¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180919
°ä²¼¹¦·ò 2018-09-19¡¾·ÖÎö»ã±¨¡¿¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼¹ØÓÚÎïÁªÍøÍþвÇ÷ÏòµÄ·ÖÎö»ã±¨
ƾ¾Ý±¾Öܶþ¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼µÄÎïÁªÍøÍþв»ã±¨£¬2018ÄêÉϰëÄ꿨°Í˹»ùÍøÂçµ½µÄIoT¶ñÒâÈí¼þÑù±¾µÄÊýÁ¿ÊÇ2017ÄêÕûÄêµÄÈý±¶£¬¶ø2017ÄêµÄÊý×ÖÔòÊÇ2016ÄêµÄ10±¶¡£Ò×Êܹ¥»÷µÄIoTÉ豸Ô̺¬MikroTik·ÓÉÆ÷ÒÔ¼°TP-Link¡¢SonicWall¡¢CiscoºÍD-LinkµÄÉ豸µÈ¡£×îÊÜӽӵĹ¥»÷ÏòÁ¿ÊÇTelnet¹¥»÷£¬Õ¼È«Êý¹¥»÷µÄ75.40%¡£ÔÚÉæ¼°µ½IoT¹¥»÷ʱ£¬Mirai¼Ò×åÊÇ·¸×ï·Ö×ÓµÄÊ×Ñ¡¶ñÒâÈí¼þ£¬ÆäÕ¼¾ÝÁËËùÓй¥»÷µÄ15.97%¡£
https://securelist.com/new-trends-in-the-world-of-iot-threats/87991/
¡¾·ÖÎö»ã±¨¡¿RiskIQ°ä²¼2018ÄêµÚ¶þ¼¾¶ÈµÄÒÆ¶¯ÍþÐ²Ì¬ÊÆ»ã±¨
RiskIQ×êÑÐÍŶӰ䲼2018ÄêµÚ¶þ¼¾¶ÈµÄÒÆ¶¯ÍþÐ²Ì¬ÊÆ»ã±¨£¬ºÚÃûµ¥ÀûÓü±¾çÔö³¤¡£×ÜÌå¶øÑÔ£¬RiskIQÔÚµÚ¶þ¼¾¶È¹²¹Û²ìµ½52885¸öºÚÃûµ¥ÀûÓã¬Õ¼ËùÓÐÀûÓõÄ4%£¬±ÈµÚÒ»¼¾¶ÈÔö³¤ÁË2%¡£Ä¾ÂíºÍ¸æ°×Èí¼þÊÇ×î³£¼ûµÄÍþв¡£Google PlayÖеĺÚÃûµ¥ÀûÓÃ×î¶à£¬´ï28533¸ö£¬±ÈµÚÒ»¼¾¶ÈÔö³¤ÁËÔ¼20000¸ö¡£×êÑÐÍŶӻ¹ÔÚÀûÓÃÉ̵êÖ®±í¹Û²ìµ½11288¸öºÚÃûµ¥ÀûÓá£
https://www.riskiq.com/blog/external-threat-management/q2-2018-mobile-threat-landscape-report/
¡¾Êý¾Ýй¶¡¿MongoDBÅäÖÃÃýÎóµ¼ÖÂÔ¼1100Íòµç×ÓÓʼþ¼Í¼¿É¹«¿ª½Ó¼û
°²È«×êÑÐÈËÔ±Bob DiachenkoÔÚ»¥ÁªÍøÉÏ·¢ÏÖÒ»¸ö¿É¹«¿ª½Ó¼ûµÄMongoDB£¬¸ÃÊý¾Ý¿âÖÐÔ̺¬Ô¼1100ÍòÌõµç×ÓÓʼþ¼Í¼¡£Êý¾Ý¿âµÄ´óÓ×Ϊ43.5GB£¬Ô̺¬ÁËÓû§µÄÑÅ»¢µç×ÓÓÊÏä¼Í¼ÒÔ¼°ÐÕÃû¡¢ÎïÀíµØÖ·¡¢ÓÊÕþ±àÂëºÍ¾Óס³ÇÊеÈÓ×ÎÒÐÅÏ¢¡£¸ÃÊý¾Ý¿âÍйÜÔÚÃÀ¹úGrupo-SMSµÄ»ù´¡ÉèÊ©ÉÏ£¬Ä¿Ç°»¹²»ÖªÂ·¸ÃÊý¾Ý¿âµÄËùÓÐÕßµÄÉí·Ý¡£
https://www.bleepingcomputer.com/news/security/database-with-11-million-email-records-exposed/
¡¾Êý¾Ýй¶¡¿GovPayNet¹ÙÍø´æÔÚ·ì϶£¬³¬¹ý1400ÍòÓû§¼Í¼ÒÉй¶
ΪÃÀ¹úÖݵ±¾ÖºÍ´¦Ëùµ±¾ÖÌṩÔÚÏßÖ§¸¶Æ½Ì¨µÄGovPayNow.com´æÔÚ°²È«·ì϶£¬³¬¹ý1400ÍòÓû§µÄÓ×ÎÒÐÅÏ¢ÒÉй¶¡£¸ÃÍøÕ¾Îª36¸öÖݵÄ2000¶à¸öµ±¾Ö»ú¹¹Ìṩ·þÎñ£¬¹«ÃñÄܹ»Í¨¹ýËüÀ´Ö§¸¶·£¿î¡¢ÅÉ˾·ÑºÍÕ˵¥µÈ¡£Æ¾¾ÝBrian KrebsµÄ˵·¨£¬¸ÃÍøÕ¾µÄÔÚÏßÖ§¸¶ÊÕÌõÊǰ´°¤´Î±àºÅµÄ£¬¹¥»÷ÕßÄܹ»Í¨¹ýÅú¸ÄURLÖеÄÊý×ÖÀ´²é¿´ÆäËüÈ˵ļͼ¡£ÕâЩ¼Í¼Ô̺¬Óû§µÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¼°ÒøÐп¨ºóËÄλÊý×ֵȡ£¸Ã¹«Ë¾°µÊ¾ÒÑÔÚÖÜÄ©½¨¸´ÁËÕâÒ»ÎÊÌâ¡£
https://www.infosecurity-magazine.com/news/government-payment-service-exposes/
¡¾·ì϶²¹¶¡¡¿Apple°ä²¼Ð°汾iOS12£¬½¨¸´¶à¿î²úÆ·Öеݲȫ·ì϶
Apple±¾ÖÜÕýʽ°ä²¼iOS 12£¬²¢½¨¸´ÁËSafari¡¢watchOSºÍtvOSÖеĶà¸ö·ì϶¡£iOS 12Öй²½¨¸´ÁË16¸ö·ì϶£¬iPhone 5s¼°Ö®ºóµÄ°æ±¾¡¢iPad Air¼°Ö®ºóµÄ°æ±¾ÒÔ¼°iPod touch 6Êܵ½Ó°Ïì¡£½ÏÑϳÁµÄ·ì϶Ô̺¬À¶ÑÀÖеÄÊäÈëÑéÖ¤·ì϶£¨CVE-2018-5383£©ÒÔ¼°SafariÖеÄÐÅϢй¶·ì϶£¨CVE-2018-4313£©µÈ¡£´Ë±í£¬tvOS 12Öн¨¸´ÁË5¸ö°²È«·ì϶£¬¶øwatchOS 5½¨¸´ÁËÁí±íµÄ4¸ö·ì϶¡£
https://www.bleepingcomputer.com/news/security/ios-12-patches-memory-bugs-safari-12-fixes-data-leaks/
¡¾¶ñÒâÈí¼þ¡¿×êÑÐÍŶӷ¢ÏÖÒÆ¶¯¼äµýÈí¼þPegasus±»ÓÃÓÚÕë¶Ô45¸ö¹ú¶ÈµÄÖ¸±ê
ƾ¾ÝCitizen LabµÄÒ»·Ýл㱨£¬´ÓǰÁ½ÄêÀ´Òƶ¯¼äµýÈí¼þPegasus±»ÓÃÓÚÕë¶ÔÈ«Çò45¸ö¹ú¶ÈµÄÖ¸±ê¡£PegasusÊÇÒÔÉ«Áй«Ë¾NSO¿ª·¢µÄ¼äµýÈí¼þ£¬Ö¼ÔÚ¼à¿ØiPhoneºÍAndroidÉ豸µÄ»î¶¯£¬¿ÉÓÃÓÚÍøÂçÓû§µÄ¶ÌÐÅ¡¢ÈÕÀú¡¢µç×ÓÓʼþ¡¢µØÎ»¡¢Âó¿Ë·çºÍÏà»úµÈÐÅÏ¢¡£PegasusÖ»Ïòµ±¾ÖºÍ·¨ÂÉ»ú¹¹ÏúÊÛ¡£¸Ã»ã±¨Ö¸³ö36ÃûÔËÓªÉÌÒ»ÏòÔÚʹÓÃPegasusÔÚ45¸ö¹ú¶ÈÄÚ·¢Õ¹¼à¶½Ðж¯¡£NSO½²»°È˳Ƹù«Ë¾Ã»ÓÐÎ¥·´Èκιú¶ÈµÄ˾·¨¡£
https://thehackernews.com/2018/09/android-ios-hacking-tool.html


¾©¹«Íø°²±¸11010802024551ºÅ