¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181204
Ðû²¼Ê±¼ä 2018-12-04
Ó¢¹úSoutheby£¨ËÕ¸»±È£©ÅÄÂôÐÐÐû²¼Æäµç×ÓÉÌÎñÍøÕ¾Sotheby's Home³ÉΪMagecartµÄ×îÐÂÊܺ¦Õß¡£SouthebyÓÚ10ÔÂ10ÈÕ·¢Ã÷²¢É¾³ýÁ˸ÃÍøÕ¾ÉϵĵÚÈý·½¶ñÒâ´úÂ룬Ȼ¶ø£¬¸Ã¶ñÒâ¾ç±¾ÖÁÉÙÓÚ2017Äê3ÔÂÒÔÀ´Ò»Ö±±£´æ£¬ÕâÒâζ×ÅÒÑÍù19¸öÔÂÄÚÎÞÊý¿Í»§¿ÉÄÜÊܵ½Ó°Ïì¡£¸Ã¶ñÒâ¾ç±¾ÓÃÓÚÇÔÈ¡Óû§ÊäÈëµÄÖ§¸¶ÐÅÏ¢£¬°üÀ¨ÐÕÃû¡¢µØµã¡¢µç×ÓÓʼþµØµãºÍÐÅÓÿ¨ºÅ¡¢µ½ÆÚÈÕÆÚÒÔ¼°CVVÂëµÈ¡£ÀàËÆÓÚÓ¢¹úº½¿Õ¹«Ë¾ºÍе°ÍøµÄ¹¥»÷ÊÂÎñ£¬¹¥»÷ÕßËÆºõÊÇÖ±½ÓѬȾµÄ¸ÃÍøÕ¾¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/southebys-site-infected-magecart/2¡¢¿¨°Í˹»ùÐû²¼2018ÄêÖØ´óÇå¾²Íþв×ÛÊö£¬º¸Ç¶à¸ö¹¥»÷ÖÖ±ð
¿¨°Í˹»ùµÄ2018ÄêÖØ´óÇå¾²Íþв×ÛÊöº¸ÇÁËÕë¶ÔÐÔ¹¥»÷¡¢Òƶ¯APTÍþв¡¢Ö÷ÒªÎó²î¡¢¶ñÒâä¯ÀÀÆ÷²å¼þ¡¢ÌìϱڲÆÔ˶¯¡¢Õë¶ÔICSµÄ½ðÈÚڲơ¢ÀÕË÷Èí¼þ¡¢ÒøÐÐľÂí¡¢ÖÇÄÜ×°±¸ÒÔ¼°Ð¡ÎÒ˽¼ÒÐÅϢй¶µÈÖÖ±ð¡£Ëæ×Å»¥ÁªÍøÈÚÈëÁËÈËÃǵÄÉúÑÄ£¬¹¥»÷ÕߵĹ¥»÷ÃæÒ²Ô½À´Ô½ÆÕ±é£¬°üÀ¨½ðÈÚ͵ÇÔ¡¢Êý¾ÝÇÔÈ¡ÒÔ¼°ÐÅÓÃË𺦵ȡ£¹¥»÷ÕßµÄÄ¿µÄ×°±¸Ô½À´Ô½¶àµØÖ¸Ïò·ÇÅÌËã»úÀàµÄ×°±¸£¬´Ó¶ùͯÖÇÄÜÍæ¾ßµ½ÍøÂçÉãÏñÍ·µÈ¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/kaspersky-security-bulletin-2018-top-security-stories/89118/3¡¢RiskIQÐû²¼2019ÄêÍøÂçÍþвչÍû£¬PII½«³ÉΪÖ÷Òª¹¥»÷Ä¿µÄ
ƾ֤RiskIQµÄ2019ÄêÍøÂçÍþвչÍû±¨¸æ£¬ÍþвÇ÷ÊÆµÄת±ä½«°üÀ¨£ºPII½«³ÉΪÖ÷ÒªµÄ¹¥»÷Ä¿µÄ£¬2018Äêͨ¹ýjs¾ç±¾ÇÔÊØÐÅÓÿ¨ÐÅÏ¢µÄÔ˶¯´ó±¬·¢£¬Ô¤¼Æ2019ÄêÕâÖÖÒªÁ콫»áÀ©Õ¹µ½Õë¶ÔPIIºÍIP£»¹¥»÷Õß½«»á¼ÌÐø·¢Ã÷ºÍÕë¶ÔÆóÒµ·À»ðǽ֮ÍâµÄäµã£¬ÀýÈçµÚÈý·½¹ºÎï³µÈí¼þºÍÊý¾ÝÍøÂ繤¾ß£»ÈÝÆ÷ºÍÎÞ·þÎñÆ÷ÅÌËãµÈÐÂÊÖÒÕ½«Îª¹¥»÷ÕßÌṩ¸ü¶àÒþ²ØµÄµØ·½£»¹ú¼ÒÖ§³ÖµÄÍøÂç¹¥»÷Ô˶¯½«¼Ó¾ç£»¹¥»÷Õß½«ÔöÌí¶Ô¿¹»úеѧϰÊÖÒյĽÓÄÉ£»»ò½«·ºÆð¸ü¶àÕë¶ÔÆäËüÊý¾ÝµÄMagecartÊÂÎñ¡£
ÔÎÄÁ´½Ó£º
https://www.riskiq.com/blog/external-threat-management/2019-cybersecurity-predictions/4¡¢Ó¢¹úµç×ÓÓʼþ¼°É罻ýÌå¹¥»÷ÊýÄ¿Ïà±ÈÈ¥Äê´ó·ùÉÏÉý
ƾ֤Parliament StreetµÄÒ»·Ýб¨¸æ£¬Ó¢¹ú¾¯Ô±ÕýÔÚÃæÁÙÔ½À´Ô½´óµÄÉ罻ýÌåºÍÅÌËã»úÈëÇÖ°¸¼þÊÓ²ìѹÁ¦¡£±¨¸æÖ¸³ö£¬ÔÚÒÑÍùÁ½¸ö²ÆÄêÄÚ14¸ö¾¯Ô±²½¶Ó¹²¾ÙÐÐÁË2547ÆðÉ罻ýÌåºÍÅÌËã»úÈëÇÖ°¸¼þµÄÊӲ졣ÆäÖÐ2016-2017ÄêΪ1181Æð£¬2017-2018ÄêΪ1354Æð£¬ÔöÌíÁË14%¡£FDM GroupµÄCOO Sheila Flavell³ÆÏÔÈ»ÍøÂç·¸·¨µÄÀ˳±ÕýÔںľ¡¾¯Ô±ÒÔ¼°ÆóÒµµÄ×ÊÔ´£¬½â¾öÕâ¸öÎÊÌâÐèÒªÅäºÏµÄÆð¾¢¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2018/12/03/social-media-hacking-rise/5¡¢Ê¹ÓÃÓ¢¹úÍÑÅ·²Ý°¸»°Ì⣬SofacyжñÒâÔ˶¯·Ö·¢Zebrocy
°£ÉÕÜÑо¿Ö°Ô±·¢Ã÷¶íÂÞ˹APT×éÖ¯SofacyÔÚ×î½üµÄ¶ñÒâ¹¥»÷Ô˶¯ÖÐʹÓÃÁËÓ¢¹úÍÑÅ·²Ý°¸µÄ»°Ì⣬²¢ÇÒÊÔͼ·Ö·¢¶ñÒâÈí¼þZebrocy¡£¸Ã¹¥»÷Ô˶¯×îÏÈÓÚ11ÔÂ15ÈÕ£¬¹¥»÷ÕßÖ÷Ҫͨ¹ý¶ñÒâOfficeÎĵµÖеÄsettings.xml.rels×é¼þ´ÓÍⲿԴ¼ÓÔØ¶ñÒâÄÚÈÝ£¬Æä×îÖÕpayloadÊÇDelphiºÍ.NET°æ±¾µÄZebrocy¡£Zebrocy½«ÍøÂçϵͳÉϵÄÀú³ÌÁÐ±í¡¢ÆÁÄ»½ØÍ¼¡¢Çý¶¯Æ÷ö¾ÙÐÅÏ¢²¢·¢ËÍÖÁC&C·þÎñÆ÷¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/russian-hackers-use-brexit-lures-recent-attacks6¡¢ÍòºÀÂùÝÒòÊý¾Ý¿âй¶ÔâÕûÌåËßËÏ£¬±»Ë÷Åâ125ÒÚÃÀÔª
ÍòºÀ¹ú¼ÊÂùݼ¯ÍÅ(Marriott International)¿ËÈÕÒò¿Í»§Êý¾Ý¿âй¶¶øÔâÓöÕûÌåËßËÏ£¬Ë÷Åâ½ð¶î¸ß´ï125ÒÚÃÀÔª¡£ÉÏÖÜÎåÍòºÀÐû²¼ÆìÏÂϲ´ïÎÝÂùÝ(Starwood Hotel)µÄÒ»¸ö¿Í»§Ô¤¶©Êý¾Ý¿â±»ºÚ¿ÍÈëÇÖ£¬Ô¼5ÒÚ¿Í»§µÄÐÅÏ¢¿ÉÄÜй¶¡£¾ÝϤ£¬ºÚ¿ÍÈëÇÖÔçÔÚ2014Äê¾ÍÒѾ×îÏÈ¡£Ëæºó£¬ÃÀ¹úGeragos&Geragos״ʦÊÂÎñËùµÄ״ʦ±¾¡¤Ã·ÈûÀ˹(Ben Meiselas)ºÍUnderdog LawÖ´·¨ÕÕÁÏÂõ¿Ë¶û¡¤¸»ÀÕ(Michael Fuller)´ú±íÁ½ÃûÔ¸æ´óÎÀ¡¤Ô¼º²Ñ·(David Johnson)ºÍ¿ËÀï˹¡¤¹þÀï˹(Chris Harris)¶ÔÍòºÀ¹ú¼ÊÂùÝÌáÆðÕûÌåËßËÏ£¬Ë÷Åâ125ÒÚÃÀÔª¡£ËäÈ»ÕâÒ»½ð¶î¿´ÆðÀ´Ê®·ÖÖØ´ó£¬µ«Ò²½öÏ൱ÓÚ5ÒÚDZÔÚÊܺ¦¿Í»§Ã¿ÈË»ñµÃ25ÃÀÔªµÄÅâ³¥¡£
ÔÎÄÁ´½Ó£º
http://tech.sina.com.cn/i/2018-12-03/doc-ihprknvs8439051.shtmlÉùÃ÷£º±¾×ÊѶÓÉ×ðÁú¿Ê±Î¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