¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190109

°ä²¼¹¦·ò 2019-01-09
1¡¢Î¢Èí°ä²¼2019Äê1Ô°²È«¸üР£¬½¨¸´51¸ö·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

2019ÄêµÄµÚÒ»¸öWindows°²È«¸üй²½¨¸´ÁË51¸ö·ì϶ £¬³ÁÒªµÄ·ì϶Ô̺¬£ºDHCP¿Í»§¶ËËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2019-0547£©¡¢Hyper-VÐé¹¹»úÌÓÒÝ·ì϶£¨CVE-2019-0550ºÍCVE-2019-0551£©¡¢Skype for AndroidÖеÄËøÆÁÃÜÂëÈÆ¹ý·ì϶£¨CVE-2019-0622£©ÒÔ¼°Êý¾Ý¿âÒýÇæJetÖеÄRCE·ì϶£¨CVE-2019-0579£©µÈ¡£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-january-2019-patch-tuesday-includes-51-security-updates/


2¡¢Î¢Èí°ä·¢GitHubÃâÓöȻ§ÏÖ¿ÉÎÞÏÞ´´½¨Ë½Óд洢¿â

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


΢Èí°ä·¢GitHubÃâÓöȻ§´Ë¿ÌÄܹ»´´½¨ÎÞÏÞÁ¿µÄ¸öÈË´æ´¢¿â £¬ÔÚ´Ë֮ǰ £¬ÈôÊÇÄãÏë´´½¨¸öÈË´æ´¢¿â £¬ÄÇôÿÔÂÖÁÉÙ±ØÒªÖ§¸¶7ÃÀÔªµÄÓöÈ¡£´Ë¿ÌGitHubÃâÓöȻ§´´½¨µÄ¸öÈË´æ´¢¿â×î¶àÄܹ»Õ¼ÓÐ3ÃûºÏ×÷Õß £¬ÈôÊÇÄãÏëÔö³¤¸ü¶àµÄºÏ×÷Õß £¬ÄÇôÿÔ±ØÒªÖ§¸¶7ÃÀÔªÉý¼¶µ½¸ß¼¶ÕË»§¡£ÈôÊÇÄã֮ǰÒѾ­Ö§¸¶7ÃÀÔª £¬ÄÇôÄãÄܹ»Æ¾¾Ý×ÔÉíÐèÒª½µ¼¶ÎªÃâÓöȻ§ £¬Í¬Ê±Ë½Óд洢¿âµÄÄÚÈݾùÒѱ£Áô¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-announces-unlimited-private-repos-for-github-free/


3¡¢ÃÀ¹ú³ø·¿ÓþßÔì×÷ÉÌoxo.comÔâµ½MageCart¹¥»÷

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÃÀ¹ú³ø·¿ÓþßÔì×÷ÉÌOXO InternationalÔâµ½ºÚ¿Í¹¥»÷ £¬¿Í»§µÄ¸¶¿îÐÅÏ¢±»ÇÔ¡£Æ¾¾ÝOXOµÄÊý¾Ýй¶֪ͨ £¬ÔÚ2017Äê6ÔÂ9ÈÕ-2017Äê11ÔÂ28ÈÕ¡¢2018Äê6ÔÂ8ÈÕ-2018Äê6ÔÂ9ÈÕºÍ2018Äê7ÔÂ20ÈÕ-2018Äê10ÔÂ16ÈÕÆÚ¼ä £¬¿Í»§ÔÚÆäÍøÕ¾www.oxo.comÉÏÊäÈëµÄ¶©µ¥Ö§¸¶ÐÅÏ¢Êܵ½ÇÖº¦ £¬Ô̺¬ÐÅÓþ¿¨ÐÅÏ¢¡¢Õ˵¥µØÖ·¡¢µç×ÓÓʼþµØÖ·ºÍµç»°ºÅÂë¡£BleepingComputerµÄ½øÒ»²½×êÑÐÅú×¢ÖÁÉÙÓÐÒ»´Î¹¥»÷ÊÇMageCart¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/oxo-discloses-magecart-attack-that-targeted-customer-data-on-oxocom/


4¡¢ºÚ¿ÍÇÔÈ¡Titan Distributors¹«Ë¾½üÒ»ÄêµÄ¿Í»§Ö§¸¶Êý¾Ý

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Titan Distributors¹«Ë¾Ôâµ½ºÚ¿ÍÈëÇÖ £¬²¿Ãſͻ§µÄÖ§¸¶Êý¾Ý±»ÇÔ¡£¸Ã¹«Ë¾°µÊ¾ £¬2017Äê11ÔÂ23ÈÕÖÁ2018Äê10ÔÂ25ÈÕÆÚ¼äÆäÔÚÏßÉ̵걻ֲÈë¶ñÒâ´úÂë £¬ÕâЩ´úÂëÓÃÓÚÇÔÈ¡Óû§µÄÖ§¸¶ÐÅÏ¢ £¬Ô̺¬ÐÕÃû¡¢Õ˵¥µØÖ·¡¢µç»°ºÅÂë¡¢ÐÅÓþ¿¨ºÅÂë¡¢µ½ÆÚÈÕÆÚºÍÑéÖ¤Â롣ƾ¾ÝTitan˾·¨ÕÕ·÷Butler£¦SnowÏò»ªÊ¢¶ÙÖݼì²ì³¤·¢³öµÄÒ»·âÐÅ £¬ÊÜÓ°ÏìµÄÓû§ÊýÁ¿Îª1838ÈË¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/79595/hacking/titan-manufacturing-security-breach.html


5¡¢Ó¡¶È³¬¹ý1.1ÍòÁ¾¹«¹²Æû³µµÄʵʱGPS×ø±êÔÚÆØ¹â

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

°²È«×êÑÐÔ±Justin Paine·¢ÏÖÒ»¸öδÉèÃÜÂëµÄElasticSearch·þÎñÆ÷ £¬¸Ã·þÎñÆ÷Ô̺¬À´×Ô27¼ÒÓ¡¶È¹úÓÐÔËÊä»ú¹¹µÄÊý¾Ý £¬ÆäÖÐÔ̺¬³¬¹ý1.1ÍòÁ¾¹«¹²Æû³µµÄʵʱGPS×ø±êºÍ·ÏßÐÅÏ¢¡£·ÖÆçÔËÊä»ú¹¹µÄÊý¾Ý²¢²»Ò»Ñù £¬ÔÚijЩ°¸ÀýÖÐ £¬»¹Ô̺¬³Ë¿ÍµÄÓû§ÃûºÍµç×ÓÓʼþµØÖ·¡£¸Ã·þÎñÆ÷ÖÁÉÙÒÑÔÚ»¥ÁªÍøÉÏÆØ¹âÁËÈýÖܵŦ·ò¡£ÔÚPaine֪ͨӡ¶ÈCERTºó £¬¸Ã·þÎñÆ÷µÃµ½±£»¤ £¬µ«CERT»Ø¾øÐ¹Â©¸Ã·þÎñÆ÷µÄËùÓÐÕß¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/real-time-location-data-for-over-11000-indian-buses-left-exposed-online/


6¡¢Ê®¶à¿îiOSÓÎÏ·±»·¢ÏÖÏòGolduckµÄC&C·þÎñÆ÷·¢ËÍÐÅÏ¢

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÍŶÓWandera·¢ÏÖApp StoreÉϵÄ14¿îÓÎÏ·Ïò¶ñÒâÈí¼þGolduck LoaderµÄÒÑÖªC&C·þÎñÆ÷·¢ËÍÊý¾Ý¡£GolduckÊÇÒ»¸ö¸æ°×Èí¼þ·Ö·¢Æ½Ì¨ £¬×êÑÐÈËÔ±·¢ÏÖÕâÊ®¶à¿îiOSÓÎÏ·²û·¢³öÓëϰȾÁËGolduckµÄAndroidÀûÓÃÀàËÆµÄÐÐΪ £¬¼´ÔÚÀûÓ÷¨Ê½Ö÷ÆÁÄ»µÄ¶à¸öÇøÓò×¢Èë¸æ°×¡£´Ë±í £¬ÕâЩÓÎÏ·»¹ÏòGolduckµÄC£¦C·þÎñÆ÷·¢ËÍ´óÁ¿ÐÅϢƬ¶Î £¬Ô̺¬IPµØÖ·¡¢µØÎ»Êý¾Ý¡¢É豸ÀàÐͺÍÉ豸ÉÏÏÔʾµÄ¸æ°×ÊýÁ¿µÈ¡£App StoreÒѾ­Ï¼ÜÁËÕâЩÓꦵÄÀûÓá£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/apple-ios-games-found-talking-to-golduck-malware-candc-servers/


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù