360-CERT每日安全简报
Daily Security Briefing
2020-01-04 星期六
<<Previous
Next>>
漏洞
Vulnerability
CVE-2019-10758:mongo-express 远程代码执行漏洞风险提示
https://mp.weixin.qq.com/s/5BZ-dGO_-Cc0UQ1VXuW90g
CA20191218-01: Windows 的CA 客户端自动化代理存在安全风险
http://seclists.org/fulldisclosure/2020/Jan/5
IBM 云 Private-OpenSSL 多个漏洞 CVE-2019-1563,CVE-2019-1549,CVE-2019-1547
https://www.ibm.com/blogs/psirt/security-bulletin-security-vulnerabilities-affect-ibm-cloud-private-openssl-cve-2019-1563-cve-2019-1549-cve-2019-1547/
安全研究
Security Research
CVE-2019-11045:PHP DirectoryIterator 类空字符截断漏洞
https://bugs.php.net/bug.php?id=78863
下一代网络隔离方案:自适应微隔离应该如何设计?
https://www.freebuf.com/articles/es/223314.html
SysWhispers:通过直接系统调用进行AV/EDR规避
https://www.kitploit.com/2020/01/syswhispers-avedr-evasion-via-direct.html
浅析通过操纵BGP Communities影响路由选路
https://www.freebuf.com/articles/network/223879.html
安全资讯
Security Information
openEuler 操作系统源码正式公开
https://www.oschina.net/news/112518/openeuler-opensource?p=1&from=timeline&isappinstalled=0
符合ISO26262标准的软件测试解决方案
https://mp.weixin.qq.com/s/LIoVveIdXVgX28vNGiw8bg
安全工具
Security Tools
Kamerka GUI-终极物联网/工业控制系统侦察工具
https://www.kitploit.com/2020/01/kamerka-gui-ultimate-internet-of.html
BLUESPAWN:监控 windows 系统实时活动的安全工具
https://github.com/ION28/BLUESPAWN
恶意软件
Malware
疑似APT34部分工具泄露
https://twitter.com/hackerfantastic/status/1213205684147257344
<<Previous
Next>>