FBIÖÒÑÔÒÁÀʺڿÍʹÓÃF5 BIG-IPÎó²î¹¥»÷ADC×°±¸£»£»£»£»£»£»£»ÈýÐÇÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´GalaxyÉϵĶà¸öÎó²î

Ðû²¼Ê±¼ä 2020-08-10

1.FBIÖÒÑÔÒÁÀʺڿÍʹÓÃF5 BIG-IPÎó²î¹¥»÷ADC×°±¸


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


FBIÐû²¼Ë½ÈËÐÐҵ֪ͨ£¨PIN£©£¬£¬£¬£¬£¬£¬ÌåÏÖÒÁÀʺڿÍ×Ô2020Äê7Ô³õÒÔÀ´Ò»Ö±ÔÚʵÑéʹÓÃF5 BIG-IPµÄÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-5902£©À´¹¥»÷²Æ²ú500Ç¿ÆóÒµ¡¢Õþ¸®»ú¹¹ºÍÒøÐÐʹÓõÄÓ¦Óý»¸¶¿ØÖÆÆ÷£¨ADC£©×°±¸¡£¡£¡£¡£ ¡£¡£¡£Æ¾Ö¤FBIµÄÊӲ죬£¬£¬£¬£¬£¬×Ô2019Äê8ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬¸ÃºÚ¿Í×éÖ¯ÌᳫÁ˶à´ÎÕë¶ÔVPN×°±¸µÄ¹¥»÷£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨µ«²»ÏÞÓÚPulse Secure£¨CVE 2019-11510£¬£¬£¬£¬£¬£¬CVE 2019-11539£©ºÍCitrix ADC /Íø¹Ø£¨CVE 2019-19781£©¡£¡£¡£¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬FBI PIN»¹ÌṩÁËΣº¦Ö¸±ê£¨IOC£©ºÍÕ½Êõ¡¢ÊÖÒÕÓë³ÌÐò£¨TTP£©£¬£¬£¬£¬£¬£¬×ÊÖú˽ӪÐÐÒµ×é֯ʶ±ðÆäÍøÂçÉϵÄÏà¹Ø¶ñÒâ»î¶¯¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fbi-iranian-hackers-trying-to-exploit-critical-f5-big-ip-flaw/


2.ºÚ¿ÍʹÓÃαÔìµÄÇå¾²½¨Òé¶ÔcPanelÓû§´¹ÂÚ¹¥»÷


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


ºÚ¿ÍαÔìWebÍйÜÖÎÀíÃæ°åÖеÄÎó²îÖÒÑÔ£¬£¬£¬£¬£¬£¬Õë¶ÔcPanelÓû§Ìᳫ´¹ÂÚ¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£¸Ã´¹ÂÚÈí¼þÒÔcPanel½ôÆÈ¸üÐÂÇëÇóΪÖ÷Ì⣬£¬£¬£¬£¬£¬Éù³ÆÒÑÐû²¼¸üÐÂÀ´ÐÞ¸´cPanelºÍWHMÈí¼þ°æ±¾88.0.3 +¡¢86.0.21 +ºÍ78.0.49+ÖеÄÇå¾²ÎÊÌ⣬£¬£¬£¬£¬£¬²¢½¨ÒéËùÓÐÓû§×°ÖøüС£¡£¡£¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹×¢²áÁËÓòÃûcpanel7831.com£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃAmazon Simple Email Service£¨SES£©·¢Ë͵ç×ÓÓʼþ£¬£¬£¬£¬£¬£¬ÒÔʹȦÌ×Ô½·¢ÕæÊµ¡£¡£¡£¡£ ¡£¡£¡£µ±Êܺ¦Õßµã»÷¸üÐÂÄúµÄcPanelºÍWHM×°ÖÃÁ´½Óºó£¬£¬£¬£¬£¬£¬»á±»Öض¨Ïòµ½´¹ÂÚÍøÒ³£¬£¬£¬£¬£¬£¬²¢±»ÒªÇóÊäÈëcPanelƾ֤µÇ¼¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-security-advisory-used-in-clever-cpanel-phishing-attack/


3.HDL×Ô¶¯»¯ÏµÍ³ÖеÄÎó²îʹIoT×°±¸Ò×±»Ô¶³ÌÐ®ÖÆ


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


Ñо¿Ö°Ô±Barak Sternberg·¢Ã÷HDL×Ô¶¯»¯ÏµÍ³Öб£´æÎó²î£¬£¬£¬£¬£¬£¬Ê¹IoT×°±¸Ò×±»Ô¶³ÌÐ®ÖÆ¡£¡£¡£¡£ ¡£¡£¡£ÔÚÑо¿Óû§ÔõÑùÉèÖúͿØÖÆHDL×é¼þʱ£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÔÚÒÆ¶¯Ó¦ÓóÌÐòÉÏ×¢²áÐÂÕÊ»§Ê±»á×Ô¶¯ÌìÉúÁíÒ»¸öÕÊ»§£¨ÔÚÔ­Óû§ÃûÖÐÌí¼ÓÁË×Ö·û´®debug£©À´Ó¦ÓÃÉèÖᣡ£¡£¡£ ¡£¡£¡£ÆäÄ¿µÄÊÇÓ¦ÓÃÉèÖò¢½«ÍâµØ×°±¸µÄÉèÖ÷¢Ë͵½ÍⲿHDLЧÀÍÆ÷£¬£¬£¬£¬£¬£¬ÒÔ±ãÆäËûÊÚȨÓû§¿ÉÒÔÏÂÔØËü²¢¿ØÖÆÖÇÄܼҾÓ¡£¡£¡£¡£ ¡£¡£¡£¹¥»÷Õß¿ÉÒÔ×¢²ádebugÓû§ÃûµÄµç×ÓÓʼþµØµãÀ´ÎüÊÕÓйظü¸ÄÃÜÂëµÄ˵Ã÷£¬£¬£¬£¬£¬£¬²¢¿ÉÒÔ¿ØÖÆHDL×Ô¶¯»¯ÇéÐÎÖеÄ×é¼þ£¨µÆ¹â£¬£¬£¬£¬£¬£¬Î¶ȣ¬£¬£¬£¬£¬£¬ÉãÏñ»ú£¬£¬£¬£¬£¬£¬ÖÖÖÖ´«¸ÐÆ÷£©ÒÔ¼°ÉèÖᣡ£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/bugs-in-hdl-automation-expose-iot-devices-to-remote-hijacking/


4.Ñо¿Ö°Ô±·¢Ã÷ÎÀÐÇÅþÁ¬Ò×ÔâÍøÂç¹¥»÷²¢±»ºÚ¿Í×èµ²


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


Å£½ò´óѧµÄÑо¿Ô±James Pavur·¢Ã÷È«ÇòÎÀÐÇÅþÁ¬Ò×ÔâÍøÂç¹¥»÷²¢±»ºÚ¿Í×èµ²¡£¡£¡£¡£ ¡£¡£¡£Í¨³£ÇéÐÎÏ£¬£¬£¬£¬£¬£¬ÎÀÐÇISP¿ÉÒÔÔÚÆ«Ô¶µØÇøÌṩ»¥ÁªÍøÅþÁ¬¡£¡£¡£¡£ ¡£¡£¡£µ±ÎÀÐÇISPΪ¿Í»§Ó뻥ÁªÍøÅþÁ¬Ê±£¬£¬£¬£¬£¬£¬Ëü»áͨ¹ýͨѶÐŵÀ½«¿Í»§ÐźŴ«Êäµ½ÎÀÐÇÉÏ£¬£¬£¬£¬£¬£¬Ö®ºóÐźű»·¢Ë͵½µØÇòµÄÍøÂçÅþÁ¬£¬£¬£¬£¬£¬£¬·µ»ØµÄÏìÓ¦ÐźŻáÔÚÎÀÐǺÍÓû§Ö®¼ä¾ÙÐй㲥´«Êä¡£¡£¡£¡£ ¡£¡£¡£ÒÔÊǺڿͿÉÒÔ¹¥»÷λÓÚÌìÏÂÁíÒ»¸ö½ÇÂäµÄÎÀÐÇ£¬£¬£¬£¬£¬£¬ÈôÊÇ×èµ²Àֳɣ¬£¬£¬£¬£¬£¬Ôò¿ÉÈÝÒ×µØÇÔÌýÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¡£PavurʵÑé·¢Ã÷£¬£¬£¬£¬£¬£¬¿É×èµ²ÍùÀ´ÓʼþºÍPayPalÕÊ»§Æ¾Ö¤Ö®ÀàµÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/satellite-internet-connections-intercepted-hackers/


5.ÈýÐÇÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´GalaxyÉϵĶà¸öÎó²î


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


ÈýÐÇÐû²¼8Ô·ÝÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´GalaxyÉϵĶà¸öÑÏÖØµÄÎó²î¡£¡£¡£¡£ ¡£¡£¡£×îΪÑÏÖØµÄÎó²îÊÇÓÉAndroid²Ù×÷ϵͳÖеÄÕûÊýÒç³öÎó²îÒýÆðµÄÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-0240£©£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚ·ÇÌØÈ¨Àú³ÌÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬´Ë´Î¸üл¹ÐÞ¸´ÁËÆä¿ò¼ÜÖеÄÌáȨÎó²î£¨CVE-2020-0238ºÍCVE-2020-0257£©¡¢IDÎó²î£¨CVE-2020-0239¡¢CVE-2020-0249ºÍCVE-2020-0258)£¬£¬£¬£¬£¬£¬Ã½Ìå¿ò¼ÜÖеÄÌáȨÎó²î£¨CVE-2020-0241¡¢CVE-2020-0242ºÍCVE-2020-0243£©£¬£¬£¬£¬£¬£¬ÒÔ¼°ÏµÍ³ÖÐÌáȨÎó²î£¨CVE-2020-0108ºÍCVE-2020-0256£©µÈÎó²î¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/samsung-rolls-out-android-updates-fixing-critical-vulnerabilities/


6.°¢¸ùÍ¢Ô¼12Íò¹«Ãñ¼ìÒßÐÅÏ¢ÒòÊý¾Ý¿âÉèÖùýʧй¶


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


°¢¸ùÍ¢ÒòÉèÖùýʧ£¬£¬£¬£¬£¬£¬½«°üÀ¨Ô¼115000¸öCOVID-19¼ìÒß¿íÃâÉêÇëÈËÒ½ÁÆÊý¾ÝµÄElasticsearchÊý¾Ý¿âÔÚÍøÂçÉϹûÕæ¡£¡£¡£¡£ ¡£¡£¡£Ð¹Â¶Êý¾Ý°üÀ¨ÉêÇëÈËÐÕÃû¡¢Éí·ÝÖ¤ºÅ¡¢Ë°ºÅ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµãµÈÐÅÏ¢£¬£¬£¬£¬£¬£¬»¹°üÀ¨ÉêÇëÈ˹ÍÖ÷ÐÕÃû¡¢µØµãºÍµç»°ºÅÂëµÈÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¡£Æ¾Ö¤ÏÖÓеÄÖ¤¾Ý£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÒÔΪÕâЩÊý¾ÝÊôÓÚ°¢¸ù͢ʥºú°²Õþ¸®ºÍ¸Ã¹ú¹«¹²ÎÀÉú²¿¡£¡£¡£¡£ ¡£¡£¡£Rapid7ÔÆÇ徲ʵ¼ùÊÖÒÕ¸±×ܲÃChris DeRamusÌåÏÖ£¬£¬£¬£¬£¬£¬Ð¹Â¶ÐÅÏ¢¿É±»Ê¹ÓþÙÐÐ˰Îñڲƭ¡¢Éí·ÝµÁÓûòÈÎºÎÆäËûÐÎʽµÄȦÌס£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.digitaljournal.com/life/health/argentina-exposes-covid-19-health-data-in-error/article/575797