Snatch¿Éͨ¹ýÇå¾²Ä£Ê½ÖØÆôÀ´Èƹýɱ¶¾Èí¼þ£»£»£»£»·ðÂÞÀï´ïÖÝÅíÈø¿ÆÀÊÐÔâÍøÂç¹¥»÷£¬£¬£¬ÊÐÕþЧÀÍÖÐÖ¹
Ðû²¼Ê±¼ä 2019-12-111.ÀÕË÷Èí¼þSnatch¿Éͨ¹ýÇå¾²Ä£Ê½ÖØÆôÀ´Èƹýɱ¶¾Èí¼þ
ÀÕË÷Èí¼þSnatchÕýÔÚʹÓÃÒ»ÖÖǰËùδ¼ûµÄ¼¼ÇÉÀ´Èƹýɱ¶¾Èí¼þ£¬£¬£¬ÏêϸÀ´Ëµ£¬£¬£¬Ëü¿ÉÒÔ½«Êܺ¦ÕßµÄÅÌËã»úÒÔÇå¾²Ä£Ê½ÖØÐÂÆô¶¯£¬£¬£¬È»ºóÔËÐмÓÃÜÀú³Ì¡£¡£¡£´ó´ó¶¼É±¶¾Èí¼þ¶¼ÎÞ·¨ÔÚWindowsÇ徲ģʽÏÂÆô¶¯£¬£¬£¬Òò´ËSnatchÄÑÒÔ±»¼ì²âµ½¡£¡£¡£Æ¾Ö¤Sophos LabsµÄ±¨¸æ£¬£¬£¬¸ÃÀÕË÷Èí¼þͨ¹ýWindows×¢²á±íÏîÌí¼ÓÁËÒ»¸öÔÚÇ徲ģʽÏÂÆô¶¯µÄЧÀÍ£¬£¬£¬¸ÃЧÀͽ«ÔËÐÐSnatch¡£¡£¡£Ñо¿Ö°Ô±ÖÒÑÔ³ÆÕâÖÖģʽ¿ÉÄܻᱻÆäËüÀÕË÷Èí¼þËùÄ£Äâ¡£¡£¡£Snatch×Ô2018ÄêÏÄÈÕÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬ÆäÖ÷Òª¾ÙÐÐÕë¶ÔÐԵĹ¥»÷¡£¡£¡£Óë´ó´ó¶¼ÀÕË÷Èí¼þ²î±ð£¬£¬£¬Snatch»¹»áÇÔÈ¡ÊÜѬȾϵͳÉϵÄÎļþ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/snatch-ransomware-reboots-pcs-in-windows-safe-mode-to-bypass-antivirus-apps/
2.ÃÀ¹úÁè¼Ý75Íò·Ý³öÉú֤ʵÉêÇëÔÚÔÆÐ§ÀÍÆ÷ÖÐ̻¶
Ó¢¹úÇå¾²³§ÉÌFidus Information Security·¢Ã÷Ò»¸öÉèÖùýʧµÄÔÆÐ§ÀÍÆ÷ÖÐ̻¶ÁËÁè¼Ý75Íò·ÝÃÀ¹ú³öÉú֤ʵÉêÇë¡£¡£¡£¸ÃÊý¾Ý¿â´æ´¢ÔÚûÓÐÃÜÂë±£»£»£»£»¤µÄAWS´æ´¢Í°ÖУ¬£¬£¬Ì»Â¶µÄÊý¾Ý°üÀ¨ÉêÇëÈËÐÕÃû¡¢³öÉúÈÕÆÚ¡¢¼ÒͥסַºÍµç×ÓÓʼþµØµã¡¢µç»°ºÅÂëÒÔ¼°ÒÔǰµÄסַºÍ¼ÒÍ¥³ÉÔ±µÄÐÕÃûµÈÃô¸ÐÐÅÏ¢¡£¡£¡£ÓÉÓÚ¸ÃÊý¾Ý¿âµÄËùÓÐÕßÉÐδ»ØÓ¦Ñо¿ÍŶӵÄ֪ͨ£¬£¬£¬Òò´ËFidusûÓÐ͸¶¸Ã¹«Ë¾µÄÃû³Æ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/data-leak-exposes-750k-birth-cert/
