¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180802
Ðû²¼Ê±¼ä 2018-08-02¡¾ÍþвÇ鱨¡¿ÃÀ¹úÉÌÎñ²¿ÖƲÃÃûµ¥ÐÂÔö44¼ÒÖйú¸ß¿Æ¼¼ÆóÒµ
ƾ֤ÃÀ¹úÁª°î¹«±¨£¨FederalRegister£¬£¬£¬£¬£¬ÃÀ¹úÁª°îÕþ¸®µÄÕþ¸®¹«±¨£©ÍøÕ¾Ðû²¼µÄ×îÐÂÐÅÏ¢ÏÔʾ£¬£¬£¬£¬£¬ÃÀ¹úBIS½«ÓÚÃÀ¶«Ê±¼ä8ÔÂ1ÈÕÕýʽÒÔ¹ú¼ÒÇå¾²ºÍÍâ½»ÀûÒæÎªÓÉ£¬£¬£¬£¬£¬½«44¼ÒÖйúÆóÒµ£¨8¸öʵÌåºÍ36¸öÁ¥Êô»ú¹¹£©ÁÐÈë³ö¿Ú¹ÜÖÆÊµÌåÇåµ¥£¬£¬£¬£¬£¬ÆäÖаüÀ¨Ðí¶àÑо¿»ú¹¹¡£¡£¡£¡£ÃÀ¹úÕýʽ×îÏȶÔÖйú¾ÙÐÐÊÖÒÕ·â±Õ¡£¡£¡£¡£Õâ44¼ÒÆóÒµËùÓж¼ÊÇÖйú¸ß¿Æ¼¼ÆóÒµ£¬£¬£¬£¬£¬ÒÔº½¿Õº½Ìì¡¢¾ü¹¤ÀàÆóҵΪÖ÷¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://weibo.com/ttarticle/p/show?id=2309614268300610741920
¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷ʹÓÃNSOÌØ¹¤Èí¼þÕë¶ÔÉ³ÌØ°¢À²®ÈËȨ×éÖ¯µÄ¹¥»÷»î¶¯
2018Äê6Ô¹ú¼ÊÌØÉâ×éÖ¯µÄÒ»ÃûÊÂÇéÖ°Ô±ÊÕµ½¶ñÒâµÄWhatsAppÐÂÎÅ£¬£¬£¬£¬£¬ÆäÖаüÀ¨ÓëÉ³ÌØ°¢À²®ÓйصĴ¹ÂÚÁ´½Ó¡£¡£¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷ÁíÒ»Î»É³ÌØÈËȨÖ÷ÒåÕßÒ²ÊÕµ½ÁËÀàËÆµÄÐÂÎÅ¡£¡£¡£¡£ÆÊÎöÅú×¢ÕâЩ¶ñÒâÐÂÎŽ«»áµ¼ÖÂѬȾÒÔÉ«ÁÐ¼à¿Ø¹©Ó¦ÉÌNSO¼¯ÍųöÊÛµÄÉÌÒµÌØ¹¤Èí¼þPegasus¡£¡£¡£¡£PegasusÖ¼ÔÚÔÊÐí¹¥»÷Õß»á¼ûÄ¿µÄµÄÊý¾Ý£¬£¬£¬£¬£¬°üÀ¨¶ÌÐÅ¡¢µç×ÓÓʼþ¡¢WhatsAppÐÂÎÅ¡¢Óû§µÄλÖá¢Âó¿Ë·çºÍÉãÏñÍ·¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/iphone-hacking-spyware.html
¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷ʹÓÃRMSºÍTeamViewerÕë¶Ô¶í¹¤ÒµÆóÒµµÄ´¹ÂÚ¹¥»÷
¿¨°Í˹»ùʵÑéÊÒICS CERT·¢Ã÷Ö÷ÒªÕë¶Ô¶íÂÞ˹¹¤ÒµÆóÒµµÄÍøÂç´¹Âڻ£¬£¬£¬£¬£¬¸Ã¹¥»÷»î¶¯Ê¹ÓÃÕýµ±µÄÔ¶³ÌÖÎÀíÈí¼þTeamViewerºÍRMSÀ´Ô¶³Ì¿ØÖÆÊÜѬȾµÄϵͳ¡£¡£¡£¡£Æ¾Ö¤ÏÖÓеķ¢Ã÷£¬£¬£¬£¬£¬¹¥»÷ÕßµÄÖ÷ҪĿµÄÊÇ´ÓÄ¿µÄÆóÒµµÄÕË»§ÖÐÇÔÈ¡×ʽ𣬣¬£¬£¬£¬µ«³ýÁ˾¼ÃËðʧ֮Í⣬£¬£¬£¬£¬ÕâЩ¹¥»÷»¹»áµ¼ÖÂÄ¿µÄÆóÒµµÄÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯ÓÚ2017Äê11ÔÂ×îÏÈ£¬£¬£¬£¬£¬ÏÖÔÚ»¹ÔÚÒ»Á¬¾ÙÐÐÖС£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securelist.com/attacks-on-industrial-enterprises-using-rms-and-teamviewer/87104/
¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷ÓÃÓÚ·Ö·¢FlawedAmmyy RATµÄÀ¬»øÓʼþ»î¶¯
Ç÷ÊÆ¿Æ¼¼Ñо¿ÍŶӼì²âµ½ÓÃÓÚ·Ö·¢Ô¶¿ØÄ¾ÂíFlawedAmmyy RATµÄÀ¬»øÓʼþ»î¶¯¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯»¹ÔÚ¶ñÒâPDFÎĵµÖÐʹÓÃ.SettingContent-msÎļþÀàÐÍÒÔÌӱܼì²â¡£¡£¡£¡£Ñо¿ÍŶӳÆÊÕµ½¸ÃÀ¬»øÓʼþµÄµç×ÓÓʼþÕË»§ÖÐÓÐÁè¼Ý50%ÊôÓÚÂíÀ´Î÷ÑÇ¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢¿ÏÄáÑÇ¡¢ÂÞÂíÄáÑÇ¡¢²¨À¼ºÍ°ÂµØÀûµÈ¹ú¼ÒµÄÒøÐС£¡£¡£¡£¸ÃFlawedAmmyy RAT±äÌåÓë½©Ê¬ÍøÂçNecurs·Ö·¢µÄÕë¶ÔÒøÐкÍPoS»úÓû§µÄ±äÌåÏàͬ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/spam-campaign-abusing-settingcontent-ms-found-dropping-same-flawedammy-rat-distributed-by-necurs/
¡¾ÍþвÇ鱨¡¿Ñо¿Åú×¢ÎåÖÖÎļþÀàÐÍÕ¼ËùÓÐÀ¬»øÓʼþ¶ñÒ⸽¼þµÄ85%
ƾ֤·ÒÀ¼ÍøÂçÇå¾²¹«Ë¾F-SecureµÄ±¨¸æ£¬£¬£¬£¬£¬Ö»¹ÜµÁ°æ×ÊÔ´ÊǶñÒâÈí¼þµÄÖ÷ҪȪԴ£¬£¬£¬£¬£¬µ«À¬»øÓʼþÈÔÈ»ÊǽñÌìµÄÖ÷ҪѬȾǰÑԺͷ¸·¨·Ö×ÓµÄÊ×Ñ¡¹¤¾ß¡£¡£¡£¡£À¬»øÓʼþÈÔÈ»ÓÐÓõÄÖ÷ÒªÔµ¹ÊÔÓÉÖ®Ò»ÊÇÓû§ÎÞ·¨Ê¶±ðÀ¬»øÓʼþ¡£¡£¡£¡£À¬»øÓʼþµÄµã»÷ÂÊÒѾ´Ó2017ÄêϰëÄêµÄ13.4£¥ÉÏÉýÖÁ2018ÄêÉϰëÄêµÄ14.2£¥¡£¡£¡£¡£ÎåÖÖÎļþÀàÐÍ×é³ÉÁË85£¥µÄ¶ñÒ⸽¼þ£¬£¬£¬£¬£¬»®·ÖÊÇ.ZIP¡¢.DOC¡¢.XLS¡¢.PDFºÍ.7Z¡£¡£¡£¡£2018Äê´º¼¾µÄÀ¬»øÓʼþÑù±¾ÖУ¬£¬£¬£¬£¬46%ÊÇÔ¼»áթƻ£¬£¬£¬£¬£¬23%ÊÇЯ´ø¶ñÒ⸽¼þµÄÓʼþ£¬£¬£¬£¬£¬31%°üÀ¨¶ñÒâÍøÕ¾µÄÁ´½Ó¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/just-five-file-types-make-up-85-percent-of-all-spam-malicious-attachments/
¡¾Êý¾Ýй¶¡¿RedditÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬²¿·ÖÓû§µÄÊý¾Ýй¶
RedditÐû²¼ÆäÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬²¿·ÖÓû§µÄÊý¾Ýй¶¡£¡£¡£¡£¹¥»÷ÕßÈÆ¹ýË«ÒòËØÈÏÖ¤£¨2FA£©½øÈëÁ˼¸ÃûÔ±¹¤µÄÕË»§£¬£¬£¬£¬£¬²¢ÇÔÈ¡Á˲¿·Öµç×ÓÓʼþµØµã¡¢ÈÕÖ¾¼Í¼ÒÔ¼°°üÀ¨¼ÓÑιþÏ£ÃÜÂëµÄÒ»¸ö2007ÄêµÄÊý¾Ý¿â±¸·Ý¡£¡£¡£¡£¸Ã¹¥»÷ÊÂÎñ±¬·¢ÔÚ6ÔÂ14ÈÕÖÁ6ÔÂ18ÈÕÖ®¼ä£¬£¬£¬£¬£¬¹¥»÷ÕßÇÔÈ¡µÄÊý¾Ý¿â±¸·Ý°üÀ¨2005ÄêÖÁ2007Äê5ÔÂʱ´úµÄÓû§Êý¾Ý£¬£¬£¬£¬£¬ÈçÕË»§Æ¾Ö¤£¨Óû§ÃûºÍ¼ÓÑιþÏ£ÃÜÂ룩¡¢µç×ÓÓʼþµØµãºÍ¹ûÕæ/˽ÈËÐÂÎÅ¡£¡£¡£¡£ÔÚ2007Äê5ÔÂÖ®ºó×¢²áµÄÓû§ºÍÐû²¼µÄÌû×Ó±»ÒÔΪÊÇÇå¾²µÄ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/reddit-announces-security-breach-after-hackers-bypassed-staffs-2fa/