Cisco°ä²¼°²È«¸üР£¬½¨¸´¶à¸ö²úÆ·Öеķì϶£»WooCommerceÖзì϶¿Éµ¼ÖÂÍøÕ¾ÊÕÊÜ £¬Ó°ÏìÉÏÍò¼ÒÉ̵ê

°ä²¼¹¦·ò 2020-08-24

1.Cisco°ä²¼°²È«¸üР£¬½¨¸´¶à¸ö²úÆ·Öеķì϶


1.png


Cisco°ä²¼°²È«¸üР£¬ÒÔ½¨¸´Æä¶à¸ö²úÆ·Öеķì϶¡£Õâ´Î°²È«¸üÐÂÖн¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶ΪTreck IP²Ö¿âÖеķì϶Ripple20 £¬ÕâЩ·ì϶¿Éµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡¢»Ø¾ø·þÎñ£¨DoS£©»òÐÅϢй¶£»ÓÃÓÚCisco ENCS 5400-WϵÁкÍCSP 5000-WϵÁеÄCisco vWAASĬÈÏÍ´´¦·ì϶£¨CVE-2020-3446£© £¬¿É±»ÀûÓÃÒÔÖÎÀíԱȨÏÞ½Ó¼ûNFVIS CLI£»Ë¼¿ÆÖÇÄÜÈí¼þÖÎÀíÆ÷£¨SSM On-Prem£©±¾µØÌØÈ¨Éý¼¶·ì϶£¨CVE-2020-3443£©ÒÔ¼°Ë¼¿ÆÊÓÆµ¼à¿Ø8000ϵÁÐIPÉãÏñ»ú˼¿Æ·¢ÏÖºÍ̸Զ³ÌÖ´Ðкͻؾø·þÎñ·ì϶£¨CVE-2020-3506ºÍCVE-2020-3507£©¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/08/20/cisco-releases-security-updates


2.FBIºÍCISAÖÒ¸æÕë¶ÔÃÀ¹úƫԶµØÓò¹¤È˵Ĵ¹µö»î¶¯


2.png


ÃÀ¹úFBIºÍCISA½áºÏ°ä²¼¾¯±¨ £¬ÖÒ¸æÄ¿Ç°Õë¶ÔÃÀ¹ú¶à¸öÐÐÒµ²¿ÃŵÄÓïÒôÍøÂç´¹µö»î¶¯£¨Vishing£©¡£VishingÊÇÒ»ÖÖÉç»á¹¤³Ì¹¥»÷ £¬¹¥»÷ÕßÔÚÓïÒôºô½ÐÆÚ¼ä·ÂÕÕÊÜÐÅÀµµÄʵÌå £¬ÒÔÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¸Ã»ú¹¹°µÊ¾ £¬×Ô2020Äê7ÔÂÖÐÑ® £¬ÍøÂç·¸×ï·Ö×Ó·¢Õ¹ÁËÕâÒ»»î¶¯ £¬Ö¼ÔÚıȡÀûÒæ¡£´Ë±í £¬¹¥»÷Õß»¹×¢²áÁËÓÃÓÚÍøÂç´¹µöµÄÓò £¬ÒÔ¿Ë¡ָ±ê¹«Ë¾µÄÄÚ²¿VPNµÇÂ¼Ò³Ãæ £¬À´ÇÔÈ¡Á½³É·ÖÉí·ÝÑéÖ¤£¨2FA£©ºÍÒ»´ÎÐÔÃÜÂ루OTP£©¡£Îª´Ë £¬FBIºÍCISAÌá³öһϵÁн¨Òé´ëÊ© £¬ÒÔ»º½â´ËÀ๥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-govt-warns-remote-workers-of-ongoing-vishing-campaign/


3.WooCommerceÖзì϶¿Éµ¼ÖÂÍøÕ¾ÊÕÊÜ £¬Ó°ÏìÉÏÍò¼ÒÉ̵ê


3.jpg


WebARX·¢ÏÖWordPress²å¼þWooCommerceÖзì϶¿Éµ¼ÖÂÍøÕ¾ÊÕÊÜ £¬Ó°ÏìÉÏÍò¼ÒÉ̵ꡣƾ¾Ý·ÖÎöÔ±¶Ô·ì϶µÄ·ÖÎö £¬·¢ÏÖËüÃÇÊÇÓɲ»×ãËæ»úÊýÁîÅÆºÍÊÚȨ²é³­µ¼ÖµÄ £¬ÈôÊdzɹ¦ÀûÓÃÕâЩ·ì϶ £¬Ôòδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»¼ìË÷ËùÓÐЧ»§ºÍÓÅ»Ýȯ´úÂëµÄÁбí £¬²¢ÔÚÍøÕ¾µÄҳü¡¢Ò³½Å»òÖÎÀíÒ³Ãæ×¢ÈëXSS £¬ÒÔ´¥·¢Ô¶³ÌÖ´ÐдúÂë·ì϶¡£´Ë±í £¬ºÚ¿Í»¹Äܹ»ÀûÓÃJavaScript¼üÅ̼ͼ·¨Ê½×¢ÈëµÇ¼±íµ¥ £¬ÒÔÊÕÊÜÖÎÀíÔ¹ØÊ»§¡£Ä¿Ç° £¬¸Ã²å¼þÔÚ´Óǰ7ÌìÄÚÒѱ»ÏÂÔØÁ˳¬¹ý12000´Î¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/wordpress-woocommerce-stores-under-attack-patch-now/


4.Diebold Nixdorf½¨¸´¿É±»ÓÃÓÚ´æ¿îαÔì¹¥»÷µÄ·ì϶


4.jpg


ATMÔì×÷ÉÌDiebold NixdorfºÍNCR°ä²¼ÁËÈí¼þ¸üР£¬½¨¸´¿É±»ÓÃÓÚ´æ¿îαÔì¹¥»÷µÄ·ì϶¡£Õâ´Î½¨¸´µÄ·ì϶±»×·×ÙΪCVE-2020-9062ºÍCVE-2020-10124 £¬±ðÀëÓ°ÏìÁËÔËÐÐWincor ProbaseÈí¼þµÄDiebold Nixdorf ProCash 2100xe USB ATMºÍÔËÐÐAPTRA XFSÈí¼þµÄNCR SelfServ ATM¡£ÕâЩ·ì϶¿É±»ºÚ¿ÍÀûÓÃÒÔÅú¸ÄÆäÒøÐп¨ÉϵĴæ¿î½ð¶î £¬²¢ÔÚÒøÐз¢ÏÖÕË»§Óà¶îÒ쳣֮ǰ½øÐÐڲƭÐÔÈ¡¿î¡£ÕâЩ·ì϶ԴÓÚATMÏÖ½ð´æ·ÅÏäºÍÖ÷»úÖ®¼ä·¢Ë͵ÄÐÂÎŶÌȱ¼ÓÃܺÍÉí·ÝÑéÖ¤»·½Ú £¬Ä¿Ç°DieboldºÍNCR¾ùÒѰ䲼Èí¼þ¸üР£¬ÒÔ±£»¤ÏÖ½ð´æ¿îÄ£¿éÓëÖ÷»úÖ®¼äµÄͨѶ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/107421/hacking/diebold-nixdorf-ncr-deposit-forgery.html


5.Spikey¹¥»÷¿ÉÀûÓÃÐźŴ¦ÖÃÈí¼þ¿Ë¡ÎïÀíÔ¿³×


5.jpg


ÐÂ¼ÓÆÂ¹úÁ¢´óѧµÄ×êÑÐÈËÔ±·¢ÏÖÒ»ÖÖÕë¶ÔÎïÀíËøµÄй¥»÷Õ½ÊõSpikey £¬¿ÉÀûÓÃÐźŴ¦ÖÃÈí¼þ¿Ë¡ÎïÀíÔ¿³×¡£´ËÀ๥»÷Äܹ»ÀûÓÃÖÇÄÜÊÖ»úµÄÂó¿Ë·ç²¶»ñÔ¿³×²åÈë»ò°Î³öʱµÄ½ðÊôµã»÷Éù £¬²¢ÓÃÐźŴ¦ÖÃÈí¼þ½øÐÐÆÆÒë £¬ÒÔ´§¶ÈÔ¿³×µÄ״̬ £¬×îÖÕÄܹ»ÓÃ3D´òÓ¡¼¼Êõ¿Ë¡³öÎïÀíÔ¿³×¡£×êÑÐÈËÔ±°µÊ¾½«À´»¹¿ÉÄÜͨ¹ý¶ñÒâÈí¼þϰȾÊܺ¦ÕßµÄÖÇÄÜÊÖ»ú»òÖÇÄÜÍó±í £¬ÒԴ˼ͼÉùÒô²¢ÌáÒé¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/08/21/spikey-attack-can-duplicate-physical-keys-by-listening-to-click-sounds/


6.Ó¢¹úMyerscough´óѧÔâµ½DoS¹¥»÷µ¼ÖÂϵͳÍÑ»ú


6.jpg


Ó¢¹úMyerscough´óѧÔÚ°ä²¼¿¼ÊԳɾÍÈ·µ±ÌìÔâµ½DoS¹¥»÷ £¬µ¼ÖÂϵͳÍÑ»ú¡£¸Ã´óѧ°µÊ¾ £¬DoS¹¥»÷ÑϳÁ·ÛËéÁËÆäËùÓÐIT»ù´¡ÉèÊ© £¬µ¼ÖÂϵͳ´¦ÓÚÍÑ»ú״̬ £¬Ñ§ÉúÎÞ·¨½Ó¼ûÃÅ»§ÍøÕ¾GCSEºÍ²éÎÊ¿¼ÊÔÁ˾Ö¡£´Ë±í £¬Ñ§ÌÃÔ±¹¤Ò²Ö»ÄÜͨ¹ýÉ罻ýÌ幤¾ßÁªÏµ £¬²¢ÇÒÔÚ·þÎñÆ÷¸´Ô­Ö®Ç°Ö»ÄÜÊÖ¶¯ÏòËùÓÐѧÉú·¢ËÍÆä³É¾ÍµÄµç×ÓÓʼþ¡£¸ÃѧÌõĽ²»°È˰µÊ¾ £¬Ä¿Ç°²¢Ã»ÓÐѧÉúµÄÊý¾ÝÔ⵽й¶ £¬¶ø±¾µØ¾¯·½Ò²ÔÚ¶Ô´ËÊ·¢Õ¹µ÷²é¡£


Ô­ÎÄÁ´½Ó£º

https://www.bbc.com/news/uk-england-lancashire-53822246