ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ9ÖÜ
°ä²¼¹¦·ò 2019-03-04±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǽü7ÍòÕŰͻùË¹Ì¹ÒøÐп¨ÐÅÏ¢ÔÚ°µÍøÏúÊÛ£¬£¬£¬£¬£¬£¬£¬ÊÛ¼Û½ü350ÍòÃÀÔª£»£»£»£»£»£»£»£»Èý¸ö4G/5G·ì϶£¬£¬£¬£¬£¬£¬£¬¿Éµ¼Ö¹¥»÷ÕßÈÆ¹ýÆä·À»¤Õ½Êõ£»£»£»£»£»£»£»£»Õë¶ÔInstagramÓû§µÄ¼±¾çÖ¸»È¦Ì×£¬£¬£¬£¬£¬£¬£¬Ú¿Æ½ð¶îÀۼƸߴï300ÍòÓ¢°÷£»£»£»£»£»£»£»£»Chrome 0day·ì϶£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýPDFÍøÂçÓû§ÐÅÏ¢£»£»£»£»£»£»£»£»CoinomiÇ®°üÃ÷ÎÄ´«ÊäÓû§ÃÜÂ룬£¬£¬£¬£¬£¬£¬µ¼ÖÂÔ¼7ÍòÃÀÔª±»ÇÔ¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£
³ÁÒª°²È«·ì϶Áбí
Apache Airflow±à×ëAirflowÔªÊý¾Ý¿âÖжÔÏóµÄ״̬´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
https://lists.apache.org/thread.html/f656fddf9c49293b3ec450437c46709eb01a12d1645136b2f1b8573b@%3Cdev.airflow.apache.org%3E
2. F5 BIG-IPÑéÖ¤SSLÔ¶³Ì»Ø¾ø·þÎñ·ì϶
F5 BIG-IPÑéÖ¤SSL´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿É½øÐлؾø·þÎñ¹¥»÷¡£¡£¡£¡£¡£¡£
https://support.f5.com/csp/article/K54167061
3. Cisco RV110W/RV130W/RV215W Routers CVE-2019-1663Ô¶³ÌºÅÁîÖ´Ðзì϶
Cisco?RV110W Wireless-N VPN Firewall¡¢RV130W Wireless-N Multifunction VPN RouterºÍRV215W Wireless-N VPN Router WEB½Ó¿Ú´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190227-rmi-cmd-ex
4. Linux kernel net/ipv4/netfilter/nf_nat_snmp_basic_main.cÔ½½ç¶Áд·ì϶
Linux kernel net/ipv4/netfilter/nf_nat_snmp_basic_main.cûÓгä·Ö²é³ASN.1³¤¶È£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿É½øÐлؾø·þÎñ¹¥»÷»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c4c07b4d6fa1f11880eab8e076d3d060ef3f55fc
5. OpenSSL°²È«ÈƹýÐÅϢй¶·ì϶
OpenSSL´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉÈÆ¹ý°²È«ÏÞ¶È£¬£¬£¬£¬£¬£¬£¬»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£
https://www.openssl.org/news/secadv/20190226.txt
³ÁÒª°²È«ÊÂÎñ×ÛÊö

Group-IB×êÑÐÈËÔ±·¢ÏÖ69189ÕŰͻùË¹Ì¹ÒøÐп¨µÄÐÅÏ¢ÔÚ°µÍøÉÏÏúÊÛ¡£¡£¡£¡£¡£¡£ÕâÅúÊý¾Ý·ÖΪÁ½¸öÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬×ÜÊÛ¼ÛԼΪ350ÍòÃÀÔª¡£¡£¡£¡£¡£¡£µÚÒ»¸öÊý¾Ý¿âÊÇ1Ôµ×ÔÚJoker's StashÉϰ䲼µÄ£¬£¬£¬£¬£¬£¬£¬¹²Ô̺¬1535ÕÅÒøÐп¨ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ96£¥µÄÒøÐп¨¶¼ÓëMeezan BankÓйء£¡£¡£¡£¡£¡£µÚ¶þ¸öÊý¾Ý¿âÊÇ1ÔÂ30ÈÕÔÚJoker's StashÉϰ䲼µÄ£¬£¬£¬£¬£¬£¬£¬Ô̺¬67654ÕÅÒøÐп¨ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Í¬ÑùÓÐ96£¥µÄÒøÐп¨ÓëMeezan BankÓйء£¡£¡£¡£¡£¡£ÕâЩÊý¾Ý¿ÉÄܽ²ÁËÈ»¸ÃµØÓòÕë¶Ô½ðÈÚ»ú¹¹µÄ¹¥»÷ÕߵĻ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/81579/cyber-crime/pakistani-banks-cards-darkweb.html
2¡¢Èý¸ö4G/5G·ì϶£¬£¬£¬£¬£¬£¬£¬¿Éµ¼Ö¹¥»÷ÕßÈÆ¹ýÆä·À»¤Õ½Êõ
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/02/location-tracking-imsi-catchers.html
3¡¢Õë¶ÔInstagramÓû§µÄ¼±¾çÖ¸»È¦Ì×£¬£¬£¬£¬£¬£¬£¬Ú¿Æ½ð¶îÀۼƸߴï300ÍòÓ¢°÷
ÔÎÄÁ´½Ó£º
https://cyware.com/news/new-get-rich-quick-scheme-costs-instagram-users-over-3-million-61d5d384
4¡¢Chrome 0day·ì϶£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýPDFÍøÂçÓû§ÐÅÏ¢
ÔÎÄÁ´½Ó£º
https://cyware.com/news/google-chrome-zero-day-vulnerability-could-allow-attackers-to-collect-user-information-via-pdf-files-01b8df3d
5¡¢CoinomiÇ®°üÃ÷ÎÄ´«ÊäÓû§ÃÜÂ룬£¬£¬£¬£¬£¬£¬µ¼ÖÂÔ¼7ÍòÃÀÔª±»ÇÔ
ÔÎÄÁ´½Ó£º
https://cyware.com/news/cryptocurrency-wallet-coinomi-sends-users-passwords-to-googles-spellchecker-in-plain-text-3b3b794c
ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