ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ9ÖÜ
Ðû²¼Ê±¼ä 2019-03-04±¾ÖÜÇ徲̬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǽü7ÍòÕÅ°Í»ù˹̹ÒøÐп¨ÐÅÏ¢ÔÚ°µÍø³öÊÛ£¬ÊÛ¼Û½ü350ÍòÃÀÔª£»Èý¸ö4G/5GÎó²î£¬¿Éµ¼Ö¹¥»÷ÕßÈƹýÆä·À»¤Õ½ÂÔ£»Õë¶ÔInstagramÓû§µÄ¿ìËÙÖ¸»È¦Ì×£¬Õ©Æ½ð¶îÀۼƸߴï300ÍòÓ¢°÷£»Chrome 0dayÎó²î£¬¹¥»÷Õß¿Éͨ¹ýPDFÍøÂçÓû§ÐÅÏ¢£»CoinomiÇ®°üÃ÷ÎÄ´«ÊäÓû§ÃÜÂ룬µ¼ÖÂÔ¼7ÍòÃÀÔª±»ÇÔ¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
Ö÷ÒªÇå¾²Îó²îÁбí
Apache Airflow±à¼AirflowÔªÊý¾Ý¿âÖй¤¾ßµÄ״̬±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://lists.apache.org/thread.html/f656fddf9c49293b3ec450437c46709eb01a12d1645136b2f1b8573b@%3Cdev.airflow.apache.org%3E
2. F5 BIG-IPÑéÖ¤SSLÔ¶³Ì¾Ü¾ø·þÎñÎó²î
F5 BIG-IPÑéÖ¤SSL±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ɾÙÐоܾø·þÎñ¹¥»÷¡£
https://support.f5.com/csp/article/K54167061
3. Cisco RV110W/RV130W/RV215W Routers CVE-2019-1663Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î
Cisco?RV110W Wireless-N VPN Firewall¡¢RV130W Wireless-N Multifunction VPN RouterºÍRV215W Wireless-N VPN Router WEB½Ó¿Ú±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐí§Òâ´úÂë¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190227-rmi-cmd-ex
4. Linux kernel net/ipv4/netfilter/nf_nat_snmp_basic_main.cÔ½½ç¶ÁдÎó²î
Linux kernel net/ipv4/netfilter/nf_nat_snmp_basic_main.cûÓгä·Ö¼ì²éASN.1³¤¶È£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ɾÙÐоܾø·þÎñ¹¥»÷»òÖ´ÐÐí§Òâ´úÂë¡£
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c4c07b4d6fa1f11880eab8e076d3d060ef3f55fc
5. OpenSSLÇå¾²ÈƹýÐÅϢй¶Îó²î
OpenSSL±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÈƹýÇå¾²ÏÞÖÆ£¬»ñÈ¡Ãô¸ÐÐÅÏ¢¡£
https://www.openssl.org/news/secadv/20190226.txt
Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö

Group-IBÑо¿Ö°Ô±·¢Ã÷69189ÕÅ°Í»ù˹̹ÒøÐп¨µÄÐÅÏ¢ÔÚ°µÍøÉϳöÊÛ¡£ÕâÅúÊý¾Ý·ÖΪÁ½¸öÊý¾Ý¿â£¬×ÜÊÛ¼ÛԼΪ350ÍòÃÀÔª¡£µÚÒ»¸öÊý¾Ý¿âÊÇ1ÔÂβÔÚJoker's StashÉÏÐû²¼µÄ£¬¹²°üÀ¨1535ÕÅÒøÐп¨ÐÅÏ¢£¬ÆäÖÐ96£¥µÄÒøÐп¨¶¼ÓëMeezan BankÓйء£µÚ¶þ¸öÊý¾Ý¿âÊÇ1ÔÂ30ÈÕÔÚJoker's StashÉÏÐû²¼µÄ£¬°üÀ¨67654ÕÅÒøÐп¨ÐÅÏ¢£¬Í¬ÑùÓÐ96£¥µÄÒøÐп¨ÓëMeezan BankÓйء£ÕâЩÊý¾Ý¿ÉÄÜÅú×¢Îú¸ÃµØÇøÕë¶Ô½ðÈÚ»ú¹¹µÄ¹¥»÷ÕßµÄÔ˶¯¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/81579/cyber-crime/pakistani-banks-cards-darkweb.html
2¡¢Èý¸ö4G/5GÎó²î£¬¿Éµ¼Ö¹¥»÷ÕßÈƹýÆä·À»¤Õ½ÂÔ
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/02/location-tracking-imsi-catchers.html
3¡¢Õë¶ÔInstagramÓû§µÄ¿ìËÙÖ¸»È¦Ì×£¬Õ©Æ½ð¶îÀۼƸߴï300ÍòÓ¢°÷
ÔÎÄÁ´½Ó£º
https://cyware.com/news/new-get-rich-quick-scheme-costs-instagram-users-over-3-million-61d5d384
4¡¢Chrome 0dayÎó²î£¬¹¥»÷Õß¿Éͨ¹ýPDFÍøÂçÓû§ÐÅÏ¢
ÔÎÄÁ´½Ó£º
https://cyware.com/news/google-chrome-zero-day-vulnerability-could-allow-attackers-to-collect-user-information-via-pdf-files-01b8df3d
5¡¢CoinomiÇ®°üÃ÷ÎÄ´«ÊäÓû§ÃÜÂ룬µ¼ÖÂÔ¼7ÍòÃÀÔª±»ÇÔ
ÔÎÄÁ´½Ó£º
https://cyware.com/news/cryptocurrency-wallet-coinomi-sends-users-passwords-to-googles-spellchecker-in-plain-text-3b3b794c
ÉùÃ÷£º±¾×ÊѶÓÉÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøάËûÃüÇ徲С×é·ÒëºÍÕûÀí