ÎÖ˹±¤Ë®Îñ¾ÖÔâºÚ¿Í¹¥»÷£»¿ÆÂÞÀ­¶àÖÝIT·þÎñÉÌCTSÔâµ½ÀÕË÷Èí¼þ¹¥»÷£»RyukбäÖÖ½âÃÜÆ÷ÓÐbug

Ðû²¼Ê±¼ä 2019-12-10


1.AirtelÓ¦ÓóÌÐò±£´æÎó²î¿Éµ¼Ö¿ͻ§Êý¾Ý̻¶


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


ÍøÂçÇå¾²Ñо¿Ö°Ô±Ehraz Ahmed·¢Ã÷Ó¡¶ÈAirtel¹«Ë¾µÄÓ¦ÓóÌÐò±£´æÇå¾²Îó²î £¬µ¼ÖÂÓû§µÄÃô¸ÐÐÅϢ̻¶¡£¿É»ñÈ¡µÄÐÅÏ¢°üÀ¨í§ÒâÓû§µÄÐÕÃû¡¢ÐԱ𡢵ç×ÓÓʼþµØÖ·¡¢³öÉúÈÕÆÚ¡¢×¡Ö·¡¢¶©ÔÄÐÅÏ¢¡¢ÍøÂçÐÅÏ¢¡¢¼¤»îÈÕÆÚ¡¢Óû§ÀàÐÍ£¨Ô¤¸¶·Ñ»òºó¸¶·Ñ£©¡¢IMEIºÅÂëµÈ¡£AhmedÌåÏÖAirtel¹«Ë¾µÄÿ¸öÓû§¶¼±£´æÎ£º¦ £¬Õâ¿ÉÄÜÓ°ÏìÁËËùÓÐ3.255ÒÚÓû§¡£Airtel½²»°ÈËÈÏ¿ÉÁËÕâÒ»ÎÊÌâ £¬²¢ÌåÏÖ¹«Ë¾ÔÚÊÕµ½¾¯±¨ºóÁ¬Ã¦ÐÞ¸´Á˸ÃÎó²î¡£


  Ô­ÎÄÁ´½Ó£º

https://economictimes.indiatimes.com/tech/internet/security-flaw-in-airtel-app-exposes-customers-data-fixed-now/articleshow/72421661.cms


2.¿ÆÂÞÀ­¶àÖÝIT·þÎñÉÌCTSÔâµ½ÀÕË÷Èí¼þ¹¥»÷


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


¿ÆÂÞÀ­¶àÖÝIT·þÎñÉÌCTSÔâÀÕË÷Èí¼þ¹¥»÷ £¬²¨¼°100¶à¼ÒÑÀ¿ÆÕïËù¡£CTSרΪÑÀ¿ÆÕïËùÌṩIT·þÎñ £¬°üÀ¨ÍøÂçÇå¾²¡¢Êý¾Ý±¸·ÝºÍIPÓïÒôµç»°µÈ¡£¸Ã¹«Ë¾ÓÚ11ÔÂ25ÈÕÔâµ½¹¥»÷ £¬µ¼ÖÂ100¶à¼ÒÑÀ¿ÆÕïËùµÄÅÌËã»úѬȾÁËÀÕË÷Èí¼þSodinokibi¡£CTS¾Ü¾øÁ˹¥»÷ÕßË÷Òª70ÍòÃÀÔªÊê½ðµÄÒªÇó £¬ÓÉÓÚϵͳһֱÖÐÖ¹ £¬ÏÖÔÚÐí¶àÑÀ¿ÆÕïËùÈÔÈ»ÎÞ·¨Õý³£ÓªÒµ¡£


 Ô­ÎÄÁ´½Ó£º

https://krebsonsecurity.com/2019/12/ransomware-at-colorado-it-provider-affects-100-dental-offices/


