ÈýÐǺÍLGÖÇÄÜ×°±¸½«Óû§Ãô¸ÐÊý¾Ý·¢Ë͵½ÏàÖú¹«Ë¾£»£» £»£»£»£»£»¿ªÔ´ÔÆ×¢²áÈí¼þHarbor±£´æí§ÒâÖÎÀíÔ±×¢²áÎó²î

Ðû²¼Ê±¼ä 2019-09-20

1.ÈýÐǺÍLGÖÇÄÜ×°±¸½«Óû§Ãô¸ÐÊý¾Ý·¢Ë͵½ÏàÖú¹«Ë¾


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ñо¿Ö°Ô±·¢Ã÷×ÝÈ»ÊÇÔÚ×°±¸ÏÐÖÃʱ£¬£¬£¬ £¬£¬ÈýÐÇ¡¢LGºÍRokuµÈ¹«Ë¾µÄÖÇÄܵçÊÓÒ²»áÏòÏàÖúµÄ¿Æ¼¼¹«Ë¾·¢ËÍÃô¸ÐµÄÓû§Êý¾Ý¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Á½¸öÍŶӵÄ×ÔÁ¦Ñо¿£¬£¬£¬ £¬£¬ÖÇÄܵçÊÓµÄOTTƽ̨»á½«Óû§µÄÃô¸ÐÊý¾Ýй¶¸øFacebook¡¢ÑÇÂíÑ·¡¢¹È¸èºÍNetflixµÈ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£µÚÒ»·Ý±¨¸æÑо¿ÁË81̨װ±¸£¬£¬£¬ £¬£¬·¢Ã÷ÓÐ72̨װ±¸½«Êý¾Ý·¢Ë͵½·ÇÖÆÔìÉÌµÄÆäËü¹«Ë¾¡£¡£¡£¡£¡£¡£¡£µÚ¶þ·Ý±¨¸æ·¢Ã÷´ÓÖÇÄܵçÊÓ·¢Ë͵ÄÊý¾ÝÒ²Óë¹È¸èºÍFacebookÖÎÀíµÄ¸ú×ÙÆ÷Óйأ¬£¬£¬ £¬£¬Ñо¿Ö°Ô±³Æ89%µÄAmazon Fire TVƵµÀºÍ69%µÄRokuƵµÀ¶¼°üÀ¨ÓÃÓÚ¸ú×ÙÓû§ÊÕ¿´Ï°¹ßºÍÆ«ºÃÐÅÏ¢µÄ¸ú×ÙÆ÷¡£¡£¡£¡£¡£¡£¡£ÕâЩ¸ú×ÙÆ÷»¹¿ÉÒÔʶ±ð×°±¸ºÍʹÓÃλÖ㬣¬£¬ £¬£¬°üÀ¨×°±¸ÐòÁкźÍID¡¢Wi-FiÃû³ÆºÍMACµØµãµÈ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/smart-tvs-leak-data/148482/


2.Windows Defender²¡¶¾É¨Ã蹦ЧÔÚиüкóËð»µ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


΢ÈíÐû²¼µÄWindows¸üÐÂKB4052623£¨°æ±¾4.18.1908.7£©Ê¹µÃWindows DefenderµÄ²¡¶¾É¨Ã蹦ЧÎÞ·¨Õý³£ÔËÐС£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Óû§µÄÐÎò£¬£¬£¬ £¬£¬µ±Óû§ÊµÑéÔËÐпìËÙɨÃè»òÍêȫɨÃèʱ£¬£¬£¬ £¬£¬Windows Defender½«Ö»É¨ÃèԼĪ40¸öÎļþÈ»ºó×èֹɨÃ裬£¬£¬ £¬£¬µ«×Ô½ç˵ɨÃ蹦ЧÔË×÷Õý³£¡£¡£¡£¡£¡£¡£¡£Î¢Èí¶Ô´Ë»ØÓ¦³ÆDefenderµÄÖÕ¶ËʵʱɨÃ蹦Ч²»ÊÜÓ°Ï죬£¬£¬ £¬£¬Ö»ÓÐÖÎÀíÔ±ÌᳫµÄÊÖ¶¯É¨Ãè»òÍýÏëɨÃè»áÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£Î¢ÈíÒѾ­Ðû²¼ÁËв¹¶¡KB2267602£¨°æ±¾1.301.1684.0£©½â¾ö´ËÎÊÌâ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/windows-defender-antivirus-scans-broken-after-new-update/


3.¿ªÔ´ÔÆ×¢²áÈí¼þHarbor±£´æí§ÒâÖÎÀíÔ±×¢²áÎó²î


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Palo Alto NetworksµÄUnit 42Ñо¿ÍŶӷ¢Ã÷¿ªÔ´ÔÆ×¢²áÈí¼þHarbor±£´æí§ÒâÖÎÀíÔ±×¢²áÎó²î¡£¡£¡£¡£¡£¡£¡£Harbor±»ÓÃÓÚ´æ´¢¡¢ÊðÃûºÍɨÃèÈÝÆ÷¾µÏñµÈ£¬£¬£¬ £¬£¬¸ÃÈí¼þÓëDocker Hub¡¢Docker RegistryºÍGoogle Container RegistryµÈ¼æÈÝ£¬£¬£¬ £¬£¬ÆäÓû§ºÍÏàÖúͬ°é°üÀ¨Ç÷ÊÆ¿Æ¼¼¡¢Pivotal¡¢DataYesºÍOnStarµÈ¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-16097£©ÊÇÒ»¸öÌáȨÎó²î£¬£¬£¬ £¬£¬ÔÊÐí·ÇÖÎÀíÔ±Óû§Í¨¹ýÏò/api/users API·¢ËͶñÒâPOSTÇëÇóÀ´½¨Éèí§ÒâÐÂÖÎÀíÔ±ÕË»§¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁ˹̼þ°æ±¾1.7.0-1.8.2£¬£¬£¬ £¬£¬Ñо¿Ö°Ô±É¨Ã軥ÁªÍø·¢Ã÷ÓÐ1300¸öHarbor¿É¹ûÕæ»á¼û£¬£¬£¬ £¬£¬ÕâÒâζ×ÅËüÃǶ¼Ò×Êܹ¥»÷¡£¡£¡£¡£¡£¡£¡£HarborÔÚй̼þ°æ±¾1.7.6ºÍ1.8.3ÖÐÐÞ¸´Á˸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/patch-now-1300-harbor-cloud-registries-open-to-attack/


4.MagecartºÚ¿ÍÈëÇÖÁ½¼ÒÂùݹÙÍø¹¥»÷ÒÆ¶¯Óû§


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ç÷ÊÆ¿Æ¼¼·¢Ã÷MagecartºÚ¿Íͨ¹ýÈëÇÖÁ½¼ÒÁ¬ËøÂùݵÄÍøÕ¾À´Õë¶ÔAndroidºÍiOSÓû§¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñ±¬·¢ÔÚ8ÔÂ9ÈÕ£¬£¬£¬ £¬£¬¹¥»÷ÕßÔÚÄ¿µÄÍøÕ¾µÄ¸¶¿îÒ³ÃæÉÏÖ²ÈëÁËJavaScript´úÂ룬£¬£¬ £¬£¬µ±Í¨¹ý̨ʽʱ»ú¼ûʱ½«Ö»»áÏÂÔØÍ¨Ë×µÄJavaScript´úÂ룬£¬£¬ £¬£¬¶øÍ¨¹ýÒÆ¶¯×°±¸»á¼ûʱÔò»áÏÂÔØÐÅÓÿ¨ÐÅÏ¢ÇÔÈ¡¾ç±¾¡£¡£¡£¡£¡£¡£¡£Ç÷ÊÆ¿Æ¼¼ÌåÏÖÕâ¿ÉÄÜÊÇΪÁËÌÓ±ÜPCÇå¾²Èí¼þµÄ¼ì²â¡£¡£¡£¡£¡£¡£¡£ËäȻֻÓÐÁ½¸öÁ¬ËøÂùÝÊܵ½¹¥»÷£¬£¬£¬ £¬£¬µ«Ç±ÔÚÊܺ¦ÕßµÄÊýÄ¿ºÜ¸ß£¬£¬£¬ £¬£¬ÓÉÓÚÆäÖÐÒ»¸öÆ·ÅÆÔÚ14¸ö¹ú¼ÒÓµÓÐ107¼ÒÂùݣ¬£¬£¬ £¬£¬ÁíÒ»¸öÔòÔÚ14¸ö¹ú¼ÒÓµÓÐ73¼ÒÂùÝ¡£¡£¡£¡£¡£¡£¡£¸Ã¾ç±¾ÇÔÈ¡µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢·¿¼äÆ«ºÃºÍÐÅÓÿ¨ÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÉõÖÁ½¨ÉèÁ˶àÖÖÓïÑÔµÄÐÅÓÿ¨±í¸ñ£¬£¬£¬ £¬£¬°üÀ¨Ó¢Óï¡¢Î÷°àÑÀÓï¡¢Òâ´óÀûÓï¡¢·¨Óï¡¢µÂÓï¡¢ÆÏÌÑÑÀÓï¡¢¶íÓïºÍºÉÀ¼Óï¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/magecart-hackers-target-mobile-users-hotel-websites


5.½©Ê¬ÍøÂçAmadeyʹÓÃÐéαÍË˰ÓʼþÃé×¼ÃÀ¹ú


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


CofenseÇå¾²Ñо¿Ö°Ô±·¢Ã÷Ò»¸öеÄÍøÂç´¹Âڻαװ³ÉÍË˰ÓʼþÏòÃÀ¹ú¹«Ãñ·Ö·¢½©Ê¬ÍøÂçAmadey¡£¡£¡£¡£¡£¡£¡£AmadeyÊÇÒ»¸öÏà¶Ô½ÏеĽ©Ê¬ÍøÂ磬£¬£¬ £¬£¬µ«ÒÑÓжà¸ö·¸·¨ÍÅ»ïʹÓÃËüÀ´Èö²¥µÚ¶þ½×¶Îpayload£¬£¬£¬ £¬£¬ÆäÖÐÒ»¸öÊÇÎÛÃûÕÑÖøµÄTA505¡£¡£¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂçÖ®Ç°ÔøÍ¨¹ýRIG EK¾ÙÐÐÈö²¥¡£¡£¡£¡£¡£¡£¡£¸Ã´¹ÂÚÓʼþÖÐÁ´½Óµ½µÄ¶ñÒâÍøÕ¾ÓòÃûÊÇhxxp://yosemitemanagement[.]com/fonts/page5/£¬£¬£¬ £¬£¬ËüÒªÇóÓû§ÏÂÔØ²¢Ìîдһ¸öÎĵµÀ´»ñµÃÍË˰£¬£¬£¬ £¬£¬µ«ÏÖʵÉϸÃÎĵµ°üÀ¨¶ñÒâVisual Basic¾ç±¾¡£¡£¡£¡£¡£¡£¡£CofenseÔÚ±¨¸æÖÐÅû¶Á˴˴ι¥»÷»î¶¯µÄÏêϸIoC¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/amadey-botnet-targets-us-taxpayers-with-tax-refund-notice/


6.ºÚ¿ÍÈëÇÖCLICK2GOVÍøÕ¾²¢ÊÛÂô2ÍòÕÅÐÅÓÿ¨ÐÅÏ¢


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Gemini AdvisoryÔÚÒ»·ÝеÄÑо¿±¨¸æÖÐÖÒÑԳƣ¬£¬£¬ £¬£¬´Ó2019Äê8ÔÂ×îÏÈÀ´×Ô5¸öÖÝ8¸ö¶¼»áµÄÁè¼Ý2ÍòÌõÐÅÓÿ¨¼Í¼ÔÚ°µÍøÊг¡ÉÏÏúÊÛ¡£¡£¡£¡£¡£¡£¡£ÕâЩÊý¾ÝȪԴÓÚÃÀ¹úÕþ¸®µÄÕ˵¥Ö§¸¶Ð§ÀÍClick2Gov£¬£¬£¬ £¬£¬¸ÃЧÀÍÔøÔÚ2017ºÍ2018ÄêÔâºÚ¿Í¹¥»÷£¬£¬£¬ £¬£¬µ¼Ö½ü30ÍòÕÅÃÀ¹ú¹«ÃñµÄÐÅÓÿ¨ÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£ÔÚ×îÐÂÒ»´ÎÊܵ½¹¥»÷µÄ8¸ö¶¼»áÖУ¬£¬£¬ £¬£¬ÓÐ6¸ö¶¼»áÔøÔÚÉÏÒ»´Î¹¥»÷ÖÐÊܵ½Ë𺦡£¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎúÕâÒ»´ÎºÚ¿ÍÊÇÔõÑùÈëÇÖÕâЩ¶¼»áµÄClick2GovÃÅ»§ÍøÕ¾µÄ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/two-years-later-hackers-are-still-breaching-local-government-payment-portals/