¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181112
°ä²¼¹¦·ò 2018-11-12
ƾ¾Ý°Í»ù˹̹Áª¹úµ÷²é¾ÖFIAµÄ˵·¨£¬ÏÕЩËùÓеİͻùË¹Ì¹ÒøÐж¼Êܵ½×î½üµÄÊý¾Ýй¶ÊÂÎñµÄÓ°Ïì¡£¾Ý³Æ¸ÃÊÂÎñÓëÔÚ°µÍøÊг¡ÉϳöÏÖµÄÔ¼2ÍòÕŰͻùË¹Ì¹ÒøÐнè¼Ç¿¨ÐÅÏ¢Óйء£¸Ã»ú¹¹ÔÚµ÷²éÓë¸ÃÊÂÎñÓйصÄ100¶àÆðÍøÂç¹¥»÷£¬Ä¿Ç°Éв»Ã÷ÏÔÊý¾Ýй¶ÊÂÎñ²úÉúµÄ¾ßÌ幦·ò£¬Ò²²»ÖªÂ·¹¥»÷ÕßÈôºÎ½øÈëÕâЩ°Í»ùË¹Ì¹ÒøÐеÄϵͳ¡£½ØÖÁÉÏÖÜÄ©£¬Ò»Ð©°Í»ùË¹Ì¹ÒøÐÐÒѾÔÝÍ£ÔÚ¹ú±íʹÓÃËüÃǵĽè¼Ç¿¨£¬²¢½ûÓÃÁËÕâЩ¿¨µÄËùÓйú¼ÊÂòÂô¡£PakCERTͬÑù°ä²¼ÁËÒ»·Ý¹ØÓÚÊý¾Ýй¶µÄ¹¦·ò±íºÍ¹æÄ£µÄ»ã±¨¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/77847/cyber-crime/pakistani-banks-data-breach.html2¡¢ÈüÃÅÌú¿Ë°ä²¼¹ØÓÚLazarusµÄATM¹¥»÷¹¤¾ßFastcashµÄ·ÖÎö»ã±¨
ÈüÃÅÌú¿Ë°ä²¼¹ØÓÚLazarusÓÃÓÚ¹¥»÷ATMµÄ¹¤¾ßFastCashµÄ·ÖÎö»ã±¨¡£ÖÁÉÙ×Ô2016ÄêÒÔÀ´£¬¸ÃAPT×éÖ¯Ò»ÏòÔÚʹÓÃÕâÖÖ¶ñÒâÈí¼þ£¬´ÓÑÇÖ޺ͷÇÖÞµÄÖÐÓ×ÐÍÒøÐÐATMÖÐÇÔÈ¡Á˳¬¹ýÊý°ÙÍòÃÀÔª¡£FastCashľÂí×÷ÓÃÓÚÒøÐÐÄÚ²¿ÍøÂçÖеÄÓÃÓÚ´¦ÖÃATMÂòÂôÒªÇóµÄ»¥»»»úÀûÓ÷þÎñÆ÷ÖУ¬Ö¼ÔÚÀ¹½ØºÍºË×¼Ú²ÆÐÔµÄATMÌáÈ¡ÏÖ½ðÒªÇ󣬲¢·¢ËÍÐéαµÄºË×¼ÏìÓ¦¡£¸ÃľÂíרÃÅÕë¶ÔÔËÐÐIBM AIXϵͳµÄ»¥»»»úÀûÓ÷þÎñÆ÷£¬ÈüÃÅÌú¿Ë·¢ÏÖ¸Ã×éÖ¯¹¥»÷µÄËùÓзþÎñÆ÷¶¼ÔËÐÐÒѹýÆÚµÄAIX OS°æ±¾¡£
ÔÎÄÁ´½Ó£º
https://www.symantec.com/blogs/threat-intelligence/fastcash-lazarus-atm-malware3¡¢×êÑÐÍŶӷ¢ÏÖÖØÒªÕë¶Ô°ÍÎ÷½ðÈÚ»ú¹¹µÄ¶ñÒâÈí¼þ·Ö·¢»î¶¯
˼¿ÆTalosÍŶӷ¢ÏÖÁ½¸öÔÚ½øÐÐÖеĶñÒâÈí¼þ·Ö·¢»î¶¯£¬ÕâЩ»î¶¯ÓÃÓÚÏò°ÍÎ÷µÄ½ðÈÚ»ú¹¹Óû§´«²¼ÒøÐÐľÂí¡£¹¥»÷»î¶¯²úÉúÔÚ10Ôµ׺Í11Ô³õ£¬ÕâÁ½¸ö¹¥»÷»î¶¯Ê¹ÓÃÁË·ÖÆçµÄ³õʼϰȾÎļþÀàÐͺÍÁ½¸ö·ÖÆçµÄÒøÐÐľÂí£¬µ«ÔÚϰȾ¹ý³ÌÖжԸ÷ÀàÎļþʹÓÃÁËÒ»ÑùµÄ¶¨Ãû¹æ¶¨£¬²¢¶¼Ê¹ÓÃÁ˶ÌÁ´½ÓÀ´°µ²ØÏÖʵµÄ·Ö·¢·þÎñÆ÷µØÖ·¡£ÔÚ·ÖÎöÕâЩ»î¶¯Ê±£¬Talos»¹·¢ÏÖÁËÒ»¸öеÄÀ¬»øÓʼþ½©Ê¬ÍøÂç¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2018/11/metamorfo-brazilian-campaigns.html4¡¢¼ÓÄôóÓÊÕþй¶Լ4500ÃûOCS¿Í»§µÄ´óÂé¶©µ¥ÐÅÏ¢
ÉÏÖÜÈý°²Ê¡´óÂéÍøµê£¨OCS£©ÔÚTwitterÉÏй©³Æ£¬Î´Öª¹¥»÷Õß´Ó¼ÓÄôóÓÊÕþ½Ó¼ûÁËÔ¼4500Ãû¿Í»§µÄ¶©µ¥¼Í¼£¬Ô¼Õ¼¸Ã¹«Ë¾¿Í»§ÈºµÄ2%¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬Ç©ÊÕÈ˵ÄÐÕÃû»òËõд¡¢ÓÊÕþ±àÂë¡¢½»¸¶ÈÕÆÚ¡¢OCS±àºÅ¡¢ÓÊÕþ°ü¹üºÅÒÔ¼°OCS¹«Ë¾µÄÃû³ÆºÍÒµÎñµØÖ·µÈ¡£µ«OCS¼á³ÆÆëÈ«µÄ¿Í»§µØÖ·¡¢¶©µ¥ÄÚÈݺ͸¶¿îÐÅϢûÓÐÊܵ½ÇÖº¦¡£¸Ãй¶ÊÂÎñÓÚ11ÔÂ1ÈÕ±»·¢ÏÖ£¬¼ÓÄôóÓÊÕþºÍOCSÔÚºÏ×÷µ÷²éÊÂÎñµÄÆðÒò¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/canada-post-leaked-personal-data-orders-of-thousands-of-cannabis-smokers/5¡¢·ðÂÞÀï´ïÖÝÎÀÉúÊ𱻺ڿÍÈëÇÖ£¬²¿ÃŵØÓòµÄ»¼ÕßÐÅϢй¶
¾Ý±¨Â··ðÂÞÀï´ïÖÝÎÀÉúÊðµÄÒ»ÃûCMSÔ±¹¤µÄOutlook 365ÕË»§±»ºÚ¿ÍÈëÇÖ£¬Escambia¡¢Santa Rosa¡¢OkaloosaºÍWaltonµØÓòµÄ»¼ÕßÐÅÏ¢±»ÇÔ¡£¸ÃÕË»§µÄδÊÚȨ½Ó¼û²úÉúÔÚ10ÔÂ8ÈÕÖÁ10ÔÂ16ÈÕÖ®¼ä£¬²¿ÃÅÓû§µÄÐÕÃû¡¢Ò½ÁÆÇé¿öµÈÐÅÏ¢¿ÉÄÜй¶¡£Æ¾¾Ý¸ÃÎÀÉúÊðµÄÉêÃ÷£¬Ã»ÓÐÖ¤¾ÝÅú×¢»¼ÕßµÄÉç±£ºÅÂë¡¢ÒøÐÐÕË»§»òÐÅÓþ¿¨ÐÅÏ¢±»ÇÔ¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/florida-department-of-health-breached-patients-private-information-exposed-523724.shtml6¡¢ICS-CERTÖÒ¸æ³ÆÈðÊ¿ÂÞÊÏÒ½ÁÆÆ÷е´æÔÚ¶à¸ö°²È«·ì϶
°²È«³§ÉÌMedigate·¢ÏÖÈðʿҽÁƱ£½¡¹«Ë¾ÂÞÊÏÔì×÷µÄÈýÖÖÒ½ÁÆÆ÷еÖдæÔÚÎå¸ö°²È«·ì϶£¬¿ÉÄܵ¼Ö»¼ÕßÃæ¶Ô·çÏÕ¡£ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬Accu-ChekѪÌÇÒÇ¡¢CoaguChekÉ豸ºÍCobas±ãЯʽ´²±ß»¤Àíϵͳ¡£ICS-CERTÒ²ÔÚÓйػ㱨ÖÐÁгöÁËÊÜÓ°Ïì²úÆ·ºÍ°æ±¾µÄ¾ßÌåÇåµ¥¡£ÈðÊ¿ÂÞÊÏÔÚ½¨¸´ÕâЩ·ì϶£¬Ô¤¼Æ±¾Ô½«°ä²¼Óйؽ¨¸´²¹¶¡¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/flaws-roche-medical-devices-can-put-patients-riskÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