¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190109
°ä²¼¹¦·ò 2019-01-09
2019ÄêµÄµÚÒ»¸öWindows°²È«¸üй²½¨¸´ÁË51¸ö·ì϶£¬£¬£¬£¬£¬³ÁÒªµÄ·ì϶Ô̺¬£ºDHCP¿Í»§¶ËËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2019-0547£©¡¢Hyper-VÐé¹¹»úÌÓÒÝ·ì϶£¨CVE-2019-0550ºÍCVE-2019-0551£©¡¢Skype for AndroidÖеÄËøÆÁÃÜÂëÈÆ¹ý·ì϶£¨CVE-2019-0622£©ÒÔ¼°Êý¾Ý¿âÒýÇæJetÖеÄRCE·ì϶£¨CVE-2019-0579£©µÈ¡£¡£¡£¡£¡£¡£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-january-2019-patch-tuesday-includes-51-security-updates/2¡¢Î¢Èí°ä·¢GitHubÃâÓöȻ§ÏÖ¿ÉÎÞÏÞ´´½¨Ë½Óд洢¿â
΢Èí°ä·¢GitHubÃâÓöȻ§´Ë¿ÌÄܹ»´´½¨ÎÞÏÞÁ¿µÄ¸öÈË´æ´¢¿â£¬£¬£¬£¬£¬ÔÚ´Ë֮ǰ£¬£¬£¬£¬£¬ÈôÊÇÄãÏë´´½¨¸öÈË´æ´¢¿â£¬£¬£¬£¬£¬ÄÇôÿÔÂÖÁÉÙ±ØÒªÖ§¸¶7ÃÀÔªµÄÓöȡ£¡£¡£¡£¡£¡£´Ë¿ÌGitHubÃâÓöȻ§´´½¨µÄ¸öÈË´æ´¢¿â×î¶àÄܹ»Õ¼ÓÐ3ÃûºÏ×÷Õߣ¬£¬£¬£¬£¬ÈôÊÇÄãÏëÔö³¤¸ü¶àµÄºÏ×÷Õߣ¬£¬£¬£¬£¬ÄÇôÿÔ±ØÒªÖ§¸¶7ÃÀÔªÉý¼¶µ½¸ß¼¶ÕË»§¡£¡£¡£¡£¡£¡£ÈôÊÇÄã֮ǰÒѾ֧¸¶7ÃÀÔª£¬£¬£¬£¬£¬ÄÇôÄãÄܹ»Æ¾¾Ý×ÔÉíÐèÒª½µ¼¶ÎªÃâÓöȻ§£¬£¬£¬£¬£¬Í¬Ê±Ë½Óд洢¿âµÄÄÚÈݾùÒѱ£Áô¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-announces-unlimited-private-repos-for-github-free/3¡¢ÃÀ¹ú³ø·¿ÓþßÔì×÷ÉÌoxo.comÔâµ½MageCart¹¥»÷
ÃÀ¹ú³ø·¿ÓþßÔì×÷ÉÌOXO InternationalÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬¿Í»§µÄ¸¶¿îÐÅÏ¢±»ÇÔ¡£¡£¡£¡£¡£¡£Æ¾¾ÝOXOµÄÊý¾Ýй¶֪ͨ£¬£¬£¬£¬£¬ÔÚ2017Äê6ÔÂ9ÈÕ-2017Äê11ÔÂ28ÈÕ¡¢2018Äê6ÔÂ8ÈÕ-2018Äê6ÔÂ9ÈÕºÍ2018Äê7ÔÂ20ÈÕ-2018Äê10ÔÂ16ÈÕÆÚ¼ä£¬£¬£¬£¬£¬¿Í»§ÔÚÆäÍøÕ¾www.oxo.comÉÏÊäÈëµÄ¶©µ¥Ö§¸¶ÐÅÏ¢Êܵ½ÇÖº¦£¬£¬£¬£¬£¬Ô̺¬ÐÅÓþ¿¨ÐÅÏ¢¡¢Õ˵¥µØÖ·¡¢µç×ÓÓʼþµØÖ·ºÍµç»°ºÅÂë¡£¡£¡£¡£¡£¡£BleepingComputerµÄ½øÒ»²½×êÑÐÅú×¢ÖÁÉÙÓÐÒ»´Î¹¥»÷ÊÇMageCart¹¥»÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/oxo-discloses-magecart-attack-that-targeted-customer-data-on-oxocom/4¡¢ºÚ¿ÍÇÔÈ¡Titan Distributors¹«Ë¾½üÒ»ÄêµÄ¿Í»§Ö§¸¶Êý¾Ý
