¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180919
Ðû²¼Ê±¼ä 2018-09-19¡¾ÆÊÎö±¨¸æ¡¿¿¨°Í˹»ùʵÑéÊÒÐû²¼¹ØÓÚÎïÁªÍøÍþвÇ÷ÊÆµÄÆÊÎö±¨¸æ
ƾ֤±¾Öܶþ¿¨°Í˹»ùʵÑéÊÒÐû²¼µÄÎïÁªÍøÍþв±¨¸æ£¬£¬£¬£¬£¬£¬£¬2018ÄêÉϰëÄ꿨°Í˹»ùÍøÂçµ½µÄIoT¶ñÒâÈí¼þÑù±¾µÄÊýÄ¿ÊÇ2017ÄêÕûÄêµÄÈý±¶£¬£¬£¬£¬£¬£¬£¬¶ø2017ÄêµÄÊý×ÖÔòÊÇ2016ÄêµÄ10±¶¡£¡£¡£¡£¡£¡£¡£Ò×Êܹ¥»÷µÄIoT×°±¸°üÀ¨MikroTik·ÓÉÆ÷ÒÔ¼°TP-Link¡¢SonicWall¡¢CiscoºÍD-LinkµÄ×°±¸µÈ¡£¡£¡£¡£¡£¡£¡£×îÊܽӴýµÄ¹¥»÷ÏòÁ¿ÊÇTelnet¹¥»÷£¬£¬£¬£¬£¬£¬£¬Õ¼ËùÓй¥»÷µÄ75.40%¡£¡£¡£¡£¡£¡£¡£ÔÚÉæ¼°µ½IoT¹¥»÷ʱ£¬£¬£¬£¬£¬£¬£¬Mirai¼Ò×åÊÇ·¸·¨·Ö×ÓµÄÊ×Ñ¡¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬ÆäÕ¼ÓÐÁËËùÓй¥»÷µÄ15.97%¡£¡£¡£¡£¡£¡£¡£
https://securelist.com/new-trends-in-the-world-of-iot-threats/87991/
¡¾ÆÊÎö±¨¸æ¡¿RiskIQÐû²¼2018ÄêµÚ¶þ¼¾¶ÈµÄÒÆ¶¯ÍþÐ²Ì¬ÊÆ±¨¸æ
RiskIQÑо¿ÍŶÓÐû²¼2018ÄêµÚ¶þ¼¾¶ÈµÄÒÆ¶¯ÍþÐ²Ì¬ÊÆ±¨¸æ£¬£¬£¬£¬£¬£¬£¬ºÚÃûµ¥Ó¦Óü±¾çÔöÌí¡£¡£¡£¡£¡£¡£¡£×ÜÌå¶øÑÔ£¬£¬£¬£¬£¬£¬£¬RiskIQÔÚµÚ¶þ¼¾¶È¹²ÊӲ쵽52885¸öºÚÃûµ¥Ó¦Ó㬣¬£¬£¬£¬£¬£¬Õ¼ËùÓÐÓ¦ÓõÄ4%£¬£¬£¬£¬£¬£¬£¬±ÈµÚÒ»¼¾¶ÈÔöÌíÁË2%¡£¡£¡£¡£¡£¡£¡£Ä¾ÂíºÍ¹ã¸æÈí¼þÊÇ×î³£¼ûµÄÍþв¡£¡£¡£¡£¡£¡£¡£Google PlayÖеĺÚÃûµ¥Ó¦ÓÃ×î¶à£¬£¬£¬£¬£¬£¬£¬´ï28533¸ö£¬£¬£¬£¬£¬£¬£¬±ÈµÚÒ»¼¾¶ÈÔöÌíÁËÔ¼20000¸ö¡£¡£¡£¡£¡£¡£¡£Ñо¿ÍŶӻ¹ÔÚÓ¦ÓÃÊÐËÁÖ®ÍâÊӲ쵽11288¸öºÚÃûµ¥Ó¦Óᣡ£¡£¡£¡£¡£¡£
https://www.riskiq.com/blog/external-threat-management/q2-2018-mobile-threat-landscape-report/
¡¾Êý¾Ýй¶¡¿MongoDBÉèÖùýʧµ¼ÖÂÔ¼1100Íòµç×ÓÓʼþ¼Í¼¿É¹ûÕæ»á¼û
Çå¾²Ñо¿Ö°Ô±Bob DiachenkoÔÚ»¥ÁªÍøÉÏ·¢Ã÷Ò»¸ö¿É¹ûÕæ»á¼ûµÄMongoDB£¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÖаüÀ¨Ô¼1100ÍòÌõµç×ÓÓʼþ¼Í¼¡£¡£¡£¡£¡£¡£¡£Êý¾Ý¿âµÄ¾ÞϸΪ43.5GB£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÁËÓû§µÄÑÅ»¢µç×ÓÓÊÏä¼Í¼ÒÔ¼°ÐÕÃû¡¢ÎïÀíµØµã¡¢ÓÊÕþ±àÂëºÍÆÜÉí¶¼»áµÈСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÍйÜÔÚÃÀ¹úGrupo-SMSµÄ»ù´¡ÉèÊ©ÉÏ£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚ»¹²»ÖªµÀ¸ÃÊý¾Ý¿âµÄËùÓÐÕßµÄÉí·Ý¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/database-with-11-million-email-records-exposed/
¡¾Êý¾Ýй¶¡¿GovPayNet¹ÙÍø±£´æÎó²î£¬£¬£¬£¬£¬£¬£¬Áè¼Ý1400ÍòÓû§¼Í¼ÒÉй¶
ΪÃÀ¹úÖÝÕþ¸®ºÍµØ·½Õþ¸®ÌṩÔÚÏßÖ§¸¶Æ½Ì¨µÄGovPayNow.com±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬Áè¼Ý1400ÍòÓû§µÄСÎÒ˽¼ÒÐÅÏ¢ÒÉй¶¡£¡£¡£¡£¡£¡£¡£¸ÃÍøÕ¾Îª36¸öÖݵÄ2000¶à¸öÕþ¸®»ú¹¹ÌṩЧÀÍ£¬£¬£¬£¬£¬£¬£¬¹«Ãñ¿ÉÒÔͨ¹ýËüÀ´Ö§¸¶·£¿£¿£¿£¿î¡¢ÅÆÕշѺÍÕ˵¥µÈ¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Brian KrebsµÄ˵·¨£¬£¬£¬£¬£¬£¬£¬¸ÃÍøÕ¾µÄÔÚÏßÖ§¸¶ÊÕÌõÊǰ´Ë³Ðò±àºÅµÄ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄURLÖеÄÊý×ÖÀ´Éó²éÆäËüÈ˵ļͼ¡£¡£¡£¡£¡£¡£¡£ÕâЩ¼Í¼°üÀ¨Óû§µÄÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¼°ÒøÐп¨ºóËÄλÊý×ֵȡ£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖÒÑÔÚÖÜÄ©ÐÞ¸´ÁËÕâÒ»ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£
https://www.infosecurity-magazine.com/news/government-payment-service-exposes/
¡¾Îó²î²¹¶¡¡¿AppleÐû²¼Ð°汾iOS12£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´¶à¿î²úÆ·ÖеÄÇå¾²Îó²î
Apple±¾ÖÜÕýʽÐû²¼iOS 12£¬£¬£¬£¬£¬£¬£¬²¢ÐÞ¸´ÁËSafari¡¢watchOSºÍtvOSÖеĶà¸öÎó²î¡£¡£¡£¡£¡£¡£¡£iOS 12Öй²ÐÞ¸´ÁË16¸öÎó²î£¬£¬£¬£¬£¬£¬£¬iPhone 5s¼°Ö®ºóµÄ°æ±¾¡¢iPad Air¼°Ö®ºóµÄ°æ±¾ÒÔ¼°iPod touch 6Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£½ÏÑÏÖØµÄÎó²î°üÀ¨À¶ÑÀÖеÄÊäÈëÑéÖ¤Îó²î£¨CVE-2018-5383£©ÒÔ¼°SafariÖеÄÐÅϢй¶Îó²î£¨CVE-2018-4313£©µÈ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬tvOS 12ÖÐÐÞ¸´ÁË5¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬¶øwatchOS 5ÐÞ¸´ÁËÁíÍâµÄ4¸öÎó²î¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/ios-12-patches-memory-bugs-safari-12-fixes-data-leaks/
¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷ÒÆ¶¯Ìع¤Èí¼þPegasus±»ÓÃÓÚÕë¶Ô45¸ö¹ú¼ÒµÄÄ¿µÄ
ƾ֤Citizen LabµÄÒ»·Ýб¨¸æ£¬£¬£¬£¬£¬£¬£¬ÒÑÍùÁ½ÄêÀ´Òƶ¯Ìع¤Èí¼þPegasus±»ÓÃÓÚÕë¶ÔÈ«Çò45¸ö¹ú¼ÒµÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£PegasusÊÇÒÔÉ«Áй«Ë¾NSO¿ª·¢µÄÌØ¹¤Èí¼þ£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ¼à¿ØiPhoneºÍAndroid×°±¸µÄ»î¶¯£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚÍøÂçÓû§µÄ¶ÌÐÅ¡¢ÈÕÀú¡¢µç×ÓÓʼþ¡¢Î»Öá¢Âó¿Ë·çºÍÏà»úµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£PegasusÖ»ÏòÕþ¸®ºÍÖ´·¨»ú¹¹³öÊÛ¡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÖ¸³ö36ÃûÔËÓªÉÌÒ»Ö±ÔÚʹÓÃPegasusÔÚ45¸ö¹ú¼ÒÄÚ¿ªÕ¹¼àÊÓÐж¯¡£¡£¡£¡£¡£¡£¡£NSO½²»°È˳Ƹù«Ë¾Ã»ÓÐÎ¥·´Èκιú¼ÒµÄÖ´·¨¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2018/09/android-ios-hacking-tool.html