¹¥»÷ÕßÀÄÓÃBitbucket·þÎñ£¬£¬£¬£¬£¬Òѵ¼ÖÂ50¶àÍòÖ÷»úϰȾ¶ñÒâÈí¼þ;·ÉÀûÆÖÖÇÄܵÆÅÝ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬¿Éµ¼ÖºڿÍÈëÇÖ¼ÒÍ¥WiFi

°ä²¼¹¦·ò 2020-02-06

1.¹¥»÷ÕßÀÄÓÃBitbucket·þÎñ£¬£¬£¬£¬£¬Òѵ¼ÖÂ50¶àÍòÖ÷»úϰȾ¶ñÒâÈí¼þ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¹¥»÷ÕßÔÚÀÄÓôúÂëÍйܷþÎñBitbucket´æ´¢7ÖÖ¶ñÒâÈí¼þpayload£¬£¬£¬£¬£¬¸Ã¹¥»÷»î¶¯ÒÑÔÚÈ«ÇòÁìÓòÄÚϰȾÁ˳¬¹ý50Íǫ̀ÉÌÓÃÍÆËã»ú ¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý°²È«³§ÉÌCybereason°ä²¼µÄÒ»·Ý»ã±¨£¬£¬£¬£¬£¬¹¥»÷Õß²¿Êðµ½Ö¸±êϵͳµÄ¶ñÒâpayloadÔ̺¬Predator¡¢Azorult¡¢Evasive Monero Miner¡¢ÀÕË÷Èí¼þSTOP¡¢Vidar¡¢Amadey botºÍIntelRapid ¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯ÖØÒªÕë¶ÔѰÕÒµÁ°æÃ³Ò×Èí¼þ£¨ÀýÈçAdobe Photoshop¡¢Microsoft OfficeµÈ£©µÄÓû§ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/bitbucket-abused-to-infect-500-000-hosts-with-malware-cocktail/


2.¹È¸è°ä²¼2ÔÂAndroid°²È«¸üУ¬£¬£¬£¬£¬½¨¸´25¸ö·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¹È¸è°ä²¼2020Äê2ÔµÄAndroid°²È«¸üУ¬£¬£¬£¬£¬¹²½¨¸´25¸ö·ì϶£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Á½¸öÑϳÁ¼¶´ËÍâ·ì϶ ¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸ö·ì϶¶¼Î»ÓÚAndroidµÄϵͳ×é¼þÖУ¬£¬£¬£¬£¬µÚÒ»¸ö·ì϶ÊÇÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-0022£©£¬£¬£¬£¬£¬¸Ã·ì϶½öÔÚAndroid 8.0¡¢8.1ºÍ9Éϲű»ÒÔΪÊÇÑϳÁ¼¶±ð£¬£¬£¬£¬£¬¶øÔÚAndroid 10ÉÏËüÖ»Äܵ¼Ö»ؾø·þÎñ£¬£¬£¬£¬£¬Òò¶ø±»ÒÔΪÊÇÖеȼ¶±ð ¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¸ö·ì϶ÊÇ¿ÉÄܵ¼ÖÂÐÅϢй¶µÄ·ì϶£¨CVE-2020-0023£©£¬£¬£¬£¬£¬¸Ã·ì϶½öÓ°ÏìÁËAndroid 10 ¡£¡£¡£¡£¡£¡£¡£¸ü¶à·ì϶ÐÅÏ¢Çë²Î¿¼ÒÔÏÂÁ´½Ó ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/androids-february-2020-update-patches-critical-system-vulnerabilities


3.·ÉÀûÆÖÖÇÄܵÆÅÝ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬¿Éµ¼ÖºڿÍÈëÇÖ¼ÒÍ¥WiFi


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Check Point×êÑÐÈËÔ±Åû¶·ÉÀûÆÖHueÖÇÄܵÆÅÝÖеÄÒ»¸ö¸ßΣ·ì϶£¬£¬£¬£¬£¬¸Ã·ì϶£¨CVE-2020-6007£©¿ÉÔÊÐíºÚ¿Í´Ó100¶àÃ×±íͨ¹ýÎÞÏß½Ó¼ûÈëÇÖÖ¸±êµÄ¼ÒÍ¥WiFiÍøÂç ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚÖÇÄܵÆÅݵÄZigbeeͨѶºÍ̸ִÐз½Ê½ÖУ¬£¬£¬£¬£¬ÊÇÒ»¸ö»ùÓڶѵĻº³åÇøÒç³öÎÊÌâ ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ÎÞÏßÉøÈë¼ÒÍ¥»ò°ì¹«ÊÒµÄÍÆËã»úÍøÂç¡¢´«²¼ÀÕË÷Èí¼þ»ò¼äµýÈí¼þ ¡£¡£¡£¡£¡£¡£¡£Check Point»¹È·ÈÏ»º³åÇøÒçÆô³ÌÉúÔÚ±»³ÆÎª¡°ÍøÇÅ¡±µÄ×é¼þÉÏ£¬£¬£¬£¬£¬¸Ã×é¼þ½ÓÊÜͨ¹ýZigbeeºÍ̸´ÓÆäËûÉ豸£¨ÈçÒÆ¶¯ÀûÓûòAlexa¼ÒÍ¥ÖúÀí£©·¢Ë͵½µÆÅݵÄÔ¶³ÌºÅÁî ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÒѾ­ÔÚ×îеĹ̼þ¸üÐÂÖн¨¸´ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/02/philips-smart-light-bulb-hacking.html


