Å·Ã˳ÉÔ±¹ú½øÐÐÍøÂ簲ȫÑÝϰ£¬£¬£¬ £¬£¬£¬¼ÓǿӦ¶ÔÑ¡¾ÙÆÚ¼äµÄÍøÂçÍþв£»£»£»£»£»£»¹¥»÷ÕßÀûÓùȸèÔÆÌáÒéDNS½Ù³Ö¹¥»÷£»£»£»£»£»£»ÀÕË÷Èí¼þPlanetary½âÃܹ¤¾ß

°ä²¼¹¦·ò 2019-04-08
1.Å·Ã˳ÉÔ±¹ú½øÐÐÍøÂ簲ȫÑÝϰ£¬£¬£¬ £¬£¬£¬¼ÓǿӦ¶ÔÑ¡¾ÙÆÚ¼äµÄÍøÂçÍþв

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ΪÁËÓ­½Ó¼´½«ÔÚ2019Äê5ÔÂ23ÈÕÖÁ26ÈÕ½øÐеÄÅ·ÃËÒé»áÑ¡¾Ù£¬£¬£¬ £¬£¬£¬Å·ÃËÍøÂ簲ȫ¾Ö£¨ENISA£©¼°Å·Ã˳ÉÔ±¹ú½áºÏ½øÐÐÁËÒ»ÏîÃûΪEU ELEx19µÄÑÝϰ£¬£¬£¬ £¬£¬£¬ÒÔ¼ÓǿӦ¶ÔÑ¡¾ÙÆÚ¼äµÄÍøÂ簲ȫÍþв¡£¡£¡£¡£¡£ ¡£Æ¾¾ÝÅ·ÃËÒé»á£¬£¬£¬ £¬£¬£¬ÕâÏîÑÝϰµÄÖ¸±êÊÇÕÒµ½Ô¤·À¡¢¼ì²â¼°»º½âÓ°ÏìÅ·ÃËÑ¡¾ÙµÄÍøÂ簲ȫÊÂÎñµÄ²½Öè¡£¡£¡£¡£¡£ ¡£ÕâÏîÑÝϰÄܹ»Ê¹Å·Ã˳ÉÔ±¹ú²âÊÔÆäΣ»£»£»£»£»£»úÏìÓ¦¹æ»®£¬£¬£¬ £¬£¬£¬²¢Ìá¸ß¿ç¾³Ð­µ÷ÏìÓ¦µÄÄÜÁ¦¡£¡£¡£¡£¡£ ¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/eu-states-test-and-strengthen-readiness-for-election-cyber-threats/

2.¹¥»÷ÕßÀûÓùȸèÔÆÌáÒéDNS½Ù³Ö¹¥»÷£¬£¬£¬ £¬£¬£¬ÖØÒªÕë¶ÔD-Link·ÓÉÆ÷

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×êÑÐÈËÔ±Troy Mursch·¢´Ë¿Ì´ÓǰÈý¸öÔÂÖй¥»÷ÕßÀûÓùȸèÔÆÆ½Ì¨ÌáÒéÁËÈý´ÎÕë¶ÔD-Link·ÓÉÆ÷µÄDNS½Ù³Ö¹¥»÷¡£¡£¡£¡£¡£ ¡£µÚÒ»²¨¹¥»÷º£³±²úÉúÔÚ2018Äê12ÔÂ29ÈÕ£¬£¬£¬ £¬£¬£¬ÖØÒªÕë¶ÔD-Link DSLϵÁеÄ·ÓÉÆ÷£¬£¬£¬ £¬£¬£¬²¢½«ÆäÁ÷Á¿³Á¶¨Ïòµ½Î»ÓÚ¼ÓÄôóµÄ¶ñÒâDNS·þÎñÆ÷¡£¡£¡£¡£¡£ ¡£µÚ¶þ²¨¹¥»÷²úÉúÔÚ2ÔÂ6ÈÕ£¬£¬£¬ £¬£¬£¬Õë¶ÔͬÑùµÄÖ¸±ê¡£¡£¡£¡£¡£ ¡£×îеÄÒ»²¨¹¥»÷²úÉúÔÚ3ÔÂ26ÈÕ£¬£¬£¬ £¬£¬£¬»¹Õë¶ÔTOTOLINK¡¢SecutechµÈ·ÓÉÆ÷¡£¡£¡£¡£¡£ ¡£×êÑÐÈËÔ±¹À¼ÆÓг¬¹ý1.7Íǫ̀É豸Êܵ½Ó°Ïì¡£¡£¡£¡£¡£ ¡£ËùÓÐÕâЩ¹¥»÷µÄÆðÔ´¶¼ÊǹȸèÔÆÆ½Ì¨ÉϵÄÖ÷»ú¡£¡£¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/hackers-abuse-google-cloud-platform-to-attack-d-link-routers/143492/

3.×êÑÐÍŶӰ䲼ÀÕË÷Èí¼þPlanetaryµÄ½âÃܹ¤¾ß
8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

Emsisoft°ä²¼ÀÕË÷Èí¼þ¼Ò×åPlanetaryµÄÃâ·Ñ½âÃÜÆ÷¡£¡£¡£¡£¡£ ¡£PlanetaryÒòÔÚ¼ÓÃÜÎļþºóÔö³¤ÐÐÐÇÃû³ÆµÄÀ©´óÃû¶øµÃÃû£¬£¬£¬ £¬£¬£¬ÀýÈç.mira¡¢.yum¡¢.Pluto»ò.Neptune£¬£¬£¬ £¬£¬£¬×îеÄÒ»¸ö±äÌåÊÇÔö³¤.miraÀ©´óÃû¡£¡£¡£¡£¡£ ¡£¸Ã½âÃܹ¤¾ßdecrypt_Planetary.exe¿ÉÔ®ÊÖÊܺ¦Õ߸´Ô­½âÃÜÃÜÔ¿£¬£¬£¬ £¬£¬£¬²¢×Ô¶¯½âÃÜËùÓб»¼ÓÃܵÄÎļþ¡£¡£¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/ransomware/decryptor/planetary-ransomware-decryptor-gets-your-files-back-for-free/

4.ÂÞ¿ËΤ¶û×Ô¶¯»¯½¨¸´Stratix»¥»»»úÖеĶà¸öDoS·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÂÞ¿ËΤ¶û×Ô¶¯»¯°ä²¼Allen-Bradley Stratix¹¤Òµ»¥»»»úµÄ°²È«¸üУ¬£¬£¬ £¬£¬£¬½¨¸´ÁË˼¿ÆÈí¼þÒýÈëµÄ5¸öDoS·ì϶¡£¡£¡£¡£¡£ ¡£Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâÊý¾Ý°üÀ´´¥·¢ÕâЩ·ì϶£¬£¬£¬ £¬£¬£¬µ¼Ö»º³åÇøÒç³ö¡¢ÄÚ´æºÄ¾¡»òÉ豸³ÁмÓÔØµÈÎÊÌ⣬£¬£¬ £¬£¬£¬´Ó¶øµ¼Ö»ؾø·þÎñ¡£¡£¡£¡£¡£ ¡£ÕâЩ·ì϶µÄ±àºÅ±ðÀëΪCVE-2018-15373¡¢CVE-2018-0466¡¢CVE-2018-0467¡¢CVE-2018-0470¡¢CVE-2018-0473£¬£¬£¬ £¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/83477/security/rockwell-patches-stratix-flaws.html

5.˼¿Æ³Áн¨¸´RV320ºÍRV325·ÓÉÆ÷ÖеÄÁ½¸ö·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


˼¿Æ×îÖÕ³Áн¨¸´ÁËRV320ºÍRV325 VPN·ÓÉÆ÷ÖеĺÅÁî×¢Èë·ì϶£¨CVE-2019-1652£©ºÍÐÅϢй¶·ì϶£¨CVE-2019-1653£©£¬£¬£¬ £¬£¬£¬ÆëÈ«µÄ½¨¸´´Ë¿Ì¿ÉÔڹ̼þ°æ±¾1.4.2.22ÖÐÕÒµ½¡£¡£¡£¡£¡£ ¡£µ«Í¬Ê±Ë¼¿ÆÔÙ´ÎÅû¶ÁËÓ°ÏìRV320ºÍRV325·ÓÉÆ÷µÄÁ½¸öзì϶£¨CVE-2019-1828¡¢CVE-2019-1827£©£¬£¬£¬ £¬£¬£¬ÕâÁ½¸ö·ì϶¶¼»¹Ã»Óн¨¸´²¹¶¡¡£¡£¡£¡£¡£ ¡£CVE-2019-1828Óë·ÓÉÆ÷ʹÓõÄÈõÍ´´¦¼ÓÃÜËã·¨Óйأ¬£¬£¬ £¬£¬£¬CVE-2019-1827ÔòÊÇÊäÈëÃýÎóÑéÖ¤²»³ä·ÖÎÊÌ⣬£¬£¬ £¬£¬£¬¿Éµ¼ÖÂXSS¹¥»÷¡£¡£¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/cisco-finally-patches-routers-bugs-as-new-unpatched-flaws-surface/143528/

6.жñÒâÈí¼þXwo£¬£¬£¬ £¬£¬£¬ÖØÒªÕë¶ÔʹÓÃĬÈÏÃÜÂëµÄWeb·þÎñ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


AT£¦T Alien Labs·¢ÏÖPython±àдµÄжñÒâÈí¼þXwo£¬£¬£¬ £¬£¬£¬¸Ã¶ñÒâÈí¼þÔÚ»ý¼«µØÉ¨Ã軥ÁªÍø£¬£¬£¬ £¬£¬£¬ÒÔ·¢ÏÖʹÓÃĬÈÏÃÜÂëµÄWeb·þÎñ¡£¡£¡£¡£¡£ ¡£XwoµÄ´úÂëÀàËÆÓÚÀÕË÷Èí¼þMongoLock£¬£¬£¬ £¬£¬£¬²¢ÇÒʹÓÃÁËÀàËÆµÄC£¦CÓòÃû£¬£¬£¬ £¬£¬£¬ÔÚC£¦C»ù´¡ÉèÊ©ÖÐÒ²ÓгÁµþÖ®´¦¡£¡£¡£¡£¡£ ¡£XwoÖØÒªÍøÂçweb·þÎñµÄÐÅÏ¢£¬£¬£¬ £¬£¬£¬Ô̺¬FTP¡¢MySQL¡¢PostgreSQL¡¢MongoDB¡¢Tomcat¡¢Git¡¢PhpMyAdminµÈµÄõè¾¶¡¢ÊÇ·ñʹÓÃĬÈÏÍ´´¦ÒÔ¼°ÅäÏàÐÅÏ¢µÈ¡£¡£¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/83402/malware/xwo-malware.html