¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190215

Ðû²¼Ê±¼ä 2019-02-15
1¡¢VallettaÒøÐÐÔâºÚ¿Í¹¥»÷£¬£¬£¬¹¥»÷ÕßÊÔͼÇÔÈ¡1300ÍòÅ·Ôª

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

Âí¶úËûVallettaÒøÐÐÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬¹¥»÷ÕßÊÔͼ½«1300ÍòŷԪתÈëÓ¢¹ú¡¢ÃÀ¹ú¡¢½Ý¿Ë¹²ºÍ¹úºÍÏã¸ÛÒøÐеÄÕË»§¡£¡£¡£¡£¡£ÕâЩÉúÒâÔÚ30·ÖÖÓÄÚ±»×èÖ¹£¬£¬£¬µ«¹¥»÷ÕßÊÇ·ñÒѾ­»ñµÃ×ʽðÉÐδ»ñµÃ֤ʵ¡£¡£¡£¡£¡£¸ÃÒøÐÐÒѾ­¹Ø±ÕÁËÆäϵͳ£¬£¬£¬²¢ÔÝʱ×èÖ¹ÁËËùÓÐÓªÒµ¡£¡£¡£¡£¡£Æ¾Ö¤Âí¶úËûʱ±¨µÄ±¨µÀ£¬£¬£¬ÕâÆð¹¥»÷ÊÂÎñ±¬·¢ÔÚ±¾ÖÜÈýÉÏÎç¡£¡£¡£¡£¡£¸ÃÒøÐÐÌåÏÖ£¬£¬£¬Ã»Óпͻ§ÕË»§¼°Æä×ʽðÊܵ½Ë𺦡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2019/02/14/bank-of-valletta-cyber-attack/

2¡¢Á¬Ëø²ÍÌüTruluckÔâºÚ¿ÍÈëÇÖ£¬£¬£¬²¿·Ö¿Í»§µÄÖ§¸¶ÐÅϢй¶

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÐÝ˹¶ÙÁ¬Ëø²ÍÌüTruluck¡¯s Seafood, Steak & Crab House±¬·¢Êý¾Ýй¶ÊÂÎñ£¬£¬£¬²¿·Ö¿Í»§µÄÐÅÓÿ¨ÐÅÏ¢±»ÇÔ¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñÓ°ÏìÁËλÓÚAustin¡¢Houston¡¢Naples¡¢SouthlakeºÍChicagoµÄ8¼Ò²ÍÌü¡£¡£¡£¡£¡£¸ÃÊÂÎñ±¬·¢ÔÚ2018Äê11ÔÂ21ÈÕÖÁ12ÔÂ8ÈÕʱ´ú£¬£¬£¬Æ¾Ö¤TruluckµÄ˵·¨£¬£¬£¬¹¥»÷ÕßÔÚÊÜÓ°Ïì²ÍÌüµÄPoSϵͳÖÐÖ²ÈëÁ˶ñÒâÈí¼þ£¬£¬£¬ÒÔÇÔÈ¡¿Í»§µÄÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¡£¡£¸Ã¹«Ë¾»¹³ÆÐ¹Â¶µÄÐÅÏ¢Öв»°üÀ¨ÈκÎÐÕÃûºÍµØµãÐÅÏ¢¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/trulucks-seafood-steak-crab-house-reports-data-breach-at-8-of-its-restaurants-b1fccc72

3¡¢0patch.comÐû²¼OpenOffice´úÂëÖ´ÐÐ0dayµÄÐÞ¸´²¹¶¡

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

0patch.comÍÆ³öOpenOfficeÁãÈÕÎó²î£¨CVE-2018-16858£©µÄÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÇå¾²Ñо¿Ô±AlexInf¨¹hr·¢Ã÷µÄ£¬£¬£¬¿ÉÓÃÓÚÌᳫĿ¼±éÀú¹¥»÷£¬£¬£¬Ó°ÏìÁËOpenOfficeµÄËùÓа汾ºÍLibreOfficeµÄ°æ±¾6.0.6/6.1.2.1¡£¡£¡£¡£¡£LibreOfficeÒѾ­ÔÚа汾6.0.7/6.1.3ÖÐÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£¡£ËäÈ»¸ÃÎó²îÓ°ÏìÁËOpenOfficeµÄLinuxºÍWindows°æ±¾£¬£¬£¬µ«0patchÍÆ³öµÄÐÞ¸´²¹¶¡Ö»Õë¶ÔWindowsƽ̨¿ÉÓᣡ£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/openoffice-zero-day-code-execution-flaw-gets-free-micropatch/

