Ó¡¶Èµ±¾Ö»ú¹¹Òâ±íй¶1250Íò»³ÔÐÅ®ÐÔµÄÒ½ÁÆÐÅÏ¢£»£»£»£»£»£»£»2.6Íò¸öKibanaÊ·ý£»£»£»£»£»£»£»1.35Íò¸öiSCSI´æ´¢¼¯Èº
°ä²¼¹¦·ò 2019-04-03
×êÑÐÈËÔ±·¢ÏÖ³¬¹ý2.6Íò¸öKibanaÊ·ýÔÚÍøÉ϶³ö¡£¡£¡£¡£¡£KibanaÊÇÒ»¸ö¿ªÔ´µÄ·ÖÎöºÍ¿ÉÊÓ»¯Æ½Ì¨£¬£¬£¬£¬£¬£¬Ö¼ÔÚʵʱ³½ÎöElasticsearchÊý¾Ý¿âÖеÄÊý¾Ý¡£¡£¡£¡£¡£´óÎÞÊý¶³öµÄÊ·ý¶¼Ã»ÓÐÊܵ½±£»£»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÓû§½Ó¼ûÒDZíÅÌ¡£¡£¡£¡£¡£ÕâЩÊ·ýÊôÓÚµç×Ó½ø½¨Æ½Ì¨¡¢ÒøÐÐϵͳ¡¢Í£³µÖÎÀíϵͳ¡¢Ò½ÔººÍ´óѧµÈ´óÐÍ»ú¹¹£¬£¬£¬£¬£¬£¬ÃÀ¹ú£¨8311¸ö£©ÊǶ³öÊ·ý×î¶àµÄ¹ú¶È£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÖйú£¨7282£©¡¢µÂ¹ú£¨1709£©ºÍ·¨¹ú£¨1152£©¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬ºÜ¶àÊ·ý¶¼ÔËÐйýÆÚµÄÈí¼þ°æ±¾£¨´æÔÚËÁÒâÎļþÔ̺¬·ì϶£©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/kibana-data-security.html2.³¬¹ý1.35Íò¸öiSCSI´æ´¢¼¯ÈºÒòÅäÖÃÃýÎóÔÚÍøÉ϶³ö
°²È«×êÑÐÈËÔ±A Shadow·¢ÏÖ³¬¹ý1.35Íò¸öiSCSI´æ´¢¼¯ÈºÒòÅäÖÃÃýÎóÔÚÍøÉ϶³ö¡£¡£¡£¡£¡£ÕâЩ¼¯ÈºÒòδÆôÓÃÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬µ¼Ö·¸×ï·Ö×ÓÄܹ»Í¨¹ý»¥ÁªÍø½Ó¼ûÕâЩ´ÅÅÌÕóÁкÍNASÉ豸£¬£¬£¬£¬£¬£¬Ê¹µÃÆóÒµµÄÃô¸ÐÊý¾ÝÃæ¶Ô·çÏÕ¡£¡£¡£¡£¡£ÕâЩiSCSI¼¯ÈºÊôÓÚ˽Ӫ¹«Ë¾¡¢µ±¾Ö»ú¹¹¡¢´óѧºÍ×êÑлú¹¹µÈ£¬£¬£¬£¬£¬£¬ÊÇÍøÂç·¸×OÍŵÄÃÎÏë¹¥»÷Ö¸±ê¡£¡£¡£¡£¡£
https://www.zdnet.com/article/over-13k-iscsi-storage-clusters-left-exposed-online-without-a-password/
3.ŦԼÊ׸®°Â¶û°ÍÄáÊÐÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬ËðʧÈÔÔÚÆÀ¹ÀÖÐ
ÃÀ¹úŦԼÖÝÊ׸®°Â¶û°ÍÄáÊÐÓÚ3ÔÂ30ÈÕÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬µ±Ç°ÈÔ²»Ã÷ÏÔÆäÍÆËã»úϵͳµÄÊÜËðˮƽ£¬£¬£¬£¬£¬£¬µ«Æ¾¾Ý¸ÃÊйÙÍø°ä²¼µÄÐÂΟ壬£¬£¬£¬£¬£¬ËùÓеijÇÊзþÎñ¶¼ÒÑ¿ÉÓ㬣¬£¬£¬£¬£¬µ«µ®ÉúÖ¤Ã÷¡¢éæÃüÖ¤Ã÷ºÍ³É»éÖ¤Êé·þÎñÖ®±í¡£¡£¡£¡£¡£Ã»ÓÐÖ¤¾ÝÅú×¢Ó×ÎÒÊý¾ÝÊÜË𣬣¬£¬£¬£¬£¬µ«³ÇÊеÄн×Ê·þÎñÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬²»ÄÜÈ·¶¨¸ÃÊÐÊÇ·ñ»áÖ§¸¶Êê½ð¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-york-albany-capital-hit-by-ransomware-attack/4.Ó¡¶Èµ±¾Ö»ú¹¹Òâ±íй¶1250Íò»³ÔÐÅ®ÐÔµÄÒ½ÁÆÐÅÏ¢
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/indian-govt-agency-left-details-of-millions-of-pregnant-women-exposed-online/5¡£¡£¡£¡£¡£Google°ä²¼4ÔÂAndroid°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´¶à¸ö·ì϶
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/google-fixes-two-critical-android-code-execution-vulnerabilities/6.Apache°ä²¼Ð°汾2.4.39£¬£¬£¬£¬£¬£¬½¨¸´¶à¸ö·ì϶
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/apache-bug-lets-normal-users-gain-root-access-via-scripts/


¾©¹«Íø°²±¸11010802024551ºÅ