ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ20ÖÜ
°ä²¼¹¦·ò 2019-05-20±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2019Äê5ÔÂ13ÈÕÖÁ19ÈÕ¹²ÊÕ¼°²È«·ì϶74¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicrosoft Windows Remote Desktop Services CVE-2019-0708Ô¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£»Adobe Media Encoder CVE-2019-7842¿ªÊͺóʹÓÃÔ¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£» Facebook WhatsApp CVE-2019-3568»º³åÇøÒç¶Âí½Å£»£»£»£»£»£»Apple Safari¶à¸öÄÚ´æ·ÛËéËÁÒâ´úÂëÖ´Ðзì϶£»£»£»£»£»£»Adobe AcrobatºÍReader¶à¸ö¿ªÊͺóʹÓôúÂëÖ´Ðзì϶¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ΢Èí½¨¸´79¸ö·ì϶£¬£¬£¬£¬£¬Ô̺¬RDPÖеÄRCE·ì϶£¨CVE-2019-0708£©£»£»£»£»£»£»¹¥»÷ÕßÀûÓûªË¶ÖÐÑëÈ˹¥»÷·Ö·¢PleadºóÃÅ£»£»£»£»£»£»Stack Overflow°ä²¼²¼¸æ³ÆÆäÔâºÚ¿ÍÈëÇÖ£»£»£»£»£»£»Î´ÉèÃÜÂëµÄÊý¾Ý¿âй¶½ü90%°ÍÄÃÂí¹«ÃñÐÅÏ¢£»£»£»£»£»£»¶íÂÞ˹ºÚ¿Í×éÖ¯ÏúÊÛÃÀ¹ú3´ó·´²¡¶¾¹«Ë¾Ô´Âë¡£¡£¡£¡£¡£
³ÁÒª°²È«·ì϶Áбí
1. Microsoft Windows Remote Desktop Services CVE-2019-0708Ô¶³Ì´úÂëÖ´Ðзì϶
Microsoft Windows Remote Desktop Services´¦ÖÃÄÚ´æ¶ÔÏó´æÔÚÄÚ´æ·ÛËé·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄRDPÒªÇ󣬣¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
2. Adobe Media Encoder CVE-2019-7842¿ªÊͺóʹÓÃÔ¶³Ì´úÂëÖ´Ðзì϶
Adobe Media Encoder´¦ÖÃÎļþ´æÔÚÄÚ´æ·ÛËé·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/media-encoder/apsb19-29.html
3. Facebook WhatsApp CVE-2019-3568»º³åÇøÒç¶Âí½Å
Facebook WhatsApp´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://www.facebook.com/security/advisories/cve-2019-3568
4. Apple Safari¶à¸öÄÚ´æ·ÛËéËÁÒâ´úÂëÖ´Ðзì϶
Apple Safari WebKit´æÔÚ¶à¸öÄÚ´æ·ÛËé·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³ÒªÇ󣬣¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://support.apple.com/zh-cn/HT210123
5. Adobe AcrobatºÍReader¶à¸ö¿ªÊͺóʹÓôúÂëÖ´Ðзì϶
Adobe AcrobatºÍReader´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³ÒªÇ󣬣¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/acrobat/apsb19-18.html
³ÁÒª°²È«ÊÂÎñ×ÛÊö
Öܶþ΢Èí°ä²¼5ÔÂWindows°²È«¸üУ¬£¬£¬£¬£¬½¨¸´79¸ö·ì϶¡£¡£¡£¡£¡£ÆäÖÐÔ̺¬RDP·þÎñÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-0708£©£¬£¬£¬£¬£¬´Ë·ì϶ÊÇÔ¤Éí·ÝÑéÖ¤£¬£¬£¬£¬£¬ÎÞÐèÓû§½»»¥£¬£¬£¬£¬£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂ룻£»£»£»£»£»ÌáȨ0day£¨CVE-2019-0863£©£¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÔÊÐí¹¥»÷ÕßÌáÉýÖÁÖÎÀíԱȨÏÞ£»£»£»£»£»£»Õë¶ÔIntel CPU MDS¹¥»÷µÄ·ì϶½¨¸´£¬£¬£¬£¬£¬ÕâЩ·ì϶ӰÏìÁË2011ÄêÒÔÀ´ÏÕЩËùÓеÄIntel CPU¡£¡£¡£¡£¡£ÆëÈ«·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-may-2019-patch-tuesday-arrives-with-fix-for-windows-zero-day-mds-attacks/
2¡¢¹¥»÷ÕßÀûÓûªË¶ÖÐÑëÈ˹¥»÷·Ö·¢PleadºóÃÅ
4Ôµ×ESET×êÑÐÈËÔ±¹Û²ìµ½ÀûÓá°AsusWSPanel.exe¡±·Ö·¢PleadºóÃŵĹ¥»÷»î¶¯¡£¡£¡£¡£¡£AsusWSPanel.exeÊÇ»ªË¶ÔÆ´æ´¢·þÎñWebStorageµÄWindows¿Í»§¶Ë¡£¡£¡£¡£¡£×êÑÐÈËÔ±¸ø³öÁËÁ½ÖÖ¿ÉÄܵĹ¥»÷³¡¾°£¬£¬£¬£¬£¬Ò»ÖÖÊÇ»ªË¶Ôâµ½¹©¸øÁ´¹¥»÷£¬£¬£¬£¬£¬ÁíÒ»ÖÖÊǹ¥»÷ÕßÀûÓÃÖÐÑëÈ˹¥»÷ºÍÒ×Êܹ¥»÷µÄ·ÓÉÆ÷À´´«²¼¶ñÒâÈí¼þ¡£¡£¡£¡£¡£½øÒ»²½µÄ·ÖÎöºó×êÑÐÈËÔ±ÒÔΪºóÒ»ÖÖ¹¥»÷³¡¾°µÄ¿ÉÄÜÐÔ¸ü´ó¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/bad-actors-using-mitm-attacks-against-asus-to-distribute-plead-backdoor/
3¡¢Stack Overflow°ä²¼²¼¸æ³ÆÆäÔâºÚ¿ÍÈëÇÖ
5ÔÂ16ÈÕStack Overflow°ä²¼ÁËÒ»Ìõ¼ò¶ÌµÄ²¼¸æ£¬£¬£¬£¬£¬³Æ5ÔÂ11ÈÕºÚ¿ÍÈëÇÖÁËÆä³ö²úϵͳ¡£¡£¡£¡£¡£Æ¾¾ÝStack Overflow¹¤³Ì¸±×ܲÃMary FergusonµÄ˵·¨£¬£¬£¬£¬£¬ºÚ¿Í»ñµÃÁ˿϶¨Ë®Æ½µÄ³ö²úϵͳ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬Stack Overflow·¢ÏÖ²¢µ÷²éÁ˽ӼûµÄÁìÓò£¬£¬£¬£¬£¬²¢ÇÒ½¨¸´ÁËËùÓеÄÒÑÖª·ì϶¡£¡£¡£¡£¡£µ÷²éûÓз¢ÏÖºÚ¿Í»ñµÃÓû§Êý¾ÝµÄÈκÎÖ¤¾Ý¡£¡£¡£¡£¡£Ä¿Ç°µ÷²éÔÚ½øÐÐÖУ¬£¬£¬£¬£¬Òò¶øStack Overflow²¢Î´Åû¶¸ü¶àϸ½Ú¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/stack-overflow-says-hackers-breached-production-systems/
4¡¢Î´ÉèÃÜÂëµÄÊý¾Ý¿âй¶½ü90%°ÍÄÃÂí¹«ÃñÐÅÏ¢
°²È«×êÑÐÔ±Bob DiachenkoʹÓÃShodanÔÚAWSÉÏ·¢ÏÖÒ»¸öδÊܱ£»£»£»£»£»£»¤µÄElasticsearchÊý¾Ý¿â£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âй¶ÁËÊý°ÙÍò°ÍÄÃÂí¹«ÃñµÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£Æ¾¾Ý×êÑÐÈËÔ±µÄ±íÊö£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÔ̺¬3427396Ìõ±êǩΪ¡°»¼Õß¡±µÄ¼Í¼ÒÔ¼°468086Ìõ±êǩΪ¡°²âÊÔ»¼Õß¡±µÄ¼Í¼¡£¡£¡£¡£¡£ÕâЩÐÅÏ¢Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éí·ÝÖ¤ºÅÂë¡¢µØÖ·¡¢ÓÊÏäºÍµç»°ºÅÂëµÈ¡£¡£¡£¡£¡£ÈôÊÇÊý¾ÝûÓгÁ¸´£¬£¬£¬£¬£¬ÕâЩ¼Í¼Լռ¸Ã¹ú×ÜÈ˶¡µÄ90%¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/sensitive-information-of-millions-of-panama-citizens-leaked/
5¡¢¶íÂÞ˹ºÚ¿Í×éÖ¯ÏúÊÛÃÀ¹ú3´ó·´²¡¶¾¹«Ë¾Ô´Âë
×Ô3Ô·ÝÒÔÀ´£¬£¬£¬£¬£¬¶íÂÞ˹ºÚ¿ÍÍÅ»ïFxmspÔÚµØÏÂÂÛ̳ÉÏÐû³ÆÏúÊÛÈý¼ÒÃÀ¹ú·´²¡¶¾¹«Ë¾µÄÈí¼þ²úÆ·Ô´ÂëºÍ¹«Ë¾ÍøÂç½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£³õ²½µÄ¼ÛÖµÊǽӼûȨÏÞ25ÍòÃÀÔª£¬£¬£¬£¬£¬Ô´´úÂë15ÍòÃÀÔª£¬£¬£¬£¬£¬µ«±¨¼Û²¢²»¹Ì¶¨¡£¡£¡£¡£¡£Fxmsp²¢Î´Ö¸³ö¾ßÌåµÄ¹«Ë¾Ãû³Æ£¬£¬£¬£¬£¬µ«ÌṩÁËÔ̺¬30TBÊý¾ÝµÄÎļþ¼Ð½ØÆÁ£¬£¬£¬£¬£¬¾Ý³ÆÕâЩÊý¾ÝÔ̺¬¿ª·¢Îĵµ¡¢ÈËΪÖÇÄÜÄ£ÐÍ¡¢Web°²È«Èí¼þºÍ·´²¡¶¾Èí¼þµÄ´úÂëµÈ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-selling-access-and-source-code-from-antivirus-companies/


¾©¹«Íø°²±¸11010802024551ºÅ