Ó¡¶Èµ±¾Ö»ú¹¹Òâ±íй¶1250Íò»³ÔÐÅ®ÐÔµÄÒ½ÁÆÐÅÏ¢£»2.6Íò¸öKibanaÊ·ý£»1.35Íò¸öiSCSI´æ´¢¼¯Èº
°ä²¼¹¦·ò 2019-04-03
×êÑÐÈËÔ±·¢ÏÖ³¬¹ý2.6Íò¸öKibanaÊ·ýÔÚÍøÉ϶³ö¡£KibanaÊÇÒ»¸ö¿ªÔ´µÄ·ÖÎöºÍ¿ÉÊÓ»¯Æ½Ì¨£¬Ö¼ÔÚʵʱ³½ÎöElasticsearchÊý¾Ý¿âÖеÄÊý¾Ý¡£´óÎÞÊý¶³öµÄÊ·ý¶¼Ã»ÓÐÊܵ½±£»¤£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÓû§½Ó¼ûÒDZíÅÌ¡£ÕâЩÊ·ýÊôÓÚµç×Ó½ø½¨Æ½Ì¨¡¢ÒøÐÐϵͳ¡¢Í£³µÖÎÀíϵͳ¡¢Ò½ÔººÍ´óѧµÈ´óÐÍ»ú¹¹£¬ÃÀ¹ú£¨8311¸ö£©ÊǶ³öÊ·ý×î¶àµÄ¹ú¶È£¬Æä´ÎÊÇÖйú£¨7282£©¡¢µÂ¹ú£¨1709£©ºÍ·¨¹ú£¨1152£©¡£´Ë±í£¬ºÜ¶àÊ·ý¶¼ÔËÐйýÆÚµÄÈí¼þ°æ±¾£¨´æÔÚËÁÒâÎļþÔ̺¬·ì϶£©¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/kibana-data-security.html2.³¬¹ý1.35Íò¸öiSCSI´æ´¢¼¯ÈºÒòÅäÖÃÃýÎóÔÚÍøÉ϶³ö
°²È«×êÑÐÈËÔ±A Shadow·¢ÏÖ³¬¹ý1.35Íò¸öiSCSI´æ´¢¼¯ÈºÒòÅäÖÃÃýÎóÔÚÍøÉ϶³ö¡£ÕâЩ¼¯ÈºÒòδÆôÓÃÉí·ÝÑéÖ¤£¬µ¼Ö·¸×ï·Ö×ÓÄܹ»Í¨¹ý»¥ÁªÍø½Ó¼ûÕâЩ´ÅÅÌÕóÁкÍNASÉ豸£¬Ê¹µÃÆóÒµµÄÃô¸ÐÊý¾ÝÃæ¶Ô·çÏÕ¡£ÕâЩiSCSI¼¯ÈºÊôÓÚ˽Ӫ¹«Ë¾¡¢µ±¾Ö»ú¹¹¡¢´óѧºÍ×êÑлú¹¹µÈ£¬ÊÇÍøÂç·¸×OÍŵÄÃÎÏë¹¥»÷Ö¸±ê¡£
https://www.zdnet.com/article/over-13k-iscsi-storage-clusters-left-exposed-online-without-a-password/
3.ŦԼÊ׸®°Â¶û°ÍÄáÊÐÔâÀÕË÷Èí¼þ¹¥»÷£¬ËðʧÈÔÔÚÆÀ¹ÀÖÐ
ÃÀ¹úŦԼÖÝÊ׸®°Â¶û°ÍÄáÊÐÓÚ3ÔÂ30ÈÕÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µ±Ç°ÈÔ²»Ã÷ÏÔÆäÍÆËã»úϵͳµÄÊÜËðˮƽ£¬µ«Æ¾¾Ý¸ÃÊйÙÍø°ä²¼µÄÐÂΟ壬ËùÓеijÇÊзþÎñ¶¼ÒÑ¿ÉÓ㬵«µ®ÉúÖ¤Ã÷¡¢éæÃüÖ¤Ã÷ºÍ³É»éÖ¤Êé·þÎñÖ®±í¡£Ã»ÓÐÖ¤¾ÝÅú×¢Ó×ÎÒÊý¾ÝÊÜË𣬵«³ÇÊеÄн×Ê·þÎñÊܵ½Ó°Ï죬²»ÄÜÈ·¶¨¸ÃÊÐÊÇ·ñ»áÖ§¸¶Êê½ð¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-york-albany-capital-hit-by-ransomware-attack/4.Ó¡¶Èµ±¾Ö»ú¹¹Òâ±íй¶1250Íò»³ÔÐÅ®ÐÔµÄÒ½ÁÆÐÅÏ¢
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/indian-govt-agency-left-details-of-millions-of-pregnant-women-exposed-online/5¡£Google°ä²¼4ÔÂAndroid°²È«¸üУ¬½¨¸´¶à¸ö·ì϶
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/google-fixes-two-critical-android-code-execution-vulnerabilities/6.Apache°ä²¼Ð°汾2.4.39£¬½¨¸´¶à¸ö·ì϶
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/apache-bug-lets-normal-users-gain-root-access-via-scripts/


¾©¹«Íø°²±¸11010802024551ºÅ