¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180914

Ðû²¼Ê±¼ä 2018-09-14

¡¾Õþ²ß¹æÔò¡¿ÎÀ½¡Î¯Ðû²¼¡¶¹ú¼Ò¿µ½¡Ò½ÁÆ´óÊý¾Ý±ê×¼¡¢Çå¾²ºÍЧÀÍÖÎÀí²½·¥£¨ÊÔÐУ©¡·


ΪÔöÇ¿¿µ½¡Ò½ÁÆ´óÊý¾ÝЧÀÍÖÎÀí£¬£¬ £¬£¬ £¬Ôö½ø¡°»¥ÁªÍø+Ò½ÁÆ¿µ½¡¡±Éú³¤£¬£¬ £¬£¬ £¬³ä·ÖÑéÕ¹¿µ½¡Ò½ÁÆ´óÊý¾Ý×÷Ϊ¹ú¼ÒÖ÷Òª»ù´¡ÐÔÕ½ÂÔ×ÊÔ´µÄ×÷Ó㬣¬ £¬£¬ £¬Æ¾Ö¤Ïà¹ØÖ´ÂÉÀýÔò£¬£¬ £¬£¬ £¬¹ú¼ÒÎÀÉú¿µ½¡Î¯Ô±»áÐû²¼¡¶¹ú¼Ò¿µ½¡Ò½ÁÆ´óÊý¾Ý±ê×¼¡¢Çå¾²ºÍЧÀÍÖÎÀí²½·¥£¨ÊÔÐУ©¡·¡£¡£²½·¥Ëù³Æ¿µ½¡Ò½ÁÆ´óÊý¾Ý£¬£¬ £¬£¬ £¬ÊÇÖ¸ÔÚÈËÃǼ²²¡·ÀÖΡ¢¿µ½¡ÖÎÀíµÈÀú³ÌÖб¬·¢µÄÓ뿵½¡Ò½ÁÆÏà¹ØµÄÊý¾Ý¡£¡£¸÷¼¶ÖÖÖÖÒ½ÁÆÎÀÉúÆø¹¹ºÍÏà¹ØÆóÊÂÒµµ¥Î»ÊÇ¿µ½¡Ò½ÁÆ´óÊý¾ÝÇå¾²ºÍÓ¦ÓÃÖÎÀíµÄÔðÈε¥Î»¡£¡£


http://www.nhfpc.gov.cn/guihuaxxs/s10741/201809/758ec2f510c74683b9c4ab4ffbe46557.shtml


¡¾ÆÊÎö±¨¸æ¡¿NexusguardÐû²¼2018ÄêQ2Íþв±¨¸æ£¬£¬ £¬£¬ £¬DDoS¹¥»÷ͬ±ÈÔöÌíÁè¼Ý500%


ƾ֤NexusguardµÄ2018ÄêµÚ¶þ¼¾¶ÈÍþв±¨¸æ£¬£¬ £¬£¬ £¬DDoS¹¥»÷ƽ¾ùÔöÌíÁè¼Ý26Gbps£¬£¬ £¬£¬ £¬¹æÄ£ÔöÌíÁËÁè¼Ý500%¡£¡£Óë2017ÄêͬÆÚÏà±È£¬£¬ £¬£¬ £¬DDoS¹¥»÷µÄ×î´ó¹æÄ£·­ÁËËı¶£¬£¬ £¬£¬ £¬´ï359Gbps¡£¡£Ñо¿Ö°Ô±³ÆÊý¾ÝµÄ¼¤ÔöÔ´ÓÚÎïÁªÍø½©Ê¬ÍøÂçSatoriµÄÔöÌí¡£¡£×î´óµÄ0dayΣº¦À´×ÔÓÚ²î±ðµÄ¼ÒÓ÷ÓÉÆ÷£¬£¬ £¬£¬ £¬¹¥»÷Õß¿ÉÄÜʹÓÃÕâЩװ±¸Õë¶ÔÒªº¦Ð§ÀͺÍÍøÂçÌᳫ´ó¹æÄ£DDoS¹¥»÷¡£¡£Synºé·º¹¥»÷Õ¼ÓÐÁËÖ÷µ¼Ö°Î»¡£¡£


https://www.infosecurity-magazine.com/news/ddos-attacks-increase-in-size-by/


¡¾¹¥»÷ÊÂÎñ¡¿Ó¢¹ú°®¶¡±¤´óѧÔâDDoS¹¥»÷£¬£¬ £¬£¬ £¬¹ÙÍøÔÝʱÎÞ·¨»á¼û


Ó¢¹ú°®¶¡±¤´óѧÔâµ½ÍøÂç¹¥»÷£¬£¬ £¬£¬ £¬ÆäÍøÕ¾ÔÝʱ²»¿É»á¼û¡£¡£Æ¾Ö¤°®¶¡±¤Íí±¨£¬£¬ £¬£¬ £¬¸Ã´óѧÖ÷ÒªµÄed.ac.ukÍøÕ¾×èÖ¹ÖÜËÄÔçÉÏÈÔÈ»ÎÞ·¨»á¼û£¬£¬ £¬£¬ £¬ÕâÅú×¢ÆäÔâµ½ÁËÑÏÖØµÄDDoS¹¥»÷¡£¡£¸Ã´óѧµÄÐÂÎŽ²»°ÈË³ÆÆäÒѽÓÄÉÁËÑÏ¿áµÄ²½·¥À´± £»£»£»£»£»£»¤ITϵͳºÍÊý¾Ý£¬£¬ £¬£¬ £¬²¢½«¼ÌÐøÓëISP¡¢ÍøÂç·¸·¨ÊÓ²ìÖ°Ô±ÒÔ¼°ÆäËü´óѧÏàÖúÒÔ×èÖ¹ÕâÐ©ÍøÂç¹¥»÷¡£¡£