Titan Distributors¹«Ë¾Ôâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬²¿Ãſͻ§µÄÖ§¸¶Êý¾Ý±»ÇÔ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾£¬£¬£¬£¬£¬2017Äê11ÔÂ23ÈÕÖÁ2018Äê10ÔÂ25ÈÕÆÚ¼äÆäÔÚÏßÉ̵걻ֲÈë¶ñÒâ´úÂ룬£¬£¬£¬£¬ÕâЩ´úÂëÓÃÓÚÇÔÈ¡Óû§µÄÖ§¸¶ÐÅÏ¢£¬£¬£¬£¬£¬Ô̺¬ÐÕÃû¡¢Õ˵¥µØÖ·¡¢µç»°ºÅÂë¡¢ÐÅÓþ¿¨ºÅÂë¡¢µ½ÆÚÈÕÆÚºÍÑéÖ¤Âë¡£¡£¡£¡£¡£¡£Æ¾¾ÝTitan˾·¨ÕÕ·÷Butler£¦SnowÏò»ªÊ¢¶ÙÖݼì²ì³¤·¢³öµÄÒ»·âÐÅ£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÓû§ÊýÁ¿Îª1838ÈË¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/79595/hacking/titan-manufacturing-security-breach.html5¡¢Ó¡¶È³¬¹ý1.1ÍòÁ¾¹«¹²Æû³µµÄʵʱGPS×ø±êÔÚÆØ¹â
°²È«×êÑÐÔ±Justin Paine·¢ÏÖÒ»¸öδÉèÃÜÂëµÄElasticSearch·þÎñÆ÷£¬£¬£¬£¬£¬¸Ã·þÎñÆ÷Ô̺¬À´×Ô27¼ÒÓ¡¶È¹úÓÐÔËÊä»ú¹¹µÄÊý¾Ý£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬³¬¹ý1.1ÍòÁ¾¹«¹²Æû³µµÄʵʱGPS×ø±êºÍ·ÏßÐÅÏ¢¡£¡£¡£¡£¡£¡£·ÖÆçÔËÊä»ú¹¹µÄÊý¾Ý²¢²»Ò»Ñù£¬£¬£¬£¬£¬ÔÚijЩ°¸ÀýÖУ¬£¬£¬£¬£¬»¹Ô̺¬³Ë¿ÍµÄÓû§ÃûºÍµç×ÓÓʼþµØÖ·¡£¡£¡£¡£¡£¡£¸Ã·þÎñÆ÷ÖÁÉÙÒÑÔÚ»¥ÁªÍøÉÏÆØ¹âÁËÈýÖܵŦ·ò¡£¡£¡£¡£¡£¡£ÔÚPaine֪ͨӡ¶ÈCERTºó£¬£¬£¬£¬£¬¸Ã·þÎñÆ÷µÃµ½±£»£»£»£»£»£»£»£»¤£¬£¬£¬£¬£¬µ«CERT»Ø¾øÐ¹Â©¸Ã·þÎñÆ÷µÄËùÓÐÕß¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/real-time-location-data-for-over-11000-indian-buses-left-exposed-online/6¡¢Ê®¶à¿îiOSÓÎÏ·±»·¢ÏÖÏòGolduckµÄC&C·þÎñÆ÷·¢ËÍÐÅÏ¢
°²È«×êÑÐÍŶÓWandera·¢ÏÖApp StoreÉϵÄ14¿îÓÎÏ·Ïò¶ñÒâÈí¼þGolduck LoaderµÄÒÑÖªC&C·þÎñÆ÷·¢ËÍÊý¾Ý¡£¡£¡£¡£¡£¡£GolduckÊÇÒ»¸ö¸æ°×Èí¼þ·Ö·¢Æ½Ì¨£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÕâÊ®¶à¿îiOSÓÎÏ·²û·¢³öÓëϰȾÁËGolduckµÄAndroidÀûÓÃÀàËÆµÄÐÐΪ£¬£¬£¬£¬£¬¼´ÔÚÀûÓ÷¨Ê½Ö÷ÆÁÄ»µÄ¶à¸öÇøÓò×¢Èë¸æ°×¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ÕâЩÓÎÏ·»¹ÏòGolduckµÄC£¦C·þÎñÆ÷·¢ËÍ´óÁ¿ÐÅϢƬ¶Î£¬£¬£¬£¬£¬Ô̺¬IPµØÖ·¡¢µØÎ»Êý¾Ý¡¢É豸ÀàÐͺÍÉ豸ÉÏÏÔʾµÄ¸æ°×ÊýÁ¿µÈ¡£¡£¡£¡£¡£¡£App StoreÒѾϼÜÁËÕâЩÓꦵÄÀûÓᣡ£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/apple-ios-games-found-talking-to-golduck-malware-candc-servers/ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