¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181121

Ðû²¼Ê±¼ä 2018-11-21
1¡¢¿¨°Í˹»ùÐû²¼2019ÄêÍøÂçÍþвÇ÷ÊÆµÄÕ¹Íû±¨¸æ

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


¿¨°Í˹»ùʵÑéÊÒÐû²¼¶Ô2019ÄêÍøÂçÍþвÇ÷ÊÆµÄÒ»¸öÕ¹ÍûÆÊÎö£¬Ö÷ÒªÄÚÈݰüÀ¨£º»òÐí²»»áÔÙ·¢Ã÷¸ü¶àµÄ´óÐÍAPT×éÖ¯£»ÍøÂçÓ²¼þÓëÎïÁªÍøÍþв½«»áÒ»Ö±ÔöÇ¿£»ÓëÍâ½»ºÍÕþÖÎÓйصĹûÕæÅê»÷£»¶«ÄÏÑǺÍÖж«µØÇø»òÐí»á·ºÆð¸ü¶àµÄ¹¥»÷×éÖ¯£»£¨Ring -£©È¨ÏÞ£¬±ÈRing 0¸ü¸ßµÄȨÏÞ£»×îÊܽӴýµÄѬȾǰÑÔ-´¹ÂÚ£»»ò½«·ºÆð¸ü¶àÀàËÆ¡°°ÂÔËÇýÖ𽢡±µÄ¹¥»÷£»¹©Ó¦Á´¹¥»÷½«¼ÌÐø£»Òƶ¯¶ñÒâÈí¼þ²»»á·ºÆð´ó±¬·¢£¬µ«¸ß¼¶¹¥»÷Õß»á¼ÌÐøÑ°ÕÒÈëÇÖ×°±¸µÄÒªÁì ¡£

  

 Ô­ÎÄÁ´½Ó£º

https://securelist.com/kaspersky-security-bulletin-threat-predictions-for-2019/88878/


2¡¢FireEyeÐû²¼¹ØÓÚAPT29µÄд¹ÂÚÔ˶¯µÄÆÊÎö±¨¸æ

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!



2018Äê11ÔÂ14ÈÕFireEye¼ì²âµ½Õë¶Ô¶à¸öÐÐÒµµÄ20¶à¸ö¿Í»§µÄÐÂÕë¶ÔÐÔ´¹ÂÚ¹¥»÷£¬º­¸ÇÖǿ⡢ִ·¨»ú¹¹¡¢Ã½Ìå¡¢ÃÀ¹ú¾ü·½¡¢Í¼Ïñ¡¢ÔËÊä¡¢ÖÆÒ©¡¢Õþ¸®»ú¹¹ÒÔ¼°¹ú·À³Ð°üÉ̵È ¡£ÕâЩ´¹ÂÚ¹¥»÷ʹÓÃαװ³ÉÀ´×ÔÃÀ¹ú¹úÎñÔºµÄ´¹ÂÚÓʼþ£¬ÊÔͼÈö²¥Cobalt Strike Beacon ¡£Æ¾Ö¤¶ÔÆäTTPµÄÆÊÎö£¬Æä±³ºóµÄ¹¥»÷×éÖ¯ÒÉΪAPT29 ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2018/11/not-so-cozy-an-uncomfortable-examination-of-a-suspected-apt29-phishing-campaign.html


3¡¢ÃÀ¹ú´ó¶¼»áÈËÊÙ°ü¹Ü¹«Ë¾ÒâÍâй¶²¿·Ö¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ƾ֤¼ÓÀû¸£ÄáÑÇÖÝÐû²¼µÄÊý¾Ýй¶֪ͨ£¬ÃÀ¹ú´ó¶¼»áÈËÊÙ°ü¹Ü¹«Ë¾£¨MetLife£©ÓÚ10ÔÂ18ÈÕÒâÍâй¶Á˲¿·Ö¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢£¬ÕâЩÐÅÏ¢ÒÔ¸½¼þµÄÐÎʽ±»·¢Ë͸øÓëMetLifeÏàÖúµÄBenefits Administrator£¨¸£ÀûÖÎÀíÔ±£©£¬²¢Ëæºó±»É¾³ý ¡£Ïà¹ØÊý¾Ý°üÀ¨¿Í»§µÄÉç±£ºÅÂë¡¢°ü¹Ü¹æÄ£¡¢³öÉúÈÕÆÚ¡¢ÐÔ±ðºÍµØµãµÈ ¡£Ö»¹ÜÒÔΪ¿Í»§µÄPII²¢Ã»ÓÐÊܵ½Ë𺦣¬µ«MetLifeÈÔÈ»¾öÒéΪÊÜÓ°ÏìµÄ¿Í»§ÌṩһÄêµÄÐÅÓÃ¼à¿Ø·þÎñ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/data-leak-incident-reported-by-fortune-500-metropolitan-life-insurance-company-523865.shtml


