¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍþвÇ鱨Öܱ¨-2020ÄêµÚ7ÖÜ£¨2020.2.10-2020.2.16£©
2020-02-16
Ò»¡¢ Íþвͨ¸æ
? ΢Èí¸üжà¸ö²úÆ·¸ßΣÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2020-02-13 10:40:00 GMT
¡¾¸ÅÊö¡¿
±±¾©Ê±¼ä2ÔÂ12ÈÕ£¬Î¢ÈíÐû²¼2ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË100¸öÇå¾²ÎÊÌâ£¬Éæ¼°InternetExplorer¡¢MicrosoftEdge¡¢MicrosoftExchangeServer¡¢MicrosoftOfficeµÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨ÌáȨºÍÔ¶³Ì´úÂëÖ´ÐеȸßΣÎó²î¡£
¡¾Á´½Ó¡¿
http://blog.nsfocus.net/microsoft-releases-multiple-announcement-for-critical-threats/
? DjangoSQL×¢ÈëÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2020-02-13 11:00:00 GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬Django¹Ù·½Ðû²¼Ç徲ͨ¸æÐû²¼ÁËÒ»¸öͨ¹ýStringAgg£¨ÍÑÀë·û£©µÄDZÔÚSQL×¢ÈëÎó²î£¨CVE-2020-7471£©¡£ÈôÊǽ«²»ÊÜÐÅÍеÄÊý¾ÝÓÃ×÷StringAggÍÑÀë·û£¬Ôò²¿·Ö°æ±¾µÄDjango½«ÔÊÐíSQL×¢È롣ͨ¹ý½«È«ÐÄÉè¼ÆµÄÍÑÀë·ûת´ï¸øcontrib.postgres.aggregates.StringAggʵÀý£¬¿ÉÒÔÍ»ÆÆ×ªÒå²¢×¢Èë¶ñÒâSQL¡£
¡¾Á´½Ó¡¿
http://blog.nsfocus.net/django-sql-injection-vulnerability/
¶þ¡¢ °µÍøÇ鱨
|
·ÖÀà |
·¢Ã÷ʱ¼ä |
°µÍøÉúÒâÎÊÌâ |
|
½ðÈÚ |
2020-02-08 13:39 |
88000Ìõ19Äê»îÔ¾¹ÉÃñÐÅϢȯÉÌÄÚ²¿Á÷³ö |
|
½ðÈÚ |
2020-02-07 22:50 |
Ììϰü¹ÜÊý¾Ý3600Íò×óÓÒ31¸öÊ¡·ÖÊпɴò°ü |
|
»¥ÁªÍø |
2020-02-11 10:23 |
ijÉ繤¿â120GÊý¾Ý |
|
½ðÈÚ |
2020-02-11 22:31 |
ÒøÐп¨Êý¾Ý1809Ìõ¸÷´óÐÐÒøÐп¨Êý¾Ýº¬¿¨ºÅµÈ |
|
»¥ÁªÍø |
2020-02-13 00:39 |
335wÌìϱ¦ÂèÊý¾Ý ¿ÉÓÃÓÚÓ×½Ìѧǰ½ÌÓýÍÆ¹ã |
|
»¥ÁªÍø |
2020-02-13 22:16 |
Å®ÐÔ¹ºÎïÆ½Ì¨_Ä³Íø¹ºÊý¾Ý16Íò |
|
½ðÈÚ |
2020-02-13 16:08 |
2020ÄêµÚÒ»Åúij֤ȯ¶ÌÐÅ×èµ²¹ÉÃñÊý¾Ý38w |
|
½ðÈÚ |
2020-02-14 09:15 |
11Íò Ä³ÍøÕ¾»áÔ±Êý¾ÝÕ˺ÅÃÜÂëÊÖ»ú |
Èý¡¢ ÈÈÃÅ×ÊѶ
1. Adobe 2ÔÂÇå¾²¸üÐÂÇå¾²
¡¾¸ÅÊö¡¿
ÍâµØÊ±¼ä2020Äê2ÔÂ11ÈÕ£¬Adobe¹Ù·½Ðû²¼ÁË2ÔÂÇå¾²¸üУ¬ÐÞ¸´ÁËAdobe¶à¿î²úÆ·µÄ¶à¸öÎó²î£¬°üÀ¨Adobe Experience Manager¡¢Adobe Digital Editions¡¢Adobe Flash Playe¡¢Adobe Acrobat and ReaderÒÔ¼°Adobe FramemakerµÈ¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/%e3%80%90adobe-monthly-update%e3%80%91%e3%80%8aadobe-febuary-security-updates-report%e3%80%8b/
2. Apache Dubbo·´ÐòÁл¯Îó²î
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬ChekmarxÍŶӵÄÑо¿Ö°Ô±·¢Ã÷²¢Ðû²¼ÁËApache DubboÖб£´æµÄÒ»¸ö·´ÐòÁл¯Îó²î£¨CVE-2019-17564£©¡£Apache DubboÊÇÒ»¿î¸ßÐÔÄÜJava RPC¿ò¼Ü¡£µ±ÔÚDubboÓ¦ÓÃÖÐÆôÓÃÁËHTTPÐÒé¾ÙÐÐͨѶʱ±£´æ¸ÃÎó²î£¬¹¥»÷Õß¿ÉÄÜÌá½»Ò»¸ö°üÀ¨Java¹¤¾ßµÄPOSTÇëÇóÀ´ÍêÈ«ÆÆËðApache DubboµÄÌṩÕßʵÀý¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/apache-dubbo-anti-sequential-vulnerabilitycve-2019-17564-security-threats-report/
3. ÃÀ¹úÕþ¸®»ú¹¹Åû¶³¯Ïʶà¸ö¶ñÒâÈí¼þ¼Ò×å
¡¾¸ÅÊö¡¿
CyberCommand(ÃÀ¹úÍøÂç˾Á)¡¢CISA(ÃÀ¹úÁìÍÁÇå¾²ÊÖÏÂÊôÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö)ºÍFBI(ÃÀ¹úÁª°îÊÓ²ì¾Ö)ÔÚÍâµØÊ±¼ä2ÔÂ14ÈÕÆØ¹â³¯ÏÊÁù¸öжñÒâÈí¼þ¼Ò×åºÍÒ»¸ö¶ñÒâÈí¼þµÄ¸üУ¬ÕâЩ¶ñÒâÈí¼þ»®·ÖÊÇBISTROMATH¡¢SLICKSHOES¡¢CROWDEDFLOUNDER¡¢HOTCROISSANT¡¢ARTFULPIE¡¢BUFFETLINEºÍHOPLIGHT£¬²¢ÔÚCISAÍøÕ¾Ðû²¼Ïêϸ±¨¸æ¡£CISA½«ÕâЩ¶ñÒâÈí¼þ¹éÓÚ³¯ÏÊÕþ¸®Ö§³ÖµÄºÚ¿Í×éÖ¯Lazarus Group£¬¼´HIDDEN COBRA£¬¸Ã×éÖ¯Êdz¯ÏÊ×î´ó¡¢×î»îÔ¾µÄºÚ¿Í×éÖ¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://twitter.com/USCERT_gov/status/1228305555908853760
https://www.us-cert.gov/ncas/analysis-reports
4. Google´ÓÓ¦ÓÃÊÐËÁÖÐɾ³ýÁË500¶à¸ö¶ñÒâChromeÀ©Õ¹³ÌÐò
¡¾¸ÅÊö¡¿
¾ÓÉ˼¿ÆDuo SecurityÍŶӾÙÐÐΪÆÚÁ½¸öÔµÄÊÓ²ìÖ®ºó£¬GoogleÒÑ´ÓÆä¹Ù·½ÍøÉÏÊÐËÁÖÐɾ³ýÁË500¶à¸ö¶ñÒâChromeÀ©Õ¹³ÌÐò£¬É¾³ýµÄÀ©Õ¹³ÌÐòͨ¹ýÔÚÓû§µÄä¯ÀÀ»á»°ÖÐ×¢Èë¶ñÒâ¹ã¸æ¾ÙÐжñÒâ¹¥»÷£¬À©Õ¹×¢ÈëµÄ¶ñÒâ´úÂëÔÚÌØ¶¨Ìõ¼þÏ»ἤ»î£¬²¢½«Óû§Öض¨Ïòµ½Ìض¨Õ¾µã¡£ÕâЩÀ©Õ¹ÊÇÒ»¸öÒѾ¿ªÕ¹ÁËÖÁÉÙÁ½ÄêµÄ´óÐͶñÒâÈí¼þ¹¥»÷Ô˶¯µÄÒ»²¿·Ö¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.zdnet.com/article/google-removes-500-malicious-chrome-extensions-from-the-web-store/
5. Outlaw×éÖ¯¸üй¤¾ß°üÕë¶Ô¸ü¶àϵͳ¾ÙÐÐÍÚ¿ó
¡¾¸ÅÊö¡¿
½üÆÚ·¢Ã÷Outlaw¹¥»÷×é֯ˢÐÂÁËɨÃèÔ˶¯µÄ¹æ±ÜÊÖÒÕ£¬²¢Í¨¹ýɱËÀ¾ºÕùµÐÊÖºÍ×Ô¼ºÒÔǰµÄ¿ó¹¤À´Ìá¸ßÁ˲ɿóÀûÈ󣬲¢¶Ô¹¤¾ß°üµÄ¹¦Ð§¾ÙÐÐÁ˸üУ¬ÕâЩ¹¤¾ß°üÖ¼ÔÚÇÔÈ¡Æû³µºÍ½ðÈÚÐÐÒµµÄÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.trendmicro.com/trendlabs-security-intelligence/outlaw-updates-kit-to-kill-older-miner-versions-targets-more-systems/
6. Õë¶Ô°Í»ù˹̹È˵ÄÍøÂçÌØ¹¤Ô˶¯
¡¾¸ÅÊö¡¿
Õë¶Ô°Í»ù˹̹ÁìÍÁÉÏʵÌåºÍСÎÒ˽¼Ò·¢Ã÷Á½¸ö×ÔÁ¦µÄ¹¥»÷Ô˶¯The Spark CampaignºÍThe Pierogi Campaign£¬Á½Õß¶¼Ê¹ÓÃÉç»á¹¤³Ìѧ£¬»®·Öͨ¹ýSparkºÍPierogiºóÃÅѬȾÊܺ¦Õß¡£´Ë´Î¹¥»÷Ô˶¯¹éÒòÓÚGaza Cybergang×éÖ¯£¨Ò²±»³ÆÎªMoleRATs£©£¬¸Ã×éÖ¯³öÓÚÕþÖÎÄîÍ·£¬×Ô2012ÄêÒÔÀ´Ò»Ö±ÔÚÖж«µØÇø¿ªÕ¹Ô˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.cybereason.com/blog/new-cyber-espionage-campaigns-targeting-palestinians-part-one
https://www.cybereason.com/blog/new-cyber-espionage-campaigns-targeting-palestinians-part-2-the-discovery-of-the-new-mysterious-pierogi-backdoor

¾ÅÓÎÀϸçÔÆ





