µ¤Âó˰ÎñЧÀÍй¶120Íò¹«ÃñµÄCPRºÅÂ룻£»DellÐÞ¸´SupportAssistÖеIJ»¿ÉÐÅËÑË÷·¾¶Îó²î

Ðû²¼Ê±¼ä 2020-02-11

1.µ¤Âó˰ÎñЧÀÍй¶120Íò¹«ÃñµÄCPRºÅÂë


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


µ¤ÂóÕþ¸®·¢Ã÷TastSelv Borger˰ÎñЧÀÍй¶ÁË120Íò¹«ÃñµÄCPR£¨µ¤ÂóÉí·ÝÖ¤¼þ£©ºÅÂë¡£¡£¡£¡£¡£¸ÃЧÀÍÓÉÃÀ¹úDXC Technology¹«Ë¾ÖÎÀí£¬£¬£¬£¬£¬ÔÊÐíµ¤Âó¹«ÃñÉó²éºÍ¸ü¸ÄÆäÄÉ˰É걨±í¡¢Äê¶È±¨±í²¢½ÉÄÉÊ£Óà˰¿î¡£¡£¡£¡£¡£ÔÚ·¢Ã÷֮ǰ£¬£¬£¬£¬£¬°üÀ¨CPRºÅÔÚÄÚµÄÊý¾ÝÒÑ̻¶ÁË¿ìÒªÎåÄêµÄʱ¼ä¡£¡£¡£¡£¡£DR NewsÍøÕ¾±¨¸æ³Æ£¬£¬£¬£¬£¬Ò»µ©µÇ¼Tastselv BorgerµÄÓû§¸üÕýÁËËûÃǵÄÁªÏµÐÅÏ¢£¬£¬£¬£¬£¬Ó¦ÓóÌÐòÖеĹýʧ¾Í»áµ¼ÖÂCPRºÅ×÷ÎªÍøÖ·µÄÒ»²¿·Ö·¢Ë͵½GoogleºÍAdobe¡£¡£¡£¡£¡£DXCÒÑÈ·ÈϸÃÎó²î²¢Òѽâ¾ö¸ÃÎÊÌâ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/97571/data-breach/1-2m-cpr-numbers-leak.html


2.ÒÔÉ«ÁÐÇå¾²²½¶Ó½ü3¸öÔÂÄÚÊܵ½10000´ÎÍøÂç¹¥»÷


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


¾ÝÏ£²®À´ÓïÐÂÎÅÍøÕ¾YnetÖÜÈÕ±¨µÀ£¬£¬£¬£¬£¬ÔÚÒÑÍùµÄÈý¸öÔÂÖУ¬£¬£¬£¬£¬ÒÔÉ«ÁÐÇå¾²²½¶ÓµÄÊ®¸öÖ÷ÒªÍøÕ¾³ÉΪÁË10000¶àÆðÍøÂç¹¥»÷µÄÄ¿µÄ¡£¡£¡£¡£¡£¸ÃÊý¾ÝÊÇ»ùÓÚÒÔÉ«ÁÐ-ÃÀ¹úÍøÂçÇå¾²¹«Ë¾ImpervaµÄ±¨¸æ£¬£¬£¬£¬£¬±¨¸æÖл¹ÏÔʾÁíÍâÔ¼40¸öÒÔÉ«ÁÐÖ´·¨ºÍÕþ¸®ÍøÕ¾Ôâµ½ÁËÊýǧ´ÎÒÔÉϵÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£ÒÔÉ«Áйú¼ÒÍøÂçÖÎÀí¾Ö³ÆÕþ¸®ÍøÕ¾Êܵ½¸ß¶ÈÏȽøµÄ·ÀÓùϵͳµÄ±£»£»¤£¬£¬£¬£¬£¬ÕâЩ¹¥»÷¶ÔÆäûÓÐÓ°Ïì¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.xinhuanet.com/english/2020-02/10/c_138768894.htm


3.¹¥»÷ÕßʹÓÃÃâ·ÑÈí¼þLock My PCËø¶¨Óû§ÅÌËã»ú


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÊÖÒÕÖ§³ÖÕ©Æ­ÕßʹÓÃÃûΪLock My PCµÄÃâ·Ñ¹¤¾ßÀ´Ëø¶¨Óû§µÄÅÌËã»ú£¬£¬£¬£¬£¬²¢ÒªÇóÖ§¸¶½âËøÓöÈ¡£¡£¡£¡£¡£¶àÄêÀ´Î±×°³É΢Èí¡¢¹È¸èµÈ¹«Ë¾µÄÊÖÒÕÖ§³ÖÕ©Æ­ÕßÒ»Ö±ÔÚʹÓÃWindows Syskey³ÌÐò½«Óû§µÄÏµÍ³Ëø¶¨£¬£¬£¬£¬£¬µ«ÓÉÓÚ΢ÈíÔÚWindows 10 1709ÖÐɾ³ýÁ˶ÔSyskeyµÄËùÓÐÖ§³Ö£¬£¬£¬£¬£¬Òò´ËÕ©Æ­ÕßÒÑÇл»µ½Lock My PC¡£¡£¡£¡£¡£ÓëSyskey¼ÓÃÜWindows SAMÊý¾Ý¿â²¢Ê¹ÓÃÊäÈëµÄÃÜÂë¶ÔÆä¾ÙÐнâÃܲî±ð£¬£¬£¬£¬£¬Lock My PC²»¼ÓÃÜÈκÎÄÚÈÝ£¬£¬£¬£¬£¬½öʹÓÃÃÜÂë×èÖ¹¶ÔÅÌËã»úµÄ»á¼û¡£¡£¡£¡£¡£¸ÃÈí¼þ»¹ÒÔÇ徲ģʽÔËÐУ¬£¬£¬£¬£¬Ê¹µÃûÓÐÃÜÂë»òboot»Ö¸´¹¤¾ßʱºÜÄѽûÓÃËü¡£¡£¡£¡£¡£Lock My PCµÄ¿ª·¢Ö°Ô±FSPro Labs·¢Ã÷ÆäÈí¼þ±»ÀÄÓúóÐû²¼²»ÔÙÌṩÃâ·Ñ°æ±¾£¬£¬£¬£¬£¬²¢ÇÒΪÊܺ¦ÕßÌṩÁËÃâ·ÑµÄ»Ö¸´ÃÜÂë¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/lock-my-pc-used-by-tech-support-scammers-dev-offers-free-recovery/


4.Â׶عú¼ÒФÏñ»­ÀÈÔÚ2019ÄêQ4Ôâµ½½ü35Íò·âÀ¬»øÓʼþ¹¥»÷


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ƾ֤Ӣ¹úÐÅÏ¢×ÔÓÉ·¨°¸Åû¶µÄÊý¾Ý£¬£¬£¬£¬£¬Parliament StreetÖǿⷢÃ÷Â׶عú¼ÒФÏñ»­ÀÈÔÚ2019ÄêµÚËÄÐò¶ÈÔâµ½½ü35Íò´ÎÀ¬»øÓʼþ¹¥»÷¡£¡£¡£¡£¡£¹ú¼ÒФÏñ»­ÀÈÊÇÂ×¶Ø×ʢÃûµÄÃÀÊõ¹ÝÖ®Ò»£¬£¬£¬£¬£¬Ã¿Äê½Ó´ý110ÍòÖÁ120ÍòÓοÍ£¬£¬£¬£¬£¬ÆäЧÀÍÆ÷´æ´¢ÁËÐí¶àÓο͵ĸ¶¿îÃ÷ϸºÍµç×ÓÓʼþµØµãµÈ˽ÈËÐÅÏ¢¡£¡£¡£¡£¡£ÔÚÕâ½ü35Íò·â±»×èÖ¹µÄÀ¬»øÓʼþÖУ¬£¬£¬£¬£¬ÓÐ56%±»Ê¶±ðΪÕʺÅÍøÂç¹¥»÷£¬£¬£¬£¬£¬ÁíÍâ61710·âÊÇÓÉÓÚ·¢¼þÈËÔÚ¡°ÍþвÇ鱨ºÚÃûµ¥¡±É϶ø±»×èÖ¹£¬£¬£¬£¬£¬ÉÐÓÐ85793·â±»ÒÔΪ°üÀ¨À¬»øÓʼþÄÚÈÝÒÔ¼°418·â°üÀ¨²¡¶¾¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/national-portrait-gallery-email


5.¼ÓÃÜÉúÒâËùAltsbitÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬½«ÓÚ5ÔÂ8ÈչرÕ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


¾Ý±¨µÀ£¬£¬£¬£¬£¬×ܲ¿Î»ÓÚÒâ´óÀûµÄ¼ÓÃÜÇ®±ÒÉúÒâÆ½Ì¨AltsbitÌåÏÖÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬ÏÕЩËùÓÐBTC¡¢ETH¡¢ARRRºÍVRSC×ʽ𶼱»µÁ£¬£¬£¬£¬£¬Ö»ÓÐһС²¿·Ö·ÅÔÚÀäÇ®°üÖеÄ×ʽðÊÇÇå¾²µÄ¡£¡£¡£¡£¡£×èÖ¹·¢¸åʱ£¬£¬£¬£¬£¬ËðʧµÄBTCºÍETHµÄ¼ÛֵԼΪ6.3ÍòÃÀÔª¡£¡£¡£¡£¡£¸ÃÉúÒâËùÌåÏÖûÓÐ×ã¹»µÄ×ʽðÀ´Åâ³¥Óû§£¬£¬£¬£¬£¬Òò´ËÒªÇóÓû§ÉêÇ벿·ÖÍ˿¡£¡£¡£¡£ÍË¿îʱ¼äΪ2ÔÂ10ÈÕµ½5ÔÂ8ÈÕ£¬£¬£¬£¬£¬ÔÚÕâÌìÆÚÖ®ºó¸ÃÉúÒâËù½«¹Ø±Õ¡£¡£¡£¡£¡£ºÚ¿Í×éÖ¯LulzSecÔÚTwitterÖÐÉù³Æ¶Ô´ËÊÂÎñÈÏÕæ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.coindesk.com/new-crypto-exchange-altsbit-says-it-will-close-following-hack


6.DellÐÞ¸´SupportAssistÖеIJ»¿ÉÐÅËÑË÷·¾¶Îó²î


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


DellÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´SupportAssist ClientÈí¼þÖеÄÒ»¸ö²»¿ÉÐÅËÑË÷·¾¶Îó²î£¬£¬£¬£¬£¬¸ÃÎó²î£¨CVE-2020-5316£©ÔÊÐíDZÔÚµÄÍâµØ¹¥»÷ÕßÔÚÒ×Êܹ¥»÷µÄÅÌËã»úÉÏÒÔÖÎÀíԱȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£SupportAssistÊÇԤװÖÃÔÚ´ó´ó¶¼DellÉè±¹ØÁ¬ÄÖ§³ÖÈí¼þ£¬£¬£¬£¬£¬Òò´Ë¸ÃÎó²îµÄDZÔÚÓ°Ïì¹æÄ£½Ï¹ã¡£¡£¡£¡£¡£Æ¾Ö¤DellµÄÎó²îת´ï£¬£¬£¬£¬£¬¾­ÓÉÍâµØÉí·ÝÑéÖ¤µÄµÍÌØÈ¨Óû§¿ÉÄÜʹÓôËÎó²îµ¼ÖÂSupportAssist¶þ½øÖÆÎļþ¼ÓÔØí§ÒâDLL£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÌØÈ¨´úÂëµÄÖ´ÐС£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSv3»ù±¾µÃ·ÖΪ7.8·Ö£¬£¬£¬£¬£¬Ó°ÏìÁËÉÌÓÃPCµÄSupportAssist 2.1.3»ò¸üÔç°æ±¾£¬£¬£¬£¬£¬ÒÔ¼°¼ÒÓÃPCµÄSupportAssist 3.4»ò¸üÔç°æ±¾¡£¡£¡£¡£¡£DellÒѾ­ÔÚа汾ÖÐÐÞ¸´Á˸ÃÎó²î£¬£¬£¬£¬£¬ÈôÊÇÆôÓÃÁË×Ô¶¯Éý¼¶£¬£¬£¬£¬£¬ÔòËùÓа汾µÄSupportAssist¶¼»á×Ô¶¯×°ÖÃ×îп¯Ðеİ汾¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/dell-supportassist-bug-exposes-business-home-pcs-to-attacks/