È«ÇòÎïÁªÍø/ICSΣº¦±¨¸æ£¨2020°æ£©£»£»£»£»£»£»Avast¡¢AVGºÍAviraɱ¶¾Èí¼þ±£´æDLLÐ®ÖÆÎó²î

Ðû²¼Ê±¼ä 2019-10-24
1¡¢CyberXÐû²¼È«ÇòÎïÁªÍø/ICSΣº¦±¨¸æ£¨2020°æ£©

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

ƾ֤CyberXµÄ¡¶È«ÇòÎïÁªÍø/ICSΣº¦±¨¸æ¡·2020°æ£¬ £¬Ðí¶à¹¤ÒµÆóÒµÖÐÈÔÈ»±£´æ¹ýʱµÄ²Ù×÷ϵͳ£¬ £¬Õâ´øÀ´ÁËÑÏÖØµÄΣº¦¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÊÇ»ùÓÚÈ«Çò1800¶à¸ö¹¤ÒµÆóÒµÇéÐÎÖдÓ2018Äê10ÔÂÖÁ2019Äê10ÔÂÖ®¼äÍøÂçµÄÊý¾Ý¡£¡£¡£¡£¡£¡£ÊӲ칤¾ßÖÐÓÐ62%µÄ×°±¸ÔËÐеÄÊǹýʱÇÒ²»ÊÜÖ§³ÖµÄWindows°æ±¾£¨ÀýÈçWindows XPºÍ2000£©£¬ £¬ÈôÊǰѼ´½«ÔÚ2020Äê1ÔÂ×èÖ¹Ö§³ÖµÄWindows 7ÅÌËãÔÚÄÚ£¬ £¬ÔòÕâÒ»Êý×ÖÉÏÉýÖÁ71£¥¡£¡£¡£¡£¡£¡£CyberX»¹·¢Ã÷£¬ £¬ÔÚ64£¥µÄÇéÐÎÏÂÆóÒµÔÚÍøÂç´«ÊäÖÐδ¶ÔÃÜÂë¾ÙÐмÓÃÜ£¬ £¬ÕâʹµÃ¹¥»÷Õ߸üÈÝÒ׽ػñÃÜÂë¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/outdated-oss-still-present-many-industrial-organizations-report

2¡¢Avast¡¢AVGºÍAviraɱ¶¾Èí¼þ±£´æDLLÐ®ÖÆÎó²î


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


SafeBreach LabsÇå¾²Ñо¿Ö°Ô±·¢Ã÷Avast¡¢AVGºÍAviraɱ¶¾Èí¼þ±£´æDLLÐ®ÖÆÎó²î£¬ £¬¿ÉÔÊÐí¹¥»÷Õß¼ÓÔØ¶ñÒâDLLÎļþÒÔÈÆ¹ý¼ì²âºÍÌáȨ¡£¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-17093£©Ó°ÏìÁ˰汾19.8ÒÔϵÄËùÓÐAvastºÍAVGɱ¶¾Èí¼þ£¬ £¬Îó²îÔµ¹ÊÔ­ÓÉÊÇAVGSvc.exeÊÔͼÔÚÆô¶¯Ê±¼ÓÔØDLL£¬ £¬µ«ËüÔÚ¹ýʧµÄÎļþ¼ÐÖÐËÑË÷Îļþ£¨ÀýÈçC£º\Program Files\System32\£©£¬ £¬Ê¹µÃ¹¥»÷Õß¿ÉÒÔ½«Í¬ÃûDLL·ÅÈë¸ÃÎļþ¼ÐÖдӶøµ¼Ö¸ÃDLL±»ÒÔSYSTEMÌØÈ¨¼ÓÔØ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚAvira Antivirus 2019Öз¢Ã÷ÁËÀàËÆµÄÎÊÌ⣨CVE-2019-17449£©¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/avast-avira-products-vulnerable-dll-hijacking

3¡¢·µÏÖÍøÕ¾PouringPoundsÔÚÍøÉÏ̻¶2TBÃô¸ÐÐÅÏ¢

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

Ó¢¹ú·µÏÖÍøÕ¾PouringPounds.com¼°ÆäÓ¡¶Èæ¢ÃÃÍøÕ¾CashKaro.comÒâÍâ̻¶2TBÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£ÕâÁ½¸öÍøÕ¾¾ù¹éÊôPouringPounds¹«Ë¾£¬ £¬Ñо¿Ö°Ô±·¢Ã÷ÆäelasticЧÀÍÆ÷δÉèÃÜÂ룬 £¬µ¼Ö¿ͻ§µÄÃô¸ÐÐÅÏ¢ÔÚÍøÉÏ̻¶£¬ £¬°üÀ¨ÐÕÃû¡¢ÊÖ»úºÅÂë¡¢µç×ÓÓʼþµØµã¡¢Óû§ÃûºÍÃ÷ÎÄÃÜÂë¡¢IPµØµã¡¢ÒøÐп¨ÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄÊӲ죬 £¬¸ÃÊý¾Ý¿âÔÚÍøÉÏ̻¶Á˳¤´ï6ÖܵÄʱ¼ä¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÓÚ9ÔÂ4ÈÕ֪ͨÁËPouringPounds£¬ £¬µ«Ö±µ½9ÔÂ21ÈÕ¸ÃÊý¾Ý¿â²Å»ñµÃ±£»£»£»£»£»£»¤¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/cashback-websites-double-breach/

4¡¢ÃÉ´óÄÃÖÝÒ½ÔºÔâ´¹ÂÚ¹¥»÷£¬ £¬12.9ÍòÌõ»¼Õ߼ͼй¶


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÃÉ´óÄÃÖÝ¿¨Àû˹Åå¶ûÊеÄÒ»¼ÒÒ½ÔºÔâ´¹ÂÚ¹¥»÷£¬ £¬µ¼ÖÂ12.9ÍòÌõ¿Í»§¼Í¼й¶¡£¡£¡£¡£¡£¡£ËäÈ»¸ÃÒ½ÔºÔÚ6Ô·ݷ¢Ã÷й¶ÊÂÎñ£¬ £¬µ«ÊÓ²ìÅú×¢¹¥»÷ÕßÔçÔÚ5ÔÂ24ÈÕ¾Í×îÏÈÍøÂ综Õߵļͼ¡£¡£¡£¡£¡£¡£¸ÃÒ½ÔºµÄ¶àÃûÔ±¹¤Ôâ´¹ÂÚ¹¥»÷£¬ £¬ÓÊÏ䯾֤±»ÇÔ£¬ £¬µ¼Ö¹¥»÷ÕßÄܹ»»á¼û»¼ÕßµÄÐÅÏ¢£¬ £¬°üÀ¨ÐÕÃû¡¢µØµã¡¢²¡ÀúºÅ¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢²¡Ê·ºÍÖÎÁÆÐÅÏ¢¡¢Ð§ÀÍÈÕÆÚ¡¢ÖÎÁƺÍתÕïҽʦ¡¢Õ˵¥ºÅºÍ°ü¹ÜÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¸ÃÒ½ÔºÌåÏÖ250Ãû»¼ÕßµÄÉç»áÇå¾²ºÅÂë¿ÉÄÜÒ²Ôâй¶¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://hotforsecurity.bitdefender.com/blog/hospital-leaks-129k-patient-records-in-sophisticated-phishing-scam-21674.html

5¡¢Õ˵¥Ð§ÀÍÉÌBilltrustÔâ¶ñÒâÈí¼þ¹¥»÷µ¼ÖÂЧÀÍÖÐÖ¹


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÃÀ¹úÕ˵¥Ð§ÀÍÉÌBilltrustÔâ¶ñÒâÈí¼þ¹¥»÷£¬ £¬µ¼ÖÂËùÓÐЧÀÍÖÐÖ¹¡£¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñ±¬·¢ÔÚ10ÔÂ17ÈÕ£¬ £¬ËäÈ»Billtrust²¢Î´¹ûÕæ´ËÊÂÎñ£¬ £¬µ«Æä¿Í»§Ö®Ò»WittichenÐû²¼Í¨¸æ³ÆÎüÊÕµ½Á˸ù«Ë¾µÄ¶ñÒâÈí¼þ¹¥»÷֪ͨ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾»¹¼û¸æWittichen£¬ £¬Ã»Óпͻ§µÄÊý¾ÝÔڴ˴ι¥»÷ÖÐÊܵ½Ë𺦣¬ £¬²¢ÇÒÓÉÓÚÉæ¼°µÄÊý¾ÝÁ¿Ì«´ó£¬ £¬¸Ã¹«Ë¾ÕýÔÚÆ¾Ö¤ÍýÏëµÄʱ¼ä±íÀ´»Ö¸´Ð§ÀÍ¡£¡£¡£¡£¡£¡£Ö»¹Ü¸Ã¹«Ë¾²¢Î´Ö¸³öÍøÂç¹¥»÷µÄÀàÐÍ£¬ £¬µ«ÓÐÐÂÎÅÈËÊ¿³Æ¹¥»÷Ô­ÓÉÊÇÀÕË÷Èí¼þBitPaymer¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÉÐδ¶Ô´Ë¾ÙÐÐ̸ÂÛ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/billing-provider-billtrust-suffers-outage-after-malware-attack/

6¡¢Ñо¿ÍŶӷ¢Ã÷Magecart Group 5ÓëCobalt±£´æ¹ØÁª

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Ñо¿Ö°Ô±·¢Ã÷Magecart Group 5Óë´¹ÂڻDridexºÍ·¸·¨ÍŶÓCobalt±£´æ¹ØÁª¡£¡£¡£¡£¡£¡£Magecart×éÖ¯³Êɡ״½á¹¹£¬ £¬Óɼ¸¸ö²î±ðµÄ·ÖÖ§»ú¹¹×é³É£¬ £¬Ã¿¸ö·ÖÖ§»ú¹¹¶¼Ê¹ÓÃÏàͬµÄ¹¥»÷·½·¨ - ¼´Í¨¹ýJavaScript´úÂëÇÔȡ֧¸¶Ò³ÃæÉϵÄÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£Magecart Group 5רÃÅÕë¶ÔµçÉ̵ũӦÁ´£¬ £¬Í¨¹ý¼ì²é¸ÃÍŶӵÄÓòÃûÊýÄ¿¼°ÆäÓëÆäËû¶ñÒâ»î¶¯µÄÁªÏµ£¬ £¬MalwarebytesÑо¿Ö°Ô±½«ÆäÓëרÃÅÕë¶ÔÒøÐкÍATMµÄ·¸·¨ÍÅ»ïCobalt¹ØÁªÆðÀ´¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/magecart-5-linked-carbanak-gang/149419/