¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190125
°ä²¼¹¦·ò 2019-01-25
±¾ÖÜÈý˼¿Æ°ä²¼Á˶à¿î²úÆ·µÄ°²È«¸üУ¬£¬£¬£¬£¬Ô̺¬SD-WAN¡¢Webex¡¢Firepower·À»ðǽÒÔ¼°SMB·ÓÉÆ÷µÈ¡£¡£¡£¡£¡£Ö»ÓÐÒ»¸ö·ì϶±»¹éÀàΪcritical£¬£¬£¬£¬£¬¸Ã·ì϶£¨CVE-2019-1651£©Ó°ÏìÁË˼¿ÆSD-WAN½â¾ö¹æ»®ÖеÄvContainer×é¼þ£¬£¬£¬£¬£¬¿É±»Ô¶³Ì¹¥»÷ÕßÀûÓÃÒÔ´¥·¢DoSÒÔ¼°ÒÔrootȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£SD-WANÖÐµÄÆäËü·ì϶Ô̺¬Éí·ÝÑéÖ¤ÈÆ¹ý¡¢ÌáȨºÍËÁÒâÎļþ¸²¸ÇµÈ¡£¡£¡£¡£¡£¸ü¶à·ì϶ÐÅÏ¢Çë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/cisco-patches-flaws-webex-sd-wan-other-products2¡¢Moxa½¨¸´IIoTÍø¹ØThingsPro 2ÖеÄ7¸ö°²È«·ì϶
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/flaws-moxa-iiot-product-expose-ics-remote-attacks3¡¢×êÑÐÈËÔ±ÔÚ¶à¸öBMC¹Ì¼þÖз¢ÏÖзì϶pantsdown
IBM Linux¼¼ÊõÖÐÐĵÄÈí¼þ¹¤³ÌʦStewart Smith·¢ÏÖÓ°Ïì¶à¸öµ×°åÖÎÀí½ÚÔìÆ÷£¨BMC£©¹Ì¼þ²Ö¿âºÍÓ²¼þµÄÑϳÁ·ì϶¡£¡£¡£¡£¡£¸Ã·ì϶£¨CVE-2019-6260£©±»³ÆÎª¡°pantsdown¡±£¬£¬£¬£¬£¬Smith³Æ¸Ã·ìÏ¶ÖØÒªÓ°ÏìÁËʹÓÃASPEED ast2400ºÍast2500ƬÉÏϵͳ£¨SoC£©µÄ²úÆ·£¬£¬£¬£¬£¬OpenBMC¡¢AMIµÄBMCºÍSuperMicroµÈBMC¹Ì¼þ²Ö¿â¾ùÊÜÓ°Ïì¡£¡£¡£¡£¡£IBMµÄOpenPOWERϵͳÒѰ䲼Á˸÷ì϶µÄ½¨¸´²¹¶¡¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/bmc-caught-with-pantsdown-over-new-batch-of-security-flaws/4¡¢ÒøÐÐľÂíRedamanжñÒâ»î¶¯£¬£¬£¬£¬£¬ÖØÒªÕë¶Ô¶íÂÞË¹ÒøÐÐ
Palo Alto NetworksµÄUnit 42×êÑÐÍÅ¶Ó¹Û²ìµ½ÒøÐÐľÂíRedamanÔÚ2018ÄêϰëÄê»ý¼«½øÐй¥»÷»î¶¯¡£¡£¡£¡£¡£´Ó2018Äê9Ôµ½12Ô£¬£¬£¬£¬£¬¸ÃľÂí»ý¼«Í¨¹ýÀ¬»øÓʼþ´«²¼£¬£¬£¬£¬£¬ÖØÒªÕë¶Ô¶íÂÞ˹½ðÈÚ»ú¹¹£¬£¬£¬£¬£¬²¢Í¨¹ý¼Ù×°³ÉPDFÎĵµµÄWindows¿ÉÖ´ÐÐÎļþ½»¸¶payload¡£¡£¡£¡£¡£ÕâЩ¶ñÒ⸽¼þµÄÎļþÌåʽһÏòÔڱ䶯£¬£¬£¬£¬£¬2018Äê9ÔÂÊÇ.zipÎļþ£¬£¬£¬£¬£¬10ÔÂÊÇ.zip¡¢.7zºÍ.rarÎļþ£¬£¬£¬£¬£¬11ÔÂÊÇ.rarÎļþ£¬£¬£¬£¬£¬12ÔÂÓÖÔì³ÉÁË.gzÎļþ¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÒÔΪ´Ë¾Ù¿ÉÄÜÊÇΪÁËÌӱܼì²â¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/redaman-spams-russian-banking-customers-with-rotating-tactics/141129/5¡¢ÒøÐÐľÂíUrsnifжñÒâ»î¶¯£¬£¬£¬£¬£¬ÀûÓÃÎÞÎļþ¼¼ÊõÌӱܼì²â
Cisco Talos·¢ÏÖÒøÐÐľÂíUrsnifµÄÒ»¸öжñÒâ»î¶¯£¬£¬£¬£¬£¬¸Ã»î¶¯ÖÐʹÓÃÁËPowerShellÀ´´«²¼UrsnifÒÔʵÏÖÎÞÎļþϰȾ¡£¡£¡£¡£¡£UrsnifÒ²±»³ÆÎªGozi ISFB£¬£¬£¬£¬£¬ÊÇÒøÐÐľÂíGoziµÄºóÊÀ£¬£¬£¬£¬£¬GoziµÄÔ´ÂëÔÚ2014Äêй¶ºó£¬£¬£¬£¬£¬ÔÚÆä»ù´¡Éϵ®ÉúÁ˺ܶàÆäËüµÄÒøÐÐľÂí¼Ò×壬£¬£¬£¬£¬ÀýÈçGozNym¡£¡£¡£¡£¡£¸ÃжñÒâ»î¶¯Í¨¹ýWordÎĵµÖеĶñÒâVBAºêÀ´·Ö·¢payload£¬£¬£¬£¬£¬×êÑÐÈËÔ±Ôڻ㱨ÖÐÁгöÁ˸öñÒâ»î¶¯µÄ¾ßÌåIoCÖ¸±ê£¬£¬£¬£¬£¬Ô̺¬¹þÏ£Öµ¡¢C2·þÎñÆ÷ÓòÃûÒÔ¼°payloadÃû³ÆµÈ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-ursnif-malware-campaign-uses-fileless-infection-to-avoid-detection/6¡¢ÃÀ°¢À˹¼ÓÖݹ«¹²ÔöÔ®²¿ÃÅÊý¾Ýй¶£¬£¬£¬£¬£¬Ó°ÏìÔ¼8.7ÍòÈË
ÔÎÄÁ´½Ó£º
https://www.usnews.com/news/best-states/alaska/articles/2019-01-24/alaska-notifies-87-000-people-after-computer-security-breachÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