¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180903

°ä²¼¹¦·ò 2018-09-03

¡¾Íþвµý±¨¡¿×êÑÐÅúעȫÇòǰ100Íò¸öÍøÕ¾ÖÐ51.8%ÒÑʹÓÃHTTPS


ƾ¾Ý×êÑÐÈËÔ±Scott Helme¶ÔÈ«Çò×î³£½Ó¼ûµÄAlexaǰ100Íò¸öÍøÕ¾µÄ·ÖÎö£¬£¬£¬ £¬£¬£¬51.8%µÄÍøÕ¾ÒÑʹÓÃHTTPS£¬£¬£¬ £¬£¬£¬¶øÕâÒ»Êý×ÖÔÚÁù¸öÔÂǰÊÇ38.4%¡£¡£¡£¡£¡£ÕâÒ»Ôö³¤µÄ²¿ÃÅÔ­Òò¹é¹¦ÓÚChrome´Ó7ÔÂ·ÝÆðÍ·½«HTTPÍøÕ¾ÏóÕ÷Ϊ²»°²È«µÄÍøÕ¾¡£¡£¡£¡£¡£HelmeµÄÆäËü·¢ÏÖ»¹Ô̺¬£ºÄÚÈݰ²È«Õ½ÊõCSPºÍHTTPÑϸñ´«Ê䰲ȫHSTSµÄʹÓÃÂÊÏÔÖøÔö³¤£¬£¬£¬ £¬£¬£¬±ðÀëΪ40%ºÍ23%£»£»£»£»£»£»¼ÓÃÜËã·¨RSAÒÀÈ»ÊÇ×îÊÜ»¶Ó­µÄÑ¡Ôñ£¬£¬£¬ £¬£¬£¬¼´±ãÍÖÔ²ÇúÏßECDSAÔ½·¢°²È«¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/over-50-of-top-global-sites-now-on/


¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±ÑÝʾÓÃÓÚÇÔÈ¡ÊÖ»úÁé¸ÐÐÅÏ¢µÄÉùѧ±ßÐÅ·¹¥»÷SonarSnoop


À´×ÔÀ¼¿¨Ë¹ÌØ´óѧºÍÁÖѩƽ´óѧµÄÒ»¸ö×êÑÐÍŶÓÑÝʾÓÃÓÚÇÔÈ¡ÊÖ»úÁé¸ÐÐÅÏ¢µÄÉùѧ±ßÐÅ·¹¥»÷SonarSnoop¡£¡£¡£¡£¡£SonarSnoop½«ÖÇÄÜÊÖ»úµ±³öÉùÄÉϵͳ£¬£¬£¬ £¬£¬£¬»ùÓÚÓû§ÊÖÖ¸ÔÚÆÁÄ»ÉϵÄÒÆ¶¯À´ÇÔÊØÐÅÏ¢¡£¡£¡£¡£¡£¸Ã¹¥»÷·½Ê½ÒÀÀµÓÚÊÖ»úÑïÉùÆ÷·¢³öµÄÉùÒôÒÔ¼°Âó¿Ë·çÍøÂçµ½µÄ»ØÉù£¬£¬£¬ £¬£¬£¬Ëü²¢²»±ØÒªÆÚ´ýÓû§²úÉúÉùÒôÐźÅ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/sonarsnoop-acoustic-side-channel-attack-can-steal-touchscreen-interactions/


¡¾Íþвµý±¨¡¿°²È«×êÑÐÈËÔ±ÑÝʾÕë¶ÔTPMоƬµÄÁ½ÖÖй¥»÷¼¼Êõ


º«¹ú¹ú¶È°²È«×êÑÐËùµÄ4Ãû×êÑÐÈËÔ±ÑÝʾÕë¶ÔTPMоƬµÄÁ½ÖÖй¥»÷¼¼Êõ¡£¡£¡£¡£¡£TPM£¨¿ÉÐÅÆ½Ì¨Ä£¿£¿£¿£¿£¿£¿£¿é£©Í¨³£²¿ÊðÔڸ߼ÛÖµµÄÍÆËã»úÉÏ£¬£¬£¬ £¬£¬£¬ÀýÈçÆóÒµ»òµ±¾ÖÍøÂçÖеÄÍÆËã»ú¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖµÄÕâÁ½¸ö·ì϶£¬£¬£¬ £¬£¬£¬SRTM·ì϶£¨CVE-2018-6622£©ºÍDRTM£¨tboot£©·ì϶£¨CVE-2017-16837£©¶¼±ØÒª¶ÔÉ豸½øÐÐÎïÀí½Ó¼û£¬£¬£¬ £¬£¬£¬µ«ÕⲢûÓнµµÍËüÃǵÄΣÏÕÐÔ¡£¡£¡£¡£¡£ÓйØÓû§±ØÒªÊµÊ±×°Öù̼þ¸üС£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/researchers-detail-two-new-attacks-on-tpm-chips/


¡¾¶ñÒâÈí¼þ¡¿Check Point°ä²¼¹ØÓÚCEIDPageLock rootkitµÄ·ÖÎö»ã±¨


Check Point×êÑÐÈËÔ±°ä²¼¹ØÓÚCEIDPageLock rootkitµÄ·ÖÎö»ã±¨£¬£¬£¬ £¬£¬£¬CEIDPageLockÓÉRIG EK·Ö·¢£¬£¬£¬ £¬£¬£¬ÖØÒªÕë¶ÔÖйú¡£¡£¡£¡£¡£CEIDPageLockÖØÒªÓÃÓÚ½Ù³ÖÓû§ä¯ÀÀÆ÷µÄÖ÷Ò³£¬£¬£¬ £¬£¬£¬½«Óû§³Á¶¨ÏòÖÁ¸æ°×ÍøÕ¾2345.com¶ø²»Å¤×ªä¯ÀÀÆ÷ÖÐÏÔʾµÄURL¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÕâÖÖ¸æ°×ÊÕÈë»ñÀû£¬£¬£¬ £¬£¬£¬²¢ÍøÂçÓû§µÄÍøÕ¾½Ó¼û¼Í¼ÒÔ½øÐо«×¼¸æ°×ÍÆËÍ»òÏúÊÛÕâЩÊý¾Ý¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://research.checkpoint.com/ceidpagelock-a-chinese-rootkit/


¡¾¶ñÒâÈí¼þ¡¿°²È«×êÑÐÍŶӷ¢ÏÖÖ»¼ÓÃÜexeÎļþµÄÐÂÀÕË÷Èí¼þ


MalwareHunterTeam·¢ÏÖÒ»¸öеÄÖ»¼ÓÃÜexeÎļþµÄÀÕË÷Èí¼þ£¬£¬£¬ £¬£¬£¬¸ÃÀÕË÷Èí¼þÓÐÒ»¸öÆæ¹ÖµÄ±êÌ⣺°Â°ÍÂíµÄÓÀºãÖ®À¶ÀÕË÷²¡¶¾¡£¡£¡£¡£¡£Ä¿Ç°»¹²»Ã÷ÏÔ¸ÃÀÕË÷Èí¼þµÄ·Ö·¢·½Ê½¡£¡£¡£¡£¡£¸ÃÀÕË÷Èí¼þÔÚϰȾϵͳºó»áɱËÀ¿¨°Í˹»ù¡¢McAfeeºÍÈðÐǵÈɱ¶¾Èí¼þµÄ¹ý³Ì£¬£¬£¬ £¬£¬£¬²¢ÏÔʾһÕ۰ÍÂíµÄͼƬ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/barack-obamas-blackmail-virus-ransomware-only-encrypts-exe-files/


¡¾·ì϶²¹¶¡¡¿×êÑÐÈËÔ±·¢ÏÖFiservƽ̨´æÔÚ°²È«·ì϶£¬£¬£¬ £¬£¬£¬¿Éµ¼ÖÂÊý°Ù¼ÒÒøÐеÄÓû§ÐÅϢй¶


°²È«×êÑÐÈËÔ±Kristian Erik Hermansen·¢ÏÖ½ðÈÚ»ú¹¹¼¼Êõ·þÎñÌṩÉÌFiservµÄÍøÂçÆ½Ì¨´æÔÚ·ì϶£¬£¬£¬ £¬£¬£¬¿Éµ¼ÖÂÊý°Ù¼ÒÒøÐеÄÊý¾Ýй¶¡£¡£¡£¡£¡£FiservûÓÐÃ÷È·×¢Ã÷Óм¸¶à½ðÈÚ»ú¹¹¿ÉÄÜÊܵ½Ó°Ï죬£¬£¬ £¬£¬£¬µ«¾Ý±¨Â·Ä¿Ç°ÓÐ1700¼ÒÒøÐÐÔÚʹÓÃFiservƽ̨¡£¡£¡£¡£¡£Fiserv½²»°È˳Ƹù«Ë¾ÔÚÊÕµ½»ã±¨ºó24Ó×ʱÄÚ¿ª·¢Á˽¨¸´²¹¶¡²¢½øÐÐÁ˲¿Ê𡣡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/hundreds-of-banks-exposed-from/