LightInTheBoxй¶1.3TB Web·þÎñÆ÷ÈÕÖ¾£»BitglassÐû²¼2019Äê½ðÈÚÐÐÒµÊý¾Ýй¶±¨¸æ

Ðû²¼Ê±¼ä 2019-12-18



1.LightInTheBoxй¶1.3TB Web·þÎñÆ÷ÈÕÖ¾


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


vpnMentorÑо¿Ö°Ô±·¢Ã÷ÔÚÏßÁãÊÛÉÌLightInTheBoxµÄElasticsearchÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬ÆäÖаüÀ¨1.3TB Web·þÎñÆ÷ÈÕÖ¾¡£LightInTheBoxרעÓÚСÅä¼þ¡¢´ò°çºÍÅäÊεÄÏúÊÛ£¬Æä´ó²¿·Ö¿Í»§Î»ÓÚ±±ÃÀºÍÅ·ÖÞ¡£Ñо¿Ö°Ô±ÔÚ11ÔÂÏÂÑ®·¢Ã÷Á˸ÃÊý¾Ý¿â£¬Êý¾Ý¿âÖеļͼ×ܼÆÁè¼Ý15ÒÚÌõ£¬»¹°üÀ¨Æä×ÓÍøÕ¾MiniInTheBox.comµÄÊý¾Ý¡£ÈÕÖ¾°üÀ¨8ÔÂ9ÈÕÖÁ10ÔÂ11ÈÕÖ®¼äµÄÍøÕ¾Ô˶¯£¬°üÀ¨µç×ÓÓʼþµØµã¡¢IPµØµã¡¢ÆÜÉí¹ú¼Ò/µØÇøÒÔ¼°Ã¿¸ö·Ã¿Í»á¼ûµÄÒ³ÃæµÈÐÅÏ¢¡£


  Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95231/data-breach/lightinthebox-data-leak.html


2.¼ÓÄôóÁÙ´²ÊµÑéÊÒ·þÎñÉÌLifeLabsй¶1500Íò¿Í»§ÐÅÏ¢


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


¼ÓÄôóÁÙ´²ÊµÑéÊÒ·þÎñÌṩÉÌLifeLabsй¶¶à´ï1500Íò¼ÓÄÃÖÁ¹«ÃñµÄСÎÒ˽¼ÒÐÅÏ¢¡£Æ¾Ö¤ÆäÐû²¼µÄÊý¾Ýй¶֪ͨ£¬Î´¾­ÊÚȨµÄ¹¥»÷Õß»á¼ûÁË1500Íò¿Í»§µÄÐÕÃû¡¢µØµã¡¢µç×ÓÓʼþ¡¢µÇ¼Ãû¡¢ÃÜÂë¡¢³öÉúÈÕÆÚºÍÒ½ÁÆ¿¨ºÅÂë¡£ÆäÖÐÔ¼8.5Íò¿Í»§µÄʵÑéÊÒЧ¹ûÒ²Ôâй¶¡£¾Ý±¨µÀй¶µÄÊý¾ÝÖ÷ҪΪ2016Ä꼰֮ǰµÄÊý¾Ý£¬Éæ¼°µÄ¿Í»§¾ø´ó´ó¶¼À´×ÔÓÚ±°Ê«Ê¡ºÍ°²¼òªʡ¡£ÔÚ·¢Ã÷й¶ºó£¬LifeLabs´ÓºÚ¿ÍÄÇÀﹺÖÃÁ˱»µÁµÄÊý¾Ý£¬µ«²»ÖªµÀËûÃÇΪ´ËÖ§¸¶Á˼¸¶àÊê½ð¡£LifeLabs½«ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩһÄêµÄÃâ·ÑÉí·Ý͵ÇÔ±£»¤·þÎñ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/lifelabs-data-breach-exposes-personal-info-of-15-million-customers/


3.Ó¢ÌØ¶û¿ìËÙ´æ´¢Èí¼þÖб£´æDLLÐ®ÖÆÎó²î


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Ó¢ÌØ¶û¿ìËÙ´æ´¢ÊÖÒÕ£¨Intel RST£©Èí¼þÖб£´æÒ»¸öDLLÐ®ÖÆÎó²î£¬¸ÃÎó²î¿ÉÔÊÐí¶ñÒâ³ÌÐòÏÔʾΪÊÜÐÅÍгÌÐò£¬´Ó¶øÈƹý·À²¡¶¾ÒýÇæ¡£SafeBreachµÄÑо¿Ö°Ô±·¢Ã÷IAStorDataMgrSvc.exe½«ÊµÑé´ÓC:\Program Files\Intel\Intel(R) Rapid Storage Technology\Îļþ¼ÐϼÓÔØ4¸öDLL£¨IoctlLog.dll¡¢IoctlNet.dll¡¢IoctlSim.dll¡¢DriverSim.dll£©£¬µ«ÕâЩDLLÔڸ÷¾¶Ï²¢²»±£´æ£¬Òò´ËÑо¿Ö°Ô±¿ÉÒÔ½¨Éè×Ô¼ºµÄDLLʹIAStorDataMgrSvc.exeÔÚÆô¶¯Ê±¼ÓÔØ£¬¸ÃDLL½«ÒÔSYSTEMÌØÈ¨¼ÓÔØ²¢ÊµÖÊÉϾßÓжÔÅÌËã»úµÄÍêÈ«»á¼ûȨÏÞ¡£Ó¢ÌضûÒÑÓÚ12ÔÂ10ÈÕÐû²¼ÁË¿ìËÙ´æ´¢Èí¼þµÄ¸üаæÔ­À´½â¾ö¸ÃÎó²î¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/update-intels-rapid-storage-app-to-fix-bug-letting-malware-evade-av/


4.˼¿ÆTalosÅû¶WAGO PLCÖеĶà¸öÎó²î


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


˼¿ÆTalosÑо¿Ö°Ô±ÔÚWAGOÖÆÔìµÄ¿É±à³ÌÂß¼­¿ØÖÆÆ÷£¨PLC£©Öз¢Ã÷¶à¸öÑÏÖØÎó²î£¬ÕâЩÎó²î¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐС¢¾Ü¾ø·þÎñ¹¥»÷»ò»ñȡװ±¸µÄµÇ¼ƾ֤¡£ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨WAGO PFC200ºÍPFC100¿ØÖÆÆ÷£¬ËüÃDZ»ÆÕ±éÓÃÓÚÆû³µ¡¢Ìú·¡¢µçÁ¦¹¤³Ì¡¢ÖÆÔìºÍÐÞ½¨ÎïÖÎÀíµÈÐÐÒµÖС£Õâ9¸öÎó²î£¨CVE-2019-5073~CVE-2019-5075£¬CVE-2019-5077~CVE-2019-5082£©µÄ»ù´¡Ôµ¹ÊÔ­ÓÉÔÚÓÚ¿ØÖÆÆ÷ʹÓõÄÊäÈë/Êä³ö¼ì²éÉèÖ÷þÎñµÄЭÒé´¦Öóͷ£´úÂëÖб£´æÎÊÌâ¡£TalosÌåÏÖûÓÐÖ¤¾ÝÅú×¢ÕâЩÎó²îÒÑÔÚÒ°ÍⱻʹÓá£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/several-critical-vulnerabilities-found-wago-controllers


5.F-SecureÔÚClickShareÎÞÏßÑÝʾϵͳÖз¢Ã÷¶à¸öÎó²î


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


F-SecureÑо¿Ö°Ô±·¢Ã÷°Í¿É£¨Barco£©¹«Ë¾ClickShareÎÞÏßÑÝʾϵͳ±£´æ¶à¸ö¿É±»Ê¹ÓõÄÇå¾²Îó²î£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²î×èµ²ºÍ¸Ä¶¯ÑÝʾÀú³ÌÖеÄÐÅÏ¢¡¢ÇÔÈ¡ÃÜÂëµÈÉñÃØÐÅÏ¢ÒÔ¼°×°ÖúóÃÅºÍÆäËü¶ñÒâÈí¼þµÈ¡£ÕâЩÎó²îµÄCVE IDΪCVE-2017-7936¡¢CVE-2017-7932ÒÔ¼°CVE-2019-18824~CVE-2019-18833¡£Ñо¿Ö°Ô±ÓÚ10ÔÂ9ÈÕÓë°Í¿É·ÖÏíÁËÕâЩ·¢Ã÷£¬°Í¿ÉÒÑÔÚÆäÍøÕ¾ÉÏÐû²¼Á˹̼þ°æÔ­À´»º½â²¿·ÖÎó²î£¬ÁíÒ»Ð©Éæ¼°ÎïÀíά»¤µÄÓ²¼þ×é¼þÖеÄÎó²î¿ÉÄܲ»»á±»ÐÞ¸´¡£


 Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2019/12/17/wireless-presentation-system-vulnerabilities/


6.BitglassÐû²¼2019Äê½ðÈÚÐÐÒµÊý¾Ýй¶±¨¸æ


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


¾ÝBitglass³Æ£¬2019ÄêËùÓÐÊý¾Ýй¶ÊÂÎñÖÐÖ»ÓÐ6£¥Éæ¼°µ½½ðÈÚ·þÎñ¹«Ë¾£¬¿ÉÊÇÓëÆäËûÐÐÒµÏà±È£¬ÕâЩÊÂÎñËðº¦Á˸ü¶àµÄ¼Í¼¡£2019ÄêËùÓÐ×ß©¼Í¼ÖÐ×ܼÆÓÐ60£¥ÒÔÉÏÊÇÓɽðÈÚ·þÎñ»ú¹¹Ð¹Â¶µÄ£¬ÕâÖÁÉÙ²¿·ÖÓëCapital OneÌØ´óÊý¾Ýй¶ÊÂÎñÓйØ£¬¸ÃÊÂÎñй¶ÁËÁè¼Ý1ÒÚÌõ¼Í¼¡£2019ÄêºÚ¿ÍºÍ¶ñÒâÈí¼þÈÔÈ»ÊǽðÈÚ·þÎñÊý¾Ýй¶µÄÖ÷ÒªÔµ¹ÊÔ­ÓÉ£¬Õ¼74.5£¥£¨ÂÔ¸ßÓÚ2018ÄêµÄ73.5£¥£©¡£ÄÚ²¿Íþв´Ó2018ÄêµÄ2.9£¥ÔöÌíµ½½ñÄêµÄ5.5£¥£¬¶øÒâÍâй¶´Ó14.7£¥ÔöÌíµ½18.2£¥¡£ÔÚÒÑÍù¼¸ÄêÖУ¬½ðÈÚ·þÎñƽ¾ùÿÌõй¶¼Í¼µÄ±¾Ç®ÓÐËùÔöÌí£¨210ÃÀÔª£©£¬Áè¼ÝÁËÒ½ÁƱ£½¡ÐÐÒµ£¨429ÃÀÔª£©Ö®ÍâµÄËùÓÐÆäËüÐÐÒµ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2019/12/17/data-breaches-financial-services/