CISA°ä²¼ICS 5ÄêÕ½Êõ¡¶È·±£¹¤ÒµÏµÍ³°²È«£ºÍ³Ò»´òËã¡·£»Citrix½¨¸´ÍøÂç²úÆ·ÖÐ11¸ö·ì϶£¬¿Éµ¼ÖÂDoS¹¥»÷
°ä²¼¹¦·ò 2020-07-091.CISA°ä²¼ICS 5ÄêÕ½Êõ¡¶È·±£¹¤ÒµÏµÍ³°²È«£ºÍ³Ò»´òËã¡·
ÍøÂ簲ȫºÍ»ù´¡½á¹¹°²È«¾Ö£¨CISA£©°ä²¼µÄ¹¤Òµ½ÚÔìϵͳ£¨ICS£©5ÄêÕ½Êõ¡¶È·±£¹¤ÒµÏµÍ³°²È«£ºÍ³Ò»´òËã¡·ÊÇÒ»Ïî¶àÄêµÄ³Áµã¹¤×÷£¬Ö¼ÔÚÌá¸ßCISAÔ¤²â¡¢È·¶¨ÓÅÏȼ¶ºÍÖÎÀí¹ú¶È¼¶ICS·çÏÕµÄÄÜÁ¦¡£Í¨¹ýÕâÒ»¡°One CISA¡±´òË㣬CISA½«Óë¹Ø¼ü»ù´¡¼Ü¹¹£¨CI£©ËùÓÐÕߺÍÔËÓªÉ̺Ï×÷£¬³ÉÁ¢ICS°²È«Ö°ÄÜ£¬´Ó¶ø±£ÏÕICSÀûÒæÓйØÕßÃâÊÜICSÍþвµÄ·çÏÕ¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/07/07/cisa-releases-securing-industrial-control-systems-unified
2.Èí¼þͬÃË£¨BSA£©°ä²¼¹¹½¨°²È«¿¿µÃסµÄÎïÁªÍøµÄÕþ²ßºÍ×¼Ôò
BSA£¨Ò²³ÆÎªÈí¼þͬÃË£¬Ç°ÉíÊÇóÒ×Èí¼þͬÃË£©°ä²¼Á˹¹½¨°²È«¿¿µÃסµÄÎïÁªÍøµÄÕþ²ßºÍ×¼Ôò¡£ÆäºôÓõ¶ÔÏû·ÑÎïÁªÍøºÍ¹¤ÒµÎïÁªÍø½øÐзֱ棬Ìṩ¼¯³É°²È«ÐԵļ¤Àø´ëÊ©£¬Ðµ÷¹ú¶ÈºÍ¹ú¼ÊÕþ²ß£¬³ÉÁ¢¶¨ÆÚ¸üеĻù×¼°²È«ÒªÇó¡£²¢Ô¤²â£¬Ô̺¬ÎïÁªÍøÔÚÄڵĻúеÓë»úе(M2M)ÏνÓÔÚ½«À´¼¸Ä꽫Ôö³¤Ò»±¶ÒÔÉÏ£¬´Ó2018ÄêµÄ61ÒÚ´ÎÔö³¤µ½2023.1ÄêµÄ147ÒڴΡ£
ÔÎÄÁ´½Ó£º
https://www.schneier.com/blog/archives/2020/07/iot_security_pr.html
3.Citrix½¨¸´Æä¶à¿îÍøÂç²úÆ·ÖÐ11¸ö·ì϶£¬¿Éµ¼ÖÂDoS¹¥»÷
Citrix±¾Öܶþ½¨¸´ÁËÆä¶à¿îÍøÂç²úÆ·ÖеÄ11¸ö·ì϶£¬²¢Ç¿µ÷ÕâЩ·ì϶ÓëÒѱ»ÀûÓõÄCVE-2019-19781Î޹ء£Õâ´Î½¨¸´µÄ·ì϶ӰÏìÁËCitrix ADC¡¢Íø¹ØºÍSD-WAN WANÓÅ»¯£¨WANOP£©°æ±¾£¬ºÚ¿ÍÄܹ»ÀûÓÃËüÃÇÀ´µÁÊØÐÅÏ¢¡¢ÌáÒéDoS¹¥»÷¡¢½øÐб¾µØÌØÈ¨ÌáÉý¡¢ÌáÒéXSS¹¥»÷¡¢ÈƹýÊÚȨºÍ×¢Èë´úÂëµÈ¡£Ö»¹ÜijЩ·ì϶Äܹ»±»Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÀûÓ㬵«ÔÚ´óÎÞÊýÇé¿öÏ£¬ÀûÓÃÕâЩ·ì϶±ØÒªÖ¸±êϵͳ½Ó¼ûȨÏÞµÈÏȾöǰÌá¡£´Ë±í£¬ÊÜÓ°Ïì²úÆ·µÄÔÆ°æ±¾²»ÈÝÒ×Êܵ½¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/citrix-patches-11-vulnerabilities-networking-products?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Securityweek+%28SecurityWeek+RSS+Feed%29
4.NVIDIA½¨¸´ÁËGeForce ExperienceÖеĴúÂëÖ´Ðзì϶
NVIDIA½¨¸´ÁËWindows NVIDIA GeForce Experience£¨GFE£©Öеķì϶£¨CVE?2020?5964£©£¬¸Ã·ì϶ÔÊÐí±¾µØ¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂ룬ÌáÒéDoS¹¥»÷»ò½Ó¼ûÌØÈ¨ÐÅÏ¢¡£¸Ã·ì϶CVSS V3 ÆÀ·ÖΪ6.5·Ö£¬ÒªÇó¹¥»÷ÕßÓµÓб¾µØÓû§½Ó¼ûȨÏÞ²¢ÇÒÎÞ·¨Ô¶³ÌÀûÓ㬵«ÈÔÄܹ»Í¨¹ý¶ñÒ⹤¾ß½øÐÐÀûÓ᣸÷ì϶»áÓ°ÏìÔËÐÐNVIDIA GeForce Experience 3.20.4֮ǰ°æ±¾µÄWindowsϵͳ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/nvidia-fixes-code-execution-bug-in-geforce-experience-software/
5.³õ´ÎÆØ¹âµÄ¶íÂÞ˹BECÚ¿ÆÍÅ»ïÕë¶Ô²Æ¸»500Ç¿ÆóÒµ
¶íÂÞ˹BECÚ¿ÆÍÅ»ïCosmic LynxÒÀ¸½¶ñÒâÈí¼þEmotetºÍTrickBot£¬×Ô2019Äê7ÔÂÒÔÀ´£¬ÌáÒéÁ˳¬¹ý200´ÎBEC¹¥»÷£¬²¢ÓµÓÐÆäËûBECÍÅ»ïûÓеIJÙ×÷¸´ÔÓÐÔ¡£Cosmic LynxËù¹¥»÷µÄ¹«Ë¾±é²¼È«Çò£¬ÆäÖкܶàÔÚ¡¶²Æ¸»¡· 500Ç¿°ñµ¥ÖлòÔÚÈ«Çò2000Ç¿°ñµ¥ÖС£¸ÃÍÅ»ïͨ³£¼ÙÒâÖ¸±ê¹«Ë¾µÄÊ×ϯִÐй٣¬Ïò¸ß²ãÖ÷¹Ü·¢Ë͵ç×ÓÓʼþÒªÇó£¬ÒªÊµÏÖ¶ÔÒ»¼ÒÑÇÖÞ¹«Ë¾µÄÊÕ¹º¡£Ö®ºó»á·î¸æÖ¸±ê¹«Ë¾Ô±¹¤£¬µÚÈý·½Ë¾·¨ÕÕ·÷½«ÐÖúʵÏÖÂòÂôµÄ¸¶¿î£¬²¢½Ù³ÖÒ»ÃûÕæÕýÂÉʦµÄÓÊÏäÏòÊܺ¦Õß·¢ËͽéÉÜÐÔµç×ÓÓʼþ¸ÅÊö¸ÃÁ÷³Ì¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/first-reported-russian-bec-scam-gang-targets-fortune-500-firms/
6.µÂ¹úµ±¾Ö½É»ñÁËÍйÜÃÀ¹ú¾¯¾ÖÊý¾ÝBlueLeaksµÄ·þÎñÆ÷
µÂ¹úµ±¾ÖÓÚ7ÔÂ7ÈսɻñÁËÍйÜÃÀ¹ú¾¯¾ÖÊý¾ÝBlueLeaksµÄ·þÎñÆ÷£¬¸Ã·þÎñÆ÷ÊôÓÚÒ»¸ö¼¤½ø×éÖ¯DDoSecrets£¨É¢²¼Ê½»Ø¾ø±£ÃÜ£©¡£DDoSecrets°µÊ¾£¬Ëü´ÓÄäÃûºÚ¿Í×éÖ¯ÄÇÀïÊÕµ½ÁËÕâЩÎļþ£¬Ô̺¬É¨ÃèµÄÎĵµ¡¢ÊÓÆµ¡¢µç×ÓÓʼþ¡¢ÒôƵÎļþ¡¢Åàѵ×ÊÁÏ¡¢¸öÈË·¨Âɾ¯±¨ÒÔ¼°À´×Ô200¶à¸öÃÀ¹ú¾¯Ô±¾ÖºÍ·¨ÂÉÖÐÐĵÄÊý¾Ý¡£¶øBlueLeaksÊý¾ÝÊÇ´ÓÐÝ˹¶ØµÄÒ»¼ÒÏòÃÀ¹ú·¨ÂÉ»ú¹¹Ìá¹©ÍøÂçÍйܷþÎñµÄ¹«Ë¾±»ÇԵġ£´Ë±í£¬ÔÚBlueLeaks°ä²¼ËÄÌìºó£¬Twitter¹ýÎʲ¢ÓÀÔ¶²»ÈÝÁËDDoSecrets¹Ù·½TwitterÕÊ»§£¬ÓÉÓÚÆäÓøÃÕÊ»§À´´«²¼BlueLeaks¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/german-authorities-seize-blueleaks-server-that-hosted-data-on-us-cops/#ftag=RSSbaffb68


¾©¹«Íø°²±¸11010802024551ºÅ