¶íÂÞ˹Èý¸ö˽ÈËÒøÐеĽü90Íò¿Í»§ÐÅÏ¢±»¹ûÕæ£»£»£» £»WordPress Live ChatÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î

Ðû²¼Ê±¼ä 2019-06-12
1¡¢WordPress̸Ìì²å¼þLive ChatÐÂÎó²î£¬£¬£¬¿Éµ¼Ö»Ự±»Ð®ÖÆ

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
Çå¾²Ñо¿Ö°Ô±Alert LogicÅû¶WordPressʵʱ̸Ìì²å¼þLive ChatÖеÄÒ»¸öÑÏÖØÎó²î¡£¡£¡£ ¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-12498£©Ô´ÓÚ¶ÔÉí·ÝÑéÖ¤µÄ²»×¼È·¼ì²é£¬£¬£¬¿ÉÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß»á¼ûREST API¶Ëµã£¬£¬£¬´Ó¶øÇÔȡ̸Ìì¼Í¼»òÐ®ÖÆÌ¸Ìì»á»°¡£¡£¡£ ¡£¡£¡£¡£Live Chat±»Áè¼Ý5Íò¼ÒÆóÒµÍøÕ¾Ê¹ÓÃÒÔÌṩ¿Í»§Ö§³ÖºÍ̸Ìì»á»°¡£¡£¡£ ¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËLive Chat8.0.32¼°¸üÔçµÄ°æ±¾£¬£¬£¬½¨ÒéÓû§¸üÐÂÖÁ×îа汾¡£¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/06/wordpress-live-chat-plugin.html

2¡¢TecsonÓ͹޼à²â×°±¸ÑÏÖØÎó²î£¬£¬£¬ÔÊÐí¹¥»÷Õß»á¼ûWebÉèÖýçÃæ

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
Çå¾²Ñо¿Ö°Ô±Maxim Rupp·¢Ã÷µÂ¹úÖÆÔìÉÌTecsonÉú²úµÄһЩÓ͹޼à²â×°±¸±£´æÑÏÖØÎó²î£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚûÓÐÆ¾Ö¤µÄÇéÐÎÏ»á¼ûWebÉèÖýçÃæ¡£¡£¡£ ¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-12254£©µÄCVSSÆÀ·ÖΪ9.8·Ö£¬£¬£¬Ó°ÏìÁËLX-Net¡¢LX-Q-Net¡¢e-litro net¡¢SmartBox4 LANºÍSmartBox4 pro LANϵÁвúÆ·¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷ÕßÖ»ÐèÒªÖªµÀWebЧÀÍÆ÷ÉϵÄÌØ¶¨URLºÍÓÐÓÃÇëÇóµÄÃûÌ㬣¬£¬¼´¿É»á¼ûÉèÖýçÃæ²¢Éó²éºÍÐÞ¸ÄÉèÖ㬣¬£¬°üÀ¨ÃÜÂë¡¢¾¯±¨²ÎÊýºÍÊä³ö״̬µÈËùÓÐÉèÖᣡ£¡£ ¡£¡£¡£¡£½¨ÒéÓû§¸üÐÂÖÁ¹Ì¼þ6.3»ò½ûÓö˿Úת·¢¼°Ô¶³Ì»á¼û¡£¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/critical-vulnerability-exposes-oil-tank-monitoring-devices-attacks

3¡¢Ê©ÄÍµÂµçÆøModicon M580¶à¸öÎó²î£¬£¬£¬¿Éµ¼ÖÂDoS¼°ÐÅϢй¶

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
˼¿ÆTalosÅû¶ʩÄÍµÂµçÆøModicon M580ÖеĶà¸öÎó²î¡£¡£¡£ ¡£¡£¡£¡£Modicon M580ÊÇÊ©ÄÍµÂµçÆøModiconϵÁпɱà³Ì×Ô¶¯»¯¿ØÖÆÆ÷µÄ×îвúÆ·£¬£¬£¬Ñо¿Ö°Ô±ÔÚÆä¹Ì¼þ°æ±¾SV2.70Öз¢Ã÷¶à¸öÎó²î£¬£¬£¬°üÀ¨¿Éµ¼ÖÂDoSµÄÎó²î£¨CVE-2018-7846¡¢CVE-2018-7849¡¢CVE-2018-7843£©£¬£¬£¬¿Éµ¼ÖÂÐÅϢй¶µÄÎó²î£¨CVE-2018-7844¡¢CVE-2018-7848£©¼°Éí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2018-7842£©µÈ¡£¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.talosintelligence.com/2019/06/vulnerability-spotlight-multiple.html

4¡¢FIN8 APTÇÄÈ»Á½Äêºó»Ø¹é£¬£¬£¬Ö÷ÒªÕë¶ÔÂùݵÄPOSϵͳ

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
Çå¾²³§ÉÌMorphisec·¢Ã÷APT×éÖ¯FIN8µÄй¥»÷»î¶¯£¬£¬£¬Õâ±ê¼ÇןÃ×éÖ¯ÔÚÇÄÈ»Á½ÄêºóÔٴηºÆð¡£¡£¡£ ¡£¡£¡£¡£ÉÏÒ»´Î¹ØÓÚFIN8µÄ±¨¸æÊÇ2016ÄêºÍ2017ÄêFireEyeºÍroot9BÐû²¼µÄһϵÁÐÑо¿±¨¸æ£¬£¬£¬Æäʱ¸Ã×éÖ¯Ö÷ÒªÕë¶ÔÁãÊÛÒµµÄPOSϵͳ¡£¡£¡£ ¡£¡£¡£¡£MoprihsecÌåÏÖÔÚ2019ÄêÊӲ쵽FIN8Õë¶ÔÂùÝÒµPOSϵͳµÄй¥»÷»î¶¯£¬£¬£¬¹¥»÷ÕßʹÓÃÁËÓë֮ǰÏàͬµÄ¶ñÒâÈí¼þ£¬£¬£¬µ«¸ÄÉÆÁËÌӱܼì²â»úÖÆºÍ³¤ÆÚÐÔ»úÖÆ£¬£¬£¬ÕâÅú×¢¸Ã×éÖ¯Ò»Ö±ÔÚ¶Ô¶ñÒ⹤¾ß¾ÙÐпª·¢¡£¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/fin8-hackers-return-after-two-years-with-attacks-against-hospitality-sector/

5¡¢NSHAÔâ´¹ÂÚ¹¥»÷£¬£¬£¬½ü3000Ãû»¼ÕßµÄPHIÐÅϢй¶

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾
 
¼ÓÄôóÐÂ˹¿ÆÉáÊ¡ÎÀÉú¾Ö£¨NSHA£©ÕýÔÚת´ïÒ»ÆðÉæ¼°½ü3000Ãû»¼ÕßµÄÒþ˽й¶ÊÂÎñ¡£¡£¡£ ¡£¡£¡£¡£¸Ã²¿·ÖÌåÏÖ£¬£¬£¬ÔÚ2019Äê5ÔÂ8ÈÕÆäÔ±¹¤µÄµç×ÓÓÊÏäÕË»§Ôâµ½´¹ÂÚ¹¥»÷£¬£¬£¬¹¥»÷ÕßÇÔÈ¡ÁËÆäÓÊÏäµÄµÇ¼ƾ֤£¬£¬£¬²¢¿ÉÄÜ»á¼ûÁË»¼ÕßµÄPHIÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¡£NSHAµÄITÍŶÓÓÚ2019Äê5ÔÂ13ÈÕ¼ì²âµ½¸ÃÊÂÎñ£¬£¬£¬²¢½«¾ÙÐнøÒ»²½µÄÊӲ졣¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://globalnews.ca/news/5373338/nova-scotia-health-authority-privacy-breach/

6¡¢¶íÂÞ˹Èý¸ö˽ÈËÒøÐеĽü90Íò¿Í»§ÐÅÏ¢±»¹ûÕæ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

 
¶íÂÞ˹Èý¼ÒÖ÷Ҫ˽ÈËÒøÐеĽü90Íò¿Í»§Êý¾Ý±»¹ûÕæ£¬£¬£¬°üÀ¨OTP Bank¡¢Alfa BankºÍHCF Bank¡£¡£¡£ ¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µç»°ºÅÂë¡¢µØµã¡¢ÐÅÓöî¶È¡¢»¤ÕÕÏêϸÐÅÏ¢ÒÔ¼°Ä³Ð©°¸ÀýÖеÄÊÂÇéËùÔÚ¡¢³öÉúÄê·ÝºÍÕË»§Óà¶î¡£¡£¡£ ¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎúÕâЩй¶Êý¾Ý¿âµÄȪԴ¡£¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/personal-information-of-nearly-900000-banking-customers-of-three-major-russian-banks-leaked-online-54e078f9