ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ10ÖÜ
Ðû²¼Ê±¼ä 2019-03-11±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ΢ÈíÐû²¼Çå¾²±¨¸æVolume 24£¬£¬2018Äê´¹ÂÚ¹¥»÷ÔöÌí250£¥£»£»£»£»Ñо¿Åú×¢2018Ä걬·¢12449ÆðÊý¾Ýй¶ÊÂÎñ£¬£¬±È2017ÄêÔöÌí424%£»£»£»£»Dalil¹«Ë¾MongoDB¿É¹ûÕæ»á¼û£¬£¬500¶àÍòÓû§Êý¾Ýй¶£»£»£»£»2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾ÖУ¬£¬WordPressÕ¼90%£»£»£»£»Ñо¿ÍŶӷ¢Ã÷2Ô·ÝÀÕË÷Èí¼þShadeµÄ¹¥»÷»î¶¯ìÉý¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£
Ö÷ÒªÇå¾²Îó²îÁбí
Cisco NX-OS Software CLIÑéÖ¤²ÎÊý±£´æÇå¾²Îó²î£¬£¬ÔÊÐíÍâµØ¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ÌáÉýȨÏÞÖ´ÐÐí§ÒâosÏÂÁî¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-cmdinj-1610
2. Google Chrome FileReaderÊͷźóʹÓôúÂëÖ´ÐÐÎó²î
Google Chrome FileReaderµÄʵÏÖ±£´æÊͷźóʹÓÃÎó²î£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâWEBÒ³£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html
3. Adobe ColdFusion CVE-2019-7816ÎļþÉÏ´«ÏÞÖÆÈÆ¹ýÎó²î
Adobe ColdFusionÎļþÉÏ´«ÊµÏÖ±£´æÇå¾²Îó²î£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ÉÏ´«í§ÒâÎļþ£¬£¬²¢Ö´ÐС£¡£¡£
https://helpx.adobe.com/security/products/coldfusion/apsb19-14.html
4. Samsung Galaxy S9Éí·ÝÑéÖ¤´úÂëÖ´ÐÐÎó²î
Samsung Galaxy S9 GameServiceReceiver¸üлúÖÆ±£´æÇå¾²Îó²î£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-19-255/
5. Nokia Alcatel Lucent I-240W-Q GPON ONT CVE-2019-3922»º³åÇøÒç³öÎó²î
Nokia Alcatel Lucent I-240W-Q GPON ONT´¦Öóͷ£ÌØÊâµÄHTTP POSTÇëÇó±£´æÇå¾²Îó²î£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://www.tenable.com/security/research/tra-2019-09
Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö

ƾ֤΢ÈíµÄÇå¾²Ç鱨±¨¸æ£¨SIR£©Volume 24£¬£¬ÔÚ2018Äê1ÔÂÖÁ12ÔÂʱ´ú£¬£¬ÍøÂç´¹ÂÚ¹¥»÷ÔöÌíÁË250%¡£¡£¡£¹¥»÷ÕßÔÚÔËÓªÍøÂç´¹Âڻʱ½ÓÄɶàÑù»¯µÄ»ù´¡ÉèÊ©£¬£¬°üÀ¨ÍйÜЧÀÍÆ÷ºÍ¹«¹²ÔƵȡ£¡£¡£ÁíÒ»·½Ã棬£¬2018Äêʱ´ú¶ñÒâÈí¼þµÄÊýĿϽµÁËÔ¼34%¡£¡£¡£±ðµÄ£¬£¬Ëæ×Å2018ÄêÄêβ¼ÓÃÜÇ®±Ò¼ÛÇ®µÄϵø£¬£¬¶ñÒâÍÚ¿ó»î¶¯Ò²Ï½µÁË36%¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-sees-250-percent-phishing-increase-malware-decline-by-34-percent/
2¡¢Ñо¿Åú×¢2018Ä걬·¢12449ÆðÊý¾Ýй¶ÊÂÎñ£¬£¬±È2017ÄêÔöÌí424%
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/12-449-data-breaches-confirmed-in-2018-a-424-percent-increase-over-the-previous-year/
3¡¢Dalil¹«Ë¾MongoDB¿É¹ûÕæ»á¼û£¬£¬500¶àÍòÓû§Êý¾Ýй¶
ÔÎÄÁ´½Ó£º
https://www.vpnmentor.com/blog/dalil-data-breach/
4¡¢2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾ÖУ¬£¬WordPressÕ¼90%
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/wordpress-accounted-for-90-percent-of-all-hacked-cms-sites-in-2018/
5¡¢Ñо¿ÍŶӷ¢Ã÷2Ô·ÝÀÕË÷Èí¼þShadeµÄ¹¥»÷»î¶¯ìÉý
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/threat-analysis/2019/03/spotlight-troldesh-ransomware-aka-shade/
ÉùÃ÷£º±¾×ÊѶÓÉ¿Ðý¹ú¼ÊÓÎϷάËûÃüÇ徲С×é·ÒëºÍÕûÀí