GitHubÐÞ¸´9¸öGitÎó²î£¬£¬£¬£¬£¬£¬±Þ²ßÓû§¾ÙÐиüУ»£»£»£»£»£»£»£»¿¨°Í˹»ùÐû²¼2019ÄêÍøÂçÍþвµÄͳ¼ÆÊý¾Ý±¨¸æ
Ðû²¼Ê±¼ä 2019-12-16
1.GitHubÐÞ¸´9¸öGitÎó²î£¬£¬£¬£¬£¬£¬±Þ²ßÓû§¾ÙÐиüÐÂ
ÔÚÐÞ¸´GitÖеÄ9¸öÎó²îÖ®ºó£¬£¬£¬£¬£¬£¬GitHub±Þ²ßÓû§Ö´ÐС°Òªº¦¡±µÄGitÏîÄ¿´úÂë¸üС£¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²îÊÇÓÉGitLabµÄJoern SchneeweiszºÍ΢ÈíÇå¾²ÏìÓ¦ÖÐÐÄ·¢Ã÷²¢±¨¸æµÄ£¬£¬£¬£¬£¬£¬GitHubÖ¸³ö£º¡°ÈôÊǿˡ²»ÊÜÐÅÈεĴ洢¿â£¬£¬£¬£¬£¬£¬³ýÁ˸üÐÂÖ®ÍâûÓÐÒªÁì¿ÉÒÔ×èÖ¹±¾ÎÄÖÐÅû¶µÄÈκÎÎó²î´øÀ´µÄΣº¦¡±¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÎÊÌâ½öÓ°ÏìÁËWindowsƽ̨£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓÃÎó²îÁýÕÖí§Òâ·¾¶¡¢Ô¶³ÌÖ´ÐдúÂëÒÔ¼°ÁýÕÖ.git/Ŀ¼ÏµÄÎļþµÈ¡£¡£¡£¡£¡£¡£¡£¡£Îó²îµÄ±àºÅΪCVE-2019-1348~CVE-2019-1354ºÍCVE-2019-1387£¬£¬£¬£¬£¬£¬ÍêÕûÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cbronline.com/news/git-project-patches
2.NpmÍŶÓÕë¶Ôеġ°¶þ½øÖÆÖ²È롱Îó²î·¢³öÖÒÑÔ
NpmÍŶÓÐû²¼Çå¾²¾¯±¨£¬£¬£¬£¬£¬£¬½¨ÒéËùÓÐÓû§¸üÐÂÖÁ×îа汾£¨6.13.4£©£¬£¬£¬£¬£¬£¬ÒÔ±ÜÃâ¡°¶þ½øÖÆÖ²È롱¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÎļþ±éÀúºÍí§ÒâÎļþÁýÕÖÎÊÌâµÄ×éºÏ£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ²Èë¶ñÒâ¶þ½øÖÆÎļþ»òÁýÕÖÓû§ÅÌËã»úÉϵÄÎļþ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î½öÔÚͨ¹ýnpmÏÂÁîÐпͻ§¶Ë£¨CLI£©×°ÖÃÊÜѬȾµÄÈí¼þ°üʱ´ú²Å»á´¥·¢¡£¡£¡£¡£¡£¡£¡£¡£Npm¿ª·¢Ö°Ô±ÌåÏÖËûÃÇÒ»Ö±ÔÚnpmÃÅ»§ÖÐɨÃè¿ÉÄܰüÀ¨´ËÎó²îʹÓõÄÈí¼þ°ü£¬£¬£¬£¬£¬£¬µ«Î´·¢Ã÷ÈκοÉÒɰ¸Àý¡£¡£¡£¡£¡£¡£¡£¡£³ýÁËnpmÖ®Í⣬£¬£¬£¬£¬£¬ÁíÒ»¸öJavaScript°ü¹ÜÀíÆ÷yarnÒ²Êܵ½Ó°Ï죬£¬£¬£¬£¬£¬yarnÍŶÓÔÚа汾1.21.1ÖÐÐÞ¸´Á˸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/npm-team-warns-of-new-binary-planting-bug/
3.ÂÞÂíÄáÑÇ·¸·¨ÍÅ»ïʹÓÃÍÚ¿óÈí¼þѬȾ40¶àÍòÓû§
ƾ֤¶íº¥¶íÖݱ±ÇøÃÀ¹úÉó²é¹Ù°ì¹«ÊÒµÄÐÂΟ壬£¬£¬£¬£¬£¬ÂÞÂíÄáÑǵÄÒ»¸öÍøÂç·¸·¨ÍÅ»ïͨ¹ý¶ñÒâÍÚ¿óÈí¼þѬȾÁËÁè¼Ý40Íǫ̀ÅÌËã»ú¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïµÄÃû³ÆÎªBayrob Group£¬£¬£¬£¬£¬£¬ËüÒÑÔÚ°µÍøÉϳöÊÛ±»µÁµÄÓû§ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤ÈÏÕæ´Ë°¸µÄFBIÌØ¹¤Eric SmithµÄ˵·¨£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ï×Ô2007Äê×îÏȻ£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¹«ÃñµÄÅÌËã»ú¾ÙÐÐÍڿ󣬣¬£¬£¬£¬£¬²¢ÇÒÇÔÈ¡²ÆÎñÐÅÏ¢¡¢ÃÜÂë¡¢µç×ÓÓʼþµÈСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Æä¶ñÒâÈí¼þÖ÷Ҫͨ¹ýαװ³ÉÒøÐкÍÇå¾²³§É̵ĵç×ÓÓʼþÈö²¥¡£¡£¡£¡£¡£¡£¡£¡£¾Ý³Æ¸ÃÍÅ»ïÒѾ׬ǮÁè¼Ý400ÍòÃÀÔª£¬£¬£¬£¬£¬£¬µ«ÏÖÔÚ²¢²»ÇåÎúÆäÖÐÓм¸¶àÀ´×ÔÍÚ¿ó¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://finance.yahoo.com/news/romanian-cybergang-infects-over-400-100025512.html
4.ÐÂÔóÎ÷ÖÝHackensackÒ½ÔºÔâµ½ÀÕË÷Èí¼þ¹¥»÷
ÐÂÔóÎ÷ÖÝ×î´óµÄÒ½ÔºHackensack Meridian Health³ÉΪÀÕË÷Èí¼þ¹¥»÷µÄÊܺ¦Õߣ¬£¬£¬£¬£¬£¬ÆäÄÚ²¿ÍøÂçÔâÀÕË÷Èí¼þÆÆË𣬣¬£¬£¬£¬£¬¸ÃÒ½Ôº¾öÒéÖ§¸¶Êê½ðÒÔ½âÃÜÎļþ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃҽԺûÓÐ͸¶¹¥»÷ÕßʹÓõÄÀÕË÷Èí¼þÀàÐÍ£¬£¬£¬£¬£¬£¬Ò²Ã»ÓÐ͸¶¹¥»÷ÕßÈëÇֵķ½·¨ºÍÒÑÖ§¸¶µÄÊê½ð½ð¶î£¬£¬£¬£¬£¬£¬µ«ÌåÏÖ¹¥»÷±¬·¢ÔÚ12ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬ÆÈʹÆä×÷·ÏÁËһЩÍâ¿ÆÊÖÊõºÍÆäËü³ÌÐò¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚÆäÍøÂçµÄÖ÷ÒªÁÙ´²ÏµÍ³Òѻָ´ÔËÐУ¬£¬£¬£¬£¬£¬²¢ÇÒITר¼ÒÕýÔÚÆð¾¢Ê¹ÆäËùÓеÄÓ¦ÓóÌÐò»Ö¸´ÔÚÏß¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÒ½Ôº»¹ÌåÏÖ£¬£¬£¬£¬£¬£¬Ã»Óм£ÏóÅú×¢¹¥»÷Õß»á¼ûÁË»¼ÕßµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/95152/cyber-crime/new-jersey-hospital-ransomware-attack.html
5.ÒÁÀÊÐû³Æ×î½üÁ½´Î´ì°ÜÕë¶ÔÆä»ù´¡ÉèÊ©µÄÍøÂç¹¥»÷
ÒÁÀʵçÐŲ¿³¤Äº±Ä¬µÂ¡¤¼ÖÍߵ¡¤°¢ÔúÀ¼Ö»ôÃ×(Mohammad Javad Azari Jahromi)ÌåÏÖÒÁÀÊÔÚÒ»ÖÜÄÚµÚ¶þ´Î´ì°ÜÕë¶ÔÆä»ù´¡ÉèÊ©µÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÐÂÎÅÊÇÓÉISNAºÍMehrÐÂÎÅÉ籨µÀµÄ£¬£¬£¬£¬£¬£¬¼Ö»ôÃ×½«Õâ´Î¹¥»÷½ç˵Ϊ´ó¹æÄ£¹¥»÷£¬£¬£¬£¬£¬£¬²¢½«Æä¹éÓÉÓÚAPT27¡£¡£¡£¡£¡£¡£¡£¡£APT27×Ô2010ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹úµÄ¹ú·À³Ð°üÉÌ¡¢½ðÈÚЧÀ͹«Ë¾ºÍÖÐÑǹú¼ÒÊý¾ÝÖÐÐĵȡ£¡£¡£¡£¡£¡£¡£¡£¼Ö»ôÃ×ûÓÐ͸¶¹¥»÷µÄϸ½ÚÒÔ¼°¹¥»÷ÕßÕë¶ÔµÄÏêϸĿµÄ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/95169/apt/iran-foiled-2-attack.html
6.¿¨°Í˹»ùÐû²¼2019ÄêÍøÂçÍþвµÄͳ¼ÆÊý¾Ý±¨¸æ
¿¨°Í˹»ùÐû²¼2019ÄêÍøÂçÍþвͳ¼ÆÊý¾Ý±¨¸æ£¬£¬£¬£¬£¬£¬¸Ã±¨¸æÊÇ»ùÓÚ2018Äê11Ôµ½2019Äê10ÔÂʱ´ú´ÓÈ«Çò203¸ö¹ú¼ÒºÍµØÇøµÄKSNÓû§ÍøÂçµÄ¶ñÒâ»î¶¯Êý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ±¨¸æÊ±´ú£¬£¬£¬£¬£¬£¬ÓÐ19.8%µÄÓû§ÅÌËã»úÖÁÉÙÔâÊÜÒ»´Î¶ñÒâÈí¼þÀà±ðµÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿¨°Í˹»ùÇå¾²½â¾ö¼Æ»®×èÖ¹ÁËÀ´×ÔÈ«ÇòÔÚÏß×ÊÔ´µÄ9.7Òڴι¥»÷¡£¡£¡£¡£¡£¡£¡£¡£Web·´²¡¶¾×é¼þʶ±ð³ö2.7ÒÚ¸ö²î±ðµÄ¶ñÒâURL¡£¡£¡£¡£¡£¡£¡£¡£ÍøÂç·À²¡¶¾Èí¼þ¼ì²âµ½2461Íò¸ö²î±ðµÄ¶ñÒâÑù±¾¡£¡£¡£¡£¡£¡£¡£¡£75.5Íò¸öÓû§ÅÌËã»úÔâµ½ÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£226ÍòÓû§ÅÌËã»úÔâµ½¶ñÒâÍÚ¿ó¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿¨°Í˹»ùÇå¾²½â¾ö¼Æ»®ÔÚ76.6Íǫ̀װ±¸ÉÏ×èÖ¹ÁËÕë¶ÔÔÚÏßÒøÐÐÕË»§µÄ¶ñÒâÈí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/kaspersky-security-bulletin-2019-statistics/95475/


¾©¹«Íø°²±¸11010802024551ºÅ