ÃÀ¹úColonialPipelineϰȾÀÕË÷Èí¼þ£¬ÖØÒªÊäÓ͹ÜÍ£ÔË£»AMD SCSIAdapterÇý¶¯¸üпɵ¼ÖÂWin10ϵͳ±ÀÀ£
°ä²¼¹¦·ò 2021-05-101.ÃÀ¹úColonial PipelineϰȾÀÕË÷Èí¼þ£¬ÖØÒªÊäÓ͹ÜÍ£ÔË

ÃÀ¹ú×î´óµÄȼÁϹÜ·¹«Ë¾Colonial PipelineÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬5500Ó¢ÀïÊäÓ͹ÜÍ£ÔË¡£Colonial PipelineÿÌì´ÓµÂ¿ËÈøË¹ÖÝÊäËÍ250ÍòͰʯÓ͵½¶«º£°¶ºÍŦԼ£¬¸Ã¹Ü·¸²¸ÇÁËÃÀ¹ú¶«º£°¶45£¥µÄȼÁϹ©¸ø¡£¸Ã¹«Ë¾ÔÚÉÏÖÜÁù°µÊ¾£¬ÆäÓÚ5ÔÂ7ÈÕÔâµ½ÀÕË÷¹¥»÷£¬·¢ÏÖ¹¥»÷ºó×Ô¶¯¹Ø¹ØÁ˹ؼüµÄϵͳÒÔÔ¤·À´«²¼£¬Ä¿Ç°ÕýÓ밲ȫ¹«Ë¾ºÏ×÷¶Ô¸ÃÊÂÎñµÄÐÔÖʺÍÁìÓò½øÐе÷²é¡£ÃÀ¹úµÄij¹ÙÔ±³Æ£¬Õâ´ÎÀÕË÷¹¥»÷ÊÂÎñÓëDarkSideÍÅ»ïÓйء£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/largest-us-pipeline-shuts-down-operations-after-ransomware-attack/
2.·¨¹úЬÀàºÍÊÎÆ·¹«Ë¾VejaÔâµ½¹¥»÷£¬Óû§ÐÅϢй¶

Damien Licata Caruso»ã±¨³Æ£¬Veja¹«Ë¾ÔÚ4ÔÂ26ÈÕÔâµ½¹¥»÷£¬Óû§ÐÅϢй¶¡£VejaÊǵ퍹úЬÀàºÍÊÎÆ·Æ·ÅÆ£¬ÖØÒªÒÔÆä»·±£»î¶¯Ð¬¶øÎÅÃû¡£Õâ´ÎÊÂÎñй¶ÁË2004Äê´´½¨µÄÔ̺¬¿Í»§ÐÅÏ¢Êý¾Ý¿â£¬Éæ¼°ÔÚÏ߲ɰì»ò¶©ÔÄVejaÐÂÎŵĿͻ§µÄÓʼþµØÖ·µÈÐÅÏ¢¡£¸ÃÆ·ÅÆµÄÊ×´´ÈËS¨¦bastienKopp³ÆÕâ´Î²¢Î´Ð¹Â¶ÓйØÒøÐеľßÌåÐÅÏ¢£¬²¢ÇÒËùÓÐÃÜÂë¶¼±»¼ÓÃܵġ£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/fr-eco-friendly-sneaker-brand-veja-hacked/
3.´ó»ªÒøÐÐÒòÆäÔ±¹¤Ôâµ½Ú¿ÆÐ¹Â¶Ç§ÓàÖйú¹«ÃñµÄÐÅÏ¢

ÐÂ¼ÓÆÂ´ó»ªÒøÐУ¨UOB£©ÒòÆäÔ±¹¤Ôâµ½Ú¿ÆÐ¹Â¶Ç§ÓàÖйú¹«ÃñµÄÐÅÏ¢¡£¾ÝϤ£¬¸ÃÔ±¹¤±»¼ÙÒâΪÖйú¾¯·½µÄȦÌ×ËùºýŪ£¬Ð¹Â¶ÁË1166ÃûÖйú¹«ÃñµÄÓ×ÎÒ¾ßÌåÐÅÏ¢£¬Ô̺¬¿Í»§µÄÐÕÃû¡¢Éí·ÝÖ¤¡¢ÊÖ»úºÅÂëÒÔ¼°ÕË»§Óà¶îµÈ¡£´ó»ªÒøÐаµÊ¾£¬²¢Ã»Óпͻ§µÄÒøÐÐÕʺÅй¶£¬²¢ÇÒÆäITϵͳÒÀÈ»Êǰ²È«µÄ¡£Ä¿Ç°£¬¸ÃÔ±¹¤Òѱ»Í£Ö°£¬²¢ÔÚÐÖú¾¯·½¶Ô´ËʽøÐе÷²é¡£
ÔÎÄÁ´½Ó£º
https://mothership.sg/2021/05/uob-employee-leak-customers-scam/
4.AMD SCSIAdapterÇý¶¯¸üпɵ¼ÖÂWindows 10ϵͳ±ÀÀ£

AMD SCSIAdapterÇý¶¯¸üпɵ¼ÖÂWindows 10ϵͳ±ÀÀ£¡£ºÜ¶àÓû§»ã±¨£¬ÔÚ×°ÖøÃÇý¶¯Ê±»á±»ÌáÐѳÁÆôϵͳ£¬¶øºó³öÏÖÀ¶ÆÁËÀ»ú(BSOD)µÄÎÊÌ⣬²¢ÏÔʾ¡°²»³É½Ó¼ûµÄÆô¶¯É豸¡±£¨INACCESSIBLE_BOOT_DEVICE£©µÄÃýÎóÌáÐÑ¡£Windows Latest°µÊ¾£¬Ä¿Ç°¸ÃÎÊÌâËÆºõ½öÓ°ÏìijЩAMDÓ²¼þƽ̨£¬ÓÈÆäÊÇʹÓÃÁ˼¼¼ÎX570Ö÷°åµÄÍÆËã»ú¡£Ä¿Ç°£¬Î¢ÈíÒÑ´ÓWindows UpdateÖÐÒÆ³ýÁ˸øüС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-pulls-windows-10-amd-driver-causing-pcs-not-to-boot/
5.CISA¡¢NCSC¡¢FBIÓëNSA½áºÏ°ä²¼ÓйضíÂÞ˹SVRµÄÕ÷ѯ

CISAÓëÓ¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©¡¢Áª¹úµ÷²é¾Ö£¨FBI£©ºÍ¹ú¶È°²È«¾Ö£¨NSA£©½áºÏ°ä²¼ÓйضíÂÞ˹SVRµÄ°²È«Õ÷ѯ¡£¸ÃÕ÷ѯָ³öSVRËÆºõÒÑͨ¹ý¸ü¸ÄÆä¼¼ÊõºÍ·¨Ê½£¨TTP£©£¬À´Ô¤·À×éÖ¯·¢ÏÔìä»î¶¯ºÍ²ÉÈ¡²¹¾È´ëÊ©¡£´Ë±í£¬SVRÖØÒªÕë¶Ôµ±¾Ö¡¢Öǿ⡢Õþ²ßºÍÄÜÔ´ÓйصÄ×éÖ¯£¬ÒÔ¼°ÓÐʱЧÐÔµÄÖ¸±ê£¬ÀýÈç2020ÄêÓëCOVID-19ÒßÃçÓйصÄ×éÖ¯¡£ºÚ¿ÍÖØÒªÊ¹ÓÃÁËCVE-2018-13379¡¢CVE-2019-1653ºÍCVE-2019-2725µÈ11¸ö·ì϶¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2021/05/07/joint-ncsc-cisa-fbi-nsa-cybersecurity-advisory-russian-svr
6.×êÑÐÍŶӷ¢ÏÖWordPress CleanTalk´æÔÚSQL×¢Èë·ì϶

WordfenceÍŶÓÅû¶WordPress²å¼þCleanTalk´æÔÚSQL×¢Èë·ì϶¡£¸Ã²å¼þÓµÓÐÀ¬»øÓʼþ·À»¤¡¢·´À¬»øÓʼþºÍ·À»ðǽµÈÖ°ÄÜ£¬Äܹ»¹ýÂ˵ôWordPress CMSÍøÕ¾ÉϵÄÀ¬»øÓʼþºÍÆÀÂÛ¡£¸Ã·ì϶׷×ÙΪCVE-2021-24295£¬ÊÇ»ùÓÚ¹¦·òµÄSQLäע·ì϶£¬¹¥»÷Õß¿ÉÀûÓô˷ì϶À´½Ó¼ûÓû§µÄµç×ÓÓʼþ¡¢ÃÜÂë¡¢ÐÅÓþ¿¨Êý¾ÝºÍÆäËûÃô¸ÐÐÅÏ¢¡£Ä¿Ç°£¬¸Ã·ì϶ÒÑͨ¹ý°æ±¾5.153.4½â¾ö¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/117721/security/anti-spam-wordpress-plugin-flaw.html


¾©¹«Íø°²±¸11010802024551ºÅ