΢ÈíSMBv3È䳿¼¶0day£¨CVE-2020-0796£©£»£»£»£»£»£»Å·ÖÞµçÁ¦ÔËÓªÉÌͬÃËENTSO-E°ì¹«ÍøÂçÔâºÚ¿ÍÈëÇÖ
Ðû²¼Ê±¼ä 2020-03-111.΢ÈíSMBv3È䳿¼¶0day£¨CVE-2020-0796£©£¬£¬£¬£¬£¬£¬ÉÐÎÞÐÞ¸´²¹¶¡
΢ÈíSMBv3È䳿¼¶0day£¨CVE-2020-0796£©µÄÐÅÏ¢ÔÚÍøÉÏÒâÍâй¶£¬£¬£¬£¬£¬£¬ÏÖÔÚÉÐδÐû²¼¸ÃÎó²îµÄÈκÎÊÖÒÕϸ½Ú£¬£¬£¬£¬£¬£¬µ«Cisco TalosºÍFortinetµÄÍøÕ¾ÉÏÒÑÐû²¼Á˸ÃÎó²îµÄ¼ò¶Ì¸ÅÊö¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îδ°üÀ¨ÔÚ3ÔµÄÇå¾²¸üÐÂÖУ¬£¬£¬£¬£¬£¬²¢ÇÒÉв»ÇåÎúºÎʱÐÞ¸´¡£¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤FortinetµÄ˵·¨£¬£¬£¬£¬£¬£¬¸ÃÎó²î±»ÐÎòΪ¡°Microsoft SMBЧÀÍÆ÷ÖеĻº³åÇøÒç³öÎó²î¡±£¬£¬£¬£¬£¬£¬²¢»ñµÃÁË×î¸ßÑÏÖØÆ·¼¶£¬£¬£¬£¬£¬£¬¡°Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚÓ¦ÓóÌÐòµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£¡±Ë¼¿ÆTalosÌåÏÖ¸ÃÎó²îʹϵͳÒ×Ôâ¡°È䳿»¯¡±¹¥»÷£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅÔÚÊܺ¦ÕßÖ®¼äµÄ×ªÒÆºÜÈÝÒס£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î½öÓ°ÏìSMBv3£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄϵͳ°üÀ¨Windows 10 v1903¡¢Windows 10 v1909¡¢Windows Server v1903ºÍWindows Server v1909¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/details-about-new-smb-wormable-bug-leak-in-microsoft-patch-tuesday-snafu/
2.Å·ÖÞµçÁ¦ÔËÓªÉÌͬÃËENTSO-E°ì¹«ÍøÂçÔâºÚ¿ÍÈëÇÖ
Å·ÖÞµçÁ¦ÔËÓªÉÌͬÃË£¨ENTSO-E£©ÔÚÒ»·Ý¼ò¶ÌµÄÉùÃ÷ÖÐÌåÏÖ£¬£¬£¬£¬£¬£¬½üÆÚÆä°ì¹«ÍøÂçÔâµ½ºÚ¿ÍÈëÇÖ¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ¸Ã°ì¹«ÍøÂ粢δÅþÁ¬µ½ÈκÎÔËÓªÖеĵçÁ¦´«Êäϵͳ£¬£¬£¬£¬£¬£¬ÕâÒâζ׏¥»÷½öÏÞÓÚITϵͳ£¬£¬£¬£¬£¬£¬Ã»ÓÐÓ°ÏìÒªº¦¿ØÖÆÏµÍ³¡£¡£¡£¡£¡£¡£¡£¡£ENTSO-E×ܲ¿Î»ÓÚ²¼Â³Èû¶û£¬£¬£¬£¬£¬£¬ÓÉ35¸öÅ·ÖÞ¹ú¼ÒµÄ42¼ÒµçÍøÔËÓªÉÌ×é³É¡£¡£¡£¡£¡£¡£¡£¡£ENTSO-EÌåÏÖÒѾ¾ÙÐÐÁËΣº¦ÆÀ¹ÀºÍÖÆ¶©ÁËÓ¦¼±ÍýÏ룬£¬£¬£¬£¬£¬ÒÔïÔ̽øÒ»²½¹¥»÷µÄΣº¦ºÍÓ°Ï죬£¬£¬£¬£¬£¬µ«Ã»ÓÐ͸¶ÓëÈëÇÖºÎʱ×îÏÈÒÔ¼°Ë¿ÉÄܶԹ¥»÷ÈÏÕæÓйصÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cyberscoop.com/european-entso-breach-fingrid/
3.¶ñÒâÈí¼þбäÖÖ¿ÉÈÆ¹ýChrome 80ÖеÄcookie¼ÓÃÜËã·¨
¹È¸èÓÚ2Ô³õÍÆ³öÁËChrome 80£¬£¬£¬£¬£¬£¬²¢ÔÚÆäÖжÔcookieºÍÃÜÂëÌí¼ÓÁËAES-256¼ÓÃÜËã·¨¾ÙÐб£»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬ÏÖÔÚÒÑÓÐÖÁÉÙËĸö¶ñÒâÈí¼þÍÆ³öÁË¿ÉÈÆ¹ý¸Ã¼ÓÃܵÄбäÖÖ£¬£¬£¬£¬£¬£¬°üÀ¨ÐÅÏ¢ÇÔȡľÂíKPot¡¢Raccoon¡¢RedlineÒÔ¼°AZORult¡£¡£¡£¡£¡£¡£¡£¡£ÔÚChrome 80֮ǰ£¬£¬£¬£¬£¬£¬cookieºÍÃÜÂë¶¼ÊÇͨ¹ýWindows DPAPI¾ÙÐмÓÃÜ£¬£¬£¬£¬£¬£¬ÔÚChrome 80Ö®ºó£¬£¬£¬£¬£¬£¬Êý¾ÝÊ×ÏÈͨ¹ýAES¼ÓÃÜ£¬£¬£¬£¬£¬£¬È»ºóʹÓÃCrypProtectData DPAPI¶ÔÃÜÔ¿¾ÙÐмÓÃÜ£¬£¬£¬£¬£¬£¬Òò´Ë¿Éͨ¹ýCryptUnprotectDataÄæ×ª¸ÃÀú³Ì»ñµÃAES-256µÄÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/malware-unfazed-by-google-chromes-new-password-cookie-encryption/
4.¹¥»÷ÕßʹÓÃÒøÐÐľÂíGeost¹¥»÷¶íÂÞ˹½ðÈÚ»ú¹¹
Ç÷ÊÆ¿Æ¼¼Çå¾²Ñо¿Ö°Ô±ÊӲ쵽¹¥»÷ÕßʹÓÃÒøÐÐľÂíGeost¹¥»÷¶íÂÞ˹½ðÈÚ»ú¹¹¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÖ÷ÒªÒÀÀµ´øÓÐËæ»úÌìÉúµÄЧÀÍÆ÷Ö÷»úÃûµÄ·Ç¹Ù·½ÍøÒ³À´·Ö·¢¸ÃÒøÐÐľÂí£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷»î¶¯Ö÷ÒªÕë¶ÔÎÞ·¨»á¼ûGoogle PlayÊÐËÁµÄAndroidÓû§ÒÔ¼°ÄÇЩÇãÏòÓÚËÑË÷Google¹Ù·½AndroidÊг¡Éϲ»¿ÉÓÃAPPµÄÓû§¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÃûΪ¡°§å§ã§ä§Ñ§ß§à§Ó§Ü§Ñ¡±£¨¶íÓï¡°ÉèÖá±£©£¬£¬£¬£¬£¬£¬Ê¹ÓÃGoogle Play