¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190109

°ä²¼¹¦·ò 2019-01-09
1¡¢Î¢Èí°ä²¼2019Äê1Ô°²È«¸üУ¬½¨¸´51¸ö·ì϶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

2019ÄêµÄµÚÒ»¸öWindows°²È«¸üй²½¨¸´ÁË51¸ö·ì϶£¬³ÁÒªµÄ·ì϶Ô̺¬£ºDHCP¿Í»§¶ËËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2019-0547£©¡¢Hyper-VÐé¹¹»úÌÓÒÝ·ì϶£¨CVE-2019-0550ºÍCVE-2019-0551£©¡¢Skype for AndroidÖеÄËøÆÁÃÜÂëÈÆ¹ý·ì϶£¨CVE-2019-0622£©ÒÔ¼°Êý¾Ý¿âÒýÇæJetÖеÄRCE·ì϶£¨CVE-2019-0579£©µÈ¡£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-january-2019-patch-tuesday-includes-51-security-updates/


2¡¢Î¢Èí°ä·¢GitHubÃâÓöȻ§ÏÖ¿ÉÎÞÏÞ´´½¨Ë½Óд洢¿â

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


΢Èí°ä·¢GitHubÃâÓöȻ§´Ë¿ÌÄܹ»´´½¨ÎÞÏÞÁ¿µÄ¸öÈË´æ´¢¿â£¬ÔÚ´Ë֮ǰ£¬ÈôÊÇÄãÏë´´½¨¸öÈË´æ´¢¿â£¬ÄÇôÿÔÂÖÁÉÙ±ØÒªÖ§¸¶7ÃÀÔªµÄÓöÈ¡£´Ë¿ÌGitHubÃâÓöȻ§´´½¨µÄ¸öÈË´æ´¢¿â×î¶àÄܹ»Õ¼ÓÐ3ÃûºÏ×÷Õߣ¬ÈôÊÇÄãÏëÔö³¤¸ü¶àµÄºÏ×÷Õߣ¬ÄÇôÿÔ±ØÒªÖ§¸¶7ÃÀÔªÉý¼¶µ½¸ß¼¶ÕË»§¡£ÈôÊÇÄã֮ǰÒѾ­Ö§¸¶7ÃÀÔª£¬ÄÇôÄãÄܹ»Æ¾¾Ý×ÔÉíÐèÒª½µ¼¶ÎªÃâÓöȻ§£¬Í¬Ê±Ë½Óд洢¿âµÄÄÚÈݾùÒѱ£Áô¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-announces-unlimited-private-repos-for-github-free/


3¡¢ÃÀ¹ú³ø·¿ÓþßÔì×÷ÉÌoxo.comÔâµ½MageCart¹¥»÷

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

ÃÀ¹ú³ø·¿ÓþßÔì×÷ÉÌOXO InternationalÔâµ½ºÚ¿Í¹¥»÷£¬¿Í»§µÄ¸¶¿îÐÅÏ¢±»ÇÔ¡£Æ¾¾ÝOXOµÄÊý¾Ýй¶֪ͨ£¬ÔÚ2017Äê6ÔÂ9ÈÕ-2017Äê11ÔÂ28ÈÕ¡¢2018Äê6ÔÂ8ÈÕ-2018Äê6ÔÂ9ÈÕºÍ2018Äê7ÔÂ20ÈÕ-2018Äê10ÔÂ16ÈÕÆÚ¼ä£¬¿Í»§ÔÚÆäÍøÕ¾www.oxo.comÉÏÊäÈëµÄ¶©µ¥Ö§¸¶ÐÅÏ¢Êܵ½ÇÖº¦£¬Ô̺¬ÐÅÓþ¿¨ÐÅÏ¢¡¢Õ˵¥µØÖ·¡¢µç×ÓÓʼþµØÖ·ºÍµç»°ºÅÂë¡£BleepingComputerµÄ½øÒ»²½×êÑÐÅú×¢ÖÁÉÙÓÐÒ»´Î¹¥»÷ÊÇMageCart¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/oxo-discloses-magecart-attack-that-targeted-customer-data-on-oxocom/


4¡¢ºÚ¿ÍÇÔÈ¡Titan Distributors¹«Ë¾½üÒ»ÄêµÄ¿Í»§Ö§¸¶Êý¾Ý

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

Titan Distributors¹«Ë¾Ôâµ½ºÚ¿ÍÈëÇÖ£¬²¿Ãſͻ§µÄÖ§¸¶Êý¾Ý±»ÇÔ¡£¸Ã¹«Ë¾°µÊ¾£¬2017Äê11ÔÂ23ÈÕÖÁ2018Äê10ÔÂ25ÈÕÆÚ¼äÆäÔÚÏßÉ̵걻ֲÈë¶ñÒâ´úÂ룬ÕâЩ´úÂëÓÃÓÚÇÔÈ¡Óû§µÄÖ§¸¶ÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢Õ˵¥µØÖ·¡¢µç»°ºÅÂë¡¢ÐÅÓþ¿¨ºÅÂë¡¢µ½ÆÚÈÕÆÚºÍÑéÖ¤Â롣ƾ¾ÝTitan˾·¨ÕÕ·÷Butler£¦SnowÏò»ªÊ¢¶ÙÖݼì²ì³¤·¢³öµÄÒ»·âÐÅ£¬ÊÜÓ°ÏìµÄÓû§ÊýÁ¿Îª1838ÈË¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/79595/hacking/titan-manufacturing-security-breach.html


5¡¢Ó¡¶È³¬¹ý1.1ÍòÁ¾¹«¹²Æû³µµÄʵʱGPS×ø±êÔÚÆØ¹â

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

°²È«×êÑÐÔ±Justin Paine·¢ÏÖÒ»¸öδÉèÃÜÂëµÄElasticSearch·þÎñÆ÷£¬¸Ã·þÎñÆ÷Ô̺¬À´×Ô27¼ÒÓ¡¶È¹úÓÐÔËÊä»ú¹¹µÄÊý¾Ý£¬ÆäÖÐÔ̺¬³¬¹ý1.1ÍòÁ¾¹«¹²Æû³µµÄʵʱGPS×ø±êºÍ·ÏßÐÅÏ¢¡£·ÖÆçÔËÊä»ú¹¹µÄÊý¾Ý²¢²»Ò»Ñù£¬ÔÚijЩ°¸ÀýÖУ¬»¹Ô̺¬³Ë¿ÍµÄÓû§ÃûºÍµç×ÓÓʼþµØÖ·¡£¸Ã·þÎñÆ÷ÖÁÉÙÒÑÔÚ»¥ÁªÍøÉÏÆØ¹âÁËÈýÖܵŦ·ò¡£ÔÚPaine֪ͨӡ¶ÈCERTºó£¬¸Ã·þÎñÆ÷µÃµ½±£»¤£¬µ«CERT»Ø¾øÐ¹Â©¸Ã·þÎñÆ÷µÄËùÓÐÕß¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/real-time-location-data-for-over-11000-indian-buses-left-exposed-online/


6¡¢Ê®¶à¿îiOSÓÎÏ·±»·¢ÏÖÏòGolduckµÄC&C·þÎñÆ÷·¢ËÍÐÅÏ¢

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


°²È«×êÑÐÍŶÓWandera·¢ÏÖApp StoreÉϵÄ14¿îÓÎÏ·Ïò¶ñÒâÈí¼þGolduck LoaderµÄÒÑÖªC&C·þÎñÆ÷·¢ËÍÊý¾Ý¡£GolduckÊÇÒ»¸ö¸æ°×Èí¼þ·Ö·¢Æ½Ì¨£¬×êÑÐÈËÔ±·¢ÏÖÕâÊ®¶à¿îiOSÓÎÏ·²û·¢³öÓëϰȾÁËGolduckµÄAndroidÀûÓÃÀàËÆµÄÐÐΪ£¬¼´ÔÚÀûÓ÷¨Ê½Ö÷ÆÁÄ»µÄ¶à¸öÇøÓò×¢Èë¸æ°×¡£´Ë±í£¬ÕâЩÓÎÏ·»¹ÏòGolduckµÄC£¦C·þÎñÆ÷·¢ËÍ´óÁ¿ÐÅϢƬ¶Î£¬Ô̺¬IPµØÖ·¡¢µØÎ»Êý¾Ý¡¢É豸ÀàÐͺÍÉ豸ÉÏÏÔʾµÄ¸æ°×ÊýÁ¿µÈ¡£App StoreÒѾ­Ï¼ÜÁËÕâЩÓꦵÄÀûÓá£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/apple-ios-games-found-talking-to-golduck-malware-candc-servers/


ÉêÃ÷£º±¾×ÊѶÓɱ¦ÔËÀ³¹Ù·½ÍøÕ¾Î¬ËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù