npmɾ³ý¶ñÒâÈí¼þ°ü£»£»£»£»£»£»Áè¼Ý4.3Íǫ̀SquidЧÀÍÆ÷Ò×Êܹ¥»÷£»£»£»£»£»£»BitdefenderÐÞ¸´ÌáȨÎó²î

Ðû²¼Ê±¼ä 2019-08-23

1.²¨ÌØÀ¼¹«Á¢Ñ§Ð£ÒòBECÕ©Æ­Ëðʧ290ÍòÃÀÔª


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¶íÀÕ¸ÔÖݲ¨ÌØÀ¼¹«Á¢Ñ§Ð£ÔâBECÕ©Æ­290ÍòÃÀÔª£¬£¬ £¬£¬£¬£¬£¬ÏÖÔÚËùÓÐËðʧÒѱ»×·»Ø¡£¡£¡£¡£¡£Æ¾Ö¤¸ÃÑ§ÇøÓªÒµÓëÔËÓª¸±×ܼàClaire HertzµÄÐÎò£¬£¬ £¬£¬£¬£¬£¬µ±Ñ§Ð£ÔÚÐÇÆÚÎå·¢Ã÷Õâ±ÊڲƭÉúÒâʱ£¬£¬ £¬£¬£¬£¬£¬Á¬Ã¦×ñÕÕ»¥ÁªÍø·¸·¨³ÌÐò֪ͨÁËFBIºÍ½ÌÓýίԱ»á£¬£¬ £¬£¬£¬£¬£¬²¢×îÏÈÊÓ²ìÉúÒâµÄ·½·¨¼°Ôµ¹ÊÔ­ÓÉ¡£¡£¡£¡£¡£ÒøÐкÍFBIÔÚÕâ±Ê×ʽðÍÑÀëڲƭÕßµÄÕË»§Ö®Ç°¶³½áÁË×ʽ𡣡£¡£¡£¡£¸ÃѧУÕýÔÚÉó²éËùÓеÄÖ§¸¶³ÌÐòºÍÄÚ²¿¿ØÖÆÁ÷³Ì£¬£¬ £¬£¬£¬£¬£¬²¢¶Ô²ÆÎñÖ°Ô±¾ÙÐÐÇå¾²Åàѵ¡£¡£¡£¡£¡£


   Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/portland-public-schools-recovers-29-million-lost-in-bec-scam/


2.¹¥»÷µÂÖݵط½Õþ¸®µÄºÚ¿ÍÀÕË÷250ÍòÃÀÔªÊê½ð


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÉÏÖܵ¿ËÈøË¹Öݶà¸öµØ·½Õþ¸®Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬£¬£¬£¬£¬Æ¾Ö¤ÐÅÏ¢×ÊÔ´²¿£¨DIR£©Åû¶µÄÐÂϸ½Ú£¬£¬ £¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄµØ·½Õþ¸®ÊýĿΪ22¸ö£¬£¬ £¬£¬£¬£¬£¬²¢ÇÒÓÐÖ¤¾ÝÅú×¢¹¥»÷ÕßÊÇͨ¹ýÖÎÀíЧÀÍÌṩÉÌ£¨MSP£©À´ÊµÑé¹¥»÷µÄ¡£¡£¡£¡£¡£¸Ã²¿·Ö²¢Î´Åû¶Êܹ¥»÷µÄÊÐÕòÃû³Æ£¬£¬ £¬£¬£¬£¬£¬µ«ÓÐÁ½¸öÊÐÈ·ÈÏÔâµ½Á˹¥»÷£¬£¬ £¬£¬£¬£¬£¬Ò»¸öÊDz©¸ñÊУ¬£¬ £¬£¬£¬£¬£¬ÁíÒ»¸öÊÇKeeneÊС£¡£¡£¡£¡£KeenÊг¤Gary HeinrichÌåÏÖ¹¥»÷ÕßÀÕË÷250ÍòÃÀÔªµÄÊê½ðÀ´»»È¡½âÃÜÃÜÔ¿¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-want-25-million-ransom-for-texas-ransomware-attacks/


3.npm´æ´¢¿âɾ³ý¿ÉÇÔÈ¡µÇ¼ÃÜÂëµÄ¶ñÒâÈí¼þ°ü


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÔÚ½Óµ½ReversingLabsÑо¿Ô±Tomislav PericinµÄ±¨¸æºó£¬£¬ £¬£¬£¬£¬£¬npm´ÓÆä´æ´¢¿âÖÐɾ³ýÁ˶ñÒâÈí¼þ°übb-builder¡£¡£¡£¡£¡£¸ÃÈí¼þ°üÔÚWindows²Ù×÷ϵͳÉϰ²ÅÅÁËÒ»¸ö¿ÉÖ´ÐÐÎļþ£¬£¬ £¬£¬£¬£¬£¬½«Ãô¸ÐÐÅÏ¢·¢Ë͵½Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£npm½¨ÒéµÀ£º¡°´æ´¢ÔÚ¸ÃÅÌËã»úÉϵÄËùÓÐÉñÃØºÍÃÜÔ¿Ó¦Á¬Ã¦×ªÒÆÖÁÆäËüÅÌËã»ú¡±¡£¡£¡£¡£¡£Pericin³Æbb-builderÒѾ­±»Ìí¼Óµ½npm³¤´ïÒ»ÄêµÄʱ¼ä£¬£¬ £¬£¬£¬£¬£¬ËüµÄÿ´Î¸üж¼Ìí¼ÓÁËÐµĹ¦Ð§£¬£¬ £¬£¬£¬£¬£¬ÀýÈ罫ƾ֤Ìá½»¸ø×÷ÕßµÄWebЧÀÍÆ÷¡¢¸ü¸Ä±»µÁÊý¾ÝµÄ´æ´¢Î»Öá¢ÐÞ¸´¹ýʧÒÔ¼°ÔÚÊý¾Ý·¢Ë͵½Ô¶³ÌÅÌËã»úºóɾ³ýËü¡£¡£¡£¡£¡£bb-builderµÄÿÖÜÏÂÔØÁ¿ºÜÉÙ£¬£¬ £¬£¬£¬£¬£¬×î»îÔ¾µÄʱÆÚÊÇ6ÔÂ19ÈÕÖÁ25ÈÕ£¬£¬ £¬£¬£¬£¬£¬ÆäʱµÄÏÂÔØÁ¿´ï×î¸ßµã78´Î¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/npm-pulls-malicious-package-that-stole-login-passwords/


