ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ10ÖÜ
°ä²¼¹¦·ò 2019-03-11±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ΢Èí°ä²¼°²È«»ã±¨Volume 24£¬£¬£¬£¬£¬2018Äê´¹µö¹¥»÷Ôö³¤250£¥£»£»£»£»£»£»£»£»×êÑÐÅú×¢2018Äê²úÉú12449ÆðÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬±È2017ÄêÔö³¤424%£»£»£»£»£»£»£»£»Dalil¹«Ë¾MongoDB¿É¹«¿ª½Ó¼û£¬£¬£¬£¬£¬500¶àÍòÓû§Êý¾Ýй¶£»£»£»£»£»£»£»£»2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾ÖУ¬£¬£¬£¬£¬WordPressÕ¼90%£»£»£»£»£»£»£»£»×êÑÐÍŶӷ¢ÏÖ2Ô·ÝÀÕË÷Èí¼þShadeµÄ¹¥»÷»î¶¯ìÉý¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£
³ÁÒª°²È«·ì϶Áбí
Cisco NX-OS Software CLIÑéÖ¤²ÎÊý´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐí±¾µØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬ÌáÉýȨÏÞÖ´ÐÐËÁÒâosºÅÁî¡£¡£¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-cmdinj-1610
2. Google Chrome FileReader¿ªÊͺóʹÓôúÂëÖ´Ðзì϶
Google Chrome FileReaderµÄʵÏÖ´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨¶ñÒâWEBÒ³£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html
3. Adobe ColdFusion CVE-2019-7816ÎļþÉÏ´«ÏÞ¶ÈÈÆ¹ý·ì϶
Adobe ColdFusionÎļþÉÏ´«ÊµÏÖ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬ÉÏ´«ËÁÒâÎļþ£¬£¬£¬£¬£¬²¢Ö´ÐÓ×£¡£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/coldfusion/apsb19-14.html
4. Samsung Galaxy S9Éí·ÝÑéÖ¤´úÂëÖ´Ðзì϶
Samsung Galaxy S9 GameServiceReceiver¸üлúÔì´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-19-255/
5. Nokia Alcatel Lucent I-240W-Q GPON ONT CVE-2019-3922»º³åÇøÒç¶Âí½Å
Nokia Alcatel Lucent I-240W-Q GPON ONT´¦ÖÃÌØÊâµÄHTTP POSTÒªÇó´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
https://www.tenable.com/security/research/tra-2019-09
³ÁÒª°²È«ÊÂÎñ×ÛÊö
ƾ¾Ý΢ÈíµÄ°²È«µý±¨»ã±¨£¨SIR£©Volume 24£¬£¬£¬£¬£¬ÔÚ2018Äê1ÔÂÖÁ12ÔÂÆÚ¼ä£¬£¬£¬£¬£¬ÍøÂç´¹µö¹¥»÷Ôö³¤ÁË250%¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚÔËÓªÍøÂç´¹µö»î¶¯Ê±Ñ¡È¡¶àÑù»¯µÄ»ù´¡ÉèÊ©£¬£¬£¬£¬£¬Ô̺¬ÍйܷþÎñÆ÷ºÍ¹«¹²ÔƵȡ£¡£¡£¡£¡£¡£ÁíÒ»·½Ã棬£¬£¬£¬£¬2018ÄêÆÚ¼ä¶ñÒâÈí¼þµÄÊýÁ¿½µÂäÁËÔ¼34%¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Ëæ×Å2018ÄêËêĺ¼ÓÃÜÇ®±Ò¼ÛÖµµÄ×ÅÂ䣬£¬£¬£¬£¬¶ñÒâÍÚ¿ó»î¶¯Ò²½µÂäÁË36%¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-sees-250-percent-phishing-increase-malware-decline-by-34-percent/
2¡¢×êÑÐÅú×¢2018Äê²úÉú12449ÆðÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬±È2017ÄêÔö³¤424%
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/12-449-data-breaches-confirmed-in-2018-a-424-percent-increase-over-the-previous-year/
3¡¢Dalil¹«Ë¾MongoDB¿É¹«¿ª½Ó¼û£¬£¬£¬£¬£¬500¶àÍòÓû§Êý¾Ýй¶
ÔÎÄÁ´½Ó£º
https://www.vpnmentor.com/blog/dalil-data-breach/
4¡¢2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾ÖУ¬£¬£¬£¬£¬WordPressÕ¼90%
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/wordpress-accounted-for-90-percent-of-all-hacked-cms-sites-in-2018/
5¡¢×êÑÐÍŶӷ¢ÏÖ2Ô·ÝÀÕË÷Èí¼þShadeµÄ¹¥»÷»î¶¯ìÉý
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/threat-analysis/2019/03/spotlight-troldesh-ransomware-aka-shade/
ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