¹ú¼ÒÍøÐŰìÐû²¼¡¶»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢ÖÎÀí»®¶¨¡·

Ðû²¼Ê±¼ä 2022-06-29

1¡¢¹ú¼ÒÍøÐŰìÐû²¼¡¶»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢ÖÎÀí»®¶¨¡·


6ÔÂ27ÈÕ£¬£¬ £¬£¬£¬¹ú¼Ò»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒÐû²¼¡¶»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢ÖÎÀí»®¶¨¡·£¬£¬ £¬£¬£¬×Ô2022Äê8ÔÂ1ÈÕÆðÊ©ÐС£¡£³ǫ̈¡¶»®¶¨¡·£¬£¬ £¬£¬£¬Ö¼ÔÚÔöÇ¿¶Ô»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢µÄÖÎÀí£¬£¬ £¬£¬£¬ºëÑïÉç»áÖ÷Òå½¹µã¼ÛÖµ¹Û£¬£¬ £¬£¬£¬Î¬»¤¹ú¼ÒÇå¾²ºÍÉç»á¹«¹²ÀûÒæ£¬£¬ £¬£¬£¬±£»£»£»¤¹«Ãñ¡¢·¨ÈËºÍÆäËû×éÖ¯µÄÕýµ±È¨Ò棬£¬ £¬£¬£¬Ôö½ø»¥ÁªÍøÐÅϢЧÀÍ¿µ½¡Éú³¤¡£¡£¡¶»®¶¨¡·Ã÷È·ÁËÕ˺ÅÐÅÏ¢×¢²áºÍʹÓù淶£¬£¬ £¬£¬£¬ÒªÇó»¥ÁªÍøÐÅϢЧÀÍÌṩÕßÓ¦µ±Öƶ©ºÍ¹ûÕæ»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢ÖÎÀí¹æÔò¡¢Æ½Ì¨ÌõÔ¼£¬£¬ £¬£¬£¬Ã÷È·Õ˺ÅÐÅÏ¢×¢²á¡¢Ê¹ÓúÍÖÎÀíÏà¹ØÈ¨Á¦ÒåÎñ¡£¡£


http://www.cac.gov.cn/2022-06/26/c_1657868775333429.htm


2¡¢CODESYSÐû²¼¸üУ¬£¬ £¬£¬£¬ÐÞ¸´ICS×Ô¶¯»¯Èí¼þÖеÄ11Îó²î

     

¾ÝýÌå6ÔÂ28ÈÕ±¨µÀ£¬£¬ £¬£¬£¬CODESYSÐÞ¸´ÁËICS×Ô¶¯»¯Èí¼þÖеÄ11¸öÎó²î¡£¡£CoDeSysÊÇÆ¾Ö¤¹ú¼Ê¹¤Òµ±ê×¼IEC 61131-3¶Ô¿ØÖÆÆ÷Ó¦ÓóÌÐò¾ÙÐбà³ÌµÄ¿ª·¢ÇéÐΡ£¡£Ñо¿Ö°Ô±³Æ£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²î´¥·¢¾Ü¾øÐ§ÀÍ(DoS)Ìõ¼þ¡¢Ð¹Â¶ÐÅÏ¢¡¢Ö´ÐÐí§Òâ´úÂë»òÕß¾ÙÐÐÆäËü¶ñÒâ»î¶¯¡£¡£ÆäÖÐÁ½¸öÎó²î£¨CVE-2022-31805ºÍCVE-2022-31806£©×îΪÑÏÖØ£¬£¬ £¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬ £¬£¬£¬ »®·ÖÓëÔÚPLC ÉÏÖ´ÐвÙ×÷֮ǰʹÓÃÃ÷ÎÄÑéÖ¤ÃÜÂ룬£¬ £¬£¬£¬ÒÔ¼°Ä¬ÈÏÇéÐÎÏÂδÄÜÆôÓÃÃÜÂë±£»£»£»¤ÓйØ¡£¡£


https://securityaffairs.co/wordpress/132685/security/codesys-ics-automation-software-flaws.html


3¡¢ÐÂAndroid¶ñÒâÈí¼þReviveð³äBBVAÒøÐеÄ2FAÓ¦ÓÃ

     

