LightInTheBoxй¶1.3TB Web·þÎñÆ÷ÈÕÖ¾£»£»£»£»£»£»£»Bitglass°ä²¼2019Äê½ðÈÚÐÐÒµÊý¾Ýй¶»ã±¨
°ä²¼¹¦·ò 2019-12-18
1.LightInTheBoxй¶1.3TB Web·þÎñÆ÷ÈÕÖ¾
vpnMentor×êÑÐÈËÔ±·¢´Ë¿ÌÏßÁãÊÛÉÌLightInTheBoxµÄElasticsearchÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬1.3TB Web·þÎñÆ÷ÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£LightInTheBoxרһÓÚÓ×Åä¼þ¡¢·þ×°ºÍÅäÊεÄÏúÊÛ£¬£¬£¬£¬£¬£¬£¬Æä´ó²¿Ãſͻ§Î»ÓÚ±±ÃÀºÍÅ·ÖÞ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚ11ÔÂÏÂÑ®·¢ÏÖÁ˸ÃÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬Êý¾Ý¿âÖеļͼ×ܼƳ¬¹ý15ÒÚÌõ£¬£¬£¬£¬£¬£¬£¬»¹Ô̺¬Æä×ÓÍøÕ¾MiniInTheBox.comµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÈÕÖ¾Ô̺¬8ÔÂ9ÈÕÖÁ10ÔÂ11ÈÕÖ®¼äµÄÍøÕ¾»î¶¯£¬£¬£¬£¬£¬£¬£¬Ô̺¬µç×ÓÓʼþµØÖ·¡¢IPµØÖ·¡¢¾Óס¹ú¶È/µØÓòÒÔ¼°Ã¿¸ö·Ã¿Í½Ó¼ûµÄÒ³ÃæµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/95231/data-breach/lightinthebox-data-leak.html
2.¼ÓÄôóÁÙ´²³¢ÊÔÊÒ·þÎñÉÌLifeLabsй¶1500Íò¿Í»§ÐÅÏ¢
¼ÓÄôóÁÙ´²³¢ÊÔÊÒ·þÎñÌṩÉÌLifeLabsй¶¶à´ï1500Íò¼ÓÄôó¹«ÃñµÄÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝÆä°ä²¼µÄÊý¾Ýй¶֪ͨ£¬£¬£¬£¬£¬£¬£¬Î´¾ÊÚȨµÄ¹¥»÷Õß½Ó¼ûÁË1500Íò¿Í»§µÄÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþ¡¢µÇ¼Ãû¡¢ÃÜÂë¡¢µ®ÉúÈÕÆÚºÍÒ½ÁÆ¿¨ºÅÂë¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÔ¼8.5Íò¿Í»§µÄ³¢ÊÔÊÒÁ˾ÖÒ²Ôâй¶¡£¡£¡£¡£¡£¡£¡£¾Ý±¨Â·Ð¹Â¶µÄÊý¾ÝÖØÒªÎª2016Ä꼰֮ǰµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬Éæ¼°µÄ¿Í»§¾ø´óÎÞÊýÀ´×ÔÓÚ±°Ê«Ê¡ºÍ°²´ÖÂÔÊ¡¡£¡£¡£¡£¡£¡£¡£ÔÚ·¢ÏÖй¶ºó£¬£¬£¬£¬£¬£¬£¬LifeLabs´ÓºÚ¿ÍÄÇÀï²É°ìÁ˱»µÁµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬µ«²»ÖªÂ·ËûÃÇΪ´ËÖ§¸¶Á˼¸¶àÊê½ð¡£¡£¡£¡£¡£¡£¡£LifeLabs½«ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩһÄêµÄÃâ·ÑÉí·Ý͵ÇÔ±£»£»£»£»£»£»£»¤·þÎñ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/lifelabs-data-breach-exposes-personal-info-of-15-million-customers/
3.Ó¢ÌØ¶û¼±¾ç´æ´¢Èí¼þÖдæÔÚDLL½Ù³Ö·ì϶
Ó¢ÌØ¶û¼±¾ç´æ´¢¼¼Êõ£¨Intel RST£©Èí¼þÖдæÔÚÒ»¸öDLL½Ù³Ö·ì϶£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÔÊÐí¶ñÒⷨʽÏÔʾΪÊÜÐÅÀµ·¨Ê½£¬£¬£¬£¬£¬£¬£¬´Ó¶øÈƹý·À²¡¶¾ÒýÇæ¡£¡£¡£¡£¡£¡£¡£SafeBreachµÄ×êÑÐÈËÔ±·¢ÏÖIAStorDataMgrSvc.exe½«³¢ÊÔ´ÓC:\Program Files\Intel\Intel(R) Rapid Storage Technology\Îļþ¼ÐϼÓÔØ4¸öDLL£¨IoctlLog.dll¡¢IoctlNet.dll¡¢IoctlSim.dll¡¢DriverSim.dll£©£¬£¬£¬£¬£¬£¬£¬µ«ÕâЩDLLÔÚ¸Ãõ辶ϲ¢²»´æÔÚ£¬£¬£¬£¬£¬£¬£¬Òò¶ø×êÑÐÈËÔ±Äܹ»´´½¨×Ô¼ºµÄDLLʹIAStorDataMgrSvc.exeÔÚÆô¶¯Ê±¼ÓÔØ£¬£¬£¬£¬£¬£¬£¬¸ÃDLL½«ÒÔSYSTEMÌØÈ¨¼ÓÔØ²¢ÄÚÈÝÉÏÓµÓжÔÍÆËã»úµÄÆëÈ«½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£Ó¢ÌضûÒÑÓÚ12ÔÂ10ÈÕ°ä²¼Á˼±¾ç´æ´¢Èí¼þµÄ¸üаæÕý±¾½â¾ö¸Ã·ì϶¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/update-intels-rapid-storage-app-to-fix-bug-letting-malware-evade-av/
4.˼¿ÆTalosÅû¶WAGO PLCÖеĶà¸ö·ì϶
˼¿ÆTalos×êÑÐÈËÔ±ÔÚWAGOÔì×÷µÄ¿É±à³ÌÂß¼½ÚÔìÆ÷£¨PLC£©Öз¢ÏÖ¶à¸öÑϳÁ·ì϶£¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐÓ×¢»Ø¾ø·þÎñ¹¥»÷»ò»ñÈ¡É豸µÄµÇ¼ʹ´¦¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬WAGO PFC200ºÍPFC100½ÚÔìÆ÷£¬£¬£¬£¬£¬£¬£¬ËüÃDZ»¿í·ºÓÃÓÚÆû³µ¡¢Ìú·¡¢µçÁ¦¹¤³Ì¡¢Ôì×÷ºÍ¹¹ÖþÎïÖÎÀíµÈÐÐÒµÖС£¡£¡£¡£¡£¡£¡£Õâ9¸ö·ì϶£¨CVE-2019-5073~CVE-2019-5075£¬£¬£¬£¬£¬£¬£¬CVE-2019-5077~CVE-2019-5082£©µÄµ××ÓÔÒòÔÚÓÚ½ÚÔìÆ÷ʹÓõÄÊäÈë/Êä³ö²é³ÅäÖ÷þÎñµÄºÍ̸´¦ÖôúÂëÖдæÔÚÎÊÌâ¡£¡£¡£¡£¡£¡£¡£Talos°µÊ¾Ã»ÓÐÖ¤¾ÝÅú×¢ÕâЩ·ì϶ÒÑÔÚÒ°±í±»ÀûÓᣡ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/several-critical-vulnerabilities-found-wago-controllers
5.F-SecureÔÚClickShareÎÞÏßÑÝʾϵͳÖз¢ÏÖ¶à¸ö·ì϶

F-Secure×êÑÐÈËÔ±·¢ÏְͿɣ¨Barco£©¹«Ë¾ClickShareÎÞÏßÑÝʾϵͳ´æÔÚ¶à¸ö¿É±»ÀûÓõݲȫ·ì϶£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶À¹½ØºÍ´Û¸ÄÑÝʾ¹ý³ÌÖеÄÐÅÏ¢¡¢ÇÔÈ¡ÃÜÂëµÈ»úÃÜÐÅÏ¢ÒÔ¼°×°ÖúóÃÅºÍÆäËü¶ñÒâÈí¼þµÈ¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶µÄCVE IDΪCVE-2017-7936¡¢CVE-2017-7932ÒÔ¼°CVE-2019-18824~CVE-2019-18833¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÓÚ10ÔÂ9ÈÕÓë°Í¿É·ÖÏíÁËÕâЩ·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬°Í¿ÉÒÑÔÚÆäÍøÕ¾Éϰ䲼Á˹̼þ°æÕý±¾»º½â²¿ÃÅ·ì϶£¬£¬£¬£¬£¬£¬£¬ÁíÒ»Ð©Éæ¼°ÎïÀíÊØ»¤µÄÓ²¼þ×é¼þÖеķì϶¿ÉÄܲ»»á±»½¨¸´¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/12/17/wireless-presentation-system-vulnerabilities/
6.Bitglass°ä²¼2019Äê½ðÈÚÐÐÒµÊý¾Ýй¶»ã±¨
¾ÝBitglass³Æ£¬£¬£¬£¬£¬£¬£¬2019ÄêËùº±¼û¾Ýй¶ÊÂÎñÖÐÖ»ÓÐ6£¥Éæ¼°µ½½ðÈÚ·þÎñ¹«Ë¾£¬£¬£¬£¬£¬£¬£¬µ«ÊÇÓëÆäËûÐÐÒµÏà±È£¬£¬£¬£¬£¬£¬£¬ÕâЩÊÂÎñÇÖº¦Á˸ü¶àµÄ¼Í¼¡£¡£¡£¡£¡£¡£¡£2019ÄêËùÓÐй©¼Í¼ÖÐ×ܼÆÓÐ60£¥ÒÔÉÏÊÇÓɽðÈÚ·þÎñ»ú¹¹Ð¹Â¶µÄ£¬£¬£¬£¬£¬£¬£¬ÕâÖÁÉÙ²¿ÃÅÓëCapital OneÌØ´óÊý¾Ýй¶ÊÂÎñÓйأ¬£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñй¶Á˳¬¹ý1Òڱʼͼ¡£¡£¡£¡£¡£¡£¡£2019ÄêºÚ¿ÍºÍ¶ñÒâÈí¼þÒÀÈ»ÊǽðÈÚ·þÎñÊý¾Ýй¶µÄÖØÒªÔÒò£¬£¬£¬£¬£¬£¬£¬Õ¼74.5£¥£¨ÂÔ¸ßÓÚ2018ÄêµÄ73.5£¥£©¡£¡£¡£¡£¡£¡£¡£ÄÚ²¿Íþв´Ó2018ÄêµÄ2.9£¥Ôö³¤µ½½ñÄêµÄ5.5£¥£¬£¬£¬£¬£¬£¬£¬¶øÒâ±íй¶´Ó14.7£¥Ôö³¤µ½18.2£¥¡£¡£¡£¡£¡£¡£¡£ÔÚ´Óǰ¼¸ÄêÖУ¬£¬£¬£¬£¬£¬£¬½ðÈÚ·þÎñ¾ùÔÈÿÌõй¶¼Í¼µÄ³É±¾ÓÐËùÔö³¤£¨210ÃÀÔª£©£¬£¬£¬£¬£¬£¬£¬³¬¹ýÁËÒ½ÁƱ£½¡ÐÐÒµ£¨429ÃÀÔª£©Ö®±íµÄËùÓÐÆäËüÐÐÒµ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/12/17/data-breaches-financial-services/


¾©¹«Íø°²±¸11010802024551ºÅ