https://www.infosecurity-magazine.com/news/edinburgh-uni-hit-by-major-cyber/


¡¾ÍþвÇ鱨¡¿F-SecureÑо¿Ö°Ô±ÑÝʾ¿ÉÇÔÈ¡ÄÚ´æÐÅÏ¢µÄÐÂÀäÆô¶¯¹¥»÷ÊÖÒÕ


·ÒÀ¼Çå¾²³§ÉÌF-SecureµÄÑо¿Ö°Ô±·¢Ã÷Ò»ÖÖÐµĹ¥»÷ÒªÁ죬£¬ £¬£¬ £¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÀäÆô¶¯ºóÔÚÊý·ÖÖÓÄÚ»Ö¸´ÄÚ´æÖеÄÊý¾Ý£¬£¬ £¬£¬ £¬ÕâЩÊý¾Ý¿ÉÄܰüÀ¨ÃÜÂë¡¢ÃÜÔ¿ºÍÆäËüÃô¸ÐÐÅÏ¢µÈ¡£¡£Ñо¿Ö°Ô±³ÆËùÓеÄÏÖ´úÅÌËã»ú¶¼Êܵ½Ó°Ï죬£¬ £¬£¬ £¬²¢Ðû²¼ÁËʵÑé¹¥»÷µÄÑÝʾÊÓÆµ¡£¡£ÎªÁËÏìÓ¦ËûÃǵÄÑо¿Ð§¹û£¬£¬ £¬£¬ £¬Î¢Èí¸üÐÂÁËÆäBitlocker Countermeasures£¬£¬ £¬£¬ £¬¶øÆ»¹ûÔòÌåÏÖÅ䱸ÁËApple T2оƬµÄMac×°±¸ÒѾ­°üÀ¨ÁËÏà¹ØÇå¾²²½·¥¡£¡£


https://thehackernews.com/2018/09/cold-boot-attack-encryption.html


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷FeedifyѬȾÓÃÓÚÇÔÈ¡Óû§ÐÅÏ¢µÄ¶ñÒâMageCart¾ç±¾


Çå¾²Ñо¿Ö°Ô±Placebo·¢Ã÷ÍÆËÍ֪ͨЧÀÍFeedifyµÄ¾ç±¾ÖÐѬȾÁ˶ñÒâMageCart¾ç±¾¡£¡£MageCartÓÃÓÚÔÚÓû§Ìá½»±íµ¥Ê±ÇÔÈ¡Óû§µÄÒøÐп¨ÐÅÏ¢µÈ£¬£¬ £¬£¬ £¬RiskIQ×î½ü·¢Ã÷¸Ã·¸·¨ÍÅ»ïÓëÓ¢¹úº½¿Õ¹«Ë¾µÄÊý¾Ýй¶ÊÂÎñÓйء£¡£Ñо¿Ö°Ô±·¢Ã÷https://cdn.feedify.net/getjs/feedbackembad-min-1.0[.]jsÎļþÖаüÀ¨MageCart¶ñÒâ´úÂ룬£¬ £¬£¬ £¬Óû§Ìá½»µÄÐÅÏ¢¶¼½«±»·¢Ë͵½https://info-stat.ws/js/slider[.]js¡£¡£FeedifyÉÐδ×÷³ö»ØÓ¦¡£¡£


https://www.bleepingcomputer.com/news/security/feedify-hacked-with-magecart-information-stealing-script/


¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷·¸·¨ÍÅ»ïOilRig¶ÔÖж«µØÇøÌᳫÐµĹ¥»÷»î¶¯


·¸·¨ÍÅ»ïOilRig×Ô2016ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬ £¬£¬ £¬Ö÷ÒªÕë¶ÔÖж«µØÇøµÄÕþ¸®»ú¹¹ºÍÆóÒµ¡£¡£2018Äê8Ô£¬£¬ £¬£¬ £¬Palo Alto NetworksµÄUnit 42Ñо¿ÍŶӷ¢Ã÷¸Ã×é֯ʹÓÃжñÒâÈí¼þBONDUPDATERÕë¶ÔÖж«Õþ¸®»ú¹¹µÄһϵÁй¥»÷»î¶¯¡£¡£BONDUPDATERÊÇÒ»¸öľÂí£¬£¬ £¬£¬ £¬Æä°üÀ¨»ù±¾µÄºóÃŹ¦Ð§£¬£¬ £¬£¬ £¬²¢¿ÉÒÔÉÏ´«/ÏÂÔØÎļþÒÔ¼°Ö´ÐÐÏÂÁî¡£¡£BONDUPDATERʹÓÃDNSËíµÀÓëC2ЧÀÍÆ÷¾ÙÐÐͨѶ¡£¡£


https://researchcenter.paloaltonetworks.com/2018/09/unit42-oilrig-uses-updated-bondupdater-target-middle-eastern-government/



¡¾ÈËÉú¾ÍÊDz©¼¯ÍÅADLabÕûÀíÐû²¼¡¿