LightInTheBoxй¶1.3TB WebЧÀÍÆ÷ÈÕÖ¾£»£»BitglassÐû²¼2019Äê½ðÈÚÐÐÒµÊý¾Ýй¶±¨¸æ
Ðû²¼Ê±¼ä 2019-12-18
1.LightInTheBoxй¶1.3TB WebЧÀÍÆ÷ÈÕÖ¾
vpnMentorÑо¿Ö°Ô±·¢Ã÷ÔÚÏßÁãÊÛÉÌLightInTheBoxµÄElasticsearchÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬£¬£¬ÆäÖаüÀ¨1.3TB WebЧÀÍÆ÷ÈÕÖ¾¡£¡£¡£¡£LightInTheBoxרעÓÚСÅä¼þ¡¢´ò°çºÍÅäÊεÄÏúÊÛ£¬£¬£¬£¬£¬Æä´ó²¿·Ö¿Í»§Î»ÓÚ±±ÃÀºÍÅ·ÖÞ¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ11ÔÂÏÂÑ®·¢Ã÷Á˸ÃÊý¾Ý¿â£¬£¬£¬£¬£¬Êý¾Ý¿âÖеļͼ×ܼÆÁè¼Ý15ÒÚÌõ£¬£¬£¬£¬£¬»¹°üÀ¨Æä×ÓÍøÕ¾MiniInTheBox.comµÄÊý¾Ý¡£¡£¡£¡£ÈÕÖ¾°üÀ¨8ÔÂ9ÈÕÖÁ10ÔÂ11ÈÕÖ®¼äµÄÍøÕ¾»î¶¯£¬£¬£¬£¬£¬°üÀ¨µç×ÓÓʼþµØµã¡¢IPµØµã¡¢ÆÜÉí¹ú¼Ò/µØÇøÒÔ¼°Ã¿¸ö·Ã¿Í»á¼ûµÄÒ³ÃæµÈÐÅÏ¢¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/95231/data-breach/lightinthebox-data-leak.html
2.¼ÓÄôóÁÙ´²ÊµÑéÊÒЧÀÍÉÌLifeLabsй¶1500Íò¿Í»§ÐÅÏ¢
¼ÓÄôóÁÙ´²ÊµÑéÊÒЧÀÍÌṩÉÌLifeLabsй¶¶à´ï1500Íò¼ÓÄÃÖÁ¹«ÃñµÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£Æ¾Ö¤ÆäÐû²¼µÄÊý¾Ýй¶֪ͨ£¬£¬£¬£¬£¬Î´¾ÊÚȨµÄ¹¥»÷Õß»á¼ûÁË1500Íò¿Í»§µÄÐÕÃû¡¢µØµã¡¢µç×ÓÓʼþ¡¢µÇ¼Ãû¡¢ÃÜÂë¡¢³öÉúÈÕÆÚºÍÒ½ÁÆ¿¨ºÅÂë¡£¡£¡£¡£ÆäÖÐÔ¼8.5Íò¿Í»§µÄʵÑéÊÒЧ¹ûÒ²Ôâй¶¡£¡£¡£¡£¾Ý±¨µÀй¶µÄÊý¾ÝÖ÷ҪΪ2016Ä꼰֮ǰµÄÊý¾Ý£¬£¬£¬£¬£¬Éæ¼°µÄ¿Í»§¾ø´ó´ó¶¼À´×ÔÓÚ±°Ê«Ê¡ºÍ°²¼òªʡ¡£¡£¡£¡£ÔÚ·¢Ã÷й¶ºó£¬£¬£¬£¬£¬LifeLabs´ÓºÚ¿ÍÄÇÀﹺÖÃÁ˱»µÁµÄÊý¾Ý£¬£¬£¬£¬£¬µ«²»ÖªµÀËûÃÇΪ´ËÖ§¸¶Á˼¸¶àÊê½ð¡£¡£¡£¡£LifeLabs½«ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩһÄêµÄÃâ·ÑÉí·Ý͵ÇÔ±£»£»¤Ð§ÀÍ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/lifelabs-data-breach-exposes-personal-info-of-15-million-customers/
3.Ó¢ÌØ¶û¿ìËÙ´æ´¢Èí¼þÖб£´æDLLÐ®ÖÆÎó²î
Ó¢ÌØ¶û¿ìËÙ´æ´¢ÊÖÒÕ£¨Intel RST£©Èí¼þÖб£´æÒ»¸öDLLÐ®ÖÆÎó²î£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¶ñÒâ³ÌÐòÏÔʾΪÊÜÐÅÈγÌÐò£¬£¬£¬£¬£¬´Ó¶øÈƹý·À²¡¶¾ÒýÇæ¡£¡£¡£¡£SafeBreachµÄÑо¿Ö°Ô±·¢Ã÷IAStorDataMgrSvc.exe½«ÊµÑé´ÓC:\Program Files\Intel\Intel(R) Rapid Storage Technology\Îļþ¼ÐϼÓÔØ4¸öDLL£¨IoctlLog.dll¡¢IoctlNet.dll¡¢IoctlSim.dll¡¢DriverSim.dll£©£¬£¬£¬£¬£¬µ«ÕâЩDLLÔڸ÷¾¶Ï²¢²»±£´æ£¬£¬£¬£¬£¬Òò´ËÑо¿Ö°Ô±¿ÉÒÔ½¨Éè×Ô¼ºµÄDLLʹIAStorDataMgrSvc.exeÔÚÆô¶¯Ê±¼ÓÔØ£¬£¬£¬£¬£¬¸ÃDLL½«ÒÔSYSTEMÌØÈ¨¼ÓÔØ²¢ÊµÖÊÉϾßÓжÔÅÌËã»úµÄÍêÈ«»á¼ûȨÏÞ¡£¡£¡£¡£Ó¢ÌضûÒÑÓÚ12ÔÂ10ÈÕÐû²¼ÁË¿ìËÙ´æ´¢Èí¼þµÄ¸üаæÔÀ´½â¾ö¸ÃÎó²î¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/update-intels-rapid-storage-app-to-fix-bug-letting-malware-evade-av/
4.˼¿ÆTalosÅû¶WAGO PLCÖеĶà¸öÎó²î
˼¿ÆTalosÑо¿Ö°Ô±ÔÚWAGOÖÆÔìµÄ¿É±à³ÌÂß¼¿ØÖÆÆ÷£¨PLC£©Öз¢Ã÷¶à¸öÑÏÖØÎó²î£¬£¬£¬£¬£¬ÕâЩÎó²î¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐС¢¾Ü¾øÐ§À͹¥»÷»ò»ñȡװ±¸µÄµÇ¼ƾ֤¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨WAGO PFC200ºÍPFC100¿ØÖÆÆ÷£¬£¬£¬£¬£¬ËüÃDZ»ÆÕ±éÓÃÓÚÆû³µ¡¢Ìú·¡¢µçÁ¦¹¤³Ì¡¢ÖÆÔìºÍÐÞ½¨ÎïÖÎÀíµÈÐÐÒµÖС£¡£¡£¡£Õâ9¸öÎó²î£¨CVE-2019-5073~CVE-2019-5075£¬£¬£¬£¬£¬CVE-2019-5077~CVE-2019-5082£©µÄ»ù´¡Ôµ¹ÊÔÓÉÔÚÓÚ¿ØÖÆÆ÷ʹÓõÄÊäÈë/Êä³ö¼ì²éÉèÖÃЧÀ͵ÄÐÒé´¦Öóͷ£´úÂëÖб£´æÎÊÌâ¡£¡£¡£¡£TalosÌåÏÖûÓÐÖ¤¾ÝÅú×¢ÕâЩÎó²îÒÑÔÚÒ°ÍⱻʹÓᣡ£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/several-critical-vulnerabilities-found-wago-controllers
5.F-SecureÔÚClickShareÎÞÏßÑÝʾϵͳÖз¢Ã÷¶à¸öÎó²î

F-SecureÑо¿Ö°Ô±·¢Ã÷°Í¿É£¨Barco£©¹«Ë¾ClickShareÎÞÏßÑÝʾϵͳ±£´æ¶à¸ö¿É±»Ê¹ÓõÄÇå¾²Îó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²î×èµ²ºÍ¸Ä¶¯ÑÝʾÀú³ÌÖеÄÐÅÏ¢¡¢ÇÔÈ¡ÃÜÂëµÈÉñÃØÐÅÏ¢ÒÔ¼°×°ÖúóÃÅºÍÆäËü¶ñÒâÈí¼þµÈ¡£¡£¡£¡£ÕâЩÎó²îµÄCVE IDΪCVE-2017-7936¡¢CVE-2017-7932ÒÔ¼°CVE-2019-18824~CVE-2019-18833¡£¡£¡£¡£Ñо¿Ö°Ô±ÓÚ10ÔÂ9ÈÕÓë°Í¿É·ÖÏíÁËÕâЩ·¢Ã÷£¬£¬£¬£¬£¬°Í¿ÉÒÑÔÚÆäÍøÕ¾ÉÏÐû²¼Á˹̼þ°æÔÀ´»º½â²¿·ÖÎó²î£¬£¬£¬£¬£¬ÁíÒ»Ð©Éæ¼°ÎïÀíά»¤µÄÓ²¼þ×é¼þÖеÄÎó²î¿ÉÄܲ»»á±»ÐÞ¸´¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/12/17/wireless-presentation-system-vulnerabilities/
6.BitglassÐû²¼2019Äê½ðÈÚÐÐÒµÊý¾Ýй¶±¨¸æ
¾ÝBitglass³Æ£¬£¬£¬£¬£¬2019ÄêËùÓÐÊý¾Ýй¶ÊÂÎñÖÐÖ»ÓÐ6£¥Éæ¼°µ½½ðÈÚЧÀ͹«Ë¾£¬£¬£¬£¬£¬¿ÉÊÇÓëÆäËûÐÐÒµÏà±È£¬£¬£¬£¬£¬ÕâЩÊÂÎñËðº¦Á˸ü¶àµÄ¼Í¼¡£¡£¡£¡£2019ÄêËùÓÐ×ß©¼Í¼ÖÐ×ܼÆÓÐ60£¥ÒÔÉÏÊÇÓɽðÈÚЧÀÍ»ú¹¹Ð¹Â¶µÄ£¬£¬£¬£¬£¬ÕâÖÁÉÙ²¿·ÖÓëCapital OneÌØ´óÊý¾Ýй¶ÊÂÎñÓйأ¬£¬£¬£¬£¬¸ÃÊÂÎñй¶ÁËÁè¼Ý1ÒÚÌõ¼Í¼¡£¡£¡£¡£2019ÄêºÚ¿ÍºÍ¶ñÒâÈí¼þÈÔÈ»ÊǽðÈÚЧÀÍÊý¾Ýй¶µÄÖ÷ÒªÔµ¹ÊÔÓÉ£¬£¬£¬£¬£¬Õ¼74.5£¥£¨ÂÔ¸ßÓÚ2018ÄêµÄ73.5£¥£©¡£¡£¡£¡£ÄÚ²¿Íþв´Ó2018ÄêµÄ2.9£¥ÔöÌíµ½½ñÄêµÄ5.5£¥£¬£¬£¬£¬£¬¶øÒâÍâй¶´Ó14.7£¥ÔöÌíµ½18.2£¥¡£¡£¡£¡£ÔÚÒÑÍù¼¸ÄêÖУ¬£¬£¬£¬£¬½ðÈÚЧÀÍÆ½¾ùÿÌõй¶¼Í¼µÄ±¾Ç®ÓÐËùÔöÌí£¨210ÃÀÔª£©£¬£¬£¬£¬£¬Áè¼ÝÁËÒ½ÁƱ£½¡ÐÐÒµ£¨429ÃÀÔª£©Ö®ÍâµÄËùÓÐÆäËüÐÐÒµ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/12/17/data-breaches-financial-services/


¾©¹«Íø°²±¸11010802024551ºÅ