¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181121

°ä²¼¹¦·ò 2018-11-21
1¡¢¿¨°Í˹»ù°ä²¼2019ÄêÍøÂçÍþвÇ÷ÏòµÄÔ¤²â»ã±¨

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼¶Ô2019ÄêÍøÂçÍþвÇ÷ÏòµÄÒ»¸öÔ¤²â·ÖÎö £¬£¬£¬£¬ £¬£¬ÖØÒªÄÚÈÝÔ̺¬£º»òÐí²»»áÔÙ·¢ÏÖ¸ü¶àµÄ´óÐÍAPT×éÖ¯£» £»£»£» £»£» £»ÍøÂçÓ²¼þÓëÎïÁªÍøÍþв½«»á²»ÐݼÓÇ¿£» £»£»£» £»£» £»Óë±í½»ºÍÕþÖÎÓйصĹ«¿ª±¨³ð£» £»£»£» £»£» £»¶«ÄÏÑǺÍÖж«µØÓò»òÐí»á³öÏÖ¸ü¶àµÄ¹¥»÷×éÖ¯£» £»£»£» £»£» £»£¨Ring -£©È¨ÏÞ £¬£¬£¬£¬ £¬£¬±ÈRing 0¸ü¸ßµÄȨÏÞ£» £»£»£» £»£» £»×îÊÜ»¶Ó­µÄϰȾý½é-´¹µö£» £»£»£» £»£» £»»ò½«³öÏÖ¸ü¶àÀàËÆ¡°°ÂÔ˱÷³ý½¢¡±µÄ¹¥»÷£» £»£»£» £»£» £»¹©¸øÁ´¹¥»÷½«³ÖÐø£» £»£»£» £»£» £»Òƶ¯¶ñÒâÈí¼þ²»»á³öÏÖ´ó·¢×÷ £¬£¬£¬£¬ £¬£¬µ«¸ß¼¶¹¥»÷Õß»á³ÖÐøÑ°ÕÒÈëÇÖÉ豸µÄ²½Öè¡£¡£¡£¡£¡£¡£¡£¡£

  

 Ô­ÎÄÁ´½Ó£º

https://securelist.com/kaspersky-security-bulletin-threat-predictions-for-2019/88878/


2¡¢FireEye°ä²¼¹ØÓÚAPT29µÄд¹µö»î¶¯µÄ·ÖÎö»ã±¨

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



2018Äê11ÔÂ14ÈÕFireEye¼ì²âµ½Õë¶Ô¶à¸öÐÐÒµµÄ20¶à¸ö¿Í»§µÄÐÂÕë¶ÔÐÔ´¹µö¹¥»÷ £¬£¬£¬£¬ £¬£¬º­¸ÇÖǿ⡢·¨ÂÉ»ú¹¹¡¢Ã½Ìå¡¢ÃÀ¹ú¾ü·½¡¢Í¼Ïñ¡¢ÔËÊä¡¢ÔìÒ©¡¢µ±¾Ö»ú¹¹ÒÔ¼°¹ú·À³Ð°üÉ̵ȡ£¡£¡£¡£¡£¡£¡£¡£ÕâЩ´¹µö¹¥»÷ÀûÓüÙ×°³ÉÀ´×ÔÃÀ¹ú¹úÎñÔºµÄ´¹µöÓʼþ £¬£¬£¬£¬ £¬£¬ÊÔͼ´«²¼Cobalt Strike Beacon¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý¶ÔÆäTTPµÄ·ÖÎö £¬£¬£¬£¬ £¬£¬Æä±³ºóµÄ¹¥»÷×éÖ¯ÒÉΪAPT29¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2018/11/not-so-cozy-an-uncomfortable-examination-of-a-suspected-apt29-phishing-campaign.html


3¡¢ÃÀ¹ú´ó³ÇÊÐÈËÊÙ±£ÏÕ¹«Ë¾Òâ±íй¶²¿Ãſͻ§µÄÓ×ÎÒÐÅÏ¢

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾Ý¼ÓÀû¸£ÄáÑÇÖݰ䲼µÄÊý¾Ýй¶֪ͨ £¬£¬£¬£¬ £¬£¬ÃÀ¹ú´ó³ÇÊÐÈËÊÙ±£ÏÕ¹«Ë¾£¨MetLife£©ÓÚ10ÔÂ18ÈÕÒâ±íй¶Á˲¿Ãſͻ§µÄÓ×ÎÒÐÅÏ¢ £¬£¬£¬£¬ £¬£¬ÕâЩÐÅÏ¢ÒÔ¸½¼þµÄ´ó¾Ö±»·¢Ë͸øÓëMetLifeºÏ×÷µÄBenefits Administrator£¨¸£ÀûÖÎÀíÔ±£© £¬£¬£¬£¬ £¬£¬²¢Ëæºó±»É¾³ý¡£¡£¡£¡£¡£¡£¡£¡£ÓйØÊý¾ÝÔ̺¬¿Í»§µÄÉç±£ºÅÂë¡¢±£ÏÕÁìÓò¡¢µ®ÉúÈÕÆÚ¡¢ÐÔ±ðºÍµØÖ·µÈ¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÒÔΪ¿Í»§µÄPII²¢Ã»ÓÐÊܵ½ÇÖº¦ £¬£¬£¬£¬ £¬£¬µ«MetLifeÒÀÈ»¾ö¶¨ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩһÄêµÄÐÅÓþ¼à¿Ø·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/data-leak-incident-reported-by-fortune-500-metropolitan-life-insurance-company-523865.shtml


4¡¢OSIsoft LLCÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬ £¬£¬ËùÓÐÓòÕÊ»§µÄµÇ¼ʹ´¦¶¼±»ÇÔÈ¡

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


11ÔÂ16ÈÕOSIsoft LLCÏò¼ÓÖÝÖݼì²ì³¤°ì¹«ÊҰ䲼֪ͨ³Æ¸Ã¹«Ë¾Ôâµ½ºÚ¿ÍÈëÇÖ £¬£¬£¬£¬ £¬£¬Ô̺¬¹«Ë¾Ô±¹¤¡¢ÕÕ·÷¡¢ÊµÏ°ÉúºÍµÚÈý·½³Ð°üÉ̵ÄÊý¾ÝÒÉй¶¡£¡£¡£¡£¡£¡£¡£¡£OSIsoftÊÇʵʱÊý¾ÝÖÎÀíÈí¼þPI SystemµÄ¿ª·¢ÉÌ £¬£¬£¬£¬ £¬£¬¸ÃÈí¼þ±»³¬¹ý65%µÄ²Æ¸»500Ç¿¹¤Òµ¹«Ë¾ËùʹÓᣡ£¡£¡£¡£¡£¡£¡£OSIsoft°µÊ¾·¢ÏÖÁËÉæ¼°29Ì¨ÍÆËã»úºÍ135¸öÕË»§µÄÍ´´¦ÍµÇԻµÄÖ±½ÓÖ¤¾Ý £¬£¬£¬£¬ £¬£¬½ø¶øµÃ³ö½áÂÛËùÓеÄOSIÓòÕË»§¶¼Òѱ»Í»ÆÆ¡£¡£¡£¡£¡£¡£¡£¡£¼øÓÚ¸ÃÊý¾Ýй¶ÊÂÎñµÄÑϳÁÐÔ £¬£¬£¬£¬ £¬£¬OSIsoftÔÚ¶à¸ö°²È«·þÎñÉ̵ÄÔ®ÊÖϽøÐе÷²é¡£¡£¡£¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/osisoft-breached-all-domain-accounts-emails-and-passwords-assumed-compromised-523863.shtml


5¡¢TalkTalkÈëÇÖÊÂÎñÖеÄÁ½ÃûºÚ¿Í±»ÅÐÈëÓü £¬£¬£¬£¬ £¬£¬ÔøÔì³É7700ÍòÓ¢°÷µÄËðʧ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¾ÝÓ¢¹úÖðÈÕÓʱ¨±¨Â· £¬£¬£¬£¬ £¬£¬Á½ÃûºÚ¿ÍÒò2015ÄêµÄTalkTalkÈëÇÖÊÂÎñ±»ÅÐÈëÓü¡£¡£¡£¡£¡£¡£¡£¡£TalkTalkÊÇÓ¢¹ú×î´óµÄµçÐŹ«Ë¾Ö®Ò» £¬£¬£¬£¬ £¬£¬ÕâÁ½ÃûºÚ¿Í¹²ÇÔÈ¡Á˳¬¹ý15.6ÍòÃû¿Í»§µÄÓ×ÎÒÐÅÏ¢¡¢²ÆÕþÐÅÏ¢¼°ÐÅÓþ¿¨ÐÅÏ¢ £¬£¬£¬£¬ £¬£¬Ôì³ÉµÄËðʧ´ï7700ÍòÓ¢°÷¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÄê23ËêµÄMatthew HanleyºÍ21ËêµÄConnor AllsoppÈÏ¿ÉÁËÓйØÖ¸¿Ø £¬£¬£¬£¬ £¬£¬²¢±ðÀë±»Åд¦12¸öÔºÍ8¸öÔµÄÓÐÆÚͽÐÌ¡£¡£¡£¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/11/talktalk-data-breach.html


6¡¢Adobe°ä²¼Flash Player´¹Î£°²È«¸üР£¬£¬£¬£¬ £¬£¬½¨¸´Ò»¸öËÁÒâ´úÂëÖ´Ðзì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


±¾ÖܶþAdobeÕë¶ÔFlash Player¸ßΣ·ì϶£¨CVE-2018-15981£©°ä²¼´¹Î£°²È«¸üС£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÒ»¸öÀàÐÍ»ìºÏÃýÎó £¬£¬£¬£¬ £¬£¬¿Éµ¼Ö¹¥»÷ÕßÔÚÓû§²»ÖªÇéµÄÇé¿öÏÂÖ´ÐÐËÁÒâ¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁËWindows¡¢macOS¡¢LinuxºÍChrome OSµÈƽ̨ÉϵÄFlash Player 31.0.0.148¼°¸üÔçµÄ°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ°æ±¾31.0.0.153¡£¡£¡£¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://threatpost.com/critical-adobe-flash-bug-impacts-windows-macos-linux-and-chrome-os/139264/


ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù