ÎÖ˹±¤Ë®Îñ¾ÖÔâºÚ¿Í¹¥»÷ £»¿ÆÂÞÀ­¶àÖÝIT·þÎñÉÌCTSÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £»RyukбäÖÖ½âÃÜÆ÷ÓÐbug

Ðû²¼Ê±¼ä 2019-12-10


1.AirtelÓ¦ÓóÌÐò±£´æÎó²î¿Éµ¼Ö¿ͻ§Êý¾Ý̻¶


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÍøÂçÇå¾²Ñо¿Ö°Ô±Ehraz Ahmed·¢Ã÷Ó¡¶ÈAirtel¹«Ë¾µÄÓ¦ÓóÌÐò±£´æÇå¾²Îó²î£¬µ¼ÖÂÓû§µÄÃô¸ÐÐÅϢ̻¶¡£¿É»ñÈ¡µÄÐÅÏ¢°üÀ¨í§ÒâÓû§µÄÐÕÃû¡¢ÐԱ𡢵ç×ÓÓʼþµØµã¡¢³öÉúÈÕÆÚ¡¢×¡Ö·¡¢¶©ÔÄÐÅÏ¢¡¢ÍøÂçÐÅÏ¢¡¢¼¤»îÈÕÆÚ¡¢Óû§ÀàÐÍ£¨Ô¤¸¶·Ñ»òºó¸¶·Ñ£©¡¢IMEIºÅÂëµÈ¡£AhmedÌåÏÖAirtel¹«Ë¾µÄÿ¸öÓû§¶¼±£´æÎ£º¦£¬Õâ¿ÉÄÜÓ°ÏìÁËËùÓÐ3.255ÒÚÓû§¡£Airtel½²»°ÈËÈÏ¿ÉÁËÕâÒ»ÎÊÌ⣬²¢ÌåÏÖ¹«Ë¾ÔÚÊÕµ½¾¯±¨ºóÁ¬Ã¦ÐÞ¸´Á˸ÃÎó²î¡£


  Ô­ÎÄÁ´½Ó£º

https://economictimes.indiatimes.com/tech/internet/security-flaw-in-airtel-app-exposes-customers-data-fixed-now/articleshow/72421661.cms


2.¿ÆÂÞÀ­¶àÖÝIT·þÎñÉÌCTSÔâµ½ÀÕË÷Èí¼þ¹¥»÷


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


¿ÆÂÞÀ­¶àÖÝIT·þÎñÉÌCTSÔâÀÕË÷Èí¼þ¹¥»÷£¬²¨¼°100¶à¼ÒÑÀ¿ÆÕïËù¡£CTSרΪÑÀ¿ÆÕïËùÌṩIT·þÎñ£¬°üÀ¨ÍøÂçÇå¾²¡¢Êý¾Ý±¸·ÝºÍIPÓïÒôµç»°µÈ¡£¸Ã¹«Ë¾ÓÚ11ÔÂ25ÈÕÔâµ½¹¥»÷£¬µ¼ÖÂ100¶à¼ÒÑÀ¿ÆÕïËùµÄÅÌËã»úѬȾÁËÀÕË÷Èí¼þSodinokibi¡£CTS¾Ü¾øÁ˹¥»÷ÕßË÷Òª70ÍòÃÀÔªÊê½ðµÄÒªÇó£¬ÓÉÓÚϵͳһֱÖÐÖ¹£¬ÏÖÔÚÐí¶àÑÀ¿ÆÕïËùÈÔÈ»ÎÞ·¨Õý³£ÓªÒµ¡£


 Ô­ÎÄÁ´½Ó£º

https://krebsonsecurity.com/2019/12/ransomware-at-colorado-it-provider-affects-100-dental-offices/


3.ÎÖ˹±¤Ë®Îñ¾ÖÔâºÚ¿Í¹¥»÷£¬Ô¼3000¿Í»§ÐÅÏ¢±»ÇÔ


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÎÖ˹±¤Ë®Îñ¾ÖÌåÏÖÆäÒ»¼Ò³Ð°üÉÌCentralSquareÔâºÚ¿ÍÈëÇÖ£¬µ¼ÖÂÔ¼3000ÃûʹÓÃÐÅÓÿ¨Ö§¸¶Ë®·ÑÕ˵¥µÄÓû§Òþ˽ÐÅÏ¢¿ÉÄܱ»ÇÔ¡£±»µÁµÄÐÅÏ¢¿ÉÄܰüÀ¨ÐÕÃû¡¢µØµãºÍÐÅÓÿ¨Êý¾Ý£¬°üÀ¨¿¨ºÅºÍÇå¾²Â룬ÊÜÓ°ÏìµÄÓû§ÎªÔÚ8ÔÂ27ÈÕÖÁ10ÔÂ23ÈÕÖ®¼ä¾ÙÐÐÔÚÏ߸¶¿îµÄÓû§¡£Ë®Îñ¾ÖÅ®½²»°ÈËMary GugliuzzaÌåÏÖÒѾ­Í¨ÖªÁË¿ÉÄÜÊÜÓ°ÏìµÄÓû§£¬CentralSquare½«ÎªÊÜÓ°ÏìµÄÓû§ÌṩһÄêµÄÃâ·ÑÐÅÓÃ¼à¿Ø·þÎñ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.nbcdfw.com/news/local/3000-Fort-Worth-Water-Department-Customers-Victims-of-Data-Breach-565838632.html


4.Spotify´¹ÂÚ¹¥»÷Ö÷ÒªÇÔÈ¡Óû§µÄÐÅÓÿ¨ÐÅÏ¢


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Ñо¿Ö°Ô±·¢Ã÷Ò»¸öеĴ¹ÂÚ¹¥»÷Ô˶¯£¬¹¥»÷ÕßÖ÷ÒªÕë¶ÔSpotifyÓû§£¬ÊÔͼÓÕÆ­ÆäÕË»§Æ¾Ö¤ºÍ¸¶¿îÐÅÏ¢¡£¸Ã´¹ÂÚÓʼþÔÚÄ£ÄâSpotifyÒ³ÃæÖг£¼ûµÄÅäÉ«¼Æ»®¡¢logo¡¢×ÖÌåºÍÊ¢ÐÐͼƬÉÏÖ§¸¶Á˺ܴóÆð¾¢£¬ÊÔͼÓÕÆ­Óû§ÐÅÍÐÆäÕË»§ÓÉÓÚÖ§¸¶Ê§°Ü¶øÎÞ·¨¼ÌÐøÏíÊܶ©ÔÄ·þÎñ¡£ÊÜÆ­µÄÓû§±»ÒªÇó»á¼ûÒ»¸öÐéαµÄSpotify´¹ÂÚÍøÕ¾£¬²¢ÊäÈëÏêϸµÄµÇ¼ÐÅÏ¢ºÍÖ§¸¶ÐÅÏ¢£¬°üÀ¨ÐÅÓÿ¨ºÅÂëºÍCVVÂë¡£Spotify¹«Ë¾ÖÒÑÔÓû§³Æ£¬¸Ã¹«Ë¾¾ø²»»áͨ¹ýµç×ÓÓʼþÒªÇó»áÔ±ÌṩСÎÒ˽¼ÒÒþ˽ÐÅÏ¢£¬ÀýÈçÖ§¸¶ÐÅÏ¢¡¢ÕË»§ÃÜÂë»ò˰ÎñºÅÂëµÈ¡£


 Ô­ÎÄÁ´½Ó£º

https://au.finance.yahoo.com/news/spotify-scam-harvests-credit-card-details-200027468.html


5.д¹ÂÚÔ˶¯Ö÷ÒªÕë¶ÔÉϹžíÖáOLÓÎÏ·Íæ¼Ò


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


´¹ÂÚ¹¥»÷Õßαװ³ÉÉϹžíÖáÓÎÏ·µÄ¿ª·¢Õߣ¬Õë¶Ô¾ßÓÐPlayStation¿ØÖÆÌ¨£¨¿ÉÄÜÉÐÓÐÆäËû£©µÄÓÎÏ·Õß¾ÙÐд¹ÂÚ¹¥»÷¡£ËûÃÇÏòÓû§·¢ËÍËæ»úµÄ˽ÈËÐÅÏ¢£¬ÖÒÑÔÆäÕË»§·ºÆðÇå¾²ÎÊÌ⣬ҪÇóÓû§ÔÚ15·ÖÖÓµÄʱ¼äÀïÌṩµç×ÓÓʼþµØµã¡¢ÃÜÂëºÍ³öÉúÈÕÆÚ£¬²»È»ÆäÕË»§½«±»·â½û¡£¸Ã´¹ÂÚ¹¥»÷µÄ×îÖÕÄ¿µÄÊÇÇÔÈ¡Íæ¼ÒÕË»§ÄÚµÄÓÎÏ·ÉÌÆ·²¢ÔÚ°µÍøÉϳöÊÛ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-elder-scrolls-online-devs-run-playstation-phishing-scam/


6.RyukбäÖÖ½âÃÜÆ÷ÓÐbug£¬¿ÉÄܵ¼ÖÂÊý¾ÝÓÀÊÀɥʧ


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ƾ֤Çå¾²³§ÉÌEmsisoftµÄ˵·¨£¬ÀÕË÷Èí¼þRyuk×îбäÖֵĽâÃÜÆ÷±£´æÒ»¸öbug£¬×ÝÈ»Êܺ¦ÕßÖ§¸¶ÁËÊê½ð£¬Ò²¿ÉÄÜ»áÓÉÓÚ´Ëbugµ¼ÖÂÊý¾ÝÎÞ·¨»Ö¸´ºÍɥʧ¡£¸Ã±äÖÖ¶ÔÆä¼ÓÃÜÀú³Ì¾ÙÐÐÁËÐ޸ģ¬ÈôÊÇÎļþ¾ÞϸÁè¼Ý54.4MB£¬ÔòÖ»¾ÙÐв¿·Ö¼ÓÃÜ£¬ÒªÁìÊǶÔÒ»¶¨ÃüÄ¿µÄ100Íò×Ö½ÚÊý¾Ý¿é¾ÙÐмÓÃÜ¡£È»¶øÆä½âÃÜÆ÷ÔÚÅÌËãÎļþ¾Þϸʱ´Óĩβ½Ø¶ÏÁËÒ»¸ö×Ö½Ú£¬ËäÈ»´ó´ó¶¼ÎļþÖÐ×îºóÒ»¸ö×Ö½ÚÖ»ÊÇÌî³ä£¬µ«Ä³Ð©À©Õ¹ÃûµÄÎļþ£¨ÀýÈçÐéÄâ´ÅÅÌÎļþ¡¢OracleÊý¾Ý¿âÎļþ£©ÔÚ×îºóÒ»¸ö×Ö½ÚÖд洢Ö÷ÒªÐÅÏ¢£¬Ê¹µÃË𻵵ÄÎļþÔÚ½âÃܺóÎÞ·¨×¼È·¼ÓÔØ¡£¸üÔã¸âµÄÊÇ£¬½âÃÜÆ÷»áÒÔΪÒÑ׼ȷ½âÃܲ¢É¾³ý¼ÓÃܵÄÎļþ£¬Ê¹µÃÊý¾Ý¸üÄѻָ´¡£Emsisoft½¨ÒéÓû§±£´æ¼ÓÃÜÎļþµÄ±¸·Ý£¬ÒÔÃâ±»½âÃÜÆ÷ËùÆÆËð¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ryuk-ransomware-decryptor-is-broken-could-lead-to-data-loss/