΢Èí¶à¸ö¹©¸øÉ̵Ä40¶à¸öÇý¶¯·¨Ê½´æÔÚÌáȨ·ì϶£»Delta ICSϵͳ»º³åÇøÒç¶Âí½Å£»StockX±»µÁÊý¾Ý¿âÔÚ°µÍøÏúÊÛ
°ä²¼¹¦·ò 2019-08-12
Eclypsium×êÑÐÈËÔ±Åû¶³¬¹ý20¼Ò΢Èí¹©¸øÉÌÌṩµÄ40¶à¸öWindowsÇý¶¯·¨Ê½´æÔÚÌáȨ·ì϶£¬¿ÉÄܻᱻºÚ¿ÍÀûÓá£ÊÜÓ°ÏìµÄ³§ÉÌÔ̺¬³ÛÃûBIOS³§É̼°¸÷´óÓ²¼þ¹©¸øÉÌ£¬ÀýÈ绪˶¡¢¶«Ö¥¡¢Intel¡¢¼¼¼Î¡¢Nvidia¡¢»ªÎªµÈ¡£ÓÉÓÚÕâЩÇý¶¯¶¼¾¹ýÁË΢ÈíÈÏÖ¤£¬Òò¶ø¶ñÒⷨʽÄܹ»ÀûÓÃËüÃÇ´ÓÓû§¿Õ¼ä£¨Ring3£©ÌáȨÖÁÄÚºËȨÏÞ£¨Ring0£©¡£Eclypsium°µÊ¾ÕâЩÇý¶¯Ó°ÏìÁËËùÓа汾µÄWindows£¬ÕâÒâζ×ÅÖÁÉÙÊý°ÙÍòÓû§Ãæ¶Ô·çÏÕ¡£IntelºÍ»ªÎªµÈÒѾ°ä²¼ÁËÓйؽ¨¸´²¹¶¡¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/over-40-windows-hardware-drivers-vulnerable-to-privilege-escalation/
2¡¢Delta ICSϵͳ´æÔÚ»º³åÇøÒç¶Âí½Å£¬¿Éµ¼ÖÂÉ豸±»ÊÕÊÜ
×êÑÐÈËÔ±Åû¶Delta¹¤¿ØÏµÍ³enteliBUS ManagerÖеÄÒ»¸ö°²È«·ì϶£¬¸Ã·ì϶¿Éµ¼ÖÂÉ豸±»ÊÕÊÜ¡£Æ¾¾ÝMcAfee×êÑÐÈËÔ±µÄ±íÊö£¬¸Ã·ì϶£¨CVE-2019-9569£©ÊÇÓÉ»º³åÇøÒç³öµ¼Öµġ£¹¥»÷Õß¿Éͨ¹ý¹ã²¥Í¨Ñ¶ÌáÒé¹¥»÷£¬ÕâÒâζÕßËûÃÇÉõÖÁÎÞÐè֪·¹¥»÷Ö¸±êµÄÍøÂçµØÎ»¡£Delta ControlsÒѾ°ä²¼Á˸÷ì϶µÄ½¨¸´²¹¶¡£¬µ«×êÑÐÈËÔ±³ÆÍ¨¹ýShodanËÑË÷ÈÔ¿É·¢ÏÖ1600¸öÒ×Êܹ¥»÷µÄϵͳÔÚÍøÉ϶³ö¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/def-con-2019-delta-ics-flaw-allows-total-industrial-takeover/147142/
3¡¢Ð¶ñÒâÈí¼þClipsa£¬ÖØÒªÕë¶ÔWordPressÍøÕ¾ÌáÒ鱩Á¦ÆÆ½â¹¥»÷
Avast·¢ÏÖÒ»¸öеĶñÒâÈí¼þ¼Ò×åClipsa£¬¸Ã±äÖÖÖØÒªÉ¨Ã軥ÁªÍø²¢Õë¶ÔWordPressÍøÕ¾ÌáÒ鱩Á¦ÆÆ½â¹¥»÷¡£Ò»µ©Ï°È¾É豸£¬Clipsa½«ÌáÒé¶àÖÖ¹¥»÷ÐÐΪ£¬Ô̺¬ÇÔÈ¡¼ÓÃÜÇ®±ÒÂòÂô¡¢×°ÖöñÒâ¿ó¹¤¡¢É¨ÃèÒ×Êܹ¥»÷µÄWordPressÍøÕ¾µÈ¡£ÊÜϰȾµÄÓû§ÖØÒªÎ»ÓÚÓ¡¶È£¬²¨¼°³¬¹ý2.8ÍòÓû§£»Æä´ÎÊÇ·ÆÂɱöºÍ°ÍÎ÷¡£×êÑÐÈËÔ±·ÖÎöÁËÓë¸Ã±äÖÖÓйصÄ9412¸ö±ÈÌØ±ÒµØÖ·£¬·¢ÏÖ·¸×ï·Ö×ÓµÄÊÕ³ÉΪ3¸ö±ÈÌØ±Ò¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/89612/malware/clipsa-malware.html
