GitHub½¨¸´9¸öGit·ì϶ £¬¶½´ÙÓû§½øÐиüР£»¿¨°Í˹»ù°ä²¼2019ÄêÍøÂçÍþвµÄͳ¼ÆÊý¾Ý»ã±¨

°ä²¼¹¦·ò 2019-12-16


1.GitHub½¨¸´9¸öGit·ì϶ £¬¶½´ÙÓû§½øÐиüÐÂ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚ½¨¸´GitÖеÄ9¸ö·ì϶֮ºó £¬GitHub¶½´ÙÓû§Ö´ÐÓ×°¹Ø¼ü¡±µÄGitÏîÄ¿´úÂë¸üС£ÕâЩ·ì϶ÊÇÓÉGitLabµÄJoern SchneeweiszºÍ΢Èí°²È«ÏìÓ¦ÖÐÐÄ·¢ÏÖ²¢»ã±¨µÄ £¬GitHubÖ¸³ö£º¡°ÈôÊǿˡ²»ÊÜÐÅÀµµÄ´æ´¢¿â £¬³ýÁ˸üÐÂÖ®±íûÓв½ÖèÄܹ»Ô¤·À±¾ÎÄÖÐÅû¶µÄÈκηì϶´øÀ´µÄ·çÏÕ¡±¡£ÕâЩÎÊÌâ½öÓ°ÏìÁËWindowsƽ̨ £¬¹¥»÷Õß¿ÉÄÜÀûÓ÷ì϶¸²¸ÇËÁÒâõè¾¶¡¢Ô¶³ÌÖ´ÐдúÂëÒÔ¼°¸²¸Ç.git/Ŀ¼ÏµÄÎļþµÈ¡£·ì϶µÄ±àºÅΪCVE-2019-1348~CVE-2019-1354ºÍCVE-2019-1387 £¬ÆëÈ«ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£


  Ô­ÎÄÁ´½Ó£º

https://www.cbronline.com/news/git-project-patches


2.NpmÍŶÓÕë¶Ôеġ°¶þ½øÔìÖ²È롱·ì϶·¢³öÖÒ¸æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


NpmÍŶӰ䲼°²È«¾¯±¨ £¬½¨ÒéËùÓÐЧ»§¸üÐÂÖÁ×îа汾£¨6.13.4£© £¬ÒÔÔ¤·À¡°¶þ½øÔìÖ²È롱¹¥»÷¡£¸Ã·ì϶ÊÇÎļþ±éÀúºÍËÁÒâÎļþ¸²¸ÇÎÊÌâµÄ×éºÏ £¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ֲÈë¶ñÒâ¶þ½øÔìÎļþ»ò¸²¸ÇÓû§ÍÆËã»úÉϵÄÎļþ¡£¸Ã·ì϶½öÔÚͨ¹ýnpmºÅÁîÐпͻ§¶Ë£¨CLI£©×°ÖÃÊÜϰȾµÄÈí¼þ°üÆÚ¼ä²Å»á´¥·¢¡£Npm¿ª·¢ÈËÔ±°µÊ¾ËûÃÇÒ»ÏòÔÚnpmÃÅ»§ÖÐɨÃè¿ÉÄÜÔ̺¬´Ë·ì϶ÀûÓõÄÈí¼þ°ü £¬µ«Î´·¢ÏÖÈκοÉÒɰ¸Àý¡£³ýÁËnpmÖ®±í £¬ÁíÒ»¸öJavaScript°üÖÎÀíÆ÷yarnÒ²Êܵ½Ó°Ïì £¬yarnÍŶÓÔÚа汾1.21.1Öн¨¸´Á˸ÃÎÊÌâ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/npm-team-warns-of-new-binary-planting-bug/


3.ÂÞÂíÄáÑÇ·¸×ïÍÅ»ïÀûÓÃÍÚ¿óÈí¼þϰȾ40¶àÍòÓû§


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾Ý¶íº¥¶íÖݱ±ÇøÃÀ¹ú¼ì²ì¹Ù°ì¹«ÊÒµÄÐÂΟå £¬ÂÞÂíÄáÑǵÄÒ»¸öÍøÂç·¸×ïÍÅ»ïͨ¹ý¶ñÒâÍÚ¿óÈí¼þϰȾÁ˳¬¹ý40ÍòÌ¨ÍÆËã»ú¡£¸ÃÍÅ»ïµÄÃû³ÆÎªBayrob Group £¬ËüÒÑÔÚ°µÍøÉÏÏúÊÛ±»µÁµÄÓû§ÐÅÏ¢¡£Æ¾¾ÝÕÆ¹Ü´Ë°¸µÄFBI¼éϸEric SmithµÄ˵·¨ £¬¸ÃÍÅ»ï×Ô2007ÄêÆðÍ·»î¶¯ £¬ÖØÒªÕë¶ÔÃÀ¹ú¹«ÃñµÄÍÆËã»ú½øÐÐÍÚ¿ó £¬²¢ÇÒÇÔÈ¡²ÆÕþÐÅÏ¢¡¢ÃÜÂë¡¢µç×ÓÓʼþµÈÓ×ÎÒÐÅÏ¢¡£Æä¶ñÒâÈí¼þÖØÒªÍ¨¹ý¼Ù×°³ÉÒøÐкͰ²È«³§É̵ĵç×ÓÓʼþ´«²¼¡£¾Ý³Æ¸ÃÍÅ»ïÒѾ­»ñÀû³¬¹ý400ÍòÃÀÔª £¬µ«Ä¿Ç°²¢²»Ã÷ÏÔÆäÖÐÓм¸¶àÀ´×ÔÍÚ¿ó¹¥»÷¡£


 Ô­ÎÄÁ´½Ó£º

https://finance.yahoo.com/news/romanian-cybergang-infects-over-400-100025512.html


4.ÐÂÔóÎ÷ÖÝHackensackÒ½ÔºÔâµ½ÀÕË÷Èí¼þ¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÐÂÔóÎ÷ÖÝ×î´óµÄÒ½ÔºHackensack Meridian Health³ÉΪÀÕË÷Èí¼þ¹¥»÷µÄÊܺ¦Õß £¬ÆäÄÚ²¿ÍøÂçÔâÀÕË÷Èí¼þ·ÛËé £¬¸ÃÒ½Ôº¾ö¶¨Ö§¸¶Êê½ðÒÔ½âÃÜÎļþ¡£¸ÃҽԺûÓÐй©¹¥»÷ÕßʹÓõÄÀÕË÷Èí¼þÀàÐÍ £¬Ò²Ã»ÓÐй©¹¥»÷ÕßÈëÇֵķ½Ê½ºÍÒÑÖ§¸¶µÄÊê½ð½ð¶î £¬µ«°µÊ¾¹¥»÷²úÉúÔÚ12ÔÂ2ÈÕ £¬ÆÈʹÆäÈ¡µÞÁËһЩ±í¿ÆÊÖÊõºÍÆäËü·¨Ê½¡£Ä¿Ç°ÆäÍøÂçµÄÖØÒªÁÙ´²ÏµÍ³ÒѸ´Ô­ÔËÐÐ £¬²¢ÇÒITר¼ÒÔÚÖÂÁ¦Ê¹ÆäËùÓеÄÀûÓ÷¨Ê½¸´Ô­ÔÚÏß¡£¸ÃÒ½Ôº»¹°µÊ¾ £¬Ã»Óм£ÏóÅú×¢¹¥»÷Õß½Ó¼ûÁË»¼ÕßµÄÐÅÏ¢¡£


 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95152/cyber-crime/new-jersey-hospital-ransomware-attack.html


5.ÒÁÀÊÐû³Æ×î½üÁ½´Î´ì°ÜÕë¶ÔÆä»ù´¡ÉèÊ©µÄÍøÂç¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÒÁÀʵçÐŲ¿³¤Äº±Ä¬µÂ¡¤¼ÖÍߵ¡¤°¢ÔúÀ¼Ö»ôÃ×(Mohammad Javad Azari Jahromi)°µÊ¾ÒÁÀÊÔÚÒ»ÖÜÄÚµÚ¶þ´Î´ì°ÜÕë¶ÔÆä»ù´¡ÉèÊ©µÄÍøÂç¹¥»÷¡£¸ÃÐÂÎÅÊÇÓÉISNAºÍMehrÐÂÎÅÉ籨·µÄ £¬¼Ö»ôÃ×½«Õâ´Î¹¥»÷½ç˵Ϊ´ó¹æÄ£¹¥»÷ £¬²¢½«Æä¹éÓÉÓÚAPT27¡£APT27×Ô2010ÄêÒÔÀ´Ò»Ïò»îÔ¾ £¬ÖØÒªÕë¶ÔÃÀ¹úµÄ¹ú·À³Ð°üÉÌ¡¢½ðÈÚ·þÎñ¹«Ë¾ºÍÖÐÑǹú¶ÈÊý¾ÝÖÐÐĵÈ¡£¼Ö»ôÃ×ûÓÐй©¹¥»÷µÄϸ½ÚÒÔ¼°¹¥»÷ÕßÕë¶ÔµÄ¾ßÌåÖ¸±ê¡£


 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95169/apt/iran-foiled-2-attack.html


6.¿¨°Í˹»ù°ä²¼2019ÄêÍøÂçÍþвµÄͳ¼ÆÊý¾Ý»ã±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ù°ä²¼2019ÄêÍøÂçÍþвͳ¼ÆÊý¾Ý»ã±¨ £¬¸Ã»ã±¨ÊÇ»ùÓÚ2018Äê11Ôµ½2019Äê10ÔÂÆÚ¼ä´ÓÈ«Çò203¸ö¹ú¶ÈºÍµØÓòµÄKSNÓû§ÍøÂçµÄ¶ñÒâ»î¶¯Êý¾Ý¡£Ôڻ㱨ÆÚ¼ä £¬ÓÐ19.8%µÄÓû§ÍÆËã»úÖÁÉÙÔâ·êÒ»´Î¶ñÒâÈí¼þÀà´ËÍâÍøÂç¹¥»÷¡£¿¨°Í˹»ù°²È«½â¾ö¹æ»®×èÖ¹ÁËÀ´×ÔÈ«ÇòÔÚÏß×ÊÔ´µÄ9.7Òڴι¥»÷¡£Web·´²¡¶¾×é¼þ¼ø±ð³ö2.7ÒÚ¸ö·ÖÆçµÄ¶ñÒâURL¡£ÍøÂç·À²¡¶¾Èí¼þ¼ì²âµ½2461Íò¸ö·ÖÆçµÄ¶ñÒâÑù±¾¡£75.5Íò¸öÓû§ÍÆËã»úÔâµ½ÀÕË÷Èí¼þ¹¥»÷¡£226ÍòÓû§ÍÆËã»úÔâµ½¶ñÒâÍÚ¿ó¹¥»÷¡£¿¨°Í˹»ù°²È«½â¾ö¹æ»®ÔÚ76.6Íǫ̀É豸ÉÏ×èÖ¹ÁËÕë¶ÔÔÚÏßÒøÐÐÕË»§µÄ¶ñÒâÈí¼þ¹¥»÷¡£


 Ô­ÎÄÁ´½Ó£º

https://securelist.com/kaspersky-security-bulletin-2019-statistics/95475/