CISA°ä²¼ICS 5ÄêÕ½Êõ¡¶È·±£¹¤ÒµÏµÍ³°²È«£ºÍ³Ò»´òËã¡· £»£»£»£»£»Citrix½¨¸´ÍøÂç²úÆ·ÖÐ11¸ö·ì϶ £¬£¬£¬£¬£¬¿Éµ¼ÖÂDoS¹¥»÷

°ä²¼¹¦·ò 2020-07-09

1.CISA°ä²¼ICS 5ÄêÕ½Êõ¡¶È·±£¹¤ÒµÏµÍ³°²È«£ºÍ³Ò»´òËã¡·


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÍøÂ簲ȫºÍ»ù´¡½á¹¹°²È«¾Ö£¨CISA£©°ä²¼µÄ¹¤Òµ½ÚÔìϵͳ£¨ICS£©5ÄêÕ½Êõ¡¶È·±£¹¤ÒµÏµÍ³°²È«£ºÍ³Ò»´òËã¡·ÊÇÒ»Ïî¶àÄêµÄ³Áµã¹¤×÷ £¬£¬£¬£¬£¬Ö¼ÔÚÌá¸ßCISAÔ¤²â¡¢È·¶¨ÓÅÏȼ¶ºÍÖÎÀí¹ú¶È¼¶ICS·çÏÕµÄÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£Í¨¹ýÕâÒ»¡°One CISA¡±´òËã £¬£¬£¬£¬£¬CISA½«Óë¹Ø¼ü»ù´¡¼Ü¹¹£¨CI£©ËùÓÐÕߺÍÔËÓªÉ̺Ï×÷ £¬£¬£¬£¬£¬³ÉÁ¢ICS°²È«Ö°ÄÜ £¬£¬£¬£¬£¬´Ó¶ø±£ÏÕICSÀûÒæÓйØÕßÃâÊÜICSÍþвµÄ·çÏÕ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/07/cisa-releases-securing-industrial-control-systems-unified


2.Èí¼þÁªÃË£¨BSA£©°ä²¼¹¹½¨°²È«¿¿µÃסµÄÎïÁªÍøµÄÕþ²ßºÍ×¼Ôò


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


BSA£¨Ò²³ÆÎªÈí¼þÁªÃË £¬£¬£¬£¬£¬Ç°ÉíÊÇóÒ×Èí¼þÁªÃË£©°ä²¼Á˹¹½¨°²È«¿¿µÃסµÄÎïÁªÍøµÄÕþ²ßºÍ×¼Ôò¡£¡£¡£¡£¡£¡£¡£ÆäºôÓõ¶ÔÏû·ÑÎïÁªÍøºÍ¹¤ÒµÎïÁªÍø½øÐÐ·Ö±æ £¬£¬£¬£¬£¬Ìṩ¼¯³É°²È«ÐԵļ¤Àø´ëÊ© £¬£¬£¬£¬£¬Ð­µ÷¹ú¶ÈºÍ¹ú¼ÊÕþ²ß £¬£¬£¬£¬£¬³ÉÁ¢¶¨ÆÚ¸üеĻù×¼°²È«ÒªÇ󡣡£¡£¡£¡£¡£¡£²¢Ô¤²â £¬£¬£¬£¬£¬Ô̺¬ÎïÁªÍøÔÚÄڵĻúеÓë»úе(M2M)ÏνÓÔÚ½«À´¼¸Ä꽫Ôö³¤Ò»±¶ÒÔÉÏ £¬£¬£¬£¬£¬´Ó2018ÄêµÄ61ÒÚ´ÎÔö³¤µ½2023.1ÄêµÄ147ÒڴΡ£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.schneier.com/blog/archives/2020/07/iot_security_pr.html


3.Citrix½¨¸´Æä¶à¿îÍøÂç²úÆ·ÖÐ11¸ö·ì϶ £¬£¬£¬£¬£¬¿Éµ¼ÖÂDoS¹¥»÷


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Citrix±¾Öܶþ½¨¸´ÁËÆä¶à¿îÍøÂç²úÆ·ÖеÄ11¸ö·ì϶ £¬£¬£¬£¬£¬²¢Ç¿µ÷ÕâЩ·ì϶ÓëÒѱ»ÀûÓõÄCVE-2019-19781Î޹ء£¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ·ì϶ӰÏìÁËCitrix ADC¡¢Íø¹ØºÍSD-WAN WANÓÅ»¯£¨WANOP£©°æ±¾ £¬£¬£¬£¬£¬ºÚ¿ÍÄܹ»ÀûÓÃËüÃÇÀ´µÁÊØÐÅÏ¢¡¢ÌáÒéDoS¹¥»÷¡¢½øÐб¾µØÌØÈ¨ÌáÉý¡¢ÌáÒéXSS¹¥»÷¡¢ÈƹýÊÚȨºÍ×¢Èë´úÂëµÈ¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜijЩ·ì϶Äܹ»±»Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÀûÓà £¬£¬£¬£¬£¬µ«ÔÚ´óÎÞÊýÇé¿öÏ £¬£¬£¬£¬£¬ÀûÓÃÕâЩ·ì϶±ØÒªÖ¸±êϵͳ½Ó¼ûȨÏÞµÈÏȾöǰÌá¡£¡£¡£¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬ÊÜÓ°Ïì²úÆ·µÄÔÆ°æ±¾²»ÈÝÒ×Êܵ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/citrix-patches-11-vulnerabilities-networking-products?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Securityweek+%28SecurityWeek+RSS+Feed%29


4.NVIDIA½¨¸´ÁËGeForce ExperienceÖеĴúÂëÖ´Ðзì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


NVIDIA½¨¸´ÁËWindows NVIDIA GeForce Experience£¨GFE£©Öеķì϶£¨CVE?2020?5964£© £¬£¬£¬£¬£¬¸Ã·ì϶ÔÊÐí±¾µØ¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë £¬£¬£¬£¬£¬ÌáÒéDoS¹¥»÷»ò½Ó¼ûÌØÈ¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶CVSS V3 ÆÀ·ÖΪ6.5·Ö £¬£¬£¬£¬£¬ÒªÇó¹¥»÷ÕßÓµÓб¾µØÓû§½Ó¼ûȨÏÞ²¢ÇÒÎÞ·¨Ô¶³ÌÀûÓà £¬£¬£¬£¬£¬µ«ÈÔÄܹ»Í¨¹ý¶ñÒ⹤¾ß½øÐÐÀûÓᣡ£¡£¡£¡£¡£¡£¸Ã·ì϶»áÓ°ÏìÔËÐÐNVIDIA GeForce Experience 3.20.4֮ǰ°æ±¾µÄWindowsϵͳ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nvidia-fixes-code-execution-bug-in-geforce-experience-software/


5.³õ´ÎÆØ¹âµÄ¶íÂÞ˹BECÚ¿Æ­ÍÅ»ïÕë¶Ô²Æ¸»500Ç¿ÆóÒµ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¶íÂÞ˹BECÚ¿Æ­ÍÅ»ïCosmic LynxÒÀ¸½¶ñÒâÈí¼þEmotetºÍTrickBot £¬£¬£¬£¬£¬×Ô2019Äê7ÔÂÒÔÀ´ £¬£¬£¬£¬£¬ÌáÒéÁ˳¬¹ý200´ÎBEC¹¥»÷ £¬£¬£¬£¬£¬²¢ÓµÓÐÆäËûBECÍÅ»ïûÓеIJÙ×÷¸´ÔÓÐÔ¡£¡£¡£¡£¡£¡£¡£Cosmic LynxËù¹¥»÷µÄ¹«Ë¾±é²¼È«Çò £¬£¬£¬£¬£¬ÆäÖкܶàÔÚ¡¶²Æ¸»¡· 500Ç¿°ñµ¥ÖлòÔÚÈ«Çò2000Ç¿°ñµ¥ÖС£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïͨ³£¼ÙÒâÖ¸±ê¹«Ë¾µÄÊ×ϯִÐй٠£¬£¬£¬£¬£¬Ïò¸ß²ãÖ÷¹Ü·¢Ë͵ç×ÓÓʼþÒªÇó £¬£¬£¬£¬£¬ÒªÊµÏÖ¶ÔÒ»¼ÒÑÇÖÞ¹«Ë¾µÄÊÕ¹º¡£¡£¡£¡£¡£¡£¡£Ö®ºó»á·î¸æÖ¸±ê¹«Ë¾Ô±¹¤ £¬£¬£¬£¬£¬µÚÈý·½Ë¾·¨ÕÕ·÷½«Ð­ÖúʵÏÖÂòÂôµÄ¸¶¿î £¬£¬£¬£¬£¬²¢½Ù³ÖÒ»ÃûÕæÕýÂÉʦµÄÓÊÏäÏòÊܺ¦Õß·¢ËͽéÉÜÐÔµç×ÓÓʼþ¸ÅÊö¸ÃÁ÷³Ì¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/first-reported-russian-bec-scam-gang-targets-fortune-500-firms/


6.µÂ¹úµ±¾Ö½É»ñÁËÍйÜÃÀ¹ú¾¯¾ÖÊý¾ÝBlueLeaksµÄ·þÎñÆ÷


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


µÂ¹úµ±¾ÖÓÚ7ÔÂ7ÈսɻñÁËÍйÜÃÀ¹ú¾¯¾ÖÊý¾ÝBlueLeaksµÄ·þÎñÆ÷ £¬£¬£¬£¬£¬¸Ã·þÎñÆ÷ÊôÓÚÒ»¸ö¼¤½ø×éÖ¯DDoSecrets£¨É¢²¼Ê½»Ø¾ø±£ÃÜ£©¡£¡£¡£¡£¡£¡£¡£DDoSecrets°µÊ¾ £¬£¬£¬£¬£¬Ëü´ÓÄäÃûºÚ¿Í×éÖ¯ÄÇÀïÊÕµ½ÁËÕâЩÎļþ £¬£¬£¬£¬£¬Ô̺¬É¨ÃèµÄÎĵµ¡¢ÊÓÆµ¡¢µç×ÓÓʼþ¡¢ÒôƵÎļþ¡¢Åàѵ×ÊÁÏ¡¢¸öÈË·¨Âɾ¯±¨ÒÔ¼°À´×Ô200¶à¸öÃÀ¹ú¾¯Ô±¾ÖºÍ·¨ÂÉÖÐÐĵÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¶øBlueLeaksÊý¾ÝÊÇ´ÓÐÝ˹¶ØµÄÒ»¼ÒÏòÃÀ¹ú·¨ÂÉ»ú¹¹Ìá¹©ÍøÂçÍйܷþÎñµÄ¹«Ë¾±»ÇԵġ£¡£¡£¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬ÔÚBlueLeaks°ä²¼ËÄÌìºó £¬£¬£¬£¬£¬Twitter¹ýÎʲ¢ÓÀÔ¶²»ÈÝÁËDDoSecrets¹Ù·½TwitterÕÊ»§ £¬£¬£¬£¬£¬ÓÉÓÚÆäÓøÃÕÊ»§À´´«²¼BlueLeaks¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/german-authorities-seize-blueleaks-server-that-hosted-data-on-us-cops/#ftag=RSSbaffb68