¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181025

°ä²¼¹¦·ò 2018-10-26
1 £¬¹úÌ©º½¿Õ´î¿Í×ÊÁÏÒɱíй £¬²¨¼°Ô¼940Íò³Ë¿Í

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

¹úÌ©º½¿Õ23ÈÕÍí°ä²¼²¼¸æ³Æ £¬¸Ã¹«Ë¾¼°È«×Ê×Ó¹«Ë¾¸ÛÁúº½¿ÕÓÐÏÞ¹«Ë¾µÄ³Ë¿Í×ÊÁÏÔ⵽δÊÚȨ½Ó¼û £¬Ô¼940Íò³Ë¿Í×ÊÁϱ»ÇÔÈ¡ £¬Ô̺¬³Ë¿ÍµÄÐÕÃû¡¢ÉúÈÕ¡¢µç»°¡¢µØÖ·¡¢Éí·ÝÖ¤¼°»¤ÕպŵÈÃô¸ÐÐÅÏ¢¡£´Ë±í £¬»¹ÓÐ403ÕÅÒÑÓâÆÚµÄÐÅÓþ¿¨ºÅÂëй¶¡£¹úÌ©º½¿Õ³ÆÊÜÓ°ÏìµÄÐÅϢϵͳÓ뺽°àÔË×÷ϵͳΪ¶ÀÁ¢µÄϵͳ £¬Õâ´ÎÊÂÎñ²»»á¶Ôº½°à°²È«×é³ÉÈκÎÓ°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://securingtomorrow.mcafee.com/mcafee-labs/android-timpdoor-turns-mobile-devices-into-hidden-proxies/

2 £¬Pocket iNetÒòAmazon S3ÅäÖÃÃýÎóµ¼Ö²¿ÃÅÔ±¹¤µÄÐÅϢй¶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

UpGuard×êÑÐÍŶӷ¢ÏÖÒ»¸öAmazon S3 bucket¿É¹«¿ª½Ó¼û £¬¸ÃÊý¾Ý¿âÊôÓÚ»ªÊ¢¶Ù»¥ÁªÍø·þÎñÌṩÉÌPocket iNet¡£¸ÃÊý¾Ý¿â´óÓ×Ϊ73GB £¬Ô̺¬´óÁ¿Ãô¸ÐÐÅÏ¢ £¬Ô̺¬²¿ÃÅÔ±¹¤µÄAWSÃÜÔ¿ºÍÃ÷ÎÄÃÜÂë¡¢¹«Ë¾ÍøÂç¼Ü¹¹µÄ¾ßÌåÅäÏàÐÅÏ¢¡¢ÄÚ²¿ÍøÂçͼ±íºÍÉ豸ÕÕÆ¬µÈ¡£Pocket iNetÈ·ÈÏÁË¸ÃÆðÊÂÎñ £¬²¢ÔÚ½Óµ½»ã±¨ºóµÄ7ÌìÄÚ½¨¸´Á˸ÃÎÊÌâ¡£


Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/pocket-inet-isp-exposes-misconfigured-73-gb-amazon-s3-bucket-to-the-internet-523392.shtml

3 £¬×êÑÐÈËÔ±ÔÚTwitterÉÏÅû¶µÚ¶þ¸öWindowsÁãÈÕ·ì϶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


°²È«×êÑÐÈËÔ±SandboxEscaperÔÙ´ÎÔÚTwitterÉÏÅû¶һ¸öWindowsÁãÈÕ·ì϶ £¬¸Ã·ìÏ¶ËÆºõ´æÔÚÓÚÊý¾Ý¹²Ïí·þÎñ£¨dssvc.dll£©ÖÐ £¬ÔÊÐíµÍȨÏÞÓû§½øÐÐÌáȨ¡£ÓÉÓÚMicrosoftÊý¾Ý¹²Ïí·þÎñÊÇÔÚWindows 10ÖÐÒýÈëµÄ £¬Òò¶ø¸Ã·ì϶²»»áÓ°Ïì¾É°æ±¾µÄ²Ù×÷ϵͳ £¬ÈçWin 7 ºÍWin 8.1¡£¸Ã×êÑÐÈËÔ±Á½¸öÔÂÇ°ÔøÅû¶ÁíÒ»¸öWindows´òË㹤×÷ÖеÄÁãÈÕ·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/10/windows-zero-day-exploit.html