4.˼¿ÆTalosÅû¶Mini-SNMPDÖеÄDoS¼°ÐÅϢй¶·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Mini-SNMPDÊǵ¥Ò»ÍøÂçÖÎÀíºÍ̸·þÎñÆ÷µÄÇáÁ¿¼¶ÊµÏÖ£¬£¬£¬£¬£¬ÓÉÓÚÆä½ÏÓ׵ĴúÂë´óÓ׺ÍÄÚ´æÕ¼ÓÃÁ¿£¬£¬£¬£¬£¬¸ÃÈí¼þרÃÅÕë¶ÔǶÈëʽϵͳ ¡£¡£¡£¡£¡£¡£¡£ËüÄܹ»ÔÚUbuntu¡¢Alpine LinuxºÍFreeBSDµÄx86ºÍARMƽ̨ÉÏÔËÐÐ ¡£¡£¡£¡£¡£¡£¡£Ë¼¿ÆTalos×êÑÐÈËÔ±ÔÚMini-SNMPDÖз¢ÏÖÈý¸ö·ì϶£¬£¬£¬£¬£¬Ô̺¬Á½¸öÔ½½ç¶Á·ì϶£¨CVE-2020-6058ºÍCVE-2020-6059£¬£¬£¬£¬£¬¿Éµ¼ÖÂDoS»òÐÅϢй¶£©ºÍÒ»¸ö²Ö¿âÒç¶Âí½Å£¨CVE-2020-6060£© ¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄMini-SNMPD°æ±¾Îª1.4£¬£¬£¬£¬£¬ÕâЩ·ì϶ÒÑÔÚMini-SNMPD 1.5Öеõ½½¨¸´ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/vulnerabilities-mini-snmpd-lead-dos-information-disclosure


5.Crew£¦Concierge¹«Ë¾Ôƴ洢Ͱй¶1.7Íò´¬Ô±ÐÅÏ¢


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ò»¼Ò¸öÈËÓÎͧ´¬Ô¹ØÐƸ»ú¹¹£¨Crew£¦Concierge£©µÄAWS´æ´¢Í°¿ÉÔÚ»¥ÁªÍøÉϹ«¿ª½Ó¼û£¬£¬£¬£¬£¬µ¼ÖÂ1.7Íò´¬Ô±µÄÃô¸ÐÐÅϢй¶ ¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝÓ¢¹úÐÂÎÅÍøÕ¾VerdictµÄ±¨Â·£¬£¬£¬£¬£¬¸Ã´æ´¢Í°Ð¹Â¶ÁË17379Ãû´¬Ô±µÄ¼òÀúÒÔ¼°³ÉǧÉÏÍòµÄENG1Ò½ÁÆÖ¤Ã÷ºÍ»¤ÕÕɨÃè¼þ£¬£¬£¬£¬£¬¾Ý³Æ¹²ÓÐ9Íò¸öÎļþ¶³ö£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬³øÊ¦µÄ²Ëµ¥Ñù±¾ ¡£¡£¡£¡£¡£¡£¡£×Ô2019Äê2ÔÂÒÔÀ´£¬£¬£¬£¬£¬¸Ã´æ´¢Í°ÒѾ­Â¶³öÁ˳¤´ï11¸öԵŦ·ò ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2020/02/04/crew_and_concierge_data_breach/


6.Íþ˹¿µÐÇÖÝÀ­ÐÁÊÐÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬ÊÐÕþ·þÎñÖжÏ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Íþ˹¿µÐÇÖÝÀ­ÐÁÊÐÔÚÉÏÖÜÎåÔçÉÏÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬µ¼Ö¸ÃÊеÄÍøÕ¾¡¢µç×ÓÓʼþ¡¢ÓïÒôÓʼþºÍÖ§¸¶ÏµÍ³¾ù±»¹Ø¹Ø ¡£¡£¡£¡£¡£¡£¡£¹ÙÔ±ÃǰµÊ¾¿ÉÄܱØÒªÒ»ÖÜÒÔÉϵŦ·òÄÜÁ¦¸´Ô­Õý³£ ¡£¡£¡£¡£¡£¡£¡£À­ÐÁÊÐÊг¤¿ÆÀ÷ɭ£¨Case Mason£©°µÊ¾¸ÃÊÐÉÐδÊÕµ½¹¥»÷ÕßµÄÊê½ðÒªÇ󣬣¬£¬£¬£¬²¢ÇÒ°µÊ¾¼´±ãÊÕµ½ÕâÑùµÄÒªÇ󣬣¬£¬£¬£¬¸ÃÊÐÒ²²»»á¸¶¿î ¡£¡£¡£¡£¡£¡£¡£ÖݺÍÁª¹ú»ú¹¹ÒÑ»ñϤ¸ÃÊÂÎñ£¬£¬£¬£¬£¬Ä¿Ç°ÔÚµ÷²é¹¥»÷²úÉúµÄ·½Ê½ºÍ±³ºóµÄÔ­Òò ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/racine-mayor-refuses-to-pay/