LightInTheBoxй¶1.3TB Web·þÎñÆ÷ÈÕÖ¾£»Bitglass°ä²¼2019Äê½ðÈÚÐÐÒµÊý¾Ýй¶»ã±¨
°ä²¼¹¦·ò 2019-12-18
1.LightInTheBoxй¶1.3TB Web·þÎñÆ÷ÈÕÖ¾
vpnMentor×êÑÐÈËÔ±·¢´Ë¿ÌÏßÁãÊÛÉÌLightInTheBoxµÄElasticsearchÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬ÆäÖÐÔ̺¬1.3TB Web·þÎñÆ÷ÈÕÖ¾¡£LightInTheBoxרһÓÚÓ×Åä¼þ¡¢·þ×°ºÍÅäÊεÄÏúÊÛ£¬Æä´ó²¿Ãſͻ§Î»ÓÚ±±ÃÀºÍÅ·ÖÞ¡£×êÑÐÈËÔ±ÔÚ11ÔÂÏÂÑ®·¢ÏÖÁ˸ÃÊý¾Ý¿â£¬Êý¾Ý¿âÖеļͼ×ܼƳ¬¹ý15ÒÚÌõ£¬»¹Ô̺¬Æä×ÓÍøÕ¾MiniInTheBox.comµÄÊý¾Ý¡£ÈÕÖ¾Ô̺¬8ÔÂ9ÈÕÖÁ10ÔÂ11ÈÕÖ®¼äµÄÍøÕ¾»î¶¯£¬Ô̺¬µç×ÓÓʼþµØÖ·¡¢IPµØÖ·¡¢¾Óס¹ú¶È/µØÓòÒÔ¼°Ã¿¸ö·Ã¿Í½Ó¼ûµÄÒ³ÃæµÈÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/95231/data-breach/lightinthebox-data-leak.html
2.¼ÓÄôóÁÙ´²³¢ÊÔÊÒ·þÎñÉÌLifeLabsй¶1500Íò¿Í»§ÐÅÏ¢
¼ÓÄôóÁÙ´²³¢ÊÔÊÒ·þÎñÌṩÉÌLifeLabsй¶¶à´ï1500Íò¼ÓÄôó¹«ÃñµÄÓ×ÎÒÐÅÏ¢¡£Æ¾¾ÝÆä°ä²¼µÄÊý¾Ýй¶֪ͨ£¬Î´¾ÊÚȨµÄ¹¥»÷Õß½Ó¼ûÁË1500Íò¿Í»§µÄÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþ¡¢µÇ¼Ãû¡¢ÃÜÂë¡¢µ®ÉúÈÕÆÚºÍÒ½ÁÆ¿¨ºÅÂë¡£ÆäÖÐÔ¼8.5Íò¿Í»§µÄ³¢ÊÔÊÒÁ˾ÖÒ²Ôâй¶¡£¾Ý±¨Â·Ð¹Â¶µÄÊý¾ÝÖØÒªÎª2016Ä꼰֮ǰµÄÊý¾Ý£¬Éæ¼°µÄ¿Í»§¾ø´óÎÞÊýÀ´×ÔÓÚ±°Ê«Ê¡ºÍ°²´ÖÂÔÊ¡¡£ÔÚ·¢ÏÖй¶ºó£¬LifeLabs´ÓºÚ¿ÍÄÇÀï²É°ìÁ˱»µÁµÄÊý¾Ý£¬µ«²»ÖªÂ·ËûÃÇΪ´ËÖ§¸¶Á˼¸¶àÊê½ð¡£LifeLabs½«ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩһÄêµÄÃâ·ÑÉí·Ý͵ÇÔ±£»¤·þÎñ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/lifelabs-data-breach-exposes-personal-info-of-15-million-customers/
3.Ó¢ÌØ¶û¼±¾ç´æ´¢Èí¼þÖдæÔÚDLL½Ù³Ö·ì϶
Ó¢ÌØ¶û¼±¾ç´æ´¢¼¼Êõ£¨Intel RST£©Èí¼þÖдæÔÚÒ»¸öDLL½Ù³Ö·ì϶£¬¸Ã·ì϶¿ÉÔÊÐí¶ñÒⷨʽÏÔʾΪÊÜÐÅÀµ·¨Ê½£¬´Ó¶øÈƹý·À²¡¶¾ÒýÇæ¡£SafeBreachµÄ×êÑÐÈËÔ±·¢ÏÖIAStorDataMgrSvc.exe½«³¢ÊÔ´ÓC:\Program Files\Intel\Intel(R) Rapid Storage Technology\Îļþ¼ÐϼÓÔØ4¸öDLL£¨IoctlLog.dll¡¢IoctlNet.dll¡¢IoctlSim.dll¡¢DriverSim.dll£©£¬µ«ÕâЩDLLÔÚ¸Ãõ辶ϲ¢²»´æÔÚ£¬Òò¶ø×êÑÐÈËÔ±Äܹ»´´½¨×Ô¼ºµÄDLLʹIAStorDataMgrSvc.exeÔÚÆô¶¯Ê±¼ÓÔØ£¬¸ÃDLL½«ÒÔSYSTEMÌØÈ¨¼ÓÔØ²¢ÄÚÈÝÉÏÓµÓжÔÍÆËã»úµÄÆëÈ«½Ó¼ûȨÏÞ¡£Ó¢ÌضûÒÑÓÚ12ÔÂ10ÈÕ°ä²¼Á˼±¾ç´æ´¢Èí¼þµÄ¸üаæÕý±¾½â¾ö¸Ã·ì϶¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/update-intels-rapid-storage-app-to-fix-bug-letting-malware-evade-av/
4.˼¿ÆTalosÅû¶WAGO PLCÖеĶà¸ö·ì϶
˼¿ÆTalos×êÑÐÈËÔ±ÔÚWAGOÔì×÷µÄ¿É±à³ÌÂß¼½ÚÔìÆ÷£¨PLC£©Öз¢ÏÖ¶à¸öÑϳÁ·ì϶£¬ÕâЩ·ì϶¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐÓ×¢»Ø¾ø·þÎñ¹¥»÷»ò»ñÈ¡É豸µÄµÇ¼ʹ´¦¡£ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬WAGO PFC200ºÍPFC100½ÚÔìÆ÷£¬ËüÃDZ»¿í·ºÓÃÓÚÆû³µ¡¢Ìú·¡¢µçÁ¦¹¤³Ì¡¢Ôì×÷ºÍ¹¹ÖþÎïÖÎÀíµÈÐÐÒµÖС£Õâ9¸ö·ì϶£¨CVE-2019-5073~CVE-2019-5075£¬CVE-2019-5077~CVE-2019-5082£©µÄµ××ÓÔÒòÔÚÓÚ½ÚÔìÆ÷ʹÓõÄÊäÈë/Êä³ö²é³ÅäÖ÷þÎñµÄºÍ̸´¦ÖôúÂëÖдæÔÚÎÊÌâ¡£Talos°µÊ¾Ã»ÓÐÖ¤¾ÝÅú×¢ÕâЩ·ì϶ÒÑÔÚÒ°±í±»ÀûÓá£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/several-critical-vulnerabilities-found-wago-controllers
5.F-SecureÔÚClickShareÎÞÏßÑÝʾϵͳÖз¢ÏÖ¶à¸ö·ì϶

F-Secure×êÑÐÈËÔ±·¢ÏְͿɣ¨Barco£©¹«Ë¾ClickShareÎÞÏßÑÝʾϵͳ´æÔÚ¶à¸ö¿É±»ÀûÓõݲȫ·ì϶£¬¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶À¹½ØºÍ´Û¸ÄÑÝʾ¹ý³ÌÖеÄÐÅÏ¢¡¢ÇÔÈ¡ÃÜÂëµÈ»úÃÜÐÅÏ¢ÒÔ¼°×°ÖúóÃÅºÍÆäËü¶ñÒâÈí¼þµÈ¡£ÕâЩ·ì϶µÄCVE IDΪCVE-2017-7936¡¢CVE-2017-7932ÒÔ¼°CVE-2019-18824~CVE-2019-18833¡£×êÑÐÈËÔ±ÓÚ10ÔÂ9ÈÕÓë°Í¿É·ÖÏíÁËÕâЩ·¢ÏÖ£¬°Í¿ÉÒÑÔÚÆäÍøÕ¾Éϰ䲼Á˹̼þ°æÕý±¾»º½â²¿ÃÅ·ì϶£¬ÁíÒ»Ð©Éæ¼°ÎïÀíÊØ»¤µÄÓ²¼þ×é¼þÖеķì϶¿ÉÄܲ»»á±»½¨¸´¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/12/17/wireless-presentation-system-vulnerabilities/
6.Bitglass°ä²¼2019Äê½ðÈÚÐÐÒµÊý¾Ýй¶»ã±¨
¾ÝBitglass³Æ£¬2019ÄêËùº±¼û¾Ýй¶ÊÂÎñÖÐÖ»ÓÐ6£¥Éæ¼°µ½½ðÈÚ·þÎñ¹«Ë¾£¬µ«ÊÇÓëÆäËûÐÐÒµÏà±È£¬ÕâЩÊÂÎñÇÖº¦Á˸ü¶àµÄ¼Í¼¡£2019ÄêËùÓÐй©¼Í¼ÖÐ×ܼÆÓÐ60£¥ÒÔÉÏÊÇÓɽðÈÚ·þÎñ»ú¹¹Ð¹Â¶µÄ£¬ÕâÖÁÉÙ²¿ÃÅÓëCapital OneÌØ´óÊý¾Ýй¶ÊÂÎñÓйأ¬¸ÃÊÂÎñй¶Á˳¬¹ý1Òڱʼͼ¡£2019ÄêºÚ¿ÍºÍ¶ñÒâÈí¼þÒÀÈ»ÊǽðÈÚ·þÎñÊý¾Ýй¶µÄÖØÒªÔÒò£¬Õ¼74.5£¥£¨ÂÔ¸ßÓÚ2018ÄêµÄ73.5£¥£©¡£ÄÚ²¿Íþв´Ó2018ÄêµÄ2.9£¥Ôö³¤µ½½ñÄêµÄ5.5£¥£¬¶øÒâ±íй¶´Ó14.7£¥Ôö³¤µ½18.2£¥¡£ÔÚ´Óǰ¼¸ÄêÖУ¬½ðÈÚ·þÎñ¾ùÔÈÿÌõй¶¼Í¼µÄ³É±¾ÓÐËùÔö³¤£¨210ÃÀÔª£©£¬³¬¹ýÁËÒ½ÁƱ£½¡ÐÐÒµ£¨429ÃÀÔª£©Ö®±íµÄËùÓÐÆäËüÐÐÒµ¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/12/17/data-breaches-financial-services/


¾©¹«Íø°²±¸11010802024551ºÅ