Snatch¿Éͨ¹ýÇå¾²Ä£Ê½ÖØÆôÀ´Èƹýɱ¶¾Èí¼þ£»£»£» £»£»£»·ðÂÞÀï´ïÖÝÅíÈø¿ÆÀ­ÊÐÔâÍøÂç¹¥»÷£¬£¬£¬£¬£¬ÊÐÕþЧÀÍÖÐÖ¹

Ðû²¼Ê±¼ä 2019-12-11

1.ÀÕË÷Èí¼þSnatch¿Éͨ¹ýÇå¾²Ä£Ê½ÖØÆôÀ´Èƹýɱ¶¾Èí¼þ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÀÕË÷Èí¼þSnatchÕýÔÚʹÓÃÒ»ÖÖǰËùδ¼ûµÄ¼¼ÇÉÀ´Èƹýɱ¶¾Èí¼þ£¬£¬£¬£¬£¬ÏêϸÀ´Ëµ£¬£¬£¬£¬£¬Ëü¿ÉÒÔ½«Êܺ¦ÕßµÄÅÌËã»úÒÔÇå¾²Ä£Ê½ÖØÐÂÆô¶¯£¬£¬£¬£¬£¬È»ºóÔËÐмÓÃÜÀú³Ì¡£¡£¡£¡£ ¡£´ó´ó¶¼É±¶¾Èí¼þ¶¼ÎÞ·¨ÔÚWindowsÇ徲ģʽÏÂÆô¶¯£¬£¬£¬£¬£¬Òò´ËSnatchÄÑÒÔ±»¼ì²âµ½¡£¡£¡£¡£ ¡£Æ¾Ö¤Sophos LabsµÄ±¨¸æ£¬£¬£¬£¬£¬¸ÃÀÕË÷Èí¼þͨ¹ýWindows×¢²á±íÏîÌí¼ÓÁËÒ»¸öÔÚÇ徲ģʽÏÂÆô¶¯µÄЧÀÍ£¬£¬£¬£¬£¬¸ÃЧÀͽ«ÔËÐÐSnatch¡£¡£¡£¡£ ¡£Ñо¿Ö°Ô±ÖÒÑÔ³ÆÕâÖÖģʽ¿ÉÄܻᱻÆäËüÀÕË÷Èí¼þËùÄ£Äâ¡£¡£¡£¡£ ¡£Snatch×Ô2018ÄêÏÄÈÕÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬£¬ÆäÖ÷Òª¾ÙÐÐÕë¶ÔÐԵĹ¥»÷¡£¡£¡£¡£ ¡£Óë´ó´ó¶¼ÀÕË÷Èí¼þ²î±ð£¬£¬£¬£¬£¬Snatch»¹»áÇÔÈ¡ÊÜѬȾϵͳÉϵÄÎļþ¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/snatch-ransomware-reboots-pcs-in-windows-safe-mode-to-bypass-antivirus-apps/


2.ÃÀ¹úÁè¼Ý75Íò·Ý³öÉú֤ʵÉêÇëÔÚÔÆÐ§ÀÍÆ÷ÖÐ̻¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ó¢¹úÇå¾²³§ÉÌFidus Information Security·¢Ã÷Ò»¸öÉèÖùýʧµÄÔÆÐ§ÀÍÆ÷ÖÐ̻¶ÁËÁè¼Ý75Íò·ÝÃÀ¹ú³öÉú֤ʵÉêÇë¡£¡£¡£¡£ ¡£¸ÃÊý¾Ý¿â´æ´¢ÔÚûÓÐÃÜÂë±£»£»£» £»£»£»¤µÄAWS´æ´¢Í°ÖУ¬£¬£¬£¬£¬Ì»Â¶µÄÊý¾Ý°üÀ¨ÉêÇëÈËÐÕÃû¡¢³öÉúÈÕÆÚ¡¢¼ÒͥסַºÍµç×ÓÓʼþµØµã¡¢µç»°ºÅÂëÒÔ¼°ÒÔǰµÄסַºÍ¼ÒÍ¥³ÉÔ±µÄÐÕÃûµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£ ¡£ÓÉÓÚ¸ÃÊý¾Ý¿âµÄËùÓÐÕßÉÐδ»ØÓ¦Ñо¿ÍŶӵÄ֪ͨ£¬£¬£¬£¬£¬Òò´ËFidusûÓÐ͸¶¸Ã¹«Ë¾µÄÃû³Æ¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/data-leak-exposes-750k-birth-cert/


3.·ðÂÞÀï´ïÖÝÅíÈø¿ÆÀ­ÊÐÔâÍøÂç¹¥»÷£¬£¬£¬£¬£¬ÊÐÕþЧÀÍÖÐÖ¹


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


·ðÂÞÀï´ïÖÝÅíÈø¿ÆÀ­ÊÐÖÜĩʱ´úÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬ÊÐÕþЧÀÍÊܵ½Ó°Ïì¡£¡£¡£¡£ ¡£¸ÃÊÂÎñ±¬·¢ÔÚÖÜÁùÆÆÏþ1:30×óÓÒ£¬£¬£¬£¬£¬¸ÃÊеÄIT²¿·ÖÒ»Ö±ÔÚÆð¾¢»Ö¸´ÍøÂç¡£¡£¡£¡£ ¡£ÏÖÔÚÉв»ÇåÎúÊÂÎñÊÇÓÉÄÄÖÖÀàÐ͵ÄÍøÂç¹¥»÷µ¼Öµģ¬£¬£¬£¬£¬Ò²²»ÇåÎúÓм¸¶ą̀ÅÌËã»úÊܵ½Ó°Ï죬£¬£¬£¬£¬µ«¸ÃÊеĴ󲿷ÖÍøÂçÅþÁ¬¶¼ÒѶϿª£¬£¬£¬£¬£¬°üÀ¨Pensacola EnergyÔÚÏßÖ§¸¶ÏµÍ³ÒÔ¼°¶¼»áÎÀÉúÉèÊ©¡¢»ùÓÚÅÌËã»úµÄͨѶЧÀÍ£¨°üÀ¨µç×ÓÓʼþϵͳ£©µÈ£¬£¬£¬£¬£¬µ«911ºÍÆäËü½ôÆÈЧÀÍ£¨¾¯Ô±ºÍÏû·À²¿·Ö£©Ã»ÓÐÊܵ½Ó°Ïì¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/pensacola-florida-hit-by-cyber-attack-city-services-impacted/


4.Ã÷ÄáËÕ´ïÖÝÒ½ÁÆ»ú¹¹SEMOMSÔâµ½ÀÕË÷Èí¼þ¹¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ã÷ÄáËÕ´ïÖÝÒ»¼ÒרÃÅÖÎÁÆÃ沿¡¢ÑÀ³Ý¡¢¿ÚÇ»µÄÒ½ÁÆ»ú¹¹£¨SEMOMS£©Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬¸ÃÊÂÎñ±¬·¢ÔÚ9ÔÂ23ÈÕ£¬£¬£¬£¬£¬ITÖ°Ô±ÔÚÊÂÎñ±¬·¢ºóÁ¬Ã¦½ÓÄÉÁ˱£»£»£» £»£»£»¤²½·¥¡£¡£¡£¡£ ¡£SEMOMSÔÚÆäÍøÕ¾ÉϽÒÏþµÄÉùÃ÷ÖÐÌåÏÖ£¬£¬£¬£¬£¬Ö»¹ÜÏÖÔÚûÓÐÖ¤¾ÝÅú×¢¹¥»÷Õß»á¼û»òÉó²éÁË»¼ÕßÐÅÏ¢£¬£¬£¬£¬£¬µ«¸Ã»ú¹¹ÒѾ­½ÓÄÉÁ˲½·¥²¢Í¨ÖªÁË¿ÉÄÜÊÜÓ°ÏìµÄ»¼Õß¡£¡£¡£¡£ ¡£SEMOMS³Æ»¼ÕߵIJÆÎñÐÅÏ¢¡¢²¡Àú»òÉç»áÇå¾²ºÅÂë¾ù²»»áÊܵ½ÊÂÎñµÄÓ°Ïì¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/ransomware-attack-on-minnesota/


5.Ô˶¯ÁãÊÛÉÌSweaty Betty¹ÙÍøÑ¬È¾Magecart¾ç±¾


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Å®ÐÔÔ˶¯×°ÁãÊÛÉÌSweaty BettyÒÑͨ¹ýµç×ÓÓʼþ¼û¸æÓû§ÆäÖ§¸¶ÐÅÏ¢¿ÉÄܱ»ÇÔ¡£¡£¡£¡£ ¡£¸Ã¹«Ë¾³Æ¹ÙÍøµÄÖ§¸¶Ò³Ãæ±»Ö²ÈëÁËÇÔÈ¡¸¶¿îÐÅÏ¢µÄ¶ñÒâ´úÂ룬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ¿Í»§ÎªÔÚ11ÔÂ19ÈÕÐÇÆÚ¶þÏÂÖç6.24pm£¨GMT£©µ½11ÔÂ27ÈÕÐÇÆÚÈýÏÂÖç2.52pm£¨GMT£©Ö®¼ä¹ºÎïµÄ¿Í»§¡£¡£¡£¡£ ¡£¿£¿£¿£¿£¿£¿£¿ÉÄܱ»ÇÔµÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢ÃÜÂë¡¢Õ˵¥µØµã¡¢½»¸¶µØµã¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢ÐÅÓÿ¨ºÅ¡¢CVVÂëºÍÓÐÓÃÆÚµÈ¡£¡£¡£¡£ ¡£ÏÖÔÚÉв»ÇåÎúÓм¸¶à¿Í»§Êܵ½¸ÃÊÂÎñµÄÓ°Ï죬£¬£¬£¬£¬µ«¸Ã¹«Ë¾ÌåÏÖÖ»ÓÐÔÚÖ§¸¶Ò³ÃæÉÏÐÂÊäÈëÁËÐÅÏ¢¶ø²»ÊÇʹÓÃÒÑÉúÑÄÐÅÏ¢µÄ¿Í»§²ÅÊܵ½Ó°Ïì¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://hotforsecurity.bitdefender.com/blog/hackers-steal-credit-card-details-from-sweaty-betty-customers-21888.html


6.΢ÈíÐû²¼12ÔÂWindowsÇå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´36¸öÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


΢ÈíÔÚ12ÔÂWindowsÇå¾²¸üÐÂÖÐÐÞ¸´ÁË36¸öÎó²î£¬£¬£¬£¬£¬ÆäÖаüÀ¨7¸öÑÏÖØÎó²î£¬£¬£¬£¬£¬27¸öÖ÷ÒªÎó²î£¬£¬£¬£¬£¬1ÆäÖеÈÎó²îºÍ1¸öµÍΣÎó²î¡£¡£¡£¡£ ¡£ÐèÒª¹Ø×¢µÄÎó²îÊÇWin32k×é¼þÖеÄÌØÈ¨ÌáÉý0day£¬£¬£¬£¬£¬¸ÃÎó²î£¨CVE-2019-1458£©ÊÇÓÉ¿¨°Í˹»ùÑо¿Ö°Ô±·¢Ã÷µÄ£¬£¬£¬£¬£¬²¢ÒÑÔÚÒ°Íâ±»Æð¾¢Ê¹Óᣡ£¡£¡£ ¡£Æ¾Ö¤Î¢ÈíµÄÇ徲ͨ¸æ£¬£¬£¬£¬£¬¸ÃÎó²î±¬·¢ÔÚWin32k×é¼þÎÞ·¨×¼È·´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄÚºËģʽÏÂÔËÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£ÒªÊ¹ÓôËÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß±ØÐèÊ×ÏȵǼϵͳ£¬£¬£¬£¬£¬È»ºó¿Éͨ¹ýÔËÐÐʹÓôËÎó²îµÄ¶ñÒâÈí¼þÀ´½ÓÊÜϵͳ¡£¡£¡£¡£ ¡£¸ü¶àÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsofts-december-2019-patch-tuesday-fixes-win32k-zero-day-36-flaws/