¶íÂÞ˹з¨°¸Ç¿ÔìÊÖ»úºÍPCԤװÖñ¾¹úÈí¼þ£»£»£»£»£»£»£»£»¿¨°Í˹»ù°ä²¼2019ÄêQ3 DDoS¹¥»÷»ã±¨
°ä²¼¹¦·ò 2019-11-121¡¢¶íÂÞ˹з¨°¸Ç¿ÔìÊÖ»úºÍPCԤװÖñ¾¹úÈí¼þ
¶íÂÞ˹Òé»áÔÚÍÆ¶¯Ò»ÏîÁ¢·¨£¬£¬£¬£¬£¬£¬£¬¸Ã·¨°¸½«Ç¿ÔìÒªÇóËùÓÐÔÚ¶íÂÞ˹ÏúÊ۵ĵç×ÓÉ豸£¨Ô̺¬ÖÇÄÜÊÖ»ú¡¢PCºÍÖÇÄܵçÊӵȣ©Ô¤×°Öñ¾¹ú¿Æ¼¼¹«Ë¾µÄÀûÓᣡ£¡£¡£¡£Õâ¿ÉÄÜ»á´øÀ´°²È«Òþ»¼¡£¡£¡£¡£¡£Á¢·¨Õß°µÊ¾¸Ã·¨°¸ÊÇΪÁ˱£»£»£»£»£»£»£»£»¤±¾µØµÄ¼¼ÊõÊг¡ÃâÊܱí¹ú£¨¿ÉÄÜÊÇÖ¸ÃÀ¹ú£©µÄ¾ºÕù¡£¡£¡£¡£¡£µ±¾Ö½«Õë¶ÔÿÖÖÉ豸ÀàÐͰ䲼һ·ÝÈí¼þÁÐ±í£¬£¬£¬£¬£¬£¬£¬É豸¹©¸øÉ̱ØÒªÔÚ¶íÂÞ˹ÏúÊÛµÄÉ豸ÉÏԤװÖÃÕâЩÈí¼þ¡£¡£¡£¡£¡£ÈôÊǹ©¸øÉ̲»×ñÊØ»®¶¨£¬£¬£¬£¬£¬£¬£¬½«±»´¦ÒÔ×î¸ß20Íò¬²¼£¨Ô¼ºÏ3100ÃÀÔª£©µÄ·£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£¸Ã·¨°¸µÃµ½ÁËËùÓÐÖØÒªÕþµ³µÄÖ§³Ö£¬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅËüºÜÓпÉÄܽ«ÔÚ2020Äê7ÔÂ1ÈÕÉúЧ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/phones-and-pcs-sold-in-russia-will-have-to-come-pre-installed-with-russian-apps/
2¡¢¿¨°Í˹»ù°ä²¼2019ÄêQ3 DDoS¹¥»÷»ã±¨
¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼2019ÄêµÚÈý¼¾¶ÈµÄDDoS¹¥»÷¶¯Ì¬»ã±¨¡£¡£¡£¡£¡£Æ¾¾Ý¸Ã»ã±¨£¬£¬£¬£¬£¬£¬£¬DDoS¹¥»÷ÔÚ½ñÄê³ÖÐøÎ¬³ÖÔö³¤Ì¬ÊÆ£¬£¬£¬£¬£¬£¬£¬µ«¼¼Êõ¸üÏȽøµÄÖÇÄÜÐ͹¥»÷·´¶øÓÐËù½µÂä¡£¡£¡£¡£¡£¿£¿£¿£¿£¿¨°Í˹»ùÔ¤²âDDoSÊг¡½«±äµÃ¹ÄºÍ²¢ÖÕ³¡Ôö³¤£¬£¬£¬£¬£¬£¬£¬ÈôÊǸýáÂÛÕýÈ·£¬£¬£¬£¬£¬£¬£¬µÚËÄʱ¶ÈµÄ¹Ø¼üÖ¸±êÔö³¤½«²»»áÄÇô¿É¹Û¡£¡£¡£¡£¡£ÆßÔ·ÝÊDZ¾¼¾¶ÈDDoS»î¶¯µÄ¶¥·åʱÆÚ£¬£¬£¬£¬£¬£¬£¬×î³£¼ûµÄ¹¥»÷ÀàÐÍÒÀÈ»ÊÇSYN·ººé£¨79.7%£©£¬£¬£¬£¬£¬£¬£¬Linux½©Ê¬ÍøÂçÒÀȻռ¹¥»÷»î¶¯µÄ¾ø´óÎÞÊý£¨97.75%£©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/ddos-report-q3-2019/94958/
3¡¢ÀÕË÷Èí¼þ¼´·þÎñBuran»ý¼«ÔÚ°µÍøÂÛ̳´«²¼
ƾ¾ÝMcAfee×êÑÐÈËÔ±Alexandre MundoºÍMarc RiveroµÄ·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬ÐµÄÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©BuranÔÚ°µÍøÂÛ̳ÉÏ»ý¼«´«²¼¡£¡£¡£¡£¡£BuranÔËÓªÕßËÆºõÕýÖÂÁ¦Óë·¸×ï¿Í»§³ÉÁ¢Ó×ÎÒ¹ØÏµ£¬£¬£¬£¬£¬£¬£¬ËüÃÇÔÚ´òÕÛÏúÊÛÒÔÎüÒý¸ü¶à·¸×ï·Ö×Ó¡£¡£¡£¡£¡£×ÜÌå¶øÑÔ£¬£¬£¬£¬£¬£¬£¬Buran×÷ÕßÖ»Õ¼¾ÝϰȾÊÕÈëÖеÄ25£¥£¬£¬£¬£¬£¬£¬£¬Õâ±ÈRaaSÔËÓªÕßͨ³£ÒªÇóµÄ30%-40%ÒªµÍµÄ¶à¡£¡£¡£¡£¡£¸ÃRaaSÊÔͼͨ¹ýÕâÖÖ·½Ê½ÓëÆäËüµÐÊÖ½øÐоºÕù¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/vegalocker-evolves-into-buran-ransomware-as-a-service/
4¡¢´¹µö»î¶¯¼Ù×°³ÉÓ¢¹ú˾·¨²¿´«²¼Predator the Thief
Cofense×êÑÐÈËÔ±·¢ÏÖÒ»¸öеÄÍøÂç´¹µö»î¶¯¼Ù×°³ÉÓ¢¹ú˾·¨²¿´«²¼¶ñÒâÈí¼þPredator the Thief¡£¡£¡£¡£¡£¸Ã´¹µöÓʼþÖÐÔ̺¬Î±ÔìµÄ·¨Ôº´«Æ±²¢´øÓÐÓ¢¹ú˾·¨²¿»Õ±ê£¬£¬£¬£¬£¬£¬£¬ÒªÇóÊܺ¦Õßµã»÷Á´½ÓÒÔÏàʶ°¸¼þÐÅÏ¢¡£¡£¡£¡£¡£µ±Êܺ¦Õßµã»÷Á´½Óºó£¬£¬£¬£¬£¬£¬£¬½«»á´ÓÔÆ·þÎñÉÌ´¦ÏÂÔØÔ̺¬Predator the ThiefµÄÎĵµ¡£¡£¡£¡£¡£Predator the ThiefÊÇÔÚ°µÍøÂÛ̳ÉÏÏúÊÛµÄÒ»ÖÖ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬ËüÄܹ»ÇÔÈ¡Óû§Ãû¡¢ÃÜÂë¡¢ä¯ÀÀÆ÷Êý¾ÝºÍ¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢µÈ£¬£¬£¬£¬£¬£¬£¬»¹Äܹ»Ê¹ÓÃÉãÏñÍ·½øÐÐÅÄÕÕ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÓÚ2018Äê7Ô³õ´Î³öÏÖ¡£¡£¡£¡£¡£¸Ã´¹µö»î¶¯ÖØÒªÕë¶Ô±£ÏÕÒµºÍÁãÊÛÒµµÄÔ±¹¤¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/phishing-campaign-delivers-data-stealing-malware-via-fake-court-summons-emails/
5¡¢AdobeÒÆ¶¯SDKÖеÄĬÈÏÅäÖôæÔÚ°²È«·çÏÕ
Nightwatch Cybersecurity·¢ÏÖAdobeµÄÒÆ¶¯Èí¼þ¿ª·¢Ì×¼þ£¨SDK£©¸½´øµÄʾÀýÅäÖÃÎļþ´æÔÚ°²È«·çÏÕ£¬£¬£¬£¬£¬£¬£¬Adobe×î½ü°ä²¼ÁËSDKµÄ¸üа汾½¨¸´¸ÃÎÊÌâ¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌṩµÄSDK×÷Ϊģ°å£¬£¬£¬£¬£¬£¬£¬¿É¹©¿ª·¢ÈËÔ±ÔÚ¸÷ÀàÆ½Ì¨´ó½«ÆäÀûÓ÷¨Ê½ÓëAdobeµÄÔÆ·þÎñ¼¯³ÉÔÚһ·¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÔìäÖ÷ÀûÓ÷¨Ê½ÅäÖÃÎļþADBMobileConfig.jsonÔ̺¬¿ÉÄܵ¼Ö°²È«ÎÊÌâµÄÉèÖ㬣¬£¬£¬£¬£¬£¬ÕâЩÎÊÌâÖØÒªÓëSSL/HTTPSÉèÖÃÓйأ¬£¬£¬£¬£¬£¬£¬Ô̺¬Ä¬ÈϹعطÖÎöÉèÖá¢Ïνӵ½mediaHeartbeat¶ÔÏóµÄÊý¾Ý´«Êä´¦ÓÚÒ»ÑùµÄ²»°²È«×´Ì¬¡¢Ä¬Èϲ»Ê¹ÓÃSSLÏνӵȡ£¡£¡£¡£¡£×êÑÐÈËÔ±×ܹ²ÔÚ·ÖÆçµÄƽ̨ÉÏ·¢ÏÖÁË28¸öÄ£°å£¬£¬£¬£¬£¬£¬£¬Ò»Ð©¿ª·¢ÈËÔ±Ò»ÏòÔÚ×Ô¼ºµÄÀûÓ÷¨Ê½ÖÐʹÓÃÕâЩÅäÖÃÎļþ£¬£¬£¬£¬£¬£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»²é¿´»òÅú¸ÄÓÉÀûÓ÷¨Ê½´«Ê仨AdobeÔÆ·þÎñµÄÐÅÏ¢¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://nakedsecurity.sophos.com/2019/11/11/adobe-fixes-sdk-weakness-affecting-mobile-apps/
6¡¢Check Point ZoneAlarm²úÆ·ÂÛ̳Óû§Êý¾Ýй¶
ÒÔÉ«Áа²È«³§ÉÌCheck PointÆìϵÄZoneAlarmÂÛ̳Óû§Êý¾Ýй¶¡£¡£¡£¡£¡£Ö»¹ÜZoneAlarm¼°Check PointÉÐδ¹«¿ªÅû¶´ËÊÂÎñ£¬£¬£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾ÒѾͨ¹ýµç×ÓÓʼþÏòÓû§·¢ËÍÁ˾¯±¨¡£¡£¡£¡£¡£Óʼþ֪ͨÖаµÊ¾ºÚ¿Íδ¾ÊÚȨ»ñÈ¡ÁËÂÛ̳Óû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢¹þÏ£ÃÜÂëºÍÉúÈյĽӼûȨÏÞ£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§Á¢¿Ì¸ü¸ÄÆäÃÜÂë¡£¡£¡£¡£¡£¸Ã¹«Ë¾»¹³ÎÇå˵ֻÓÐÔÚ¡°forums.zonealarm.com¡±ÓòÖÐ×¢²áµÄÓû§£¨Ô¼Îª4500ÈË£©Êܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬¸ÃÂÛ̳ÊÇÒ»¸öµ¥¶ÀµÄÍøÕ¾£¬£¬£¬£¬£¬£¬£¬²»»áÓ°ÏìCheck PointµÄÈÎºÎÆäËüÍøÕ¾¡£¡£¡£¡£¡£¸ÃÊÂÎñµÄÔÒòÓëvBulletin֮ǰ½¨¸´µÄRCE 0day£¨CVE-2019-16759£©Óйء£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/11/zonealarm-forum-data-breach.html


¾©¹«Íø°²±¸11010802024551ºÅ