Cisco°ä²¼°²È«¸üР£¬£¬£¬£¬£¬½¨¸´¶à¸ö²úÆ·Öеķì϶£»£»£»£»£»£»WooCommerceÖзì϶¿Éµ¼ÖÂÍøÕ¾ÊÕÊÜ £¬£¬£¬£¬£¬Ó°ÏìÉÏÍò¼ÒÉ̵ê

°ä²¼¹¦·ò 2020-08-24

1.Cisco°ä²¼°²È«¸üР£¬£¬£¬£¬£¬½¨¸´¶à¸ö²úÆ·Öеķì϶


1.png


Cisco°ä²¼°²È«¸üР£¬£¬£¬£¬£¬ÒÔ½¨¸´Æä¶à¸ö²úÆ·Öеķì϶¡£¡£ ¡£¡£¡£¡£Õâ´Î°²È«¸üÐÂÖн¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶ΪTreck IP²Ö¿âÖеķì϶Ripple20 £¬£¬£¬£¬£¬ÕâЩ·ì϶¿Éµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡¢»Ø¾ø·þÎñ£¨DoS£©»òÐÅϢй¶£»£»£»£»£»£»ÓÃÓÚCisco ENCS 5400-WϵÁкÍCSP 5000-WϵÁеÄCisco vWAASĬÈÏÍ´´¦·ì϶£¨CVE-2020-3446£© £¬£¬£¬£¬£¬¿É±»ÀûÓÃÒÔÖÎÀíԱȨÏÞ½Ó¼ûNFVIS CLI£»£»£»£»£»£»Ë¼¿ÆÖÇÄÜÈí¼þÖÎÀíÆ÷£¨SSM On-Prem£©±¾µØÌØÈ¨Éý¼¶·ì϶£¨CVE-2020-3443£©ÒÔ¼°Ë¼¿ÆÊÓÆµ¼à¿Ø8000ϵÁÐIPÉãÏñ»ú˼¿Æ·¢ÏÖºÍ̸Զ³ÌÖ´Ðкͻؾø·þÎñ·ì϶£¨CVE-2020-3506ºÍCVE-2020-3507£©¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/08/20/cisco-releases-security-updates


2.FBIºÍCISAÖÒ¸æÕë¶ÔÃÀ¹úƫԶµØÓò¹¤È˵Ĵ¹µö»î¶¯


2.png


ÃÀ¹úFBIºÍCISA½áºÏ°ä²¼¾¯±¨ £¬£¬£¬£¬£¬ÖÒ¸æÄ¿Ç°Õë¶ÔÃÀ¹ú¶à¸öÐÐÒµ²¿ÃŵÄÓïÒôÍøÂç´¹µö»î¶¯£¨Vishing£©¡£¡£ ¡£¡£¡£¡£VishingÊÇÒ»ÖÖÉç»á¹¤³Ì¹¥»÷ £¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÓïÒôºô½ÐÆÚ¼äÄ£ÄâÊÜÐÅÀµµÄʵÌå £¬£¬£¬£¬£¬ÒÔÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¸Ã»ú¹¹°µÊ¾ £¬£¬£¬£¬£¬×Ô2020Äê7ÔÂÖÐÑ® £¬£¬£¬£¬£¬ÍøÂç·¸×ï·Ö×Ó·¢Õ¹ÁËÕâÒ»»î¶¯ £¬£¬£¬£¬£¬Ö¼ÔÚıȡÀûÒæ¡£¡£ ¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬¹¥»÷Õß»¹×¢²áÁËÓÃÓÚÍøÂç´¹µöµÄÓò £¬£¬£¬£¬£¬ÒÔ¿Ë¡ָ±ê¹«Ë¾µÄÄÚ²¿VPNµÇÂ¼Ò³Ãæ £¬£¬£¬£¬£¬À´ÇÔÈ¡Á½³É·ÖÉí·ÝÑéÖ¤£¨2FA£©ºÍÒ»´ÎÐÔÃÜÂ루OTP£©¡£¡£ ¡£¡£¡£¡£Îª´Ë £¬£¬£¬£¬£¬FBIºÍCISAÌá³öһϵÁн¨Òé´ëÊ© £¬£¬£¬£¬£¬ÒÔ»º½â´ËÀ๥»÷¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-govt-warns-remote-workers-of-ongoing-vishing-campaign/


3.WooCommerceÖзì϶¿Éµ¼ÖÂÍøÕ¾ÊÕÊÜ £¬£¬£¬£¬£¬Ó°ÏìÉÏÍò¼ÒÉ̵ê


3.jpg


WebARX·¢ÏÖWordPress²å¼þWooCommerceÖзì϶¿Éµ¼ÖÂÍøÕ¾ÊÕÊÜ £¬£¬£¬£¬£¬Ó°ÏìÉÏÍò¼ÒÉ̵ê¡£¡£ ¡£¡£¡£¡£Æ¾¾Ý·ÖÎöÔ±¶Ô·ì϶µÄ·ÖÎö £¬£¬£¬£¬£¬·¢ÏÖËüÃÇÊÇÓɲ»×ãËæ»úÊýÁîÅÆºÍÊÚȨ²é³­µ¼Ö嵀 £¬£¬£¬£¬£¬ÈôÊdzɹ¦ÀûÓÃÕâЩ·ì϶ £¬£¬£¬£¬£¬Ôòδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»¼ìË÷ËùÓÐЧ»§ºÍÓÅ»Ýȯ´úÂëµÄÁÐ±í £¬£¬£¬£¬£¬²¢ÔÚÍøÕ¾µÄҳü¡¢Ò³½Å»òÖÎÀíÒ³Ãæ×¢ÈëXSS £¬£¬£¬£¬£¬ÒÔ´¥·¢Ô¶³ÌÖ´ÐдúÂë·ì϶¡£¡£ ¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬ºÚ¿Í»¹Äܹ»ÀûÓÃJavaScript¼üÅ̼ͼ·¨Ê½×¢ÈëµÇ¼±íµ¥ £¬£¬£¬£¬£¬ÒÔÊÕÊÜÖÎÀíÔ¹ØÊ»§¡£¡£ ¡£¡£¡£¡£Ä¿Ç° £¬£¬£¬£¬£¬¸Ã²å¼þÔÚ´Óǰ7ÌìÄÚÒѱ»ÏÂÔØÁ˳¬¹ý12000´Î¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/wordpress-woocommerce-stores-under-attack-patch-now/


4.Diebold Nixdorf½¨¸´¿É±»ÓÃÓÚ´æ¿îαÔì¹¥»÷µÄ·ì϶


4.jpg


ATMÔì×÷ÉÌDiebold NixdorfºÍNCR°ä²¼ÁËÈí¼þ¸üР£¬£¬£¬£¬£¬½¨¸´¿É±»ÓÃÓÚ´æ¿îαÔì¹¥»÷µÄ·ì϶¡£¡£ ¡£¡£¡£¡£Õâ´Î½¨¸´µÄ·ì϶±»×·×ÙΪCVE-2020-9062ºÍCVE-2020-10124 £¬£¬£¬£¬£¬±ðÀëÓ°ÏìÁËÔËÐÐWincor ProbaseÈí¼þµÄDiebold Nixdorf ProCash 2100xe USB ATMºÍÔËÐÐAPTRA XFSÈí¼þµÄNCR SelfServ ATM¡£¡£ ¡£¡£¡£¡£ÕâЩ·ì϶¿É±»ºÚ¿ÍÀûÓÃÒÔÅú¸ÄÆäÒøÐп¨ÉϵĴæ¿î½ð¶î £¬£¬£¬£¬£¬²¢ÔÚÒøÐз¢ÏÖÕË»§Óà¶îÒ쳣֮ǰ½øÐÐڲƭÐÔÈ¡¿î¡£¡£ ¡£¡£¡£¡£ÕâЩ·ì϶ԴÓÚATMÏÖ½ð´æ·ÅÏäºÍÖ÷»úÖ®¼ä·¢Ë͵ÄÐÂÎŶÌȱ¼ÓÃܺÍÉí·ÝÑéÖ¤»·½Ú £¬£¬£¬£¬£¬Ä¿Ç°DieboldºÍNCR¾ùÒѰ䲼Èí¼þ¸üР£¬£¬£¬£¬£¬ÒÔ±£»£»£»£»£»£»¤ÏÖ½ð´æ¿îÄ£¿£¿£¿£¿£¿£¿éÓëÖ÷»úÖ®¼äµÄͨѶ¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/107421/hacking/diebold-nixdorf-ncr-deposit-forgery.html


5.Spikey¹¥»÷¿ÉÀûÓÃÐźŴ¦ÖÃÈí¼þ¿Ë¡ÎïÀíÔ¿³×


5.jpg


ÐÂ¼ÓÆÂ¹úÁ¢´óѧµÄ×êÑÐÈËÔ±·¢ÏÖÒ»ÖÖÕë¶ÔÎïÀíËøµÄй¥»÷Õ½ÊõSpikey £¬£¬£¬£¬£¬¿ÉÀûÓÃÐźŴ¦ÖÃÈí¼þ¿Ë¡ÎïÀíÔ¿³×¡£¡£ ¡£¡£¡£¡£´ËÀ๥»÷Äܹ»ÀûÓÃÖÇÄÜÊÖ»úµÄÂó¿Ë·ç²¶»ñÔ¿³×²åÈë»ò°Î³öʱµÄ½ðÊôµã»÷Éù £¬£¬£¬£¬£¬²¢ÓÃÐźŴ¦ÖÃÈí¼þ½øÐÐÆÆÒë £¬£¬£¬£¬£¬ÒÔ´§¶ÈÔ¿³×µÄ״̬ £¬£¬£¬£¬£¬×îÖÕÄܹ»ÓÃ3D´òÓ¡¼¼Êõ¿Ë¡³öÎïÀíÔ¿³×¡£¡£ ¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾½«À´»¹¿ÉÄÜͨ¹ý¶ñÒâÈí¼þϰȾÊܺ¦ÕßµÄÖÇÄÜÊÖ»ú»òÖÇÄÜÍó±í £¬£¬£¬£¬£¬ÒԴ˼ͼÉùÒô²¢ÌáÒé¹¥»÷¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/08/21/spikey-attack-can-duplicate-physical-keys-by-listening-to-click-sounds/


6.Ó¢¹úMyerscough´óѧÔâµ½DoS¹¥»÷µ¼ÖÂϵͳÍÑ»ú


6.jpg


Ó¢¹úMyerscough´óѧÔÚ°ä²¼¿¼ÊԳɾÍÈ·µ±ÌìÔâµ½DoS¹¥»÷ £¬£¬£¬£¬£¬µ¼ÖÂϵͳÍÑ»ú¡£¡£ ¡£¡£¡£¡£¸Ã´óѧ°µÊ¾ £¬£¬£¬£¬£¬DoS¹¥»÷ÑϳÁ·ÛËéÁËÆäËùÓÐIT»ù´¡ÉèÊ© £¬£¬£¬£¬£¬µ¼ÖÂϵͳ´¦ÓÚÍÑ»ú״̬ £¬£¬£¬£¬£¬Ñ§ÉúÎÞ·¨½Ó¼ûÃÅ»§ÍøÕ¾GCSEºÍ²éÎÊ¿¼ÊÔÁ˾Ö¡£¡£ ¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬Ñ§ÌÃÔ±¹¤Ò²Ö»ÄÜͨ¹ýÉ罻ýÌ幤¾ßÁªÏµ £¬£¬£¬£¬£¬²¢ÇÒÔÚ·þÎñÆ÷¸´Ô­Ö®Ç°Ö»ÄÜÊÖ¶¯ÏòËùÓÐѧÉú·¢ËÍÆä³É¾ÍµÄµç×ÓÓʼþ¡£¡£ ¡£¡£¡£¡£¸ÃѧÌõĽ²»°È˰µÊ¾ £¬£¬£¬£¬£¬Ä¿Ç°²¢Ã»ÓÐѧÉúµÄÊý¾ÝÔ⵽й¶ £¬£¬£¬£¬£¬¶ø±¾µØ¾¯·½Ò²ÔÚ¶Ô´ËÊ·¢Õ¹µ÷²é¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bbc.com/news/uk-england-lancashire-53822246