¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180919

°ä²¼¹¦·ò 2018-09-19

¡¾·ÖÎö»ã±¨¡¿¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼¹ØÓÚÎïÁªÍøÍþвÇ÷ÏòµÄ·ÖÎö»ã±¨


ƾ¾Ý±¾Öܶþ¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼µÄÎïÁªÍøÍþв»ã±¨ £¬2018ÄêÉϰëÄ꿨°Í˹»ùÍøÂçµ½µÄIoT¶ñÒâÈí¼þÑù±¾µÄÊýÁ¿ÊÇ2017ÄêÕûÄêµÄÈý±¶ £¬¶ø2017ÄêµÄÊý×ÖÔòÊÇ2016ÄêµÄ10±¶¡£Ò×Êܹ¥»÷µÄIoTÉ豸Ô̺¬MikroTik·ÓÉÆ÷ÒÔ¼°TP-Link¡¢SonicWall¡¢CiscoºÍD-LinkµÄÉ豸µÈ¡£×îÊÜÓ­½ÓµÄ¹¥»÷ÏòÁ¿ÊÇTelnet¹¥»÷ £¬Õ¼È«Êý¹¥»÷µÄ75.40%¡£ÔÚÉæ¼°µ½IoT¹¥»÷ʱ £¬Mirai¼Ò×åÊÇ·¸×ï·Ö×ÓµÄÊ×Ñ¡¶ñÒâÈí¼þ £¬ÆäÕ¼¾ÝÁËËùÓй¥»÷µÄ15.97%¡£


https://securelist.com/new-trends-in-the-world-of-iot-threats/87991/


¡¾·ÖÎö»ã±¨¡¿RiskIQ°ä²¼2018ÄêµÚ¶þ¼¾¶ÈµÄÒÆ¶¯ÍþÐ²Ì¬ÊÆ»ã±¨


RiskIQ×êÑÐÍŶӰ䲼2018ÄêµÚ¶þ¼¾¶ÈµÄÒÆ¶¯ÍþÐ²Ì¬ÊÆ»ã±¨ £¬ºÚÃûµ¥ÀûÓü±¾çÔö³¤¡£×ÜÌå¶øÑÔ £¬RiskIQÔÚµÚ¶þ¼¾¶È¹²¹Û²ìµ½52885¸öºÚÃûµ¥ÀûÓà £¬Õ¼ËùÓÐÀûÓõÄ4% £¬±ÈµÚÒ»¼¾¶ÈÔö³¤ÁË2%¡£Ä¾ÂíºÍ¸æ°×Èí¼þÊÇ×î³£¼ûµÄÍþв¡£Google PlayÖеĺÚÃûµ¥ÀûÓÃ×î¶à £¬´ï28533¸ö £¬±ÈµÚÒ»¼¾¶ÈÔö³¤ÁËÔ¼20000¸ö¡£×êÑÐÍŶӻ¹ÔÚÀûÓÃÉ̵êÖ®±í¹Û²ìµ½11288¸öºÚÃûµ¥ÀûÓá£


https://www.riskiq.com/blog/external-threat-management/q2-2018-mobile-threat-landscape-report/


¡¾Êý¾Ýй¶¡¿MongoDBÅäÖÃÃýÎóµ¼ÖÂÔ¼1100Íòµç×ÓÓʼþ¼Í¼¿É¹«¿ª½Ó¼û


°²È«×êÑÐÈËÔ±Bob DiachenkoÔÚ»¥ÁªÍøÉÏ·¢ÏÖÒ»¸ö¿É¹«¿ª½Ó¼ûµÄMongoDB £¬¸ÃÊý¾Ý¿âÖÐÔ̺¬Ô¼1100ÍòÌõµç×ÓÓʼþ¼Í¼¡£Êý¾Ý¿âµÄ´óÓ×Ϊ43.5GB £¬Ô̺¬ÁËÓû§µÄÑÅ»¢µç×ÓÓÊÏä¼Í¼ÒÔ¼°ÐÕÃû¡¢ÎïÀíµØÖ·¡¢ÓÊÕþ±àÂëºÍ¾Óס³ÇÊеÈÓ×ÎÒÐÅÏ¢¡£¸ÃÊý¾Ý¿âÍйÜÔÚÃÀ¹úGrupo-SMSµÄ»ù´¡ÉèÊ©ÉÏ £¬Ä¿Ç°»¹²»ÖªÂ·¸ÃÊý¾Ý¿âµÄËùÓÐÕßµÄÉí·Ý¡£


https://www.bleepingcomputer.com/news/security/database-with-11-million-email-records-exposed/


