»ªË¶Ðû²¼Live Update¸üÐÂ;Norsk HydroÒòÀÕË÷Èí¼þËðʧ³¬4100ÍòÃÀÔª;LUCKY ELEPHANT¹¥»÷»î¶¯

Ðû²¼Ê±¼ä 2019-03-28
1¡¢»ªË¶È·ÈÏÔ⹩ӦÁ´¹¥»÷£¬£¬ £¬£¬£¬£¬ÒÑÐû²¼Live UpdateÇå¾²¸üÐÂ


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


»ªË¶È·ÈÏÆäЧÀÍÆ÷Ôâµ½ÈëÇÖ£¬£¬ £¬£¬£¬£¬Live Update¹¤¾ßÔâµ½¸Ä¶¯¡£¡£¡£¡£¡£¡£Æ¾Ö¤¸Ã¹«Ë¾µÄÉùÃ÷£¬£¬ £¬£¬£¬£¬»ªË¶ÒѾ­Ðû²¼ÁËLive Updateа汾3.6.8À´ÐÞ¸´¸ÃÎÊÌ⣬£¬ £¬£¬£¬£¬¸Ã°æ±¾ÒýÈëÁ˶àÖÖÇå¾²ÑéÖ¤»úÖÆ£¬£¬ £¬£¬£¬£¬²¢ÊµÑéÁËÔöÇ¿µÄ¶Ëµ½¶Ë¼ÓÃÜ¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬¸Ã¹«Ë¾»¹ÌṩÁËÒ»¸öÕï¶Ï¹¤¾ß£¬£¬ £¬£¬£¬£¬ÓÃÓÚ¼ì²éÓû§µÄϵͳÊÇ·ñÊܵ½Ñ¬È¾¡£¡£¡£¡£¡£¡£Ó뿨°Í˹»ùºÍÈüÃÅÌú¿ËÔ¤¹ÀµÄ100ÍòÊܺ¦Õß²î±ð£¬£¬ £¬£¬£¬£¬»ªË¶³Æ¸Ã¹¥»÷Ö»Õë¶ÔÉÙÊýÌØ¶¨Óû§ÈºÌ壬£¬ £¬£¬£¬£¬²¢ÇÒÖ»ÓÐÉÙÊý×°±¸Êܵ½Ñ¬È¾¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2019/03/27/asus-fixes-live-update/

2¡¢Norsk HydroÒòÀÕË÷Èí¼þ¹¥»÷Ëðʧ³¬4100ÍòÃÀÔª


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÔÚÉÏÖÜÔâµ½ÀÕË÷Èí¼þLockerGoga¹¥»÷Ö®ºó£¬£¬ £¬£¬£¬£¬Å²ÍþÂÁÉú²úÉÌNorsk HydroÈÔÔÚ»Ö¸´ÆäITϵͳ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³Æ»ùÓڸ߲ãÆÀ¹À£¬£¬ £¬£¬£¬£¬ÆðÔ´Ô¤¼ÆÍøÂç¹¥»÷Ôì³ÉµÄËðʧԼΪ3-3.5ÒÚŲÍþ¿ËÀÊ£¨ºÏ3500-4100ÍòÃÀÔª£©£¬£¬ £¬£¬£¬£¬Ö÷ÒªËðʧȪԴÓÚÀûÈóºÍÂÁ²Ä¼·Ñ¹ÓªÒµµÄËðʧ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³ÆÂÁ²Ä¼·Ñ¹½â¾ö¼Æ»®ÒѾ­»Ö¸´ÁË70-80%£¬£¬ £¬£¬£¬£¬µ«ÐÞ½¨ÏµÍ³ÓªÒµÈÔδ»Ö¸´¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/norsk-hydro-ransomware-costs-hit-1-1/

3¡¢UrsnifľÂíй¥»÷»î¶¯£¬£¬ £¬£¬£¬£¬Ö÷ÒªÕë¶ÔÒâ´óÀû

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

ƾ֤Cybaze-Yoroi ZLabÑо¿Ö°Ô±µÄ·¢Ã÷£¬£¬ £¬£¬£¬£¬Ò»¸öеÄUrsnifľÂí±äÖÖÕýÔÚÃé×¼Òâ´óÀûµÄÆóÒµ¡£¡£¡£¡£¡£¡£¸Ã±äÖÖͨ¹ý´¹ÂÚÓʼþ¾ÙÐзַ¢£¬£¬ £¬£¬£¬£¬ÓʼþÖаüÀ¨ÐéαGoogleÔÆÅÌÒ³ÃæµÄÁ´½Ó£¬£¬ £¬£¬£¬£¬µ±Óû§ÔÚÕâ¸öÐéÎ±Ò³ÃæÉϵã»÷ÏÂÔØÁ´½Óʱ£¬£¬ £¬£¬£¬£¬½«»á´Óblogger[.]scentasticyoga[.]comÏÂÔØ¶ñÒâÎļþ¡£¡£¡£¡£¡£¡£¸Ã±äÖÖʹÓÃVBScript½ÅÔ­À´Èƹý·À²¡¶¾²úÆ·µÄ¼ì²â¡£¡£¡£¡£¡£¡£Æ¾Ö¤¶ÔÔ¶³ÌC2ЧÀÍÆ÷µÄÊӲ죬£¬ £¬£¬£¬£¬¸Ã¹¥»÷»î¶¯×Ô3ÔÂ5ÈÕÆðÒ»Ö±»îÔ¾¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/ursnif-trojans-latest-campaign-affects-several-organizations-in-italy-b8a16f69

4¡¢LUCKY ELEPHANT¹¥»÷»î¶¯£¬£¬ £¬£¬£¬£¬Ö÷ÒªÕë¶ÔÄÏÑÇÕþ¸®»ú¹¹


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


NETSCOUTÑо¿ÍŶӷ¢Ã÷Ò»¸öÐµĹ¥»÷»î¶¯LUCKY ELEPHANT£¬£¬ £¬£¬£¬£¬¸Ã¹¥»÷»î¶¯Ö÷ҪʹÓÃÐéαµÄÕþ¸®¡¢µçÐÅ¡¢¾ü¶ÓÍøÕ¾À´ÇÔÈ¡Óû§µÄµÇ¼ƾ֤¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ¹ú¼Ò°üÀ¨°Í»ù˹̹¡¢ÃϼÓÀ­¹ú¡¢Ë¹ÀïÀ¼¿¨¡¢Âí¶û´ú·ò¡¢ÃåµéºÍÄá²´¶û¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯ÓÚ3Ô³õ±»·¢Ã÷£¬£¬ £¬£¬£¬£¬Æ¾Ö¤¹¥»÷ÕßʹÓõÄIPµØµã£¬£¬ £¬£¬£¬£¬¹¥»÷ÕßÒÉÓëÓ¡¶ÈAPT×éÖ¯APT-C-35ÓйØ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/82963/hacking/lucky-elephant-campaign.html

5¡¢GAOб¨¸æ³ÆÃÀ¹úÁª°î´¢±¸ÏµÍ³ÃæÁÙδÊÚȨ»á¼ûΣº¦


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ƾ֤ÃÀ¹úÕþ¸®ÎÊÔð¾Ö£¨GAO£©Ðû²¼µÄÖÎÀí±¨¸æ£¬£¬ £¬£¬£¬£¬ÓÉÓÚÃÀ¹ú²ÆÎñ²¿µÄÅÌËã»úϵͳ±£´æÇå¾²Îó²î£¬£¬ £¬£¬£¬£¬µ¼ÖÂÁª°î´¢±¸ÒøÐУ¨FRB£©Ô⵽δÊÚȨ»á¼ûΣº¦µÄÔöÌí¡£¡£¡£¡£¡£¡£ÔÚ2018²ÆÎñÄê¶ÈÉó¼ÆÊ±´ú£¬£¬ £¬£¬£¬£¬GAO·¢Ã÷FRBÔËÓªµÄÒªº¦½ðÈÚϵͳ±£´æÎó²î¡£¡£¡£¡£¡£¡£¾ÝGAO³Æ£¬£¬ £¬£¬£¬£¬ÔÚÍêÈ«½â¾öÕâЩÎó²î֮ǰ£¬£¬ £¬£¬£¬£¬Î´ÊÚȨ»á¼û¡¢¸Ä¶¯»òÅû¶Ãô¸ÐÊý¾ÝµÄΣº¦½«»áÔöÌí¡£¡£¡£¡£¡£¡£Æ¾Ö¤Éó¼ÆÐ§¹ûºÍ½¨Ò飬£¬ £¬£¬£¬£¬Áª°î´¢±¸ÏµÍ³ÀíÊ»áÌåÏÖÕýÔÚ½â¾öÕâЩÎÊÌâ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-federal-reserve-system-exposed-to-increased-risk-of-unauthorized-access/

6¡¢NVIDIAÐû²¼GeForce ExperienceÇå¾²¸üУ¬£¬ £¬£¬£¬£¬ÐÞ¸´Ò»¸öÌáȨÎó²î


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


NVIDIAÐû²¼Windowsƽ̨GeForce ExperienceÈí¼þµÄÇå¾²¸üУ¬£¬ £¬£¬£¬£¬ÐÞ¸´Ò»¸öÑÏÖØµÄÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-5674£©µÄCVSS V3ÆÀ·ÖΪ8.8·Ö£¬£¬ £¬£¬£¬£¬¿ÉÔÊÐíDZÔÚµÄÍâµØ¹¥»÷ÕßÌáȨ¡¢Ö´ÐÐí§Òâ´úÂë¼°´¥·¢DoS¹¥»÷¡£¡£¡£¡£¡£¡£ËäÈ»¸ÃÎó²îÎÞ·¨Ô¶³ÌʹÓ㬣¬ £¬£¬£¬£¬µ«¹¥»÷ÕßÈÔ¿Éͨ¹ýÆäËüÒªÁìÔ¶³ÌÖ²Èë¶ñÒâÈí¼þÀ´Ê¹ÓøÃÎó²î¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ°æ±¾Îª3.18֮ǰµÄËùÓÐGeForce Experience°æ±¾¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nvidia-patches-high-severity-geforce-experience-vulnerability/

ÉùÃ÷£º±¾×ÊѶÓÉÄϹ¬NGÓéÀÖάËûÃüÇ徲С×é·­ÒëºÍÕûÀí