¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180918
Ðû²¼Ê±¼ä 2018-09-18¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӳÆÁè¼Ý20ÒŲ́װ±¸ÈÔÊÜBlueBorneÎó²îµÄÓ°Ïì
Armis LabsÑо¿ÍŶӳÆÁè¼Ý20ÒÚ×°±¸ÈÔÊÜÒ»ÄêǰÅû¶µÄBlueBorneÎó²îµÄÓ°Ïì¡£¡£¡£¡£¡£BlueBorne°üÀ¨9¸öÀ¶ÑÀÎó²î£¬£¬£¬£¬ÓÚ2017Äê9Ô±»Åû¶²¢Ëæºó¾ÙÐÐÐÞ¸´¡£¡£¡£¡£¡£µ½Ò»ÄêºóµÄ½ñÌ죬£¬£¬£¬Ô¼Èý·ÖÖ®¶þµÄÊÜÓ°Ïì×°±¸ÒѾ¾ÙÐÐÁ˸üУ¬£¬£¬£¬µ«ÈÔÓдó×ÚµÄЧÀÍÆ÷¡¢ÖÇÄÜÊÖ±í¡¢Ò½ÁÆ×°±¸ºÍ¹¤Òµ×°±¸µÈ»¹Î´¾ÙÐÐÐÞ¸´£¬£¬£¬£¬°üÀ¨7.68ÒŲ́Linux×°±¸¡¢7.34ÒŲ́ÔËÐÐAndroid5.1¼°¸üÔç°æ±¾µÄ×°±¸¡¢2.61ÒŲ́ÔËÐÐAndroid6¼°¸üÔç°æ±¾µÄ×°±¸¡¢2ÒŲ́Windows×°±¸ÒÔ¼°5000Íǫ̀ÔËÐÐiOS9.3.5¼°¸üÔç°æ±¾µÄ×°±¸¡£¡£¡£¡£¡£
https://www.armis.com/blueborne-one-year-later/
¡¾¹¥»÷ÊÂÎñ¡¿EOSBetÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬¼ÛÖµÔ¼20ÍòÃÀÔªµÄEOS±»ÇÔ
¶Ä²©Ó¦ÓÃEOSBetÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬¼ÛÖµÔ¼20ÍòÃÀÔªµÄEOS±»ÇÔ¡£¡£¡£¡£¡£¸ÃÓ¦ÓûùÓÚEOSÇø¿éÁ´£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÆäÖÇÄܺÏÔ¼ÖеÄÎó²î£¬£¬£¬£¬´ÓEOSBetµÄÇ®°üÖÐÇÔÈ¡ÁËÔ¼4Íò¸öEOS¡£¡£¡£¡£¡£ÏÖÔÚ¸ÃÓ¦ÓÃÒÑÏÂÏß¡£¡£¡£¡£¡£Æ¾Ö¤¸Ã¹«Ë¾µÄ˵·¨£¬£¬£¬£¬¹¥»÷Õßͨ¹ýαÔì¹þÏ£Ð®ÖÆÁËEOSBetµÄÉúÒâ×ʽ𡣡£¡£¡£¡£¸ÃÊÂÎñÈÔ´¦ÓÚ½øÒ»²½µÄÊÓ²ìȡ֤֮ÖС£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/76258/hacking/eosbet-gambling-application-hacked.html
¡¾Îó²î²¹¶¡¡¿Çå¾²Ñо¿ÍŶÓÔÚ»ôÄáΤ¶ûPDAÖз¢Ã÷Ò»¸öÌáȨÎó²î
¹È¸èAndroidÍŶÓÔÚ»ôÄáΤ¶ûµÄPDA£¨ÕÆÉϵçÄÔ£©Öз¢Ã÷Ò»¸öÑÏÖØµÄÌáȨÎó²î£¬£¬£¬£¬¸ÃÎó²î£¨CVE-2018-14825£©¿ÉÔÊÐí¹¥»÷Õß¾ÙÐÐÌáȨ²¢¶ÔÃÜÂëºÍÉñÃØÎĵµµÈÃô¸ÐÐÅÏ¢¾ÙÐÐδÊÚȨ»á¼û¡£¡£¡£¡£¡£»£»£»£»ôÄáΤ¶ûµÄPDA±»ÆÕ±éÓÃÓÚÄÜÔ´¡¢Ò½ÁÆ¿µ½¡¡¢Òªº¦ÖÆÔìÒÔ¼°ÉÌÒµÉèÊ©µÈÁìÓò¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ×°±¸ÔËÐеÄAndroid°æ±¾°üÀ¨´Ó4.4µ½8.1¡£¡£¡£¡£¡£»£»£»£»ôÄáΤ¶ûÒѾÕë¶ÔÆä×°±¸Ðû²¼ÁËÏà¹ØÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/76268/hacking/honeywell-android-based-handheld-device-flaw.html
¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶÓÐû²¼¹ØÓÚжñÒâÈí¼þXBashµÄÆÊÎö±¨¸æ
