¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190320
°ä²¼¹¦·ò 2019-03-20
±¾ÖÜÒ»£¨3ÔÂ18ÈÕ£©Íí¼äŲÍþÂÁÒµ¾ÞÍ·Norsk HydroÔâµ½´ó¹æÄ£ÍøÂç¹¥»÷£¬£¬£¬£¬£¬¼¸¼Ò¹¤³§±»Ò»Ê±¹Ø¹Ø¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÐÂÎŰ䲼»áÉÏ£¬£¬£¬£¬£¬Norsk HydroÊ×ϯ²ÆÕþ¹ÙEivind Kallevikй©¸Ã¹«Ë¾Ôâµ½½ÏеÄÀÕË÷Èí¼þLockerGogaµÄ¹¥»÷£¬£¬£¬£¬£¬Æä³ö²ú¼°ÔËÓª¾ùÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾±»ÆÈÔÚŲÍþ¡¢¿¨Ëþ¶ûºÍ°ÍÎ÷µÈ¹ú¶ÈÇл»ÖÁÈËΪ²Ù×÷£¬£¬£¬£¬£¬ÒÔ¸´ÔÆäÔËÓª»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£Kallevik»¹°µÊ¾¸Ã¹«Ë¾ÒѾ¿ÉÄÜ´¦ÖÃËùÓпͻ§µÄ¶©µ¥²¢½»¸¶£¬£¬£¬£¬£¬µ«½«À´µÄ¶©µ¥¿ÉÄÜ»áÊܵ½Ó°Ï죬£¬£¬£¬£¬ÓÉÓÚ¹«Ë¾ÍøÂçÈÔδ¸´Ô¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/lockergoga-ransomware-sends-norsk-hydro-into-manual-mode/2¡¢Libssh2°ä²¼°²È«¸üУ¬£¬£¬£¬£¬¹²½¨¸´9¸ö°²È«·ì϶
±¾ÖÜÒ»libssh2°ä²¼Ð°汾1.8.1£¬£¬£¬£¬£¬¹²½¨¸´9¸ö°²È«·ì϶£¬£¬£¬£¬£¬Ô̺¬Ô½½çд·ì϶£¨CVE-2019-3855~CVE-2019-3857¼°CVE-2019-3863£©ºÍÔ½½ç¶Á·ì϶£¨CVE-2019-3858~CVE-2019-3862£©¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶ӰÏìÁËLibssh2 1.8.1֮ǰµÄËùÓа汾£¬£¬£¬£¬£¬ÈôÊDZ»ÀûÓÿɵ¼ÖÂËÁÒâ´úÂëÖ´Ðм°»Ø¾ø·þÎñµÈÑϳÁºó¹û£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì½øÐиüС£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/03/libssh2-vulnerabilities.html3¡¢89£¥µÄÅ·Ã˵±¾ÖÍøÕ¾´æÔÚµÚÈý·½¸æ°×¸ú×پ籾
µ¤Âóä¯ÀÀÆ÷·ÖÎö¹«Ë¾CookiebotÔÚ25¸öÅ·Ã˳ÉÔ±¹úÈ·µ±¾Ö¹ÙÍøÉÏ·¢ÏÖ¸æ°×¸ú×پ籾£¬£¬£¬£¬£¬Õâ»òÐíÕ¼×ܹ²28¸ö³ÉÔ±¹úµÄ89%£¬£¬£¬£¬£¬Ö»Óе¹ú¡¢Î÷°àÑÀºÍºÉÀ¼È·µ±¾ÖÍøÕ¾Ã»ÓÐóÒ׸æ°×¸ú×ÙÆ÷¡£¡£¡£¡£¡£¡£¡£¡£·¨¹úµ±¾ÖÍøÕ¾Éϵĸæ°×¸ú×ÙÆ÷×î¶à£¬£¬£¬£¬£¬ÓÐ52¼Ò·ÖÆçµÄ¹«Ë¾ÔÚ¸ú×ÙÓû§µÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ¸æ°×¸ú×ÙÆ÷ÖØÒªÊÇÔÚµÚÈý·½²å¼þµÄÔ®ÊÖÏÂÉøÈë½øµ±¾ÖÍøÕ¾£¬£¬£¬£¬£¬ÀýÈçÊÓÆµ²¥·ÅÆ÷²å¼þ¡¢ÍøÕ¾·ÖÎö¼°Í¼±í²å¼þµÈ¡£¡£¡£¡£¡£¡£¡£¡£ÕâÏÔȻΥ·´ÁËÅ·Ã˵ÄÊý¾Ý±£»£»£»£»£»£»£»£»¤ÂÉÀýGDPR¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/89-percent-of-eu-government-sites-infiltrated-by-ad-tracking-scripts/4¡¢×êÑÐÍŶӷ¢ÏÖÁ½¸öÕë¶ÔNetflixºÍAMEXµÄ´ó¹æÄ£´¹µö¹¥»÷
Office 365Íþв×êÑÐÍŶӷ¢ÏÖÁ½¸öÕë¶ÔNetflixºÍAMEX£¨ÃÀ¹úÔËͨ£©µÄ´ó¹æÄ£ÍøÂç´¹µö»î¶¯£¬£¬£¬£¬£¬Õë¶ÔNetflix¿Í»§¶ËµÄ´¹µö»î¶¯½«Êܺ¦Õß³Á¶¨Ïòµ½Ò»¸öÐéαµÄÏÂÔØ±íµ¥£¬£¬£¬£¬£¬¸Ã±íµ¥»áÍøÂçÓû§µÄÐÅÓþ¿¨ÐÅÏ¢£¨Ô̺¬¿¨ºÅ¡¢µ½ÆÚÈÕÆÚ¡¢PINÂëºÍ°²È«Â룩ºÍÕ˵¥ÐÅÏ¢£¨Ô̺¬ÐÕÃû¡¢ÓÊÏ䵨ַ¡¢SSN¡¢×¡Ö·¡¢µç»°ºÅÂëºÍµ®ÉúÈÕÆÚ£©¡£¡£¡£¡£¡£¡£¡£¡£Õë¶ÔAMEXÓû§µÄ´¹µö»î¶¯Ôò»áÍøÂçÓ×ÎÒÐÅÏ¢ºÍÐÅÓþ¿¨ÐÅÏ¢£¬£¬£¬£¬£¬ÒÔ¼°Óû§IDºÍÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/netflix-and-amex-customers-actively-targeted-by-phishing-campaigns/5¡¢ÐÂSextortion´¹µöÓʼþ£¬£¬£¬£¬£¬¼Ù×°³ÉCIA½øÐÐÚ²Æ
ÉÏÖÜÄ©³öÏÖÁËÒ»¸öеÄsextortion´¹µö»î¶¯£¬£¬£¬£¬£¬¸Ã´¹µöÓʼþ¼Ù×°³ÉCIAµÄ¹ú¼Ê·¨Âɵ÷²é£¬£¬£¬£¬£¬Ðû³ÆÊܺ¦ÕßÒò²Î¼Ó·Ö·¢ºÍ´æ´¢¶ùͯɫÇéÄÚÈݱ»µ÷²é£¬£¬£¬£¬£¬³ý·ÇÖ§¸¶¼ÛÖµ1ÍòÃÀÔªµÄ±ÈÌØ±Ò£¬£¬£¬£¬£¬²»È»½«ÔÚ2019Äê4ÔÂ8ÈÕ±»´þ²¶¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩµç×ÓÓʼþµÄ·¢Ë͵ØÖ·Ô̺¬cia¡¢govºÍmlµÈÎı¾£¬£¬£¬£¬£¬Ê¹Æä¿´ËÆÀ´×ÔÓÚµ±¾ÖÓòÃûµÄÓÊÏä¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-sextortion-email-uses-cia-investigation-as-scare-tactic/6¡¢ÐÂÀÕË÷Èí¼þJNEC.a£¬£¬£¬£¬£¬ÀûÓÃWinRAR Ace·ì϶½øÐд«²¼
×êÑÐÈËÔ±·¢ÏÖÒ»¸öеÄÀÕË÷Èí¼þJNEC.aÀûÓÃ×î½ü»ã±¨µÄWinRAR´úÂëÖ´Ðзì϶½øÐд«²¼¡£¡£¡£¡£¡£¡£¡£¡£JNEC.a»á¼ÓÃÜÍÆËã»úÉϵÄÊý¾Ý£¬£¬£¬£¬£¬²¢ÔÚÎļþºó¸½¼Ó.JnecÀ©´óÃû£¬£¬£¬£¬£¬Æä½âÃÜÃÜÔ¿µÄ¼ÛÖµÊÇ0.05±ÈÌØ±Ò£¨Ô¼200ÃÀÔª£©¡£¡£¡£¡£¡£¡£¡£¡£JNEC.aÊÇÓÃ.NET±àдµÄ£¬£¬£¬£¬£¬¼Ù×°³ÉGoogleUpdate.exe¸éÖÃÔÚWindows StartupÎļþ¼ÐÖУ¬£¬£¬£¬£¬ÒÔÔÚÍÆËã»úÆô¶¯Ê±×Ô¶¯Æô¶¯¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝMichael GillespieµÄ·ÖÎö£¬£¬£¬£¬£¬¸ÃÀÕË÷Èí¼þ´æÔÚbug£¬£¬£¬£¬£¬¼´±ãÊÇ¿ª·¢Õß×Ô¼ºÒ²ÎÞ·¨½âÃܸÃÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/jneca-ransomware-spread-by-winrar-ace-exploit/ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