FBIÖÒ¸æÒÁÀʺڿÍÀûÓÃF5 BIG-IP·ì϶¹¥»÷ADCÉ豸£»ÈýÐǰ䲼°²È«¸üУ¬½¨¸´GalaxyÉϵĶà¸ö·ì϶

°ä²¼¹¦·ò 2020-08-10

1.FBIÖÒ¸æÒÁÀʺڿÍÀûÓÃF5 BIG-IP·ì϶¹¥»÷ADCÉ豸


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


FBI°ä²¼¸öÈËÐÐҵ֪ͨ£¨PIN£©£¬°µÊ¾ÒÁÀʺڿÍ×Ô2020Äê7Ô³õÒÔÀ´Ò»ÏòÔÚ³¢ÊÔÀûÓÃF5 BIG-IPµÄÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-5902£©À´¹¥»÷²Æ¸»500Ç¿ÆóÒµ¡¢µ±¾Ö»ú¹¹ºÍÒøÐÐʹÓõÄÀûÓý»¸¶½ÚÔìÆ÷£¨ADC£©É豸¡£Æ¾¾ÝFBIµÄµ÷²é£¬×Ô2019Äê8ÔÂÒÔÀ´£¬¸ÃºÚ¿Í×éÖ¯ÌáÒéÁËÂÅ´ÎÕë¶ÔVPNÉ豸µÄ¹¥»÷£¬ÆäÖÐÔ̺¬µ«²»ÏÞÓÚPulse Secure£¨CVE 2019-11510£¬CVE 2019-11539£©ºÍCitrix ADC /Íø¹Ø£¨CVE 2019-19781£©¡£´Ë±í£¬FBI PIN»¹ÌṩÁË·çÏÕÖ¸±ê£¨IOC£©ºÍÕ½Êõ¡¢¼¼ÊõÓ뷨ʽ£¨TTP£©£¬Ô®ÊÖ˽ӪÐÐÒµ×éÖ¯¼ø±ðÆäÍøÂçÉϵÄÓйضñÒâ»î¶¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fbi-iranian-hackers-trying-to-exploit-critical-f5-big-ip-flaw/


2.ºÚ¿ÍÀûÓÃαÔìµÄ°²È«½¨Òé¶ÔcPanelÓû§´¹µö¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ºÚ¿ÍαÔìWebÍйÜÖÎÀíÃæ°åÖеķì϶ÖҸ棬Õë¶ÔcPanelÓû§ÌáÒé´¹µö¹¥»÷¡£¸Ã´¹µöÈí¼þÒÔcPanel´¹Î£¸üÐÂÒªÇóΪÖ÷Ì⣬Ðû³ÆÒѰ䲼¸üÐÂÀ´½¨¸´cPanelºÍWHMÈí¼þ°æ±¾88.0.3 +¡¢86.0.21 +ºÍ78.0.49+ÖеݲȫÎÊÌ⣬²¢½¨ÒéËùÓÐЧ»§×°ÖøüС£´Ë±í£¬¹¥»÷Õß»¹×¢²áÁËÓòÃûcpanel7831.com£¬²¢Ê¹ÓÃAmazon Simple Email Service£¨SES£©·¢Ë͵ç×ÓÓʼþ£¬ÒÔʹȦÌ×Ô½·¢ÕæÊµ¡£µ±Êܺ¦Õßµã»÷¸üÐÂÄúµÄcPanelºÍWHM×°ÖÃÁ´½Óºó£¬»á±»³Á¶¨Ïòµ½´¹µöÍøÒ³£¬²¢±»ÒªÇóÊäÈëcPanelÍ´´¦µÇ¼¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-security-advisory-used-in-clever-cpanel-phishing-attack/


3.HDL×Ô¶¯»¯ÏµÍ³Öеķì϶ʹIoTÉ豸Ò×±»Ô¶³Ì½Ù³Ö


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±Barak Sternberg·¢ÏÖHDL×Ô¶¯»¯ÏµÍ³ÖдæÔÚ·ì϶£¬Ê¹IoTÉ豸Ò×±»Ô¶³Ì½Ù³Ö¡£ÔÚ×êÑÐÓû§ÈôºÎÅäÖúͽÚÔìHDL×é¼þʱ£¬×êÑÐÈËÔ±·¢´Ë¿ÌÒÆ¶¯ÀûÓ÷¨Ê½ÉÏ×¢²áÐÂÕÊ»§Ê±»á×Ô¶¯ÌìÉúÁíÒ»¸öÕÊ»§£¨ÔÚÔ­Óû§ÃûÖÐÔö³¤ÁË×Ö·û´®debug£©À´ÀûÓÃÉèÖá£ÆäÖ÷ÕÅÊÇÀûÓÃÉèÖò¢½«±¾µØÉ豸µÄÅäÖ÷¢Ë͵½±í²¿HDL·þÎñÆ÷£¬ÒÔ±ãÆäËûÊÚȨÓû§Äܹ»ÏÂÔØËü²¢½ÚÔìÖÇÄܼҾÓ¡£¹¥»÷ÕßÄܹ»×¢²ádebugÓû§ÃûµÄµç×ÓÓʼþµØÖ·À´½Ó¹ÜÓйظü¸ÄÃÜÂëµÄ×¢Ã÷£¬²¢Äܹ»½ÚÔìHDL×Ô¶¯»¯»·¾³ÖеÄ×é¼þ£¨µÆ¹â£¬Î¶È£¬ÉãÏñ»ú£¬¸÷Àà´«¸ÐÆ÷£©ÒÔ¼°ÅäÖá£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/bugs-in-hdl-automation-expose-iot-devices-to-remote-hijacking/


4.×êÑÐÈËÔ±·¢ÏÖÎÀÐÇÏνÓÒ×ÔâÍøÂç¹¥»÷²¢±»ºÚ¿ÍÀ¹½Ø


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Å£½ò´óѧµÄ×êÑÐÔ±James Pavur·¢ÏÖÈ«ÇòÎÀÐÇÏνÓÒ×ÔâÍøÂç¹¥»÷²¢±»ºÚ¿ÍÀ¹½Ø¡£Í¨³£Çé¿öÏ£¬ÎÀÐÇISPÄܹ»ÔÚÆ«Ô¶µØÓòÌṩ»¥ÁªÍøÏνÓ¡£µ±ÎÀÐÇISPΪ¿Í»§Ó뻥ÁªÍøÏνÓʱ£¬Ëü»áͨ¹ýͨѶÐÅ·½«¿Í»§ÐźŴ«Êäµ½ÎÀÐÇÉÏ£¬Ö®ºóÐźű»·¢Ë͵½µØÇòµÄÍøÂçÏνÓ£¬·µ»ØµÄÏìÓ¦ÐźŻáÔÚÎÀÐǺÍÓû§Ö®¼ä½øÐй㲥´«Êä¡£ËùÒÔºÚ¿ÍÄܹ»¹¥»÷λÓÚÊÀ½çÁíÒ»¸ö½ÇÂäµÄÎÀÐÇ£¬ÈôÊÇÀ¹½Ø³É¹¦£¬Ôò¿ÉµÈÏеØÇÔÌýÐÅÏ¢¡£Pavur³¢ÊÔ·¢ÏÖ£¬¿ÉÀ¹½ØÍùÀ´ÓʼþºÍPayPalÕÊ»§Í´´¦Ö®ÀàµÄÃô¸ÐÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/satellite-internet-connections-intercepted-hackers/


5.ÈýÐǰ䲼°²È«¸üУ¬½¨¸´GalaxyÉϵĶà¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÈýÐǰ䲼8Ô·ݰ²È«¸üУ¬½¨¸´GalaxyÉϵĶà¸öÑϳÁµÄ·ì϶¡£×îΪÑϳÁµÄ·ì϶ÊÇÓÉAndroid²Ù×÷ϵͳÖеÄÕûÊýÒç¶Âí½ÅÒýÆðµÄÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-0240£©£¬Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚ·ÇÌØÈ¨¹ý³ÌÖÐÖ´ÐÐËÁÒâ´úÂë¡£´Ë±í£¬Õâ´Î¸üл¹½¨¸´ÁËÆä¿ò¼ÜÖеÄÌáȨ·ì϶£¨CVE-2020-0238ºÍCVE-2020-0257£©¡¢ID·ì϶£¨CVE-2020-0239¡¢CVE-2020-0249ºÍCVE-2020-0258)£¬Ã½Ìå¿ò¼ÜÖеÄÌáȨ·ì϶£¨CVE-2020-0241¡¢CVE-2020-0242ºÍCVE-2020-0243£©£¬ÒÔ¼°ÏµÍ³ÖÐÌáȨ·ì϶£¨CVE-2020-0108ºÍCVE-2020-0256£©µÈ·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/samsung-rolls-out-android-updates-fixing-critical-vulnerabilities/


6.°¢¸ùÍ¢Ô¼12Íò¹«Ãñ¼ìÒßÐÅÏ¢ÒòÊý¾Ý¿âÅäÖÃÃýÎóй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°¢¸ùÍ¢ÒòÅäÖÃÃýÎ󣬽«Ô̺¬Ô¼115000¸öCOVID-19¼ìÒß»íÃâÉêÇëÈËÒ½ÁÆÊý¾ÝµÄElasticsearchÊý¾Ý¿âÔÚÍøÂçÉϹ«¿ª¡£Ð¹Â¶Êý¾ÝÔ̺¬ÉêÇëÈËÐÕÃû¡¢Éí·ÝÖ¤ºÅ¡¢Ë°ºÅ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·µÈÐÅÏ¢£¬»¹Ô̺¬ÉêÇëÈ˹ÍÖ÷ÐÕÃû¡¢µØÖ·ºÍµç»°ºÅÂëµÈÐÅÏ¢¡£Æ¾¾ÝÏÖÓеÄÖ¤¾Ý£¬×êÑÐÈËÔ±ÒÔΪÕâЩÊý¾ÝÊôÓÚ°¢¸ù͢ʥºú°²µ±¾ÖºÍ¸Ã¹ú¹«¹²ÎÀÉú²¿¡£Rapid7ÔÆ°²È«Êµ¼Ê¼¼Êõ¸±×ܲÃChris DeRamus°µÊ¾£¬Ð¹Â¶ÐÅÏ¢¿É±»ÀûÓýøÐÐ˰Îñڲƭ¡¢Éí·ÝµÁÓûòÈÎºÎÆäËû´ó¾ÖµÄȦÌס£


Ô­ÎÄÁ´½Ó£º

http://www.digitaljournal.com/life/health/argentina-exposes-covid-19-health-data-in-error/article/575797