ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ11ÖÜ

Ðû²¼Ê±¼ä 2019-03-18

±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2019Äê3ÔÂ11ÈÕÖÁ17ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´55¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Internet Explorer½Å±¾ÒýÇæCVE-2019-0783Ô¶³ÌÄÚ´æÆÆ»µÂ©¶´£»Microsoft Windows ActiveX CVE-2019-0784Ô¶³Ì´úÂëÖ´ÐЩ¶´; Microsoft AzureÄþ¾²ÏÞÖÆÈƹý©¶´£»Google Chrome V8¶ÑÒç³ö©¶´£»LCDS LAquis SCADAÔ½½ç䩶´¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇGoogle PlayÖÐ210¸öAPPѬȾ¹ã¸æÈí¼þSimBad £¬²¨¼°1.5ÒÚÓû§£»¿¨°Í˹»ùÐû²¼2018ÄêÀ¬»øÓʼþ¼°µöÓã¹¥»÷³ÂËߣ»Õë¶ÔWordPressµÄй¥»÷À˳± £¬Ö÷ÒªÀûÓùºÎï³µ²å¼þÖеÄXSS©¶´£»ÐµÄATM skimmer¹¥»÷ £¬¿É½Ù³ÖATMÄÚÖÃÉãÏñÍ·£»ÃÀ¹úJacksonÏØÕþ¸®ÏòÀÕË÷Èí¼þ¹¥»÷ÕßÖ§¸¶40ÍòÃÀÔªÊê½ð¡£

ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖС£

ÖØÒªÄþ¾²Â©¶´Áбí


1. Microsoft Internet Explorer½Å±¾ÒýÇæCVE-2019-0783Ô¶³ÌÄÚ´æÆÆ»µÂ©¶´
Microsoft Internet Explorer´¦ÖÃÄڴ湤¾ß´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄwebÇëÇó £¬ÓÕʹÓû§½âÎö £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0783

2. Microsoft Windows ActiveX CVE-2019-0784Ô¶³Ì´úÂëÖ´ÐЩ¶´
Microsoft ActiveX Data objects (ADO)´¦ÖÃÄڴ湤¾ß´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0784

3. Microsoft AzureÄþ¾²ÏÞÖÆÈƹý©¶´
Microsoft Azure SSH KeypairsʹÓÃcloud-initµÄLinuxÓ³ÏñÅäÖÃÈí¼þµÄ¸ü¸Ä £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬ÈƹýÄþ¾²ÏÞÖÆ¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0816

4. Google Chrome V8¶ÑÒç³ö©¶´
Google Chrome V8´æÔڶѻº³åÇøÒç³ö©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄwebÒ³ £¬ÓÕʹÓû§½âÎö £¬¿ÉÌáÉýȨÏÞ¡£
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop_12.html

5. LCDS LAquis SCADAÔ½½ç䩶´
LCDS LAquis SCADA´¦ÖÃelsÎļþ´æÔÚÔ½½ç䩶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÖ´ÐÐÈÎÒâ´úÂë¡£
https://ics-cert.us-cert.gov/advisories/ICSA-19-073-01

ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢Google PlayÖÐ210¸öAPPѬȾ¹ã¸æÈí¼þSimBad £¬²¨¼°1.5ÒÚÓû§


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝCheck PointµÄÒ»·Ý³ÂËß £¬Ñо¿ÈËÔ±ÔÚGoogle PlayÖз¢ÏÖ210¸öAPPѬȾÁ˹ã¸æÈí¼þSimBad £¬ÕâЩAPPµÄ×Ü°²×°Á¿´ï1.5ÒڴΡ£´ó¶àÊýAPP¶¼ÊÇÈü³µ»òÉä»÷ÓÎÏ· £¬ÆäÖÐÃûΪSnow Heavy Excavator SimulatorµÄAPPÏÂÔØÁ¿Áè¼Ý1000Íò¡£SimBadαװ³É¹ã¸æ¹¤¾ß°üRXDrioder £¬µ±Óû§°²×°ÁËÊÜѬȾµÄAPPºó £¬¸ÃAPP»áÔÚÉ豸Æô¶¯»òÓû§½âËøʱ×Ô¶¯Æô¶¯²¢ÏÔʾ¹ã¸æ £¬´ËÍâ £¬¶ñÒâ´úÂ뻹»áÖ´ÐдÓC&C·þÎñÆ÷½ÓÊÕµ½µÄÃüÁî £¬°üÂÞɾ³ýͼ±ê¡¢ºǫ́¹ã¸æ¡¢´ò¿ªÍøÒ³µÈ¡£GoogleÒѾ­Ï¼ÜÁËÕâЩAPP¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/simbad-adware-found-in-210-android-apps-with-over-150m-installs/

2¡¢¿¨°Í˹»ùÐû²¼2018ÄêÀ¬»øÓʼþ¼°µöÓã¹¥»÷³ÂËß


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ùÐû²¼2018ÄêµÄÀ¬»øÓʼþºÍµöÓã¹¥»÷ͳ¼Æ³ÂËß £¬³ÂËßµÄÖ÷Òª·¢ÏÖ°üÂÞ£ºÈ«Çòµç×ÓÓʼþÁ÷Á¿ÖеÄÀ¬»øÓʼþÊý¾ÝµÄÕ¼±ÈΪ52.48% £¬±È2017Äê½µµÍ4.15¸ö°Ù·Öµã£»2018Äê×î´óµÄÀ¬»øÓʼþÀ´Ô´¹úÊÇÖйú£¨11.69£¥£©£»74.15£¥µÄÀ¬»øÓʼþСÓÚ2 KB£»À¬»øÓʼþÖÐ×î³£±»¼ì²âµ½µÄ©¶´ÀûÓÃÊÇWin32.CVE-2017-11882¡£

Ô­ÎÄÁ´½Ó£º
https://securelist.com/spam-and-phishing-in-2018/89701/

3¡¢Õë¶ÔWordPressµÄй¥»÷À˳± £¬Ö÷ÒªÀûÓùºÎï³µ²å¼þÖеÄXSS©¶´


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


DefiantÑо¿ÈËÔ±Mikey Veenstra·¢ÏÖÒ»¸öÕë¶ÔWordPress¹ºÎïÍøÕ¾µÄ¹¥»÷À˳± £¬¹¥»÷ÕßÀûÓùºÎï³µ²å¼þ¡°Abondoned Cart Lite for WooCommerce¡±ÖеÄXSS©¶´ £¬ÏòÍøÕ¾Ö²ÈëºóÃŲ¢»ñµÃÍøÕ¾µÄ¿ØÖÆȨ¡£¾Ý±¨µÀ¸Ã²å¼þÒÑÔÚÁè¼Ý2Íò¸öWordPressÍøÕ¾ÉÏ°²×°¡£¹¥»÷ÕßÖ²ÈëµÄºóÃÅ°üÂÞÒ»¸ö¹ÜÀíÔ±ÕË»§woouserÒÔ¼°Ôڷǻ²å¼þÖÐÖ²ÈëµÄPHPºóÃÅ¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/hackers-abuse-xss-vulnerability-in-cart-plugin-to-target-wordpress-based-shopping-sites-ff4b4019

4¡¢ÐµÄATM skimmer¹¥»÷ £¬¿É½Ù³ÖATMÄÚÖÃÉãÏñÍ·


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝKrebs on SecurityµÄÒ»·ÝгÂËß £¬Ñо¿ÈËÔ±Ôڵ¿ËÈø˹ÖݺÕ˹ÌØÊеÄATMÉÏ·¢ÏÖÁËеÄskimmer¹¥»÷ £¬¹¥»÷Õßͨ¹ý½Ù³ÖATMÖÐÄÚÖõÄÉãÏñÍ·ÒÔÇÔÈ¡Óû§µÄPINÂë¡£¸Ãskimmer°üÂÞÒ»¸öÉãÏñÍ·²¿¼þ £¬ÓÃÓÚÁýÕÖÔÚATMÄÚÖõÄÄþ¾²ÉãÏñÍ·ÉÏÃæ £¬Óû§ºÜÄÑ´ÓÍⲿ¿´µ½¸Ãskimmer¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/new-atm-skimming-attack-enables-scammers-to-hijack-the-atms-in-built-camera-and-steal-a-users-pin-3d2c4884

5¡¢ÃÀ¹úJacksonÏØÕþ¸®ÏòÀÕË÷Èí¼þ¹¥»÷ÕßÖ§¸¶40ÍòÃÀÔªÊê½ð


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úÇÇÖÎÑÇÖݽܿËÑ·ÏØÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬Õþ¸®Ïò·¸×ï·Ö×ÓÖ§¸¶ÁË40ÍòÃÀÔªµÄÊê½ðÒÔ»ñµÃ½âÃÜÃÜÔ¿¡£´Ë´Î¹¥»÷ʼþÓ°ÏìÁ˸ÃÏØËùÓв¿ÃŵļÆËã»úϵͳ £¬°üÂÞµç×ÓÓʼþ·þÎñºÍ½ô¼±·þÎñ £¬·þÎñ´¦²»µÃ²»Ê¹ÓÃÖ½ÕÅÒÔÍê³ÉÊÂÇé¡£ÓÉÓÚ¸ÃÏØûÓб¸·Ýϵͳ £¬ÏØÕþ¸®²»µÃ²»Âú×ã¹¥»÷ÕßµÄÒªÇóÒÔ»»È¡ÕýÈ·µÄ½âÃÜÃÜÔ¿¡£Æ¾¾ÝFBIµÄÊÓ²ì £¬·¸×ï·Ö×ÓʹÓõÄÀÕË÷Èí¼þ¿ÉÄÜÊÇRyuk £¬¹¥»÷ÕßÒÉΪ¶«Å·µÄÒ»¸ö×éÖ¯¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ransomware-attack-on-jackson-county-gets-cybercriminals-400-000/

ÉùÃ÷£º±¾×ÊѶÓɶ«É­Æ½Ì¨Î¬ËûÃüÄþ¾²Ð¡×é·­ÒëºÍÕûÀí