¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180802

Ðû²¼Ê±¼ä 2018-08-02

¡¾ÍþвÇ鱨¡¿ÃÀ¹úÉÌÎñ²¿ÖƲÃÃûµ¥ÐÂÔö44¼ÒÖйú¸ß¿Æ¼¼ÆóÒµ


ƾ֤ÃÀ¹úÁª°î¹«±¨£¨FederalRegister £¬£¬£¬£¬£¬ÃÀ¹úÁª°îÕþ¸®µÄÕþ¸®¹«±¨£©ÍøÕ¾Ðû²¼µÄ×îÐÂÐÅÏ¢ÏÔʾ £¬£¬£¬£¬£¬ÃÀ¹úBIS½«ÓÚÃÀ¶«Ê±¼ä8ÔÂ1ÈÕÕýʽÒÔ¹ú¼ÒÇå¾²ºÍÍâ½»ÀûÒæÎªÓÉ £¬£¬£¬£¬£¬½«44¼ÒÖйúÆóÒµ£¨8¸öʵÌåºÍ36¸öÁ¥Êô»ú¹¹£©ÁÐÈë³ö¿Ú¹ÜÖÆÊµÌåÇåµ¥ £¬£¬£¬£¬£¬ÆäÖаüÀ¨Ðí¶àÑо¿»ú¹¹¡£¡£¡£¡£ÃÀ¹úÕýʽ×îÏȶÔÖйú¾ÙÐÐÊÖÒÕ·â±Õ¡£¡£¡£¡£Õâ44¼ÒÆóÒµËùÓж¼ÊÇÖйú¸ß¿Æ¼¼ÆóÒµ £¬£¬£¬£¬£¬ÒÔº½¿Õº½Ìì¡¢¾ü¹¤ÀàÆóҵΪÖ÷¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://weibo.com/ttarticle/p/show?id=2309614268300610741920


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷ʹÓÃNSOÌØ¹¤Èí¼þÕë¶ÔÉ³ÌØ°¢À­²®ÈËȨ×éÖ¯µÄ¹¥»÷»î¶¯

2018Äê6Ô¹ú¼ÊÌØÉâ×éÖ¯µÄÒ»ÃûÊÂÇéÖ°Ô±ÊÕµ½¶ñÒâµÄWhatsAppÐÂÎÅ £¬£¬£¬£¬£¬ÆäÖаüÀ¨ÓëÉ³ÌØ°¢À­²®ÓйصĴ¹ÂÚÁ´½Ó¡£¡£¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷ÁíÒ»Î»É³ÌØÈËȨÖ÷ÒåÕßÒ²ÊÕµ½ÁËÀàËÆµÄÐÂÎÅ¡£¡£¡£¡£ÆÊÎöÅú×¢ÕâЩ¶ñÒâÐÂÎŽ«»áµ¼ÖÂѬȾÒÔÉ«ÁÐ¼à¿Ø¹©Ó¦ÉÌNSO¼¯ÍųöÊÛµÄÉÌÒµÌØ¹¤Èí¼þPegasus¡£¡£¡£¡£PegasusÖ¼ÔÚÔÊÐí¹¥»÷Õß»á¼ûÄ¿µÄµÄÊý¾Ý £¬£¬£¬£¬£¬°üÀ¨¶ÌÐÅ¡¢µç×ÓÓʼþ¡¢WhatsAppÐÂÎÅ¡¢Óû§µÄλÖá¢Âó¿Ë·çºÍÉãÏñÍ·¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/iphone-hacking-spyware.html


¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷ʹÓÃRMSºÍTeamViewerÕë¶Ô¶í¹¤ÒµÆóÒµµÄ´¹ÂÚ¹¥»÷


¿¨°Í˹»ùʵÑéÊÒICS CERT·¢Ã÷Ö÷ÒªÕë¶Ô¶íÂÞ˹¹¤ÒµÆóÒµµÄÍøÂç´¹Âڻ £¬£¬£¬£¬£¬¸Ã¹¥»÷»î¶¯Ê¹ÓÃÕýµ±µÄÔ¶³ÌÖÎÀíÈí¼þTeamViewerºÍRMSÀ´Ô¶³Ì¿ØÖÆÊÜѬȾµÄϵͳ¡£¡£¡£¡£Æ¾Ö¤ÏÖÓеķ¢Ã÷ £¬£¬£¬£¬£¬¹¥»÷ÕßµÄÖ÷ҪĿµÄÊÇ´ÓÄ¿µÄÆóÒµµÄÕË»§ÖÐÇÔÈ¡×ʽ𠣬£¬£¬£¬£¬µ«³ýÁ˾­¼ÃËðʧ֮Íâ £¬£¬£¬£¬£¬ÕâЩ¹¥»÷»¹»áµ¼ÖÂÄ¿µÄÆóÒµµÄÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯ÓÚ2017Äê11ÔÂ×îÏÈ £¬£¬£¬£¬£¬ÏÖÔÚ»¹ÔÚÒ»Á¬¾ÙÐÐÖС£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://securelist.com/attacks-on-industrial-enterprises-using-rms-and-teamviewer/87104/


¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷ÓÃÓÚ·Ö·¢FlawedAmmyy RATµÄÀ¬»øÓʼþ»î¶¯


Ç÷ÊÆ¿Æ¼¼Ñо¿ÍŶӼì²âµ½ÓÃÓÚ·Ö·¢Ô¶¿ØÄ¾ÂíFlawedAmmyy RATµÄÀ¬»øÓʼþ»î¶¯¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯»¹ÔÚ¶ñÒâPDFÎĵµÖÐʹÓÃ.SettingContent-msÎļþÀàÐÍÒÔÌӱܼì²â¡£¡£¡£¡£Ñо¿ÍŶӳÆÊÕµ½¸ÃÀ¬»øÓʼþµÄµç×ÓÓʼþÕË»§ÖÐÓÐÁè¼Ý50%ÊôÓÚÂíÀ´Î÷ÑÇ¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢¿ÏÄáÑÇ¡¢ÂÞÂíÄáÑÇ¡¢²¨À¼ºÍ°ÂµØÀûµÈ¹ú¼ÒµÄÒøÐС£¡£¡£¡£¸ÃFlawedAmmyy RAT±äÌåÓë½©Ê¬ÍøÂçNecurs·Ö·¢µÄÕë¶ÔÒøÐкÍPoS»úÓû§µÄ±äÌåÏàͬ¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/spam-campaign-abusing-settingcontent-ms-found-dropping-same-flawedammy-rat-distributed-by-necurs/


¡¾ÍþвÇ鱨¡¿Ñо¿Åú×¢ÎåÖÖÎļþÀàÐÍÕ¼ËùÓÐÀ¬»øÓʼþ¶ñÒ⸽¼þµÄ85%


ƾ֤·ÒÀ¼ÍøÂçÇå¾²¹«Ë¾F-SecureµÄ±¨¸æ £¬£¬£¬£¬£¬Ö»¹ÜµÁ°æ×ÊÔ´ÊǶñÒâÈí¼þµÄÖ÷ҪȪԴ £¬£¬£¬£¬£¬µ«À¬»øÓʼþÈÔÈ»ÊǽñÌìµÄÖ÷ҪѬȾǰÑԺͷ¸·¨·Ö×ÓµÄÊ×Ñ¡¹¤¾ß¡£¡£¡£¡£À¬»øÓʼþÈÔÈ»ÓÐÓõÄÖ÷ÒªÔµ¹ÊÔ­ÓÉÖ®Ò»ÊÇÓû§ÎÞ·¨Ê¶±ðÀ¬»øÓʼþ¡£¡£¡£¡£À¬»øÓʼþµÄµã»÷ÂÊÒѾ­´Ó2017ÄêϰëÄêµÄ13.4£¥ÉÏÉýÖÁ2018ÄêÉϰëÄêµÄ14.2£¥¡£¡£¡£¡£ÎåÖÖÎļþÀàÐÍ×é³ÉÁË85£¥µÄ¶ñÒ⸽¼þ £¬£¬£¬£¬£¬»®·ÖÊÇ.ZIP¡¢.DOC¡¢.XLS¡¢.PDFºÍ.7Z¡£¡£¡£¡£2018Äê´º¼¾µÄÀ¬»øÓʼþÑù±¾ÖÐ £¬£¬£¬£¬£¬46%ÊÇÔ¼»áÕ©Æ­»î¶¯ £¬£¬£¬£¬£¬23%ÊÇЯ´ø¶ñÒ⸽¼þµÄÓʼþ £¬£¬£¬£¬£¬31%°üÀ¨¶ñÒâÍøÕ¾µÄÁ´½Ó¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/just-five-file-types-make-up-85-percent-of-all-spam-malicious-attachments/


¡¾Êý¾Ýй¶¡¿RedditÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬²¿·ÖÓû§µÄÊý¾Ýй¶


RedditÐû²¼ÆäÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬²¿·ÖÓû§µÄÊý¾Ýй¶¡£¡£¡£¡£¹¥»÷ÕßÈÆ¹ýË«ÒòËØÈÏÖ¤£¨2FA£©½øÈëÁ˼¸ÃûÔ±¹¤µÄÕË»§ £¬£¬£¬£¬£¬²¢ÇÔÈ¡Á˲¿·Öµç×ÓÓʼþµØµã¡¢ÈÕÖ¾¼Í¼ÒÔ¼°°üÀ¨¼ÓÑιþÏ£ÃÜÂëµÄÒ»¸ö2007ÄêµÄÊý¾Ý¿â±¸·Ý¡£¡£¡£¡£¸Ã¹¥»÷ÊÂÎñ±¬·¢ÔÚ6ÔÂ14ÈÕÖÁ6ÔÂ18ÈÕÖ®¼ä £¬£¬£¬£¬£¬¹¥»÷ÕßÇÔÈ¡µÄÊý¾Ý¿â±¸·Ý°üÀ¨2005ÄêÖÁ2007Äê5ÔÂʱ´úµÄÓû§Êý¾Ý £¬£¬£¬£¬£¬ÈçÕË»§Æ¾Ö¤£¨Óû§ÃûºÍ¼ÓÑιþÏ£ÃÜÂ룩¡¢µç×ÓÓʼþµØµãºÍ¹ûÕæ/˽ÈËÐÂÎÅ¡£¡£¡£¡£ÔÚ2007Äê5ÔÂÖ®ºó×¢²áµÄÓû§ºÍÐû²¼µÄÌû×Ó±»ÒÔΪÊÇÇå¾²µÄ¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/reddit-announces-security-breach-after-hackers-bypassed-staffs-2fa/