¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190301

Ðû²¼Ê±¼ä 2019-03-01
1¡¢Chrome 0dayÎó²î£¬ £¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¿Éͨ¹ýPDFÍøÂçÓû§ÐÅÏ¢

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾



EdgeSpotÑо¿Ö°Ô±ÊӲ쵽ʹÓÃChromeÁãÈÕÎó²îÇÔÈ¡Óû§ÐÅÏ¢µÄ¶ñÒâPDFÎļþ¡£¡£¡£¡£ ¡£¡£¡£¡£µ±Óû§Í¨¹ýChromeµÄPDFÉó²éÆ÷·­¿ª¸Ã¶ñÒâÎļþʱ£¬ £¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÎó²îÍøÂçÓû§µÄÐÅÏ¢£¬ £¬£¬£¬£¬ £¬£¬£¬²¢·¢ËÍÖÁÔ¶³ÌЧÀÍÆ÷¡£¡£¡£¡£ ¡£¡£¡£¡£ÕâЩÐÅÏ¢°üÀ¨ÏµÍ³µÄÏêϸÐÅÏ¢£¬ £¬£¬£¬£¬ £¬£¬£¬ÀýÈçIPµØµã¡¢²Ù×÷ϵͳ°æ±¾ºÅ¡¢Chrome°æ±¾ºÅ¡¢PDFÎļþ·¾¶µÈ¡£¡£¡£¡£ ¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬ £¬£¬£¬£¬ £¬£¬£¬¶ñÒâPDFÎļþÔÚAdobe ReaderÖв»»áÖ´ÐÐÈκζñÒâ»î¶¯¡£¡£¡£¡£ ¡£¡£¡£¡£GoogleÈ·ÈÏÁËÕâÒ»Îó²î£¬ £¬£¬£¬£¬ £¬£¬£¬²¢ÔÊÐí½«ÔÚ4ÔÂβ¾ÙÐÐÐÞ¸´¡£¡£¡£¡£ ¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/google-chrome-zero-day-vulnerability-could-allow-attackers-to-collect-user-information-via-pdf-files-01b8df3d

2¡¢CoinomiÇ®°üÃ÷ÎÄ´«ÊäÓû§ÃÜÂ룬 £¬£¬£¬£¬ £¬£¬£¬µ¼ÖÂÔ¼7ÍòÃÀÔª±»ÇÔ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¼ÓÃÜÇ®±ÒÇ®°üCoinomiÔÚÇ®°üÉèÖÃÀú³ÌÖлὫÓû§µÄÃ÷ÎÄÃÜÂëͨ¹ýHTTP·¢ËÍÖÁ¹È¸èµÄƴд¼ì²é³ÌÐò£¬ £¬£¬£¬£¬ £¬£¬£¬µ¼ÖÂÓû§µÄÕË»§ºÍ×ʽðÒ×ÊÜÖÐÐÄÈË£¨MiTM£©¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃ×èµ²µ½µÄÃÜÂëµÇÈÎÃü»§µÄÕË»§²¢Çå¿ÕÆä×ʽ𡣡£¡£¡£ ¡£¡£¡£¡£Ò»¸öÓû§Al MaawaliÌåÏÖ£¬ £¬£¬£¬£¬ £¬£¬£¬ÆäÕË»§ÖеÄ×ʽðÒò´ËËðʧÁË90%£¬ £¬£¬£¬£¬ £¬£¬£¬¼ÛÖµÔ¼7ÍòÃÀÔª¡£¡£¡£¡£ ¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/cryptocurrency-wallet-coinomi-sends-users-passwords-to-googles-spellchecker-in-plain-text-3b3b794c

3¡¢Ë¼¿ÆTalosÖÒÑÔÕë¶ÔElasticsearchЧÀÍÆ÷µÄÐÂÒ»ÂÖ¹¥»÷»î¶¯

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

˼¿ÆTalosÑо¿Ö°Ô±ÖÒÑԳƽüÆÚÕë¶ÔElasticsearchЧÀÍÆ÷µÄ¹¥»÷»î¶¯¼¤Ôö¡£¡£¡£¡£ ¡£¡£¡£¡£ÕâЩ¹¥»÷»î¶¯Ö÷ÒªÈö²¥¶ñÒâÈí¼þºÍÍÚ¿óÈí¼þ£¬ £¬£¬£¬£¬ £¬£¬£¬¾Ý³ÆÓÐ6¸ö²î±ðµÄ·¸·¨ÍÅ»ï¼ÓÈëÆäÖС£¡£¡£¡£ ¡£¡£¡£¡£ÆäÄ¿µÄÖ÷ÒªÊǰ汾1.4.2¼°¸üÔç°æ±¾µÄElasticsearchЧÀÍÆ÷£¬ £¬£¬£¬£¬ £¬£¬£¬²¢Ê¹ÓÃЧÀÍÆ÷ÖÐδ´ò²¹¶¡µÄ¾ÉÎó²î¾ÙÐÐÈö²¥¡£¡£¡£¡£ ¡£¡£¡£¡£×î³£±»Ê¹ÓõÄÁ½¸öÎó²îÊÇCVE-2014-3120ºÍCVE-2015-1427£¬ £¬£¬£¬£¬ £¬£¬£¬¿ÉÔÊÐíÖ´ÐÐí§ÒâshellÏÂÁî¡£¡£¡£¡£ ¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/targeted-malware-attacks-against-elasticsearch-clusters-surge/

