WordPress Jetpack²å¼þ·ì϶ӰÏìÊý°ÙÍòÍøÕ¾£» £»£»£» £»£»T-MobileÔâºÚ¿Í¹¥»÷¿Í»§ÕË»§ÐÅϢй¶

°ä²¼¹¦·ò 2019-11-22
1¡¢WordPress Jetpack²å¼þ·ì϶ӰÏìÊý°ÙÍòÍøÕ¾

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

Jetpack¿ª·¢ÍŶӶ½´ÙWordPressÍøÕ¾ÖÎÀíÔ±Á¢¿ÌÀûÓÃJetpack 7.9.1¹Ø¼ü°²È«¸üУ¬£¬£¬£¬£¬£¬£¬ÒÔ½¨¸´Ò»¸ö¹Ø¼ü·ì϶¡£¡£¡£¡£¡£¡£¹ÌÈ»¸ÃÍŶÓûÓÐÅû¶Óйظ÷ì϶µÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬µ«Æ¾¾ÝJetpackµÄ²¼¸æ£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ӰÏìÁË´Ó5.1µ½2017Äê7ÔÂÒÔÀ´µÄËùÓа汾¡£¡£¡£¡£¡£¡£¿£¿ £¿£¿£¿ª·¢ÈËÔ±°µÊ¾Ã»Óз¢Ïָ÷ì϶±»Ò°±íÀûÓõÄÖ¤¾Ý¡£¡£¡£¡£¡£¡£JetpackÊÇÒ»¸öÊÜ»¶Ó­µÄWordPress²å¼þ£¬£¬£¬£¬£¬£¬£¬ËüΪÖÎÀíÔ±ÌṩÃâ·ÑµÄ°²È«ÐÔºÍÕ¾µãÖÎÀíÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬¸Ã²å¼þµÄ»îÔ¾×°ÖÃÁ¿Îª³¬¹ý500Íò£¬£¬£¬£¬£¬£¬£¬¿ª·¢ÍŶӰµÊ¾ÒÑÓг¬¹ý400ÍòÍøÕ¾×°ÖÃÁ˸üС£¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/millions-of-sites-exposed-by-flaw-in-jetpack-wordpress-plugin/

2¡¢Oracle EBS½Ó¼û½ÚÔì²»µ±·ì϶ӰÏìÉÏÍò¼ÒÆóÒµ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

Oracleµç×ÓÉÌÎñÌ×¼þ£¨EBS£©ÖеÄÁ½¸ö¹Ø¼ü·ì϶¿Éµ¼Ö¹¥»÷Õ߯ëÈ«½ÚÔ칫˾µÄERP½â¾ö¹æ»®¡£¡£¡£¡£¡£¡£¸Ã·ì϶±»¹éÀàΪCWE-284£º½Ó¼û½ÚÔì²»µ±£¬£¬£¬£¬£¬£¬£¬ÆäCVSSµÃ·ÖΪ9.9·Ö£¬£¬£¬£¬£¬£¬£¬±»¸ú×ÙΪCVE-2019-2638ºÍCVE-2019-2633¡£¡£¡£¡£¡£¡£ÈôÊdzɹ¦ÀûÓÃÕâÁ½¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬Î´¾­ÊÚȨµÄ¹¥»÷Õ߿ɰѳֵç×Ó»ã¿îÁ÷³Ì²¢´òÓ¡ÒøÐÐ֧Ʊ¶ø²»±»·¢ÏÖ¡£¡£¡£¡£¡£¡£OracleÔÚ4Ô³ÁÒª²¹¶¡¸üÐÂÖн¨¸´Á˸÷ì϶£¬£¬£¬£¬£¬£¬£¬µ«Æ¾¾ÝOnapsis×êÑÐÍŶӵĹÀ¼Æ£¬£¬£¬£¬£¬£¬£¬µ±Ç°Ô¼ÓÐ50£¥µÄOracle EBS¿Í»§ÉÐδ²¿Êð²¹¶¡£¡£¡£¡£¡£¡£¨¿ÉÄܶà´ï1Íò¸öÆóÒµ£©¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/thousands-of-enterprises-at-risk-due-to-oracle-ebs-critical-flaws/

3¡¢×êÑÐÈËÔ±Åû¶Windows UACÖÐÌáȨ·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ZDI×êÑÐÈËÔ±Åû¶WindowsÖеÄÒ»¸ö¸ßΣ·ì϶µÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶Դ×ÔÓû§ÕÊ»§½ÚÔ죨UAC£©Ö°ÄÜ£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÓëUACµÄÓû§½çÃæ½øÐн»»¥£¬£¬£¬£¬£¬£¬£¬ÎÞÌØÈ¨µÄ¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ÔÚͨ³£×ÀÃæÉÏÆô¶¯¸ßÌØÈ¨µÄWebä¯ÀÀÆ÷£¬£¬£¬£¬£¬£¬£¬½ø¶øÄܹ»×°ÖöñÒâ´úÂë»òÖ´ÐÐÆäËü¶ñÒâ»î¶¯¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾¹¥»÷Õß±ØÐëÊ×ÏÈÓµÓÐÖ¸±êϵͳÉϵĵÍÌØÈ¨Óû§Éí·Ý£¬£¬£¬£¬£¬£¬£¬²¢Äܹ»½Ó¼û½»»¥Ê½×ÀÃæ¡£¡£¡£¡£¡£¡£¸Ã·ì϶£¨CVE-2019-1388£©µÄCVSSÆÀ·ÖΪ7.8·Ö£¬£¬£¬£¬£¬£¬£¬Î¢ÈíÔÚÉÏÖܰ䲼µÄ°²È«¸üÐÂÖн¨¸´Á˸÷ì϶¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/windows-uac-flaw-privilege-escalation/150463/

4¡¢×êÑÐÍŶӷ¢ÏÖ11.9ÒÚÕÅÒ½ÁÆÍ¼ÏñÔÚÍøÉÏй¶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


GreenboneµÄ×îÐÂ×êÑÐÅú×¢£¬£¬£¬£¬£¬£¬£¬Î´Êܱ£» £»£»£» £»£»¤µÄͼƬ´æµµºÍͨѶϵͳ£¨PACS£©ÔÚÍøÉ϶³öÁ˶à´ï11.9ÒÚ¸öÒ½ÁÆÍ¼Ïñ£¬£¬£¬£¬£¬£¬£¬Ô̺¬XÉäÏßͼÏñÒÔ¼°CT¡¢MRIºÍÆäËûҽѧɨÃèÁ˾ֵÈ¡£¡£¡£¡£¡£¡£´óÎÞÊýÒ½ÁÆ»ú¹¹¶¼Ê¹ÓÃPACS·þÎñÆ÷À´´æ´¢Ò½ÁÆÍ¼Ïñ²¢ÓëÆäËüÒ½ÁÆ»ú¹¹¹²Ïí£¬£¬£¬£¬£¬£¬£¬µ«Î´Êܱ£» £»£»£» £»£»¤µÄPACS·þÎñÆ÷¿ÉÄÜ»áÔì³É»¼ÕßÊý¾Ýй¶¡£¡£¡£¡£¡£¡£ÕâÒ»Êý¾ÝÓë2019Äê7ÔÂÖÁ9ÔÂÖ®¼ä¹Û²ìµ½µÄÁ˾ÖÔö³¤ÁË60%¡£¡£¡£¡£¡£¡£ÔÚÆØ¹âµÄͼÏñ×ÜÊýÖУ¬£¬£¬£¬£¬£¬£¬ÃÀ¹ú¡¢Ó¡¶È¡¢ÄÏ·Ç¡¢°ÍÎ÷ºÍ¶ò¹Ï¶à¶ûÕ¼75£¥£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ¼ÓÐ7.86ÒÚÕÅͼÏñÈ·ÈÏÀ´×ÔÃÀ¹ú£¬£¬£¬£¬£¬£¬£¬Ô¼ÓÐ1.21ÒÚÕÅÀ´×ÔÓ¡¶È¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/11/20/confidential-medical-images/

5¡¢ÐÂP2P½©Ê¬ÍøÂçRobotoÕë¶ÔLinux Webmin·þÎñÆ÷

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

×êÑÐÈËÔ±·¢ÏÖÒ»¸öеÄP2P½©Ê¬ÍøÂçRoboto£¬£¬£¬£¬£¬£¬£¬¸Ã½©Ê¬ÍøÂçÖØÒªÕë¶ÔLinux Webmin·þÎñÆ÷¡£¡£¡£¡£¡£¡£RobotoÀûÓÃWebminÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-15107£©Ö´ÐÐÈëÇÖ£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÔÚ8ÔÂ17ÈÕ±»½¨¸´£¬£¬£¬£¬£¬£¬£¬ÖÎÀíÔ±¿É¸üÐÂÖÁа汾Webmin 1.930½â¾ö¸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔÓм¸¶ą̀Webmin·þÎñÆ÷Êܵ½¹¥»÷¡£¡£¡£¡£¡£¡£RobotoÖ§³Ö7ÖÖÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬Ô̺¬·´µ¯shell¡¢×ÔÎÒÐ¶ÔØ¡¢ÍøÂç¹ý³ÌÓëÍøÂçÐÅÏ¢¡¢ÍøÂçbotÐÅÏ¢¡¢Ö´ÐÐϵͳºÅÁî¡¢ÔËÐÐURLÖÐÖ¸¶¨µÄ¼ÓÃÜÎļþÒÔ¼°ÌáÒéDDoS¹¥»÷¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/linux-webmin-servers-being-attacked-by-new-p2p-roboto-botnet/

6¡¢T-MobileÔâºÚ¿Í¹¥»÷¿Í»§ÕË»§ÐÅϢй¶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ÒÆ¶¯ÔËÓªÉÌT-Mobile°ä²¼Êý¾Ýй¶֪ͨ°µÊ¾£¬£¬£¬£¬£¬£¬£¬Î´¾­ÊÚȨµÄµÚÈý·½½Ó¼ûÁ˸ù«Ë¾²¿ÃÅʹÓÃÔ¤¸¶·Ñ·þÎñµÄ¿Í»§ÕË»§ÐÅÏ¢¡£¡£¡£¡£¡£¡£T-MobileûÓÐÅû¶ÊÜÓ°ÏìµÄ¿Í»§ÊýÁ¿£¬£¬£¬£¬£¬£¬£¬µ«°µÊ¾¿ÉÄÜÔâµ½½Ó¼ûµÄÊý¾ÝÔ̺¬ÐÕÃû¡¢Õ˵¥ÓʼĵØÖ·¡¢µç»°ºÅÂë¡¢Õ˺š¢ÌײÍÓöȺÍÒµÎñÖ°Äܵȣ¬£¬£¬£¬£¬£¬£¬µ«²»Ô̺¬²ÆÕþÊý¾Ý£¨ÐÅÓþ¿¨ÐÅÏ¢£©¡¢Éç»á°²È«ºÅÂë¼°ÃÜÂë¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾µÄÍøÂ簲ȫÍŶÓÒѾ­×èÖ¹ÁË·¸·¨½Ó¼û¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/t-mobile-discloses-data-breach-impacting-prepaid-customers/