¹ú¼ÒÍøÐŰìÐû²¼¡¶»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢¹ÜÀí¹æ¶¨¡·

Ðû²¼Ê±¼ä 2022-06-29

1¡¢¹ú¼ÒÍøÐŰìÐû²¼¡¶»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢¹ÜÀí¹æ¶¨¡·


6ÔÂ27ÈÕ£¬¹ú¼Ò»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒÐû²¼¡¶»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢¹ÜÀí¹æ¶¨¡·£¬×Ô2022Äê8ÔÂ1ÈÕÆðÊ©ÐС£³ǫ̈¡¶¹æ¶¨¡·£¬Ö¼ÔÚ¼ÓÇ¿¶Ô»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢µÄ¹ÜÀí£¬ºëÑïÉç»áÖ÷ÒåºËÐļÛÖµ¹Û£¬Î¬»¤¹ú¼ÒÄþ¾²ºÍÉç»á¹«¹²ÀûÒæ£¬± £»¤¹«Ãñ¡¢·¨ÈËºÍÆäËû×éÖ¯µÄºÏ·¨È¨Ò棬´Ù½ø»¥ÁªÍøÐÅÏ¢·þÎñ½¡¿µÉú³¤¡£¡¶¹æ¶¨¡·Ã÷È·ÁËÕ˺ÅÐÅÏ¢×¢²áºÍʹÓù淶£¬ÒªÇó»¥ÁªÍøÐÅÏ¢·þÎñÌṩÕßÓ¦µ±Öƶ¨ºÍ¹ûÈ»»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢¹ÜÀí¹æÔò¡¢Æ½Ì¨ÌõÔ¼£¬Ã÷È·Õ˺ÅÐÅÏ¢×¢²á¡¢Ê¹Óú͹ÜÀíÏà¹ØÈ¨ÀûÒåÎñ¡£


http://www.cac.gov.cn/2022-06/26/c_1657868775333429.htm


2¡¢CODESYSÐû²¼¸üУ¬ÐÞ¸´ICS×Ô¶¯»¯Èí¼þÖеÄ11©¶´

     

¾ÝýÌå6ÔÂ28ÈÕ±¨µÀ£¬CODESYSÐÞ¸´ÁËICS×Ô¶¯»¯Èí¼þÖеÄ11¸ö©¶´¡£CoDeSysÊÇÆ¾¾Ý¹ú¼Ê¹¤Òµ³ß¶ÈIEC 61131-3¶Ô¿ØÖÆÆ÷Ó¦Ó÷¨Ê½½øÐбà³ÌµÄ¿ª·¢»·¾³¡£Ñо¿ÈËÔ±³Æ£¬¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ©¶´´¥·¢¾Ü¾ø·þÎñ(DoS)Ìõ¼þ¡¢Ð¹Â¶ÐÅÏ¢¡¢Ö´ÐÐÈÎÒâ´úÂë»òÕß½øÐÐÆäËü¶ñÒâ»î¶¯¡£ÆäÖÐÁ½¸ö©¶´£¨CVE-2022-31805ºÍCVE-2022-31806£©×îΪÑÏÖØ£¬CVSSÆÀ·ÖΪ9.8£¬ ·Ö±ðÓëÔÚPLC ÉÏÖ´ÐвÙ×÷֮ǰʹÓÃÃ÷ÎÄÑéÖ¤ÃÜÂ룬ÒÔ¼°Ä¬ÈÏÇé¿öÏÂδÄÜÆôÓÃÃÜÂë± £»¤ÓйØ¡£


https://securityaffairs.co/wordpress/132685/security/codesys-ics-automation-software-flaws.html


3¡¢ÐÂAndroid¶ñÒâÈí¼þReviveð³äBBVAÒøÐеÄ2FAÓ¦ÓÃ

     

CleafyÔÚ6ÔÂ27ÈÕÅû¶ÁËÒ»ÖÖеÄAndroid¶ñÒâÈí¼þRevive¡£¸Ã¶ñÒâÈí¼þÓÚ6ÔÂ15ÈÕÊ״α»·¢ÏÖ£¬Í¨¹ýµöÓã»î¶¯½øÐÐÁ÷´«£¬Ö÷ÒªÕë¶ÔÎ÷°àÑÀ½ðÈÚ·þÎñ¹«Ë¾BBVA¡£Reviveαװ³ÉBBVAÒøÐеÄ2FA¹¤¾ß£¬²¢Éù³ÆÇ¶Èëµ½ÕæÕýÒøÐÐÓ¦ÓÃÖеÄ2FA¹¦Ð§²»ÔÙÂú×ãÄþ¾²¼¶±ðÒªÇó£¬ÒªÇóÄ¿±ê°²×°´Ë¸½¼Ó¹¤¾ßÀ´Éý¼¶ÆäÄþ¾²ÐÔ¡£ReviveÈÔ´¦ÓÚÔçÆÚ½×¶Î£¬¿ª·¢Õß¿ÉÄÜÊÇÊܵ½ÁË¿ªÔ´¼äµýÈí¼þTeradroidµÄÆô·¢¡£´ËÍ⣬Æä×îÖÕÄ¿µÄÊÇͨ¹ýʹÓÃÏàËÆµÄÒ³ÃæÀ´»ñÈ¡ÒøÐеǼƾ¾Ý²¢½øÐÐÕË»§½Ó¹Ü¹¥»÷(ATO)¡£


https://www.bleepingcomputer.com/news/security/android-malware-revive-impersonates-bbva-bank-s-2fa-app/


4¡¢Vice SocietyÉù³Æ¶ÔInnsbruckÒ½¿Æ´óѧµÄ¹¥»÷ÂôÁ¦

     

¾Ý6ÔÂ27ÈÕ±¨µÀ£¬Vice SocietyÉù³Æ¹¥»÷ÁËÒò˹²¼Â³¿ËÒ½¿Æ´óѧ£¨Med.University of Innsbruck£©¡£ÕâËù°ÂµØÀû´óѧµÄITϵͳÓÚ6ÔÂ20ÈÕ·¢ÉúÖжÏ£¬µ¼ÖÂÔÚÏß·þÎñÆ÷ºÍ¼ÆËã»úϵͳÎÞ·¨·ÃÎÊ¡£6ÔÂ26ÈÕ£¬Vice Society½«¸Ã´óѧÌí¼Óµ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾£¬²¢¹ûÈ»Á˱»µÁÎļþµÄÇåµ¥¡£6ÔÂ28ÈÕ£¬¸ÃѧР£»ØÓ¦³Æ£¬È·ÈÏÉÏÖܵÄÖжÏȷʵÓɸÃÍÅ»ïµÄ¹¥»÷Ôì³ÉµÄ£¬ËûÃÇĿǰÕýÔÚ¶Ôй¶Êý¾ÝµÄ·¶Î§ºÍÐÔÖʽøÐзÖÎöºÍÊӲ졣¾ÝϤ£¬Vice Society×î½üÒ»Ö±ÔÚÕë¶ÔÅ·ÖÞµÄ×éÖ¯£¬ÌرðÊǹú¼Ò/¹«¹²ÊµÌåºÍ½ÌÓý»ú¹¹¡£


https://www.bleepingcomputer.com/news/security/vice-society-claims-ransomware-attack-on-med-university-of-innsbruck/


5¡¢Carnival CruisesÒòÊý¾Ýй¶Ê¼þ±»·£¿î125ÍòÃÀÔª

     

ýÌå6ÔÂ27Èճƣ¬Carnival CruisesÒò2019ÄêµÄÊý¾Ýй¶Ê¼þ±»·£¿î125ÍòÃÀÔª¡£¸ÃʼþÓÚ2019Äê5Ô±»·¢ÏÖ£¬ÔÚ10¸öÔºóµÄ2020Äê3Ô²ű»Åû¶£¬Ð¹Â¶ÁË180000¸öÔ±¹¤ºÍ¿Í»§µÄÐÅÏ¢£¬Éæ¼°ÐÕÃû¡¢Éç»áÄþ¾²ºÅÂë¡¢µØÖ·¡¢»¤ÕÕºÅÂë¡¢¼ÝʻִÕÕºÅÂë¡¢Ö§¸¶¿¨ÐÅÏ¢ºÍ½¡¿µÐÅÏ¢µÈ¡£Ë¾·¨²¿³¤Ö¸³ö£¬¸Ã¹«Ë¾½«¸öÈËÐÅÏ¢´æ´¢ÔÚµç×ÓÓʼþÖУ¬²¢Ê¹ÓÃÔÓÂÒÎÞÕµÄÒªÁìÀ´´¦ÖÃÃô¸ÐÊý¾Ý£¬Ê¹Î¥¹æÍ¨Öª±äµÃÔ½·¢À§ÄÑ¡£³ýÁ˾­¼Ã´¦·£Í⣬¸Ã¹«Ë¾»¹Í¬ÒâʵʩΥ¹æÏìÓ¦¼Æ»®£¬ÎªÔ±¹¤Öƶ¨ÓʼþÅàѵ¼Æ»®£¬½ÓÊܶÀÁ¢µÄÐÅÏ¢Äþ¾²ÆÀ¹ÀµÈ¡£


https://therecord.media/carnival-cruises-to-pay-1-25-million-fine-for-2019-data-breach/


6¡¢AMD³ÆÕýÔÚÊÓ²ìRansomHouseÇÔÈ¡Æä450GBÊý¾ÝµÄʼþ

     

ýÌå6ÔÂ28ÈÕ±¨µÀ£¬°ëµ¼Ì幫˾AMDÌåÏÖËûÃÇÕýÔÚÊÓ²ìRansomHouseÇÔÈ¡Æä450 GBÊý¾ÝµÄʼþ¡£ÔÚ¹ýÈ¥µÄÒ»ÖÜÀRansomHouseÒ»Ö±ÔÚTelegramÉϳÆËûÃǽ«³öÊÛÒ»¼ÒÒÔ×ÖĸA¿ªÍ·µÄÖøÃûÈý×Öĸ¹«Ë¾µÄÊý¾Ý¡£6ÔÂ27ÈÕ£¬¸ÃÍŻォAMDÌí¼Óµ½ËûÃǵÄÊý¾ÝÐ¹Â¶ÍøÕ¾£¬Éù³ÆÇÔÈ¡ÁË450 GBµÄÊý¾Ý¡£RansomHouseÌåÏÖ£¬ËûÃǵĺÏ×÷»ï°éÔ¼Ò»ÄêǰÈëÇÖÁËAMDµÄÍøÂç¡£±»µÁÊý¾Ý°üÂÞÑо¿ºÍ²ÆÕþÐÅÏ¢£¬¹¥»÷Õß²¢Î´ÁªÏµAMDË÷ÒªÊê½ð£¬ÒòΪ½«Êý¾Ý³öÊÛ¸øÆäËüʵÌå»ò¹¥»÷ÍÅ»ï¸üÓмÛÖµ¡£


https://www.bleepingcomputer.com/news/security/amd-investigates-ransomhouse-hack-claims-theft-of-450gb-data/