信息清静周报-2019年第10周
宣布时间 2019-03-11本周清静态势综述
本周值得关注的网络清静事务是微软宣布清静报告Volume 24,2018年垂纶攻击增添250%;研究批注2018年爆发12449起数据泄露事务,比2017年增添424%;Dalil公司MongoDB可果真会见,500多万用户数据泄露;2018年被黑客入侵的网站中,WordPress占90%;研究团队发明2月份勒索软件Shade的攻击运动飙升。
凭证以上综述,本周清静威胁为中。
主要清静误差列表
Cisco NX-OS Software CLI验证参数保存清静误差,允许外地攻击者可以使用误差提交特殊的请求,提升权限执行恣意os下令。
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-cmdinj-1610
2. Google Chrome FileReader释放后使用代码执行误差
Google Chrome FileReader的实现保存释放后使用误差,允许远程攻击者使用误差构建恶意WEB页,诱使用户剖析,可使应用程序崩�;蛑葱许б獯搿�
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html
3. Adobe ColdFusion CVE-2019-7816文件上传限制绕过误差
Adobe ColdFusion文件上传实现保存清静误差,允许远程攻击者使用误差提交特殊的请求,上传恣意文件,并执行。
https://helpx.adobe.com/security/products/coldfusion/apsb19-14.html
4. Samsung Galaxy S9身份验证代码执行误差
Samsung Galaxy S9 GameServiceReceiver更新机制保存清静误差,允许远程攻击者使用误差提交特殊的请求,可执行恣意代码。
https://www.zerodayinitiative.com/advisories/ZDI-19-255/
5. Nokia Alcatel Lucent I-240W-Q GPON ONT CVE-2019-3922缓冲区溢出误差
Nokia Alcatel Lucent I-240W-Q GPON ONT处置惩罚特殊的HTTP POST请求保存清静误差,允许远程攻击者使用误差提交特殊的请求,可执行恣意代码。
https://www.tenable.com/security/research/tra-2019-09
主要清静事务综述
凭证微软的清静情报报告(SIR)Volume 24,在2018年1月至12月时代,网络垂纶攻击增添了250%。攻击者在运营网络垂纶运动时接纳多样化的基础设施,包括托管服务器和公共云等。另一方面,2018年时代恶意软件的数目下降了约34%。别的,随着2018年年尾加密钱币价钱的下跌,恶意挖矿运动也下降了36%。
原文链接:
https://www.bleepingcomputer.com/news/security/microsoft-sees-250-percent-phishing-increase-malware-decline-by-34-percent/
2、研究批注2018年爆发12449起数据泄露事务,比2017年增添424%
原文链接:
https://www.bleepingcomputer.com/news/security/12-449-data-breaches-confirmed-in-2018-a-424-percent-increase-over-the-previous-year/
3、Dalil公司MongoDB可果真会见,500多万用户数据泄露
原文链接:
https://www.vpnmentor.com/blog/dalil-data-breach/
4、2018年被黑客入侵的网站中,WordPress占90%
原文链接:
https://www.zdnet.com/article/wordpress-accounted-for-90-percent-of-all-hacked-cms-sites-in-2018/
5、研究团队发明2月份勒索软件Shade的攻击运动飙升
原文链接:
https://blog.malwarebytes.com/threat-analysis/2019/03/spotlight-troldesh-ransomware-aka-shade/
声明:本资讯由尊龙凯官网入口维他命清静小组翻译和整理


京公网安备11010802024551号