作者信息:2016年11月7日 By 第十二届全国人民代表大会常务委员会

第一章 总 则
  第一条 为了保障网络安全,维护网络空间主权和国家安全、社会公共利益,保护公民、法人和其他组织的合法权益,促进经济社会信息化健康发展,制定本法。
  第二条 在中华人民共和国境内建设、运营、维护和使用网络,以及网络安全的监督管理,适用本法。
  第三条 国家坚持网络安全与信息化发展并重,遵循积极利用、科学发展、依法管理、确保安全的方针,推进网络基础设施建设和互联互通,鼓励网络技术创新和应用,支持培养网络安全人才,建立健全网络安全保障体系,提高网络安全保护能力。
  第四条 国家制定并不断完善网络安全战略,明确保障网络安全的基本要求和主要目标,提出重点领域的网络安全政策、工作任务和措施。
  第五条 国家采取措施,监测、防御、处置来源于中华人民共和国境内外的网络安全风险和威胁,保护关键信息基础设施免受攻击、侵入、干扰和破坏,依法惩治网络违法犯罪活动,维护网络空间安全和秩序。
  第六条 国家倡导诚实守信、健康文明的网络行为,推动传播社会主义核心价值观,采取措施提高全社会的网络安全意识和水平,形成全社会共同参与促进网络安全的良好环境。
  第七条 国家积极开展网络空间治理、网络技术研发和标准制定、打击网络违法犯罪等方面的国际交流与合作,推动构建和平、安全、开放、合作的网络空间,建立多边、民主、透明的网络治理体系。
  第八条 国家网信部门负责统筹协调网络安全工作和相关监督管理工作。国务院电信主管部门、公安部门和其他有关机关依照本法和有关法律、行政法规的规定,在各自职责范围内负责网络安全保护和监督管理工作。
  第九条 网络运营者开展经营和服务活动,必须遵守法律、行政法规,尊重社会公德,遵守商业道德,诚实信用,履行网络安全保护义务,接受政府和社会的监督,承担社会责任。
  第十条 建设、运营网络或者通过网络提供服务,应当依照法律、行政法规的规定和国家标准的强制性要求,采取技术措施和其他必要措施,保障网络安全、稳定运行,有效应对网络安全事件,防范网络违法犯罪活动,维护网络数据的完整性、保密性和可用性。
  第十一条 网络相关行业组织按照章程,加强行业自律,制定网络安全行为规范,指导会员加强网络安全保护,提高网络安全保护水平,促进行业健康发展。
  第十二条 国家保护公民、法人和其他组织依法使用网络的权利,促进网络接入普及,提升网络服务水平,为社会提供安全、便利的网络服务,保障网络信息依法有序自由流动。
  第十三条 国家支持研究开发有利于未成年人健康成长的网络产品和服务,依法惩治利用网络从事危害未成年人身心健康的活动,为未成年人提供安全、健康的网络环境。
第七章 附 则
  第七十六条 本法下列用语的含义:
  第七十七条 存储、处理涉及国家秘密信息的网络的运行安全保护,除应当遵守本法外,还应当遵守保密法律、行政法规的规定。
  第七十八条 军事网络的安全保护,由中央军事委员会另行规定。
标题:Disassembling a Mobile Trojan Attack

作者信息:November 7, 2016. 10:27 am By Nikita Buchka, Anton Kivva

In early August we detected several cases of a banking Trojan being downloaded automatically when users viewed certain news sites on their Android devices. Later it became apparent that this was being caused by advertising messages from the Google AdSense network, and was not restricted to news sites. In fact, any site using AdSense to display adverts could potentially have displayed messages that downloaded the dangerous Trojan-Banker.AndroidOS.Svpeng and automatically saved it to the device’s SD card. This behavior surprised us: typically, the browser warns users about downloading a potentially dangerous file, and offers them a choice of whether or not to save the file. We intercepted traffic coming from the attacked device when this sort of “advert” was displayed, and figured out how the malicious program was downloaded and automatically saved.

标题:Watch out! A new LinkedIn Phishing campaign is spreading in the wild

作者信息:November 6, 2016  By Pierluigi Paganini

Experts from Heimdal Security reported a recent LinkedIn phishing campaign aiming to collect confidential information from unsuspecting users.
Phishing attacks continue to be a serious threat, crooks exploit paradigms such as social medial platforms and mobile in the attempt of stealing sensitive
data.According to 2015 Verizon Data Breach Investigation Report, 23% of email recipients open phishing messages and 11% click on malicious attachments … and this is just the tip of the iceberg.

“The link is placed on the recipient’s name and leads to a password reset page, secured by HTTPS. Strangely enough, this is actually a safe page, which could prompt the email recipients to believe that the rest of the email is valid and legitimate as well.” continues the analysis.
Going forward, the experts noticed many other strange issues, I invite you to give a look at the analysis. Awareness of such kind of scams is important to make them ineffective.
标题:Russia Demands Explanation for US Military Hacking Reports

作者信息:November 07, 2016 By Eduard Kovacs

Moscow has asked Washington to provide clarifications on reports that the U.S. military has hacked into Russia’s critical infrastructure and its intention to leverage this access to retaliate in case of serious disruptions to the upcoming elections.
NBC News reported on Friday that it learned from a senior U.S. intelligence official and top-secret documents that United States military hackers have broken into Russia’s telecommunications networks, electric grid and Kremlin’s command systems. This will allegedly allow the U.S. to attack these critical systems if necessary.

"The threats directed against Moscow and our state's leadership are unprecedented because they are voiced at the level of the US vice president," said Kremlin spokesman Dmitry Peskov. "To the backdrop of this aggressive, unpredictable line, we must take measures to protect (our) interests, to hedge risks."
Guccifer 2.0, the hacker who has taken credit for the Democratic Party cyberattacks, said he will be observing the elections in the United States and urged other hackers to “monitor the elections from inside the system.” Some security experts believe Guccifer 2.0 is a persona used by Russia to throw investigators off track.
标题:Databases of Indian embassies leaked online. Too easy hack them

作者信息:November 6, 2016  By Pierluigi Paganini

The databases of the Indian Embassies in Switzerland, Mali, Romania, Italy, Malawi, and Libya were leaked online by two grey hat hackers.
Today I was contacted by a security pentester who goes online with the moniker Kapustkiy who revealed me to have breached the Indian Embassies in Switzerland, Mali, Romania, Italy, Malawi, and Libya. Kapustkiy and his friend Kasimierz (@Kasimierz_) told me that they were initially white hats in the past, but decided to change to grey hats to get the media attention and force many administrators of websites online to seriously consider cyber security.
印度驻六国的大使馆员工信息被泄露在网络上几个小时后,被下线。这六个国家是瑞士、马里、罗马尼亚、意大利、马拉维以及利比亚等,这些个人的信息是被两个灰客(Grey hat)泄露的:他们两个人原来都是白帽子(White hat),但是他们的工作并未得到重视或者媒体的关注,因此采用这种偏激的方式来引起外界的重视。

I had no opportunity to check the authenticity of the data, I tried to reach the embassy online but at the time I was writing the website of the Indian Embassy in Rome is unavailable.
标题:Tesco Bank confirms almost 20,000 customers had money stolen from accounts by hackers

作者信息:Monday, November 07, 2016 - 09:33 am By  Irish Examiner Ltd

Nearly 20,000 Tesco Bank (译者注:https://www.tescobank.com/sss/auth)customers have had money stolen from their accounts as a result of a weekend hack attack, the group's chief executive has said.
The British bank confirmed that of its 136,000 current account holders, 40,000 had seen suspicious transactions over the weekend, while money had been fraudulently withdrawn from around 20,000 accounts.
A spokesman would not disclose the total amount that has been stolen from the accounts, adding that the incident is currently being treated as a "criminal

The bank has temporarily frozen online transactions as part of emergency security measures, and was earlier forced to block some customers' cards after "suspicious activity" was detected in its fraud prevention system.
Mr Higgins issued an apology to customers and said the bank would refund accounts as soon as possible.
"We apologise for the worry and inconvenience that this has caused for customers, and can only stress that we are taking every step to protect our customers' accounts.
"We can reassure customers that any financial loss as a result of this activity will be resolved fully by Tesco Bank, and we are working to refund accounts that have been subject to fraud as soon as possible," he said.
The news sent Tesco shares lower by 1.2% in early trading.

//TESCO 乐购(标题的特易购普遍被翻译为乐购)银行首页的道歉申明 http://www.tescobank.com/?referrerid=tesco/redirect
Tesco Bank can confirm that, over the weekend, some of its customers’ current accounts have been subject to online criminal activity, in some cases resulting in money being withdrawn fraudulently.
We apologise for the worry and inconvenience that this has caused for customers, and can only stress that we are taking every step to protect our customers’ accounts.
As a precautionary measure, we took the decision on Sunday 6 November 2016 to temporarily stop online transactions from current accounts. This will only affect current account customers. While online debit transactions will not be available, current account customers will still be able to use their cards for cash withdrawals, chip and pin payments, and all existing bill payments and direct debits will continue as normal. We are working hard to resume normal service on current accounts as soon as possible.
We can reassure customers that any financial loss as a result of this activity will be resolved fully by Tesco Bank. This afternoon we began the process of refunding all customer current accounts that have been subjected to online criminal activity and we expect this process to be completed by the end of tomorrow.
We continue to work with the authorities and regulators to address the fraud and will keep our customers informed through regular updates on our website, Twitter and Your Community.
If customers have any concerns at all, we would advise them to contact our customer service team who will be able to provide assistance.
Benny Higgins
Chief Executive
