FBI°ä²¼2019Ä껥ÁªÍø·¸×ï»ã±¨£»£»£»£»£»2019ÄêÊý¾Ýй©»ã±¨£»£»£»£»£»Ó¢Ìضû½¨¸´CSME°²È«ÒýÇæÖеÄÌáȨ·ì϶
°ä²¼¹¦·ò 2020-02-131.FBI°ä²¼2019Ä껥ÁªÍø·¸×ï»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬Ôì³ÉËðʧ´ï35ÒÚÃÀÔª
ƾ¾Ý±¾ÖܶþFBI°ä²¼µÄ2019Äê¡¶»¥ÁªÍø·¸×ï»ã±¨¡·£¬£¬£¬£¬£¬£¬£¬£¬2019ÄêÆóÒµºÍÓ×ÎÒÒòÍøÂç·¸×ïÔì³ÉµÄËðʧ´ï35ÒÚÃÀÔª£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖнöBECÚ¿Æ£¨ÓÖ³ÆEAC£¬£¬£¬£¬£¬£¬£¬£¬µç×ÓÓʼþÕË»§ÈëÇÖ£©¾Í¸øÈËÃÇÔì³ÉÁË17ÒÚÃÀÔªµÄËðʧ¡£¡£¡£¡£¡£¸Ã»ã±¨³Æ£¬£¬£¬£¬£¬£¬£¬£¬2019ÄêÈËÃÇÏòFBI»ã±¨ÁË467361ÆðÍøÂç·¸×ïͶËߣ¬£¬£¬£¬£¬£¬£¬£¬¾ùÔÈÿÌì½ü1300Æð£¬£¬£¬£¬£¬£¬£¬£¬±ÈÉÏÒ»ÄêÔö³¤Á˳¬¹ý10ÍòÆð¡£¡£¡£¡£¡£×î³£»ã±¨µÄͶËßÊÇÍøÂç´¹µöºÍÀàËÆµÄȦÌס¢Î´¸¶¿î/δËÍ»õÚ¿ÆÒÔ¼°Ú²ÆÀÕË÷¡£¡£¡£¡£¡£ÍøÂç·¸×ï·Ö×Ó³ÖÐøÊ¹ÓÃÀÕË÷Èí¼þ¹¥»÷¹«Ë¾ºÍµ±¾Ö»ú¹¹£¬£¬£¬£¬£¬£¬£¬£¬¸Ã»ã±¨ÏÔʾֻ¹ÜÈ¥ÄêÀÕË÷Èí¼þ¹¥»÷µÄÊýÁ¿ÓÐËùÏ÷¼õ£¬£¬£¬£¬£¬£¬£¬£¬µ«ËðʧµÄ×ܶîÈ´ÓÐËùÔö³¤£¬£¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þµÄÊýÁ¿ÔÚÔö³¤¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/fbi-3-5b-lost-in-2019-to-known-cyberscams-ransomware/152815/
2.Risk Based Security°ä²¼2019ÄêÊý¾Ýй©»ã±¨
Risk Based Security°ä²¼2019ÄêµÄÊý¾Ýй©»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬»ã±¨ÏÔʾ2019ÄêÓг¬¹ý151ÒڱʼÍ¼й¶£¬£¬£¬£¬£¬£¬£¬£¬ÓëÉÏÒ»Äê¶È£¨Ð¹Â¶¼Í¼Ϊ53ÒÚÌõ£©Ïà±È´ó·ùÔö³¤284£¥¡£¡£¡£¡£¡£ÆäÖÐ135ÒڱʼͼÊÇͨ¹ýÍøÂçй¶µÄ£¨Ô̺¬ÎÞÒâÖÐÔÚÍøÉ϶³ö£©£¬£¬£¬£¬£¬£¬£¬£¬Áí±íÓÐ15ÒڱʼͼÊÇÓÉÓںڿ͹¥»÷й¶µÄ£¬£¬£¬£¬£¬£¬£¬£¬ÆäËüÀàÐ͵ÄÊÂÎñºÏÆðÀ´Ð¹Â¶ÁË1.2Òڱʼͼ¡£¡£¡£¡£¡£2019Ä깫¿ª»ã±¨µÄÊý¾Ýй¶ÊÂÎñÊýÁ¿Îª7098´Î£¬£¬£¬£¬£¬£¬£¬£¬Óë2018Äê»ã±¨µÄ7035´ÎÏà±È½öÔö³¤ÁË1£¥¡£¡£¡£¡£¡£ºÚ¿ÍÈëÇÖÕ¼¹«¿ª»ã±¨µÄÊý¾Ýй¶ÊÂÎñµÄ5184Æð£¬£¬£¬£¬£¬£¬£¬£¬¶ø»ã±¨µÄÍøÂçÊÂÎñÖ»ÓÐ343Æð¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/over-151-billion-records-exposed-data-breaches-2019
3.ºÚ¿Í¿ÉÀûÓó¬¹ý1.2Íò¸öJenkins·þÎñÆ÷ÌáÒéDDoS·Å´ó¹¥»÷
Radware×êÑÐÈËÔ±·¢ÏÖºÚ¿Í¿ÉÀûÓÃ1.2Íò¶ą̀¶³öÔÚ»¥ÁªÍøÉϵÄJenkins·þÎñÆ÷ÌáÒéDDoS·Å´ó¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÔÒòÊÇÕâЩ·þÎñÆ÷ÉÐδװÖ÷ì϶£¨CVE-2020-2100£©µÄ½¨¸´²¹¶¡¡£¡£¡£¡£¡£¸Ã·ì϶Óɽ£ÇÅ´óѧµÄAdam Thorn·¢ÏÖ²¢Åû¶£¬£¬£¬£¬£¬£¬£¬£¬ËüÊÇÓÉĬÈÏÇé¿öÏÂÆôÓò¢ÔÚÃæÏò¹«¼ÒµÄ·þÎñÆ÷Öй«¿ªµÄÍøÂç·¢ÏÖ·þÎñ£¨UDP¶à²¥/¹ã²¥£©ÒýÆðµÄ¡£¡£¡£¡£¡£¸Ã·ì϶ʹ¹¥»÷ÕßÄܹ»Í¨¹ýÔÚ¶Ë¿ÚUDP/33848ÉÏ·´ÉäUDPÒªÇóÀ´ÀÄÓÃJenkins·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÔ̺¬JenkinsÔªÊý¾ÝµÄDDoS·Å´ó¹¥»÷¡£¡£¡£¡£¡£Á½ÖÜǰ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÒÑÔÚJenkins 2.219ºÍLTS 2.204.2Öн¨¸´£¬£¬£¬£¬£¬£¬£¬£¬²½ÖèÊÇĬÈϽûÓÃJenkinsµÄÁ½¸öÍøÂç·¢ÏÖ·þÎñ£¨UDP¶à²¥/¹ã²¥ºÍDNS¶à²¥£©¡£¡£¡£¡£¡£µ«ÈÔÓÐ1.2Íò¶ą̀·þÎñÆ÷δװÖý¨¸´²¹¶¡£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ·þÎñÆ÷ÖØÒªÉ¢²¼ÔÚÑÇÖÞ£¬£¬£¬£¬£¬£¬£¬£¬Å·Ö޺ͱ±ÃÀ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/02/11/cve-2020-2100/
4.Ó¢ÌØ¶û½¨¸´CSME°²È«ÒýÇæÖеÄÌáȨ·ì϶
Ó¢ÌØ¶û½¨¸´CSME°²È«ÒýÇæÖеÄÒ»¸öÑϳÁ·ì϶£¨CVE-2019-14598£©£¬£¬£¬£¬£¬£¬£¬£¬²¢¶½´ÙÓû§¾¡¿ì¸üС£¡£¡£¡£¡£Æ¾¾ÝÓ¢ÌØ¶û±¾Öܶþ°ä²¼µÄ°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬£¬CSME¹Ì¼þÖдæÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬±¾µØ¹¥»÷Õß¿ÉÀûÓø÷ì϶ÌáÒéÌØÈ¨Éý¼¶¡¢»Ø¾ø·þÎñºÍÐÅϢй¶¹¥»÷¡£¡£¡£¡£¡£¸Ã·ì϶µÄCVSS¸ù»ùµÃ·ÖΪ8.2£¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁË12.0.49£¨½öÔ̺¬IOT£º12.0.56£©¡¢13.0.21ºÍ14.0.11֮ǰµÄCSME°æ±¾¡£¡£¡£¡£¡£Ó¢Ìضû½¨ÒéÓû§½«ÏµÍ³Ôì×÷ÉÌÌṩµÄCSME°æ±¾¸üÐÂΪ12.0.49¡¢13.0.21ºÍ14.0.11»ò¸ü¸ß°æ±¾ÒÔ½â¾ö´ËÎÊÌâ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/intel-warns-of-critical-security-flaw-in-csme-engine/
5.Adobe°ä²¼2Ô°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´35¸öÑϳÁ·ì϶
AdobeÔÚ2Ô°²È«¸üÐÂÖн¨¸´ÁË40¶à¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ35¸öΪÑϳÁ¼¶±ð¡£¡£¡£¡£¡£Æ¾¾ÝAdobe°ä²¼µÄ°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬£¬´óÎÞÊý·ì϶¶¼ÓëÎĵµ´¦Ö÷¨Ê½Adobe FramemakerÓйء£¡£¡£¡£¡£WindowsϵͳÉϵÄAdobe Framemaker°æ±¾2019.0.4¼°¸üµÍ°æ±¾×ܹ²Êܵ½21¸ö·ì϶µÄÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬ËùÓÐÕâЩ·ì϶¾ù±»ÊÓΪÑϳÁ¼¶±ð¡£¡£¡£¡£¡£·ì϶ÁìÓòº¸Ç»º³åÇøÒç³ö¡¢¶ÑÒç³ö¡¢Ô½½çдºÍÄÚ´æ°Ü»µµÈ£¬£¬£¬£¬£¬£¬£¬£¬ÈκÎÒ»¸öÎÊÌâ¶¼¿ÉÄܵ¼ÖÂËÁÒâ´úÂëÖ´ÐС£¡£¡£¡£¡£³ý´ËÖ®±í£¬£¬£¬£¬£¬£¬£¬£¬WindowsºÍmacOSÉϵÄAdobe Acrobat DC¡¢Reader DC¡¢Acrobat/Reader 2017ºÍAcrobat/Reader 2015ÖÐ×ܹ²½¨¸´ÁË12¸öÑϳÁ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐлòËÁÒâÎļþдÈë¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/adobe-addresses-over-40-vulnerabilities-many-critical-in-patch-update/
6.ÑÅÊ«À¼÷ìÔÆÊý¾Ý¿â¶³ö4.4ÒÚÌõÄÚ²¿¼Í¼
°²È«×êÑÐÔ±Jeremiah Fowler·¢ÏÖÑÅÊ«À¼÷ìµÄÒ»¸öÔÆÊý¾Ý¿âδÉèÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂ4.4ÒÚÌõÄÚ²¿¼Í¼й¶£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬´¿Îı¾µç×ÓÓʼþµØÖ·£¨Ô̺¬À´×Ô@estee.comÓòµÄÄÚ²¿µç×ÓÓʼþµØÖ·£©ºÍCMS¡¢ÖÐÑë¼þµÄ»î¶¯ÈÕÖ¾µÈÄÚÈÝ¡£¡£¡£¡£¡£µ«¼Í¼ÖÐûÓÐÔ̺¬¿Í»§µÄ¸¶¿îÊý¾Ý»òÃô¸ÐµÄÔ±¹¤ÐÅÏ¢¡£¡£¡£¡£¡£FowlerÖ¸³öÕâЩÈÕÖ¾Êý¾ÝÄܹ»ÓÃ×÷¸ü´óµÄÍøÂç¹¥»÷µÄ¿úËÅ£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçÈÕÖ¾ÖÐÔ̺¬IPµØÖ·¡¢¶Ë¿Ú¡¢õè¾¶ºÍ´æ´¢ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚÓ³É乫˾µÄÄÚ²¿ÍøÂç¡£¡£¡£¡£¡£ÑÅÊ«À¼÷ìÔÚ½Óµ½»ã±¨ºóµ±Ìì¹Ø¹ØÁ˶ÔÊý¾Ý¿âµÄ½Ó¼û£¬£¬£¬£¬£¬£¬£¬£¬µ«Ä¿Ç°Éв»Ã÷ÏÔ¸ÃÊý¾Ý¿âÔÚÍøÂçÉ϶³öÁ˶೤¹¦·òÒÔ¼°ÊÇ·ñÒÑÔâµ½ºÚ¿Í½Ó¼û¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/estee-lauder-440m-records-email-network-info/152789/


¾©¹«Íø°²±¸11010802024551ºÅ