Pwn2OwnÊ×ÈÕÑÇÂíÑ·Echo¼°ÈýÐÇË÷ÄáµçÊÓ±»¹¥ÆÆ£»2019ÄêÇï¼¾´¹µö¹¥»÷»î¶¯Ôö³¤ÖÁÈýÄêÀ´×î¸ß¼Í¼

°ä²¼¹¦·ò 2019-11-08
1¡¢Pwn2OwnÊ×ÈÕÑÇÂíÑ·Echo¼°ÈýÐÇË÷ÄáµçÊÓ¾ù±»¹¥ÆÆ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÔÚPwn2Own Tokyo 2019ºÚ¿Í´óÈüµÄµÚÒ»Ì죬ÑÇÂíÑ·EchoÖÇÄÜÒôÏä¡¢ÈýÐǺÍË÷ÄáµÄÖÇÄܵçÊÓ¡¢Ó×Ã×9ÊÖ»úÒÔ¼°NetgearºÍTP-Link·ÓÉÆ÷¾ù±»²ÎÈüÕß¹¥ÆÆ¡£±¾´Î´óÈüÊÇÓÉZero Day Initiative×éÖ¯µÄ£¬Ö¸±êÉ豸Ô̺¬17¿î£¬¹²³ÐŵÌṩ³¬¹ý75ÍòÃÀÔªµÄÏÖ½ðºÍ½±Æ·¡£ÕâÒ²Êdzõ´ÎPwn2Own½«FacebookµÄPortalÖÇÄÜÏÔʾÆ÷ºÍOculus Quest VRÍ·¿øÁÐÈëÖ¸±ê¡£ÔÚ´óÈüÊ×ÈÕ²ÎÈüÕßÒѾ­»ñµÃÁË19.5ÍòÃÀÔªµÄ¼Î½±£¬ÊÕ³É×î¶àµÄÊÇFluoroacetateÍŶÓ£¬¸ÃÍŶӱðÀë¹¥ÆÆÁËË÷ÄáX800GµçÊÓ¡¢ÑÇÂíÑ·Echo¡¢ÈýÐÇQ60µçÊÓ¡¢Ó×Ã×9ºÍGalaxy S10¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/facebook-portal-survives-pwn2own-hacking-contest-amazon-echo-got-hacked/

2¡¢ÃÀ¹úÍøÂç˾ÁÔÚVirusTotalÉÏ·ÖÏí7¸ö¶ñÒâÑù±¾


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úÍøÂç˾ÁÔÚVirusTotalÉϰ䲼ÁË7¸öеĶñÒâÈí¼þÑù±¾£¬ÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©¼¤ÀøÓû§²é¿´ÕâЩÑù±¾²¢½Ó¼ûCISAµÄ¶ñÒâ´úÂë·À»¤Êµ¼Ê¡£ÓÐ×êÑÐÈËÔ±ÔÚTwitterÉϻظ´³ÆÕâЩÑù±¾¿ÉÄÜÓëAPT28ÓйØ¡£¸Ã»ú¹¹ÉÏÒ»´Î¹²Ïí¶ñÒâÑù±¾ÊÇÔÚÁ½¸öÔÂǰ£¬ÆäÊ±ÍøÂç˾Á°ä²¼ÁË11¸öÓ볯ÏÊAPT×éÖ¯LazarusÓйصÄÑù±¾¡£


Ô­ÎÄÁ´½Ó£º

https://www.us-cert.gov/ncas/current-activity/2019/11/06/us-cyber-command-shares-seven-new-malware-samples

3¡¢Magento 1.x½«ÖÕ³¡¸üУ¬20¶àÍò¸öÍøÕ¾Ãæ¶Ô·çÏÕ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Magento 1.x·ÖÖ§½«ÔÚ2020Äê6Ô´ﵽÐÔÃüÖÜÆÚ£¨EOL£©£¬½ìʱ»ùÓÚ¸ÃÆ½Ì¨µÄÔÚÏßÉ̵꽫ÎÞ·¨ÊÕµ½°²È«¸üУ¬ÕâÒâζ×ÅËüÃǽ«Ãæ¶ÔÍøÕ¾±»ºÚ¿ÍÈëÇÖ»òϰȾ¶ñÒâ´úÂ루ÈçMagecart£©µÄ·çÏÕ¡£¾Ýͳ¼ÆÄ¿Ç°ÊÜÓ°ÏìµÄÔÚÏßÉ̵êÊýÁ¿ÔÚ20Íòµ½24ÍòÖ®¼ä£¬ÕâЩÉÌµê±ØÒªÔÚ½«À´9¸öÔÂÄÚ¶ÔÆäºó¶Ëƽ̨½øÐÐÉý¼¶£¬ºÃ±ÈǨáãµ½Magento 2.x·ÖÖ§¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/between-200000-and-240000-magento-online-stores-will-reach-eol-next-year/

4¡¢¼ÓÀû¸£ÄáÑÇÖÝDMVй¶¼ÝʻԱÊý¾Ý³¤´ïËÄÄ깦·ò


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖÝÆû³µÖÎÀí²¿ÃÅ£¨DMV£©Ð¹Â¶ÊýǧÃû¼ÝʻԱµÄÊý¾Ý³¤´ï4ÄêµÄ¹¦·ò¡£¹²ÓÐ3200Ãû¼ÝʻԱ±»Éæ¼°£¬ËûÃǵÄÐÅÏ¢±»Î¥¹æ·ÖÏí¸ø7¸ö»ú¹¹£¬Ô̺¬San DiegoºÍSanta ClaraÏØµÄµØÓò¼ì²ì¹Ù¡¢Ó×ÐÍÆóÒµÖÎÀí¾Ö¡¢¹ú˰¾ÖµÈ²¿ÃÅ¡£¾Ý¡¶Âåɼí¶Ê±±¨±¨Â·¡·£¬ÕâЩ»ú¹¹¿ÉÔÚ·¸×ï»î¶¯µ÷²é»ò˰·¨µ÷²éÖÐÎ¥¹æ½Ó¼ûDMV¶³öµÄÊý¾Ý£¬µ«Êý¾ÝûÓж³ö¸øÓ×ÎÒ¡£ÔÚ8ÔÂ2ÈÕ·¢ÏÖÎ¥¹æÐÐΪºó²»¾ÃDMV¼´ÏÞ¶ÈÁ˶ÔÊý¾ÝµÄ½Ó¼û¡£

Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/california-dmv-exposes-drivers/

5¡¢2019ÄêÇï¼¾´¹µö¹¥»÷»î¶¯Ôö³¤ÖÁÈýÄêÀ´×î¸ß¼Í¼


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝAPWGµÄͳ¼ÆÊý¾Ý£¬2019ÄêÇï¼¾ÍøÂç´¹µö¹¥»÷Ôö³¤ÖÁÈýÄêÀ´µÄ×î¸ß¼Í¼¡£ÔÚ2019Äê7ÔÂÖÁ9ÔÂÆÚ¼ä¼ì²âµ½µÄ´¹µöÍøÕ¾×ÜÊýΪ266387£¬±È2019ÄêµÚ¶þ¼¾¶ÈµÄ182465Ôö³¤ÁË46%£¬ÏÕЩÊÇ2018ÄêµÚËÄʱ¶ÈµÄ138328µÄÁ½±¶¡£³ýÁË´¹µöÍøÕ¾ÊýÁ¿µÄÔö³¤Ö®±í£¬2019ÄêµÚÈý¼¾¶ÈÊÜ´¹µö¹¥»÷µÄÆ·ÅÆÊýÁ¿Ò²ÏÔÖøÔö³¤£¬¾ùÔÈÿÔÂÓÐ400¶à¸öÆ·ÅÆÊܵ½¹¥»÷£¬¶øµÚ¶þ¼¾¶ÈΪ313¸ö¡£

Ô­ÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/11/07/phishing-attacks-levels-rise/

6¡¢ÑÇÂíÑ·°²·ÀÃÅÁåRing Video DoorbellÒ×ÔâMitm¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Bitdefender°²È«×êÑÐÈËÔ±·¢ÏÖÑÇÂíÑ·µÄRing Video Doorbell ProÉ豸ÖдæÔÚ¸ßΣ·ì϶£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐÖÐÑëÈ˹¥»÷²¢ÇÔÈ¡Óû§µÄWi-FiÃÜÂë¡£Ring Video DoorbellÊÇÒ»¸ö´øÉãÏñÍ·µÄÖÇÄÜÎÞÏß°²·ÀÃÅÁ壬×êÑÐÈËÔ±·¢ÏÖ¸ÃÉ豸ÓëAPPµÄͨѶΪ²»°²È«µÄHTTP´«Ê䣬¹¥»÷Õß¿ÉÓÕÆ­Óû§³ÁÐÂÅäÖøÃÉ豸²¢Ðá̽ÆäÃÜÂ룬½ø¶øÄܹ»ÌáÒé¸÷Àà¶ñÒâ»î¶¯£¬Ô̺¬Óë¼ÒÍ¥ÍøÂçÖеÄÉ豸½»»¥¡¢½Ó¼û±¾µØNAS¡¢ÈëÇÔìäËüÉ豸µÈ¡£¸Ã¹«Ë¾ÔÚ9ÔÂ5ÈÕ°ä²¼Á˽¨¸´²¹¶¡¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/11/ring-doorbell-wifi-password.html