ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ10ÖÜ
°ä²¼¹¦·ò 2019-03-11±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ΢Èí°ä²¼°²È«»ã±¨Volume 24£¬2018Äê´¹µö¹¥»÷Ôö³¤250£¥£»×êÑÐÅú×¢2018Äê²úÉú12449ÆðÊý¾Ýй¶ÊÂÎñ£¬±È2017ÄêÔö³¤424%£»Dalil¹«Ë¾MongoDB¿É¹«¿ª½Ó¼û£¬500¶àÍòÓû§Êý¾Ýй¶£»2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾ÖУ¬WordPressÕ¼90%£»×êÑÐÍŶӷ¢ÏÖ2Ô·ÝÀÕË÷Èí¼þShadeµÄ¹¥»÷»î¶¯ìÉý¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
³ÁÒª°²È«·ì϶Áбí
Cisco NX-OS Software CLIÑéÖ¤²ÎÊý´æÔÚ°²È«·ì϶£¬ÔÊÐí±¾µØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÌáÉýȨÏÞÖ´ÐÐËÁÒâosºÅÁî¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-cmdinj-1610
2. Google Chrome FileReader¿ªÊͺóʹÓôúÂëÖ´Ðзì϶
Google Chrome FileReaderµÄʵÏÖ´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨¶ñÒâWEBÒ³£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html
3. Adobe ColdFusion CVE-2019-7816ÎļþÉÏ´«ÏÞ¶ÈÈÆ¹ý·ì϶
Adobe ColdFusionÎļþÉÏ´«ÊµÏÖ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÉÏ´«ËÁÒâÎļþ£¬²¢Ö´ÐС£
https://helpx.adobe.com/security/products/coldfusion/apsb19-14.html
4. Samsung Galaxy S9Éí·ÝÑéÖ¤´úÂëÖ´Ðзì϶
Samsung Galaxy S9 GameServiceReceiver¸üлúÔì´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-19-255/
5. Nokia Alcatel Lucent I-240W-Q GPON ONT CVE-2019-3922»º³åÇøÒç¶Âí½Å
Nokia Alcatel Lucent I-240W-Q GPON ONT´¦ÖÃÌØÊâµÄHTTP POSTÒªÇó´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâ´úÂë¡£
https://www.tenable.com/security/research/tra-2019-09
³ÁÒª°²È«ÊÂÎñ×ÛÊö
ƾ¾Ý΢ÈíµÄ°²È«µý±¨»ã±¨£¨SIR£©Volume 24£¬ÔÚ2018Äê1ÔÂÖÁ12ÔÂÆÚ¼ä£¬ÍøÂç´¹µö¹¥»÷Ôö³¤ÁË250%¡£¹¥»÷ÕßÔÚÔËÓªÍøÂç´¹µö»î¶¯Ê±Ñ¡È¡¶àÑù»¯µÄ»ù´¡ÉèÊ©£¬Ô̺¬ÍйܷþÎñÆ÷ºÍ¹«¹²ÔƵȡ£ÁíÒ»·½Ã棬2018ÄêÆÚ¼ä¶ñÒâÈí¼þµÄÊýÁ¿½µÂäÁËÔ¼34%¡£´Ë±í£¬Ëæ×Å2018ÄêËêĺ¼ÓÃÜÇ®±Ò¼ÛÖµµÄ×ÅÂ䣬¶ñÒâÍÚ¿ó»î¶¯Ò²½µÂäÁË36%¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-sees-250-percent-phishing-increase-malware-decline-by-34-percent/
2¡¢×êÑÐÅú×¢2018Äê²úÉú12449ÆðÊý¾Ýй¶ÊÂÎñ£¬±È2017ÄêÔö³¤424%
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/12-449-data-breaches-confirmed-in-2018-a-424-percent-increase-over-the-previous-year/
3¡¢Dalil¹«Ë¾MongoDB¿É¹«¿ª½Ó¼û£¬500¶àÍòÓû§Êý¾Ýй¶
ÔÎÄÁ´½Ó£º
https://www.vpnmentor.com/blog/dalil-data-breach/
4¡¢2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾ÖУ¬WordPressÕ¼90%
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/wordpress-accounted-for-90-percent-of-all-hacked-cms-sites-in-2018/
5¡¢×êÑÐÍŶӷ¢ÏÖ2Ô·ÝÀÕË÷Èí¼þShadeµÄ¹¥»÷»î¶¯ìÉý
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/threat-analysis/2019/03/spotlight-troldesh-ransomware-aka-shade/
ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