¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181101

°ä²¼¹¦·ò 2018-11-01
1¡¢¹«°²»ú¹Ø»¥ÁªÍø°²È«¼à¶½²é³­»®¶¨½ñÈÕÆðÍ·Ö´ÐÐ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¡¶¹«°²»ú¹Ø»¥ÁªÍø°²È«¼à¶½²é³­»®¶¨¡·ÒѾ­ÓÚ2018Äê9ÔÂ5ÈÕ¹«°²²¿²¿³¤°ì¹«»áÒéͨ¹ý£¬×Ô2018Äê11ÔÂ1ÈÕÆðÖ´ÐÐ ¡£±¾»®¶¨ºÏÓÃÓÚ¹«°²»ú¹ØÒÀ·¨¶Ô»¥ÁªÍø·þÎñÌṩÕߺÍÁªÍøÊ¹Óõ¥ÔªÍƹã˾·¨¡¢ÐÐÕþÂÉÀý»®¶¨µÄÍøÂ簲ȫʹÃüÇé¿ö½øÐеݲȫ¼à¶½²é³­ ¡£»¥ÁªÍø°²È«¼à¶½²é³­¹¤×÷ÓÉÏØ¼¶ÒÔÉÏ´¦ËùÈËÃñµ±¾Ö¹«°²»ú¹ØÍøÂ簲ȫ±£ÎÀ²¿ÃÅ×éÖ¯Ö´ÐÐ ¡£¹«°²»ú¹Ø¶Ô»¥ÁªÍø°²È«¼à¶½²é³­¹¤×÷Öз¢ÏֵĿÉÄÜ·çÏÕ¹ú¶È°²È«¡¢¹«¹²°²È«¡¢Éç»áÖÈÐòµÄÍøÂ簲ȫ·çÏÕ£¬¸Ãµ±ÊµÊ±´«µÝÓйØÖ÷¹Ü²¿Ãź͵¥Ôª ¡£

   

Ô­ÎÄÁ´½Ó£º

http://www.mps.gov.cn/n2254314/n2254409/n4904353/c6263180/content.html


2¡¢×êÑÐÍŶӰ䲼2018ÄêµÚÈý¼¾¶ÈDDoS¹¥»÷Ç÷ÏòµÄ·ÖÎö»ã±¨

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¿¨°Í˹»ù°ä²¼2018ÄêµÚÈý¼¾¶ÈDDoS¹¥»÷Ç÷ÏòµÄ·ÖÎö»ã±¨£¬»ã±¨µÄÖØÒª·¢ÏÖÔ̺¬£ºÍ¨¹ý½©Ê¬ÍøÂçÌáÒéµÄDDoS¹¥»÷ÊýÁ¿ÔÚ8Ô·ݴﵽ¶¥·å£¬×îµÍ¹È³Ê´Ë¿Ì7Ô³õ£»³ÖÐøÐÔDDoS¹¥»÷µÄÊýÁ¿ÓÐËù½µÂ䣬Ȼ¶ø³ÖÐø¹¦·ò¶ÌÓÚ4Ó×ʱµÄ¹¥»÷Ôö³¤ÁË17.5¸ö°Ù·Öµã£¬´ï86.94%£»SYN·ººé¹¥»÷ÒÀÈ»ÅÅÔÚµÚһ루83.2%£©£»ÖйúÒÀÈ»Êǹ¥»÷ÊýÁ¿×î¶àµÄµØÓò£¨78%£© ¡£

 

 Ô­ÎÄÁ´½Ó£º

https://securelist.com/ddos-report-in-q3-2018/88617/


3¡¢Windows 10зì϶ÔÊÐíUWPÀûÓýӼûÈ«ÊýÎļþϵͳ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ͨÓÃWindowsƽ̨£¨UWP£©ÀûÓÃÔÊÐíÀûÓ÷¨Ê½ÔÚÖ°ºÎWindows 10É豸ÉÏÔËÐУ¬Ô̺¬Ì¨Ê½»ú¡¢Xbox¡¢ÎïÁªÍøÉ豸ºÍSurface HubµÈ ¡£Î¢ÈíΪUWPÀûÓÃÌṩÁËÒ»¸öAPIÀ´½Ó¼ûÎļþϵͳ£¬Õý³£Çé¿öϸÃAPI»áµ¯³ö¶Ô»°¿òÉêÇëÓû§µÄȨÏÞÐí¿É£¬µ«×êÑÐÈËÔ±·¢ÏÖ¸ÃAPI´æÔÚÖÂÃü·ì϶£¬¶ñÒâµÄUWPÀûÓÿÉÈÆ¹ýÓû§µÄȨÏÞÒªÇó½Ó¼ûÆëÈ«µÄÎļþϵͳ ¡£Î¢ÈíÒѾ­ÔÚWindows 10°æ±¾1809Öн¨¸´Á˸÷ì϶ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/10/windows10-uwp-apps.html


