¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190306

Ðû²¼Ê±¼ä 2019-03-06
1¡¢Î¢ÈíÐû²¼Çå¾²±¨¸æVolume 24£¬£¬£¬£¬ £¬£¬£¬£¬2018Äê´¹ÂÚ¹¥»÷ÔöÌí250£¥

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

ƾ֤΢ÈíµÄÇå¾²Ç鱨±¨¸æ£¨SIR£©Volume 24£¬£¬£¬£¬ £¬£¬£¬£¬ÔÚ2018Äê1ÔÂÖÁ12ÔÂʱ´ú£¬£¬£¬£¬ £¬£¬£¬£¬ÍøÂç´¹ÂÚ¹¥»÷ÔöÌíÁË250%¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚÔËÓªÍøÂç´¹Âڻʱ½ÓÄɶàÑù»¯µÄ»ù´¡ÉèÊ©£¬£¬£¬£¬ £¬£¬£¬£¬°üÀ¨ÍйÜЧÀÍÆ÷ºÍ¹«¹²ÔƵȡ£¡£¡£¡£¡£ÁíÒ»·½Ã棬£¬£¬£¬ £¬£¬£¬£¬2018Äêʱ´ú¶ñÒâÈí¼þµÄÊýĿϽµÁËÔ¼34%¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬£¬£¬Ëæ×Å2018ÄêÄêβ¼ÓÃÜÇ®±Ò¼ÛÇ®µÄϵø£¬£¬£¬£¬ £¬£¬£¬£¬¶ñÒâÍÚ¿ó»î¶¯Ò²Ï½µÁË36%¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-sees-250-percent-phishing-increase-malware-decline-by-34-percent/

2¡¢APWGÐû²¼´¹ÂÚ¹¥»÷±¨¸æ£¬£¬£¬£¬ £¬£¬£¬£¬¹¥»÷ÕßתÏòÕë¶ÔSaaSºÍÓÊÏäЧÀÍ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

ƾ֤APWGµÄд¹ÂÚ¹¥»÷±¨¸æ£¬£¬£¬£¬ £¬£¬£¬£¬2018ÄêÍøÂç´¹ÂÚÕ¾µãµÄÊýĿһֱϽµ£¬£¬£¬£¬ £¬£¬£¬£¬Q4¼ì²âµ½µÄ´¹ÂÚÕ¾µãÊýĿΪ138328£¬£¬£¬£¬ £¬£¬£¬£¬±ÈQ3µÄ151014ÒªµÍ£¬£¬£¬£¬ £¬£¬£¬£¬¶øQ2ÊÇ233040£¬£¬£¬£¬ £¬£¬£¬£¬Q1ÊÇ263538¡£¡£¡£¡£¡£Õë¶ÔSaaSºÍWebmailЧÀ͵Ĵ¹ÂÚ¹¥»÷´ÓQ3µÄ20.1£¥ÔöÌíÖÁQ4µÄ½ü30£¥£¬£¬£¬£¬ £¬£¬£¬£¬¶øÕë¶ÔÔÆ´æ´¢ºÍÎļþÍйÜÕ¾µãµÄ¹¥»÷ÔòÒ»Á¬Ï½µ£¬£¬£¬£¬ £¬£¬£¬£¬´ÓQ1µÄ11.3£¥Ï½µÖÁQ4µÄ4%¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬£¬£¬Ê¹ÓÃSSLµÄ´¹ÂÚÕ¾µãÔÚQ4ÂÔÓÐϽµ£¬£¬£¬£¬ £¬£¬£¬£¬µ«ÈÔÓÐ47%¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.marketwatch.com/press-release/apwg-report-phishers-shift-efforts-to-attack-saas-and-webmail-services-2019-03-04

3¡¢2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾ÖУ¬£¬£¬£¬ £¬£¬£¬£¬WordPressÕ¼90%

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

ƾ֤SucuriµÄÒ»·ÝÊӲ챨¸æ£¬£¬£¬£¬ £¬£¬£¬£¬ÔÚ2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾µÄCMSÂþÑÜÖУ¬£¬£¬£¬ £¬£¬£¬£¬WordPressÒ£Ò£ÁìÏÈ£¬£¬£¬£¬ £¬£¬£¬£¬Õ¼90%£¬£¬£¬£¬ £¬£¬£¬£¬¶þÈýËÄÃû»®·ÖÊÇMagento£¨4.6£¥£©¡¢Joomla£¨4.3£¥£©ºÍDrupal£¨3.7£¥£©¡£¡£¡£¡£¡£68%µÄÊÜÑ¬È¾ÍøÕ¾±»Ö²ÈëÁ˺óÃÅ£¬£¬£¬£¬ £¬£¬£¬£¬56%µÄÊÜÑ¬È¾ÍøÕ¾ÍйÜÁËÆäËü¶ñÒâÈí¼þ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬£¬£¬51%µÄÊÜÑ¬È¾ÍøÕ¾±»°²ÅÅÁËSEOÀ¬»øÐÅÏ¢Ò³Ãæ£¬£¬£¬£¬ £¬£¬£¬£¬2017ÄêÕâÒ»Êý×ÖÊÇ44%¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/wordpress-accounted-for-90-percent-of-all-hacked-cms-sites-in-2018/

4¡¢ÐÂÀÕË÷Èí¼þ¼´Ð§ÀÍJokerooÔÚ°µÍøÊг¡ÉÏÍÆ¹ã

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

Ñо¿Ö°Ô±Damian·¢Ã÷Jokeroo RaaSÔÚ°µÍøÂÛ̳Exploit.inºÍTwitterÉϾÙÐÐÍÆ¹ã¡£¡£¡£¡£¡£·¸·¨·Ö×Ó±ØÐèÏÈÖ§¸¶Ò»¶¨µÄ½ð¶î²Å»ª³ÉΪ»áÔ±£¬£¬£¬£¬ £¬£¬£¬£¬ÕâЩ»áÔ±µÄÌײͼÛÇ®´Ó90ÃÀÔªµ½300¡¢600ÃÀÔª²»µÈ¡£¡£¡£¡£¡£ÆäÒDZíÅÌÒ³ÃæµÄÊý¾ÝÏÔʾ¸ÃRaaSÒѾ­Ñ¬È¾ÁË923¸öÊܺ¦Õß²¢ÇÒ»ñµÃÁË7.13¸ö±ÈÌØ±ÒµÄÊê½ð£¬£¬£¬£¬ £¬£¬£¬£¬µ«BleepingComputerÒÔΪÕâЩֻÊDzâÊÔÊý¾Ý¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/jokeroo-ransomware-as-a-service-offers-multiple-membership-packages/

5¡¢Outdoor Tech»¬Ñ©Í·¿ø¶à¸öÎó²î£¬£¬£¬£¬ £¬£¬£¬£¬¿Éµ¼ÖÂÓû§ÐÅϢй¶

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

Pen Test PartnersµÄÑо¿Ö°Ô±ÔÚOutdoor Tech CHIPS»¬Ñ©Í·¿øµÄÖÇÄܶú»úÖз¢Ã÷¶à¸öÇå¾²Îó²î£¬£¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÇÔȡĿµÄÓû§µÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬ £¬£¬£¬£¬°üÀ¨ËûÃǵĵç×ÓÓʼþ¡¢ÃÜÂë¡¢GPSλÖÃÊý¾ÝµÈ£¬£¬£¬£¬ £¬£¬£¬£¬ÉõÖÁ¿ÉÒÔÇÔÌýËûÃǵÄ˽ÈË̸»°¡£¡£¡£¡£¡£Outdoor Tech¹«Ë¾²¢Î´¶ÔÏà¹ØÎÊÌâ×÷³ö»ØÓ¦¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/smart-ski-helmet-headphone-flaws-leak-personal-gps-data/142456/

6¡¢Ñо¿Ö°Ô±Åû¶ÂÞ¼¼Harmony HubÖеÄ4¸öÇå¾²Îó²î

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

Tenable Network SecurityµÄÑо¿Ö°Ô±Joseph BinghamÔÚBSides SF 2019Çå¾²¾Û»áÉÏÅû¶ÁËÂÞ¼¼Harmony HubÖеÄ4¸öÎó²îµÄÏà¹ØÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£Harmony HubÊÇÒ»¸öÖÇÄܼҾÓ×°±¸£¬£¬£¬£¬ £¬£¬£¬£¬¿É×÷Ϊ¼ÒÍ¥Éú̬ϵͳµÄÖÐÐÄÀ´ÅþÁ¬ÉãÏñÍ·¡¢ÕÕÃ÷¡¢¹©Å¯¡¢ÃÅËøµÈÆäËü×°±¸¡£¡£¡£¡£¡£ÕâЩÎó²î°üÀ¨Ä¬ÈÏÆ¾Ö¤Îó²î£¨CVE-2018-15720£©¡¢Éí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2018-15721£©ÒÔ¼°ÏÂÁî×¢ÈëÎó²î£¨CVE-2018-15722ºÍCVE-2018-15722£©£¬£¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²î»ñµÃLogitech×°±¸µÄÍêÈ«¿ØÖÆÈ¨¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/remote-root-bug-logitech-harmony-hub/142488/

ÉùÃ÷£º±¾×ÊѶÓÉ¿­·¢k8άËûÃüÇ徲С×é·­ÒëºÍÕûÀí