ÔÚÏß¹¤×÷ÖÎÀíÍøÕ¾Trelloй¶´óÁ¿Óû§Êý¾Ý£»£»£»£»£»£»£»£»·¨¹ú¹¤Òµ¹«Ë¾Bouygues¼°5¼ÒÂÉʦÊÂÎñËùÔâµ½Maze¹¥»÷

°ä²¼¹¦·ò 2020-02-04

1.·¨¹ú¹¤Òµ¹«Ë¾Bouygues¼°5¼ÒÂÉʦÊÂÎñËùÔâµ½Maze¹¥»÷


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


·¨¹ú¹¤Òµ¹«Ë¾Bouygues Construction¼°Îå¼ÒÂÉʦÊÂÎñËù³ÉΪÀÕË÷Èí¼þMazeµÄ×îÐÂÊܺ¦Õߣ¬£¬£¬£¬£¬£¬ £¬¾Ý³Æ¹¥»÷ÕßÇÔÈ¡ÁËËùÓÐÕâЩ¹«Ë¾µÄÃô¸ÐÄÚ²¿Êý¾Ý¡£¡£¡£¡£¡£Maze¹¥»÷ÕßÒѾ­ÔÚÆäÍøÕ¾Éϰ䲼ÁËÁ½¼ÒÂÉʦÊÂÎñËùµÄ¿Í»§Êý¾Ý£¬£¬£¬£¬£¬£¬ £¬²¢³ÐŵºÜ¿ì»á°ä²¼ÆäËü¹«Ë¾µÄÊý¾Ý¡£¡£¡£¡£¡£BouyguesÔÚÉÏÖÜÎå°ä²¼ÁËÒ»·Ý¼ò¶ÌÉêÃ÷£¬£¬£¬£¬£¬£¬ £¬ÈÏ¿ÉÔÚÆäÍøÂçÉϼì²âµ½ÀÕË÷²¡¶¾£¬£¬£¬£¬£¬£¬ £¬µ«²¢Î´»ØÓ¦Æä¹Ø¼üÊý¾ÝÊÇ·ñ±»µÁ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/maze-ransomware-law-firms-french/


2.Ó¢¹ú´È±¯»ú¹¹ÔâÍøÂçڲƭËðʧ³¬¹ý100ÍòÃÀÔª


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ó¢¹úÉçÇø×¡·¿´È±¯»ú¹¹Red KiteÖܶþ°ä·¢ËüÒѳÉÎªÍøÂçÚ¿Æ­µÄÊܺ¦Õߣ¬£¬£¬£¬£¬£¬ £¬·¸×ï·Ö×Ó¼Ù×°³ÉÕæÕýµÄ·þÎñÌṩÉÌÆ­È¡ÁË93.2ÍòÓ¢°÷×ʽ𡣡£¡£¡£¡£Æ¾¾Ý¸Ã»ú¹¹µÄÃèÊö£¬£¬£¬£¬£¬£¬ £¬·¸×ï·Ö×Ó·ÂÕÕÁËÏòRed KiteÌṩ·þÎñµÄÒÑÖªÁªÏµÈ˵ÄÓòÃûºÍµç×ÓÓʼþÐÅÏ¢£¬£¬£¬£¬£¬£¬ £¬µ¼ÖÂÔ±¹¤ÎóÒÔΪÕâÊÇÕæÕýµÄ¸ú½ø»á»°¡£¡£¡£¡£¡£¸Ã»ú¹¹»¹ÈÏ¿ÉÔ±¹¤Ã»ÓвÉÈ¡Ã÷È·µÄÁ÷³Ì£¬£¬£¬£¬£¬£¬ £¬µ¼ÖÂΪԤ·ÀڲƭÐÔÂòÂô¶øÖ´Ðеĸ¶¿îÑéÖ¤Á÷³ÌÎÞЧ¡£¡£¡£¡£¡£¸ÃÊÂÎñ²úÉúÔÚ2019Äê8ÔÂÏÂÑ®£¬£¬£¬£¬£¬£¬ £¬¾¯·½ÈÔÔڶԴ˽øÐе÷²é¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/red-kite-spoofing-scam/


3.Ç÷Ïò¿Æ¼¼½¨¸´Æä·´Íþв¹¤¾ß°üÖеĶà¸ö·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ç÷Ïò¿Æ¼¼°ä²¼·´Íþв¹¤¾ß°ü£¨ATTK£©µÄ°²È«¸üУ¬£¬£¬£¬£¬£¬ £¬½¨¸´ÓëÔÚ2019Äê10Ô½¨¸´µÄÒ»¸ö·ì϶Óйصĸü¶à·ì϶¡£¡£¡£¡£¡£È¥Ä갲ȫ×êÑÐÔ±John Page·¢ÏÖATTKÊܵ½·ì϶£¨CVE-2019-9491£©µÄÓ°Ï죬£¬£¬£¬£¬£¬ £¬Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ÔÚÒ»ÑùµÄĿ¼ÖÐÖ²ÈëÃûΪcmd.exe»òRegedit.exeµÄ¶ñÒâÎļþÀ´ÒÔÌáÉýµÄÌØÈ¨Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¸Ã·ì϶ÔÚÈ¥Äê10Ôµİ汾1.62.0.1223ÖнøÐÐÁ˽¨²¹£¬£¬£¬£¬£¬£¬ £¬µ«×êÑÐÈËÔ±Stefan Kanthak·¢ÏÖÁËÆäËüÈýÖÖÀàËÆµÄ¹¥»÷²½Ö裨Ô̺¬CVE-2019-20358ºÍCVE-2019-20358£©£¬£¬£¬£¬£¬£¬ £¬Ç÷Ïò¿Æ¼¼ÔÚÉÏÖܰ䲼ÁËа汾1.62.0.1228½¨¸´ÕâЩ·ì϶¡£¡£¡£¡£¡£ÀûÓÃÕâЩ·ì϶±ØÒªÎïÀí»òÔ¶³Ì½Ó¼ûÖ¸±êϵͳ£¬£¬£¬£¬£¬£¬ £¬µ«Ç÷Ïò¿Æ¼¼½¨Òé¿Í»§¾¡¿ì×°Öò¹¶¡¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/trend-micro-patches-more-vulnerabilities-anti-threat-toolkit


4.ºÚ¿Í»ý¼«ÀûÓÃNSC²úÆ··ì϶ɨÃè²¢½Ù³ÖÖÇÄÜÃŽûϵ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾Ý°²È«³§ÉÌSonicWallµÄÒ»·Ý»ã±¨£¬£¬£¬£¬£¬£¬ £¬ºÚ¿ÍÔÚ»ý¼«ÀûÓ÷ì϶£¨CVE-2019-7256£©À´ËÑË÷²¢½Ù³Ö»¥ÁªÍøÉϵÄÖÇÄÜÃŽûϵͳ£¬£¬£¬£¬£¬£¬ £¬²¢ÓÃÓÚÌáÒéDDoS¹¥»÷¡£¡£¡£¡£¡£¹¥»÷Õß¶Ô×¼µÄÉ豸ÊÇNortek°²È«Óë½ÚÔ죨NSC£©²úÆ·Linear eMerge E3£¬£¬£¬£¬£¬£¬ £¬¸Ã²úÆ·±»¹éΪӲ¼þÀà±ð¡°½Ó¼û½ÚÔìϵͳ¡±£¬£¬£¬£¬£¬£¬ £¬³£±»×°ÖÃÔÚ¹«Ë¾×ܲ¿¡¢¹¤³§»ò¹¤ÒµÔ°ÇøÖС£¡£¡£¡£¡£2019Äê5ÔÂApplied RiskÅû¶ÁËÓйØÓ°ÏìNSC Linear eMerge E3É豸µÄÊ®¸ö·ì϶µÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬ £¬Ö»¹ÜÓÐÁù¸ö·ì϶µÄÑϳÁÐÔ£¨CVSSv3£©µÃ·ÖΪ9.8»òÂú·Ö10·Ö£¬£¬£¬£¬£¬£¬ £¬µ«NSCδÄÜÌṩ²¹¶¡¡£¡£¡£¡£¡£ºÚ¿ÍÔÚÀûÓõķì϶ÊÇÆäÖеÄÒ»¸öÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2019-7256£©£¬£¬£¬£¬£¬£¬ £¬ÆäCVSSv3µÃ·ÖΪ10·Ö¡£¡£¡£¡£¡£×êÑÐÈËԱͨ¹ýShodanËÑË÷ÒýÇæ·¢ÏÖÓÐ2375¸öeMergeÉ豸¶³öÔÚ»¥ÁªÍøÉÏ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hackers-are-hijacking-smart-building-access-systems-to-launch-ddos-attacks/


5.ÐÂMagecart¹¥»÷º£³±ÖØÒªÕë¶Ôµç×ÓÉÌÎñÍø


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×êÑÐÈËÔ±·¢ÏÖÒ»¸öMagecart·¸×ïÍŻﲻ½öϰȾÁ˶«¾©°ÂÔË»áÃÅÆ±¾­ÏúÉ̵ÄÍøÕ¾£¬£¬£¬£¬£¬£¬ £¬»¹ÌáÒéÁËÕë¶Ôµç×ÓÉÌÎñÍøÕ¾µÄ¹¥»÷º£³±¡£¡£¡£¡£¡£ÉϸöÔ°²È«×êÑÐÔ±Jacob PimentalºÍMax Kersten·¢ÏÖ°ÂÔË»áÃÅÆ±¾­ÏúÉÌÍøÕ¾olympictickets2020[.]com¼°Å·ÖÞ±­ÃÅÆ±¾­ÏúÉÌÍøÕ¾eurotickets2020[.]com¾ùϰȾÁËMagecart´úÂ룬£¬£¬£¬£¬£¬ £¬¸Ã¶ñÒâ´úÂ뽫ËùÓб»µÁÐÅÏ¢·¢Ë͵½opendoorcdn[.]com¡£¡£¡£¡£¡£ÔÚ³ÖÐøµ÷²é¹ý³ÌÖУ¬£¬£¬£¬£¬£¬ £¬×êÑÐÈËÔ±·¢ÏÖ¶à¸öÍøÕ¾×ÔÈ¥Äê10ÔÂÒÔÀ´¾ùϰȾÁËͳһMagecart´úÂ룬£¬£¬£¬£¬£¬ £¬Ô̺¬supremeproducts[.]co.uk¡¢partsplaceinc[.]com¡¢zhik[.]comµÈ¡£¡£¡£¡£¡£¶ñÒâ´úÂëÓɶíÂÞ˹ÍйܷþÎñÌṩÉÌSelectelÍйÜ£¬£¬£¬£¬£¬£¬ £¬Ä¿Ç°OpendoorCDNÓòÃûÒѱ»ÔÝÍ£·þÎñ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/magecart-group-jumps-from-olympic-ticket-website-to-new-wave-of-e-commerce-shops/


6.ÔÚÏß¹¤×÷ÖÎÀíÍøÕ¾Trelloй¶´óÁ¿Óû§Êý¾Ý


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾ÝNaked SecurityµÄÒ»·Ý»ã±¨£¬£¬£¬£¬£¬£¬ £¬ÔÚÏß¹¤×÷ÖÎÀíÍøÕ¾Trelloй¶ÁË´óÁ¿Óû§µÄ¸öÈËÊý¾Ý£¬£¬£¬£¬£¬£¬ £¬Ô̺¬ÐÕÃû¡¢µØÖ·¡¢»úÄÜÆÀ¼¶ºÍ¹«Ë¾ÅàѵÊÓÆµµÈ¡£¡£¡£¡£¡£Ð¹Â¶µÄÔ­ÒòÊDz¿ÃÅÓû§ÃýÎ󵨽«ÆäTrelloÃæ°åÅäÖÃΪpublic£¬£¬£¬£¬£¬£¬ £¬ÕâʹµÃÈκÎÈ˶¼Äܹ»²é¿´ÆäÖеÄÄÚÈÝ£¬£¬£¬£¬£¬£¬ £¬ÉõÖÁGoogleÖ®ÀàµÄËÑË÷ÒýÇæÄܹ»½«Ãæ°åÖеÄÄÚ°üÈÝÈëË÷Òý£¬£¬£¬£¬£¬£¬ £¬½ö±ØÒªÍ¨¹ýÒ»ÖÖ³ÆÎª¡°dork¡±µÄÌØÊâÀàÐͼ´¿ÉËÑË÷µ½¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.techworm.net/2020/02/trello-search-exposes-private-data.html