4¡¢Î÷ÃÅ×ÓÐÞ¸´SICAM 230ÖеÄÔ¶³Ì´úÂëÖ´ÐкÍÌáȨÎó²î

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

Î÷ÃÅ×ÓSICAM 230¿ØÖÆÏµÍ³±»ÆÕ±éÓÃÓÚICSÓ¦Ó㬣¬£¬ÀýÈ繫ÓÃÊÂÒµµÄ¼¯³ÉÄÜԴϵͳÒÔ¼°ÖÇÄܵçÍøµÄ¼à¿ØÏµÍ³µÈ¡£¡£¡£¡£¡£Æ¾Ö¤Î÷ÃÅ×ÓÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬SICAM 230±£´æ¶ÑÒç³öµ¼ÖµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-3991£©»ººÍ³åÇøÒç³öµ¼ÖµÄÌáȨÎó²î£¨CVE-2018-3990£©¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬Î÷ÃÅ×Ó¹²Ðû²¼ÁË16¸öÇ徲ͨ¸æ£¬£¬£¬ÐÞ¸´Á˶à¸öÎó²î£¬£¬£¬ÆäÖаüÀ¨EN100ÒÔÌ«ÍøÍ¨Ñ¶Ä£¿£¿£¿£¿£¿éºÍSIPROTEC 5¼ÌµçÆ÷ÖеÄ3¸ö¿Éµ¼ÖÂDoSµÄÎó²î£¨CVE-2018-16563¡¢CVE-2018-11451ºÍCVE-2018-11452£©¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì×°ÖÃÏà¹Ø²úÆ·µÄ¸üС£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/siemens-critical-remote-code-execution/141768/

5¡¢Õë¶ÔmacOSµÄShlayerľÂí£¬£¬£¬¿É½ûÓÃGatekeeper±£»£»¤»úÖÆ

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

Carbon BlackµÄTAUÑо¿ÍŶӷ¢Ã÷Õë¶ÔmacOSµÄShlayerľÂíµÄбäÖÖ£¬£¬£¬¸Ã±äÖÖͨ¹ý¶ñÒâFlash¸üоÙÐзַ¢£¬£¬£¬¿ÉÓ°ÏìmacOS°æ±¾10.10.5µ½10.14.3¡£¡£¡£¡£¡£Ñо¿ÍŶÓÖ¸³ö£¬£¬£¬¸Ã±äÌå½ÓÄÉÁ˶à²ã»ìÏý£¬£¬£¬²¢ÇÒÄܹ»¾ÙÐÐÌáȨ¡£¡£¡£¡£¡£¸Ã±äÌ廹»á½ûÓÃmacOSÉϵÄGatekeeper±£»£»¤»úÖÆÀ´ÔËÐеڶþ½×¶Îpayload¡£¡£¡£¡£¡£¸Ã±äÌåµÄ´ó´ó¶¼Ñù±¾¶¼ÊÇDMGÎļþ£¬£¬£¬Ò»Ð©Ñù±¾»¹Ê¹ÓÃÕýµ±µÄApple¿ª·¢ÕßID¾ÙÐÐÊðÃû¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/new-shlayer-variant-disables-gatekeeper-protection-mechanism-to-run-second-stage-payloads-cce39f23

6¡¢ÐÂLinuxľÂíSpeakUp£¬£¬£¬Ö÷ÒªÕë¶Ô¶«ÑǺÍÀ­¶¡ÃÀÖÞ

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Check PointÑо¿Ö°Ô±·¢Ã÷Ò»¸öеÄLinuxºóÃÅľÂíSpeakUp£¬£¬£¬¸ÃľÂíʹÓÃÁËÁùÖÖ²î±ðLinux¿¯ÐаæÖеÄÒÑÖªÎó²î£¬£¬£¬ÆäÄ¿µÄÖ÷ÒªÊǶ«ÑǺÍÀ­¶¡ÃÀÖÞµÄЧÀÍÆ÷£¬£¬£¬°üÀ¨AWSÍйܵÄЧÀÍÆ÷¡£¡£¡£¡£¡£SpeakUpµÄ³õʼѬȾÏòÁ¿ÊÇ×î½ü±¨¸æµÄThinkPHPÖеÄÎó²î¡£¡£¡£¡£¡£ËäÈ»SpeakUp±³ºóµÄ¹¥»÷ÕßµÄÉí·ÝÉв»Ã÷È·£¬£¬£¬µ«Ñо¿Ö°Ô±·¢Ã÷SpeakUpÓëZettabit±£´æÐí¶àÅäºÏÖ®´¦¡£¡£¡£¡£¡£¸ü¶àIoCÖ¸±êÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://research.checkpoint.com/speakup-a-new-undetected-backdoor-linux-trojan/


ÉùÃ÷£º±¾×ÊѶÓÉÄϹ¬NGÓéÀÖάËûÃüÇ徲С×é·­ÒëºÍÕûÀí