ÄÜÔ´¹©Ó¦ÉÌE.Onй¶497¸ö¿Í»§µÄµç×ÓÓʼþµØµã£»£»£»£»£»£»Ë¼¿ÆÐÞ¸´ÍøÂçºÍͨѶװ±¸ÖеÄ18¸öÎó²î

Ðû²¼Ê±¼ä 2019-07-08
1.ÄÜÔ´¹©Ó¦ÉÌE.Onй¶497¸ö¿Í»§µÄµç×ÓÓʼþµØµã

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ÄÜÔ´¹©Ó¦ÉÌE.On³ÆÆäÒ»¸ö¡°ÏµÍ³¹ýʧ¡±µ¼ÖÂÊý°Ù¸ö¿Í»§µÄµç×ÓÓʼþµØµãÔÚÒDZíÅ̶ÁÊýÇëÇóÖÐй¶¡£¡£¡£¸Ã×Ô¶¯ÓʼþÔ­±¾½öÕë¶ÔÿСÎÒ˽¼Ò£¬£¬£¬£¬£¬£¬£¬µ«ÓʼþÖйýʧµØÁгöÁËÁíÍâ497¸öÊÕ¼þÈË¡£¡£¡£¸Ã¹«Ë¾³Æ¸ÃÊÂÎñûÓе¼ÖÂÈκÎÕË»§ÐÅÏ¢»ò²ÆÎñϸ½Úй¶¡£¡£¡£¸Ã¹«Ë¾»¹ÌåÏÖÕýÔÚ¾ÙÐÐÄÚ²¿ÊӲ죬£¬£¬£¬£¬£¬£¬²¢»áÔÚÐëҪʱ֪ͨÓйØÕþ¸®¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bbc.com/news/technology-48888383

2.й¥»÷»î¶¯Ê¹ÓÃGolang¶ñÒâÈí¼þÃé×¼LinuxЧÀÍÆ÷

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

F5 NetworksÑо¿Ö°Ô±·¢Ã÷Ò»¸öеĶñÒâÍÚ¿ó»î¶¯£¬£¬£¬£¬£¬£¬£¬¸Ã»î¶¯Ö÷ÒªÏòLinuxЧÀÍÆ÷·Ö·¢ÐµÄGolang¶ñÒâÈí¼þ¡£¡£¡£¸Ã»î¶¯ÓÚ6ÔÂ10ÈÕ×óÓÒ×îÏÈ£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÒѾ­Ñ¬È¾ÁËÊýǧ̨»úе¡£¡£¡£¹¥»÷Õß½«¶ñÒâ´úÂëÍйÜÔÚ±»ÈëÇÖµÄÖÐÎĵçÉÌÍøÕ¾ÉÏ£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃPastebinЧÀÍÍйÜbash¾ç±¾¡£¡£¡£¹¥»÷ÕßʹÓÃ7ÖÖÒªÁì¾ÙÐÐÈö²¥£¬£¬£¬£¬£¬£¬£¬°üÀ¨4¸öWebÓ¦ÓÃÎó²î¡¢SSHƾ֤ö¾Ù¡¢RedisÊý¾Ý¿âÃÜÂëö¾ÙÒÔ¼°Ê¹ÓÃÒÑÓÐSSHÃØÔ¿ÅþÁ¬ÆäËüÅÌËã»ú¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/88005/malware/cryptomining-campaign-golang-malware.html

3.´ÈÉÆ»ú¹¹St John AmbulanceÔâÀÕË÷Èí¼þ¹¥»÷

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ÃÀ¹úÇÀ¾È´ÈÉÆ»ú¹¹St John AmbulanceÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬ËùÓмÓÈëÁËÅàѵ¿Î³ÌµÄÓû§Êý¾Ý¶¼ÊÜÓ°Ïì¡£¡£¡£¸Ã»ú¹¹ÓÚ7ÔÂ2ÈÕ·¢Ã÷ÊÜÀÕË÷²¡¶¾Ñ¬È¾£¬£¬£¬£¬£¬£¬£¬²¨¼°µÄÓû§Êý¾Ý°üÀ¨Ô¤¶©ºÍ¼ÓÈëÅàѵ¿Î³ÌµÄÖ°Ô±ÐÕÃû¡¢¿Î³ÌÏêÇé¡¢ÁªÏµÐÅÏ¢¡¢Óöȡ¢·¢Æ±ÒÔ¼°¼ÝÕÕÐÅÏ¢¡£¡£¡£¸Ã»ú¹¹³ÆÕâ´Î¹¥»÷²¢Î´¶ÔÆäÔËӪϵͳ±¬·¢Ó°Ïì¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/st-john-ambulance-hit-with-ransomware-attack-af0b8047

4.¿ËÂÞµØÑÇÕþ¸®Ôâ¶ñÒâÈí¼þSilentTrinity¹¥»÷

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

¿ËÂÞµØÑÇÕþ¸®Ô±¹¤ÔÚ2019Äê2ÔÂÖÁ4ÔÂʱ´úÔâµ½´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬¸Ã´¹ÂÚÓʼþαװ³É¿ËÂÞµØÑÇÓÊÕþ»òÆäËüÁãÊÛЧÀ͵ÄËÍ»õ֪ͨ£¬£¬£¬£¬£¬£¬£¬Í¨¹ý¶ñÒâURLÏòÓû§·Ö·¢°üÀ¨¶ñÒâºêµÄExcelÎĵµ¡£¡£¡£¸ÃÎĵµÔÚ¹¥»÷ʱ´ú·Ö·¢¹ýÁ½ÖÖpayload£¬£¬£¬£¬£¬£¬£¬Ò»¸öÊÇEmpireºóÃÅ£¬£¬£¬£¬£¬£¬£¬ÁíÒ»¸öÊÇSilentTrinity¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/croatian-government-targeted-by-mysterious-hackers/

5.˼¿ÆÐÞ¸´ÍøÂçºÍͨѶװ±¸ÖеÄ18¸öÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

˼¿ÆÐû²¼Ò»ÏµÁÐ17¸öÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÍøÂçºÍͨѶװ±¸ÖеÄ18¸öÎó²î¡£¡£¡£Îó²î¹æÄ£°üÀ¨´ÓÏÂÁîºÍ´úÂëÖ´Ðе½¾Ü¾øÐ§À͵È¡£¡£¡£½ÏΪÑÏÖØµÄÎó²î°üÀ¨Web Security ApplianceÖÐÓÉÓÚ·¢ËÍÃûÌùýʧµÄÖ¤Êéµ¼ÖµľܾøÐ§ÀÍÎó²îÒÔ¼°JabberÖеÄDLLÔ¤¼ÓÔØ´úÂëÖ´ÐÐÎó²î¡£¡£¡£Ë¼¿ÆSmall Business½»Á÷»úÐÞ¸´Á½¸ö¸ßΣÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÒ»¸öÊÇHTTPÇëÇóµ¼ÖµľܾøÐ§ÀÍÎó²î£¬£¬£¬£¬£¬£¬£¬ÁíÒ»¸öÊÇSSLÖ¤Êé´¦Öóͷ£Àú³ÌÖеÄÄÚ´æËð»µÎó²î¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2019/07/05/cisco_patch_fix/

6.MagentoÐÞ¸´¿Éµ¼ÖÂÍøÕ¾±»½ÓÊܵÄÇå¾²Îó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

MagentoÐÞ¸´Ò»¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÐ®ÖÆÖÎÀí»Ø»°²¢½ÓÊÜÍøÕ¾¡£¡£¡£Æ¾Ö¤RIPS TechnologiesµÄÆÊÎö±¨¸æ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÊ×ÏÈ¿ÉʹÓô洢ÐÍXSSÎó²î½«JavaScript payload×¢ÈëMagentoÊÐËÁµÄÖÎÀíºó¶Ë¡£¡£¡£Í¨¹ýÕâÖÖ·½·¨£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÐ®ÖÆÖÎÆÊÎö»°£¬£¬£¬£¬£¬£¬£¬È»ºóʹÓÃRCEÎó²î£¨Phar·´ÐòÁл¯Îó²î£©À´½ÓÊÜÔÚÏßÊÐËÁ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/87955/hacking/magento-security-flaws.html