logoÓÕʹÓû§ÏÂÔØºÍ×°Ö㬣¬£¬£¬£¬£¬ËüÒªÇóÊܺ¦ÕßÊÚÓèÆäÖÎÀíÔ±ÌØÈ¨£¬£¬£¬£¬£¬£¬°üÀ¨»á¼ûSMS¶ÌÐŵÄÄÜÁ¦ÒÔ´Ó¶íÂÞË¹ÒøÐÐЧÀÍÎüÊÕÈ·È϶ÌÐÅ¡£¡£¡£¡£¡£¡£¡£¡£GeostÊ״ηºÆðÓÚ2019Äê10Ô£¬£¬£¬£¬£¬£¬Æäʱ¸ÃľÂíѬȾÁËÁè¼Ý80ÍòÃûÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityintelligence.com/news/geost-banking-trojan-targets-russian-banks-via-unofficial-webpages/?web_view=true
5.˼¿ÆTalosÅû¶WAGO e!COCKPITÖеĶà¸öÎó²î
˼¿ÆTalosÅû¶WAGO e!COCKPIT²úÆ·ÖеĶà¸öÎó²î¡£¡£¡£¡£¡£¡£¡£¡£e!COCKPITÊÇÒ»¸ö¼¯³É¿ª·¢ÇéÐΣ¬£¬£¬£¬£¬£¬Ö¼ÔÚ¼ÓËÙ×Ô¶¯»¯Ê¹ÃüÒÔ¼°»úеºÍÏîÄ¿µÄÆô¶¯ËÙÂÊ¡£¡£¡£¡£¡£¡£¡£¡£e!COCKPITÈí¼þÓë²î±ðµÄ×Ô¶¯»¯¿ØÖÆÆ÷£¨°üÀ¨PFC100ºÍPFC200£©±£´æ½Ó¿Ú£¬£¬£¬£¬£¬£¬ËüÃÇÖеÄÎó²îÔÊÐíÔ¶³Ì¹¥»÷Õß¾ÙÐÐÖÖÖÖ¶ñÒâ»î¶¯£¬£¬£¬£¬£¬£¬°üÀ¨ÏÂÁî×¢Èë¡¢ÐÅϢй¶ºÍÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£ÍêÕûÎó²îºÍÊÜÓ°Ïì¹Ì¼þ°æ±¾ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2020/03/wago-vulnerability-spotlight-march-2020.html
6.ÃÀComcast Xfinityй¶½ü20Íò¸¶·Ñ¿Í»§ÐÅÏ¢
ÃÀ¹úComcast XfinityÔÚ¹«Ë¾µÄÔÚÏßĿ¼ÖÐй¶Á˽ü20Íò¿Í»§µÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ¿Í»§ÏòComcast XfinityÖ§¸¶ÁËÓöȣ¬£¬£¬£¬£¬£¬ÒÔ½«ÆäÐÕÃû¡¢µç»°ºÅÂëºÍµØµãµÈСÎÒ˽¼ÒÏêϸÐÅÏ¢´æ´¢ÔÚ¹«¹²Êý¾Ý¿âÖ®Í⣬£¬£¬£¬£¬£¬µ«ComcastÔÚÆäecolisting.comÍøÕ¾ÉÏÕÕ¾ÉÁгöÁËËûÃǵÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ComcastÔÚ2ÔÂ5ÈÕÌåÏÖ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚÒâʶµ½¹ýʧºóÁ¬Ã¦É¾³ýÁËÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬²¢ÇÒÕâЩÐÅÏ¢ÔÚÍøÉÏ̻¶µÄʱ¼äСÓÚÒ»¸öÔ¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ¸ÃÍøÕ¾ÏÔʾXfinityÓïÒôЧÀͽ«²»ÔÙÌṩĿ¼ÁÐ±í¹¦Ð§¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.grahamcluley.com/comcast-xfinity-200000-customers-privacy/


¾©¹«Íø°²±¸11010802024551ºÅ