4.Áè¼Ý4.3Íǫ̀δÐÞ²¹SquidЧÀÍÆ÷Ò×Êܹ¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Squid 4.0.23µ½4.7±£´æÒ»¸ö¶Ñ»º³åÇøÒç³öÎó²î£¬£¬ £¬£¬£¬£¬£¬¸ÃÎó²î¿Éµ¼Ö´úÂëÖ´Ðк;ܾøÐ§À͹¥»÷¡£¡£¡£¡£¡£¸ÃÎó²î±»±êʶΪCVE-2019-12527£¬£¬ £¬£¬£¬£¬£¬ÆäCVSSµÃ·ÖΪ8.8·Ö¡£¡£¡£¡£¡£Squid¿ª·¢ÍŶÓÔÚ7ÔÂ9ÈÕÐû²¼Ð°汾4.8ÐÞ¸´Á˸ÃÎó²î£¬£¬ £¬£¬£¬£¬£¬Ö»¹Ü¸ÃÎó²îÒÑÔÚ7Ô·ݱ»ÐÞ¸´£¬£¬ £¬£¬£¬£¬£¬µ«ShodanÉÏÈÔ¿É·¢Ã÷31576¸öÔËÐа汾4.7µÄSquidЧÀÍÆ÷£¬£¬ £¬£¬£¬£¬£¬×ܹ²ÓÐÁè¼Ý4.3Íǫ̀δÐÞ²¹µÄЧÀÍÆ÷Ò×Êܹ¥»÷¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/unpatched-squid-servers-exposed-to-dos-code-execution-attacks/


5.BitdefenderÐÞ¸´ÆäÃâ·Ñɱ¶¾Èí¼þÖеÄÌáȨÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


BitdefenderÐÞ¸´ÁËÃâ·Ñɱ¶¾Èí¼þ2020ÖеÄÌáȨÎó²î¡£¡£¡£¡£¡£¸ÃÎó²î±»±êʶΪCVE-2019-15295£¬£¬ £¬£¬£¬£¬£¬ÒòÓÉÊÇ´ÓÊÜÐÅÈÎλÖüÓÔØDLLʱȱ·¦ÑéÖ¤¡£¡£¡£¡£¡£SafeBreach LabsµÄPeleg HadarÌåÏÖ£¬£¬ £¬£¬£¬£¬£¬BitdefenderµÄÇ徲ЧÀÍ£¨vsserv.exe£©ºÍ¸üÐÂЧÀÍ£¨updatesrv.exe£©ÊÇÒÔ¾ßÓÐSYSTEMȨÏÞµÄÒÑÊðÃûÀú³ÌÆô¶¯µÄ£¬£¬ £¬£¬£¬£¬£¬ËüÃÇÊÔͼ´ÓPATHÇéÐαäÁ¿ÖмÓÔØDLLÎļþ£¨'RestartWatchDog.dll'£©¡£¡£¡£¡£¡£ÆäÖÐÒ»¸öλÖÃÊÇc:/python27£¬£¬ £¬£¬£¬£¬£¬Òò´Ë¹¥»÷Õß¿Éͨ¹ý×Ô¼ºµÄDLLʹÓÃBitdefenderµÄÊðÃûÀú³Ì¾ÙÐÐÌáȨ¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/bitdefender-fixes-privilege-escalation-bug-in-free-antivirus-2020/


6.PokerTracker¹ÙÍø±»Ö²ÈëÐÅÓÿ¨ÐÅÏ¢ÇÔÈ¡¾ç±¾


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Poker Tracker¹ÙÍøÔâµ½ÈëÇÖ²¢±»Ö²ÈëÁËMagecart¾ç±¾£¬£¬ £¬£¬£¬£¬£¬¸Ã¾ç±¾×¨ÓÃÓÚÇÔÈ¡¿Í»§µÄÖ§¸¶ÐÅÏ¢¡£¡£¡£¡£¡£MalwarebytesÓÚ8ÔÂ8ÈÕ¼ì²âµ½ÁËÕâÒ»¹¥»÷»î¶¯£¬£¬ £¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÊÓ²ìºó·¢Ã÷¶ñÒâ¾ç±¾ÊÇ´Óajaxclick[.]com»ñÈ¡µÄ£¬£¬ £¬£¬£¬£¬£¬±ðµÄ£¬£¬ £¬£¬£¬£¬£¬PokerTracker×ÓÓòÃûpt4.pokertracker.comÒ²±»Ñ¬È¾¡£¡£¡£¡£¡£Ñ¬È¾µÄÔµ¹ÊÔ­ÓÉ»òÐíÊÇPokerTracker.comʹÓÃÁ˹ýʱµÄÈí¼þ°æ±¾£ºDrupal 6.3.x£¬£¬ £¬£¬£¬£¬£¬×îа汾Ϊ8.6.17¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/pokertrackercom-hacked-to-inject-payment-card-stealing-script/