¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181204
°ä²¼¹¦·ò 2018-12-04
Ó¢¹úSoutheby£¨ËÕ¸»±È£©ÅÄÂôÐа䷢Æäµç×ÓÉÌÎñÍøÕ¾Sotheby's Home³ÉΪMagecartµÄ×îÐÂÊܺ¦Õß¡£¡£¡£¡£¡£SouthebyÓÚ10ÔÂ10ÈÕ·¢ÏÖ²¢É¾³ýÁ˸ÃÍøÕ¾ÉϵĵÚÈý·½¶ñÒâ´úÂ룬£¬£¬£¬£¬£¬È»¶ø£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâ¾ç±¾ÖÁÉÙÓÚ2017Äê3ÔÂÒÔÀ´Ò»Ïò´æÔÚ£¬£¬£¬£¬£¬£¬ÕâÒâζ×Å´Óǰ19¸öÔÂÄÚÎÞÊý¿Í»§¿ÉÄÜÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¸Ã¶ñÒâ¾ç±¾ÓÃÓÚÇÔÈ¡Óû§ÊäÈëµÄÖ§¸¶ÐÅÏ¢£¬£¬£¬£¬£¬£¬Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·ºÍÐÅÓþ¿¨ºÅ¡¢µ½ÆÚÈÕÆÚÒÔ¼°CVVÂëµÈ¡£¡£¡£¡£¡£ÀàËÆÓÚÓ¢¹úº½¿Õ¹«Ë¾ºÍе°ÍøµÄ¹¥»÷ÊÂÎñ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßËÆºõÊÇÖ±½ÓϰȾµÄ¸ÃÍøÕ¾¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/southebys-site-infected-magecart/2¡¢¿¨°Í˹»ù°ä²¼2018Äê³Á´ó°²È«Íþв×ÛÊö£¬£¬£¬£¬£¬£¬º¸Ç¶à¸ö¹¥»÷Àà±ð
¿¨°Í˹»ùµÄ2018Äê³Á´ó°²È«Íþв×ÛÊöº¸ÇÁËÕë¶ÔÐÔ¹¥»÷¡¢Òƶ¯APTÍþв¡¢³ÁÒª·ì϶¡¢¶ñÒâä¯ÀÀÆ÷²å¼þ¡¢ÊÀ½ç±Ú²Æ»î¶¯¡¢Õë¶ÔICSµÄ½ðÈÚڲơ¢ÀÕË÷Èí¼þ¡¢ÒøÐÐľÂí¡¢ÖÇÄÜÉ豸ÒÔ¼°Ó×ÎÒÐÅϢй¶µÈÀà±ð¡£¡£¡£¡£¡£Ëæ×Å»¥ÁªÍøÈÚÈëÁËÈËÃǵÄÉúÑÄ£¬£¬£¬£¬£¬£¬¹¥»÷ÕߵĹ¥»÷ÃæÒ²Ô½À´Ô½¿í·º£¬£¬£¬£¬£¬£¬Ô̺¬½ðÈÚ͵ÇÔ¡¢Êý¾ÝÇÔÈ¡ÒÔ¼°ÃûÍûÇÖº¦µÈ¡£¡£¡£¡£¡£¹¥»÷ÕßµÄÖ¸±êÉ豸ԽÀ´Ô½¶àµØÖ¸Ïò·ÇÍÆËã»úÀàµÄÉ豸£¬£¬£¬£¬£¬£¬´Ó¶ùͯÖÇÄÜÍæ¾ßµ½ÍøÂçÉãÏñÓŵȡ£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/kaspersky-security-bulletin-2018-top-security-stories/89118/3¡¢RiskIQ°ä²¼2019ÄêÍøÂçÍþвԤ²â£¬£¬£¬£¬£¬£¬PII½«³ÉÎªÖØÒª¹¥»÷Ö¸±ê
ƾ¾ÝRiskIQµÄ2019ÄêÍøÂçÍþвԤ²â»ã±¨£¬£¬£¬£¬£¬£¬ÍþвÇ÷ÏòµÄ±ä¶¯½«Ô̺¬£ºPII½«³ÉÎªÖØÒªµÄ¹¥»÷Ö¸±ê£¬£¬£¬£¬£¬£¬2018Äêͨ¹ýjs¾ç±¾ÇÔÊØÐÅÓþ¿¨ÐÅÏ¢µÄ»î¶¯´ó·¢×÷£¬£¬£¬£¬£¬£¬Ô¤¼Æ2019ÄêÕâÖÖ²½Ö轫»áÀ©´óµ½Õë¶ÔPIIºÍIP£»£»£»£»£»£»£»£»¹¥»÷Õß½«»á³ÖÐø·¢ÏÖºÍÕë¶ÔÆóÒµ·À»ðǽ֮±íµÄäµã£¬£¬£¬£¬£¬£¬ÀýÈçµÚÈý·½¹ºÎï³µÈí¼þºÍÊý¾ÝÍøÂ繤¾ß£»£»£»£»£»£»£»£»ÈÝÆ÷ºÍÎÞ·þÎñÆ÷ÍÆËãµÈм¼Êõ½«Îª¹¥»÷ÕßÌṩ¸ü¶à°µ²ØµÄ´¦Ëù£»£»£»£»£»£»£»£»¹ú¶ÈÖ§³ÖµÄÍøÂç¹¥»÷»î¶¯½«¼Ó¾ç£»£»£»£»£»£»£»£»¹¥»÷Õß½«Ôö³¤Æ¥µÐ»úе½ø½¨¼¼ÊõµÄѡȡ£»£»£»£»£»£»£»£»»ò½«³öÏÖ¸ü¶àÕë¶ÔÆäËüÊý¾ÝµÄMagecartÊÂÎñ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.riskiq.com/blog/external-threat-management/2019-cybersecurity-predictions/4¡¢Ó¢¹úµç×ÓÓʼþ¼°É罻ýÌå¹¥»÷ÊýÁ¿Ïà±ÈÈ¥Äê´ó·ùÉÏÉý
ƾ¾ÝParliament StreetµÄÒ»·Ýл㱨£¬£¬£¬£¬£¬£¬Ó¢¹ú¾¯Ô±ÔÚÃæ¶ÔÔ½À´Ô½´óµÄÉ罻ýÌåºÍÍÆËã»úÈëÇÖ°¸¼þµ÷²éѹÁ¦¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬ÔÚ´ÓǰÁ½¸ö²ÆÄêÄÚ14¸ö¾¯Ô±¶ÓÁй²½øÐÐÁË2547ÆðÉ罻ýÌåºÍÍÆËã»úÈëÇÖ°¸¼þµÄµ÷²é¡£¡£¡£¡£¡£ÆäÖÐ2016-2017ÄêΪ1181Æð£¬£¬£¬£¬£¬£¬2017-2018ÄêΪ1354Æð£¬£¬£¬£¬£¬£¬Ôö³¤ÁË14%¡£¡£¡£¡£¡£FDM GroupµÄCOO Sheila Flavell³ÆÏÔÈ»ÍøÂç·¸×ïµÄÀ˳¹ØýÔںľ¡¾¯Ô±ÒÔ¼°ÆóÒµµÄ×ÊÔ´£¬£¬£¬£¬£¬£¬½â¾öÕâ¸öÎÊÌâ±ØÒª¹²Í¬µÄÖÂÁ¦¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2018/12/03/social-media-hacking-rise/5¡¢ÀûÓÃÓ¢¹úÍÑÅ·²Ý°¸»°Ì⣬£¬£¬£¬£¬£¬SofacyжñÒâ»î¶¯·Ö·¢Zebrocy
°£ÉÕÜ×êÑÐÈËÔ±·¢ÏÖ¶íÂÞ˹APT×éÖ¯SofacyÔÚ×î½üµÄ¶ñÒâ¹¥»÷»î¶¯ÖÐÀûÓÃÁËÓ¢¹úÍÑÅ·²Ý°¸µÄ»°Ì⣬£¬£¬£¬£¬£¬²¢ÇÒÊÔͼ·Ö·¢¶ñÒâÈí¼þZebrocy¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯ÆðÍ·ÓÚ11ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÖØÒªÍ¨¹ý¶ñÒâOfficeÎĵµÖеÄsettings.xml.rels×é¼þ´Ó±í²¿Ô´¼ÓÔØ¶ñÒâÄÚÈÝ£¬£¬£¬£¬£¬£¬Æä×îÖÕpayloadÊÇDelphiºÍ.NET°æ±¾µÄZebrocy¡£¡£¡£¡£¡£Zebrocy½«ÍøÂçϵͳÉϵĹý³ÌÁÐ±í¡¢ÆÁÄ»½ØÍ¼¡¢Çý¶¯Æ÷ö¾ÙÐÅÏ¢²¢·¢ËÍÖÁC&C·þÎñÆ÷¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/russian-hackers-use-brexit-lures-recent-attacks6¡¢ÍòºÀ¾ÆµêÒòÊý¾Ý¿âй¶Ô⼯ÌåËßËÏ£¬£¬£¬£¬£¬£¬±»Ë÷Åâ125ÒÚÃÀÔª
ÍòºÀ¹ú¼Ê¾Æµê¼¯ÍÅ(Marriott International)½üÈÕÒò¿Í»§Êý¾Ý¿âй¶¶øÔâ·ê¼¯ÌåËßËÏ£¬£¬£¬£¬£¬£¬Ë÷Åâ½ð¶î¸ß´ï125ÒÚÃÀÔª¡£¡£¡£¡£¡£ÉÏÖÜÎåÍòºÀ°ä·¢ÆìÏÂϲ´ïÎݾƵê(Starwood Hotel)µÄÒ»¸ö¿Í»§Ô¤Ô¼Êý¾Ý¿â±»ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬Ô¼5ÒÚ¿Í»§µÄÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬ºÚ¿ÍÈëÇÖÔçÔÚ2014Äê¾ÍÒѾÆðÍ·¡£¡£¡£¡£¡£Ëæºó£¬£¬£¬£¬£¬£¬ÃÀ¹úGeragos&GeragosÂÉʦÊÂÎñËùµÄÂÉʦ±¾¡¤Ã·ÈûÀ˹(Ben Meiselas)ºÍUnderdog Law˾·¨ÕÕ·÷Âõ¿Ë¶û¡¤¸»ÀÕ(Michael Fuller)´ú±íÁ½ÃûÔ¸æ´óÎÀ¡¤Ô¼º²Ñ·(David Johnson)ºÍ¿ËÀï˹¡¤¹þÀï˹(Chris Harris)¶ÔÍòºÀ¹ú¼Ê¾ÆµêÌáÆð¼¯ÌåËßËÏ£¬£¬£¬£¬£¬£¬Ë÷Åâ125ÒÚÃÀÔª¡£¡£¡£¡£¡£¹ÌÈ»ÕâÒ»½ð¶î¿´ÆðÀ´¼«¶È¾Þ´ó£¬£¬£¬£¬£¬£¬µ«Ò²½öÏ൱ÓÚ5ÒÚDZÔÚÊܺ¦¿Í»§Ã¿È˵õ½25ÃÀÔªµÄÅâ³¥¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
http://tech.sina.com.cn/i/2018-12-03/doc-ihprknvs8439051.shtmlÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