µ¤Âó˰ÎñЧÀÍй¶120Íò¹«ÃñµÄCPRºÅÂ룻£»£»£»DellÐÞ¸´SupportAssistÖеIJ»¿ÉÐÅËÑË÷·¾¶Îó²î

Ðû²¼Ê±¼ä 2020-02-11

1.µ¤Âó˰ÎñЧÀÍй¶120Íò¹«ÃñµÄCPRºÅÂë


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


µ¤ÂóÕþ¸®·¢Ã÷TastSelv Borger˰ÎñЧÀÍй¶ÁË120Íò¹«ÃñµÄCPR£¨µ¤ÂóÉí·ÝÖ¤¼þ£©ºÅÂë¡£¡£¡£¸ÃЧÀÍÓÉÃÀ¹úDXC Technology¹«Ë¾ÖÎÀí£¬£¬£¬£¬£¬ÔÊÐíµ¤Âó¹«ÃñÉó²éºÍ¸ü¸ÄÆäÄÉ˰É걨±í¡¢Äê¶È±¨±í²¢½ÉÄÉÊ£Óà˰¿î¡£¡£¡£ÔÚ·¢Ã÷֮ǰ£¬£¬£¬£¬£¬°üÀ¨CPRºÅÔÚÄÚµÄÊý¾ÝÒÑ̻¶ÁË¿ìÒªÎåÄêµÄʱ¼ä¡£¡£¡£DR NewsÍøÕ¾±¨¸æ³Æ£¬£¬£¬£¬£¬Ò»µ©µÇ¼Tastselv BorgerµÄÓû§¸üÕýÁËËûÃǵÄÁªÏµÐÅÏ¢£¬£¬£¬£¬£¬Ó¦ÓóÌÐòÖеĹýʧ¾Í»áµ¼ÖÂCPRºÅ×÷ÎªÍøÖ·µÄÒ»²¿·Ö·¢Ë͵½GoogleºÍAdobe¡£¡£¡£DXCÒÑÈ·ÈϸÃÎó²î²¢Òѽâ¾ö¸ÃÎÊÌâ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/97571/data-breach/1-2m-cpr-numbers-leak.html


2.ÒÔÉ«ÁÐÇå¾²²½¶Ó½ü3¸öÔÂÄÚÊܵ½10000´ÎÍøÂç¹¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¾ÝÏ£²®À´ÓïÐÂÎÅÍøÕ¾YnetÖÜÈÕ±¨µÀ£¬£¬£¬£¬£¬ÔÚÒÑÍùµÄÈý¸öÔÂÖУ¬£¬£¬£¬£¬ÒÔÉ«ÁÐÇå¾²²½¶ÓµÄÊ®¸öÖ÷ÒªÍøÕ¾³ÉΪÁË10000¶àÆðÍøÂç¹¥»÷µÄÄ¿µÄ¡£¡£¡£¸ÃÊý¾ÝÊÇ»ùÓÚÒÔÉ«ÁÐ-ÃÀ¹úÍøÂçÇå¾²¹«Ë¾ImpervaµÄ±¨¸æ£¬£¬£¬£¬£¬±¨¸æÖл¹ÏÔʾÁíÍâÔ¼40¸öÒÔÉ«ÁÐÖ´·¨ºÍÕþ¸®ÍøÕ¾Ôâµ½ÁËÊýǧ´ÎÒÔÉϵÄÍøÂç¹¥»÷¡£¡£¡£ÒÔÉ«Áйú¼ÒÍøÂçÖÎÀí¾Ö³ÆÕþ¸®ÍøÕ¾Êܵ½¸ß¶ÈÏȽøµÄ·ÀÓùϵͳµÄ±£»£»£»£»¤£¬£¬£¬£¬£¬ÕâЩ¹¥»÷¶ÔÆäûÓÐÓ°Ïì¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.xinhuanet.com/english/2020-02/10/c_138768894.htm


3.¹¥»÷ÕßʹÓÃÃâ·ÑÈí¼þLock My PCËø¶¨Óû§ÅÌËã»ú


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÊÖÒÕÖ§³ÖÕ©Æ­ÕßʹÓÃÃûΪLock My PCµÄÃâ·Ñ¹¤¾ßÀ´Ëø¶¨Óû§µÄÅÌËã»ú£¬£¬£¬£¬£¬²¢ÒªÇóÖ§¸¶½âËøÓöȡ£¡£¡£¶àÄêÀ´Î±×°³É΢Èí¡¢¹È¸èµÈ¹«Ë¾µÄÊÖÒÕÖ§³ÖÕ©Æ­ÕßÒ»Ö±ÔÚʹÓÃWindows Syskey³ÌÐò½«Óû§µÄÏµÍ³Ëø¶¨£¬£¬£¬£¬£¬µ«ÓÉÓÚ΢ÈíÔÚWindows 10 1709ÖÐɾ³ýÁ˶ÔSyskeyµÄËùÓÐÖ§³Ö£¬£¬£¬£¬£¬Òò´ËÕ©Æ­ÕßÒÑÇл»µ½Lock My PC¡£¡£¡£ÓëSyskey¼ÓÃÜWindows SAMÊý¾Ý¿â²¢Ê¹ÓÃÊäÈëµÄÃÜÂë¶ÔÆä¾ÙÐнâÃܲî±ð£¬£¬£¬£¬£¬Lock My PC²»¼ÓÃÜÈκÎÄÚÈÝ£¬£¬£¬£¬£¬½öʹÓÃÃÜÂë×èÖ¹¶ÔÅÌËã»úµÄ»á¼û¡£¡£¡£¸ÃÈí¼þ»¹ÒÔÇ徲ģʽÔËÐУ¬£¬£¬£¬£¬Ê¹µÃûÓÐÃÜÂë»òboot»Ö¸´¹¤¾ßʱºÜÄѽûÓÃËü¡£¡£¡£Lock My PCµÄ¿ª·¢Ö°Ô±FSPro Labs·¢Ã÷ÆäÈí¼þ±»ÀÄÓúóÐû²¼²»ÔÙÌṩÃâ·Ñ°æ±¾£¬£¬£¬£¬£¬²¢ÇÒΪÊܺ¦ÕßÌṩÁËÃâ·ÑµÄ»Ö¸´ÃÜÂë¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/lock-my-pc-used-by-tech-support-scammers-dev-offers-free-recovery/


4.Â׶عú¼ÒФÏñ»­ÀÈÔÚ2019ÄêQ4Ôâµ½½ü35Íò·âÀ¬»øÓʼþ¹¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤Ӣ¹úÐÅÏ¢×ÔÓÉ·¨°¸Åû¶µÄÊý¾Ý£¬£¬£¬£¬£¬Parliament StreetÖǿⷢÃ÷Â׶عú¼ÒФÏñ»­ÀÈÔÚ2019ÄêµÚËÄÐò¶ÈÔâµ½½ü35Íò´ÎÀ¬»øÓʼþ¹¥»÷¡£¡£¡£¹ú¼ÒФÏñ»­ÀÈÊÇÂ×¶Ø×ʢÃûµÄÃÀÊõ¹ÝÖ®Ò»£¬£¬£¬£¬£¬Ã¿Äê½Ó´ý110ÍòÖÁ120ÍòÓοÍ£¬£¬£¬£¬£¬ÆäЧÀÍÆ÷´æ´¢ÁËÐí¶àÓο͵ĸ¶¿îÃ÷ϸºÍµç×ÓÓʼþµØµãµÈ˽ÈËÐÅÏ¢¡£¡£¡£ÔÚÕâ½ü35Íò·â±»×èÖ¹µÄÀ¬»øÓʼþÖУ¬£¬£¬£¬£¬ÓÐ56%±»Ê¶±ðΪÕʺÅÍøÂç¹¥»÷£¬£¬£¬£¬£¬ÁíÍâ61710·âÊÇÓÉÓÚ·¢¼þÈËÔÚ¡°ÍþвÇ鱨ºÚÃûµ¥¡±É϶ø±»×èÖ¹£¬£¬£¬£¬£¬ÉÐÓÐ85793·â±»ÒÔΪ°üÀ¨À¬»øÓʼþÄÚÈÝÒÔ¼°418·â°üÀ¨²¡¶¾¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/national-portrait-gallery-email


