¹ú¼ÒÍøÐŰìÐû²¼¡¶»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢ÖÎÀí»®¶¨¡·
Ðû²¼Ê±¼ä 2022-06-291¡¢¹ú¼ÒÍøÐŰìÐû²¼¡¶»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢ÖÎÀí»®¶¨¡·
6ÔÂ27ÈÕ£¬¹ú¼Ò»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒÐû²¼¡¶»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢ÖÎÀí»®¶¨¡·£¬×Ô2022Äê8ÔÂ1ÈÕÆðÊ©ÐС£³ǫ̈¡¶»®¶¨¡·£¬Ö¼ÔÚÔöÇ¿¶Ô»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢µÄÖÎÀí£¬ºëÑïÉç»áÖ÷Òå½¹µã¼ÛÖµ¹Û£¬Î¬»¤¹ú¼ÒÇå¾²ºÍÉç»á¹«¹²ÀûÒæ£¬±£»¤¹«Ãñ¡¢·¨ÈËºÍÆäËû×éÖ¯µÄÕýµ±È¨Ò棬Ôö½ø»¥ÁªÍøÐÅÏ¢·þÎñ¿µ½¡Éú³¤¡£¡¶»®¶¨¡·Ã÷È·ÁËÕ˺ÅÐÅÏ¢×¢²áºÍʹÓù淶£¬ÒªÇó»¥ÁªÍøÐÅÏ¢·þÎñÌṩÕßÓ¦µ±Öƶ©ºÍ¹ûÕæ»¥ÁªÍøÓû§Õ˺ÅÐÅÏ¢ÖÎÀí¹æÔò¡¢Æ½Ì¨ÌõÔ¼£¬Ã÷È·Õ˺ÅÐÅÏ¢×¢²á¡¢Ê¹ÓúÍÖÎÀíÏà¹ØÈ¨Á¦ÒåÎñ¡£
http://www.cac.gov.cn/2022-06/26/c_1657868775333429.htm
2¡¢CODESYSÐû²¼¸üУ¬ÐÞ¸´ICS×Ô¶¯»¯Èí¼þÖеÄ11Îó²î
¾ÝýÌå6ÔÂ28ÈÕ±¨µÀ£¬CODESYSÐÞ¸´ÁËICS×Ô¶¯»¯Èí¼þÖеÄ11¸öÎó²î¡£CoDeSysÊÇÆ¾Ö¤¹ú¼Ê¹¤Òµ±ê×¼IEC 61131-3¶Ô¿ØÖÆÆ÷Ó¦ÓóÌÐò¾ÙÐбà³ÌµÄ¿ª·¢ÇéÐΡ£Ñо¿Ö°Ô±³Æ£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²î´¥·¢¾Ü¾ø·þÎñ(DoS)Ìõ¼þ¡¢Ð¹Â¶ÐÅÏ¢¡¢Ö´ÐÐí§Òâ´úÂë»òÕß¾ÙÐÐÆäËü¶ñÒâÔ˶¯¡£ÆäÖÐÁ½¸öÎó²î£¨CVE-2022-31805ºÍCVE-2022-31806£©×îΪÑÏÖØ£¬CVSSÆÀ·ÖΪ9.8£¬ »®·ÖÓëÔÚPLC ÉÏÖ´ÐвÙ×÷֮ǰʹÓÃÃ÷ÎÄÑéÖ¤ÃÜÂ룬ÒÔ¼°Ä¬ÈÏÇéÐÎÏÂδÄÜÆôÓÃÃÜÂë±£»¤Óйء£
https://securityaffairs.co/wordpress/132685/security/codesys-ics-automation-software-flaws.html
3¡¢ÐÂAndroid¶ñÒâÈí¼þReviveð³äBBVAÒøÐеÄ2FAÓ¦ÓÃ
CleafyÔÚ6ÔÂ27ÈÕÅû¶ÁËÒ»ÖÖеÄAndroid¶ñÒâÈí¼þRevive¡£¸Ã¶ñÒâÈí¼þÓÚ6ÔÂ15ÈÕÊ״α»·¢Ã÷£¬Í¨¹ý´¹ÂÚÔ˶¯¾ÙÐÐÈö²¥£¬Ö÷ÒªÕë¶ÔÎ÷°àÑÀ½ðÈÚ·þÎñ¹«Ë¾BBVA¡£Reviveαװ³ÉBBVAÒøÐеÄ2FA¹¤¾ß£¬²¢Éù³ÆÇ¶Èëµ½ÕæÕýÒøÐÐÓ¦ÓÃÖеÄ2FA¹¦Ð§²»ÔÙÖª×ãÇå¾²¼¶±ðÒªÇó£¬ÒªÇóÄ¿µÄ×°Öô˸½¼Ó¹¤¾ßÀ´Éý¼¶ÆäÇå¾²ÐÔ¡£ReviveÈÔ´¦ÓÚÔçÆÚ½×¶Î£¬¿ª·¢Õß¿ÉÄÜÊÇÊܵ½ÁË¿ªÔ´Ìع¤Èí¼þTeradroidµÄÆô·¢¡£±ðµÄ£¬Æä×îÖÕÄ¿µÄÊÇͨ¹ýʹÓÃÏàËÆµÄÒ³ÃæÀ´»ñÈ¡ÒøÐеǼƾ֤²¢¾ÙÐÐÕË»§½ÓÊܹ¥»÷(ATO)¡£
https://www.bleepingcomputer.com/news/security/android-malware-revive-impersonates-bbva-bank-s-2fa-app/
4¡¢Vice SocietyÉù³Æ¶ÔInnsbruckÒ½¿Æ´óѧµÄ¹¥»÷ÈÏÕæ
¾Ý6ÔÂ27ÈÕ±¨µÀ£¬Vice SocietyÉù³Æ¹¥»÷ÁËÒò˹²¼Â³¿ËÒ½¿Æ´óѧ£¨Med.University of Innsbruck£©¡£ÕâËù°ÂµØÀû´óѧµÄITϵͳÓÚ6ÔÂ20ÈÕ±¬·¢ÖÐÖ¹£¬µ¼ÖÂÔÚÏß·þÎñÆ÷ºÍÅÌËã»úϵͳÎÞ·¨»á¼û¡£6ÔÂ26ÈÕ£¬Vice Society½«¸Ã´óѧÌí¼Óµ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾£¬²¢¹ûÕæÁ˱»µÁÎļþµÄÇåµ¥¡£6ÔÂ28ÈÕ£¬¸ÃѧУ»ØÓ¦³Æ£¬È·ÈÏÉÏÖܵÄÖÐֹȷʵÓɸÃÍÅ»ïµÄ¹¥»÷Ôì³ÉµÄ£¬ËûÃÇÏÖÔÚÕýÔÚ¶Ôй¶Êý¾ÝµÄ¹æÄ£ºÍÐÔ×Ó¾ÙÐÐÆÊÎöºÍÊӲ졣¾ÝϤ£¬Vice Society×î½üÒ»Ö±ÔÚÕë¶ÔÅ·ÖÞµÄ×éÖ¯£¬ÌØÊâÊǹú¼Ò/¹«¹²ÊµÌåºÍ½ÌÓý»ú¹¹¡£
https://www.bleepingcomputer.com/news/security/vice-society-claims-ransomware-attack-on-med-university-of-innsbruck/
5¡¢Carnival CruisesÒòÊý¾Ýй¶ÊÂÎñ±»·£¿î125ÍòÃÀÔª
ýÌå6ÔÂ27Èճƣ¬Carnival CruisesÒò2019ÄêµÄÊý¾Ýй¶ÊÂÎñ±»·£¿î125ÍòÃÀÔª¡£¸ÃÊÂÎñÓÚ2019Äê5Ô±»·¢Ã÷£¬ÔÚ10¸öÔºóµÄ2020Äê3Ô²ű»Åû¶£¬Ð¹Â¶ÁË180000¸öÔ±¹¤ºÍ¿Í»§µÄÐÅÏ¢£¬Éæ¼°ÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢µØµã¡¢»¤ÕÕºÅÂë¡¢¼ÝʻִÕÕºÅÂë¡¢Ö§¸¶¿¨ÐÅÏ¢ºÍ¿µ½¡ÐÅÏ¢µÈ¡£Ë¾·¨²¿³¤Ö¸³ö£¬¸Ã¹«Ë¾½«Ð¡ÎÒ˽¼ÒÐÅÏ¢´æ´¢ÔÚµç×ÓÓʼþÖУ¬²¢Ê¹ÓÃÔÓÂÒÎÞÕµÄÒªÁìÀ´´¦Öóͷ£Ãô¸ÐÊý¾Ý£¬Ê¹Î¥¹æÍ¨Öª±äµÃÔ½·¢ÄÑÌâ¡£³ýÁ˾¼Ã´¦·ÖÍ⣬¸Ã¹«Ë¾»¹ÔÞ³ÉʵÑéÎ¥¹æÏìÓ¦ÍýÏ룬ΪԱ¹¤Öƶ©ÓʼþÅàѵÍýÏ룬½ÓÊÜ×ÔÁ¦µÄÐÅÏ¢Çå¾²ÆÀ¹ÀµÈ¡£
https://therecord.media/carnival-cruises-to-pay-1-25-million-fine-for-2019-data-breach/
6¡¢AMD³ÆÕýÔÚÊÓ²ìRansomHouseÇÔÈ¡Æä450GBÊý¾ÝµÄÊÂÎñ
ýÌå6ÔÂ28ÈÕ±¨µÀ£¬°ëµ¼Ì幫˾AMDÌåÏÖËûÃÇÕýÔÚÊÓ²ìRansomHouseÇÔÈ¡Æä450 GBÊý¾ÝµÄÊÂÎñ¡£ÔÚÒÑÍùµÄÒ»ÖÜÀRansomHouseÒ»Ö±ÔÚTelegramÉϳÆËûÃǽ«³öÊÛÒ»¼ÒÒÔ×ÖĸA¿ªÍ·µÄÖøÃûÈý×Öĸ¹«Ë¾µÄÊý¾Ý¡£6ÔÂ27ÈÕ£¬¸ÃÍŻォAMDÌí¼Óµ½ËûÃǵÄÊý¾ÝÐ¹Â¶ÍøÕ¾£¬Éù³ÆÇÔÈ¡ÁË450 GBµÄÊý¾Ý¡£RansomHouseÌåÏÖ£¬ËûÃǵÄÏàÖúͬ°éÔ¼Ò»ÄêǰÈëÇÖÁËAMDµÄÍøÂç¡£±»µÁÊý¾Ý°üÀ¨Ñо¿ºÍ²ÆÎñÐÅÏ¢£¬¹¥»÷Õß²¢Î´ÁªÏµAMDË÷ÒªÊê½ð£¬ÓÉÓÚ½«Êý¾Ý³öÊÛ¸øÆäËüʵÌå»ò¹¥»÷ÍÅ»ï¸üÓмÛÖµ¡£
https://www.bleepingcomputer.com/news/security/amd-investigates-ransomhouse-hack-claims-theft-of-450gb-data/


¾©¹«Íø°²±¸11010802024551ºÅ