµÄChrome web storeÕÊ»§£¬£¬ £¬ £¬ £¬²¢ÉÏ´«ÁËÒ»¸ö¶ñÒâ°æ±¾3.39.4 ¡£¡£¡£¸Ã°æ±¾ÓÃÓÚÇÔÈ¡Óû§µÄÑÇÂíÑ·¡¢Î¢Èí¡¢GithubºÍ¹È¸èµÈÊ¢ÐÐÍøÕ¾µÄƾ֤£¬£¬ £¬ £¬ £¬ÒÔ¼°MyEtherWalletºÍMyMoneroµÈÔÚÏß¼ÓÃÜÇ®±ÒÇ®°üºÍ¼ÓÃÜÇ®±ÒÉúÒâÆ½Ì¨Idex.marketµÄƾ֤ ¡£¡£¡£±»µÁµÄÐÅÏ¢½«±»·¢ËÍÖÁλÓÚÎÚ¿ËÀ¼µÄmegaopac[.]hostЧÀÍÆ÷ ¡£¡£¡£¸Ã¹«Ë¾ÔÚÊÂÎñ±¬·¢ËÄСʱ֮ºó¸üÐÂÁËÒ»¸öÇå½àµÄ°æ±¾3.39.5 ¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/09/mega-file-upload-chrome-extension.html


¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷ʹÓÃ.tkÓòÃûµÄ´ó¹æÄ£¹ã¸æÕ©Æ­»î¶¯


ZscalerµÄÑо¿Ö°Ô±·¢Ã÷ʹÓÃ.tkÓòÃûµÄ´ó¹æÄ£¹ã¸æÕ©Æ­»î¶¯ ¡£¡£¡£×Ô2018Äê5ÔÂÒÔÀ´£¬£¬ £¬ £¬ £¬¸Ã¶ñÒâ»î¶¯Ò»Ö±´¦ÓÚ»îԾ״̬ ¡£¡£¡£¹¥»÷Õß½«Óû§Öض¨ÏòÖÁÐéαµÄ²©¿ÍÍøÕ¾£¬£¬ £¬ £¬ £¬ÕâÐ©ÍøÕ¾ÉÏµÄ¹ã¸æÊÕÈëÿÔ´ï2ÍòÃÀÔªÒÔÉÏ ¡£¡£¡£²¿·Ö.tkÓòÃû»¹±»ÓÃÓÚÊÖÒÕÖ§³ÖÕ©Æ­ ¡£¡£¡£.tkÓòÃûÊÇÒ»¸ö¹ú¼Ò/µØÇø¼¶µÄ¶¥¼¶ÓòÃû£¬£¬ £¬ £¬ £¬Ëü´ú±íÁËÁ¥ÊôÓÚÐÂÎ÷À¼µÄµº¹úTokelau ¡£¡£¡£¸ÃÓòÃûÊÇÃâ·ÑµÄ£¬£¬ £¬ £¬ £¬ÕâÒýÆðÁ˹¥»÷ÕßµÄÐËȤ ¡£¡£¡£Ñо¿Ö°Ô±×ܹ²·¢Ã÷ÁËÓë¸Ã¶ñÒâ»î¶¯ÓйصÄ3804¸ö.tkÓòÃû ¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zscaler.com/blogs/research/spam-campaigns-leveraging-tk-domains


¡¾ÍþвÇ鱨¡¿Group-IB·¢Ã÷Ö÷ÒªÕë¶Ô¶íÂÞ˹ºÍ¶«Å·ÒøÐеÄз¸·¨ÍÅ»ïSilence


Group-IBÐû²¼¹ØÓÚз¸·¨ÍÅ»ïSilenceµÄÆÊÎö±¨¸æ ¡£¡£¡£±¨¸æÖ¸³ö£¬£¬ £¬ £¬ £¬SilenceÖÁÉÙÓë¶íÂÞ˹ºÍ¶«Å·µÄÒøÐкͽðÈÚ»ú¹¹µÄ80ÍòÃÀԪ͵ÇÔ°¸ÓÐ¹Ø ¡£¡£¡£¾ÝGroup-IB³Æ£¬£¬ £¬ £¬ £¬¸Ã×éÖ¯ÔÚÒÑÍùÈýÄêÖÐÒ»Ö±Õë¶Ô¶íÂÞ˹ºÍ¶«Å·µÄ½ðÈÚ»ú¹¹Ìᳫ¹¥»÷ ¡£¡£¡£Silence¿ª·¢ÁËһЩ×Ô¼ºµÄ¹¤¾ß£¬£¬ £¬ £¬ £¬°üÀ¨»ù´¡ÉèÊ©¹¥»÷¿ò¼ÜSilence¡¢ATM¹¥»÷¹¤¾ßÏäAtmosphere¡¢ÃÜÂë»ñÈ¡¹¤¾ßFarseÒÔ¼°ÈÕÖ¾ÒÆ³ý¹¤¾ßCleaner ¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/new-silence-hacking-group-suspected-of-having-ties-to-cyber-security-industry/


¡¾ÍþвÇ鱨¡¿·¸·¨ÍÅ»ïFIN6¾íÍÁÖØÀ´£¬£¬ £¬ £¬ £¬Ö÷ÒªÕë¶ÔÃÀ¹úºÍÅ·ÖÞµÄPoSϵͳ


IBM X-Force IRISÑо¿ÍŶӷ¢Ã÷·¸·¨ÍÅ»ïFIN6µÄй¥»÷»î¶¯ ¡£¡£¡£¸Ã¹¥»÷»î¶¯Ö÷ÒªÕë¶ÔÃÀ¹úºÍÅ·ÖÞµÄÁãÊÛÉ̵ÄPoSϵͳ ¡£¡£¡£ÏÖÔÚÉв»ÇåÎú¼¸¶àÆóÒµÔâµ½Á˹¥»÷ ¡£¡£¡£FIN6ͨʺóÃÅÈí¼þGrabnewÀ´ÍøÂçÓû§µÄƾ֤ÐÅÏ¢£¬£¬ £¬ £¬ £¬È»ºóʹÓöñÒâÈí¼þTrinity£¨ÓÖ½ÐFrameworkPOS£©²éÕÒºÍÉøÍ¸PoS×°±¸ ¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ90%µÄй¥»÷»î¶¯¶¼Ê¹ÓÃÁËÓë֮ǰFIN6¹¥»÷ÏàͬµÄÕ½ÂԺ͹¤¾ß ¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/fin6-returns-to-attack-retailers-in-us-europe/


¡¾Îó²î²¹¶¡¡¿Ë¼¿ÆÐû²¼¶à¿î²úÆ·µÄÇå¾²¸üУ¬£¬ £¬ £¬ £¬ÐÞ¸´16¸öÇå¾²Îó²î


±¾ÖÜÈý˼¿ÆÐû²¼ÁËRVϵÁС¢SD-WANºÍUmbrellaµÈ²úÆ·µÄÇå¾²¸üУ¬£¬ £¬ £¬ £¬¹²ÐÞ¸´ÁË16¸öÇå¾²Îó²î ¡£¡£¡£ÆäÖаüÀ¨RVϵÁзÀ»ðǽºÍ·ÓÉÆ÷µÄwebÖÎÀí½çÃæÖеĻº³åÇøÒç³öÎó²î£¨CVE-2018-0423£©£¬£¬ £¬ £¬ £¬¸ÃÎó²î¿ÉÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐÐí§Òâ´úÂë»ò´¥·¢¾Ü¾øÐ§ÀÍ£»£»£»£»£»£»Umbrella APIÖеĸßΣÎó²î£¨CVE-2018-0435£©£¬£¬ £¬ £¬ £¬¸ÃÎó²î¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßÉó²éºÍÐÞ¸ÄÆäËü×éÖ¯µÄÊý¾Ý ¡£¡£¡£½¨ÒéÓû§¾¡¿ì×°ÖÃÕâЩ¸üР¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cisco-releases-16-security-alerts-rated-critical-and-high/