¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180917
°ä²¼¹¦·ò 2018-09-17
΢Èí°ä²¼¹ØÓڿɵ¼ÖÂDoSµÄ°²È«·ì϶FragmentSmackµÄ°²È«²¼¸æ£¬¸Ã·ì϶£¨CVE-2018-5391£©ÊÇÒ»ÖÖIPË鯬¹¥»÷£¨Teardrop¹¥»÷£©£¬¿Éµ¼ÖÂÍÆËã»úµÄCPU´ïµ½×î´óÀûÓÃÂʲ¢ÇÒ²Ù×÷ϵͳÎÞÏìÓ¦¡£¸Ã·ì϶ӰÏìÁËWindows 7¡¢8ºÍ10ÒÔ¼°Server 2008¡¢2012ºÍ2016ϵͳ¡£½¨ÒéÓû§¾¡¿ì×°ÖÃÏàÓ¦µÄ¸üС£
https://www.bleepingcomputer.com/news/security/windows-systems-vulnerable-to-fragmentsmack-90s-like-dos-bug/
2¡¢×êÑÐÈËÔ±·¢ÏÖmacOS°²È«Èí¼þWebroot SecureAnywhere´æÔÚÄں˼¶·ì϶
TrustwaveµÄ×êÑÐÈËÔ±·¢ÏÖmacOS°²È«Èí¼þWebroot SecureAnywhereÖдæÔÚÒ»¸ö¿É±»±¾µØÀûÓõÄÄں˼¶·ì϶¡£¸Ã·ì϶£¨CVE-2018-16962£©ÊÇÓɶÌȱ¶ÔÓû§Ö¸ÕëµÄÑéÖ¤¶øµ¼Öµģ¬ÔÚijЩÇé¿öÏ£¬¸Ã·ì϶¿ÉÄÜÓëÆäËü·ì϶½áºÏÒÔ½øÐб¾µØÌáȨ£¬µ¼ÖÂÒÔÄں˼¶È¨ÏÞÖ´ÐжñÒâÈí¼þ¡£Webroot SecureAnywhere°æ±¾9.0.8.34Öн¨¸´Á˸ÃÎÊÌâ¡£
https://securityaffairs.co/wordpress/76220/hacking/webroot-secureanywhere-flaw.html
3¡¢×êÑÐÈËÔ±ÑÝʾͨ¹ýCSSºÍHTMLÍøÒ³µ¼ÖÂiPhone³ÁÆôºÍMac¿¨ËÀµÄй¥»÷²½Öè
Wire°²È«×êÑÐÈËÔ±Sabri HaddoucheÉè¼Æ³öÒ»ÖÖͨ¹ýCSS&HTMLÍøÒ³¼±¾çºÄ¾¡Æ»¹ûÉ豸×ÊÔ´µÄ¹¥»÷²½Öè¡£¸Ã¹¥»÷¿É¼±¾ç¿÷ËðËùÓеÄͼÐÎ×ÊÔ´²¢µ¼Ö²Ù×÷ϵͳ±ÀÀ£»ò¿¨ËÀ£¬ËùÓÐʹÓÃWebKitäÖȾÒýÇæµÄiOSä¯ÀÀÆ÷ÒÔ¼°macOSÖеÄSafariºÍMail¶¼Êܵ½Ó°Ïì¡£¶ÔÓÚiOS£¬¸Ã¹¥»÷½«µ¼ÖÂÄں˱ÀÀ£²¢³ÁÆô£»¶ÔÓÚmacOS£¬¸Ã¹¥»÷½«µ¼ÖÂSafari»á»°³ÁÆô¼°É豸¿¨ËÀ¡£Ä¿Ç°»¹Ã»Óз¨×Ó·À»¤´ËÀ๥»÷¡£
https://www.bleepingcomputer.com/news/security/new-css-attack-restarts-an-iphone-or-freezes-a-mac/
4¡¢×êÑÐÍŶӷ¢ÏÖ¼Ù×°³ÉÓ¢¹ú˰Îñ¾ÖHMRCµÄ´¹µöÓʼþ¹¥»÷
Malwarebytes Labs×êÑÐÍŶӷ¢ÏÖ¼Ù×°³ÉÓ¢¹ú˰Îñ¾ÖHMRCµÄÍøÂç´¹µö»î¶¯¡£¸Ã´¹µöÓʼþµÄÖ÷ÌâÊÇ542.94Ó¢°÷µÄÍË˰£¬ÓʼþÕýÎÄÖÐÔ̺¬ÓÃÓÚÍË˰µÄÍøÕ¾Á´½Ó¡£¸Ã´¹µöÍøÕ¾µÄµÚÒ»¸öÈë¿ÚµãÊÇÐéαµÄOutlookµÇÂ¼Ò³Ãæ£¬ÆäÍøÖ·ÊÇonlinehmrevnue(.)from-tx(.)com/webGBTxid/checkValidation(.)php£¬Ò»µ©Óû§ÊäÈëÓйØÍ´´¦£¬¾Í»áÌø×ªµ½Ò»¸öÓÃÓÚÍøÂçÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂëµÈÐÅÏ¢µÄÍøÒ³¡£
https://blog.malwarebytes.com/cybercrime/2018/09/hmrc-phish-swipes-email-login-payment-details/
5¡¢°²È«×êÑÐÈËÔ±·¢ÏÖÀÕË÷Èí¼þDharmaµÄбäÌåBrrr
×êÑÐÈËÔ±Jakub Kroustek·¢ÏÖÀÕË÷Èí¼þDharma¼Ò×åµÄÒ»¸öбäÌ壬¸Ã±äÌåÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.brrrÀ©´óÃû¡£Dharmaͨ¹ýRDPÏνӰ춯½øÐзַ¢£¬¹¥»÷Õßͨ¹ýɨÃèÊ¢¿ªµÄTCP3389¶Ë¿Ú£¬¶ÔÆä½øÐб©Á¦ÆÆ½âÒÔ»ñµÃµÇ¼ʹ´¦¡£¹¥»÷ÕßÒ²¿ÉÄÜ´ÓµØÏÂÂÛ̳²É°ì¿É½Ó¼ûµÄRDPµÇ¼ʹ´¦¡£Brrr»áÔÚ¼ÓÃܵÄÎļþºóÔö³¤.id-[id].[email].brrrÀ©´óÃû¡£Ä¿Ç°»¹Ã»Óз¨×ÓÃâ·Ñ½âÃܸñäÌå¼ÓÃܵÄÎļþ¡£
https://www.bleepingcomputer.com/news/security/new-brrr-dharma-ransomware-variant-released/
6¡¢Ó¢¹ú²¼Àï˹Íжû»ú³¡Ôâµ½ºÚ¿Í¹¥»÷£¬º½°àÐÅÏ¢ÏÔʾÆÁÒÑÖÕ³¡·þÎñÁ½Ìì
Ó¢¹ú²¼Àï˹Íжû»ú³¡Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Æäº½°àÐÅÏ¢ÏÔʾÆÁÒÑÖÕ³¡·þÎñÁ½Ìì¡£¸Ã»ú³¡µÄ½²»°È˰µÊ¾º½°à²»ÊÜÓ°Ï죬µ«±ØÐëʹÓÃÓ¦¼±´ëÊ©ºÍÊÖ¶¯µÄÁ÷³Ì£¬Ô̺¬°×°åºÍ¼ÇºÅ±ÊµÈÀ´°ü°ìÏÔʾÆÁ¡£¸Ã»ú³¡Ã»ÓÐÏò¹¥»÷ÕßÖ§¸¶Êê½ð¡£Õâ²»ÊÇÒ»´ÎÕë¶ÔÐԵĹ¥»÷£¬¶øÊÇËæ»úµÄ¹¥»÷¡£¸Ã»ú³¡ÔÚÈ·±£Æäº½°àÐÅϢϵͳÔÚ³ÁÐÂÉÏÏß֮ǰÊǰ²È«µÄ¡£
https://securityaffairs.co/wordpress/76248/breaking-news/bristol-airport-cyber-attack.html
ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