¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190215
Ðû²¼Ê±¼ä 2019-02-15
Âí¶úËûVallettaÒøÐÐÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÊÔͼ½«1300ÍòŷԪתÈëÓ¢¹ú¡¢ÃÀ¹ú¡¢½Ý¿Ë¹²ºÍ¹úºÍÏã¸ÛÒøÐеÄÕË»§¡£¡£¡£ÕâЩÉúÒâÔÚ30·ÖÖÓÄÚ±»×èÖ¹£¬£¬£¬£¬£¬£¬£¬µ«¹¥»÷ÕßÊÇ·ñÒѾ»ñµÃ×ʽðÉÐδ»ñµÃ֤ʵ¡£¡£¡£¸ÃÒøÐÐÒѾ¹Ø±ÕÁËÆäϵͳ£¬£¬£¬£¬£¬£¬£¬²¢ÔÝʱ×èÖ¹ÁËËùÓÐÓªÒµ¡£¡£¡£Æ¾Ö¤Âí¶úËûʱ±¨µÄ±¨µÀ£¬£¬£¬£¬£¬£¬£¬ÕâÆð¹¥»÷ÊÂÎñ±¬·¢ÔÚ±¾ÖÜÈýÉÏÎç¡£¡£¡£¸ÃÒøÐÐÌåÏÖ£¬£¬£¬£¬£¬£¬£¬Ã»Óпͻ§ÕË»§¼°Æä×ʽðÊܵ½Ë𺦡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/02/14/bank-of-valletta-cyber-attack/2¡¢Á¬Ëø²ÍÌüTruluckÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬²¿·Ö¿Í»§µÄÖ§¸¶ÐÅϢй¶
ÔÎÄÁ´½Ó£º
https://cyware.com/news/trulucks-seafood-steak-crab-house-reports-data-breach-at-8-of-its-restaurants-b1fccc723¡¢0patch.comÐû²¼OpenOffice´úÂëÖ´ÐÐ0dayµÄÐÞ¸´²¹¶¡

0patch.comÍÆ³öOpenOfficeÁãÈÕÎó²î£¨CVE-2018-16858£©µÄÐÞ¸´²¹¶¡¡£¡£¡£¸ÃÎó²îÊÇÓÉÇå¾²Ñо¿Ô±AlexInf¨¹hr·¢Ã÷µÄ£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚÌᳫĿ¼±éÀú¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËOpenOfficeµÄËùÓа汾ºÍLibreOfficeµÄ°æ±¾6.0.6/6.1.2.1¡£¡£¡£LibreOfficeÒѾÔÚа汾6.0.7/6.1.3ÖÐÐÞ¸´Á˸ÃÎó²î¡£¡£¡£ËäÈ»¸ÃÎó²îÓ°ÏìÁËOpenOfficeµÄLinuxºÍWindows°æ±¾£¬£¬£¬£¬£¬£¬£¬µ«0patchÍÆ³öµÄÐÞ¸´²¹¶¡Ö»Õë¶ÔWindowsƽ̨¿ÉÓᣡ£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/openoffice-zero-day-code-execution-flaw-gets-free-micropatch/4¡¢Î÷ÃÅ×ÓÐÞ¸´SICAM 230ÖеÄÔ¶³Ì´úÂëÖ´ÐкÍÌáȨÎó²î

Î÷ÃÅ×ÓSICAM 230¿ØÖÆÏµÍ³±»ÆÕ±éÓÃÓÚICSÓ¦Ó㬣¬£¬£¬£¬£¬£¬ÀýÈ繫ÓÃÊÂÒµµÄ¼¯³ÉÄÜԴϵͳÒÔ¼°ÖÇÄܵçÍøµÄ¼à¿ØÏµÍ³µÈ¡£¡£¡£Æ¾Ö¤Î÷ÃÅ×ÓÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬SICAM 230±£´æ¶ÑÒç³öµ¼ÖµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2018-3991£©»ººÍ³åÇøÒç³öµ¼ÖµÄÌáȨÎó²î£¨CVE-2018-3990£©¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Î÷ÃÅ×Ó¹²Ðû²¼ÁË16¸öÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Á˶à¸öÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨EN100ÒÔÌ«ÍøÍ¨Ñ¶Ä£¿£¿£¿£¿£¿éºÍSIPROTEC 5¼ÌµçÆ÷ÖеÄ3¸ö¿Éµ¼ÖÂDoSµÄÎó²î£¨CVE-2018-16563¡¢CVE-2018-11451ºÍCVE-2018-11452£©¡£¡£¡£½¨ÒéÓû§¾¡¿ì×°ÖÃÏà¹Ø²úÆ·µÄ¸üС£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/siemens-critical-remote-code-execution/141768/5¡¢Õë¶ÔmacOSµÄShlayerľÂí£¬£¬£¬£¬£¬£¬£¬¿É½ûÓÃGatekeeper±£»£»£»£»¤»úÖÆ

Carbon BlackµÄTAUÑо¿ÍŶӷ¢Ã÷Õë¶ÔmacOSµÄShlayerľÂíµÄбäÖÖ£¬£¬£¬£¬£¬£¬£¬¸Ã±äÖÖͨ¹ý¶ñÒâFlash¸üоÙÐзַ¢£¬£¬£¬£¬£¬£¬£¬¿ÉÓ°ÏìmacOS°æ±¾10.10.5µ½10.14.3¡£¡£¡£Ñо¿ÍŶÓÖ¸³ö£¬£¬£¬£¬£¬£¬£¬¸Ã±äÌå½ÓÄÉÁ˶à²ã»ìÏý£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÄܹ»¾ÙÐÐÌáȨ¡£¡£¡£¸Ã±äÌ廹»á½ûÓÃmacOSÉϵÄGatekeeper±£»£»£»£»¤»úÖÆÀ´ÔËÐеڶþ½×¶Îpayload¡£¡£¡£¸Ã±äÌåµÄ´ó´ó¶¼Ñù±¾¶¼ÊÇDMGÎļþ£¬£¬£¬£¬£¬£¬£¬Ò»Ð©Ñù±¾»¹Ê¹ÓÃÕýµ±µÄApple¿ª·¢ÕßID¾ÙÐÐÊðÃû¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/new-shlayer-variant-disables-gatekeeper-protection-mechanism-to-run-second-stage-payloads-cce39f236¡¢ÐÂLinuxľÂíSpeakUp£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶Ô¶«ÑǺÍÀ¶¡ÃÀÖÞ
ÔÎÄÁ´½Ó£º
https://research.checkpoint.com/speakup-a-new-undetected-backdoor-linux-trojan/ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí