FBIÖÒÑÔÒÁÀʺڿÍʹÓÃF5 BIG-IPÎó²î¹¥»÷ADC×°±¸ £»ÈýÐÇÐû²¼Çå¾²¸üР£¬ÐÞ¸´GalaxyÉϵĶà¸öÎó²î

Ðû²¼Ê±¼ä 2020-08-10

1.FBIÖÒÑÔÒÁÀʺڿÍʹÓÃF5 BIG-IPÎó²î¹¥»÷ADC×°±¸


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


FBIÐû²¼Ë½ÈËÐÐҵ֪ͨ£¨PIN£© £¬ÌåÏÖÒÁÀʺڿÍ×Ô2020Äê7Ô³õÒÔÀ´Ò»Ö±ÔÚʵÑéʹÓÃF5 BIG-IPµÄÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-5902£©À´¹¥»÷²Æ²ú500Ç¿ÆóÒµ¡¢Õþ¸®»ú¹¹ºÍÒøÐÐʹÓõÄÓ¦Óý»¸¶¿ØÖÆÆ÷£¨ADC£©×°±¸ ¡£Æ¾Ö¤FBIµÄÊÓ²ì £¬×Ô2019Äê8ÔÂÒÔÀ´ £¬¸ÃºÚ¿Í×éÖ¯ÌᳫÁ˶à´ÎÕë¶ÔVPN×°±¸µÄ¹¥»÷ £¬ÆäÖаüÀ¨µ«²»ÏÞÓÚPulse Secure£¨CVE 2019-11510 £¬CVE 2019-11539£©ºÍCitrix ADC /Íø¹Ø£¨CVE 2019-19781£© ¡£±ðµÄ £¬FBI PIN»¹ÌṩÁËΣº¦Ö¸±ê£¨IOC£©ºÍÕ½Êõ¡¢ÊÖÒÕÓë³ÌÐò£¨TTP£© £¬×ÊÖú˽ӪÐÐÒµ×é֯ʶ±ðÆäÍøÂçÉϵÄÏà¹Ø¶ñÒâÔ˶¯ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fbi-iranian-hackers-trying-to-exploit-critical-f5-big-ip-flaw/


2.ºÚ¿ÍʹÓÃαÔìµÄÇå¾²½¨Òé¶ÔcPanelÓû§´¹ÂÚ¹¥»÷


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ºÚ¿ÍαÔìWebÍйÜÖÎÀíÃæ°åÖеÄÎó²îÖÒÑÔ £¬Õë¶ÔcPanelÓû§Ìᳫ´¹ÂÚ¹¥»÷ ¡£¸Ã´¹ÂÚÈí¼þÒÔcPanel½ôÆÈ¸üÐÂÇëÇóΪÖ÷Ìâ £¬Éù³ÆÒÑÐû²¼¸üÐÂÀ´ÐÞ¸´cPanelºÍWHMÈí¼þ°æ±¾88.0.3 +¡¢86.0.21 +ºÍ78.0.49+ÖеÄÇå¾²ÎÊÌâ £¬²¢½¨ÒéËùÓÐÓû§×°ÖøüР¡£±ðµÄ £¬¹¥»÷Õß»¹×¢²áÁËÓòÃûcpanel7831.com £¬²¢Ê¹ÓÃAmazon Simple Email Service£¨SES£©·¢Ë͵ç×ÓÓʼþ £¬ÒÔʹȦÌ×Ô½·¢ÕæÊµ ¡£µ±Êܺ¦Õßµã»÷¸üÐÂÄúµÄcPanelºÍWHM×°ÖÃÁ´½Óºó £¬»á±»Öض¨Ïòµ½´¹ÂÚÍøÒ³ £¬²¢±»ÒªÇóÊäÈëcPanelƾ֤µÇ¼ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-security-advisory-used-in-clever-cpanel-phishing-attack/


3.HDL×Ô¶¯»¯ÏµÍ³ÖеÄÎó²îʹIoT×°±¸Ò×±»Ô¶³ÌÐ®ÖÆ


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Ñо¿Ö°Ô±Barak Sternberg·¢Ã÷HDL×Ô¶¯»¯ÏµÍ³Öб£´æÎó²î £¬Ê¹IoT×°±¸Ò×±»Ô¶³ÌÐ®ÖÆ ¡£ÔÚÑо¿Óû§ÔõÑùÉèÖúͿØÖÆHDL×é¼þʱ £¬Ñо¿Ö°Ô±·¢Ã÷ÔÚÒÆ¶¯Ó¦ÓóÌÐòÉÏ×¢²áÐÂÕÊ»§Ê±»á×Ô¶¯ÌìÉúÁíÒ»¸öÕÊ»§£¨ÔÚÔ­Óû§ÃûÖÐÌí¼ÓÁË×Ö·û´®debug£©À´Ó¦ÓÃÉèÖà ¡£ÆäÄ¿µÄÊÇÓ¦ÓÃÉèÖò¢½«ÍâµØ×°±¸µÄÉèÖ÷¢Ë͵½ÍⲿHDL·þÎñÆ÷ £¬ÒÔ±ãÆäËûÊÚȨÓû§¿ÉÒÔÏÂÔØËü²¢¿ØÖÆÖÇÄÜ¼Ò¾Ó ¡£¹¥»÷Õß¿ÉÒÔ×¢²ádebugÓû§ÃûµÄµç×ÓÓʼþµØµãÀ´ÎüÊÕÓйظü¸ÄÃÜÂëµÄ˵Ã÷ £¬²¢¿ÉÒÔ¿ØÖÆHDL×Ô¶¯»¯ÇéÐÎÖеÄ×é¼þ£¨µÆ¹â £¬ÎÂ¶È £¬ÉãÏñ»ú £¬ÖÖÖÖ´«¸ÐÆ÷£©ÒÔ¼°ÉèÖà ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/bugs-in-hdl-automation-expose-iot-devices-to-remote-hijacking/


4.Ñо¿Ö°Ô±·¢Ã÷ÎÀÐÇÅþÁ¬Ò×ÔâÍøÂç¹¥»÷²¢±»ºÚ¿Í×èµ²


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Å£½ò´óѧµÄÑо¿Ô±James Pavur·¢Ã÷È«ÇòÎÀÐÇÅþÁ¬Ò×ÔâÍøÂç¹¥»÷²¢±»ºÚ¿Í×èµ² ¡£Í¨³£ÇéÐÎÏ £¬ÎÀÐÇISP¿ÉÒÔÔÚÆ«Ô¶µØÇøÌṩ»¥ÁªÍøÅþÁ¬ ¡£µ±ÎÀÐÇISPΪ¿Í»§Ó뻥ÁªÍøÅþÁ¬Ê± £¬Ëü»áͨ¹ýͨѶÐŵÀ½«¿Í»§ÐźŴ«Êäµ½ÎÀÐÇÉÏ £¬Ö®ºóÐźű»·¢Ë͵½µØÇòµÄÍøÂçÅþÁ¬ £¬·µ»ØµÄÏìÓ¦ÐźŻáÔÚÎÀÐǺÍÓû§Ö®¼ä¾ÙÐй㲥´«Êä ¡£ÒÔÊǺڿͿÉÒÔ¹¥»÷λÓÚÌìÏÂÁíÒ»¸ö½ÇÂäµÄÎÀÐÇ £¬ÈôÊÇ×èµ²ÀÖ³É £¬Ôò¿ÉÈÝÒ×µØÇÔÌýÐÅÏ¢ ¡£PavurʵÑé·¢Ã÷ £¬¿É×èµ²ÍùÀ´ÓʼþºÍPayPalÕÊ»§Æ¾Ö¤Ö®ÀàµÄÃô¸ÐÐÅÏ¢ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/satellite-internet-connections-intercepted-hackers/


5.ÈýÐÇÐû²¼Çå¾²¸üР£¬ÐÞ¸´GalaxyÉϵĶà¸öÎó²î


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÈýÐÇÐû²¼8Ô·ÝÇå¾²¸üР£¬ÐÞ¸´GalaxyÉϵĶà¸öÑÏÖØµÄÎó²î ¡£×îΪÑÏÖØµÄÎó²îÊÇÓÉAndroid²Ù×÷ϵͳÖеÄÕûÊýÒç³öÎó²îÒýÆðµÄÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-0240£© £¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚ·ÇÌØÈ¨Àú³ÌÖÐÖ´ÐÐí§Òâ´úÂë ¡£±ðµÄ £¬´Ë´Î¸üл¹ÐÞ¸´ÁËÆä¿ò¼ÜÖеÄÌáȨÎó²î£¨CVE-2020-0238ºÍCVE-2020-0257£©¡¢IDÎó²î£¨CVE-2020-0239¡¢CVE-2020-0249ºÍCVE-2020-0258) £¬Ã½Ìå¿ò¼ÜÖеÄÌáȨÎó²î£¨CVE-2020-0241¡¢CVE-2020-0242ºÍCVE-2020-0243£© £¬ÒÔ¼°ÏµÍ³ÖÐÌáȨÎó²î£¨CVE-2020-0108ºÍCVE-2020-0256£©µÈÎó²î ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/samsung-rolls-out-android-updates-fixing-critical-vulnerabilities/


6.°¢¸ùÍ¢Ô¼12Íò¹«Ãñ¼ìÒßÐÅÏ¢ÒòÊý¾Ý¿âÉèÖùýʧй¶


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


°¢¸ùÍ¢ÒòÉèÖùýʧ £¬½«°üÀ¨Ô¼115000¸öCOVID-19¼ìÒß¿íÃâÉêÇëÈËÒ½ÁÆÊý¾ÝµÄElasticsearchÊý¾Ý¿âÔÚÍøÂçÉϹûÕæ ¡£Ð¹Â¶Êý¾Ý°üÀ¨ÉêÇëÈËÐÕÃû¡¢Éí·ÝÖ¤ºÅ¡¢Ë°ºÅ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµãµÈÐÅÏ¢ £¬»¹°üÀ¨ÉêÇëÈ˹ÍÖ÷ÐÕÃû¡¢µØµãºÍµç»°ºÅÂëµÈÐÅÏ¢ ¡£Æ¾Ö¤ÏÖÓеÄÖ¤¾Ý £¬Ñо¿Ö°Ô±ÒÔΪÕâЩÊý¾ÝÊôÓÚ°¢¸ù͢ʥºú°²Õþ¸®ºÍ¸Ã¹ú¹«¹²ÎÀÉú²¿ ¡£Rapid7ÔÆÇ徲ʵ¼ùÊÖÒÕ¸±×ܲÃChris DeRamusÌåÏÖ £¬Ð¹Â¶ÐÅÏ¢¿É±»Ê¹ÓþÙÐÐ˰Îñڲƭ¡¢Éí·ÝµÁÓûòÈÎºÎÆäËûÐÎʽµÄȦÌ× ¡£


Ô­ÎÄÁ´½Ó£º

http://www.digitaljournal.com/life/health/argentina-exposes-covid-19-health-data-in-error/article/575797