¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190313

Ðû²¼Ê±¼ä 2019-03-13
1¡¢F5 NetworksÒÔ6.7ÒÚÃÀÔªµÄ¼ÛÇ®ÊÕ¹ºNGINX

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


±¾ÖÜÒ»F5 NetworksÐû²¼½«ÒÔ6.7ÒÚÃÀÔªµÄ¼ÛÇ®ÊÕ¹ºNGINX£¬£¬£¬£¬Ë«·½¶­Ê»áÒÑÅú×¼´Ë´ÎÉúÒ⣬£¬£¬£¬¸ÃÉúÒâÔ¤¼Æ½«ÓÚ2019ÄêµÚ¶þ¼¾¶ÈÍê³É¡£¡£¡£NGINXÊÇÌìÏÂÉÏʹÓÃ×îÆÕ±éµÄÍøÂçЧÀÍÆ÷Èí¼þÖ®Ò»£¬£¬£¬£¬F5 NetworksÃ÷È·ÌåÏÖ£¬£¬£¬£¬ÊÕ¹ºÍê³ÉºóNGINXÆ·ÅÆ¼°Æä¾É½ðɽ×ܲ¿½«¼á³ÖÎȹ̣¬£¬£¬£¬NGINXÊ×ϯִÐйÙRobertsonºÍÊ×´´ÈËIgor SysoevÒÔ¼°Maxim Konovalov½«¼ÌÐøÏòµ¼NGINX¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/03/f5-networks-acquires-nginx.html

2¡¢Õë¶ÔWordPressµÄй¥»÷À˳±£¬£¬£¬£¬Ö÷ҪʹÓùºÎï³µ²å¼þÖеÄXSSÎó²î

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


DefiantÑо¿Ö°Ô±Mikey Veenstra·¢Ã÷Ò»¸öÕë¶ÔWordPress¹ºÎïÍøÕ¾µÄ¹¥»÷À˳±£¬£¬£¬£¬¹¥»÷ÕßʹÓùºÎï³µ²å¼þ¡°Abondoned Cart Lite for WooCommerce¡±ÖеÄXSSÎó²î£¬£¬£¬£¬ÏòÍøÕ¾Ö²ÈëºóÃŲ¢»ñµÃÍøÕ¾µÄ¿ØÖÆÈ¨¡£¡£¡£¾Ý±¨µÀ¸Ã²å¼þÒÑÔÚÁè¼Ý2Íò¸öWordPressÍøÕ¾ÉÏ×°Öᣡ£¡£¹¥»÷ÕßÖ²ÈëµÄºóÃŰüÀ¨Ò»¸öÖÎÀíÔ±ÕË»§woouserÒÔ¼°Ôڷǻ²å¼þÖÐÖ²ÈëµÄPHPºóÃÅ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/hackers-abuse-xss-vulnerability-in-cart-plugin-to-target-wordpress-based-shopping-sites-ff4b4019

3¡¢ÐÂÀÕË÷Èí¼þYatron£¬£¬£¬£¬Ê¹ÓÃEternalBlueºÍDoublePulsar¾ÙÐÐÈö²¥

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

Ñо¿Ö°Ô±A Shadow·¢Ã÷ÐÂÀÕË÷Èí¼þYatronÕýÔÚTwitterÉϾÙÐÐÍÆ¹ã¡£¡£¡£Yatron»áÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.YatronÀ©Õ¹Ãû£¬£¬£¬£¬ÈôÊÇÊܺ¦ÕßÔÚ72СʱÄÚδ֧¸¶Êê½ð£¬£¬£¬£¬Yatron»áÊÔͼɾ³ý¼ÓÃܵÄÎļþ¡£¡£¡£Æ¾Ö¤GillespieµÄ˵·¨£¬£¬£¬£¬¸ÃÀÕË÷Èí¼þÊÇ»ùÓÚHiddenTear£¬£¬£¬£¬µ«ÐÞ¸ÄÁ˼ÓÃÜËã·¨¡£¡£¡£Yatron»¹°üÀ¨EternalBlueºÍDoublePulsarµÄÎó²îʹÓôúÂ룬£¬£¬£¬ÓÃÓÚÑ¬È¾Í³Ò»ÍøÂçÖÐµÄÆäËüWindows»úе¡£¡£¡£Yatron±»×÷ΪRansomware-as-a-Service¾ÙÐÐÍÆ¹ã£¬£¬£¬£¬ÊÛ¼ÛΪ100ÃÀÔª¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/yatron-ransomware-plans-to-spread-using-eternalblue-nsa-exploits/

