¹ú¼ÒÍøÐŰìÐû²¼¡¶»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢ÖÎÀí»®¶¨¡·

Ðû²¼Ê±¼ä 2022-06-29

1¡¢¹ú¼ÒÍøÐŰìÐû²¼¡¶»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢ÖÎÀí»®¶¨¡·


6ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬¹ú¼Ò»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒÐû²¼¡¶»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢ÖÎÀí»®¶¨¡·£¬£¬£¬£¬£¬£¬£¬£¬×Ô2022Äê8ÔÂ1ÈÕÆðÊ©ÐС£¡£¡£³ǫ̈¡¶»®¶¨¡·£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÔöÇ¿¶Ô»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢µÄÖÎÀí£¬£¬£¬£¬£¬£¬£¬£¬ºëÑïÉç»áÖ÷Òå½¹µã¼ÛÖµ¹Û£¬£¬£¬£¬£¬£¬£¬£¬Î¬»¤¹ú¼ÒÇå¾²ºÍÉç»á¹«¹²ÀûÒæ£¬£¬£¬£¬£¬£¬£¬£¬±£»£»£» £»¤¹«Ãñ¡¢·¨ÈËºÍÆäËû×éÖ¯µÄÕýµ±È¨Ò棬£¬£¬£¬£¬£¬£¬£¬Ôö½ø»¥ÁªÍøÐÅϢЧÀÍ¿µ½¡Éú³¤¡£¡£¡£¡¶»®¶¨¡·Ã÷È·ÁËÕ˺ÅÐÅÏ¢×¢²áºÍʹÓù淶£¬£¬£¬£¬£¬£¬£¬£¬ÒªÇó»¥ÁªÍøÐÅϢЧÀÍÌṩÕßÓ¦µ±Öƶ©ºÍ¹ûÕæ»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢ÖÎÀí¹æÔò¡¢Æ½Ì¨ÌõÔ¼£¬£¬£¬£¬£¬£¬£¬£¬Ã÷È·Õ˺ÅÐÅÏ¢×¢²á¡¢Ê¹ÓúÍÖÎÀíÏà¹ØÈ¨Á¦ÒåÎñ¡£¡£¡£


http://www.cac.gov.cn/2022-06/26/c_1657868775333429.htm


2¡¢CODESYSÐû²¼¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ICS×Ô¶¯»¯Èí¼þÖеÄ11Îó²î

     

¾ÝýÌå6ÔÂ28ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬CODESYSÐÞ¸´ÁËICS×Ô¶¯»¯Èí¼þÖеÄ11¸öÎó²î¡£¡£¡£CoDeSysÊÇÆ¾Ö¤¹ú¼Ê¹¤Òµ±ê×¼IEC 61131-3¶Ô¿ØÖÆÆ÷Ó¦ÓóÌÐò¾ÙÐбà³ÌµÄ¿ª·¢ÇéÐΡ£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²î´¥·¢¾Ü¾øÐ§ÀÍ(DoS)Ìõ¼þ¡¢Ð¹Â¶ÐÅÏ¢¡¢Ö´ÐÐí§Òâ´úÂë»òÕß¾ÙÐÐÆäËü¶ñÒâ»î¶¯¡£¡£¡£ÆäÖÐÁ½¸öÎó²î£¨CVE-2022-31805ºÍCVE-2022-31806£©×îΪÑÏÖØ£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬£¬£¬ »®·ÖÓëÔÚPLC ÉÏÖ´ÐвÙ×÷֮ǰʹÓÃÃ÷ÎÄÑéÖ¤ÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Ä¬ÈÏÇéÐÎÏÂδÄÜÆôÓÃÃÜÂë±£»£»£» £»¤Óйء£¡£¡£


https://securityaffairs.co/wordpress/132685/security/codesys-ics-automation-software-flaws.html


3¡¢ÐÂAndroid¶ñÒâÈí¼þReviveð³äBBVAÒøÐеÄ2FAÓ¦ÓÃ

     

CleafyÔÚ6ÔÂ27ÈÕÅû¶ÁËÒ»ÖÖеÄAndroid¶ñÒâÈí¼þRevive¡£¡£¡£¸Ã¶ñÒâÈí¼þÓÚ6ÔÂ15ÈÕÊ״α»·¢Ã÷£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ý´¹Âڻ¾ÙÐÐÈö²¥£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÎ÷°àÑÀ½ðÈÚЧÀ͹«Ë¾BBVA¡£¡£¡£Reviveαװ³ÉBBVAÒøÐеÄ2FA¹¤¾ß£¬£¬£¬£¬£¬£¬£¬£¬²¢Éù³ÆÇ¶Èëµ½ÕæÕýÒøÐÐÓ¦ÓÃÖеÄ2FA¹¦Ð§²»ÔÙÖª×ãÇå¾²¼¶±ðÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÒªÇóÄ¿µÄ×°Öô˸½¼Ó¹¤¾ßÀ´Éý¼¶ÆäÇå¾²ÐÔ¡£¡£¡£ReviveÈÔ´¦ÓÚÔçÆÚ½×¶Î£¬£¬£¬£¬£¬£¬£¬£¬¿ª·¢Õß¿ÉÄÜÊÇÊܵ½ÁË¿ªÔ´Ìع¤Èí¼þTeradroidµÄÆô·¢¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬Æä×îÖÕÄ¿µÄÊÇͨ¹ýʹÓÃÏàËÆµÄÒ³ÃæÀ´»ñÈ¡ÒøÐеǼƾ֤²¢¾ÙÐÐÕË»§½ÓÊܹ¥»÷(ATO)¡£¡£¡£


https://www.bleepingcomputer.com/news/security/android-malware-revive-impersonates-bbva-bank-s-2fa-app/


4¡¢Vice SocietyÉù³Æ¶ÔInnsbruckÒ½¿Æ´óѧµÄ¹¥»÷ÈÏÕæ

     

¾Ý6ÔÂ27ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬Vice SocietyÉù³Æ¹¥»÷ÁËÒò˹²¼Â³¿ËÒ½¿Æ´óѧ£¨Med.University of Innsbruck£©¡£¡£¡£ÕâËù°ÂµØÀû´óѧµÄITϵͳÓÚ6ÔÂ20ÈÕ±¬·¢ÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÔÚÏßЧÀÍÆ÷ºÍÅÌËã»úϵͳÎÞ·¨»á¼û¡£¡£¡£6ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Vice Society½«¸Ã´óѧÌí¼Óµ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬²¢¹ûÕæÁ˱»µÁÎļþµÄÇåµ¥¡£¡£¡£6ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃѧУ»£»£» £»ØÓ¦³Æ£¬£¬£¬£¬£¬£¬£¬£¬È·ÈÏÉÏÖܵÄÖÐֹȷʵÓɸÃÍÅ»ïµÄ¹¥»÷Ôì³ÉµÄ£¬£¬£¬£¬£¬£¬£¬£¬ËûÃÇÏÖÔÚÕýÔÚ¶Ôй¶Êý¾ÝµÄ¹æÄ£ºÍÐÔ×Ó¾ÙÐÐÆÊÎöºÍÊӲ졣¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬£¬Vice Society×î½üÒ»Ö±ÔÚÕë¶ÔÅ·ÖÞµÄ×éÖ¯£¬£¬£¬£¬£¬£¬£¬£¬ÌØÊâÊǹú¼Ò/¹«¹²ÊµÌåºÍ½ÌÓý»ú¹¹¡£¡£¡£


https://www.bleepingcomputer.com/news/security/vice-society-claims-ransomware-attack-on-med-university-of-innsbruck/


5¡¢Carnival CruisesÒòÊý¾Ýй¶ÊÂÎñ±»·£¿£¿£¿£¿£¿î125ÍòÃÀÔª

     

ýÌå6ÔÂ27Èճƣ¬£¬£¬£¬£¬£¬£¬£¬Carnival CruisesÒò2019ÄêµÄÊý¾Ýй¶ÊÂÎñ±»·£¿£¿£¿£¿£¿î125ÍòÃÀÔª¡£¡£¡£¸ÃÊÂÎñÓÚ2019Äê5Ô±»·¢Ã÷£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ10¸öÔºóµÄ2020Äê3Ô²ű»Åû¶£¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÁË180000¸öÔ±¹¤ºÍ¿Í»§µÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°ÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢µØµã¡¢»¤ÕÕºÅÂë¡¢¼ÝʻִÕÕºÅÂë¡¢Ö§¸¶¿¨ÐÅÏ¢ºÍ¿µ½¡ÐÅÏ¢µÈ¡£¡£¡£Ë¾·¨²¿³¤Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾½«Ð¡ÎÒ˽¼ÒÐÅÏ¢´æ´¢ÔÚµç×ÓÓʼþÖУ¬£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÔÓÂÒÎÞÕµÄÒªÁìÀ´´¦Öóͷ£Ãô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Ê¹Î¥¹æÍ¨Öª±äµÃÔ½·¢ÄÑÌâ¡£¡£¡£³ýÁ˾­¼Ã´¦·ÖÍ⣬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾»¹ÔÞ³ÉʵÑéÎ¥¹æÏìÓ¦ÍýÏ룬£¬£¬£¬£¬£¬£¬£¬ÎªÔ±¹¤Öƶ©ÓʼþÅàѵÍýÏ룬£¬£¬£¬£¬£¬£¬£¬½ÓÊÜ×ÔÁ¦µÄÐÅÏ¢Çå¾²ÆÀ¹ÀµÈ¡£¡£¡£


https://therecord.media/carnival-cruises-to-pay-1-25-million-fine-for-2019-data-breach/


6¡¢AMD³ÆÕýÔÚÊÓ²ìRansomHouseÇÔÈ¡Æä450GBÊý¾ÝµÄÊÂÎñ

     

ýÌå6ÔÂ28ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬°ëµ¼Ì幫˾AMDÌåÏÖËûÃÇÕýÔÚÊÓ²ìRansomHouseÇÔÈ¡Æä450 GBÊý¾ÝµÄÊÂÎñ¡£¡£¡£ÔÚÒÑÍùµÄÒ»ÖÜÀ£¬£¬£¬£¬£¬£¬£¬RansomHouseÒ»Ö±ÔÚTelegramÉϳÆËûÃǽ«³öÊÛÒ»¼ÒÒÔ×ÖĸA¿ªÍ·µÄÖøÃûÈý×Öĸ¹«Ë¾µÄÊý¾Ý¡£¡£¡£6ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÍŻォAMDÌí¼Óµ½ËûÃǵÄÊý¾ÝÐ¹Â¶ÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬Éù³ÆÇÔÈ¡ÁË450 GBµÄÊý¾Ý¡£¡£¡£RansomHouseÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ËûÃǵÄÏàÖúͬ°éÔ¼Ò»ÄêǰÈëÇÖÁËAMDµÄÍøÂç¡£¡£¡£±»µÁÊý¾Ý°üÀ¨Ñо¿ºÍ²ÆÎñÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß²¢Î´ÁªÏµAMDË÷ÒªÊê½ð£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ½«Êý¾Ý³öÊÛ¸øÆäËüʵÌå»ò¹¥»÷ÍÅ»ï¸üÓмÛÖµ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/amd-investigates-ransomhouse-hack-claims-theft-of-450gb-data/