ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ10ÖÜ
Ðû²¼Ê±¼ä 2019-03-11±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇ΢ÈíÐû²¼Äþ¾²³ÂËßVolume 24£¬2018ÄêµöÓã¹¥»÷Ôö³¤250£¥£»Ñо¿±íÃ÷2018Äê·¢Éú12449ÆðÊý¾Ýй¶Ê¼þ£¬±È2017ÄêÔö³¤424%£»Dalil¹«Ë¾MongoDB¿É¹ûÈ»·ÃÎÊ£¬500¶àÍòÓû§Êý¾Ýй¶£»2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾ÖУ¬WordPressÕ¼90%£»Ñо¿ÍŶӷ¢ÏÖ2Ô·ÝÀÕË÷Èí¼þShadeµÄ¹¥»÷»î¶¯ìÉý¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
ÖØÒªÄþ¾²Â©¶´Áбí
Cisco NX-OS Software CLIÑéÖ¤²ÎÊý´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíµ±µØ¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÌáÉýȨÏÞÖ´ÐÐÈÎÒâosÃüÁî¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-cmdinj-1610
2. Google Chrome FileReaderÊͷźóʹÓôúÂëÖ´ÐЩ¶´
Google Chrome FileReaderµÄʵÏÖ´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴¹¹½¨¶ñÒâWEBÒ³£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html
3. Adobe ColdFusion CVE-2019-7816ÎļþÉÏ´«ÏÞÖÆÈƹý©¶´
Adobe ColdFusionÎļþÉÏ´«ÊµÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÉÏ´«ÈÎÒâÎļþ£¬²¢Ö´ÐС£
https://helpx.adobe.com/security/products/coldfusion/apsb19-14.html
4. Samsung Galaxy S9Éí·ÝÑéÖ¤´úÂëÖ´ÐЩ¶´
Samsung Galaxy S9 GameServiceReceiver¸üлúÖÆ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-19-255/
5. Nokia Alcatel Lucent I-240W-Q GPON ONT CVE-2019-3922»º³åÇøÒç³ö©¶´
Nokia Alcatel Lucent I-240W-Q GPON ONT´¦ÖÃÌØÊâµÄHTTP POSTÇëÇó´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.tenable.com/security/research/tra-2019-09
ÖØÒªÄþ¾²Ê¼þ×ÛÊö

ƾ¾Ý΢ÈíµÄÄþ¾²Ç鱨³ÂËߣ¨SIR£©Volume 24£¬ÔÚ2018Äê1ÔÂÖÁ12ÔÂÆڼ䣬ÍøÂçµöÓã¹¥»÷Ôö³¤ÁË250%¡£¹¥»÷ÕßÔÚÔËÓªÍøÂçµöÓã»î¶¯Ê±½ÓÄɶàÑù»¯µÄ»ù´¡ÉèÊ©£¬°üÂÞÍйܷþÎñÆ÷ºÍ¹«¹²ÔƵȡ£ÁíÒ»·½Ã棬2018ÄêÆÚ¼ä¶ñÒâÈí¼þµÄÊýÁ¿Ï½µÁËÔ¼34%¡£´ËÍ⣬Ëæ×Å2018ÄêÄêÄ©¼ÓÃÜ»õ±Ò¼Û¸ñµÄϵø£¬¶ñÒâÍÚ¿ó»î¶¯Ò²Ï½µÁË36%¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-sees-250-percent-phishing-increase-malware-decline-by-34-percent/
2¡¢Ñо¿±íÃ÷2018Äê·¢Éú12449ÆðÊý¾Ýй¶Ê¼þ£¬±È2017ÄêÔö³¤424%
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/12-449-data-breaches-confirmed-in-2018-a-424-percent-increase-over-the-previous-year/
3¡¢Dalil¹«Ë¾MongoDB¿É¹ûÈ»·ÃÎÊ£¬500¶àÍòÓû§Êý¾Ýй¶
ÔÎÄÁ´½Ó£º
https://www.vpnmentor.com/blog/dalil-data-breach/
4¡¢2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾ÖУ¬WordPressÕ¼90%
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/wordpress-accounted-for-90-percent-of-all-hacked-cms-sites-in-2018/
5¡¢Ñо¿ÍŶӷ¢ÏÖ2Ô·ÝÀÕË÷Èí¼þShadeµÄ¹¥»÷»î¶¯ìÉý
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/threat-analysis/2019/03/spotlight-troldesh-ransomware-aka-shade/
ÉùÃ÷£º±¾×ÊѶÓɶ«Éƽ̨άËûÃüÄþ¾²Ð¡×é·ÒëºÍÕûÀí