CiscoÐû²¼Çå¾²¸üУ¬£¬£¬ £¬£¬£¬ÐÞ¸´¶à¸ö²úÆ·ÖеÄÎó²î£»£»£»£»£» £»WooCommerceÖÐÎó²î¿Éµ¼ÖÂÍøÕ¾½ÓÊÜ£¬£¬£¬ £¬£¬£¬Ó°ÏìÉÏÍò¼ÒÊÐËÁ

Ðû²¼Ê±¼ä 2020-08-24

1.CiscoÐû²¼Çå¾²¸üУ¬£¬£¬ £¬£¬£¬ÐÞ¸´¶à¸ö²úÆ·ÖеÄÎó²î


1.png


CiscoÐû²¼Çå¾²¸üУ¬£¬£¬ £¬£¬£¬ÒÔÐÞ¸´Æä¶à¸ö²úÆ·ÖеÄÎó²î¡£ ¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÇå¾²¸üÐÂÖÐÐÞ¸´µÄ½ÏΪÑÏÖØµÄÎó²îΪTreck IP¿ÍÕ»ÖеÄÎó²îRipple20£¬£¬£¬ £¬£¬£¬ÕâЩÎó²î¿Éµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡¢¾Ü¾øÐ§ÀÍ£¨DoS£©»òÐÅϢй¶£»£»£»£»£» £»ÓÃÓÚCisco ENCS 5400-WϵÁкÍCSP 5000-WϵÁеÄCisco vWAASĬÈÏÆ¾Ö¤Îó²î£¨CVE-2020-3446£©£¬£¬£¬ £¬£¬£¬¿É±»Ê¹ÓÃÒÔÖÎÀíԱȨÏÞ»á¼ûNFVIS CLI£»£»£»£»£» £»Ë¼¿ÆÖÇÄÜÈí¼þÖÎÀíÆ÷£¨SSM On-Prem£©ÍâµØÌØÈ¨Éý¼¶Îó²î£¨CVE-2020-3443£©ÒÔ¼°Ë¼¿ÆÊÓÆµ¼à¿Ø8000ϵÁÐIPÉãÏñ»ú˼¿Æ·¢Ã÷ЭÒéÔ¶³ÌÖ´Ðк;ܾøÐ§ÀÍÎó²î£¨CVE-2020-3506ºÍCVE-2020-3507£©¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/08/20/cisco-releases-security-updates


2.FBIºÍCISAÖÒÑÔÕë¶ÔÃÀ¹úƫԶµØÇø¹¤È˵Ĵ¹Âڻ


2.png


ÃÀ¹úFBIºÍCISAÁªºÏÐû²¼¾¯±¨£¬£¬£¬ £¬£¬£¬ÖÒÑÔÏÖÔÚÕë¶ÔÃÀ¹ú¶à¸öÐÐÒµ²¿·ÖµÄÓïÒôÍøÂç´¹Âڻ£¨Vishing£©¡£ ¡£¡£¡£¡£¡£¡£¡£VishingÊÇÒ»ÖÖÉç»á¹¤³Ì¹¥»÷£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßÔÚÓïÒôºô½Ðʱ´úÄ£ÄâÊÜÐÅÈεÄʵÌ壬£¬£¬ £¬£¬£¬ÒÔÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£ ¡£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹ÌåÏÖ£¬£¬£¬ £¬£¬£¬×Ô2020Äê7ÔÂÖÐÑ®£¬£¬£¬ £¬£¬£¬ÍøÂç·¸·¨·Ö×ÓÕö¿ªÁËÕâÒ»»î¶¯£¬£¬£¬ £¬£¬£¬Ö¼ÔÚıȡÀûÒæ¡£ ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬¹¥»÷Õß»¹×¢²áÁËÓÃÓÚÍøÂç´¹ÂÚµÄÓò£¬£¬£¬ £¬£¬£¬ÒÔ¿Ë¡ĿµÄ¹«Ë¾µÄÄÚ²¿VPNµÇÂ¼Ò³Ãæ£¬£¬£¬ £¬£¬£¬À´ÇÔÈ¡Á½ÒòËØÉí·ÝÑéÖ¤£¨2FA£©ºÍÒ»´ÎÐÔÃÜÂ루OTP£©¡£ ¡£¡£¡£¡£¡£¡£¡£Îª´Ë£¬£¬£¬ £¬£¬£¬FBIºÍCISAÌá³öһϵÁн¨Òé²½·¥£¬£¬£¬ £¬£¬£¬ÒÔ»º½â´ËÀ๥»÷¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-govt-warns-remote-workers-of-ongoing-vishing-campaign/


3.WooCommerceÖÐÎó²î¿Éµ¼ÖÂÍøÕ¾½ÓÊÜ£¬£¬£¬ £¬£¬£¬Ó°ÏìÉÏÍò¼ÒÊÐËÁ


3.jpg


WebARX·¢Ã÷WordPress²å¼þWooCommerceÖÐÎó²î¿Éµ¼ÖÂÍøÕ¾½ÓÊÜ£¬£¬£¬ £¬£¬£¬Ó°ÏìÉÏÍò¼ÒÊÐËÁ¡£ ¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤ÆÊÎöÔ±¶ÔÎó²îµÄÆÊÎö£¬£¬£¬ £¬£¬£¬·¢Ã÷ËüÃÇÊÇÓÉȱ·¦Ëæ»úÊýÁîÅÆºÍÊÚȨ¼ì²éµ¼Öµģ¬£¬£¬ £¬£¬£¬ÈôÊÇÀÖ³ÉʹÓÃÕâЩÎó²î£¬£¬£¬ £¬£¬£¬Ôòδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔ¼ìË÷ËùÓÐÓû§ºÍÓÅ»Ýȯ´úÂëµÄÁÐ±í£¬£¬£¬ £¬£¬£¬²¢ÔÚÍøÕ¾µÄҳü¡¢Ò³½Å»òÖÎÀíÒ³Ãæ×¢ÈëXSS£¬£¬£¬ £¬£¬£¬ÒÔ´¥·¢Ô¶³ÌÖ´ÐдúÂëÎó²î¡£ ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬ºÚ¿Í»¹¿ÉÒÔʹÓÃJavaScript¼üÅ̼ͼ³ÌÐò×¢ÈëµÇ¼±íµ¥£¬£¬£¬ £¬£¬£¬ÒÔ½ÓÊÜÖÎÀíÔ±ÕÊ»§¡£ ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬ £¬£¬£¬¸Ã²å¼þÔÚÒÑÍù7ÌìÄÚÒѱ»ÏÂÔØÁËÁè¼Ý12000´Î¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/wordpress-woocommerce-stores-under-attack-patch-now/


4.Diebold NixdorfÐÞ¸´¿É±»ÓÃÓÚ´æ¿îαÔì¹¥»÷µÄÎó²î


4.jpg


ATMÖÆÔìÉÌDiebold NixdorfºÍNCRÐû²¼ÁËÈí¼þ¸üУ¬£¬£¬ £¬£¬£¬ÐÞ¸´¿É±»ÓÃÓÚ´æ¿îαÔì¹¥»÷µÄÎó²î¡£ ¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄÎó²î±»×·×ÙΪCVE-2020-9062ºÍCVE-2020-10124£¬£¬£¬ £¬£¬£¬»®·ÖÓ°ÏìÁËÔËÐÐWincor ProbaseÈí¼þµÄDiebold Nixdorf ProCash 2100xe USB ATMºÍÔËÐÐAPTRA XFSÈí¼þµÄNCR SelfServ ATM¡£ ¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²î¿É±»ºÚ¿ÍʹÓÃÒÔÐÞ¸ÄÆäÒøÐп¨ÉϵĴæ¿î½ð¶î£¬£¬£¬ £¬£¬£¬²¢ÔÚÒøÐз¢Ã÷ÕË»§Óà¶îÒ쳣֮ǰ¾ÙÐÐڲƭÐÔÈ¡¿î¡£ ¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²îÔ´ÓÚATMÏÖ½ð´æ·ÅÏäºÍÖ÷»úÖ®¼ä·¢Ë͵ÄÐÂÎÅȱÉÙ¼ÓÃܺÍÉí·ÝÑéÖ¤»·½Ú£¬£¬£¬ £¬£¬£¬ÏÖÔÚDieboldºÍNCR¾ùÒÑÐû²¼Èí¼þ¸üУ¬£¬£¬ £¬£¬£¬ÒÔ±£»£»£»£»£» £»¤ÏÖ½ð´æ¿îÄ£¿£¿£¿£¿éÓëÖ÷»úÖ®¼äµÄͨѶ¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/107421/hacking/diebold-nixdorf-ncr-deposit-forgery.html


5.Spikey¹¥»÷¿ÉʹÓÃÐźŴ¦Öóͷ£Èí¼þ¿Ë¡ÎïÀíÔ¿³×


5.jpg


ÐÂ¼ÓÆÂ¹úÁ¢´óѧµÄÑо¿Ö°Ô±·¢Ã÷Ò»ÖÖÕë¶ÔÎïÀíËøµÄй¥»÷Õ½ÂÔSpikey£¬£¬£¬ £¬£¬£¬¿ÉʹÓÃÐźŴ¦Öóͷ£Èí¼þ¿Ë¡ÎïÀíÔ¿³×¡£ ¡£¡£¡£¡£¡£¡£¡£´ËÀ๥»÷¿ÉÒÔʹÓÃÖÇÄÜÊÖ»úµÄÂó¿Ë·ç²¶»ñÔ¿³×²åÈë»ò°Î³öʱµÄ½ðÊôµã»÷Éù£¬£¬£¬ £¬£¬£¬²¢ÓÃÐźŴ¦Öóͷ£Èí¼þ¾ÙÐÐÆÆÒ룬£¬£¬ £¬£¬£¬ÒÔÍÆ¶ÏÔ¿³×µÄÐÎ×´£¬£¬£¬ £¬£¬£¬×îÖÕ¿ÉÒÔÓÃ3D´òÓ¡ÊÖÒÕ¿Ë¡³öÎïÀíÔ¿³×¡£ ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖδÀ´»¹¿ÉÄÜͨ¹ý¶ñÒâÈí¼þѬȾÊܺ¦ÕßµÄÖÇÄÜÊÖ»ú»òÖÇÄÜÊÖ±í£¬£¬£¬ £¬£¬£¬ÒԴ˼ͼÉùÒô²¢Ìᳫ¹¥»÷¡£ ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/08/21/spikey-attack-can-duplicate-physical-keys-by-listening-to-click-sounds/


6.Ó¢¹úMyerscough´óѧÔâµ½DoS¹¥»÷µ¼ÖÂϵͳÍÑ»ú


6.jpg


Ó¢¹úMyerscough´óѧÔÚÐû²¼¿¼ÊÔЧ¹ûÈ·µ±ÌìÔâµ½DoS¹¥»÷£¬£¬£¬ £¬£¬£¬µ¼ÖÂϵͳÍÑ»ú¡£ ¡£¡£¡£¡£¡£¡£¡£¸Ã´óѧÌåÏÖ£¬£¬£¬ £¬£¬£¬DoS¹¥»÷ÑÏÖØÆÆËðÁËÆäËùÓÐIT»ù´¡ÉèÊ©£¬£¬£¬ £¬£¬£¬µ¼ÖÂϵͳ´¦ÓÚÍÑ»ú״̬£¬£¬£¬ £¬£¬£¬Ñ§ÉúÎÞ·¨»á¼ûÃÅ»§ÍøÕ¾GCSEºÍÅÌÎÊ¿¼ÊÔЧ¹û¡£ ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬Ñ§Ð£Ô±¹¤Ò²Ö»ÄÜͨ¹ýÉ罻ýÌ幤¾ßÁªÏµ£¬£¬£¬ £¬£¬£¬²¢ÇÒÔÚЧÀÍÆ÷»Ö¸´Ö®Ç°Ö»ÄÜÊÖ¶¯ÏòËùÓÐѧÉú·¢ËÍÆäЧ¹ûµÄµç×ÓÓʼþ¡£ ¡£¡£¡£¡£¡£¡£¡£¸ÃѧУµÄ½²»°ÈËÌåÏÖ£¬£¬£¬ £¬£¬£¬ÏÖÔÚ²¢Ã»ÓÐѧÉúµÄÊý¾ÝÔ⵽й¶£¬£¬£¬ £¬£¬£¬¶øÍâµØ¾¯·½Ò²ÕýÔÚ¶Ô´ËÊÂÕö¿ªÊӲ졣 ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bbc.com/news/uk-england-lancashire-53822246