3.·ðÂÞÀï´ïÖÝÅíÈø¿ÆÀÊÐÔâÍøÂç¹¥»÷£¬£¬£¬ÊÐÕþЧÀÍÖÐÖ¹
·ðÂÞÀï´ïÖÝÅíÈø¿ÆÀÊÐÖÜĩʱ´úÔâµ½ÍøÂç¹¥»÷£¬£¬£¬ÊÐÕþЧÀÍÊܵ½Ó°Ïì¡£¡£¡£¸ÃÊÂÎñ±¬·¢ÔÚÖÜÁùÆÆÏþ1:30×óÓÒ£¬£¬£¬¸ÃÊеÄIT²¿·ÖÒ»Ö±ÔÚÆð¾¢»Ö¸´ÍøÂç¡£¡£¡£ÏÖÔÚÉв»ÇåÎúÊÂÎñÊÇÓÉÄÄÖÖÀàÐ͵ÄÍøÂç¹¥»÷µ¼Öµģ¬£¬£¬Ò²²»ÇåÎúÓм¸¶ą̀ÅÌËã»úÊܵ½Ó°Ï죬£¬£¬µ«¸ÃÊеĴ󲿷ÖÍøÂçÅþÁ¬¶¼ÒѶϿª£¬£¬£¬°üÀ¨Pensacola EnergyÔÚÏßÖ§¸¶ÏµÍ³ÒÔ¼°¶¼»áÎÀÉúÉèÊ©¡¢»ùÓÚÅÌËã»úµÄͨѶЧÀÍ£¨°üÀ¨µç×ÓÓʼþϵͳ£©µÈ£¬£¬£¬µ«911ºÍÆäËü½ôÆÈЧÀÍ£¨¾¯Ô±ºÍÏû·À²¿·Ö£©Ã»ÓÐÊܵ½Ó°Ïì¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/pensacola-florida-hit-by-cyber-attack-city-services-impacted/
4.Ã÷ÄáËÕ´ïÖÝÒ½ÁÆ»ú¹¹SEMOMSÔâµ½ÀÕË÷Èí¼þ¹¥»÷
Ã÷ÄáËÕ´ïÖÝÒ»¼ÒרÃÅÖÎÁÆÃ沿¡¢ÑÀ³Ý¡¢¿ÚÇ»µÄÒ½ÁÆ»ú¹¹£¨SEMOMS£©Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬¸ÃÊÂÎñ±¬·¢ÔÚ9ÔÂ23ÈÕ£¬£¬£¬ITÖ°Ô±ÔÚÊÂÎñ±¬·¢ºóÁ¬Ã¦½ÓÄÉÁ˱£»£»£»£»¤²½·¥¡£¡£¡£SEMOMSÔÚÆäÍøÕ¾ÉϽÒÏþµÄÉùÃ÷ÖÐÌåÏÖ£¬£¬£¬Ö»¹ÜÏÖÔÚûÓÐÖ¤¾ÝÅú×¢¹¥»÷Õß»á¼û»òÉó²éÁË»¼ÕßÐÅÏ¢£¬£¬£¬µ«¸Ã»ú¹¹ÒѾ½ÓÄÉÁ˲½·¥²¢Í¨ÖªÁË¿ÉÄÜÊÜÓ°ÏìµÄ»¼Õß¡£¡£¡£SEMOMS³Æ»¼ÕߵIJÆÎñÐÅÏ¢¡¢²¡Àú»òÉç»áÇå¾²ºÅÂë¾ù²»»áÊܵ½ÊÂÎñµÄÓ°Ïì¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/ransomware-attack-on-minnesota/
5.Ô˶¯ÁãÊÛÉÌSweaty Betty¹ÙÍøÑ¬È¾Magecart¾ç±¾
Å®ÐÔÔ˶¯×°ÁãÊÛÉÌSweaty BettyÒÑͨ¹ýµç×ÓÓʼþ¼û¸æÓû§ÆäÖ§¸¶ÐÅÏ¢¿ÉÄܱ»ÇÔ¡£¡£¡£¸Ã¹«Ë¾³Æ¹ÙÍøµÄÖ§¸¶Ò³Ãæ±»Ö²ÈëÁËÇÔÈ¡¸¶¿îÐÅÏ¢µÄ¶ñÒâ´úÂ룬£¬£¬ÊÜÓ°ÏìµÄ¿Í»§ÎªÔÚ11ÔÂ19ÈÕÐÇÆÚ¶þÏÂÖç6.24pm£¨GMT£©µ½11ÔÂ27ÈÕÐÇÆÚÈýÏÂÖç2.52pm£¨GMT£©Ö®¼ä¹ºÎïµÄ¿Í»§¡£¡£¡£¿£¿£¿£¿£¿ÉÄܱ»ÇÔµÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢ÃÜÂë¡¢Õ˵¥µØµã¡¢½»¸¶µØµã¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢ÐÅÓÿ¨ºÅ¡¢CVVÂëºÍÓÐÓÃÆÚµÈ¡£¡£¡£ÏÖÔÚÉв»ÇåÎúÓм¸¶à¿Í»§Êܵ½¸ÃÊÂÎñµÄÓ°Ï죬£¬£¬µ«¸Ã¹«Ë¾ÌåÏÖÖ»ÓÐÔÚÖ§¸¶Ò³ÃæÉÏÐÂÊäÈëÁËÐÅÏ¢¶ø²»ÊÇʹÓÃÒÑÉúÑÄÐÅÏ¢µÄ¿Í»§²ÅÊܵ½Ó°Ïì¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://hotforsecurity.bitdefender.com/blog/hackers-steal-credit-card-details-from-sweaty-betty-customers-21888.html
6.΢ÈíÐû²¼12ÔÂWindowsÇå¾²¸üУ¬£¬£¬ÐÞ¸´36¸öÎó²î
΢ÈíÔÚ12ÔÂWindowsÇå¾²¸üÐÂÖÐÐÞ¸´ÁË36¸öÎó²î£¬£¬£¬ÆäÖаüÀ¨7¸öÑÏÖØÎó²î£¬£¬£¬27¸öÖ÷ÒªÎó²î£¬£¬£¬1ÆäÖеÈÎó²îºÍ1¸öµÍΣÎó²î¡£¡£¡£ÐèÒª¹Ø×¢µÄÎó²îÊÇWin32k×é¼þÖеÄÌØÈ¨ÌáÉý0day£¬£¬£¬¸ÃÎó²î£¨CVE-2019-1458£©ÊÇÓÉ¿¨°Í˹»ùÑо¿Ö°Ô±·¢Ã÷µÄ£¬£¬£¬²¢ÒÑÔÚÒ°Íâ±»Æð¾¢Ê¹Óᣡ£¡£Æ¾Ö¤Î¢ÈíµÄÇ徲ͨ¸æ£¬£¬£¬¸ÃÎó²î±¬·¢ÔÚWin32k×é¼þÎÞ·¨×¼È·´¦Öóͷ£ÄÚ´æÖеŤ¾ßʱ£¬£¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄÚºËģʽÏÂÔËÐÐí§Òâ´úÂë¡£¡£¡£ÒªÊ¹ÓôËÎó²î£¬£¬£¬¹¥»÷Õß±ØÐèÊ×ÏȵǼϵͳ£¬£¬£¬È»ºó¿Éͨ¹ýÔËÐÐʹÓôËÎó²îµÄ¶ñÒâÈí¼þÀ´½ÓÊÜϵͳ¡£¡£¡£¸ü¶àÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsofts-december-2019-patch-tuesday-fixes-win32k-zero-day-36-flaws/


¾©¹«Íø°²±¸11010802024551ºÅ