µ¤Âó˰Îñ·þÎñй¶120Íò¹«ÃñµÄCPRºÅÂ룻DellÐÞ¸´SupportAssistÖеIJ»¿ÉÐÅËÑË÷·¾¶Îó²î
Ðû²¼Ê±¼ä 2020-02-111.µ¤Âó˰Îñ·þÎñй¶120Íò¹«ÃñµÄCPRºÅÂë
µ¤ÂóÕþ¸®·¢Ã÷TastSelv Borger˰Îñ·þÎñй¶ÁË120Íò¹«ÃñµÄCPR£¨µ¤ÂóÉí·ÝÖ¤¼þ£©ºÅÂë¡£¸Ã·þÎñÓÉÃÀ¹úDXC Technology¹«Ë¾ÖÎÀí£¬ÔÊÐíµ¤Âó¹«ÃñÉó²éºÍ¸ü¸ÄÆäÄÉ˰É걨±í¡¢Äê¶È±¨±í²¢½ÉÄÉÊ£Óà˰¿î¡£ÔÚ·¢Ã÷֮ǰ£¬°üÀ¨CPRºÅÔÚÄÚµÄÊý¾ÝÒÑ̻¶ÁË¿ìÒªÎåÄêµÄʱ¼ä¡£DR NewsÍøÕ¾±¨¸æ³Æ£¬Ò»µ©µÇ¼Tastselv BorgerµÄÓû§¸üÕýÁËËûÃǵÄÁªÏµÐÅÏ¢£¬Ó¦ÓóÌÐòÖеĹýʧ¾Í»áµ¼ÖÂCPRºÅ×÷ÎªÍøÖ·µÄÒ»²¿·Ö·¢Ë͵½GoogleºÍAdobe¡£DXCÒÑÈ·ÈϸÃÎó²î²¢Òѽâ¾ö¸ÃÎÊÌâ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/97571/data-breach/1-2m-cpr-numbers-leak.html
2.ÒÔÉ«ÁÐÇå¾²²½¶Ó½ü3¸öÔÂÄÚÊܵ½10000´ÎÍøÂç¹¥»÷
¾ÝÏ£²®À´ÓïÐÂÎÅÍøÕ¾YnetÖÜÈÕ±¨µÀ£¬ÔÚÒÑÍùµÄÈý¸öÔÂÖУ¬ÒÔÉ«ÁÐÇå¾²²½¶ÓµÄÊ®¸öÖ÷ÒªÍøÕ¾³ÉΪÁË10000¶àÆðÍøÂç¹¥»÷µÄÄ¿µÄ¡£¸ÃÊý¾ÝÊÇ»ùÓÚÒÔÉ«ÁÐ-ÃÀ¹úÍøÂçÇå¾²¹«Ë¾ImpervaµÄ±¨¸æ£¬±¨¸æÖл¹ÏÔʾÁíÍâÔ¼40¸öÒÔÉ«ÁÐÖ´·¨ºÍÕþ¸®ÍøÕ¾Ôâµ½ÁËÊýǧ´ÎÒÔÉϵÄÍøÂç¹¥»÷¡£ÒÔÉ«Áйú¼ÒÍøÂçÖÎÀí¾Ö³ÆÕþ¸®ÍøÕ¾Êܵ½¸ß¶ÈÏȽøµÄ·ÀÓùϵͳµÄ±£»¤£¬ÕâЩ¹¥»÷¶ÔÆäûÓÐÓ°Ïì¡£
ÔÎÄÁ´½Ó£º
http://www.xinhuanet.com/english/2020-02/10/c_138768894.htm
3.¹¥»÷ÕßʹÓÃÃâ·ÑÈí¼þLock My PCËø¶¨Óû§ÅÌËã»ú
ÊÖÒÕÖ§³ÖÕ©ÆÕßʹÓÃÃûΪLock My PCµÄÃâ·Ñ¹¤¾ßÀ´Ëø¶¨Óû§µÄÅÌËã»ú£¬²¢ÒªÇóÖ§¸¶½âËøÓöȡ£¶àÄêÀ´Î±×°³É΢Èí¡¢¹È¸èµÈ¹«Ë¾µÄÊÖÒÕÖ§³ÖÕ©ÆÕßÒ»Ö±ÔÚʹÓÃWindows Syskey³ÌÐò½«Óû§µÄÏµÍ³Ëø¶¨£¬µ«ÓÉÓÚ΢ÈíÔÚWindows 10 1709ÖÐɾ³ýÁ˶ÔSyskeyµÄËùÓÐÖ§³Ö£¬Òò´ËÕ©ÆÕßÒÑÇл»µ½Lock My PC¡£ÓëSyskey¼ÓÃÜWindows SAMÊý¾Ý¿â²¢Ê¹ÓÃÊäÈëµÄÃÜÂë¶ÔÆä¾ÙÐнâÃܲî±ð£¬Lock My PC²»¼ÓÃÜÈκÎÄÚÈÝ£¬½öʹÓÃÃÜÂë×èÖ¹¶ÔÅÌËã»úµÄ»á¼û¡£¸ÃÈí¼þ»¹ÒÔÇ徲ģʽÔËÐУ¬Ê¹µÃûÓÐÃÜÂë»òboot»Ö¸´¹¤¾ßʱºÜÄѽûÓÃËü¡£Lock My PCµÄ¿ª·¢Ö°Ô±FSPro Labs·¢Ã÷ÆäÈí¼þ±»ÀÄÓúóÐû²¼²»ÔÙÌṩÃâ·Ñ°æ±¾£¬²¢ÇÒΪÊܺ¦ÕßÌṩÁËÃâ·ÑµÄ»Ö¸´ÃÜÂë¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/lock-my-pc-used-by-tech-support-scammers-dev-offers-free-recovery/
4.Â׶عú¼ÒФÏñ»ÀÈÔÚ2019ÄêQ4Ôâµ½½ü35Íò·âÀ¬»øÓʼþ¹¥»÷
ƾ֤Ӣ¹úÐÅÏ¢×ÔÓÉ·¨°¸Åû¶µÄÊý¾Ý£¬Parliament StreetÖǿⷢÃ÷Â׶عú¼ÒФÏñ»ÀÈÔÚ2019ÄêµÚËÄÐò¶ÈÔâµ½½ü35Íò´ÎÀ¬»øÓʼþ¹¥»÷¡£¹ú¼ÒФÏñ»ÀÈÊÇÂ×¶Ø×ʢÃûµÄÃÀÊõ¹ÝÖ®Ò»£¬Ã¿Äê½Ó´ý110ÍòÖÁ120ÍòÓοͣ¬Æä·þÎñÆ÷´æ´¢ÁËÐí¶àÓο͵ĸ¶¿îÃ÷ϸºÍµç×ÓÓʼþµØµãµÈ˽ÈËÐÅÏ¢¡£ÔÚÕâ½ü35Íò·â±»×èÖ¹µÄÀ¬»øÓʼþÖУ¬ÓÐ56%±»Ê¶±ðΪÕʺÅÍøÂç¹¥»÷£¬ÁíÍâ61710·âÊÇÓÉÓÚ·¢¼þÈËÔÚ¡°ÍþвÇ鱨ºÚÃûµ¥¡±É϶ø±»×èÖ¹£¬ÉÐÓÐ85793·â±»ÒÔΪ°üÀ¨À¬»øÓʼþÄÚÈÝÒÔ¼°418·â°üÀ¨²¡¶¾¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/national-portrait-gallery-email
5.¼ÓÃÜÉúÒâËùAltsbitÔâºÚ¿Í¹¥»÷£¬½«ÓÚ5ÔÂ8ÈչرÕ
¾Ý±¨µÀ£¬×ܲ¿Î»ÓÚÒâ´óÀûµÄ¼ÓÃÜÇ®±ÒÉúÒâÆ½Ì¨AltsbitÌåÏÖÔâµ½ºÚ¿ÍÈëÇÖ£¬ÏÕЩËùÓÐBTC¡¢ETH¡¢ARRRºÍVRSC×ʽ𶼱»µÁ£¬Ö»ÓÐһС²¿·Ö·ÅÔÚÀäÇ®°üÖеÄ×ʽðÊÇÇå¾²µÄ¡£×èÖ¹·¢¸åʱ£¬ËðʧµÄBTCºÍETHµÄ¼ÛֵԼΪ6.3ÍòÃÀÔª¡£¸ÃÉúÒâËùÌåÏÖûÓÐ×ã¹»µÄ×ʽðÀ´Åâ³¥Óû§£¬Òò´ËÒªÇóÓû§ÉêÇ벿·ÖÍ˿ÍË¿îʱ¼äΪ2ÔÂ10ÈÕµ½5ÔÂ8ÈÕ£¬ÔÚÕâÌìÆÚÖ®ºó¸ÃÉúÒâËù½«¹Ø±Õ¡£ºÚ¿Í×éÖ¯LulzSecÔÚTwitterÖÐÉù³Æ¶Ô´ËÊÂÎñÈÏÕæ¡£
ÔÎÄÁ´½Ó£º
https://www.coindesk.com/new-crypto-exchange-altsbit-says-it-will-close-following-hack
6.DellÐÞ¸´SupportAssistÖеIJ»¿ÉÐÅËÑË÷·¾¶Îó²î
DellÐû²¼Çå¾²¸üУ¬ÐÞ¸´SupportAssist ClientÈí¼þÖеÄÒ»¸ö²»¿ÉÐÅËÑË÷·¾¶Îó²î£¬¸ÃÎó²î£¨CVE-2020-5316£©ÔÊÐíDZÔÚµÄÍâµØ¹¥»÷ÕßÔÚÒ×Êܹ¥»÷µÄÅÌËã»úÉÏÒÔÖÎÀíԱȨÏÞÖ´ÐÐí§Òâ´úÂë¡£SupportAssistÊÇԤװÖÃÔÚ´ó´ó¶¼DellÉè±¹ØÁ¬ÄÖ§³ÖÈí¼þ£¬Òò´Ë¸ÃÎó²îµÄDZÔÚÓ°Ïì¹æÄ£½Ï¹ã¡£Æ¾Ö¤DellµÄÎó²îת´ï£¬¾ÓÉÍâµØÉí·ÝÑéÖ¤µÄµÍÌØÈ¨Óû§¿ÉÄÜʹÓôËÎó²îµ¼ÖÂSupportAssist¶þ½øÖÆÎļþ¼ÓÔØí§ÒâDLL£¬´Ó¶øµ¼ÖÂÌØÈ¨´úÂëµÄÖ´ÐС£¸ÃÎó²îµÄCVSSv3»ù±¾µÃ·ÖΪ7.8·Ö£¬Ó°ÏìÁËÉÌÓÃPCµÄSupportAssist 2.1.3»ò¸üÔç°æ±¾£¬ÒÔ¼°¼ÒÓÃPCµÄSupportAssist 3.4»ò¸üÔç°æ±¾¡£DellÒѾÔÚа汾ÖÐÐÞ¸´Á˸ÃÎó²î£¬ÈôÊÇÆôÓÃÁË×Ô¶¯Éý¼¶£¬ÔòËùÓа汾µÄSupportAssist¶¼»á×Ô¶¯×°ÖÃ×îп¯Ðеİ汾¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/dell-supportassist-bug-exposes-business-home-pcs-to-attacks/


¾©¹«Íø°²±¸11010802024551ºÅ