ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ34ÖÜ
°ä²¼¹¦·ò 2019-09-02>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2019Äê8ÔÂ26ÈÕÖÁ9ÔÂ01ÈÕ¹²ÊÕ¼°²È«·ì϶49¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇCisco REST API ContainerÑéÖ¤ÈÆ¹ý·ì϶£»BloodHound components/Modals/HelpModal.jsxËÁÒâºÅÁîÖ´Ðзì϶£»Datalogic AV7000 Linear Barcode ScannerÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£»Delta Controls enteliBUS Controllers»º³åÇøÒç¶Âí½Å£»Linux kernel net/wireless/marvell/mwifiex»º³åÇøÒç¶Âí½Å¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÍйܷþÎñÉÌHostinger½ü1400ÍòÓû§ÐÅÏ¢±»ÍϿ⣻2019ÄêÉϰëÄê»ã±¨µÄ·ì϶Öг¬¹ý34%佨¸´£»Android¶ñÒâÀûÓÃCamScannerÏÂÔØÁ¿³¬1ÒÚ£»2024ÄêÈ«ÇòÊý¾Ýй¶³É±¾Ô¤¼Æ½«´ï5ÍòÒÚÃÀÔª£»ÃÀ¹úÊý°Ù¼ÒÑÀ¿ÆÕïËùÔâÀÕË÷Èí¼þSodinokibi¹¥»÷¡£
>³ÁÒª°²È«·ì϶Áбí
1. Cisco REST API ContainerÑéÖ¤ÈÆ¹ý·ì϶
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190828-iosxe-rest-auth-bypass
2. BloodHound components/Modals/HelpModal.jsxËÁÒâºÅÁîÖ´Ðзì϶
https://github.com/BloodHoundAD/BloodHound
3. Datalogic AV7000 Linear Barcode ScannerÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶
https://www.us-cert.gov/ics/advisories/icsa-19-239-02
4. Delta Controls enteliBUS Controllers»º³åÇøÒç¶Âí½Å
https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9569
5. Linux kernel net/wireless/marvell/mwifiex»º³åÇøÒç¶Âí½Å
https://vigilance.fr/vulnerability/Linux-kernel-buffer-overflow-via-net-wireless-marvell-mwifiex-30180
>³ÁÒª°²È«ÊÂÎñ×ÛÊö
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hostinger-resets-customer-passwords-after-security-incident/
2¡¢2019ÄêÉϰëÄê»ã±¨µÄ·ì϶Öг¬¹ý34%佨¸´
ÔÎÄÁ´½Ó£º
https://pages.riskbasedsecurity.com/2019-midyear-vulnerability-quickview-report
3¡¢Android¶ñÒâÀûÓÃCamScannerÏÂÔØÁ¿³¬1ÒÚ
¿¨°Í˹»ù×êÑÐÈËÔ±·¢ÏÖCamScannerµÄÃâ·Ñ°æ´æÔÚÒ»¸ö°µ²ØµÄTrojan DropperÄ£¿é£¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÓû§²»ÖªÇéµÄÇé¿öÏÂÏÂÔØºÍ×°ÖöñÒⷨʽ¡£CamScannerÊÇÒ»¿îÊÜÓ½ÓµÄÊÖ»úPDF´´½¨APP£¬ËüÔÚGoogle PlayÉ̵êµÄÏÂÔØÁ¿³¬¹ý1ÒÚ¡£¶ñÒâÄ£¿éÏÖʵÉϲ¢²»´æÔÚÓÚCamScanner×ÔÉíµÄ´úÂëÖУ¬¶øÊÇÔÚµÚÈý·½¸æ°×¿âÖУ¬Òò¶øÄܹ»´§¶ÈÕâÊÇÈí¼þ¿ª·¢ÕߺͲ»Â·µÂµÄ¸æ°×É̺Ï×÷µÄÁ˾֡£¸ÃÄ£¿éÄܹ»Í¨¹ý¶àÖÖ·½Ê½ÀûÓÃÊÜϰȾµÄÉ豸£¬´ÓÏÔʾÇÖÈëÐÔ¸æ°×µ½¸¶·Ñ¶©ÔÄÇÔÈ¡»°·ÑµÈ¡£Ó¦¸Ã°ÑÎȵÄÊÇ£¬CamScannerµÄ¸¶·Ñ°æ±¾²»Ô̺¬µÚÈý·½¸æ°×¿â¡£GoogleÒѾ´Ó¹Ù·½PlayÉ̵êÖÐɾ³ýÁ˸ÃAPP¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/08/android-camscanner-malware.html
4¡¢2024ÄêÈ«ÇòÊý¾Ýй¶³É±¾Ô¤¼Æ½«´ï5ÍòÒÚÃÀÔª
ƾ¾ÝÕ°²©ÍøÂçµÄ×îÐÂÔ¤²â£¬Ëæ×żà¹Ü·£¿îµÄÖ´ÐÐÒÔ¼°ÆóÒµÔ½·¢ÒÀÀµÓÚÊý×Öϵͳ£¬µ½2024ÄêÈ«ÇòÊý¾Ýй¶µÄ³É±¾Ô¤¼Æ½«Ôö³¤µ½5ÍòÒÚÃÀÔªÒÔÉÏ¡£ÕâÒ»Êý¾ÝÀ´×ÔÓڸù«Ë¾°ä²¼µÄ×îл㱨¡¶ÍøÂç·¸×ïºÍ°²È«µÄ½«À´£º2019-2024Íþв·ÖÎö¡¢Ó°ÏìÆÀ¹À»ººÍ½âÕ½Êõ»ã±¨¡·¡£¸Ã¹«Ë¾Ðû³Æ£¬Ôڻ㱨ÆÚ¼äÄÚÔ¤¼ÆÊý¾Ýй¶³É±¾½«´Ó2019ÄêµÄ3ÍòÒÚÃÀԪÿÄêÔö³¤11%¡£»ã±¨Öл¹³Æ¹ÌÈ»´ó¹æÄ£µÄÊý¾Ýй¶¿ÉÄܳÉΪͷÌõÐÂÎÅ£¬µ«ËüÃDz¢²»Ô¸¶¨»áÖ±½ÓÓ°Ïì³É±¾£¬ÓÉÓÚ·£¿îºÍÒµÎñËðʧÓëÊý¾Ýй¶µÄ¹æÄ£²¢²»çÇÃÜÓйء£
https://www.infosecurity-magazine.com/news/breach-costs-trillion/
5¡¢ÃÀ¹úÊý°Ù¼ÒÑÀ¿ÆÕïËùÔâÀÕË÷Èí¼þSodinokibi¹¥»÷
8ÔÂ26ÈÕÃÀ¹úÊý°Ù¼ÒÑÀ¿ÆÕïËùÔâÀÕË÷Èí¼þSodinokibi¹¥»÷£¬»¼ÕßÐÅÏ¢±»¼ÓÃÜ¡£ÕâÊǹ¥»÷Õßͨ¹ýÈëÇÖÈí¼þ¹©¸øÉ̲¢ÀûÓÃÆä²úÆ·ÔÚ¿Í»§ÏµÍ³ÉÏÖ²ÈëÀÕË÷Èí¼þµÄÁíÒ»¸ö°¸Àý¡£ÔÚ±¾ÆðÊÂÎñÖУ¬Èí¼þ¹©¸øÉÌÊÇThe Digital Dental RecordºÍPerCSoft£¬ËûÃǺÏ×÷¿ª·¢ÁËÒ½ÁƼͼ±£ÁôºÍ±¸·ÝÈí¼þDDS Safe¡£ÉÏÖÜÄ©ºÚ¿ÍÍÅ»ïÈëÇÖÁ˸ÃÈí¼þ±³ºóµÄ»ù´¡ÉèÊ©£¬²¢ÀûÓÃËüÔÚÊý°Ù¸öÑÀÒ½ÕïËùµÄÍÆËã»úÉϲ¿ÊðÁËÀÕË÷Èí¼þSodinokibi¡£ÕâÁ½¼Ò¹«Ë¾Ñ¡ÔñÖ§¸¶Êê½ð»ñÈ¡½âÃÜÆ÷£¬µ«Ä¿Ç°¸´Ô½ø¶È»ºÂý£¬Ò»Ð©ÑÀ¿ÆÕïËùÐû³Æ½âÃÜÆ÷Ҫô²»Æð×÷Óã¬ÒªÃ´Ã»Óи´ÔËùº±¼û¾Ý¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/ransomware-hits-hundreds-of-dentist-offices-in-the-us/


¾©¹«Íø°²±¸11010802024551ºÅ