Rockwell AutomationµÄPLC´æÔÚÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£»£»£»£»£»Ó¡¶ÈZee5ÔÙ´ÎÊý¾Ýй¶£¬£¬£¬ £¬£¬£¬ £¬Éæ¼°900ÍòÓû§µÄPII

°ä²¼¹¦·ò 2021-03-01

1.Rockwell AutomationµÄPLC´æÔÚÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶


1.jpg


×êÑÐÈËÔ±·¢ÏÖRockwell AutomationµÄ¿É±à³ÌÂß¼­½ÚÔìÆ÷£¨PLC£©ÖдæÔÚÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¡£¡£¡£¡£¡£¸Ã·ì϶±»×·×ÙΪCVE-2021-22681£¬£¬£¬ £¬£¬£¬ £¬CVSSÆÀ·ÖΪ10£¬£¬£¬ £¬£¬£¬ £¬Æä´æÔÚÓÚLogix DesignerÈí¼þÖУ¬£¬£¬ £¬£¬£¬ £¬ÊÇÓÉÓÚÑéÖ¤½ÚÔìÆ÷ͨѶµÄ˽ÓÐÃÜÔ¿±£»£»£»£»£»¤²»¼°µ¼Öµġ£¡£¡£¡£¡£Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ìÏ¶ÈÆ¹ýÑéÖ¤»úÔìÀ´ÏνÓLogix½ÚÔìÆ÷¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬£¬ £¬ÀûÓô˷ì϶ºÍµÚÈý·½¹¤¾ß»¹Äܸü¸Ä½ÚÔìÆ÷µÄÅäÖúÍÀûÓ÷¨Ê½´úÂë¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115085/ics-scada/rockwell-automation-software-flaw.html


2.Amazon AlexaÖдæÔÚ¿ÉÈÆ¹ýÉóºËÁ÷³ÌµÄ·ì϶


2.jpg


×êÑÐÍŶÓÔÚÍøÂçºÍÉ¢²¼Ê½ÏµÍ³°²È«×êÑлᣨNDSS£©ÉÏÌá³ö AlexaÖдæÔÚ¿ÉÈÆ¹ýÉóºËÁ÷³ÌµÄ·ì϶¡£¡£¡£¡£¡£ºÚ¿Í¿ÉÀûÓø÷ì϶ÒÔËÁÒ⿪·¢ÕßµÄÃûÒå°ä²¼¶ñÒâÀûÓ㬣¬£¬ £¬£¬£¬ £¬ÉõÖÁÔÚÉóºËͨ¹ýºó¸ü¸Äºó¶Ë´úÂ룬£¬£¬ £¬£¬£¬ £¬À´ÇÔÈ¡Óû§µÄÃô¸ÐÐÅÏ¢£¬£¬£¬ £¬£¬£¬ £¬ÀýÈçµç»°ºÅÂëºÍµØÖ·¡£¡£¡£¡£¡£×êÑÐÈËÔ±Ú¹ÊÍÕâÊÇÓÉÓÚAmazon²»Ñ¡È¡ÈκÎ×Ô¶¯»¯µÄ²½ÖèÀ´¼ì²â¶ñÒâÈí¼þ£¬£¬£¬ £¬£¬£¬ £¬¶øÒÀÀµÓÚÈËΪÉóºËÔòÈÝÒ׳öÏÖ±¨´ðÃýÎ󡣡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/02/alert-malicious-amazon-alexa-skills-can.html


3.Ó¡¶ÈZee5ÔÙ´ÎÊý¾Ýй¶£¬£¬£¬ £¬£¬£¬ £¬Éæ¼°900ÍòÓû§µÄPII


3.jpg


×êÑÐÈËÔ±Rajshekhar Rajaharia·¢ÏÖZee5ÔٴβúÉúÊý¾Ýй¶ÊÂÎñ£¬£¬£¬ £¬£¬£¬ £¬Éæ¼°900ÍòÓû§µÄPII¡£¡£¡£¡£¡£Zee5ÊÇÓ¡¶ÈOTTƽ̨£¬£¬£¬ £¬£¬£¬ £¬Õ¼Óг¬¹ý1.5ÒÚÓû§¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñй¶Á˳¬¹ý900ÍòÓû§µÄÓ×ÎÒÊý¾Ý£¬£¬£¬ £¬£¬£¬ £¬Ô̺¬Óû§µÄÃû×Ö¡¢µç×ÓÓʼþµØÖ·¡¢µ®ÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢Óû§ÃûÒÔ¼°Éϴθüй¦·òµÄ¼Í¼¹¦·ò´Á¡£¡£¡£¡£¡£ÕâÊÇZee5µÚ¶þ´Î°ä²¼ÓйØÊý¾Ýй¶µÄÐÂÎÅ£¬£¬£¬ £¬£¬£¬ £¬µÚÒ»´Î²úÉúÈ¥Äê5Ô·Ý£¬£¬£¬ £¬£¬£¬ £¬ÔøÐ¹Â¶ÁËÉÏǧ¸öÓû§µÄÓû§ÃûºÍ´¿Îı¾ÃÜÂë¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://techdator.net/zee5-data-breach-pii-of-9-million-zee5-users-allegedly-leaked-online/


4.½üÆÚµÄAOLÓʼþ´¹µö»î¶¯Õë¶ÔÖÐÀÏÄêÈËÇÔȡʹ´¦


4.jpg


BleepingComputerÖÒ¸æ½üÆÚµÄAOLÓʼþ´¹µö»î¶¯Õë¶ÔÖÐÀÏÄêÈËÇÔȡʹ´¦¡£¡£¡£¡£¡£µ±´óÎÞÊýÈËʹÓÃGmail¡¢Outlook»òÆäËûÏÖ´úÃâ·ÑÓʼþ·þÎñʱ£¬£¬£¬ £¬£¬£¬ £¬ºÜ¶àÀÏÄêÈËÈÔÔÚʹÓÃAOL¡£¡£¡£¡£¡£¶øÕâ´Î´¹µö»î¶¯ÖØÒªÕë¶ÔÕâһȺÈË£¬£¬£¬ £¬£¬£¬ £¬ÒÔÓÊÏ佫ÔÚ3ÌìÄڹعØÎªÖ÷Ì⣬£¬£¬ £¬£¬£¬ £¬ÓÕʹÓû§ÔÚ´¹µöÒ³ÃæµÇ¼ÕÊ»§À´½øÐÐÑéÖ¤£¬£¬£¬ £¬£¬£¬ £¬ÇÔÈ¡ÆäÍ´´¦¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬£¬ £¬Ïà±Å×ÚÕë¶ÔÆäËû·þÎñ£¨ÀýÈçGmail£©µÄ»î¶¯£¬£¬£¬ £¬£¬£¬ £¬Õâ´Î¹¥»÷¸üÈÝÒ×ͨ¹ýAOLµÄµç×ÓÓʼþ¹ýÂËÆ÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/beware-aol-phishing-email-states-your-account-will-be-closed/


5.FortiGuard Labs°ä²¼2020ÄêÍþÐ²Ì¬ÊÆµÄ»ØÊ׻㱨


5.jpg


FortiGuard Labs°ä²¼ÁË2020ÄêÍþÐ²Ì¬ÊÆµÄ»ØÊ׻㱨¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬ £¬£¬£¬ £¬Õë¶ÔÎïÁªÍø£¨IoT£©É豸£¨ÀýÈç¼ÒÍ¥ÓéÀÖϵͳ¡¢¼Òͥ·ÓÉÆ÷ºÍÏνӵݲȫÉ豸£©µÄ¹¥»÷³ÉÎªÖØÒªÍþв£»£»£»£»£»¹©¸øÁ´¹¥»÷³ÉΪ½¹µã£¬£¬£¬ £¬£¬£¬ £¬SolarWinds¹¥»÷ÊÂÎñ½«¸ÃÎÊÌâÍÆÏòÁËи߶ȣ»£»£»£»£»ÀÕË÷Èí¼þ»î¶¯ÔÚ2020ÄêϰëÄêÔö³¤ÁËÆß±¶£¬£¬£¬ £¬£¬£¬ £¬ÖØÒªÖ¸±êÐÐÒµÔ̺¬Ò½ÁƱ£½¡¡¢×¨Òµ·þÎñ¹«Ë¾¡¢Ïû·ÑÕß·þÎñ¹«Ë¾¡¢¹«¹²²¿ÃźͽðÈÚ·þÎñ¹«Ë¾¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.fortinet.com/blog/industry-trends/fortiguard-labs-global-threat-landscape-report-2021


6.Dragos°ä²¼2020ÄêICSÍøÂ簲ȫµÄ»ØÊ׻㱨


6.jpg


Dragos°ä²¼ÁË2020ÄêICSÍøÂ簲ȫµÄ»ØÊ׻㱨£¬£¬£¬ £¬£¬£¬ £¬Õë¶ÔICS/OTµÄÍøÂçÍþв¡¢·ì϶¡¢ÆÀ¹ÀºÍÊÂÎñÏìÓ¦½øÐÐÁË·ÖÎö¡£¡£¡£¡£¡£2020ÄêÓÐ703¸öICS/OT·ì϶£¬£¬£¬ £¬£¬£¬ £¬±È2019ÄêÔö³¤ÁË29£¥¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖÁËËĸöÖØÒªÕë¶ÔÄÜÔ´ºÍÔì×÷ÒµµÄÐÂICSÍŻ£¬£¬ £¬£¬£¬ £¬±ðÀëÊÇKAMACITE¡¢STIBNITE¡¢TALONITEºÍVANADINITE¡£¡£¡£¡£¡£»ã±¨»¹Ìá³öÁ˼ÓÇ¿ICS»·¾³°²È«ÐÔ½¨Ò飬£¬£¬ £¬£¬£¬ £¬Ô̺¬Ôö³¤OTÍøÂçµÄ¿É¼ûÐÔ¡¢È·¶¨³ÁÒªÐÔ¼°ÓÅÏȼ¶¡¢¼ÓÇ¿ÊÂÎñÏìÓ¦ÄÜÁ¦¡¢ÍøÂç¸ôÀëÑéÖ¤ºÍ°²È«Ö¤ÊéÖÎÀíµÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.dragos.com/year-in-review/