Ó¡¶ÈÕþ¸®»ú¹¹ÒâÍâй¶1250ÍòÓÐÉíÅ®ÐÔµÄÒ½ÁÆÐÅÏ¢£»£»£»£»2.6Íò¸öKibanaʵÀý£»£»£»£»1.35Íò¸öiSCSI´æ´¢¼¯Èº
Ðû²¼Ê±¼ä 2019-04-03
Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý2.6Íò¸öKibanaʵÀýÔÚÍøÉÏ̻¶¡£¡£¡£¡£¡£KibanaÊÇÒ»¸ö¿ªÔ´µÄÆÊÎöºÍ¿ÉÊÓ»¯Æ½Ì¨£¬£¬£¬Ö¼ÔÚʵʱÆÊÎöElasticsearchÊý¾Ý¿âÖеÄÊý¾Ý¡£¡£¡£¡£¡£´ó´ó¶¼Ì»Â¶µÄʵÀý¶¼Ã»ÓÐÊܵ½±£»£»£»£»¤£¬£¬£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÓû§»á¼ûÒDZíÅÌ¡£¡£¡£¡£¡£ÕâЩʵÀýÊôÓÚµç×Óѧϰƽ̨¡¢ÒøÐÐϵͳ¡¢Í£³µÖÎÀíϵͳ¡¢Ò½ÔººÍ´óѧµÈ´óÐÍ»ú¹¹£¬£¬£¬ÃÀ¹ú£¨8311¸ö£©ÊÇ̻¶ʵÀý×î¶àµÄ¹ú¼Ò£¬£¬£¬Æä´ÎÊÇÖйú£¨7282£©¡¢µÂ¹ú£¨1709£©ºÍ·¨¹ú£¨1152£©¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬Ðí¶àʵÀý¶¼ÔËÐйýʱµÄÈí¼þ°æ±¾£¨±£´æí§ÒâÎļþ°üÀ¨Îó²î£©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/kibana-data-security.html2.Áè¼Ý1.35Íò¸öiSCSI´æ´¢¼¯ÈºÒòÉèÖùýʧÔÚÍøÉÏ̻¶
Çå¾²Ñо¿Ö°Ô±A Shadow·¢Ã÷Áè¼Ý1.35Íò¸öiSCSI´æ´¢¼¯ÈºÒòÉèÖùýʧÔÚÍøÉÏ̻¶¡£¡£¡£¡£¡£ÕâЩ¼¯ÈºÒòδÆôÓÃÉí·ÝÑéÖ¤£¬£¬£¬µ¼Ö·¸·¨·Ö×Ó¿ÉÒÔͨ¹ý»¥ÁªÍø»á¼ûÕâЩ´ÅÅÌÕóÁкÍNAS×°±¸£¬£¬£¬Ê¹µÃÆóÒµµÄÃô¸ÐÊý¾ÝÃæÁÙΣº¦¡£¡£¡£¡£¡£ÕâЩiSCSI¼¯ÈºÊôÓÚ˽Ӫ¹«Ë¾¡¢Õþ¸®»ú¹¹¡¢´óѧºÍÑо¿»ú¹¹µÈ£¬£¬£¬ÊÇÍøÂç·¸·¨¼¯ÍŵÄÀíÏë¹¥»÷Ä¿µÄ¡£¡£¡£¡£¡£
https://www.zdnet.com/article/over-13k-iscsi-storage-clusters-left-exposed-online-without-a-password/
3.ŦԼÊ׸®°Â¶û°ÍÄáÊÐÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ËðʧÈÔÔÚÆÀ¹ÀÖÐ

ÃÀ¹úŦԼÖÝÊ׸®°Â¶û°ÍÄáÊÐÓÚ3ÔÂ30ÈÕÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬Ä¿½ñÈÔ²»ÇåÎúÆäÅÌËã»úϵͳµÄÊÜËðˮƽ£¬£¬£¬µ«Æ¾Ö¤¸ÃÊйÙÍøÐû²¼µÄÐÂΟ壬£¬£¬ËùÓеͼ»áЧÀͶ¼ÒÑ¿ÉÓ㬣¬£¬µ«³öÉú֤ʵ¡¢éæÃü֤ʵºÍÍê»éÖ¤ÊéЧÀͳýÍâ¡£¡£¡£¡£¡£Ã»ÓÐÖ¤¾ÝÅúעСÎÒ˽¼ÒÊý¾ÝÊÜË𣬣¬£¬µ«¶¼»áµÄн×ÊЧÀÍÊܵ½Ó°Ï죬£¬£¬²»¿ÉÈ·¶¨¸ÃÊÐÊÇ·ñ»áÖ§¸¶Êê½ð¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-york-albany-capital-hit-by-ransomware-attack/4.Ó¡¶ÈÕþ¸®»ú¹¹ÒâÍâй¶1250ÍòÓÐÉíÅ®ÐÔµÄÒ½ÁÆÐÅÏ¢
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/indian-govt-agency-left-details-of-millions-of-pregnant-women-exposed-online/5¡£¡£¡£¡£¡£GoogleÐû²¼4ÔÂAndroidÇå¾²¸üУ¬£¬£¬ÐÞ¸´¶à¸öÎó²î
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/google-fixes-two-critical-android-code-execution-vulnerabilities/6.ApacheÐû²¼Ð°汾2.4.39£¬£¬£¬ÐÞ¸´¶à¸öÎó²î
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/apache-bug-lets-normal-users-gain-root-access-via-scripts/