¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180830

Ðû²¼Ê±¼ä 2018-08-30
¡¾ÆÊÎö±¨¸æ¡¿Ñо¿»ú¹¹Ðû²¼2018ÄêÖÐÇå¾²×ÛÊö£¬£¬£¬ £¬£¬£¬£¬¶ñÒâÍÚ¿ó¹¥»÷ͬ±ÈÔöÌí956£¥
Ç÷ÊÆ¿Æ¼¼Ðû²¼2018ÄêÖÐÇå¾²×ÛÊö±¨¸æ£¬£¬£¬ £¬£¬£¬£¬±¨¸æÖ¸³öÓë2017ÄêÕûÄêÏà±È£¬£¬£¬ £¬£¬£¬£¬2018ÄêÉϰëÄê¶ñÒâÍÚ¿ó¹¥»÷µÄ¼ì²âÊýÄ¿ÔöÌíÁË96%£»£»£»¶øÓë2017ÄêÉϰëÄêÏà±È£¬£¬£¬ £¬£¬£¬£¬ÔòÔöÌíÁË956%£¨½ü10±¶£©¡£¡£¡£¡£¡£±¨¸æ»¹Ö¸³ö£¬£¬£¬ £¬£¬£¬£¬Ç÷ÊÆ¿Æ¼¼ÔÚ2018ÄêÉϰëÄê×èÖ¹ÁË200¶àÒÚ´ÎÍþв£¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õߵ폷¨Õ½ÂÔÒѾ­±¬·¢ÁËת±ä£¬£¬£¬ £¬£¬£¬£¬´Ó°²ÅÅ¿ìËÙÖ§¸¶µÄÀÕË÷Èí¼þתÏòÇÔÈ¡Óû§µÄ×ʽðºÍÅÌËã»úËãÁ¦µÈÒþÄäµÄÊֶΡ£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.trendmicro.com/vinfo/us/security/research-and-analysis/threat-reports/roundup/unseen-threats-imminent-losses


¡¾¹¥»÷ÊÂÎñ¡¿Î÷°àÑÀÒøÐйÙÍøÔâµ½DDoS¹¥»÷£¬£¬£¬ £¬£¬£¬£¬ÍøÕ¾ÔÝʱÎÞ·¨»á¼û


ƾ֤·͸ÉçµÄ±¨µÀ£¬£¬£¬ £¬£¬£¬£¬´Ó8ÔÂ26ÈÕÐÇÆÚÈÕ×îÏÈÎ÷°àÑÀÒøÐеĹÙÍøÔâµ½ÁËÂþÑÜʽ¾Ü¾øÐ§À͹¥»÷£¨DDoS£©£¬£¬£¬ £¬£¬£¬£¬ÆäÍøÕ¾ÔÝʱÎÞ·¨»á¼û¡£¡£¡£¡£¡£¸ÃÒøÐеĽ²»°ÈËÌåÏÖ£¬£¬£¬ £¬£¬£¬£¬´Ë´Î¹¥»÷¶Ô¸ÃÒøÐеÄЧÀÍ»ò¸ÃÒøÐÐÓëÅ·ÖÞÖÐÑëÒøÐлòÆäËü»ú¹¹µÄͨѶûÓÐÔì³ÉÈκÎÓ°Ï죬£¬£¬ £¬£¬£¬£¬²¢ÇÒûÓÐÈκÎÊý¾Ýй¶µÄΣº¦¡£¡£¡£¡£¡£×èÖ¹ÖܶþÏÂÖ磬£¬£¬ £¬£¬£¬£¬¸ÃÒøÐеÄÍøÕ¾ÈÔ´¦ÓÚÀëÏß״̬¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://uk.reuters.com/article/us-spain-cyber-cenbank/bank-of-spains-website-hit-by-cyber-attack-idUKKCN1LC23B


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷ÓÃÓÚ·Ö·¢DarkComet RATµÄÀ¬»øÓʼþ»î¶¯


Çå¾²Ñо¿Ô±Vishal Thakur·¢Ã÷Ò»¸öÓÃÓÚ·Ö·¢DarkComet RATµÄÀ¬»øÓʼþ»î¶¯¡£¡£¡£¡£¡£¸ÃÀ¬»øÓʼþÖаüÀ¨Ãû³ÆÎªDOC000YUT600.pdf.zµÄ¸½¼þ£¬£¬£¬ £¬£¬£¬£¬Æä»á½«DarkComet RAT×°Öõ½Óû§µÄÅÌËã»úÉÏ¡£¡£¡£¡£¡£DarkComet¿ÉÒÔ¼ÍÈÎÃü»§µÄÓ¦ÓóÌÐòʹÓÃÇéÐκͼüÅÌÇû÷¼Í¼£¬£¬£¬ £¬£¬£¬£¬²¢½«ÕâЩÊý¾ÝÉúÑÄÔÚ£¥UserProfile£¥\AppData\Roaming\dclogs\Îļþ¼ÐϵÄÈÕÖ¾ÎļþÖС£¡£¡£¡£¡£ÕâЩÎļþ»áÒÔ²î±ðµÄ¾àÀëÉÏ´«ÖÁ¹¥»÷Õß¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/beware-of-fake-shipping-docs-malspam-pushing-the-darkcomet-rat/


¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶÓÐû²¼¹ØÓÚAndroidÌØ¹¤Èí¼þBusyGasperµÄÆÊÎö±¨¸æ


¿¨°Í˹»ùʵÑéÊÒÔÚ2018ÄêÍ·¼ì²âµ½Ò»¸öеÄAndroidÌØ¹¤Èí¼þBusyGasper¡£¡£¡£¡£¡£BusyGasperµÄÖØ´óÐÔ²»¸ß£¬£¬£¬ £¬£¬£¬£¬µ«¾ßÓÐÒ»Ð©ÌØÊâµÄ¹¦Ð§£¬£¬£¬ £¬£¬£¬£¬ÀýÈç¼àÌý×°±¸µÄ´«¸ÐÆ÷£¨Ô˶¯´«¸ÐÆ÷µÈ£©¡£¡£¡£¡£¡£ÆäЭÒé¾ßÓÐÔ¼100¸öÏÂÁ£¬£¬ £¬£¬£¬£¬»¹¿ÉÒÔÈÆ¹ý½ÚµçÓÅ»¯¹¦Ð§Doze¡£¡£¡£¡£¡£BusyGasper¿ÉÒÔÇÔÈ¡ÐÂÎÅÓ¦Óã¨ÈçWhatsApp¡¢ViberºÍFacebook£©µÄÊý¾Ý£¬£¬£¬ £¬£¬£¬£¬²¢¾ßÓмüÅ̼ͼ¹¦Ð§¡£¡£¡£¡£¡£BusyGasperͨ¹ýÊÖ¶¯×°Ö㬣¬£¬ £¬£¬£¬£¬Ö÷ÒªÕë¶Ô¶íÂÞ˹£¬£¬£¬ £¬£¬£¬£¬ÆäC&CЧÀÍÆ÷µÄIPÊôÓÚ¶íÂÞ˹µÄÒ»¸öÃâ·ÑµÄÍøÂçÍйÜЧÀÍUcoz¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://securelist.com/busygasper-the-unfriendly-spy/87627/


¡¾Îó²î²¹¶¡¡¿PHPÈí¼þ°ü¿âPackagistµÄ¹ÙÍøÐÞ¸´Ò»¸ö¿É±»Ð®ÖƵÄÇå¾²Îó²î


PackagistÍŶÓÔÚÆä¹Ù·½ÍøÕ¾ÉÏÐÞ¸´ÁËÒ»¸ö¿Éµ¼ÖÂÆäЧÀͱ»Ð®ÖƵÄÇå¾²Îó²î¡£¡£¡£¡£¡£PackagistÊÇPHP×î´óµÄÈí¼þ°ü´æ´¢¿â£¬£¬£¬ £¬£¬£¬£¬ÆäÿÔµÄ×°ÖðüÏÂÔØ´ÎÊýÁè¼Ý4ÒڴΡ£¡£¡£¡£¡£Çå¾²Ñо¿Ô±Max Justicz·¢Ã÷²¢±¨¸æÁËÕâ¸öÎó²î£¬£¬£¬ £¬£¬£¬£¬Æ¾Ö¤JusticzµÄ˵·¨£¬£¬£¬ £¬£¬£¬£¬PackagistÖ÷Ò³ÉÏÌá½»ÐÂPHP°üµÄ°´Å¥µÄÊäÈë×Ö¶ÎÔÊÐí¹¥»÷ÕßÒÔ$(MALICIOUS_COMMANDS)µÄÃûÌÃÔËÐжñÒâÏÂÁî¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/critical-flaw-fixed-in-packagist-phps-largest-package-repository/


¡¾Îó²î²¹¶¡¡¿Çå¾²Ñо¿Ö°Ô±·¢Ã÷OpenSSH±£´æÁíÒ»¸öÓû§Ãûö¾ÙÎó²î


QualysµÄÇå¾²Ñо¿Ö°Ô±ÔÚ×îа汾µÄOpenSSHÖз¢Ã÷ÁËÒ»¸öеÄÓû§Ãûö¾ÙÎó²î£¨CVE-2018-15919£©¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁË2011Äê9ÔÂÖ®ºóµÄËùÓÐOpenSSH°æ±¾¡£¡£¡£¡£¡£¸ÃÎó²îÓëÑо¿Ö°Ô±ÉÏÖÜ·¢Ã÷µÄÎó²î£¨CVE-2018-15473£©ÀàËÆ£¬£¬£¬ £¬£¬£¬£¬¶¼ÔÊÐí¹¥»÷ÕßÍÆ²âЧÀÍÆ÷ÉϵÄÓÐÓÃÓû§Ãû¡£¡£¡£¡£¡£OpenSSHµÄ¿ª·¢Ö°Ô±³Æ¸ÃÎó²îµÄÑÏÖØÐԽϵͣ¬£¬£¬ £¬£¬£¬£¬Òò´Ë²¢²»»áÓÅÏÈÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/openssh-versions-since-2011-vulnerable-to-oracle-attack/