3.ÎÖ˹±¤Ë®Îñ¾ÖÔâºÚ¿Í¹¥»÷ £¬Ô¼3000¿Í»§ÐÅÏ¢±»ÇÔ


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


ÎÖ˹±¤Ë®Îñ¾ÖÌåÏÖÆäÒ»¼Ò³Ð°üÉÌCentralSquareÔâºÚ¿ÍÈëÇÖ £¬µ¼ÖÂÔ¼3000ÃûʹÓÃÐÅÓÿ¨Ö§¸¶Ë®·ÑÕ˵¥µÄÓû§Òþ˽ÐÅÏ¢¿ÉÄܱ»ÇÔ¡£±»µÁµÄÐÅÏ¢¿ÉÄܰüÀ¨ÐÕÃû¡¢µØÖ·ºÍÐÅÓÿ¨Êý¾Ý £¬°üÀ¨¿¨ºÅºÍÇå¾²Âë £¬ÊÜÓ°ÏìµÄÓû§ÎªÔÚ8ÔÂ27ÈÕÖÁ10ÔÂ23ÈÕÖ®¼ä¾ÙÐÐÔÚÏ߸¶¿îµÄÓû§¡£Ë®Îñ¾ÖÅ®½²»°ÈËMary GugliuzzaÌåÏÖÒѾ­Í¨ÖªÁË¿ÉÄÜÊÜÓ°ÏìµÄÓû§ £¬CentralSquare½«ÎªÊÜÓ°ÏìµÄÓû§ÌṩһÄêµÄÃâ·ÑÐÅÓÃ¼à¿Ø·þÎñ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.nbcdfw.com/news/local/3000-Fort-Worth-Water-Department-Customers-Victims-of-Data-Breach-565838632.html


4.Spotify´¹ÂÚ¹¥»÷Ö÷ÒªÇÔÈ¡Óû§µÄÐÅÓÿ¨ÐÅÏ¢


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


Ñо¿Ö°Ô±·¢Ã÷Ò»¸öеĴ¹ÂÚ¹¥»÷Ô˶¯ £¬¹¥»÷ÕßÖ÷ÒªÕë¶ÔSpotifyÓû§ £¬ÊÔͼÓÕÆ­ÆäÕË»§Æ¾Ö¤ºÍ¸¶¿îÐÅÏ¢¡£¸Ã´¹ÂÚÓʼþÔÚÄ£ÄâSpotifyÒ³ÃæÖг£¼ûµÄÅäÉ«¼Æ»®¡¢logo¡¢×ÖÌåºÍÊ¢ÐÐͼƬÉÏÖ§¸¶Á˺ܴóÆð¾¢ £¬ÊÔͼÓÕÆ­Óû§ÏàÐÅÆäÕË»§ÓÉÓÚÖ§¸¶Ê§°Ü¶øÎÞ·¨¼ÌÐøÏíÊܶ©ÔÄ·þÎñ¡£ÊÜÆ­µÄÓû§±»ÒªÇó»á¼ûÒ»¸öÐéαµÄSpotify´¹ÂÚÍøÕ¾ £¬²¢ÊäÈëÏêϸµÄµÇ¼ÐÅÏ¢ºÍÖ§¸¶ÐÅÏ¢ £¬°üÀ¨ÐÅÓÿ¨ºÅÂëºÍCVVÂë¡£Spotify¹«Ë¾ÖÒÑÔÓû§³Æ £¬¸Ã¹«Ë¾¾ø²»»áͨ¹ýµç×ÓÓʼþÒªÇó»áÔ±ÌṩСÎÒ˽¼ÒÒþ˽ÐÅÏ¢ £¬ÀýÈçÖ§¸¶ÐÅÏ¢¡¢ÕË»§ÃÜÂë»ò˰ÎñºÅÂëµÈ¡£


 Ô­ÎÄÁ´½Ó£º

https://au.finance.yahoo.com/news/spotify-scam-harvests-credit-card-details-200027468.html


5.д¹ÂÚÔ˶¯Ö÷ÒªÕë¶ÔÉϹžíÖáOLÓÎÏ·Íæ¼Ò


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


´¹ÂÚ¹¥»÷Õßαװ³ÉÉϹžíÖáÓÎÏ·µÄ¿ª·¢Õß £¬Õë¶Ô¾ßÓÐPlayStation¿ØÖÆÌ¨£¨¿ÉÄÜÉÐÓÐÆäËû£©µÄÓÎÏ·Õß¾ÙÐд¹ÂÚ¹¥»÷¡£ËûÃÇÏòÓû§·¢ËÍËæ»úµÄ˽ÈËÐÅÏ¢ £¬ÖÒÑÔÆäÕË»§·ºÆðÇå¾²ÎÊÌâ £¬ÒªÇóÓû§ÔÚ15·ÖÖÓµÄʱ¼äÀïÌṩµç×ÓÓʼþµØÖ·¡¢ÃÜÂëºÍ³öÉúÈÕÆÚ £¬²»È»ÆäÕË»§½«±»·â½û¡£¸Ã´¹ÂÚ¹¥»÷µÄ×îÖÕÄ¿µÄÊÇÇÔÈ¡Íæ¼ÒÕË»§ÄÚµÄÓÎÏ·ÉÌÆ·²¢ÔÚ°µÍøÉϳöÊÛ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-elder-scrolls-online-devs-run-playstation-phishing-scam/


6.RyukбäÖÖ½âÃÜÆ÷ÓÐbug £¬¿ÉÄܵ¼ÖÂÊý¾ÝÓÀÊÀɥʧ


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


ƾ֤Çå¾²³§ÉÌEmsisoftµÄ˵·¨ £¬ÀÕË÷Èí¼þRyuk×îбäÖֵĽâÃÜÆ÷±£´æÒ»¸öbug £¬×ÝÈ»Êܺ¦ÕßÖ§¸¶ÁËÊê½ð £¬Ò²¿ÉÄÜ»áÓÉÓÚ´Ëbugµ¼ÖÂÊý¾ÝÎÞ·¨»Ö¸´ºÍɥʧ¡£¸Ã±äÖÖ¶ÔÆä¼ÓÃÜÀú³Ì¾ÙÐÐÁËÐÞ¸Ä £¬ÈôÊÇÎļþ¾ÞϸÁè¼Ý54.4MB £¬ÔòÖ»¾ÙÐв¿·Ö¼ÓÃÜ £¬ÒªÁìÊǶÔÒ»¶¨ÃüÄ¿µÄ100Íò×Ö½ÚÊý¾Ý¿é¾ÙÐмÓÃÜ¡£È»¶øÆä½âÃÜÆ÷ÔÚÅÌËãÎļþ¾Þϸʱ´Óĩβ½Ø¶ÏÁËÒ»¸ö×Ö½Ú £¬ËäÈ»´ó´ó¶¼ÎļþÖÐ×îºóÒ»¸ö×Ö½ÚÖ»ÊÇÌî³ä £¬µ«Ä³Ð©À©Õ¹ÃûµÄÎļþ£¨ÀýÈçÐéÄâ´ÅÅÌÎļþ¡¢OracleÊý¾Ý¿âÎļþ£©ÔÚ×îºóÒ»¸ö×Ö½ÚÖд洢Ö÷ÒªÐÅÏ¢ £¬Ê¹µÃË𻵵ÄÎļþÔÚ½âÃܺóÎÞ·¨×¼È·¼ÓÔØ¡£¸üÔã¸âµÄÊÇ £¬½âÃÜÆ÷»áÒÔΪÒÑ׼ȷ½âÃܲ¢É¾³ý¼ÓÃܵÄÎļþ £¬Ê¹µÃÊý¾Ý¸üÄѻָ´¡£Emsisoft½¨ÒéÓû§±£´æ¼ÓÃÜÎļþµÄ±¸·Ý £¬ÒÔÃâ±»½âÃÜÆ÷ËùÆÆËð¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ryuk-ransomware-decryptor-is-broken-could-lead-to-data-loss/