4¡¢Topps.comÔâFormjacking¹¥»÷£¬ £¬£¬£¬£¬ £¬£¬£¬²¿·Ö¿Í»§µÄÖ§¸¶ÐÅϢй¶

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

ÌåÓý¹«Ë¾Topps³ÉΪFormjacking¹¥»÷µÄ×îÐÂÊܺ¦Õߣ¬ £¬£¬£¬£¬ £¬£¬£¬Æ¾Ö¤¸Ã¹«Ë¾Ðû²¼µÄ֪ͨ£¬ £¬£¬£¬£¬ £¬£¬£¬´Ë´Î¹¥»÷ÊÂÎñÓ°ÏìÁË2018Äê11ÔÂ19ÈÕÖÁ2019Äê1ÔÂ9ÈÕʱ´úÔÚÆä¹ÙÍøTopps.com϶©µ¥µÄ¿Í»§¡£¡£¡£¡£ ¡£¡£¡£¡£±»ÇÔÈ¡µÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢Óʼĵص㡢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµãÒÔ¼°ÐÅÓÿ¨/½è¼Ç¿¨ºÅ¡¢µ½ÆÚÈÕÆÚºÍÇå¾²ÂëµÈÖ§¸¶ÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖʹÓÃPayPal¾ÙÐÐÖ§¸¶µÄ¿Í»§Î´ÊÜÓ°Ïì¡£¡£¡£¡£ ¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/sports-company-topps-becomes-the-latest-victim-of-formjacking-attack-3422027d

5¡¢NEWSQUESTÍøÕ¾±£´æ×¢È룬 £¬£¬£¬£¬ £¬£¬£¬¿Éµ¼ÖÂä¯ÀÀÆ÷±»Ð®ÖÆ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

ƾ֤UKNIP247µÄ±¨µÀ£¬ £¬£¬£¬£¬ £¬£¬£¬Ó¢¹úÐÂÎÅÍøÕ¾NewsquestÔâµ½ºÚ¿ÍÈëÇÖ£¬ £¬£¬£¬£¬ £¬£¬£¬Æä¹ÙÍø±»×¢È벡¶¾£¬ £¬£¬£¬£¬ £¬£¬£¬µ¼ÖÂÈκλá¼ûNewquestÍøÕ¾µÄÓû§µÄä¯ÀÀÆ÷±»Ð®ÖÆ¡£¡£¡£¡£ ¡£¡£¡£¡£ÕâЩÓû§±»Öض¨Ïòµ½Ò»¸ö³é½±ÍøÕ¾£¬ £¬£¬£¬£¬ £¬£¬£¬Ö»Óе±Óû§ÖØÆôÁËä¯ÀÀÆ÷»òÅÌËã»úÖ®ºó£¬ £¬£¬£¬£¬ £¬£¬£¬²Å»ª»Ö¸´Æä»á¼û¡£¡£¡£¡£ ¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.uknip.co.uk/2019/02/newsquest-websites-comprised-by-major-security-breach/

6¡¢Ë¼¿ÆÐÞ¸´RV110WµÈ·ÓÉÆ÷×°±¸ÖеÄRCEÎó²î

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


˼¿ÆÐû²¼Ç徲ͨ¸æ£¬ £¬£¬£¬£¬ £¬£¬£¬ÐÞ¸´ÁËRV110W¡¢RV130WºÍRV215W·ÓÉÆ÷×°±¸ÖеĸßΣÎó²î£¨CVE-2019-1663£©¡£¡£¡£¡£ ¡£¡£¡£¡£¸ÃÎó²î¿ÉÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐÐí§Òâ´úÂ룬 £¬£¬£¬£¬ £¬£¬£¬ÆäCVSS 3.0ÆÀ·ÖΪ9.8·Ö¡£¡£¡£¡£ ¡£¡£¡£¡£¸ÃÎó²îµÄÔµ¹ÊÔ­ÓÉÊÇÈí¼þ¿ÉÒÔ¶ÔÄڴ滺³åÇø½çÏßÖ®ÍâµÄλÖþÙÐÐÔ½½ç¶ÁÈ¡ºÍдÈë¡£¡£¡£¡£ ¡£¡£¡£¡£ºÃÐÂÎÅÊÇ£¬ £¬£¬£¬£¬ £¬£¬£¬ÔÚĬÈÏÉèÖÃÏÂÈýÖÖ×°±¸¶¼½ûÓÃÁËWebÖÎÀí½Ó¿ÚµÄÔ¶³ÌÅþÁ¬¡£¡£¡£¡£ ¡£¡£¡£¡£Ë¼¿ÆÒѾ­Ôڹ̼þ°æ±¾RV110W 1.2.2.1¡¢RV130W 1.0.3.45ºÍRV215W 1.3.1.1ÖÐÐÞ¸´ÁËÕâ¸öÎó²î¡£¡£¡£¡£ ¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£¡£ ¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-rce-vulnerability-in-rv110w-rv130w-and-rv215w-routers/

ÉùÃ÷£º±¾×ÊѶÓÉ¿­·¢k8άËûÃüÇ徲С×é·­ÒëºÍÕûÀí