Palo Alto NetworksµÄUnit 42Ñо¿ÍŶӷ¢Ã÷Ò»¸öеĶñÒâÈí¼þ¼Ò×åXbash¡£¡£¡£¡£¡£XbashÓë·¸·¨ÍÅ»ïIron GroupÓйأ¬£¬£¬£¬Ëü¿ÉÒÔÕë¶ÔLinuxºÍWindowsЧÀÍÆ÷£¬£¬£¬£¬²¢½«½©Ê¬ÍøÂç¡¢ÀÕË÷Èí¼þ¡¢¶ñÒâÍÚ¿óÒÔ¼°È䳿¹¦Ð§ÕûºÏÔÚÒ»Æð¡£¡£¡£¡£¡£XbashÖ÷ÒªÕë¶ÔδÐÞ¸´µÄÎó²îºÍÈõÃÜÂë¾ÙÐÐÈö²¥£¬£¬£¬£¬ÆäĬÈÏ»áÏú»ÙÊý¾Ý£¬£¬£¬£¬²¢ÇÒÎÞ·¨»Ö¸´£¬£¬£¬£¬Òò´ËÖ§¸¶Êê½ðÊÇûÓÐÐëÒªµÄ¡£¡£¡£¡£¡£Xbash»¹¾ßÓÐ×ÔÎÒÈö²¥¹¦Ð§¡£¡£¡£¡£¡£ÏÖÔÚÒÑÓÐ48ÃûÊܺ¦ÕßÖ§¸¶ÁËÊê½ð£¨Ô¼6000ÃÀÔª£©£¬£¬£¬£¬ÕâÒâζןöñÒâÈí¼þ´¦ÓÚ»îÔ¾Ö®ÖС£¡£¡£¡£¡£
https://researchcenter.paloaltonetworks.com/2018/09/unit42-xbash-combines-botnet-ransomware-coinmining-worm-targets-linux-windows/
¡¾¶ñÒâÈí¼þ¡¿Ñо¿Ö°Ô±³ÆÍ¨¹ýÓÀºãÖ®À¶·Ö·¢µÄ¶ñÒâÍÚ¿óÈí¼þWannamineÈÔÔÚ»îÔ¾
CybereasonµÄÇå¾²Ñо¿Ö°Ô±Amit Serper³ÆÍ¨¹ýÓÀºãÖ®À¶Îó²îʹÓþÙÐÐÈö²¥µÄ¶ñÒâÍÚ¿óÈí¼þWannamineÈÔÈ»´¦ÓÚ»îԾ״̬¡£¡£¡£¡£¡£ËäȻ΢ÈíÔÚ2017Äê3ÔÂ14ÈÕÐÞ¸´Á˸ÃÎó²î£¬£¬£¬£¬µ«Æ¾Ö¤ShodanµÄɨÃèЧ¹û£¬£¬£¬£¬»¥ÁªÍøÉÏÈÔ±£´æÔ¼100Íò¸öÒ×Êܹ¥»÷µÄ×°±¸¡£¡£¡£¡£¡£¸ÃWannamineбäÌåÒ²±£´æÒ»¸ö֮ǰµÄ±äÌåûÓйýµÄÐÂÐÐΪ£¬£¬£¬£¬Æä»áɱËÀÆäÓàÅþÁ¬µ½3333¡¢5555ºÍ7777¶Ë¿Ú£¨WannamineµÄ±ê×¼ÅþÁ¬¶Ë¿Ú£©µÄÀú³Ì¡£¡£¡£¡£¡£
https://www.cybereason.com/blog/wannamine-cryptominer-eternalblue-wannacry
¡¾Çå¾²Îó²î¡¿Ñо¿ÍŶÓÅû¶NUUOÍøÂçÊÓÆµÂ¼Ïñ»úÖеÄÐÂ0day£¬£¬£¬£¬¶à´ï80Íǫ̀װ±¸ÒÉÊÜÓ°Ïì
ƾ֤±¾ÖÜÒ»Tenable ResearchÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬£¬Ñо¿ÍŶÓÔÚNUUO¹«Ë¾µÄÍøÂçÊÓÆµÂ¼Ïñ»ú£¨NVR£©¹Ì¼þÖз¢Ã÷Ò»¸öеÄ0day Peekaboo£¬£¬£¬£¬¶à´ï80Íǫ̀װ±¸ÒÉÊÜÓ°Ïì¡£¡£¡£¡£¡£PeekabooÎó²î£¨CVE-2018-1149£©ÊÇÒ»¸öδÂÄÀúÖ¤µÄÕ»»º³åÇøÒç³öÎó²î£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¹¥»÷ÕßÒÔroot»òÖÎÀíԱȨÏÞÖ´ÐÐÔ¶³Ì¶ñÒâ´úÂë¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ»á¼û¼à¿ØÉãÏñÍ·¡¢¼àÊÓºÍʹÓÃÊÓÆµÔ´»òÖ²Èë¶ñÒâÈí¼þ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬Ñо¿ÍŶӻ¹·¢Ã÷ÁíÒ»¸öÎó²î£¨CVE-2018-1150£©£¬£¬£¬£¬¸ÃÎó²îÊÇNUUO NVRMini2 WebЧÀÍÆ÷ÖеĺóÃÅ£¬£¬£¬£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÐÞ¸ÄÓû§µÄÃÜÂë¡£¡£¡£¡£¡£
https://threatpost.com/zero-day-bug-allows-hackers-to-access-cctv-surveillance-cameras/137499/


¾©¹«Íø°²±¸11010802024551ºÅ