4¡¢×êÑÐÈËÔ±ÔÚа䲼µÄiOS 12.1Öз¢ÏÖÃÜÂëÈÆ¹ý·ì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

ÔÚApple°ä²¼iOS 12.1µÄ¼¸¸öÓ×ʱÄÚ£¬Î÷°àÑÀ×êÑÐÈËÔ±Jose Rodriguez·¢ÏÖÁËÒ»¸öеÄÃÜÂëÈÆ¹ý·ì϶ ¡£¸Ã·ì϶ÓëiOS 12.1ÖеÄÐÂÖ°ÄÜGroup FaceTimeÓйØ£¬×êÑÐÈËÔ±Åû¶ÁËÓйØPoCÊÓÆµ ¡£¸Ã·ìÏ¶ËÆºõºÏÓÃÓÚËùÓеÄiPhoneÐͺÅ£¬Ô̺¬iPhone XºÍXS ¡£ÓÉÓÚĿǰûÓÐһʱ½â¾ö¸ÃÎÊÌâµÄworkaround£¬½¨ÒéÓû§ÆÚ´ýAppleµÄ¸üР¡£ÕâÒѾ­ÊÇRodriguez½üÆÚµÚÈý´ÎѸËÙ·¢ÏÖiOS 12ÖеÄÃÜÂëÈÆ¹ý·ì϶ÁË ¡£

  

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/10/iphone-ios-passcode-bypass.html


5¡¢Ë¼¿ÆÅû¶ASAºÍFTD²úÆ·ÖеÄÐÂ0day£¬¿Éµ¼Ö»ؾø·þÎñ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


˼¿Æ°²È«ÍŶÓÅû¶Æä×ÔÊÊÓ¦°²È«É豸£¨ASA£©ºÍFirepowerÍþв·ÀÓùÈí¼þ£¨FTD£©ÖеĻỰ³õʼ»¯ºÍ̸£¨SIP£©²é³­ÒýÇæ´æÔÚÒ»¸ö¿Éµ¼Ö»ؾø·þÎñµÄÁãÈÕ·ì϶ ¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâSIPÒªÇóÀ´´¥·¢¸Ã·ì϶£¬µ¼ÖÂDoS ¡£¸Ã·ì϶£¨CVE-2018-15454£©Ó°ÏìÔËÐÐASA 9.4+ºÍFTD 6.0+µÄÉ豸£¬Ô̺¬¶à¸öÐͺŵĹ¤Òµ°²È«É豸ºÍ·À»ðǽµÈ²úÆ· ¡£Ä¿Ç°»¹Ã»Óи÷ì϶µÄ½¨¸´²¹¶¡ºÍworkaround£¬µ«Äܹ»²ÉȡһЩ»º½â´ëÊ©×èÖ¹Ô¶³Ì¹¥»÷Õß·ÛËéÆäÉ豸 ¡£

  

Ô­ÎÄÁ´½Ó£º

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181031-asaftd-sip-dos


6¡¢×êÑлú¹¹°ä²¼¹ØÓÚÀÕË÷Èí¼þ¼´·þÎñKraken CryptorµÄ·ÖÎö»ã±¨

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Insikt GroupÓëMcAfee¹²Í¬°ä²¼¹ØÓÚÀÕË÷Èí¼þKraken CryptorµÄ·ÖÎö»ã±¨ ¡£KrakenÓÚ2018Äê8Ô³õ´ÎÔÚÒ°±í³öÏÖ£¬ÓÉ»îÔ¾ÔÚ¶íÂÞ˹·¸×ïÂÛ̳ÉϵÄÍÅ»ïThisWasKraken½øÐзַ¢ ¡£KrakenÊÇÒ»¸öÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©µÄ»áÔ±ÔìÏúÊÛ´òË㣬ÓÉThisWasKrakenÕÆ¹Ü¾­Óª£¬ÆäÖØÒª·Ö·¢·½Ê½ÊÇFallout EK ¡£×êÑÐÈËÔ±»¹·¢ÏÖThisWasKrakenÀûÓÃÔÚÏ߶ij¡BitcoinPenguinÀ´Ï´Ç® ¡£Insikt GroupÐÅÄîÊ®×ãµØÒÔΪThisWasKrakenÍŶӵijÉÔ±¾ÓסÔÚÒÁÀÊ¡¢°ÍÎ÷»òǰËÕÁª¹ú¶È ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.recordedfuture.com/kraken-cryptor-ransomware/


ÉêÃ÷£º±¾×ÊѶÓɱ¦ÔËÀ³¹Ù·½ÍøÕ¾Î¬ËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù