ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ2ÖÜ
Ðû²¼Ê±¼ä 2019-01-14±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÐÂDNSÐ®ÖÆÀ˳±Ï¯¾íÈ«Çò£¬£¬£¬£¬ÒÉΪÒÁÀʺڿÍËùΪ£»£»£»Google PlayϼÜ85¸ö¹ã¸æapp£¬£¬£¬£¬Ñ¬È¾Ô¼900ÍòAndroidÓû§£»£»£»Ó¡¶ÈÁè¼Ý1.1ÍòÁ¾¹«¹²Æû³µµÄʵʱGPS×ø±êÔÚÆØ¹â£»£»£»AvastÐû²¼2019ÄêÍøÂçÍþÐ²Ì¬ÊÆµÄÕ¹Íû±¨¸æ£»£»£»IBM TWCÌìÆøÓ¦ÓÃÒò³öÊÛÓû§Êý¾ÝÔâµ½ÆðËß¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£
Ö÷ÒªÇå¾²Îó²îÁбí
Cisco Identity Services Engine Admin Portal²»×¼È·ÉúÑÄÃÜÂëÐÅÏ¢£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬Éó²éÃ÷ÎÄÃÜÂëÐÅÏ¢£¬£¬£¬£¬Î´ÊÚȨ»á¼û¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190109-ise-passwd
2. Imperva SecureSphereÌí¼Óí§ÒâsshÃÜÔ¿Îó²î
Imperva SecureSphere±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÏòÖÎÀíÔ±Óû§µÄauthorized_keysÌí¼Óí§ÒâsshÃÜÔ¿¡£¡£¡£¡£
https://www.exploit-db.com/exploits/45130
3. Juniper Junos OS BGP¾Ü¾øÐ§ÀÍÎó²î
Juniper Junos OS´¦Öóͷ£BGPÐÂÎű£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿É¾ÙÐоܾøÐ§À͹¥»÷¡£¡£¡£¡£
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10912&actp=METADATA
4. Microsoft Visual Studio CVE-2019-0546í§Òâ´úÂëÖ´ÐÐÎó²î
Microsoft Visual StudioÔÚC++±àÒëÆ÷δ׼ȷ´¦Öóͷ£C++½á¹¹Ìض¨×éºÏ£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬¿ÉÒÔÓ¦Óù¦Ð§³ÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0546
5. Microsoft Exchange ServerÔ¶³ÌÐÅϢй¶Îó²î
Microsoft Exchange Server PowerShell APIÔÚcalendar contributorsȨÏÞÖÎÀíÖб£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿É»ñÈ¡Ãô¸ÐÈÕÀúµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0588
Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö

FireEye·¢Ã÷Ò»²¨Õë¶ÔÈ«ÇòµÄ´ó¹æÄ£DNSÐ®ÖÆÀ˳±£¬£¬£¬£¬Ó°ÏìÁËÖж«¡¢±±·Ç¡¢Å·Ö޺ͱ±ÃÀµÄÊýÊ®¸öÓòÃû¡£¡£¡£¡£ÕâЩÓòÃûÊôÓÚÕþ¸®¡¢µçÐźͻ¥ÁªÍø»ù´¡ÉèÊ©µÈ¡£¡£¡£¡£ËäÈ»ÏÖÔÚÑо¿Ö°Ô±»¹Ã»Óн«´Ë»î¶¯ÓëÈκι¥»÷×éÖ¯¹ØÁªÆðÀ´£¬£¬£¬£¬µ«ÆðÔ´µÄÑо¿Åú×¢¹¥»÷ÕßÒÉÓëÒÁÀÊÓйء£¡£¡£¡£¸Ã¹¥»÷»î¶¯µÄ¶à¸ö¼¯ÈºÔÚ2017Äê1ÔÂÖÁ2019Äê1ÔÂʱ´úÒ»Ö±´¦ÓÚ»îԾ״̬£¬£¬£¬£¬²¢ÇÒ±£´æ¶à¸ö²»Öظ´µÄÓòÃû¡¢IPµØµã¼¯Èº¡£¡£¡£¡£ÕâÒâζןù¥»÷»î¶¯¿ÉÄܲ¢²»Êǵ¥¸ö¹¥»÷ÕߵĻ¡£¡£¡£¡£¹¥»÷ÕßµÄÊÖÒÕÖ÷񻃾¼°ÐÞ¸ÄDNS A¼Í¼¡¢NS¼Í¼ºÍÖØ¶¨Ïò¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.fireeye.com/blog/threat-research/2019/01/global-dns-hijacking-campaign-dns-record-manipulation-at-scale.html
2¡¢Google PlayϼÜ85¸ö¹ã¸æapp£¬£¬£¬£¬Ñ¬È¾Ô¼900ÍòAndroidÓû§

Ç÷ÊÆ¿Æ¼¼µÄÑо¿Ö°Ô±ÔÚGoogle PlayÊÐËÁ·¢Ã÷85¸ö¹ã¸æÓ¦Ó㬣¬£¬£¬Ô¼900ÍòAndroidÓû§Êܵ½Ñ¬È¾¡£¡£¡£¡£ÕâЩappαװ³ÉÓÎÏ·¡¢Á÷ýÌåµçÊÓºÍÄ£ÄâÒ£¿£¿£¿£¿£¿ØÆ÷µÈ£¬£¬£¬£¬ÔÚ×°±¸ºǫ́¾²Ä¬ÔËÐУ¬£¬£¬£¬²¢Ã¿¸ô15»ò30·ÖÖÓʹÓÃÈ«ÆÁ¹ã¸æºäÕ¨Óû§×°±¸¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÕâЩappÀ´×ÔÓÚ²î±ðµÄ¿ª·¢Ö°Ô±£¬£¬£¬£¬²¢ÇÒÓµÓвî±ðµÄAPKÖ¤Ê鹫Կ£¬£¬£¬£¬µ«ËüÃǵĴúÂëºÍÃüÃû·½·¨¶¼Ê®·ÖÏàËÆ¡£¡£¡£¡£Google PlayÔÚ½Óµ½Í¨ÖªºóÒÑϼÜÁËÕâЩӦÓᣡ£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/android-adware-malware.html
3¡¢Ó¡¶ÈÁè¼Ý1.1ÍòÁ¾¹«¹²Æû³µµÄʵʱGPS×ø±êÔÚÆØ¹â

Çå¾²Ñо¿Ô±Justin Paine·¢Ã÷Ò»¸öδÉèÃÜÂëµÄElasticSearchЧÀÍÆ÷£¬£¬£¬£¬¸ÃЧÀÍÆ÷°üÀ¨À´×Ô27¼ÒÓ¡¶È¹úÓÐÔËÊä»ú¹¹µÄÊý¾Ý£¬£¬£¬£¬ÆäÖаüÀ¨Áè¼Ý1.1ÍòÁ¾¹«¹²Æû³µµÄʵʱGPS×ø±êºÍõè¾¶ÐÅÏ¢¡£¡£¡£¡£²î±ðÔËÊä»ú¹¹µÄÊý¾Ý²¢²»Ïàͬ£¬£¬£¬£¬ÔÚijЩ°¸ÀýÖУ¬£¬£¬£¬»¹°üÀ¨Âÿ͵ÄÓû§ÃûºÍµç×ÓÓʼþµØµã¡£¡£¡£¡£¸ÃЧÀÍÆ÷ÖÁÉÙÒÑÔÚ»¥ÁªÍøÉÏÆØ¹âÁËÈýÖܵÄʱ¼ä¡£¡£¡£¡£ÔÚPaine֪ͨӡ¶ÈCERTºó£¬£¬£¬£¬¸ÃЧÀÍÆ÷»ñµÃ±£»£»£»¤£¬£¬£¬£¬µ«CERT¾Ü¾øÍ¸Â¶¸ÃЧÀÍÆ÷µÄËùÓÐÕß¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/real-time-location-data-for-over-11000-indian-buses-left-exposed-online/
4¡¢AvastÐû²¼2019ÄêÍøÂçÍþÐ²Ì¬ÊÆµÄÕ¹Íû±¨¸æ

AvastµÄ2019ÄêÍþÐ²Ì¬ÊÆÕ¹Íû±¨¸æÖ¸³ö£¬£¬£¬£¬ÔÚ2019Äê¶Ô¿¹ÐÔAI½«ÓÀ´ÀèÃ÷¡£¡£¡£¡£Ñо¿Ö°Ô±Õ¹ÍûDeepAttacks¹¥»÷½«¸üƵÈԵطºÆð£¨ÕâÀ๥»÷ͨ³£Ê¹ÓÃAIÌìÉúµÄÄÚÈÝÀ´ÌÓ±ÜAIÇå¾²¿ØÖƲ½·¥£©¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ÎïÁªÍøÍþв½«±äµÃÔ½·¢Öش󣬣¬£¬£¬Â·ÓÉÆ÷Ò²½«Ô½À´Ô½¶àµØ³ÉΪ¹¥»÷Ä¿µÄ£¬£¬£¬£¬¹ã¸æ¡¢´¹ÂÚºÍÐéαӦÓý«¼ÌÐøÖ÷µ¼Òƶ¯ÍþвÁìÓò¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cdn2.hubspot.net/hubfs/486579/Avast_Threat_Landscape_Report_2019.pdf
5¡¢IBM TWCÌìÆøÓ¦ÓÃÒò³öÊÛÓû§Êý¾ÝÔâµ½ÆðËß

Âåɼí¶ÊÐÏò¼ÓÀû¸£ÄáÑÇÖÝ·¨ÔºÌáÆðËßËÏ£¬£¬£¬£¬¿ØËßIBM×Ó¹«Ë¾TWCµÄÌìÆøÓ¦Óã¨Weather Channel£©ÍÚ¾òÓû§µÄÒþ˽Êý¾Ý²¢½«ÕâЩÐÅÏ¢³öÊÛ¸øµÚÈý·½£¬£¬£¬£¬°üÀ¨¹ã¸æ¹«Ë¾¡£¡£¡£¡£Âåɼí¶Êз½ÃæÌåÏÖ£¬£¬£¬£¬Weather ChannelÔÚÐí¶àÓû§²»ÖªÇéµÄÇéÐÎϸú×ÙÓû§µÄµØÀíλÖÃÊý¾Ý£¬£¬£¬£¬²¢½«ÕâЩÊý¾ÝÓÃÓÚÓëÌìÆøÔ¤¸æÍêÈ«ÎÞ¹ØµÄ¹ã¸æµÈÉÌÒµÓÃ;¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/city-of-la-sues-weather-channel-app-for-sharing-location-data-with-advertisers/
ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí