ÃÀ¹úGilletteÒ½ÔºÔâÀÕË÷Èí¼þ¹¥»÷£»Magecart¶ñÒâÓòÃûÐÔÃüÖÜÆÚµÄ·ÖÎö»ã±¨

°ä²¼¹¦·ò 2019-09-23

1.TescoÍ£³µÀûÓôæÔÚ·ì϶µ¼ÖÂÊýǧÍò³µÅÆÍ¼Ïñй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚ±íýThe Register±¨Â·ÊýǧÍòÕÅANPR£¨³µÅÆ×Ô¶¯¼ø±ð£©Í¼ÏñÔÚMicrosoft AzureÖж³öÖ®ºó£¬TescoÒÑ¹Ø¹ØÆäÍ£³µÑéÖ¤WebÀûÓá£ÕâЩͼÏñÓÉÓ¢¹ú¸÷µØµÄ19¸öTescoÍ£³µ³¡ËùÅÄÉãµÄ½øÈëºÍÍÑÀëµÄÆû³µÕÕÆ¬×é³É£¬ÕÕÆ¬ÖÐ͹ÆðÏÔʾÁËÆû³µµÄ³µÅÆ£¬¹ÌÈ»ÓÉÓÚ·Ö±æÂʽϵͶø¿´²»µ½¼ÝʻԱ¡£ANPRͼÏñÒÔ´øÓй¦·ò´ÁµÄjpegÌåʽ±£ÁôÔÚAzure blobÖУ¬²¢ÇÒͼÏñÎļþÃûÒ²Ô̺¬¹¦·òÐÅÏ¢£¬´Ó¶øÊ¹µÃÈκÎÕýÈ·´§¶È³öËùÐèHTTP POSTÒªÇóÌåʽµÄÈËÄܹ»ÅúÁ¿»ñÈ¡ÕâЩͼÏñÒÔ¹©·¸·¨Ê¹Óá£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2019/09/20/tesco_parking_app_10s_millions_anpr_photos_exposed/


2.ÐÂÎ÷À¼³èÎïÁãÊÛÉÌAnimatesÔâºÚ¿ÍÇÔÈ¡2700Ãû¿Í»§ÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÐÂÎ÷À¼³èÎïÁãÊÛÉÌAnimatesÔâ·êÊý¾Ýй¶ÊÂÎñ£¬µ¼ÖÂ2700λ¿Í»§µÄÓ×ÎҺͲÆÕþÐÅϢй¶¡£¸ÃÊÂÎñ²úÉúÔÚ2019Äê6ÔÂ29ÈÕÖÁ9ÔÂ13ÈÕÖ®¼ä£¬ÊÂÎñÔ­ÒòÊÇδ¾­ÊÚȨµÄµÚÈý·½½Ó¼û¡£Animates°µÊ¾¿Í»§µÄÐÅÓþ¿¨/½è¼Ç¿¨Êý¾ÝÊǹ¥»÷ÕßµÄÖ¸±ê£¬Í¬Ê±¿Í»§µÄÓ×ÎÒÐÅÏ¢Ò²Ôâй¶£¬Ô̺¬µØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢Óû§ÃûºÍÃÜÂë¡£¶ÔÓÚʹÓÃLayby»òPayPalÔÚÏß¹ºÎïµÄ¿Í»§£¬Æä¸¶¿îÐÅÏ¢²»ÊÜÓ°Ïì¡£Animates»¹È·ÈϳÆÊµÌåµêµÄÂòÂôδÊÜÓ°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://www.animates.co.nz/data-breach/


3.ÃÀ¹úGilletteÒ½ÔºÔâÀÕË÷Èí¼þ¹¥»÷µ¼Ö·þÎñÖжÏ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÃÀ¹úÎÀÉú²¿·¢³öµÄ¾¯±¨£¬GilletteÒ½ÔºÔÚÉÏÖÜÎåÔâµ½ÀÕË÷Èí¼þ¹¥»÷¡£¸Ã¹¥»÷Ô¼²úÉúÔÚÖÜÎåÁ賿3µã£¬µ¼ÖÂÒ½ÔºÔâ·êÁËÑϳÁµÄÍÆËã»úÎÊÌâÒÔ¼°·þÎñÖжÏ¡£ÔÚÖÜÎå·Å¹¤¹¦·ò£¬¸ÃÒ½ÔºµÄµç»°ÏµÍ³ÒѳÁÐÂÉÏÏߣ¬µ«ÈÔ²»ÄܲÉÈ¡ÈκÎл¼Õߣ¬²¢ÇÒÆä³¢ÊÔÊÒ¡¢ºôÎüÒ½Öμ°·ÅÉä¿ÆÒ²²»ÄÜÌṩ²é³­ºÍÒ½ÖηþÎñ¡£¸ÃÒ½ÔºÕý½«ÃÅÕï·þÎñ»ò¼¹Øï·þÎñµÄ»¼Õß·ÖÁ÷ÖÁÆäËüÒ½Ôº¡£ÎÀÉú²¿ÖÒ¸æÆäËüÒ½Ôº¼ì²âÆäIT·þÎñ£¬²¢ÔÚ·¢ÏÖÈκοÉÒÉÄÚÈÝʱÌáÐѵ±¾Ö¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/wy-gillette-hospital-targeted-in-ransomware-attack/


4.Atlassian½¨¸´Jira ServerºÍService DeskÖеÄÁ½¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Atlassian°ä²¼Jira ServerºÍService DeskµÄ°²È«¸üУ¬½¨¸´Á½¸ö°²È«·ì϶¡£µÚÒ»¸ö·ì϶ÊÇURLõè¾¶±éÀú·ì϶£¨CVE-2019-14994£©£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶²é¿´Ö¸±êÊ·ýÖеÄËùÓÐJiraÏîÄ¿£¬Ô̺¬Service DeskÏîÄ¿¡¢Jira CoreÏîÄ¿ºÍJira SoftwareÏîÄ¿¡£Tenable×êÑÐÈËÔ±Satnam Narang»ã±¨³Æ2.5Íò¶à¸öÒ×Êܹ¥»÷µÄÊ·ýÔÚÍøÉ϶³ö£¬ËüÃÇÊôÓÚÒ½ÁÆ¡¢µ±¾Ö¡¢½ÌÓýºÍÔì×÷ÐÐÒµµÈ¡£µÚ¶þ¸ö·ì϶ÊÇJira Importers²å¼þÖеÄÄ£°å×¢Èë·ì϶£¨CVE-2019-15001£©£¬¸Ã·ì϶ӰÏìÁËJira ServerºÍJira Data CenterµÄ7.0.10°æ±¾£¬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶Զ³ÌÖ´ÐдúÂë¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/jira-server-and-service-desk-fix-critical-security-bugs/


5.VMware½¨¸´ESXi¡¢WorkstationµÈ²úÆ·ÖеÄÁ½¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


VMware°ä²¼°²È«¸üУ¬½¨¸´¶à¸ö²úÆ·ÖеÄÁ½¸ö·ì϶¡£µÚÒ»¸ö·ì϶ÊÇESXi¡¢Workstation¡¢Fusion¡¢VMRCºÍHorizon ClientÖеÄuse-after-free·ì϶£¬¸Ã·ì϶£¨CVE-2019-5527£©µÄCVSS v3ÆÀ·ÖΪ8.5·Ö£¬ÊÇÒ»¸öÐé¹¹»úÌÓÒÝ·ì϶£¬¿Í»§»úÉÏÓµÓзÇÖÎÀíԱȨÏ޵ı¾µØ¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚËÞÖ÷»úÉÏÖ´ÐдúÂë¡£µÚ¶þ¸ö·ì϶ÊÇWorkstationºÍFusionÖеÄDoS·ì϶£¨CVE-2019-5535£©£¬¸Ã·ì϶µÄCVSS v3ÆÀ·ÖΪ4.7·Ö¡£¸Ã·ì϶ÓëVMNATµÄIPv6ģʽÓйØ£¬¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâIPv6Êý¾Ý°üÀ´²»ÈÝNATģʽÏ¿ͻ§»úÉϵÄÍøÂç½Ó¼û¡£


Ô­ÎÄÁ´½Ó£º

https://www.vmware.com/security/advisories/VMSA-2019-0014.html


6.×êÑÐÍŶӰ䲼Magecart¶ñÒâÓòÃûÐÔÃüÖÜÆÚµÄ·ÖÎö»ã±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝRiskIQµÄÒ»·ÝÐÂ×êÑУ¬·¸×ï·Ö×ÓÔÚ¶þ´ÎÀûÓÃMagecart¶ñÒâÓòÃû½øÐÐÆäËü¶ñÒâ»î¶¯¡£ÔÚMagecartÁ÷Á¿±»sinkhole»òÆäËü·½Ê½ÖÕ³¡»î¶¯ºó£¬·¸×ï·Ö×Ó»á²É°ìÕâЩÓòÃû£¬´Ó¶øÀûÓñ»MagecartÉøÈëµÄÍøÕ¾·Ö·¢¶ñÒâ¸æ°×»ò½øÐÐÆäËü¶ñÒâ»î¶¯¡£ÕâÊÇÓÉÓÚÍøÕ¾ËùÓÐÕßÍùÍùûÓйØ×¢ÆäÍøÕ¾ÉÏÔËÐеÄJavaScript¾ç±¾£¬Êý¾ÝÏÔʾMagecartƲÔüÆ÷ÔÚÍøÕ¾ÉϵľùÔÈÍ£¶Ù¹¦·ò³¬¹ýÁ½¸öÔ£¬²¢ÇÒÓкܶàÏÕЩÊÇÎÞÆÚÏÞµØÍ£¶ÙÔÚÄÇÀï¡£ÕâÖÖ²»Ë½¼ûÐÔÒâζ×ÅÒ»µ©¶ñÒâÓòÃû±»Ôٴ줻¹¥»÷ÕßÄܹ»½øÐÐÆäËü¶ñÒâ»î¶¯À´Í¶»ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.riskiq.com/blog/labs/magecart-reused-domains/