LightInTheBoxй¶1.3TB WebЧÀÍÆ÷ÈÕÖ¾£»£»£»BitglassÐû²¼2019Äê½ðÈÚÐÐÒµÊý¾Ýй¶±¨¸æ
Ðû²¼Ê±¼ä 2019-12-18
1.LightInTheBoxй¶1.3TB WebЧÀÍÆ÷ÈÕÖ¾
vpnMentorÑо¿Ö°Ô±·¢Ã÷ÔÚÏßÁãÊÛÉÌLightInTheBoxµÄElasticsearchÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨1.3TB WebЧÀÍÆ÷ÈÕÖ¾¡£¡£¡£¡£¡£LightInTheBoxרעÓÚСÅä¼þ¡¢´ò°çºÍÅäÊεÄÏúÊÛ£¬£¬£¬£¬£¬£¬Æä´ó²¿·Ö¿Í»§Î»ÓÚ±±ÃÀºÍÅ·ÖÞ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ11ÔÂÏÂÑ®·¢Ã÷Á˸ÃÊý¾Ý¿â£¬£¬£¬£¬£¬£¬Êý¾Ý¿âÖеļͼ×ܼÆÁè¼Ý15ÒÚÌõ£¬£¬£¬£¬£¬£¬»¹°üÀ¨Æä×ÓÍøÕ¾MiniInTheBox.comµÄÊý¾Ý¡£¡£¡£¡£¡£ÈÕÖ¾°üÀ¨8ÔÂ9ÈÕÖÁ10ÔÂ11ÈÕÖ®¼äµÄÍøÕ¾»î¶¯£¬£¬£¬£¬£¬£¬°üÀ¨µç×ÓÓʼþµØµã¡¢IPµØµã¡¢ÆÜÉí¹ú¼Ò/µØÇøÒÔ¼°Ã¿¸ö·Ã¿Í»á¼ûµÄÒ³ÃæµÈÐÅÏ¢¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/95231/data-breach/lightinthebox-data-leak.html
2.¼ÓÄôóÁÙ´²ÊµÑéÊÒЧÀÍÉÌLifeLabsй¶1500Íò¿Í»§ÐÅÏ¢
¼ÓÄôóÁÙ´²ÊµÑéÊÒЧÀÍÌṩÉÌLifeLabsй¶¶à´ï1500Íò¼ÓÄÃÖÁ¹«ÃñµÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£Æ¾Ö¤ÆäÐû²¼µÄÊý¾Ýй¶֪ͨ£¬£¬£¬£¬£¬£¬Î´¾ÊÚȨµÄ¹¥»÷Õß»á¼ûÁË1500Íò¿Í»§µÄÐÕÃû¡¢µØµã¡¢µç×ÓÓʼþ¡¢µÇ¼Ãû¡¢ÃÜÂë¡¢³öÉúÈÕÆÚºÍÒ½ÁÆ¿¨ºÅÂë¡£¡£¡£¡£¡£ÆäÖÐÔ¼8.5Íò¿Í»§µÄʵÑéÊÒЧ¹ûÒ²Ôâй¶¡£¡£¡£¡£¡£¾Ý±¨µÀй¶µÄÊý¾ÝÖ÷ҪΪ2016Ä꼰֮ǰµÄÊý¾Ý£¬£¬£¬£¬£¬£¬Éæ¼°µÄ¿Í»§¾ø´ó´ó¶¼À´×ÔÓÚ±°Ê«Ê¡ºÍ°²¼òªʡ¡£¡£¡£¡£¡£ÔÚ·¢Ã÷й¶ºó£¬£¬£¬£¬£¬£¬LifeLabs´ÓºÚ¿ÍÄÇÀﹺÖÃÁ˱»µÁµÄÊý¾Ý£¬£¬£¬£¬£¬£¬µ«²»ÖªµÀËûÃÇΪ´ËÖ§¸¶Á˼¸¶àÊê½ð¡£¡£¡£¡£¡£LifeLabs½«ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩһÄêµÄÃâ·ÑÉí·Ý͵ÇÔ±£»£»£»¤Ð§ÀÍ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/lifelabs-data-breach-exposes-personal-info-of-15-million-customers/
3.Ó¢ÌØ¶û¿ìËÙ´æ´¢Èí¼þÖб£´æDLLÐ®ÖÆÎó²î
Ó¢ÌØ¶û¿ìËÙ´æ´¢ÊÖÒÕ£¨Intel RST£©Èí¼þÖб£´æÒ»¸öDLLÐ®ÖÆÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¶ñÒâ³ÌÐòÏÔʾΪÊÜÐÅÈγÌÐò£¬£¬£¬£¬£¬£¬´Ó¶øÈƹý·À²¡¶¾ÒýÇæ¡£¡£¡£¡£¡£SafeBreachµÄÑо¿Ö°Ô±·¢Ã÷IAStorDataMgrSvc.exe½«ÊµÑé´ÓC:\Program Files\Intel\Intel(R) Rapid Storage Technology\Îļþ¼ÐϼÓÔØ4¸öDLL£¨IoctlLog.dll¡¢IoctlNet.dll¡¢IoctlSim.dll¡¢DriverSim.dll£©£¬£¬£¬£¬£¬£¬µ«ÕâЩDLLÔڸ÷¾¶Ï²¢²»±£´æ£¬£¬£¬£¬£¬£¬Òò´ËÑо¿Ö°Ô±¿ÉÒÔ½¨Éè×Ô¼ºµÄDLLʹIAStorDataMgrSvc.exeÔÚÆô¶¯Ê±¼ÓÔØ£¬£¬£¬£¬£¬£¬¸ÃDLL½«ÒÔSYSTEMÌØÈ¨¼ÓÔØ²¢ÊµÖÊÉϾßÓжÔÅÌËã»úµÄÍêÈ«»á¼ûȨÏÞ¡£¡£¡£¡£¡£Ó¢ÌضûÒÑÓÚ12ÔÂ10ÈÕÐû²¼ÁË¿ìËÙ´æ´¢Èí¼þµÄ¸üаæÔÀ´½â¾ö¸ÃÎó²î¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/update-intels-rapid-storage-app-to-fix-bug-letting-malware-evade-av/
4.˼¿ÆTalosÅû¶WAGO PLCÖеĶà¸öÎó²î
˼¿ÆTalosÑо¿Ö°Ô±ÔÚWAGOÖÆÔìµÄ¿É±à³ÌÂß¼¿ØÖÆÆ÷£¨PLC£©Öз¢Ã÷¶à¸öÑÏÖØÎó²î£¬£¬£¬£¬£¬£¬ÕâЩÎó²î¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐС¢¾Ü¾øÐ§À͹¥»÷»ò»ñȡװ±¸µÄµÇ¼ƾ֤¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨WAGO PFC200ºÍPFC100¿ØÖÆÆ÷£¬£¬£¬£¬£¬£¬ËüÃDZ»ÆÕ±éÓÃÓÚÆû³µ¡¢Ìú·¡¢µçÁ¦¹¤³Ì¡¢ÖÆÔìºÍÐÞ½¨ÎïÖÎÀíµÈÐÐÒµÖС£¡£¡£¡£¡£Õâ9¸öÎó²î£¨CVE-2019-5073~CVE-2019-5075£¬£¬£¬£¬£¬£¬CVE-2019-5077~CVE-2019-5082£©µÄ»ù´¡Ôµ¹ÊÔÓÉÔÚÓÚ¿ØÖÆÆ÷ʹÓõÄÊäÈë/Êä³ö¼ì²éÉèÖÃЧÀ͵ÄÐÒé´¦Öóͷ£´úÂëÖб£´æÎÊÌâ¡£¡£¡£¡£¡£TalosÌåÏÖûÓÐÖ¤¾ÝÅú×¢ÕâЩÎó²îÒÑÔÚÒ°ÍⱻʹÓᣡ£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/several-critical-vulnerabilities-found-wago-controllers
5.F-SecureÔÚClickShareÎÞÏßÑÝʾϵͳÖз¢Ã÷¶à¸öÎó²î

F-SecureÑо¿Ö°Ô±·¢Ã÷°Í¿É£¨Barco£©¹«Ë¾ClickShareÎÞÏßÑÝʾϵͳ±£´æ¶à¸ö¿É±»Ê¹ÓõÄÇå¾²Îó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²î×èµ²ºÍ¸Ä¶¯ÑÝʾÀú³ÌÖеÄÐÅÏ¢¡¢ÇÔÈ¡ÃÜÂëµÈÉñÃØÐÅÏ¢ÒÔ¼°×°ÖúóÃÅºÍÆäËü¶ñÒâÈí¼þµÈ¡£¡£¡£¡£¡£ÕâЩÎó²îµÄCVE IDΪCVE-2017-7936¡¢CVE-2017-7932ÒÔ¼°CVE-2019-18824~CVE-2019-18833¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÓÚ10ÔÂ9ÈÕÓë°Í¿É·ÖÏíÁËÕâЩ·¢Ã÷£¬£¬£¬£¬£¬£¬°Í¿ÉÒÑÔÚÆäÍøÕ¾ÉÏÐû²¼Á˹̼þ°æÔÀ´»º½â²¿·ÖÎó²î£¬£¬£¬£¬£¬£¬ÁíÒ»Ð©Éæ¼°ÎïÀíά»¤µÄÓ²¼þ×é¼þÖеÄÎó²î¿ÉÄܲ»»á±»ÐÞ¸´¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/12/17/wireless-presentation-system-vulnerabilities/
6.BitglassÐû²¼2019Äê½ðÈÚÐÐÒµÊý¾Ýй¶±¨¸æ
¾ÝBitglass³Æ£¬£¬£¬£¬£¬£¬2019ÄêËùÓÐÊý¾Ýй¶ÊÂÎñÖÐÖ»ÓÐ6£¥Éæ¼°µ½½ðÈÚЧÀ͹«Ë¾£¬£¬£¬£¬£¬£¬¿ÉÊÇÓëÆäËûÐÐÒµÏà±È£¬£¬£¬£¬£¬£¬ÕâЩÊÂÎñËðº¦Á˸ü¶àµÄ¼Í¼¡£¡£¡£¡£¡£2019ÄêËùÓÐ×ß©¼Í¼ÖÐ×ܼÆÓÐ60£¥ÒÔÉÏÊÇÓɽðÈÚЧÀÍ»ú¹¹Ð¹Â¶µÄ£¬£¬£¬£¬£¬£¬ÕâÖÁÉÙ²¿·ÖÓëCapital OneÌØ´óÊý¾Ýй¶ÊÂÎñÓйأ¬£¬£¬£¬£¬£¬¸ÃÊÂÎñй¶ÁËÁè¼Ý1ÒÚÌõ¼Í¼¡£¡£¡£¡£¡£2019ÄêºÚ¿ÍºÍ¶ñÒâÈí¼þÈÔÈ»ÊǽðÈÚЧÀÍÊý¾Ýй¶µÄÖ÷ÒªÔµ¹ÊÔÓÉ£¬£¬£¬£¬£¬£¬Õ¼74.5£¥£¨ÂÔ¸ßÓÚ2018ÄêµÄ73.5£¥£©¡£¡£¡£¡£¡£ÄÚ²¿Íþв´Ó2018ÄêµÄ2.9£¥ÔöÌíµ½½ñÄêµÄ5.5£¥£¬£¬£¬£¬£¬£¬¶øÒâÍâй¶´Ó14.7£¥ÔöÌíµ½18.2£¥¡£¡£¡£¡£¡£ÔÚÒÑÍù¼¸ÄêÖУ¬£¬£¬£¬£¬£¬½ðÈÚЧÀÍÆ½¾ùÿÌõй¶¼Í¼µÄ±¾Ç®ÓÐËùÔöÌí£¨210ÃÀÔª£©£¬£¬£¬£¬£¬£¬Áè¼ÝÁËÒ½ÁƱ£½¡ÐÐÒµ£¨429ÃÀÔª£©Ö®ÍâµÄËùÓÐÆäËüÐÐÒµ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/12/17/data-breaches-financial-services/


¾©¹«Íø°²±¸11010802024551ºÅ