ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ22ÖÜ
Ðû²¼Ê±¼ä 2019-06-10±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2019Äê6ÔÂ03ÈÕÖÁ09ÈÕ¹²ÊÕ¼Çå¾²Îó²î51¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇVimºÍNeovim OSÏÂÁî×¢ÈëÎó²î£»Exim deliver_message() ´úÂëÖ´ÐÐÎó²î£» Citrix Workspace app and Receiver for WindowsÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»PHP php_jpg_get16¶ÑÒç³öÎó²î£»NETGEAR Insight post-authenticationÏÂÁî×¢ÈëÎó²î¡£±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇGandCrab×èÖ¹ÔËÓª£¬¹¥»÷ÕßÐû²¼¹Ø±ÕRaaS·þÎñ£»AMCAÔâºÚ¿ÍÈëÇÖ£¬µ¼ÖÂ1190ÍòQuest Diagnostics»¼ÕßÐÅϢй¶£»WestpacÒøÐÐÔâºÚ¿Í¹¥»÷£¬Ô¼10ÍòÃû¿Í»§ÐÅϢй¶£»Windows RDPÐÂ0day£¬¿ÉЮÖÆÔ¶³Ì×ÀÃæ»á»°£»AMCAÊý¾Ý鶻¹²¨¼°Ô¼770ÍòLabCorp¿Í»§¡£
Ö÷ÒªÇå¾²Îó²îÁбí
VimºÍNeovim getchar.cÎļþ±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâOSÏÂÁî¡£
https://github.com/vim/vim/commit/53575521406739cf20bbe4e384d88e7dca11f040
2. Exim deliver_message() ´úÂëÖ´ÐÐÎó²î
Exim deliver_message()²»×¼È·ÑéÖ¤ÎüÊÕÈëµØµãÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://exim.org/static/doc/security/CVE-2019-10149.txt
3. Citrix Workspace app and Receiver for WindowsÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Citrix Workspace app and Receiver for Windows±£´æÇå¾²Îó²î£¬ÓÉÓÚδǿÖÆÖ´ÐÐÍâµØÇý¶¯Æ÷»á¼ûÊ×Ñ¡Ï¹¥»÷Õß¿ÉÒÔ¶Ô¿Í»§¶ËÍâµØÇý¶¯Æ÷¾ÙÐжÁ/д»á¼û£¬½ø¶øÔÚ¿Í»§¶ËÉè±¹ØÁ¬Ä´úÂëÖ´ÐС£
https://support.citrix.com/article/CTX251986
4. PHP php_jpg_get16¶ÑÒç³öÎó²î
PHP php_jpg_get16±£´æ¶ÑÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²î¿ÉÌá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓóÌÐò±ÀÀ£»òÖ´ÐÐí§Òâ´úÂë¡£
https://bugs.php.net/bug.php?id=77988
5. NETGEAR Insight post-authenticationÏÂÁî×¢ÈëÎó²î
NETGEAR Insight Cloud post-authentication±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐí§ÒâÏÂÁî¡£
https://kb.netgear.com/000060977/Security-Advisory-for-Post-Authentication-Command-Injection-on-Insight-Cloud-PSV-2018-0366
Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö

ÀÕË÷Èí¼þGandCrabµÄ¿ª·¢ÕßÔÚºÚ¿ÍÂÛ̳ÉÏÐû²¼½«ÔÚÒ»¸öÔÂÄڹرÕÆäRaaS£¨ÀÕË÷Èí¼þ¼´·þÎñ£©ÓªÒµ£¬×Ô2018Äê1ÔÂÕýʽÍƳöÒÔÀ´£¬GandCrab RaaSÒ»Ö±ÔÚ¸ÃÂÛ̳ÉÏÐû´«×Ô¼ºµÄ·þÎñ¡£¹¥»÷ÕßÌåÏÖËûÃÇÒѾ¿¿¸ÃÀÕË÷Èí¼þ׬ȡÁËÁè¼Ý20ÒÚÃÀÔªµÄÊê½ð£¬Òò´Ë¾öÒé¡°ÍËÐÝ¡±£¬µ«ÕâÒ»Êý×ÖµÄÕæʵÐÔ´æÒÉ¡£¹¥»÷Õß»¹ÌåÏÖ½«É¾³ýËùÓеĽâÃÜÃÜÔ¿£¬Ê¹µÃÊܺ¦ÕßÎÞ·¨»Ö¸´Îļþ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/gandcrab-ransomware-operation-says-its-shutting-down/
2¡¢AMCAÔâºÚ¿ÍÈëÇÖ£¬µ¼ÖÂ1190ÍòQuest Diagnostics»¼ÕßÐÅϢй¶
ÃÀ¹úÕ˵¥·þÎñ¹«Ë¾AMCAÔâºÚ¿ÍÈëÇÖ£¬¸ÃÊÂÎñµ¼ÖÂѪҺ¼ì²â¹«Ë¾Quest DiagnosticsµÄ1190Íò»¼ÕßÐÅϢй¶¡£Æ¾Ö¤AMCAµÄͨ¸æ£¬¸ÃÊÂÎñ±¬·¢ÔÚ2018Äê8ÔÂ1ÈÕÖÁ2019Äê3ÔÂ30ÈÕʱ´ú£¬Î´¾ÊÚȨµÄ¹¥»÷Õß»á¼ûÁËAMCAµÄϵͳ£¬¸Ãϵͳ°üÀ¨Quest DiagnosticsµÄ»¼ÕßÐÅÏ¢¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÒøÐÐÕË»§Êý¾ÝºÍÐÅÓÿ¨ºÅµÈ²ÆÎñÐÅÏ¢ÒÔ¼°Ò½ÁÆÐÅÏ¢ºÍÉç»áÇå¾²ºÅÂëµÈСÎÒ˽¼ÒÐÅÏ¢¡£QuestºÍAMCAÕýÔÚ¶Ô´ËÊÂÎñ¾ÙÐÐÊӲ졣
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/billing-details-for-119m-quest-diagnostics-clients-exposed/
3¡¢WestpacÒøÐÐÔâºÚ¿Í¹¥»÷£¬Ô¼10ÍòÃû¿Í»§ÐÅϢй¶
ÔÎÄÁ´½Ó£º
https://au.finance.yahoo.com/news/100-000-australians-reportedly-risk-232227017.html
4¡¢Windows RDPÐÂ0day£¬¿ÉЮÖÆÔ¶³Ì×ÀÃæ»á»°
¿¨ÄÚ»ù÷¡CERT/CCÅû¶Windows RDP·þÎñÖеÄÒ»¸öδÐÞ¸´µÄ0day£¨CVE-2019-9510£©£¬¸ÃÎó²î¿ÉÔÊÐí¹¥»÷ÕßÈƹýÔ¶³Ì×ÀÃæ»á»°ÖеÄÆÁÄ»Ëø¶¨²¢Ð®ÖƻỰ¡£¸ÃÎó²îÓëRDPµÄÍøÂçÉí·ÝÑéÖ¤NLAÓйأ¬CERTÐÎòµÄ¹¥»÷³¡¾°Îª£ºÓû§Ê¹ÓÃRDPÅþÁ¬µ½Windows 10 1803»òServer 2019»ò¸üеÄϵͳ£¬È»ºóËø¶¨Ô¶³Ì×ÀÃæ»á»°²¢ÍÑÀë¿Í»§¶Ë£¬´Ëʱ¹¥»÷Õß¿ÉÖÐÖ¹RDPÍøÂçÅþÁ¬£¬Õ⽫µ¼ÖÂËü×Ô¶¯ÖØÁ¬²¢ÈƹýWindowsÆÁÄ»Ëø¶¨£¬´Ó¶ø¾ÙÐв»·¨»á¼û¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/remote-desktop-zero-day-bug-allows-attackers-to-hijack-sessions/
5¡¢AMCAÊý¾Ý鶻¹²¨¼°Ô¼770ÍòLabCorp¿Í»§
LabCorpÒ²Êܵ½µÚÈý·½¹©Ó¦ÉÌAMCAÊý¾Ýй¶ÊÂÎñµÄÓ°Ï죬Լ770Íò¿Í»§ÐÅϢй¶¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µØµã¡¢µç»°ºÅÂë¡¢·þÎñÈÕÆÚÒÔ¼°ÐÅÓÿ¨ºÍÒøÐÐÐÅÏ¢µÈ¡£¸ÃÊÂÎñ±¬·¢ÔÚ2018Äê8ÔÂ1ÈÕÖÁ2019Äê3ÔÂ30ÈÕÖ®¼ä£¬´ËÇ°Íâý±¨µÀQuest DiagnosticsµÄ¿Í»§ÐÅÏ¢ÔÚ¸ÃÊÂÎñÖÐй¶¡£LabCorpÌåÏÖ¿Í»§µÄÉç»áÇå¾²ºÅÂ벢δй¶£¬±ðµÄ¿Í»§µÄ¼ì²âЧ¹û¡¢Ò½ÁÆÕï¶ÏÐÅϢҲδй¶¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/around-77-million-labcorp-customers-impacted-from-amca-data-breach-c3edd754