¶íÂÞ˹µ±¾Ö°ä·¢³É¹¦½øÐл¥ÁªÍø¶Ï¿ª²âÊÔ£»ÃÀ¹ú»õÔË·þÎñTruckstop.comÔâµ½¶ñÒâÈí¼þ¹¥»÷

°ä²¼¹¦·ò 2019-12-25


1.¶íÂÞ˹µ±¾Ö°ä·¢³É¹¦½øÐл¥ÁªÍø¶Ï¿ª²âÊÔ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶íÂÞ˹µ±¾ÖÖÜÒ»°ä·¢³É¹¦½øÐл¥ÁªÍø¶Ï¿ª²âÊÔ¡£¸ÃÏî²âÊÔ´ÓÉÏÖÜÆðÍ·½øÐÐ £¬³ÖÐøÁ˶àÌì £¬Éæ¼°¶íÂÞ˹µ±¾Ö»ú¹¹¡¢±¾µØ»¥ÁªÍø·þÎñÌṩÉ̺ͶíÂÞ˹±¾µØ»¥ÁªÍø¹«Ë¾¡£³¢ÊÔµÄÖ÷ÕÅÊDzâÊԸùú¶ÈµÄ»¥ÁªÍø»ù´¡ÉèÊ©£¨ÔÚ¶íÂÞ˹ÄÚ²¿³ÆÎªRuNet£©ÊÇ·ñÄܹ»ÔÚ²»½Ó¼ûÈ«ÇòDNSϵͳºÍ±í²¿»¥ÁªÍøµÄÇé¿öÏÂÔËÐС£»¥ÁªÍøÁ÷Á¿ÔÚ¶íÂÞ˹ÄÚ²¿½øÐÐÁ˳ÁзÓÉ £¬ÓÐЧµØÊ¹¶íÂÞ˹µÄRuNet³ÉΪÊÀ½çÉÏ×î´óµÄÄÚÁªÍø¡£µ±¾ÖûÓÐй©ÓйزâÊÔ¼°Æä×é¼þµÄÈκμ¼Êõϸ½Ú £¬Ö»ÊÇÅú×¢µ±¾Ö²âÊÔÁ˼¸ÖÖ¶Ï¿ªÏνӵij¡¾° £¬Ô̺¬·ÂÕÕ¹ú±íÍøÂç¹¥»÷µÄ³¡¾°¡£µ±¾ÖÔÚ°ä²¼»áÉϰµÊ¾¸Ã³¢ÊÔ»ñµÃÁ˳ɹ¦¡£


  Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/russia-successfully-disconnected-from-the-internet/


2.Chromeä¯ÀÀÆ÷ÊÜÐÂMagellan 2.0·ì϶ӰÏì


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ò»×éеÄSQLite·ì϶Äܹ»Ê¹¹¥»÷ÕßÔÚChromeä¯ÀÀÆ÷ÖÐÔ¶³ÌÖ´ÐжñÒâ´úÂë¡£¸Ã×é·ì϶¹²ÓÐ5¸ö£¨CVE-2019-13734 £¬CVE-2019-13750~CVE-2019-13753£© £¬±»³ÆÎªMagellan 2.0·ì϶¡£ÕâЩ·ì϶ÊÇÓÉ´¦ÖÃSQLiteÊý¾Ý¿â´ÓµÚÈý·½½Ó¹Üµ½µÄSQLºÅÁîʱµÄÊäÈëÑéÖ¤²»ÕýÈ·ÒýÆðµÄ¡£×êÑÐÍŶӰµÊ¾Magellan 2.0·ì϶¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÓעй©·¨Ê½ÄÚ´æ»òµ¼Ö·¨Ê½±ÀÀ£¡£¹È¸èÒѾ­ÔÚChrome 79.0.3945.79Öн¨¸´Á˸÷ì϶¡£


 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-chrome-impacted-by-new-magellan-2-0-vulnerabilities/


3.NVIDIA°ä²¼GFE°²È«¸üР£¬½¨¸´Ò»¸öÌáȨ·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


NVIDIA°ä²¼Windows GeForce Experience£¨GFE£©Èí¼þµÄ°²È«¸üР£¬½¨¸´Ò»¸ö¿Éµ¼ÖÂDZÔÚ±¾µØ¹¥»÷Õß´¥·¢»Ø¾ø·þÎñ»òÌØÈ¨ÌáÉýµÄ°²È«·ì϶¡£¸Ã·ì϶£¨CVE-2019-5702£©µÄCVSS V3ÆÀ·ÖΪ8.4 £¬Ó°ÏìÁËGFE 3.20.2֮ǰµÄ°æ±¾¡£Ö»¹Ü´Ë·ì϶ҪÇó¹¥»÷ÕßÓµÓб¾µØÓû§½Ó¼ûȨÏÞ²¢ÇÒ²»Äܱ»Ô¶³ÌÀûÓà £¬µ«ÈÔÄܹ»Í¨¹ýÔÚϵͳÉÏÔ¶³Ì¿ªÊͶñÒ⹤¾ßÀ´ÀÄÓÃËü¡£Æ¾¾ÝNVIDIAµÄ˵·¨ £¬¸Ã·ì϶µÄÀûÓÃÄÑ¶È½ÏµÍ £¬Ö»±ØÒªºÜÉÙµÄÌØÈ¨²¢ÇÒÎÞÐèÓû§½»»¥¡£½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nvidia-patches-high-severity-vulnerability-in-geforce-experience/


4.P2P½©Ê¬ÍøÂçMoziÖØÒªÕë¶ÔÍø¼þ¡¢D-LinkºÍ»ªÎªÂ·ÓÉÆ÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖÐÂP2P½©Ê¬ÍøÂçMoziÔÚ»ý¼«Õë¶ÔÍø¼þ¡¢D-LinkºÍ»ªÎªµÄ·ÓÉÆ÷¡£¸Ã½©Ê¬ÍøÂçÓë¶ñÒâÈí¼þGafgytÓÐ¹Ø £¬ÓÉÓÚËü³ÁÓÃÁ˺óÕߵIJ¿ÃÅ´úÂë¡£MoziµÄÖØÒªÖ÷ÕÅÊÇÓÃÓÚDDoS¹¥»÷¡£×êÑÐÈËÔ±·¢Ïָý©Ê¬ÍøÂçʹÓÃÒ»ÖÖ¶¨ÔìµÄÀ©´óÉ¢²¼Ê½¹þÏ£±í£¨DHT£©ºÍ̸À´ÊµÏÖ £¬¸ÃºÍ̸ͨ³£±»torrent¿Í»§¶ËºÍÆäËûP2Pƽ̨ÓÃÓÚ´æ´¢½ÚµãÁªÏµÐÅÏ¢¡£Mozi»¹Ê¹ÓÃECDSA384ºÍXORËã·¨À´È·±£½©Ê¬ÍøÂç×é¼þºÍP2PÍøÂçµÄÆëÈ«ÐԺͰ²È«ÐÔ¡£MoziÖØÒªÍ¨¹ýtelnetÀûÓÃÈõÃÜÂë½Ó¼ûÒ×Êܹ¥»÷µÄÉ豸 £¬²¢ÔÚ¼ÓÔØ¶ñÒâÈí¼þºóËÑË÷ºÍϰȾÆäËüÒ×Êܹ¥»÷µÄÉ豸¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-mozi-p2p-botnet-takes-over-netgear-d-link-huawei-routers/


5.ÀÕË÷Èí¼þMaze¹¥»÷ÅíÈø¿ÆÀ­Êв¢ÀÕË÷100ÍòÃÀÔª


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÀÕË÷Èí¼þMaze±³ºóµÄ¹¥»÷Õß°ä²¼Á˾ݳÆÊÇ´ÓÅíÈø¿ÆÀ­ÊÐÇÔÈ¡µÄ2GBÎļþ¡£±¾Ô³õÅíÈø¿ÆÀ­ÊÐÔâ·êÀÕË÷Èí¼þ¹¥»÷ £¬Æäµç×ÓÓʼþ·þÎñ¡¢µç»°·þÎñµÈ¾ùÊÜÓ°Ïì £¬ÆäʱMaze¹¥»÷ÕßÌá³ö100ÍòÃÀÔªµÄÊê½ðÒªÇó £¬µ«ÅíÈø¿ÆÀ­ÊÐûÓÐÈ·ÈÏÕâÒ»ÐÂÎŲ¢°µÊ¾¸ÃÊÐÔÚ´Ó±¸·ÝÖлºÂý¸´Ô­¡£Maze¹¥»÷Õß°µÊ¾´Ó¸ÃÊÐÇÔÈ¡ÁË32GBµÄÎļþ £¬²¢°ä²¼ÁË2GBµÄÎļþ×÷Ϊ֤Ã÷¡£ÅíÈø¿ÆÀ­ÊÐÉÐδ¶Ô´Ë½øÐлØÓ¦¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/maze-ransomware-releases-files-stolen-from-city-of-pensacola/


6.ÃÀ¹ú»õÔË·þÎñTruckstop.comÔâµ½¶ñÒâÈí¼þ¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹ú»õÔË·þÎñ¹«Ë¾Truckstop.comÔâµ½¶ñÒâÈí¼þ¹¥»÷ £¬¶à¸öÔÚÏß·þÎñÖжÏ¡£Truckstop.comÓÚ12ÔÂ21ÈÕ£¨ÐÇÆÚÁù£©¹«¿ªÃ÷ÖªÓû§Æä¡°Óöµ½¼¼ÊõÎÊÌ⡱ £¬²¢ÖÂÁ¦ÓÚ¾¡¿ì½â¾ö¸ÃÎÊÌâ¡£ÔÚ12ÔÂ23ÈÕÐÇÆÚÒ»µÄÉêÃ÷ÖÐ £¬Truckstop.com°µÊ¾ÖжÏÊÇ¡°ÓɶñÒâÈí¼þÒýÆðµÄ¡± £¬µ«Ã»ÓÐй©ÊÇ·ñÓпͻ§ÐÅÏ¢±»Ð¹Â¶¡£½ØÖÁ12ÔÂ22ÈÕÐÇÆÚÈÕ £¬ÖÁÉÙ7¸öÊôÓÚTruckstop.comµÄÕ¾µã±»¹Ø¹ØÁË £¬Ô̺¬»õÎï×°ÔØ·þÎñ¡¢³ÐÔËÈË·þÎñ¡¢°²È«ºÏ¹æ·þÎñSaferWatch¡¢ÍÐÊÕ±£¸¶·þÎñ¡¢RFP¹¤¾ßºÍʵʱ»õÔË·þÎñµÈ¡£


 Ô­ÎÄÁ´½Ó£º

https://finance.yahoo.com/news/malware-hits-truckstop-com-sites-175226734.html