¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181025

Ðû²¼Ê±¼ä 2018-10-26
1£¬£¬£¬£¬¹úÌ©º½¿ÕÓοÍ×ÊÁÏÒÉÍâй£¬£¬£¬£¬²¨¼°Ô¼940ÍòÂÿÍ

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

¹úÌ©º½¿Õ23ÈÕÍíÐû²¼Í¨¸æ³Æ£¬£¬£¬£¬¸Ã¹«Ë¾¼°È«×Ê×Ó¹«Ë¾¸ÛÁúº½¿ÕÓÐÏÞ¹«Ë¾µÄÂÿÍ×ÊÁÏÔ⵽δÊÚȨ»á¼û£¬£¬£¬£¬Ô¼940ÍòÂÿÍ×ÊÁϱ»ÇÔÈ¡£¬£¬£¬£¬°üÀ¨Âÿ͵ÄÐÕÃû¡¢ÉúÈÕ¡¢µç»°¡¢µØµã¡¢Éí·ÝÖ¤¼°»¤ÕպŵÈÃô¸ÐÐÅÏ¢¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬£¬ÉÐÓÐ403ÕÅÒÑÓâÆÚµÄÐÅÓÿ¨ºÅÂëй¶¡£ ¡£¡£¡£¹úÌ©º½¿Õ³ÆÊÜÓ°ÏìµÄÐÅϢϵͳÓ뺽°àÔË×÷ϵͳΪ×ÔÁ¦µÄϵͳ£¬£¬£¬£¬´Ë´ÎÊÂÎñ²»»á¶Ôº½°àÇå¾²×é³ÉÈκÎÓ°Ïì¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securingtomorrow.mcafee.com/mcafee-labs/android-timpdoor-turns-mobile-devices-into-hidden-proxies/

2£¬£¬£¬£¬Pocket iNetÒòAmazon S3ÉèÖùýʧµ¼Ö²¿·ÖÔ±¹¤µÄÐÅϢй¶

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

UpGuardÑо¿ÍŶӷ¢Ã÷Ò»¸öAmazon S3 bucket¿É¹ûÕæ»á¼û£¬£¬£¬£¬¸ÃÊý¾Ý¿âÊôÓÚ»ªÊ¢¶Ù»¥ÁªÍøÐ§ÀÍÌṩÉÌPocket iNet¡£ ¡£¡£¡£¸ÃÊý¾Ý¿â¾ÞϸΪ73GB£¬£¬£¬£¬°üÀ¨´ó×ÚÃô¸ÐÐÅÏ¢£¬£¬£¬£¬°üÀ¨²¿·ÖÔ±¹¤µÄAWSÃÜÔ¿ºÍÃ÷ÎÄÃÜÂë¡¢¹«Ë¾ÍøÂç¼Ü¹¹µÄÏêϸÉèÖÃÐÅÏ¢¡¢ÄÚ²¿ÍøÂçͼ±íºÍ×°±¸ÕÕÆ¬µÈ¡£ ¡£¡£¡£Pocket iNetÈ·ÈÏÁË¸ÃÆðÊÂÎñ£¬£¬£¬£¬²¢ÔÚ½Óµ½±¨¸æºóµÄ7ÌìÄÚÐÞ¸´Á˸ÃÎÊÌâ¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/pocket-inet-isp-exposes-misconfigured-73-gb-amazon-s3-bucket-to-the-internet-523392.shtml

3£¬£¬£¬£¬Ñо¿Ö°Ô±ÔÚTwitterÉÏÅû¶µÚ¶þ¸öWindowsÁãÈÕÎó²î

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Çå¾²Ñо¿Ö°Ô±SandboxEscaperÔÙ´ÎÔÚTwitterÉÏÅû¶һ¸öWindowsÁãÈÕÎó²î£¬£¬£¬£¬¸ÃÎó²îËÆºõ±£´æÓÚÊý¾Ý¹²ÏíЧÀÍ£¨dssvc.dll£©ÖУ¬£¬£¬£¬ÔÊÐíµÍȨÏÞÓû§¾ÙÐÐÌáȨ¡£ ¡£¡£¡£ÓÉÓÚMicrosoftÊý¾Ý¹²ÏíЧÀÍÊÇÔÚWindows 10ÖÐÒýÈëµÄ£¬£¬£¬£¬Òò´Ë¸ÃÎó²î²»»áÓ°Ïì¾É°æ±¾µÄ²Ù×÷ϵͳ£¬£¬£¬£¬ÈçWin 7 ºÍWin 8.1¡£ ¡£¡£¡£¸ÃÑо¿Ö°Ô±Á½¸öÔÂÇ°ÔøÅû¶ÁíÒ»¸öWindowsÍýÏëʹÃüÖеÄÁãÈÕÎó²î¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/10/windows-zero-day-exploit.html


4£¬£¬£¬£¬FireEyeÒÔΪTRITON¹¥»÷»î¶¯Óë¶íÂÞ˹Ñо¿»ú¹¹CNIIHM±£´æ¹ØÁª

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

ƾ֤FireEye¶ÔTRITONµÄ¹éÒòÆÊÎö£¬£¬£¬£¬¸Ã¶ñÒâ»î¶¯Óë¶íÂÞ˹Õþ¸®µÄÑо¿»ú¹¹»¯Ñ§ºÍÁ¦Ñ§ÖÐÑë¿ÆÑ§Ñо¿Ôº(CNIIHM)±£´æ¹ØÁª¡£ ¡£¡£¡£TRITON¹¥»÷±¬·¢ÔÚ2017Äê8Ô·Ý£¬£¬£¬£¬¹¥»÷ÕßÖ÷ÒªÕë¶ÔÒªº¦»ù´¡ÉèÊ©ÖеÄICSϵͳ¡£ ¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷µÄÖ¤¾Ý°üÀ¨¶Ô¶à¸ö¶ñÒâÈí¼þ°æ±¾µÄ²âÊԻÒÔ¼°TRITONµÄÐÐΪģʽÇкÏĪ˹¿ÆµØÇøµÄʱ¼äµÈ¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2018/10/triton-attribution-russian-government-owned-lab-most-likely-built-tools.html


5£¬£¬£¬£¬Ñо¿ÍŶӷ¢Ã÷ʹÓÃSMS·Ö·¢Android/TimpDoorµÄÍøÂç´¹Âڻ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

McAfeeÑо¿ÍŶӷ¢Ã÷Ò»¸öʹÓÃSMS·Ö·¢¶ñÒâÈí¼þAndroid/TimpDoorµÄÍøÂç´¹Âڻ¡£ ¡£¡£¡£TimpDoor°üÀ¨Ò»¸öÍøÂçÊðÀí£¬£¬£¬£¬ÓÃÓÚ´«ÊäÀ´×ÔµÚÈý·½Ð§ÀÍÆ÷µÄ¼ÓÃÜÁ÷Á¿¡£ ¡£¡£¡£Ñ¬È¾ÁËTimpDoorµÄ×°±¸¿É±»¿´³ÉºóÃÅ£¬£¬£¬£¬ÓÃÓÚÉñÃØ»á¼ûÆóÒµºÍ¼ÒÍ¥µÄÄÚ²¿ÍøÂ磬£¬£¬£¬Ò²¿ÉÓÃÓÚ·¢ËÍÀ¬»øÓʼþµÈ¡£ ¡£¡£¡£×îÔçµÄTimpDoor±äÌå·ºÆðÓÚ3Ô·Ý£¬£¬£¬£¬×îеÄÔòÊÇ8ÔÂβ¡£ ¡£¡£¡£Æ¾Ö¤McAfeeµÄÒ£²âÊý¾Ý£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÖÁÉÙѬȾÁËÔ¼5000̨װ±¸¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securingtomorrow.mcafee.com/mcafee-labs/android-timpdoor-turns-mobile-devices-into-hidden-proxies/

6£¬£¬£¬£¬Ñо¿»ú¹¹Ðû²¼2018ÄêÓ¢¹úUnisysÇå¾²Ö¸Êý£¬£¬£¬£¬ÖØµã¹Ø×¢Éí·Ý͵ÇÔÎÊÌâ

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

Ñо¿»ú¹¹Ðû²¼2018ÄêÓ¢¹úUnisysÇå¾²Ö¸Êý£¬£¬£¬£¬56%µÄÓ¢¹úÊÜ·ÃÕßÌåÏÖËûÃǺÜÊǹØ×¢Éí·Ý͵ÇÔÎÊÌ⣬£¬£¬£¬ÕâʹµÃÉí·Ý͵ÇÔ³ÉΪ×îÊܹØ×¢µÄÍþв£¬£¬£¬£¬ÒøÐп¨Õ©Æ­ºÍ¹ú¼Ò¹«¹²Çå¾²½ôËæØÊºó¡£ ¡£¡£¡£¶ø2017ÄêÓëÕ½Õù»ò¿Ö²ÀÖ÷ÒåÓйصĹú¼ÒÇå¾²ÊÇ×îÊܹØ×¢µÄÎÊÌâ¡£ ¡£¡£¡£65£¥µÄÓ¢¹ú¹«Ãñ»¹¹Ø×¢Í¨¹ýÉ罻ýÌå¾ÙÐÐЭ×÷ºÍ²ß»®¹¥»÷µÄ¿Ö²À·Ö×Ó¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬£¬63£¥µÄÊÜ·ÃÕßÌåÏÖËûÃǵ£ÐÄ×Ô¼ºµÄÉ罻ýÌå×ÊÁϱ»¹¥»÷ÕßÇÔÈ¡¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2018/10/24/uk-citizens-fear-identity-theft/


ÉùÃ÷£º±¾×ÊѶÓÉÈËÉú¾ÍÊDz©Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí