LightInTheBoxй¶1.3TB WebЧÀÍÆ÷ÈÕÖ¾£»£»£»£»£»BitglassÐû²¼2019Äê½ðÈÚÐÐÒµÊý¾Ýй¶±¨¸æ
Ðû²¼Ê±¼ä 2019-12-18
1.LightInTheBoxй¶1.3TB WebЧÀÍÆ÷ÈÕÖ¾
vpnMentorÑо¿Ö°Ô±·¢Ã÷ÔÚÏßÁãÊÛÉÌLightInTheBoxµÄElasticsearchÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨1.3TB WebЧÀÍÆ÷ÈÕÖ¾¡£¡£¡£¡£¡£¡£LightInTheBoxרעÓÚСÅä¼þ¡¢´ò°çºÍÅäÊεÄÏúÊÛ£¬£¬£¬£¬£¬£¬£¬Æä´ó²¿·Ö¿Í»§Î»ÓÚ±±ÃÀºÍÅ·ÖÞ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ11ÔÂÏÂÑ®·¢Ã÷Á˸ÃÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬Êý¾Ý¿âÖеļͼ×ܼÆÁè¼Ý15ÒÚÌõ£¬£¬£¬£¬£¬£¬£¬»¹°üÀ¨Æä×ÓÍøÕ¾MiniInTheBox.comµÄÊý¾Ý¡£¡£¡£¡£¡£¡£ÈÕÖ¾°üÀ¨8ÔÂ9ÈÕÖÁ10ÔÂ11ÈÕÖ®¼äµÄÍøÕ¾»î¶¯£¬£¬£¬£¬£¬£¬£¬°üÀ¨µç×ÓÓʼþµØµã¡¢IPµØµã¡¢ÆÜÉí¹ú¼Ò/µØÇøÒÔ¼°Ã¿¸ö·Ã¿Í»á¼ûµÄÒ³ÃæµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/95231/data-breach/lightinthebox-data-leak.html
2.¼ÓÄôóÁÙ´²ÊµÑéÊÒЧÀÍÉÌLifeLabsй¶1500Íò¿Í»§ÐÅÏ¢
¼ÓÄôóÁÙ´²ÊµÑéÊÒЧÀÍÌṩÉÌLifeLabsй¶¶à´ï1500Íò¼ÓÄÃÖÁ¹«ÃñµÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£Æ¾Ö¤ÆäÐû²¼µÄÊý¾Ýй¶֪ͨ£¬£¬£¬£¬£¬£¬£¬Î´¾ÊÚȨµÄ¹¥»÷Õß»á¼ûÁË1500Íò¿Í»§µÄÐÕÃû¡¢µØµã¡¢µç×ÓÓʼþ¡¢µÇ¼Ãû¡¢ÃÜÂë¡¢³öÉúÈÕÆÚºÍÒ½ÁÆ¿¨ºÅÂë¡£¡£¡£¡£¡£¡£ÆäÖÐÔ¼8.5Íò¿Í»§µÄʵÑéÊÒЧ¹ûÒ²Ôâй¶¡£¡£¡£¡£¡£¡£¾Ý±¨µÀй¶µÄÊý¾ÝÖ÷ҪΪ2016Ä꼰֮ǰµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬Éæ¼°µÄ¿Í»§¾ø´ó´ó¶¼À´×ÔÓÚ±°Ê«Ê¡ºÍ°²¼òªʡ¡£¡£¡£¡£¡£¡£ÔÚ·¢Ã÷й¶ºó£¬£¬£¬£¬£¬£¬£¬LifeLabs´ÓºÚ¿ÍÄÇÀﹺÖÃÁ˱»µÁµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬µ«²»ÖªµÀËûÃÇΪ´ËÖ§¸¶Á˼¸¶àÊê½ð¡£¡£¡£¡£¡£¡£LifeLabs½«ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩһÄêµÄÃâ·ÑÉí·Ý͵ÇÔ±£»£»£»£»£»¤Ð§ÀÍ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/lifelabs-data-breach-exposes-personal-info-of-15-million-customers/
3.Ó¢ÌØ¶û¿ìËÙ´æ´¢Èí¼þÖб£´æDLLÐ®ÖÆÎó²î
Ó¢ÌØ¶û¿ìËÙ´æ´¢ÊÖÒÕ£¨Intel RST£©Èí¼þÖб£´æÒ»¸öDLLÐ®ÖÆÎó²î£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¶ñÒâ³ÌÐòÏÔʾΪÊÜÐÅÈγÌÐò£¬£¬£¬£¬£¬£¬£¬´Ó¶øÈƹý·À²¡¶¾ÒýÇæ¡£¡£¡£¡£¡£¡£SafeBreachµÄÑо¿Ö°Ô±·¢Ã÷IAStorDataMgrSvc.exe½«ÊµÑé´ÓC:\Program Files\Intel\Intel(R) Rapid Storage Technology\Îļþ¼ÐϼÓÔØ4¸öDLL£¨IoctlLog.dll¡¢IoctlNet.dll¡¢IoctlSim.dll¡¢DriverSim.dll£©£¬£¬£¬£¬£¬£¬£¬µ«ÕâЩDLLÔڸ÷¾¶Ï²¢²»±£´æ£¬£¬£¬£¬£¬£¬£¬Òò´ËÑо¿Ö°Ô±¿ÉÒÔ½¨Éè×Ô¼ºµÄDLLʹIAStorDataMgrSvc.exeÔÚÆô¶¯Ê±¼ÓÔØ£¬£¬£¬£¬£¬£¬£¬¸ÃDLL½«ÒÔSYSTEMÌØÈ¨¼ÓÔØ²¢ÊµÖÊÉϾßÓжÔÅÌËã»úµÄÍêÈ«»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£Ó¢ÌضûÒÑÓÚ12ÔÂ10ÈÕÐû²¼ÁË¿ìËÙ´æ´¢Èí¼þµÄ¸üаæÔÀ´½â¾ö¸ÃÎó²î¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/update-intels-rapid-storage-app-to-fix-bug-letting-malware-evade-av/
4.˼¿ÆTalosÅû¶WAGO PLCÖеĶà¸öÎó²î
˼¿ÆTalosÑо¿Ö°Ô±ÔÚWAGOÖÆÔìµÄ¿É±à³ÌÂß¼¿ØÖÆÆ÷£¨PLC£©Öз¢Ã÷¶à¸öÑÏÖØÎó²î£¬£¬£¬£¬£¬£¬£¬ÕâЩÎó²î¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐС¢¾Ü¾øÐ§À͹¥»÷»ò»ñȡװ±¸µÄµÇ¼ƾ֤¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨WAGO PFC200ºÍPFC100¿ØÖÆÆ÷£¬£¬£¬£¬£¬£¬£¬ËüÃDZ»ÆÕ±éÓÃÓÚÆû³µ¡¢Ìú·¡¢µçÁ¦¹¤³Ì¡¢ÖÆÔìºÍÐÞ½¨ÎïÖÎÀíµÈÐÐÒµÖС£¡£¡£¡£¡£¡£Õâ9¸öÎó²î£¨CVE-2019-5073~CVE-2019-5075£¬£¬£¬£¬£¬£¬£¬CVE-2019-5077~CVE-2019-5082£©µÄ»ù´¡Ôµ¹ÊÔÓÉÔÚÓÚ¿ØÖÆÆ÷ʹÓõÄÊäÈë/Êä³ö¼ì²éÉèÖÃЧÀ͵ÄÐÒé´¦Öóͷ£´úÂëÖб£´æÎÊÌâ¡£¡£¡£¡£¡£¡£TalosÌåÏÖûÓÐÖ¤¾ÝÅú×¢ÕâЩÎó²îÒÑÔÚÒ°ÍⱻʹÓᣡ£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/several-critical-vulnerabilities-found-wago-controllers
5.F-SecureÔÚClickShareÎÞÏßÑÝʾϵͳÖз¢Ã÷¶à¸öÎó²î
F-SecureÑо¿Ö°Ô±·¢Ã÷°Í¿É£¨Barco£©¹«Ë¾ClickShareÎÞÏßÑÝʾϵͳ±£´æ¶à¸ö¿É±»Ê¹ÓõÄÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²î×èµ²ºÍ¸Ä¶¯ÑÝʾÀú³ÌÖеÄÐÅÏ¢¡¢ÇÔÈ¡ÃÜÂëµÈÉñÃØÐÅÏ¢ÒÔ¼°×°ÖúóÃÅºÍÆäËü¶ñÒâÈí¼þµÈ¡£¡£¡£¡£¡£¡£ÕâЩÎó²îµÄCVE IDΪCVE-2017-7936¡¢CVE-2017-7932ÒÔ¼°CVE-2019-18824~CVE-2019-18833¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÓÚ10ÔÂ9ÈÕÓë°Í¿É·ÖÏíÁËÕâЩ·¢Ã÷£¬£¬£¬£¬£¬£¬£¬°Í¿ÉÒÑÔÚÆäÍøÕ¾ÉÏÐû²¼Á˹̼þ°æÔÀ´»º½â²¿·ÖÎó²î£¬£¬£¬£¬£¬£¬£¬ÁíÒ»Ð©Éæ¼°ÎïÀíά»¤µÄÓ²¼þ×é¼þÖеÄÎó²î¿ÉÄܲ»»á±»ÐÞ¸´¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/12/17/wireless-presentation-system-vulnerabilities/
6.BitglassÐû²¼2019Äê½ðÈÚÐÐÒµÊý¾Ýй¶±¨¸æ
¾ÝBitglass³Æ£¬£¬£¬£¬£¬£¬£¬2019ÄêËùÓÐÊý¾Ýй¶ÊÂÎñÖÐÖ»ÓÐ6£¥Éæ¼°µ½½ðÈÚЧÀ͹«Ë¾£¬£¬£¬£¬£¬£¬£¬¿ÉÊÇÓëÆäËûÐÐÒµÏà±È£¬£¬£¬£¬£¬£¬£¬ÕâЩÊÂÎñËðº¦Á˸ü¶àµÄ¼Í¼¡£¡£¡£¡£¡£¡£2019ÄêËùÓÐ×ß©¼Í¼ÖÐ×ܼÆÓÐ60£¥ÒÔÉÏÊÇÓɽðÈÚЧÀÍ»ú¹¹Ð¹Â¶µÄ£¬£¬£¬£¬£¬£¬£¬ÕâÖÁÉÙ²¿·ÖÓëCapital OneÌØ´óÊý¾Ýй¶ÊÂÎñÓйأ¬£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñй¶ÁËÁè¼Ý1ÒÚÌõ¼Í¼¡£¡£¡£¡£¡£¡£2019ÄêºÚ¿ÍºÍ¶ñÒâÈí¼þÈÔÈ»ÊǽðÈÚЧÀÍÊý¾Ýй¶µÄÖ÷ÒªÔµ¹ÊÔÓÉ£¬£¬£¬£¬£¬£¬£¬Õ¼74.5£¥£¨ÂÔ¸ßÓÚ2018ÄêµÄ73.5£¥£©¡£¡£¡£¡£¡£¡£ÄÚ²¿Íþв´Ó2018ÄêµÄ2.9£¥ÔöÌíµ½½ñÄêµÄ5.5£¥£¬£¬£¬£¬£¬£¬£¬¶øÒâÍâй¶´Ó14.7£¥ÔöÌíµ½18.2£¥¡£¡£¡£¡£¡£¡£ÔÚÒÑÍù¼¸ÄêÖУ¬£¬£¬£¬£¬£¬£¬½ðÈÚЧÀÍÆ½¾ùÿÌõй¶¼Í¼µÄ±¾Ç®ÓÐËùÔöÌí£¨210ÃÀÔª£©£¬£¬£¬£¬£¬£¬£¬Áè¼ÝÁËÒ½ÁƱ£½¡ÐÐÒµ£¨429ÃÀÔª£©Ö®ÍâµÄËùÓÐÆäËüÐÐÒµ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/12/17/data-breaches-financial-services/