˼¿Æ2020ÄêCISO»ù×¼»ã±¨ £»4G LTEзì϶ÔÊÐí¹¥»÷Õß×¢²á¸¶·ÑµÄ¶©ÔÄ»òÍøÕ¾·þÎñ

°ä²¼¹¦·ò 2020-02-25

1.˼¿Æ°ä²¼2020ÄêCISO»ù×¼»ã±¨£¬½Òʾ½ñÄêÍøÂ簲ȫԸ¾°


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


˼¿ÆµÄ2020ÄêCISO»ù×¼»ã±¨Ô̺¬Á˶԰²È«¸¨µ¼ÕßÓÐЧµÄÈκθߵÍÎÄÐÅÏ¢£¬´ÓÈôºÎÓ°Ïì¶­Ê»ᵽÄÄЩ»ã±¨Ö¸±ê¶ÔÆäÓÐЧ£¬ÔÙµ½Í £»úµÄÔ­ÒòÒÔ¼°ÈôºÎ´¦Öø´ÔÓÐԵȡ£ÎªÁËÔ®ÊÖ°²È«¸¨µ¼ÕßʵÏÖËûÃǶÔ×éÖ¯µÄ½øÕ¹£¬¸Ã»ã±¨Õë¶Ô2020ÄêÌá³öÁË20Ìõ½¨Òé¡£»ã±¨µÄһЩ·¢ÏÖÔ̺¬£ºÔÚÊܰ²È«ÊÂÎñÓ°ÏìµÄÒµÎñÁìÓòÖУ¬Æ·ÅÆÃûÓþÒѳÉΪ½ö´ÎÓÚÔËÓªµÄµÚ¶þ´óÊÜÓ°ÏìÁìÓò £»×ÔÔ¸Åû¶µÄ°²È«ÊÂÎñÒѴﺹÇà×î¸ßÖµ £»ÔÚ°²È«ÐÔºÍÍøÂ磬»ò¶ËµãÖÎÀíºÍ°²È«Ó××éÖ®¼ä½øÐÐÁ˼«¶È/¼«ÆäºÏ×÷µÄÆóҵΥ¹æ³É±¾ÏÔÖø½µµÍ¡£


Ô­ÎÄÁ´½Ó£º

https://blogs.cisco.com/security/a-20-20-vision-for-cybersecurity


2.4G LTEзì϶ÔÊÐí¹¥»÷Õß×¢²á¸¶·ÑµÄ¶©ÔÄ»òÍøÕ¾·þÎñ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


²¨ºè³¶û´óѧµÄÒ»ÏîÐÂ×êÑÐÅú×¢£¬4GÒÆ¶¯Í¨Ñ¶³ß¶ÈÖеÄÒ»¸ö·ì϶¿ÉÄÜʹ¹¥»÷Õß¼ÙðÓû§À´×¢²á¶©ÔÄ»ò¸¶·ÑÍøÕ¾·þÎñ¡£ÕâÏî¹¥»÷¼¼Êõ±»³ÆÎªIMP4GT£¬×êÑÐÈËÔ±³ÆÆäÓ°ÏìÁËËùÓеÄLTEͨѶÉ豸£¬ÕâÔ̺¬¡°ÏÕЩËùÓеġ±ÖÇÄÜÊÖ»ú¡¢Æ½°åµçÄԺͲ¿ÃÅIoTÉ豸¡£IMP4GTµÄ¹Ø¼üÉí·ÖÊÇÀûÓÃÈí¼þ½ç˵µÄÎÞÏßµçÀ´À¹½ØºÍºýÅªÒÆ¶¯É豸Óë»ùÕ¾Ö®¼äµÄͨѶÐÅ·¡£¹ÌÈ»Êý¾Ý°üÔÚÊÖ»úºÍ»ùÕ¾Ö®¼äÒÔ¼ÓÃÜ·½Ê½´«Ê䣬µ«ÓÉÓÚ²»×ãÆëÈ«ÐÔ± £»¤£¬Äܹ»Í¨¹ýÅú¸ÄÊý¾Ý°üÀ´´¥·¢ÃýÎó¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/lte-security-flaw-can-be-abused-to-take-out-subscriptions-at-your-expense/?&web_view=true


3.Foxmail¸ßΣDll½Ù³Ö·ì϶£¬²¹¶¡ÉÐδ°ä²¼


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Foxmail´æÔÚDLL½Ù³Ö·ì϶£¨CNVD-2020-12839£©£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£¸Ã·ì϶µÄ·çÏÕ¼¶±ð±»½ç˵Ϊ¸ß£¬ÊÜÓ°ÏìµÄ°æ±¾ÎªFoxmail 7.2.15.65¡£Ä¿Ç°³§ÉÌÉÐδÌṩ·ì϶½¨¸´¹æ»®£¬½¨ÒéÓû§¹Ø×¢³§É̵ÄÖ÷Ò³¸üв¢ÔÚ²¹¶¡°ä²¼ºóʵʱ¸üС£


Ô­ÎÄÁ´½Ó£º

https://www.cnvd.org.cn/flaw/show/CNVD-2020-12839


4.RallyhoodÔÆÊý¾Ý¿âй¶4.1TBÎļþ£¬Éæ¼°Êý°ÙÍòÓû§


Éç½»ÍøÂçÆ½Ì¨RallyhoodÔÚÒ»¸ö¹«¿ªÂ¶³öµÄAWS´æ´¢Í°Öд洢Á˳¤´ïÊ®ÄêµÄÓû§Îļþ¡£¸Ã´æ´¢Í°ÖÐÔ̺¬µÄÊý¾Ý¿É×·Òäµ½2011Ä꣬¹²ÓÐ4.1TBµÄÎļþ£¬Éæ¼°Êý°ÙÍòÓû§¡£ÕâЩÎļþÖÐÔ̺¬µÄÃô¸ÐÊý¾ÝÔ̺¬¹²ÏíÃÜÂëÁÐ±í¡¢ºÏͬ»òÆäËûÐí¿ÉÇåµ¥ºÍºÍ̸¡¢±£ÃܺÍ̸µÈ¡£RallyhoodÉÐδÔÚÆäÍøÕ¾»òÈκÎÉ罻ýÌåÉϰ䲼ÈκÎÊÂÎñÉêÃ÷¡£


Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2020/02/23/rallyhood-exposed-decade-data/


5.Tetrad¹«Ë¾ÔÆÊý¾Ý¿âй¶1.2ÒÚÃÀ¹úÏû·ÑÕßÊý¾Ý


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


UpGuardÔÚ2ÔÂ3ÈÕ·¢ÏÖÊг¡·ÖÎö¹«Ë¾TetradµÄAmazon S3´æ´¢Í°¿É¹«¿ª½Ó¼û£¬ÆäÖÐÔ̺¬1.2ÒÚÃÀ¹úÏû·ÑÕßµÄÓ×ÎÒÊý¾ÝºÍÐÐΪ·ÖÎö¡£¸Ã´æ´¢¿âÔ̺¬Ô¼747GBÊý¾Ý£¬ÆäÖÐÔ¼ÓÐÒ»°ëÀ´×ÔÓÚ¿Í»§ÆóÒµ£¬Ô̺¬ChipotleÔ±¹¤µÄÒÆ¶¯µç»°Êý¾Ý¡¢70ÍòKate Spade¿Í»§µÄ¼ÒÍ¥µØÖ·¡¢ÒûÁÏÁãÊÛÉÌBevmoµÄ350Íò»áÔ±¿¨ÕÊ»§¼°µØÖ·µÈ¡£¸ÃÊý¾Ý¿â»¹Ô̺¬À´×ÔExperian MosaicÏû·ÑÕßÐÐΪ·ÖÎö²úÆ·µÄ10GBÊý¾Ý£¬ÆäÖÐÔ̺¬1.2ÒÚÏû·ÑÕߵļÒÍ¥µØÖ·¡¢ÐÕÃû¡¢ÐÔ±ðºÍÆäËû¾ßÌåÐÅÏ¢¡£Ä¿Ç°Éв»Ã÷ÏԸô洢ͰµÄ¶³ö¹¦·òÓж೤¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/120-million-us-consumers-exposed/


6.Moxa½¨¸´AWK-3131A¹¤ÒµÍøÂçÉ豸ÖеÄ12¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝMoxaºÍ˼¿ÆTalos°ä²¼µÄ²¼¸æ£¬Moxa AWK-3131A¹¤ÒµAP /ÍøÇÅ/¿Í»§¶ËÉ豸Êܵ½12¸ö·ì϶µÄÓ°Ï죬¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩ·ì϶ÔÚ×éÖ¯µÄ¹¤ÒµÏµÍ³ÖнøÐжñÒâ»î¶¯¡£ËùÓзì϶¶¼±»ÁÐΪ³ÁÒª»ò¸ßÑϳÁÐÔ£¬¹¥»÷ÕßÄܹ»ÀûÓÃËüÃÇÌáȨΪrootÓû§¡¢Ê¹ÓÃÓ²±àÂëµÄ¼ÓÃÜÃÜÔ¿½âÃÜÁ÷Á¿¡¢×¢ÈëºÅÁî²¢Ô¶³Ì½ÚÔìÉ豸¡¢ÔÚÉ豸ÉÏÔËÐÐ×Ô½ç˵Õï¶Ï¾ç±¾¡¢Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë¡¢µ¼Ö»ؾø·þÎñ£¨DoS£©Çé¿ö²¢»ñµÃ¶ÔÉ豸µÄÔ¶³ÌShell½Ó¼û¡£Ö»¹ÜÔÚ´óÎÞÊýÇé¿öÏ·ì϶ÀûÓñØÒªµÍÌØÈ¨µÄÉí·ÝÑéÖ¤£¬µ«²¿ÃÅ·ì϶Äܹ»ÓÉδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÀûÓá£MoxaÔÚ2ÔÂ24ÈÕ°ä²¼ÁËÓйؽ¨¸´²¹¶¡¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/vulnerabilities-moxa-networking-device-expose-industrial-environments-attacks