¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181204

°ä²¼¹¦·ò 2018-12-04
1¡¢MagecartÔÙÌíÐÂÊܺ¦Õߣ¬Ó¢¹úSouthebyÍøÕ¾±»Ï°È¾³¬¹ýÒ»Äê

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢¹úSoutheby£¨ËÕ¸»±È£©ÅÄÂôÐа䷢Æäµç×ÓÉÌÎñÍøÕ¾Sotheby's Home³ÉΪMagecartµÄ×îÐÂÊܺ¦Õß¡£SouthebyÓÚ10ÔÂ10ÈÕ·¢ÏÖ²¢É¾³ýÁ˸ÃÍøÕ¾ÉϵĵÚÈý·½¶ñÒâ´úÂ룬Ȼ¶ø£¬¸Ã¶ñÒâ¾ç±¾ÖÁÉÙÓÚ2017Äê3ÔÂÒÔÀ´Ò»Ïò´æÔÚ£¬ÕâÒâζ×Å´Óǰ19¸öÔÂÄÚÎÞÊý¿Í»§¿ÉÄÜÊܵ½Ó°Ïì¡£¸Ã¶ñÒâ¾ç±¾ÓÃÓÚÇÔÈ¡Óû§ÊäÈëµÄÖ§¸¶ÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·ºÍÐÅÓþ¿¨ºÅ¡¢µ½ÆÚÈÕÆÚÒÔ¼°CVVÂëµÈ¡£ÀàËÆÓÚÓ¢¹úº½¿Õ¹«Ë¾ºÍе°ÍøµÄ¹¥»÷ÊÂÎñ£¬¹¥»÷ÕßËÆºõÊÇÖ±½ÓϰȾµÄ¸ÃÍøÕ¾¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/southebys-site-infected-magecart/


2¡¢¿¨°Í˹»ù°ä²¼2018Äê³Á´ó°²È«Íþв×ÛÊö£¬º­¸Ç¶à¸ö¹¥»÷Àà±ð

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ùµÄ2018Äê³Á´ó°²È«Íþв×ÛÊöº­¸ÇÁËÕë¶ÔÐÔ¹¥»÷¡¢Òƶ¯APTÍþв¡¢³ÁÒª·ì϶¡¢¶ñÒâä¯ÀÀÆ÷²å¼þ¡¢ÊÀ½ç±­Ú²Æ­»î¶¯¡¢Õë¶ÔICSµÄ½ðÈÚڲƭ¡¢ÀÕË÷Èí¼þ¡¢ÒøÐÐľÂí¡¢ÖÇÄÜÉ豸ÒÔ¼°Ó×ÎÒÐÅϢй¶µÈÀà±ð¡£Ëæ×Å»¥ÁªÍøÈÚÈëÁËÈËÃǵÄÉúÑÄ£¬¹¥»÷ÕߵĹ¥»÷ÃæÒ²Ô½À´Ô½¿í·º£¬Ô̺¬½ðÈÚ͵ÇÔ¡¢Êý¾ÝÇÔÈ¡ÒÔ¼°ÃûÍûÇÖº¦µÈ¡£¹¥»÷ÕßµÄÖ¸±êÉ豸ԽÀ´Ô½¶àµØÖ¸Ïò·ÇÍÆËã»úÀàµÄÉ豸£¬´Ó¶ùͯÖÇÄÜÍæ¾ßµ½ÍøÂçÉãÏñÓŵÈ¡£

 

 Ô­ÎÄÁ´½Ó£º

https://securelist.com/kaspersky-security-bulletin-2018-top-security-stories/89118/


3¡¢RiskIQ°ä²¼2019ÄêÍøÂçÍþвԤ²â£¬PII½«³ÉÎªÖØÒª¹¥»÷Ö¸±ê

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝRiskIQµÄ2019ÄêÍøÂçÍþвԤ²â»ã±¨£¬ÍþвÇ÷ÏòµÄ±ä¶¯½«Ô̺¬£ºPII½«³ÉÎªÖØÒªµÄ¹¥»÷Ö¸±ê£¬2018Äêͨ¹ýjs¾ç±¾ÇÔÊØÐÅÓþ¿¨ÐÅÏ¢µÄ»î¶¯´ó·¢×÷£¬Ô¤¼Æ2019ÄêÕâÖÖ²½Ö轫»áÀ©´óµ½Õë¶ÔPIIºÍIP £»¹¥»÷Õß½«»á³ÖÐø·¢ÏÖºÍÕë¶ÔÆóÒµ·À»ðǽ֮±íµÄäµã£¬ÀýÈçµÚÈý·½¹ºÎï³µÈí¼þºÍÊý¾ÝÍøÂ繤¾ß £»ÈÝÆ÷ºÍÎÞ·þÎñÆ÷ÍÆËãµÈм¼Êõ½«Îª¹¥»÷ÕßÌṩ¸ü¶à°µ²ØµÄ´¦Ëù £»¹ú¶ÈÖ§³ÖµÄÍøÂç¹¥»÷»î¶¯½«¼Ó¾ç £»¹¥»÷Õß½«Ôö³¤Æ¥µÐ»úе½ø½¨¼¼ÊõµÄѡȡ £»»ò½«³öÏÖ¸ü¶àÕë¶ÔÆäËüÊý¾ÝµÄMagecartÊÂÎñ¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.riskiq.com/blog/external-threat-management/2019-cybersecurity-predictions/


