F5Ðû²¼2019ÄêTLSÒ£²â±¨¸æ£¬£¬£¬£¬ £¬¹Ø×¢¼ÓÃÜÁìÓòµÄÉú³¤£»£»£»£»£»£»£»2019Äê61£¥µÄÒªº¦Í¨Ñ¶ÐÐÒµÔâÊܶñÒâÈí¼þ¹¥»÷

Ðû²¼Ê±¼ä 2020-03-02

1.F5Ðû²¼2019ÄêTLSÒ£²â±¨¸æ£¬£¬£¬£¬ £¬¹Ø×¢¼ÓÃÜÁìÓòµÄÉú³¤


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


F5ʵÑéÊÒÐû²¼¡¶2019ÄêTLSÒ£²â±¨¸æ¡·£¬£¬£¬£¬ £¬¸Ã±¨¸æÌṩÁËÓйØÍøÂç¼ÓÃÜÔõÑùÒ»Ö±Éú³¤µÄÉî¿Ì¿´·¨¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÑо¿ÁËInternet¶¥¼¶ÍøÕ¾Ê¹ÓÃÄÄÖÖ¼ÓÃÜÆ÷ºÍSSL/TLS°æ±¾¾ÙÐб£»£»£»£»£»£»£»¤£¬£¬£¬£¬ £¬²¢Ê״μì²éÁËWebÉÏÊý×ÖÖ¤ÊéµÄʹÓúÍÉó²éÁËÖ§³ÖµÄЭÒ飨ÈçDNS£©ºÍÓ¦ÓóÌÐò²ã±êÍ·¡£¡£¡£¡£¡£¡£ÊÖÒÕÌṩÉÌÓëÕþ¸®Ö®¼äµÄÈ«Çò±ç˵£¨Ò²³ÆÎªCrypto Wars 2.0£©ÈÔÔÚ¼ÌÐø¡£¡£¡£¡£¡£¡£Õþ¸®Ô½À´Ô½¶àµØÊµÑé¿ØÖÆ¼ÓÃܵÄʹÓ÷½·¨£¬£¬£¬£¬ £¬²¢ÇÒÎÒÃǾ­³£¿£¿£¿£¿£¿£¿´µ½Á¢·¨²»ÍêÉÆ£¨»ò¾ÓÐÄÃÔºý£©µÄÁ¢·¨¡£¡£¡£¡£¡£¡£ChromeÊÇʹÓÃ×îÆÕ±éµÄÍøÂçä¯ÀÀÆ÷£¬£¬£¬£¬ £¬Æä¿ÉÒÔͨ¹ýÇå¾²µÄHTTPSÅþÁ¬»á¼ûÁè¼Ý86%µÄÍøÒ³£¬£¬£¬£¬ £¬FirefoxµÄÊý×ÖÉԵͣ¬£¬£¬£¬ £¬µ«Ò²ÓÐ80.5%¡£¡£¡£¡£¡£¡£ÔÚAlexaÅÅÃûǰ100ÍòµÄÍøÕ¾ÖУ¬£¬£¬£¬ £¬½üÈý·ÖÖ®Ò»ÏÖÔÚ½ÓÊÜTLS 1.3ÅþÁ¬¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.f5.com/content/dam/f5-labs-v2/article/pdfs/F5Labs-2019-TLS-Telemetry-Report-Summary.pdf


2.Ó¢¹ú²â»æ»ú¹¹Ordnance SurveyÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬ £¬Ô±¹¤Êý¾Ýй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¾ÝÍâý±¨µÀ£¬£¬£¬£¬ £¬Ó¢¹ú²â»æ»ú¹¹Ordnance SurveyÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬ £¬µ¼Ö½ü1000ÃûÔ±¹¤µÄÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¾Ý³ÆÕþ¸®ÓÚ1Ô·ݷ¢Ã÷²¢Á¬Ã¦ÏìÓ¦ÁËÈëÇÖÊÂÎñ£¬£¬£¬£¬ £¬²¢ÇÒ֪ͨÁËÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©£¬£¬£¬£¬ £¬µ«¸ÃÊÂÎñÖ±µ½ÏÖÔڲű»¹ûÕæ¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎúÈëÇÖ±¬·¢µÄÏêϸʱ¼ä£¬£¬£¬£¬ £¬µ«¾ÝVerdict³Æ£¬£¬£¬£¬ £¬¹¥»÷ÕßÊÇͨ¹ýÍøÂç´¹ÂÚ¹¥»÷ÈëÇÖÁËCFOµÄµç×ÓÓʼþÕË»§£¬£¬£¬£¬ £¬´Ó¶øÇÔÈ¡ÁËÈËΪµ¥Îļþ¡£¡£¡£¡£¡£¡£Ordnance SurveyÌåÏÖûÓÐÈκοͻ§ÐÅϢй¶£¬£¬£¬£¬ £¬Æä×ÔÉíµÄϵͳҲ²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/ordnance-survey-breach-hits/?&web_view=true


3.ÃÀ¹úWalgreensÒ©µêÒÆ¶¯APP±£´æÎó²îй¶Óû§ÐÅÏ¢


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹úµÚ¶þ´óÒ©µêÎÖ¶û¸ñÁÖ£¨Walgreens£©ÌåÏÖÆä¹Ù·½Òƶ¯APP±£´æÒ»¸öÎó²î£¬£¬£¬£¬ £¬µ¼Ö²¿·ÖÓû§µÄСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£¡£¡£¡£¸ÃÎó²î±»ÐÎòΪAPPСÎÒ˽¼ÒÇå¾²ÐÂÎÅת´ï¹¦Ð§ÖеĹýʧ£¬£¬£¬£¬ £¬¿ÉÄÜй¶µÄÐÅÏ¢°üÀ¨Óû§µÄÐÕÃû¡¢´¦·½ÏêϸÐÅÏ¢¡¢ÊÐËÁ±àºÅºÍËÍ»õµØµã£¨ÈôÊÇÓУ©¡£¡£¡£¡£¡£¡£ÕâЩÊý¾Ý̻¶µÄʱ¼äΪ1ÔÂ9ÈÕ£¨ÐÇÆÚËÄ£©ºÍ1ÔÂ15ÈÕ£¨ÐÇÆÚÈý£©Ö®¼ä£¬£¬£¬£¬ £¬WalgreensÒÑÓÚ1ÔÂ15ÈÕµÃÖªÎó²îÈ·µ±ÌìÐÞ¸´Á˸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ã»ÓÐ͸¶ÏêϸÊÜÓ°ÏìÓû§µÄÊýÄ¿£¬£¬£¬£¬ £¬µ«ÌåÏÖÃô¸Ð´¦·½ÐÅϢй¶µÄÓû§Õ¼ÊÜÓ°ÏìÓû§×ÜÊýµÄһС²¿·Ö¡£¡£¡£¡£¡£¡£¸ÃAPPÔÚGoogle PlayÊÐËÁÖеÄÏÂÔØ´ÎÊýΪÁè¼Ý1000Íò´Î£¬£¬£¬£¬ £¬ÔÚiOSÖÐµÄÆÀ·ÖÊýÄ¿Áè¼Ý250Íò¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/walgreens-says-mobile-app-leaked-users-personal-data/


4.2019Äê61£¥µÄÒªº¦Í¨Ñ¶ÐÐÒµÔâÊܶñÒâÈí¼þ¹¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤¹ú¼ÊÎÞÏßͨѶչÀÀ»á£¨IWCE£©µÄµ÷ÑУ¬£¬£¬£¬ £¬ÔÚÒÑÍùµÄ12¸öÔÂÖÐÓÐÎå·ÖÖ®Ò»µÄÒªº¦Í¨Ñ¶ÐÐÒµÔâÓöÁËÇå¾²ÊÂÎñ¡£¡£¡£¡£¡£¡£ÎªÁ˶ÔÄ¿½ñÊÖÒÕ¾ÙÐлù×¼²âÊÔ£¬£¬£¬£¬ £¬IWCE¶ÔÒªº¦Í¨Ñ¶ÐÐÒµµÄÖÁÉÙ597ÃûרҵְԱ¾ÙÐÐÁËÊӲ졣¡£¡£¡£¡£¡£¸ÃÊӲ컹»ØÊ×ÁËÐÐÒµÄÚµÄÊÖÒÕÌôÕ½¡£¡£¡£¡£¡£¡£Í¨¹ý¸ÃÊӲ죬£¬£¬£¬ £¬61£¥µÄÊÜ·ÃÕßÌåÏÖÔâÊÜÁ˶ñÒâÈí¼þ¹¥»÷£¬£¬£¬£¬ £¬56£¥ÔòÊÇÍøÂç´¹ÂÚ¹¥»÷µÄÊܺ¦Õߣ¬£¬£¬£¬ £¬27£¥ÌåÏÖ´¦Öóͷ£¹ýÀÕË÷Èí¼þ£¬£¬£¬£¬ £¬22%ÔâÓöÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬ £¬16%Ôâµ½DDoS¹¥»÷¡£¡£¡£¡£¡£¡£10£¥µÄµÄÊÜ·ÃÕß±¨¸æ³ÆÔâµ½¸ß¼¶Íþв¹¥»÷£¬£¬£¬£¬ £¬ÔÚ´ËÀ๥»÷Öй¥»÷Õßͨ³£³¤Ê±¼äDZÔÚÔÚÆäÍøÂçÖС£¡£¡£¡£¡£¡£ÍøÂç¹¥»÷ÆÆËðÁËÕý³£µÄÔËÓªºÍЧÀÍ£¬£¬£¬£¬ £¬ÆäÐÞ¸´±¾Ç®Îª£º38£¥µÄ±¾Ç®²»µ½10ÍòÃÀÔª£¬£¬£¬£¬ £¬10£¥µÄ±¾Ç®ÔÚ10ÍòÃÀÔªÖÁ100ÍòÃÀÔªÖ®¼ä£¬£¬£¬£¬ £¬¶ø2£¥µÄ±¾Ç®ÔÚ100ÍòÖÁ1000ÍòÃÀÔªÖ®¼ä¡£¡£¡£¡£¡£¡£Ðí¶à¹«Ë¾£¨64%£©ÕýÔÚÓëµÚÈý·½¹©Ó¦ÉÌÇ©ÊðÊý¾Ý±£»£»£»£»£»£»£»¤ºÍÍøÂçÇ徲ЭÒ飬£¬£¬£¬ £¬ÓÉÓÚ¹¥»÷¼°ÆäÓ°Ïì¿ÉÄÜÀ´×ÔµÚÈý·½¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://finbold.com/61-percent-critical-communications-industry-suffers-malware-attacks/


5.2019Äê·¸·¨ÍÅ»ïTA505Æð¾¢Õë¶Ôº«¹ú½ðÈÚ»ú¹¹


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


º«¹ú½ðÈÚÇå¾²Ñо¿Ëù£¨Financial Security Institute£©Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬ £¬TA505ÔÚ2019ÄêµÄ´ó²¿·Öʱ¼äÀï¶¼ÔÚʵÑéÕë¶Ôº«¹ú½ðÈÚ¡¢ÖÆÔìºÍÒ½ÁÆÐ§ÀÍÆóÒµÌᳫ´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£·¸·¨ÍÅ»ïTA505×Ô2014ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬ £¬²¢ÇÒËÆºõÓë·¸·¨ÍÅ»ïFIN7¹²Ïí¹¤¾ß¡¢ÊÖÒպͳÌÐò¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖTA505·¢Ë͵ÄÐí¶àÍøÂç´¹ÂÚÓʼþ¶¼°üÀ¨¶ñÒâExcelÎĵµ£¬£¬£¬£¬ £¬²¢ÇÒʹÓÃÔ¶¿ØÄ¾ÂíFlawedAmmyy¼àÊÓÓû§µÄ»î¶¯ºÍÍøÂçÓû§Ãû/ÃÜÂë¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬TA505»¹ÔÚ¶Ìʱ¼äÄÚʹÓÃÁËÒ»ÖÖÃûΪRapidµÄÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cyberscoop.com/ta505-south-korea-bank-phishing/


6.ºÚ¿ÍʹÓÃWooCommerce²å¼þ0day¹¥»÷ÊýÍò¸öWordPressÍøÕ¾


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ºÚ¿ÍÕýÔÚʹÓÃWordPress²å¼þÖеÄ0day¹¥»÷ÊýÒÔÍò¼ÆµÄÍøÕ¾£¬£¬£¬£¬ £¬ÕâЩÎó²îʹËûÃÇ¿ÉÒÔ½¨Éè¶ñÒâÖÎÀíÔ±ÕÊ»§²¢Ö²ÈëºóÃųÌÐò¡£¡£¡£¡£¡£¡£NinTechNetÑо¿Ö°Ô±ÔÚWooCommerce²å¼þµÄFlexible Checkout×Ö¶ÎÖз¢Ã÷´æ´¢ÐÍXSS 0day£¬£¬£¬£¬ £¬¸Ã²å¼þµÄ×°ÖÃÊýĿΪ2Íò¡£¡£¡£¡£¡£¡£²å¼þ¿ª·¢ÍŶÓÔÚ½Óµ½±¨¸æºóѸËÙÍÆ³öÁË2.3.2°æ±¾ÒÔÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬ £¬µ«ÈÔÓÐһЩÓû§Ôâµ½¹¥»÷¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬DefiantÑо¿Ö°Ô±»¹ÔÚÆäËü¼¸¸ö²å¼þÖз¢Ã÷3¸ö0day£¬£¬£¬£¬ £¬°üÀ¨Async JavaScript£¨10Íò+×°Öã©¡¢10Web Map Builder for Google Maps£¨2Íò+×°Öã©¡¢ Modern Events Calendar Lite£¨4Íò+×°Öã©ÖеĴ洢ÐÍXSS¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-bugs-in-wordpress-plugins-let-hackers-take-over-sites/