¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180914

Ðû²¼Ê±¼ä 2018-09-14

¡¾Õþ²ß¹æÔò¡¿ÎÀ½¡Î¯Ðû²¼¡¶¹ú¼Ò¿µ½¡Ò½ÁÆ´óÊý¾Ý±ê×¼¡¢Çå¾²ºÍ·þÎñÖÎÀí²½·¥£¨ÊÔÐУ©¡·


ΪÔöÇ¿¿µ½¡Ò½ÁÆ´óÊý¾Ý·þÎñÖÎÀí£¬Ôö½ø¡°»¥ÁªÍø+Ò½ÁÆ¿µ½¡¡±Éú³¤£¬³ä·ÖÑéÕ¹¿µ½¡Ò½ÁÆ´óÊý¾Ý×÷Ϊ¹ú¼ÒÖ÷Òª»ù´¡ÐÔÕ½ÂÔ×ÊÔ´µÄ×÷Óã¬Æ¾Ö¤Ïà¹ØÖ´ÂÉÀýÔò£¬¹ú¼ÒÎÀÉú¿µ½¡Î¯Ô±»áÐû²¼¡¶¹ú¼Ò¿µ½¡Ò½ÁÆ´óÊý¾Ý±ê×¼¡¢Çå¾²ºÍ·þÎñÖÎÀí²½·¥£¨ÊÔÐУ©¡·¡£²½·¥Ëù³Æ¿µ½¡Ò½ÁÆ´óÊý¾Ý£¬ÊÇÖ¸ÔÚÈËÃǼ²²¡·ÀÖΡ¢¿µ½¡ÖÎÀíµÈÀú³ÌÖб¬·¢µÄÓ뿵½¡Ò½ÁÆÏà¹ØµÄÊý¾Ý¡£¸÷¼¶ÖÖÖÖÒ½ÁÆÎÀÉúÆø¹¹ºÍÏà¹ØÆóÊÂÒµµ¥Î»ÊÇ¿µ½¡Ò½ÁÆ´óÊý¾ÝÇå¾²ºÍÓ¦ÓÃÖÎÀíµÄÔðÈε¥Î»¡£


http://www.nhfpc.gov.cn/guihuaxxs/s10741/201809/758ec2f510c74683b9c4ab4ffbe46557.shtml


¡¾ÆÊÎö±¨¸æ¡¿NexusguardÐû²¼2018ÄêQ2Íþв±¨¸æ£¬DDoS¹¥»÷ͬ±ÈÔöÌíÁè¼Ý500%


ƾ֤NexusguardµÄ2018ÄêµÚ¶þ¼¾¶ÈÍþв±¨¸æ£¬DDoS¹¥»÷ƽ¾ùÔöÌíÁè¼Ý26Gbps£¬¹æÄ£ÔöÌíÁËÁè¼Ý500%¡£Óë2017ÄêͬÆÚÏà±È£¬DDoS¹¥»÷µÄ×î´ó¹æÄ£·­ÁËËı¶£¬´ï359Gbps¡£Ñо¿Ö°Ô±³ÆÊý¾ÝµÄ¼¤ÔöÔ´ÓÚÎïÁªÍø½©Ê¬ÍøÂçSatoriµÄÔöÌí¡£×î´óµÄ0dayΣº¦À´×ÔÓÚ²î±ðµÄ¼ÒÓ÷ÓÉÆ÷£¬¹¥»÷Õß¿ÉÄÜʹÓÃÕâЩװ±¸Õë¶ÔÒªº¦·þÎñºÍÍøÂçÌᳫ´ó¹æÄ£DDoS¹¥»÷¡£Synºé·º¹¥»÷Õ¼ÓÐÁËÖ÷µ¼Ö°Î»¡£


https://www.infosecurity-magazine.com/news/ddos-attacks-increase-in-size-by/


¡¾¹¥»÷ÊÂÎñ¡¿Ó¢¹ú°®¶¡±¤´óѧÔâDDoS¹¥»÷£¬¹ÙÍøÔÝʱÎÞ·¨»á¼û


Ó¢¹ú°®¶¡±¤´óѧÔâµ½ÍøÂç¹¥»÷£¬ÆäÍøÕ¾ÔÝʱ²»¿É»á¼û¡£Æ¾Ö¤°®¶¡±¤Íí±¨£¬¸Ã´óѧÖ÷ÒªµÄed.ac.ukÍøÕ¾×èÖ¹ÖÜËÄÔçÉÏÈÔÈ»ÎÞ·¨»á¼û£¬ÕâÅú×¢ÆäÔâµ½ÁËÑÏÖØµÄDDoS¹¥»÷¡£¸Ã´óѧµÄÐÂÎŽ²»°ÈË³ÆÆäÒѽÓÄÉÁËÑÏ¿áµÄ²½·¥À´±£»¤ITϵͳºÍÊý¾Ý£¬²¢½«¼ÌÐøÓëISP¡¢ÍøÂç·¸·¨ÊÓ²ìÖ°Ô±ÒÔ¼°ÆäËü´óѧÏàÖúÒÔ×èÖ¹ÕâÐ©ÍøÂç¹¥»÷¡£


https://www.infosecurity-magazine.com/news/edinburgh-uni-hit-by-major-cyber/


¡¾ÍþвÇ鱨¡¿F-SecureÑо¿Ö°Ô±ÑÝʾ¿ÉÇÔÈ¡ÄÚ´æÐÅÏ¢µÄÐÂÀäÆô¶¯¹¥»÷ÊÖÒÕ


·ÒÀ¼Çå¾²³§ÉÌF-SecureµÄÑо¿Ö°Ô±·¢Ã÷Ò»ÖÖÐµĹ¥»÷ÒªÁ죬¿ÉÔÊÐí¹¥»÷ÕßÔÚÀäÆô¶¯ºóÔÚÊý·ÖÖÓÄÚ»Ö¸´ÄÚ´æÖеÄÊý¾Ý£¬ÕâЩÊý¾Ý¿ÉÄܰüÀ¨ÃÜÂë¡¢ÃÜÔ¿ºÍÆäËüÃô¸ÐÐÅÏ¢µÈ¡£Ñо¿Ö°Ô±³ÆËùÓеÄÏÖ´úÅÌËã»ú¶¼Êܵ½Ó°Ï죬²¢Ðû²¼ÁËʵÑé¹¥»÷µÄÑÝʾÊÓÆµ¡£ÎªÁËÏìÓ¦ËûÃǵÄÑо¿Ð§¹û£¬Î¢Èí¸üÐÂÁËÆäBitlocker Countermeasures£¬¶øÆ»¹ûÔòÌåÏÖÅ䱸ÁËApple T2оƬµÄMac×°±¸ÒѾ­°üÀ¨ÁËÏà¹ØÇå¾²²½·¥¡£


https://thehackernews.com/2018/09/cold-boot-attack-encryption.html


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷FeedifyѬȾÓÃÓÚÇÔÈ¡Óû§ÐÅÏ¢µÄ¶ñÒâMageCart¾ç±¾


Çå¾²Ñо¿Ö°Ô±Placebo·¢Ã÷ÍÆËÍ֪ͨ·þÎñFeedifyµÄ¾ç±¾ÖÐѬȾÁ˶ñÒâMageCart¾ç±¾¡£MageCartÓÃÓÚÔÚÓû§Ìá½»±íµ¥Ê±ÇÔÈ¡Óû§µÄÒøÐп¨ÐÅÏ¢µÈ£¬RiskIQ×î½ü·¢Ã÷¸Ã·¸·¨ÍÅ»ïÓëÓ¢¹úº½¿Õ¹«Ë¾µÄÊý¾Ýй¶ÊÂÎñÓйØ¡£Ñо¿Ö°Ô±·¢Ã÷https://cdn.feedify.net/getjs/feedbackembad-min-1.0[.]jsÎļþÖаüÀ¨MageCart¶ñÒâ´úÂ룬Óû§Ìá½»µÄÐÅÏ¢¶¼½«±»·¢Ë͵½https://info-stat.ws/js/slider[.]js¡£FeedifyÉÐδ×÷³ö»ØÓ¦¡£


https://www.bleepingcomputer.com/news/security/feedify-hacked-with-magecart-information-stealing-script/


¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷·¸·¨ÍÅ»ïOilRig¶ÔÖж«µØÇøÌᳫÐµĹ¥»÷Ô˶¯


·¸·¨ÍÅ»ïOilRig×Ô2016ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬Ö÷ÒªÕë¶ÔÖж«µØÇøµÄÕþ¸®»ú¹¹ºÍÆóÒµ¡£2018Äê8Ô£¬Palo Alto NetworksµÄUnit 42Ñо¿ÍŶӷ¢Ã÷¸Ã×é֯ʹÓÃжñÒâÈí¼þBONDUPDATERÕë¶ÔÖж«Õþ¸®»ú¹¹µÄһϵÁй¥»÷Ô˶¯¡£BONDUPDATERÊÇÒ»¸öľÂí£¬Æä°üÀ¨»ù±¾µÄºóÃŹ¦Ð§£¬²¢¿ÉÒÔÉÏ´«/ÏÂÔØÎļþÒÔ¼°Ö´ÐÐÏÂÁî¡£BONDUPDATERʹÓÃDNSËíµÀÓëC2·þÎñÆ÷¾ÙÐÐͨѶ¡£


https://researchcenter.paloaltonetworks.com/2018/09/unit42-oilrig-uses-updated-bondupdater-target-middle-eastern-government/



¡¾×ðÁú¿­Ê±¼¯ÍÅADLabÕûÀíÐû²¼¡¿