WSpot¹«Ë¾ÒòAWS´æ´¢Í°ÅäÖÃÃýÎóй¶250ÍòÓû§ÐÅÏ¢

°ä²¼¹¦·ò 2021-11-26

CloudLinux½¨¸´Imunify360ÖеÄPHP·´ÐòÁл¯·ì϶


CloudLinux½¨¸´Imunify360ÖеÄPHP·´ÐòÁл¯·ì϶.png


Cisco TaloÔÚ11ÔÂ22ÈÕÅû¶ÁËCloudLinuxµÄ²úÆ·Imunify360ÖеÄPHP·´ÐòÁл¯·ì϶¡£¸Ã²úÆ·ÊÇ»ùÓÚLinuxµÄWeb·þÎñÆ÷µÄ°²È«Æ½Ì¨£¬Óû§¿ÉÀûÓÃÆäͨ¹ý¸÷ÀàÅäÖÃÀ´ÊµÊ±± £»¤ÍøÕ¾ºÍWeb·þÎñÆ÷µÄ°²È«¡£¸Ã·ì϶(CVE-2021-21956)CVSSÆÀ·ÖΪ8.2£¬´æÔÚÓÚAi-BolitÖ°ÄÜÖУ¬¹¥»÷ÕßÄܹ»Í¨¹ý¸Ã·ì϶ÔÚÖ¸±êϵͳÖÐÖ´ÐÐËÁÒâ´úÂ룬»òÆëÈ«½ÚÔì·þÎñÆ÷¡£Ä¿Ç°£¬CloudLinuxÒѽ¨¸´¸Ã·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/11/vulnerability-spotlight-php-deserialize.html


Vestas¹«Ë¾ÒÉËÆÔâµ½ÀÕË÷¹¥»÷µ¼Ö²¿ÃÅÒµÎñÁÙʱÖжÏ


Vestas¹«Ë¾ÒÉËÆÔâµ½ÀÕË÷¹¥»÷µ¼Ö²¿ÃÅÒµÎñÁÙʱÖжÏ.png


È«Çò×î´óµÄ·çÁ¦ÎÐÂÖ»úÔì×÷ÉÌVestasÔÚÉÏÖÜÁù°ä²¼¹«¸æ£¬³ÆÆäÔâµ½ÍøÂç¹¥»÷¡£¹¥»÷²úÉúÔÚ11ÔÂ19ÈÕ£¬Æä¶à¸öÒµÎñ²¿ÃŵÄITϵͳ±»ÆÈ¹Ø¹Ø£¬Ó°ÏìÁËÆä¿Í»§¡¢Ô±¹¤ºÍÆäËûÀûÒæÓйØÕß¡£11ÔÂ22ÈÕ£¬¸Ã¹«Ë¾ÓÖ°ä²¼¹«¸æ³Æ³õ´ëÊ©²éÁ˾ÖÏÔʾ£¬²¿ÃÅÊý¾ÝÒѱ»Ð¹Â¶¡£¹ÌÈ»VestasûÓÐй©ËûÃÇÔâµ½¹¥»÷µÄÀàÐÍ£¬µ«Í¨¹ýÆäÃèÊö·ÖÎöËÆºõÊÇÀÕË÷¹¥»÷¡£Õâ¼Òµ¤Âó¹«Ë¾ÔÚ2020ÄêµÄÊÕÈë¿¿½ü150ÒÚÅ·Ôª£¬Ê¹Æä³ÉΪÓÐÀû¿ÉͼµÄÖ¸±ê¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/wind-turbine-giant-offline-after/


Hooshyarane VatanÐû³Æ¶ÔÂíººº½¿Õ¹«Ë¾µÄ¹¥»÷ÕÆ¹Ü


Hooshyarane VatanÐû³Æ¶ÔÂíººº½¿Õ¹«Ë¾µÄ¹¥»÷ÕÆ¹Ü.png


ºÚ¿ÍÍÅ»ïÔÚ11ÔÂ21ÈÕ·¢ÎÄ³ÆÆäÒѳɹ¦¹¥»÷Mahan Air£¬²¢ÒÑÇÔÈ¡¸Ã¹«Ë¾ÓëIRGCÓйصÄÄÚ²¿Îļþ¡¢µç×ÓÓʼþºÍ»ã±¨¡£Mahan AirÊÇÒÁÀÊ×î´óµÄ˽Ӫº½¿Õ¹«Ë¾£¬Æä°µÊ¾ÔÚÖÜÄ©Ôâµ½¹¥»÷£¬ËùÓйú¼ÊºÍ¹úÄÚº½°àûÓÐÊܵ½ÈκÎÓ°Ï죬ÒÀÈ»ÕÕ³£ÔËÐУ¬µ«Óû§ÎÞ·¨½Ó¼ûMahanµÄÍøÕ¾¡£¸Ã¹«Ë¾»¹°µÊ¾ÓÉÓÚÆäÔÚÒÁÀʺ½¿ÕÒµµÄְλµ¼ÖÂÆäÔâµ½ÂŴι¥»÷£¬ÕâÊôÓÚÕý³£¾°Ï󣬲¢ÇÒËûÃÇÒѾ­Ôڶ̹¦·òÄڳɹ¦×èÖ¹ÁËÕâ´Î¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/124880/hacking/mahan-air-cyberattack.html


WSpot¹«Ë¾ÒòAWS´æ´¢Í°ÅäÖÃÃýÎóй¶250ÍòÓû§ÐÅÏ¢


WSpot¹«Ë¾ÒòAWS´æ´¢Í°ÅäÖÃÃýÎóй¶250ÍòÓû§ÐÅÏ¢.png


°²È«¹«Ë¾SafetyDetectives·¢ÏÖ°ÍÎ÷Èí¼þ¹«Ë¾WSpotÒÑй¶³¬¹ý250ÍòÓû§µÄÐÅÏ¢¡£WSpotµÄ²úÆ·¿ÉÓÃÓÚÆóÒµ± £»¤ÆäÄÚ²¿µÄWiFiÍøÂ磬²¢ÌṩÎÞÃÜÂëµÄÔÚÏß½Ó¼û£¬¸Ã¹«Ë¾µÄ¿Í»§Ô̺¬Sicredi¡¢±ØÊ¤¿ÍºÍUnimedµÈ¡£×êÑÐÈËÔ±ÓÚ9ÔÂ2ÈÕ·¢ÏÖWSpotÅäÖÃÃýÎóµÄAmazon Web Services S3´æ´¢Í°Ð¹Â¶ÁË10 GBµÄÊý¾Ý£¬²¢ÓÚ9ÔÂ7ÈÕ֪ͨWSpot¡£WSpot°µÊ¾´ËÊÂÎñÓ°ÏìÁËÆä5%µÄ¿Í»§Èº£¬ÒÑÔÚ11ÔÂ18ÈÕ½¨¸´ÊµÏÖ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/wifi-software-firm-exposed-users-data/


NCSC·¢ÏÖ4000¶à¸öÔÚÏßÉ̵êÈÝÒ×Ôâµ½Magecart¹¥»÷


NCSC·¢ÏÖ4000¶à¸öÔÚÏßÉ̵êÈÝÒ×Ôâµ½Magecart¹¥»÷.png


Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ(NCSC)11ÔÂ22ÈÕ°ä²¼°²È«×ÊѶ£¬³Æ4151¸öÔÚÏßÉ̵êÈÝÒ×Ôâµ½Magecart¹¥»÷¡£Magecart¹¥»÷Ö¼ÔÚÇÔȡ֧¸¶ÐÅÏ¢£¬Í¨¹ýÏòÔÚÏßÉ̵ê×¢Èë½ÅÕý±¾ÍøÂçÓû§ÔÚ½áÕËÒ³ÃæÌá½»µÄÓ×ÎÒÐÅÏ¢¡£NCSC³ÆËûÃÇ×Ô2020Äê4ÔÂÆðÍ·¼à¿ØÕâЩÉ̵꣬·¢ÏÖ´óÎÞÊýÉ̵궼ÊÜMagentoƽ̨ÖеÄÒ»¸ö·ì϶µÄÓ°Ïì¡£´Ë±í£¬¸Ã×ÊѶÓ×ÎҺͼÒÍ¥ÈôºÎ°²È«µØÔÚÏß¹ºÎïÌṩÁ˽¨ÒéºÍÌṩÁìµ¼¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/uk-govt-warns-thousands-of-smbs-their-online-stores-were-hacked/


Kaspersky°ä²¼2021ÄêºÚÎåÆÚ¼äÚ¿Æ­»î¶¯µÄ·ÖÎö»ã±¨


Kaspersky°ä²¼2021ÄêºÚÎåÆÚ¼äÚ¿Æ­»î¶¯µÄ·ÖÎö»ã±¨.png


11ÔÂ22ÈÕ£¬Kaspersky°ä²¼2021ÄêºÚÎåÆÚ¼äÚ¿Æ­»î¶¯µÄ·ÖÎö»ã±¨¡£»ã±¨ÖØÒª·ÖÎöÁËÓëÈ«Çò½Ó¼ûÁ¿×î´óµÄÎå¸öÁãÊÛÆ½Ì¨£ºÎÖ¶ûÂê¡¢eBay¡¢ÑÇÂíÑ·¡¢°¢Àï°Í°ÍºÍ Mercado Libre¡£×êÑз¢ÏÖ£¬2021Äêǰ10¸öÔ¼ì²âµ½40584415ÆðÕë¶ÔµçÉÌÆ½Ì¨ÒÔ¼°ÒøÐлú¹¹µÄ´¹µö¹¥»÷ £»Õë¶Ôµç×ÓÖ§¸¶ÏµÍ³µÄ´¹µö»î¶¯Ôö³¤ÁË208% £»10ÔÂ27ÈÕÖÁ11ÔÂ19ÈÕ·¢ÏÖÁË221745·âÓëºÚÎåÓйصÄÓʼþ¡£»ã±¨Ö¸³ö£¬ÐþÉ«ÐÇÆÚÎå²»½ö¶Ô¹ºÎïÕßÀ´ËµÊdzÁÒªµÄÒ»Ì죬¶Ô¹¥»÷ÕßÀ´ËµÒ²ÊÇÈç´Ë¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/black-friday-2021/104915/