ÎÖ˹±¤Ë®Îñ¾ÖÔâºÚ¿Í¹¥»÷£»¿ÆÂÞÀ­¶àÖÝIT·þÎñÉÌCTSÔâµ½ÀÕË÷Èí¼þ¹¥»÷£»RyukбäÖÖ½âÃÜÆ÷ÓÐbug

°ä²¼¹¦·ò 2019-12-10


1.AirtelÀûÓ÷¨Ê½´æÔÚ·ì϶¿Éµ¼Ö¿ͻ§Êý¾Ý¶³ö


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÍøÂ簲ȫ×êÑÐÈËÔ±Ehraz Ahmed·¢ÏÖÓ¡¶ÈAirtel¹«Ë¾µÄÀûÓ÷¨Ê½´æÔÚ°²È«·ì϶ £¬µ¼ÖÂÓû§µÄÃô¸ÐÐÅϢ¶³ö¡£¿É»ñÈ¡µÄÐÅÏ¢Ô̺¬ËÁÒâÓû§µÄÐÕÃû¡¢ÐԱ𡢵ç×ÓÓʼþµØÖ·¡¢µ®ÉúÈÕÆÚ¡¢×¡Ö·¡¢¶©ÔÄÐÅÏ¢¡¢ÍøÂçÐÅÏ¢¡¢¼¤»îÈÕÆÚ¡¢Óû§ÀàÐÍ£¨Ô¤¸¶·Ñ»òºó¸¶·Ñ£©¡¢IMEIºÅÂëµÈ¡£Ahmed°µÊ¾Airtel¹«Ë¾µÄÿ¸öÓû§¶¼´æÔÚ·çÏÕ £¬Õâ¿ÉÄÜÓ°ÏìÁËËùÓÐ3.255ÒÚÓû§¡£Airtel½²»°ÈËÈÏ¿ÉÁËÕâÒ»ÎÊÌâ £¬²¢°µÊ¾¹«Ë¾ÔÚÊÕµ½¾¯±¨ºóÁ¢¿Ì½¨¸´Á˸÷ì϶¡£


  Ô­ÎÄÁ´½Ó£º

https://economictimes.indiatimes.com/tech/internet/security-flaw-in-airtel-app-exposes-customers-data-fixed-now/articleshow/72421661.cms


2.¿ÆÂÞÀ­¶àÖÝIT·þÎñÉÌCTSÔâµ½ÀÕË÷Èí¼þ¹¥»÷


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¿ÆÂÞÀ­¶àÖÝIT·þÎñÉÌCTSÔâÀÕË÷Èí¼þ¹¥»÷ £¬²¨¼°100¶à¼ÒÑÀ¿ÆÕïËù¡£CTSרΪÑÀ¿ÆÕïËùÌṩIT·þÎñ £¬Ô̺¬ÍøÂ簲ȫ¡¢Êý¾Ý±¸·ÝºÍIPÓïÒôµç»°µÈ¡£¸Ã¹«Ë¾ÓÚ11ÔÂ25ÈÕÔâµ½¹¥»÷ £¬µ¼ÖÂ100¶à¼ÒÑÀ¿ÆÕïËùµÄÍÆËã»úϰȾÁËÀÕË÷Èí¼þSodinokibi¡£CTS»Ø¾øÁ˹¥»÷ÕßË÷Òª70ÍòÃÀÔªÊê½ðµÄÒªÇó £¬ÓÉÓÚϵͳ²»ÐÝÖжÏ £¬Ä¿Ç°ºÜ¶àÑÀ¿ÆÕïËùÒÀÈ»ÎÞ·¨Õý³£½»Òס£


 Ô­ÎÄÁ´½Ó£º

https://krebsonsecurity.com/2019/12/ransomware-at-colorado-it-provider-affects-100-dental-offices/


3.ÎÖ˹±¤Ë®Îñ¾ÖÔâºÚ¿Í¹¥»÷ £¬Ô¼3000¿Í»§ÐÅÏ¢±»ÇÔ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÎÖ˹±¤Ë®Îñ¾Ö°µÊ¾ÆäÒ»¼Ò³Ð°üÉÌCentralSquareÔâºÚ¿ÍÈëÇÖ £¬µ¼ÖÂÔ¼3000ÃûʹÓÃÐÅÓþ¿¨Ö§¸¶Ë®·ÑÕ˵¥µÄÓû§ÒþÖÔÐÅÏ¢¿ÉÄܱ»ÇÔ¡£±»µÁµÄÐÅÏ¢¿ÉÄÜÔ̺¬ÐÕÃû¡¢µØÖ·ºÍÐÅÓþ¿¨Êý¾Ý £¬Ô̺¬¿¨ºÅºÍ°²È«Âë £¬ÊÜÓ°ÏìµÄÓû§ÎªÔÚ8ÔÂ27ÈÕÖÁ10ÔÂ23ÈÕÖ®¼ä½øÐÐÔÚÏ߸¶¿îµÄÓû§¡£Ë®Îñ¾ÖÅ®½²»°ÈËMary Gugliuzza°µÊ¾ÒѾ­Í¨ÖªÁË¿ÉÄÜÊÜÓ°ÏìµÄÓû§ £¬CentralSquare½«ÎªÊÜÓ°ÏìµÄÓû§ÌṩһÄêµÄÃâ·ÑÐÅÓþ¼à¿Ø·þÎñ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.nbcdfw.com/news/local/3000-Fort-Worth-Water-Department-Customers-Victims-of-Data-Breach-565838632.html


4.Spotify´¹µö¹¥»÷ÖØÒªÇÔÈ¡Óû§µÄÐÅÓþ¿¨ÐÅÏ¢


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖÒ»¸öеĴ¹µö¹¥»÷»î¶¯ £¬¹¥»÷ÕßÖØÒªÕë¶ÔSpotifyÓû§ £¬ÊÔͼºýŪÆäÕË»§Í´´¦ºÍ¸¶¿îÐÅÏ¢¡£¸Ã´¹µöÓʼþÔÚ·ÂÕÕSpotifyÒ³ÃæÖг£¼ûµÄÅäÉ«¹æ»®¡¢logo¡¢×ÖÌåºÍÊ¢ÐÐͼƬÉÏÖ§³öÁ˺ܴóµÖÁ¦ £¬ÊÔͼºýŪÓû§ÏàÐÅÆäÕË»§ÓÉÓÚÖ§¸¶Ê§°Ü¶øÎÞ·¨³ÖÐøÏíÊܶ©ÔÄ·þÎñ¡£ÊÜÆ­µÄÓû§±»ÒªÇó½Ó¼ûÒ»¸öÐéαµÄSpotify´¹µöÍøÕ¾ £¬²¢ÊäÈë¾ßÌåµÄµÇ¼ÐÅÏ¢ºÍÖ§¸¶ÐÅÏ¢ £¬Ô̺¬ÐÅÓþ¿¨ºÅÂëºÍCVVÂë¡£Spotify¹«Ë¾ÖÒ¸æÓû§³Æ £¬¸Ã¹«Ë¾¾ø²»»áͨ¹ýµç×ÓÓʼþÒªÇó»áÔ±ÌṩÓ×ÎÒÒþÖÔÐÅÏ¢ £¬ÀýÈçÖ§¸¶ÐÅÏ¢¡¢ÕË»§ÃÜÂë»ò˰ÎñºÅÂëµÈ¡£


 Ô­ÎÄÁ´½Ó£º

https://au.finance.yahoo.com/news/spotify-scam-harvests-credit-card-details-200027468.html


5.д¹µö»î¶¯ÖØÒªÕë¶ÔÉϹžíÖáOLÓÎÏ·Íæ¼Ò


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


´¹µö¹¥»÷Õß¼Ù×°³ÉÉϹžíÖáÓÎÏ·µÄ¿ª·¢Õß £¬Õë¶ÔÓµÓÐPlayStation½ÚÔį̀£¨¿ÉÄÜ»¹ÓÐÆäËû£©µÄÓÎÏ·Õß½øÐд¹µö¹¥»÷¡£ËûÃÇÏòÓû§·¢ËÍËæ»úµÄ¸öÈËÐÅÏ¢ £¬ÖÒ¸æÆäÕË»§³öÏÖ°²È«ÎÊÌâ £¬ÒªÇóÓû§ÔÚ15·ÖÖӵŦ·òÀïÌṩµç×ÓÓʼþµØÖ·¡¢ÃÜÂëºÍµ®ÉúÈÕÆÚ £¬²»È»ÆäÕË»§½«±»·â½û¡£¸Ã´¹µö¹¥»÷µÄ×îÖÕÖ÷ÕÅÊÇÇÔÈ¡Íæ¼ÒÕË»§ÄÚµÄÓÎÏ·ÉÌÆ·²¢ÔÚ°µÍøÉÏÏúÊÛ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-elder-scrolls-online-devs-run-playstation-phishing-scam/


6.RyukбäÖÖ½âÃÜÆ÷ÓÐbug £¬¿ÉÄܵ¼ÖÂÊý¾ÝÓÀÔ¼ûÔʧ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ƾ¾Ý°²È«³§ÉÌEmsisoftµÄ˵·¨ £¬ÀÕË÷Èí¼þRyuk×îбäÖֵĽâÃÜÆ÷´æÔÚÒ»¸öbug £¬¼´±ãÊܺ¦ÕßÖ§¸¶ÁËÊê½ð £¬Ò²¿ÉÄÜ»áÓÉÓÚ´Ëbugµ¼ÖÂÊý¾ÝÎÞ·¨¸´Ô­ºÍÃÔʧ¡£¸Ã±äÖÖ¶ÔÆä¼ÓÃܹý³Ì½øÐÐÁËÅú¸Ä £¬ÈôÊÇÎļþ´óÓ׳¬¹ý54.4MB £¬ÔòÖ»½øÐв¿ÃżÓÃÜ £¬²½ÖèÊǶԿ϶¨ÊýÁ¿µÄ100Íò×Ö½ÚÊý¾Ý¿é½øÐмÓÃÜ¡£È»¶øÆä½âÃÜÆ÷ÔÚÍÆËãÎļþ´óÓ×ʱ´Óĩβ½Ø¶ÏÁËÒ»¸ö×Ö½Ú £¬¹ÌÈ»´óÎÞÊýÎļþÖÐ×îºóÒ»¸ö×Ö½ÚÖ»ÊÇÌî³ä £¬µ«Ä³Ð©À©´óÃûµÄÎļþ£¨ÀýÈçÐé¹¹´ÅÅÌÎļþ¡¢OracleÊý¾Ý¿âÎļþ£©ÔÚ×îºóÒ»¸ö×Ö½ÚÖд洢³ÁÒªÐÅÏ¢ £¬Ê¹µÃ°Ü»µµÄÎļþÔÚ½âÃܺóÎÞ·¨ÕýÈ·¼ÓÔØ¡£¸üÔã¸âµÄÊÇ £¬½âÃÜÆ÷»áÒÔΪÒÑÕýÈ·½âÃܲ¢É¾³ý¼ÓÃܵÄÎļþ £¬Ê¹µÃÊý¾Ý¸üÄѸ´Ô­¡£Emsisoft½¨ÒéÓû§±£Áô¼ÓÃÜÎļþµÄ±¸·Ý £¬ÒÔÃâ±»½âÃÜÆ÷Ëù·ÛËé¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ryuk-ransomware-decryptor-is-broken-could-lead-to-data-loss/