5.¼ÓÃÜÉúÒâËùAltsbitÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬½«ÓÚ5ÔÂ8ÈչرÕ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¾Ý±¨µÀ£¬£¬£¬£¬£¬×ܲ¿Î»ÓÚÒâ´óÀûµÄ¼ÓÃÜÇ®±ÒÉúÒâÆ½Ì¨AltsbitÌåÏÖÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬ÏÕЩËùÓÐBTC¡¢ETH¡¢ARRRºÍVRSC×ʽ𶼱»µÁ£¬£¬£¬£¬£¬Ö»ÓÐһС²¿·Ö·ÅÔÚÀäÇ®°üÖеÄ×ʽðÊÇÇå¾²µÄ¡£¡£¡£×èÖ¹·¢¸åʱ£¬£¬£¬£¬£¬ËðʧµÄBTCºÍETHµÄ¼ÛֵԼΪ6.3ÍòÃÀÔª¡£¡£¡£¸ÃÉúÒâËùÌåÏÖûÓÐ×ã¹»µÄ×ʽðÀ´Åâ³¥Óû§£¬£¬£¬£¬£¬Òò´ËÒªÇóÓû§ÉêÇ벿·ÖÍ˿¡£¡£ÍË¿îʱ¼äΪ2ÔÂ10ÈÕµ½5ÔÂ8ÈÕ£¬£¬£¬£¬£¬ÔÚÕâÌìÆÚÖ®ºó¸ÃÉúÒâËù½«¹Ø±Õ¡£¡£¡£ºÚ¿Í×éÖ¯LulzSecÔÚTwitterÖÐÉù³Æ¶Ô´ËÊÂÎñÈÏÕæ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.coindesk.com/new-crypto-exchange-altsbit-says-it-will-close-following-hack


6.DellÐÞ¸´SupportAssistÖеIJ»¿ÉÐÅËÑË÷·¾¶Îó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


DellÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´SupportAssist ClientÈí¼þÖеÄÒ»¸ö²»¿ÉÐÅËÑË÷·¾¶Îó²î£¬£¬£¬£¬£¬¸ÃÎó²î£¨CVE-2020-5316£©ÔÊÐíDZÔÚµÄÍâµØ¹¥»÷ÕßÔÚÒ×Êܹ¥»÷µÄÅÌËã»úÉÏÒÔÖÎÀíԱȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£SupportAssistÊÇԤװÖÃÔÚ´ó´ó¶¼DellÉè±¹ØÁ¬ÄÖ§³ÖÈí¼þ£¬£¬£¬£¬£¬Òò´Ë¸ÃÎó²îµÄDZÔÚÓ°Ïì¹æÄ£½Ï¹ã¡£¡£¡£Æ¾Ö¤DellµÄÎó²îת´ï£¬£¬£¬£¬£¬¾­ÓÉÍâµØÉí·ÝÑéÖ¤µÄµÍÌØÈ¨Óû§¿ÉÄÜʹÓôËÎó²îµ¼ÖÂSupportAssist¶þ½øÖÆÎļþ¼ÓÔØí§ÒâDLL£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÌØÈ¨´úÂëµÄÖ´ÐС£¡£¡£¸ÃÎó²îµÄCVSSv3»ù±¾µÃ·ÖΪ7.8·Ö£¬£¬£¬£¬£¬Ó°ÏìÁËÉÌÓÃPCµÄSupportAssist 2.1.3»ò¸üÔç°æ±¾£¬£¬£¬£¬£¬ÒÔ¼°¼ÒÓÃPCµÄSupportAssist 3.4»ò¸üÔç°æ±¾¡£¡£¡£DellÒѾ­ÔÚа汾ÖÐÐÞ¸´Á˸ÃÎó²î£¬£¬£¬£¬£¬ÈôÊÇÆôÓÃÁË×Ô¶¯Éý¼¶£¬£¬£¬£¬£¬ÔòËùÓа汾µÄSupportAssist¶¼»á×Ô¶¯×°ÖÃ×îп¯Ðеİ汾¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/dell-supportassist-bug-exposes-business-home-pcs-to-attacks/