4¡¢ÃÀ¹ú±£ÏÕ¹«Ë¾State FarmÔâײ¿â¹¥»÷£¬²¿ÃÅÓû§Í´´¦Ð¹Â¶
ÃÀ¹ú±£ÏÕ¹«Ë¾State FarmÏòÓû§·¢ËÍÊý¾Ýй¶֪ͨÓʼþ³Æ£¬ÆäÔÚ7Ô·ÝÔ⵽ײ¿â¹¥»÷£¬µ¼Ö²¿ÃÅÓû§µÄÍ´´¦Ð¹Â¶¡£¸Ã¹«Ë¾³ÆÃ»ÓÐЧ»§ÒþÖÔÐÅϢй¶£¬Ò²Ã»Óз¢ÏÖÓйصÄڲƻ£¬µ«ÒªÇóÊÜÓ°ÏìµÄÓû§³ÁÖÃÆäÃÜÂë¡£³õ´Î¹¥»÷²úÉúÔÚ7ÔÂ6ÈÕ£¬Ëæºóÿ¸ô¼¸Ìì²úÉúÒ»´Î£¬Ò»Ïò³ÖÐøµ½7ÔÂ22ÈÕ¡£¸Ã¹«Ë¾²¢Î´Ð¹Â©ÊÜÓ°ÏìµÄ¾ßÌåÈËÊý¡£
5¡¢StockX±»µÁÊý¾Ý¿âÔÚ°µÍøÏúÊÛ£¬Ô̺¬684ÍòÓû§ÐÅÏ¢
×êÑÐÈËÔ±·¢ÏÖÒ»¸öÔ̺¬684Íò±»µÁÓû§ÐÅÏ¢µÄStockXÊý¾Ý¿âÔÚ°µÍøÉÏÏúÊÛ£¬ÕâЩÐÅÏ¢Ô̺¬µç×ÓÓʼþµØÖ·¡¢ÐÕÃû¡¢×¡Ö·¡¢²É°ì¼Í¼ÒÔ¼°MD5¹þÏ£ÃÜÂë¡£Have I been PwnedÍøÕ¾ÒѾÊÕ¼Á˸ÃÊý¾Ý¿â£¬Óû§¿ÉÔÚ¸ÃÍøÕ¾ÉϼìË÷×Ô¼ºµÄÕË»§ÊÇ·ñ±»µÁ¡£¸ÃÊý¾Ý¿â×îÔçÔÚApollonÊг¡ÉÏÏúÊÛ£¬¼ÛֵΪ300ÃÀÔª£¬ËæºóÔÚ°µÍøÂÛ̳ÉÏÒÔ½ö2.15ÃÀÔªµÄ¼ÛÖµÁ÷ͨ£¬ÕâÒâζ×Å´óÁ¿Ç±ÔÚ¹¥»÷Õß¿ÉÄÜÒѾռÓÐÁ˸ÃÊý¾Ý¿â¡£ÓÐÈ˽âÃÜÁ˸ÃÊý¾Ý¿âÖеÄ36.7Íò¸öÕË»§ÃÜÂ룬²¢ÒÔ400ÃÀÔªµÄ¼ÛÖµÏúÊÛ¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/database-from-stockx-hack-sold-online-check-if-youre-included/
Emsisoft×êÑÐÈËÔ±°ä²¼ÀÕË÷Èí¼þJSWorm 4.0µÄÃâ·Ñ½âÃܹ¤¾ß¡£ÓëÒÔǰµÄ°æ±¾Ò»Ñù£¬JSWorm 4.0ÊÇÓÃC++±àдµÄ£¬Ê¹ÓÃAES-256µÄ¶¨Ôì°æ±¾½øÐмÓÃÜ¡£¸Ã¶ñÒâÈí¼þ»áÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.[ID-][].JSWRMÀ©´óÃû£¬²¢¿ªÊÍÃûΪJSWRM-DECRYPT.htaµÄÀÕË÷µ¥¾Ý¡£Êܵ½Ï°È¾µÄÓû§¿Éͨ¹ýEmsisoft°ä²¼µÄÖ¸ÄϽâÃÜÆäÎļþ¡£ÔÚ5Ô·Ý×êÑÐÈËÔ±»¹°ä²¼ÁËJSWorm 2.0µÄ½âÃܹ¤¾ß¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/89666/malware/emsisoft-decryptor-jsworm-4-0.html


¾©¹«Íø°²±¸11010802024551ºÅ