CitrixËùÓвúÆ·´æÔÚ´úÂëÖ´Ðзì϶£¨CVE-2019-19781£©£» £»£»£»£»£»ÓÎÏ·¿ª·¢ÉÌZyngaй¶½ü1.73ÒÚÓû§ÕË»§ÐÅÏ¢

°ä²¼¹¦·ò 2019-12-24


1.ÓÎÏ·¿ª·¢ÉÌZyngaй¶½ü1.73ÒÚÓû§ÕË»§ÐÅÏ¢


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÓÎÏ·¿ª·¢ÉÌZyngaÔÚ9Ô·ÝÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬£¬ £¬£¬½ü1.73ÒÚ¸öÓû§ÃûºÍÃÜÂëй¶¡£¡£¡£ ¡£¡£¹ÌÈ»ZyngaÓÚ9Ôµ×ÈÏ¿ÉÁËÕâÒ»ÊÂÎñ£¬£¬ £¬£¬£¬£¬ £¬£¬µ«Êý¾ÝÐ¹Â¶Í¨ÖªÍøÕ¾HaveIBeenPwned´Ë¿ÌÍøÂçµ½ÁËÓйØÊÜÓ°ÏìÕË»§ÊýÁ¿µÄ¹Ù·½Êý×Ö¡£¡£¡£ ¡£¡£Æ¾¾Ý¸ÃÍøÕ¾µÄ¸üУ¬£¬ £¬£¬£¬£¬ £¬£¬¹²ÓÐ1.729ÒÚ¸ö·ÖÆçµÄµç×ÓÓʼþµØÖ·ÒÔ¼°Óû§ÃûºÍÃÜÂëÔÚÕâ´Î¹¥»÷ÖÐй¶£¬£¬ £¬£¬£¬£¬ £¬£¬ºÃÐÂÎÅÊÇÕâЩÃÜÂëÒÔ¼ÓÑεÄSHA-1É¢Áдó¾Ö´æ´¢£¬£¬ £¬£¬£¬£¬ £¬£¬Ê¹ÆäÄÑÒÔ±»ÆÆ½â¡£¡£¡£ ¡£¡£


  Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/zynga-breach-hit-173-million/


2.ST Logisticsй¶Լ2400ÃûMindefºÍSAFÈËÔ±ÐÅÏ¢


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÐÂ¼ÓÆÂ¹ú·À²¿£¨Mindef£©ºÍÎä×°¶ÓÁУ¨SAF£©Ô¼2400Ãû¹¤×÷ÈËÔ±µÄÓ×ÎÒÊý¾Ý¿ÉÄÜÔÚ´¹µö¹¥»÷ÖÐй¶¡£¡£¡£ ¡£¡£¸ÃÊÂÎñÓëSAFºÍMindefµÄ¸öÈ˹©¸øÉÌST LogisticsÓйØ£¬£¬ £¬£¬£¬£¬ £¬£¬ST LogisticsÖØÒªÌṩµÚÈý·½ºóÇÚ·þÎñ£¬£¬ £¬£¬£¬£¬ £¬£¬ÀýÈçeMartÁãÊÛºÍÉ豸·þÎñ¡£¡£¡£ ¡£¡£MindefÔÚÒ»·ÝÉêÃ÷ÖаµÊ¾Ð¹Â¶µÄÊý¾ÝÔ̺¬ÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢ÁªÏµµç»°¡¢µç×ÓÓʼþºÍסլµØÖ·µÄ×éºÏ¡£¡£¡£ ¡£¡£ST Logistics°µÊ¾ÊÂÎñ²úÉúµÄÔ­ÒòÊÇÆäÔ±¹¤Ôâµ½´¹µöÓʼþ¹¥»÷£¬£¬ £¬£¬£¬£¬ £¬£¬µ«Î´Ìṩ¹¥»÷²úÉúµÄ¹¦·òµÈ¾ßÌåÐÅÏ¢¡£¡£¡£ ¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.straitstimes.com/singapore/personal-data-of-2400-mindef-saf-staff-may-have-been-leaked


3.Champagne Bakery Cafe²ÍÌüÔâµ½PoS¶ñÒâÈí¼þ¹¥»÷


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Champagne French Bakery Caf¨¦²ÍÌüÔâµ½PoS¶ñÒâÈí¼þ¹¥»÷£¬£¬ £¬£¬£¬£¬ £¬£¬¿Í»§µÄÐÅÓþ¿¨Êý¾Ý±»ÇÔ¡£¡£¡£ ¡£¡£Æ¾¾Ý¸Ã²ÍÌü°ä²¼µÄÊý¾Ýй¶֪ͨ£¬£¬ £¬£¬£¬£¬ £¬£¬ÔÚ2019Äê2ÔÂ13ÈÕµ½2019Äê9ÔÂ27ÈյŦ·ò¶ÎÄÚ£¬£¬ £¬£¬£¬£¬ £¬£¬ÓÐ8¼Ò²ÍÌüµÄPoSϵͳϰȾÁ˶ñÒâÈí¼þ£¬£¬ £¬£¬£¬£¬ £¬£¬¾ßÌåµÄϰȾ¹¦·òÁìÓòÒò²ÍÌü¶øÒì¡£¡£¡£ ¡£¡£ÆäÖÐ7¼Ò²ÍÌüϰȾµÄ¶ñÒâÈí¼þÔÚ3Ô·ݵÄijЩÐÇÆÚûÓгɹ¦»ñÈ¡Óû§ÐÅÓþ¿¨Êý¾Ý¡£¡£¡£ ¡£¡£¿ £¿£¿£¿£¿£¿£¿£¿ÉÄܱ»ÇÔµÄÊý¾ÝÔ̺¬³Ö¿¨ÈËÐÕÃû¡¢¿¨ºÅ¡¢ÓÐЧÆÚºÍÄÚ²¿ÑéÖ¤Â룬£¬ £¬£¬£¬£¬ £¬£¬Ä³Ð©Çé¿öÏÂÒ²¿ÉÄܲ»Ô̺¬³Ö¿¨ÈËÐÕÃû¡£¡£¡£ ¡£¡£¸Ã²ÍÌüÒÑ´ÓËùÓÐÊÜϰȾµÄµØÖ·¶Ï¸ùÁ˶ñÒâÈí¼þ¡£¡£¡£ ¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.champagnebakery.com/champagne-french-bakery-cafe-substitute-notice/


4.RavnAirº½¿Õ¹«Ë¾ÔâÍøÂç¹¥»÷±»ÆÈÈ¡µÞ6´Îº½°à


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


RavnAirº½¿Õ¹«Ë¾ÔÚÔâµ½ÍøÂç¹¥»÷Ö®ºóÓÚÖÜÁù±»ÆÈÈ¡µÞÖÁÉÙ6´Î°¢À­Ë¹¼Óº½°à£¬£¬ £¬£¬£¬£¬ £¬£¬Ó°ÏìÁËԼĪ260Ãû³Ë¿Í¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾°µÊ¾£¬£¬ £¬£¬£¬£¬ £¬£¬ÍøÂç¹¥»÷ÆÈʹÆä¶Ï¿ªÁËDash 8·É»úµÄÊØ»¤ÏµÍ³ºÍºó±¸ÏµÍ³µÄÏνÓ£¬£¬ £¬£¬£¬£¬ £¬£¬¸ÃµØÓò±»ÆÈÈ¡µÞÁËËùÓÐÉæ¼°Dash 8·É»úµÄº½°à¡£¡£¡£ ¡£¡£µ±È«¹úÎçÆäº½°à¹¦·ò±íÒѸ´Ô­Õý³£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾ÒÑÏòFBIºÍÆäËüµ÷²éµ±¾Ö»ã±¨ÁËÕâÒ»ÊÂÎñ£¬£¬ £¬£¬£¬£¬ £¬£¬²¢¹ÍÓÃÁËÒ»¼ÒÍøÂ簲ȫ¹«Ë¾À´¸´Ô­ÏµÍ³¡£¡£¡£ ¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95530/cyber-crime/ravnair-alaska-airline-cyberattack.html


5.×êÑÐÍŶÓÅû¶Õë¶Ô¼ÓÄôóÒøÐеĴó¹æÄ£´¹µö»î¶¯


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


½üÆÚCheck Point¼ì²âµ½Ò»¸ö¼ÙÒâ¼ÓÄôó»Ê¼ÒÒøÐУ¨RBC£©Ïò¶à¸ö×éÖ¯ºÍÊܺ¦Õß·¢ËͶñÒâPDF¸½¼þµÄ´¹µöÓʼþ¹¥»÷¡£¡£¡£ ¡£¡£¶ÔÆä¶ñÒâÑù±¾½øÐе÷²éºó·¢ÏÖ£¬£¬ £¬£¬£¬£¬ £¬£¬¸Ã¹¥»÷»î¶¯ÖØÒªÕë¶Ô¼ÓÄôóÒøÐÐÓû§£¬£¬ £¬£¬£¬£¬ £¬£¬²¢ÇÒÖÁÉÙÒѾ­³ÖÐøÁËÁ½Äê¡£¡£¡£ ¡£¡£×ÜÌå¶øÑÔ£¬£¬ £¬£¬£¬£¬ £¬£¬×êÑÐÈËÔ±¼ì²âµ½300¶à¸öÀàËÆµÄ´¹µöÓòÃû£¬£¬ £¬£¬£¬£¬ £¬£¬ÕâЩÓòÃûÍйÜÁËÕë¶ÔÒÔÏÂÒøÐеĴ¹µöÍøÕ¾£º¼ÓÄôó»Ê¼ÒÒøÐÓ×¢·áÒµÒøÐÓ×¢ÃÉÌØÀû¶ûÒøÐÓ×¢¼ÓÄôóµÛ¹úóÒ×ÒøÐÓ×¢ÃÀ¹úÔËͨ¡¢¸»¹úÒøÐеȡ£¡£¡£ ¡£¡£¾ßÌåIoCÖ¸±êÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£ ¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://research.checkpoint.com/2019/canadian-banks-targeted-in-a-massive-phishing-campaign/


6.CitrixËùÓвúÆ·´æÔÚ´úÂëÖ´Ðзì϶£¨CVE-2019-19781£©


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°²È«×¨¼ÒMikhail KlyuchnikovÔÚCitrix Application Delivery ControllerºÍCitrix Gateway²úÆ·Öз¢ÏÖÒ»¸öÑϳÁµÄ´úÂëÖ´Ðзì϶£¬£¬ £¬£¬£¬£¬ £¬£¬¸Ã·ì϶£¨CVE-2019-19781£©Ê¹158¸ö¹ú¶ÈµÄ³¬¹ý8Íò¼Ò¹«Ë¾Ãæ¶Ô·çÏÕ¡£¡£¡£ ¡£¡£ÓÉÓÚÀûÓø÷ì϶µÄ¹¥»÷ÕßÎÞÐèÉí·ÝÑéÖ¤¼´¿É½Ó¼û¹«Ë¾µÄÄÚ²¿ÍøÂ磬£¬ £¬£¬£¬£¬ £¬£¬Òò¶ø¸Ã·ì϶ÓÈÆäΣÏÕ¡£¡£¡£ ¡£¡£³É¹¦ÀûÓø÷ì϶¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐÓ×£¡£¡£ ¡£¡£Æ¾¾ÝCitrix£¬£¬ £¬£¬£¬£¬ £¬£¬¸Ã·ì϶ӰÏìÁËËùÓÐÊÜÖ§³ÖµÄ²úÆ·°æ±¾ºÍƽ̨£¬£¬ £¬£¬£¬£¬ £¬£¬Ö»¹ÜCitrixÉÐδ°ä²¼Ð¹̼þÀ´½â¾ö¸ÃÎÊÌ⣬£¬ £¬£¬£¬£¬ £¬£¬µ«¸Ã¹«Ë¾ÒѰ䲼ÁËÒ»Ì×Õë¶Ô¶ÀÁ¢ÏµÍ³ºÍ¼¯ÈºµÄ»º½â´ëÊ©£¬£¬ £¬£¬£¬£¬ £¬£¬²¢Ç¿ÁÒ½¨ÒéÊÜÓ°ÏìµÄ¿Í»§Ñ¡È¡ËüÃÇ¡£¡£¡£ ¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-citrix-flaw-may-expose-thousands-of-firms-to-attacks/