CodeMeterÖдæÔÚÑϳÁ·ì϶£¬¿Éµ¼ÖÂOT¹©¸øÁ´¹¥»÷£»ACSC°ä²¼¡¶2019¨C2020Äê¶ÈÍøÂçÍþв»ã±¨¡·
°ä²¼¹¦·ò 2020-09-11
Claroty·¢ÏÖÎ÷ÃÅ×ӵȶ¥¼¶ICS¹©¸øÉÌʹÓõĵÚÈý·½¹¤Òµ×é¼þCodeMeterÖдæÔÚ6¸öÑϳÁµÄ·ì϶£¬»ò½«µ¼ÖÂOT¹©¸øÁ´¹¥»÷£¬ÕâЩ·ì϶µÄCVSSÆÀ·Ö¾ùΪ10.0¡£CISA°µÊ¾£¬¹¥»÷Õ߳ɹ¦ÀûÓÃÕâЩ·ì϶ºó¿É¸ü¸ÄºÍαÔìÐí¿ÉÖ¤Îļþ£¬µ¼Ö»ؾø·þÎñÇé¿ö£¬Ç±ÔÚµØÊµÏÖÔ¶³ÌÖ´ÐдúÂë¡¢¶ÁÈ¡¶ÑÊý¾Ý²¢×èÖ¹ÒÀÀµCodeMeterµÄµÚÈý·½Èí¼þµÄÕý³£ÔËÐС£ÆäÖÐ×îÑϳÁµÄ·ì϶¿Éͨ¹ý·ÛËéCodeMeterͨѶºÍ̸ºÍÄÚ²¿APÒÔIÔ¶³ÌÖ´ÐдúÂ룬ʵÏÖICSϵͳµÄÆëÈ«ÊÕÊÜ¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/critical-bugs-enable-ot-supply/
2.ºÚ¿Í¹¥»÷˹Âå·¥¿Ë¼ÓÃÜÇ®±ÒÂòÂôËù£¬µÁÈ¡¼ÛÖµ540ÍòÃÀԪǮ±Ò

ºÚ¿Í¹¥»÷˹Âå·¥¿Ë¼ÓÃÜÇ®±ÒÂòÂôËùETERBASE£¬µÁÈ¡Á˼ÛÖµ540ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò¡£¸Ã¹«Ë¾ÓÚ±¾ÖÜËÄÅû¶¸ÃÊÂÎñ£¬°µÊ¾Æä´æ´¢Á˱ÈÌØ±Ò¡¢ÒÔÌ«±Ò¡¢ALGO¡¢Ripple¡¢TezosºÍTRONµÄÁù¸ö¼ÓÃÜÇ®°üÎļþ±»µÁ£¬ÆäÒѼì²âµ½¹¥»÷£¬µ«ÎÞ·¨×èÖ¹ËüµÄ²úÉú¡£ETERBASE°µÊ¾£¬ËüÔÚÕâЩǮ±Ò±»µÁʱ¾Í¶ÔÆä½øÐÐÁ˸ú×Ù£¬Ä¿Ç°±»µÁ×ʽðÔÚ¸÷×ÔÇø¿éÁ´ÉϵÄ×ªÒÆ£¬¸Ã¹«Ë¾Ò²ÁªÏµÁ˱»µÁ×Ê½ðµØµãµÄÂòÂôËùÒÔ¶³½á±»µÁ×ʽð¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/slovak-cryptocurrency-exchange-eterbase-discloses-5-4-million-hack/
3.×êÑÐÈËÔ±·¢ÏÖÐÂÐ͹¥»÷Raccoon£¬Õë¶ÔTLS¼ÓÃܺÍ̸ÇÔÊØÐÅÏ¢

×êÑÐÈËÔ±Åû¶ÁËÕë¶ÔTLS¼ÓÃܺÍ̸µÄÐÂÐ͹¥»÷·½Ê½Raccoon£¬¸Ã¹¥»÷¿ÉÓÃÓÚ½âÃÜÓû§ºÍ·þÎñÆ÷Ö®¼äµÄHTTPSÏνӲ¢¶ÁÈ¡Ãô¸ÐͨѶ¡£Raccoon¹¥»÷´Óµ××ÓÉÏ˵Êǰ´Ê±¹¥»÷£¬¹¥»÷Õß»áÕÉÁ¿Ö´ÐÐÒÑÖªÃÜÂë²Ù×÷ËùÐèµÄ¹¦·ò£¬ÒÔÈ·¶¨²¿ÃÅËã·¨¡£×êÑÐÈËÔ±³Æ£¬ËùÓÐʹÓÃDiffie-HellmanÃÜÔ¿»¥»»À´³ÉÁ¢TLSÏνӵķþÎñÆ÷¶¼ÈÝÒ×Êܵ½´ËÀ๥»÷¡£Ä¿Ç°£¬Ò»Ð©¹©¸øÉÌ£¬ÈçMicrosoft¡¢Mozilla¡¢OpenSSLºÍF5 NetworksÒѰ䲼°²È«¸üÐÂÒÔ×èÖ¹Raccoon¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/raccoon-attack-allows-hackers-to-break-tls-encryption-under-certain-conditions/
4.ZeppelinÉý¼¶»Ø¹é£¬ÒÔ·¢Æ±ÎªÖ÷Ìâ´«²¼ÐµÄľÂí

