¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180809

°ä²¼¹¦·ò 2018-08-09

¡¾·ÖÎö»ã±¨¡¿NETSCOUT°ä²¼2018ÉϰëÄêÈ«ÇòÍþвµý±¨»ã±¨


NETSCOUT°ä²¼2018ÉϰëÄêÈ«ÇòÍþвµý±¨»ã±¨£¬»ã±¨µÄÖØÒª·¢ÏÖÔ̺¬£º1¡¢DDoS¹¥»÷½øÈëTB¼¶Ê±ÆÚ£»2¡¢¹¥»÷µÄ¹æÄ£¸ü´ó£¬µ«ÆµÂʽµÂ䣻3¡¢APT×éÖ¯³¬¹ýÁË´«Í³µÄÎę̀£»4¡¢·¸×ï·Ö×Óѡȡ¶àÑù»¯µÄ¹¥»÷²½Ö裻5¡¢²¿ÃŹú¶È³ÉΪDDoS¹¥»÷µÄ³ÁÔÖÇø£»6¡¢Õë¶Ô¸ü¶à´¹Ö±ÐÐÒµ£»7¡¢ÐµÄDDoS¹¥»÷ÏòÁ¿±»Ñ¸¿ìÀûÓã»8¡¢¾ÉµÄ¹¥»÷ÏòÁ¿»À·¢µÚ¶þ´º£»9¡¢ÓÐÕë¶ÔÐÔµÄAPT¹¥»÷ÒýÈ뻥ÁªÍø¼¶´ËÍâÀ©É¢¡£´Ë±í£¬»ã±¨»¹º­¸ÇÁËеķ¸×ïÈí¼þƽ̨ºÍÖ¸±ê¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.netscout.com/sites/default/files/2018-08/NETSCOUT_ThreatReport_FINAL_080618b.pdf


¡¾·ÖÎö»ã±¨¡¿×êÑÐÍŶӰ䲼2018ÄêÏļ¾·ì϶ÀûÓù¤¾ß°üµÄ·ÖÎö»ã±¨


Malwarebytes Labs×êÑÐÍŶӰ䲼2018ÄêÏļ¾·ì϶ÀûÓù¤¾ß°üµÄ·ÖÎö»ã±¨¡£ÔÚ´º¼¾EK¹¥»÷»î¶¯µÄÉÏÉýÇ÷ÏòÒ»Á¬µ½ÁËÏᄀ£³ýÁËRIGºÍGrandSoft EKÖ®±í£¬ÎÒÃǹ۲쵽µÄ´ó²¿ÃÅEKµÄ¹¥»÷»î¶¯¶¼ÔÚÑÇÖÞ£¬Õâ¿ÉÄÜÊÇÓÉÓڸõØÓò¸üÈÝÒ×Óöµ½Ò×Êܹ¥»÷µÄϵͳ¡£´Ë±í£¬ÎÒÃÇ»¹·¢ÏÖÁ˺ܶàÓ×¹æÄ£ÇÒ²»³ÉÊìµÄ¹¥»÷ÕßʹÓÃÒ»Á½¸ö·ì϶ÀûÓÃÖ±½ÓǶÈëÊÜϰȾµÄÍøÕ¾ÖеÄÐÐΪ£¬Õâͨ³£ÊÇÒ»¸öµ¥¶ÀµÄ×÷ÕßµÄÐÐΪ¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.malwarebytes.com/threat-analysis/2018/08/exploit-kits-summer-2018-review/


¡¾°²È«²¥±¨¡¿OWASP°ä²¼°²È«Ò½ÁÆÆ÷е²¿Êð³ß¶ÈV2£¬Ö¼ÔÚÌáÉýÒ½ÁÆÉ豸µÄ°²È«ÐÔ


×÷Ϊ²»ÐÝ·¢Õ¹µÄÎïÁªÍøµÄÒ»¸ö¹Ø¼ü×Ó¼¯£¬Ò½ÁÆÉ豸ԽÀ´Ô½ÈÝÒ×Êܵ½½©Ê¬ÍøÂçºÍ¶ñÒâÈí¼þµÄ¹¥»÷¡£ÎªÁËÓ¦¶ÔÕâÖÖÈÕÒæÔö³¤µÄ°²È«ÐÔÐèÒª£¬CSAºÍOWASP½áºÏ°ä²¼ÁËOWASP°²È«Ò½ÁÆÆ÷е²¿Êð³ß¶ÈV2¡£¸Ã³ß¶ÈÔÚ³ö¸ñÊDzɹº½ÚÔì·½Ãæ½øÐÐÁ˼ÓÇ¿£¬²¢¶Ô°²È«Éó¼ÆºÍÆÀ¹ÀÒÔ¼°ÒþÖÔÓ°ÏìÆÀ¹À½øÐÐÁ˸üС£¸Ã³ß¶ÈµÄÖ÷ÕÅÊÇÈ·±£Ò½ÁÆ»ú¹¹×ñÑ­Ò½ÁÆÆ÷еºÍITϵͳµÄ×î¼Ñ°²È«Êµ¼Ê¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/improved-standards-for-securing/


¡¾°²È«²¥±¨¡¿SnapchatÔ´ÂëÔÚGitHubÉÏÆØ¹â£¬¹«Ë¾»úÃÜ¿ÉÄܱíй


Ê¢ÐеÄÉ罻ýÌåÀûÓÃSnapchatµÄÔ´´úÂë±»Ò»ÃûºÚ¿Í°ä²¼ÔÚGitHubÉÏ¡£¸ÃGitHubÕË»§ÎªKhaled Alshehri£¬ÊÇÒ»Ãû°Í»ù˹̹Óû§£¬ÆäÔÚSource-Snapchat´æ´¢¿âÖа䲼ÁËÌý˵ÊÇSnapchatµÄiOSÀûÓõĴúÂë¡£µ×²ã´úÂë¿ÉÄÜ»áй¶¹«Ë¾µÄ»úÃÜÐÅÏ¢£¬ÀýÈçappµÄÕûÌåÉè¼Æ¡¢¹¤×÷·½Ê½ÒÔ¼°¹æ»®µÄ½«À´Ö°ÄܵÈ¡£SnapchatµÄĸ¹«Ë¾Snap Inc.ƾ¾ÝDMCA·¨ÒªÇóɾ³ýÁ˸ô洢¿â¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/snapchat-hack-source-code.html


¡¾·ì϶²¹¶¡¡¿×êÑÐÈËÔ±·¢ÏÖOpenEMR´æÔÚ¶à¸ö°²È«·ì϶£¬¿Éµ¼Ö»¼ÕßµÄÒ½ÁÆÊý¾Ýй¶


×êÑÐÈËÔ±ÔÚOpenEMRÈí¼þÖз¢ÏÖÁ˽ü¶þÊ®¶þ¸ö°²È«·ì϶£¬ÆäÖÐÔ̺¬¿ÉÔÊÐíδ¾­ÊÚȨ½Ó¼ûÒ½ÁƼͼµÄÑϳÁ·ì϶¡£OpenEMRÊÇÒ»¸ö¼«¶ÈÊÜÓ­½ÓµÄÓÃÓÚÒ½ÁÆÐÅÏ¢ºÍÒ©Îï¼Í¼µÄ¿ªÔ´ÖÎÀíÈí¼þ£¬¿ÉÔÚ¶àÖÖ²Ù×÷ϵͳ£¨Ô̺¬Windows¡¢LinuxºÍmacOS£©ÉÏÔËÐС£¾Ý¹À¼Æ£¬È«ÇòÔ¼ÓÐ1.5Íò¸ö·ÖÆç¹æÄ£µÄÒ½ÁÆ»ú¹¹ÔÚʹÓÃOpenEMR¡£·ì϶µÄÁìÓòÔ̺¬Éí·ÝÑéÖ¤ÈÆ¹ý¡¢SQL×¢Èë¡¢ÐÅϢй¶¡¢ÎļþÉÏ´«¡¢CSRFºÍRCEµÈ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.helpnetsecurity.com/2018/08/08/openemr-vulnerabilities/


¡¾°²È«·ì϶¡¿×êÑÐÈËÔ±³ÆWhatsApp´æÔÚ¶à¸ö°²È«·ì϶£¬¿ÉÀ¹½ØºÍÅú¸ÄÓû§µÄÐÂÎÅÄÚÈÝ


Check PointµÄ°²È«×êÑÐÈËÔ±·¢ÏÖWhatsApp´æÔÚ¶à¸ö°²È«·ì϶£¬¿ÉÔÊÐí¶ñÒâÓû§À¹½ØºÍÅú¸Ä¸öÈË»òȺ×éµÄ̸ÌìÄÚÈÝ¡£×êÑÐÈËÔ±³ÆÕâЩ·ì϶ÀûÓÃÁËWhatsApp°²È«ºÍ̸Öеķì϶£¬¿ÉÔÊÐí¶ñÒâÓû§´´½¨ºÍ´«²¼¿´ÆðÀ´ÊÇÀ´×Ô¿ÉÐÅÆðÔ´µÄÃýÎóÐÂÎÅ»òÐéαÐÂÎÅ¡£×êÑÐÈËԱͨ¹ýÊÓÆµÑÝʾÁËÆä¹¥»÷¹ý³Ì¡£µ«WhatsAppÍŶÓÒÔΪÕâÊÇÒ»ÖÖÉè¼ÆÉϵĺâÁ¿£¬²¢²»³ïËã×ö³öÈκν¨¸´¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/whatsapp-modify-chat-fake-news.html