¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181225
Ðû²¼Ê±¼ä 2018-12-25
12ÔÂ21ÈÕά»ù½âÃÜÅû¶1.6Íò·ÝÎļþ£¬ÕâЩÎļþÊÇÃÀ¹ú´óʹ¹ÝµÄ¹ºÎïÇåµ¥¡£Æ¾Ö¤ÕâЩÎļþ£¬ÃÀ¹úפ¶à¹ú´óʹ¹Ý¶¼Ôø¹ºÖÃÌØ¹¤×°±¸¡£ÀýÈç2018Äê8Ô£¬ÃÀ¹ú×¤Èø¶ûÍß¶àʹ¹ÝÐû²¼Ò»·Ý²É¹ºÐèÇ󣬯äÖаüÀ¨94¼þÌØ¹¤×°±¸£¬°üÀ¨ÄÜ×°ÖÃÔÚÆû³µÀïµÄÒ¹ÊÓÉãÏñÍ·ÒÔ¼°Î±×°Ôڸֱʡ¢´ò»ð»ú¡¢³ÄÉÀŦ¿Û¡¢ÑÛ¾µµÈÒ»Ñùƽ³£ÓÃÆ·ÖеÄÉãÏñÍ·¡£ÃÀ¹úפÎÚ¿ËÀ¼Ê¹¹ÝÔò²É¹ºÁ˼Òô»úºÍÒþ²ØÎÞÏßµç×°±¸µÈ¡£
ÔÎÄÁ´½Ó£º
https://shoppinglist.wikileaks.org/2¡¢Îó²îʹÓù¤¾ß°üUnderminerÔÚ12ÔÂÍÆ³öˢа汾
Malwarebytes Labs·¢Ã÷Îó²îʹÓù¤¾ß°üUnderminerÔÚ12Ô·ÝÍÆ³öÁËˢеİ汾¡£ÔÚ2018ÄêÇï¼¾£¬UnderminerÖ÷ҪʹÓÃIEÖеÄÎó²î£¨CVE-2018-8174£©ºÍFlash PlayerÖеÄÎó²î£¨CVE-2018-4878£©¡£µ«ÔÚ12Ô·ݣ¬Ñо¿Ö°Ô±ÒÔΪа汾µÄUnderminerʵÏÖÁË×î½üµÄFlash PlayerÎó²îʹÓã¨CVE-2018-15982£©¡£Æä×îÖÕpayloadµÄ´ò°üºÍÖ´Ðеķ½·¨ÈÔÊÇUnderminer¶ÀÍ̵쬯äpayloadΪHidden Bee¡£
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/threat-analysis/2018/12/underminer-exploit-kit-improves-latest-iteration/3¡¢Ó¢¹úÕþ¸®ÍƳö¹ú¼ÒÍøÂçÇå¾²ÊÖÒÕÆðÔ´Õ½ÂÔÕ÷¼¯Òâ¼û¸å
Ó¢¹úÕþ¸®ÍƳö¹ú¼ÒÍøÂçÇå¾²ÊÖÒÕÆðÔ´Õ½ÂÔµÄÕ÷¼¯Òâ¼û¸å£¬ÕâÒ»ÆðÔ´Õ½ÂÔµÄÄ¿µÄÊǽâ¾ö¸üÆÕ±éµÄÍøÂçÇå¾²ÄÜÁ¦²î±ð¡£±¨¸æÖжÔÍøÂçÇå¾²ÊÖÒÕ¾ÙÐÐÁËÃ÷È·½ç˵£¬²¢½«ÔÚ2019ÄêÐû²¼ÍêÕûµÄÍøÂçÇ徲֪ʶϵͳ£¨CyBoK£©¡£ÆðÔ´Õ½ÂÔ»¹½«½¨ÉèÒ»¸öеġ¢×ÔÁ¦µÄÓ¢¹úÍøÂçÇ徲ίԱ»á£¬¸ÃίԱ»á½«ÈÏÕæÖÆ¶©º¸Ç²î±ðרҵµÄ¿ò¼Ü£¬µÓÚ¨ÍøÂçÇ徲רҵµÄ½á¹¹»ù´¡¡£Õþ¸®»¹½«¼ÌÐøÖ§³ÖÉú³¤ÐÐÒµÖ÷µ¼µÄÅàѵÉú̬ϵͳ¡£
ÔÎÄÁ´½Ó£º
https://www.gov.uk/government/publications/cyber-security-skills-strategy/initial-national-cyber-security-skills-strategy-increasing-the-uks-cyber-security-capability-a-call-for-views-executive-summary4¡¢Ñо¿ÍŶÓÅû¶»ªÎªÂ·ÓÉÆ÷ÖеÄÐÅϢй¶Îó²î
NewSky SecurityÅû¶»ªÎªÂ·ÓÉÆ÷ÖеÄÒ»¸öÐÅϢй¶Îó²î£¬¸ÃÎó²î£¨CVE-2018-7900£©Ê¹µÃ¹¥»÷·ÓÉÆ÷µÄÀú³ÌÔ½·¢¼ò»¯¡£¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÅжÏ·ÓÉÆ÷ÊÇ·ñ¾ßÓÐĬÈÏÆ¾Ö¤£¬¶øÎÞÐèÅþÁ¬µ½×°±¸¡£¸ÃÎó²îµÄÔÀíÊÇ·ÓÉÆ÷Ãæ°åµÄµÇÂ¼Ò³ÃæµÄhtmlÔ´ÂëÖаüÀ¨Ò»¸öÌØ¶¨µÄ±äÁ¿£¬¸Ã±äÁ¿µÄÌØ¶¨ÖµÕ¹ÏÖÁË·ÓÉÆ÷ÊÇ·ñ¾ßÓÐĬÈÏÃÜÂ룬Òò´Ë¹¥»÷Õß¿ÉÒÔÔÚZoomEye/ShodanÉÏÒþʽµØ»ñÈ¡¾ßÓÐĬÈÏÃÜÂëµÄ×°±¸ÁÐ±í¡£ÔÚ½Óµ½±¨¸æºó£¬»ªÎªÒѾÐÞ¸´Á˸ÃÎó²î¡£
ÔÎÄÁ´½Ó£º
https://blog.newskysecurity.com/information-disclosure-vulnerability-cve-2018-7900-makes-it-easy-for-attackers-to-find-huawei-3e7039b6f44f5¡¢Ê©ÄÍµÂµçÆøÐÞ¸´EVLinkµç¶¯Æû³µ³äµçÕ¾ÖеĶà¸öÇå¾²Îó²î
Ê©ÄÍµÂµçÆøÌåÏÖÆäEVLinkµç¶¯Æû³µ³äµçÕ¾µÄParkingÂäµØÊ½µ¥Î»£¨v3.2.0-12_v1¼°¸üÔç°æ±¾£©±£´æÈý¸öÇå¾²Îó²î£¬°üÀ¨Ó²±àÂëÆ¾Ö¤Îó²î£¨CVE-2018-7800£©¡¢´úÂë×¢ÈëÎó²î£¨CVE-2018-7801£©ºÍSQL×¢ÈëÎó²î£¨CVE-2018-7802£©¡£EVLinkͨ³£ÓÃÓڰ칫ÊÒ¡¢Âùݺͳ¬Êеȵط½£¬¸Ã¹«Ë¾ÒѾΪÕâЩÎó²îÌṩÁËÐÞ¸´²¹¶¡¡£±¾ÔÂÔçЩʱ¼ä¿¨°Í˹»ùʵÑéÊÒÅû¶ChargePoint HomeµÄ³äµç×®±£´æ¶à¸öÎó²î£¬Ñо¿Ö°Ô±»¹Ö¸³öEVͨѶÐÒé¡¢EVÖ§¸¶ÏµÍ³ºÍºó¶ËͨѶµÄÇå¾²ÐÔ¶¼Ò×Êܹ¥»÷¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/critical-bug-patched-in-schneider-electric-vehicle-charging-station/140370/6¡¢AkamaiÐû²¼Ð´¹ÂÚÕ½ÂÔÑо¿±¨¸æ£¬ÖØµã¹Ø×¢ÓÎÏ·¡¢Éç½»¼°Öн±
ƾ֤AkamaiµÄд¹ÂÚÕ½ÂÔÑо¿±¨¸æ£¬Ê¢Ðеġ°Èý¸öÎÊÌ⡱ÔÚÏßС¿¼ÊÔ±»·¢Ã÷ÊÇÒ»¸ö´óÐ͵ÄÍøÂç´¹ÂÚÕ©ÆÔ˶¯¡£¸Ã´¹ÂÚÔ˶¯Ä£ÄâÁËËĸöÐÐÒµ£¨°üÀ¨º½¿Õ¡¢ÁãÊÛ¡¢ÓéÀÖºÍʳÎµÄ78¸öÆ·ÅÆ£¬ÀýÈçµÏÊ¿ÄáÀÖÔ°¡¢Dunkin'DonutsºÍTargetµÈ¡£¸ÃȦÌ×ͨ³£ÔÊÐí¿¼ÊÔÖ®ºó¸øÓè½±Àø£¬µ«ÏÖʵÉÏ»áÒªÇóÓû§ÔÚ½ÓÊܽ±Æ·Ö®Ìõ¼þ¹©Ð¡ÎÒ˽¼ÒÐÅÏ¢£¬²¢ÔÚÉ罻ýÌåÉÏÈö²¥Á´½Ó¡£AkamaiµÄ±¨¸æ»¹¹Ø×¢ÁËÓÎÏ·¡¢Éç½»¼°Öн±µÈ´¹ÂÚÕ½ÂÔ¡£
ÔÎÄÁ´½Ó£º
https://www.akamai.com/us/en/multimedia/documents/report/a-new-era-in-phishing-research-paper.pdfÉùÃ÷£º±¾×ÊѶÓÉ×ðÁú¿Ê±Î¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