¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180720
°ä²¼¹¦·ò 2018-07-20¡¾Íþвµý±¨¡¿×êÑлú¹¹°ä²¼¿É×èÖ¹ÀÕË÷Èí¼þGandCrab v4.1.2µÄ·À»¤·¨Ê½
º«¹ú°²È«³§ÉÌAhnLab°ä²¼¿ÉÓÃÓÚ×èÖ¹ÀÕË÷Èí¼þGandCrab v4.1.2µÄ·À»¤·¨Ê½£¬¸Ã·¨Ê½Í¨¹ýÔÚÓû§µÄÍÆËã»úÉÏ´´½¨Ò»¸öÌØÊâµÄÎļþÀ´×èÖ¹GandCrab¡£Õâ¸öÎļþÊÇ[Ê®Áù½øÔì×Ö·û´®].lock£¬ÆäÊ®Áù½øÔì×Ö·û´®ÊÇÆ¾¾ÝÍÆËã»ú¸ùÇý¶¯Æ÷µÄ¾íÐÅÏ¢ºÍSalsa20Ëã·¨ÌìÉúµÄ£¬GandCrab»áƾ¾Ý´ËÎļþÅжÏÍÆËã»úÊÇ·ñÒѱ»Ï°È¾¹ý¡£¸Ã·À»¤·¨Ê½Ö»ºÏÓÃÓÚv4.1.2°æ±¾¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/vaccine-available-for-gandcrab-ransomware-v412/
¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±·¢ÏÖϰȾ³¬¹ý1.8Íò¸ö·ÓÉÆ÷µÄн©Ê¬ÍøÂçAnarchy
NewSky SecurityµÄ°²È«×êÑÐÈËÔ±·¢ÏÖÒ»¸öеĽ©Ê¬ÍøÂ磬¸Ã½©Ê¬ÍøÂçÀûÓûªÎªHG532·ÓÉÆ÷Öзì϶£¨CVE-2017-17215£©½øÐд«²¼£¬ÔÚ1ÌìÄÚϰȾÁ˳¬¹ý1.8Íò¸ö·ÓÉÆ÷¡£×êÑÐÈËÔ±ÒÔΪ¸Ã½©Ê¬ÍøÂç±³ºóµÄ×÷ÕßÊÇWicked/Anarchy£¬AnarchyÔø´´½¨¹ýIoT¶ñÒâÈí¼þMiraiµÄ¶à¸ö±äÖÖ£¬Ô̺¬Wicked¡¢OmniºÍOwari£¨Sora£©¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/router-crapfest-malware-author-builds-18-000-strong-botnet-in-a-day/
¡¾·ì϶²¹¶¡¡¿ABB½¨¸´ÆäHMI²úÆ·ÖеÄÒ»¸ö¿Éµ¼ÖÂËÁÒâ´úÂëÖ´Ðеķì϶
ÈðÊ¿¹¤Òµ¼¼Êõ¹«Ë¾ABBÔÚ½¨¸´ÆäHMI²úÆ·ÖеÄÒ»¸ö¿Éµ¼ÖÂËÁÒâ´úÂëÖ´Ðеݲȫ·ì϶£¨CVE-2018-10616£©¡£¸Ã·ì϶ӰÏìÁËËùÓа汾µÄPanel Builder 800¡£Panel Builder 800Êǹ¤Òµ×Ô¶¯»¯ÏµÍ³µÄ²Ù×÷Ãæ°å¹¤¾ß£¬¸Ã¹¤¾ßÔÚÈ«ÇòÁìÓòÄÚ±»¿í·ºÓÃÓÚ»¯¹¤¡¢Ôì×÷¡¢Ë®°Ó¡¢ÄÜÔ´¡¢¹©Ë®¡¢Ê³Æ·ÒÔ¼°Å©ÒµµÈÐÐÒµ¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýºýŪÓû§´ò¿ª¶ñÒâÎļþÀ´ÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/abb-patch-code-execution-flaw-hmi-tool
