˼¿Æ2020ÄêCISO»ù×¼±¨¸æ£»£»£»£»£»£»£»4G LTEÐÂÎó²îÔÊÐí¹¥»÷Õß×¢²á¸¶·ÑµÄ¶©ÔÄ»òÍøÕ¾Ð§ÀÍ
Ðû²¼Ê±¼ä 2020-02-251.˼¿ÆÐû²¼2020ÄêCISO»ù×¼±¨¸æ£¬£¬£¬Õ¹ÏÖ½ñÄêÍøÂçÇå¾²Ô¸¾°
˼¿ÆµÄ2020ÄêCISO»ù×¼±¨¸æ°üÀ¨Á˶ÔÇå¾²Ïòµ¼ÕßÓÐÓõÄÈκÎÉÏÏÂÎÄÐÅÏ¢£¬£¬£¬´ÓÔõÑùÓ°Ïì¶Ê»ᵽÄÄЩ±¨¸æÖ¸±ê¶ÔÆäÓÐÓ㬣¬£¬ÔÙµ½Í£»£»£»£»£»£»£»úµÄÔµ¹ÊÔÓÉÒÔ¼°ÈçÄÇÀïÖÃÖØ´óÐԵȡ£¡£¡£¡£¡£¡£¡£¡£ÎªÁË×ÊÖúÇå¾²Ïòµ¼ÕßʵÏÖËûÃǶÔ×éÖ¯µÄÆÚÍû£¬£¬£¬¸Ã±¨¸æÕë¶Ô2020ÄêÌá³öÁË20Ìõ½¨Òé¡£¡£¡£¡£¡£¡£¡£¡£±¨¸æµÄһЩ·¢Ã÷°üÀ¨£ºÔÚÊÜÇå¾²ÊÂÎñÓ°ÏìµÄÓªÒµÁìÓòÖУ¬£¬£¬Æ·ÅÆÉùÓþÒѳÉΪ½ö´ÎÓÚÔËÓªµÄµÚ¶þ´óÊÜÓ°ÏìÁìÓò£»£»£»£»£»£»£»×ÔÔ¸Åû¶µÄÇå¾²ÊÂÎñÒÑ´ïÀúÊ·×î¸ßÖµ£»£»£»£»£»£»£»ÔÚÇå¾²ÐÔºÍÍøÂ磬£¬£¬»ò¶ËµãÖÎÀíºÍÇ徲С×éÖ®¼ä¾ÙÐÐÁ˺ÜÊÇ/¼«ÆäÐ×÷µÄÆóҵΥ¹æ±¾Ç®ÏÔÖø½µµÍ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blogs.cisco.com/security/a-20-20-vision-for-cybersecurity
2.4G LTEÐÂÎó²îÔÊÐí¹¥»÷Õß×¢²á¸¶·ÑµÄ¶©ÔÄ»òÍøÕ¾Ð§ÀÍ
²¨ºè³¶û´óѧµÄÒ»ÏîÐÂÑо¿Åú×¢£¬£¬£¬4GÒÆ¶¯Í¨Ñ¶±ê×¼ÖеÄÒ»¸öÎó²î¿ÉÄÜʹ¹¥»÷Õßð³äÓû§À´×¢²á¶©ÔÄ»ò¸¶·ÑÍøÕ¾Ð§ÀÍ¡£¡£¡£¡£¡£¡£¡£¡£ÕâÏî¹¥»÷ÊÖÒÕ±»³ÆÎªIMP4GT£¬£¬£¬Ñо¿Ö°Ô±³ÆÆäÓ°ÏìÁËËùÓеÄLTEͨѶװ±¸£¬£¬£¬Õâ°üÀ¨¡°ÏÕЩËùÓеġ±ÖÇÄÜÊÖ»ú¡¢Æ½°åµçÄԺͲ¿·ÖIoT×°±¸¡£¡£¡£¡£¡£¡£¡£¡£IMP4GTµÄÒªº¦ÒªËØÊÇʹÓÃÈí¼þ½ç˵µÄÎÞÏßµçÀ´×èµ²ºÍÓÕÆÒÆ¶¯×°±¸Óë»ùÕ¾Ö®¼äµÄͨѶÐŵÀ¡£¡£¡£¡£¡£¡£¡£¡£ËäÈ»Êý¾Ý°üÔÚÊÖ»úºÍ»ùÕ¾Ö®¼äÒÔ¼ÓÃÜ·½·¨´«Ê䣬£¬£¬µ«ÓÉÓÚȱ·¦ÍêÕûÐÔ±£»£»£»£»£»£»£»¤£¬£¬£¬¿ÉÒÔͨ¹ýÐÞ¸ÄÊý¾Ý°üÀ´´¥·¢¹ýʧ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/lte-security-flaw-can-be-abused-to-take-out-subscriptions-at-your-expense/?&web_view=true
3.Foxmail¸ßΣDllÐ®ÖÆÎó²î£¬£¬£¬²¹¶¡ÉÐδÐû²¼
Foxmail±£´æDLLÐ®ÖÆÎó²î£¨CNVD-2020-12839£©£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îµÄΣº¦¼¶±ð±»½ç˵Ϊ¸ß£¬£¬£¬ÊÜÓ°ÏìµÄ°æ±¾ÎªFoxmail 7.2.15.65¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ³§ÉÌÉÐδÌṩÎó²îÐÞ¸´¼Æ»®£¬£¬£¬½¨ÒéÓû§¹Ø×¢³§É̵ÄÖ÷Ò³¸üв¢ÔÚ²¹¶¡Ðû²¼ºóʵʱ¸üС£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cnvd.org.cn/flaw/show/CNVD-2020-12839
4.RallyhoodÔÆÊý¾Ý¿âй¶4.1TBÎļþ£¬£¬£¬Éæ¼°Êý°ÙÍòÓû§
Éç½»ÍøÂçÆ½Ì¨RallyhoodÔÚÒ»¸ö¹ûÕæÌ»Â¶µÄAWS´æ´¢Í°Öд洢Á˳¤´ïÊ®ÄêµÄÓû§Îļþ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã´æ´¢Í°ÖаüÀ¨µÄÊý¾Ý¿É×·Ëݵ½2011Ä꣬£¬£¬¹²ÓÐ4.1TBµÄÎļþ£¬£¬£¬Éæ¼°Êý°ÙÍòÓû§¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÎļþÖаüÀ¨µÄÃô¸ÐÊý¾Ý°üÀ¨¹²ÏíÃÜÂëÁÐ±í¡¢ÌõÔ¼»òÆäËûÔÊÐíÇåµ¥ºÍÐÒé¡¢±£ÃÜÐÒéµÈ¡£¡£¡£¡£¡£¡£¡£¡£RallyhoodÉÐδÔÚÆäÍøÕ¾»òÈκÎÉ罻ýÌåÉÏÐû²¼ÈκÎÊÂÎñÉùÃ÷¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2020/02/23/rallyhood-exposed-decade-data/
5.Tetrad¹«Ë¾ÔÆÊý¾Ý¿âй¶1.2ÒÚÃÀ¹úÏûºÄÕßÊý¾Ý
UpGuardÔÚ2ÔÂ3ÈÕ·¢Ã÷Êг¡ÆÊÎö¹«Ë¾TetradµÄAmazon S3´æ´¢Í°¿É¹ûÕæ»á¼û£¬£¬£¬ÆäÖаüÀ¨1.2ÒÚÃÀ¹úÏûºÄÕßµÄСÎÒ˽¼ÒÊý¾ÝºÍÐÐΪÆÊÎö¡£¡£¡£¡£¡£¡£¡£¡£¸Ã´æ´¢¿â°üÀ¨Ô¼747GBÊý¾Ý£¬£¬£¬ÆäÖÐÔ¼ÓÐÒ»°ëÀ´×ÔÓÚ¿Í»§ÆóÒµ£¬£¬£¬°üÀ¨ChipotleÔ±¹¤µÄÒÆ¶¯µç»°Êý¾Ý¡¢70ÍòKate Spade¿Í»§µÄ¼ÒÍ¥µØµã¡¢ÒûÁÏÁãÊÛÉÌBevmoµÄ350Íò»áÔ±¿¨ÕÊ»§¼°µØµãµÈ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â»¹°üÀ¨À´×ÔExperian MosaicÏûºÄÕßÐÐΪÆÊÎö²úÆ·µÄ10GBÊý¾Ý£¬£¬£¬ÆäÖаüÀ¨1.2ÒÚÏûºÄÕߵļÒÍ¥µØµã¡¢ÐÕÃû¡¢ÐÔ±ðºÍÆäËûÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎú¸Ã´æ´¢Í°µÄ̻¶ʱ¼äÓж೤¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/120-million-us-consumers-exposed/
6.MoxaÐÞ¸´AWK-3131A¹¤ÒµÍøÂç×°±¸ÖеÄ12¸öÎó²î
ƾ֤MoxaºÍ˼¿ÆTalosÐû²¼µÄͨ¸æ£¬£¬£¬Moxa AWK-3131A¹¤ÒµAP /ÍøÇÅ/¿Í»§¶Ë×°±¸Êܵ½12¸öÎó²îµÄÓ°Ï죬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓÃÕâЩÎó²îÔÚ×éÖ¯µÄ¹¤ÒµÏµÍ³ÖоÙÐжñÒâ»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£ËùÓÐÎó²î¶¼±»ÁÐΪÖ÷Òª»ò¸ßÑÏÖØÐÔ£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃËüÃÇÌáȨΪrootÓû§¡¢Ê¹ÓÃÓ²±àÂëµÄ¼ÓÃÜÃÜÔ¿½âÃÜÁ÷Á¿¡¢×¢ÈëÏÂÁî²¢Ô¶³Ì¿ØÖÆ×°±¸¡¢ÔÚ×°±¸ÉÏÔËÐÐ×Ô½ç˵Õï¶Ï¾ç±¾¡¢Ô¶³ÌÖ´ÐÐí§Òâ´úÂë¡¢µ¼Ö¾ܾøÐ§ÀÍ£¨DoS£©×´Ì¬²¢»ñµÃ¶Ô×°±¸µÄÔ¶³ÌShell»á¼û¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÔÚ´ó´ó¶¼ÇéÐÎÏÂÎó²îʹÓÃÐèÒªµÍÌØÈ¨µÄÉí·ÝÑéÖ¤£¬£¬£¬µ«²¿·ÖÎó²î¿ÉÒÔÓÉδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßʹÓᣡ£¡£¡£¡£¡£¡£¡£MoxaÔÚ2ÔÂ24ÈÕÐû²¼ÁËÏà¹ØÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/vulnerabilities-moxa-networking-device-expose-industrial-environments-attacks


¾©¹«Íø°²±¸11010802024551ºÅ