¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181121
Ðû²¼Ê±¼ä 2018-11-21
¿¨°Í˹»ùʵÑéÊÒÐû²¼¶Ô2019ÄêÍøÂçÍþвÇ÷ÊÆµÄÒ»¸öÕ¹ÍûÆÊÎö£¬£¬£¬£¬£¬£¬Ö÷ÒªÄÚÈݰüÀ¨£º»òÐí²»»áÔÙ·¢Ã÷¸ü¶àµÄ´óÐÍAPT×éÖ¯£»£»£»£»£»£»£»ÍøÂçÓ²¼þÓëÎïÁªÍøÍþв½«»áÒ»Ö±ÔöÇ¿£»£»£»£»£»£»£»ÓëÍâ½»ºÍÕþÖÎÓйصĹûÕæÅê»÷£»£»£»£»£»£»£»¶«ÄÏÑǺÍÖж«µØÇø»òÐí»á·ºÆð¸ü¶àµÄ¹¥»÷×éÖ¯£»£»£»£»£»£»£»£¨Ring -£©È¨ÏÞ£¬£¬£¬£¬£¬£¬±ÈRing 0¸ü¸ßµÄȨÏÞ£»£»£»£»£»£»£»×îÊܽӴýµÄѬȾǰÑÔ-´¹ÂÚ£»£»£»£»£»£»£»»ò½«·ºÆð¸ü¶àÀàËÆ¡°°ÂÔËÇýÖ𽢡±µÄ¹¥»÷£»£»£»£»£»£»£»¹©Ó¦Á´¹¥»÷½«¼ÌÐø£»£»£»£»£»£»£»Òƶ¯¶ñÒâÈí¼þ²»»á·ºÆð´ó±¬·¢£¬£¬£¬£¬£¬£¬µ«¸ß¼¶¹¥»÷Õß»á¼ÌÐøÑ°ÕÒÈëÇÖ×°±¸µÄÒªÁì¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/kaspersky-security-bulletin-threat-predictions-for-2019/88878/2¡¢FireEyeÐû²¼¹ØÓÚAPT29µÄд¹ÂڻµÄÆÊÎö±¨¸æ
2018Äê11ÔÂ14ÈÕFireEye¼ì²âµ½Õë¶Ô¶à¸öÐÐÒµµÄ20¶à¸ö¿Í»§µÄÐÂÕë¶ÔÐÔ´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬º¸ÇÖǿ⡢ִ·¨»ú¹¹¡¢Ã½Ìå¡¢ÃÀ¹ú¾ü·½¡¢Í¼Ïñ¡¢ÔËÊä¡¢ÖÆÒ©¡¢Õþ¸®»ú¹¹ÒÔ¼°¹ú·À³Ð°üÉ̵ȡ£¡£¡£¡£ÕâЩ´¹ÂÚ¹¥»÷ʹÓÃαװ³ÉÀ´×ÔÃÀ¹ú¹úÎñÔºµÄ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬ÊÔͼÈö²¥Cobalt Strike Beacon¡£¡£¡£¡£Æ¾Ö¤¶ÔÆäTTPµÄÆÊÎö£¬£¬£¬£¬£¬£¬Æä±³ºóµÄ¹¥»÷×éÖ¯ÒÉΪAPT29¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.fireeye.com/blog/threat-research/2018/11/not-so-cozy-an-uncomfortable-examination-of-a-suspected-apt29-phishing-campaign.html3¡¢ÃÀ¹ú´ó¶¼»áÈËÊÙ°ü¹Ü¹«Ë¾ÒâÍâй¶²¿·Ö¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢
ƾ֤¼ÓÀû¸£ÄáÑÇÖÝÐû²¼µÄÊý¾Ýй¶֪ͨ£¬£¬£¬£¬£¬£¬ÃÀ¹ú´ó¶¼»áÈËÊÙ°ü¹Ü¹«Ë¾£¨MetLife£©ÓÚ10ÔÂ18ÈÕÒâÍâй¶Á˲¿·Ö¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬£¬ÕâЩÐÅÏ¢ÒÔ¸½¼þµÄÐÎʽ±»·¢Ë͸øÓëMetLifeÏàÖúµÄBenefits Administrator£¨¸£ÀûÖÎÀíÔ±£©£¬£¬£¬£¬£¬£¬²¢Ëæºó±»É¾³ý¡£¡£¡£¡£Ïà¹ØÊý¾Ý°üÀ¨¿Í»§µÄÉç±£ºÅÂë¡¢°ü¹Ü¹æÄ£¡¢³öÉúÈÕÆÚ¡¢ÐÔ±ðºÍµØµãµÈ¡£¡£¡£¡£Ö»¹ÜÒÔΪ¿Í»§µÄPII²¢Ã»ÓÐÊܵ½Ë𺦣¬£¬£¬£¬£¬£¬µ«MetLifeÈÔÈ»¾öÒéΪÊÜÓ°ÏìµÄ¿Í»§ÌṩһÄêµÄÐÅÓÃ¼à¿ØÐ§ÀÍ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/data-leak-incident-reported-by-fortune-500-metropolitan-life-insurance-company-523865.shtml4¡¢OSIsoft LLCÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬ËùÓÐÓòÕÊ»§µÄµÇ¼ƾ֤¶¼±»ÇÔÈ¡
11ÔÂ16ÈÕOSIsoft LLCÏò¼ÓÖÝÖÝÉó²é³¤°ì¹«ÊÒÐû²¼Í¨Öª³Æ¸Ã¹«Ë¾Ôâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬°üÀ¨¹«Ë¾Ô±¹¤¡¢ÕÕÁÏ¡¢ÊµÏ°ÉúºÍµÚÈý·½³Ð°üÉ̵ÄÊý¾ÝÒÉй¶¡£¡£¡£¡£OSIsoftÊÇʵʱÊý¾ÝÖÎÀíÈí¼þPI SystemµÄ¿ª·¢ÉÌ£¬£¬£¬£¬£¬£¬¸ÃÈí¼þ±»Áè¼Ý65%µÄ²Æ²ú500Ç¿¹¤Òµ¹«Ë¾ËùʹÓᣡ£¡£¡£OSIsoftÌåÏÖ·¢Ã÷ÁËÉæ¼°29̨ÅÌËã»úºÍ135¸öÕË»§µÄƾ֤͵ÇԻµÄÖ±½ÓÖ¤¾Ý£¬£¬£¬£¬£¬£¬½ø¶øµÃ³ö½áÂÛËùÓеÄOSIÓòÕË»§¶¼Òѱ»Í»ÆÆ¡£¡£¡£¡£¼øÓÚ¸ÃÊý¾Ýй¶ÊÂÎñµÄÑÏÖØÐÔ£¬£¬£¬£¬£¬£¬OSIsoftÕýÔÚ¶à¸öÇ徲ЧÀÍÉ̵Ä×ÊÖúϾÙÐÐÊӲ졣¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/osisoft-breached-all-domain-accounts-emails-and-passwords-assumed-compromised-523863.shtml5¡¢TalkTalkÈëÇÖÊÂÎñÖеÄÁ½ÃûºÚ¿Í±»ÅÐÈëÓü£¬£¬£¬£¬£¬£¬ÔøÔì³É7700ÍòÓ¢°÷µÄËðʧ
¾ÝÓ¢¹úÖðÈÕÓʱ¨±¨µÀ£¬£¬£¬£¬£¬£¬Á½ÃûºÚ¿ÍÒò2015ÄêµÄTalkTalkÈëÇÖÊÂÎñ±»ÅÐÈëÓü¡£¡£¡£¡£TalkTalkÊÇÓ¢¹ú×î´óµÄµçÐŹ«Ë¾Ö®Ò»£¬£¬£¬£¬£¬£¬ÕâÁ½ÃûºÚ¿Í¹²ÇÔÈ¡ÁËÁè¼Ý15.6ÍòÃû¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢¡¢²ÆÎñÐÅÏ¢¼°ÐÅÓÿ¨ÐÅÏ¢£¬£¬£¬£¬£¬£¬Ôì³ÉµÄËðʧ´ï7700ÍòÓ¢°÷¡£¡£¡£¡£ÏÖÄê23ËêµÄMatthew HanleyºÍ21ËêµÄConnor AllsoppÈÏ¿ÉÁËÏà¹ØÖ¸¿Ø£¬£¬£¬£¬£¬£¬²¢»®·Ö±»Åд¦12¸öÔºÍ8¸öÔµÄÓÐÆÚͽÐÌ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/11/talktalk-data-breach.html6¡¢AdobeÐû²¼Flash Player½ôÆÈÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´Ò»¸öí§Òâ´úÂëÖ´ÐÐÎó²î
±¾ÖܶþAdobeÕë¶ÔFlash Player¸ßΣÎó²î£¨CVE-2018-15981£©Ðû²¼½ôÆÈÇå¾²¸üС£¡£¡£¡£¸ÃÎó²îÊÇÒ»¸öÀàÐÍ»ìÏý¹ýʧ£¬£¬£¬£¬£¬£¬¿Éµ¼Ö¹¥»÷ÕßÔÚÓû§²»ÖªÇéµÄÇéÐÎÏÂÖ´ÐÐí§Òâ¶ñÒâ´úÂë¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËWindows¡¢macOS¡¢LinuxºÍChrome OSµÈƽ̨ÉϵÄFlash Player 31.0.0.148¼°¸üÔçµÄ°æ±¾¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ°æ±¾31.0.0.153¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/critical-adobe-flash-bug-impacts-windows-macos-linux-and-chrome-os/139264/ÉùÃ÷£º±¾×ÊѶÓÉ¿·¢k8άËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