È«ÇòÎïÁªÍø/ICSΣº¦±¨¸æ£¨2020°æ£©£»£»£»£»£»Avast¡¢AVGºÍAviraɱ¶¾Èí¼þ±£´æDLLÐ®ÖÆÎó²î
Ðû²¼Ê±¼ä 2019-10-24
ƾ֤CyberXµÄ¡¶È«ÇòÎïÁªÍø/ICSΣº¦±¨¸æ¡·2020°æ£¬£¬£¬£¬£¬£¬£¬Ðí¶à¹¤ÒµÆóÒµÖÐÈÔÈ»±£´æ¹ýʱµÄ²Ù×÷ϵͳ£¬£¬£¬£¬£¬£¬£¬Õâ´øÀ´ÁËÑÏÖØµÄΣº¦¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÊÇ»ùÓÚÈ«Çò1800¶à¸ö¹¤ÒµÆóÒµÇéÐÎÖдÓ2018Äê10ÔÂÖÁ2019Äê10ÔÂÖ®¼äÍøÂçµÄÊý¾Ý¡£¡£¡£¡£¡£¡£ÊӲ칤¾ßÖÐÓÐ62%µÄ×°±¸ÔËÐеÄÊǹýʱÇÒ²»ÊÜÖ§³ÖµÄWindows°æ±¾£¨ÀýÈçWindows XPºÍ2000£©£¬£¬£¬£¬£¬£¬£¬ÈôÊǰѼ´½«ÔÚ2020Äê1ÔÂ×èÖ¹Ö§³ÖµÄWindows 7ÅÌËãÔÚÄÚ£¬£¬£¬£¬£¬£¬£¬ÔòÕâÒ»Êý×ÖÉÏÉýÖÁ71£¥¡£¡£¡£¡£¡£¡£CyberX»¹·¢Ã÷£¬£¬£¬£¬£¬£¬£¬ÔÚ64£¥µÄÇéÐÎÏÂÆóÒµÔÚÍøÂç´«ÊäÖÐδ¶ÔÃÜÂë¾ÙÐмÓÃÜ£¬£¬£¬£¬£¬£¬£¬ÕâʹµÃ¹¥»÷Õ߸üÈÝÒ׽ػñÃÜÂë¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/outdated-oss-still-present-many-industrial-organizations-report2¡¢Avast¡¢AVGºÍAviraɱ¶¾Èí¼þ±£´æDLLÐ®ÖÆÎó²î
SafeBreach LabsÇå¾²Ñо¿Ö°Ô±·¢Ã÷Avast¡¢AVGºÍAviraɱ¶¾Èí¼þ±£´æDLLÐ®ÖÆÎó²î£¬£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷Õß¼ÓÔØ¶ñÒâDLLÎļþÒÔÈÆ¹ý¼ì²âºÍÌáȨ¡£¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-17093£©Ó°ÏìÁ˰汾19.8ÒÔϵÄËùÓÐAvastºÍAVGɱ¶¾Èí¼þ£¬£¬£¬£¬£¬£¬£¬Îó²îÔµ¹ÊÔÓÉÊÇAVGSvc.exeÊÔͼÔÚÆô¶¯Ê±¼ÓÔØDLL£¬£¬£¬£¬£¬£¬£¬µ«ËüÔÚ¹ýʧµÄÎļþ¼ÐÖÐËÑË÷Îļþ£¨ÀýÈçC£º\Program Files\System32\£©£¬£¬£¬£¬£¬£¬£¬Ê¹µÃ¹¥»÷Õß¿ÉÒÔ½«Í¬ÃûDLL·ÅÈë¸ÃÎļþ¼ÐÖдӶøµ¼Ö¸ÃDLL±»ÒÔSYSTEMÌØÈ¨¼ÓÔØ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚAvira Antivirus 2019Öз¢Ã÷ÁËÀàËÆµÄÎÊÌ⣨CVE-2019-17449£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/avast-avira-products-vulnerable-dll-hijacking3¡¢·µÏÖÍøÕ¾PouringPoundsÔÚÍøÉÏ̻¶2TBÃô¸ÐÐÅÏ¢

Ó¢¹ú·µÏÖÍøÕ¾PouringPounds.com¼°ÆäÓ¡¶Èæ¢ÃÃÍøÕ¾CashKaro.comÒâÍâ̻¶2TBÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£ÕâÁ½¸öÍøÕ¾¾ù¹éÊôPouringPounds¹«Ë¾£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÆäelasticЧÀÍÆ÷δÉèÃÜÂ룬£¬£¬£¬£¬£¬£¬µ¼Ö¿ͻ§µÄÃô¸ÐÐÅÏ¢ÔÚÍøÉÏ̻¶£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢ÊÖ»úºÅÂë¡¢µç×ÓÓʼþµØµã¡¢Óû§ÃûºÍÃ÷ÎÄÃÜÂë¡¢IPµØµã¡¢ÒøÐп¨ÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄÊӲ죬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÔÚÍøÉÏ̻¶Á˳¤´ï6ÖܵÄʱ¼ä¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÓÚ9ÔÂ4ÈÕ֪ͨÁËPouringPounds£¬£¬£¬£¬£¬£¬£¬µ«Ö±µ½9ÔÂ21ÈÕ¸ÃÊý¾Ý¿â²Å»ñµÃ±£»£»£»£»£»¤¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/cashback-websites-double-breach/4¡¢ÃÉ´óÄÃÖÝÒ½ÔºÔâ´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬12.9ÍòÌõ»¼Õ߼ͼй¶
ÃÉ´óÄÃÖÝ¿¨Àû˹Åå¶ûÊеÄÒ»¼ÒÒ½ÔºÔâ´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂ12.9ÍòÌõ¿Í»§¼Í¼й¶¡£¡£¡£¡£¡£¡£ËäÈ»¸ÃÒ½ÔºÔÚ6Ô·ݷ¢Ã÷й¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬µ«ÊÓ²ìÅú×¢¹¥»÷ÕßÔçÔÚ5ÔÂ24ÈÕ¾Í×îÏÈÍøÂ综Õߵļͼ¡£¡£¡£¡£¡£¡£¸ÃÒ½ÔºµÄ¶àÃûÔ±¹¤Ôâ´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÓÊÏ䯾֤±»ÇÔ£¬£¬£¬£¬£¬£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»»á¼û»¼ÕßµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢µØµã¡¢²¡ÀúºÅ¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢²¡Ê·ºÍÖÎÁÆÐÅÏ¢¡¢Ð§ÀÍÈÕÆÚ¡¢ÖÎÁƺÍתÕïҽʦ¡¢Õ˵¥ºÅºÍ°ü¹ÜÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¸ÃÒ½ÔºÌåÏÖ250Ãû»¼ÕßµÄÉç»áÇå¾²ºÅÂë¿ÉÄÜÒ²Ôâй¶¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://hotforsecurity.bitdefender.com/blog/hospital-leaks-129k-patient-records-in-sophisticated-phishing-scam-21674.html
5¡¢Õ˵¥Ð§ÀÍÉÌBilltrustÔâ¶ñÒâÈí¼þ¹¥»÷µ¼ÖÂЧÀÍÖÐÖ¹
ÃÀ¹úÕ˵¥Ð§ÀÍÉÌBilltrustÔâ¶ñÒâÈí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂËùÓÐЧÀÍÖÐÖ¹¡£¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñ±¬·¢ÔÚ10ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬£¬ËäÈ»Billtrust²¢Î´¹ûÕæ´ËÊÂÎñ£¬£¬£¬£¬£¬£¬£¬µ«Æä¿Í»§Ö®Ò»WittichenÐû²¼Í¨¸æ³ÆÎüÊÕµ½Á˸ù«Ë¾µÄ¶ñÒâÈí¼þ¹¥»÷֪ͨ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾»¹¼û¸æWittichen£¬£¬£¬£¬£¬£¬£¬Ã»Óпͻ§µÄÊý¾ÝÔڴ˴ι¥»÷ÖÐÊܵ½Ë𺦣¬£¬£¬£¬£¬£¬£¬²¢ÇÒÓÉÓÚÉæ¼°µÄÊý¾ÝÁ¿Ì«´ó£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÕýÔÚÆ¾Ö¤ÍýÏëµÄʱ¼ä±íÀ´»Ö¸´Ð§ÀÍ¡£¡£¡£¡£¡£¡£Ö»¹Ü¸Ã¹«Ë¾²¢Î´Ö¸³öÍøÂç¹¥»÷µÄÀàÐÍ£¬£¬£¬£¬£¬£¬£¬µ«ÓÐÐÂÎÅÈËÊ¿³Æ¹¥»÷ÔÓÉÊÇÀÕË÷Èí¼þBitPaymer¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÉÐδ¶Ô´Ë¾ÙÐÐ̸ÂÛ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/billing-provider-billtrust-suffers-outage-after-malware-attack/
6¡¢Ñо¿ÍŶӷ¢Ã÷Magecart Group 5ÓëCobalt±£´æ¹ØÁª
ÔÎÄÁ´½Ó£º
https://threatpost.com/magecart-5-linked-carbanak-gang/149419/


¾©¹«Íø°²±¸11010802024551ºÅ