Cisco°ä²¼°²È«¸üУ¬£¬£¬£¬£¬½¨¸´¶à¸ö²úÆ·Öеķì϶£»£»£»£»£»£»WooCommerceÖзì϶¿Éµ¼ÖÂÍøÕ¾ÊÕÊÜ£¬£¬£¬£¬£¬Ó°ÏìÉÏÍò¼ÒÉ̵ê
°ä²¼¹¦·ò 2020-08-241.Cisco°ä²¼°²È«¸üУ¬£¬£¬£¬£¬½¨¸´¶à¸ö²úÆ·Öеķì϶

Cisco°ä²¼°²È«¸üУ¬£¬£¬£¬£¬ÒÔ½¨¸´Æä¶à¸ö²úÆ·Öеķì϶¡£¡£¡£¡£¡£¡£Õâ´Î°²È«¸üÐÂÖн¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶ΪTreck IP²Ö¿âÖеķì϶Ripple20£¬£¬£¬£¬£¬ÕâЩ·ì϶¿Éµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡¢»Ø¾ø·þÎñ£¨DoS£©»òÐÅϢй¶£»£»£»£»£»£»ÓÃÓÚCisco ENCS 5400-WϵÁкÍCSP 5000-WϵÁеÄCisco vWAASĬÈÏÍ´´¦·ì϶£¨CVE-2020-3446£©£¬£¬£¬£¬£¬¿É±»ÀûÓÃÒÔÖÎÀíԱȨÏÞ½Ó¼ûNFVIS CLI£»£»£»£»£»£»Ë¼¿ÆÖÇÄÜÈí¼þÖÎÀíÆ÷£¨SSM On-Prem£©±¾µØÌØÈ¨Éý¼¶·ì϶£¨CVE-2020-3443£©ÒÔ¼°Ë¼¿ÆÊÓÆµ¼à¿Ø8000ϵÁÐIPÉãÏñ»ú˼¿Æ·¢ÏÖºÍ̸Զ³ÌÖ´Ðкͻؾø·þÎñ·ì϶£¨CVE-2020-3506ºÍCVE-2020-3507£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/08/20/cisco-releases-security-updates
2.FBIºÍCISAÖÒ¸æÕë¶ÔÃÀ¹úƫԶµØÓò¹¤È˵Ĵ¹µö»î¶¯

ÃÀ¹úFBIºÍCISA½áºÏ°ä²¼¾¯±¨£¬£¬£¬£¬£¬ÖÒ¸æÄ¿Ç°Õë¶ÔÃÀ¹ú¶à¸öÐÐÒµ²¿ÃŵÄÓïÒôÍøÂç´¹µö»î¶¯£¨Vishing£©¡£¡£¡£¡£¡£¡£VishingÊÇÒ»ÖÖÉç»á¹¤³Ì¹¥»÷£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÓïÒôºô½ÐÆÚ¼äÄ£ÄâÊÜÐÅÀµµÄʵÌ壬£¬£¬£¬£¬ÒÔÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹°µÊ¾£¬£¬£¬£¬£¬×Ô2020Äê7ÔÂÖÐÑ®£¬£¬£¬£¬£¬ÍøÂç·¸×ï·Ö×Ó·¢Õ¹ÁËÕâÒ»»î¶¯£¬£¬£¬£¬£¬Ö¼ÔÚıȡÀûÒæ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬¹¥»÷Õß»¹×¢²áÁËÓÃÓÚÍøÂç´¹µöµÄÓò£¬£¬£¬£¬£¬ÒÔ¿Ë¡ָ±ê¹«Ë¾µÄÄÚ²¿VPNµÇÂ¼Ò³Ãæ£¬£¬£¬£¬£¬À´ÇÔÈ¡Á½³É·ÖÉí·ÝÑéÖ¤£¨2FA£©ºÍÒ»´ÎÐÔÃÜÂ루OTP£©¡£¡£¡£¡£¡£¡£Îª´Ë£¬£¬£¬£¬£¬FBIºÍCISAÌá³öһϵÁн¨Òé´ëÊ©£¬£¬£¬£¬£¬ÒÔ»º½â´ËÀ๥»÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-govt-warns-remote-workers-of-ongoing-vishing-campaign/
3.WooCommerceÖзì϶¿Éµ¼ÖÂÍøÕ¾ÊÕÊÜ£¬£¬£¬£¬£¬Ó°ÏìÉÏÍò¼ÒÉ̵ê

WebARX·¢ÏÖWordPress²å¼þWooCommerceÖзì϶¿Éµ¼ÖÂÍøÕ¾ÊÕÊÜ£¬£¬£¬£¬£¬Ó°ÏìÉÏÍò¼ÒÉ̵ꡣ¡£¡£¡£¡£¡£Æ¾¾Ý·ÖÎöÔ±¶Ô·ì϶µÄ·ÖÎö£¬£¬£¬£¬£¬·¢ÏÖËüÃÇÊÇÓɲ»×ãËæ»úÊýÁîÅÆºÍÊÚȨ²é³µ¼Öµģ¬£¬£¬£¬£¬ÈôÊdzɹ¦ÀûÓÃÕâЩ·ì϶£¬£¬£¬£¬£¬Ôòδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»¼ìË÷ËùÓÐЧ»§ºÍÓÅ»Ýȯ´úÂëµÄÁÐ±í£¬£¬£¬£¬£¬²¢ÔÚÍøÕ¾µÄҳü¡¢Ò³½Å»òÖÎÀíÒ³Ãæ×¢ÈëXSS£¬£¬£¬£¬£¬ÒÔ´¥·¢Ô¶³ÌÖ´ÐдúÂë·ì϶¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ºÚ¿Í»¹Äܹ»ÀûÓÃJavaScript¼üÅ̼ͼ·¨Ê½×¢ÈëµÇ¼±íµ¥£¬£¬£¬£¬£¬ÒÔÊÕÊÜÖÎÀíÔ¹ØÊ»§¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬¸Ã²å¼þÔÚ´Óǰ7ÌìÄÚÒѱ»ÏÂÔØÁ˳¬¹ý12000´Î¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/wordpress-woocommerce-stores-under-attack-patch-now/
4.Diebold Nixdorf½¨¸´¿É±»ÓÃÓÚ´æ¿îαÔì¹¥»÷µÄ·ì϶

ATMÔì×÷ÉÌDiebold NixdorfºÍNCR°ä²¼ÁËÈí¼þ¸üУ¬£¬£¬£¬£¬½¨¸´¿É±»ÓÃÓÚ´æ¿îαÔì¹¥»÷µÄ·ì϶¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ·ì϶±»×·×ÙΪCVE-2020-9062ºÍCVE-2020-10124£¬£¬£¬£¬£¬±ðÀëÓ°ÏìÁËÔËÐÐWincor ProbaseÈí¼þµÄDiebold Nixdorf ProCash 2100xe USB ATMºÍÔËÐÐAPTRA XFSÈí¼þµÄNCR SelfServ ATM¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶¿É±»ºÚ¿ÍÀûÓÃÒÔÅú¸ÄÆäÒøÐп¨ÉϵĴæ¿î½ð¶î£¬£¬£¬£¬£¬²¢ÔÚÒøÐз¢ÏÖÕË»§Óà¶îÒ쳣֮ǰ½øÐÐÚ²ÆÐÔÈ¡¿î¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶ԴÓÚATMÏÖ½ð´æ·ÅÏäºÍÖ÷»úÖ®¼ä·¢Ë͵ÄÐÂÎŶÌȱ¼ÓÃܺÍÉí·ÝÑéÖ¤»·½Ú£¬£¬£¬£¬£¬Ä¿Ç°DieboldºÍNCR¾ùÒѰ䲼Èí¼þ¸üУ¬£¬£¬£¬£¬ÒÔ±£»£»£»£»£»£»¤ÏÖ½ð´æ¿îÄ£¿£¿£¿£¿£¿£¿éÓëÖ÷»úÖ®¼äµÄͨѶ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/107421/hacking/diebold-nixdorf-ncr-deposit-forgery.html
5.Spikey¹¥»÷¿ÉÀûÓÃÐźŴ¦ÖÃÈí¼þ¿Ë¡ÎïÀíÔ¿³×

ÐÂ¼ÓÆÂ¹úÁ¢´óѧµÄ×êÑÐÈËÔ±·¢ÏÖÒ»ÖÖÕë¶ÔÎïÀíËøµÄй¥»÷Õ½ÊõSpikey£¬£¬£¬£¬£¬¿ÉÀûÓÃÐźŴ¦ÖÃÈí¼þ¿Ë¡ÎïÀíÔ¿³×¡£¡£¡£¡£¡£¡£´ËÀ๥»÷Äܹ»ÀûÓÃÖÇÄÜÊÖ»úµÄÂó¿Ë·ç²¶»ñÔ¿³×²åÈë»ò°Î³öʱµÄ½ðÊôµã»÷Éù£¬£¬£¬£¬£¬²¢ÓÃÐźŴ¦ÖÃÈí¼þ½øÐÐÆÆÒ룬£¬£¬£¬£¬ÒÔ´§¶ÈÔ¿³×µÄ״̬£¬£¬£¬£¬£¬×îÖÕÄܹ»ÓÃ3D´òÓ¡¼¼Êõ¿Ë¡³öÎïÀíÔ¿³×¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾½«À´»¹¿ÉÄÜͨ¹ý¶ñÒâÈí¼þϰȾÊܺ¦ÕßµÄÖÇÄÜÊÖ»ú»òÖÇÄÜÍó±í£¬£¬£¬£¬£¬ÒԴ˼ͼÉùÒô²¢ÌáÒé¹¥»÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://latesthackingnews.com/2020/08/21/spikey-attack-can-duplicate-physical-keys-by-listening-to-click-sounds/
6.Ó¢¹úMyerscough´óѧÔâµ½DoS¹¥»÷µ¼ÖÂϵͳÍÑ»ú

Ó¢¹úMyerscough´óѧÔÚ°ä²¼¿¼ÊԳɾÍÈ·µ±ÌìÔâµ½DoS¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂϵͳÍÑ»ú¡£¡£¡£¡£¡£¡£¸Ã´óѧ°µÊ¾£¬£¬£¬£¬£¬DoS¹¥»÷ÑϳÁ·ÛËéÁËÆäËùÓÐIT»ù´¡ÉèÊ©£¬£¬£¬£¬£¬µ¼ÖÂϵͳ´¦ÓÚÍÑ»ú״̬£¬£¬£¬£¬£¬Ñ§ÉúÎÞ·¨½Ó¼ûÃÅ»§ÍøÕ¾GCSEºÍ²éÎÊ¿¼ÊÔÁ˾֡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Ñ§ÌÃÔ±¹¤Ò²Ö»ÄÜͨ¹ýÉ罻ýÌ幤¾ßÁªÏµ£¬£¬£¬£¬£¬²¢ÇÒÔÚ·þÎñÆ÷¸´Ô֮ǰֻÄÜÊÖ¶¯ÏòËùÓÐѧÉú·¢ËÍÆä³É¾ÍµÄµç×ÓÓʼþ¡£¡£¡£¡£¡£¡£¸ÃѧÌõĽ²»°È˰µÊ¾£¬£¬£¬£¬£¬Ä¿Ç°²¢Ã»ÓÐѧÉúµÄÊý¾ÝÔ⵽й¶£¬£¬£¬£¬£¬¶ø±¾µØ¾¯·½Ò²ÔÚ¶Ô´ËÊ·¢Õ¹µ÷²é¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bbc.com/news/uk-england-lancashire-53822246


¾©¹«Íø°²±¸11010802024551ºÅ