F5°ä²¼2019ÄêTLSÒ£²â»ã±¨£¬£¬£¬£¬£¬¹Ø×¢¼ÓÃÜÁìÓòµÄ·¢Õ¹£»£»£»£»£»£»£»£»2019Äê61£¥µÄ¹Ø¼üͨѶÐÐÒµÔâ·ê¶ñÒâÈí¼þ¹¥»÷
°ä²¼¹¦·ò 2020-03-021.F5°ä²¼2019ÄêTLSÒ£²â»ã±¨£¬£¬£¬£¬£¬¹Ø×¢¼ÓÃÜÁìÓòµÄ·¢Õ¹
F5³¢ÊÔÊÒ°ä²¼¡¶2019ÄêTLSÒ£²â»ã±¨¡·£¬£¬£¬£¬£¬¸Ã»ã±¨ÌṩÁËÓйØÍøÂç¼ÓÃÜÈôºÎ²»ÐÝ·¢Õ¹µÄÉî¿Ì¼û½â¡£¡£¡£¡£¡£¡£¡£¸Ã»ã±¨×êÑÐÁËInternet¶¥¼¶ÍøÕ¾Ê¹ÓÃÄÄÖÖ¼ÓÃÜÆ÷ºÍSSL/TLS°æ±¾½øÐб£»£»£»£»£»£»£»£»¤£¬£¬£¬£¬£¬²¢³õ´Î²é³ÁËWebÉÏÊý×ÖÖ¤ÊéµÄʹÓúͲ鿴ÁËÖ§³ÖµÄºÍ̸£¨ÈçDNS£©ºÍÀûÓ÷¨Ê½²ã±êÍ·¡£¡£¡£¡£¡£¡£¡£¼¼ÊõÌṩÉÌÓëµ±¾ÖÖ®¼äµÄÈ«ÇòÕù³³£¨Ò²³ÆÎªCrypto Wars 2.0£©ÈÔÔÚ³ÖÐø¡£¡£¡£¡£¡£¡£¡£µ±¾ÖÔ½À´Ô½¶àµØ³¢ÊÔ½ÚÔì¼ÓÃܵÄʹÓ÷½Ê½£¬£¬£¬£¬£¬²¢ÇÒÎÒÃǾ³£¿£¿£¿£¿£¿£¿£¿£¿´µ½Á¢·¨²»ÃÀÂú£¨»òÓÐÒâ³éÏ󣩵ÄÁ¢·¨¡£¡£¡£¡£¡£¡£¡£ChromeÊÇʹÓÃ×î¿í·ºµÄÍøÂçä¯ÀÀÆ÷£¬£¬£¬£¬£¬ÆäÄܹ»Í¨¹ý°²È«µÄHTTPSÏνӽӼû³¬¹ý86%µÄÍøÒ³£¬£¬£¬£¬£¬FirefoxµÄÊý×ÖÉԵͣ¬£¬£¬£¬£¬µ«Ò²ÓÐ80.5%¡£¡£¡£¡£¡£¡£¡£ÔÚAlexaÅÅÃûǰ100ÍòµÄÍøÕ¾ÖУ¬£¬£¬£¬£¬½üÈý·ÖÖ®Ò»´Ë¿Ì½ÓÊÜTLS 1.3Ïνӡ£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.f5.com/content/dam/f5-labs-v2/article/pdfs/F5Labs-2019-TLS-Telemetry-Report-Summary.pdf
2.Ó¢¹ú²â»æ»ú¹¹Ordnance SurveyÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬Ô±¹¤Êý¾Ýй¶
¾Ý±íý±¨Â·£¬£¬£¬£¬£¬Ó¢¹ú²â»æ»ú¹¹Ordnance SurveyÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬µ¼Ö½ü1000ÃûÔ±¹¤µÄÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¾Ý³Æµ±¾ÖÓÚ1Ô·ݷ¢ÏÖ²¢Á¢¼´ÏìÓ¦ÁËÈëÇÖÊÂÎñ£¬£¬£¬£¬£¬²¢ÇÒ֪ͨÁËÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©£¬£¬£¬£¬£¬µ«¸ÃÊÂÎñÖ±µ½´Ë¿Ì²Å±»¹«¿ª¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔÈëÇÖ²úÉúµÄ¾ßÌ幦·ò£¬£¬£¬£¬£¬µ«¾ÝVerdict³Æ£¬£¬£¬£¬£¬¹¥»÷ÕßÊÇͨ¹ýÍøÂç´¹µö¹¥»÷ÈëÇÖÁËCFOµÄµç×ÓÓʼþÕË»§£¬£¬£¬£¬£¬´Ó¶øÇÔÈ¡Á˹¤×ʵ¥Îļþ¡£¡£¡£¡£¡£¡£¡£Ordnance Survey°µÊ¾Ã»ÓÐÈκοͻ§ÐÅϢй¶£¬£¬£¬£¬£¬Æä×ÔÉíµÄϵͳҲ²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/ordnance-survey-breach-hits/?&web_view=true
3.ÃÀ¹úWalgreensÒ©µêÒÆ¶¯APP´æÔÚ·ì϶й¶Óû§ÐÅÏ¢
ÃÀ¹úµÚ¶þ´óÒ©µêÎÖ¶û¸ñÁÖ£¨Walgreens£©°µÊ¾Æä¹Ù·½Òƶ¯APP´æÔÚÒ»¸ö·ì϶£¬£¬£¬£¬£¬µ¼Ö²¿ÃÅÓû§µÄÓ×ÎÒÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶±»ÃèÊöΪAPPÓ×ÎÒ°²È«ÐÂÎÅ´«µÝÖ°ÄÜÖеÄÃýÎ󣬣¬£¬£¬£¬¿ÉÄÜй¶µÄÐÅÏ¢Ô̺¬Óû§µÄÐÕÃû¡¢´¦·½¾ßÌåÐÅÏ¢¡¢É̵ê±àºÅºÍËÍ»õµØÖ·£¨ÈôÊÇÓУ©¡£¡£¡£¡£¡£¡£¡£ÕâЩÊý¾Ý¶³öµÄ¹¦·òΪ1ÔÂ9ÈÕ£¨ÐÇÆÚËÄ£©ºÍ1ÔÂ15ÈÕ£¨ÐÇÆÚÈý£©Ö®¼ä£¬£¬£¬£¬£¬WalgreensÒÑÓÚ1ÔÂ15ÈÕµÃÖª·ì϶ȷµ±Ì콨¸´Á˸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ã»ÓÐй©¾ßÌåÊÜÓ°ÏìÓû§µÄÊýÁ¿£¬£¬£¬£¬£¬µ«°µÊ¾Ãô¸Ð´¦·½ÐÅϢй¶µÄÓû§Õ¼ÊÜÓ°ÏìÓû§×ÜÊýµÄÒ»Óײ¿ÃÅ¡£¡£¡£¡£¡£¡£¡£¸ÃAPPÔÚGoogle PlayÉ̵êÖеÄÏÂÔØ´ÎÊýΪ³¬¹ý1000Íò´Î£¬£¬£¬£¬£¬ÔÚiOSÖÐµÄÆÀ·ÖÊýÁ¿³¬¹ý250Íò¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/walgreens-says-mobile-app-leaked-users-personal-data/
4.2019Äê61£¥µÄ¹Ø¼üͨѶÐÐÒµÔâ·ê¶ñÒâÈí¼þ¹¥»÷
ƾ¾Ý¹ú¼ÊÎÞÏßͨѶչÀÀ»á£¨IWCE£©µÄµ÷ÑУ¬£¬£¬£¬£¬ÔÚ´ÓǰµÄ12¸öÔÂÖÐÓÐÎå·ÖÖ®Ò»µÄ¹Ø¼üͨѶÐÐÒµÔâ·êÁ˰²È«ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£ÎªÁ˶Ե±Ç°¼¼Êõ½øÐлù×¼²âÊÔ£¬£¬£¬£¬£¬IWCE¶Ô¹Ø¼üͨѶÐÐÒµµÄÖÁÉÙ597ÃûרҵÈËÔ±½øÐÐÁ˵÷²é¡£¡£¡£¡£¡£¡£¡£¸Ãµ÷²é»¹»ØÊ×ÁËÐÐÒµÄڵļ¼ÊõÌôÕ½¡£¡£¡£¡£¡£¡£¡£Í¨¹ý¸Ãµ÷²é£¬£¬£¬£¬£¬61£¥µÄÊÜ·ÃÕß°µÊ¾Ôâ·êÁ˶ñÒâÈí¼þ¹¥»÷£¬£¬£¬£¬£¬56£¥ÔòÊÇÍøÂç´¹µö¹¥»÷µÄÊܺ¦Õߣ¬£¬£¬£¬£¬27£¥°µÊ¾´¦ÖùýÀÕË÷Èí¼þ£¬£¬£¬£¬£¬22%Ôâ·êÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬16%Ôâµ½DDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£10£¥µÄµÄÊÜ·ÃÕ߻㱨³ÆÔâµ½¸ß¼¶Íþв¹¥»÷£¬£¬£¬£¬£¬ÔÚ´ËÀ๥»÷Öй¥»÷Õßͨ³£³¤¹¦·òÂñ·üÔÚÆäÍøÂçÖÓ×£¡£¡£¡£¡£¡£¡£ÍøÂç¹¥»÷·ÛËéÁËÕý³£µÄÔËÓªºÍ·þÎñ£¬£¬£¬£¬£¬Æä½¨¸´³É±¾Îª£º38£¥µÄ³É±¾²»µ½10ÍòÃÀÔª£¬£¬£¬£¬£¬10£¥µÄ³É±¾ÔÚ10ÍòÃÀÔªÖÁ100ÍòÃÀÔªÖ®¼ä£¬£¬£¬£¬£¬¶ø2£¥µÄ³É±¾ÔÚ100ÍòÖÁ1000ÍòÃÀÔªÖ®¼ä¡£¡£¡£¡£¡£¡£¡£ºÜ¶à¹«Ë¾£¨64%£©ÔÚÓëµÚÈý·½¹©¸øÉÌÇ©¶¨Êý¾Ý±£»£»£»£»£»£»£»£»¤ºÍÍøÂ簲ȫºÍ̸£¬£¬£¬£¬£¬ÓÉÓÚ¹¥»÷¼°ÆäÓ°Ïì¿ÉÄÜÀ´×ÔµÚÈý·½¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://finbold.com/61-percent-critical-communications-industry-suffers-malware-attacks/
5.2019Äê·¸×ïÍÅ»ïTA505»ý¼«Õë¶Ôº«¹ú½ðÈÚ»ú¹¹
º«¹ú½ðÈÚ°²È«×êÑÐËù£¨Financial Security Institute£©×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬TA505ÔÚ2019ÄêµÄ´ó²¿Ãʦ·òÀï¶¼ÔÚ³¢ÊÔÕë¶Ôº«¹ú½ðÈÚ¡¢Ôì×÷ºÍÒ½ÁÆ·þÎñÆóÒµÌáÒé´¹µö¹¥»÷¡£¡£¡£¡£¡£¡£¡£·¸×ïÍÅ»ïTA505×Ô2014ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬²¢ÇÒËÆºõÓë·¸×ïÍÅ»ïFIN7¹²Ïí¹¤¾ß¡¢¼¼ÊõºÍ·¨Ê½¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾TA505·¢Ë͵ĺܶàÍøÂç´¹µöÓʼþ¶¼Ô̺¬¶ñÒâExcelÎĵµ£¬£¬£¬£¬£¬²¢ÇÒʹÓÃÔ¶¿ØÄ¾ÂíFlawedAmmyy¼à¶½Óû§µÄ»î¶¯ºÍÍøÂçÓû§Ãû/ÃÜÂë¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬TA505»¹Ôڶ̹¦·òÄÚʹÓÃÁËÒ»ÖÖÃûΪRapidµÄÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cyberscoop.com/ta505-south-korea-bank-phishing/
6.ºÚ¿ÍÀûÓÃWooCommerce²å¼þ0day¹¥»÷ÊýÍò¸öWordPressÍøÕ¾
ºÚ¿ÍÔÚÀûÓÃWordPress²å¼þÖеÄ0day¹¥»÷ÊýÒÔÍò¼ÆµÄÍøÕ¾£¬£¬£¬£¬£¬ÕâЩ·ì϶ʹËûÃÇÄܹ»´´½¨¶ñÒâÖÎÀíÔ¹ØÊ»§²¢Ö²ÈëºóÃÅ·¨Ê½¡£¡£¡£¡£¡£¡£¡£NinTechNet×êÑÐÈËÔ±ÔÚWooCommerce²å¼þµÄFlexible Checkout×Ö¶ÎÖз¢ÏÖ´æ´¢ÐÍXSS 0day£¬£¬£¬£¬£¬¸Ã²å¼þµÄ×°ÖÃÊýÁ¿Îª2Íò¡£¡£¡£¡£¡£¡£¡£²å¼þ¿ª·¢ÍŶÓÔÚ½Óµ½»ã±¨ºóѸËÙÍÆ³öÁË2.3.2°æ±¾ÒÔ½¨¸´¸Ã·ì϶£¬£¬£¬£¬£¬µ«ÈÔÓÐһЩÓû§Ôâµ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Defiant×êÑÐÈËÔ±»¹ÔÚÆäËü¼¸¸ö²å¼þÖз¢ÏÖ3¸ö0day£¬£¬£¬£¬£¬Ô̺¬Async JavaScript£¨10Íò+×°Öã©¡¢10Web Map Builder for Google Maps£¨2Íò+×°Öã©¡¢ Modern Events Calendar Lite£¨4Íò+×°Öã©ÖеĴ洢ÐÍXSS¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/critical-bugs-in-wordpress-plugins-let-hackers-take-over-sites/


¾©¹«Íø°²±¸11010802024551ºÅ