4¡¢OSIsoft LLCÔâºÚ¿ÍÈëÇÖ£¬ËùÓÐÓòÕÊ»§µÄµÇ¼ƾ֤¶¼±»ÇÔÈ¡

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


11ÔÂ16ÈÕOSIsoft LLCÏò¼ÓÖÝÖÝÉó²é³¤°ì¹«ÊÒÐû²¼Í¨Öª³Æ¸Ã¹«Ë¾Ôâµ½ºÚ¿ÍÈëÇÖ£¬°üÀ¨¹«Ë¾Ô±¹¤¡¢ÕÕÁÏ¡¢ÊµÏ°ÉúºÍµÚÈý·½³Ð°üÉ̵ÄÊý¾ÝÒÉй¶ ¡£OSIsoftÊÇʵʱÊý¾ÝÖÎÀíÈí¼þPI SystemµÄ¿ª·¢ÉÌ£¬¸ÃÈí¼þ±»Áè¼Ý65%µÄ²Æ²ú500Ç¿¹¤Òµ¹«Ë¾ËùʹÓà ¡£OSIsoftÌåÏÖ·¢Ã÷ÁËÉæ¼°29̨ÅÌËã»úºÍ135¸öÕË»§µÄƾ֤͵ÇÔÔ˶¯µÄÖ±½ÓÖ¤¾Ý£¬½ø¶øµÃ³ö½áÂÛËùÓеÄOSIÓòÕË»§¶¼Òѱ»Í»ÆÆ ¡£¼øÓÚ¸ÃÊý¾Ýй¶ÊÂÎñµÄÑÏÖØÐÔ£¬OSIsoftÕýÔÚ¶à¸öÇå¾²·þÎñÉ̵Ä×ÊÖúϾÙÐÐÊÓ²ì ¡£

 

 Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/osisoft-breached-all-domain-accounts-emails-and-passwords-assumed-compromised-523863.shtml


5¡¢TalkTalkÈëÇÖÊÂÎñÖеÄÁ½ÃûºÚ¿Í±»ÅÐÈëÓü£¬ÔøÔì³É7700ÍòÓ¢°÷µÄËðʧ

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


¾ÝÓ¢¹úÖðÈÕÓʱ¨±¨µÀ£¬Á½ÃûºÚ¿ÍÒò2015ÄêµÄTalkTalkÈëÇÖÊÂÎñ±»ÅÐÈëÓü ¡£TalkTalkÊÇÓ¢¹ú×î´óµÄµçÐŹ«Ë¾Ö®Ò»£¬ÕâÁ½ÃûºÚ¿Í¹²ÇÔÈ¡ÁËÁè¼Ý15.6ÍòÃû¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢¡¢²ÆÎñÐÅÏ¢¼°ÐÅÓÿ¨ÐÅÏ¢£¬Ôì³ÉµÄËðʧ´ï7700ÍòÓ¢°÷ ¡£ÏÖÄê23ËêµÄMatthew HanleyºÍ21ËêµÄConnor AllsoppÈÏ¿ÉÁËÏà¹ØÖ¸¿Ø£¬²¢»®·Ö±»Åд¦12¸öÔºÍ8¸öÔµÄÓÐÆÚͽÐÌ ¡£

 

 Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/11/talktalk-data-breach.html


6¡¢AdobeÐû²¼Flash Player½ôÆÈÇå¾²¸üУ¬ÐÞ¸´Ò»¸öí§Òâ´úÂëÖ´ÐÐÎó²î

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


±¾ÖܶþAdobeÕë¶ÔFlash Player¸ßΣÎó²î£¨CVE-2018-15981£©Ðû²¼½ôÆÈÇå¾²¸üР¡£¸ÃÎó²îÊÇÒ»¸öÀàÐÍ»ìÏý¹ýʧ£¬¿Éµ¼Ö¹¥»÷ÕßÔÚÓû§²»ÖªÇéµÄÇéÐÎÏÂÖ´ÐÐí§Òâ¶ñÒâ´úÂë ¡£¸ÃÎó²îÓ°ÏìÁËWindows¡¢macOS¡¢LinuxºÍChrome OSµÈƽ̨ÉϵÄFlash Player 31.0.0.148¼°¸üÔçµÄ°æ±¾ ¡£½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ°æ±¾31.0.0.153 ¡£

 

 Ô­ÎÄÁ´½Ó£º

https://threatpost.com/critical-adobe-flash-bug-impacts-windows-macos-linux-and-chrome-os/139264/


ÉùÃ÷£º±¾×ÊѶÓÉ×ðÁú¿­Ê±Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí