¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181123

°ä²¼¹¦·ò 2018-11-23
1¡¢VMware°ä²¼¸üУ¬£¬£¬ £¬£¬£¬½¨¸´Ðé¹¹»úÌÓÒÝ·ì϶CVE-2018-6983

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


VMware½¨¸´Ì츮±­ÉÏÅû¶µÄÐé¹¹»úÌÓÒÝ·ì϶£¨CVE-2018-6983£©£¬£¬£¬ £¬£¬£¬¸Ã·ì϶ÊÇÒ»¸öÕûÊýÒç¶Âí½Å£¬£¬£¬ £¬£¬£¬³É¹¦ÀûÓø÷ì϶¿Éµ¼ÖÂÐé¹¹»úÌÓÒݲ¢ÔÚËÞÖ÷»úÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬VMware Workstation¡¢VMware FusionµÈ£¬£¬£¬ £¬£¬£¬VMwareÔÚWorkstation°æ±¾ 14.1.2/15.0.2¼°Fusion°æ±¾10.1.5/11.0.2Öн¨¸´Á˸÷ì϶£¬£¬£¬ £¬£¬£¬½¨ÒéÓû§¾¡¿ì½øÐиüС£¡£¡£¡£¡£

  

 Ô­ÎÄÁ´½Ó£º

https://www.vmware.com/security/advisories/VMSA-2018-0030.html


2¡¢µÂ¹úÉí·ÝÖ¤RFIDоƬ±»ÆØ´æÔÚ·ì϶£¬£¬£¬ £¬£¬£¬¿ÉÓÃÓÚαÔìÉí·Ý

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°²È«³§ÉÌSEC Consult±¾ÖÜÅû¶µÂ¹úRFIDоƬÉí·ÝÖ¤ÖеÄÒ»¸ö°²È«·ì϶£¬£¬£¬ £¬£¬£¬¸Ã·ì϶¿ÉÔÊÐí¹¥»÷ÕßαÔì×Ô¼ºµÄÉí·Ý¡£¡£¡£¡£¡£µÂ¹ú´Ó2010ÄêÆðͷʹÓÃÕâÖÖ´øÓÐÉ䯵¼ø±ð£¨RFID£©Ð¾Æ¬µÄÊý×ÖÉí·ÝÖ¤£¬£¬£¬ £¬£¬£¬²¢ÔÚоƬÖд洢¹«ÃñµÄÉí·ÝÊý¾Ý£¬£¬£¬ £¬£¬£¬Ô̺¬ÐÕÃû¡¢ÉúÈÕ¡¢ÕÕÆ¬µÈ£¬£¬£¬ £¬£¬£¬¿Éͨ¹ýÏàÓ¦µÄ¿Í»§¶ËÈí¼þ£¨eID client£©¶ÁȡоƬÊý¾Ý²¢½øÐÐÏßÉÏÈÏÖ¤¡£¡£¡£¡£¡£×êÑÐÈËÔ±Wolfgang Ettlinger·¢´Ë¿ÌÕâ¸ö¹ý³ÌÖÐÄܹ»Ê¹ÓÃαÔìµÄÊý¾ÝÈÆ¹ý·þÎñÆ÷µÄ±£»£»£» £»£»£»£»¤£¬£¬£¬ £¬£¬£¬´Ó¶øµ÷»»Éí·Ý¡£¡£¡£¡£¡£GovernikusÒÑÔÚ2018Äê8Ô·ݰ䲼µÄAutent SDK 3.8.1.2Öн¨¸´Á˸÷ì϶¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/german-eid-authentication-flaw-lets-you-change-identity/


3¡¢×êÑÐÍŶӷ¢ÏÖÓÃÓÚ·Ö·¢AzorultľÂíµÄжñÒâ»î¶¯FindMyName

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Palo Alto NetworksµÄUnit42×êÑÐÍŶӴÓ2018Äê10ÔÂ20ÈÕÆð¹Û²ìµ½ÓÃÓÚ·Ö·¢AzorultľÂíбäÌåµÄ¶ñÒâ»î¶¯FindMyName¡£¡£¡£¡£¡£¸Ã»î¶¯µÃÃûÓÚÆäʹÓõÄÓòÃûfindmyname[.]pw¡£¡£¡£¡£¡£¸ÃAzorult±äÌåͨ¹ýFallout EK½øÐзַ¢£¬£¬£¬ £¬£¬£¬×êÑÐÈËԱͨ¹ý¶ÈÎö·¢ÏָöñÒâÑù±¾Ê¹ÓÃÁ˸߼¶»ìºÏ¼¼ÊõÒÔÌӱܼì²â¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬£¬×êÑÐÈËÔ±»¹·¢ÏÖAzorultÓÖÓÐËùÑݱ䣬£¬£¬ £¬£¬£¬Æä´Ë¿ÌÖ§³Ö´Ó¸ü¶àµÄä¯ÀÀÆ÷¡¢ÀûÓ÷¨Ê½ºÍ¼ÓÃÜÇ®±ÒÇ®°üÖÐÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://researchcenter.paloaltonetworks.com/2018/11/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit/


