°Ä´óÀûÑǹ«Ë¾BlueScopeÔâµ½¹¥»÷µ¼Ö²¿·ÖÓªÒµÖÐÖ¹£»£»£»£» £»ÈÕ±¾¹«Ë¾NikkeiÔâµ½¹¥»÷£¬£¬£¬£¬Áè¼Ý1.2ÍòÈËÐÅϢй¶

Ðû²¼Ê±¼ä 2020-05-19

1.°Ä´óÀûÑǹ«Ë¾BlueScopeÔâµ½¹¥»÷µ¼Ö²¿·ÖÓªÒµÖÐÖ¹


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


°Ä´óÀûÑǹ«Ë¾BlueScopeÓÚÉÏÖÜÎåÈ·¶¨£¬£¬£¬£¬ÆäÔâµ½ÁËÍøÂç¹¥»÷²¢ÇÒÒѾ­Ó°Ïìµ½ÁËËûÃǵÄITϵͳ£¬£¬£¬£¬µ¼Ö¸ù«Ë¾²¿·ÖÓªÒµÖÐÖ¹¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬´Ë´ÎÊÂÎñÓ°ÏìÁËÆäÔÚ°Ä´óÀûÑǵÄÖÆÔìºÍÏúÊÛÓªÒµ£¬£¬£¬£¬µ«Í¨¹ýһЩ±äͨ²½·¥£¬£¬£¬£¬¸Ã¹«Ë¾µÄÆäËûÁ÷³ÌÈÔ¿ÉÒÔÕý³£ÔËÐС£¡£¡£¡£¾Ý¹«Ë¾CFO Tania Archibald˵£¬£¬£¬£¬´Ë´Î¹¥»÷ÊÇÔڸù«Ë¾µÄÃÀ¹úÓªÒµÖз¢Ã÷µÄ£¬£¬£¬£¬Ö®ºó¹«Ë¾Á¬Ã¦¶Ô´ËÊÂ×ö³öÁËÏìÓ¦²½·¥¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬¸Ã¹«Ë¾ÕýÔÚÆð¾¢ÐÞ¸´ÊÜÓ°Ïìϵͳ£¬£¬£¬£¬ÒÔ»Ö¸´Õý³£Ð§ÀͺÍÔËÓª£¬£¬£¬£¬Éл¹Ã»ÓÐÕë¶Ô´Ë´Î¹¥»÷µÄÏêϸÐÅÏ¢¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/bluescope-reports-cyber-incident-affecting-australian-operations/


2.ÈÕ±¾¹«Ë¾NikkeiÔâµ½¹¥»÷£¬£¬£¬£¬Áè¼Ý1.2ÍòÈËÐÅϢй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÈÕ±¾µÄÈÕ¾­¼¯ÍÅ£¨Nikkei Inc.£©5ÔÂ12ÈÕÐû²¼£¬£¬£¬£¬ÆäÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬µ¼Ö¼¯ÍÅ12514È˵ÄСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨¶­Ê»á³ÉÔ±¡¢ÕýʽºÍ¼æÖ°Ô±¹¤ÒÔ¼°ÈÕ¾­×ܲ¿¼°ÆäijЩ¼¯ÍŹ«Ë¾ÆäËûÖ°Ô±µÄÐÕÃûºÍµç×ÓÓʼþµØµã¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬Ã»ÓÐ×ß©Óë¶ÁÕߺͿͻ§ÓйصÄÐÅÏ¢£¬£¬£¬£¬Ò²Ã»ÓÐ×ß©Æä¼ÇÕßÍøÂçµÄÐÂÎű¨µÀÐÅÏ¢¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬´Ë´Î¹¥»÷±¬·¢ÔÚ5ÔÂ8ÈÕ£¬£¬£¬£¬¸Ã¹«Ë¾Ô±¹¤ÊÕµ½²¢·­¿ªÁËÒ»·â´øÓв¡¶¾¸½¼þµÄµç×ÓÓʼþµ¼ÖÂÆäÅÌËã»úÊܵ½Ñ¬È¾¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬Ñ¬È¾²¡¶¾ÊÇÐÂÐͲ¡¶¾£¬£¬£¬£¬Òò´ËÏÖÔÚÐè񻮮·ÑһЩʱ¼ä¾ÙÐмì²â¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://mainichi.jp/english/articles/20200513/p2a/00m/0na/002000c


3.ÃÀ¹úFinCENÖÒÑÔÏÖÔÚ±£´æ´ó¹æÄ£µÄÐéÄâÇ®±ÒÕ©Æ­»î¶¯


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹ú½ðÈÚ·¸·¨Ö´·¨ÍøÂçFinCENÖÒÑÔÏÖÔÚ±£´æ´ó¹æÄ£µÄÐéÄâÇ®±ÒÕ©Æ­»î¶¯¡£¡£¡£¡£FinCENÈÏÕæÈËKenneth BlancoÌåÏÖ£¬£¬£¬£¬ÏÖÔÚÍøÂç·¸·¨·Ö×ÓÖ÷ÒªÒÔÐéÄâÇ®±ÒΪĿµÄ£¬£¬£¬£¬Òò´ËÓ¦ÖØµã¹Ø×¢½ðÈÚÕ©Æ­¡£¡£¡£¡£FinCENÌåÏÖ£¬£¬£¬£¬×Ô2013ÄêÒÔÀ´£¬£¬£¬£¬ËûÃÇ×ܹ²ÊÕµ½Á˽ü7ÍòÆð¼ÓÃÜÇ®±ÒÕ©Æ­»î¶¯µÄ¿ÉÒɻ±¨¸æ£¨SAR£©£¬£¬£¬£¬¶øÔÚCOVID-19ʱ´ú£¬£¬£¬£¬ÕâÖÖÍþвÔöÌíÁË10±¶¡£¡£¡£¡£ÔÚÒßÇéʱ´ú£¬£¬£¬£¬ÆäËûÀàÐ͵ÄÍøÂç¹¥»÷Ò²²ã³ö²»Ç£¬£¬£¬ºÃ±ÈÀÕË÷Èí¼þ¹¥»÷¡¢ÐéαҽÁƲúÆ·ÏúÊۺʹú±ÒͶ×ÊÕ©Æ­µÈ¡£¡£¡£¡£ÓÉÓÚCOVID-19£¬£¬£¬£¬´ó²¿·ÖÈ˺ÍÕþ¸®¹ÙÔ±ÔڼҰ칫£¬£¬£¬£¬ÕâÐ©ÍøÂç×ï·¸»áͨ¹ý¹¥»÷VPNºÍÔ¶³Ì×ÀÃæÐ­ÒéµÈÔ¶³ÌÓ¦ÓóÌÐòÖеÄÎó²î£¬£¬£¬£¬ÒÔÇÔÊØÐÅÏ¢¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2020/05/fincen-chief-blanco-warns-of-wide-scale.html


4.ºÚ¿Í×éÖ¯RATicate'sʹÓÃNSIS×°ÖóÌÐò·Ö·¢RAT


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


SophosµÄÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öºÚ¿Í×éÖ¯RATicate's£¬£¬£¬£¬¸Ã×é֯ʹÓÃNSIS×°ÖóÌÐò¶Ô¹¤Òµ¹«Ë¾Ìᳫ¿Í¹¥»÷£¬£¬£¬£¬ÒÔ·Ö·¢RATºÍÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ¡£¡£¡£¡£¸Ã×éÖ¯ÔÚ2019Äê11ÔÂÖÁ2020Äê1ÔÂʱ´úÕë¶ÔÅ·ÖÞ¡¢Öж«ºÍº«¹úµÄ¹«Ë¾×ܹ²ÌᳫÁË5´Î¹¥»÷¡£¡£¡£¡£Sophos±¨¸æËµÃ÷£¬£¬£¬£¬ºÚ¿ÍÓÃÁ½ÖÖ·½·¨Í¨¹ý´¹ÂÚÈí¼þ·Ö·¢RAT£¬£¬£¬£¬ÆäÒ»ÊÇʹÓôøÓÐÓÐNSIS×°ÖóÌÐòµÄZIP¡¢UDFºÍIMG¸½¼þ£¬£¬£¬£¬Æä¶þÊÇ´ÓÔ¶³ÌЧÀÍÆ÷ÏÂÔØÓÐÓøºÔØXLSºÍRTFÎĵµ¡£¡£¡£¡£Sophos·¢Ã÷´Ë´Î¹¥»÷Öкڿͻ¹ÓÃÁËÐí¶à¹¤¾ß£¬£¬£¬£¬°üÀ¨Lokibot£¬£¬£¬£¬Betabot£¬£¬£¬£¬FormbookºÍAgentTeslaµÈ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2020/05/sophos-found-group-abusing-nsis.html


5.ÐÂÐ͹¥»÷BIAS¿ÉʹÓÃÀ¶ÑÀ¹¥»÷ÊÖ»úµÈ×°±¸


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



Ñо¿Ö°Ô±·¢Ã÷ÁËÀ¶ÑÀÎÞÏßЭÒéÖеÄÒ»¸öÐÂÎó²îBIAS£¬£¬£¬£¬¿É±»Ê¹Óù¥»÷ÏÖ´ú»¥Á¬×°±¸£¬£¬£¬£¬ÀýÈçÖÇÄÜÊÖ»ú¡¢Æ½°åµçÄÔ¡¢Ìõ¼Ç±¾µçÄÔºÍÖÇÄÜIoT×°±¸µÈ¡£¡£¡£¡£¸ÃÎó²îÈ«³ÆÎªBluetooth Impersonation AttackS£¬£¬£¬£¬Ó°ÏìÁ˾­µä°æÀ¶ÑÀЭÒé¡£¡£¡£¡£¸Ã¹¥»÷·½·¨Õë¶ÔµÄÊÇ×°±¸¼äµÄºã¾ÃÃÜÔ¿£¬£¬£¬£¬µ±Á½¸öÀ¶ÑÀ×°±¸Ê×´ÎÅä¶Ôʱ½«ÌìÉú´ËÃÜÔ¿£¬£¬£¬£¬¶øBIAS¿ÉÒÔʹ¹¥»÷Õßð³äÏÈǰÅä¶Ô×°±¸µÄÉí·Ý£¬£¬£¬£¬²¢ÀֳɾÙÐÐÉí·ÝÑéÖ¤²¢ÅþÁ¬µ½ÁíÒ»¸ö×°±¸£¬£¬£¬£¬¶øÎÞÐèÖªµÀ֮ǰÔÚÁ½ÕßÖ®¼äµÄºã¾ÃÃÜÔ¿¡£¡£¡£¡£Ò»µ©¹¥»÷Àֳɣ¬£¬£¬£¬¹¥»÷Õß±ã¿ÉÒÔ»á¼û»ò¿ØÖÆÁíÒ»¸ö×°±¸¡£¡£¡£¡£Ñо¿Ö°Ô±²âÊÔÁËCypress¡¢¸ßͨ(Qualcomm)¡¢Æ»¹û(Apple)¡¢Ó¢Ìضû(Intel)¡¢ÈýÐÇ(Samsung)ºÍCSRµÄÀ¶ÑÀоƬ£¬£¬£¬£¬·¢Ã÷¾ù±£´æ´ËÎÊÌâ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/smartphones-laptops-iot-devices-vulnerable-to-new-bias-bluetooth-attack/


6.LinuxÒç³öÎó²îÆÊÎö£¬£¬£¬£¬¿ÉÏò¸¸Àú³Ì·¢ËÍí§ÒâÐźÅ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


LinuxÄÚºËÔÚ¹ýÂËÐźŴ¦Öóͷ£³ÌÐòʱ£¬£¬£¬£¬¶Ô×Ó/¸¸Àú³Ì±êʶ´¦Öóͷ£µÄËÉÉ¢ÑéÖ¤Öб£´æÎó²î£¬£¬£¬£¬Ôµ¹ÊÔ­ÓÉÊÇinclude/linux/sched.hÖеÄexec_idÖ»ÓÐ32룬£¬£¬£¬ÕûÊýÒç³ö¿ÉÄÜ»á×ÌÈÅdo_notify_parent±£»£»£»£» £»¤»úÖÆ¡£¡£¡£¡£Òò´ËÍâµØ¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÈÆ¹ý¼ì²é£¬£¬£¬£¬½«í§ÒâÐźŷ¢Ë͵½¸¸ÌØÈ¨Àú³Ì¡£¡£¡£¡£Ê¹ÓÃÕûÊýÒç³ö֮ǰ¾­ÓɵÄʱ¼äÁ¿£¬£¬£¬£¬ÒÔ¼°Ïò¸¸Àú³Ì·¢ËÍÐźŵÄÑéÖ¤µÄȱʧ¿ÉÄÜ»á»á¶Ô²Ù×÷Ôì³ÉÖØ´óµÄÍþв¡£¡£¡£¡£×î¿ÉÄܵĹ¥»÷ǰÑÔÊÇÊÔͼ¹¥»÷setuidÀú³ÌµÄÍâµØÓû§£¬£¬£¬£¬ÏÖÔÚÒÑͨ¹ý5.5.18°æ±¾ÐÞ¸´¸ÃÎÊÌâ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://blog.pi3.com.pl/?p=705