¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180813

Ðû²¼Ê±¼ä 2018-08-13

¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷Õë¶Ô°ÍÎ÷ÒøÐеÄDNSÐ®ÖÆ¹¥»÷Ô˶¯


RadwareÑо¿ÍŶӷ¢Ã÷¹¥»÷ÕßÕýÔÚÕë¶Ô°ÍÎ÷µÄDLink DSL·ÓÉÆ÷£¬Í¨¹ýDNSÐ®ÖÆ¹¥»÷½«ÒøÐÐÓû§Öض¨ÏòÖÁ´¹ÂÚÍøÕ¾²¢ÇÔÈ¡ÆäÒøÐÐÕË»§µÄµÇ¼ƾ֤¡£¹¥»÷ÕßÐÞ¸ÄÁËÕâЩ·ÓÉÆ÷×°±¸ÖеÄDNSÉèÖ㬽«ÆäÖ¸Ïò¶ñÒâµÄDNS·þÎñÆ÷£¨69.162.89.185ºÍ198.50.222.136£©£¬ÕâЩװ±¸ÔÚ»á¼ûBanco de Brasil£¨www.bb.com.br£©ºÍItau Unibanco£¨www.itau.com.br£©Ê±½«±»Öض¨ÏòÖÁ¶ñÒâµÄipµØµã¡£Ñо¿Ö°Ô±Ç¿µ÷³Æ£¬ÕâÖÖÐ®ÖÆ²»ÐèÒªÈκεÄÓû§½»»¥¡£

Ô­ÎÄÁ´½Ó£ºhttps://security.radware.com/ddos-threats-attacks/threat-advisories-attack-reports/dns-hijacking-brazil-banks/


¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶÓÑÝʾÔõÑù¹¥»÷Ò½ÁÆ×°±¸£¬Ä£ÄâºÍÐ޸ϼÕßµÄÉúÃüÌåÕ÷


McAfeeÑо¿ÍŶÓÑÝʾÔõÑù¹¥»÷Ò½ÁÆ×°±¸²¢Ä£ÄâºÍÐ޸ϼÕßµÄÉúÃüÌåÕ÷¡£RWHATЭÒéÊÇÒ½ÁÆ×°±¸ÓÃÓÚ¼à¿Ø»¼Õß²¡ÇéºÍÉúÃüÌåÕ÷µÄÍøÂçЭÒéÖ®Ò»£¬Ñо¿Ö°Ô±·¢Ã÷¸ÃЭÒéûÓÐʹÓÃÉí·ÝÑéÖ¤ºÍ¼ÓÃÜ£¬²¢ÇÒ·¢ËÍÁËһЩÃô¸ÐµÄ¡¢ÓÉHIPAA¹ÜÖÆµÄ»¼ÕßÐÅÏ¢£¬ÀýÈçÐÕÃû¡¢³öÉúÈÕÆÚ¡¢»¼Õß´²Î»ºÅºÍ·¿¼äºÅµÈ¡£Ñо¿Ö°Ô±¿ÉÒÔͨ¹ý¼òÆÓµÄÒªÁ콫ÐÅÏ¢×¢ÈëЭÒéÖÐÀ´Ä£ÄâºÍÐ޸ϼÕßµÄÊý¾Ý£¬Õâ¿ÉÄÜÓÕÆ­Ò½ÎñÖ°Ô±£¬µ¼ÖÂÑÏÖØµÄЧ¹û¡£

Ô­ÎÄÁ´½Ó£ºhttps://securingtomorrow.mcafee.com/mcafee-labs/80-to-0-in-under-5-seconds-falsifying-a-medical-patients-vitals/


¡¾¶ñÒâÈí¼þ¡¿Çå¾²Ñо¿Ö°Ô±·¢Ã÷ÀÕË÷Èí¼þDharmaµÄбäÖÖCmb


Çå¾²Ñо¿Ö°Ô±Michael Gillespie·¢Ã÷ÀÕË÷Èí¼þDharmaµÄÒ»¸öбäÖÖ£¬¸Ã±äÖÖÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.cmbÀ©Õ¹Ãû¡£ÏÖÔÚ»¹Ã»Óв½·¥Ã⺬»ìÃܸñäÖÖ¼ÓÃܵÄÎļþ¡£¹¥»÷ÕßÊ×ÏÈÔÚInternetÉÏɨÃ迪ÆôÁËTCP¶Ë¿Ú3389µÄÖ÷»ú£¬È»ºóͨ¹ý±©Á¦ÆÆ½âÆäRDPÃÜÂ룬²¢ÔÚ»ñµÃ»á¼ûȨÏÞºóÊÖ¶¯×°ÖÃÀÕË÷Èí¼þDharma¡£¸Ã±äÖÖÔÚ¼ÓÃÜÎļþºó¸½¼ÓµÄÀ©Õ¹ÃûÀàËÆÓÚ.id-[id].[email].cmbµÄÃûÌá£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/new-cmb-dharma-ransomware-variant-released/


¡¾Êý¾Ýй¶¡¿Ñо¿Ö°Ô±³ÆGoDaddyÒòAWSÉèÖùýʧµ¼Ö²¿·ÖÊý¾Ýй¶


UpGuardÑо¿ÍŶӷ¢Ã÷GoDaddyÒòAWSÉèÖùýʧµ¼Ö²¿·ÖÊý¾Ýй¶£¬Ð¹Â¶Éæ¼°µÄÎļþËÆºõÊÇGoDaddyÔÚAWSÔÆÉÏÔËÐеĻù´¡ÉèÊ©¡£Ð¹Â¶µÄÎļþ°üÀ¨Ô¼3.1Íò¸öϵͳµÄ»ù±¾ÉèÖÃÐÅÏ¢£¬ÈçÖ÷»úÃû¡¢²Ù×÷ϵͳ¡¢ÊÂÇé¸ºÔØ¡¢AWSÇøÓò¡¢ÄÚ´æºÍCPU¹æ¸ñµÈ£¬ÉõÖÁ»¹°üÀ¨AWSÔÚ²î±ðÇéÐÎϸøÓèµÄÕÛ¿ÛÐÅÏ¢µÈ¡£ÏÖʵÉÏ£¬ÕâЩÊý¾ÝÖ±½Óй¶ÁËÒ»¸ö¹æÄ£ºÜÊÇ´óµÄAWSÔÆ»ù´¡ÉèÊ©°²ÅÅÇéÐΡ£

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75271/data-breach/godaddy-aws-data-leak.html


¡¾Çå¾²²¥±¨¡¿ÃÀ¹úTSAÈÏ¿ÉÕë¶ÔÃÀ¹ú¹«ÃñµÄÐÂ¼à¿ØÏîÄ¿Quiet Skies


ƾ֤ÃÀ¹úÔËÊäÇå¾²ÖÎÀí¾Ö£¨TSA£©£¬½ü¼¸¸öÔÂÀ´Quiet SkiesÏîÄ¿ÒѾ­¼à¿ØÁËÔ¼5000Ãûº£ÄÚº½°àÉϵÄÃÀ¹ú¹«Ãñ¡£¸ÃÏîĿּÔÚÍøÂ繫Ãñ¼°ÆäÐÐΪµÄÆÕ±éÐÅÏ¢£¬ÆäÊܵ½ÁËÒþ˽± £»¤Ö÷ÒåÕߵį·ÆÀ£¬ÓÉÓÚÕþ¸®¶ÔûÓÐÉæÏÓ·¸·¨»ò¼ÓÈë¿Ö²À×éÖ¯µÄÃÀ¹ú¹«ÃñʵÑéÁË¼à¿Ø¡£Æ¾Ö¤Quiet SkiesÏîÄ¿£¬ÌìÌì³Ë×øº£ÄÚº½°àµÄ¹«ÃñÖж¼ÓÐÔ¼40-50È˱»Ñ¡ÖУ¬ÆäÖÐÔ¼ÓÐ35ÈË»áÊܵ½¿Õ¾¯µÄ¸ú×ÙºÍ¼à¿Ø¡£

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75263/digital-id/quiet-skies-surveillance-us.html


¡¾Îó²î²¹¶¡¡¿Ñо¿Ö°Ô±Åû¶25¿îAndroidÖÇÄÜÊÖ»úÖеÄ47¸öÇå¾²Îó²î


KryptowireÇå¾²Ñо¿Ö°Ô±Åû¶25¿îAndroidÖÇÄÜÊÖ»úµÄ¹Ì¼þºÍĬÈÏÓ¦ÓÃÖеÄ47¸öÇå¾²Îó²î£¬ÆäÖÐÔÚÃÀ¹úÏúÊÛµÄÊÖ»úÐͺÅΪ11¿î¡£Ãûµ¥ÉϵÄÖÇÄÜÊÖ»úÆ·ÅÆ£¨OEM£©°üÀ¨ÖÐÐË¡¢Ë÷Äᡢŵ»ùÑÇ¡¢LG¡¢»ªË¶ºÍAlcatelµÈ¡£Ò»Ð©Îó²îÔÊÐí¹¥»÷Õß´ÓÓû§µÄÊÖ»úÖмìË÷»ò·¢ËͶÌÐÅ¡¢½ØÆÁ»ò¼ÆÁ¡¢¼ìË÷ÁªÏµÈËÁÐ±í¡¢Ç¿ÖÆ×°ÖõÚÈý·½í§ÒâÓ¦ÓÃÒÔ¼°´Ó×°±¸ÉϲÁ³ýÓû§µÄÊý¾ÝµÈ¡£ÏêϸÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/vulnerabilities-found-in-the-firmware-of-25-android-smartphone-models/