Cisco°ä²¼°²È«¸üУ¬½¨¸´¶à¸ö²úÆ·Öеķì϶£»WooCommerceÖзì϶¿Éµ¼ÖÂÍøÕ¾ÊÕÊÜ£¬Ó°ÏìÉÏÍò¼ÒÉ̵ê
°ä²¼¹¦·ò 2020-08-241.Cisco°ä²¼°²È«¸üУ¬½¨¸´¶à¸ö²úÆ·Öеķì϶

Cisco°ä²¼°²È«¸üУ¬ÒÔ½¨¸´Æä¶à¸ö²úÆ·Öеķì϶¡£Õâ´Î°²È«¸üÐÂÖн¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶ΪTreck IP²Ö¿âÖеķì϶Ripple20£¬ÕâЩ·ì϶¿Éµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡¢»Ø¾ø·þÎñ£¨DoS£©»òÐÅϢй¶£»ÓÃÓÚCisco ENCS 5400-WϵÁкÍCSP 5000-WϵÁеÄCisco vWAASĬÈÏÍ´´¦·ì϶£¨CVE-2020-3446£©£¬¿É±»ÀûÓÃÒÔÖÎÀíԱȨÏÞ½Ó¼ûNFVIS CLI£»Ë¼¿ÆÖÇÄÜÈí¼þÖÎÀíÆ÷£¨SSM On-Prem£©±¾µØÌØÈ¨Éý¼¶·ì϶£¨CVE-2020-3443£©ÒÔ¼°Ë¼¿ÆÊÓÆµ¼à¿Ø8000ϵÁÐIPÉãÏñ»ú˼¿Æ·¢ÏÖºÍ̸Զ³ÌÖ´Ðкͻؾø·þÎñ·ì϶£¨CVE-2020-3506ºÍCVE-2020-3507£©¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/08/20/cisco-releases-security-updates
2.FBIºÍCISAÖÒ¸æÕë¶ÔÃÀ¹úƫԶµØÓò¹¤È˵Ĵ¹µö»î¶¯

ÃÀ¹úFBIºÍCISA½áºÏ°ä²¼¾¯±¨£¬ÖÒ¸æÄ¿Ç°Õë¶ÔÃÀ¹ú¶à¸öÐÐÒµ²¿ÃŵÄÓïÒôÍøÂç´¹µö»î¶¯£¨Vishing£©¡£VishingÊÇÒ»ÖÖÉç»á¹¤³Ì¹¥»÷£¬¹¥»÷ÕßÔÚÓïÒôºô½ÐÆÚ¼ä·ÂÕÕÊÜÐÅÀµµÄʵÌ壬ÒÔÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¸Ã»ú¹¹°µÊ¾£¬×Ô2020Äê7ÔÂÖÐÑ®£¬ÍøÂç·¸×ï·Ö×Ó·¢Õ¹ÁËÕâÒ»»î¶¯£¬Ö¼ÔÚıȡÀûÒæ¡£´Ë±í£¬¹¥»÷Õß»¹×¢²áÁËÓÃÓÚÍøÂç´¹µöµÄÓò£¬ÒÔ¿Ë¡ָ±ê¹«Ë¾µÄÄÚ²¿VPNµÇÂ¼Ò³Ãæ£¬À´ÇÔÈ¡Á½³É·ÖÉí·ÝÑéÖ¤£¨2FA£©ºÍÒ»´ÎÐÔÃÜÂ루OTP£©¡£Îª´Ë£¬FBIºÍCISAÌá³öһϵÁн¨Òé´ëÊ©£¬ÒÔ»º½â´ËÀ๥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-govt-warns-remote-workers-of-ongoing-vishing-campaign/
3.WooCommerceÖзì϶¿Éµ¼ÖÂÍøÕ¾ÊÕÊÜ£¬Ó°ÏìÉÏÍò¼ÒÉ̵ê

WebARX·¢ÏÖWordPress²å¼þWooCommerceÖзì϶¿Éµ¼ÖÂÍøÕ¾ÊÕÊÜ£¬Ó°ÏìÉÏÍò¼ÒÉ̵ꡣƾ¾Ý·ÖÎöÔ±¶Ô·ì϶µÄ·ÖÎö£¬·¢ÏÖËüÃÇÊÇÓɲ»×ãËæ»úÊýÁîÅÆºÍÊÚȨ²é³µ¼Öµģ¬ÈôÊdzɹ¦ÀûÓÃÕâЩ·ì϶£¬Ôòδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»¼ìË÷ËùÓÐЧ»§ºÍÓÅ»Ýȯ´úÂëµÄÁÐ±í£¬²¢ÔÚÍøÕ¾µÄҳü¡¢Ò³½Å»òÖÎÀíÒ³Ãæ×¢ÈëXSS£¬ÒÔ´¥·¢Ô¶³ÌÖ´ÐдúÂë·ì϶¡£´Ë±í£¬ºÚ¿Í»¹Äܹ»ÀûÓÃJavaScript¼üÅ̼ͼ·¨Ê½×¢ÈëµÇ¼±íµ¥£¬ÒÔÊÕÊÜÖÎÀíÔ¹ØÊ»§¡£Ä¿Ç°£¬¸Ã²å¼þÔÚ´Óǰ7ÌìÄÚÒѱ»ÏÂÔØÁ˳¬¹ý12000´Î¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/wordpress-woocommerce-stores-under-attack-patch-now/
4.Diebold Nixdorf½¨¸´¿É±»ÓÃÓÚ´æ¿îαÔì¹¥»÷µÄ·ì϶

ATMÔì×÷ÉÌDiebold NixdorfºÍNCR°ä²¼ÁËÈí¼þ¸üУ¬½¨¸´¿É±»ÓÃÓÚ´æ¿îαÔì¹¥»÷µÄ·ì϶¡£Õâ´Î½¨¸´µÄ·ì϶±»×·×ÙΪCVE-2020-9062ºÍCVE-2020-10124£¬±ðÀëÓ°ÏìÁËÔËÐÐWincor ProbaseÈí¼þµÄDiebold Nixdorf ProCash 2100xe USB ATMºÍÔËÐÐAPTRA XFSÈí¼þµÄNCR SelfServ ATM¡£ÕâЩ·ì϶¿É±»ºÚ¿ÍÀûÓÃÒÔÅú¸ÄÆäÒøÐп¨ÉϵĴæ¿î½ð¶î£¬²¢ÔÚÒøÐз¢ÏÖÕË»§Óà¶îÒ쳣֮ǰ½øÐÐÚ²ÆÐÔÈ¡¿î¡£ÕâЩ·ì϶ԴÓÚATMÏÖ½ð´æ·ÅÏäºÍÖ÷»úÖ®¼ä·¢Ë͵ÄÐÂÎŶÌȱ¼ÓÃܺÍÉí·ÝÑéÖ¤»·½Ú£¬Ä¿Ç°DieboldºÍNCR¾ùÒѰ䲼Èí¼þ¸üУ¬ÒÔ±£»¤ÏÖ½ð´æ¿îÄ£¿éÓëÖ÷»úÖ®¼äµÄͨѶ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/107421/hacking/diebold-nixdorf-ncr-deposit-forgery.html
5.Spikey¹¥»÷¿ÉÀûÓÃÐźŴ¦ÖÃÈí¼þ¿Ë¡ÎïÀíÔ¿³×

ÐÂ¼ÓÆÂ¹úÁ¢´óѧµÄ×êÑÐÈËÔ±·¢ÏÖÒ»ÖÖÕë¶ÔÎïÀíËøµÄй¥»÷Õ½ÊõSpikey£¬¿ÉÀûÓÃÐźŴ¦ÖÃÈí¼þ¿Ë¡ÎïÀíÔ¿³×¡£´ËÀ๥»÷Äܹ»ÀûÓÃÖÇÄÜÊÖ»úµÄÂó¿Ë·ç²¶»ñÔ¿³×²åÈë»ò°Î³öʱµÄ½ðÊôµã»÷Éù£¬²¢ÓÃÐźŴ¦ÖÃÈí¼þ½øÐÐÆÆÒ룬ÒÔ´§¶ÈÔ¿³×µÄ״̬£¬×îÖÕÄܹ»ÓÃ3D´òÓ¡¼¼Êõ¿Ë¡³öÎïÀíÔ¿³×¡£×êÑÐÈËÔ±°µÊ¾½«À´»¹¿ÉÄÜͨ¹ý¶ñÒâÈí¼þϰȾÊܺ¦ÕßµÄÖÇÄÜÊÖ»ú»òÖÇÄÜÍó±í£¬ÒԴ˼ͼÉùÒô²¢ÌáÒé¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://latesthackingnews.com/2020/08/21/spikey-attack-can-duplicate-physical-keys-by-listening-to-click-sounds/
6.Ó¢¹úMyerscough´óѧÔâµ½DoS¹¥»÷µ¼ÖÂϵͳÍÑ»ú

Ó¢¹úMyerscough´óѧÔÚ°ä²¼¿¼ÊԳɾÍÈ·µ±ÌìÔâµ½DoS¹¥»÷£¬µ¼ÖÂϵͳÍÑ»ú¡£¸Ã´óѧ°µÊ¾£¬DoS¹¥»÷ÑϳÁ·ÛËéÁËÆäËùÓÐIT»ù´¡ÉèÊ©£¬µ¼ÖÂϵͳ´¦ÓÚÍÑ»ú״̬£¬Ñ§ÉúÎÞ·¨½Ó¼ûÃÅ»§ÍøÕ¾GCSEºÍ²éÎÊ¿¼ÊÔÁ˾֡£´Ë±í£¬Ñ§ÌÃÔ±¹¤Ò²Ö»ÄÜͨ¹ýÉ罻ýÌ幤¾ßÁªÏµ£¬²¢ÇÒÔÚ·þÎñÆ÷¸´Ô֮ǰֻÄÜÊÖ¶¯ÏòËùÓÐѧÉú·¢ËÍÆä³É¾ÍµÄµç×ÓÓʼþ¡£¸ÃѧÌõĽ²»°È˰µÊ¾£¬Ä¿Ç°²¢Ã»ÓÐѧÉúµÄÊý¾ÝÔ⵽й¶£¬¶ø±¾µØ¾¯·½Ò²ÔÚ¶Ô´ËÊ·¢Õ¹µ÷²é¡£
ÔÎÄÁ´½Ó£º
https://www.bbc.com/news/uk-england-lancashire-53822246


¾©¹«Íø°²±¸11010802024551ºÅ