¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181114

°ä²¼¹¦·ò 2018-11-14
1¡¢×êÑлú¹¹°ä²¼ÃÀ¹úÐÅÓþ¿¨Ú²Æ­»ã±¨£¬´Óǰ1ÄêÄÚÒÑÓÐ6000ÍòÐÅÓþ¿¨ÐÅÏ¢±»ÇÔ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝGemini Advisory°ä²¼µÄÃÀ¹úÐÅÓþ¿¨Ú²Æ­»ã±¨£¬Ö»¹Ü2015ÄêÃÀ¹ú½ðÈÚÒµ¾ÍÒÑ´ó¹æÄ£Ç¨áãµ½EMVоƬ¿¨³ß¶È£¬µ«ÔÚ´Óǰ12¸öÔÂÄÚÈÔÓÐ6000ÍòÕÅÐÅÓþ¿¨µÄÐÅÏ¢±»ÇÔ¡£ÆäÖÐ4580Íò£¨75%£©µÄÐÅÓþ¿¨ÐÅÏ¢ÊÇͨ¹ýPoS»úÉϵÄʵ¿¨ÂòÂô±»ÇԵģ¬Ö»ÓÐ25%µÄÐÅÓþ¿¨ÐÅÏ¢±»ÔÚÏßÇÔÈ¡¡£ÕâЩʵ¿¨ÖÐ90%ÊÇEMV¿¨¡£´Óǰ12¸öÔÂÄÚº­µç×ÓÉÌÎñÖб»ÇÔµÄÐÅÓþ¿¨ÊýÁ¿Ôö³¤ÁË14%£¬ÕâÒâζÕß·¸×ï·Ö×ÓÔÚ´Óʵ¿¨ÂòÂôתÏòÎÞ¿¨Ú²Æ­¡£

   

Ô­ÎÄÁ´½Ó£º

https://geminiadvisory.io/card-fraud-on-the-rise/


2¡¢RiskIQºÍFlashpoint½áºÏ°ä²¼¹ØÓÚMagecart¹¥»÷µÄ·ÖÎö»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝRiskIQºÍFlashpoint½áºÏ°ä²¼µÄ¡¶Magecart¹¥»÷¶´²ì¡·»ã±¨£¬MagecartÊÇÖÁÉÙ7¸öÍøÂç·¸×ïÍÅ»ïµÄ×ܳÆ¡£Magecart¹¥»÷ͨ¹ýÔÚµç×ÓÉÌÎñÍøÕ¾ÉÏÖ²Èë¶ñÒâ½ÅÕý±¾ÇÔÈ¡Óû§µÄÐÅÓþ¿¨ÐÅÏ¢£¬ÊýÊ®¸öÈ«Çò³ÛÃûÆ·ÅÆµÄµç×ÓÉÌÎñÍøÕ¾¶¼ÊÇËüµÄÊܺ¦Õߣ¬Ô̺¬Ticketmaster¡¢British AirwaysÒÔ¼°Ðµ°µÈ¡£×êÑÐÈËÔ±Ôڻ㱨Öй¹½¨ÁËMagecart¹¥»÷µÄ¹¦·òÏߣ¬²¢³Áµã½éÉÜÁËËüÃǵĶñÒâ¾ç±¾¡¢¹¥»÷Õ½ÊõÒÔ¼°Ö¸±êÑ¡ÔñµÈÐÅÏ¢¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.riskiq.com/blog/external-threat-management/inside-magecart/


3¡¢×êÑÐÍŶӷ¢ÏÖÕë¶Ô°Í»ù˹̹µÄÐÂAPT×éÖ¯The White Company

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Cylance×êÑÐÍŶӷ¢ÏÖÒ»¸öÖØÒªÕë¶Ô°Í»ù˹̹µ±¾ÖºÍ¾ü¶ÓµÄÐÂAPT×éÖ¯The White Company£¨°×É«¹«Ë¾£©¡£¸ÃAPT×éÖ¯ËÆºõÊÇÓɹú¶ÈÔÞÖúµÄ£¬Æä´ó¹æÄ£¼äµý»î¶¯±»³ÆÎªOperation Shaheen£¨É³ÐÀÐж¯£©¡£The White CompanyʹÓÃÁ˶àÖÖ¸´ÔӵIJ½ÖèÀ´ÌӱܹéÒò£¬ÀýÈçÌӱܷÀ²¡¶¾Èí¼þ¼ì²â¡¢×ÔÎÒ¸²ÃðºÍ¶Ï¸ùºÛ¼£ÒÔ¼°ÓÐÒâÁôÏÂÏ໥ì¶ÜµÄÖ¤¾ÝµÈ¡£
  Ô­ÎÄÁ´½Ó£º
https://news.softpedia.com/news/the-white-company-a-new-state-sponsored-apt-discovered-by-cylance-523745.shtml


4¡¢×êÑÐÍŶӰ䲼¹ØÓÚжñÒâÍÚ¿óÈí¼þWebCobraµÄ·ÖÎö»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


McAfee³¢ÊÔÊÒµÄ×êÑÐÈËÔ±·¢ÏÖÒ»¸öжíÂÞ˹¶ñÒâÈí¼þWebCobra£¬WebCobra»áƾ¾ÝËùϰȾµÄϵͳ¼Ü¹¹µÄ·ÖÆç×°ÖÃ·ÖÆçµÄ¶ñÒâÍÚ¿óÈí¼þ£¬Ô̺¬Cryptonight£¨x86£©ºÍClaymore Zcash£¨x64£©¡£×êÑÐÈËÔ±ÒÔΪÕâÖÖ¶ñÒâÈí¼þÊÇͨ¹ýDZÔÚÓк¦µÄ·¨Ê½£¨PUP£©·Ö·¢µÄ£¬ÆäϰȾÁìÓò±é²¼È«Çò£¬µ«ÖØÒªÊÇÔÚ°ÍÎ÷¡¢ÄϷǺÍÃÀ¹ú¡£

 

 Ô­ÎÄÁ´½Ó£º

https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/webcobra-malware-uses-victims-computers-to-mine-cryptocurrency/


5¡¢×êÑÐÈËÔ±ÔÚGoogle PlayÉÏ·¢ÏÖ°µ²ØÒ»ÄêÖ®¾ÃµÄ¶ñÒâͨ»°¹àÒôapp

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÈËÔ±Lukas StefankoÔÚGoogle PlayÉÏ·¢ÏÖÒ»¸ö¶ñÒâµÄͨ»°¹àÒôapp£¬¸Ãapp×Ô2017Äê11ÔÂ30ÈÕÆðÔÚGoogle PlayÉÏ¿ÉÓã¬ÒѰµ²ØÁËÔ¼Ò»ÄêµÄ¹¦·ò£¬ÆäÏÂÔØ´ÎÊý³¬¹ý5000´Î¡£¸Ã¶ñÒâapp»á´Óhttp://adsmserver[.]club/up/update.apk£¨¸ÃÁ´½ÓĿǰÒѱ»É¾³ý£©ÏÂÔØÒ»¸öÐéαµÄFlash Player¸üУ¬²¢ºýŪÓû§½øÐÐ×°Öá£ÓÉÓÚÓÐЧºÉÔØÒѲ»³ÉÓã¬×êÑÐÈËԱδÄܽøÇ°½øÒ»²½µÄ·ÖÎö¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/trojanized-android-app-found-on-google-play-with-more-than-5-000-installs-523743.shtml


6¡¢Î¢Èí°ä²¼11Ô°²È«¸üУ¬½¨¸´64¸ö·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


΢Èí°ä²¼11Ô·ݵݲȫ¸üУ¬¹²½¨¸´64¸ö·ì϶£¬ÆäÖÐÔ̺¬12¸ö¸ßΣ·ì϶¡£ÆäÖÐÓÉ¿¨°Í˹»ù³¢ÊÔÊһ㱨µÄÁãÈÕ·ì϶£¨CVE-2018-8589£©Òѱ»¹¥»÷ÕßÔÚÒ°±í»ý¼«ÀûÓ᣸÷ì϶ÊÇÒ»¸öÌáȨ·ì϶£¬ÓëWindowsÉ豸Çý¶¯·¨Ê½Win32k.sysÓйØ¡ £¿¨°Í˹»ù´òËãÓÚÖÜÈý°ä²¼¹ØÓڸ÷ì϶±»APT×éÖ¯»ý¼«ÀûÓõĸü¶àÐÅÏ¢¡£¾ßÌå·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-november-2018-patch-tuesday-fixes-12-critical-vulnerabilities/


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù