ÃÀ¹úÄÜÔ´²¿°ä²¼2019ÄêQ1µçÁ¦ÍøÂ紹ΣÇé¿öºÍ×ÌÈŻ㱨£»PrinterLogic´òÓ¡ÖÎÀíÈí¼þ¶à¸ö·ì϶£¬¿Éµ¼ÖÂRCE

°ä²¼¹¦·ò 2019-05-06
1¡¢ÃÀ¹úÄÜÔ´²¿°ä²¼2019ÄêQ1µçÁ¦ÍøÂ紹ΣÇé¿öºÍ×ÌÈŻ㱨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
ƾ¾ÝÃÀ¹úÄÜÔ´²¿°ä²¼µÄ2019ÄêµÚÒ»¼¾¶ÈµçÁ¦ÍøÂ紹ΣÇé¿öºÍ×ÌÈŻ㱨£¬3ÔÂ5ÈÕÉÏÎç9:12µ½ÏÂÎç6:57ÆÚ¼ä±±ÃÀµçÍøÔâ·êµ½Ò»¸ö¡°µ¼ÖµçÁ¦ÏµÍ³ÔËÓªÖжϵÄÍøÂçÊÂÎñ¡±£¬ÊÜÓ°ÏìµÄµØÓòÔ̺¬¼ÓÖݵĿ˶÷ÏØºÍÂåɼí¶ÏØ¡¢ÓÌËûÖݵÄÑκþÏØºÍ»³¶íÃ÷ÖݵĿµ¸¥Ë¹ÏØ¡£Æ¾¾ÝÃÀ¹úÄÜÔ´²¿µÄ½ç˵£¬¡°ÍøÂçÊÂÎñ¡±ÊÇÖ¸¡°Î´ÊÚȨ½Ó¼û¡±µ¼ÖµÄÍøÂçÖжÏ£¬µ«Ã»Óиü¶àÐÅÏ¢Åú×¢¸ÃÊÂÎñÊÇÔ¶³ÌºÚ¿Í¹¥»÷»¹ÊÇÆóÒµÄÚ²¿µÄ¹¥»÷¡£´Óº¹ÇàÉÏ¿´£¬±±ÃÀµçÍø´ÓδÔâµ½ÍøÂç¹¥»÷µ¼ÖµķÛËé»òÖжÏ£¬ÈôÊÇʼþÊôʵ£¬ÕâÒ»ÊÂÎñ¿ÉÄܳÉΪº¹ÇàÐÔµÄÊÂÎñ¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.avast.com/western-us-power-grid-hit-by-cyber-event

2¡¢ºÚ¿Íͨ¹ý±©Á¦¹¥»÷ÊÕÊÜ29¸öIoT DDoS½©Ê¬ÍøÂç

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
ƾ¾ÝZDNet±¨Â·£¬ÃûΪSubbyµÄºÚ¿Íͨ¹ý±©Á¦¹¥»÷ÊÕÊÜÁË29¸öIoT DDoS½©Ê¬ÍøÂç¡£SubbyʹÓÃÁËÓû§Ãû×ÖµäºÍ³£ÓÃÃÜÂëÁбíÀ´¶ÔÕâ29¸ö½©Ê¬ÍøÂçµÄC&C»ù´¡ÉèÊ©½øÐб©Á¦¹¥»÷£¬ÆäÖÐһЩÉèʩʹÓÃÁ˱ÈÁ¦ÈõµÄÍ´´¦£¬ÀýÈçroot:root¡¢admin:admin¡¢oof:oofµÈ¡£Æ¾¾ÝSubbyµÄ˵·¨£¬ÕâЩ½©Ê¬ÍøÂç¶¼±ÈÁ¦Ó×£¬ÏÖʵµÄbot×ÜÊý½öΪ2.5Íò¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/hacker-takes-over-29-iot-botnets/

3¡¢×êÑÐÍŶÓÖÒ¸æÕë¶ÔOffice 365ÕÊ»§µÄÊÕÊܺ£³±

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
ƾ¾ÝBarracuda NetworksµÄ·ÖÎö£¬3Ô·ÝÕë¶ÔÔÆµç×ÓÓÊÏäµÄATO£¨ÕË»§ÊÕÊÜ£©¹¥»÷¼¤Ôö£¬½öÔÚÒ»¸öÔÂÄÚ¹¥»÷Õß¾Íͨ¹ýÊýǧ¸öÊÜËðµÄOffice 365 ÕË»§·¢ËÍÁ˳¬¹ý150Íò·âÀ¬»øÓʼþ¡£×êÑÐÈËÔ±³ÆËùÓеĵ÷²é¶ÔÏóÖÐÓг¬¹ý1/4£¨29%£©µÄÆóÒµÔâµ½Õë¶ÔOffice 365ÕÊ»§µÄ¹¥»÷£¬ÕâЩ¹¥»÷Ô̺¬×²¿â¡¢±©Á¦¹¥»÷µÈ¡£¹¥»÷Õßͨ¹ýÊÜËðÕË»§½øÐÐÐÅÏ¢ÇÔÈ¡¡¢²ÆÕþÊý¾ÝÇÔÈ¡¡¢Éí·Ý͵ÇÔÒÔ¼°BECڲƭµÈ·½Ê½»ñµÃÀûÒæ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/researchers-warn-office-365-1/

4¡¢×êÑÐÈËÔ±·¢ÏÖ100¶à¸öJenkins²å¼þ´æÔÚ°²È«·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
NCC Group°²È«×êÑÐÔ±Viktor Gazdag·¢ÏÖ100¶à¸öJenkins²å¼þ´æÔÚ°²È«·ì϶¡£JenkinsÊÇÓÉCloudBeesºÍJenkinsÉçÇøÊØ»¤µÄ¿ªÔ´×Ô¶¯»¯·þÎñÆ÷£¬ËüÔÚÈ«ÇòÕ¼Óг¬¹ý100ÍòÓû§¡£Ò»Ð©Ò×Êܹ¥»÷µÄ²å¼þÊÇÓɵÚÈý·½¿ª·¢µÄ£¬ÓÃÓÚ½Ó¼ûTwitter¡¢AWSºÍAzureµÈ·þÎñ¡£×êÑÐÈËÔ±·¢ÏֵĴóÎÞÊý·ì϶¶¼ÊÇÃ÷ÎÄÃÜÂë´æ´¢¡¢CSRF·ì϶¡¢¶ÌȱȨÏ޲鳭µÈ¡£Jenkins¿ª·¢ÍŶÓÕë¶ÔÕâЩ·ì϶°ä²¼Á˰²È«²¼¸æ¡£

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/84910/hacking/jenkins-plugins-flaws.html

5¡¢PrinterLogic´òÓ¡ÖÎÀíÈí¼þ¶à¸ö·ì϶£¬¿Éµ¼ÖÂRCE

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
PrinterLogic´òÓ¡ÖÎÀíÈí¼þδÕýÈ·ÑéÖ¤ÆäSSLÖ¤ÊéºÍÈí¼þ¸üаüµÄÆðÔ´ºÍÆëÈ«ÐÔ£¬¿ÉÔÊÐí¹¥»÷Õß³ÁÐÂÅäÖÃÈí¼þ²¢Ô¶³ÌÖ´ÐдúÂ루CVE-2018-5408¡¢CVE-2018-5409£©¡£´Ë±í£¬PrinterLogicδ¶Ôä¯ÀÀÆ÷ÊäÈë½øÐÐÌØÊâ×Ö·û¹ýÂË£¬¿ÉÔÊÐíδ¾­ÊÚȨµÄÔ¶³Ì¹¥»÷Õ߸ü¸ÄÅäÖÃÎļþ£¨CVE-2019-9505£©¡£18.3.1.96¼°Ö®Ç°µÄ°æ±¾Ò×Êܹ¥»÷£¬½¨ÒéÓû§¾¡¿ì½øÐÐÉý¼¶¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.kb.cert.org/vuls/id/169249/

6¡¢½üÒ»°ëµÄÃÀ¹úÆóҵûÓÐΪ¼ÓÖÝÏû·ÑÕßÒþÖÔ·¨°¸×öºÃ³ï±¸

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
ÃÀ¹ú¼ÓÖݵÄÏû·ÑÕßÒþÖÔ·¨°¸£¨CCPA£©½«ÓÚ2020Äê1ÔÂ1ÈÕÉúЧ£¬µ«ºÜ¶àÃÀ¹úÆóÒµ²¢Î´¶Ô´Ë×öºÃ³ï±¸¡£Æ¾¾Ý¹ú¼ÊÒþÖÔר¼ÒЭ»á£¨IAPP£©ºÍOneTrustµÄÒ»Ïîµ÷ÑУ¬Ö»ÓÐ55%µÄÆóÒµ³Æ½«ÔÚ1ÔÂ1ÈÕ֮ǰ×öºÃ³ï±¸¡£CCPAÓëGDPRÀàËÆ£¬Í¨¹ýÂÉÀý½«ÒþÖԵĽÚÔìȨ½»¸øÏû·ÑÕߣ¬ÒªÇóÆóҵƾ¾ÝÍøÂçµÄÊý¾ÝΪÏû·ÑÕßÌṩ¡°ºÏ·¨¡±µÄÈ¨ÊÆ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/nearly-half-of-us-orgs-not-ready-1/