¾ÆµêÖÎÀí¹«Ë¾AavGoÒâ±íй¶800Íò¿Í»§ÐÅÏ¢£»£»£» £»£»£»£»£»Î¢Èí½¨¸´PowerShellÖ÷ÌâÖеÄWDACÈÆ¹ý·ì϶

°ä²¼¹¦·ò 2019-07-18

1¡¢¾ÆµêÖÎÀí¹«Ë¾AavGoÒâ±íй¶800Íò¿Í»§ÐÅÏ¢


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Wizcase°²È«×êÑÐÔ±Daniel Brown·¢Ï־ƵêÖÎÀíÉÌAavGoµÄÒ»¸öElasticsearchÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬ £¬£¬ £¬£¬ £¬ £¬£¬¸ÃÊý¾Ý¿âÔ̺¬800ÍòÌõ¿Í»§ÐÅÏ¢£¬ £¬£¬ £¬£¬ £¬ £¬£¬Ô̺¬Ô¤Ô¼ÐÅÏ¢¡¢¿Í»§Í¶Ëß¡¢·¢Æ±¡¢¹¤µ¥¡¢Ô±¹¤±¸Íü¼ºÍÐÂÎÅ¡¢¾Æµê·¿¼äͼƬ¡¢ÎïÆ·°Ü»µÍ¼Æ¬ÒÔ¼°¿Í»§µÄÓ×ÎÒÐÅÏ¢£¨ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢ÓÊÏ䵨ַ¡¢×¡Ö·¡¢»éÒöÇé¿ö¡¢µÇ¼ÐÅÏ¢ºÍ¸¶¿î·½Ê½£©¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý»¹Ô̺¬¾ÆµêÖÎÀíÔ±µÄ¾ßÌåµÇ¼ÐÅÏ¢£¬ £¬£¬ £¬£¬ £¬ £¬£¬ÀýÈçÖÎÀíÃæ°å¡¢Ô¤Ô¼ÏµÍ³ºÍÄÚ²¿Êý¾Ý¿âµÄÓû§ÃûºÍÃÜÂë¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ¾ÆµêÔ̺¬The Row Hotel¡¢Stay Cal HotelsµÈÊ®¶à¼Ò¾Æµê¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÒÑÔÚ7ÔÂ16ÈÕ¶ÔÊý¾Ý¿â²ÉÈ¡Á˱£»£»£» £»£»£»£»£»¤´ëÊ©¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/unprotected-elasticsearch-database-belonging-to-aavgo-exposed-8-million-records-of-guest-details-f5fb1eac


2¡¢CPL³Æ220Íò»¼ÕßÐÅÏ¢ÊÜAMCAÊý¾Ýй¶ÊÂÎñÓ°Ïì


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÁÙ´²²¡Àíѧ³¢ÊÔÊÒ£¨CPL£©³ÉΪAMCAÊý¾Ýй¶ÊÂÎñµÄ×îÐÂÊܺ¦Õß¡£¡£¡£¡£¡£¡£AMCAÒÑÏò3.45ÍòCPL»¼Õß·¢ËÍÁËÊý¾Ýй¶֪ͨ£¬ £¬£¬ £¬£¬ £¬ £¬£¬Æ¾¾ÝAMCAÌṩµÄÐÅÏ¢£¬ £¬£¬ £¬£¬ £¬ £¬£¬CPL¹À¼Æ»¹ÓÐ220Íò»¼ÕßÊܵ½´ËÊÂÎñµÄÓ°Ïì¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬CPL»¼ÕßµÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢·þÎñÈÕÆÚ¡¢Óà¶î¡¢ÐÅÓþ¿¨ÐÅÏ¢ºÍÒ½ÉúÐÅÏ¢¡£¡£¡£¡£¡£¡£AMCAÈ·ÈÏ»¼ÕßµÄÉç»á°²È«ºÅÂëδÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/clinical-pathology-laboratories-notifies-patients-of-security-incident-caused-by-amca-data-breach-37f8382c


3¡¢Sprint³ÆºÚ¿Íͨ¹ýÈýÐÇÍøÕ¾ÈëÇÔìä¿Í»§ÕË»§


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÃÀ¹úµçÐŹ«Ë¾Sprint°µÊ¾ºÚ¿ÍÉè·¨ÀûÓÃÈýÐÇÍøÕ¾Samsung.comÉϵÄаìºÅÂë¡°Add a line¡±Ò³Ãæ×÷Ϊ¹¥»÷Ìø°å£¬ £¬£¬ £¬£¬ £¬ £¬£¬ÈëÇÔìä¿Í»§ÕË»§¡£¡£¡£¡£¡£¡£ÔÚ·¢¸ø¿Í»§µÄ֪ͨº¯ÖÐSprint°µÊ¾¹²²úÉúÁËÁ½ÆðÎ¥¹æÐÐΪ£¬ £¬£¬ £¬£¬ £¬ £¬£¬Ò»Â·²úÉúÔÚ6ÔÂ8ÈÕ£¬ £¬£¬ £¬£¬ £¬ £¬£¬Áíһ·²úÉúÔÚ6ÔÂ22ÈÕ¡£¡£¡£¡£¡£¡£ºÚ¿ÍÄܹ»½Ó¼ûµÄ¿Í»§ÐÅÏ¢Ô̺¬Óû§ID¡¢Õʺš¢ÕÊ»§´´½¨ÈÕÆÚ¡¢ÐÕÃû¡¢Õʵ¥µØÖ·¡¢µç»°ºÅÂë¡¢É豸ÀàÐÍ¡¢É豸ID¡¢Ã¿ÔÂÓöȵȡ£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/sprint-accounts-breached-by-hackers-using-samsung-site/


4¡¢Î¢Èí½¨¸´PowerShellÖ÷ÌâÖеÄWDACÈÆ¹ý·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


΢Èí°ä²¼Ð°汾PowerShell Core£¬ £¬£¬ £¬£¬ £¬ £¬£¬½¨¸´Ò»¸ö¿ÉÔÊÐí±¾µØ¹¥»÷ÕßÈÆ¹ýWindows DefenderÀûÓ÷¨Ê½½ÚÔ죨WDAC£©µÄ·ì϶£¬ £¬£¬ £¬£¬ £¬ £¬£¬¸Ã·ì϶±»ÏóÕ÷ΪCVE-2019-1167¡£¡£¡£¡£¡£¡£ÔÚÆôÓÃWDACʱ£¬ £¬£¬ £¬£¬ £¬ £¬£¬PowerShell½«×Ô¶¯½øÈëÔ¼ÊøËµ»°Ä£Ê½ÒÔÏ޶ȶÔijЩWindows APIµÄ½Ó¼û£¬ £¬£¬ £¬£¬ £¬ £¬£¬µ«¸Ã·ì϶¿ÉÈÆ¹ýPowerShellÔ¼ÊøËµ»°Ä£Ê½ºÍWDAC¡£¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁË6.1.5֮ǰµÄËùÓÐPowerShell Core 6.0¡¢6.1°æ±¾ºÍ6.2.2֮ǰµÄPowerShell Core 6.2°æ±¾£¬ £¬£¬ £¬£¬ £¬ £¬£¬½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/microsoft/microsoft-patches-powershell-core-security-bug-to-fix-wdac-bypass/


5¡¢LenovoEMC/Iomega NAS±»ÆØ´æÔÚÐÅϢй¶·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×êÑÐÈËÔ±ÖÒ¸æ³Æ£¬ £¬£¬ £¬£¬ £¬ £¬£¬LenovoEMC/IomegaÆ·ÅÆµÄNASÉ豸ÖдæÔÚÐÅϢй¶·ì϶£¬ £¬£¬ £¬£¬ £¬ £¬£¬µ¼Ö´óÁ¿Ãô¸ÐÊý¾ÝÔÚ¹«ÍøÉ϶³ö¡£¡£¡£¡£¡£¡£LenovoEMCºÍIomegaµÄNAS²úÆ·ÖØÒªÃæ¶ÔÖÐÓ×ÐÍÆóÒµ¡£¡£¡£¡£¡£¡£¸Ã·ì϶£¨CVE-2019-6160£©Ô´ÓÚδÊܱ£»£»£» £»£»£»£»£»¤µÄAPIŲÓ㬠£¬£¬ £¬£¬ £¬ £¬£¬ÈκÎÈ˶¼Äܹ»Í¨¹ýShodan²éÕÒÒ×Êܹ¥»÷µÄNASÉ豸£¬ £¬£¬ £¬£¬ £¬ £¬£¬¶øºóͨ¹ý·¢ËͶñÒâÒªÇóÏÂÔØÉ豸ÉϵÄÎļþ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚshodanÉÏ·¢ÏÖÁ˶³öÔÚ¹«ÍøµÄ36TBÊý¾Ý£¬ £¬£¬ £¬£¬ £¬ £¬£¬Éæ¼°5114¸öÉ豸¡£¡£¡£¡£¡£¡£¸Ã·ì϶Ŀǰ»¹Ã»Óа䲼¾ßÌåµÄ½¨¸´¹¦·ò¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.helpnetsecurity.com/2019/07/17/lenovoemc-nas-devices-flaw/


6¡¢Drupal CMS½¨¸´¿Éµ¼ÖÂÍøÕ¾±»ÊÕÊܵÄÑϳÁ·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Drupal CMS¿ª·¢ÍŶӰ䲼8.7.5°æ±¾£¬ £¬£¬ £¬£¬ £¬ £¬£¬½¨¸´½Ó¼ûÈÆ¹ý·ì϶£¨CVE-2019-6342£©¡£¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁËDrupal 8.7.4 ¡¢8.7.3¼°¸üÔç°æ±¾¡¢8.6.x¼°¸üÔç°æ±¾£¬ £¬£¬ £¬£¬ £¬ £¬£¬¶øDrupal 7.x²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÉÐÎÞ¿ÉÓõÄexp£¬ £¬£¬ £¬£¬ £¬ £¬£¬ÃÀ¹úCISAÒ²·¢³öÖҸ棬 £¬£¬ £¬£¬ £¬ £¬£¬¶½´ÙDrupalÖÎÀíÔ±ºÍÓû§Éý¼¶µ½Drupal 8.7.5°æ±¾¡£¡£¡£¡£¡£¡£Æ¾¾ÝDrupal CoreʹÓÃÇé¿öͳ¼ÆÊý¾Ý£¬ £¬£¬ £¬£¬ £¬ £¬£¬¹²ÓÐÔ¼29Íò¸öÍøÕ¾ÔÚʹÓÃDrupal 8.x¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/drupal-patches-critical-bug-that-lets-hackers-take-over-sites/