CleafyÔÚ6ÔÂ27ÈÕÅû¶ÁËÒ»ÖÖеÄAndroid¶ñÒâÈí¼þRevive¡£¡£¸Ã¶ñÒâÈí¼þÓÚ6ÔÂ15ÈÕÊ״α»·¢Ã÷£¬£¬ £¬£¬£¬Í¨¹ý´¹Âڻ¾ÙÐÐÈö²¥£¬£¬ £¬£¬£¬Ö÷ÒªÕë¶ÔÎ÷°àÑÀ½ðÈÚЧÀ͹«Ë¾BBVA¡£¡£Reviveαװ³ÉBBVAÒøÐеÄ2FA¹¤¾ß£¬£¬ £¬£¬£¬²¢Éù³ÆÇ¶Èëµ½ÕæÕýÒøÐÐÓ¦ÓÃÖеÄ2FA¹¦Ð§²»ÔÙÖª×ãÇå¾²¼¶±ðÒªÇ󣬣¬ £¬£¬£¬ÒªÇóÄ¿µÄ×°Öô˸½¼Ó¹¤¾ßÀ´Éý¼¶ÆäÇå¾²ÐÔ¡£¡£ReviveÈÔ´¦ÓÚÔçÆÚ½×¶Î£¬£¬ £¬£¬£¬¿ª·¢Õß¿ÉÄÜÊÇÊܵ½ÁË¿ªÔ´Ìع¤Èí¼þTeradroidµÄÆô·¢¡£¡£±ðµÄ£¬£¬ £¬£¬£¬Æä×îÖÕÄ¿µÄÊÇͨ¹ýʹÓÃÏàËÆµÄÒ³ÃæÀ´»ñÈ¡ÒøÐеǼƾ֤²¢¾ÙÐÐÕË»§½ÓÊܹ¥»÷(ATO)¡£¡£


https://www.bleepingcomputer.com/news/security/android-malware-revive-impersonates-bbva-bank-s-2fa-app/


4¡¢Vice SocietyÉù³Æ¶ÔInnsbruckÒ½¿Æ´óѧµÄ¹¥»÷ÈÏÕæ

     

¾Ý6ÔÂ27ÈÕ±¨µÀ£¬£¬ £¬£¬£¬Vice SocietyÉù³Æ¹¥»÷ÁËÒò˹²¼Â³¿ËÒ½¿Æ´óѧ£¨Med.University of Innsbruck£©¡£¡£ÕâËù°ÂµØÀû´óѧµÄITϵͳÓÚ6ÔÂ20ÈÕ±¬·¢ÖÐÖ¹£¬£¬ £¬£¬£¬µ¼ÖÂÔÚÏßЧÀÍÆ÷ºÍÅÌËã»úϵͳÎÞ·¨»á¼û¡£¡£6ÔÂ26ÈÕ£¬£¬ £¬£¬£¬Vice Society½«¸Ã´óѧÌí¼Óµ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾£¬£¬ £¬£¬£¬²¢¹ûÕæÁ˱»µÁÎļþµÄÇåµ¥¡£¡£6ÔÂ28ÈÕ£¬£¬ £¬£¬£¬¸ÃѧУ»£»£»ØÓ¦³Æ£¬£¬ £¬£¬£¬È·ÈÏÉÏÖܵÄÖÐֹȷʵÓɸÃÍÅ»ïµÄ¹¥»÷Ôì³ÉµÄ£¬£¬ £¬£¬£¬ËûÃÇÏÖÔÚÕýÔÚ¶Ôй¶Êý¾ÝµÄ¹æÄ£ºÍÐÔ×Ó¾ÙÐÐÆÊÎöºÍÊӲ졣¡£¾ÝϤ£¬£¬ £¬£¬£¬Vice Society×î½üÒ»Ö±ÔÚÕë¶ÔÅ·ÖÞµÄ×éÖ¯£¬£¬ £¬£¬£¬ÌØÊâÊǹú¼Ò/¹«¹²ÊµÌåºÍ½ÌÓý»ú¹¹¡£¡£


https://www.bleepingcomputer.com/news/security/vice-society-claims-ransomware-attack-on-med-university-of-innsbruck/


5¡¢Carnival CruisesÒòÊý¾Ýй¶ÊÂÎñ±»·£¿ £¿£¿£¿£¿î125ÍòÃÀÔª

     

ýÌå6ÔÂ27Èճƣ¬£¬ £¬£¬£¬Carnival CruisesÒò2019ÄêµÄÊý¾Ýй¶ÊÂÎñ±»·£¿ £¿£¿£¿£¿î125ÍòÃÀÔª¡£¡£¸ÃÊÂÎñÓÚ2019Äê5Ô±»·¢Ã÷£¬£¬ £¬£¬£¬ÔÚ10¸öÔºóµÄ2020Äê3Ô²ű»Åû¶£¬£¬ £¬£¬£¬Ð¹Â¶ÁË180000¸öÔ±¹¤ºÍ¿Í»§µÄÐÅÏ¢£¬£¬ £¬£¬£¬Éæ¼°ÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢µØµã¡¢»¤ÕÕºÅÂë¡¢¼ÝʻִÕÕºÅÂë¡¢Ö§¸¶¿¨ÐÅÏ¢ºÍ¿µ½¡ÐÅÏ¢µÈ¡£¡£Ë¾·¨²¿³¤Ö¸³ö£¬£¬ £¬£¬£¬¸Ã¹«Ë¾½«Ð¡ÎÒ˽¼ÒÐÅÏ¢´æ´¢ÔÚµç×ÓÓʼþÖУ¬£¬ £¬£¬£¬²¢Ê¹ÓÃÔÓÂÒÎÞÕµÄÒªÁìÀ´´¦Öóͷ£Ãô¸ÐÊý¾Ý£¬£¬ £¬£¬£¬Ê¹Î¥¹æÍ¨Öª±äµÃÔ½·¢ÄÑÌâ¡£¡£³ýÁ˾­¼Ã´¦·ÖÍ⣬£¬ £¬£¬£¬¸Ã¹«Ë¾»¹ÔÞ³ÉʵÑéÎ¥¹æÏìÓ¦ÍýÏ룬£¬ £¬£¬£¬ÎªÔ±¹¤Öƶ©ÓʼþÅàѵÍýÏ룬£¬ £¬£¬£¬½ÓÊÜ×ÔÁ¦µÄÐÅÏ¢Çå¾²ÆÀ¹ÀµÈ¡£¡£


https://therecord.media/carnival-cruises-to-pay-1-25-million-fine-for-2019-data-breach/


6¡¢AMD³ÆÕýÔÚÊÓ²ìRansomHouseÇÔÈ¡Æä450GBÊý¾ÝµÄÊÂÎñ

     

ýÌå6ÔÂ28ÈÕ±¨µÀ£¬£¬ £¬£¬£¬°ëµ¼Ì幫˾AMDÌåÏÖËûÃÇÕýÔÚÊÓ²ìRansomHouseÇÔÈ¡Æä450 GBÊý¾ÝµÄÊÂÎñ¡£¡£ÔÚÒÑÍùµÄÒ»ÖÜÀ£¬ £¬£¬£¬RansomHouseÒ»Ö±ÔÚTelegramÉϳÆËûÃǽ«³öÊÛÒ»¼ÒÒÔ×ÖĸA¿ªÍ·µÄÖøÃûÈý×Öĸ¹«Ë¾µÄÊý¾Ý¡£¡£6ÔÂ27ÈÕ£¬£¬ £¬£¬£¬¸ÃÍŻォAMDÌí¼Óµ½ËûÃǵÄÊý¾ÝÐ¹Â¶ÍøÕ¾£¬£¬ £¬£¬£¬Éù³ÆÇÔÈ¡ÁË450 GBµÄÊý¾Ý¡£¡£RansomHouseÌåÏÖ£¬£¬ £¬£¬£¬ËûÃǵÄÏàÖúͬ°éÔ¼Ò»ÄêǰÈëÇÖÁËAMDµÄÍøÂç¡£¡£±»µÁÊý¾Ý°üÀ¨Ñо¿ºÍ²ÆÎñÐÅÏ¢£¬£¬ £¬£¬£¬¹¥»÷Õß²¢Î´ÁªÏµAMDË÷ÒªÊê½ð£¬£¬ £¬£¬£¬ÓÉÓÚ½«Êý¾Ý³öÊÛ¸øÆäËüʵÌå»ò¹¥»÷ÍÅ»ï¸üÓмÛÖµ¡£¡£


https://www.bleepingcomputer.com/news/security/amd-investigates-ransomhouse-hack-claims-theft-of-450gb-data/