OpenSMTPDÐÂRCE·ì϶£¬Ó°Ïì¶à¸öLinux¿¯Ðа棻ÃÀ¹úµçÁ¦¹©¸øÉÌRMLDÔâÀÕË÷Èí¼þ¹¥»÷
°ä²¼¹¦·ò 2020-02-261.OpenSMTPDÐÂRCE·ì϶£¬Ó°Ïì¶à¸öLinux¿¯Ðаæ
°²È«×êÑÐÈËÔ±ÔÚÓʼþ·þÎñÆ÷OpenSMTPDÖз¢ÏÖÒ»¸öеÄÑϳÁ·ì϶£¨CVE-2020-8794£©£¬¹¥»÷ÕßÄܹ»Ô¶³ÌÀûÓø÷ì϶ÒÔrootÓû§Éí·ÝÔËÐÐShellºÅÁî¡£OpenSMTPDÀûÓÃÔÚ¶à¸ö»ùÓÚUnixµÄϵͳÉÏ£¬Ô̺¬FreeBSD¡¢NetBSD¡¢macOS¡¢Linux£¨Alpine¡¢Arch¡¢Debian¡¢Fedora¡¢CentOS£©¡£¸Ã·ì϶ӰÏìÁËOpenSMTPDµÄĬÈÏ×°Öã¬Qualys×êÑÐÈËÔ±Ö¸³ö¸ÃÎÊÌâÊÇÔÚ2015Äê12ÔÂÒýÈëµÄ£¬µ«Ö»ÓÐÔÚ2018Äê5ÔÂÖ®ºó°ä²¼µÄOpenSMTPD°æ±¾ÉÏÄÜÁ¦¹»ÀûÓÃËüÒÔrootÌØÈ¨Ö´ÐдúÂë¡£OpenSMTPD 6.6.4p1ÖÐÒѾ½¨¸´Á˸÷ì϶£¬½¨ÒéÓû§¾¡¿ì×°ÖøüС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-critical-rce-bug-in-openbsd-smtp-server-threatens-linux-distros/
2.¹È¸è½¨¸´ChromeÖеÄÀàÐÍ»ìºÏ0day£¬ÒÑÔÚÒ°±íÀûÓÃ
¹È¸è½¨¸´ChromeÖеÄÒ»¸öÒÑÔÚÒ°±íÀûÓõÄ0day£¨CVE-2020-6418£©£¬ÕâÊÇ´ÓǰһÄêÖеÚÈý¸ö±»·¢´Ë¿ÌÒ°±íÀûÓõÄChrome 0day¡£¸Ã·ì϶±»ÃèÊöΪV8ÒýÇæÖеÄÀàÐÍ»ìºÏ·ì϶£¬ÓйؾßÌåÐÅÏ¢ÉÐδ¹«¿ª¡£¸Ã·ì϶µÄ½¨¸´²¹¶¡×÷ΪChrome°æ±¾80.0.3987.122µÄÒ»²¿ÃŰ䲼£¬Õâ¸ö¸üкÏÓÃÓÚWindows¡¢MacºÍLinuxÓû§£¬µ«²»ºÏÓÃÓÚChrome OS¡¢iOSºÍAndroidÓû§¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/google-patches-chrome-zero-day-under-active-attacks/
3.Å·ÖÞÍøÂçÓëÐÅÏ¢°²È«¾Ö°ä²¼Ò½ÔºÍøÂ簲ȫ²É¹ºÖ¸ÄÏ
Å·ÖÞÍøÂçÓëÐÅÏ¢°²È«¾Ö£¨ENISA£©°ä²¼Ò½ÔºÍøÂ簲ȫ²É¹ºÖ¸ÄÏ¡£¸ÃÖ¸ÄÏÖ¼ÔÚÔ®ÊÖÒ½ÔºÔڲɹºÐÂ×ʲúʱÂú×ãÐÅÏ¢°²È«·½ÃæµÄÒªÇó£¬ÌṩÁ˽«ÍøÂ簲ȫ×÷ΪҽԺ²É¹º¹ý³ÌÖÐÒ»Ïî»®¶¨µÄÓÅÁ¼Êµ¼ÊºÍ½¨Ò飬²¢ÇÒ½éÉÜÁËÒ½Ôº×ʲú¼¯ÖÐÒÔ¼°ÓëÖ®ÓйصÄ×î͹ÆðÍøÂ簲ȫÍþв¡£¸Ã»ã±¨ÖØÒªÕë¶ÔÔÚÒ½Ôºµ£Èμ¼ÊõÖ°ÎñµÄÒ½ÁƱ£½¡×¨ÒµÈËÔ±£¨CIO£¬CISO£¬CTO£¬ITÍŶÓÒÔ¼°Ò½ÁƱ£½¡×éÖ¯ÖеIJɹºÈËÔ±£©£¬²¢ÇÒ¿ÉÒÔΪҽÁÆÉ豸Ôì×÷ÉÌÌṩ²Î¿¼¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/02/25/cybersecurity-procurement-hospitals/
4.¿¨°Í˹»ù°ä²¼2019ÄêÒÆ¶¯¶ñÒâÈí¼þÑݱä»ã±¨
¿¨°Í˹»ù°ä²¼2019ÄêÒÆ¶¯¶ñÒâÈí¼þÑݱä»ã±¨£¬»ã±¨Ö¸³öÊÜstalkerware£¨¸ú×ÙÈí¼þ£©Ï°È¾µÄÓû§ÊýÁ¿´Ó2018ÄêµÄ40386ÈËÔö³¤µ½2019ÄêµÄ67500ÈË£¬ÔÚ2019ÄêÔö³¤Á˽ü40£¥¡£»ã±¨»¹·¢ÏÖ£º×Ô2018ÄêÒÔÀ´£¬¿¨°Í˹»ù¼ì²âµ½µÄ¸æ°×Èí¼þ×°ÖðüÊýÁ¿ÏÕЩ·ÁËÒ»·¬£»ÒÁÀÊÊÇÕ¼ÓÐ×î¶àAndroid¶ñÒâÈí¼þ¾¯±¨µÄ¹ú¶È£¬¿¨°Í˹»ùµÄËùÓÐÒÁÀÊÓû§ÖÐÓÐ60£¥ÔÚ2019ÄêÔÚÆäÊÖ»úÉÏ×°ÖÃÁ˶ñÒâÀûÓã»HiddenAd¸æ°×Èí¼þ¼Ò×åÊÇ2019Äê×îÊ¢ÐеĶñÒâÈí¼þÍþв¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/mobile-malware-evolution-2019/96280/
5.µÏ¿¨Ù¯Elasticsearch·þÎñÆ÷й¶1.23Òڼͼ
·¨¹úÌåÓýÁãÊÛ¾ÞÍ·µÏ¿¨Ù¯Ð¹Â¶³¬¹ý1.23ÒÚÌõ¿Í»§ºÍÔ±¹¤ÐÅÏ¢¼Í¼¡£2ÔÂ12ÈÕvpnMentor×êÑÐÍŶÓÔڸù«Ë¾µÄÒ»¸ö¿É¹«¿ª½Ó¼ûµÄElasticsearch·þÎñÆ÷ÉÏ·¢ÏÖÁËÕâЩÊý¾Ý£¬Êý¾Ý¿âµÄ×Ü´óÓ×Ϊ9GB£¬Ô̺¬µÏ¿¨Ù¯Î÷°àÑÀ·ÖµêÒÔ¼°¿ÉÄÜÊÇÓ¢¹ú·ÖµêµÄÐÅÏ¢¡£Ð¹Â©µÄÊý¾ÝÔ̺¬Ô±¹¤Óû§Ãû¡¢Î´¼ÓÃܵÄÃÜÂëÒÔ¼°Ó×ÎÒÉí·ÝÐÅÏ¢£¨PII£©£¬ÀýÈçÉç»á°²È«ºÅÂë¡¢ÐÕÃû¡¢µØÖ·¡¢ÊÖ»úºÅÂëºÍµ®ÉúÈÕÆÚ£¬»¹Ô̺¬Î´¼ÓÃܵĿͻ§µç×ÓÓʼþºÍµÇ¼ÐÅÏ¢¡£µÏ¿¨Ù¯ÔÚ2ÔÂ17ÈչعØÁ˶ÔÊý¾Ý¿âµÄ¹«¹²½Ó¼û¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/sports-giant-decathlon-leaks-123/
6.ÃÀ¹úµçÁ¦¹©¸øÉÌRMLDÔâÀÕË÷Èí¼þ¹¥»÷
ÂíÈøÖîÈûÖݵçÁ¦¹©¸øÉÌRMLDÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Æä¹ÙÍøhttp://rmld.comĿǰ²»³ÉÓ㬲¢ÇÒÎÞ·¨Ô¤¼Æ¾ßÌåµÄ¸´Ô¹¦·ò¡£RMLD°µÊ¾µçÁ¦·þÎñ²¢Î´Êܵ½¹¥»÷µÄÓ°Ï죬µçÍøÒÀÈ»°²È«£¬²¢ÇÒûÓм£ÏóÅú×¢¿Í»§µÄ²ÆÕþÊý¾ÝÊܵ½ÇÖº¦£¬µ«¹¥»÷ÖпÉÄܶ³öµÄ¿Í»§Êý¾ÝÔ̺¬ÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·ÒÔ¼°µçÁ¿Ê¹Óüͼ¡£RMLDÉÐδȷÈÏÀÕË÷Èí¼þÈôºÎ½øÈëÆäÍÆËã»úϵͳ£¬Ò²Ã»ÓÐ×¢Ã÷¹¥»÷ÕßÒªÇ󼸶àÊê½ð£¬µ«°µÊ¾»Ø¾øÖ§¸¶Êê½ð¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/ransomware-attack-at-us-power/


¾©¹«Íø°²±¸11010802024551ºÅ