ÃÀ¹úColonialPipelineѬȾÀÕË÷Èí¼þ£¬£¬£¬£¬£¬ £¬£¬Ö÷ÒªÊäÓ͹ÜÍ£ÔË£»£»£»£»£»£»AMD SCSIAdapterÇý¶¯¸üпɵ¼ÖÂWin10ϵͳÍß½â

Ðû²¼Ê±¼ä 2021-05-10

1.ÃÀ¹úColonial PipelineѬȾÀÕË÷Èí¼þ£¬£¬£¬£¬£¬ £¬£¬Ö÷ÒªÊäÓ͹ÜÍ£ÔË


1.jpg


ÃÀ¹ú×î´óµÄȼÁϹܵÀ¹«Ë¾Colonial PipelineÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬ £¬£¬5500Ó¢ÀïÊäÓ͹ÜÍ£ÔË¡£¡£¡£¡£¡£¡£¡£Colonial PipelineÌìÌì´ÓµÂ¿ËÈøË¹ÖÝÔËËÍ250ÍòͰʯÓ͵½¶«º£°¶ºÍŦԼ£¬£¬£¬£¬£¬ £¬£¬¸Ã¹ÜµÀÁýÕÖÁËÃÀ¹ú¶«º£°¶45£¥µÄȼÁϹ©Ó¦¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÉÏÖÜÁùÌåÏÖ£¬£¬£¬£¬£¬ £¬£¬ÆäÓÚ5ÔÂ7ÈÕÔâµ½ÀÕË÷¹¥»÷£¬£¬£¬£¬£¬ £¬£¬·¢Ã÷¹¥»÷ºó×Ô¶¯¹Ø±ÕÁËÒªº¦µÄϵͳÒÔ×èÖ¹Èö²¥£¬£¬£¬£¬£¬ £¬£¬ÏÖÔÚÕýÓëÇå¾²¹«Ë¾ÏàÖú¶Ô¸ÃÊÂÎñµÄÐÔ×Ӻ͹æÄ£¾ÙÐÐÊӲ졣¡£¡£¡£¡£¡£¡£ÃÀ¹úµÄij¹ÙÔ±³Æ£¬£¬£¬£¬£¬ £¬£¬´Ë´ÎÀÕË÷¹¥»÷ÊÂÎñÓëDarkSideÍÅ»ïÓйØ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/largest-us-pipeline-shuts-down-operations-after-ransomware-attack/


2.·¨¹úЬÀàºÍÊÎÆ·¹«Ë¾VejaÔâµ½¹¥»÷£¬£¬£¬£¬£¬ £¬£¬Óû§ÐÅϢй¶


2.jpg


Damien Licata Caruso±¨¸æ³Æ£¬£¬£¬£¬£¬ £¬£¬Veja¹«Ë¾ÔÚ4ÔÂ26ÈÕÔâµ½¹¥»÷£¬£¬£¬£¬£¬ £¬£¬Óû§ÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£VejaÊǵ퍹úЬÀàºÍÊÎÆ·Æ·ÅÆ£¬£¬£¬£¬£¬ £¬£¬Ö÷ÒªÒÔÆä»·±£Ô˶¯Ð¬¶øÖøÃû¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñй¶ÁË2004Ä꽨ÉèµÄ°üÀ¨¿Í»§ÐÅÏ¢Êý¾Ý¿â£¬£¬£¬£¬£¬ £¬£¬Éæ¼°ÔÚÏß¹ºÖûò¶©ÔÄVejaÐÂÎŵĿͻ§µÄÓʼþµØµãµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¸ÃÆ·ÅÆµÄÊ×´´ÈËS¨¦bastienKopp³Æ´Ë´Î²¢Î´Ð¹Â¶ÓйØÒøÐеÄÏêϸÐÅÏ¢£¬£¬£¬£¬£¬ £¬£¬²¢ÇÒËùÓÐÃÜÂë¶¼±»¼ÓÃܵÄ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/fr-eco-friendly-sneaker-brand-veja-hacked/


3.´ó»ªÒøÐÐÒòÆäÔ±¹¤Ô⵽թƭй¶ǧÓàÖйú¹«ÃñµÄÐÅÏ¢


3.jpg


ÐÂ¼ÓÆÂ´ó»ªÒøÐУ¨UOB£©ÒòÆäÔ±¹¤Ô⵽թƭй¶ǧÓàÖйú¹«ÃñµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬ £¬£¬¸ÃÔ±¹¤±»Ã°³äΪÖйú¾¯·½µÄȦÌ×ËùÓÕÆ­£¬£¬£¬£¬£¬ £¬£¬Ð¹Â¶ÁË1166ÃûÖйú¹«ÃñµÄСÎÒ˽¼ÒÏêϸÐÅÏ¢£¬£¬£¬£¬£¬ £¬£¬°üÀ¨¿Í»§µÄÐÕÃû¡¢Éí·ÝÖ¤¡¢ÊÖ»úºÅÂëÒÔ¼°ÕË»§Óà¶îµÈ¡£¡£¡£¡£¡£¡£¡£´ó»ªÒøÐÐÌåÏÖ£¬£¬£¬£¬£¬ £¬£¬²¢Ã»Óпͻ§µÄÒøÐÐÕʺÅй¶£¬£¬£¬£¬£¬ £¬£¬²¢ÇÒÆäITϵͳÈÔÈ»ÊÇÇå¾²µÄ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬ £¬£¬¸ÃÔ±¹¤Òѱ»Í£Ö°£¬£¬£¬£¬£¬ £¬£¬²¢ÕýÔÚЭÖú¾¯·½¶Ô´ËʾÙÐÐÊӲ졣¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://mothership.sg/2021/05/uob-employee-leak-customers-scam/


4.AMD SCSIAdapterÇý¶¯¸üпɵ¼ÖÂWindows 10ϵͳÍß½â


4.jpg


AMD SCSIAdapterÇý¶¯¸üпɵ¼ÖÂWindows 10ϵͳÍ߽⡣¡£¡£¡£¡£¡£¡£Ðí¶àÓû§±¨¸æ£¬£¬£¬£¬£¬ £¬£¬ÔÚ×°ÖøÃÇý¶¯Ê±»á±»ÌáÐÑÖØÆôϵͳ£¬£¬£¬£¬£¬ £¬£¬È»ºó·ºÆðÀ¶ÆÁËÀ»ú(BSOD)µÄÎÊÌ⣬£¬£¬£¬£¬ £¬£¬²¢ÏÔʾ¡°²»¿É»á¼ûµÄÆô¶¯×°±¸¡±£¨INACCESSIBLE_BOOT_DEVICE£©µÄ¹ýʧÌáÐÑ¡£¡£¡£¡£¡£¡£¡£Windows LatestÌåÏÖ£¬£¬£¬£¬£¬ £¬£¬ÏÖÔÚ¸ÃÎÊÌâËÆºõ½öÓ°ÏìijЩAMDÓ²¼þƽ̨£¬£¬£¬£¬£¬ £¬£¬ÓÈÆäÊÇʹÓÃÁ˼¼¼ÎX570Ö÷°åµÄÅÌËã»ú¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬ £¬£¬Î¢ÈíÒÑ´ÓWindows UpdateÖÐÒÆ³ýÁ˸øüС£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-pulls-windows-10-amd-driver-causing-pcs-not-to-boot/


5.CISA¡¢NCSC¡¢FBIÓëNSAÁªºÏÐû²¼ÓйضíÂÞ˹SVRµÄ×Éѯ


5.jpg


CISAÓëÓ¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©¡¢Áª°îÊÓ²ì¾Ö£¨FBI£©ºÍ¹ú¼ÒÇå¾²¾Ö£¨NSA£©ÁªºÏÐû²¼ÓйضíÂÞ˹SVRµÄÇå¾²×Éѯ¡£¡£¡£¡£¡£¡£¡£¸Ã×Éѯָ³öSVRËÆºõÒÑͨ¹ý¸ü¸ÄÆäÊÖÒպͳÌÐò£¨TTP£©£¬£¬£¬£¬£¬ £¬£¬À´×èÖ¹×éÖ¯·¢Ã÷Æä»î¶¯ºÍ½ÓÄɵ÷½â²½·¥¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ £¬£¬SVRÖ÷ÒªÕë¶ÔÕþ¸®¡¢Öǿ⡢Õþ²ßºÍÄÜÔ´Ïà¹ØµÄ×éÖ¯£¬£¬£¬£¬£¬ £¬£¬ÒÔ¼°ÓÐʱЧÐÔµÄÄ¿µÄ£¬£¬£¬£¬£¬ £¬£¬ÀýÈç2020ÄêÓëCOVID-19ÒßÃçÏà¹ØµÄ×éÖ¯¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍÖ÷ҪʹÓÃÁËCVE-2018-13379¡¢CVE-2019-1653ºÍCVE-2019-2725µÈ11¸öÎó²î¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/05/07/joint-ncsc-cisa-fbi-nsa-cybersecurity-advisory-russian-svr


6.Ñо¿ÍŶӷ¢Ã÷WordPress CleanTalk±£´æSQL×¢ÈëÎó²î


6.jpg


WordfenceÍŶÓÅû¶WordPress²å¼þCleanTalk±£´æSQL×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£¡£¸Ã²å¼þ¾ßÓÐÀ¬»øÓʼþ·À»¤¡¢·´À¬»øÓʼþºÍ·À»ðǽµÈ¹¦Ð§£¬£¬£¬£¬£¬ £¬£¬¿ÉÒÔ¹ýÂ˵ôWordPress CMSÍøÕ¾ÉϵÄÀ¬»øÓʼþºÍ̸ÂÛ¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î×·×ÙΪCVE-2021-24295£¬£¬£¬£¬£¬ £¬£¬ÊÇ»ùÓÚʱ¼äµÄSQLäעÎó²î£¬£¬£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉʹÓôËÎó²îÀ´»á¼ûÓû§µÄµç×ÓÓʼþ¡¢ÃÜÂë¡¢ÐÅÓÿ¨Êý¾ÝºÍÆäËûÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬ £¬£¬¸ÃÎó²îÒÑͨ¹ý°æ±¾5.153.4½â¾ö¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/117721/security/anti-spam-wordpress-plugin-flaw.html