Î÷°àÑÀ°²È«³§ÉÌProsegurÔâµ½ÀÕË÷Èí¼þRyuk¹¥»÷ £»¿¨°Í˹»ù½¨¸´Web ProtectionÖ°ÄÜÖеĶà¸ö·ì϶

°ä²¼¹¦·ò 2019-11-29
1¡¢Î÷°àÑÀ°²È«³§ÉÌProsegurÔâµ½ÀÕË÷Èí¼þRyuk¹¥»÷

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Î÷°àÑÀ°²È«³§ÉÌProsegurÔÚÒ»·ÝÉêÃ÷Öа䷢ÔâÀÕË÷Èí¼þ¹¥»÷£¬Õû¸ö¹«Ë¾µÄÍøÂç¶¼ÒѹعØ¡£Ö»¹ÜûÓеõ½¹Ù·½È·ÈÏ£¬µ«BleepingComputerÏàʶµ½¸Ã¹¥»÷Ó°ÏìÁËProsegurÔÚÅ·ÖÞµÄËùÓеØÖ·¡£ÔÚTwitterÉϵĸüÐÂÖУ¬ProsegurÈ·Èϵ¼ÖÂÆä·þÎñÖжϵĶñÒâÈí¼þÊÇRyuk£¬²¢½«ÊÂÎñÏóÕ÷Ϊ¡°Í¨³£ÐÔ¹¥»÷¡±¡£¸Ã¹«Ë¾°µÊ¾ÒѲÉÈ¡×î´óˮƽµÄ°²È«´ëÊ©×èÖ¹¸Ã¶ñÒâÈí¼þÔÚÆäÄÚ²¿¼°¿Í»§¶ËÍøÂçÖд«²¼¡£×÷ΪԤ·À´ëÊ©£¬¸Ã¹«Ë¾½«³ÖÐøÏÞ¶ÈͨѶ£¬Ö±µ½È·ÈÏÆäϵͳÒѸɾ»£¬²¢ÔÚÖÂÁ¦ÒÔ×î¿ìµÄ¿ìÂʸ´Ô­ÊÜÓ°ÏìµÄ·þÎñ¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ryuk-ransomware-forces-prosegur-security-firm-to-shut-down-network/

2¡¢GPHealthÒ½ÁÆÖÐÐÄ»¼ÕßÊý¾Ý±»ÀÕË÷Èí¼þ¼ÓÃÜ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Great Plains HealthÒ½ÁÆÖÐÐÄÔÚ±¾ÖܳõÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Ô±¹¤±»ÆÈʹÓÃÖ½ºÍ±Ê½øÐа칫¡£¸ÃÊÂÎñ²úÉúÔÚÖÜÒ»ÍíÉÏ7µã×óÓÒ£¬ÖܶþGPHealth°ä·¢È¡µÞ´óÁ¿·Ç´¹Î£»¼ÕßµÄÔ¤Ô¼ºÍÁ÷³Ì£¬µ«²»Ó°ÏìÊÖÊõºÍÒ½ÁÆÓ°ÏñÅÄÉã¡£GPHealthÊ×ϯִÐйÙMel McNea°µÊ¾Ã»ÓÐÀíÓÉÒÉ»ó»¼ÕßÊý¾ÝÔâµ½½Ó¼û£¬µ«¸Ã¹«Ë¾½«½øÐÐÈ«ÃæµÄÉó²é¡£¸Ã¹«Ë¾»¹°µÊ¾ÔÚÓë·¨Âɲ¿ÃźÏ×÷½øÐе÷²é¡£Ä¿Ç°Éв»Ã÷ÏÔ¹¥»÷ÖÐʹÓõÄÀÕË÷Èí¼þÀàÐÍÒÔ¼°¸Ã¹«Ë¾ÊÇ·ñÖ§¸¶ÁËÊê½ð¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ransomware-locks-medical-records-at-great-plains-health/

3¡¢Á¬Ëø²ÍÌüOn The Border¿Í»§Ö§¸¶ÐÅÏ¢±»µÁ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Á¬Ëø²ÍÌüOn The Border֪ͨ¿Í»§ÆäÖ§¸¶ÐÅÏ¢¿ÉÄÜÒѱ»ºÚ¿ÍÇÔÈ¡¡£¸Ã¹«Ë¾ÓÚ11ÔÂ14ÈÕ·¢ÏÖÁË´ËÊÂÎñ£¬¹«Ë¾µ÷²éÒÔΪÓÐ27¸öÖݵIJÍÌüÊܵ½Ó°Ï졣ĿǰµÄÖ¤¾ÝÅú×¢ÕâЩ²ÍÌüÔÚ2019Äê4ÔÂ10ÈÕÖÁ2019Äê8ÔÂ10ÈÕÖ®¼äϰȾÁ˶ñÒâÈí¼þ£¬¿ÉÄܱ»ÇԵĿͻ§ÐÅÏ¢Ô̺¬ÐÕÃû¡¢ÐÅÓþ¿¨ºÅ¡¢ÓÐЧÆÚ¡¢ÑéÖ¤ÂëµÈ£¬µ«²»Ô̺¬µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¼°Éí·ÝID¡£Õ¼ÓÐOn The BorderµÄ¸öÈËͶ×ʹ«Ë¾Argonne Capital GroupÒ²Õ¼Óпì²ÍÁ¬ËøµêKrystal£¬¸ÃÁ¬Ëøµê½üÆÚÒ²Ôâµ½Ö§¸¶ÐÅϢ͵ÇÔÊÂÎñ£¬Ä¿Ç°»¹²»Ã÷ÏÔÕâÁ½ÆðÊÂÎñÖ®¼äÊÇ·ñ´æÔÚ¹ØÁª¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/malware-found-payment-system-used-border-restaurants

4¡¢¿¨°Í˹»ù½¨¸´Web ProtectionÖ°ÄÜÖеĶà¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ù½¨¸´ÁËһЩ·ì϶£¬ÕâЩ·ì϶ӰÏìÁËÆäɱ¶¾Èí¼þ¡¢Internet°²È«¡¢°²È«ÔƵȲúÆ·ÖеÄWeb ProtectionÖ°ÄÜ¡£Æ¾¾Ý×êÑÐÈËÔ±Wladimir PalantµÄÃèÊö£¬¿¨°Í˹»ùWeb ProtectionÖ°ÄܱØÒªÓëÖ÷ÀûÓ÷¨Ê½½øÐÐͨѶ£¬²¢ÇÒʹÓÃÒ»¸öWebÓò²»ÖªÂ·µÄÃÜÔ¿À´È·±£°²È«Í¨Ñ¶¡£È»¶øÓÉÓÚ´æÔÚ·ì϶£¬ÍøÕ¾Äܹ»ºÜÈÝÒ׵ػñÈ¡´ËÃÜÔ¿£¬²¢ÏñWeb ProtectionÒ»ÑùÓëKasperskyÀûÓ÷¨Ê½³ÉÁ¢ÏνӺͷ¢ËͺÅÁî¡£ÈôÊÇûÓÐ×°Öÿ¨°Í˹»ùµÄä¯ÀÀÆ÷²å¼þ£¬¿¨°Í˹»ù½«Ö±½Ó½«Æä¾ç±¾×¢Èëµ½ÍøÒ³ÖС£¸Ã·ì϶£¨CVE-2019-15685£©¿ÉÓÃÓÚ¾²Ä¬½ûÓøæ°×À¹½ØºÍ¸ú×Ù± £»¤Ö°ÄÜ¡£ÔÚ7Ô·ݿ¨°Í˹»ù½¨¸´´Ë·ì϶ºó£¬×êÑÐÈËÔ±·¢ÏÖÓÖÒýÈëÁËеÄÎÊÌ⣬Ô̺¬¿Éµ¼ÖÂɱ¶¾Èí¼þ±ÀÀ£µÄ·ì϶£¨CVE-2019-15686£©ÒÔ¼°ÐÅϢй¶µÄ·ì϶£¨CVE-2019-15687£©¡£¿¨°Í˹»ùÔÚ11ÔÂ28ÈÕ°ä²¼ÁËеĽ¨¸´²¹¶¡¡£

Ô­ÎÄÁ´½Ó£º
https://www.securityweek.com/kaspersky-patches-several-vulnerabilities-web-protection-features

5¡¢·¸×ïÍÅ»ïRevengeHotelsÖØÒªÕë¶ÔÈ«Çò¾Æµê


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ù°ä²¼¹ØÓÚ·¸×ïÍÅ»ïRevengeHotelsµÄÕë¶ÔÐÔ¶ñÒâ»î¶¯µÄ·ÖÎö»ã±¨¡£¸ÃÍÅ»ïÖØÒªÕë¶Ô¾Æµê¡¢¿Íµê¡¢±ö¹ÝºÍÓÎÀÀ¹«Ë¾£¬¿¨°Í˹»ùÒÑÈ·Èϳ¬¹ý20¼Ò¾Æµê³ÉΪÊܺ¦Õߣ¬ÕâЩ¾Æµê±ðÀëλÓÚ°ÍÎ÷µÄ8¸öÖݺͰ¢¸ùÍ¢¡¢²£ÀûάÑÇ¡¢ÖÇÀûµÈ¹ú¶È¡£¸Ã·¸×ïÍÅ»ïÖ¼ÔÚÇÔÈ¡´æ´¢ÔھƵêϵͳÖÐÒÔ¼°´ÓBooking.comµÈÔÚÏß¹Û¹âÉçÇÔÈ¡µÄ¿Í»§ÐÅÓþ¿¨Êý¾Ý¡£¸ÃÍÅ»ï×Ô2015ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬µ«Æä»î¶¯ÔÚ2019Äê´ïµ½¶¥·å¡£ÖØÒªµÄ¹¥»÷ý½éÊÇͨ¹ýµç×ÓÓʼþ·¢Ë͵ĶñÒâWord¡¢Excel»òPDFÎĵµ£¬ËüÃÇÔ̺¬RevengeRAT¡¢NjRAT¡¢NanoCoreRAT¡¢888 RATµÈ¶ñÒâÈí¼þ¡£

Ô­ÎÄÁ´½Ó£º
https://securelist.com/revengehotels/95229/

6¡¢ºÉÀ¼NCSCÖÒ¸æ3ÖÖÀÕË÷Èí¼þÒÑϰȾȫÇò1800¼ÒÆóÒµ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ºÉÀ¼¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©µÄ»úÃܻ㱨ÏÔʾ£¬È«ÇòÖÁÉÙÓÐ1800¼Ò¹«Ë¾Êܵ½3ÖÖÀÕË÷Èí¼þµÄÓ°Ïì¡£ÕâÈýÖÖÀÕË÷Èí¼þ±ðÀëÊÇLockerGoga¡¢MegaCortexºÍRyuk£¬ËüÃDz¿ÃÅÒÀÀµÓÚÒ»ÑùµÄ»ù´¡ÉèÊ©£¬ÕâÅú×¢ËüÃÇ»ñÈ¡ÆóÒµÍøÂç½Ó¼ûȨÏ޵ķ½Ê½¿ÉÄÜÓëÒ»¸öµ¥Ò»ÈëÇÖÕßÓйØ¡£NCSCûÓÐÔڻ㱨ÖÐÌṩÊÜÓ°Ï칫˾µÄÃû³Æ£¬µ«°µÊ¾¹¥»÷ÕßµÄÖ¸±êÊÇÊÕÈëÆðÔ´´ïÊý°ÙÍò»òÊýÊ®ÒÚÃÀÔªµÄ´óÐÍÆóÒµ¡£Êܺ¦ÕßÀ´×ÔÆû³µ¡¢¹¹Öþ¡¢»¯Ñ§¡¢Ò½ÁÆ¡¢Ê³Æ·ºÍÓéÀֵȸ÷¸öÁìÓò£¬ÖÁÉÙÓÐÒ»¸ö¹Ø¼ü»ù´¡ÉèÊ©ÁìÓòµÄÆóÒµÔâµ½¹¥»÷¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/dutch-govt-warns-of-3-ransomware-infecting-1-800-businesses/