ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ11ÖÜ

°ä²¼¹¦·ò 2019-03-18

±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2019Äê3ÔÂ11ÈÕÖÁ17ÈÕ¹²ÊÕ¼°²È«·ì϶55¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Internet Explorer¾ç±¾ÒýÇæCVE-2019-0783Ô¶³ÌÄÚ´æ·ÛËé·ì϶£»Microsoft Windows ActiveX CVE-2019-0784Ô¶³Ì´úÂëÖ´Ðзì϶; Microsoft Azure°²È«ÏÞ¶ÈÈÆ¹ý·ì϶£»Google Chrome V8¶ÑÒç¶Âí½Å£»LCDS LAquis SCADAÔ½½çд·ì϶ ¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇGoogle PlayÖÐ210¸öAPPϰȾ¸æ°×Èí¼þSimBad£¬²¨¼°1.5ÒÚÓû§£»¿¨°Í˹»ù°ä²¼2018ÄêÀ¬»øÓʼþ¼°´¹µö¹¥»÷»ã±¨£»Õë¶ÔWordPressµÄй¥»÷º£³±£¬ÖØÒªÀûÓùºÎï³µ²å¼þÖеÄXSS·ì϶£»ÐµÄATM skimmer¹¥»÷£¬¿É½Ù³ÖATMÄÚÖÃÉãÏñÍ·£»ÃÀ¹úJacksonÏØµ±¾ÖÏòÀÕË÷Èí¼þ¹¥»÷ÕßÖ§¸¶40ÍòÃÀÔªÊê½ð ¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖÐ ¡£

³ÁÒª°²È«·ì϶Áбí


1. Microsoft Internet Explorer¾ç±¾ÒýÇæCVE-2019-0783Ô¶³ÌÄÚ´æ·ÛËé·ì϶
Microsoft Internet Explorer´¦ÖÃÄÚ´æ¶ÔÏó´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄwebÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë ¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0783

2. Microsoft Windows ActiveX CVE-2019-0784Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft ActiveX Data objects (ADO)´¦ÖÃÄÚ´æ¶ÔÏó´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë ¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0784

3. Microsoft Azure°²È«ÏÞ¶ÈÈÆ¹ý·ì϶
Microsoft Azure SSH KeypairsʹÓÃcloud-initµÄLinuxÓ³ÏñÅäÖÃÈí¼þµÄ¸ü¸Ä£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Èƹý°²È«ÏÞ¶È ¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0816

4. Google Chrome V8¶ÑÒç¶Âí½Å
Google Chrome V8´æÔÚ¶Ñ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄwebÒ³£¬ÓÕʹÓû§½âÎö£¬¿ÉÌáÉýȨÏÞ ¡£
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop_12.html

5. LCDS LAquis SCADAÔ½½çд·ì϶
LCDS LAquis SCADA´¦ÖÃelsÎļþ´æÔÚÔ½½çд·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâ´úÂë ¡£
https://ics-cert.us-cert.gov/advisories/ICSA-19-073-01

³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Google PlayÖÐ210¸öAPPϰȾ¸æ°×Èí¼þSimBad£¬²¨¼°1.5ÒÚÓû§


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ƾ¾ÝCheck PointµÄÒ»·Ý»ã±¨£¬×êÑÐÈËÔ±ÔÚGoogle PlayÖз¢ÏÖ210¸öAPPϰȾÁ˸æ°×Èí¼þSimBad£¬ÕâЩAPPµÄ×Ü×°ÖÃÁ¿´ï1.5ÒÚ´Î ¡£´óÎÞÊýAPP¶¼ÊÇÈü³µ»òÉä»÷ÓÎÏ·£¬ÆäÖÐÃûΪSnow Heavy Excavator SimulatorµÄAPPÏÂÔØÁ¿³¬¹ý1000Íò ¡£SimBad¼Ù×°³É¸æ°×¹¤¾ß°üRXDrioder£¬µ±Óû§×°ÖÃÁËÊÜϰȾµÄAPPºó£¬¸ÃAPP»áÔÚÉ豸Æô¶¯»òÓû§½âËøÊ±×Ô¶¯Æô¶¯²¢ÏÔʾ¸æ°×£¬´Ë±í£¬¶ñÒâ´úÂ뻹»áÖ´ÐдÓC&C·þÎñÆ÷½Ó¹Üµ½µÄºÅÁÔ̺¬É¾³ýͼ±ê¡¢ºó¶Ü¸æ°×¡¢´ò¿ªÍøÒ³µÈ ¡£GoogleÒѾ­Ï¼ÜÁËÕâЩAPP ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/simbad-adware-found-in-210-android-apps-with-over-150m-installs/

2¡¢¿¨°Í˹»ù°ä²¼2018ÄêÀ¬»øÓʼþ¼°´¹µö¹¥»÷»ã±¨


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¿¨°Í˹»ù°ä²¼2018ÄêµÄÀ¬»øÓʼþºÍ´¹µö¹¥»÷ͳ¼Æ»ã±¨£¬»ã±¨µÄÖØÒª·¢ÏÖÔ̺¬£ºÈ«Çòµç×ÓÓʼþÁ÷Á¿ÖеÄÀ¬»øÓʼþÊý¾ÝµÄÕ¼±ÈΪ52.48%£¬±È2017Äê½µµÍ4.15¸ö°Ù·Öµã£»2018Äê×î´óµÄÀ¬»øÓʼþÆðÔ´¹úÊÇÖйú£¨11.69£¥£©£»74.15£¥µÄÀ¬»øÓʼþÓ×ÓÚ2 KB£»À¬»øÓʼþÖÐ×î³£±»¼ì²âµ½µÄ·ì϶ÀûÓÃÊÇWin32.CVE-2017-11882 ¡£

Ô­ÎÄÁ´½Ó£º
https://securelist.com/spam-and-phishing-in-2018/89701/

3¡¢Õë¶ÔWordPressµÄй¥»÷º£³±£¬ÖØÒªÀûÓùºÎï³µ²å¼þÖеÄXSS·ì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Defiant×êÑÐÈËÔ±Mikey Veenstra·¢ÏÖÒ»¸öÕë¶ÔWordPress¹ºÎïÍøÕ¾µÄ¹¥»÷º£³±£¬¹¥»÷ÕßÀûÓùºÎï³µ²å¼þ¡°Abondoned Cart Lite for WooCommerce¡±ÖеÄXSS·ì϶£¬ÏòÍøÕ¾Ö²ÈëºóÃŲ¢»ñµÃÍøÕ¾µÄ½ÚÔìȨ ¡£¾Ý±¨Â·¸Ã²å¼þÒÑÔÚ³¬¹ý2Íò¸öWordPressÍøÕ¾ÉÏ×°Öà ¡£¹¥»÷ÕßÖ²ÈëµÄºóÃÅÔ̺¬Ò»¸öÖÎÀíÔ¹ØË»§woouserÒÔ¼°Ôڷǻ²å¼þÖÐÖ²ÈëµÄPHPºóÃÅ ¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/hackers-abuse-xss-vulnerability-in-cart-plugin-to-target-wordpress-based-shopping-sites-ff4b4019

4¡¢ÐµÄATM skimmer¹¥»÷£¬¿É½Ù³ÖATMÄÚÖÃÉãÏñÍ·


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ƾ¾ÝKrebs on SecurityµÄÒ»·Ýл㱨£¬×êÑÐÈËÔ±Ôڵ¿ËÈøË¹ÖݺÕË¹ÌØÊеÄATMÉÏ·¢ÏÖÁËеÄskimmer¹¥»÷£¬¹¥»÷Õßͨ¹ý½Ù³ÖATMÖÐÄÚÖõÄÉãÏñÍ·ÒÔÇÔÈ¡Óû§µÄPINÂë ¡£¸ÃskimmerÔ̺¬Ò»¸öÉãÏñÍ·²¿¼þ£¬ÓÃÓÚ¸²¸ÇÔÚATMÄÚÖõݲȫÉãÏñÍ·ÉÏÃæ£¬Óû§ºÜÄÑ´Ó±í²¿¿´µ½¸Ãskimmer ¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/new-atm-skimming-attack-enables-scammers-to-hijack-the-atms-in-built-camera-and-steal-a-users-pin-3d2c4884

5¡¢ÃÀ¹úJacksonÏØµ±¾ÖÏòÀÕË÷Èí¼þ¹¥»÷ÕßÖ§¸¶40ÍòÃÀÔªÊê½ð


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÃÀ¹úÇÇÖÎÑÇÖݽܿËÑ·ÏØÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µ±¾ÖÏò·¸×ï·Ö×ÓÖ§¸¶ÁË40ÍòÃÀÔªµÄÊê½ðÒÔ»ñµÃ½âÃÜÃÜÔ¿ ¡£Õâ´Î¹¥»÷ÊÂÎñÓ°ÏìÁ˸ÃÏØËùÓв¿ÃŵÄÍÆËã»úϵͳ£¬Ô̺¬µç×ÓÓʼþ·þÎñºÍ´¹Î£·þÎñ£¬´¦Ê´¦²»µÃ²»Ê¹ÓÃÖ½ÕÅÒÔʵÏÖ¹¤×÷ ¡£ÓÉÓÚ¸ÃÏØÃ»Óб¸·Ýϵͳ£¬Ïص±¾Ö²»µÃ²»Âú×ã¹¥»÷ÕßµÄÒªÇóÒÔ»»È¡ÕýÈ·µÄ½âÃÜÃÜÔ¿ ¡£Æ¾¾ÝFBIµÄµ÷²é£¬·¸×ï·Ö×ÓʹÓõÄÀÕË÷Èí¼þ¿ÉÄÜÊÇRyuk£¬¹¥»÷ÕßÒÉΪ¶«Å·µÄÒ»¸ö×éÖ¯ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ransomware-attack-on-jackson-county-gets-cybercriminals-400-000/

ÉêÃ÷£º±¾×ÊѶÓɱ¦ÔËÀ³¹Ù·½ÍøÕ¾Î¬ËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù