¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181109

Ðû²¼Ê±¼ä 2018-11-09
1¡¢ÃÀ¹úÍøÂç˾ÁCNMF½«ÏòVirusTotal¹²Ïí¶ñÒâÈí¼þÑù±¾

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


±¾ÖÜÒ»ÃÀ¹úÍøÂç˾Á£¨USCYBERCOM£©µÄÏÂÊôµ¥Î»¹ú¼ÒÍøÂçʹÃü²½¶Ó£¨CNMF£©Ðû²¼Æô¶¯Ò»¸öÐÂÏîÄ¿ £¬£¬£¬ÃÀ¹ú¹ú·À²¿½«Í¨¹ý¸ÃÏîÄ¿Ïò¸üÆÕ±éµÄÍøÂçÇå¾²ÉçÇø¹²ÏíÆä·¢Ã÷µÄ¶ñÒâÈí¼þÑù±¾¡£¡£¡£¡£¡£¸ÃÏîĿͨ¹ýÔÚÏßɨÃèЧÀÍVirusTotal¾ÙÐÐ £¬£¬£¬±ðµÄUSCYBERCOM»¹½¨ÉèÁËÒ»¸öеÄTwitterÕÊ»§£¨@CNMF_VirusAlert£© £¬£¬£¬ÓÃÓÚÐû²¼Ð¶ñÒâÈí¼þÑù±¾µÄVirusTotalÁ´½Ó¡£¡£¡£¡£¡£´Ë¾Ù»ñµÃÁËÍøÂçÇå¾²½ìµÄÒ»ÖÂºÃÆÀ¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/us-cyber-command-starts-uploading-foreign-apt-malware-to-virustotal/


2¡¢¾Ýͳ¼Æ2018ÄêǰÈý¼¾¶ÈÒÆ¶¯¶ñÒâÈí¼þ×ÜÊýͬ±ÈÔöÌí40%

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ƾ֤Çå¾²³§ÉÌG DATAµÄͳ¼Æ £¬£¬£¬×èÖ¹2018ÄêµÚÈý¼¾¶ÈÄ© £¬£¬£¬G DATAµÄÆÊÎöʦÒѾ­·¢Ã÷ÁËÔ¼320Íò¸öÒÆ¶¯¶ñÒâÈí¼þÑù±¾ £¬£¬£¬ÓëÈ¥ÄêͬÆÚÏà±È£¨2017ÄêǰÈý¼¾¶ÈµÄÊý¾ÝÊÇÔ¼220Íò¸öÒÆ¶¯¶ñÒâÈí¼þÑù±¾£© £¬£¬£¬ÔöÌíÁË40%¡£¡£¡£¡£¡£ÍøÂç·¸·¨·Ö×ÓÔ½À´Ô½¹Ø×¢Òƶ¯×°±¸ £¬£¬£¬ÓÈÆäÊÇAndroid×°±¸ £¬£¬£¬ÆäÔµ¹ÊÔ­ÓÉÊÇÈ«ÇòÊ®·ÖÖ®°ËµÄÉú³Ý¶¼ÔÚʹÓøÃϵͳ¡£¡£¡£¡£¡£ÕâҲʹµÃÒÆ¶¯Éè±¹ØÁ¬ÄÇå¾²Ô½À´Ô½Ö÷Òª¡£¡£¡£¡£¡£
  Ô­ÎÄÁ´½Ó£º
https://www.gdatasoftware.com/blog/2018/11/31255-cyber-attacks-on-android-devices-on-the-rise


3¡¢Ñо¿ÍŶӷ¢Ã÷2018Äê9Ô·ÝÀÕË÷Èí¼þ¹¥»÷ÊýÄ¿ì­Éý

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


BBR¹«Ë¾µÄÑо¿ÍŶӷ¢Ã÷2018Äê9Ô·ÝÀÕË÷Èí¼þ¹¥»÷µÄÊýÄ¿ÔÙ´Îì­Éý £¬£¬£¬Ïà±È8Ô·ÝÔöÌíÁËÒ»±¶ÒÔÉÏ¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎúÕâÒ»Ç÷ÊÆÊÇ·ñ»áÑÓÐøÏÂÈ¥¡£¡£¡£¡£¡£ÔÚ9Ô·Ý֮ǰ £¬£¬£¬2018ÄêµÄÀÕË÷Èí¼þ¹¥»÷Óë2017Äê¼á³ÖÏà¶ÔÎÈ¹Ì £¬£¬£¬Ò½ÁƱ£½¡ÐÐÒµÒÀ¾ÉÊÇ×î±»Õë¶ÔµÄÐÐÒµ£¨37%£©¡£¡£¡£¡£¡£ÔÚµÚÈý¼¾¶È £¬£¬£¬½ðÈÚÐÐÒµÔâµ½µÄÀÕË÷Èí¼þ¹¥»÷Ïà±ÈÉÏÒ»¼¾¶ÈÔöÌíÁË18¸ö°Ù·Öµã¡£¡£¡£¡£¡£ÀÕË÷Êê½ð×î¸ßµÄÀÕË÷Èí¼þÊÇRyukºÍBitPaymer¡£¡£¡£¡£¡£Æ¾Ö¤¸Ã¹«Ë¾µÄÊý¾Ý £¬£¬£¬ÔÚ2018ÄêµÄǰ9¸öÔ £¬£¬£¬71%µÄÀÕË÷Èí¼þ¹¥»÷Ö÷ÒªÕë¶ÔÖÐСÐÍÆóÒµ¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.beazley.com/news/2018/beazley_breach_insights_october_2018.html


4¡¢nginx¿ª·¢ÍŶÓÐû²¼Çå¾²¸üР£¬£¬£¬ÐÞ¸´¶à¸öÎó²î

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


¿ªÔ´WebЧÀÍÆ÷nginxÔÚ11ÔÂ6ÈÕÐû²¼Ð°汾1.15.6ºÍ1.14.1 £¬£¬£¬ÐÞ¸´Ö®Ç°°æ±¾ÖеĶà¸öÇå¾²Îó²î¡£¡£¡£¡£¡£ÆäÖаüÀ¨ÄÚ´æºÄ¾¡Îó²î£¨CVE-2018-16843£©ºÍCPUºÄ¾¡Îó²î£¨CVE-2018-16844£© £¬£¬£¬¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÖÆµÄHTTP/2ÇëÇóµ¼Ö¾ܾøÐ§ÀÍÇéÐΡ£¡£¡£¡£¡£±ðµÄ £¬£¬£¬¿ª·¢ÍŶӻ¹ÐÞ¸´ÁËMP4Ä£¿£¿£¿£¿éÖеÄÄÚ´æ×ß©Îó²î£¨CVE-2018-16845£©¡£¡£¡£¡£¡£Æ¾Ö¤NetcraftµÄͳ¼Æ £¬£¬£¬×èÖ¹2018Äê10Ô·ÝÔ¼ÓÐ25.28%µÄ´óÐÍÍøÕ¾ÊÇ»ùÓÚnginxµÄ¡£¡£¡£¡£¡£½¨ÒéÍøÕ¾ÖÎÀíÔ±¾¡¿ì¾ÙÐиüС£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/nginx-security-issues-expose-more-than-14-million-servers-to-dos-attacks-523659.shtml


5¡¢¼íÆÒÕ¯¶à¼ÒISPÔâµ½¸Ã¹úÀúÊ·ÉÏ×î´ó¹æÄ£µÄDDoS¹¥»÷

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


±¾ÖܼíÆÒÕ¯×î´óµÄ¼¸¼Ò»¥ÁªÍøÐ§ÀÍÌṩÉÌ£¨ISP£©Ôâµ½ÁË´ó¹æÄ£µÄDDoS¹¥»÷ £¬£¬£¬°üÀ¨EZECOM¡¢SINET¡¢TelcotechºÍDigi¡£¡£¡£¡£¡£¾ÝÍâµØÃ½Ì屨µÀ £¬£¬£¬´Ë´ÎDDoS¹¥»÷ÊǸùúÀúÊ·ÉÏ×î´ó¹æÄ£µÄ¹¥»÷Ö®Ò» £¬£¬£¬±¾ÖÜÒ»µÄDDoS¹¥»÷Á÷Á¿´ï½ü150Gbps¡£¡£¡£¡£¡£¹ØÓڴ˴ι¥»÷µÄÔµ¹ÊÔ­ÓɺÍÄîÍ·Éв»ÇåÎú £¬£¬£¬Ò²Ã»Óй¥»÷ÕßÐû³Æ¶Ô´ËÈÏÕæ¡£¡£¡£¡£¡£Ò»ÖÖ¿ÉÄܵÄÇéÐÎÊÇISP¾ºÕùµÐÊÖÖ®¼äµÄÏ໥¹¥»÷¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/cambodias-isps-hit-by-some-of-the-biggest-ddos-attacks-in-the-countrys-history/


6¡¢Ñо¿Ö°Ô±ÑÝʾÔõÑùʹÓÃcookieÐ®ÖÆ´ó½®ÎÞÈË»úÕË»§

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Check PointÑо¿Ö°Ô±·¢Ã÷´ó½®ÎÞÈË»ú±£´æÇå¾²Îó²î £¬£¬£¬¿Éµ¼ÖÂÓû§ÕÊ»§±»Ð®ÖÆ £¬£¬£¬½ø¶øµ¼ÖÂÎÞÈË»úº½ÐÐ×ÊÁϵÈÐÅÏ¢¿É±»¹¥»÷Õß»á¼û¡£¡£¡£¡£¡£¸ÃÎó²îµÄÔµ¹ÊÔ­ÓÉÊÇ´ó½®ÔÚ¶à¸öƽ̨ÉÏʹÓÃÁËÏàͬµÄcookie £¬£¬£¬°üÀ¨ÔÚÏßÂÛ̳¡¢Òƶ¯APPºÍWeb app DJI FlightHub¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Í¨¹ýÔÚ´ó½®ÂÛ̳ÉÏʵÑéXSS¹¥»÷ £¬£¬£¬ÀֳɵØÇÔÈ¡ÁËÓû§µÄcookie £¬£¬£¬½ø¶ø¿ÉÒÔͨ¹ý¸ÃcookieµÇ¼ÆäËüƽ̨»á¼ûÓû§µÄ×ÊÁÏ¡£¡£¡£¡£¡£´ó½®ÌåÏÖÒѾ­ÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/dji-drone-flight-logs-photos-and-videos-exposed-to-unauthorized-access/


ÉùÃ÷£º±¾×ÊѶÓÉÄϹ¬NGÓéÀÖάËûÃüÇ徲С×é·­ÒëºÍÕûÀí