GitHubÐÞ¸´9¸öGitÎó²î£¬£¬£¬±Þ²ßÓû§¾ÙÐиüУ»£»£»£»¿¨°Í˹»ùÐû²¼2019ÄêÍøÂçÍþвµÄͳ¼ÆÊý¾Ý±¨¸æ
Ðû²¼Ê±¼ä 2019-12-16
1.GitHubÐÞ¸´9¸öGitÎó²î£¬£¬£¬±Þ²ßÓû§¾ÙÐиüÐÂ
ÔÚÐÞ¸´GitÖеÄ9¸öÎó²îÖ®ºó£¬£¬£¬GitHub±Þ²ßÓû§Ö´ÐС°Òªº¦¡±µÄGitÏîÄ¿´úÂë¸üС£¡£¡£¡£¡£¡£ÕâЩÎó²îÊÇÓÉGitLabµÄJoern SchneeweiszºÍ΢ÈíÇå¾²ÏìÓ¦ÖÐÐÄ·¢Ã÷²¢±¨¸æµÄ£¬£¬£¬GitHubÖ¸³ö£º¡°ÈôÊǿˡ²»ÊÜÐÅÈεĴ洢¿â£¬£¬£¬³ýÁ˸üÐÂÖ®ÍâûÓÐÒªÁì¿ÉÒÔ×èÖ¹±¾ÎÄÖÐÅû¶µÄÈκÎÎó²î´øÀ´µÄΣº¦¡±¡£¡£¡£¡£¡£¡£ÕâЩÎÊÌâ½öÓ°ÏìÁËWindowsƽ̨£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓÃÎó²îÁýÕÖí§Òâ·¾¶¡¢Ô¶³ÌÖ´ÐдúÂëÒÔ¼°ÁýÕÖ.git/Ŀ¼ÏµÄÎļþµÈ¡£¡£¡£¡£¡£¡£Îó²îµÄ±àºÅΪCVE-2019-1348~CVE-2019-1354ºÍCVE-2019-1387£¬£¬£¬ÍêÕûÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cbronline.com/news/git-project-patches
2.NpmÍŶÓÕë¶Ôеġ°¶þ½øÖÆÖ²È롱Îó²î·¢³öÖÒÑÔ
NpmÍŶÓÐû²¼Çå¾²¾¯±¨£¬£¬£¬½¨ÒéËùÓÐÓû§¸üÐÂÖÁ×îа汾£¨6.13.4£©£¬£¬£¬ÒÔ±ÜÃâ¡°¶þ½øÖÆÖ²È롱¹¥»÷¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÎļþ±éÀúºÍí§ÒâÎļþÁýÕÖÎÊÌâµÄ×éºÏ£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ²Èë¶ñÒâ¶þ½øÖÆÎļþ»òÁýÕÖÓû§ÅÌËã»úÉϵÄÎļþ¡£¡£¡£¡£¡£¡£¸ÃÎó²î½öÔÚͨ¹ýnpmÏÂÁîÐпͻ§¶Ë£¨CLI£©×°ÖÃÊÜѬȾµÄÈí¼þ°üʱ´ú²Å»á´¥·¢¡£¡£¡£¡£¡£¡£Npm¿ª·¢Ö°Ô±ÌåÏÖËûÃÇÒ»Ö±ÔÚnpmÃÅ»§ÖÐɨÃè¿ÉÄܰüÀ¨´ËÎó²îʹÓõÄÈí¼þ°ü£¬£¬£¬µ«Î´·¢Ã÷ÈκοÉÒɰ¸Àý¡£¡£¡£¡£¡£¡£³ýÁËnpmÖ®Í⣬£¬£¬ÁíÒ»¸öJavaScript°ü¹ÜÀíÆ÷yarnÒ²Êܵ½Ó°Ï죬£¬£¬yarnÍŶÓÔÚа汾1.21.1ÖÐÐÞ¸´Á˸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/npm-team-warns-of-new-binary-planting-bug/
3.ÂÞÂíÄáÑÇ·¸·¨ÍÅ»ïʹÓÃÍÚ¿óÈí¼þѬȾ40¶àÍòÓû§
ƾ֤¶íº¥¶íÖݱ±ÇøÃÀ¹úÉó²é¹Ù°ì¹«ÊÒµÄÐÂΟ壬£¬£¬ÂÞÂíÄáÑǵÄÒ»¸öÍøÂç·¸·¨ÍÅ»ïͨ¹ý¶ñÒâÍÚ¿óÈí¼þѬȾÁËÁè¼Ý40Íǫ̀ÅÌËã»ú¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïµÄÃû³ÆÎªBayrob Group£¬£¬£¬ËüÒÑÔÚ°µÍøÉϳöÊÛ±»µÁµÄÓû§ÐÅÏ¢¡£¡£¡£¡£¡£¡£Æ¾Ö¤ÈÏÕæ´Ë°¸µÄFBIÌØ¹¤Eric SmithµÄ˵·¨£¬£¬£¬¸ÃÍÅ»ï×Ô2007Äê×îÏȻ£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¹«ÃñµÄÅÌËã»ú¾ÙÐÐÍڿ󣬣¬£¬²¢ÇÒÇÔÈ¡²ÆÎñÐÅÏ¢¡¢ÃÜÂë¡¢µç×ÓÓʼþµÈСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£Æä¶ñÒâÈí¼þÖ÷Ҫͨ¹ýαװ³ÉÒøÐкÍÇå¾²³§É̵ĵç×ÓÓʼþÈö²¥¡£¡£¡£¡£¡£¡£¾Ý³Æ¸ÃÍÅ»ïÒѾ׬ǮÁè¼Ý400ÍòÃÀÔª£¬£¬£¬µ«ÏÖÔÚ²¢²»ÇåÎúÆäÖÐÓм¸¶àÀ´×ÔÍÚ¿ó¹¥»÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://finance.yahoo.com/news/romanian-cybergang-infects-over-400-100025512.html
4.ÐÂÔóÎ÷ÖÝHackensackÒ½ÔºÔâµ½ÀÕË÷Èí¼þ¹¥»÷
ÐÂÔóÎ÷ÖÝ×î´óµÄÒ½ÔºHackensack Meridian Health³ÉΪÀÕË÷Èí¼þ¹¥»÷µÄÊܺ¦Õߣ¬£¬£¬ÆäÄÚ²¿ÍøÂçÔâÀÕË÷Èí¼þÆÆË𣬣¬£¬¸ÃÒ½Ôº¾öÒéÖ§¸¶Êê½ðÒÔ½âÃÜÎļþ¡£¡£¡£¡£¡£¡£¸ÃҽԺûÓÐ͸¶¹¥»÷ÕßʹÓõÄÀÕË÷Èí¼þÀàÐÍ£¬£¬£¬Ò²Ã»ÓÐ͸¶¹¥»÷ÕßÈëÇֵķ½·¨ºÍÒÑÖ§¸¶µÄÊê½ð½ð¶î£¬£¬£¬µ«ÌåÏÖ¹¥»÷±¬·¢ÔÚ12ÔÂ2ÈÕ£¬£¬£¬ÆÈʹÆä×÷·ÏÁËһЩÍâ¿ÆÊÖÊõºÍÆäËü³ÌÐò¡£¡£¡£¡£¡£¡£ÏÖÔÚÆäÍøÂçµÄÖ÷ÒªÁÙ´²ÏµÍ³Òѻָ´ÔËÐУ¬£¬£¬²¢ÇÒITר¼ÒÕýÔÚÆð¾¢Ê¹ÆäËùÓеÄÓ¦ÓóÌÐò»Ö¸´ÔÚÏß¡£¡£¡£¡£¡£¡£¸ÃÒ½Ôº»¹ÌåÏÖ£¬£¬£¬Ã»Óм£ÏóÅú×¢¹¥»÷Õß»á¼ûÁË»¼ÕßµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/95152/cyber-crime/new-jersey-hospital-ransomware-attack.html
5.ÒÁÀÊÐû³Æ×î½üÁ½´Î´ì°ÜÕë¶ÔÆä»ù´¡ÉèÊ©µÄÍøÂç¹¥»÷
ÒÁÀʵçÐŲ¿³¤Äº±Ä¬µÂ¡¤¼ÖÍߵ¡¤°¢ÔúÀ¼Ö»ôÃ×(Mohammad Javad Azari Jahromi)ÌåÏÖÒÁÀÊÔÚÒ»ÖÜÄÚµÚ¶þ´Î´ì°ÜÕë¶ÔÆä»ù´¡ÉèÊ©µÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¸ÃÐÂÎÅÊÇÓÉISNAºÍMehrÐÂÎÅÉ籨µÀµÄ£¬£¬£¬¼Ö»ôÃ×½«Õâ´Î¹¥»÷½ç˵Ϊ´ó¹æÄ£¹¥»÷£¬£¬£¬²¢½«Æä¹éÓÉÓÚAPT27¡£¡£¡£¡£¡£¡£APT27×Ô2010ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹úµÄ¹ú·À³Ð°üÉÌ¡¢½ðÈÚЧÀ͹«Ë¾ºÍÖÐÑǹú¼ÒÊý¾ÝÖÐÐĵȡ£¡£¡£¡£¡£¡£¼Ö»ôÃ×ûÓÐ͸¶¹¥»÷µÄϸ½ÚÒÔ¼°¹¥»÷ÕßÕë¶ÔµÄÏêϸĿµÄ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/95169/apt/iran-foiled-2-attack.html
6.¿¨°Í˹»ùÐû²¼2019ÄêÍøÂçÍþвµÄͳ¼ÆÊý¾Ý±¨¸æ
¿¨°Í˹»ùÐû²¼2019ÄêÍøÂçÍþвͳ¼ÆÊý¾Ý±¨¸æ£¬£¬£¬¸Ã±¨¸æÊÇ»ùÓÚ2018Äê11Ôµ½2019Äê10ÔÂʱ´ú´ÓÈ«Çò203¸ö¹ú¼ÒºÍµØÇøµÄKSNÓû§ÍøÂçµÄ¶ñÒâ»î¶¯Êý¾Ý¡£¡£¡£¡£¡£¡£ÔÚ±¨¸æÊ±´ú£¬£¬£¬ÓÐ19.8%µÄÓû§ÅÌËã»úÖÁÉÙÔâÊÜÒ»´Î¶ñÒâÈí¼þÀà±ðµÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿¨°Í˹»ùÇå¾²½â¾ö¼Æ»®×èÖ¹ÁËÀ´×ÔÈ«ÇòÔÚÏß×ÊÔ´µÄ9.7Òڴι¥»÷¡£¡£¡£¡£¡£¡£Web·´²¡¶¾×é¼þʶ±ð³ö2.7ÒÚ¸ö²î±ðµÄ¶ñÒâURL¡£¡£¡£¡£¡£¡£ÍøÂç·À²¡¶¾Èí¼þ¼ì²âµ½2461Íò¸ö²î±ðµÄ¶ñÒâÑù±¾¡£¡£¡£¡£¡£¡£75.5Íò¸öÓû§ÅÌËã»úÔâµ½ÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£226ÍòÓû§ÅÌËã»úÔâµ½¶ñÒâÍÚ¿ó¹¥»÷¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿¨°Í˹»ùÇå¾²½â¾ö¼Æ»®ÔÚ76.6Íǫ̀װ±¸ÉÏ×èÖ¹ÁËÕë¶ÔÔÚÏßÒøÐÐÕË»§µÄ¶ñÒâÈí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/kaspersky-security-bulletin-2019-statistics/95475/