¡¾Êý¾Ýй¶¡¿GovPayNet¹ÙÍø´æÔÚ·ì϶ £¬³¬¹ý1400ÍòÓû§¼Í¼ÒÉй¶


ΪÃÀ¹úÖݵ±¾ÖºÍ´¦Ëùµ±¾ÖÌṩÔÚÏßÖ§¸¶Æ½Ì¨µÄGovPayNow.com´æÔÚ°²È«·ì϶ £¬³¬¹ý1400ÍòÓû§µÄÓ×ÎÒÐÅÏ¢ÒÉй¶¡£¸ÃÍøÕ¾Îª36¸öÖݵÄ2000¶à¸öµ±¾Ö»ú¹¹Ìṩ·þÎñ £¬¹«ÃñÄܹ»Í¨¹ýËüÀ´Ö§¸¶·£¿î¡¢ÅÉ˾·ÑºÍÕ˵¥µÈ¡£Æ¾¾ÝBrian KrebsµÄ˵·¨ £¬¸ÃÍøÕ¾µÄÔÚÏßÖ§¸¶ÊÕÌõÊǰ´°¤´Î±àºÅµÄ £¬¹¥»÷ÕßÄܹ»Í¨¹ýÅú¸ÄURLÖеÄÊý×ÖÀ´²é¿´ÆäËüÈ˵ļͼ¡£ÕâЩ¼Í¼Ô̺¬Óû§µÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¼°ÒøÐп¨ºóËÄλÊý×ֵȡ£¸Ã¹«Ë¾°µÊ¾ÒÑÔÚÖÜÄ©½¨¸´ÁËÕâÒ»ÎÊÌâ¡£


https://www.infosecurity-magazine.com/news/government-payment-service-exposes/


¡¾·ì϶²¹¶¡¡¿Apple°ä²¼Ð°汾iOS12 £¬½¨¸´¶à¿î²úÆ·Öеݲȫ·ì϶


Apple±¾ÖÜÕýʽ°ä²¼iOS 12 £¬²¢½¨¸´ÁËSafari¡¢watchOSºÍtvOSÖеĶà¸ö·ì϶¡£iOS 12Öй²½¨¸´ÁË16¸ö·ì϶ £¬iPhone 5s¼°Ö®ºóµÄ°æ±¾¡¢iPad Air¼°Ö®ºóµÄ°æ±¾ÒÔ¼°iPod touch 6Êܵ½Ó°Ïì¡£½ÏÑϳÁµÄ·ì϶Ô̺¬À¶ÑÀÖеÄÊäÈëÑéÖ¤·ì϶£¨CVE-2018-5383£©ÒÔ¼°SafariÖеÄÐÅϢй¶·ì϶£¨CVE-2018-4313£©µÈ¡£´Ë±í £¬tvOS 12Öн¨¸´ÁË5¸ö°²È«·ì϶ £¬¶øwatchOS 5½¨¸´ÁËÁí±íµÄ4¸ö·ì϶¡£


https://www.bleepingcomputer.com/news/security/ios-12-patches-memory-bugs-safari-12-fixes-data-leaks/


¡¾¶ñÒâÈí¼þ¡¿×êÑÐÍŶӷ¢ÏÖÒÆ¶¯¼äµýÈí¼þPegasus±»ÓÃÓÚÕë¶Ô45¸ö¹ú¶ÈµÄÖ¸±ê


ƾ¾ÝCitizen LabµÄÒ»·Ýл㱨 £¬´ÓǰÁ½ÄêÀ´Òƶ¯¼äµýÈí¼þPegasus±»ÓÃÓÚÕë¶ÔÈ«Çò45¸ö¹ú¶ÈµÄÖ¸±ê¡£PegasusÊÇÒÔÉ«Áй«Ë¾NSO¿ª·¢µÄ¼äµýÈí¼þ £¬Ö¼ÔÚ¼à¿ØiPhoneºÍAndroidÉ豸µÄ»î¶¯ £¬¿ÉÓÃÓÚÍøÂçÓû§µÄ¶ÌÐÅ¡¢ÈÕÀú¡¢µç×ÓÓʼþ¡¢µØÎ»¡¢Âó¿Ë·çºÍÏà»úµÈÐÅÏ¢¡£PegasusÖ»Ïòµ±¾ÖºÍ·¨ÂÉ»ú¹¹ÏúÊÛ¡£¸Ã»ã±¨Ö¸³ö36ÃûÔËÓªÉÌÒ»ÏòÔÚʹÓÃPegasusÔÚ45¸ö¹ú¶ÈÄÚ·¢Õ¹¼à¶½Ðж¯¡£NSO½²»°È˳Ƹù«Ë¾Ã»ÓÐÎ¥·´Èκιú¶ÈµÄ˾·¨¡£


https://thehackernews.com/2018/09/android-ios-hacking-tool.html



¡¾GA»Æ½ð¼×¼¯ÍÅADLabÕû¶Ù°ä²¼¡¿