¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180919
Ðû²¼Ê±¼ä 2018-09-19¡¾ÆÊÎö±¨¸æ¡¿¿¨°Í˹»ùʵÑéÊÒÐû²¼¹ØÓÚÎïÁªÍøÍþвÇ÷ÊÆµÄÆÊÎö±¨¸æ
ƾ֤±¾Öܶþ¿¨°Í˹»ùʵÑéÊÒÐû²¼µÄÎïÁªÍøÍþв±¨¸æ£¬£¬2018ÄêÉϰëÄ꿨°Í˹»ùÍøÂçµ½µÄIoT¶ñÒâÈí¼þÑù±¾µÄÊýÄ¿ÊÇ2017ÄêÕûÄêµÄÈý±¶£¬£¬¶ø2017ÄêµÄÊý×ÖÔòÊÇ2016ÄêµÄ10±¶¡£¡£Ò×Êܹ¥»÷µÄIoT×°±¸°üÀ¨MikroTik·ÓÉÆ÷ÒÔ¼°TP-Link¡¢SonicWall¡¢CiscoºÍD-LinkµÄ×°±¸µÈ¡£¡£×îÊܽӴýµÄ¹¥»÷ÏòÁ¿ÊÇTelnet¹¥»÷£¬£¬Õ¼ËùÓй¥»÷µÄ75.40%¡£¡£ÔÚÉæ¼°µ½IoT¹¥»÷ʱ£¬£¬Mirai¼Ò×åÊÇ·¸·¨·Ö×ÓµÄÊ×Ñ¡¶ñÒâÈí¼þ£¬£¬ÆäÕ¼ÓÐÁËËùÓй¥»÷µÄ15.97%¡£¡£
https://securelist.com/new-trends-in-the-world-of-iot-threats/87991/
¡¾ÆÊÎö±¨¸æ¡¿RiskIQÐû²¼2018ÄêµÚ¶þ¼¾¶ÈµÄÒÆ¶¯ÍþÐ²Ì¬ÊÆ±¨¸æ
RiskIQÑо¿ÍŶÓÐû²¼2018ÄêµÚ¶þ¼¾¶ÈµÄÒÆ¶¯ÍþÐ²Ì¬ÊÆ±¨¸æ£¬£¬ºÚÃûµ¥Ó¦Óü±¾çÔöÌí¡£¡£×ÜÌå¶øÑÔ£¬£¬RiskIQÔÚµÚ¶þ¼¾¶È¹²ÊӲ쵽52885¸öºÚÃûµ¥Ó¦Ó㬣¬Õ¼ËùÓÐÓ¦ÓõÄ4%£¬£¬±ÈµÚÒ»¼¾¶ÈÔöÌíÁË2%¡£¡£Ä¾ÂíºÍ¹ã¸æÈí¼þÊÇ×î³£¼ûµÄÍþв¡£¡£Google PlayÖеĺÚÃûµ¥Ó¦ÓÃ×î¶à£¬£¬´ï28533¸ö£¬£¬±ÈµÚÒ»¼¾¶ÈÔöÌíÁËÔ¼20000¸ö¡£¡£Ñо¿ÍŶӻ¹ÔÚÓ¦ÓÃÊÐËÁÖ®ÍâÊӲ쵽11288¸öºÚÃûµ¥Ó¦Óᣡ£
https://www.riskiq.com/blog/external-threat-management/q2-2018-mobile-threat-landscape-report/
¡¾Êý¾Ýй¶¡¿MongoDBÉèÖùýʧµ¼ÖÂÔ¼1100Íòµç×ÓÓʼþ¼Í¼¿É¹ûÕæ»á¼û
Çå¾²Ñо¿Ö°Ô±Bob DiachenkoÔÚ»¥ÁªÍøÉÏ·¢Ã÷Ò»¸ö¿É¹ûÕæ»á¼ûµÄMongoDB£¬£¬¸ÃÊý¾Ý¿âÖаüÀ¨Ô¼1100ÍòÌõµç×ÓÓʼþ¼Í¼¡£¡£Êý¾Ý¿âµÄ¾ÞϸΪ43.5GB£¬£¬°üÀ¨ÁËÓû§µÄÑÅ»¢µç×ÓÓÊÏä¼Í¼ÒÔ¼°ÐÕÃû¡¢ÎïÀíµØµã¡¢ÓÊÕþ±àÂëºÍÆÜÉí¶¼»áµÈСÎÒ˽¼ÒÐÅÏ¢¡£¡£¸ÃÊý¾Ý¿âÍйÜÔÚÃÀ¹úGrupo-SMSµÄ»ù´¡ÉèÊ©ÉÏ£¬£¬ÏÖÔÚ»¹²»ÖªµÀ¸ÃÊý¾Ý¿âµÄËùÓÐÕßµÄÉí·Ý¡£¡£
https://www.bleepingcomputer.com/news/security/database-with-11-million-email-records-exposed/
¡¾Êý¾Ýй¶¡¿GovPayNet¹ÙÍø±£´æÎó²î£¬£¬Áè¼Ý1400ÍòÓû§¼Í¼ÒÉй¶
ΪÃÀ¹úÖÝÕþ¸®ºÍµØ·½Õþ¸®ÌṩÔÚÏßÖ§¸¶Æ½Ì¨µÄGovPayNow.com±£´æÇå¾²Îó²î£¬£¬Áè¼Ý1400ÍòÓû§µÄСÎÒ˽¼ÒÐÅÏ¢ÒÉй¶¡£¡£¸ÃÍøÕ¾Îª36¸öÖݵÄ2000¶à¸öÕþ¸®»ú¹¹ÌṩЧÀÍ£¬£¬¹«Ãñ¿ÉÒÔͨ¹ýËüÀ´Ö§¸¶·£¿£¿£¿£¿£¿î¡¢ÅÆÕշѺÍÕ˵¥µÈ¡£¡£Æ¾Ö¤Brian KrebsµÄ˵·¨£¬£¬¸ÃÍøÕ¾µÄÔÚÏßÖ§¸¶ÊÕÌõÊǰ´Ë³Ðò±àºÅµÄ£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄURLÖеÄÊý×ÖÀ´Éó²éÆäËüÈ˵ļͼ¡£¡£ÕâЩ¼Í¼°üÀ¨Óû§µÄÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¼°ÒøÐп¨ºóËÄλÊý×ֵȡ£¡£¸Ã¹«Ë¾ÌåÏÖÒÑÔÚÖÜÄ©ÐÞ¸´ÁËÕâÒ»ÎÊÌâ¡£¡£
https://www.infosecurity-magazine.com/news/government-payment-service-exposes/
¡¾Îó²î²¹¶¡¡¿AppleÐû²¼Ð°汾iOS12£¬£¬ÐÞ¸´¶à¿î²úÆ·ÖеÄÇå¾²Îó²î
Apple±¾ÖÜÕýʽÐû²¼iOS 12£¬£¬²¢ÐÞ¸´ÁËSafari¡¢watchOSºÍtvOSÖеĶà¸öÎó²î¡£¡£iOS 12Öй²ÐÞ¸´ÁË16¸öÎó²î£¬£¬iPhone 5s¼°Ö®ºóµÄ°æ±¾¡¢iPad Air¼°Ö®ºóµÄ°æ±¾ÒÔ¼°iPod touch 6Êܵ½Ó°Ïì¡£¡£½ÏÑÏÖØµÄÎó²î°üÀ¨À¶ÑÀÖеÄÊäÈëÑéÖ¤Îó²î£¨CVE-2018-5383£©ÒÔ¼°SafariÖеÄÐÅϢй¶Îó²î£¨CVE-2018-4313£©µÈ¡£¡£±ðµÄ£¬£¬tvOS 12ÖÐÐÞ¸´ÁË5¸öÇå¾²Îó²î£¬£¬¶øwatchOS 5ÐÞ¸´ÁËÁíÍâµÄ4¸öÎó²î¡£¡£
https://www.bleepingcomputer.com/news/security/ios-12-patches-memory-bugs-safari-12-fixes-data-leaks/
¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷ÒÆ¶¯Ìع¤Èí¼þPegasus±»ÓÃÓÚÕë¶Ô45¸ö¹ú¼ÒµÄÄ¿µÄ
ƾ֤Citizen LabµÄÒ»·Ýб¨¸æ£¬£¬ÒÑÍùÁ½ÄêÀ´Òƶ¯Ìع¤Èí¼þPegasus±»ÓÃÓÚÕë¶ÔÈ«Çò45¸ö¹ú¼ÒµÄÄ¿µÄ¡£¡£PegasusÊÇÒÔÉ«Áй«Ë¾NSO¿ª·¢µÄÌØ¹¤Èí¼þ£¬£¬Ö¼ÔÚ¼à¿ØiPhoneºÍAndroid×°±¸µÄ»î¶¯£¬£¬¿ÉÓÃÓÚÍøÂçÓû§µÄ¶ÌÐÅ¡¢ÈÕÀú¡¢µç×ÓÓʼþ¡¢Î»Öá¢Âó¿Ë·çºÍÏà»úµÈÐÅÏ¢¡£¡£PegasusÖ»ÏòÕþ¸®ºÍÖ´·¨»ú¹¹³öÊÛ¡£¡£¸Ã±¨¸æÖ¸³ö36ÃûÔËÓªÉÌÒ»Ö±ÔÚʹÓÃPegasusÔÚ45¸ö¹ú¼ÒÄÚ¿ªÕ¹¼àÊÓÐж¯¡£¡£NSO½²»°È˳Ƹù«Ë¾Ã»ÓÐÎ¥·´Èκιú¼ÒµÄÖ´·¨¡£¡£
https://thehackernews.com/2018/09/android-ios-hacking-tool.html


¾©¹«Íø°²±¸11010802024551ºÅ