¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180807
°ä²¼¹¦·ò 2018-08-07¡¾·ÖÎö»ã±¨¡¿ICS-CERT°ä²¼ÁªÍøµçÁ¦ÏµÍ³ÍøÂç°²È«Ì¬ÊÆ·ÖÎö»ã±¨
CNCERTÏÂÊôµÄ¹¤Òµ»¥ÁªÍø°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨ICS-CERT£©Õë¶ÔÎÒ¹úÁªÍøµçÁ¦ÏµÍ³µÄÍøÂç°²È«Ì¬ÊÆ½øÐзÖÎö£¬£¬£¬£¬£¬£¬2018Äê1-2¼¾¶ÈÆÚ¼ä¼à²â·¢ÏÖ¶³öÔÚ¹«¹²»¥ÁªÍøµÄµçÁ¦ÐÐÒµÍøÂç×ʲú1147¸ö£¬£¬£¬£¬£¬£¬²¿ÃÅÉ豸´æÔÚÑϳÁµÄ°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£Í¨¹ýÒýÈëÁªÍøµçÁ¦ÏµÍ³ÍøÂ簲ȫÍþвָÊý£¬£¬£¬£¬£¬£¬´ÓÉ豸×ʲúºÍWEB×ʲúÁ½¸ö½Ç¶È£¬£¬£¬£¬£¬£¬½áºÏ·ì϶ÍþвµÈ¼¶¡¢Ì½²â´ÎÊýºÍ¹¥»÷´ÎÊý£¬£¬£¬£¬£¬£¬¶ÔÎÒ¹ú·ÖÆçµØÓòµÄÁªÍøµçÁ¦ÏµÍ³°²È«ÍþвָÊý½øÐÐÁË×ۺϷÖÎö£¬£¬£¬£¬£¬£¬·¢ÏÖÎÞÊýÊ¡·ÝÇé¿öÓÅÁ¼£¬£¬£¬£¬£¬£¬¶ø¹ã¶«¡¢±±¾©µÈÊ¡Êа²È«´ó¾ÖÏà¶ÔÑϸñ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.ics-cert.org.cn/portal/page/121/95290efb86b44d7d8cd7ee222f3e9e24.html
¡¾·ÖÎö»ã±¨¡¿×êÑлú¹¹°ä²¼2018ÄêQ2ÍøÂçÍþвÇ÷ÏòµÄ·ÖÎö»ã±¨
¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼¹ØÓÚ2018ÄêQ2ÍøÂçÍþвÇ÷ÏòµÄͳ¼Æ»ã±¨£¬£¬£¬£¬£¬£¬»ã±¨º¸ÇÁ˵ڶþ¼¾¶ÈµÄÓÐÕë¶ÔÐԵĹ¥»÷»î¶¯£¬£¬£¬£¬£¬£¬ÈçOperation Parliament¡¢APT×éÖ¯Energetic Bear¡¢Òƶ¯ÍþвZooPark¡¢Õë¶Ô·ÓÉÆ÷µÄ½©Ê¬ÍøÂçVPNFilter¡¢Õë¶ÔÖÐÑÇÊý¾ÝÖÐÐĵÄLuckyMouseÒÔ¼°Õë¶ÔÅ·ÖÞ½ðÈÚ»ú¹¹ºÍÉúÎï×éÖ¯µÄOlympic Destroyer¡£¡£¡£¡£¡£¡£¡£»ã±¨»¹º¸ÇÁ˲¿ÃŶñÒâÈí¼þ¼°Æäм¼Êõ£¬£¬£¬£¬£¬£¬ÈçSynAckºÍRoaming MantisµÈ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securelist.com/it-threat-evolution-q2-2018/87172/
¡¾Íþвµý±¨¡¿FBI°ä²¼°²È«²¼¸æ¾¯Ê¾ÎïÁªÍøÉ豸Öеݲȫ·çÏÕ
ÃÀ¹úFBIÖÒ¸æ³ÆÓû§µÄÎïÁªÍøÉ豸¿ÉÄÜÒѱ»ÊÕÊÜ£¬£¬£¬£¬£¬£¬ÕâЩIoT½©Ê¬ÍøÂç±»ÓÃÓÚÌáÒéDDoS¹¥»÷µÈ¡£¡£¡£¡£¡£¡£¡£´Ó·ÓÉÆ÷ºÍNASÉ豸µ½DVR¡¢Ê÷Ý®ÅÉÉõÖÁÊÇÖÇÄܳµ¿â£¬£¬£¬£¬£¬£¬ËùÓÐIoTÉ豸¶¼¿ÉÄÜÃæ¶Ô·çÏÕ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿£¿ÉÒɵļ£ÏóÔ̺¬»¥ÁªÍøÔÂʹÓÃÁ¿µÄ´ó·ùÔö³¤¡¢¸ß¶îµÄISPÕ˵¥¡¢É豸ÔËÐлºÂý»òÎÞ·¨ÔËÐÓ×¢DNS²éÎʺÍÁ÷Á¿Òì³£ÒÔ¼°ÍøÂçÏνÓËÙ¶ÈÂýµÈ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ³£»£»£»£»£»áÕë¶ÔÓµÓÐÈõ¿ÚÁ佨¸´µÄ¹Ì¼þ»òÈí¼þ·ì϶ÒÔ¼°Ê¹ÓÃĬÈÏÓû§ÃûºÍÃÜÂëµÄÉ豸½øÐб©Á¦¹¥»÷¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/fbi-in-smart-device-security/
¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖϰȾ³¬¹ý10ÍòÌ¨ÍÆËã»úµÄ½©Ê¬ÍøÂçBlack
Check Point×êÑÐÍŶӷ¢ÏÖÒøÐжñÒâÈí¼þRamnitµÄеĴó¹æÄ£¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬ÔÚ2018Äê5ÔÂÖÁ7ÔÂÆÚ¼äÒÔ185.44.75.109ΪC&C·þÎñÆ÷µÄ½©Ê¬ÍøÂçBlackϰȾÁ˳¬¹ý10ÍòÌ¨ÍÆËã»ú¡£¡£¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂçµÄÌØµãÔ̺¬£º´óÁ¿Ñù±¾Ê¹ÓÃÓ²±àÂëµÄÓòÃû¶ø²»ÊÇDGA£»£»£»£»£»C£¦C·þÎñÆ÷²¢²»Ìṩ¶î±íµÄÄ£¿£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬ÈçVNC¡¢ÃÜÂëÇÔÈ¡·¨Ê½»òFtpGrabberµÈ£»£»£»£»£»¶î±íµÄÄ£¿£¿£¿£¿£¿£¿£¿£¿é£¨FTPServer¡¢WebInjects£©ÓëRamnit¼¯³ÉÔÚÒ»¸ö°üÖУ»£»£»£»£»Ramnit×÷ΪÁíÒ»¸ö¶ñÒâÈí¼þNgiowebµÄ¼ÓÔØ·¨Ê½¡£¡£¡£¡£¡£¡£¡£½ØÖÁ2018Äê7Ô³õ£¬£¬£¬£¬£¬£¬Ï°È¾ÁËNgiowebµÄÍÆËã»úÊýÁ¿³¬¹ýÁË13.9Íǫ̀¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://research.checkpoint.com/ramnits-network-proxy-servers/
¡¾·ì϶²¹¶¡¡¿HP°ä²¼InkJet´òÓ¡»úµÄ¹Ì¼þ¸üУ¬£¬£¬£¬£¬£¬½¨¸´Á½¸ö¿Éµ¼ÖÂRCEµÄ°²È«·ì϶
»ÝÆÕ°ä²¼InkJet´òÓ¡»úµÄ¹Ì¼þ¸üУ¬£¬£¬£¬£¬£¬½¨¸´ÁËÁ½¸ö°²È«·ì϶£¨CVE-2018-5924ºÍCVE-2018-5925£©¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸ö·ì϶¿Éͨ¹ý·¢ËÍÖÁÖ¸±êÉ豸µÄ¶ñÒâÎļþ´¥·¢£¬£¬£¬£¬£¬£¬µ¼Ö²ֿâ»ò¾²Ì¬»º³åÇøÒç³ö£¬£¬£¬£¬£¬£¬×îÖÕÔÊÐíÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÉ豸Ô̺¬Pagewide Pro¡¢DesignJet¡¢OfficeJet¡¢DeskJetºÍEnvyϵÁеȡ£¡£¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì×°ÖÃÕâЩ¹Ì¼þ¸üС£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.helpnetsecurity.com/2018/08/06/hp-inkjet-printer-vulnerabilities/
¡¾¶ñÒâÈí¼þ¡¿°²È«×êÑÐÈËÔ±·¢ÏÖжñÒâÍÚ¿óÈí¼þZombieBoy
°²È«×êÑÐÈËÔ±James Quinn·¢ÏÖеÄÍÚ¿óÈ䳿ZombieBoy£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÍÚ¿óÈí¼þ¿ÉΪÆä×÷Õß´øÀ´Ã¿Ô¼ÛÖµÔ¼1000ÃÀÔªµÄÃÅÂÞ±Ò¡£¡£¡£¡£¡£¡£¡£ZombieBoyÀûÓõķì϶Ô̺¬RDP·ì϶CVE-2017-9073¡¢SMB·ì϶CVE-2017-0143ºÍCVE-2017-0146µÈ£¬£¬£¬£¬£¬£¬Ò»µ©ÔÚÖ¸±êϵͳÖгÉÁ¢Á˺óÃÅ£¬£¬£¬£¬£¬£¬Ëü¾ÍÄܹ»½øÒ»²½ÌṩÆäËü¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬ÈçÀÕË÷Èí¼þ»ò¼üÅ̼ͼ·¨Ê½µÈ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±Åû¶Á˹ØÓÚZombieBoyµÄ¸ü¶àIoC¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75070/malware/zombieboy-monero-miner.html


¾©¹«Íø°²±¸11010802024551ºÅ