ÃÀ¹úColonialPipelineѬȾÀÕË÷Èí¼þ£¬Ö÷ÒªÊäÓ͹ÜÍ£ÔË £»AMD SCSIAdapterÇý¶¯¸üпɵ¼ÖÂWin10ϵͳÍß½â

Ðû²¼Ê±¼ä 2021-05-10

1.ÃÀ¹úColonial PipelineѬȾÀÕË÷Èí¼þ£¬Ö÷ÒªÊäÓ͹ÜÍ£ÔË


1.jpg


ÃÀ¹ú×î´óµÄȼÁϹܵÀ¹«Ë¾Colonial PipelineÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬5500Ó¢ÀïÊäÓ͹ÜÍ£ÔË ¡£Colonial PipelineÿÌì´ÓµÂ¿ËÈøË¹ÖÝÊäËÍ250ÍòͰʯÓ͵½¶«º£°¶ºÍŦԼ£¬¸Ã¹ÜµÀÁýÕÖÁËÃÀ¹ú¶«º£°¶45£¥µÄȼÁϹ©Ó¦ ¡£¸Ã¹«Ë¾ÔÚÉÏÖÜÁùÌåÏÖ£¬ÆäÓÚ5ÔÂ7ÈÕÔâµ½ÀÕË÷¹¥»÷£¬·¢ÏÖ¹¥»÷ºóÖ÷¶¯¹Ø±ÕÁËÒªº¦µÄϵͳÒÔÖÆÖ¹Á÷´«£¬Ä¿Ç°ÕýÓëÄþ¾²¹«Ë¾ºÏ×÷¶Ô¸ÃʼþµÄÐÔÖʺͷ¶Î§½øÐÐÊÓ²ì ¡£ÃÀ¹úµÄij¹ÙÔ±³Æ£¬´Ë´ÎÀÕË÷¹¥»÷ʼþÓëDarkSideÍÅ»ïÓйØ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/largest-us-pipeline-shuts-down-operations-after-ransomware-attack/


2.·¨¹úЬÀàºÍÊÎÆ·¹«Ë¾VejaÔâµ½¹¥»÷£¬Óû§ÐÅϢй¶


2.jpg


Damien Licata Caruso³ÂË߳ƣ¬Veja¹«Ë¾ÔÚ4ÔÂ26ÈÕÔâµ½¹¥»÷£¬Óû§ÐÅϢй¶ ¡£VejaÊǵ퍹úЬÀàºÍÊÎÆ·Æ·ÅÆ£¬Ö÷ÒªÒÔÆä»·±£Ô˶¯Ð¬¶øÎÅÃû ¡£´Ë´Îʼþй¶ÁË2004Äê´´½¨µÄ°üÂÞ¿Í»§ÐÅÏ¢Êý¾Ý¿â£¬Éæ¼°ÔÚÏß¹ºÖûò¶©ÔÄVejaÐÂÎŵĿͻ§µÄÓʼþµØÖ·µÈÐÅÏ¢ ¡£¸ÃÆ·ÅÆµÄÊ×´´ÈËS¨¦bastienKopp³Æ´Ë´Î²¢Î´Ð¹Â¶ÓйØÒøÐеÄÏêϸÐÅÏ¢£¬¶øÇÒËùÓÐÃÜÂë¶¼±»¼ÓÃܵÄ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/fr-eco-friendly-sneaker-brand-veja-hacked/


3.´ó»ªÒøÐÐÒòÆäÔ±¹¤Ô⵽թƭй¶ǧÓàÖйú¹«ÃñµÄÐÅÏ¢


3.jpg


ÐÂ¼ÓÆÂ´ó»ªÒøÐУ¨UOB£©ÒòÆäÔ±¹¤Ô⵽թƭй¶ǧÓàÖйú¹«ÃñµÄÐÅÏ¢ ¡£¾ÝϤ£¬¸ÃÔ±¹¤±»Ã°³äΪÖйú¾¯·½µÄÆ­¾ÖËùÆÛÆ­£¬Ð¹Â¶ÁË1166ÃûÖйú¹«ÃñµÄ¸öÈËÏêϸÐÅÏ¢£¬°üÂÞ¿Í»§µÄÐÕÃû¡¢Éí·ÝÖ¤¡¢ÊÖ»úºÅÂëÒÔ¼°ÕË»§Óà¶îµÈ ¡£´ó»ªÒøÐÐÌåÏÖ£¬²¢Ã»Óпͻ§µÄÒøÐÐÕʺÅй¶£¬¶øÇÒÆäITϵͳÈÔÈ»ÊÇÄþ¾²µÄ ¡£Ä¿Ç°£¬¸ÃÔ±¹¤Òѱ»Í£Ö°£¬²¢ÕýÔÚЭÖú¾¯·½¶Ô´ËʽøÐÐÊÓ²ì ¡£


Ô­ÎÄÁ´½Ó£º

https://mothership.sg/2021/05/uob-employee-leak-customers-scam/


4.AMD SCSIAdapterÇý¶¯¸üпɵ¼ÖÂWindows 10ϵͳÍß½â


4.jpg


AMD SCSIAdapterÇý¶¯¸üпɵ¼ÖÂWindows 10ϵͳÍ߽⠡£Ðí¶àÓû§³ÂËߣ¬ÔÚ°²×°¸ÃÇý¶¯Ê±»á±»ÌáÊ¾ÖØÆôϵͳ£¬È»ºó·ºÆðÀ¶ÆÁËÀ»ú(BSOD)µÄÎÊÌ⣬²¢ÏÔʾ¡°²»ÐзÃÎÊµÄÆô¶¯É豸¡±£¨INACCESSIBLE_BOOT_DEVICE£©µÄ´íÎóÌáʾ ¡£Windows LatestÌåÏÖ£¬Ä¿Ç°¸ÃÎÊÌâËÆºõ½öÓ°ÏìijЩAMDÓ²¼þƽ̨£¬ÓÈÆäÊÇʹÓÃÁ˼¼¼ÎX570Ö÷°åµÄ¼ÆËã»ú ¡£Ä¿Ç°£¬Î¢ÈíÒÑ´ÓWindows UpdateÖÐÒÆ³ýÁ˸øüР¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-pulls-windows-10-amd-driver-causing-pcs-not-to-boot/


5.CISA¡¢NCSC¡¢FBIÓëNSAÁªºÏÐû²¼ÓйضíÂÞ˹SVRµÄ×Éѯ


5.jpg


CISAÓëÓ¢¹ú¹ú¼ÒÍøÂçÄþ¾²ÖÐÐÄ£¨NCSC£©¡¢Áª°îÊÓ²ì¾Ö£¨FBI£©ºÍ¹ú¼ÒÄþ¾²¾Ö£¨NSA£©ÁªºÏÐû²¼ÓйضíÂÞ˹SVRµÄÄþ¾²×Éѯ ¡£¸Ã×Éѯָ³öSVRËÆºõÒÑͨ¹ý¸ü¸ÄÆä¼¼ÊõºÍ·¨Ê½£¨TTP£©£¬À´ÖÆÖ¹×éÖ¯·¢ÏÖÆä»î¶¯ºÍ½ÓÄɵ÷Í£´ëÊ© ¡£´ËÍ⣬SVRÖ÷ÒªÕë¶ÔÕþ¸®¡¢Öǿ⡢Õþ²ßºÍÄÜÔ´Ïà¹ØµÄ×éÖ¯£¬ÒÔ¼°ÓÐʱЧÐÔµÄÄ¿±ê£¬ÀýÈç2020ÄêÓëCOVID-19ÒßÃçÏà¹ØµÄ×éÖ¯ ¡£ºÚ¿ÍÖ÷ҪʹÓÃÁËCVE-2018-13379¡¢CVE-2019-1653ºÍCVE-2019-2725µÈ11¸ö©¶´ ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/05/07/joint-ncsc-cisa-fbi-nsa-cybersecurity-advisory-russian-svr


6.Ñо¿ÍŶӷ¢ÏÖWordPress CleanTalk´æÔÚSQL×¢Èë©¶´


6.jpg


WordfenceÍŶÓÅû¶WordPress²å¼þCleanTalk´æÔÚSQL×¢Èë©¶´ ¡£¸Ã²å¼þ¾ßÓÐÀ¬»øÓʼþ·À»¤¡¢·´À¬»øÓʼþºÍ·À»ðǽµÈ¹¦Ð§£¬¿ÉÒÔ¹ýÂ˵ôWordPress CMSÍøÕ¾ÉϵÄÀ¬»øÓʼþºÍÆÀÂÛ ¡£¸Ã©¶´×·×ÙΪCVE-2021-24295£¬ÊÇ»ùÓÚʱ¼äµÄSQLäע©¶´£¬¹¥»÷Õß¿ÉÀûÓôË©¶´À´·ÃÎÊÓû§µÄµç×ÓÓʼþ¡¢ÃÜÂë¡¢ÐÅÓÿ¨Êý¾ÝºÍÆäËûÃô¸ÐÐÅÏ¢ ¡£Ä¿Ç°£¬¸Ã©¶´ÒÑͨ¹ý°æ±¾5.153.4½â¾ö ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/117721/security/anti-spam-wordpress-plugin-flaw.html