4¡¢°²È«³§ÉÌ·¢ÏÖ¿ÉÕë¶ÔLinux·þÎñÆ÷µÄMirai±äÌåBotmasters

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ArborµÄASERT×êÑÐÍŶӷ¢ÏÖÒ»¸öеÄMirai±äÌå´Ë¿ÌÄܹ»Ï°È¾Linux·þÎñÆ÷ÁË£¬£¬£¬ £¬£¬£¬¸Ã±äÌåÊÇBotmasters£¬£¬£¬ £¬£¬£¬Í¨¹ý½«¹¥»÷Ö¸±ê´ÓIoTÉ豸ת±äΪÉÌÓÃLinux·þÎñÆ÷£¬£¬£¬ £¬£¬£¬Botmasters²»ÔÙ±ØÒªÎª·ÖÆçµÄ¼Ü¹¹½øÐвüô£¬£¬£¬ £¬£¬£¬¶øÊÇÄܹ»¼Ù¶¨¹¥»÷Ö¸±êΪx86ƽ̨¡£¡£¡£¡£¡£Ò»Ð©¹¥»÷ÕßÔÚʹÓö¨ÔìµÄ¹¤¾ßͨ¹ýHadoop YARN·ì϶·Ö·¢¸Ã¶ñÒâÈí¼þ¡£¡£¡£¡£¡£ÓÉÓÚÉÌÓÃLinux·þÎñÆ÷µÄ´ø¿íÒª±ÈIoTÉ豸Ҫ´óµÃ¶à£¬£¬£¬ £¬£¬£¬Òò¶ø¸Ã¶ñÒâÈí¼þ¿É¹¹½¨Ð§Äܸü¸ßµÄDDoS½©Ê¬ÍøÂ磬£¬£¬ £¬£¬£¬Æä·çÏÕ²»ÈÝÓ×êï¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://asert.arbornetworks.com/mirai-not-just-for-iot-anymore/


5¡¢×êÑÐÍŶӷ¢ÏÖÖØÒªÕë¶Ô¶íÂÞ˹µÄÐÂRotexyľÂí

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¿¨°Í˹»ù³¢ÊÔÊÒ·¢ÏÖÖØÒªÕë¶Ô¶íÂÞ˹µÄRotexyľÂíбäÌ壬£¬£¬ £¬£¬£¬ÔÚ2018Äê8ÔÂÖÁ10ÔµÄÈý¸öÔÂÄÚ£¬£¬£¬ £¬£¬£¬¸Ã±äÌå×ܹ²Ïò¶íÂÞ˹Óû§ÌáÒéÁË7ÍòÂŴι¥»÷¡£¡£¡£¡£¡£RotexyľÂí¼Ò×åµÄÒ»¸öÓÐÈ¤ÌØµãÊÇͬʱʹÓÃÁËÈýÖÖºÅÁîÔ´£¬£¬£¬ £¬£¬£¬Ô̺¬¹È¸èÔÆÍÆËÍ·þÎñ£¨GCM£©-ÓÃÓÚ½«JSONÌåʽµÄÐÅÏ¢·¢ËÍÖÁÒÆ¶¯É豸¡¢C&C·þÎñÆ÷ÒÔ¼°¶ÌÐÅ¡£¡£¡£¡£¡£ÕâÊǸÃľÂí¼Ò×åµÄÒ»¸öÌØÉ«¡£¡£¡£¡£¡£RotexyµÄбäÌå×ÛºÏÁËÒøÐÐľÂíºÍÀÕË÷Èí¼þµÄÖ°ÄÜ£¬£¬£¬ £¬£¬£¬ËüÒÔAvitoPay.apkµÄÃû³Æ´«²¼£¬£¬£¬ £¬£¬£¬´Óyoula9d6h.tk¡¢prodam8n9.tk¡¢prodamfkz.ml¡¢avitoe0ys.tkµÈÍøÕ¾ÏÂÔØ¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securelist.com/the-rotexy-mobile-trojan-banker-and-ransomware/88893/


6¡¢×êÑÐÍŶӷ¢ÏÖÐÂÔöPoS¶ñÒâÄ £¿ £¿£¿£¿£¿£¿£¿£¿éµÄTrickBotбäÌå

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ç÷Ïò¿Æ¼¼µÄ×êÑÐÍŶӷ¢ÏÖÒøÐÐľÂíTrickBotÐÂÔöÁËÒ»¸öPoS¶ñÒâÄ £¿ £¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬ £¬£¬£¬Ê¹Æä±äµÃÔ½·¢Î£ÏÕ¡£¡£¡£¡£¡£¸ÃÄ £¿ £¿£¿£¿£¿£¿£¿£¿éÓÃÓÚɨÃèÊÜϰȾµÄÍÆËã»úÊÇ·ñÏνӵ½ÈκÎÖ§³ÖPoS·þÎñµÄÉ豸ºÍÍøÂ磬£¬£¬ £¬£¬£¬²¢ÍøÂçÓйØÐÅÏ¢¡£¡£¡£¡£¡£×êÑÐÈËÔ±»¹ÔÚµ÷²é¹¥»÷ÕßÈôºÎÀûÓÃÕâЩÐÅÏ¢£¬£¬£¬ £¬£¬£¬µ«¿ÉÄܵÄÇé¿öÊǹ¥»÷ÕßÔÚÍøÂçÐÅÏ¢ÒÔΪ½«À´µÄÈëÇÖ×ö³ï±¸¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.trendmicro.com/trendlabs-security-intelligence/trickbots-bigger-bag-of-tricks/


ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù