È«ÇòÎïÁªÍø/ICS·çÏջ㱨£¨2020°æ£©£»Avast¡¢AVGºÍAviraɱ¶¾Èí¼þ´æÔÚDLL½Ù³Ö·ì϶

°ä²¼¹¦·ò 2019-10-24
1¡¢CyberX°ä²¼È«ÇòÎïÁªÍø/ICS·çÏջ㱨£¨2020°æ£©

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ƾ¾ÝCyberXµÄ¡¶È«ÇòÎïÁªÍø/ICS·çÏջ㱨¡·2020°æ£¬ºÜ¶à¹¤ÒµÆóÒµÖÐÒÀÈ»´æÔÚ¹ýÆÚµÄ²Ù×÷ϵͳ£¬Õâ´øÀ´ÁËÑϳÁµÄ·çÏÕ¡£¸Ã»ã±¨ÊÇ»ùÓÚÈ«Çò1800¶à¸ö¹¤ÒµÆóÒµ»·¾³ÖдÓ2018Äê10ÔÂÖÁ2019Äê10ÔÂÖ®¼äÍøÂçµÄÊý¾Ý¡£µ÷²é¶ÔÏóÖÐÓÐ62%µÄÉ豸ÔËÐеÄÊǹýÆÚÇÒ²»ÊÜÖ§³ÖµÄWindows°æ±¾£¨ÀýÈçWindows XPºÍ2000£©£¬ÈôÊǰѼ´½«ÔÚ2020Äê1ÔÂÖÕ³¡Ö§³ÖµÄWindows 7ÍÆËãÔÚÄÚ£¬ÔòÕâÒ»Êý×ÖÉÏÉýÖÁ71£¥¡£CyberX»¹·¢ÏÖ£¬ÔÚ64£¥µÄÇé¿öÏÂÆóÒµÔÚÍøÂç´«ÊäÖÐδ¶ÔÃÜÂë½øÐмÓÃÜ£¬ÕâʹµÃ¹¥»÷Õ߸üÈÝÒ׽ػñÃÜÂë¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/outdated-oss-still-present-many-industrial-organizations-report

2¡¢Avast¡¢AVGºÍAviraɱ¶¾Èí¼þ´æÔÚDLL½Ù³Ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


SafeBreach Labs°²È«×êÑÐÈËÔ±·¢ÏÖAvast¡¢AVGºÍAviraɱ¶¾Èí¼þ´æÔÚDLL½Ù³Ö·ì϶£¬¿ÉÔÊÐí¹¥»÷Õß¼ÓÔØ¶ñÒâDLLÎļþÒÔÈÆ¹ý¼ì²âºÍÌáȨ¡£¸Ã·ì϶£¨CVE-2019-17093£©Ó°ÏìÁ˰汾19.8ÒÔϵÄËùÓÐAvastºÍAVGɱ¶¾Èí¼þ£¬·ì϶ԭÒòÊÇAVGSvc.exeÊÔͼÔÚÆô¶¯Ê±¼ÓÔØDLL£¬µ«ËüÔÚÃýÎóµÄÎļþ¼ÐÖÐËÑË÷Îļþ£¨ÀýÈçC£º\Program Files\System32\£©£¬Ê¹µÃ¹¥»÷ÕßÄܹ»½«Í¬ÃûDLL·ÅÈë¸ÃÎļþ¼ÐÖдӶøµ¼Ö¸ÃDLL±»ÒÔSYSTEMÌØÈ¨¼ÓÔØ¡£×êÑÐÈËÔ±ÔÚAvira Antivirus 2019Öз¢ÏÖÁËÀàËÆµÄÎÊÌ⣨CVE-2019-17449£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/avast-avira-products-vulnerable-dll-hijacking

3¡¢·µÏÖÍøÕ¾PouringPoundsÔÚÍøÉ϶³ö2TBÃô¸ÐÐÅÏ¢

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Ó¢¹ú·µÏÖÍøÕ¾PouringPounds.com¼°ÆäÓ¡¶Èæ¢ÃÃÍøÕ¾CashKaro.comÒⱩ¶³ö2TBÃô¸ÐÊý¾Ý¡£ÕâÁ½¸öÍøÕ¾¾ù¹éÊôPouringPounds¹«Ë¾£¬×êÑÐÈËÔ±·¢ÏÔìäelastic·þÎñÆ÷δÉèÃÜÂ룬µ¼Ö¿ͻ§µÄÃô¸ÐÐÅÏ¢ÔÚÍøÉ϶³ö£¬Ô̺¬ÐÕÃû¡¢ÊÖ»úºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢Óû§ÃûºÍÃ÷ÎÄÃÜÂë¡¢IPµØÖ·¡¢ÒøÐп¨ÐÅÏ¢µÈ¡£Æ¾¾Ý×êÑÐÈËÔ±µÄµ÷²é£¬¸ÃÊý¾Ý¿âÔÚÍøÉ϶³öÁ˳¤´ï6ÖܵŦ·ò¡£×êÑÐÈËÔ±ÓÚ9ÔÂ4ÈÕ֪ͨÁËPouringPounds£¬µ«Ö±µ½9ÔÂ21ÈÕ¸ÃÊý¾Ý¿â²ÅµÃµ½±£»¤¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/cashback-websites-double-breach/

4¡¢ÃÉ´óÄÃÖÝÒ½ÔºÔâ´¹µö¹¥»÷£¬12.9ÍòÌõ»¼Õ߼ͼй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÉ´óÄÃÖÝ¿¨Àû˹Åå¶ûÊеÄÒ»¼ÒÒ½ÔºÔâ´¹µö¹¥»÷£¬µ¼ÖÂ12.9ÍòÌõ¿Í»§¼Í¼й¶¡£¹ÌÈ»¸ÃÒ½ÔºÔÚ6Ô·ݷ¢ÏÖй¶ÊÂÎñ£¬µ«µ÷²éÅú×¢¹¥»÷ÕßÔçÔÚ5ÔÂ24ÈÕ¾ÍÆðÍ·ÍøÂ综Õߵļͼ¡£¸ÃÒ½ÔºµÄ¶àÃûÔ±¹¤Ôâ´¹µö¹¥»÷£¬ÓÊÏäÍ´´¦±»ÇÔ£¬µ¼Ö¹¥»÷Õß¿ÉÄܽӼû»¼ÕßµÄÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µØÖ·¡¢²¡ÀúºÅ¡¢µ®ÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢²¡Ê·ºÍÒ½ÖÎÐÅÏ¢¡¢·þÎñÈÕÆÚ¡¢Ò½ÖκÍתÕïҽʦ¡¢Õ˵¥ºÅºÍ±£ÏÕÐÅÏ¢µÈ¡£¸ÃÒ½Ôº°µÊ¾250Ãû»¼ÕßµÄÉç»á°²È«ºÅÂë¿ÉÄÜÒ²Ôâй¶¡£

Ô­ÎÄÁ´½Ó£º
https://hotforsecurity.bitdefender.com/blog/hospital-leaks-129k-patient-records-in-sophisticated-phishing-scam-21674.html

5¡¢Õ˵¥·þÎñÉÌBilltrustÔâ¶ñÒâÈí¼þ¹¥»÷µ¼Ö·þÎñÖжÏ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úÕ˵¥·þÎñÉÌBilltrustÔâ¶ñÒâÈí¼þ¹¥»÷£¬µ¼ÖÂËùÓзþÎñÖжÏ¡£ÕâÒ»ÊÂÎñ²úÉúÔÚ10ÔÂ17ÈÕ£¬¹ÌÈ»Billtrust²¢Î´¹«¿ª´ËÊÂÎñ£¬µ«Æä¿Í»§Ö®Ò»Wittichen°ä²¼²¼¸æ³Æ½µ­Üµ½Á˸ù«Ë¾µÄ¶ñÒâÈí¼þ¹¥»÷֪ͨ¡£¸Ã¹«Ë¾»¹·î¸æWittichen£¬Ã»Óпͻ§µÄÊý¾ÝÔÚÕâ´Î¹¥»÷ÖÐÊܵ½ÇÖº¦£¬²¢ÇÒÓÉÓÚÉæ¼°µÄÊý¾ÝÁ¿Ì«´ó£¬¸Ã¹«Ë¾ÔÚÒÀÕÕ´òËãµÄ¹¦·ò±íÀ´¸´Ô­·þÎñ¡£Ö»¹Ü¸Ã¹«Ë¾²¢Î´Ö¸³öÍøÂç¹¥»÷µÄÀàÐÍ£¬µ«ÓÐÐÂÎÅÈËÊ¿³Æ¹¥»÷Ô­ÓÉÊÇÀÕË÷Èí¼þBitPaymer¡£¸Ã¹«Ë¾ÉÐδ¶Ô´Ë½øÐÐÆÀÂÛ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/billing-provider-billtrust-suffers-outage-after-malware-attack/

6¡¢×êÑÐÍŶӷ¢ÏÖMagecart Group 5ÓëCobalt´æÔÚ¹ØÁª

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖMagecart Group 5Óë´¹µö»î¶¯DridexºÍ·¸×ïÍŶÓCobalt´æÔÚ¹ØÁª¡£Magecart×éÖ¯³Êɡ״½á¹¹£¬Óɼ¸¸ö·ÖÆçµÄ·ÖÖ§»ú¹¹×é³É£¬Ã¿¸ö·ÖÖ§»ú¹¹¶¼Ê¹ÓÃÒ»ÑùµÄ¹¥»÷·½Ê½ - ¼´Í¨¹ýJavaScript´úÂëÇÔȡ֧¸¶Ò³ÃæÉϵÄÐÅÓþ¿¨ÐÅÏ¢¡£Magecart Group 5רÃÅÕë¶ÔµçÉ̵Ĺ©¸øÁ´£¬Í¨¹ý²é³­¸ÃÍŶӵÄÓòÃûÊýÁ¿¼°ÆäÓëÆäËû¶ñÒâ»î¶¯µÄÁªÏµ£¬Malwarebytes×êÑÐÈËÔ±½«ÆäÓëרÃÅÕë¶ÔÒøÐкÍATMµÄ·¸×ïÍÅ»ïCobalt¹ØÁªÆðÀ´¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/magecart-5-linked-carbanak-gang/149419/