ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ2ÖÜ
°ä²¼¹¦·ò 2019-01-14±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÐÂDNS½Ù³Öº£³±Ï¯¾íÈ«Çò£¬£¬£¬£¬£¬£¬£¬ÒÉΪÒÁÀʺڿÍËùΪ£»£»£»£»£»£»Google PlayϼÜ85¸ö¸æ°×app£¬£¬£¬£¬£¬£¬£¬Ï°È¾Ô¼900ÍòAndroidÓû§£»£»£»£»£»£»Ó¡¶È³¬¹ý1.1ÍòÁ¾¹«¹²Æû³µµÄʵʱGPS×ø±êÔÚÆØ¹â£»£»£»£»£»£»Avast°ä²¼2019ÄêÍøÂçÍþÐ²Ì¬ÊÆµÄÔ¤²â»ã±¨£»£»£»£»£»£»IBM TWCÆøÏóÀûÓÃÒòÏúÊÛÓû§Êý¾ÝÔâµ½¸æ×´¡£¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£¡£
³ÁÒª°²È«·ì϶Áбí
Cisco Identity Services Engine Admin Portal²»ÕýÈ·±£ÁôÃÜÂëÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬²é¿´Ã÷ÎÄÃÜÂëÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Î´ÊÚȨ½Ó¼û¡£¡£¡£¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190109-ise-passwd
2. Imperva SecureSphereÔö³¤ËÁÒâsshÃÜÔ¿·ì϶
Imperva SecureSphere´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉÏòÖÎÀíÔ±Óû§µÄauthorized_keysÔö³¤ËÁÒâsshÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£
https://www.exploit-db.com/exploits/45130
3. Juniper Junos OS BGP»Ø¾ø·þÎñ·ì϶
Juniper Junos OS´¦ÖÃBGPÐÂÎÅ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿É½øÐлؾø·þÎñ¹¥»÷¡£¡£¡£¡£¡£¡£¡£
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10912&actp=METADATA
4. Microsoft Visual Studio CVE-2019-0546ËÁÒâ´úÂëÖ´Ðзì϶
Microsoft Visual StudioÔÚC++±àÒëÆ÷δÕýÈ·´¦ÖÃC++»ú¹ØÌض¨×éºÏ£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓÃÖ°ÄÜ·¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0546
5. Microsoft Exchange ServerÔ¶³ÌÐÅϢй¶·ì϶
Microsoft Exchange Server PowerShell APIÔÚcalendar contributorsȨÏÞÖÎÀíÖдæÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÈÕÀúµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0588
³ÁÒª°²È«ÊÂÎñ×ÛÊö
FireEye·¢ÏÖÒ»²¨Õë¶ÔÈ«ÇòµÄ´ó¹æÄ£DNS½Ù³Öº£³±£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËÖж«¡¢±±·Ç¡¢Å·Ö޺ͱ±ÃÀµÄÊýÊ®¸öÓòÃû¡£¡£¡£¡£¡£¡£¡£ÕâЩÓòÃûÊôÓÚµ±¾Ö¡¢µçÐźͻ¥ÁªÍø»ù´¡ÉèÊ©µÈ¡£¡£¡£¡£¡£¡£¡£¹ÌȻĿǰ×êÑÐÈËÔ±»¹Ã»Óн«´Ë»î¶¯ÓëÈκι¥»÷×éÖ¯¹ØÁªÆðÀ´£¬£¬£¬£¬£¬£¬£¬µ«³õ²½µÄ×êÑÐÅú×¢¹¥»÷ÕßÒÉÓëÒÁÀÊÓйء£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯µÄ¶à¸ö¼¯ÈºÔÚ2017Äê1ÔÂÖÁ2019Äê1ÔÂÆÚ¼äÒ»Ïò´¦ÓÚ»îԾ״̬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ´æÔÚ¶à¸ö²»³Á¸´µÄÓòÃû¡¢IPµØÖ·¼¯Èº¡£¡£¡£¡£¡£¡£¡£ÕâÒâζןù¥»÷»î¶¯¿ÉÄܲ¢²»Êǵ¥¸ö¹¥»÷ÕߵĻ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õߵļ¼ÊõÖØÒªÉæ¼°Åú¸ÄDNS A¼Í¼¡¢NS¼Í¼ºÍ³Á¶¨Ïò¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.fireeye.com/blog/threat-research/2019/01/global-dns-hijacking-campaign-dns-record-manipulation-at-scale.html
2¡¢Google PlayϼÜ85¸ö¸æ°×app£¬£¬£¬£¬£¬£¬£¬Ï°È¾Ô¼900ÍòAndroidÓû§
Ç÷Ïò¿Æ¼¼µÄ×êÑÐÈËÔ±ÔÚGoogle PlayÉ̵귢ÏÖ85¸ö¸æ°×ÀûÓ㬣¬£¬£¬£¬£¬£¬Ô¼900ÍòAndroidÓû§Êܵ½Ï°È¾¡£¡£¡£¡£¡£¡£¡£ÕâЩapp¼Ù×°³ÉÓÎÏ·¡¢Á÷ýÌåµçÊÓºÍÄ£ÄâÒ£¿£¿£¿£¿£¿£¿£¿ØÆ÷µÈ£¬£¬£¬£¬£¬£¬£¬ÔÚÉ豸ºó¶Ü¾²Ä¬ÔËÐУ¬£¬£¬£¬£¬£¬£¬²¢Ã¿¸ô15»ò30·ÖÖÓʹÓÃÈ«ÆÁ¸æ°×ºäÕ¨Óû§É豸¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖÕâЩappÀ´×ÔÓÚ·ÖÆçµÄ¿ª·¢ÈËÔ±£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÕ¼ÓÐ·ÖÆçµÄAPKÖ¤Ê鹫Կ£¬£¬£¬£¬£¬£¬£¬µ«ËüÃǵĴúÂëºÍ¶¨Ãû·½Ê½¶¼¼«¶ÈÀàËÆ¡£¡£¡£¡£¡£¡£¡£Google PlayÔÚ½Óµ½Í¨ÖªºóÒÑϼÜÁËÕâЩÀûÓᣡ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/android-adware-malware.html
3¡¢Ó¡¶È³¬¹ý1.1ÍòÁ¾¹«¹²Æû³µµÄʵʱGPS×ø±êÔÚÆØ¹â
°²È«×êÑÐÔ±Justin Paine·¢ÏÖÒ»¸öδÉèÃÜÂëµÄElasticSearch·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬¸Ã·þÎñÆ÷Ô̺¬À´×Ô27¼ÒÓ¡¶È¹úÓÐÔËÊä»ú¹¹µÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬³¬¹ý1.1ÍòÁ¾¹«¹²Æû³µµÄʵʱGPS×ø±êºÍ·ÏßÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£·ÖÆçÔËÊä»ú¹¹µÄÊý¾Ý²¢²»Ò»Ñù£¬£¬£¬£¬£¬£¬£¬ÔÚijЩ°¸ÀýÖУ¬£¬£¬£¬£¬£¬£¬»¹Ô̺¬³Ë¿ÍµÄÓû§ÃûºÍµç×ÓÓʼþµØÖ·¡£¡£¡£¡£¡£¡£¡£¸Ã·þÎñÆ÷ÖÁÉÙÒÑÔÚ»¥ÁªÍøÉÏÆØ¹âÁËÈýÖܵŦ·ò¡£¡£¡£¡£¡£¡£¡£ÔÚPaine֪ͨӡ¶ÈCERTºó£¬£¬£¬£¬£¬£¬£¬¸Ã·þÎñÆ÷µÃµ½±£»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬£¬µ«CERT»Ø¾øÐ¹Â©¸Ã·þÎñÆ÷µÄËùÓÐÕß¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/real-time-location-data-for-over-11000-indian-buses-left-exposed-online/
4¡¢Avast°ä²¼2019ÄêÍøÂçÍþÐ²Ì¬ÊÆµÄÔ¤²â»ã±¨
AvastµÄ2019ÄêÍþÐ²Ì¬ÊÆÔ¤²â»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬ÔÚ2019ÄêÆ¥µÐÐÔAI½«ÓÀ´Æ½Ã÷¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±Ô¤²âDeepAttacks¹¥»÷½«¸üƵÈԵسöÏÖ£¨ÕâÀ๥»÷ͨ³£ÀûÓÃAIÌìÉúµÄÄÚÈÝÀ´ÌÓ±ÜAI°²È«½ÚÔì´ëÊ©£©¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬ÎïÁªÍøÍþв½«±äµÃÔ½·¢¸´ÔÓ£¬£¬£¬£¬£¬£¬£¬Â·ÓÉÆ÷Ò²½«Ô½À´Ô½¶àµØ³ÉΪ¹¥»÷Ö¸±ê£¬£¬£¬£¬£¬£¬£¬¸æ°×¡¢´¹µöºÍÐéαÀûÓý«³ÖÐøÖ÷µ¼Òƶ¯ÍþвÁìÓò¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cdn2.hubspot.net/hubfs/486579/Avast_Threat_Landscape_Report_2019.pdf
5¡¢IBM TWCÆøÏóÀûÓÃÒòÏúÊÛÓû§Êý¾ÝÔâµ½¸æ×´
Âåɼí¶ÊÐÏò¼ÓÀû¸£ÄáÑÇÖÝ·¨ÔºÌá¸æ×´ËÏ£¬£¬£¬£¬£¬£¬£¬¿ØËßIBM×Ó¹«Ë¾TWCµÄÆøÏóÀûÓã¨Weather Channel£©ÍÚ¾òÓû§µÄÒþÖÔÊý¾Ý²¢½«ÕâЩÐÅÏ¢ÏúÊÛ¸øµÚÈý·½£¬£¬£¬£¬£¬£¬£¬Ô̺¬¸æ°×¹«Ë¾¡£¡£¡£¡£¡£¡£¡£Âåɼí¶Êз½Ã氵ʾ£¬£¬£¬£¬£¬£¬£¬Weather ChannelÔںܶàÓû§²»ÖªÇéµÄÇé¿öϸú×ÙÓû§µÄµØÀíµØÎ»Êý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢½«ÕâЩÊý¾ÝÓÃÓÚÓëÆøÏóÔ¤±¨ÆëÈ«Î޹صĸæ°×µÈóÒ×Óô¦¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/city-of-la-sues-weather-channel-app-for-sharing-location-data-with-advertisers/
ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