VolusionÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬³¬¹ý6500¼ÒµçÉÌÍøÕ¾Êܲ¨¼°£»£»£»£»£»¹È¸è°ä²¼10ÔÂAndroid°²È«¸üУ¬£¬£¬£¬£¬½¨¸´¶à¸öRCE·ì϶
°ä²¼¹¦·ò 2019-10-10
ƾ¾ÝzdnetµÄÐÂÎÅ£¬£¬£¬£¬£¬ºÚ¿ÍÈëÇÖVolusionµÄ»ù´¡ÉèÊ©²¢´«²¼¶ñÒâ´úÂ룬£¬£¬£¬£¬µ¼Ö³¬¹ý6500¼Òµç×ÓÉ̵êÍøÕ¾ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÊÇÒ»¸öµäÐ͵ÄMAGECART¹©¸øÁ´¹¥»÷£¬£¬£¬£¬£¬¹¥»÷Õß»ñµÃÁËVolusionµÄGoogle Cloud»ù´¡ÉèÊ©½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬²¢ÔÚÆäÖÐÅú¸ÄÁËJSÎļþ£¬£¬£¬£¬£¬Ôö³¤ÓÃÓڼͼÓû§ÐÅÓþ¿¨ÐÅÏ¢µÄ¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ¶ñÒâ´úÂë±»¼ÓÔØµ½»ùÓÚVolusionµÄÔÚÏßÉ̵êÖÓ×£¡£¡£¡£¡£¡£¡£¡£½ØÖÁĿǰ¶ñÒâ´úÂëÈÔÔÚVolusionµÄ·þÎñÆ÷ÉÏ£¬£¬£¬£¬£¬VolusionÉÐδ¶Ô´ËÊÂÎñ½øÐлØÓ¦¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hackers-breach-volusion-and-start-collecting-card-details-from-thousands-of-sites/
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-blocks-credential-theft-attack-targeting-dozens-of-orgs/3.¹È¸è°ä²¼10ÔÂAndroid°²È«¸üУ¬£¬£¬£¬£¬½¨¸´¶à¸öRCE·ì϶
¹È¸è°ä²¼10ÔÂAndroid°²È«¸üУ¬£¬£¬£¬£¬½¨¸´Ã½Ìå¿ò¼Ü×é¼þÖеÄ3¸öÑϳÁ¼¶´ËÍâRCE·ì϶¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶£¨CVE-2019-2184¡¢CVE-2019-2185¡¢CVE-2019-2186£©Ó°ÏìÁËAndroidϵͳ°æ±¾7.1.1¡¢7.1.2¡¢8.0¡¢8.1ºÍ9¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬¹È¸è»¹½¨¸´Á˸ßͨ×é¼þÖеÄ18¸ö·ì϶£¬£¬£¬£¬£¬ÆäÖÐ8¸öΪÑϳÁ¼¶±ð£¬£¬£¬£¬£¬Ô̺¬Äں˷ì϶£¨CVE-2018-13916£©¡¢¶àÄ£ºô½Ð´¦ÖÃÆ÷·ì϶£¨CVE-2019-2271£©ºÍÆô¶¯¼¼Êõ·ì϶£¨CVE-2019-2251£©µÈ¡£¡£¡£¡£¡£¡£¡£¡£¹È¸è»¹¶Ô½üÆÚÅû¶µÄAndroid 0day£¨CVE-2019-2215£©°ä²¼Á˽¨¸´²¹¶¡£¬£¬£¬£¬£¬¸Ã·ì϶ӰÏìÁËPixel¡¢ÈýÐÇ¡¢»ªÎª¡¢Ó×Ã×µÈ18ÖÖÐͺŵÄÊÖ»ú¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/google-october-android-security-update/148964/4.TwinCAT PLC´æÔÚ¶à¸ö·ì϶£¬£¬£¬£¬£¬¿Éµ¼Ö»ؾø·þÎñ¹¥»÷
µÂ¹ú³§ÉÌBeckhoffÔì×÷µÄTwinCAT PLC´æÔÚ¶à¸öDoS·ì϶¡£¡£¡£¡£¡£¡£¡£¡£BeckhoffÖØÒªÌṩ¹¤ÒµPC¡¢I/O¼°ÏÖ³¡×ÜÏß×é¼þ¡¢Çý¶¯¼¼ÊõºÍ×Ô¶¯»¯Èí¼þµÈ¹¤Òµ½â¾ö¹æ»®£¬£¬£¬£¬£¬¸Ã¹«Ë¾°µÊ¾Æä²úÆ·ÒÑÔÚÈ«Çò³¬¹ý75¸ö¹ú¶È/µØÓòʹÓᣡ£¡£¡£¡£¡£¡£¡£Rapid7×êÑÐÈËÔ±·¢ÏÖTwinCATÊÜÁ½¸öDoS·ì϶µÄÓ°Ï죬£¬£¬£¬£¬Ô̺¬ProfinetÇý¶¯·¨Ê½Öеķì϶£¨CVE-2019-5637£©¼°×é¼þÄÚ²¿Í¨Ñ¶ºÍ̸ADSÓйصķì϶£¨CVE-2019-5636£©¡£¡£¡£¡£¡£¡£¡£¡£Rapid7Ö¸³ö£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂDoSÇé¿öµÄÊý¾Ý°üÀàÐÍͨ³£ÊÇÓÉnmapºÍÆäËûÍøÂçɨÃ跨ʽ·¢³öµÄ£¬£¬£¬£¬£¬ÕâÒâζןϷ¨µÄÍøÂçɨÃè»ò·ì϶ÖÎÀí»î¶¯¿ÉÄÜ»áÁÙʱ·ÛËéÉ豸£¬£¬£¬£¬£¬µ«´ËÀàÉ豸ͨ³£²»»á¶³öÔÚ»¥ÁªÍøÉÏ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/vulnerabilities-expose-twincat-industrial-systems-dos-attacks
5.×êÑÐÍŶÓÅû¶ʩÄÍµÂµçÆøModicon M580ÖеĶà¸ö·ì϶
˼¿ÆTalosÅû¶ʩÄÍµÂµçÆøModicon M580ÖеĶà¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£¡£Modicon M580ÊÇÊ©ÄÍµÂµçÆøµÄModicon¿É±à³Ì×Ô¶¯»¯½ÚÔìÆ÷²úÆ·ÏßÖеÄ×îвúÆ·¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖModicon¶ÔFTPµÄʹÓÃÖдæÔÚ¶à¸ö·ì϶£¬£¬£¬£¬£¬Ô̺¬FTPÃ÷ÎÄÉí·ÝÑéÖ¤·ì϶£¨CVE-2019-6846£©¡¢FTP¹Ì¼þ¸üÐÂÖ°Äܵ¼ÖµĻؾø·þÎñ·ì϶£¨CVE-2019-6844~CVE-2019-6841£¬£¬£¬£¬£¬CVE-2019-6847£©¡¢UMASÃ÷ÎÄÊý¾Ý´«Êä·ì϶£¨CVE-2019-6845£©ÒÔ¼°TFTP·þÎñÆ÷ÐÅϢй¶·ì϶£¨CVE-2019-6851£©¡£¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·°æ±¾ÎªModicon M580 BMEP582040 SV2.80¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2019/10/vuln-spotlight-schneider-electric-m580-part-2-sept-2019.html
6.macOSÖÕ¶ËÄ£ÄâÆ÷iTerm2ÆØ³ö´æÔÚ7ÄêµÄRCE·ì϶
°²È«³§ÉÌROS·¢ÏÖmacOSÖÕ¶ËÄ£ÄâÆ÷iTerm2´æÔÚÒ»¸öÓµÓÐ7Ä꺹ÇàµÄÑϳÁRCE·ì϶£¨CVE-2019-9535£©£¬£¬£¬£¬£¬¸Ã×êÑÐÊÇMozilla¿ªÔ´Ö§³Ö´òË㣨MOSS£©µÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝMozilla°ä²¼µÄ²©¿ÍÎÄÕ£¬£¬£¬£¬£¬¸ÃRCE·ì϶´æÔÚÓÚiTerm2µÄtmux¼¯³É¹¦ÄÜÖУ¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÏòÖÕ¶ËÌṩ¶ñÒâÊä³öÀ´Ö´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£ÊÓÆµÑÝʾÅú×¢£¬£¬£¬£¬£¬´Ë·ì϶µÄDZÔÚ¹¥»÷ý½éÔ̺¬Ïνӵ½¹¥»÷Õß½ÚÔìµÄ¶ñÒâSSH·þÎñÆ÷¡¢Ê¹ÓÃcurlµÈºÅÁî»ñÈ¡¶ñÒâÍøÕ¾»òʹÓÃtail -f¸ú×ÙÔ̺¬Ä³Ð©¶ñÒâÄÚÈݵÄÈÕÖ¾ÎļþµÈ£¬£¬£¬£¬£¬»òÊÇʹÓúÅÁîÐй¤¾ßÓÕʹÓû§´òÓ¡¹¥»÷Õß½ÚÔìµÄÄÚÈÝÀ´´¥·¢¡£¡£¡£¡£¡£¡£¡£¡£MozillaÖÒ¸æ³Æ¸Ã·ì϶ӰÏì3.3.5¼°¸ü¸ß°æ±¾µÄiTerm2£¬£¬£¬£¬£¬²¢ÒÑÔÚiTerm2 3.3.6Öн¨¸´¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/10/iterm2-macos-terminal-rce.html


¾©¹«Íø°²±¸11010802024551ºÅ