Snatch¿Éͨ¹ý°²È«Ä£Ê½³ÁÆôÀ´Èƹýɱ¶¾Èí¼þ £»·ðÂÞÀï´ïÖÝÅíÈø¿ÆÀ­ÊÐÔâÍøÂç¹¥»÷ £¬ÊÐÕþ·þÎñÖжÏ

°ä²¼¹¦·ò 2019-12-11

1.ÀÕË÷Èí¼þSnatch¿Éͨ¹ý°²È«Ä£Ê½³ÁÆôÀ´Èƹýɱ¶¾Èí¼þ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÀÕË÷Èí¼þSnatchÔÚʹÓÃÒ»ÖÖǰËùδ¼ûµÄ¼¼ÇÉÀ´Èƹýɱ¶¾Èí¼þ £¬¾ßÌåÀ´Ëµ £¬ËüÄܹ»½«Êܺ¦ÕßµÄÍÆËã»úÒÔ°²È«Ä£Ê½³ÁÐÂÆô¶¯ £¬¶øºóÔËÐмÓÃܹý³Ì¡£´óÎÞÊýɱ¶¾Èí¼þ¶¼ÎÞ·¨ÔÚWindows°²È«Ä£Ê½ÏÂÆô¶¯ £¬Òò¶øSnatchÄÑÒÔ±»¼ì²âµ½¡£Æ¾¾ÝSophos LabsµÄ»ã±¨ £¬¸ÃÀÕË÷Èí¼þͨ¹ýWindows×¢²á±íÏîÔö³¤ÁËÒ»¸öÔÚ°²È«Ä£Ê½ÏÂÆô¶¯µÄ·þÎñ £¬¸Ã·þÎñ½«ÔËÐÐSnatch¡£×êÑÐÈËÔ±ÖÒ¸æ³ÆÕâÖÖģʽ¿ÉÄܻᱻÆäËüÀÕË÷Èí¼þËù·ÂÕÕ¡£Snatch×Ô2018ÄêÏļ¾ÒÔÀ´Ò»Ïò»îÔ¾ £¬ÆäÖØÒª½øÐÐÕë¶ÔÐԵĹ¥»÷¡£Óë´óÎÞÊýÀÕË÷Èí¼þ·ÖÆç £¬Snatch»¹»áÇÔÈ¡ÊÜϰȾϵͳÉϵÄÎļþ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/snatch-ransomware-reboots-pcs-in-windows-safe-mode-to-bypass-antivirus-apps/


2.ÃÀ¹ú³¬¹ý75Íò·Ýµ®ÉúÖ¤Ã÷ÉêÇëÔÚÔÆ·þÎñÆ÷Öж³ö


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢¹ú°²È«³§ÉÌFidus Information Security·¢ÏÖÒ»¸öÅäÖÃÃýÎóµÄÔÆ·þÎñÆ÷Öж³öÁ˳¬¹ý75Íò·ÝÃÀ¹úµ®ÉúÖ¤Ã÷ÉêÇë¡£¸ÃÊý¾Ý¿â´æ´¢ÔÚûÓÐÃÜÂë± £»¤µÄAWS´æ´¢Í°ÖÐ £¬Â¶³öµÄÊý¾ÝÔ̺¬ÉêÇëÈËÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢¼ÒͥסַºÍµç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëÒÔ¼°ÒÔǰµÄסַºÍ¼ÒÍ¥³ÉÔ±µÄÐÕÃûµÈÃô¸ÐÐÅÏ¢¡£ÓÉÓÚ¸ÃÊý¾Ý¿âµÄËùÓÐÕßÉÐδ»ØÓ¦×êÑÐÍŶӵÄ֪ͨ £¬Òò¶øFidusûÓÐй©¸Ã¹«Ë¾µÄÃû³Æ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/data-leak-exposes-750k-birth-cert/


3.·ðÂÞÀï´ïÖÝÅíÈø¿ÆÀ­ÊÐÔâÍøÂç¹¥»÷ £¬ÊÐÕþ·þÎñÖжÏ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


·ðÂÞÀï´ïÖÝÅíÈø¿ÆÀ­ÊÐÖÜÄ©ÆÚ¼äÔâµ½ÍøÂç¹¥»÷ £¬ÊÐÕþ·þÎñÊܵ½Ó°Ïì¡£¸ÃÊÂÎñ²úÉúÔÚÖÜÁùÁ賿1:30×óÓÒ £¬¸ÃÊеÄIT²¿ÃÅÒ»ÏòÔÚÖÂÁ¦¸´Ô­ÍøÂ硣ĿǰÉв»Ã÷ÏÔÊÂÎñÊÇÓÉÄÄÖÖÀàÐ͵ÄÍøÂç¹¥»÷µ¼ÖµÄ £¬Ò²²»Ã÷ÏÔÓм¸¶àÌ¨ÍÆËã»úÊܵ½Ó°Ïì £¬µ«¸ÃÊеĴó²¿ÃÅÍøÂçÏνӶ¼ÒѶϿª £¬Ô̺¬Pensacola EnergyÔÚÏßÖ§¸¶ÏµÍ³ÒÔ¼°³ÇÊÐÎÀÉúÉèÊ©¡¢»ùÓÚÍÆËã»úµÄͨÕÛ·þÎñ£¨Ô̺¬µç×ÓÓʼþϵͳ£©µÈ £¬µ«911ºÍÆäËü´¹Î£·þÎñ£¨¾¯Ô±ºÍÏû·À²¿ÃÅ£©Ã»ÓÐÊܵ½Ó°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/pensacola-florida-hit-by-cyber-attack-city-services-impacted/


4.Ã÷ÄáËÕ´ïÖÝÒ½ÁÆ»ú¹¹SEMOMSÔâµ½ÀÕË÷Èí¼þ¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ã÷ÄáËÕ´ïÖÝÒ»¼ÒרÃÅÒ½ÖÎÃæ²¿¡¢ÑÀ³Ý¡¢¿ÚÇ»µÄÒ½ÁÆ»ú¹¹£¨SEMOMS£©Ôâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬¸ÃÊÂÎñ²úÉúÔÚ9ÔÂ23ÈÕ £¬ITÈËÔ±ÔÚÊÂÎñ²úÉúºóÂíÉϲÉÈ¡Á˱ £»¤´ëÊ©¡£SEMOMSÔÚÆäÍøÕ¾Éϰ䷢µÄÉêÃ÷ÖаµÊ¾ £¬Ö»¹ÜĿǰûÓÐÖ¤¾ÝÅú×¢¹¥»÷Õß½Ó¼û»ò²é¿´ÁË»¼ÕßÐÅÏ¢ £¬µ«¸Ã»ú¹¹ÒѾ­²ÉÈ¡ÁË´ëÊ©²¢Í¨ÖªÁË¿ÉÄÜÊÜÓ°ÏìµÄ»¼Õß¡£SEMOMS³Æ»¼ÕߵIJÆÕþÐÅÏ¢¡¢²¡Àú»òÉç»á°²È«ºÅÂë¾ù²»»áÊܵ½ÊÂÎñµÄÓ°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/ransomware-attack-on-minnesota/


5.»î¶¯ÁãÊÛÉÌSweaty Betty¹ÙÍøÏ°È¾Magecart¾ç±¾


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Å®ÐԻװÁãÊÛÉÌSweaty BettyÒÑͨ¹ýµç×ÓÓʼþ·î¸æÓû§ÆäÖ§¸¶ÐÅÏ¢¿ÉÄܱ»ÇÔ¡£¸Ã¹«Ë¾³Æ¹ÙÍøµÄÖ§¸¶Ò³Ãæ±»Ö²ÈëÁËÇÔÈ¡¸¶¿îÐÅÏ¢µÄ¶ñÒâ´úÂë £¬ÊÜÓ°ÏìµÄ¿Í»§ÎªÔÚ11ÔÂ19ÈÕÐÇÆÚ¶þÏÂÎç6.24pm£¨GMT£©µ½11ÔÂ27ÈÕÐÇÆÚÈýÏÂÎç2.52pm£¨GMT£©Ö®¼ä¹ºÎïµÄ¿Í»§¡£¿ÉÄܱ»ÇÔµÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢ÃÜÂë¡¢Õ˵¥µØÖ·¡¢½»¸¶µØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢ÐÅÓþ¿¨ºÅ¡¢CVVÂëºÍÓÐЧÆÚµÈ¡£Ä¿Ç°Éв»Ã÷ÏÔÓм¸¶à¿Í»§Êܵ½¸ÃÊÂÎñµÄÓ°Ïì £¬µ«¸Ã¹«Ë¾°µÊ¾Ö»ÓÐÔÚÖ§¸¶Ò³ÃæÉÏÐÂÊäÈëÁËÐÅÏ¢¶ø²»ÊÇʹÓÃÒѱ£ÁôÐÅÏ¢µÄ¿Í»§²ÅÊܵ½Ó°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://hotforsecurity.bitdefender.com/blog/hackers-steal-credit-card-details-from-sweaty-betty-customers-21888.html


6.΢Èí°ä²¼12ÔÂWindows°²È«¸üР£¬½¨¸´36¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


΢ÈíÔÚ12ÔÂWindows°²È«¸üÐÂÖн¨¸´ÁË36¸ö·ì϶ £¬ÆäÖÐÔ̺¬7¸öÑϳÁ·ì϶ £¬27¸ö³ÁÒª·ì϶ £¬1¸öÖеȷì϶ºÍ1¸öµÍΣ·ì϶¡£±ØÒª¹Ø×¢µÄ·ì϶ÊÇWin32k×é¼þÖеÄÌØÈ¨ÌáÉý0day £¬¸Ã·ì϶£¨CVE-2019-1458£©ÊÇÓÉ¿¨°Í˹»ù×êÑÐÈËÔ±·¢ÏÖµÄ £¬²¢ÒÑÔÚÒ°±í±»»ý¼«ÀûÓá£Æ¾¾Ý΢ÈíµÄ°²È«²¼¸æ £¬¸Ã·ì϶²úÉúÔÚWin32k×é¼þÎÞ·¨ÕýÈ·´¦ÖÃÄÚ´æÖеĶÔÏóʱ £¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÄÚºËģʽÏÂÔËÐÐËÁÒâ´úÂë¡£ÒªÀûÓô˷ì϶ £¬¹¥»÷Õß±ØÐëÊ×ÏȵǼϵͳ £¬¶øºó¿Éͨ¹ýÔËÐÐÀûÓô˷ì϶µÄ¶ñÒâÈí¼þÀ´ÊÕÊÜϵͳ¡£¸ü¶à·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsofts-december-2019-patch-tuesday-fixes-win32k-zero-day-36-flaws/