¡¾·ì϶²¹¶¡¡¿Ë¼¿Æ°ä²¼¶à¸ö²úÆ·µÄ°²È«¸üУ¬¹²½¨¸´25¸ö°²È«·ì϶
˼¿Æ°ä²¼¶à¸ö²úÆ·µÄ°²È«¸üУ¬¹²½¨¸´25¸ö·ì϶£¬ÆäÖÐÔ̺¬Cisco Policy SuiteÖеÄÒ»¸öºóÃÅÕË»§·ì϶¡£¸Ã·ì϶£¨CVE-2018-0375£©Ê¹µÃ¹¥»÷ÕßÄܹ»ÒÔrootȨÏÞ½Ó¼ûÉ豸£¬½ø¶øÖ´ÐжñÒâ²Ù×÷¡£Ë¼¿ÆÔÚCisco Policy Suite 18.2.0Öн¨¸´ÁË´Ë·ì϶£¬ËùÓÐ֮ǰµÄ°æ±¾¶¼Ò×Êܹ¥»÷¡£ÕâÊÇ´Óǰ5¸öÔÂÄÚ˼¿ÆÔÚÆäÉ豸ÖÐɾ³ýµÄµÚ5¸öºóÃÅÕË»§¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cisco-removes-undocumented-root-password-from-bandwidth-monitoring-software/
¡¾·ì϶²¹¶¡¡¿×êÑÐÍŶÓÅû¶ͼÐαà×빤¾ßCanvas DrawÖеĶà¸ö°²È«·ì϶
˼¿ÆTalos×êÑÐÍŶÓÅû¶ÔÚMac°æ±¾µÄCanvas Draw 4Öз¢ÏֵĶà¸ö°²È«·ì϶¡£Canvas Draw 4ÊÇÒ»¸öÓÃÓÚ´´½¨ºÍ±à×ëͼÐεŤ¾ß£¬¹¥»÷Õß¿Éͨ¹ý¶ñÒâTIFFÎļþ´¥·¢ÕâЩ·ì϶µ¼ÖÂËÁÒâ´úÂëÖ´ÐС£·ì϶µÄ±àºÅΪCVE-2018-3857~CVE-2018-3871£¬Ó°ÏìÁËCanvas Draw 4.0.0¼°Ö®Ç°µÄ°æ±¾£¬½¨ÒéÓû§¸üÐÂÖÁ×îа汾¡£
ÔÎÄÁ´½Ó£ºhttps://blog.talosintelligence.com/2018/07/vulnerability-spotlight-ACDsystems.html
¡¾¹¥»÷ÊÂÎñ¡¿¶íÂÞ˹PIRÒøÐÐÔâºÚ¿Í¹¥»÷£¬ËðʧԼ100ÍòÃÀÔª
ƾ¾Ý¶íÂÞ˹°²È«³§ÉÌGroup-IBµÄ»ã±¨£¬ºÚ¿ÍÍÅ»ïMoneyTakerͨ¹ý·ÓÉÆ÷ÈëÇÖÁ˶íÂÞ˹PIRÒøÐеÄÍøÂ磬²¢ÇÔÈ¡ÁËÔ¼100ÍòÃÀÔªµÄ×ʽð¡£Group-IBÈ·ÈϹ¥»÷ʼÓÚ2018Äê5ÔÂÏÂÑ®£¬¹¥»÷ÕßµÄÈë¿ÚÊǹýÆÚµÄ·ÓÉÆ÷£¬¸Ã·ÓÉÆ÷ÓÐËí·£¬¿ÉÔÊÐí¹¥»÷ÕßÖ±½Ó½Ó¼ûÒøÐеı¾µØÍøÂç¡£¹¥»÷²úÉúÔÚ7ÔÂ3ÈÕ£¬PIRÒøÐеÄÔ±¹¤ÔÚÒ»ÌìºóµÄ7ÔÂ4ÈÕ·¢ÏÖÁË´ó±ÊδÊÚȨµÄÂòÂô£¬µ«ÎªÊ±ÒÑÍí¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-breach-russian-bank-and-steal-1-million-due-to-outdated-router/


¾©¹«Íø°²±¸11010802024551ºÅ