4¡¢Ó¢¹úµç×ÓÓʼþ¼°É罻ýÌå¹¥»÷ÊýÁ¿Ïà±ÈÈ¥Äê´ó·ùÉÏÉý

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝParliament StreetµÄÒ»·Ýл㱨£¬Ó¢¹ú¾¯Ô±ÔÚÃæ¶ÔÔ½À´Ô½´óµÄÉ罻ýÌåºÍÍÆËã»úÈëÇÖ°¸¼þµ÷²éѹÁ¦¡£»ã±¨Ö¸³ö£¬ÔÚ´ÓǰÁ½¸ö²ÆÄêÄÚ14¸ö¾¯Ô±¶ÓÁй²½øÐÐÁË2547ÆðÉ罻ýÌåºÍÍÆËã»úÈëÇÖ°¸¼þµÄµ÷²é¡£ÆäÖÐ2016-2017ÄêΪ1181Æð£¬2017-2018ÄêΪ1354Æð£¬Ôö³¤ÁË14%¡£FDM GroupµÄCOO Sheila Flavell³ÆÏÔÈ»ÍøÂç·¸×ïµÄÀ˳¹ØýÔںľ¡¾¯Ô±ÒÔ¼°ÆóÒµµÄ×ÊÔ´£¬½â¾öÕâ¸öÎÊÌâ±ØÒª¹²Í¬µÄÖÂÁ¦¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2018/12/03/social-media-hacking-rise/


5¡¢ÀûÓÃÓ¢¹úÍÑÅ·²Ý°¸»°Ì⣬SofacyжñÒâ»î¶¯·Ö·¢Zebrocy

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°£É­ÕÜ×êÑÐÈËÔ±·¢ÏÖ¶íÂÞ˹APT×éÖ¯SofacyÔÚ×î½üµÄ¶ñÒâ¹¥»÷»î¶¯ÖÐÀûÓÃÁËÓ¢¹úÍÑÅ·²Ý°¸µÄ»°Ì⣬²¢ÇÒÊÔͼ·Ö·¢¶ñÒâÈí¼þZebrocy¡£¸Ã¹¥»÷»î¶¯ÆðÍ·ÓÚ11ÔÂ15ÈÕ£¬¹¥»÷ÕßÖØÒªÍ¨¹ý¶ñÒâOfficeÎĵµÖеÄsettings.xml.rels×é¼þ´Ó±í²¿Ô´¼ÓÔØ¶ñÒâÄÚÈÝ£¬Æä×îÖÕpayloadÊÇDelphiºÍ.NET°æ±¾µÄZebrocy¡£Zebrocy½«ÍøÂçϵͳÉϵĹý³ÌÁÐ±í¡¢ÆÁÄ»½ØÍ¼¡¢Çý¶¯Æ÷ö¾ÙÐÅÏ¢²¢·¢ËÍÖÁC&C·þÎñÆ÷¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/russian-hackers-use-brexit-lures-recent-attacks


6¡¢ÍòºÀ¾ÆµêÒòÊý¾Ý¿âй¶Ô⼯ÌåËßËÏ£¬±»Ë÷Åâ125ÒÚÃÀÔª

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÍòºÀ¹ú¼Ê¾Æµê¼¯ÍÅ(Marriott International)½üÈÕÒò¿Í»§Êý¾Ý¿âй¶¶øÔâ·ê¼¯ÌåËßËÏ£¬Ë÷Åâ½ð¶î¸ß´ï125ÒÚÃÀÔª¡£ÉÏÖÜÎåÍòºÀ°ä·¢ÆìÏÂϲ´ïÎݾƵê(Starwood Hotel)µÄÒ»¸ö¿Í»§Ô¤Ô¼Êý¾Ý¿â±»ºÚ¿ÍÈëÇÖ£¬Ô¼5ÒÚ¿Í»§µÄÐÅÏ¢¿ÉÄÜй¶¡£¾ÝϤ£¬ºÚ¿ÍÈëÇÖÔçÔÚ2014Äê¾ÍÒѾ­ÆðÍ·¡£Ëæºó£¬ÃÀ¹úGeragos&GeragosÂÉʦÊÂÎñËùµÄÂÉʦ±¾¡¤Ã·ÈûÀ­Ë¹(Ben Meiselas)ºÍUnderdog Law˾·¨ÕÕ·÷Âõ¿Ë¶û¡¤¸»ÀÕ(Michael Fuller)´ú±íÁ½ÃûÔ­¸æ´óÎÀ¡¤Ô¼º²Ñ·(David Johnson)ºÍ¿ËÀï˹¡¤¹þÀï˹(Chris Harris)¶ÔÍòºÀ¹ú¼Ê¾ÆµêÌáÆð¼¯ÌåËßËÏ£¬Ë÷Åâ125ÒÚÃÀÔª¡£¹ÌÈ»ÕâÒ»½ð¶î¿´ÆðÀ´¼«¶È¾Þ´ó£¬µ«Ò²½öÏ൱ÓÚ5ÒÚDZÔÚÊܺ¦¿Í»§Ã¿È˵õ½25ÃÀÔªµÄÅâ³¥¡£

  

Ô­ÎÄÁ´½Ó£º

http://tech.sina.com.cn/i/2018-12-03/doc-ihprknvs8439051.shtml


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù