˼¿Æ2020ÄêCISO»ù×¼»ã±¨£»4G LTEзì϶ÔÊÐí¹¥»÷Õß×¢²á¸¶·ÑµÄ¶©ÔÄ»òÍøÕ¾·þÎñ
°ä²¼¹¦·ò 2020-02-251.˼¿Æ°ä²¼2020ÄêCISO»ù×¼»ã±¨£¬½Òʾ½ñÄêÍøÂ簲ȫԸ¾°
˼¿ÆµÄ2020ÄêCISO»ù×¼»ã±¨Ô̺¬Á˶԰²È«¸¨µ¼ÕßÓÐЧµÄÈκθߵÍÎÄÐÅÏ¢£¬´ÓÈôºÎÓ°Ïì¶Ê»ᵽÄÄЩ»ã±¨Ö¸±ê¶ÔÆäÓÐЧ£¬ÔÙµ½Í£»úµÄÔÒòÒÔ¼°ÈôºÎ´¦Öø´ÔÓÐԵȡ£ÎªÁËÔ®ÊÖ°²È«¸¨µ¼ÕßʵÏÖËûÃǶÔ×éÖ¯µÄ½øÕ¹£¬¸Ã»ã±¨Õë¶Ô2020ÄêÌá³öÁË20Ìõ½¨Òé¡£»ã±¨µÄһЩ·¢ÏÖÔ̺¬£ºÔÚÊܰ²È«ÊÂÎñÓ°ÏìµÄÒµÎñÁìÓòÖУ¬Æ·ÅÆÃûÓþÒѳÉΪ½ö´ÎÓÚÔËÓªµÄµÚ¶þ´óÊÜÓ°ÏìÁìÓò£»×ÔÔ¸Åû¶µÄ°²È«ÊÂÎñÒѴﺹÇà×î¸ßÖµ£»ÔÚ°²È«ÐÔºÍÍøÂ磬»ò¶ËµãÖÎÀíºÍ°²È«Ó××éÖ®¼ä½øÐÐÁ˼«¶È/¼«ÆäºÏ×÷µÄÆóҵΥ¹æ³É±¾ÏÔÖø½µµÍ¡£
ÔÎÄÁ´½Ó£º
https://blogs.cisco.com/security/a-20-20-vision-for-cybersecurity
2.4G LTEзì϶ÔÊÐí¹¥»÷Õß×¢²á¸¶·ÑµÄ¶©ÔÄ»òÍøÕ¾·þÎñ
²¨ºè³¶û´óѧµÄÒ»ÏîÐÂ×êÑÐÅú×¢£¬4GÒÆ¶¯Í¨Ñ¶³ß¶ÈÖеÄÒ»¸ö·ì϶¿ÉÄÜʹ¹¥»÷Õß¼ÙðÓû§À´×¢²á¶©ÔÄ»ò¸¶·ÑÍøÕ¾·þÎñ¡£ÕâÏî¹¥»÷¼¼Êõ±»³ÆÎªIMP4GT£¬×êÑÐÈËÔ±³ÆÆäÓ°ÏìÁËËùÓеÄLTEͨѶÉ豸£¬ÕâÔ̺¬¡°ÏÕЩËùÓеġ±ÖÇÄÜÊÖ»ú¡¢Æ½°åµçÄԺͲ¿ÃÅIoTÉ豸¡£IMP4GTµÄ¹Ø¼üÉí·ÖÊÇÀûÓÃÈí¼þ½ç˵µÄÎÞÏßµçÀ´À¹½ØºÍºýÅªÒÆ¶¯É豸Óë»ùÕ¾Ö®¼äµÄͨѶÐÅ·¡£¹ÌÈ»Êý¾Ý°üÔÚÊÖ»úºÍ»ùÕ¾Ö®¼äÒÔ¼ÓÃÜ·½Ê½´«Ê䣬µ«ÓÉÓÚ²»×ãÆëÈ«ÐÔ±£»¤£¬Äܹ»Í¨¹ýÅú¸ÄÊý¾Ý°üÀ´´¥·¢ÃýÎó¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/lte-security-flaw-can-be-abused-to-take-out-subscriptions-at-your-expense/?&web_view=true
3.Foxmail¸ßΣDll½Ù³Ö·ì϶£¬²¹¶¡ÉÐδ°ä²¼
Foxmail´æÔÚDLL½Ù³Ö·ì϶£¨CNVD-2020-12839£©£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£¸Ã·ì϶µÄ·çÏÕ¼¶±ð±»½ç˵Ϊ¸ß£¬ÊÜÓ°ÏìµÄ°æ±¾ÎªFoxmail 7.2.15.65¡£Ä¿Ç°³§ÉÌÉÐδÌṩ·ì϶½¨¸´¹æ»®£¬½¨ÒéÓû§¹Ø×¢³§É̵ÄÖ÷Ò³¸üв¢ÔÚ²¹¶¡°ä²¼ºóʵʱ¸üС£
ÔÎÄÁ´½Ó£º
https://www.cnvd.org.cn/flaw/show/CNVD-2020-12839
4.RallyhoodÔÆÊý¾Ý¿âй¶4.1TBÎļþ£¬Éæ¼°Êý°ÙÍòÓû§
Éç½»ÍøÂçÆ½Ì¨RallyhoodÔÚÒ»¸ö¹«¿ªÂ¶³öµÄAWS´æ´¢Í°Öд洢Á˳¤´ïÊ®ÄêµÄÓû§Îļþ¡£¸Ã´æ´¢Í°ÖÐÔ̺¬µÄÊý¾Ý¿É×·Òäµ½2011Ä꣬¹²ÓÐ4.1TBµÄÎļþ£¬Éæ¼°Êý°ÙÍòÓû§¡£ÕâЩÎļþÖÐÔ̺¬µÄÃô¸ÐÊý¾ÝÔ̺¬¹²ÏíÃÜÂëÁÐ±í¡¢ºÏͬ»òÆäËûÐí¿ÉÇåµ¥ºÍºÍ̸¡¢±£ÃܺÍ̸µÈ¡£RallyhoodÉÐδÔÚÆäÍøÕ¾»òÈκÎÉ罻ýÌåÉϰ䲼ÈκÎÊÂÎñÉêÃ÷¡£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2020/02/23/rallyhood-exposed-decade-data/
5.Tetrad¹«Ë¾ÔÆÊý¾Ý¿âй¶1.2ÒÚÃÀ¹úÏû·ÑÕßÊý¾Ý
UpGuardÔÚ2ÔÂ3ÈÕ·¢ÏÖÊг¡·ÖÎö¹«Ë¾TetradµÄAmazon S3´æ´¢Í°¿É¹«¿ª½Ó¼û£¬ÆäÖÐÔ̺¬1.2ÒÚÃÀ¹úÏû·ÑÕßµÄÓ×ÎÒÊý¾ÝºÍÐÐΪ·ÖÎö¡£¸Ã´æ´¢¿âÔ̺¬Ô¼747GBÊý¾Ý£¬ÆäÖÐÔ¼ÓÐÒ»°ëÀ´×ÔÓÚ¿Í»§ÆóÒµ£¬Ô̺¬ChipotleÔ±¹¤µÄÒÆ¶¯µç»°Êý¾Ý¡¢70ÍòKate Spade¿Í»§µÄ¼ÒÍ¥µØÖ·¡¢ÒûÁÏÁãÊÛÉÌBevmoµÄ350Íò»áÔ±¿¨ÕÊ»§¼°µØÖ·µÈ¡£¸ÃÊý¾Ý¿â»¹Ô̺¬À´×ÔExperian MosaicÏû·ÑÕßÐÐΪ·ÖÎö²úÆ·µÄ10GBÊý¾Ý£¬ÆäÖÐÔ̺¬1.2ÒÚÏû·ÑÕߵļÒÍ¥µØÖ·¡¢ÐÕÃû¡¢ÐÔ±ðºÍÆäËû¾ßÌåÐÅÏ¢¡£Ä¿Ç°Éв»Ã÷ÏԸô洢ͰµÄ¶³ö¹¦·òÓж೤¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/120-million-us-consumers-exposed/
6.Moxa½¨¸´AWK-3131A¹¤ÒµÍøÂçÉ豸ÖеÄ12¸ö·ì϶
ƾ¾ÝMoxaºÍ˼¿ÆTalos°ä²¼µÄ²¼¸æ£¬Moxa AWK-3131A¹¤ÒµAP /ÍøÇÅ/¿Í»§¶ËÉ豸Êܵ½12¸ö·ì϶µÄÓ°Ï죬¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩ·ì϶ÔÚ×éÖ¯µÄ¹¤ÒµÏµÍ³ÖнøÐжñÒâ»î¶¯¡£ËùÓзì϶¶¼±»ÁÐΪ³ÁÒª»ò¸ßÑϳÁÐÔ£¬¹¥»÷ÕßÄܹ»ÀûÓÃËüÃÇÌáȨΪrootÓû§¡¢Ê¹ÓÃÓ²±àÂëµÄ¼ÓÃÜÃÜÔ¿½âÃÜÁ÷Á¿¡¢×¢ÈëºÅÁî²¢Ô¶³Ì½ÚÔìÉ豸¡¢ÔÚÉ豸ÉÏÔËÐÐ×Ô½ç˵Õï¶Ï¾ç±¾¡¢Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë¡¢µ¼Ö»ؾø·þÎñ£¨DoS£©Çé¿ö²¢»ñµÃ¶ÔÉ豸µÄÔ¶³ÌShell½Ó¼û¡£Ö»¹ÜÔÚ´óÎÞÊýÇé¿öÏ·ì϶ÀûÓñØÒªµÍÌØÈ¨µÄÉí·ÝÑéÖ¤£¬µ«²¿ÃÅ·ì϶Äܹ»ÓÉδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÀûÓá£MoxaÔÚ2ÔÂ24ÈÕ°ä²¼ÁËÓйؽ¨¸´²¹¶¡¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/vulnerabilities-moxa-networking-device-expose-industrial-environments-attacks


¾©¹«Íø°²±¸11010802024551ºÅ