¡¾·ÖÎö»ã±¨¡¿×êÑлú¹¹°ä²¼2018ÄêÖа²È«×ÛÊö£¬¶ñÒâÍÚ¿ó¹¥»÷ͬ±ÈÔö³¤956£¥
Ç÷Ïò¿Æ¼¼°ä²¼2018ÄêÖа²È«×ÛÊö»ã±¨£¬»ã±¨Ö¸³öÓë2017ÄêÕûÄêÏà±È£¬2018ÄêÉϰëÄê¶ñÒâÍÚ¿ó¹¥»÷µÄ¼ì²âÊýÁ¿Ôö³¤ÁË96%£»¶øÓë2017ÄêÉϰëÄêÏà±È£¬ÔòÔö³¤ÁË956%£¨½ü10±¶£©¡£»ã±¨»¹Ö¸³ö£¬Ç÷Ïò¿Æ¼¼ÔÚ2018ÄêÉϰëÄê×èÖ¹ÁË200¶àÒÚ´ÎÍþв£¬¹¥»÷Õߵķ¸×ïÕ½ÊõÒѾ²úÉúÁ˱䶯£¬´Ó²¿Êð¼±¾çÖ§¸¶µÄÀÕË÷Èí¼þתÏòÇÔÈ¡Óû§µÄ×ʽðºÍÍÆËã»úËãÁ¦µÈÒþÄäµÄ¼¿Á©¡£
ÔÎÄÁ´½Ó£ºhttps://www.trendmicro.com/vinfo/us/security/research-and-analysis/threat-reports/roundup/unseen-threats-imminent-losses
¡¾¹¥»÷ÊÂÎñ¡¿Î÷°àÑÀÒøÐйÙÍøÔâµ½DDoS¹¥»÷£¬ÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û
ƾ¾Ý·͸ÉçµÄ±¨Â·£¬´Ó8ÔÂ26ÈÕÐÇÆÚÈÕÆðÍ·Î÷°àÑÀÒøÐеĹÙÍøÔâµ½ÁËÉ¢²¼Ê½»Ø¾ø·þÎñ¹¥»÷£¨DDoS£©£¬ÆäÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û¡£¸ÃÒøÐеĽ²»°È˰µÊ¾£¬Õâ´Î¹¥»÷¶Ô¸ÃÒøÐеķþÎñ»ò¸ÃÒøÐÐÓëÅ·ÖÞÖÐÑëÒøÐлòÆäËü»ú¹¹µÄͨѼû»ÓÐÔì³ÉÈκÎÓ°Ï죬²¢ÇÒûÓÐÈκÎÊý¾Ýй¶µÄ·çÏÕ¡£½ØÖÁÖܶþÏÂÎ磬¸ÃÒøÐеÄÍøÕ¾ÈÔ´¦ÓÚÀëÏß״̬¡£
ÔÎÄÁ´½Ó£ºhttps://uk.reuters.com/article/us-spain-cyber-cenbank/bank-of-spains-website-hit-by-cyber-attack-idUKKCN1LC23B
¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±·¢ÏÖÓÃÓÚ·Ö·¢DarkComet RATµÄÀ¬»øÓʼþ»î¶¯
°²È«×êÑÐÔ±Vishal Thakur·¢ÏÖÒ»¸öÓÃÓÚ·Ö·¢DarkComet RATµÄÀ¬»øÓʼþ»î¶¯¡£¸ÃÀ¬»øÓʼþÖÐÔ̺¬Ãû³ÆÎªDOC000YUT600.pdf.zµÄ¸½¼þ£¬Æä»á½«DarkComet RAT×°Öõ½Óû§µÄÍÆËã»úÉÏ¡£DarkCometÄܹ»¼Í¼Óû§µÄÀûÓ÷¨Ê½Ê¹ÓÃÇé¿öºÍ¼üÅÌÇû÷¼Í¼£¬²¢½«ÕâЩÊý¾Ý±£ÁôÔÚ£¥UserProfile£¥\AppData\Roaming\dclogs\Îļþ¼ÐϵÄÈÕÖ¾ÎļþÖС£ÕâЩÎļþ»áÒÔ·ÖÆçµÄ¾àÀëÉÏ´«ÖÁ¹¥»÷Õß¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/beware-of-fake-shipping-docs-malspam-pushing-the-darkcomet-rat/
¡¾¶ñÒâÈí¼þ¡¿×êÑÐÍŶӰ䲼¹ØÓÚAndroid¼äµýÈí¼þBusyGasperµÄ·ÖÎö»ã±¨
¿¨°Í˹»ù³¢ÊÔÊÒÔÚ2018ËêÊ×¼ì²âµ½Ò»¸öеÄAndroid¼äµýÈí¼þBusyGasper¡£BusyGasperµÄ¸´ÔÓÐÔ²»¸ß£¬µ«ÓµÓÐÒ»Ð©ÌØÊâµÄÖ°ÄÜ£¬ÀýÈç¼àÌýÉ豸µÄ´«¸ÐÆ÷£¨»î¶¯´«¸ÐÆ÷µÈ£©¡£ÆäºÍ̸ӵÓÐÔ¼100¸öºÅÁ»¹Äܹ»Èƹý½ÚµçÓÅ»¯Ö°ÄÜDoze¡£BusyGasperÄܹ»ÇÔÈ¡ÐÂÎÅÀûÓã¨ÈçWhatsApp¡¢ViberºÍFacebook£©µÄÊý¾Ý£¬²¢ÓµÓмüÅ̼ͼְÄÜ¡£BusyGasperͨ¹ýÊÖ¶¯×°Öã¬ÖØÒªÕë¶Ô¶íÂÞ˹£¬ÆäC&C·þÎñÆ÷µÄIPÊôÓÚ¶íÂÞ˹µÄÒ»¸öÃâ·ÑµÄÍøÂçÍйܷþÎñUcoz¡£
ÔÎÄÁ´½Ó£ºhttps://securelist.com/busygasper-the-unfriendly-spy/87627/
¡¾·ì϶²¹¶¡¡¿PHPÈí¼þ°ü¿âPackagistµÄ¹ÙÍø½¨¸´Ò»¸ö¿É±»½Ù³ÖµÄ°²È«·ì϶
PackagistÍŶÓÔÚÆä¹Ù·½ÍøÕ¾ÉϽ¨¸´ÁËÒ»¸ö¿Éµ¼ÖÂÆä·þÎñ±»½Ù³ÖµÄ°²È«·ì϶¡£PackagistÊÇPHP×î´óµÄÈí¼þ°ü´æ´¢¿â£¬ÆäÿÔµÄ×°ÖðüÏÂÔØ´ÎÊý³¬¹ý4ÒڴΡ£°²È«×êÑÐÔ±Max Justicz·¢ÏÖ²¢»ã±¨ÁËÕâ¸ö·ì϶£¬Æ¾¾ÝJusticzµÄ˵·¨£¬PackagistÖ÷Ò³ÉÏÌá½»ÐÂPHP°üµÄ°´Å¥µÄÊäÈë×Ö¶ÎÔÊÐí¹¥»÷ÕßÒÔ$(MALICIOUS_COMMANDS)µÄÌåʽÔËÐжñÒâºÅÁî¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/critical-flaw-fixed-in-packagist-phps-largest-package-repository/
¡¾·ì϶²¹¶¡¡¿°²È«×êÑÐÈËÔ±·¢ÏÖOpenSSH´æÔÚÁíÒ»¸öÓû§Ãûö¾Ù·ì϶
QualysµÄ°²È«×êÑÐÈËÔ±ÔÚ×îа汾µÄOpenSSHÖз¢ÏÖÁËÒ»¸öеÄÓû§Ãûö¾Ù·ì϶£¨CVE-2018-15919£©¡£¸Ã·ì϶ӰÏìÁË2011Äê9ÔÂÖ®ºóµÄËùÓÐOpenSSH°æ±¾¡£¸Ã·ì϶Óë×êÑÐÈËÔ±ÉÏÖÜ·¢Ïֵķì϶£¨CVE-2018-15473£©ÀàËÆ£¬¶¼ÔÊÐí¹¥»÷Õ߲²â·þÎñÆ÷ÉϵÄÓÐЧÓû§Ãû¡£OpenSSHµÄ¿ª·¢ÈËÔ±³Æ¸Ã·ì϶µÄÑϳÁÐԽϵͣ¬Òò¶ø²¢²»»áÓÅÏȽ¨¸´¸Ã·ì϶¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/openssh-versions-since-2011-vulnerable-to-oracle-attack/