¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180920

Ðû²¼Ê±¼ä 2018-09-20

¡¾ÆÊÎö±¨¸æ¡¿Å·ÖÞÐ̾¯×éÖ¯Ðû²¼2018Ä껥ÁªÍøÓÐ×éÖ¯·¸·¨ÍþвÆÀ¹À±¨¸æ


Å·ÖÞÐ̾¯×éÖ¯Ò»Á¬µÚÎåÄêÐû²¼»¥ÁªÍøÓÐ×éÖ¯·¸·¨ÍþвÆÀ¹À±¨¸æ£¨IOCTA2018°æ£©£¬£¬ £¬£¬£¬£¬±¨¸æÖÐÖÜÈ«¸ÅÊöÁËÄ¿½ñÒÔ¼°Î´À´µÄ·¸·¨ÍþвºÍÇ÷ÊÆ¡£¡£¡£ ¡£¡£¡£ÆäÖ÷Òª·¢Ã÷°üÀ¨£ºÀÕË÷Èí¼þÈÔ¼á³ÖÖ÷µ¼Ö°Î»£»£»·¸·¨·Ö×Ó¼ÌÐøÊ¹ÓÃDDoS¹¥»÷Õë¶Ô˽ÈËÆóÒµºÍ¹«¹²ÐÐÒµ£»£»¶ùͯÐÔ¾ÛÁ²ÖÊÁϵÄÊýÄ¿¼ÌÐøÔöÌí£»£»ÎÞ¿¨Ö§¸¶Ú²Æ­³ÉΪÖ÷Á÷£¬£¬ £¬£¬£¬£¬µ«skimmerÈÔÔÚ¼ÌÐøÉú³¤£»£»Õë¶Ô¼ÓÃÜÇ®±Ò³ÖÓÐÕߺÍÉúÒâËùµÄ·¸·¨»î¶¯ÉÏÉý£»£»¶ñÒâÍÚ¿ó³ÉΪ³±Á÷£»£»Éç½»¹¤³ÌÈÔÈ»ÊÇÖ÷ÒªµÄ¹¥»÷ÏòÁ¿£»£»Ö÷ÒªµÄ°µÍøÊг¡±»¹Ø±Õ£¬£¬ £¬£¬£¬£¬µ«ÓªÒµ»¹ÔÚ¾ÙÐС£¡£¡£ ¡£¡£¡£


https://www.europol.europa.eu/internet-organised-crime-threat-assessment-2018


¡¾ÆÊÎö±¨¸æ¡¿AkamaiÐû²¼2018Ä껥ÁªÍøÇ徲״̬±¨¸æ£¬£¬ £¬£¬£¬£¬ÖØµã¹Ø×¢Æ¾Ö¤Ìî³ä¹¥»÷


AkamaiÐû²¼2018Ä껥ÁªÍøÇ徲״̬±¨¸æ£¬£¬ £¬£¬£¬£¬ÖØµã¹Ø×¢½ðÈÚÐÐÒµÃæÁÙµÄй¥»÷Ç÷ÊÆ - ƾ֤Ìî³ä¹¥»÷¡£¡£¡£ ¡£¡£¡£2018Äê5ÔÂÖÁ6ÔÂʱ´úAkamaiÔÚÆäÖÇÄÜÆ½Ì¨ÉϹ²¼ì²âµ½Áè¼Ý83ÒڴζñÒâµÇ¼ʵÑé¡£¡£¡£ ¡£¡£¡£±¨¸æÆÊÎöÁ˽©Ê¬ÍøÂçµÄ×îÐÂÕ½ÂÔºÍÇ÷ÊÆ£¬£¬ £¬£¬£¬£¬°üÀ¨Ä¿µÄÐÐÒµºÍ¹ú¼Ò£¬£¬ £¬£¬£¬£¬²¢ÉîÈëÑо¿ÁËÒ»¸öÕë¶ÔÁ½¸ö½ðÈÚ»ú¹¹µÄ¶à½©Ê¬ÍøÂç¡¢³¤Ê±¼äµÄƾ֤Ìî³ä¹¥»÷¡£¡£¡£ ¡£¡£¡£±¨¸æÖл¹ÆÊÎöÁËÆ¾Ö¤Ìî³ä¹¥»÷ÔöÌíµÄÔµ¹ÊÔ­ÓÉÒÔ¼°×é֯ˢÐÂÆä·À»¤²½·¥µÄÐëÒªÐÔ¡£¡£¡£ ¡£¡£¡£


https://www.akamai.com/us/en/about/our-thinking/state-of-the-internet-report/global-state-of-the-internet-security-ddos-attack-reports.jsp


¡¾¹¥»÷ÊÂÎñ¡¿ÃÀ¹ú¹úÎñÔºµç×ÓÓʼþϵͳÔâºÚ¿Í¹¥»÷£¬£¬ £¬£¬£¬£¬Ô¼1%Ô±¹¤µÄÐÅϢй¶


ÃÀ¹ú¹úÎñÔºµÄµç×ÓÓʼþϵͳÔâµ½ºÚ¿Í¹¥»÷£¬£¬ £¬£¬£¬£¬ÉÙÊýÔ±¹¤£¨²»µ½1%£©µÄСÎÒ˽¼ÒÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£ ¡£¡£¡£Æ¾Ö¤¹úÎñÔºÐû²¼µÄͨ¸æ£¬£¬ £¬£¬£¬£¬¸Ãµç×ÓÓʼþϵͳÊÇ·ÇÉñÃØÐÔµç×ÓÓʼþϵͳ£¬£¬ £¬£¬£¬£¬Æä±»ÐÎòΪÃô¸Ðµ«²»Éæ¼°ÉñÃØ¡£¡£¡£ ¡£¡£¡£¹úÎñÔº½²»°ÈËNicole ThompsonÌåÏÖÕâÒ»ÊÂÎñ»¹ÔÚÊÓ²ìÖ®ÖУ¬£¬ £¬£¬£¬£¬¹úÎñÔºÕýÔÚÓëÏàÖúͬ°éºÍ˽Ӫ²¿·ÖЧÀÍÉÌÅäºÏ¾ÙÐÐÖÜÈ«µÄÆÀ¹À¡£¡£¡£ ¡£¡£¡£


https://www.politico.com/story/2018/09/17/state-department-email-personal-information-792665


