FortinetÇå¾²²úÆ·Ó²±àÂë¼ÓÃÜÃÜÔ¿Îó²î£¨CVE-2018-9195£©£»ÃÀ¹úIT·þÎñÔËÓªÉÌVCPIÔâµ½ÀÕË÷Èí¼þryuk¹¥»÷
Ðû²¼Ê±¼ä 2019-11-26
ÃÀ¹ú·Ò×˹°²ÄÇÖݵÄ5000̨Õþ¸®ÅÌËã»úÖÐÓÐ10%Ôâµ½ÍøÂç¹¥»÷µÄÆÆË𡣸ÃÖÝÐÅÏ¢¹ÙÔ±Neal UnderwoodÌåÏÖ£¬ÀÕË÷Èí¼þ¹¥»÷¶ÔÖÝÕþ¸®Ã»ÓÐÔì³ÉÔÖÄÑÐÔµÄÓ°Ï죬ûÓÐÊý¾Ýɥʧ£¬Ò²Ã»ÓÐÖ§¸¶Êê½ð¡£µ«Underwood³ÆÄ³Ð©²¿·ÖÊÜËðÑÏÖØ£¬ÓÈÆäÊdzµÁ¾°ì¹«ÊÒ - ¸Ã°ì¹«ÊҵķÖÖ§»ú¹¹ÒѾ¹Ø±ÕÁ˳¤´ïÒ»ÖܵÄʱ¼ä¡£Underwood»¹ÌåÏÖ¸ÃÖݵÄ3Íǫ̀ÅÌËã»úÖÐÓÐ1500̨Êܵ½Á˹¥»÷¡£ÏÖÔÚÊÓ²ìÖ°Ô±»¹ÔÚÊÓ²ìÍøÂç¹¥»÷µÄȪԴ¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/cyberattack-hit-10-louisianas-state-government-servers2¡¢ÃÀ¹úIT·þÎñÔËÓªÉÌVCPIÔâµ½ÀÕË÷Èí¼þryuk¹¥»÷
×ܲ¿Î»ÓÚÃÀ¹úÍþ˹¿µÐÇÖÝÃܶûÎÖ»ùµÄIT·þÎñÉÌVCPIÔâÀÕË÷Èí¼þRyuk¹¥»÷£¬¸Ã¹«Ë¾Îª¿Í»§ÍйܵÄËùÓÐÊý¾Ý¾ù±»¼ÓÃÜ£¬¹¥»÷ÕßÀÕË÷µÄÊê½ð¸ß´ï1400ÍòÃÀÔª¡£VCPIΪ45¸öÖݵÄ110ËùÁÆÑøÔººÍ¼±Ö¢Õչ˻¤Ê¿ÉèÊ©ÌṩIT×Éѯ¡¢»¥ÁªÍø»á¼û¡¢Êý¾Ý´æ´¢ºÍÇå¾²·þÎñ£¬×ÜÌå¶øÑԸù«Ë¾ÈÏÕæÎ¬»¤Ô¼8Íǫ̀ÅÌËã»úºÍ·þÎñÆ÷¡£¹¥»÷ÊÂÎñ±¬·¢ÔÚ11ÔÂ17ÈÕÆÆÏþ1µã30·Ö×óÓÒ£¬µ«Çå¾²³§ÉÌHold Security³ÆÖ¤¾ÝÅú×¢×î³õµÄÈëÇÖ¿ÉÄÜÔçÔÚ2018Äê9Ô¾Í×îÏÈÁË¡£VCPIÊ×ϯִÐйټæËùÓÐÕßKaren ChristiansonÌåÏÖÕâ´Î¹¥»÷ÏÖʵÉÏÓ°ÏìÁËËûÃǵÄËùÓн¹µã²úÆ·£¬°üÀ¨Internet·þÎñºÍµç×ÓÓʼþ¡¢»¼Õ߼ͼ¡¢¿Í»§Õ˵¥ºÍµç»°ÏµÍ³£¬ÉõÖÁ°üÀ¨VCPI×Ô¼ºµÄÈËΪºËËãϵͳ¡£
ÔÎÄÁ´½Ó£º
https://krebsonsecurity.com/2019/11/110-nursing-homes-cut-off-from-health-records-in-ransomware-attack/3¡¢¶à¸öAndroid APPÈÔÊÜGIFÎó²î(CVE-2019-11932)Ó°Ïì
CVE-2019-11932ÊÇÔÚWhatsAppµÄAndroid°æ±¾Öз¢Ã÷µÄÒ»¸öÎó²î£¬¹¥»÷Õß¿Éͨ¹ý¶ñÒâGIFÎļþʹÓøÃÎó²îÔ¶³ÌÖ´ÐдúÂë¡£¸ÃÎó²îÊ×´ÎÅû¶ÓÚ10ÔÂ2ÈÕ£¬²¢ÒÑÔÚWhatsApp 2.19.244°æ±¾ÖÐÐÞ¸´£¬µ«Ç±ÔÚµÄÎÊÌâÈÔÈ»±£´æÓÚÃûΪlibpl_droidsonroids_gif.soµÄ¿â¡£¸Ã¿âÊÇandroid-gif-drawableÈí¼þ°üµÄÒ»²¿·Ö£¬Ðí¶àAPPÈÔÔÚʹÓþɵİ汾£¬µ¼ÖÂËüÃÇÈÔ´¦ÓÚΣÏÕÖ®ÖС£½öÔÚGoogle PlayÉÏÑо¿Ö°Ô±¾Í·¢Ã÷ÁË3000¶à¸öÊÜ´ËÎó²îÓ°ÏìµÄAPP£¬Õ⻹²»°üÀ¨µÚÈý·½Ó¦ÓÃÊÐËÁ£¨ÀýÈç1mobile¡¢9AppsµÈ£©Öеĸü¶àAPP¡£
ÔÎÄÁ´½Ó£º
https://blog.trendmicro.com/trendlabs-security-intelligence/patched-gif-processing-vulnerability-cve-2019-11932-still-afflicts-multiple-mobile-apps/4¡¢FortinetÇå¾²²úÆ·Ó²±àÂë¼ÓÃÜÃÜÔ¿Îó²î£¨CVE-2018-9195£©
SEC ConsultÇå¾²Ñо¿Ô±StefanViehb?ckÔÚFortinetµÄFortiOSÖз¢Ã÷Ó²±àÂëµÄ¼ÓÃÜÃÜÔ¿£¨CVE-2018-9195£©£¬ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨FortiGate·À»ðǽÒÔ¼°MacºÍWindows°æ±¾µÄFortiClientÖն˱£»¤Èí¼þ¡£ÕâÈýÖÖ²úƷʹÓÃÈõ¼ÓÃÜ£¨XOR£©²¢ÇÒÊÇÓ²±àÂëµÄ¼ÓÃÜÃÜÔ¿ÓëÖÖÖÖFortiGateÔÆ·þÎñ¾ÙÐÐͨѶ¡£¸ÃÃÜÔ¿ÓÃÓÚ¼ÓÃÜFortiGuard Web¹ýÂ˹¦Ð§¡¢FortiGuard·´À¬»øÓʼþ¹¦Ð§ºÍFortiGuard AntiVirus¹¦Ð§µÄÓû§Á÷Á¿¡£¹¥»÷Õß¿ÉʹÓôËÎó²îÐá̽Óû§µÄÁ÷Á¿£¬¸ú×ÙËûÃǵÄä¯ÀÀ¼Í¼»òµç×ÓÓʼþÊý¾Ý¡£Ñо¿Ö°Ô±ÓÚ2018Äê5Ô·¢Ã÷²¢±¨¸æÁËÕâЩÎÊÌ⣬µ«Fortinet»¨ÁË10µ½18¸öÔµÄʱ¼ä²Åɾ³ýÁËÓ²±àÂëµÄÃÜÔ¿¡£½¨ÒéÓû§¸üÐÂÖÁFortiOS 6.0.7»ò6.2.0¡¢FortiClient Windows 6.2.0¼°FortiClient Mac 6.2.2¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/some-fortinet-products-shipped-with-hardcoded-encryption-keys/
5¡¢ÐÂ¼ÓÆÂ»á¼ÆÎ¯Ô±»áÒâÍâй¶Լ6500Ãû»á¼ÆÊ¦Êý¾Ý
ÐÂ¼ÓÆÂ»á¼ÆÎ¯Ô±»á¡°ÎÞÒâ¼ä¡±Ïò¶à¸ö×éÖ¯·¢ËÍÁ˰üÀ¨6541Ãû»á¼ÆÖ°Ô±Êý¾ÝµÄµç×ÓÓʼþ£¬ÕâÒ»ÎÊÌâÖ±µ½ÊýÔºó²Å±»·¢Ã÷¡£Æ¾Ö¤¸ÃίԱ»áµÄÉùÃ÷£¬½ñÄê6ÔÂ12ÈÕÖÁ10ÔÂ22ÈÕÖ®¼äÕâЩÊý¾Ýͨ¹ý¶à·âµç×ÓÓʼþ±»·¢Ë͸øÁË22¸ö×éÖ¯£¬ÆäÖаüÀ¨21¸ö¾ÓÉÈÏÖ¤µÄÅàѵ×éÖ¯£¨ATO£©ºÍÒ»¸ö¹©Ó¦ÉÌ¡£ÊÜÓ°ÏìµÄÖ°Ô±°üÀ¨ÐÂ¼ÓÆÂÌØÐí»á¼ÆÊ¦×ʸñÍýÏëµÄÄ¿½ñ¼°ÒÑÍùµÄºòÑ¡È˺Í5ÔÂ17ÈÕ֮ǰ¼ÓÈë¸ÃÏîÄ¿ÖÎÀíµÄATOÖ°Ô±¼°ÆäËû¸ß¹Ü¡£Ì»Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢Éí·ÝÖ¤ºÅ¡¢³öÉúÈÕÆÚºÍ¾ÍÒµÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/security-lapse-exposes-personal-data-of-6500-singapore-accountants/
6¡¢Ð¼üÅ̼ͼľÂíPhoenixÒÑѬȾÁè¼Ý1Íò¸öϵͳ
CybereasonÑо¿Ö°Ô±ÔÚÒ»·Ý±¨¸æÖÐÌåÏÖ£¬Ò»¸öÃûΪPhoenixµÄмüÅ̼ͼľÂí´Ó7Ô·Ý×îÏȾÍÔÚºÚ¿ÍÂÛ̳ÉϳöÊÛ£¬Ä¿½ñÒÑÓÐ1Íò¶àÆðѬȾÊÂÎñÓëÖ®Óйء£ÔÚÒÑÍùµÄ¼¸¸öÔÂÖУ¬Phoenix´Ó¼òÆÓµÄ¼üÅ̼ͼľÂí£¨keylogger£©ÑݱäΪ¾ß±¸¸ü¶à¹¦Ð§µÄÐÅÏ¢ÇÔȡľÂí£¨infostealer£©¡£½Ïеİ汾¿É´Ó20ÖÖ²î±ðµÄä¯ÀÀÆ÷¡¢4¸ö²î±ðµÄÓʼþ¿Í»§¶ËÒÔ¼°FTP¿Í»§¶ËºÍ̸ÌìÓ¦ÓÃÖÐÇÔÈ¡Óû§Êý¾Ý£¨ÀýÈçÃÜÂ룩¡£±ðµÄ£¬Phoenix»¹¾ß±¸·´AVºÍ·´VMÄ£¿é£¬ÕâÁ½¸öÄ£¿é½«ÊµÑ鹨±Õ80¶àÖÖ³£¼ûµÄÇå¾²²úÆ·ºÍVMÓ¦ÓõÄÀú³Ì¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/new-phoenix-keylogger-tries-to-stop-over-80-security-products-to-avoid-detection/


¾©¹«Íø°²±¸11010802024551ºÅ