¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180813

Ðû²¼Ê±¼ä 2018-08-13

¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷Õë¶Ô°ÍÎ÷ÒøÐеÄDNSÐ®ÖÆ¹¥»÷»î¶¯


RadwareÑо¿ÍŶӷ¢Ã÷¹¥»÷ÕßÕýÔÚÕë¶Ô°ÍÎ÷µÄDLink DSL·ÓÉÆ÷£¬£¬£¬£¬£¬Í¨¹ýDNSÐ®ÖÆ¹¥»÷½«ÒøÐÐÓû§Öض¨ÏòÖÁ´¹ÂÚÍøÕ¾²¢ÇÔÈ¡ÆäÒøÐÐÕË»§µÄµÇ¼ƾ֤¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÐÞ¸ÄÁËÕâЩ·ÓÉÆ÷×°±¸ÖеÄDNSÉèÖ㬣¬£¬£¬£¬½«ÆäÖ¸Ïò¶ñÒâµÄDNSЧÀÍÆ÷£¨69.162.89.185ºÍ198.50.222.136£©£¬£¬£¬£¬£¬ÕâЩװ±¸ÔÚ»á¼ûBanco de Brasil£¨www.bb.com.br£©ºÍItau Unibanco£¨www.itau.com.br£©Ê±½«±»Öض¨ÏòÖÁ¶ñÒâµÄipµØµã¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ç¿µ÷³Æ£¬£¬£¬£¬£¬ÕâÖÖÐ®ÖÆ²»ÐèÒªÈκεÄÓû§½»»¥¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://security.radware.com/ddos-threats-attacks/threat-advisories-attack-reports/dns-hijacking-brazil-banks/


¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶÓÑÝʾÔõÑù¹¥»÷Ò½ÁÆ×°±¸£¬£¬£¬£¬£¬Ä£ÄâºÍÐ޸ϼÕßµÄÉúÃüÌåÕ÷


McAfeeÑо¿ÍŶÓÑÝʾÔõÑù¹¥»÷Ò½ÁÆ×°±¸²¢Ä£ÄâºÍÐ޸ϼÕßµÄÉúÃüÌåÕ÷¡£¡£¡£¡£¡£¡£RWHATЭÒéÊÇÒ½ÁÆ×°±¸ÓÃÓÚ¼à¿Ø»¼Õß²¡ÇéºÍÉúÃüÌåÕ÷µÄÍøÂçЭÒéÖ®Ò»£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷¸ÃЭÒéûÓÐʹÓÃÉí·ÝÑéÖ¤ºÍ¼ÓÃÜ£¬£¬£¬£¬£¬²¢ÇÒ·¢ËÍÁËһЩÃô¸ÐµÄ¡¢ÓÉHIPAA¹ÜÖÆµÄ»¼ÕßÐÅÏ¢£¬£¬£¬£¬£¬ÀýÈçÐÕÃû¡¢³öÉúÈÕÆÚ¡¢»¼Õß´²Î»ºÅºÍ·¿¼äºÅµÈ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±¿ÉÒÔͨ¹ý¼òÆÓµÄÒªÁ콫ÐÅÏ¢×¢ÈëЭÒéÖÐÀ´Ä£ÄâºÍÐ޸ϼÕßµÄÊý¾Ý£¬£¬£¬£¬£¬Õâ¿ÉÄÜÓÕÆ­Ò½ÎñÖ°Ô±£¬£¬£¬£¬£¬µ¼ÖÂÑÏÖØµÄЧ¹û¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://securingtomorrow.mcafee.com/mcafee-labs/80-to-0-in-under-5-seconds-falsifying-a-medical-patients-vitals/


¡¾¶ñÒâÈí¼þ¡¿Çå¾²Ñо¿Ö°Ô±·¢Ã÷ÀÕË÷Èí¼þDharmaµÄбäÖÖCmb


Çå¾²Ñо¿Ö°Ô±Michael Gillespie·¢Ã÷ÀÕË÷Èí¼þDharmaµÄÒ»¸öбäÖÖ£¬£¬£¬£¬£¬¸Ã±äÖÖÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.cmbÀ©Õ¹Ãû¡£¡£¡£¡£¡£¡£ÏÖÔÚ»¹Ã»Óв½·¥Ã⺬»ìÃܸñäÖÖ¼ÓÃܵÄÎļþ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈÔÚInternetÉÏɨÃ迪ÆôÁËTCP¶Ë¿Ú3389µÄÖ÷»ú£¬£¬£¬£¬£¬È»ºóͨ¹ý±©Á¦ÆÆ½âÆäRDPÃÜÂ룬£¬£¬£¬£¬²¢ÔÚ»ñµÃ»á¼ûȨÏÞºóÊÖ¶¯×°ÖÃÀÕË÷Èí¼þDharma¡£¡£¡£¡£¡£¡£¸Ã±äÖÖÔÚ¼ÓÃÜÎļþºó¸½¼ÓµÄÀ©Õ¹ÃûÀàËÆÓÚ.id-[id].[email].cmbµÄÃûÌᣡ£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-cmb-dharma-ransomware-variant-released/


¡¾Êý¾Ýй¶¡¿Ñо¿Ö°Ô±³ÆGoDaddyÒòAWSÉèÖùýʧµ¼Ö²¿·ÖÊý¾Ýй¶


UpGuardÑо¿ÍŶӷ¢Ã÷GoDaddyÒòAWSÉèÖùýʧµ¼Ö²¿·ÖÊý¾Ýй¶£¬£¬£¬£¬£¬Ð¹Â¶Éæ¼°µÄÎļþËÆºõÊÇGoDaddyÔÚAWSÔÆÉÏÔËÐеĻù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÎļþ°üÀ¨Ô¼3.1Íò¸öϵͳµÄ»ù±¾ÉèÖÃÐÅÏ¢£¬£¬£¬£¬£¬ÈçÖ÷»úÃû¡¢²Ù×÷ϵͳ¡¢ÊÂÇé¸ºÔØ¡¢AWSÇøÓò¡¢ÄÚ´æºÍCPU¹æ¸ñµÈ£¬£¬£¬£¬£¬ÉõÖÁ»¹°üÀ¨AWSÔÚ²î±ðÇéÐÎϸøÓèµÄÕÛ¿ÛÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£ÏÖʵÉÏ£¬£¬£¬£¬£¬ÕâЩÊý¾ÝÖ±½Óй¶ÁËÒ»¸ö¹æÄ£ºÜÊÇ´óµÄAWSÔÆ»ù´¡ÉèÊ©°²ÅÅÇéÐΡ£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75271/data-breach/godaddy-aws-data-leak.html


¡¾Çå¾²²¥±¨¡¿ÃÀ¹úTSAÈÏ¿ÉÕë¶ÔÃÀ¹ú¹«ÃñµÄÐÂ¼à¿ØÏîÄ¿Quiet Skies


ƾ֤ÃÀ¹úÔËÊäÇå¾²ÖÎÀí¾Ö£¨TSA£©£¬£¬£¬£¬£¬½ü¼¸¸öÔÂÀ´Quiet SkiesÏîÄ¿ÒѾ­¼à¿ØÁËÔ¼5000Ãûº£ÄÚº½°àÉϵÄÃÀ¹ú¹«Ãñ¡£¡£¡£¡£¡£¡£¸ÃÏîĿּÔÚÍøÂ繫Ãñ¼°ÆäÐÐΪµÄÆÕ±éÐÅÏ¢£¬£¬£¬£¬£¬ÆäÊܵ½ÁËÒþ˽± £»£»£»£»£»¤Ö÷ÒåÕߵį·ÆÀ£¬£¬£¬£¬£¬ÓÉÓÚÕþ¸®¶ÔûÓÐÉæÏÓ·¸·¨»ò¼ÓÈë¿Ö²À×éÖ¯µÄÃÀ¹ú¹«ÃñʵÑéÁË¼à¿Ø¡£¡£¡£¡£¡£¡£Æ¾Ö¤Quiet SkiesÏîÄ¿£¬£¬£¬£¬£¬ÌìÌì³Ë×øº£ÄÚº½°àµÄ¹«ÃñÖж¼ÓÐÔ¼40-50È˱»Ñ¡ÖУ¬£¬£¬£¬£¬ÆäÖÐÔ¼ÓÐ35ÈË»áÊܵ½¿Õ¾¯µÄ¸ú×ÙºÍ¼à¿Ø¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75263/digital-id/quiet-skies-surveillance-us.html


¡¾Îó²î²¹¶¡¡¿Ñо¿Ö°Ô±Åû¶25¿îAndroidÖÇÄÜÊÖ»úÖеÄ47¸öÇå¾²Îó²î


KryptowireÇå¾²Ñо¿Ö°Ô±Åû¶25¿îAndroidÖÇÄÜÊÖ»úµÄ¹Ì¼þºÍĬÈÏÓ¦ÓÃÖеÄ47¸öÇå¾²Îó²î£¬£¬£¬£¬£¬ÆäÖÐÔÚÃÀ¹úÏúÊÛµÄÊÖ»úÐͺÅΪ11¿î¡£¡£¡£¡£¡£¡£Ãûµ¥ÉϵÄÖÇÄÜÊÖ»úÆ·ÅÆ£¨OEM£©°üÀ¨ÖÐÐË¡¢Ë÷Äᡢŵ»ùÑÇ¡¢LG¡¢»ªË¶ºÍAlcatelµÈ¡£¡£¡£¡£¡£¡£Ò»Ð©Îó²îÔÊÐí¹¥»÷Õß´ÓÓû§µÄÊÖ»úÖмìË÷»ò·¢ËͶÌÐÅ¡¢½ØÆÁ»ò¼ÆÁ¡¢¼ìË÷ÁªÏµÈËÁÐ±í¡¢Ç¿ÖÆ×°ÖõÚÈý·½í§ÒâÓ¦ÓÃÒÔ¼°´Ó×°±¸ÉϲÁ³ýÓû§µÄÊý¾ÝµÈ¡£¡£¡£¡£¡£¡£ÏêϸÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/vulnerabilities-found-in-the-firmware-of-25-android-smartphone-models/