¡¾¹¥»÷ÊÂÎñ¡¿·ÆÂɱö¹ã²¥¹«Ë¾ABS-CBNÔâºÚ¿Í¹¥»÷£¬£¬ £¬£¬£¬£¬²¿·Ö¿Í»§µÄ²ÆÎñÊý¾ÝÒɱ»ÇÔ


·ÆÂɱö¹ã²¥¹«Ë¾ABS-CBNµÄÔÚÏßÊÐËÁѬȾMagecart¶ñÒâ¾ç±¾£¬£¬ £¬£¬£¬£¬²¿·Ö¿Í»§µÄÖ§¸¶ÐÅÏ¢ÒÉй¶¡£¡£¡£ ¡£¡£¡£Æ¾Ö¤ºÉÀ¼Çå¾²Ñо¿Ö°Ô±Willem GrootµÄ˵·¨£¬£¬ £¬£¬£¬£¬¸Ã¶ñÒâ¾ç±¾×Ô2018Äê8ÔÂÒÔÀ´Ò»Ö±»îÔ¾¡£¡£¡£ ¡£¡£¡£ABS-CBNÊÇ·ÆÂɱö×î´óµÄÓÐÏßµçÊÓЧÀÍÉÌ¡£¡£¡£ ¡£¡£¡£ÕâЩ±»×èµ²µÄÓû§²ÆÎñÊý¾Ý±»·¢Ë͵½×¢²áְλÓÚ¶íÂÞ˹ÒÁ¶û¿â´Ä¿ËµÄЧÀÍÆ÷¡£¡£¡£ ¡£¡£¡£ÏÖÔÚ»¹²»ÇåÎúÓм¸¶à¿Í»§Êܵ½Ó°Ïì¡£¡£¡£ ¡£¡£¡£


https://www.zdnet.com/article/broadcasting-giant-abs-cbn-customer-data-stolen-sent-to-russian-servers/


¡¾Çå¾²Îó²î¡¿Ñо¿Ö°Ô±Åû¶Î÷ÊýMy Cloud NAS×°±¸ÖеÄÒ»¸öÉÐδÐÞ¸´µÄÇå¾²Îó²î


SecurifyµÄÑо¿Ö°Ô±Åû¶Î÷²¿Êý¾ÝµÄMy Cloud NAS×°±¸ÖеÄÒ»¸öÉÐδÐÞ¸´µÄÇå¾²Îó²î¡£¡£¡£ ¡£¡£¡£¸ÃÎó²î£¨CVE-2018-17153£©¿ÉÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÌáȨÖÁÖÎÀíԱȨÏÞ£¬£¬ £¬£¬£¬£¬²¢»ñµÃ¶ÔÊÜÓ°ÏìNAS×°±¸µÄÍêÈ«¿ØÖÆ£¬£¬ £¬£¬£¬£¬ÒÔ¼°¿ÉÒÔÉó²é¡¢¸´ÖÆ¡¢É¾³ýºÍÁýÕÖÉè±¹ØÁ¬ÄÈκÎÎļþ¡£¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±»¹Ðû²¼ÁËÏà¹ØPoC¡£¡£¡£ ¡£¡£¡£¸ÃÎó²îÔøÓÚ2017Äê4Ô±¨¸æ¸øÎ÷²¿Êý¾Ý£¬£¬ £¬£¬£¬£¬µ«¸Ã¹«Ë¾ÖÁ½ñûÓоÙÐÐÈκλظ´ºÍÐÞ¸´¡£¡£¡£ ¡£¡£¡£


https://thehackernews.com/2018/09/wd-my-cloud-nas-hacking.html


¡¾Îó²î²¹¶¡¡¿Ë¼¿ÆÐû²¼WebexÍøÂçÂ¼ÖÆ²¥·ÅÆ÷µÄÇå¾²¸üУ¬£¬ £¬£¬£¬£¬ÐÞ¸´¶à¸öÎó²î


˼¿ÆÐÞ¸´ÁËWebexÍøÂçÂ¼ÖÆ²¥·ÅÆ÷ÖеĶà¸öÇå¾²Îó²î¡£¡£¡£ ¡£¡£¡£ÕâЩÎó²îÊÇÓÉÓÚWebexÂ¼ÖÆÎļþµÄ²»×¼È·ÑéÖ¤µ¼ÖµÄ£¬£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜͨ¹ý´¹ÂÚÁ´½Ó»ò´¹ÂÚÓʼþÓÕʹÓû§·­¿ª¶ñÒâµÄARFÎļþ´¥·¢ÕâЩÎó²î£¬£¬ £¬£¬£¬£¬µ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£ ¡£¡£¡£¸ÃÈí¼þµÄWindows¡¢OS XºÍLinux°æ±¾¶¼Êܵ½Ó°Ï죬£¬ £¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¾ÙÐиüС£¡£¡£ ¡£¡£¡£


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180919-webex



¡¾ÈËÉú¾ÍÊDz©¼¯ÍÅADLabÕûÀíÐû²¼¡¿