4 £¬FireEyeÒÔΪTRITON¹¥»÷»î¶¯Óë¶íÂÞ˹×êÑлú¹¹CNIIHM´æÔÚ¹ØÁª

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

ƾ¾ÝFireEye¶ÔTRITONµÄ¹éÒò·ÖÎö £¬¸Ã¶ñÒâ»î¶¯Óë¶íÂÞ˹µ±¾ÖµÄ×êÑлú¹¹»¯Ñ§ºÍÁ¦Ñ§ÖÐÑë¿ÆÑ§×êÑÐÔº(CNIIHM)´æÔÚ¹ØÁª¡£TRITON¹¥»÷²úÉúÔÚ2017Äê8Ô·Ý £¬¹¥»÷ÕßÖØÒªÕë¶Ô¹Ø¼ü»ù´¡ÉèÊ©ÖеÄICSϵͳ¡£×êÑÐÈËÔ±·¢ÏÖµÄÖ¤¾ÝÔ̺¬¶Ô¶à¸ö¶ñÒâÈí¼þ°æ±¾µÄ²âÊԻÒÔ¼°TRITONµÄÐÐΪģʽÇкÏĪ˹¿ÆµØÓòµÄ¹¦·òµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2018/10/triton-attribution-russian-government-owned-lab-most-likely-built-tools.html


5 £¬×êÑÐÍŶӷ¢ÏÖÀûÓÃSMS·Ö·¢Android/TimpDoorµÄÍøÂç´¹µö»î¶¯


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

McAfee×êÑÐÍŶӷ¢ÏÖÒ»¸öʹÓÃSMS·Ö·¢¶ñÒâÈí¼þAndroid/TimpDoorµÄÍøÂç´¹µö»î¶¯¡£TimpDoorÔ̺¬Ò»¸öÍøÂç´úÀí £¬ÓÃÓÚ´«ÊäÀ´×ÔµÚÈý·½·þÎñÆ÷µÄ¼ÓÃÜÁ÷Á¿¡£Ï°È¾ÁËTimpDoorµÄÉ豸¿É±»µ±×÷ºóÃÅ £¬ÓÃÓÚ°ÂÃØ½Ó¼ûÆóÒµºÍ¼ÒÍ¥µÄÄÚ²¿ÍøÂç £¬Ò²¿ÉÓÃÓÚ·¢ËÍÀ¬»øÓʼþµÈ¡£×îÔçµÄTimpDoor±äÌå³öÏÖÓÚ3Ô·Ý £¬×îеÄÔòÊÇ8Եס£Æ¾¾ÝMcAfeeµÄÒ£²âÊý¾Ý £¬¸Ã¶ñÒâÈí¼þÖÁÉÙϰȾÁËÔ¼5000̨É豸¡£


Ô­ÎÄÁ´½Ó£º

https://securingtomorrow.mcafee.com/mcafee-labs/android-timpdoor-turns-mobile-devices-into-hidden-proxies/

6 £¬×êÑлú¹¹°ä²¼2018ÄêÓ¢¹úUnisys°²È«Ö¸Êý £¬³Áµã¹Ø×¢Éí·Ý͵ÇÔÎÊÌâ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

×êÑлú¹¹°ä²¼2018ÄêÓ¢¹úUnisys°²È«Ö¸Êý £¬56%µÄÓ¢¹úÊÜ·ÃÕß°µÊ¾ËûÃǼ«¶È¹Ø×¢Éí·Ý͵ÇÔÎÊÌâ £¬ÕâʹµÃÉí·Ý͵ÇÔ³ÉΪ×îÊܹØ×¢µÄÍþв £¬ÒøÐп¨Ú¿Æ­ºÍ¹ú¶È¹«¹²°²È«½ôËæÆäºó¡£¶ø2017ÄêÓëÕ½Õù»ò¿Ö²ÀÖ÷ÒåÓйصĹú¶È°²ÂúÊÇ×îÊܹØ×¢µÄÎÊÌâ¡£65£¥µÄÓ¢¹ú¹«Ãñ»¹¹Ø×¢Í¨¹ýÉ罻ýÌå½øÐкÏ×÷ºÍ²ß¶¯¹¥»÷µÄ¿Ö²À·Ö×Ó¡£´Ë±í £¬63£¥µÄÊÜ·ÃÕß°µÊ¾ËûÃDz»°²×Ô¼ºµÄÉ罻ýÌå×ÊÁϱ»¹¥»÷ÕßÇÔÈ¡¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2018/10/24/uk-citizens-fear-identity-theft/


ÉêÃ÷£º±¾×ÊѶÓɱ¦ÔËÀ³¹Ù·½ÍøÕ¾Î¬ËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù