CISA°ä²¼ICS 5ÄêÕ½Êõ¡¶È·±£¹¤ÒµÏµÍ³°²È«£ºÍ³Ò»´òËã¡·£»Citrix½¨¸´ÍøÂç²úÆ·ÖÐ11¸ö·ì϶£¬¿Éµ¼ÖÂDoS¹¥»÷

°ä²¼¹¦·ò 2020-07-09

1.CISA°ä²¼ICS 5ÄêÕ½Êõ¡¶È·±£¹¤ÒµÏµÍ³°²È«£ºÍ³Ò»´òËã¡·


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÍøÂ簲ȫºÍ»ù´¡½á¹¹°²È«¾Ö£¨CISA£©°ä²¼µÄ¹¤Òµ½ÚÔìϵͳ£¨ICS£©5ÄêÕ½Êõ¡¶È·±£¹¤ÒµÏµÍ³°²È«£ºÍ³Ò»´òËã¡·ÊÇÒ»Ïî¶àÄêµÄ³Áµã¹¤×÷£¬Ö¼ÔÚÌá¸ßCISAÔ¤²â¡¢È·¶¨ÓÅÏȼ¶ºÍÖÎÀí¹ú¶È¼¶ICS·çÏÕµÄÄÜÁ¦ ¡£Í¨¹ýÕâÒ»¡°One CISA¡±´òË㣬CISA½«Óë¹Ø¼ü»ù´¡¼Ü¹¹£¨CI£©ËùÓÐÕߺÍÔËÓªÉ̺Ï×÷£¬³ÉÁ¢ICS°²È«Ö°ÄÜ£¬´Ó¶ø±£ÏÕICSÀûÒæÓйØÕßÃâÊÜICSÍþвµÄ·çÏÕ ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/07/cisa-releases-securing-industrial-control-systems-unified


2.Èí¼þͬÃË£¨BSA£©°ä²¼¹¹½¨°²È«¿¿µÃסµÄÎïÁªÍøµÄÕþ²ßºÍ×¼Ôò


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


BSA£¨Ò²³ÆÎªÈí¼þͬÃË£¬Ç°ÉíÊÇóÒ×Èí¼þͬÃË£©°ä²¼Á˹¹½¨°²È«¿¿µÃסµÄÎïÁªÍøµÄÕþ²ßºÍ×¼Ôò ¡£ÆäºôÓõ¶ÔÏû·ÑÎïÁªÍøºÍ¹¤ÒµÎïÁªÍø½øÐзֱ棬Ìṩ¼¯³É°²È«ÐԵļ¤Àø´ëÊ©£¬Ð­µ÷¹ú¶ÈºÍ¹ú¼ÊÕþ²ß£¬³ÉÁ¢¶¨ÆÚ¸üеĻù×¼°²È«ÒªÇó ¡£²¢Ô¤²â£¬Ô̺¬ÎïÁªÍøÔÚÄڵĻúеÓë»úе(M2M)ÏνÓÔÚ½«À´¼¸Ä꽫Ôö³¤Ò»±¶ÒÔÉÏ£¬´Ó2018ÄêµÄ61ÒÚ´ÎÔö³¤µ½2023.1ÄêµÄ147ÒÚ´Î ¡£


Ô­ÎÄÁ´½Ó£º

https://www.schneier.com/blog/archives/2020/07/iot_security_pr.html


3.Citrix½¨¸´Æä¶à¿îÍøÂç²úÆ·ÖÐ11¸ö·ì϶£¬¿Éµ¼ÖÂDoS¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Citrix±¾Öܶþ½¨¸´ÁËÆä¶à¿îÍøÂç²úÆ·ÖеÄ11¸ö·ì϶£¬²¢Ç¿µ÷ÕâЩ·ì϶ÓëÒѱ»ÀûÓõÄCVE-2019-19781ÎÞ¹Ø ¡£Õâ´Î½¨¸´µÄ·ì϶ӰÏìÁËCitrix ADC¡¢Íø¹ØºÍSD-WAN WANÓÅ»¯£¨WANOP£©°æ±¾£¬ºÚ¿ÍÄܹ»ÀûÓÃËüÃÇÀ´µÁÊØÐÅÏ¢¡¢ÌáÒéDoS¹¥»÷¡¢½øÐб¾µØÌØÈ¨ÌáÉý¡¢ÌáÒéXSS¹¥»÷¡¢ÈƹýÊÚȨºÍ×¢Èë´úÂëµÈ ¡£Ö»¹ÜijЩ·ì϶Äܹ»±»Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÀûÓ㬵«ÔÚ´óÎÞÊýÇé¿öÏ£¬ÀûÓÃÕâЩ·ì϶±ØÒªÖ¸±êϵͳ½Ó¼ûȨÏÞµÈÏȾöǰÌá ¡£´Ë±í£¬ÊÜÓ°Ïì²úÆ·µÄÔÆ°æ±¾²»ÈÝÒ×Êܵ½¹¥»÷ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/citrix-patches-11-vulnerabilities-networking-products?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Securityweek+%28SecurityWeek+RSS+Feed%29


4.NVIDIA½¨¸´ÁËGeForce ExperienceÖеĴúÂëÖ´Ðзì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


NVIDIA½¨¸´ÁËWindows NVIDIA GeForce Experience£¨GFE£©Öеķì϶£¨CVE?2020?5964£©£¬¸Ã·ì϶ÔÊÐí±¾µØ¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂ룬ÌáÒéDoS¹¥»÷»ò½Ó¼ûÌØÈ¨ÐÅÏ¢ ¡£¸Ã·ì϶CVSS V3 ÆÀ·ÖΪ6.5·Ö£¬ÒªÇó¹¥»÷ÕßÓµÓб¾µØÓû§½Ó¼ûȨÏÞ²¢ÇÒÎÞ·¨Ô¶³ÌÀûÓ㬵«ÈÔÄܹ»Í¨¹ý¶ñÒ⹤¾ß½øÐÐÀûÓà ¡£¸Ã·ì϶»áÓ°ÏìÔËÐÐNVIDIA GeForce Experience 3.20.4֮ǰ°æ±¾µÄWindowsϵͳ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nvidia-fixes-code-execution-bug-in-geforce-experience-software/


5.³õ´ÎÆØ¹âµÄ¶íÂÞ˹BECÚ¿Æ­ÍÅ»ïÕë¶Ô²Æ¸»500Ç¿ÆóÒµ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶íÂÞ˹BECÚ¿Æ­ÍÅ»ïCosmic LynxÒÀ¸½¶ñÒâÈí¼þEmotetºÍTrickBot£¬×Ô2019Äê7ÔÂÒÔÀ´£¬ÌáÒéÁ˳¬¹ý200´ÎBEC¹¥»÷£¬²¢ÓµÓÐÆäËûBECÍÅ»ïûÓеIJÙ×÷¸´ÔÓÐÔ ¡£Cosmic LynxËù¹¥»÷µÄ¹«Ë¾±é²¼È«Çò£¬ÆäÖкܶàÔÚ¡¶²Æ¸»¡· 500Ç¿°ñµ¥ÖлòÔÚÈ«Çò2000Ç¿°ñµ¥ÖÐ ¡£¸ÃÍÅ»ïͨ³£¼ÙÒâÖ¸±ê¹«Ë¾µÄÊ×ϯִÐйÙ£¬Ïò¸ß²ãÖ÷¹Ü·¢Ë͵ç×ÓÓʼþÒªÇó£¬ÒªÊµÏÖ¶ÔÒ»¼ÒÑÇÖÞ¹«Ë¾µÄÊÕ¹º ¡£Ö®ºó»á·î¸æÖ¸±ê¹«Ë¾Ô±¹¤£¬µÚÈý·½Ë¾·¨ÕÕ·÷½«Ð­ÖúʵÏÖÂòÂôµÄ¸¶¿î£¬²¢½Ù³ÖÒ»ÃûÕæÕýÂÉʦµÄÓÊÏäÏòÊܺ¦Õß·¢ËͽéÉÜÐÔµç×ÓÓʼþ¸ÅÊö¸ÃÁ÷³Ì ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/first-reported-russian-bec-scam-gang-targets-fortune-500-firms/


6.µÂ¹úµ±¾Ö½É»ñÁËÍйÜÃÀ¹ú¾¯¾ÖÊý¾ÝBlueLeaksµÄ·þÎñÆ÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µÂ¹úµ±¾ÖÓÚ7ÔÂ7ÈսɻñÁËÍйÜÃÀ¹ú¾¯¾ÖÊý¾ÝBlueLeaksµÄ·þÎñÆ÷£¬¸Ã·þÎñÆ÷ÊôÓÚÒ»¸ö¼¤½ø×éÖ¯DDoSecrets£¨É¢²¼Ê½»Ø¾ø±£ÃÜ£© ¡£DDoSecrets°µÊ¾£¬Ëü´ÓÄäÃûºÚ¿Í×éÖ¯ÄÇÀïÊÕµ½ÁËÕâЩÎļþ£¬Ô̺¬É¨ÃèµÄÎĵµ¡¢ÊÓÆµ¡¢µç×ÓÓʼþ¡¢ÒôƵÎļþ¡¢Åàѵ×ÊÁÏ¡¢¸öÈË·¨Âɾ¯±¨ÒÔ¼°À´×Ô200¶à¸öÃÀ¹ú¾¯Ô±¾ÖºÍ·¨ÂÉÖÐÐĵÄÊý¾Ý ¡£¶øBlueLeaksÊý¾ÝÊÇ´ÓÐÝ˹¶ØµÄÒ»¼ÒÏòÃÀ¹ú·¨ÂÉ»ú¹¹Ìá¹©ÍøÂçÍйܷþÎñµÄ¹«Ë¾±»Ç﵀ ¡£´Ë±í£¬ÔÚBlueLeaks°ä²¼ËÄÌìºó£¬Twitter¹ýÎʲ¢ÓÀÔ¶²»ÈÝÁËDDoSecrets¹Ù·½TwitterÕÊ»§£¬ÓÉÓÚÆäÓøÃÕÊ»§À´´«²¼BlueLeaks ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/german-authorities-seize-blueleaks-server-that-hosted-data-on-us-cops/#ftag=RSSbaffb68