GitHubÐÞ¸´9¸öGitÎó²î£¬ £¬£¬£¬£¬£¬±Þ²ßÓû§¾ÙÐиüУ»£»£»£»£»£»£»£»¿¨°Í˹»ùÐû²¼2019ÄêÍøÂçÍþвµÄͳ¼ÆÊý¾Ý±¨¸æ

Ðû²¼Ê±¼ä 2019-12-16


1.GitHubÐÞ¸´9¸öGitÎó²î£¬ £¬£¬£¬£¬£¬±Þ²ßÓû§¾ÙÐиüÐÂ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÔÚÐÞ¸´GitÖеÄ9¸öÎó²îÖ®ºó£¬ £¬£¬£¬£¬£¬GitHub±Þ²ßÓû§Ö´ÐС°Òªº¦¡±µÄGitÏîÄ¿´úÂë¸üС£¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²îÊÇÓÉGitLabµÄJoern SchneeweiszºÍ΢ÈíÇå¾²ÏìÓ¦ÖÐÐÄ·¢Ã÷²¢±¨¸æµÄ£¬ £¬£¬£¬£¬£¬GitHubÖ¸³ö£º¡°ÈôÊǿˡ²»ÊÜÐÅÈεĴ洢¿â£¬ £¬£¬£¬£¬£¬³ýÁ˸üÐÂÖ®ÍâûÓÐÒªÁì¿ÉÒÔ×èÖ¹±¾ÎÄÖÐÅû¶µÄÈκÎÎó²î´øÀ´µÄΣº¦¡±¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÎÊÌâ½öÓ°ÏìÁËWindowsƽ̨£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓÃÎó²îÁýÕÖí§Òâ·¾¶¡¢Ô¶³ÌÖ´ÐдúÂëÒÔ¼°ÁýÕÖ.git/Ŀ¼ÏµÄÎļþµÈ¡£¡£¡£¡£¡£¡£¡£¡£Îó²îµÄ±àºÅΪCVE-2019-1348~CVE-2019-1354ºÍCVE-2019-1387£¬ £¬£¬£¬£¬£¬ÍêÕûÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º

https://www.cbronline.com/news/git-project-patches


2.NpmÍŶÓÕë¶Ôеġ°¶þ½øÖÆÖ²È롱Îó²î·¢³öÖÒÑÔ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


NpmÍŶÓÐû²¼Çå¾²¾¯±¨£¬ £¬£¬£¬£¬£¬½¨ÒéËùÓÐÓû§¸üÐÂÖÁ×îа汾£¨6.13.4£©£¬ £¬£¬£¬£¬£¬ÒÔ±ÜÃâ¡°¶þ½øÖÆÖ²È롱¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÎļþ±éÀúºÍí§ÒâÎļþÁýÕÖÎÊÌâµÄ×éºÏ£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ²Èë¶ñÒâ¶þ½øÖÆÎļþ»òÁýÕÖÓû§ÅÌËã»úÉϵÄÎļþ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î½öÔÚͨ¹ýnpmÏÂÁîÐпͻ§¶Ë£¨CLI£©×°ÖÃÊÜѬȾµÄÈí¼þ°üʱ´ú²Å»á´¥·¢¡£¡£¡£¡£¡£¡£¡£¡£Npm¿ª·¢Ö°Ô±ÌåÏÖËûÃÇÒ»Ö±ÔÚnpmÃÅ»§ÖÐɨÃè¿ÉÄܰüÀ¨´ËÎó²îʹÓõÄÈí¼þ°ü£¬ £¬£¬£¬£¬£¬µ«Î´·¢Ã÷ÈκοÉÒɰ¸Àý¡£¡£¡£¡£¡£¡£¡£¡£³ýÁËnpmÖ®Í⣬ £¬£¬£¬£¬£¬ÁíÒ»¸öJavaScript°ü¹ÜÀíÆ÷yarnÒ²Êܵ½Ó°Ï죬 £¬£¬£¬£¬£¬yarnÍŶÓÔÚа汾1.21.1ÖÐÐÞ¸´Á˸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/npm-team-warns-of-new-binary-planting-bug/


3.ÂÞÂíÄáÑÇ·¸·¨ÍÅ»ïʹÓÃÍÚ¿óÈí¼þѬȾ40¶àÍòÓû§


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ƾ֤¶íº¥¶íÖݱ±ÇøÃÀ¹úÉó²é¹Ù°ì¹«ÊÒµÄÐÂΟ壬 £¬£¬£¬£¬£¬ÂÞÂíÄáÑǵÄÒ»¸öÍøÂç·¸·¨ÍÅ»ïͨ¹ý¶ñÒâÍÚ¿óÈí¼þѬȾÁËÁè¼Ý40Íǫ̀ÅÌËã»ú¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïµÄÃû³ÆÎªBayrob Group£¬ £¬£¬£¬£¬£¬ËüÒÑÔÚ°µÍøÉϳöÊÛ±»µÁµÄÓû§ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤ÈÏÕæ´Ë°¸µÄFBIÌØ¹¤Eric SmithµÄ˵·¨£¬ £¬£¬£¬£¬£¬¸ÃÍÅ»ï×Ô2007Äê×îÏȻ£¬ £¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¹«ÃñµÄÅÌËã»ú¾ÙÐÐÍÚ¿ó£¬ £¬£¬£¬£¬£¬²¢ÇÒÇÔÈ¡²ÆÎñÐÅÏ¢¡¢ÃÜÂë¡¢µç×ÓÓʼþµÈСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Æä¶ñÒâÈí¼þÖ÷Ҫͨ¹ýαװ³ÉÒøÐкÍÇå¾²³§É̵ĵç×ÓÓʼþÈö²¥¡£¡£¡£¡£¡£¡£¡£¡£¾Ý³Æ¸ÃÍÅ»ïÒѾ­×¬Ç®Áè¼Ý400ÍòÃÀÔª£¬ £¬£¬£¬£¬£¬µ«ÏÖÔÚ²¢²»ÇåÎúÆäÖÐÓм¸¶àÀ´×ÔÍÚ¿ó¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://finance.yahoo.com/news/romanian-cybergang-infects-over-400-100025512.html


4.ÐÂÔóÎ÷ÖÝHackensackÒ½ÔºÔâµ½ÀÕË÷Èí¼þ¹¥»÷


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÐÂÔóÎ÷ÖÝ×î´óµÄÒ½ÔºHackensack Meridian Health³ÉΪÀÕË÷Èí¼þ¹¥»÷µÄÊܺ¦Õߣ¬ £¬£¬£¬£¬£¬ÆäÄÚ²¿ÍøÂçÔâÀÕË÷Èí¼þÆÆË𣬠£¬£¬£¬£¬£¬¸ÃÒ½Ôº¾öÒéÖ§¸¶Êê½ðÒÔ½âÃÜÎļþ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃҽԺûÓÐ͸¶¹¥»÷ÕßʹÓõÄÀÕË÷Èí¼þÀàÐÍ£¬ £¬£¬£¬£¬£¬Ò²Ã»ÓÐ͸¶¹¥»÷ÕßÈëÇֵķ½·¨ºÍÒÑÖ§¸¶µÄÊê½ð½ð¶î£¬ £¬£¬£¬£¬£¬µ«ÌåÏÖ¹¥»÷±¬·¢ÔÚ12ÔÂ2ÈÕ£¬ £¬£¬£¬£¬£¬ÆÈʹÆä×÷·ÏÁËһЩÍâ¿ÆÊÖÊõºÍÆäËü³ÌÐò¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚÆäÍøÂçµÄÖ÷ÒªÁÙ´²ÏµÍ³Òѻָ´ÔËÐУ¬ £¬£¬£¬£¬£¬²¢ÇÒITר¼ÒÕýÔÚÆð¾¢Ê¹ÆäËùÓеÄÓ¦ÓóÌÐò»Ö¸´ÔÚÏß¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÒ½Ôº»¹ÌåÏÖ£¬ £¬£¬£¬£¬£¬Ã»Óм£ÏóÅú×¢¹¥»÷Õß»á¼ûÁË»¼ÕßµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95152/cyber-crime/new-jersey-hospital-ransomware-attack.html


5.ÒÁÀÊÐû³Æ×î½üÁ½´Î´ì°ÜÕë¶ÔÆä»ù´¡ÉèÊ©µÄÍøÂç¹¥»÷


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÒÁÀʵçÐŲ¿³¤Äº±Ä¬µÂ¡¤¼ÖÍߵ¡¤°¢ÔúÀ¼Ö»ôÃ×(Mohammad Javad Azari Jahromi)ÌåÏÖÒÁÀÊÔÚÒ»ÖÜÄÚµÚ¶þ´Î´ì°ÜÕë¶ÔÆä»ù´¡ÉèÊ©µÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÐÂÎÅÊÇÓÉISNAºÍMehrÐÂÎÅÉ籨µÀµÄ£¬ £¬£¬£¬£¬£¬¼Ö»ôÃ×½«Õâ´Î¹¥»÷½ç˵Ϊ´ó¹æÄ£¹¥»÷£¬ £¬£¬£¬£¬£¬²¢½«Æä¹éÓÉÓÚAPT27¡£¡£¡£¡£¡£¡£¡£¡£APT27×Ô2010ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬ £¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹úµÄ¹ú·À³Ð°üÉÌ¡¢½ðÈÚЧÀ͹«Ë¾ºÍÖÐÑǹú¼ÒÊý¾ÝÖÐÐĵÈ¡£¡£¡£¡£¡£¡£¡£¡£¼Ö»ôÃ×ûÓÐ͸¶¹¥»÷µÄϸ½ÚÒÔ¼°¹¥»÷ÕßÕë¶ÔµÄÏêϸĿµÄ¡£¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95169/apt/iran-foiled-2-attack.html


6.¿¨°Í˹»ùÐû²¼2019ÄêÍøÂçÍþвµÄͳ¼ÆÊý¾Ý±¨¸æ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¿¨°Í˹»ùÐû²¼2019ÄêÍøÂçÍþвͳ¼ÆÊý¾Ý±¨¸æ£¬ £¬£¬£¬£¬£¬¸Ã±¨¸æÊÇ»ùÓÚ2018Äê11Ôµ½2019Äê10ÔÂʱ´ú´ÓÈ«Çò203¸ö¹ú¼ÒºÍµØÇøµÄKSNÓû§ÍøÂçµÄ¶ñÒâ»î¶¯Êý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ±¨¸æÊ±´ú£¬ £¬£¬£¬£¬£¬ÓÐ19.8%µÄÓû§ÅÌËã»úÖÁÉÙÔâÊÜÒ»´Î¶ñÒâÈí¼þÀà±ðµÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿¨°Í˹»ùÇå¾²½â¾ö¼Æ»®×èÖ¹ÁËÀ´×ÔÈ«ÇòÔÚÏß×ÊÔ´µÄ9.7Òڴι¥»÷¡£¡£¡£¡£¡£¡£¡£¡£Web·´²¡¶¾×é¼þʶ±ð³ö2.7ÒÚ¸ö²î±ðµÄ¶ñÒâURL¡£¡£¡£¡£¡£¡£¡£¡£ÍøÂç·À²¡¶¾Èí¼þ¼ì²âµ½2461Íò¸ö²î±ðµÄ¶ñÒâÑù±¾¡£¡£¡£¡£¡£¡£¡£¡£75.5Íò¸öÓû§ÅÌËã»úÔâµ½ÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£226ÍòÓû§ÅÌËã»úÔâµ½¶ñÒâÍÚ¿ó¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿¨°Í˹»ùÇå¾²½â¾ö¼Æ»®ÔÚ76.6Íǫ̀װ±¸ÉÏ×èÖ¹ÁËÕë¶ÔÔÚÏßÒøÐÐÕË»§µÄ¶ñÒâÈí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://securelist.com/kaspersky-security-bulletin-2019-statistics/95475/