°Ä´óÀûÑǹ«Ë¾BlueScopeÔâµ½¹¥»÷µ¼Ö²¿·ÖÓªÒµÖÐÖ¹ £»£»£»ÈÕ±¾¹«Ë¾NikkeiÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬Áè¼Ý1.2ÍòÈËÐÅϢй¶

Ðû²¼Ê±¼ä 2020-05-19

1.°Ä´óÀûÑǹ«Ë¾BlueScopeÔâµ½¹¥»÷µ¼Ö²¿·ÖÓªÒµÖÐÖ¹


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


°Ä´óÀûÑǹ«Ë¾BlueScopeÓÚÉÏÖÜÎåÈ·¶¨£¬£¬£¬£¬£¬£¬ÆäÔâµ½ÁËÍøÂç¹¥»÷²¢ÇÒÒѾ­Ó°Ïìµ½ÁËËûÃǵÄITϵͳ£¬£¬£¬£¬£¬£¬µ¼Ö¸ù«Ë¾²¿·ÖÓªÒµÖÐÖ¹ ¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬´Ë´ÎÊÂÎñÓ°ÏìÁËÆäÔÚ°Ä´óÀûÑǵÄÖÆÔìºÍÏúÊÛÓªÒµ£¬£¬£¬£¬£¬£¬µ«Í¨¹ýһЩ±äͨ²½·¥£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄÆäËûÁ÷³ÌÈÔ¿ÉÒÔÕý³£ÔËÐÐ ¡£¡£¡£¾Ý¹«Ë¾CFO Tania Archibald˵£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷ÊÇÔڸù«Ë¾µÄÃÀ¹úÓªÒµÖз¢Ã÷µÄ£¬£¬£¬£¬£¬£¬Ö®ºó¹«Ë¾Á¬Ã¦¶Ô´ËÊÂ×ö³öÁËÏìÓ¦²½·¥ ¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÕýÔÚÆð¾¢ÐÞ¸´ÊÜÓ°Ïìϵͳ£¬£¬£¬£¬£¬£¬ÒÔ»Ö¸´Õý³£Ð§ÀͺÍÔËÓª£¬£¬£¬£¬£¬£¬Éл¹Ã»ÓÐÕë¶Ô´Ë´Î¹¥»÷µÄÏêϸÐÅÏ¢ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/bluescope-reports-cyber-incident-affecting-australian-operations/


2.ÈÕ±¾¹«Ë¾NikkeiÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬Áè¼Ý1.2ÍòÈËÐÅϢй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÈÕ±¾µÄÈÕ¾­¼¯ÍÅ£¨Nikkei Inc.£©5ÔÂ12ÈÕÐû²¼£¬£¬£¬£¬£¬£¬ÆäÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬µ¼Ö¼¯ÍÅ12514È˵ÄСÎÒ˽¼ÒÐÅϢй¶ ¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨¶­Ê»á³ÉÔ±¡¢ÕýʽºÍ¼æÖ°Ô±¹¤ÒÔ¼°ÈÕ¾­×ܲ¿¼°ÆäijЩ¼¯ÍŹ«Ë¾ÆäËûÖ°Ô±µÄÐÕÃûºÍµç×ÓÓʼþµØµã ¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬Ã»ÓÐ×ß©Óë¶ÁÕߺͿͻ§ÓйصÄÐÅÏ¢£¬£¬£¬£¬£¬£¬Ò²Ã»ÓÐ×ß©Æä¼ÇÕßÍøÂçµÄÐÂÎű¨µÀÐÅÏ¢ ¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷±¬·¢ÔÚ5ÔÂ8ÈÕ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Ô±¹¤ÊÕµ½²¢·­¿ªÁËÒ»·â´øÓв¡¶¾¸½¼þµÄµç×ÓÓʼþµ¼ÖÂÆäÅÌËã»úÊܵ½Ñ¬È¾ ¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬Ñ¬È¾²¡¶¾ÊÇÐÂÐͲ¡¶¾£¬£¬£¬£¬£¬£¬Òò´ËÏÖÔÚÐè񻮮·ÑһЩʱ¼ä¾ÙÐмì²â ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://mainichi.jp/english/articles/20200513/p2a/00m/0na/002000c


3.ÃÀ¹úFinCENÖÒÑÔÏÖÔÚ±£´æ´ó¹æÄ£µÄÐéÄâÇ®±ÒÕ©Æ­»î¶¯


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹ú½ðÈÚ·¸·¨Ö´·¨ÍøÂçFinCENÖÒÑÔÏÖÔÚ±£´æ´ó¹æÄ£µÄÐéÄâÇ®±ÒÕ©Æ­»î¶¯ ¡£¡£¡£FinCENÈÏÕæÈËKenneth BlancoÌåÏÖ£¬£¬£¬£¬£¬£¬ÏÖÔÚÍøÂç·¸·¨·Ö×ÓÖ÷ÒªÒÔÐéÄâÇ®±ÒΪĿµÄ£¬£¬£¬£¬£¬£¬Òò´ËÓ¦ÖØµã¹Ø×¢½ðÈÚÕ©Æ­ ¡£¡£¡£FinCENÌåÏÖ£¬£¬£¬£¬£¬£¬×Ô2013ÄêÒÔÀ´£¬£¬£¬£¬£¬£¬ËûÃÇ×ܹ²ÊÕµ½Á˽ü7ÍòÆð¼ÓÃÜÇ®±ÒÕ©Æ­»î¶¯µÄ¿ÉÒɻ±¨¸æ£¨SAR£©£¬£¬£¬£¬£¬£¬¶øÔÚCOVID-19ʱ´ú£¬£¬£¬£¬£¬£¬ÕâÖÖÍþвÔöÌíÁË10±¶ ¡£¡£¡£ÔÚÒßÇéʱ´ú£¬£¬£¬£¬£¬£¬ÆäËûÀàÐ͵ÄÍøÂç¹¥»÷Ò²²ã³ö²»Ç£¬£¬£¬£¬£¬ºÃ±ÈÀÕË÷Èí¼þ¹¥»÷¡¢ÐéαҽÁƲúÆ·ÏúÊۺʹú±ÒͶ×ÊÕ©Æ­µÈ ¡£¡£¡£ÓÉÓÚCOVID-19£¬£¬£¬£¬£¬£¬´ó²¿·ÖÈ˺ÍÕþ¸®¹ÙÔ±ÔڼҰ칫£¬£¬£¬£¬£¬£¬ÕâÐ©ÍøÂç×ï·¸»áͨ¹ý¹¥»÷VPNºÍÔ¶³Ì×ÀÃæÐ­ÒéµÈÔ¶³ÌÓ¦ÓóÌÐòÖеÄÎó²î£¬£¬£¬£¬£¬£¬ÒÔÇÔÊØÐÅÏ¢ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2020/05/fincen-chief-blanco-warns-of-wide-scale.html


4.ºÚ¿Í×éÖ¯RATicate'sʹÓÃNSIS×°ÖóÌÐò·Ö·¢RAT


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


SophosµÄÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öºÚ¿Í×éÖ¯RATicate's£¬£¬£¬£¬£¬£¬¸Ã×é֯ʹÓÃNSIS×°ÖóÌÐò¶Ô¹¤Òµ¹«Ë¾Ìᳫ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬ÒÔ·Ö·¢RATºÍÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ ¡£¡£¡£¸Ã×éÖ¯ÔÚ2019Äê11ÔÂÖÁ2020Äê1ÔÂʱ´úÕë¶ÔÅ·ÖÞ¡¢Öж«ºÍº«¹úµÄ¹«Ë¾×ܹ²ÌᳫÁË5´Î¹¥»÷ ¡£¡£¡£Sophos±¨¸æËµÃ÷£¬£¬£¬£¬£¬£¬ºÚ¿ÍÓÃÁ½ÖÖ·½·¨Í¨¹ý´¹ÂÚÈí¼þ·Ö·¢RAT£¬£¬£¬£¬£¬£¬ÆäÒ»ÊÇʹÓôøÓÐÓÐNSIS×°ÖóÌÐòµÄZIP¡¢UDFºÍIMG¸½¼þ£¬£¬£¬£¬£¬£¬Æä¶þÊÇ´ÓÔ¶³ÌЧÀÍÆ÷ÏÂÔØÓÐÓøºÔØXLSºÍRTFÎĵµ ¡£¡£¡£Sophos·¢Ã÷´Ë´Î¹¥»÷Öкڿͻ¹ÓÃÁËÐí¶à¹¤¾ß£¬£¬£¬£¬£¬£¬°üÀ¨Lokibot£¬£¬£¬£¬£¬£¬Betabot£¬£¬£¬£¬£¬£¬FormbookºÍAgentTeslaµÈ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2020/05/sophos-found-group-abusing-nsis.html


5.ÐÂÐ͹¥»÷BIAS¿ÉʹÓÃÀ¶ÑÀ¹¥»÷ÊÖ»úµÈ×°±¸


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



Ñо¿Ö°Ô±·¢Ã÷ÁËÀ¶ÑÀÎÞÏßЭÒéÖеÄÒ»¸öÐÂÎó²îBIAS£¬£¬£¬£¬£¬£¬¿É±»Ê¹Óù¥»÷ÏÖ´ú»¥Á¬×°±¸£¬£¬£¬£¬£¬£¬ÀýÈçÖÇÄÜÊÖ»ú¡¢Æ½°åµçÄÔ¡¢Ìõ¼Ç±¾µçÄÔºÍÖÇÄÜIoT×°±¸µÈ ¡£¡£¡£¸ÃÎó²îÈ«³ÆÎªBluetooth Impersonation AttackS£¬£¬£¬£¬£¬£¬Ó°ÏìÁ˾­µä°æÀ¶ÑÀЭÒé ¡£¡£¡£¸Ã¹¥»÷·½·¨Õë¶ÔµÄÊÇ×°±¸¼äµÄºã¾ÃÃÜÔ¿£¬£¬£¬£¬£¬£¬µ±Á½¸öÀ¶ÑÀ×°±¸Ê×´ÎÅä¶Ôʱ½«ÌìÉú´ËÃÜÔ¿£¬£¬£¬£¬£¬£¬¶øBIAS¿ÉÒÔʹ¹¥»÷Õßð³äÏÈǰÅä¶Ô×°±¸µÄÉí·Ý£¬£¬£¬£¬£¬£¬²¢ÀֳɾÙÐÐÉí·ÝÑéÖ¤²¢ÅþÁ¬µ½ÁíÒ»¸ö×°±¸£¬£¬£¬£¬£¬£¬¶øÎÞÐèÖªµÀ֮ǰÔÚÁ½ÕßÖ®¼äµÄºã¾ÃÃÜÔ¿ ¡£¡£¡£Ò»µ©¹¥»÷Àֳɣ¬£¬£¬£¬£¬£¬¹¥»÷Õß±ã¿ÉÒÔ»á¼û»ò¿ØÖÆÁíÒ»¸ö×°±¸ ¡£¡£¡£Ñо¿Ö°Ô±²âÊÔÁËCypress¡¢¸ßͨ(Qualcomm)¡¢Æ»¹û(Apple)¡¢Ó¢Ìضû(Intel)¡¢ÈýÐÇ(Samsung)ºÍCSRµÄÀ¶ÑÀоƬ£¬£¬£¬£¬£¬£¬·¢Ã÷¾ù±£´æ´ËÎÊÌâ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/smartphones-laptops-iot-devices-vulnerable-to-new-bias-bluetooth-attack/


6.LinuxÒç³öÎó²îÆÊÎö£¬£¬£¬£¬£¬£¬¿ÉÏò¸¸Àú³Ì·¢ËÍí§ÒâÐźÅ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


LinuxÄÚºËÔÚ¹ýÂËÐźŴ¦Öóͷ£³ÌÐòʱ£¬£¬£¬£¬£¬£¬¶Ô×Ó/¸¸Àú³Ì±êʶ´¦Öóͷ£µÄËÉÉ¢ÑéÖ¤Öб£´æÎó²î£¬£¬£¬£¬£¬£¬Ôµ¹ÊÔ­ÓÉÊÇinclude/linux/sched.hÖеÄexec_idÖ»ÓÐ32룬£¬£¬£¬£¬£¬ÕûÊýÒç³ö¿ÉÄÜ»á×ÌÈÅdo_notify_parent± £»£»£»¤»úÖÆ ¡£¡£¡£Òò´ËÍâµØ¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÈÆ¹ý¼ì²é£¬£¬£¬£¬£¬£¬½«í§ÒâÐźŷ¢Ë͵½¸¸ÌØÈ¨Àú³Ì ¡£¡£¡£Ê¹ÓÃÕûÊýÒç³ö֮ǰ¾­ÓɵÄʱ¼äÁ¿£¬£¬£¬£¬£¬£¬ÒÔ¼°Ïò¸¸Àú³Ì·¢ËÍÐźŵÄÑéÖ¤µÄȱʧ¿ÉÄÜ»á»á¶Ô²Ù×÷Ôì³ÉÖØ´óµÄÍþв ¡£¡£¡£×î¿ÉÄܵĹ¥»÷ǰÑÔÊÇÊÔͼ¹¥»÷setuidÀú³ÌµÄÍâµØÓû§£¬£¬£¬£¬£¬£¬ÏÖÔÚÒÑͨ¹ý5.5.18°æ±¾ÐÞ¸´¸ÃÎÊÌâ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://blog.pi3.com.pl/?p=705