»ªË¶°ä²¼Live Update¸üÐÂ;Norsk HydroÒòÀÕË÷Èí¼þËðʧ³¬4100ÍòÃÀÔª;LUCKY ELEPHANT¹¥»÷»î¶¯

°ä²¼¹¦·ò 2019-03-28
1¡¢»ªË¶È·ÈÏÔ⹩¸øÁ´¹¥»÷£¬ÒѰ䲼Live Update°²È«¸üÐÂ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


»ªË¶È·ÈÏÆä·þÎñÆ÷Ôâµ½ÈëÇÖ£¬Live Update¹¤¾ßÔâµ½´Û¸Ä  ¡£Æ¾¾Ý¸Ã¹«Ë¾µÄÉêÃ÷£¬»ªË¶ÒѾ­°ä²¼ÁËLive Updateа汾3.6.8À´½¨¸´¸ÃÎÊÌ⣬¸Ã°æ±¾ÒýÈëÁ˶àÖÖ°²È«ÑéÖ¤»úÔ죬²¢Ö´ÐÐÁ˼ÓÇ¿µÄ¶Ëµ½¶Ë¼ÓÃÜ  ¡£´Ë±í£¬¸Ã¹«Ë¾»¹ÌṩÁËÒ»¸öÕï¶Ï¹¤¾ß£¬ÓÃÓڲ鳭Óû§µÄϵͳÊÇ·ñÊܵ½Ï°È¾  ¡£Ó뿨°Í˹»ùºÍÈüÃÅÌú¿ËÔ¤¹ÀµÄ100ÍòÊܺ¦Õß·ÖÆç£¬»ªË¶³Æ¸Ã¹¥»÷Ö»Õë¶ÔÉÙÊýÌØ¶¨Óû§ÈºÌ壬²¢ÇÒÖ»ÓÐÉÙÊýÉ豸Êܵ½Ï°È¾  ¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2019/03/27/asus-fixes-live-update/

2¡¢Norsk HydroÒòÀÕË÷Èí¼þ¹¥»÷Ëðʧ³¬4100ÍòÃÀÔª


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚÉÏÖÜÔâµ½ÀÕË÷Èí¼þLockerGoga¹¥»÷Ö®ºó£¬Å²ÍþÂÁ³ö²úÉÌNorsk HydroÈÔÔÚ¸´Ô­ÆäITϵͳ  ¡£¸Ã¹«Ë¾³Æ»ùÓڸ߲ãÆÀ¹À£¬³õ²½¹À¼ÆÍøÂç¹¥»÷Ôì³ÉµÄËðʧԼΪ3-3.5ÒÚŲÍþ¿ËÀÊ£¨ºÏ3500-4100ÍòÃÀÔª£©£¬ÖØÒªËðʧÆðÔ´ÓÚÀûÈóºÍÂÁ²Ä¼·Ñ¹ÒµÎñµÄËðʧ  ¡£¸Ã¹«Ë¾³ÆÂÁ²Ä¼·Ñ¹½â¾ö¹æ»®ÒѾ­¸´Ô­ÁË70-80%£¬µ«¹¹ÖþϵͳҵÎñÈÔδ¸´Ô­  ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/norsk-hydro-ransomware-costs-hit-1-1/

3¡¢UrsnifľÂíй¥»÷»î¶¯£¬ÖØÒªÕë¶ÔÒâ´óÀû

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ƾ¾ÝCybaze-Yoroi ZLab×êÑÐÈËÔ±µÄ·¢ÏÖ£¬Ò»¸öеÄUrsnifľÂí±äÖÖÔÚ¶Ô×¼Òâ´óÀûµÄÆóÒµ  ¡£¸Ã±äÖÖͨ¹ý´¹µöÓʼþ½øÐзַ¢£¬ÓʼþÖÐÔ̺¬ÐéαGoogleÔÆÅÌÒ³ÃæµÄÁ´½Ó£¬µ±Óû§ÔÚÕâ¸öÐéÎ±Ò³ÃæÉϵã»÷ÏÂÔØÁ´½Óʱ£¬½«»á´Óblogger[.]scentasticyoga[.]comÏÂÔØ¶ñÒâÎļþ  ¡£¸Ã±äÖÖÀûÓÃVBScript½ÅÕý±¾Èƹý·À²¡¶¾²úÆ·µÄ¼ì²â  ¡£Æ¾¾Ý¶ÔÔ¶³ÌC2·þÎñÆ÷µÄµ÷²é£¬¸Ã¹¥»÷»î¶¯×Ô3ÔÂ5ÈÕÆðÒ»Ïò»îÔ¾  ¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/ursnif-trojans-latest-campaign-affects-several-organizations-in-italy-b8a16f69

4¡¢LUCKY ELEPHANT¹¥»÷»î¶¯£¬ÖØÒªÕë¶ÔÄÏÑǵ±¾Ö»ú¹¹


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


NETSCOUT×êÑÐÍŶӷ¢ÏÖÒ»¸öÐµĹ¥»÷»î¶¯LUCKY ELEPHANT£¬¸Ã¹¥»÷»î¶¯ÖØÒªÀûÓÃÐéαȷµ±¾Ö¡¢µçÐÅ¡¢¾ü¶ÓÍøÕ¾À´ÇÔÈ¡Óû§µÄµÇ¼ʹ´¦  ¡£ÊÜÓ°ÏìµÄ¹ú¶ÈÔ̺¬°Í»ù˹̹¡¢ÃϼÓÀ­¹ú¡¢Ë¹ÀïÀ¼¿¨¡¢Âí¶û´ú·ò¡¢ÃåµéºÍÄá²´¶û  ¡£¸Ã¹¥»÷»î¶¯ÓÚ3Ô³õ±»·¢ÏÖ£¬Æ¾¾Ý¹¥»÷ÕßʹÓõÄIPµØÖ·£¬¹¥»÷ÕßÒÉÓëÓ¡¶ÈAPT×éÖ¯APT-C-35ÓйØ  ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/82963/hacking/lucky-elephant-campaign.html

5¡¢GAOл㱨³ÆÃÀ¹úÁª¹ú´¢ÐîÏµÍ³Ãæ¶ÔδÊÚȨ½Ó¼û·çÏÕ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÃÀ¹úµ±¾ÖÎÊÔð¾Ö£¨GAO£©°ä²¼µÄÖÎÀí»ã±¨£¬ÓÉÓÚÃÀ¹ú²ÆÕþ²¿µÄÍÆËã»úϵͳ´æÔÚ°²È«·ì϶£¬µ¼ÖÂÁª¹ú´¢ÐîÒøÐУ¨FRB£©Ô⵽δÊÚȨ½Ó¼û·çÏÕµÄÔö³¤  ¡£ÔÚ2018²ÆÕþÄê¶ÈÉó¼ÆÆÚ¼ä£¬GAO·¢ÏÖFRBÔËÓªµÄ¹Ø¼ü½ðÈÚϵͳ´æÔÚ·ì϶  ¡£¾ÝGAO³Æ£¬ÔÚÆëÈ«½â¾öÕâЩ·ì϶֮ǰ£¬Î´ÊÚȨ½Ó¼û¡¢´Û¸Ä»òÅû¼ûô¸ÐÊý¾ÝµÄ·çÏÕ½«»áÔö³¤  ¡£Æ¾¾ÝÉó¼ÆÁ˾ֺͽ¨Ò飬Áª¹ú´¢ÐîϵͳÀíÊ»ᰵʾÔÚ½â¾öÕâЩÎÊÌâ  ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-federal-reserve-system-exposed-to-increased-risk-of-unauthorized-access/

6¡¢NVIDIA°ä²¼GeForce Experience°²È«¸üУ¬½¨¸´Ò»¸öÌáȨ·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


NVIDIA°ä²¼Windowsƽ̨GeForce ExperienceÈí¼þµÄ°²È«¸üУ¬½¨¸´Ò»¸öÑϳÁµÄ°²È«·ì϶  ¡£¸Ã·ì϶£¨CVE-2019-5674£©µÄCVSS V3ÆÀ·ÖΪ8.8·Ö£¬¿ÉÔÊÐíDZÔڵı¾µØ¹¥»÷ÕßÌáȨ¡¢Ö´ÐÐËÁÒâ´úÂë¼°´¥·¢DoS¹¥»÷  ¡£¹ÌÈ»¸Ã·ì϶ÎÞ·¨Ô¶³ÌÀûÓ㬵«¹¥»÷ÕßÈÔ¿Éͨ¹ýÆäËü²½ÖèÔ¶³ÌÖ²Èë¶ñÒâÈí¼þÀ´ÀûÓø÷ì϶  ¡£ÊÜÓ°ÏìµÄ°æ±¾Îª3.18֮ǰµÄËùÓÐGeForce Experience°æ±¾  ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nvidia-patches-high-severity-geforce-experience-vulnerability/

ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù