¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181107

°ä²¼¹¦·ò 2018-11-07
1¡¢¿¨°Í˹»ù°ä²¼2018ÄêQ3À¬»øÓʼþºÍ´¹µö»î¶¯µÄÇ÷Ïò·ÖÎö

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼2018ÄêµÚÈý¼¾¶ÈÀ¬»øÓʼþºÍÍøÂç´¹µö»î¶¯µÄÇ÷Ïò·ÖÎö»ã±¨¡£¡£¡£¡£¡£ÔÚ2018ÄêQ3£¬£¬£¬£¬£¬£¬À¬»øÓʼþռȫÇòÓʼþ×ÜÁ¿ÖеıÈÀýÔö³¤ÁË2.88¸ö°Ù·Öµã£¬£¬£¬£¬£¬£¬´ï52.54%¡£¡£¡£¡£¡£·´´¹µöϵͳ¹²×èÖ¹Á˳¬¹ý1.37ÒÚ¸öÌø×ªÖÁ´¹µöÍøÕ¾µÄ³Á¶¨Ïò£¬£¬£¬£¬£¬£¬±ÈÉÏÒ»¼¾¶ÈÔö³¤ÁË3000Íò¡£¡£¡£¡£¡£À¬»øÓʼþºÍ´¹µö»î¶¯³ÖÐøÀûÓñ¾¼¾¶ÈµÄ³Á´óÐÂÎű¨Â·À´´«²¼£¬£¬£¬£¬£¬£¬ÀýÈçÐÂiPhoneµÄ°ä²¼¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://securelist.com/spam-and-phishing-in-q3-2018/88686/


2¡¢×êÑÐÍŶӷ¢ÏÖÀûÓÃÐéαTelegram¼à¶½ÒÁÀÊÓû§µÄ¶ñÒâ»î¶¯

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


˼¿ÆTalosÅû¶ÁËÒÁÀʵÄһЩÓɹú¶ÈÔÞÖúµÄ¶ñÒâ»î¶¯£¬£¬£¬£¬£¬£¬ÕâЩ»î¶¯×Ô2017ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬£¬ÖØÒªÓÃÓڼලÒÁÀʵÄÔ¼4000ÍòTelegramÓû§£¨¹ÌÈ»¸ÃÀûÓÃÏÖʵÉÏÔڸùú±»²»ÈÝʹÓã©¡£¡£¡£¡£¡£Talos³ÆÕâЩ»î¶¯µÄ¸´ÔÓÐÔ¡¢×ÊÔ´ÐèÒªºÍ²½Öè¸÷²»Ò»Ñù£¬£¬£¬£¬£¬£¬µ«ÖØÒªÊ¹ÓÃÁËÈý¸öÔØÌ壺ÐéαÀûÓᢴ¹µöµÇÂ¼Ò³ÃæºÍBGP½Ù³Ö¡£¡£¡£¡£¡£ÕâЩÐéαTelegram¡°¿Ë¡Ì塱Ӧ¸Ã±»¹éÀàΪ»ÒÉ«Èí¼þ»òDZÔÚÓꦵÄÈí¼þ£¨PUP£©¡£¡£¡£¡£¡£¹ÌÈ»ÕâЩ¶ñÒâ»î¶¯¶¼Õë¶ÔÒÁÀÊ£¬£¬£¬£¬£¬£¬µ«×êÑÐÈËÔ±²¢Î´·¢ÏÖËüÃÇÖ®¼ä´æÔÚÁªÏµ¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2018/11/persian-stalker.html


3¡¢·¸×ïÍÅ»ïInceptionÀûÓÃÐÂPowerShellºóÃŶÔ׼ŷÖÞ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Palo Alto NetworksµÄUnit42°ä²¼¹ØÓÚ·¸×ïÍÅ»ïInceptionµÄй¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£InceptionÖÁÉÙ×Ô2014ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ÔøÔÚ2017ÄêÕë¶ÔÅ·ÖÞ¡¢¶íÂÞ˹ºÍÖÐÑǵØÓòÈ·µ±¾Ö»ú¹¹ÌáÒé¹¥»÷¡£¡£¡£¡£¡£Unit42¹Û²ìµ½¸Ã×éÖ¯ÔÚ2018Äê10ÔÂʹÓÃOffice·ì϶CVE-2017-11882ºÍÒ»¸öеÄPowerShellºóÃÅÕë¶ÔÅ·ÖÞµÄÖ¸±êÌáÒé¹¥»÷¡£¡£¡£¡£¡£¸ÃºóÃű»³ÆÎªPOWERSHOWER£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚÍøÂçϵͳÐÅÏ¢²¢ÉÏ´«ÖÁC2·þÎñÆ÷ÒÔ¼°¶Ï¸ùÖ¤¾Ý£¬£¬£¬£¬£¬£¬»¹¿ÉÓÃÓÚÖ´ÐÐÆäËüpayload¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://researchcenter.paloaltonetworks.com/2018/11/unit42-inception-attackers-target-europe-year-old-office-vulnerability/


4¡¢×êÑÐÈËÔ±·¢ÏÖ¶à¿î×Ô¼ÓÃÜSSD´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷Õß½âÃÜÓû§Êý¾Ý

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ºÉÀ¼Radboud´óѧµÄ×êÑÐÈËÔ±Carlo MeijerºÍBernard van Gastel·¢ÏÖ¶à¿îÊ¢ÐеÄ×Ô¼ÓÃÜSSD´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷Õß½âÃÜ´ÅÅ̺ͻñÈ¡Óû§Êý¾Ý¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬CrucialµÄCruces MX100ºÍÈýÐǵÄ850 EVOµÈ¡£¡£¡£¡£¡£CrucialÒѾ­ÎªÆäËùÓÐÊÜÓ°ÏìµÄSSD°ä²¼Á˹̼þ²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬µ«ÈýÐÇֻΪT3ºÍT5±ãЯʽSSD°ä²¼Á˽¨¸´²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬²¢½¨ÒéEVOÓû§Ê¹ÓÃÓëϵͳ¼æÈݵļÓÃÜÈí¼þ¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/11/self-encrypting-ssd-hacking.html


5¡¢Google°ä²¼11ÔÂAndroid°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´¶à¸ö·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

GoogleÔÚ11Ô·ݵÄAndroid°²È«¸üÐÂÖн¨¸´ÁË36¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬´Ë±í»¹ÓÐ17¸ö·ì϶ÓëQualcomm×é¼þÓйØ¡£¡£¡£¡£¡£½ÏÑϳÁµÄ·ì϶Ô̺¬Ó°ÏìAndroid 7.0+µÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-9527£©ºÍÓ°Ïì9.0µÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2018-9531ºÍCVE-2018-9521£©¡£¡£¡£¡£¡£ÓÉÓÚÔÚLibxaac¿âÖз¢ÏÖ´óÁ¿°²È«·ì϶£¬£¬£¬£¬£¬£¬Òò¶øGoogleÒѽ«¸Ã¿âÏóÕ÷Ϊ³¢ÊÔÐÔ²¢ÇÒ²»»á½«¸Ã¿âÔ̺¬ÔÚÖ°ºÎAndroid³ö²ú°æ±¾ÖС£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬11Եݲȫ¸üнöºÏÓÃÓÚAndroid7.0+µÄ°æ±¾£¬£¬£¬£¬£¬£¬»»¾ä»°Ëµ£¬£¬£¬£¬£¬£¬Android 6.x½«²»Ôٵõ½GoogleµÄÖ§³Ö¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://source.android.com/security/bulletin/2018-11-01.html


6¡¢Akado TelecomÒâ±íй¶ÊýǧÃû¿Í»§µÄÓ×ÎÒÐÅÏ¢

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¾Ý·͸É籨·£¬£¬£¬£¬£¬£¬¶íÂÞ˹ISP Akado TelecomÒâ±íµØ½«ÊýǧÃû¿Í»§µÄÓ×ÎÒÐÅÏ¢ÉÏ´«ÖÁRIPE NCCµÄ·þÎñÆ÷£¬£¬£¬£¬£¬£¬ÕâЩй¶µÄÓ×ÎÒÐÅÏ¢£¨PII£©Öл¹Ô̺¬Ò»Ð©¶íÂÞ˹µ±¾Ö¹ÙÔ±ºÍ¶íÂÞ˹ÃûÈË¡¢ÒøÐй¤×÷ÈËÔ±µÄµØÖ·ºÍµç»°ºÅÂëµÈ¡£¡£¡£¡£¡£RIPE NCCÊÇÅ·ÖÞ¡¢Öж«ºÍÖÐÑDz¿ÃŵØÓòµÄ·ÇͶ»úÐÔÇøÓò»¥ÁªÍø×¢²á»ú¹¹£¬£¬£¬£¬£¬£¬ÆäÊý¾Ý¿âÊǿɹ«¿ª½Ó¼ûµÄ¡£¡£¡£¡£¡£Akado Telecom°µÊ¾ÒѾ­Æô¶¯ÁËÒ»Ïî¹ØÓÚ´ËÊÂÎñµÄÄÚ²¿µ÷²é¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/akado-telecom-accidentally-leaks-customers-names-phone-numbers-and-addresses-523617.shtml


ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù