¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181114
°ä²¼¹¦·ò 2018-11-14
ƾ¾ÝGemini Advisory°ä²¼µÄÃÀ¹úÐÅÓþ¿¨Ú²Æ»ã±¨£¬£¬£¬£¬£¬£¬Ö»¹Ü2015ÄêÃÀ¹ú½ðÈÚÒµ¾ÍÒÑ´ó¹æÄ£Ç¨áãµ½EMVоƬ¿¨³ß¶È£¬£¬£¬£¬£¬£¬µ«ÔÚ´Óǰ12¸öÔÂÄÚÈÔÓÐ6000ÍòÕÅÐÅÓþ¿¨µÄÐÅÏ¢±»ÇÔ¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ4580Íò£¨75%£©µÄÐÅÓþ¿¨ÐÅÏ¢ÊÇͨ¹ýPoS»úÉϵÄʵ¿¨ÂòÂô±»ÇԵ쬣¬£¬£¬£¬£¬Ö»ÓÐ25%µÄÐÅÓþ¿¨ÐÅÏ¢±»ÔÚÏßÇÔÈ¡¡£¡£¡£¡£¡£¡£¡£ÕâЩʵ¿¨ÖÐ90%ÊÇEMV¿¨¡£¡£¡£¡£¡£¡£¡£´Óǰ12¸öÔÂÄÚºµç×ÓÉÌÎñÖб»ÇÔµÄÐÅÓþ¿¨ÊýÁ¿Ôö³¤ÁË14%£¬£¬£¬£¬£¬£¬ÕâÒâζÕß·¸×ï·Ö×ÓÔÚ´Óʵ¿¨ÂòÂôתÏòÎÞ¿¨Ú²Æ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://geminiadvisory.io/card-fraud-on-the-rise/2¡¢RiskIQºÍFlashpoint½áºÏ°ä²¼¹ØÓÚMagecart¹¥»÷µÄ·ÖÎö»ã±¨
ƾ¾ÝRiskIQºÍFlashpoint½áºÏ°ä²¼µÄ¡¶Magecart¹¥»÷¶´²ì¡·»ã±¨£¬£¬£¬£¬£¬£¬MagecartÊÇÖÁÉÙ7¸öÍøÂç·¸×ïÍÅ»ïµÄ×ܳơ£¡£¡£¡£¡£¡£¡£Magecart¹¥»÷ͨ¹ýÔÚµç×ÓÉÌÎñÍøÕ¾ÉÏÖ²Èë¶ñÒâ½ÅÕý±¾ÇÔÈ¡Óû§µÄÐÅÓþ¿¨ÐÅÏ¢£¬£¬£¬£¬£¬£¬ÊýÊ®¸öÈ«Çò³ÛÃûÆ·ÅÆµÄµç×ÓÉÌÎñÍøÕ¾¶¼ÊÇËüµÄÊܺ¦Õߣ¬£¬£¬£¬£¬£¬Ô̺¬Ticketmaster¡¢British AirwaysÒÔ¼°Ðµ°µÈ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±Ôڻ㱨Öй¹½¨ÁËMagecart¹¥»÷µÄ¹¦·òÏߣ¬£¬£¬£¬£¬£¬²¢³Áµã½éÉÜÁËËüÃǵĶñÒâ¾ç±¾¡¢¹¥»÷Õ½ÊõÒÔ¼°Ö¸±êÑ¡ÔñµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.riskiq.com/blog/external-threat-management/inside-magecart/3¡¢×êÑÐÍŶӷ¢ÏÖÕë¶Ô°Í»ù˹̹µÄÐÂAPT×éÖ¯The White Company
Cylance×êÑÐÍŶӷ¢ÏÖÒ»¸öÖØÒªÕë¶Ô°Í»ù˹̹µ±¾ÖºÍ¾ü¶ÓµÄÐÂAPT×éÖ¯The White Company£¨°×É«¹«Ë¾£©¡£¡£¡£¡£¡£¡£¡£¸ÃAPT×éÖ¯ËÆºõÊÇÓɹú¶ÈÔÞÖúµÄ£¬£¬£¬£¬£¬£¬Æä´ó¹æÄ£¼äµý»î¶¯±»³ÆÎªOperation Shaheen£¨É³ÐÀÐж¯£©¡£¡£¡£¡£¡£¡£¡£The White CompanyʹÓÃÁ˶àÖÖ¸´ÔӵIJ½ÖèÀ´ÌӱܹéÒò£¬£¬£¬£¬£¬£¬ÀýÈçÌӱܷÀ²¡¶¾Èí¼þ¼ì²â¡¢×ÔÎÒ¸²ÃðºÍ¶Ï¸ùºÛ¼£ÒÔ¼°ÓÐÒâÁôÏÂÏ໥ì¶ÜµÄÖ¤¾ÝµÈ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/the-white-company-a-new-state-sponsored-apt-discovered-by-cylance-523745.shtml
4¡¢×êÑÐÍŶӰ䲼¹ØÓÚжñÒâÍÚ¿óÈí¼þWebCobraµÄ·ÖÎö»ã±¨
McAfee³¢ÊÔÊÒµÄ×êÑÐÈËÔ±·¢ÏÖÒ»¸öжíÂÞ˹¶ñÒâÈí¼þWebCobra£¬£¬£¬£¬£¬£¬WebCobra»áƾ¾ÝËùϰȾµÄϵͳ¼Ü¹¹µÄ·ÖÆç×°ÖÃ·ÖÆçµÄ¶ñÒâÍÚ¿óÈí¼þ£¬£¬£¬£¬£¬£¬Ô̺¬Cryptonight£¨x86£©ºÍClaymore Zcash£¨x64£©¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÒÔΪÕâÖÖ¶ñÒâÈí¼þÊÇͨ¹ýDZÔÚÓк¦µÄ·¨Ê½£¨PUP£©·Ö·¢µÄ£¬£¬£¬£¬£¬£¬ÆäϰȾÁìÓò±é²¼È«Çò£¬£¬£¬£¬£¬£¬µ«ÖØÒªÊÇÔÚ°ÍÎ÷¡¢ÄϷǺÍÃÀ¹ú¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/webcobra-malware-uses-victims-computers-to-mine-cryptocurrency/5¡¢×êÑÐÈËÔ±ÔÚGoogle PlayÉÏ·¢ÏÖ°µ²ØÒ»ÄêÖ®¾ÃµÄ¶ñÒâͨ»°¹àÒôapp
°²È«×êÑÐÈËÔ±Lukas StefankoÔÚGoogle PlayÉÏ·¢ÏÖÒ»¸ö¶ñÒâµÄͨ»°¹àÒôapp£¬£¬£¬£¬£¬£¬¸Ãapp×Ô2017Äê11ÔÂ30ÈÕÆðÔÚGoogle PlayÉÏ¿ÉÓ㬣¬£¬£¬£¬£¬ÒѰµ²ØÁËÔ¼Ò»ÄêµÄ¹¦·ò£¬£¬£¬£¬£¬£¬ÆäÏÂÔØ´ÎÊý³¬¹ý5000´Î¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâapp»á´Óhttp://adsmserver[.]club/up/update.apk£¨¸ÃÁ´½ÓĿǰÒѱ»É¾³ý£©ÏÂÔØÒ»¸öÐéαµÄFlash Player¸üУ¬£¬£¬£¬£¬£¬²¢ºýŪÓû§½øÐÐ×°Öᣡ£¡£¡£¡£¡£¡£ÓÉÓÚÓÐЧºÉÔØÒѲ»³ÉÓ㬣¬£¬£¬£¬£¬×êÑÐÈËԱδÄܽøÇ°½øÒ»²½µÄ·ÖÎö¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/trojanized-android-app-found-on-google-play-with-more-than-5-000-installs-523743.shtml6¡¢Î¢Èí°ä²¼11Ô°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´64¸ö·ì϶
΢Èí°ä²¼11Ô·ݵݲȫ¸üУ¬£¬£¬£¬£¬£¬¹²½¨¸´64¸ö·ì϶£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬12¸ö¸ßΣ·ì϶¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÓÉ¿¨°Í˹»ù³¢ÊÔÊһ㱨µÄÁãÈÕ·ì϶£¨CVE-2018-8589£©Òѱ»¹¥»÷ÕßÔÚÒ°±í»ý¼«ÀûÓᣡ£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÒ»¸öÌáȨ·ì϶£¬£¬£¬£¬£¬£¬ÓëWindowsÉ豸Çý¶¯·¨Ê½Win32k.sysÓйء£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿£¿¨°Í˹»ù´òËãÓÚÖÜÈý°ä²¼¹ØÓڸ÷ì϶±»APT×éÖ¯»ý¼«ÀûÓõĸü¶àÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¾ßÌå·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-november-2018-patch-tuesday-fixes-12-critical-vulnerabilities/ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