FBIÖÒÑÔÒÁÀʺڿÍʹÓÃF5 BIG-IPÎó²î¹¥»÷ADC×°±¸£»£»£»£»£»£»ÈýÐÇÐû²¼Çå¾²¸üУ¬£¬ £¬£¬£¬£¬ÐÞ¸´GalaxyÉϵĶà¸öÎó²î

Ðû²¼Ê±¼ä 2020-08-10

1.FBIÖÒÑÔÒÁÀʺڿÍʹÓÃF5 BIG-IPÎó²î¹¥»÷ADC×°±¸


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


FBIÐû²¼Ë½ÈËÐÐҵ֪ͨ£¨PIN£©£¬£¬ £¬£¬£¬£¬ÌåÏÖÒÁÀʺڿÍ×Ô2020Äê7Ô³õÒÔÀ´Ò»Ö±ÔÚʵÑéʹÓÃF5 BIG-IPµÄÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-5902£©À´¹¥»÷²Æ²ú500Ç¿ÆóÒµ¡¢Õþ¸®»ú¹¹ºÍÒøÐÐʹÓõÄÓ¦Óý»¸¶¿ØÖÆÆ÷£¨ADC£©×°±¸¡£¡£¡£¡£¡£ ¡£¡£Æ¾Ö¤FBIµÄÊӲ죬£¬ £¬£¬£¬£¬×Ô2019Äê8ÔÂÒÔÀ´£¬£¬ £¬£¬£¬£¬¸ÃºÚ¿Í×éÖ¯ÌᳫÁ˶à´ÎÕë¶ÔVPN×°±¸µÄ¹¥»÷£¬£¬ £¬£¬£¬£¬ÆäÖаüÀ¨µ«²»ÏÞÓÚPulse Secure£¨CVE 2019-11510£¬£¬ £¬£¬£¬£¬CVE 2019-11539£©ºÍCitrix ADC /Íø¹Ø£¨CVE 2019-19781£©¡£¡£¡£¡£¡£ ¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬FBI PIN»¹ÌṩÁËΣº¦Ö¸±ê£¨IOC£©ºÍÕ½Êõ¡¢ÊÖÒÕÓë³ÌÐò£¨TTP£©£¬£¬ £¬£¬£¬£¬×ÊÖú˽ӪÐÐÒµ×é֯ʶ±ðÆäÍøÂçÉϵÄÏà¹Ø¶ñÒâ»î¶¯¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fbi-iranian-hackers-trying-to-exploit-critical-f5-big-ip-flaw/


2.ºÚ¿ÍʹÓÃαÔìµÄÇå¾²½¨Òé¶ÔcPanelÓû§´¹ÂÚ¹¥»÷


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ºÚ¿ÍαÔìWebÍйÜÖÎÀíÃæ°åÖеÄÎó²îÖÒÑÔ£¬£¬ £¬£¬£¬£¬Õë¶ÔcPanelÓû§Ìᳫ´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£¸Ã´¹ÂÚÈí¼þÒÔcPanel½ôÆÈ¸üÐÂÇëÇóΪÖ÷Ì⣬£¬ £¬£¬£¬£¬Éù³ÆÒÑÐû²¼¸üÐÂÀ´ÐÞ¸´cPanelºÍWHMÈí¼þ°æ±¾88.0.3 +¡¢86.0.21 +ºÍ78.0.49+ÖеÄÇå¾²ÎÊÌ⣬£¬ £¬£¬£¬£¬²¢½¨ÒéËùÓÐÓû§×°ÖøüС£¡£¡£¡£¡£ ¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬¹¥»÷Õß»¹×¢²áÁËÓòÃûcpanel7831.com£¬£¬ £¬£¬£¬£¬²¢Ê¹ÓÃAmazon Simple Email Service£¨SES£©·¢Ë͵ç×ÓÓʼþ£¬£¬ £¬£¬£¬£¬ÒÔʹȦÌ×Ô½·¢ÕæÊµ¡£¡£¡£¡£¡£ ¡£¡£µ±Êܺ¦Õßµã»÷¸üÐÂÄúµÄcPanelºÍWHM×°ÖÃÁ´½Óºó£¬£¬ £¬£¬£¬£¬»á±»Öض¨Ïòµ½´¹ÂÚÍøÒ³£¬£¬ £¬£¬£¬£¬²¢±»ÒªÇóÊäÈëcPanelƾ֤µÇ¼¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-security-advisory-used-in-clever-cpanel-phishing-attack/


3.HDL×Ô¶¯»¯ÏµÍ³ÖеÄÎó²îʹIoT×°±¸Ò×±»Ô¶³ÌÐ®ÖÆ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ñо¿Ö°Ô±Barak Sternberg·¢Ã÷HDL×Ô¶¯»¯ÏµÍ³Öб£´æÎó²î£¬£¬ £¬£¬£¬£¬Ê¹IoT×°±¸Ò×±»Ô¶³ÌÐ®ÖÆ¡£¡£¡£¡£¡£ ¡£¡£ÔÚÑо¿Óû§ÔõÑùÉèÖúͿØÖÆHDL×é¼þʱ£¬£¬ £¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÔÚÒÆ¶¯Ó¦ÓóÌÐòÉÏ×¢²áÐÂÕÊ»§Ê±»á×Ô¶¯ÌìÉúÁíÒ»¸öÕÊ»§£¨ÔÚÔ­Óû§ÃûÖÐÌí¼ÓÁË×Ö·û´®debug£©À´Ó¦ÓÃÉèÖᣡ£¡£¡£¡£ ¡£¡£ÆäÄ¿µÄÊÇÓ¦ÓÃÉèÖò¢½«ÍâµØ×°±¸µÄÉèÖ÷¢Ë͵½ÍⲿHDLЧÀÍÆ÷£¬£¬ £¬£¬£¬£¬ÒÔ±ãÆäËûÊÚȨÓû§¿ÉÒÔÏÂÔØËü²¢¿ØÖÆÖÇÄܼҾÓ¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷Õß¿ÉÒÔ×¢²ádebugÓû§ÃûµÄµç×ÓÓʼþµØµãÀ´ÎüÊÕÓйظü¸ÄÃÜÂëµÄ˵Ã÷£¬£¬ £¬£¬£¬£¬²¢¿ÉÒÔ¿ØÖÆHDL×Ô¶¯»¯ÇéÐÎÖеÄ×é¼þ£¨µÆ¹â£¬£¬ £¬£¬£¬£¬Î¶È£¬£¬ £¬£¬£¬£¬ÉãÏñ»ú£¬£¬ £¬£¬£¬£¬ÖÖÖÖ´«¸ÐÆ÷£©ÒÔ¼°ÉèÖᣡ£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/bugs-in-hdl-automation-expose-iot-devices-to-remote-hijacking/


4.Ñо¿Ö°Ô±·¢Ã÷ÎÀÐÇÅþÁ¬Ò×ÔâÍøÂç¹¥»÷²¢±»ºÚ¿Í×èµ²


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Å£½ò´óѧµÄÑо¿Ô±James Pavur·¢Ã÷È«ÇòÎÀÐÇÅþÁ¬Ò×ÔâÍøÂç¹¥»÷²¢±»ºÚ¿Í×èµ²¡£¡£¡£¡£¡£ ¡£¡£Í¨³£ÇéÐÎÏ£¬£¬ £¬£¬£¬£¬ÎÀÐÇISP¿ÉÒÔÔÚÆ«Ô¶µØÇøÌṩ»¥ÁªÍøÅþÁ¬¡£¡£¡£¡£¡£ ¡£¡£µ±ÎÀÐÇISPΪ¿Í»§Ó뻥ÁªÍøÅþÁ¬Ê±£¬£¬ £¬£¬£¬£¬Ëü»áͨ¹ýͨѶÐŵÀ½«¿Í»§ÐźŴ«Êäµ½ÎÀÐÇÉÏ£¬£¬ £¬£¬£¬£¬Ö®ºóÐźű»·¢Ë͵½µØÇòµÄÍøÂçÅþÁ¬£¬£¬ £¬£¬£¬£¬·µ»ØµÄÏìÓ¦ÐźŻáÔÚÎÀÐǺÍÓû§Ö®¼ä¾ÙÐй㲥´«Êä¡£¡£¡£¡£¡£ ¡£¡£ÒÔÊǺڿͿÉÒÔ¹¥»÷λÓÚÌìÏÂÁíÒ»¸ö½ÇÂäµÄÎÀÐÇ£¬£¬ £¬£¬£¬£¬ÈôÊÇ×èµ²Àֳɣ¬£¬ £¬£¬£¬£¬Ôò¿ÉÈÝÒ×µØÇÔÌýÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£PavurʵÑé·¢Ã÷£¬£¬ £¬£¬£¬£¬¿É×èµ²ÍùÀ´ÓʼþºÍPayPalÕÊ»§Æ¾Ö¤Ö®ÀàµÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/satellite-internet-connections-intercepted-hackers/


5.ÈýÐÇÐû²¼Çå¾²¸üУ¬£¬ £¬£¬£¬£¬ÐÞ¸´GalaxyÉϵĶà¸öÎó²î


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÈýÐÇÐû²¼8Ô·ÝÇå¾²¸üУ¬£¬ £¬£¬£¬£¬ÐÞ¸´GalaxyÉϵĶà¸öÑÏÖØµÄÎó²î¡£¡£¡£¡£¡£ ¡£¡£×îΪÑÏÖØµÄÎó²îÊÇÓÉAndroid²Ù×÷ϵͳÖеÄÕûÊýÒç³öÎó²îÒýÆðµÄÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-0240£©£¬£¬ £¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚ·ÇÌØÈ¨Àú³ÌÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬´Ë´Î¸üл¹ÐÞ¸´ÁËÆä¿ò¼ÜÖеÄÌáȨÎó²î£¨CVE-2020-0238ºÍCVE-2020-0257£©¡¢IDÎó²î£¨CVE-2020-0239¡¢CVE-2020-0249ºÍCVE-2020-0258)£¬£¬ £¬£¬£¬£¬Ã½Ìå¿ò¼ÜÖеÄÌáȨÎó²î£¨CVE-2020-0241¡¢CVE-2020-0242ºÍCVE-2020-0243£©£¬£¬ £¬£¬£¬£¬ÒÔ¼°ÏµÍ³ÖÐÌáȨÎó²î£¨CVE-2020-0108ºÍCVE-2020-0256£©µÈÎó²î¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/samsung-rolls-out-android-updates-fixing-critical-vulnerabilities/


6.°¢¸ùÍ¢Ô¼12Íò¹«Ãñ¼ìÒßÐÅÏ¢ÒòÊý¾Ý¿âÉèÖùýʧй¶


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


°¢¸ùÍ¢ÒòÉèÖùýʧ£¬£¬ £¬£¬£¬£¬½«°üÀ¨Ô¼115000¸öCOVID-19¼ìÒß¿íÃâÉêÇëÈËÒ½ÁÆÊý¾ÝµÄElasticsearchÊý¾Ý¿âÔÚÍøÂçÉϹûÕæ¡£¡£¡£¡£¡£ ¡£¡£Ð¹Â¶Êý¾Ý°üÀ¨ÉêÇëÈËÐÕÃû¡¢Éí·ÝÖ¤ºÅ¡¢Ë°ºÅ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµãµÈÐÅÏ¢£¬£¬ £¬£¬£¬£¬»¹°üÀ¨ÉêÇëÈ˹ÍÖ÷ÐÕÃû¡¢µØµãºÍµç»°ºÅÂëµÈÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£Æ¾Ö¤ÏÖÓеÄÖ¤¾Ý£¬£¬ £¬£¬£¬£¬Ñо¿Ö°Ô±ÒÔΪÕâЩÊý¾ÝÊôÓÚ°¢¸ù͢ʥºú°²Õþ¸®ºÍ¸Ã¹ú¹«¹²ÎÀÉú²¿¡£¡£¡£¡£¡£ ¡£¡£Rapid7ÔÆÇ徲ʵ¼ùÊÖÒÕ¸±×ܲÃChris DeRamusÌåÏÖ£¬£¬ £¬£¬£¬£¬Ð¹Â¶ÐÅÏ¢¿É±»Ê¹ÓþÙÐÐ˰Îñڲƭ¡¢Éí·ÝµÁÓûòÈÎºÎÆäËûÐÎʽµÄȦÌס£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.digitaljournal.com/life/health/argentina-exposes-covid-19-health-data-in-error/article/575797