4¡¢Î¢ÈíÐû²¼3ÔÂÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´64¸öÎó²î

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾

΢ÈíÔÚ3ÔÂWindowsÇå¾²¸üÐÂÖÐÐÞ¸´ÁË64¸öÎó²î£¬£¬£¬£¬ÆäÖаüÀ¨ÉÏÖܹȸèÌáµ½µÄ¿ÉÓëChrome 0day×éºÏʹÓõÄWin 7 0day£¨CVE-2019-0808£©£¬£¬£¬£¬ÒÔ¼°¿¨°Í˹»ùÍŶӷ¢Ã÷µÄÒѱ»Æð¾¢Ê¹ÓõÄÌáȨÎó²î£¨CVE-2019-0797£©¡£¡£¡£±ðµÄ£¬£¬£¬£¬Î¢Èí»¹ÐÞ¸´ÁËÁíÍâÁ½¸öÒѱ»¹ûÕæÅû¶µÄÎó²î£ºWindows¾Ü¾øÐ§ÀÍÎó²î£¨CVE-2019-0754£©ºÍNuGet°ü¹ÜÀíÆ÷Îó²î£¨CVE-2019-0757£©¡£¡£¡£ÏêϸÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-march-2019-patch-tuesday-includes-fixes-for-64-vulnerabilities/

5¡¢AdobeÐû²¼3ÔÂÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´Á½¸öí§Òâ´úÂëÖ´ÐÐÎó²î

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


AdobeÐû²¼3ÔÂÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´ÁËPhotoshopºÍAdobe Digital EditionsÖеÄÁ½¸öí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£ÆäÖÐÎó²î£¨CVE-2019-7094£©ÊÇÓÉÇ÷ÊÆ¿Æ¼¼ZDIµÄÑо¿Ö°Ô±·¢Ã÷µÄ£¬£¬£¬£¬¸ÃÎó²îÒÑÔÚPhotoshop CC 19.1.8ºÍPhotoshop CC 20.0.4ÖÐÐÞ¸´¡£¡£¡£ÁíÒ»¸öÎó²î£¨CVE-2019-7095£©ÊÇÓÉalbalawi-s·¢Ã÷µÄ£¬£¬£¬£¬¸ÃÎó²î¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐкÍÐÅϢй¶£¬£¬£¬£¬²¢ÒÑÔÚAdobe Digital Editions 4.5.10.186048ÖлñµÃÐÞ¸´¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-releases-march-2019-security-fixes-for-photoshop-cc-and-digital-editions/

6¡¢Ñо¿Ö°Ô±·¢Ã÷Èðʿѡ¾ÙͶƱϵͳ±£´æºóÃÅ£¬£¬£¬£¬¿ÉÔÊÐíÐÞ¸ÄѡƱ

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Ñо¿Ö°Ô±ÔÚеÄÈðÊ¿ÔÚÏßÑ¡¾ÙͶƱϵͳÖз¢Ã÷Çå¾²Îó²î£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¹¥»÷Õ߸͝ÕýÖÐѡƱ¶ø²»±»·¢Ã÷¡£¡£¡£ÕâһϵͳÊÇÓÉÈðÊ¿ÓÊÕþ¹«Ë¾ºÍ°ÍÈûÂÞÄÇScytl¹«Ë¾ÏàÖú¿ª·¢µÄ£¬£¬£¬£¬Ñо¿Ö°Ô±Ïò¸Ã¹«Ë¾ÌṩÁËPoC¡£¡£¡£ÈðÊ¿ÓÊÕþÈ·ÈÏÁËÑо¿Ö°Ô±µÄ·¢Ã÷Ч¹û£¬£¬£¬£¬²¢ÒªÇóScytlÐÞ¸´¸ÃÎÊÌâ¡£¡£¡£¸Ã¹«Ë¾»¹ÌåÏÖ£¬£¬£¬£¬Ê¹ÓÃÕâÒ»Îó²îÐèÒª»ñµÃÈðÊ¿ÓÊÕþµÄIT»ù´¡ÉèÊ©µÄ»á¼ûȨ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://motherboard.vice.com/en_us/article/zmakk3/researchers-find-critical-backdoor-in-swiss-online-voting-system

ÉùÃ÷£º±¾×ÊѶÓÉÄϹ¬NGÓéÀÖάËûÃüÇ徲С×é·­ÒëºÍÕûÀí