µ¤Âó˰Îñ·þÎñй¶120Íò¹«ÃñµÄCPRºÅÂë £»Dell½¨¸´SupportAssistÖеIJ»³ÉÐÅËÑË÷õè¾¶·ì϶

°ä²¼¹¦·ò 2020-02-11

1.µ¤Âó˰Îñ·þÎñй¶120Íò¹«ÃñµÄCPRºÅÂë


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µ¤Âóµ±¾Ö·¢ÏÖTastSelv Borger˰Îñ·þÎñй¶ÁË120Íò¹«ÃñµÄCPR£¨µ¤ÂóÉí·ÝÖ¤¼þ£©ºÅÂë¡£¸Ã·þÎñÓÉÃÀ¹úDXC Technology¹«Ë¾ÖÎÀí £¬ÔÊÐíµ¤Âó¹«Ãñ²é¿´ºÍ¸ü¸ÄÆäÄÉ˰É걨±í¡¢Äê¶È±¨±í²¢½ÉÄÉÔü×Ò˰¿î¡£ÔÚ·¢ÏÖ֮ǰ £¬Ô̺¬CPRºÅÔÚÄÚµÄÊý¾ÝÒѶ³öÁ˽«½üÎåÄêµÄ¹¦·ò¡£DR NewsÍøÕ¾»ã±¨³Æ £¬Ò»µ©µÇ¼Tastselv BorgerµÄÓû§¸üÕýÁËËûÃǵÄÁªÏµÐÅÏ¢ £¬ÀûÓ÷¨Ê½ÖеÄÃýÎó¾Í»áµ¼ÖÂCPRºÅ×÷ÎªÍøÖ·µÄÒ»²¿ÃÅ·¢Ë͵½GoogleºÍAdobe¡£DXCÒÑÈ·Èϸ÷ì϶²¢Òѽâ¾ö¸ÃÎÊÌâ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/97571/data-breach/1-2m-cpr-numbers-leak.html


2.ÒÔÉ«Áа²È«¶ÓÁнü3¸öÔÂÄÚÊܵ½10000´ÎÍøÂç¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾ÝÏ£²®À´ÓïÐÂÎÅÍøÕ¾YnetÖÜÈÕ±¨Â· £¬ÔÚ´ÓǰµÄÈý¸öÔÂÖÐ £¬ÒÔÉ«Áа²È«¶ÓÁеÄÊ®¸öÖØÒªÍøÕ¾³ÉΪÁË10000¶àÆðÍøÂç¹¥»÷µÄÖ¸±ê¡£¸ÃÊý¾ÝÊÇ»ùÓÚÒÔÉ«ÁÐ-ÃÀ¹úÍøÂ簲ȫ¹«Ë¾ImpervaµÄ»ã±¨ £¬»ã±¨Öл¹ÏÔʾÁí±íÔ¼40¸öÒÔÉ«ÁÐ˾·¨ºÍµ±¾ÖÍøÕ¾Ôâµ½ÁËÊýǧ´ÎÒÔÉϵÄÍøÂç¹¥»÷¡£ÒÔÉ«Áйú¶ÈÍøÂçÖÎÀí¾Ö³Æµ±¾ÖÍøÕ¾Êܵ½¸ß¶ÈÏȽøµÄ·ÀÓùϵͳµÄ± £»¤ £¬ÕâЩ¹¥»÷¶ÔÆäûÓÐÓ°Ïì¡£


Ô­ÎÄÁ´½Ó£º

http://www.xinhuanet.com/english/2020-02/10/c_138768894.htm


3.¹¥»÷ÕßÀûÓÃÃâ·ÑÈí¼þLock My PCËø¶¨Óû§ÍÆËã»ú


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¼¼ÊõÖ§³¶à¿Æ­ÕßʹÓÃÃûΪLock My PCµÄÃâ·Ñ¹¤¾ßÀ´Ëø¶¨Óû§µÄÍÆËã»ú £¬²¢ÒªÇóÖ§¸¶½âËøÓöÈ¡£¶àÄêÀ´¼Ù×°³É΢Èí¡¢¹È¸èµÈ¹«Ë¾µÄ¼¼ÊõÖ§³¶à¿Æ­ÕßÒ»ÏòÔÚʹÓÃWindows Syskey·¨Ê½½«Óû§µÄÏµÍ³Ëø¶¨ £¬µ«ÓÉÓÚ΢ÈíÔÚWindows 10 1709ÖÐɾ³ýÁ˶ÔSyskeyµÄËùÓÐÖ§³Ö £¬Òò¶øÚ¿Æ­ÕßÒÑÇл»µ½Lock My PC¡£ÓëSyskey¼ÓÃÜWindows SAMÊý¾Ý¿â²¢Ê¹ÓÃÊäÈëµÄÃÜÂë¶ÔÆä½øÐнâÃÜ·ÖÆç £¬Lock My PC²»¼ÓÃÜÈκÎÄÚÈÝ £¬½öʹÓÃÃÜÂë×èÖ¹¶ÔÍÆËã»úµÄ½Ó¼û¡£¸ÃÈí¼þ»¹ÒÔ°²È«Ä£Ê½ÔËÐÐ £¬Ê¹µÃûÓÐÃÜÂë»òboot¸´Ô­¹¤¾ßʱºÜÄѽûÓÃËü¡£Lock My PCµÄ¿ª·¢ÈËÔ±FSPro Labs·¢ÏÔìäÈí¼þ±»ÀÄÓúó°ä·¢²»ÔÙÌṩÃâ·Ñ°æ±¾ £¬²¢ÇÒΪÊܺ¦ÕßÌṩÁËÃâ·ÑµÄ¸´Ô­ÃÜÂë¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/lock-my-pc-used-by-tech-support-scammers-dev-offers-free-recovery/


4.Â׶عú¶ÈФÏñ»­ÀÈÔÚ2019ÄêQ4Ôâµ½½ü35Íò·âÀ¬»øÓʼþ¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÓ¢¹úÐÅÏ¢×ÔÓÉ·¨°¸Åû¶µÄÊý¾Ý £¬Parliament StreetÖǿⷢÏÖÂ׶عú¶ÈФÏñ»­ÀÈÔÚ2019ÄêµÚËÄʱ¶ÈÔâµ½½ü35Íò´ÎÀ¬»øÓʼþ¹¥»÷¡£¹ú¶ÈФÏñ»­ÀÈÊÇÂ×¶Ø×ʢÃûµÄÃÀÊõ¹ÝÖ®Ò» £¬Ã¿Äê»¶Ó­110ÍòÖÁ120ÍòÓοÍ £¬Æä·þÎñÆ÷´æ´¢Á˺ܶàÓο͵ĸ¶¿îÃ÷ϸºÍµç×ÓÓʼþµØÖ·µÈ¸öÈËÐÅÏ¢¡£ÔÚÕâ½ü35Íò·â±»×èÖ¹µÄÀ¬»øÓʼþÖÐ £¬ÓÐ56%±»¼ø±ðΪÕʺÅÍøÂç¹¥»÷ £¬Áí±í61710·âÊÇÓÉÓÚ·¢¼þÈËÔÚ¡°Íþвµý±¨ºÚÃûµ¥¡±É϶ø±»×èÖ¹ £¬»¹ÓÐ85793·â±»ÒÔΪÔ̺¬À¬»øÓʼþÄÚÈÝÒÔ¼°418·âÔ̺¬²¡¶¾¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/national-portrait-gallery-email


5.¼ÓÃÜÂòÂôËùAltsbitÔâºÚ¿Í¹¥»÷ £¬½«ÓÚ5ÔÂ8ÈչعØ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾Ý±¨Â· £¬×ܲ¿Î»ÓÚÒâ´óÀûµÄ¼ÓÃÜÇ®±ÒÂòÂôƽ̨Altsbit°µÊ¾Ôâµ½ºÚ¿ÍÈëÇÖ £¬ÏÕЩËùÓÐBTC¡¢ETH¡¢ARRRºÍVRSC×ʽ𶼱»µÁ £¬Ö»ÓÐÒ»Óײ¿ÃÅ·ÅÔÚÀäÇ®°üÖеÄ×ʽðÊǰ²È«µÄ¡£½ØÖÁ·¢¸åʱ £¬ËðʧµÄBTCºÍETHµÄ¼ÛֵԼΪ6.3ÍòÃÀÔª¡£¸ÃÂòÂôËù°µÊ¾Ã»ÓÐ×ã¹»µÄ×ʽðÀ´Åâ³¥Óû§ £¬Òò¶øÒªÇóÓû§ÉêÇ벿ÃÅÍ˿Í˿·òΪ2ÔÂ10ÈÕµ½5ÔÂ8ÈÕ £¬ÔÚ´ËÈÕÆÚÖ®ºó¸ÃÂòÂôËù½«¹Ø¹Ø¡£ºÚ¿Í×éÖ¯LulzSecÔÚTwitterÖÐÐû³Æ¶Ô´ËÊÂÎñÕÆ¹Ü¡£


Ô­ÎÄÁ´½Ó£º

https://www.coindesk.com/new-crypto-exchange-altsbit-says-it-will-close-following-hack


6.Dell½¨¸´SupportAssistÖеIJ»³ÉÐÅËÑË÷õè¾¶·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Dell°ä²¼°²È«¸üР£¬½¨¸´SupportAssist ClientÈí¼þÖеÄÒ»¸ö²»³ÉÐÅËÑË÷õè¾¶·ì϶ £¬¸Ã·ì϶£¨CVE-2020-5316£©ÔÊÐíDZÔڵı¾µØ¹¥»÷ÕßÔÚÒ×Êܹ¥»÷µÄÍÆËã»úÉÏÒÔÖÎÀíԱȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£SupportAssistÊÇԤװÖÃÔÚ´óÎÞÊýDellÉ豸ÉϵÄÖ§³ÖÈí¼þ £¬Òò¶ø¸Ã·ì϶µÄDZÔÚÓ°ÏìÁìÓò½Ï¹ã¡£Æ¾¾ÝDellµÄ·ì϶´«µÝ £¬¾­¹ý±¾µØÉí·ÝÑéÖ¤µÄµÍÌØÈ¨Óû§¿ÉÄÜÀûÓô˷ì϶µ¼ÖÂSupportAssist¶þ½øÔìÎļþ¼ÓÔØËÁÒâDLL £¬´Ó¶øµ¼ÖÂÌØÈ¨´úÂëµÄÖ´ÐС£¸Ã·ì϶µÄCVSSv3¸ù»ùµÃ·ÖΪ7.8·Ö £¬Ó°ÏìÁËÉÌÓÃPCµÄSupportAssist 2.1.3»ò¸üÔç°æ±¾ £¬ÒÔ¼°¼ÒÓÃPCµÄSupportAssist 3.4»ò¸üÔç°æ±¾¡£DellÒѾ­ÔÚа汾Öн¨¸´Á˸÷ì϶ £¬ÈôÊÇÆôÓÃÁË×Ô¶¯Éý¼¶ £¬ÔòËùÓа汾µÄSupportAssist³ÇÊÐ×Ô¶¯×°ÖÃ×îп¯Ðеİ汾¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/dell-supportassist-bug-exposes-business-home-pcs-to-attacks/