ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ11ÖÜ

°ä²¼¹¦·ò 2019-03-18

±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2019Äê3ÔÂ11ÈÕÖÁ17ÈÕ¹²ÊÕ¼°²È«·ì϶55¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Internet Explorer¾ç±¾ÒýÇæCVE-2019-0783Ô¶³ÌÄÚ´æ·ÛËé·ì϶£»Microsoft Windows ActiveX CVE-2019-0784Ô¶³Ì´úÂëÖ´Ðзì϶; Microsoft Azure°²È«ÏÞ¶ÈÈÆ¹ý·ì϶£»Google Chrome V8¶ÑÒç¶Âí½Å£»LCDS LAquis SCADAÔ½½çд·ì϶¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇGoogle PlayÖÐ210¸öAPPϰȾ¸æ°×Èí¼þSimBad£¬²¨¼°1.5ÒÚÓû§£»¿¨°Í˹»ù°ä²¼2018ÄêÀ¬»øÓʼþ¼°´¹µö¹¥»÷»ã±¨£»Õë¶ÔWordPressµÄй¥»÷º£³±£¬ÖØÒªÀûÓùºÎï³µ²å¼þÖеÄXSS·ì϶£»ÐµÄATM skimmer¹¥»÷£¬¿É½Ù³ÖATMÄÚÖÃÉãÏñÍ·£»ÃÀ¹úJacksonÏØµ±¾ÖÏòÀÕË÷Èí¼þ¹¥»÷ÕßÖ§¸¶40ÍòÃÀÔªÊê½ð¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£

³ÁÒª°²È«·ì϶Áбí


1. Microsoft Internet Explorer¾ç±¾ÒýÇæCVE-2019-0783Ô¶³ÌÄÚ´æ·ÛËé·ì϶
Microsoft Internet Explorer´¦ÖÃÄÚ´æ¶ÔÏó´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄwebÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0783

2. Microsoft Windows ActiveX CVE-2019-0784Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft ActiveX Data objects (ADO)´¦ÖÃÄÚ´æ¶ÔÏó´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0784

3. Microsoft Azure°²È«ÏÞ¶ÈÈÆ¹ý·ì϶
Microsoft Azure SSH KeypairsʹÓÃcloud-initµÄLinuxÓ³ÏñÅäÖÃÈí¼þµÄ¸ü¸Ä£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Èƹý°²È«ÏÞ¶È¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0816

4. Google Chrome V8¶ÑÒç¶Âí½Å
Google Chrome V8´æÔÚ¶Ñ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄwebÒ³£¬ÓÕʹÓû§½âÎö£¬¿ÉÌáÉýȨÏÞ¡£
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop_12.html

5. LCDS LAquis SCADAÔ½½çд·ì϶
LCDS LAquis SCADA´¦ÖÃelsÎļþ´æÔÚÔ½½çд·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâ´úÂë¡£
https://ics-cert.us-cert.gov/advisories/ICSA-19-073-01

³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Google PlayÖÐ210¸öAPPϰȾ¸æ°×Èí¼þSimBad£¬²¨¼°1.5ÒÚÓû§


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝCheck PointµÄÒ»·Ý»ã±¨£¬×êÑÐÈËÔ±ÔÚGoogle PlayÖз¢ÏÖ210¸öAPPϰȾÁ˸æ°×Èí¼þSimBad£¬ÕâЩAPPµÄ×Ü×°ÖÃÁ¿´ï1.5ÒڴΡ£´óÎÞÊýAPP¶¼ÊÇÈü³µ»òÉä»÷ÓÎÏ·£¬ÆäÖÐÃûΪSnow Heavy Excavator SimulatorµÄAPPÏÂÔØÁ¿³¬¹ý1000Íò¡£SimBad¼Ù×°³É¸æ°×¹¤¾ß°üRXDrioder£¬µ±Óû§×°ÖÃÁËÊÜϰȾµÄAPPºó£¬¸ÃAPP»áÔÚÉ豸Æô¶¯»òÓû§½âËøÊ±×Ô¶¯Æô¶¯²¢ÏÔʾ¸æ°×£¬´Ë±í£¬¶ñÒâ´úÂ뻹»áÖ´ÐдÓC&C·þÎñÆ÷½Ó¹Üµ½µÄºÅÁÔ̺¬É¾³ýͼ±ê¡¢ºó¶Ü¸æ°×¡¢´ò¿ªÍøÒ³µÈ¡£GoogleÒѾ­Ï¼ÜÁËÕâЩAPP¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/simbad-adware-found-in-210-android-apps-with-over-150m-installs/

2¡¢¿¨°Í˹»ù°ä²¼2018ÄêÀ¬»øÓʼþ¼°´¹µö¹¥»÷»ã±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ù°ä²¼2018ÄêµÄÀ¬»øÓʼþºÍ´¹µö¹¥»÷ͳ¼Æ»ã±¨£¬»ã±¨µÄÖØÒª·¢ÏÖÔ̺¬£ºÈ«Çòµç×ÓÓʼþÁ÷Á¿ÖеÄÀ¬»øÓʼþÊý¾ÝµÄÕ¼±ÈΪ52.48%£¬±È2017Äê½µµÍ4.15¸ö°Ù·Öµã£»2018Äê×î´óµÄÀ¬»øÓʼþÆðÔ´¹úÊÇÖйú£¨11.69£¥£©£»74.15£¥µÄÀ¬»øÓʼþÓ×ÓÚ2 KB£»À¬»øÓʼþÖÐ×î³£±»¼ì²âµ½µÄ·ì϶ÀûÓÃÊÇWin32.CVE-2017-11882¡£

Ô­ÎÄÁ´½Ó£º
https://securelist.com/spam-and-phishing-in-2018/89701/

3¡¢Õë¶ÔWordPressµÄй¥»÷º£³±£¬ÖØÒªÀûÓùºÎï³µ²å¼þÖеÄXSS·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Defiant×êÑÐÈËÔ±Mikey Veenstra·¢ÏÖÒ»¸öÕë¶ÔWordPress¹ºÎïÍøÕ¾µÄ¹¥»÷º£³±£¬¹¥»÷ÕßÀûÓùºÎï³µ²å¼þ¡°Abondoned Cart Lite for WooCommerce¡±ÖеÄXSS·ì϶£¬ÏòÍøÕ¾Ö²ÈëºóÃŲ¢»ñµÃÍøÕ¾µÄ½ÚÔìȨ¡£¾Ý±¨Â·¸Ã²å¼þÒÑÔÚ³¬¹ý2Íò¸öWordPressÍøÕ¾ÉÏ×°Ö᣹¥»÷ÕßÖ²ÈëµÄºóÃÅÔ̺¬Ò»¸öÖÎÀíÔ¹ØË»§woouserÒÔ¼°Ôڷǻ²å¼þÖÐÖ²ÈëµÄPHPºóÃÅ¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/hackers-abuse-xss-vulnerability-in-cart-plugin-to-target-wordpress-based-shopping-sites-ff4b4019

4¡¢ÐµÄATM skimmer¹¥»÷£¬¿É½Ù³ÖATMÄÚÖÃÉãÏñÍ·


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝKrebs on SecurityµÄÒ»·Ýл㱨£¬×êÑÐÈËÔ±Ôڵ¿ËÈøË¹ÖݺÕË¹ÌØÊеÄATMÉÏ·¢ÏÖÁËеÄskimmer¹¥»÷£¬¹¥»÷Õßͨ¹ý½Ù³ÖATMÖÐÄÚÖõÄÉãÏñÍ·ÒÔÇÔÈ¡Óû§µÄPINÂë¡£¸ÃskimmerÔ̺¬Ò»¸öÉãÏñÍ·²¿¼þ£¬ÓÃÓÚ¸²¸ÇÔÚATMÄÚÖõݲȫÉãÏñÍ·ÉÏÃæ£¬Óû§ºÜÄÑ´Ó±í²¿¿´µ½¸Ãskimmer¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/new-atm-skimming-attack-enables-scammers-to-hijack-the-atms-in-built-camera-and-steal-a-users-pin-3d2c4884

5¡¢ÃÀ¹úJacksonÏØµ±¾ÖÏòÀÕË÷Èí¼þ¹¥»÷ÕßÖ§¸¶40ÍòÃÀÔªÊê½ð


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úÇÇÖÎÑÇÖݽܿËÑ·ÏØÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µ±¾ÖÏò·¸×ï·Ö×ÓÖ§¸¶ÁË40ÍòÃÀÔªµÄÊê½ðÒÔ»ñµÃ½âÃÜÃÜÔ¿¡£Õâ´Î¹¥»÷ÊÂÎñÓ°ÏìÁ˸ÃÏØËùÓв¿ÃŵÄÍÆËã»úϵͳ£¬Ô̺¬µç×ÓÓʼþ·þÎñºÍ´¹Î£·þÎñ£¬´¦Ê´¦²»µÃ²»Ê¹ÓÃÖ½ÕÅÒÔʵÏÖ¹¤×÷¡£ÓÉÓÚ¸ÃÏØÃ»Óб¸·Ýϵͳ£¬Ïص±¾Ö²»µÃ²»Âú×ã¹¥»÷ÕßµÄÒªÇóÒÔ»»È¡ÕýÈ·µÄ½âÃÜÃÜÔ¿¡£Æ¾¾ÝFBIµÄµ÷²é£¬·¸×ï·Ö×ÓʹÓõÄÀÕË÷Èí¼þ¿ÉÄÜÊÇRyuk£¬¹¥»÷ÕßÒÉΪ¶«Å·µÄÒ»¸ö×éÖ¯¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ransomware-attack-on-jackson-county-gets-cybercriminals-400-000/

ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù