F5°ä²¼2019ÄêTLSÒ£²â»ã±¨£¬¹Ø×¢¼ÓÃÜÁìÓòµÄ·¢Õ¹ £»2019Äê61£¥µÄ¹Ø¼üͨѶÐÐÒµÔâ·ê¶ñÒâÈí¼þ¹¥»÷

°ä²¼¹¦·ò 2020-03-02

1.F5°ä²¼2019ÄêTLSÒ£²â»ã±¨£¬¹Ø×¢¼ÓÃÜÁìÓòµÄ·¢Õ¹


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


F5³¢ÊÔÊÒ°ä²¼¡¶2019ÄêTLSÒ£²â»ã±¨¡·£¬¸Ã»ã±¨ÌṩÁËÓйØÍøÂç¼ÓÃÜÈôºÎ²»ÐÝ·¢Õ¹µÄÉî¿Ì¼û½â¡£¸Ã»ã±¨×êÑÐÁËInternet¶¥¼¶ÍøÕ¾Ê¹ÓÃÄÄÖÖ¼ÓÃÜÆ÷ºÍSSL/TLS°æ±¾½øÐб £»¤£¬²¢³õ´Î²é³­ÁËWebÉÏÊý×ÖÖ¤ÊéµÄʹÓúͲ鿴ÁËÖ§³ÖµÄºÍ̸£¨ÈçDNS£©ºÍÀûÓ÷¨Ê½²ã±êÍ·¡£¼¼ÊõÌṩÉÌÓëµ±¾ÖÖ®¼äµÄÈ«ÇòÕù³³£¨Ò²³ÆÎªCrypto Wars 2.0£©ÈÔÔÚ³ÖÐø¡£µ±¾ÖÔ½À´Ô½¶àµØ³¢ÊÔ½ÚÔì¼ÓÃܵÄʹÓ÷½Ê½£¬²¢ÇÒÎÒÃǾ­³£¿´µ½Á¢·¨²»ÃÀÂú£¨»òÓÐÒâ³éÏ󣩵ÄÁ¢·¨¡£ChromeÊÇʹÓÃ×î¿í·ºµÄÍøÂçä¯ÀÀÆ÷£¬ÆäÄܹ»Í¨¹ý°²È«µÄHTTPSÏνӽӼû³¬¹ý86%µÄÍøÒ³£¬FirefoxµÄÊý×ÖÉԵͣ¬µ«Ò²ÓÐ80.5%¡£ÔÚAlexaÅÅÃûǰ100ÍòµÄÍøÕ¾ÖУ¬½üÈý·ÖÖ®Ò»´Ë¿Ì½ÓÊÜTLS 1.3ÏνÓ¡£


Ô­ÎÄÁ´½Ó£º

https://www.f5.com/content/dam/f5-labs-v2/article/pdfs/F5Labs-2019-TLS-Telemetry-Report-Summary.pdf


2.Ó¢¹ú²â»æ»ú¹¹Ordnance SurveyÔâºÚ¿ÍÈëÇÖ£¬Ô±¹¤Êý¾Ýй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾Ý±íý±¨Â·£¬Ó¢¹ú²â»æ»ú¹¹Ordnance SurveyÔâµ½ºÚ¿ÍÈëÇÖ£¬µ¼Ö½ü1000ÃûÔ±¹¤µÄÊý¾Ýй¶¡£¾Ý³Æµ±¾ÖÓÚ1Ô·ݷ¢ÏÖ²¢µ±¼´ÏìÓ¦ÁËÈëÇÖÊÂÎñ£¬²¢ÇÒ֪ͨÁËÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©£¬µ«¸ÃÊÂÎñÖ±µ½´Ë¿Ì²Å±»¹«¿ª¡£Ä¿Ç°Éв»Ã÷ÏÔÈëÇÖ²úÉúµÄ¾ßÌ幦·ò£¬µ«¾ÝVerdict³Æ£¬¹¥»÷ÕßÊÇͨ¹ýÍøÂç´¹µö¹¥»÷ÈëÇÖÁËCFOµÄµç×ÓÓʼþÕË»§£¬´Ó¶øÇÔÈ¡Á˹¤×ʵ¥Îļþ¡£Ordnance Survey°µÊ¾Ã»ÓÐÈκοͻ§ÐÅϢй¶£¬Æä×ÔÉíµÄϵͳҲ²»ÊÜÓ°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/ordnance-survey-breach-hits/?&web_view=true


3.ÃÀ¹úWalgreensÒ©µêÒÆ¶¯APP´æÔÚ·ì϶й¶Óû§ÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úµÚ¶þ´óÒ©µêÎÖ¶û¸ñÁÖ£¨Walgreens£©°µÊ¾Æä¹Ù·½Òƶ¯APP´æÔÚÒ»¸ö·ì϶£¬µ¼Ö²¿ÃÅÓû§µÄÓ×ÎÒÐÅϢй¶¡£¸Ã·ì϶±»ÃèÊöΪAPPÓ×ÎÒ°²È«ÐÂÎÅ´«µÝÖ°ÄÜÖеÄÃýÎ󣬿ÉÄÜй¶µÄÐÅÏ¢Ô̺¬Óû§µÄÐÕÃû¡¢´¦·½¾ßÌåÐÅÏ¢¡¢É̵ê±àºÅºÍËÍ»õµØÖ·£¨ÈôÊÇÓУ©¡£ÕâЩÊý¾Ý¶³öµÄ¹¦·òΪ1ÔÂ9ÈÕ£¨ÐÇÆÚËÄ£©ºÍ1ÔÂ15ÈÕ£¨ÐÇÆÚÈý£©Ö®¼ä£¬WalgreensÒÑÓÚ1ÔÂ15ÈÕµÃÖª·ì϶ȷµ±Ì콨¸´Á˸ÃÎÊÌâ¡£¸Ã¹«Ë¾Ã»ÓÐй©¾ßÌåÊÜÓ°ÏìÓû§µÄÊýÁ¿£¬µ«°µÊ¾Ãô¸Ð´¦·½ÐÅϢй¶µÄÓû§Õ¼ÊÜÓ°ÏìÓû§×ÜÊýµÄÒ»Óײ¿ÃÅ¡£¸ÃAPPÔÚGoogle PlayÉ̵êÖеÄÏÂÔØ´ÎÊýΪ³¬¹ý1000Íò´Î£¬ÔÚiOSÖÐµÄÆÀ·ÖÊýÁ¿³¬¹ý250Íò¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/walgreens-says-mobile-app-leaked-users-personal-data/


4.2019Äê61£¥µÄ¹Ø¼üͨѶÐÐÒµÔâ·ê¶ñÒâÈí¼þ¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾Ý¹ú¼ÊÎÞÏßͨѶչÀÀ»á£¨IWCE£©µÄµ÷ÑУ¬ÔÚ´ÓǰµÄ12¸öÔÂÖÐÓÐÎå·ÖÖ®Ò»µÄ¹Ø¼üͨѶÐÐÒµÔâ·êÁ˰²È«ÊÂÎñ¡£ÎªÁ˶Ե±Ç°¼¼Êõ½øÐлù×¼²âÊÔ£¬IWCE¶Ô¹Ø¼üͨѶÐÐÒµµÄÖÁÉÙ597ÃûרҵÈËÔ±½øÐÐÁ˵÷²é¡£¸Ãµ÷²é»¹»ØÊ×ÁËÐÐÒµÄڵļ¼ÊõÌôÕ½¡£Í¨¹ý¸Ãµ÷²é£¬61£¥µÄÊÜ·ÃÕß°µÊ¾Ôâ·êÁ˶ñÒâÈí¼þ¹¥»÷£¬56£¥ÔòÊÇÍøÂç´¹µö¹¥»÷µÄÊܺ¦Õߣ¬27£¥°µÊ¾´¦ÖùýÀÕË÷Èí¼þ£¬22%Ôâ·êÊý¾Ýй¶ÊÂÎñ£¬16%Ôâµ½DDoS¹¥»÷¡£10£¥µÄµÄÊÜ·ÃÕ߻㱨³ÆÔâµ½¸ß¼¶Íþв¹¥»÷£¬ÔÚ´ËÀ๥»÷Öй¥»÷Õßͨ³£³¤¹¦·òÂñ·üÔÚÆäÍøÂçÖС£ÍøÂç¹¥»÷·ÛËéÁËÕý³£µÄÔËÓªºÍ·þÎñ£¬Æä½¨¸´³É±¾Îª£º38£¥µÄ³É±¾²»µ½10ÍòÃÀÔª£¬10£¥µÄ³É±¾ÔÚ10ÍòÃÀÔªÖÁ100ÍòÃÀÔªÖ®¼ä£¬¶ø2£¥µÄ³É±¾ÔÚ100ÍòÖÁ1000ÍòÃÀÔªÖ®¼ä¡£ºÜ¶à¹«Ë¾£¨64%£©ÔÚÓëµÚÈý·½¹©¸øÉÌÇ©¶¨Êý¾Ý± £»¤ºÍÍøÂ簲ȫºÍ̸£¬ÓÉÓÚ¹¥»÷¼°ÆäÓ°Ïì¿ÉÄÜÀ´×ÔµÚÈý·½¡£


Ô­ÎÄÁ´½Ó£º

https://finbold.com/61-percent-critical-communications-industry-suffers-malware-attacks/


5.2019Äê·¸×ïÍÅ»ïTA505»ý¼«Õë¶Ôº«¹ú½ðÈÚ»ú¹¹


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


º«¹ú½ðÈÚ°²È«×êÑÐËù£¨Financial Security Institute£©×êÑÐÈËÔ±°µÊ¾£¬TA505ÔÚ2019ÄêµÄ´ó²¿Ãʦ·òÀï¶¼ÔÚ³¢ÊÔÕë¶Ôº«¹ú½ðÈÚ¡¢Ôì×÷ºÍÒ½ÁÆ·þÎñÆóÒµÌáÒé´¹µö¹¥»÷¡£·¸×ïÍÅ»ïTA505×Ô2014ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬²¢ÇÒËÆºõÓë·¸×ïÍÅ»ïFIN7¹²Ïí¹¤¾ß¡¢¼¼ÊõºÍ·¨Ê½¡£×êÑÐÈËÔ±°µÊ¾TA505·¢Ë͵ĺܶàÍøÂç´¹µöÓʼþ¶¼Ô̺¬¶ñÒâExcelÎĵµ£¬²¢ÇÒʹÓÃÔ¶¿ØÄ¾ÂíFlawedAmmyy¼à¶½Óû§µÄ»î¶¯ºÍÍøÂçÓû§Ãû/ÃÜÂë¡£´Ë±í£¬TA505»¹Ôڶ̹¦·òÄÚʹÓÃÁËÒ»ÖÖÃûΪRapidµÄÀÕË÷Èí¼þ¡£


Ô­ÎÄÁ´½Ó£º

https://www.cyberscoop.com/ta505-south-korea-bank-phishing/


6.ºÚ¿ÍÀûÓÃWooCommerce²å¼þ0day¹¥»÷ÊýÍò¸öWordPressÍøÕ¾


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ºÚ¿ÍÔÚÀûÓÃWordPress²å¼þÖеÄ0day¹¥»÷ÊýÒÔÍò¼ÆµÄÍøÕ¾£¬ÕâЩ·ì϶ʹËûÃÇÄܹ»´´½¨¶ñÒâÖÎÀíÔ¹ØÊ»§²¢Ö²ÈëºóÃÅ·¨Ê½¡£NinTechNet×êÑÐÈËÔ±ÔÚWooCommerce²å¼þµÄFlexible Checkout×Ö¶ÎÖз¢ÏÖ´æ´¢ÐÍXSS 0day£¬¸Ã²å¼þµÄ×°ÖÃÊýÁ¿Îª2Íò¡£²å¼þ¿ª·¢ÍŶÓÔÚ½Óµ½»ã±¨ºóѸ¿ìÍÆ³öÁË2.3.2°æ±¾ÒÔ½¨¸´¸Ã·ì϶£¬µ«ÈÔÓÐһЩÓû§Ôâµ½¹¥»÷¡£´Ë±í£¬Defiant×êÑÐÈËÔ±»¹ÔÚÆäËü¼¸¸ö²å¼þÖз¢ÏÖ3¸ö0day£¬Ô̺¬Async JavaScript£¨10Íò+×°Öã©¡¢10Web Map Builder for Google Maps£¨2Íò+×°Öã©¡¢ Modern Events Calendar Lite£¨4Íò+×°Öã©ÖеĴ洢ÐÍXSS¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-bugs-in-wordpress-plugins-let-hackers-take-over-sites/