¹¥»÷ÕßÀÄÓÃBitbucketЧÀÍ£¬£¬£¬£¬Òѵ¼ÖÂ50¶àÍòÖ÷»úѬȾ¶ñÒâÈí¼þ;·ÉÀûÆÖÖÇÄܵƵ¨»º³åÇøÒç³öÎó²î£¬£¬£¬£¬¿Éµ¼ÖºڿÍÈëÇÖ¼ÒÍ¥WiFi

Ðû²¼Ê±¼ä 2020-02-06

1.¹¥»÷ÕßÀÄÓÃBitbucketЧÀÍ£¬£¬£¬£¬Òѵ¼ÖÂ50¶àÍòÖ÷»úѬȾ¶ñÒâÈí¼þ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¹¥»÷ÕßÕýÔÚÀÄÓôúÂëÍйÜЧÀÍBitbucket´æ´¢7ÖÖ¶ñÒâÈí¼þpayload£¬£¬£¬£¬¸Ã¹¥»÷»î¶¯ÒÑÔÚÈ«Çò¹æÄ£ÄÚѬȾÁËÁè¼Ý50Íǫ̀ÉÌÓÃÅÌËã»ú¡£ ¡£¡£¡£¡£¡£Æ¾Ö¤Çå¾²³§ÉÌCybereasonÐû²¼µÄÒ»·Ý±¨¸æ£¬£¬£¬£¬¹¥»÷Õß°²Åŵ½Ä¿µÄϵͳµÄ¶ñÒâpayload°üÀ¨Predator¡¢Azorult¡¢Evasive Monero Miner¡¢ÀÕË÷Èí¼þSTOP¡¢Vidar¡¢Amadey botºÍIntelRapid¡£ ¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯Ö÷ÒªÕë¶ÔѰÕÒµÁ°æÉÌÒµÈí¼þ£¨ÀýÈçAdobe Photoshop¡¢Microsoft OfficeµÈ£©µÄÓû§¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/bitbucket-abused-to-infect-500-000-hosts-with-malware-cocktail/


2.¹È¸èÐû²¼2ÔÂAndroidÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´25¸öÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¹È¸èÐû²¼2020Äê2ÔµÄAndroidÇå¾²¸üУ¬£¬£¬£¬¹²ÐÞ¸´25¸öÎó²î£¬£¬£¬£¬ÆäÖаüÀ¨Á½¸öÑÏÖØ¼¶±ðµÄÎó²î¡£ ¡£¡£¡£¡£¡£ÕâÁ½¸öÎó²î¶¼Î»ÓÚAndroidµÄϵͳ×é¼þÖУ¬£¬£¬£¬µÚÒ»¸öÎó²îÊÇÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-0022£©£¬£¬£¬£¬¸ÃÎó²î½öÔÚAndroid 8.0¡¢8.1ºÍ9Éϲű»ÒÔΪÊÇÑÏÖØ¼¶±ð£¬£¬£¬£¬¶øÔÚAndroid 10ÉÏËüÖ»Äܵ¼Ö¾ܾøÐ§ÀÍ£¬£¬£¬£¬Òò´Ë±»ÒÔΪÊÇÖÐÆ·¼¶±ð¡£ ¡£¡£¡£¡£¡£µÚ¶þ¸öÎó²îÊÇ¿ÉÄܵ¼ÖÂÐÅϢй¶µÄÎó²î£¨CVE-2020-0023£©£¬£¬£¬£¬¸ÃÎó²î½öÓ°ÏìÁËAndroid 10¡£ ¡£¡£¡£¡£¡£¸ü¶àÎó²îÐÅÏ¢Çë²Î¿¼ÒÔÏÂÁ´½Ó¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/androids-february-2020-update-patches-critical-system-vulnerabilities


3.·ÉÀûÆÖÖÇÄܵƵ¨»º³åÇøÒç³öÎó²î£¬£¬£¬£¬¿Éµ¼ÖºڿÍÈëÇÖ¼ÒÍ¥WiFi


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Check PointÑо¿Ö°Ô±Åû¶·ÉÀûÆÖHueÖÇÄܵƵ¨ÖеÄÒ»¸ö¸ßΣÎó²î£¬£¬£¬£¬¸ÃÎó²î£¨CVE-2020-6007£©¿ÉÔÊÐíºÚ¿Í´Ó100¶àÃ×Íâͨ¹ýÎÞÏß»á¼ûÈëÇÖÄ¿µÄµÄ¼ÒÍ¥WiFiÍøÂç¡£ ¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚÖÇÄܵƵ¨µÄZigbeeͨѶЭÒéʵÑé·½·¨ÖУ¬£¬£¬£¬ÊÇÒ»¸ö»ùÓڶѵĻº³åÇøÒç³öÎÊÌâ¡£ ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÎÞÏßÉøÍ¸¼ÒÍ¥»ò°ì¹«ÊÒµÄÅÌËã»úÍøÂç¡¢Èö²¥ÀÕË÷Èí¼þ»òÌØ¹¤Èí¼þ¡£ ¡£¡£¡£¡£¡£Check Point»¹È·ÈÏ»º³åÇøÒç³ö±¬·¢ÔÚ±»³ÆÎª¡°ÍøÇÅ¡±µÄ×é¼þÉÏ£¬£¬£¬£¬¸Ã×é¼þ½ÓÊÜͨ¹ýZigbeeЭÒé´ÓÆäËû×°±¸£¨ÈçÒÆ¶¯Ó¦ÓûòAlexa¼ÒÍ¥ÖúÀí£©·¢Ë͵½µÆµ¨µÄÔ¶³ÌÏÂÁî¡£ ¡£¡£¡£¡£¡£¸ÃÎó²îÒѾ­ÔÚ×îеĹ̼þ¸üÐÂÖÐÐÞ¸´¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/02/philips-smart-light-bulb-hacking.html


4.˼¿ÆTalosÅû¶Mini-SNMPDÖеÄDoS¼°ÐÅϢй¶Îó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Mini-SNMPDÊǼòÆÓÍøÂçÖÎÀíЭÒéЧÀÍÆ÷µÄÇáÁ¿¼¶ÊµÏÖ£¬£¬£¬£¬ÓÉÓÚÆä½ÏСµÄ´úÂë¾ÞϸºÍÄÚ´æÕ¼ÓÃÁ¿£¬£¬£¬£¬¸ÃÈí¼þרÃÅÕë¶ÔǶÈëʽϵͳ¡£ ¡£¡£¡£¡£¡£Ëü¿ÉÒÔÔÚUbuntu¡¢Alpine LinuxºÍFreeBSDµÄx86ºÍARMƽ̨ÉÏÔËÐС£ ¡£¡£¡£¡£¡£Ë¼¿ÆTalosÑо¿Ö°Ô±ÔÚMini-SNMPDÖз¢Ã÷Èý¸öÎó²î£¬£¬£¬£¬°üÀ¨Á½¸öÔ½½ç¶ÁÎó²î£¨CVE-2020-6058ºÍCVE-2020-6059£¬£¬£¬£¬¿Éµ¼ÖÂDoS»òÐÅϢй¶£©ºÍÒ»¸ö¿ÍÕ»Òç³öÎó²î£¨CVE-2020-6060£©¡£ ¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄMini-SNMPD°æ±¾Îª1.4£¬£¬£¬£¬ÕâЩÎó²îÒÑÔÚMini-SNMPD 1.5ÖлñµÃÐÞ¸´¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/vulnerabilities-mini-snmpd-lead-dos-information-disclosure


5.Crew£¦Concierge¹«Ë¾Ôƴ洢Ͱй¶1.7Íòº£Ô±ÐÅÏ¢


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ò»¼Ò˽ÈËÓÎͧº£Ô±ÕÐÆ¸»ú¹¹£¨Crew£¦Concierge£©µÄAWS´æ´¢Í°¿ÉÔÚ»¥ÁªÍøÉϹûÕæ»á¼û£¬£¬£¬£¬µ¼ÖÂ1.7Íòº£Ô±µÄÃô¸ÐÐÅϢй¶¡£ ¡£¡£¡£¡£¡£Æ¾Ö¤Ó¢¹úÐÂÎÅÍøÕ¾VerdictµÄ±¨µÀ£¬£¬£¬£¬¸Ã´æ´¢Í°Ð¹Â¶ÁË17379Ãûº£Ô±µÄ¼òÀúÒÔ¼°³ÉǧÉÏÍòµÄENG1Ò½ÁÆÖ¤ÊµºÍ»¤ÕÕɨÃè¼þ£¬£¬£¬£¬¾Ý³Æ¹²ÓÐ9Íò¸öÎļþ̻¶£¬£¬£¬£¬ÆäÖаüÀ¨³øÊ¦µÄ²Ëµ¥Ñù±¾¡£ ¡£¡£¡£¡£¡£×Ô2019Äê2ÔÂÒÔÀ´£¬£¬£¬£¬¸Ã´æ´¢Í°ÒѾ­Ì»Â¶Á˳¤´ï11¸öÔµÄʱ¼ä¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2020/02/04/crew_and_concierge_data_breach/


6.Íþ˹¿µÐÇÖÝÀ­ÐÁÊÐÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬ÊÐÕþЧÀÍÖÐÖ¹


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Íþ˹¿µÐÇÖÝÀ­ÐÁÊÐÔÚÉÏÖÜÎåÔçÉÏÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬µ¼Ö¸ÃÊеÄÍøÕ¾¡¢µç×ÓÓʼþ¡¢ÓïÒôÓʼþºÍÖ§¸¶ÏµÍ³¾ù±»¹Ø±Õ¡£ ¡£¡£¡£¡£¡£¹ÙÔ±ÃÇÌåÏÖ¿ÉÄÜÐèÒªÒ»ÖÜÒÔÉϵÄʱ¼ä²Å»ª»Ö¸´Õý³£¡£ ¡£¡£¡£¡£¡£À­ÐÁÊÐÊг¤¿ÆÀ÷ɭ£¨Case Mason£©ÌåÏÖ¸ÃÊÐÉÐδÊÕµ½¹¥»÷ÕßµÄÊê½ðÒªÇ󣬣¬£¬£¬²¢ÇÒÌåÏÖ×ÝÈ»ÊÕµ½ÕâÑùµÄÒªÇ󣬣¬£¬£¬¸ÃÊÐÒ²²»»á¸¶¿î¡£ ¡£¡£¡£¡£¡£ÖݺÍÁª°î»ú¹¹ÒÑ»ñϤ¸ÃÊÂÎñ£¬£¬£¬£¬ÏÖÔÚÕýÔÚÊӲ칥»÷±¬·¢µÄ·½·¨ºÍ±³ºóµÄÔµ¹ÊÔ­ÓÉ¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/racine-mayor-refuses-to-pay/