Ñо¿Ö°Ô±Åû¶±£´æ4ÄêµÄLinux Wi-Fi»º³åÇøÒç³öÎó²î£»£»£»£»£»£»CenturyLinkÒâÍâ̻¶280ÍòÌõ¿Í»§¼Í¼

Ðû²¼Ê±¼ä 2019-10-21
1¡¢Ñо¿Ö°Ô±Åû¶±£´æ4ÄêµÄLinux Wi-Fi»º³åÇøÒç³öÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

GithubÊ×ϯÇå¾²¹¤³ÌʦNico Waisman·¢Ã÷Linux rtlwifiÇý¶¯³ÌÐòÖб£´æÒ»¸ö¾ßÓÐ4ÄêÀúÊ·µÄÑÏÖØÎó²î£¨CVE-2019-17666£©£¬£¬ £¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÈëÇÖÒ×Êܹ¥»÷µÄϵͳ¡£¡£¡£¡£¡£¡£rtlwifiÇý¶¯³ÌÐòÓÃÓÚÔÊÐíRealtek Wi-FiÄ£¿£¿£¿£¿£¿£¿éÓëLinuxϵͳ¾ÙÐÐͨѶ£¬£¬ £¬¹¥»÷Õß¿ÉÄÜʹÓó¤¶È²»×¼È·µÄÊý¾Ý°ü´¥·¢»º³åÇøÒç³ö£¬£¬ £¬Ê¹µÃLinux±ÀÀ£»£»£»£»£»£»òÊÇÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¾Ý³Æ¸ÃÎó²îÓ°ÏìÁËLinux°æ±¾5.3.6£¬£¬ £¬¸ÃÎÊÌâ×Ô´Ó2015ÄêÒÔÀ´¾ÍÒ»Ö±±£´æ¡£¡£¡£¡£¡£¡£LinuxÄÚºËÍŶÓÒѾ­¿ª·¢ÁËÒ»¸öÕýÔÚÐÞ¶©µÄÐÞ¸´²¹¶¡£¬£¬ £¬µ«¸Ã²¹¶¡ÉÐδ°üÀ¨ÔÚLinuxÄÚºËÖС£¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/critical-linux-wi-fi-bug-system-compromise/149325/

2¡¢ºÚ¿Íͨ¹ýÐéα²å¼þupdrat123ÈëÇÖWordPressÍøÕ¾

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


SucuriÑо¿Ö°Ô±·¢Ã÷ºÚ¿ÍʹÓÃÐéαµÄWordPress²å¼þÀ´³äµ±ºóÃųÌÐò£¬£¬ £¬ÏòÄ¿µÄÍøÕ¾ÉÏ´«Web Shell¼°±©Á¦ÆÆ½â¾ç±¾¡£¡£¡£¡£¡£¡£¸Ã²å¼þ±»ÃüÃûΪInitiatorseo»òupdrat123£¬£¬ £¬Æä¿Ë¡ÁËÕýµ±²å¼þUpdraftPlusµÄ¹¦Ð§¡£¡£¡£¡£¡£¡£¸ÃÐéα²å¼þĬÈϲ»»áÏÔʾ£¬£¬ £¬µ«¹¥»÷Õß¿Éͨ¹ý´øÓÐ×Ô½ç˵²ÎÊý£¨ÀýÈçinitiationactivity»òtestingkey£©µÄGETÇëÇó»á¼û¸Ã²å¼þ¡£¡£¡£¡£¡£¡£Ê¹ÓøúóÃÅ£¬£¬ £¬¹¥»÷Õß¿Éͨ¹ýPOSTÇëÇóÏòÄ¿µÄЧÀÍÆ÷ÉÏ´«í§Òâ¶ñÒâÎļþ£¬£¬ £¬°üÀ¨Web Shell¼°±©Á¦ÆÆ½â¾ç±¾µÈ¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬ÊÜѬȾµÄÍøÕ¾»¹¿ÉÄܻᱻÓÃÓÚDDoS¡¢À¬»øÓʼþ·¢Ë͵ȶñÒâ»î¶¯¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-backdoor-sites-by-hiding-fake-wordpress-plugins/

3¡¢Spelevo EKÔÚй¥»÷»î¶¯Öзַ¢ÀÕË÷Èí¼þMaze

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

nao_sec·¢Ã÷Îó²îʹÓù¤¾ß°üSpelevoÔÚÒ»¸öеĶñÒâ»î¶¯ÖÐʹÓÃÀÕË÷Èí¼þMazeѬȾÊܺ¦Õß¡£¡£¡£¡£¡£¡£MazeÊÇÀÕË÷Èí¼þChachaµÄ±äÖÖ£¬£¬ £¬Æä×î³õÓÚ5Ô·ݱ»MalwarebytesÇå¾²Ñо¿Ô±J¨¦r?me Segura·¢Ã÷¡£¡£¡£¡£¡£¡£ÔÚÐµĹ¥»÷»î¶¯ÖУ¬£¬ £¬Spelevo EKʵÑéʹÓÃFlash PlayerÎó²î£¨CVE-2018-15982£©ÔÚÊÜѬȾµÄϵͳÉÏ×°ÖÃMaze£¬£¬ £¬¸ÃÎó²îÓ°ÏìÁËFlash Player°æ±¾31.0.0.153/31.0.0.108¼°¸üÔç°æ±¾¡£¡£¡£¡£¡£¡£Maze»áɨÃèÓû§µÄÎĵµ¡¢ÕÕÆ¬¡¢Êý¾Ý¿âµÈÎļþ²¢Ê¹ÓÃRSAËã·¨ºÍChaCha20Á÷¼ÓÃÜÆ÷¾ÙÐмÓÃÜ¡£¡£¡£¡£¡£¡£ÏÖÔÚÉÐûÓÐMazeµÄÃ⺬»ìÃÜÆ÷Ðû²¼¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/maze-ransomware-now-delivered-by-spelevo-exploit-kit/

4¡¢Ñо¿ÍŶÓÐû²¼ÀÕË÷Èí¼þSTOP 148¸ö±äÖֵĽâÃܹ¤¾ß

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


EmsisoftºÍMichael GillespieÐû²¼ÀÕË÷Èí¼þSTOPµÄ½âÃÜÆ÷£¬£¬ £¬¿ÉÒÔ×ÊÖúÓû§½âÃÜ148¸ö±äÖÖ¼ÓÃܵÄÎļþ¡£¡£¡£¡£¡£¡£ÐèÒª×¢ÖØµÄÊÇ£¬£¬ £¬2019Äê8ÔÂÖ®ºó±»Ñ¬È¾µÄÓû§ÎÞ·¨±»½âÃÜ¡£¡£¡£¡£¡£¡£Ö»¹ÜÔÆÔÆ£¬£¬ £¬Ê¹ÓÃÀëÏßÃÜÔ¿¾ÙÐнâÃÜÒ²ÊÇÓпÉÄܵÄ£¬£¬ £¬Òò´ËÔÚÕâЩ±äÖÖÉÏÒ²¿ÉÄÜ»ñµÃһЩÀֳɡ£¡£¡£¡£¡£¡£STOPÊÇÄ¿½ñ»î¶¯×îÆÕ±éµÄÀÕË÷Èí¼þ£¬£¬ £¬¸ÃÀÕË÷Èí¼þͨ¹ý¹ã¸æÈí¼þÀ¦°ó°ü·Ö·¢£¬£¬ £¬ÕâЩÀ¦°óÈí¼þαװ³ÉµÁ°æÈí¼þ¡¢µÁ°æÓÎÏ·ÒÔ¼°Ãâ·ÑÈí¼þµÈÓÕʹÓû§ÏÂÔØ¡£¡£¡£¡£¡£¡£ËäÈ»ºÜÄÑÈ·¶¨Êܺ¦Õß¼òÖ±ÇÐÈËÊý£¬£¬ £¬µ«ID RansomwareÎüÊÕµ½ÁË11.6Íò¸öÓë¸ÃÀÕË÷Èí¼þÓйصÄʶ±ðÇëÇ󡣡£¡£¡£¡£¡£Ö»¹ÜÓÐЩÊܺ¦ÕßÀ´×ÔÃÀ¹ú£¬£¬ £¬µ«´ó´ó¶¼Êܺ¦ÕßÀ´×ÔÅ·ÖÞ¡¢ÑÇÖÞ¡¢ÄÏÃÀºÍ·ÇÖÞ£¬£¬ £¬¶íÂÞ˹µØÇøÎ´ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/stop-ransomware-decryptor-released-for-148-variants/

5¡¢ÃÀ¹úIngredion IncorporatedÔâÀÕË÷Èí¼þ¹¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹úÅäÁϹ©Ó¦ÉÌIngredion IncorporatedÐû²¼×î½ü¼ì²âµ½Óë¶ñÒâÈí¼þ¹¥»÷Ïà¹ØµÄ¿ÉÒɻ£¬£¬ £¬¸Ã¹«Ë¾ÒÑÔ¼ÇëµÚÈý·½×¨¼Ò×ÊÖúÆäÔ±¹¤ÊÓ²ìÊÂÎñ²¢»Ö¸´ÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔڸù«Ë¾Î´Åû¶Óйع¥»÷µÄÏêϸÐÅÏ¢£¬£¬ £¬²¢ÌåÏÖûÓÐÖ¤¾ÝÅú×¢ºÚ¿Í»á¼ûÁËÆä¿Í»§¡¢¹©Ó¦ÉÌ»òÔ±¹¤µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾»¹ÖÒÑԳƻָ´Ä³Ð©ÊÜÓ°ÏìµÄϵͳ½«ÆÆ·ÑһЩʱ¼ä£¬£¬ £¬²¢¿ÉÄÜÔÚÓë¿Í»§ºÍ¹©Ó¦É̵ÄÉúÒâÖзºÆðһЩÑÓÎ󡣡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/92673/hacking/ingredion-security-incident.html

6¡¢CenturyLinkÒâÍâ̻¶280ÍòÌõ¿Í»§¼Í¼

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ñо¿Ö°Ô±·¢Ã÷Ò»¸öÓµÓÐ280ÍòÌõ¼Í¼µÄCenturyLink¿Í»§ÐÅÏ¢Êý¾Ý¿âÔÚÍøÉÏ̻¶Á˳¤´ï10¸öÔµÄʱ¼ä¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÊÇÒ»¸öMongoDBЧÀÍÆ÷£¬£¬ £¬Êý¾Ý¿âÖеÄÐÅÏ¢°üÀ¨¿Í»§ÐÕÃû¡¢µØµã¡¢µç×ÓÓʼþµØµãºÍµç»°ºÅÂë¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÓëCenturyLinkʹÓõĵÚÈý·½Í¨ÖªÆ½Ì¨ÓйØ£¬£¬ £¬ÔÚÑо¿Ö°Ô±Í¨ÖªCenturyLinkÁ½Ììºó£¬£¬ £¬¸ÃÊý¾Ý¿âÒÑ»ñµÃ±£»£»£»£»£»£»¤¡£¡£¡£¡£¡£¡£CenturyLinkÔÚÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬£¬ £¬Ð¹Â¶µÄÊý¾ÝÖ÷ÒªÊǿͻ§µÄÁªÏµÐÅÏ¢£¬£¬ £¬Ã»ÓвÆÎñ»òÆäËüÃô¸ÐÐÅÏ¢Êܵ½Ë𺦡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/attacks-breaches/centurylink-customer-data-exposed-/d/d-id/1336123