¶íÂÞ˹Áª¹ú°²È«¾Ö³Ð°üÉÌÔâºÚ¿ÍÈëÇÖ£¬»úÃÜÏîÄ¿ÆØ¹â£»µÂ¹úCERT-BundÅû¶VLCýÌå²¥·ÅÆ÷ÖеÄRCE·ì϶
°ä²¼¹¦·ò 2019-07-22
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/russian-fsb-intel-agency-contractor-hacked-secret-projects-exposed/
2¡¢Emsisoft°ä²¼ÀÕË÷Èí¼þZeroFucksµÄ½âÃܹ¤¾ß
Emsisoft°ä²¼ÀÕË÷Èí¼þZeroFucksµÄ½âÃÜÆ÷¡£ZeroFucksʹÓÃAES-256Ëã·¨¼ÓÃÜÓû§µÄÎļþ£¬²¢Ê¹Óá°.zerofucks¡±À©´óÃû´úÌæÕý±¾µÄÎļþÀ©´óÃû¡£µ±¼ÓÃÜʵÏֺ󣬸ÃÀÕË÷Èí¼þÏòÓû§ÀÕË÷¼ÛÖµ400Å·ÔªµÄ±ÈÌØ±ÒÊê½ð£¬²¢Ðû³ÆÈôÊÇÓû§Ã»ÓÐÔÚ48Ó×ʱÄÚ¸¶¿î£¬Êê½ð½«·±¶£»ÈôÊÇÓû§Ã»ÓÐÔÚ96Ó×ʱÄÚ¸¶¿î£¬Îļþ½«±»Ïú»Ù¡£´Ë¿ÌÓû§Äܹ»Ê¹ÓÃ×êÑÐÈËÔ±°ä²¼µÄ½âÃÜÆ÷À´Ãâ·Ñ½âÃÜÎļþ¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/88716/hacking/zerofucks-ransomware-decryptor.html
3¡¢ÃÀ¹úÌïÄÉÎ÷ÖÝ¿ÆÀû¶ûά¶ûÕòÔâÀÕË÷Èí¼þRyuk¹¥»÷
¾Ý±íý±¨Â·£¬ÃÀ¹úÌïÄÉÎ÷ÖÝ¿ÆÀû¶ûά¶ûÕòÔâµ½ÀÕË÷Èí¼þRyukµÄ¹¥»÷£¬²¿ÃÅÍÆËã»úϵͳ̱»¾£¬Ò»Ð©¹«¹²·þÎñÊܵ½Ó°Ïì¡£¸ÃÕò½²»°È˰µÊ¾±¸·Ý·þÎñÆ÷ËÆºõÊǰ²È«µÄ£¬µ«ITÈËÔ¹ØýÔÚ½«ËüÃDzÎÓëÍøÂç֮ǰ¶ÔÆä½øÐвâÊÔ¡£µ÷²éÈËÔ±ÒÀÈ»²»ÖªÂ·ÀÕË÷²¡¶¾µÄÆðÔ´£¬µ«ÒÔΪËü¿ÉÄÜÀ´×ÔÓÚµç×ÓÓʼþÖеÄÁ´½Ó¡£¸ÃÕòûÓÐÏòºÚ¿ÍÖ§¸¶Êê½ð£¬²¢ÇÒ֪ͨÁËÁª¹úµ±¾Ö¡£Ä¿Ç°·þÎñÒÑÕý³£ÔË×÷¡£
ÔÎÄÁ´½Ó£ºhttps://www.localmemphis.com/news/local-news/hackers-cause-headaches-on-servers-in-town-of-collierville-with-ransomware-attack/
4¡¢µÂ¹úCERT-BundÅû¶VLCýÌå²¥·ÅÆ÷ÖеÄRCE·ì϶
µÂ¹úÍøÂ簲ȫ¼à¹Ü»ú¹¹CERT-Bund·¢ÏÖVLCýÌå²¥·ÅÆ÷´æÔÚÒ»¸öRCE·ì϶£¬¸Ã·ì϶£¨CVE-2019-13615£©Ó°ÏìÁËVLCµÄ×îв»±ä°æ±¾3.0.7.1¡£¸Ã·ì϶ԴÓÚÒ»¸ö»º³åÇøÒç³öÎÊÌ⣬δ¾ÊÚȨµÄ¹¥»÷Õß¿ÉÀûÓø÷ì϶´¥·¢ÐÅϢй¶¡¢ÎļþÅú¸Ä»ò·þÎñÖжϡ£¸Ã·ì϶´æÔÚÓÚ¶à¸öƽ̨µÄVLC°æ±¾ÖУ¬Ô̺¬Windows¡¢LinuxºÍUNIX£¬µ«macOSδÊÜÓ°Ïì¡£¸Ã·ì϶µÄ½¨¸´²¹¶¡»¹ÔÚ¿ª·¢¹ý³ÌÖС£
ÔÎÄÁ´½Ó£ºhttps://news.softpedia.com/news/critical-flaw-in-vlc-media-player-discovered-by-german-cybersecurity-agency-526768.shtml
5¡¢Ë¼¿Æ½¨¸´Vision DynamicÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶
˼¿Æ°ä²¼ÁËVision Dynamic Signage DirectorµÄ°²È«²¹¶¡£¬½¨¸´Ò»¸ö¿ÉÔÊÐí¹¥»÷ÕßÔÚ±¾µØÏµÍ³ÉÏÖ´ÐÐËÁÒâ²Ù×÷µÄ°²È«·ì϶¡£¸Ã·ì϶£¨CVE-2019-1917£©´æÔÚÓÚVision Dynamic Signage DirectorµÄREST API½çÃæÖУ¬¿É±»Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÀûÓã¬ÒÔÈÆ¹ýÖ¸±êϵͳÉϵÄÉí·ÝÑéÖ¤¡£¸Ã·ì϶ÊÇÓÉÓÚ¶ÔHTTPÒªÇóµÄÑéÖ¤²»³ä·Öµ¼Öµġ£Ë¼¿Æ°µÊ¾ÔÚĬÈÏÇé¿öÏÂÎÞ·¨½ûÓÃREST API£¬Óû§Äܹ»Í¨¹ý×°ÖÃÈí¼þ¸üн¨¸´¸Ã·ì϶¡£
ÔÎÄÁ´½Ó£ºhttp://www.infosecisland.com/blogview/25211-Cisco-Patches-Critical-Flaw-in-Vision-Dynamic-Signage-Director.html
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/iran-apt34-linkedin-malware/146575/


¾©¹«Íø°²±¸11010802024551ºÅ