¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180720
Ðû²¼Ê±¼ä 2018-07-20¡¾ÍþвÇ鱨¡¿Ñо¿»ú¹¹Ðû²¼¿É×èÖ¹ÀÕË÷Èí¼þGandCrab v4.1.2µÄ·À»¤³ÌÐò
º«¹úÇå¾²³§ÉÌAhnLabÐû²¼¿ÉÓÃÓÚ×èÖ¹ÀÕË÷Èí¼þGandCrab v4.1.2µÄ·À»¤³ÌÐò£¬£¬£¬£¬£¬£¬£¬£¬¸Ã³ÌÐòͨ¹ýÔÚÓû§µÄÅÌËã»úÉϽ¨ÉèÒ»¸öÌØÊâµÄÎļþÀ´×èÖ¹GandCrab¡£¡£¡£¡£Õâ¸öÎļþÊÇ[Ê®Áù½øÖÆ×Ö·û´®].lock£¬£¬£¬£¬£¬£¬£¬£¬ÆäÊ®Áù½øÖÆ×Ö·û´®ÊÇÆ¾Ö¤ÅÌËã»ú¸ùÇý¶¯Æ÷µÄ¾íÐÅÏ¢ºÍSalsa20Ëã·¨ÌìÉúµÄ£¬£¬£¬£¬£¬£¬£¬£¬GandCrab»áƾ֤´ËÎļþÅжÏÅÌËã»úÊÇ·ñÒѱ»Ñ¬È¾¹ý¡£¡£¡£¡£¸Ã·À»¤³ÌÐòÖ»ÊÊÓÃÓÚv4.1.2°æ±¾¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/vaccine-available-for-gandcrab-ransomware-v412/
¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷ѬȾÁè¼Ý1.8Íò¸ö·ÓÉÆ÷µÄн©Ê¬ÍøÂçAnarchy
NewSky SecurityµÄÇå¾²Ñо¿Ö°Ô±·¢Ã÷Ò»¸öеĽ©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬£¬£¬¸Ã½©Ê¬ÍøÂçʹÓûªÎªHG532·ÓÉÆ÷ÖÐÎó²î£¨CVE-2017-17215£©¾ÙÐÐÈö²¥£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ1ÌìÄÚѬȾÁËÁè¼Ý1.8Íò¸ö·ÓÉÆ÷¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪ¸Ã½©Ê¬ÍøÂç±³ºóµÄ×÷ÕßÊÇWicked/Anarchy£¬£¬£¬£¬£¬£¬£¬£¬AnarchyÔø½¨Éè¹ýIoT¶ñÒâÈí¼þMiraiµÄ¶à¸ö±äÖÖ£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨Wicked¡¢OmniºÍOwari£¨Sora£©¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/router-crapfest-malware-author-builds-18-000-strong-botnet-in-a-day/
¡¾Îó²î²¹¶¡¡¿ABBÐÞ¸´ÆäHMI²úÆ·ÖеÄÒ»¸ö¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐеÄÎó²î
ÈðÊ¿¹¤ÒµÊÖÒÕ¹«Ë¾ABBÕýÔÚÐÞ¸´ÆäHMI²úÆ·ÖеÄÒ»¸ö¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐеÄÇå¾²Îó²î£¨CVE-2018-10616£©¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËËùÓа汾µÄPanel Builder 800¡£¡£¡£¡£Panel Builder 800Êǹ¤Òµ×Ô¶¯»¯ÏµÍ³µÄ²Ù×÷Ãæ°å¹¤¾ß£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹¤¾ßÔÚÈ«Çò¹æÄ£ÄÚ±»ÆÕ±éÓÃÓÚ»¯¹¤¡¢ÖÆÔ졢ˮ°Ó¡¢ÄÜÔ´¡¢¹©Ë®¡¢Ê³ÎïÒÔ¼°Å©ÒµµÈÐÐÒµ¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÓÕÆÓû§·¿ª¶ñÒâÎļþÀ´Ê¹ÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/abb-patch-code-execution-flaw-hmi-tool
¡¾Îó²î²¹¶¡¡¿Ë¼¿ÆÐû²¼¶à¸ö²úÆ·µÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬¹²ÐÞ¸´25¸öÇå¾²Îó²î
˼¿ÆÐû²¼¶à¸ö²úÆ·µÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬¹²ÐÞ¸´25¸öÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Cisco Policy SuiteÖеÄÒ»¸öºóÃÅÕË»§Îó²î¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2018-0375£©Ê¹µÃ¹¥»÷Õß¿ÉÒÔÒÔrootȨÏÞ»á¼û×°±¸£¬£¬£¬£¬£¬£¬£¬£¬½ø¶øÖ´ÐжñÒâ²Ù×÷¡£¡£¡£¡£Ë¼¿ÆÔÚCisco Policy Suite 18.2.0ÖÐÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ËùÓÐ֮ǰµÄ°æ±¾¶¼Ò×Êܹ¥»÷¡£¡£¡£¡£ÕâÊÇÒÑÍù5¸öÔÂÄÚ˼¿ÆÔÚÆä×°±¸ÖÐɾ³ýµÄµÚ5¸öºóÃÅÕË»§¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cisco-removes-undocumented-root-password-from-bandwidth-monitoring-software/
¡¾Îó²î²¹¶¡¡¿Ñо¿ÍŶÓÅû¶ͼÐα༹¤¾ßCanvas DrawÖеĶà¸öÇå¾²Îó²î
˼¿ÆTalosÑо¿ÍŶÓÅû¶ÔÚMac°æ±¾µÄCanvas Draw 4Öз¢Ã÷µÄ¶à¸öÇå¾²Îó²î¡£¡£¡£¡£Canvas Draw 4ÊÇÒ»¸öÓÃÓÚ½¨ÉèºÍ±à¼Í¼ÐεŤ¾ß£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý¶ñÒâTIFFÎļþ´¥·¢ÕâЩÎó²îµ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£¡£Îó²îµÄ±àºÅΪCVE-2018-3857~CVE-2018-3871£¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËCanvas Draw 4.0.0¼°Ö®Ç°µÄ°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¸üÐÂÖÁ×îа汾¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://blog.talosintelligence.com/2018/07/vulnerability-spotlight-ACDsystems.html
¡¾¹¥»÷ÊÂÎñ¡¿¶íÂÞ˹PIRÒøÐÐÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ËðʧԼ100ÍòÃÀÔª
ƾ֤¶íÂÞ˹Çå¾²³§ÉÌGroup-IBµÄ±¨¸æ£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ïMoneyTakerͨ¹ý·ÓÉÆ÷ÈëÇÖÁ˶íÂÞ˹PIRÒøÐеÄÍøÂ磬£¬£¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁËÔ¼100ÍòÃÀÔªµÄ×ʽ𡣡£¡£¡£Group-IBÈ·ÈϹ¥»÷ʼÓÚ2018Äê5ÔÂÏÂÑ®£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßµÄÈë¿ÚÊǹýʱµÄ·ÓÉÆ÷£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ÓÉÆ÷ÓÐËíµÀ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÖ±½Ó»á¼ûÒøÐеÄÍâµØÍøÂç¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ7ÔÂ3ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬PIRÒøÐеÄÔ±¹¤ÔÚÒ»ÌìºóµÄ7ÔÂ4ÈÕ·¢Ã÷ÁË´ó±ÊδÊÚȨµÄÉúÒ⣬£¬£¬£¬£¬£¬£¬£¬µ«ÎªÊ±ÒÑÍí¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-breach-russian-bank-and-steal-1-million-due-to-outdated-router/


¾©¹«Íø°²±¸11010802024551ºÅ