±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2019Äê7ÔÂ15ÈÕÖÁ21ÈÕ¹²ÊÕ¼°²È«·ì϶50¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇNGINX njs nxt_vsprintf»º³åÇøÒç¶Âí½Å£»SolarWinds Orion Network Performance MonitorÔ¶³Ì´úÂëÖ´Ðзì϶£»CentOS Web PanelδÊÚȨ½Ó¼û·ì϶£»Palo Alto Networks PAN-OS CVE-2019-1576ºÅÁî×¢Èë·ì϶£»Linaro OP-TEE optee_os»º³åÇøÒç¶Âí½Å¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǹ㲥µç̨KHSUÒòÀÕË÷Èí¼þ¹¥»÷µ¼Ö½ÚÄ¿Öжϣ»Evite½ü1.01ÒÚÕË»§ÐÅϢй¶£¬Òѱ»HIBPÊÕ¼£»±£¼ÓÀûÑǹú¶È˰Îñ¾ÖÔâºÚ¿ÍÈëÇÖ£¬500¶àÍò¹«ÃñÐÅÏ¢±»µÁ£»¾ÆµêÖÎÀí¹«Ë¾AavGoÒâ±íй¶800Íò¿Í»§ÐÅÏ¢£»¹þÈø¿Ë˹̹µ±¾ÖÀ¹½Ø¾³ÄÚËùÓеÄHTTPSÁ÷Á¿¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
³ÁÒª°²È«·ì϶Áбí
1. NGINX njs nxt_vsprintf»º³åÇøÒç¶Âí½Å
NGINX njs nxt/nxt_sprintf.cÎļþµÄnxt_vsprintf´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://github.com/torvalds/linux/commit/6994eefb0053799d2e07cd140df6c2ea106c41ee
2. SolarWinds Orion Network Performance MonitorÔ¶³Ì´úÂëÖ´Ðзì϶
SolarWinds Orion Network Performance Monitor OrionModuleEngine·þÎñ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»SYSTEMÓû§Ö´ÐÐËÁÒâ´úÂë¡£
http://www.securityfocus.com/bid/107061
3. CentOS Web PanelδÊÚȨ½Ó¼û·ì϶
CentOS Web Panel´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÆäËûÓû§ÃûÈÆ¹ýÑé֤δÊÚȨ½Ó¼û¡£
https://github.com/i3umi3iei3ii/CentOS-Control-Web-Panel-CVE/blob/master/CVE-2019-13360.md
4. Palo Alto Networks PAN-OS CVE-2019-1576ºÅÁî×¢Èë·ì϶
Palo Alto Networks PAN-OS´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâOSºÅÁî¡£
https://securityadvisories.paloaltonetworks.com/Home/Detail/156
5. Linaro OP-TEE optee_os»º³åÇøÒç¶Âí½Å
Linaro OP-TEE optee_os´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://github.com/OP-TEE/optee_os/commit/70697bf3c5dc3d201341b01a1a8e5bc6d2fb48f8
³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢¹ã²¥µç̨KHSUÒòÀÕË÷Èí¼þ¹¥»÷µ¼Ö½ÚÄ¿ÖжÏ
ÃÀ¹ú¼ÓÖݺ鱤ÖÝÁ¢´óѧռÓеÄKHSU¹ã²¥µç̨Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µ¼Ö¸õç̨µÄËùÓÐϵͳºÍ´æ´¢·þÎñÆ÷̱»¾£¬½ÚÄ¿±»ÆÈÖжϡ£µ«KHSUÈ·ÈϳÆÊÜϰȾµÄ·þÎñÆ÷²¢Î´Ô̺¬ÈκÎÃô¸ÐÐÅÏ¢¡£KHSUÔÚ7ÔÂ1ÈÕ·¢ÏÖÕâ´Î¹¥»÷£¬¹¥»÷ÕßÀûÓÃÁËKHSUϵͳÖеݲȫ·ì϶¡£KHSU°µÊ¾Ã»ÓÐÊÕµ½Êê½ðÒªÇó£¬Ò²²»ÖªÂ·¹¥»÷µÄÆðÔ´¡£ÔÚ·¢ÏÖÊÂÎñºó£¬KHSUÏòÁª¹ú·¨Âɲ¿ÃźÍÁª¹úͨѶίԱ»á»ã±¨ÁËÕâÒ»ÊÂÎñ¡£
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/khsu-radio-stations-regular-programming-interrupted-due-to-ransomware-attack-e39dbd3d
2¡¢Evite½ü1.01ÒÚÕË»§ÐÅϢй¶£¬Òѱ»HIBPÊÕ¼
2019Äê5ÔÂEvite°ä²¼Êý¾Ýй¶֪ͨ£¬°µÊ¾Æä·þÎñÆ÷´Ó2ÔÂ22ÈÕ·¢ÏÖδÊÚȨ½Ó¼û£¬Ô¼1000ÍòÓû§ÐÅϢй¶¡£µ«Æ¾¾ÝHave I Been PwnedÍøÕ¾ÊÕ¼µÄÊý¾Ý¿â£¬ÕâÒ»Êý×ÖÒª´óµÃ¶à£¬¹²Óнü1.01ÒÚÓû§ÐÅÏ¢±»µÁ¡£ÕâЩÊý¾Ý×îÔç¿É×·ÒäÖÁ2013Ä꣬й¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µç»°ºÅÂë¡¢ÏÖʵµØÖ·¡¢µ®ÉúÈÕÆÚ¡¢ÐÔ±ð¡¢Ã÷ÎÄÃÜÂëºÍµç×ÓÓʼþµØÖ·¡£×î³õ±»Ð¹Â¶µÄÊý¾Ý¿âÔÚDream MarketÉÏÏúÊÛ£¬µ«¸ÃÍøÕ¾Òѱ»¾¯·½¹Ø¹Ø£¬Òò¶øÄ¿Ç°Éв»Ã÷ÏÔÕâ¸ö¸ü´óµÄÊý¾Ý¿âÊÇ·ñÒ²ÔÚÏúÊÛ¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/evite-invites-over-100-million-people-to-their-data-breach/
3¡¢±£¼ÓÀûÑǹú¶È˰Îñ¾ÖÔâºÚ¿ÍÈëÇÖ£¬500¶àÍò¹«ÃñÐÅÏ¢±»µÁ
¾Ýzdnet±¨Â·£¬Ò»ºÚ¿Í×éÖ¯´Ó±£¼ÓÀûÑǹú¶È˰Îñ¾Ö£¨NRA£©ÖÐÇÔÈ¡ÁËÔ¼110¸öÊý¾Ý¿â£¬ÆäÖÐÔ̺¬½ü21GBµÄÓ×ÎÒÊý¾Ý£¬ÊÜÓ°ÏìÈËÊý³¬¹ý500Íò¡£ºÚ¿Í½«²¿Ãű»µÁÊý¾Ýͨ¹ýµç×ÓÓʼþ·¢Ë͸ø±¾µØÃ½Ì壬µ¼ÖÂÊÂÎñÆØ¹â¡£¸Ã¹úÓйز¿ÃÅÒѾÈÏ¿ÉÕâÒ»ÊÂÎñ£¬²¢ÕýÓë±£¼ÓÀûÑǹú¶È°²È«¾ÖºÏ×÷µ÷²é¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬±£¼ÓÀûÑǹ«ÃñµÄÓ×ÎÒ¼ø±ðÂ루PIN£©¡¢ÐÕÃû¡¢¼ÒͥסַºÍ²ÆÕþÊÕÈ룬ÕâЩÊý¾Ý×îÔç¿É×·Òäµ½2007Äê¡£
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/bulgarias-national-revenue-agency-hacked-to-steal-over-five-million-peoples-data-8e64c8d9
4¡¢¾ÆµêÖÎÀí¹«Ë¾AavGoÒâ±íй¶800Íò¿Í»§ÐÅÏ¢
Wizcase°²È«×êÑÐÔ±Daniel Brown·¢Ï־ƵêÖÎÀíÉÌAavGoµÄÒ»¸öElasticsearchÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬¸ÃÊý¾Ý¿âÔ̺¬800ÍòÌõ¿Í»§ÐÅÏ¢£¬Ô̺¬Ô¤Ô¼ÐÅÏ¢¡¢¿Í»§Í¶Ëß¡¢·¢Æ±¡¢¹¤µ¥¡¢Ô±¹¤±¸Íü¼ºÍÐÂÎÅ¡¢¾Æµê·¿¼äͼƬ¡¢ÎïÆ·°Ü»µÍ¼Æ¬ÒÔ¼°¿Í»§µÄÓ×ÎÒÐÅÏ¢£¨ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢ÓÊÏ䵨ַ¡¢×¡Ö·¡¢»éÒöÇé¿ö¡¢µÇ¼ÐÅÏ¢ºÍ¸¶¿î·½Ê½£©¡£Ð¹Â¶µÄÊý¾Ý»¹Ô̺¬¾ÆµêÖÎÀíÔ±µÄ¾ßÌåµÇ¼ÐÅÏ¢£¬ÀýÈçÖÎÀíÃæ°å¡¢Ô¤Ô¼ÏµÍ³ºÍÄÚ²¿Êý¾Ý¿âµÄÓû§ÃûºÍÃÜÂë¡£ÊÜÓ°ÏìµÄ¾ÆµêÔ̺¬The Row Hotel¡¢Stay Cal HotelsµÈÊ®¶à¼Ò¾Æµê¡£¸Ã¹«Ë¾ÒÑÔÚ7ÔÂ16ÈÕ¶ÔÊý¾Ý¿â²ÉÈ¡Á˱£»¤´ëÊ©¡£
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/unprotected-elasticsearch-database-belonging-to-aavgo-exposed-8-million-records-of-guest-details-f5fb1eac
5¡¢¹þÈø¿Ë˹̹µ±¾ÖÀ¹½Ø¾³ÄÚËùÓеÄHTTPSÁ÷Á¿
¹þÈø¿Ë˹̹µ±¾ÖÒÑ´Ó7ÔÂ17ÈÕÆðÍ·À¹½ØÆä¾³ÄÚµÄËùÓÐHTTPSÁ÷Á¿¡£ÔÚ±¾µØµ±¾ÖµÄÅúʾÏ£¬±¾µØISPÇ¿ÔìÓû§ÔÚÿ¸öÉ豸ºÍä¯ÀÀÆ÷ÖÐ×°Öõ±¾ÖÐû¸æµÄÖ¤Êé¡£¸ÃÖ¤Ê齫ÔÊÐíµ±¾Ö»ú¹¹½âÃÜÓû§µÄHTTPSÁ÷Á¿²¢²é¿´ÆäÄÚÈÝ¡£ÔÚÓû§×°ÖøÃÖ¤Êé֮ǰ£¬ËûÃǽ«ÎÞ·¨½Ó¼û»¥ÁªÍø¡£µ±¾Ö¹ÙÔ±°µÊ¾´Ë¾ÙÖ¼ÔÚ¼ÓÇ¿¶Ô¹«Ãñ¡¢µ±¾Ö»ú¹¹ºÍ˽ӪÆóÒµµÄ±£»¤£¬Ê¹ÆäÃâÔâºÚ¿Í¹¥»÷¡¢»¥ÁªÍøÚ²ÆµÈÍøÂçÍþв¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/kazakhstan-government-is-now-intercepting-all-https-traffic/