È«ÇòÎïÁªÍø/ICSΣº¦±¨¸æ£¨2020°æ£©£»£»£»Avast¡¢AVGºÍAviraɱ¶¾Èí¼þ±£´æDLLÐ®ÖÆÎó²î

Ðû²¼Ê±¼ä 2019-10-24
1¡¢CyberXÐû²¼È«ÇòÎïÁªÍø/ICSΣº¦±¨¸æ£¨2020°æ£©

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

ƾ֤CyberXµÄ¡¶È«ÇòÎïÁªÍø/ICSΣº¦±¨¸æ¡·2020°æ £¬£¬£¬£¬£¬£¬Ðí¶à¹¤ÒµÆóÒµÖÐÈÔÈ»±£´æ¹ýʱµÄ²Ù×÷ϵͳ £¬£¬£¬£¬£¬£¬Õâ´øÀ´ÁËÑÏÖØµÄΣº¦¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÊÇ»ùÓÚÈ«Çò1800¶à¸ö¹¤ÒµÆóÒµÇéÐÎÖдÓ2018Äê10ÔÂÖÁ2019Äê10ÔÂÖ®¼äÍøÂçµÄÊý¾Ý¡£¡£¡£¡£¡£¡£ÊӲ칤¾ßÖÐÓÐ62%µÄ×°±¸ÔËÐеÄÊǹýʱÇÒ²»ÊÜÖ§³ÖµÄWindows°æ±¾£¨ÀýÈçWindows XPºÍ2000£© £¬£¬£¬£¬£¬£¬ÈôÊǰѼ´½«ÔÚ2020Äê1ÔÂ×èÖ¹Ö§³ÖµÄWindows 7ÅÌËãÔÚÄÚ £¬£¬£¬£¬£¬£¬ÔòÕâÒ»Êý×ÖÉÏÉýÖÁ71£¥¡£¡£¡£¡£¡£¡£CyberX»¹·¢Ã÷ £¬£¬£¬£¬£¬£¬ÔÚ64£¥µÄÇéÐÎÏÂÆóÒµÔÚÍøÂç´«ÊäÖÐδ¶ÔÃÜÂë¾ÙÐмÓÃÜ £¬£¬£¬£¬£¬£¬ÕâʹµÃ¹¥»÷Õ߸üÈÝÒ׽ػñÃÜÂë¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/outdated-oss-still-present-many-industrial-organizations-report

2¡¢Avast¡¢AVGºÍAviraɱ¶¾Èí¼þ±£´æDLLÐ®ÖÆÎó²î


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


SafeBreach LabsÇå¾²Ñо¿Ö°Ô±·¢Ã÷Avast¡¢AVGºÍAviraɱ¶¾Èí¼þ±£´æDLLÐ®ÖÆÎó²î £¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷Õß¼ÓÔØ¶ñÒâDLLÎļþÒÔÈÆ¹ý¼ì²âºÍÌáȨ¡£¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-17093£©Ó°ÏìÁ˰汾19.8ÒÔϵÄËùÓÐAvastºÍAVGɱ¶¾Èí¼þ £¬£¬£¬£¬£¬£¬Îó²îÔµ¹ÊÔ­ÓÉÊÇAVGSvc.exeÊÔͼÔÚÆô¶¯Ê±¼ÓÔØDLL £¬£¬£¬£¬£¬£¬µ«ËüÔÚ¹ýʧµÄÎļþ¼ÐÖÐËÑË÷Îļþ£¨ÀýÈçC£º\Program Files\System32\£© £¬£¬£¬£¬£¬£¬Ê¹µÃ¹¥»÷Õß¿ÉÒÔ½«Í¬ÃûDLL·ÅÈë¸ÃÎļþ¼ÐÖдӶøµ¼Ö¸ÃDLL±»ÒÔSYSTEMÌØÈ¨¼ÓÔØ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚAvira Antivirus 2019Öз¢Ã÷ÁËÀàËÆµÄÎÊÌ⣨CVE-2019-17449£©¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/avast-avira-products-vulnerable-dll-hijacking

3¡¢·µÏÖÍøÕ¾PouringPoundsÔÚÍøÉÏ̻¶2TBÃô¸ÐÐÅÏ¢

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

Ó¢¹ú·µÏÖÍøÕ¾PouringPounds.com¼°ÆäÓ¡¶Èæ¢ÃÃÍøÕ¾CashKaro.comÒâÍâ̻¶2TBÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£ÕâÁ½¸öÍøÕ¾¾ù¹éÊôPouringPounds¹«Ë¾ £¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÆäelasticЧÀÍÆ÷δÉèÃÜÂë £¬£¬£¬£¬£¬£¬µ¼Ö¿ͻ§µÄÃô¸ÐÐÅÏ¢ÔÚÍøÉÏ̻¶ £¬£¬£¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢ÊÖ»úºÅÂë¡¢µç×ÓÓʼþµØµã¡¢Óû§ÃûºÍÃ÷ÎÄÃÜÂë¡¢IPµØµã¡¢ÒøÐп¨ÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄÊÓ²ì £¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÔÚÍøÉÏ̻¶Á˳¤´ï6ÖܵÄʱ¼ä¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÓÚ9ÔÂ4ÈÕ֪ͨÁËPouringPounds £¬£¬£¬£¬£¬£¬µ«Ö±µ½9ÔÂ21ÈÕ¸ÃÊý¾Ý¿â²Å»ñµÃ±£»£»£»¤¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/cashback-websites-double-breach/

4¡¢ÃÉ´óÄÃÖÝÒ½ÔºÔâ´¹ÂÚ¹¥»÷ £¬£¬£¬£¬£¬£¬12.9ÍòÌõ»¼Õ߼ͼй¶


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÃÉ´óÄÃÖÝ¿¨Àû˹Åå¶ûÊеÄÒ»¼ÒÒ½ÔºÔâ´¹ÂÚ¹¥»÷ £¬£¬£¬£¬£¬£¬µ¼ÖÂ12.9ÍòÌõ¿Í»§¼Í¼й¶¡£¡£¡£¡£¡£¡£ËäÈ»¸ÃÒ½ÔºÔÚ6Ô·ݷ¢Ã÷й¶ÊÂÎñ £¬£¬£¬£¬£¬£¬µ«ÊÓ²ìÅú×¢¹¥»÷ÕßÔçÔÚ5ÔÂ24ÈÕ¾Í×îÏÈÍøÂ综Õߵļͼ¡£¡£¡£¡£¡£¡£¸ÃÒ½ÔºµÄ¶àÃûÔ±¹¤Ôâ´¹ÂÚ¹¥»÷ £¬£¬£¬£¬£¬£¬ÓÊÏ䯾֤±»ÇÔ £¬£¬£¬£¬£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»»á¼û»¼ÕßµÄÐÅÏ¢ £¬£¬£¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢µØµã¡¢²¡ÀúºÅ¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢²¡Ê·ºÍÖÎÁÆÐÅÏ¢¡¢Ð§ÀÍÈÕÆÚ¡¢ÖÎÁƺÍתÕïҽʦ¡¢Õ˵¥ºÅºÍ°ü¹ÜÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¸ÃÒ½ÔºÌåÏÖ250Ãû»¼ÕßµÄÉç»áÇå¾²ºÅÂë¿ÉÄÜÒ²Ôâй¶¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://hotforsecurity.bitdefender.com/blog/hospital-leaks-129k-patient-records-in-sophisticated-phishing-scam-21674.html

5¡¢Õ˵¥Ð§ÀÍÉÌBilltrustÔâ¶ñÒâÈí¼þ¹¥»÷µ¼ÖÂЧÀÍÖÐÖ¹


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÃÀ¹úÕ˵¥Ð§ÀÍÉÌBilltrustÔâ¶ñÒâÈí¼þ¹¥»÷ £¬£¬£¬£¬£¬£¬µ¼ÖÂËùÓÐЧÀÍÖÐÖ¹¡£¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñ±¬·¢ÔÚ10ÔÂ17ÈÕ £¬£¬£¬£¬£¬£¬ËäÈ»Billtrust²¢Î´¹ûÕæ´ËÊÂÎñ £¬£¬£¬£¬£¬£¬µ«Æä¿Í»§Ö®Ò»WittichenÐû²¼Í¨¸æ³ÆÎüÊÕµ½Á˸ù«Ë¾µÄ¶ñÒâÈí¼þ¹¥»÷֪ͨ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾»¹¼û¸æWittichen £¬£¬£¬£¬£¬£¬Ã»Óпͻ§µÄÊý¾ÝÔڴ˴ι¥»÷ÖÐÊܵ½Ë𺦠£¬£¬£¬£¬£¬£¬²¢ÇÒÓÉÓÚÉæ¼°µÄÊý¾ÝÁ¿Ì«´ó £¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÕýÔÚÆ¾Ö¤ÍýÏëµÄʱ¼ä±íÀ´»Ö¸´Ð§ÀÍ¡£¡£¡£¡£¡£¡£Ö»¹Ü¸Ã¹«Ë¾²¢Î´Ö¸³öÍøÂç¹¥»÷µÄÀàÐÍ £¬£¬£¬£¬£¬£¬µ«ÓÐÐÂÎÅÈËÊ¿³Æ¹¥»÷Ô­ÓÉÊÇÀÕË÷Èí¼þBitPaymer¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÉÐδ¶Ô´Ë¾ÙÐÐ̸ÂÛ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/billing-provider-billtrust-suffers-outage-after-malware-attack/

6¡¢Ñо¿ÍŶӷ¢Ã÷Magecart Group 5ÓëCobalt±£´æ¹ØÁª

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ñо¿Ö°Ô±·¢Ã÷Magecart Group 5Óë´¹ÂڻDridexºÍ·¸·¨ÍŶÓCobalt±£´æ¹ØÁª¡£¡£¡£¡£¡£¡£Magecart×éÖ¯³Êɡ״½á¹¹ £¬£¬£¬£¬£¬£¬Óɼ¸¸ö²î±ðµÄ·ÖÖ§»ú¹¹×é³É £¬£¬£¬£¬£¬£¬Ã¿¸ö·ÖÖ§»ú¹¹¶¼Ê¹ÓÃÏàͬµÄ¹¥»÷·½·¨ - ¼´Í¨¹ýJavaScript´úÂëÇÔȡ֧¸¶Ò³ÃæÉϵÄÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£Magecart Group 5רÃÅÕë¶ÔµçÉ̵ũӦÁ´ £¬£¬£¬£¬£¬£¬Í¨¹ý¼ì²é¸ÃÍŶӵÄÓòÃûÊýÄ¿¼°ÆäÓëÆäËû¶ñÒâ»î¶¯µÄÁªÏµ £¬£¬£¬£¬£¬£¬MalwarebytesÑо¿Ö°Ô±½«ÆäÓëרÃÅÕë¶ÔÒøÐкÍATMµÄ·¸·¨ÍÅ»ïCobalt¹ØÁªÆðÀ´¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/magecart-5-linked-carbanak-gang/149419/