Ñо¿Ö°Ô±Åû¶±£´æ4ÄêµÄLinux Wi-Fi»º³åÇøÒç³öÎó²î£»£» £»CenturyLinkÒâÍâ̻¶280ÍòÌõ¿Í»§¼Í¼

Ðû²¼Ê±¼ä 2019-10-21
1¡¢Ñо¿Ö°Ô±Åû¶±£´æ4ÄêµÄLinux Wi-Fi»º³åÇøÒç³öÎó²î

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

GithubÊ×ϯÇå¾²¹¤³ÌʦNico Waisman·¢Ã÷Linux rtlwifiÇý¶¯³ÌÐòÖб£´æÒ»¸ö¾ßÓÐ4ÄêÀúÊ·µÄÑÏÖØÎó²î£¨CVE-2019-17666£©£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÈëÇÖÒ×Êܹ¥»÷µÄϵͳ¡£¡£¡£¡£rtlwifiÇý¶¯³ÌÐòÓÃÓÚÔÊÐíRealtek Wi-FiÄ£¿£¿£¿£¿£¿£¿éÓëLinuxϵͳ¾ÙÐÐͨѶ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓó¤¶È²»×¼È·µÄÊý¾Ý°ü´¥·¢»º³åÇøÒç³ö£¬£¬£¬£¬£¬£¬£¬Ê¹µÃLinuxÍ߽⻣» £»òÊÇÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¾Ý³Æ¸ÃÎó²îÓ°ÏìÁËLinux°æ±¾5.3.6£¬£¬£¬£¬£¬£¬£¬¸ÃÎÊÌâ×Ô´Ó2015ÄêÒÔÀ´¾ÍÒ»Ö±±£´æ¡£¡£¡£¡£LinuxÄÚºËÍŶÓÒѾ­¿ª·¢ÁËÒ»¸öÕýÔÚÐÞ¶©µÄÐÞ¸´²¹¶¡£¬£¬£¬£¬£¬£¬£¬µ«¸Ã²¹¶¡ÉÐδ°üÀ¨ÔÚLinuxÄÚºËÖС£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/critical-linux-wi-fi-bug-system-compromise/149325/

2¡¢ºÚ¿Íͨ¹ýÐéα²å¼þupdrat123ÈëÇÖWordPressÍøÕ¾

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


SucuriÑо¿Ö°Ô±·¢Ã÷ºÚ¿ÍʹÓÃÐéαµÄWordPress²å¼þÀ´³äµ±ºóÃųÌÐò£¬£¬£¬£¬£¬£¬£¬ÏòÄ¿µÄÍøÕ¾ÉÏ´«Web Shell¼°±©Á¦ÆÆ½â¾ç±¾¡£¡£¡£¡£¸Ã²å¼þ±»ÃüÃûΪInitiatorseo»òupdrat123£¬£¬£¬£¬£¬£¬£¬Æä¿Ë¡ÁËÕýµ±²å¼þUpdraftPlusµÄ¹¦Ð§¡£¡£¡£¡£¸ÃÐéα²å¼þĬÈϲ»»áÏÔʾ£¬£¬£¬£¬£¬£¬£¬µ«¹¥»÷Õß¿Éͨ¹ý´øÓÐ×Ô½ç˵²ÎÊý£¨ÀýÈçinitiationactivity»òtestingkey£©µÄGETÇëÇó»á¼û¸Ã²å¼þ¡£¡£¡£¡£Ê¹ÓøúóÃÅ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýPOSTÇëÇóÏòÄ¿µÄЧÀÍÆ÷ÉÏ´«í§Òâ¶ñÒâÎļþ£¬£¬£¬£¬£¬£¬£¬°üÀ¨Web Shell¼°±©Á¦ÆÆ½â¾ç±¾µÈ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÊÜѬȾµÄÍøÕ¾»¹¿ÉÄܻᱻÓÃÓÚDDoS¡¢À¬»øÓʼþ·¢Ë͵ȶñÒâ»î¶¯¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-backdoor-sites-by-hiding-fake-wordpress-plugins/

3¡¢Spelevo EKÔÚй¥»÷»î¶¯Öзַ¢ÀÕË÷Èí¼þMaze

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

nao_sec·¢Ã÷Îó²îʹÓù¤¾ß°üSpelevoÔÚÒ»¸öеĶñÒâ»î¶¯ÖÐʹÓÃÀÕË÷Èí¼þMazeѬȾÊܺ¦Õß¡£¡£¡£¡£MazeÊÇÀÕË÷Èí¼þChachaµÄ±äÖÖ£¬£¬£¬£¬£¬£¬£¬Æä×î³õÓÚ5Ô·ݱ»MalwarebytesÇå¾²Ñо¿Ô±J¨¦r?me Segura·¢Ã÷¡£¡£¡£¡£ÔÚÐµĹ¥»÷»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬Spelevo EKʵÑéʹÓÃFlash PlayerÎó²î£¨CVE-2018-15982£©ÔÚÊÜѬȾµÄϵͳÉÏ×°ÖÃMaze£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËFlash Player°æ±¾31.0.0.153/31.0.0.108¼°¸üÔç°æ±¾¡£¡£¡£¡£Maze»áɨÃèÓû§µÄÎĵµ¡¢ÕÕÆ¬¡¢Êý¾Ý¿âµÈÎļþ²¢Ê¹ÓÃRSAËã·¨ºÍChaCha20Á÷¼ÓÃÜÆ÷¾ÙÐмÓÃÜ¡£¡£¡£¡£ÏÖÔÚÉÐûÓÐMazeµÄÃ⺬»ìÃÜÆ÷Ðû²¼¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/maze-ransomware-now-delivered-by-spelevo-exploit-kit/

4¡¢Ñо¿ÍŶÓÐû²¼ÀÕË÷Èí¼þSTOP 148¸ö±äÖֵĽâÃܹ¤¾ß

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


EmsisoftºÍMichael GillespieÐû²¼ÀÕË÷Èí¼þSTOPµÄ½âÃÜÆ÷£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ×ÊÖúÓû§½âÃÜ148¸ö±äÖÖ¼ÓÃܵÄÎļþ¡£¡£¡£¡£ÐèÒª×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬£¬2019Äê8ÔÂÖ®ºó±»Ñ¬È¾µÄÓû§ÎÞ·¨±»½âÃÜ¡£¡£¡£¡£Ö»¹ÜÔÆÔÆ£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÀëÏßÃÜÔ¿¾ÙÐнâÃÜÒ²ÊÇÓпÉÄܵÄ£¬£¬£¬£¬£¬£¬£¬Òò´ËÔÚÕâЩ±äÖÖÉÏÒ²¿ÉÄÜ»ñµÃһЩÀֳɡ£¡£¡£¡£STOPÊÇÄ¿½ñ»î¶¯×îÆÕ±éµÄÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬£¬¸ÃÀÕË÷Èí¼þͨ¹ý¹ã¸æÈí¼þÀ¦°ó°ü·Ö·¢£¬£¬£¬£¬£¬£¬£¬ÕâЩÀ¦°óÈí¼þαװ³ÉµÁ°æÈí¼þ¡¢µÁ°æÓÎÏ·ÒÔ¼°Ãâ·ÑÈí¼þµÈÓÕʹÓû§ÏÂÔØ¡£¡£¡£¡£ËäÈ»ºÜÄÑÈ·¶¨Êܺ¦Õß¼òÖ±ÇÐÈËÊý£¬£¬£¬£¬£¬£¬£¬µ«ID RansomwareÎüÊÕµ½ÁË11.6Íò¸öÓë¸ÃÀÕË÷Èí¼þÓйصÄʶ±ðÇëÇ󡣡£¡£¡£Ö»¹ÜÓÐЩÊܺ¦ÕßÀ´×ÔÃÀ¹ú£¬£¬£¬£¬£¬£¬£¬µ«´ó´ó¶¼Êܺ¦ÕßÀ´×ÔÅ·ÖÞ¡¢ÑÇÖÞ¡¢ÄÏÃÀºÍ·ÇÖÞ£¬£¬£¬£¬£¬£¬£¬¶íÂÞ˹µØÇøÎ´ÊÜÓ°Ïì¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/stop-ransomware-decryptor-released-for-148-variants/

5¡¢ÃÀ¹úIngredion IncorporatedÔâÀÕË÷Èí¼þ¹¥»÷


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÃÀ¹úÅäÁϹ©Ó¦ÉÌIngredion IncorporatedÐû²¼×î½ü¼ì²âµ½Óë¶ñÒâÈí¼þ¹¥»÷Ïà¹ØµÄ¿ÉÒɻ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒÑÔ¼ÇëµÚÈý·½×¨¼Ò×ÊÖúÆäÔ±¹¤ÊÓ²ìÊÂÎñ²¢»Ö¸´ÊÜÓ°ÏìµÄϵͳ¡£¡£¡£¡£×èÖ¹ÏÖÔڸù«Ë¾Î´Åû¶Óйع¥»÷µÄÏêϸÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬²¢ÌåÏÖûÓÐÖ¤¾ÝÅú×¢ºÚ¿Í»á¼ûÁËÆä¿Í»§¡¢¹©Ó¦ÉÌ»òÔ±¹¤µÄÊý¾Ý¡£¡£¡£¡£¸Ã¹«Ë¾»¹ÖÒÑԳƻָ´Ä³Ð©ÊÜÓ°ÏìµÄϵͳ½«ÆÆ·ÑһЩʱ¼ä£¬£¬£¬£¬£¬£¬£¬²¢¿ÉÄÜÔÚÓë¿Í»§ºÍ¹©Ó¦É̵ÄÉúÒâÖзºÆðһЩÑÓÎ󡣡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/92673/hacking/ingredion-security-incident.html

6¡¢CenturyLinkÒâÍâ̻¶280ÍòÌõ¿Í»§¼Í¼

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Ñо¿Ö°Ô±·¢Ã÷Ò»¸öÓµÓÐ280ÍòÌõ¼Í¼µÄCenturyLink¿Í»§ÐÅÏ¢Êý¾Ý¿âÔÚÍøÉÏ̻¶Á˳¤´ï10¸öÔµÄʱ¼ä¡£¡£¡£¡£¸ÃÊý¾Ý¿âÊÇÒ»¸öMongoDBЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬Êý¾Ý¿âÖеÄÐÅÏ¢°üÀ¨¿Í»§ÐÕÃû¡¢µØµã¡¢µç×ÓÓʼþµØµãºÍµç»°ºÅÂë¡£¡£¡£¡£¸ÃÊý¾Ý¿âÓëCenturyLinkʹÓõĵÚÈý·½Í¨ÖªÆ½Ì¨ÓйØ£¬£¬£¬£¬£¬£¬£¬ÔÚÑо¿Ö°Ô±Í¨ÖªCenturyLinkÁ½Ììºó£¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÒÑ»ñµÃ±£»£» £»¤¡£¡£¡£¡£CenturyLinkÔÚÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÊý¾ÝÖ÷ÒªÊǿͻ§µÄÁªÏµÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Ã»ÓвÆÎñ»òÆäËüÃô¸ÐÐÅÏ¢Êܵ½Ë𺦡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/attacks-breaches/centurylink-customer-data-exposed-/d/d-id/1336123