ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ10ÖÜ

Ðû²¼Ê±¼ä 2019-03-11

±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2019Äê3ÔÂ04ÈÕÖÁ10ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´51¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇCisco NX-OS Software CLI CVE-2019-1610ÃüÁî×¢È멶´£»Google Chrome FileReaderÊͷźóʹÓôúÂëÖ´ÐЩ¶´; Adobe ColdFusion CVE-2019-7816ÎļþÉÏ´«ÏÞÖÆÈƹý©¶´£»Samsung Galaxy S9Éí·ÝÑéÖ¤´úÂëÖ´ÐЩ¶´£»Nokia Alcatel Lucent I-240W-Q GPON ONT CVE-2019-3922»º³åÇøÒç³ö©¶´¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇ΢ÈíÐû²¼Äþ¾²³ÂËßVolume 24 £¬2018ÄêµöÓã¹¥»÷Ôö³¤250£¥£»Ñо¿±íÃ÷2018Äê·¢Éú12449ÆðÊý¾Ýй¶Ê¼þ £¬±È2017ÄêÔö³¤424%£»Dalil¹«Ë¾MongoDB¿É¹ûÈ»·ÃÎÊ £¬500¶àÍòÓû§Êý¾Ýй¶£»2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾ÖÐ £¬WordPressÕ¼90%£»Ñо¿ÍŶӷ¢ÏÖ2Ô·ÝÀÕË÷Èí¼þShadeµÄ¹¥»÷»î¶¯ì­Éý¡£

ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖС£

ÖØÒªÄþ¾²Â©¶´Áбí


1. Cisco NX-OS Software CLI CVE-2019-1610ÃüÁî×¢È멶´
Cisco NX-OS Software CLIÑéÖ¤²ÎÊý´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíµ±µØ¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬ÌáÉýȨÏÞÖ´ÐÐÈÎÒâosÃüÁî¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-cmdinj-1610

2. Google Chrome FileReaderÊͷźóʹÓôúÂëÖ´ÐЩ¶´
Google Chrome FileReaderµÄʵÏÖ´æÔÚÊͷźóʹÓ鶴 £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴¹¹½¨¶ñÒâWEBÒ³ £¬ÓÕʹÓû§½âÎö £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html

3. Adobe ColdFusion CVE-2019-7816ÎļþÉÏ´«ÏÞÖÆÈƹý©¶´
Adobe ColdFusionÎļþÉÏ´«ÊµÏÖ´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬ÉÏ´«ÈÎÒâÎļþ £¬²¢Ö´ÐС£
https://helpx.adobe.com/security/products/coldfusion/apsb19-14.html

4. Samsung Galaxy S9Éí·ÝÑéÖ¤´úÂëÖ´ÐЩ¶´
Samsung Galaxy S9 GameServiceReceiver¸üлúÖÆ´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-19-255/

5. Nokia Alcatel Lucent I-240W-Q GPON ONT CVE-2019-3922»º³åÇøÒç³ö©¶´
Nokia Alcatel Lucent I-240W-Q GPON ONT´¦ÖÃÌØÊâµÄHTTP POSTÇëÇó´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.tenable.com/security/research/tra-2019-09

 ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢Î¢ÈíÐû²¼Äþ¾²³ÂËßVolume 24 £¬2018ÄêµöÓã¹¥»÷Ôö³¤250£¥

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ƾ¾Ý΢ÈíµÄÄþ¾²Ç鱨³ÂËߣ¨SIR£©Volume 24 £¬ÔÚ2018Äê1ÔÂÖÁ12ÔÂÆÚ¼ä £¬ÍøÂçµöÓã¹¥»÷Ôö³¤ÁË250%¡£¹¥»÷ÕßÔÚÔËÓªÍøÂçµöÓã»î¶¯Ê±½ÓÄɶàÑù»¯µÄ»ù´¡ÉèÊ© £¬°üÂÞÍйܷþÎñÆ÷ºÍ¹«¹²ÔƵÈ¡£ÁíÒ»·½Ãæ £¬2018ÄêÆÚ¼ä¶ñÒâÈí¼þµÄÊýÁ¿Ï½µÁËÔ¼34%¡£´ËÍâ £¬Ëæ×Å2018ÄêÄêÄ©¼ÓÃÜ»õ±Ò¼Û¸ñµÄϵø £¬¶ñÒâÍÚ¿ó»î¶¯Ò²Ï½µÁË36%¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-sees-250-percent-phishing-increase-malware-decline-by-34-percent/

2¡¢Ñо¿±íÃ÷2018Äê·¢Éú12449ÆðÊý¾Ýй¶Ê¼þ £¬±È2017ÄêÔö³¤424%

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÍþвÇ鱨¹«Ë¾4IQµÄÒ»·ÝгÂËß £¬2018ÄêÒÑÈ·ÈϵÄÊý¾Ýй¶Ê¼þµÄÊýÁ¿´ï12449Æ𠣬Óë2017ÄêÏà±ÈÔö³¤424% £¬ÆäÖÐ47%µÄʼþÓëÃÀ¹úºÍÖйúµÄ¹«Ë¾ÓйØ¡£¸Ã¹«Ë¾Í³¼ÆµÄÊÇÒÑÈ·ÈϵÄÊý¾Ýй¶Ê¼þ £¬ËäȻʼþµÄÊýÁ¿ÔÚ2018Äê´ó·ùÌáÉý £¬µ«Æ½¾ùй¶¹æÄ£ÔòϽµÖÁ216884Ìõ¼Ç¼ £¬±È2017ÄêҪС4.7±¶¡£´ËÍâ £¬2018ÄêÓÐ149ÒÚ±»µÁµÄԭʼÉí·Ý¼Ç¼ÔÚ°µÍøÉϽøÐÐÁ÷´« £¬µ«Ö»ÓÐ36ÒÚÊÇеĺÍÕæʵµÄ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/12-449-data-breaches-confirmed-in-2018-a-424-percent-increase-over-the-previous-year/

3¡¢Dalil¹«Ë¾MongoDB¿É¹ûÈ»·ÃÎÊ £¬500¶àÍòÓû§Êý¾Ýй¶

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


VPNMentorÑо¿ÍŶӷ¢ÏÖɳÌØ°¢À­²®Í¨ÐÅAPP DalilµÄMongoDBÊý¾Ý¿â¿É¹ûÈ»·ÃÎÊ £¬µ¼ÖÂÁè¼Ý500ÍòÓû§µÄ¸öÈËÐÅϢй¶¡£Dalilͨ¹ýÊÕ¼¯Óû§ÐÅÏ¢ £¬¿ÉÒÔ×ÊÖúÓû§Ê¶±ðδ֪µÄµç»°ºÅÂë £¬´Ó¶øÖÆֹɧÈŵ绰»òÍÆÏúµç»°µÈ¡£Ñо¿ÈËÔ±·¢ÏÖÆäMongoDBÊý¾Ý¿âδÉèÃÜÂë £¬ÕâÒâζÕß¹¥»÷ÕßÎÞÐèÉí·ÝÑéÖ¤¼´¿É·ÃÎÊÓû§µÄÊý¾Ý £¬°üÂÞÊÖ»úºÅÂë¡¢IPµØÖ·¡¢É豸Ðͺš¢ÐòÁкš¢²Ù×÷ϵͳ¡¢IMEI¡¢SIM¿¨ÐÅÏ¢¡¢GPSÐÅÏ¢ÒÔ¼°ÓÊÏäÕË»§¡¢ÐÕÃû¡¢ÐÔ±ðºÍÖ°ÒµµÈ¡£

Ô­ÎÄÁ´½Ó£º
https://www.vpnmentor.com/blog/dalil-data-breach/

4¡¢2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾ÖÐ £¬WordPressÕ¼90%

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝSucuriµÄÒ»·ÝÊÓ²ì³ÂËß £¬ÔÚ2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾µÄCMSÂþÑÜÖÐ £¬WordPressÒ£Ò£ÁìÏÈ £¬Õ¼90% £¬¶þÈýËÄÃû·Ö±ðÊÇMagento£¨4.6£¥£©¡¢Joomla£¨4.3£¥£©ºÍDrupal£¨3.7£¥£©¡£68%µÄÊÜѬȾÍøÕ¾±»Ö²ÈëÁ˺óÃÅ £¬56%µÄÊÜѬȾÍøÕ¾ÍйÜÁËÆäËü¶ñÒâÈí¼þ¡£´ËÍâ £¬51%µÄÊÜѬȾÍøÕ¾±»²¿ÊðÁËSEOÀ¬»øÐÅÏ¢Ò³Ãæ £¬2017ÄêÕâÒ»Êý×ÖÊÇ44%¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/wordpress-accounted-for-90-percent-of-all-hacked-cms-sites-in-2018/

5¡¢Ñо¿ÍŶӷ¢ÏÖ2Ô·ÝÀÕË÷Èí¼þShadeµÄ¹¥»÷»î¶¯ì­Éý

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Malwarebytes LabsÑо¿ÍŶӷ¢ÏÖÀÕË÷Èí¼þTroldesh£¨ÓÖÃûShade£©ÔÚ2018ÄêQ4µ½2019ÄêQ1ÆÚ¼äµÄ¼ì²âÊýÁ¿¼±¾çÔö¼Ó¡£Shadeͨ³£Í¨¹ýµöÓãÓʼþ½øÐÐÁ÷´« £¬Æ丽¼þÊÇ°üÂÞJavascript½Å±¾µÄzipÎļþ¡£ShadeµÄÖ÷Òª¹¥»÷Ä¿±êÊÇWindowsϵͳ £¬Æä½ÓÄÉAES 256 CBCËã·¨½øÐмÓÃÜ¡£²¿ÃÅShadeµÄ±äÖÖ´æÔÚÃâ·ÑµÄ½âÃܹ¤¾ß £¬Óû§¿ÉÔÚNoMoreRansom.orgÍøÕ¾ÉÏÕÒµ½ËüÃÇ¡£

Ô­ÎÄÁ´½Ó£º
https://blog.malwarebytes.com/threat-analysis/2019/03/spotlight-troldesh-ransomware-aka-shade/

ÉùÃ÷£º±¾×ÊѶÓɶ«É­Æ½Ì¨Î¬ËûÃüÄþ¾²Ð¡×é·­ÒëºÍÕûÀí