¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181031

Ðû²¼Ê±¼ä 2018-10-31
1¡¢µÚ¶þ¸ö¡°ÖÐÐË¡±·ºÆð£¬£¬£¬£¬£¬¸£½¨½ú»ª±»ÃÀÉÌÎñ²¿ÁÐÈë½ûÊÛÃûµ¥

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹úÉÌÎñ²¿ÖÜÒ»Ðû²¼¶Ô¸£½¨½ú»ª¼¯³Éµç·ÓÐÏÞ¹«Ë¾ÊµÑé½ûÊÛÁ£¬£¬£¬£¬Õ¥È¡ÃÀ¹úÆóÒµÏòÆä³öÊÛÊÖÒպͲúÆ·¡£¡£¡£¡£¡£¡£ÕâÊǼÌÖÐÐËÖ®ºó£¬£¬£¬£¬£¬ÃÀ¹úÕþ¸®ÔٴζÔÖйú¿Æ¼¼ÆóҵʵÑé½ûÊÛÁî¡£¡£¡£¡£¡£¡£±»´¦·ÖµÄ¸£½¨½ú»ªÍ¬ÑùÊôÓÚ¡°ÖйúÖÆÔì2025ÍýÏ롱£¬£¬£¬£¬£¬ÕâÊǶÔÖйú´æ´¢Ð¾Æ¬ÖÆÔìÒµµÄÖØ´ó¹¥»÷¡£¡£¡£¡£¡£¡£ÃÀ¹úÕþ¸®³Æ¸£½¨½ú»ªÉæ¼°Î¥·´ÃÀ¹ú¹ú¼ÒÇå¾²ÀûÒæµÄÐÐΪ£¬£¬£¬£¬£¬¸øÃÀ¹ú´øÀ´ÁËÑÏÖØµÄΣº¦¡£¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/us-bans-exports-to-chinese/


2¡¢AppleÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´iOS¡¢macOSÖеĶà¸öÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


AppleÕë¶Ô½¹µã²úÆ·Ðû²¼Çå¾²¸üУ¬£¬£¬£¬£¬°üÀ¨iOS 12.1¡¢Safari 12.0.1¡¢watchOS 5.1¡¢tvOS 12.1ºÍmacOS¸üеÈ£¬£¬£¬£¬£¬ÐÞ¸´Á˶à¸ö¿Éµ¼Ö´úÂëÖ´ÐС¢È¨ÏÞÌáÉýºÍÐÅϢй¶µÄÎó²î¡£¡£¡£¡£¡£¡£½ÏÑÏÖØµÄÎó²î°üÀ¨iOSÖеÄFaceTimeÎó²î£¨CVE-2018-4367£©£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õß´ÓÄ¿µÄ×°±¸ÌᳫFaceTimeºô½Ð£»£»£»macOSÖеĿɵ¼ÖÂ×°±¸Íß½âµÄÎó²î£¨CVE-2018-4407£©£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐíͳһ¸öWiFiÄڵĹ¥»÷Õßͨ¹ý·¢ËͶñÒâÊý¾Ý°üÀ´µ¼ÖÂÄ¿µÄ×°±¸Í߽⡣¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì¾ÙÐÐÉý¼¶¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/apple-fixes-creepy-facetime-vulnerability-crash-bug-in-macos-and-more/


3¡¢¿¨°Í˹»ùÐû²¼2018Äê¹¤ÒµÍøÂçÇ徲״̬°×ƤÊé

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¿¨°Í˹»ù×î½üÐû²¼µÄ2018Äê¹¤ÒµÍøÂçÇ徲״̬°×ƤÊéÖ¸³ö£¬£¬£¬£¬£¬Ëæ×ÅÓëÍⲿÌìϵÄÅþÁ¬Ò»Ö±Ôö¶à£¬£¬£¬£¬£¬ÔÚ¹¤ÒµITºÍOTÍøÂçÖÐÇå¾²ÐÔÕýÔÚ³ÉΪ×îÖ÷ÒªµÄÖ÷ÌâÖ®Ò»¡£¡£¡£¡£¡£¡£77%µÄ¹¤ÒµÇå¾²ÈËÊ¿ÒÔΪËûÃÇµÄÆóÒµºÜ¿ÉÄܳÉÎªÍøÂçÇå¾²ÊÂÎñµÄÄ¿µÄ£¬£¬£¬£¬£¬Í¬Ê±48%µÄÊÜ·ÃÕßÌåÏÖËûÃÇûÓÐרÃŵÄOT/ICSÊÂÎñÏìÓ¦ÍýÏë¡£¡£¡£¡£¡£¡£ÒÑÍù12¸öÔÂÄÚÁè¼ÝÒ»°ëµÄÆóÒµÌåÏÖËûÃÇûÓÐÂÄÀú¹ýÈκÎÇå¾²ÊÂÎñ£¬£¬£¬£¬£¬µ«Ðí¶àÆóÒµÊÂʵÉÏ»ù´¡Ã»Óмì²â»ò¸ú×Ù¹ýÈκι¥»÷¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://ics.kaspersky.com/media/2018-Kaspersky-ICS-Whitepaper.pdf


4¡¢Ç÷ÊÆ¿Æ¼¼Ðû²¼Ë®ÎñºÍÄÜÔ´Òªº¦»ù´¡ÉèʩΣº¦±¨¸æ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ç÷ÊÆ¿Æ¼¼Ðû²¼Ë®ÎñºÍÄÜÔ´Òªº¦»ù´¡ÉèÊ©£¨CI£©µÄΣº¦ÊӲ챨¸æ¡£¡£¡£¡£¡£¡£Í¨¹ý»¥ÁªÍøÉ¨Ã裨Ö÷ÒªÊÇShodan£©ºÍÎïÀíλÖÃÓ³É䣬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷Ðí¶à̻¶ºÍÒ×Êܹ¥»÷µÄHMIϵͳ¡£¡£¡£¡£¡£¡£ÕâЩϵͳ¶¼ÊÇÖÐСÐÍÆóÒµµÄϵͳ¡£¡£¡£¡£¡£¡£¹ØÓÚË®Îñϵͳ£¬£¬£¬£¬£¬Ì»Â¶µÄϵͳ°üÀ¨¼ÓÈÈ¡¢µØÈÈ¡¢Ë®±Ã¡¢¹ýÂË¡¢º£Ë®·´ÉøÍ¸ºÍÃð¾úϵͳµÄ¼à²âºÍ¿ØÖƽӿڵȡ£¡£¡£¡£¡£¡£¹ØÓÚÄÜԴϵͳ£¬£¬£¬£¬£¬°üÀ¨Ê¯ÓÍ¡¢×ÔÈ»Æø¡¢ÕÓÆøºÍµçÁ¦µÈϵͳ¡£¡£¡£¡£¡£¡£ÕâЩ̻¶µÄHMIʹµÃ¹¥»÷Õß¿ÉÒÔʵʱÉó²éÉú²úˮһÂÉÐÅÏ¢£¬£¬£¬£¬£¬ÉõÖÁ¿ÉÒÔÖ±½ÓÓëϵͳºÍ×°±¸¾ÙÐн»»¥¡£¡£¡£¡£¡£¡£
  Ô­ÎÄÁ´½Ó£º
https://documents.trendmicro.com/assets/white_papers/wp-exposed-and-vulnerable-critical-infrastructure-the-water-energy-industries.pdf


5¡¢McAfeeÐû²¼ÔÆÐ§ÀÍΣº¦±¨¸æ£¬£¬£¬£¬£¬21%µÄÔÆÎļþ°üÀ¨Ãô¸ÐÊý¾Ý

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


McAfeeÐû²¼ÔƽÓÄɺÍΣº¦±¨¸æ£¨2019°æ£©£¬£¬£¬£¬£¬±¨¸æµÄÖ÷Òª·¢Ã÷°üÀ¨£º21%µÄÔÆÎļþ°üÀ¨Ãô¸ÐÊý¾Ý£¬£¬£¬£¬£¬ÀàÐͰüÀ¨ÉñÃØÎļþ¡¢µç×ÓÓʼþ¡¢¼ÓÃܵÄÃÜÂë¡¢PII¡¢Ö§¸¶ÐÅÏ¢ÒÔ¼°PHIÐÅÏ¢£»£»£»8%µÄ¹²ÏíÎļþ°üÀ¨Ãô¸ÐÊý¾Ý£¬£¬£¬£¬£¬°üÀ¨Í¨¹ý¿ª·ÅÁ´½Ó¹²ÏíºÍÓëСÎÒ˽¼ÒÓʼþµØµã¹²ÏíµÄÎļþ£»£»£»¶àIaaSÕ½ÂÔÊDZê×¼£»£»£»ÔÆÍþвһÁ¬ÔöÌí£¬£¬£¬£¬£¬Æ½¾ùÿ¸ö×é֯ÿÔÂÂÄÀú31.3´ÎÔÆÇå¾²ÊÂÎñ£¬£¬£¬£¬£¬±ÈÈ¥ÄêͬÆÚÔöÌí27.7%£»£»£»ÏÕЩËùÓеÄ×éÖ¯¶¼»áÓöµ½Íþв¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.skyhighnetworks.com/cloud-computing-trends-2019/


6¡¢Ñо¿ÍŶӷ¢Ã÷Õë¶Ô¶íÂÞ˹Áª°î´¢±¸ÒøÐеÄľÂíGPlayed Banking

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


˼¿ÆTalosÍŶӷ¢Ã÷Ö÷ÒªÕë¶Ô¶íÂÞ˹Áª°î´¢±¸ÒøÐУ¨Sberbank£©µÄÒøÐÐľÂíGPlayed Banking¡£¡£¡£¡£¡£¡£GPlayed BankingÊÇÒøÐÐľÂíGPlayedµÄǰÉí£¬£¬£¬£¬£¬ËüÖ»Õë¶ÔSberbankµÄAutoPayЧÀ͵ÄÓû§¡£¡£¡£¡£¡£¡£¸ÃľÂíµÄÈö²¥·½·¨ÓëGPlayedÀàËÆ£¬£¬£¬£¬£¬¶¼ÊÇαװ³ÉÐéαµÄGoogle app store¾ÙÐÐÈö²¥¡£¡£¡£¡£¡£¡£¸ÃľÂíÊÇͨ¹ý.NET±àдµÄ£¬£¬£¬£¬£¬¶ñÒâ´úÂë°üÀ¨ÔÚPlayMarket.dllÖС£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2018/10/gplayerbanker.html


ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí