¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181106
Ðû²¼Ê±¼ä 2018-11-06
ƾ֤»ôÄáΤ¶ûÐû²¼µÄÒ»·Ýб¨¸æ£¬£¬£¬£¬£¬£¬£¬USB×°±¸ÊÇÕë¶Ô¹¤ÒµÉèÊ©µÄ¶ñÒâÈí¼þ¹¥»÷µÄÖ÷ҪǰÑÔ¡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÊÇ»ùÓÚ»ôÄáΤ¶ûµÄÇ徲ýÌå½»Á÷£¨SMX£©ÊÖÒÕÍøÂçµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬º¸ÇÁËÄÜÔ´¡¢Ê¯ÓͺÍ×ÔÈ»Æø¡¢»¯Ñ§¡¢Ö½ÕÅÖÆÔìµÈÐÐÒµ¡£¡£¡£¡£¡£¡£¡£Êý¾ÝÅú×¢£¬£¬£¬£¬£¬£¬£¬26%µÄÍþв¿ÉÄܵ¼Ö¹¤ÒµÆóҵʧȥICSÇéÐεĿɼûÐÔ»ò¿ØÖÆÈ¨£¬£¬£¬£¬£¬£¬£¬´Ó¶øÔì³ÉÖØ´óÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£16%µÄÍþвרÃÅÕë¶ÔICSºÍIoTϵͳ£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨¶ñÒâÈí¼þMirai£¨6£¥£©¡¢Stuxnet£¨2£¥£©¡¢Triton£¨2£¥£©ºÍWannaCry£¨1£¥£©¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://honeywellprocess.blob.core.windows.net/public/Support/Customer/Honeywell-USB-Threat-Report.pdf2¡¢ÃÀ»ã·áÒøÐÐÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬²¿·Ö¿Í»§×ÊÁϱ»ÇÔ
ƾ֤ÃÀ¹ú»ã·áÒøÐÐ11ÔÂ2ÈÕÏò¿Í»§·¢Ë͵ÄÊý¾Ýй¶֪ͨ£¬£¬£¬£¬£¬£¬£¬²¿·Ö¿Í»§µÄÔÚÏßÕË»§ÓÚ2018Äê10ÔÂ4ÈÕÖÁ14ÈÕʱ´úÔ⵽δÊÚȨ»á¼û£¬£¬£¬£¬£¬£¬£¬±»ÇÔµÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢×¡Ö·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢³öÉúÈÕÆÚ¡¢Õ˺š¢ÕË»§ÀàÐÍ¡¢ÕË»§Óà¶î¡¢ÀúÊ·ÉúÒâ¼Í¼¡¢ÊÕ¿îÈËÕË»§ÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£»£»£»£»ã·áÒøÐÐÌåÏÖËùÓÐÊÜÓ°ÏìµÄ¿Í»§¶¼½«»ñµÃÃâ·ÑµÄÐÅÓÃ¼à¿ØºÍÉí·Ý͵ÇÔ±£»£»£»£»¤Ð§ÀÍ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/hsbc-bank-breached-again-suspends-online-access-to-affected-accounts-523620.shtml3¡¢Ñо¿Ö°Ô±ÖÒÑÔ³ÆICS×°±¸Ò×ÊܱßÐŵÀ¹¥»÷µÄÓ°Ïì
Çå¾²Ñо¿Ö°Ô±Demos AndreouÔÚICSÍøÂçÇå¾²´ó»áÉÏÖÒÑԳƱßÐŵÀ¹¥»÷¿ÉÄܶÔICSϵͳ×é³ÉÑÏÖØµÄÍþв¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Andreou¶ÔÅäµçϵͳ³£Óõı£»£»£»£»¤×°±¸µÄÑо¿£¬£¬£¬£¬£¬£¬£¬¾ßÓÐÎïÆÊÎö¼ûȨÏ޵Ĺ¥»÷Õß¿ÉÒÔͨ¹ýʾ²¨Æ÷ºÍÔËÐпªÔ´Èí¼þµÄרÓÃÓ²¼þ×°±¸À´»ñÈ¡¼ÓÃÜÃÜÔ¿£¬£¬£¬£¬£¬£¬£¬´ËÀ๥»÷ËùÐèµÄÓ²¼þ±¾Ç®Ô¼Îª300ÃÀÔª¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷Èý¼ÒÖ÷Òª¹©Ó¦É̵Ä×°±¸¶¼±£´æÎ£º¦£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÕâЩװ±¸ÓÃÓÚ±£»£»£»£»¤µçÍø£¬£¬£¬£¬£¬£¬£¬Òò´ËÕâÖÖ¹¥»÷¿ÉÄÜ»áÔì³ÉÑÏÖØµÄЧ¹û¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/ics-devices-vulnerable-side-channel-attacks-researcher4¡¢Ñо¿Ö°Ô±ÖÒÑÔÄ£ÄâÑ¡¾ÙÐÅÏ¢ÍøÕ¾µÄ´¹ÂÚÍøÕ¾VOTE411.com
Ñо¿Ö°Ô±Amanda RousseauºÍLukas Stefanko·¢Ã÷ÓÃÓÚÄ£ÄâÑ¡¾ÙÐÅÏ¢ÍøÕ¾VOTE411.orgµÄ´¹ÂÚÕ©ÆÍøÕ¾vote411[.]com¡£¡£¡£¡£¡£¡£¡£Ëæ×ÅÃÀ¹úÖÐÆÚÑ¡¾ÙµÄÁÚ½ü£¬£¬£¬£¬£¬£¬£¬·¸·¨·Ö×ÓÔ½À´Ô½¶àµØÕë¶ÔÑ¡Ãñ¾ÙÐд¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸Ã´¹ÂÚÍøÕ¾»á½«macOSºÍiOSƽ̨µÄÓû§Öض¨ÏòÖÁÒ»¸öÐéαµÄ¶ñÒâÈí¼þѬȾ¾¯±¨Ò³Ã棬£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öµä·¶µÄÊÖÒÕÖ§³ÖȦÌ×£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚÓÕʹÓû§¶©ÔĶÌÐÅЧÀÍ»òÆÊØÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÈôÊÇ´ÓWindows»òAndroid»á¼û¸ÃÍøÕ¾£¬£¬£¬£¬£¬£¬£¬Ôò»á±»Öض¨ÏòÖÁ²î±ðµÄ´¹ÂÚÍøÕ¾¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/scammers-ride-on-voter-info-website-popularity-to-push-scareware-alerts/5¡¢¿ªÔ´Á÷ýÌåЧÀÍÆ÷IcecastÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Ò»¸öRCEÎó²î
Çå¾²Ñо¿Ö°Ô±·¢Ã÷¿ªÔ´Á÷ýÌåЧÀÍÆ÷Icecast±£´æÒ»¸öÎó²î£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼Ö»ùÓÚ¸ÃÈí¼þµÄÍøÂç¹ã²¥µç̨Í߽⡣¡£¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2018-18820£©ÊÇÒ»¸öÓësprintfº¯ÊýÓйصĻº³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓöñÒâµÄ³¬³¤HTTPÍ·´¥·¢¸ÃÎó²î£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´Ðлò¾Ü¾øÐ§ÀÍ¡£¡£¡£¡£¡£¡£¡£IcecastÔÚ11ÔÂ1ÈÕÐû²¼µÄа汾2.4.4ÖÐÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/security-bug-puts-online-radio-stations-at-risk/6¡¢Ñо¿ÍŶÓÅû¶Sophos HitmanPro.AlertÖеĶà¸öÇå¾²Îó²î
˼¿ÆTalosÍŶÓÅû¶Sophos HitmanPro.AlertÖеĶà¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£HitmanPro.AlertÊÇÒ»¸ö¶ñÒâÈí¼þ¼ì²âºÍ·À»¤¹¤¾ß£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷µÄÎó²îÓëÊäÈëÊä³ö¿ØÖÆ£¨IOCTL£©ÐÂÎÅ´¦Öóͷ£Àú³ÌÓйأ¬£¬£¬£¬£¬£¬£¬Îó²î£¨CVE-2018-3970£©¿ÉÔÊÐí¹¥»÷Õß¶ÁÈ¡ÄÚºËÄÚ´æÖеÄÄÚÈÝ£¬£¬£¬£¬£¬£¬£¬Îó²î£¨CVE-2018-3971£©¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐкÍÌáȨ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»¹ÑÝʾÁËÔõÑùʹÓøÃÎó²î¹¹½¨exploitÀ´»ñÈ¡ÍâµØSYSTEMȨÏÞ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2018/11/TALOS-2018-0636.htmlÉùÃ÷£º±¾×ÊѶÓÉ918²©ÌìÌÃάËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