¶íÂÞ˹Èý¸ö¸öÈËÒøÐеĽü90Íò¿Í»§ÐÅÏ¢±»¹«¿ª £»WordPress Live ChatÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶

°ä²¼¹¦·ò 2019-06-12
1¡¢WordPress̸Ìì²å¼þLive Chatзì϶£¬¿Éµ¼Ö»Ự±»½Ù³Ö

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
°²È«×êÑÐÈËÔ±Alert LogicÅû¶WordPressʵʱ̸Ìì²å¼þLive ChatÖеÄÒ»¸öÑϳÁ·ì϶ ¡£¸Ã·ì϶£¨CVE-2019-12498£©Ô´ÓÚ¶ÔÉí·ÝÑéÖ¤µÄ²»ÕýÈ·²é³­£¬¿ÉÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß½Ó¼ûREST API¶Ëµã£¬´Ó¶øÇÔȡ̸Ìì¼Í¼»ò½Ù³Ö̸Ìì»á»° ¡£Live Chat±»³¬¹ý5Íò¼ÒÆóÒµÍøÕ¾Ê¹ÓÃÒÔÌṩ¿Í»§Ö§³ÖºÍ̸Ìì»á»° ¡£¸Ã·ì϶ӰÏìÁËLive Chat8.0.32¼°¸üÔçµÄ°æ±¾£¬½¨ÒéÓû§¸üÐÂÖÁ×îа汾 ¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/06/wordpress-live-chat-plugin.html

2¡¢TecsonÓ͹޼à²âÉ豸ÑϳÁ·ì϶£¬ÔÊÐí¹¥»÷Õß½Ó¼ûWebÅäÖýçÃæ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
°²È«×êÑÐÈËÔ±Maxim Rupp·¢Ïֵ¹úÔì×÷ÉÌTecson³ö²úµÄһЩÓ͹޼à²âÉ豸´æÔÚÑϳÁ·ì϶£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚûÓÐÍ´´¦µÄÇé¿öϽӼûWebÅäÖýçÃæ ¡£¸Ã·ì϶£¨CVE-2019-12254£©µÄCVSSÆÀ·ÖΪ9.8·Ö£¬Ó°ÏìÁËLX-Net¡¢LX-Q-Net¡¢e-litro net¡¢SmartBox4 LANºÍSmartBox4 pro LANϵÁвúÆ· ¡£¹¥»÷ÕßÖ»±ØÒªÖªÂ·Web·þÎñÆ÷ÉϵÄÌØ¶¨URLºÍÓÐЧҪÇóµÄÌåʽ£¬¼´¿É½Ó¼ûÅäÖýçÃæ²¢²é¿´ºÍÅú¸ÄÉèÖã¬Ô̺¬ÃÜÂë¡¢¾¯±¨²ÎÊýºÍÊä³ö״̬µÈËùÓÐÉèÖà ¡£½¨ÒéÓû§¸üÐÂÖÁ¹Ì¼þ6.3»ò½ûÓö˿Úת·¢¼°Ô¶³Ì½Ó¼û ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/critical-vulnerability-exposes-oil-tank-monitoring-devices-attacks

3¡¢Ê©ÄÍµÂµçÆøModicon M580¶à¸ö·ì϶£¬¿Éµ¼ÖÂDoS¼°ÐÅϢй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
˼¿ÆTalosÅû¶ʩÄÍµÂµçÆøModicon M580ÖеĶà¸ö·ì϶ ¡£Modicon M580ÊÇÊ©ÄÍµÂµçÆøModiconϵÁпɱà³Ì×Ô¶¯»¯½ÚÔìÆ÷µÄ×îвúÆ·£¬×êÑÐÈËÔ±ÔÚÆä¹Ì¼þ°æ±¾SV2.70Öз¢ÏÖ¶à¸ö·ì϶£¬Ô̺¬¿Éµ¼ÖÂDoSµÄ·ì϶£¨CVE-2018-7846¡¢CVE-2018-7849¡¢CVE-2018-7843£©£¬¿Éµ¼ÖÂÐÅϢй¶µÄ·ì϶£¨CVE-2018-7844¡¢CVE-2018-7848£©¼°Éí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2018-7842£©µÈ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.talosintelligence.com/2019/06/vulnerability-spotlight-multiple.html

4¡¢FIN8 APTƧ¾²Á½Äêºó»Ø¹é£¬ÖØÒªÕë¶Ô¾ÆµêµÄPOSϵͳ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
°²È«³§ÉÌMorphisec·¢ÏÖAPT×éÖ¯FIN8µÄй¥»÷»î¶¯£¬Õâ±ê־ȡ¸Ã×éÖ¯ÔÚÆ§¾²Á½ÄêºóÔٴγöÏÖ ¡£ÉÏÒ»´Î¹ØÓÚFIN8µÄ»ã±¨ÊÇ2016ÄêºÍ2017ÄêFireEyeºÍroot9B°ä²¼µÄһϵÁÐ×êÑл㱨£¬Æäʱ¸Ã×éÖ¯ÖØÒªÕë¶ÔÁãÊÛÒµµÄPOSϵͳ ¡£Moprihsec°µÊ¾ÔÚ2019Äê¹Û²ìµ½FIN8Õë¶Ô¾ÆµêÒµPOSϵͳµÄй¥»÷»î¶¯£¬¹¥»÷ÕßʹÓÃÁËÓë֮ǰһÑùµÄ¶ñÒâÈí¼þ£¬µ«¸ÄÉÆÁËÌӱܼì²â»úÔìºÍÓÆ¾ÃÐÔ»úÔ죬ÕâÅú×¢¸Ã×éÖ¯Ò»ÏòÔÚ¶Ô¶ñÒ⹤¾ß½øÐпª·¢ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/fin8-hackers-return-after-two-years-with-attacks-against-hospitality-sector/

5¡¢NSHAÔâ´¹µö¹¥»÷£¬½ü3000Ãû»¼ÕßµÄPHIÐÅϢй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
¼ÓÄôóÐÂ˹¿ÆÉáÊ¡ÎÀÉú¾Ö£¨NSHA£©ÔÚ´«µÝÒ»Â·Éæ¼°½ü3000Ãû»¼ÕßµÄÒþÖÔй¶ÊÂÎñ ¡£¸Ã²¿ÃŰµÊ¾£¬ÔÚ2019Äê5ÔÂ8ÈÕÆäÔ±¹¤µÄµç×ÓÓÊÏäÕË»§Ôâµ½´¹µö¹¥»÷£¬¹¥»÷ÕßÇÔÈ¡ÁËÆäÓÊÏäµÄµÇ¼ʹ´¦£¬²¢¿ÉÄܽӼûÁË»¼ÕßµÄPHIÐÅÏ¢ ¡£NSHAµÄITÍŶÓÓÚ2019Äê5ÔÂ13ÈÕ¼ì²âµ½¸ÃÊÂÎñ£¬²¢½«½øÇ°½øÒ»²½µÄµ÷²é ¡£

Ô­ÎÄÁ´½Ó£ºhttps://globalnews.ca/news/5373338/nova-scotia-health-authority-privacy-breach/

6¡¢¶íÂÞ˹Èý¸ö¸öÈËÒøÐеĽü90Íò¿Í»§ÐÅÏ¢±»¹«¿ª


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 
¶íÂÞ˹Èý¼ÒÖØÒª¸öÈËÒøÐеĽü90Íò¿Í»§Êý¾Ý±»¹«¿ª£¬Ô̺¬OTP Bank¡¢Alfa BankºÍHCF Bank ¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µç»°ºÅÂë¡¢µØÖ·¡¢ÐÅÓþ¶î¶È¡¢»¤ÕÕ¾ßÌåÐÅÏ¢ÒÔ¼°Ä³Ð©°¸ÀýÖеŤ×÷µØÖ·¡¢µ®ÉúÄê·ÝºÍÕË»§Óà¶î ¡£Ä¿Ç°Éв»Ã÷ÏÔÕâЩй¶Êý¾Ý¿âµÄÆðÔ´ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/personal-information-of-nearly-900000-banking-customers-of-three-major-russian-banks-leaked-online-54e078f9