ÎÖ˹±¤Ë®Îñ¾ÖÔâºÚ¿Í¹¥»÷£»¿ÆÂÞÀ¶àÖÝIT·þÎñÉÌCTSÔâµ½ÀÕË÷Èí¼þ¹¥»÷£»RyukбäÖÖ½âÃÜÆ÷ÓÐbug
°ä²¼¹¦·ò 2019-12-10
1.AirtelÀûÓ÷¨Ê½´æÔÚ·ì϶¿Éµ¼Ö¿ͻ§Êý¾Ý¶³ö
ÍøÂ簲ȫ×êÑÐÈËÔ±Ehraz Ahmed·¢ÏÖÓ¡¶ÈAirtel¹«Ë¾µÄÀûÓ÷¨Ê½´æÔÚ°²È«·ì϶£¬µ¼ÖÂÓû§µÄÃô¸ÐÐÅϢ¶³ö¡£¿É»ñÈ¡µÄÐÅÏ¢Ô̺¬ËÁÒâÓû§µÄÐÕÃû¡¢ÐԱ𡢵ç×ÓÓʼþµØÖ·¡¢µ®ÉúÈÕÆÚ¡¢×¡Ö·¡¢¶©ÔÄÐÅÏ¢¡¢ÍøÂçÐÅÏ¢¡¢¼¤»îÈÕÆÚ¡¢Óû§ÀàÐÍ£¨Ô¤¸¶·Ñ»òºó¸¶·Ñ£©¡¢IMEIºÅÂëµÈ¡£Ahmed°µÊ¾Airtel¹«Ë¾µÄÿ¸öÓû§¶¼´æÔÚ·çÏÕ£¬Õâ¿ÉÄÜÓ°ÏìÁËËùÓÐ3.255ÒÚÓû§¡£Airtel½²»°ÈËÈÏ¿ÉÁËÕâÒ»ÎÊÌ⣬²¢°µÊ¾¹«Ë¾ÔÚÊÕµ½¾¯±¨ºóÂíÉϽ¨¸´Á˸÷ì϶¡£
ÔÎÄÁ´½Ó£º
https://economictimes.indiatimes.com/tech/internet/security-flaw-in-airtel-app-exposes-customers-data-fixed-now/articleshow/72421661.cms
2.¿ÆÂÞÀ¶àÖÝIT·þÎñÉÌCTSÔâµ½ÀÕË÷Èí¼þ¹¥»÷
¿ÆÂÞÀ¶àÖÝIT·þÎñÉÌCTSÔâÀÕË÷Èí¼þ¹¥»÷£¬²¨¼°100¶à¼ÒÑÀ¿ÆÕïËù¡£CTSרΪÑÀ¿ÆÕïËùÌṩIT·þÎñ£¬Ô̺¬ÍøÂ簲ȫ¡¢Êý¾Ý±¸·ÝºÍIPÓïÒôµç»°µÈ¡£¸Ã¹«Ë¾ÓÚ11ÔÂ25ÈÕÔâµ½¹¥»÷£¬µ¼ÖÂ100¶à¼ÒÑÀ¿ÆÕïËùµÄÍÆËã»úϰȾÁËÀÕË÷Èí¼þSodinokibi¡£CTS»Ø¾øÁ˹¥»÷ÕßË÷Òª70ÍòÃÀÔªÊê½ðµÄÒªÇó£¬ÓÉÓÚϵͳ²»ÐÝÖжϣ¬Ä¿Ç°ºÜ¶àÑÀ¿ÆÕïËùÒÀÈ»ÎÞ·¨Õý³£½»Òס£
ÔÎÄÁ´½Ó£º
https://krebsonsecurity.com/2019/12/ransomware-at-colorado-it-provider-affects-100-dental-offices/
3.ÎÖ˹±¤Ë®Îñ¾ÖÔâºÚ¿Í¹¥»÷£¬Ô¼3000¿Í»§ÐÅÏ¢±»ÇÔ
ÎÖ˹±¤Ë®Îñ¾Ö°µÊ¾ÆäÒ»¼Ò³Ð°üÉÌCentralSquareÔâºÚ¿ÍÈëÇÖ£¬µ¼ÖÂÔ¼3000ÃûʹÓÃÐÅÓþ¿¨Ö§¸¶Ë®·ÑÕ˵¥µÄÓû§ÒþÖÔÐÅÏ¢¿ÉÄܱ»ÇÔ¡£±»µÁµÄÐÅÏ¢¿ÉÄÜÔ̺¬ÐÕÃû¡¢µØÖ·ºÍÐÅÓþ¿¨Êý¾Ý£¬Ô̺¬¿¨ºÅºÍ°²È«Â룬ÊÜÓ°ÏìµÄÓû§ÎªÔÚ8ÔÂ27ÈÕÖÁ10ÔÂ23ÈÕÖ®¼ä½øÐÐÔÚÏ߸¶¿îµÄÓû§¡£Ë®Îñ¾ÖÅ®½²»°ÈËMary Gugliuzza°µÊ¾ÒѾ֪ͨÁË¿ÉÄÜÊÜÓ°ÏìµÄÓû§£¬CentralSquare½«ÎªÊÜÓ°ÏìµÄÓû§ÌṩһÄêµÄÃâ·ÑÐÅÓþ¼à¿Ø·þÎñ¡£
ÔÎÄÁ´½Ó£º
https://www.nbcdfw.com/news/local/3000-Fort-Worth-Water-Department-Customers-Victims-of-Data-Breach-565838632.html
4.Spotify´¹µö¹¥»÷ÖØÒªÇÔÈ¡Óû§µÄÐÅÓþ¿¨ÐÅÏ¢
×êÑÐÈËÔ±·¢ÏÖÒ»¸öеĴ¹µö¹¥»÷»î¶¯£¬¹¥»÷ÕßÖØÒªÕë¶ÔSpotifyÓû§£¬ÊÔͼºýŪÆäÕË»§Í´´¦ºÍ¸¶¿îÐÅÏ¢¡£¸Ã´¹µöÓʼþÔÚ·ÂÕÕSpotifyÒ³ÃæÖг£¼ûµÄÅäÉ«¹æ»®¡¢logo¡¢×ÖÌåºÍÊ¢ÐÐͼƬÉÏÖ§³öÁ˺ܴóµÖÁ¦£¬ÊÔͼºýŪÓû§ÏàÐÅÆäÕË»§ÓÉÓÚÖ§¸¶Ê§°Ü¶øÎÞ·¨³ÖÐøÏíÊܶ©ÔÄ·þÎñ¡£ÊÜÆµÄÓû§±»ÒªÇó½Ó¼ûÒ»¸öÐéαµÄSpotify´¹µöÍøÕ¾£¬²¢ÊäÈë¾ßÌåµÄµÇ¼ÐÅÏ¢ºÍÖ§¸¶ÐÅÏ¢£¬Ô̺¬ÐÅÓþ¿¨ºÅÂëºÍCVVÂë¡£Spotify¹«Ë¾ÖÒ¸æÓû§³Æ£¬¸Ã¹«Ë¾¾ø²»»áͨ¹ýµç×ÓÓʼþÒªÇó»áÔ±ÌṩÓ×ÎÒÒþÖÔÐÅÏ¢£¬ÀýÈçÖ§¸¶ÐÅÏ¢¡¢ÕË»§ÃÜÂë»ò˰ÎñºÅÂëµÈ¡£
ÔÎÄÁ´½Ó£º
https://au.finance.yahoo.com/news/spotify-scam-harvests-credit-card-details-200027468.html
5.д¹µö»î¶¯ÖØÒªÕë¶ÔÉϹžíÖáOLÓÎÏ·Íæ¼Ò
´¹µö¹¥»÷Õß¼Ù×°³ÉÉϹžíÖáÓÎÏ·µÄ¿ª·¢Õߣ¬Õë¶ÔÓµÓÐPlayStation½ÚÔį̀£¨¿ÉÄÜ»¹ÓÐÆäËû£©µÄÓÎÏ·Õß½øÐд¹µö¹¥»÷¡£ËûÃÇÏòÓû§·¢ËÍËæ»úµÄ¸öÈËÐÅÏ¢£¬ÖÒ¸æÆäÕË»§³öÏÖ°²È«ÎÊÌ⣬ҪÇóÓû§ÔÚ15·ÖÖӵŦ·òÀïÌṩµç×ÓÓʼþµØÖ·¡¢ÃÜÂëºÍµ®ÉúÈÕÆÚ£¬²»È»ÆäÕË»§½«±»·â½û¡£¸Ã´¹µö¹¥»÷µÄ×îÖÕÖ÷ÕÅÊÇÇÔÈ¡Íæ¼ÒÕË»§ÄÚµÄÓÎÏ·ÉÌÆ·²¢ÔÚ°µÍøÉÏÏúÊÛ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fake-elder-scrolls-online-devs-run-playstation-phishing-scam/
6.RyukбäÖÖ½âÃÜÆ÷ÓÐbug£¬¿ÉÄܵ¼ÖÂÊý¾ÝÓÀÔ¼ûÔʧ
ƾ¾Ý°²È«³§ÉÌEmsisoftµÄ˵·¨£¬ÀÕË÷Èí¼þRyuk×îбäÖֵĽâÃÜÆ÷´æÔÚÒ»¸öbug£¬¼´±ãÊܺ¦ÕßÖ§¸¶ÁËÊê½ð£¬Ò²¿ÉÄÜ»áÓÉÓÚ´Ëbugµ¼ÖÂÊý¾ÝÎÞ·¨¸´ÔºÍÃÔʧ¡£¸Ã±äÖÖ¶ÔÆä¼ÓÃܹý³Ì½øÐÐÁËÅú¸Ä£¬ÈôÊÇÎļþ´óÓ׳¬¹ý54.4MB£¬ÔòÖ»½øÐв¿ÃżÓÃÜ£¬²½ÖèÊǶԿ϶¨ÊýÁ¿µÄ100Íò×Ö½ÚÊý¾Ý¿é½øÐмÓÃÜ¡£È»¶øÆä½âÃÜÆ÷ÔÚÍÆËãÎļþ´óÓ×ʱ´Óĩβ½Ø¶ÏÁËÒ»¸ö×Ö½Ú£¬¹ÌÈ»´óÎÞÊýÎļþÖÐ×îºóÒ»¸ö×Ö½ÚÖ»ÊÇÌî³ä£¬µ«Ä³Ð©À©´óÃûµÄÎļþ£¨ÀýÈçÐé¹¹´ÅÅÌÎļþ¡¢OracleÊý¾Ý¿âÎļþ£©ÔÚ×îºóÒ»¸ö×Ö½ÚÖд洢³ÁÒªÐÅÏ¢£¬Ê¹µÃ°Ü»µµÄÎļþÔÚ½âÃܺóÎÞ·¨ÕýÈ·¼ÓÔØ¡£¸üÔã¸âµÄÊÇ£¬½âÃÜÆ÷»áÒÔΪÒÑÕýÈ·½âÃܲ¢É¾³ý¼ÓÃܵÄÎļþ£¬Ê¹µÃÊý¾Ý¸üÄѸ´Ô¡£Emsisoft½¨ÒéÓû§±£Áô¼ÓÃÜÎļþµÄ±¸·Ý£¬ÒÔÃâ±»½âÃÜÆ÷Ëù·ÛËé¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ryuk-ransomware-decryptor-is-broken-could-lead-to-data-loss/


¾©¹«Íø°²±¸11010802024551ºÅ