×êÑÐÈËÔ±Juniper Threatlab·¢ÏÖZeppelinÉý¼¶»Ø¹é£¬ÒÔ·¢Æ±ÎªÖ÷Ìâ´«²¼ÐµÄľÂí¡£ÔÚ×îÐµĹ¥»÷»î¶¯ÖУ¬ºÚ¿ÍÒÀȻʹÓôøÓжñÒâºêµÄÖ÷ÌâΪ·¢Æ±´¹µöµç×ÓÓʼþ¡£ºÚ¿Í½«Visual Basic¾ç±¾µÄƬ¶Î°µ²ØÔÚ¸÷ÀàͼÏñºóµÄÀ¬»øÎı¾ÖУ¬¶ñÒâºê»á½âÎö²¢ÌáÈ¡ÕâЩ¾ç±¾£¬¶øºó½«ÆäдÈëc£º\wordpress\about1.vbsÖеÄÎļþÖС£Ö®ºó£¬ÀûÓõڶþ¸öºêÖ´ÐÐabout1.vbs£¬ÒÔÏÂÔØÐµÄľÂí¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/zeppelin-ransomware-returns-trojan/159092/
5.ÈýÐǰ䲼°²È«¸üУ¬½¨¸´GalaxyÉϵĶà¸ö·ì϶

ÔÚAndroid°ä²¼ÁË9Ô°²È«¸üкó£¬ÈýÐÇÒ²°ä²¼Á˰²È«¸üУ¬½¨¸´ÆäGalaxyÉϵĶà¸ö·ì϶¡£Õâ´Î½¨¸´µÄ×îÑϳÁµÄ·ì϶֮һ±»×·×ÙΪCVE-2020-0245£¬Ó°ÏìÁËMedia Framework×é¼þ£¬¿Éµ¼ÖÂÔ¶³ÌÖ´ÐдúÂëºÍÐÅÏ¢Åû¶¡£´Ë±í£¬»¹½¨¸´ÁËÆäFramework¡¢Media FrameworkºÍϵͳÖеĶà¸öȨÏÞÌáÉý·ì϶£¨CVE-2020-0074¡¢CVE-2020-0388¡¢CVE-2020-0391¡¢CVE-2020-0401¡¢CVE-2020-0392¡¢CVE-2020-0386ºÍCVE-2020-0394£©¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/samsung-fixes-critical-android-flaws-with-september-updates/
6.ACSC°ä²¼¡¶2019¨C2020Äê¶ÈÍøÂçÍþв»ã±¨¡·

°Ä´óÀûÑÇÍøÂ簲ȫÖÐÐÄ£¨ACSC£©ÒѰ䲼ÓйØ2019-2020ÄêÖØÒªÍøÂçÍþвºÍͳ¼ÆÊý¾ÝµÄÄê¶È»ã±¨¡£¸Ã»ã±¨Ç¿µ÷Ö¸³ö£¬ÍøÂç´¹µöºÍÓã²æ´¹µöÒÀÈ»ÊǺڿͻñÈ¡Ó×ÎÒÐÅÏ¢»òÓû§Ö¤ÊéÒÔ½øÈëÍøÂç»ò´«²¼¶ñÒâÄÚÈݵÄ×î³£¼û²½Ö裬ÀÕË÷Èí¼þÒѳÉΪ¶ÔÆóÒµºÍµ±¾ÖµÄ³Á´óÍþв¡£ºÚ¿Íͨ³£Í¨¹ýÓã²æÊ½´¹µö·¸·¨»ñÈ¡Óû§µÇ¼ºÍÖ¤Ê飬¶øºóÀûÓÃÔ¶³Ì×ÀÃæºÍ̸(RDP)·þÎñ×°ÖÃÀÕË÷Èí¼þ¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/09/10/acsc-releases-annual-cyber-threat-report-2019-2020


¾©¹«Íø°²±¸11010802024551ºÅ