¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190320
°ä²¼¹¦·ò 2019-03-20
±¾ÖÜÒ»£¨3ÔÂ18ÈÕ£©Íí¼äŲÍþÂÁÒµ¾ÞÍ·Norsk HydroÔâµ½´ó¹æÄ£ÍøÂç¹¥»÷£¬¼¸¼Ò¹¤³§±»Ò»Ê±¹Ø¹Ø¡£ÔÚÐÂÎŰ䲼»áÉÏ£¬Norsk HydroÊ×ϯ²ÆÕþ¹ÙEivind Kallevikй©¸Ã¹«Ë¾Ôâµ½½ÏеÄÀÕË÷Èí¼þLockerGogaµÄ¹¥»÷£¬Æä³ö²ú¼°ÔËÓª¾ùÊܵ½Ó°Ïì¡£¸Ã¹«Ë¾±»ÆÈÔÚŲÍþ¡¢¿¨Ëþ¶ûºÍ°ÍÎ÷µÈ¹ú¶ÈÇл»ÖÁÈËΪ²Ù×÷£¬ÒÔ¸´ÔÆäÔËÓª»î¶¯¡£Kallevik»¹°µÊ¾¸Ã¹«Ë¾ÒѾ¿ÉÄÜ´¦ÖÃËùÓпͻ§µÄ¶©µ¥²¢½»¸¶£¬µ«½«À´µÄ¶©µ¥¿ÉÄÜ»áÊܵ½Ó°Ï죬ÓÉÓÚ¹«Ë¾ÍøÂçÈÔδ¸´Ô¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/lockergoga-ransomware-sends-norsk-hydro-into-manual-mode/2¡¢Libssh2°ä²¼°²È«¸üУ¬¹²½¨¸´9¸ö°²È«·ì϶
±¾ÖÜÒ»libssh2°ä²¼Ð°汾1.8.1£¬¹²½¨¸´9¸ö°²È«·ì϶£¬Ô̺¬Ô½½çд·ì϶£¨CVE-2019-3855~CVE-2019-3857¼°CVE-2019-3863£©ºÍÔ½½ç¶Á·ì϶£¨CVE-2019-3858~CVE-2019-3862£©¡£ÕâЩ·ì϶ӰÏìÁËLibssh2 1.8.1֮ǰµÄËùÓа汾£¬ÈôÊDZ»ÀûÓÿɵ¼ÖÂËÁÒâ´úÂëÖ´Ðм°»Ø¾ø·þÎñµÈÑϳÁºó¹û£¬½¨ÒéÓû§¾¡¿ì½øÐиüС£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/03/libssh2-vulnerabilities.html3¡¢89£¥µÄÅ·Ã˵±¾ÖÍøÕ¾´æÔÚµÚÈý·½¸æ°×¸ú×پ籾
µ¤Âóä¯ÀÀÆ÷·ÖÎö¹«Ë¾CookiebotÔÚ25¸öÅ·Ã˳ÉÔ±¹úÈ·µ±¾Ö¹ÙÍøÉÏ·¢ÏÖ¸æ°×¸ú×پ籾£¬Õâ»òÐíÕ¼×ܹ²28¸ö³ÉÔ±¹úµÄ89%£¬Ö»Óе¹ú¡¢Î÷°àÑÀºÍºÉÀ¼È·µ±¾ÖÍøÕ¾Ã»ÓÐóÒ׸æ°×¸ú×ÙÆ÷¡£·¨¹úµ±¾ÖÍøÕ¾Éϵĸæ°×¸ú×ÙÆ÷×î¶à£¬ÓÐ52¼Ò·ÖÆçµÄ¹«Ë¾ÔÚ¸ú×ÙÓû§µÄÐÐΪ¡£ÕâЩ¸æ°×¸ú×ÙÆ÷ÖØÒªÊÇÔÚµÚÈý·½²å¼þµÄÔ®ÊÖÏÂÉøÈë½øµ±¾ÖÍøÕ¾£¬ÀýÈçÊÓÆµ²¥·ÅÆ÷²å¼þ¡¢ÍøÕ¾·ÖÎö¼°Í¼±í²å¼þµÈ¡£ÕâÏÔȻΥ·´ÁËÅ·Ã˵ÄÊý¾Ý±£»¤ÂÉÀýGDPR¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/89-percent-of-eu-government-sites-infiltrated-by-ad-tracking-scripts/4¡¢×êÑÐÍŶӷ¢ÏÖÁ½¸öÕë¶ÔNetflixºÍAMEXµÄ´ó¹æÄ£´¹µö¹¥»÷
Office 365Íþв×êÑÐÍŶӷ¢ÏÖÁ½¸öÕë¶ÔNetflixºÍAMEX£¨ÃÀ¹úÔËͨ£©µÄ´ó¹æÄ£ÍøÂç´¹µö»î¶¯£¬Õë¶ÔNetflix¿Í»§¶ËµÄ´¹µö»î¶¯½«Êܺ¦Õß³Á¶¨Ïòµ½Ò»¸öÐéαµÄÏÂÔØ±íµ¥£¬¸Ã±íµ¥»áÍøÂçÓû§µÄÐÅÓþ¿¨ÐÅÏ¢£¨Ô̺¬¿¨ºÅ¡¢µ½ÆÚÈÕÆÚ¡¢PINÂëºÍ°²È«Â룩ºÍÕ˵¥ÐÅÏ¢£¨Ô̺¬ÐÕÃû¡¢ÓÊÏ䵨ַ¡¢SSN¡¢×¡Ö·¡¢µç»°ºÅÂëºÍµ®ÉúÈÕÆÚ£©¡£Õë¶ÔAMEXÓû§µÄ´¹µö»î¶¯Ôò»áÍøÂçÓ×ÎÒÐÅÏ¢ºÍÐÅÓþ¿¨ÐÅÏ¢£¬ÒÔ¼°Óû§IDºÍÃÜÂë¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/netflix-and-amex-customers-actively-targeted-by-phishing-campaigns/5¡¢ÐÂSextortion´¹µöÓʼþ£¬¼Ù×°³ÉCIA½øÐÐÚ²Æ
ÉÏÖÜÄ©³öÏÖÁËÒ»¸öеÄsextortion´¹µö»î¶¯£¬¸Ã´¹µöÓʼþ¼Ù×°³ÉCIAµÄ¹ú¼Ê·¨Âɵ÷²é£¬Ðû³ÆÊܺ¦ÕßÒò²Î¼Ó·Ö·¢ºÍ´æ´¢¶ùͯɫÇéÄÚÈݱ»µ÷²é£¬³ý·ÇÖ§¸¶¼ÛÖµ1ÍòÃÀÔªµÄ±ÈÌØ±Ò£¬²»È»½«ÔÚ2019Äê4ÔÂ8ÈÕ±»´þ²¶¡£ÕâЩµç×ÓÓʼþµÄ·¢Ë͵ØÖ·Ô̺¬cia¡¢govºÍmlµÈÎı¾£¬Ê¹Æä¿´ËÆÀ´×ÔÓÚµ±¾ÖÓòÃûµÄÓÊÏä¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-sextortion-email-uses-cia-investigation-as-scare-tactic/6¡¢ÐÂÀÕË÷Èí¼þJNEC.a£¬ÀûÓÃWinRAR Ace·ì϶½øÐд«²¼
×êÑÐÈËÔ±·¢ÏÖÒ»¸öеÄÀÕË÷Èí¼þJNEC.aÀûÓÃ×î½ü»ã±¨µÄWinRAR´úÂëÖ´Ðзì϶½øÐд«²¼¡£JNEC.a»á¼ÓÃÜÍÆËã»úÉϵÄÊý¾Ý£¬²¢ÔÚÎļþºó¸½¼Ó.JnecÀ©´óÃû£¬Æä½âÃÜÃÜÔ¿µÄ¼ÛÖµÊÇ0.05±ÈÌØ±Ò£¨Ô¼200ÃÀÔª£©¡£JNEC.aÊÇÓÃ.NET±àдµÄ£¬¼Ù×°³ÉGoogleUpdate.exe¸éÖÃÔÚWindows StartupÎļþ¼ÐÖУ¬ÒÔÔÚÍÆËã»úÆô¶¯Ê±×Ô¶¯Æô¶¯¡£Æ¾¾ÝMichael GillespieµÄ·ÖÎö£¬¸ÃÀÕË÷Èí¼þ´æÔÚbug£¬¼´±ãÊÇ¿ª·¢Õß×Ô¼ºÒ²ÎÞ·¨½âÃܸÃÀÕË÷Èí¼þ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/jneca-ransomware-spread-by-winrar-ace-exploit/ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