ÂùÝÖÎÀí¹«Ë¾AavGoÒâÍâй¶800Íò¿Í»§ÐÅÏ¢ £»£»£» £»£»Î¢ÈíÐÞ¸´PowerShell½¹µãÖеÄWDACÈÆ¹ýÎó²î

Ðû²¼Ê±¼ä 2019-07-18

1¡¢ÂùÝÖÎÀí¹«Ë¾AavGoÒâÍâй¶800Íò¿Í»§ÐÅÏ¢


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


WizcaseÇå¾²Ñо¿Ô±Daniel Brown·¢Ã÷ÂùÝÖÎÀíÉÌAavGoµÄÒ»¸öElasticsearchÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨800ÍòÌõ¿Í»§ÐÅÏ¢£¬£¬£¬£¬£¬£¬°üÀ¨Ô¤¶©ÐÅÏ¢¡¢¿Í»§Í¶Ëß¡¢·¢Æ±¡¢¹¤µ¥¡¢Ô±¹¤±¸Íü¼ºÍÐÂÎÅ¡¢Âùݷ¿¼äͼƬ¡¢ÎïÆ·Ëð»µÍ¼Æ¬ÒÔ¼°¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢£¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢ÓÊÏ䵨µã¡¢×¡Ö·¡¢»éÒö״̬¡¢µÇ¼ÐÅÏ¢ºÍ¸¶¿î·½·¨£©¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý»¹°üÀ¨ÂùÝÖÎÀíÔ±µÄÏêϸµÇ¼ÐÅÏ¢£¬£¬£¬£¬£¬£¬ÀýÈçÖÎÀíÃæ°å¡¢Ô¤¶©ÏµÍ³ºÍÄÚ²¿Êý¾Ý¿âµÄÓû§ÃûºÍÃÜÂë¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÂùݰüÀ¨The Row Hotel¡¢Stay Cal HotelsµÈÊ®¶à¼ÒÂùݡ£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÒÑÔÚ7ÔÂ16ÈÕ¶ÔÊý¾Ý¿â½ÓÄÉÁ˱ £»£»£» £»£»¤²½·¥¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/unprotected-elasticsearch-database-belonging-to-aavgo-exposed-8-million-records-of-guest-details-f5fb1eac


2¡¢CPL³Æ220Íò»¼ÕßÐÅÏ¢ÊÜAMCAÊý¾Ýй¶ÊÂÎñÓ°Ïì


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÁÙ´²²¡ÀíѧʵÑéÊÒ£¨CPL£©³ÉΪAMCAÊý¾Ýй¶ÊÂÎñµÄ×îÐÂÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£AMCAÒÑÏò3.45ÍòCPL»¼Õß·¢ËÍÁËÊý¾Ýй¶֪ͨ£¬£¬£¬£¬£¬£¬Æ¾Ö¤AMCAÌṩµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬CPLÔ¤¼ÆÉÐÓÐ220Íò»¼ÕßÊܵ½´ËÊÂÎñµÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨CPL»¼ÕßµÄÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¡¢³öÉúÈÕÆÚ¡¢Ð§ÀÍÈÕÆÚ¡¢Óà¶î¡¢ÐÅÓÿ¨ÐÅÏ¢ºÍÒ½ÉúÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£AMCAÈ·ÈÏ»¼ÕßµÄÉç»áÇå¾²ºÅÂëδÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/clinical-pathology-laboratories-notifies-patients-of-security-incident-caused-by-amca-data-breach-37f8382c


3¡¢Sprint³ÆºÚ¿Íͨ¹ýÈýÐÇÍøÕ¾ÈëÇÖÆä¿Í»§ÕË»§


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÃÀ¹úµçÐŹ«Ë¾SprintÌåÏÖºÚ¿ÍÏ뷨ʹÓÃÈýÐÇÍøÕ¾Samsung.comÉϵÄаìºÅÂë¡°Add a line¡±Ò³Ãæ×÷Ϊ¹¥»÷Ìø°å£¬£¬£¬£¬£¬£¬ÈëÇÖÆä¿Í»§ÕË»§¡£¡£¡£¡£¡£¡£¡£ÔÚ·¢¸ø¿Í»§µÄ֪ͨº¯ÖÐSprintÌåÏÖ¹²±¬·¢ÁËÁ½ÆðÎ¥¹æÐÐΪ£¬£¬£¬£¬£¬£¬Ò»Æð±¬·¢ÔÚ6ÔÂ8ÈÕ£¬£¬£¬£¬£¬£¬ÁíÒ»Æð±¬·¢ÔÚ6ÔÂ22ÈÕ¡£¡£¡£¡£¡£¡£¡£ºÚ¿Í¿ÉÒÔ»á¼ûµÄ¿Í»§ÐÅÏ¢°üÀ¨Óû§ID¡¢Õʺš¢ÕÊ»§½¨ÉèÈÕÆÚ¡¢ÐÕÃû¡¢Õʵ¥µØµã¡¢µç»°ºÅÂë¡¢×°±¸ÀàÐÍ¡¢×°±¸ID¡¢Ã¿ÔÂÓöȵȡ£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/sprint-accounts-breached-by-hackers-using-samsung-site/


4¡¢Î¢ÈíÐÞ¸´PowerShell½¹µãÖеÄWDACÈÆ¹ýÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


΢ÈíÐû²¼Ð°汾PowerShell Core£¬£¬£¬£¬£¬£¬ÐÞ¸´Ò»¸ö¿ÉÔÊÐíÍâµØ¹¥»÷ÕßÈÆ¹ýWindows DefenderÓ¦ÓóÌÐò¿ØÖÆ£¨WDAC£©µÄÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²î±»±ê¼ÇΪCVE-2019-1167¡£¡£¡£¡£¡£¡£¡£ÔÚÆôÓÃWDACʱ£¬£¬£¬£¬£¬£¬PowerShell½«×Ô¶¯½øÈëÔ¼ÊøÓïÑÔģʽÒÔÏÞÖÆ¶ÔijЩWindows APIµÄ»á¼û£¬£¬£¬£¬£¬£¬µ«¸ÃÎó²î¿ÉÈÆ¹ýPowerShellÔ¼ÊøÓïÑÔģʽºÍWDAC¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁË6.1.5֮ǰµÄËùÓÐPowerShell Core 6.0¡¢6.1°æ±¾ºÍ6.2.2֮ǰµÄPowerShell Core 6.2°æ±¾£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/microsoft/microsoft-patches-powershell-core-security-bug-to-fix-wdac-bypass/


5¡¢LenovoEMC/Iomega NAS±»ÆØ±£´æÐÅϢй¶Îó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Ñо¿Ö°Ô±ÖÒÑԳƣ¬£¬£¬£¬£¬£¬LenovoEMC/IomegaÆ·ÅÆµÄNAS×°±¸Öб£´æÐÅϢй¶Îó²î£¬£¬£¬£¬£¬£¬µ¼Ö´ó×ÚÃô¸ÐÊý¾ÝÔÚ¹«ÍøÉÏ̻¶¡£¡£¡£¡£¡£¡£¡£LenovoEMCºÍIomegaµÄNAS²úÆ·Ö÷ÒªÃæÁÙÖÐСÐÍÆóÒµ¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-6160£©Ô´ÓÚδÊܱ £»£»£» £»£»¤µÄAPIŲÓ㬣¬£¬£¬£¬£¬ÈκÎÈ˶¼¿ÉÒÔͨ¹ýShodan²éÕÒÒ×Êܹ¥»÷µÄNAS×°±¸£¬£¬£¬£¬£¬£¬È»ºóͨ¹ý·¢ËͶñÒâÇëÇóÏÂÔØÉè±¹ØÁ¬ÄÎļþ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚshodanÉÏ·¢Ã÷ÁË̻¶ÔÚ¹«ÍøµÄ36TBÊý¾Ý£¬£¬£¬£¬£¬£¬Éæ¼°5114¸ö×°±¸¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÏÖÔÚ»¹Ã»ÓÐÐû²¼ÏêϸµÄÐÞ¸´Ê±¼ä¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.helpnetsecurity.com/2019/07/17/lenovoemc-nas-devices-flaw/


6¡¢Drupal CMSÐÞ¸´¿Éµ¼ÖÂÍøÕ¾±»½ÓÊܵÄÑÏÖØÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Drupal CMS¿ª·¢ÍŶÓÐû²¼8.7.5°æ±¾£¬£¬£¬£¬£¬£¬ÐÞ¸´»á¼ûÈÆ¹ýÎó²î£¨CVE-2019-6342£©¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËDrupal 8.7.4 ¡¢8.7.3¼°¸üÔç°æ±¾¡¢8.6.x¼°¸üÔç°æ±¾£¬£¬£¬£¬£¬£¬¶øDrupal 7.x²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÉÐÎÞ¿ÉÓõÄexp£¬£¬£¬£¬£¬£¬ÃÀ¹úCISAÒ²·¢³öÖÒÑÔ£¬£¬£¬£¬£¬£¬±Þ²ßDrupalÖÎÀíÔ±ºÍÓû§Éý¼¶µ½Drupal 8.7.5°æ±¾¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Drupal CoreʹÓÃÇéÐÎͳ¼ÆÊý¾Ý£¬£¬£¬£¬£¬£¬¹²ÓÐÔ¼29Íò¸öÍøÕ¾ÕýÔÚʹÓÃDrupal 8.x¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/drupal-patches-critical-bug-that-lets-hackers-take-over-sites/