¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190123
°ä²¼¹¦·ò 2019-01-23
×êÑÐÈËÔ±Max Justicz·¢ÏÖLinux°üÖÎÀíÆ÷apt/apt-get´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬¸Ã·ì϶£¨CVE-2019-3462£©ÔÊÐí¹¥»÷Õß½øÐÐÖÐÑëÈ˹¥»÷²¢»ñÈ¡rootȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄÆðÒòÊÇaptĬÈÏʹÓÃHTTPͨѶ£¬£¬£¬£¬£¬¶øÆätransport²½ÖèÖд¦ÖÃHTTP³Á¶¨ÏòµÄ´úÂëûÓÐÕýÈ·²é³Ä³Ð©²ÎÊý£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÖÐÑëÈ˹¥»÷ʹÓÃαÔìÊðÃûƹý¸Ã²é³£¬£¬£¬£¬£¬½ø¶øÔÚÓû§Ö÷»úÉÏ×°ÖÃËÁÒⷨʽ¡£¡£¡£¡£¡£¡£ÓÉÓÚapt×ÔÉíÒѾ»ñÈ¡ÁËrootȨÏÞ£¬£¬£¬£¬£¬¸Ã¶ñÒⷨʽ¿ÉÔÚrootȨÏÞÏÂÖ´ÐС£¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁìÓò¼«Îª¿í·º£¬£¬£¬£¬£¬ËùÓÐʹÓÃÀϰ汾aptµÄÖ÷»ú¶¼Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£apt¿ª·¢ÈËÔ±ÒÑÔÚ°æ±¾1.4.9Öн¨¸´Á˸÷ì϶¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/linux-apt-http-hacking.html2¡¢Check Point°ä²¼2019ÍøÂ簲ȫ»ã±¨£¬£¬£¬£¬£¬³Áµã·ÖÎöÍøÂç¹¥»÷Ç÷Ïò
ÔÎÄÁ´½Ó£º
https://blog.checkpoint.com/2019/01/21/threat-trends-analysis-report/3¡¢ÐÂÀÕË÷Èí¼þPhobosÀûÓÃRDP·þÎñ´«²¼£¬£¬£¬£¬£¬Õë¶ÔÈ«ÇòÆóÒµ

CoveWare×êÑÐÈËÔ±·¢ÏÖÕë¶ÔÈ«ÇòÆóÒµµÄÐÂÀÕË÷Èí¼þPhobos£¬£¬£¬£¬£¬Phobos³öÏÖÓÚ2018Äê12Ô·ݣ¬£¬£¬£¬£¬²¢ÇÒÓëÀÕË÷Èí¼þDharma´æÔںܶàÀàËÆÖ®´¦¡£¡£¡£¡£¡£¡£ÓëDharmaÒ»Ñù£¬£¬£¬£¬£¬PhobosÀûÓÃÊ¢¿ªµÄ»ò°²È«ÐԽϲîµÄRDP¶Ë¿Ú½øÐÐÈëÇÖ¡£¡£¡£¡£¡£¡£±»¼ÓÃܵÄÎļþ»á±»Ôö³¤.phobosÀ©´óÃû¡£¡£¡£¡£¡£¡£PhobosÒªÇóÒÔ±ÈÌØ±ÒµÄ·½Ê½Ö§¸¶Êê½ð£¬£¬£¬£¬£¬ÆäÀÕË÷µ¥¾ÝÉϵÄ×ÖÌåºÍÎı¾ÓëDharmaÆëȫһÑù¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±»¹³ÆPhobosµÄ´ó²¿ÃÅ´úÂëÒ²ÓëDharmaÒ»Ö¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/new-phobos-ransomware-exploits-weak-security-to-hit-targets-around-the-world/4¡¢ÀÕË÷Èí¼þSTOPбäÖÖRumba£¬£¬£¬£¬£¬ÖØÒªÍ¨¹ýµÁ°æÈí¼þ´«²¼

ÀÕË÷Èí¼þSTOPµÄбäÖÖRumbaÔÚ´Óǰ30ÌìÄÚ»ý¼«½øÐзַ¢£¬£¬£¬£¬£¬¸Ã±äÌ彫.rumbaÀ©´óÃû¸½¼Óµ½¼ÓÃÜÎļþºó£¬£¬£¬£¬£¬ÖØÒª°ó¸¿ÔÚ¸æ°×Èí¼þ°üºÍÆÆ½â°æÈí¼þÖд«²¼¡£¡£¡£¡£¡£¡£¾Ý±¨Â·£¬£¬£¬£¬£¬ÕâЩµÁ°æÈí¼þÔ̺¬Windows¼¤»î¹¤¾ß£¨ÀýÈçKMSPico£©¡¢Cubase¡¢PhotoshopÒÔ¼°ÆäËüÊ¢ÐÐÈí¼þµÄÆÆ½â°æµÈ¡£¡£¡£¡£¡£¡£ºÃÐÂÎÅÊÇ£¬£¬£¬£¬£¬×êÑÐÍŶÓÒѾ°ä²¼ÁËSTOPµÄÃâ·Ñ½âÃܹ¤¾ß£¬£¬£¬£¬£¬Êܵ½Ï°È¾µÄÓû§Äܹ»ÏÂÔØ¸Ã¹¤¾ß½øÐнâÃÜ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-rumba-stop-ransomware-being-installed-by-software-cracks/5¡¢ÇàÄêѧÉú×éÖ¯AIESECÒâ±íй¶400¶àÍòʵϰÉúÉêÇëÊé

ÔÎÄÁ´½Ó£º
https://techcrunch.com/2019/01/21/aiesec-data-leak/6¡¢ÃÀ¹ú¶à¼Ò´ò¶ÄÍøÕ¾Ð¹Â¶1.08ÒÚ´ò¶ÄÐÅÏ¢£¬£¬£¬£¬£¬Ô̺¬Óû§Ö§¸¶Êý¾Ý
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/online-casino-group-leaks-information-on-108-million-bets-including-user-details/ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