¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181106

Ðû²¼Ê±¼ä 2018-11-06
1¡¢»ôÄáΤ¶ûÐû²¼¹ØÓÚ¹¤ÒµÉèÊ©ÖеÄUSBÍþвµÄÆÊÎö±¨¸æ

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ƾ֤»ôÄáΤ¶ûÐû²¼µÄÒ»·Ýб¨¸æ £¬£¬£¬£¬£¬USB×°±¸ÊÇÕë¶Ô¹¤ÒµÉèÊ©µÄ¶ñÒâÈí¼þ¹¥»÷µÄÖ÷ҪǰÑÔ¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÊÇ»ùÓÚ»ôÄáΤ¶ûµÄÇ徲ýÌå½»Á÷£¨SMX£©ÊÖÒÕÍøÂçµÄÊý¾Ý £¬£¬£¬£¬£¬º­¸ÇÁËÄÜÔ´¡¢Ê¯ÓͺÍ×ÔÈ»Æø¡¢»¯Ñ§¡¢Ö½ÕÅÖÆÔìµÈÐÐÒµ¡£¡£¡£¡£¡£¡£Êý¾ÝÅú×¢ £¬£¬£¬£¬£¬26%µÄÍþв¿ÉÄܵ¼Ö¹¤ÒµÆóҵʧȥICSÇéÐεĿɼûÐÔ»ò¿ØÖÆÈ¨ £¬£¬£¬£¬£¬´Ó¶øÔì³ÉÖØ´óÖÐÖ¹¡£¡£¡£¡£¡£¡£16%µÄÍþвרÃÅÕë¶ÔICSºÍIoTϵͳ £¬£¬£¬£¬£¬ÆäÖаüÀ¨¶ñÒâÈí¼þMirai£¨6£¥£©¡¢Stuxnet£¨2£¥£©¡¢Triton£¨2£¥£©ºÍWannaCry£¨1£¥£©¡£¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://honeywellprocess.blob.core.windows.net/public/Support/Customer/Honeywell-USB-Threat-Report.pdf


2¡¢ÃÀ»ã·áÒøÐÐÔâµ½ºÚ¿Í¹¥»÷ £¬£¬£¬£¬£¬²¿·Ö¿Í»§×ÊÁϱ»ÇÔ

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ƾ֤ÃÀ¹ú»ã·áÒøÐÐ11ÔÂ2ÈÕÏò¿Í»§·¢Ë͵ÄÊý¾Ýй¶֪ͨ £¬£¬£¬£¬£¬²¿·Ö¿Í»§µÄÔÚÏßÕË»§ÓÚ2018Äê10ÔÂ4ÈÕÖÁ14ÈÕʱ´úÔ⵽δÊÚȨ»á¼û £¬£¬£¬£¬£¬±»ÇÔµÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢×¡Ö·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢³öÉúÈÕÆÚ¡¢Õ˺š¢ÕË»§ÀàÐÍ¡¢ÕË»§Óà¶î¡¢ÀúÊ·ÉúÒâ¼Í¼¡¢ÊÕ¿îÈËÕË»§ÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£»£» £»£»£»£»ã·áÒøÐÐÌåÏÖËùÓÐÊÜÓ°ÏìµÄ¿Í»§¶¼½«»ñµÃÃâ·ÑµÄÐÅÓÃ¼à¿ØºÍÉí·Ý͵ÇÔ±£»£» £»£»£»£»¤Ð§ÀÍ¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/hsbc-bank-breached-again-suspends-online-access-to-affected-accounts-523620.shtml


3¡¢Ñо¿Ö°Ô±ÖÒÑÔ³ÆICS×°±¸Ò×ÊܱßÐŵÀ¹¥»÷µÄÓ°Ïì

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Çå¾²Ñо¿Ö°Ô±Demos AndreouÔÚICSÍøÂçÇå¾²´ó»áÉÏÖÒÑԳƱßÐŵÀ¹¥»÷¿ÉÄܶÔICSϵͳ×é³ÉÑÏÖØµÄÍþв¡£¡£¡£¡£¡£¡£Æ¾Ö¤Andreou¶ÔÅäµçϵͳ³£Óõı£»£» £»£»£»£»¤×°±¸µÄÑо¿ £¬£¬£¬£¬£¬¾ßÓÐÎïÆÊÎö¼ûȨÏ޵Ĺ¥»÷Õß¿ÉÒÔͨ¹ýʾ²¨Æ÷ºÍÔËÐпªÔ´Èí¼þµÄרÓÃÓ²¼þ×°±¸À´»ñÈ¡¼ÓÃÜÃÜÔ¿ £¬£¬£¬£¬£¬´ËÀ๥»÷ËùÐèµÄÓ²¼þ±¾Ç®Ô¼Îª300ÃÀÔª¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷Èý¼ÒÖ÷Òª¹©Ó¦É̵Ä×°±¸¶¼±£´æÎ£º¦ £¬£¬£¬£¬£¬ÓÉÓÚÕâЩװ±¸ÓÃÓÚ±£»£» £»£»£»£»¤µçÍø £¬£¬£¬£¬£¬Òò´ËÕâÖÖ¹¥»÷¿ÉÄÜ»áÔì³ÉÑÏÖØµÄЧ¹û¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/ics-devices-vulnerable-side-channel-attacks-researcher


4¡¢Ñо¿Ö°Ô±ÖÒÑÔÄ£ÄâÑ¡¾ÙÐÅÏ¢ÍøÕ¾µÄ´¹ÂÚÍøÕ¾VOTE411.com

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾



Ñо¿Ö°Ô±Amanda RousseauºÍLukas Stefanko·¢Ã÷ÓÃÓÚÄ£ÄâÑ¡¾ÙÐÅÏ¢ÍøÕ¾VOTE411.orgµÄ´¹ÂÚÕ©Æ­ÍøÕ¾vote411[.]com¡£¡£¡£¡£¡£¡£Ëæ×ÅÃÀ¹úÖÐÆÚÑ¡¾ÙµÄÁÚ½ü £¬£¬£¬£¬£¬·¸·¨·Ö×ÓÔ½À´Ô½¶àµØÕë¶ÔÑ¡Ãñ¾ÙÐд¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£¸Ã´¹ÂÚÍøÕ¾»á½«macOSºÍiOSƽ̨µÄÓû§Öض¨ÏòÖÁÒ»¸öÐéαµÄ¶ñÒâÈí¼þѬȾ¾¯±¨Ò³Ãæ £¬£¬£¬£¬£¬ÕâÊÇÒ»¸öµä·¶µÄÊÖÒÕÖ§³ÖȦÌ× £¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚÓÕʹÓû§¶©ÔĶÌÐÅЧÀÍ»òÆ­ÊØÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£ÈôÊÇ´ÓWindows»òAndroid»á¼û¸ÃÍøÕ¾ £¬£¬£¬£¬£¬Ôò»á±»Öض¨ÏòÖÁ²î±ðµÄ´¹ÂÚÍøÕ¾¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/scammers-ride-on-voter-info-website-popularity-to-push-scareware-alerts/


5¡¢¿ªÔ´Á÷ýÌåЧÀÍÆ÷IcecastÐû²¼Çå¾²¸üР£¬£¬£¬£¬£¬ÐÞ¸´Ò»¸öRCEÎó²î

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Çå¾²Ñо¿Ö°Ô±·¢Ã÷¿ªÔ´Á÷ýÌåЧÀÍÆ÷Icecast±£´æÒ»¸öÎó²î £¬£¬£¬£¬£¬¿ÉÄܵ¼Ö»ùÓÚ¸ÃÈí¼þµÄÍøÂç¹ã²¥µç̨Í߽⡣¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2018-18820£©ÊÇÒ»¸öÓësprintfº¯ÊýÓйصĻº³åÇøÒç³öÎó²î £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓöñÒâµÄ³¬³¤HTTPÍ·´¥·¢¸ÃÎó²î £¬£¬£¬£¬£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´Ðлò¾Ü¾øÐ§ÀÍ¡£¡£¡£¡£¡£¡£IcecastÔÚ11ÔÂ1ÈÕÐû²¼µÄа汾2.4.4ÖÐÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/security-bug-puts-online-radio-stations-at-risk/


6¡¢Ñо¿ÍŶÓÅû¶Sophos HitmanPro.AlertÖеĶà¸öÇå¾²Îó²î

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


˼¿ÆTalosÍŶÓÅû¶Sophos HitmanPro.AlertÖеĶà¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£HitmanPro.AlertÊÇÒ»¸ö¶ñÒâÈí¼þ¼ì²âºÍ·À»¤¹¤¾ß £¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷µÄÎó²îÓëÊäÈëÊä³ö¿ØÖÆ£¨IOCTL£©ÐÂÎÅ´¦Öóͷ£Àú³ÌÓÐ¹Ø £¬£¬£¬£¬£¬Îó²î£¨CVE-2018-3970£©¿ÉÔÊÐí¹¥»÷Õß¶ÁÈ¡ÄÚºËÄÚ´æÖеÄÄÚÈÝ £¬£¬£¬£¬£¬Îó²î£¨CVE-2018-3971£©¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐкÍÌáȨ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»¹ÑÝʾÁËÔõÑùʹÓøÃÎó²î¹¹½¨exploitÀ´»ñÈ¡ÍâµØSYSTEMȨÏÞ¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2018/11/TALOS-2018-0636.html


ÉùÃ÷£º±¾×ÊѶÓÉÄϹ¬NGÓéÀÖάËûÃüÇ徲С×é·­ÒëºÍÕûÀí