¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180809

Ðû²¼Ê±¼ä 2018-08-09

¡¾ÆÊÎö±¨¸æ¡¿NETSCOUTÐû²¼2018ÉϰëÄêÈ«ÇòÍþвÇ鱨±¨¸æ


NETSCOUTÐû²¼2018ÉϰëÄêÈ«ÇòÍþвÇ鱨±¨¸æ£¬£¬ £¬£¬£¬£¬±¨¸æµÄÖ÷Òª·¢Ã÷°üÀ¨£º1¡¢DDoS¹¥»÷½øÈëTB¼¶Ê±´ú£»£»£»2¡¢¹¥»÷µÄ¹æÄ£¸ü´ó£¬£¬ £¬£¬£¬£¬µ«ÆµÂÊϽµ£»£»£»3¡¢APT×éÖ¯ÓâÔ½Á˹ŰåµÄÎę̀£»£»£»4¡¢·¸·¨·Ö×Ó½ÓÄɶàÑù»¯µÄ¹¥»÷ÒªÁ죻£»£»5¡¢²¿·Ö¹ú¼Ò³ÉΪDDoS¹¥»÷µÄÖØÔÖÇø£»£»£»6¡¢Õë¶Ô¸ü¶à±ÊÖ±ÐÐÒµ£»£»£»7¡¢ÐµÄDDoS¹¥»÷ÏòÁ¿±»Ñ¸ËÙʹÓ㻣»£»8¡¢¾ÉµÄ¹¥»÷ÏòÁ¿»À·¢µÚ¶þ´º£»£»£»9¡¢ÓÐÕë¶ÔÐÔµÄAPT¹¥»÷ÒýÈ뻥ÁªÍø¼¶±ðµÄÀ©É¢¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬±¨¸æ»¹º­¸ÇÁËÐµķ¸·¨Èí¼þƽ̨ºÍÄ¿µÄ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.netscout.com/sites/default/files/2018-08/NETSCOUT_ThreatReport_FINAL_080618b.pdf


¡¾ÆÊÎö±¨¸æ¡¿Ñо¿ÍŶÓÐû²¼2018ÄêÏÄÈÕÎó²îʹÓù¤¾ß°üµÄÆÊÎö±¨¸æ


Malwarebytes LabsÑо¿ÍŶÓÐû²¼2018ÄêÏÄÈÕÎó²îʹÓù¤¾ß°üµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£ÔÚ´º¼¾EK¹¥»÷»î¶¯µÄÉÏÉýÇ÷ÊÆÑÓÐøµ½ÁËÏÄÈÕ¡£¡£¡£¡£¡£¡£³ýÁËRIGºÍGrandSoft EKÖ®Í⣬£¬ £¬£¬£¬£¬ÎÒÃÇÊӲ쵽µÄ´ó²¿·ÖEKµÄ¹¥»÷»î¶¯¶¼ÔÚÑÇÖÞ£¬£¬ £¬£¬£¬£¬Õâ¿ÉÄÜÊÇÓÉÓڸõØÇø¸üÈÝÒ×Óöµ½Ò×Êܹ¥»÷µÄϵͳ¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬ÎÒÃÇ»¹·¢Ã÷ÁËÐí¶àС¹æÄ£ÇÒ²»¿ÉÊìµÄ¹¥»÷ÕßʹÓÃÒ»Á½¸öÎó²îʹÓÃÖ±½ÓǶÈëÊÜѬȾµÄÍøÕ¾ÖеÄÐÐΪ£¬£¬ £¬£¬£¬£¬Õâͨ³£ÊÇÒ»¸öµ¥¶ÀµÄ×÷ÕßµÄÐÐΪ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.malwarebytes.com/threat-analysis/2018/08/exploit-kits-summer-2018-review/


¡¾Çå¾²²¥±¨¡¿OWASPÐû²¼Çå¾²Ò½ÁÆÆ÷е°²Åűê×¼V2£¬£¬ £¬£¬£¬£¬Ö¼ÔÚÌáÉýÒ½ÁÆ×°±¸µÄÇå¾²ÐÔ


×÷ΪһֱÉú³¤µÄÎïÁªÍøµÄÒ»¸öÒªº¦×Ó¼¯£¬£¬ £¬£¬£¬£¬Ò½ÁÆ×°±¸Ô½À´Ô½ÈÝÒ×Êܵ½½©Ê¬ÍøÂçºÍ¶ñÒâÈí¼þµÄ¹¥»÷¡£¡£¡£¡£¡£¡£ÎªÁËÓ¦¶ÔÕâÖÖÈÕÒæÔöÌíµÄÇå¾²ÐÔÐèÇ󣬣¬ £¬£¬£¬£¬CSAºÍOWASPÁªºÏÐû²¼ÁËOWASPÇå¾²Ò½ÁÆÆ÷е°²Åűê×¼V2¡£¡£¡£¡£¡£¡£¸Ã±ê×¼ÔÚÌØÊâÊDzɹº¿ØÖÆ·½Ãæ¾ÙÐÐÁËÔöÇ¿£¬£¬ £¬£¬£¬£¬²¢¶ÔÇå¾²Éó¼ÆºÍÆÀ¹ÀÒÔ¼°Òþ˽ӰÏìÆÀ¹À¾ÙÐÐÁ˸üС£¡£¡£¡£¡£¡£¸Ã±ê×¼µÄÄ¿µÄÊÇÈ·±£Ò½ÁÆ»ú¹¹×ñÕÕÒ½ÁÆÆ÷еºÍITϵͳµÄ×î¼ÑÇ徲ʵ¼ù¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/improved-standards-for-securing/


¡¾Çå¾²²¥±¨¡¿SnapchatÔ´ÂëÔÚGitHubÉÏÆØ¹â£¬£¬ £¬£¬£¬£¬¹«Ë¾ÉñÃØ¿ÉÄÜÍâй


Ê¢ÐеÄÉ罻ýÌåÓ¦ÓÃSnapchatµÄÔ´´úÂë±»Ò»ÃûºÚ¿ÍÐû²¼ÔÚGitHubÉÏ¡£¡£¡£¡£¡£¡£¸ÃGitHubÕË»§ÎªKhaled Alshehri£¬£¬ £¬£¬£¬£¬ÊÇÒ»Ãû°Í»ù˹̹Óû§£¬£¬ £¬£¬£¬£¬ÆäÔÚSource-Snapchat´æ´¢¿âÖÐÐû²¼ÁËÌý˵ÊÇSnapchatµÄiOSÓ¦ÓõĴúÂë¡£¡£¡£¡£¡£¡£µ×²ã´úÂë¿ÉÄÜ»áй¶¹«Ë¾µÄÉñÃØÐÅÏ¢£¬£¬ £¬£¬£¬£¬ÀýÈçappµÄÕûÌåÉè¼Æ¡¢ÊÂÇé·½·¨ÒÔ¼°ÍýÏëµÄδÀ´¹¦Ð§µÈ¡£¡£¡£¡£¡£¡£SnapchatµÄĸ¹«Ë¾Snap Inc.ƾ֤DMCA·¨ÒªÇóɾ³ýÁ˸ô洢¿â¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/snapchat-hack-source-code.html


¡¾Îó²î²¹¶¡¡¿Ñо¿Ö°Ô±·¢Ã÷OpenEMR±£´æ¶à¸öÇå¾²Îó²î£¬£¬ £¬£¬£¬£¬¿Éµ¼Ö»¼ÕßµÄÒ½ÁÆÊý¾Ýй¶


Ñо¿Ö°Ô±ÔÚOpenEMRÈí¼þÖз¢Ã÷Á˽ü¶þÊ®¶þ¸öÇå¾²Îó²î£¬£¬ £¬£¬£¬£¬ÆäÖаüÀ¨¿ÉÔÊÐíδ¾­ÊÚȨ»á¼ûÒ½ÁƼͼµÄÑÏÖØÎó²î¡£¡£¡£¡£¡£¡£OpenEMRÊÇÒ»¸öºÜÊÇÊܽӴýµÄÓÃÓÚÒ½ÁÆÐÅÏ¢ºÍÒ©Îï¼Í¼µÄ¿ªÔ´ÖÎÀíÈí¼þ£¬£¬ £¬£¬£¬£¬¿ÉÔÚ¶àÖÖ²Ù×÷ϵͳ£¨°üÀ¨Windows¡¢LinuxºÍmacOS£©ÉÏÔËÐС£¡£¡£¡£¡£¡£¾ÝÔ¤¼Æ£¬£¬ £¬£¬£¬£¬È«ÇòÔ¼ÓÐ1.5Íò¸ö²î±ð¹æÄ£µÄÒ½ÁÆ»ú¹¹ÕýÔÚʹÓÃOpenEMR¡£¡£¡£¡£¡£¡£Îó²îµÄ¹æÄ£°üÀ¨Éí·ÝÑéÖ¤ÈÆ¹ý¡¢SQL×¢Èë¡¢ÐÅϢй¶¡¢ÎļþÉÏ´«¡¢CSRFºÍRCEµÈ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.helpnetsecurity.com/2018/08/08/openemr-vulnerabilities/


¡¾Çå¾²Îó²î¡¿Ñо¿Ö°Ô±³ÆWhatsApp±£´æ¶à¸öÇå¾²Îó²î£¬£¬ £¬£¬£¬£¬¿É×èµ²ºÍÐÞ¸ÄÓû§µÄÐÂÎÅÄÚÈÝ


Check PointµÄÇå¾²Ñо¿Ö°Ô±·¢Ã÷WhatsApp±£´æ¶à¸öÇå¾²Îó²î£¬£¬ £¬£¬£¬£¬¿ÉÔÊÐí¶ñÒâÓû§×èµ²ºÍÐÞ¸Ä˽ÈË»òȺ×éµÄ̸ÌìÄÚÈÝ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³ÆÕâЩÎó²îʹÓÃÁËWhatsAppÇ徲ЭÒéÖеÄÎó²î£¬£¬ £¬£¬£¬£¬¿ÉÔÊÐí¶ñÒâÓû§½¨ÉèºÍÈö²¥¿´ÆðÀ´ÊÇÀ´×Ô¿ÉÐÅȪԴµÄ¹ýʧÐÂÎÅ»òÐéαÐÂÎÅ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Í¨¹ýÊÓÆµÑÝʾÁËÆä¹¥»÷Àú³Ì¡£¡£¡£¡£¡£¡£µ«WhatsAppÍŶÓÒÔΪÕâÊÇÒ»ÖÖÉè¼ÆÉϵÄȨºâ£¬£¬ £¬£¬£¬£¬²¢²»ÍýÏë×ö³öÈκÎÐÞ¸´¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/08/whatsapp-modify-chat-fake-news.html