¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181112

Ðû²¼Ê±¼ä 2018-11-12
1¡¢FIAÌåÏÖ×î½üµÄÊý¾Ýй¶ÊÂÎñÓ°ÏìÁËÏÕЩËùÓеİͻùË¹Ì¹ÒøÐÐ

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ƾ֤°Í»ù˹̹Áª°îÊÓ²ì¾ÖFIAµÄ˵·¨£¬£¬£¬£¬ £¬ÏÕЩËùÓеİͻùË¹Ì¹ÒøÐж¼Êܵ½×î½üµÄÊý¾Ýй¶ÊÂÎñµÄÓ°Ïì¡£¡£¡£ ¡£¾Ý³Æ¸ÃÊÂÎñÓëÔÚ°µÍøÊг¡ÉÏ·ºÆðµÄÔ¼2ÍòÕŰͻùË¹Ì¹ÒøÐнè¼Ç¿¨ÐÅÏ¢ÓйØ¡£¡£¡£ ¡£¸Ã»ú¹¹ÕýÔÚÊÓ²ìÓë¸ÃÊÂÎñÓйصÄ100¶àÆðÍøÂç¹¥»÷£¬£¬£¬£¬ £¬ÏÖÔÚÉв»ÇåÎúÊý¾Ýй¶ÊÂÎñ±¬·¢µÄÏêϸʱ¼ä£¬£¬£¬£¬ £¬Ò²²»ÖªµÀ¹¥»÷ÕßÔõÑù½øÈëÕâЩ°Í»ùË¹Ì¹ÒøÐеÄϵͳ¡£¡£¡£ ¡£×èÖ¹ÉÏÖÜÄ©£¬£¬£¬£¬ £¬Ò»Ð©°Í»ùË¹Ì¹ÒøÐÐÒѾ­ÔÝÍ£ÔÚÍâÑóʹÓÃËüÃǵĽè¼Ç¿¨£¬£¬£¬£¬ £¬²¢½ûÓÃÁËÕâЩ¿¨µÄËùÓйú¼ÊÉúÒâ¡£¡£¡£ ¡£PakCERTͬÑùÐû²¼ÁËÒ»·Ý¹ØÓÚÊý¾Ýй¶µÄʱ¼ä±íºÍ¹æÄ£µÄ±¨¸æ¡£¡£¡£ ¡£

   

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/77847/cyber-crime/pakistani-banks-data-breach.html


2¡¢ÈüÃÅÌú¿ËÐû²¼¹ØÓÚLazarusµÄATM¹¥»÷¹¤¾ßFastcashµÄÆÊÎö±¨¸æ

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÈüÃÅÌú¿ËÐû²¼¹ØÓÚLazarusÓÃÓÚ¹¥»÷ATMµÄ¹¤¾ßFastCashµÄÆÊÎö±¨¸æ¡£¡£¡£ ¡£ÖÁÉÙ×Ô2016ÄêÒÔÀ´£¬£¬£¬£¬ £¬¸ÃAPT×éÖ¯Ò»Ö±ÔÚʹÓÃÕâÖÖ¶ñÒâÈí¼þ£¬£¬£¬£¬ £¬´ÓÑÇÖ޺ͷÇÖÞµÄÖÐСÐÍÒøÐÐATMÖÐÇÔÈ¡ÁËÁè¼ÝÊý°ÙÍòÃÀÔª¡£¡£¡£ ¡£FastCashľÂí×÷ÓÃÓÚÒøÐÐÄÚ²¿ÍøÂçÖеÄÓÃÓÚ´¦Öóͷ£ATMÉúÒâÇëÇóµÄ½»Á÷»úÓ¦ÓÃЧÀÍÆ÷ÖУ¬£¬£¬£¬ £¬Ö¼ÔÚ×èµ²ºÍÅú׼ڲƭÐÔµÄATMÌáÈ¡ÏÖ½ðÇëÇ󣬣¬£¬£¬ £¬²¢·¢ËÍÐéαµÄÅú×¼ÏìÓ¦¡£¡£¡£ ¡£¸ÃľÂíרÃÅÕë¶ÔÔËÐÐIBM AIXϵͳµÄ½»Á÷»úÓ¦ÓÃЧÀÍÆ÷£¬£¬£¬£¬ £¬ÈüÃÅÌú¿Ë·¢Ã÷¸Ã×éÖ¯¹¥»÷µÄËùÓÐЧÀÍÆ÷¶¼ÔËÐÐÒÑÓâÆÚµÄAIX OS°æ±¾¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.symantec.com/blogs/threat-intelligence/fastcash-lazarus-atm-malware


3¡¢Ñо¿ÍŶӷ¢Ã÷Ö÷ÒªÕë¶Ô°ÍÎ÷½ðÈÚ»ú¹¹µÄ¶ñÒâÈí¼þ·Ö·¢»î¶¯

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


˼¿ÆTalosÍŶӷ¢Ã÷Á½¸öÕýÔÚ¾ÙÐÐÖеĶñÒâÈí¼þ·Ö·¢»î¶¯£¬£¬£¬£¬ £¬ÕâЩ»î¶¯ÓÃÓÚÏò°ÍÎ÷µÄ½ðÈÚ»ú¹¹Óû§Èö²¥ÒøÐÐľÂí¡£¡£¡£ ¡£¹¥»÷»î¶¯±¬·¢ÔÚ10ÔÂβºÍ11Ô³õ£¬£¬£¬£¬ £¬ÕâÁ½¸ö¹¥»÷»î¶¯Ê¹ÓÃÁ˲î±ðµÄ³õʼѬȾÎļþÀàÐͺÍÁ½¸ö²î±ðµÄÒøÐÐľÂí£¬£¬£¬£¬ £¬µ«ÔÚѬȾÀú³ÌÖжÔÖÖÖÖÎļþʹÓÃÁËÏàͬµÄÃüÃû¹æÔò£¬£¬£¬£¬ £¬²¢¶¼Ê¹ÓÃÁ˶ÌÁ´½ÓÀ´Òþ²ØÏÖʵµÄ·Ö·¢Ð§ÀÍÆ÷µØµã¡£¡£¡£ ¡£ÔÚÆÊÎöÕâЩ»î¶¯Ê±£¬£¬£¬£¬ £¬Talos»¹·¢Ã÷ÁËÒ»¸öеÄÀ¬»øÓʼþ½©Ê¬ÍøÂç¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2018/11/metamorfo-brazilian-campaigns.html


4¡¢¼ÓÄôóÓÊÕþй¶Լ4500ÃûOCS¿Í»§µÄ´óÂé¶©µ¥ÐÅÏ¢

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÉÏÖÜÈý°²Ê¡´óÂéÍøµê£¨OCS£©ÔÚTwitterÉÏ͸¶³Æ£¬£¬£¬£¬ £¬Î´Öª¹¥»÷Õß´Ó¼ÓÄôóÓÊÕþ»á¼ûÁËÔ¼4500Ãû¿Í»§µÄ¶©µ¥¼Í¼£¬£¬£¬£¬ £¬Ô¼Õ¼¸Ã¹«Ë¾¿Í»§ÈºµÄ2%¡£¡£¡£ ¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨Ç©ÊÕÈ˵ÄÐÕÃû»òËõд¡¢ÓÊÕþ±àÂë¡¢½»¸¶ÈÕÆÚ¡¢OCS±àºÅ¡¢ÓÊÕþ°ü¹üºÅÒÔ¼°OCS¹«Ë¾µÄÃû³ÆºÍÓªÒµµØµãµÈ¡£¡£¡£ ¡£µ«OCS¼á³ÆÍêÕûµÄ¿Í»§µØµã¡¢¶©µ¥ÄÚÈݺ͸¶¿îÐÅϢûÓÐÊܵ½Ë𺦡£¡£¡£ ¡£¸Ãй¶ÊÂÎñÓÚ11ÔÂ1ÈÕ±»·¢Ã÷£¬£¬£¬£¬ £¬¼ÓÄôóÓÊÕþºÍOCSÕýÔÚÏàÖúÊÓ²ìÊÂÎñµÄÒòÓÉ¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/canada-post-leaked-personal-data-orders-of-thousands-of-cannabis-smokers/


5¡¢·ðÂÞÀï´ïÖÝÎÀÉúÊ𱻺ڿÍÈëÇÖ£¬£¬£¬£¬ £¬²¿·ÖµØÇøµÄ»¼ÕßÐÅϢй¶

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


¾Ý±¨µÀ·ðÂÞÀï´ïÖÝÎÀÉúÊðµÄÒ»ÃûCMSÔ±¹¤µÄOutlook 365ÕË»§±»ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬ £¬Escambia¡¢Santa Rosa¡¢OkaloosaºÍWaltonµØÇøµÄ»¼ÕßÐÅÏ¢±»ÇÔ¡£¡£¡£ ¡£¸ÃÕË»§µÄδÊÚȨ»á¼û±¬·¢ÔÚ10ÔÂ8ÈÕÖÁ10ÔÂ16ÈÕÖ®¼ä£¬£¬£¬£¬ £¬²¿·ÖÓû§µÄÐÕÃû¡¢Ò½ÁÆ×´Ì¬µÈÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£ ¡£Æ¾Ö¤¸ÃÎÀÉúÊðµÄÉùÃ÷£¬£¬£¬£¬ £¬Ã»ÓÐÖ¤¾ÝÅú×¢»¼ÕßµÄÉç±£ºÅÂë¡¢ÒøÐÐÕË»§»òÐÅÓÿ¨ÐÅÏ¢±»ÇÔ¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/florida-department-of-health-breached-patients-private-information-exposed-523724.shtml


6¡¢ICS-CERTÖÒÑÔ³ÆÈðÊ¿ÂÞÊÏÒ½ÁÆÆ÷е±£´æ¶à¸öÇå¾²Îó²î

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Çå¾²³§ÉÌMedigate·¢Ã÷ÈðʿҽÁƱ£½¡¹«Ë¾ÂÞÊÏÖÆÔìµÄÈýÖÖÒ½ÁÆÆ÷еÖб£´æÎå¸öÇå¾²Îó²î£¬£¬£¬£¬ £¬¿ÉÄܵ¼Ö»¼ÕßÃæÁÙΣº¦¡£¡£¡£ ¡£ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨Accu-ChekѪÌÇÒÇ¡¢CoaguChek×°±¸ºÍCobas±ãЯʽ´²±ßÕչ˻¤Ê¿ÏµÍ³¡£¡£¡£ ¡£ICS-CERTÒ²ÔÚÏà¹Ø±¨¸æÖÐÁгöÁËÊÜÓ°Ïì²úÆ·ºÍ°æ±¾µÄÏêϸÇåµ¥¡£¡£¡£ ¡£ÈðÊ¿ÂÞÊÏÕýÔÚÐÞ¸´ÕâЩÎó²î£¬£¬£¬£¬ £¬Ô¤¼Æ±¾Ô½«Ðû²¼Ïà¹ØÐÞ¸´²¹¶¡¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/flaws-roche-medical-devices-can-put-patients-risk


ÉùÃ÷£º±¾×ÊѶÓÉÈËÉú¾ÍÊDz©Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí