WSpot¹«Ë¾ÒòAWS´æ´¢Í°ÅäÖôíÎóй¶250ÍòÓû§ÐÅÏ¢

Ðû²¼Ê±¼ä 2021-11-26

CloudLinuxÐÞ¸´Imunify360ÖеÄPHP·´ÐòÁл¯Â©¶´


CloudLinuxÐÞ¸´Imunify360ÖеÄPHP·´ÐòÁл¯Â©¶´.png


Cisco TaloÔÚ11ÔÂ22ÈÕÅû¶ÁËCloudLinuxµÄ²úÎïImunify360ÖеÄPHP·´ÐòÁл¯Â©¶´¡£¸Ã²úÎïÊÇ»ùÓÚLinuxµÄWeb·þÎñÆ÷µÄÄþ¾²Æ½Ì¨£¬Óû§¿ÉÀûÓÃÆäͨ¹ýÖÖÖÖÅäÖÃÀ´ÊµÊ±±£»¤ÍøÕ¾ºÍWeb·þÎñÆ÷µÄÄþ¾²¡£¸Ã©¶´(CVE-2021-21956)CVSSÆÀ·ÖΪ8.2£¬´æÔÚÓÚAi-Bolit¹¦Ð§ÖУ¬¹¥»÷Õß¿ÉÒÔͨ¹ý¸Ã©¶´ÔÚÄ¿±êϵͳÖÐÖ´ÐÐÈÎÒâ´úÂ룬»òÍêÈ«¿ØÖÆ·þÎñÆ÷¡£Ä¿Ç°£¬CloudLinuxÒÑÐÞ¸´¸Ã©¶´¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/11/vulnerability-spotlight-php-deserialize.html


Vestas¹«Ë¾ÒÉËÆÔâµ½ÀÕË÷¹¥»÷µ¼Ö²¿ÃÅÒµÎñÔÝʱÖжÏ


Vestas¹«Ë¾ÒÉËÆÔâµ½ÀÕË÷¹¥»÷µ¼Ö²¿ÃÅÒµÎñÔÝʱÖжÏ.png


È«Çò×î´óµÄ·çÁ¦ÎÐÂÖ»úÖÆÔìÉÌVestasÔÚÉÏÖÜÁùÐû²¼Í¨¸æ£¬³ÆÆäÔâµ½ÍøÂç¹¥»÷¡£¹¥»÷·¢ÉúÔÚ11ÔÂ19ÈÕ£¬Æä¶à¸öÒµÎñ²¿ÃŵÄITϵͳ±»ÆÈ¹Ø±Õ£¬Ó°ÏìÁËÆä¿Í»§¡¢Ô±¹¤ºÍÆäËûÀûÒæÏà¹ØÕß¡£11ÔÂ22ÈÕ£¬¸Ã¹«Ë¾ÓÖÐû²¼Í¨¸æ³Æ³õ·¨Ê½²é½á¹ûÏÔʾ£¬²¿ÃÅÊý¾ÝÒѱ»Ð¹Â¶¡£ËäÈ»VestasûÓÐ͸¶ËûÃÇÔâµ½¹¥»÷µÄÀàÐÍ£¬µ«Í¨¹ýÆäÃèÊö·ÖÎöËÆºõÊÇÀÕË÷¹¥»÷¡£Õâ¼Òµ¤Âó¹«Ë¾ÔÚ2020ÄêµÄÊÕÈë½Ó½ü150ÒÚÅ·Ôª£¬Ê¹Æä³ÉΪÓÐÀû¿ÉͼµÄÄ¿±ê¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/wind-turbine-giant-offline-after/


Hooshyarane VatanÐû³Æ¶ÔÂíººº½¿Õ¹«Ë¾µÄ¹¥»÷ÂôÁ¦


Hooshyarane VatanÐû³Æ¶ÔÂíººº½¿Õ¹«Ë¾µÄ¹¥»÷ÂôÁ¦.png


ºÚ¿ÍÍÅ»ïÔÚ11ÔÂ21ÈÕ·¢ÎÄ³ÆÆäÒÑÀֳɹ¥»÷Mahan Air£¬²¢ÒÑÇÔÈ¡¸Ã¹«Ë¾ÓëIRGCÏà¹ØµÄÄÚ²¿Îļþ¡¢µç×ÓÓʼþºÍ³ÂËß¡£Mahan AirÊÇÒÁÀÊ×î´óµÄ˽Ӫº½¿Õ¹«Ë¾£¬ÆäÌåÏÖÔÚÖÜÄ©Ôâµ½¹¥»÷£¬ËùÓйú¼ÊºÍ¹úÄÚº½°àûÓÐÊܵ½ÈκÎÓ°Ï죬ÒÀÈ»ÕÕ³£ÔËÐУ¬µ«Óû§ÎÞ·¨·ÃÎÊMahanµÄÍøÕ¾¡£¸Ã¹«Ë¾»¹ÌåÏÖÒòΪÆäÔÚÒÁÀʺ½¿ÕÒµµÄְλµ¼ÖÂÆäÔâµ½¶à´Î¹¥»÷£¬ÕâÊôÓÚÕý³£ÏÖÏ󣬶øÇÒËûÃÇÒѾ­ÔÚ¶Ìʱ¼äÄÚÀÖ³É×èÖ¹Á˴˴ι¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/124880/hacking/mahan-air-cyberattack.html


WSpot¹«Ë¾ÒòAWS´æ´¢Í°ÅäÖôíÎóй¶250ÍòÓû§ÐÅÏ¢


WSpot¹«Ë¾ÒòAWS´æ´¢Í°ÅäÖôíÎóй¶250ÍòÓû§ÐÅÏ¢.png


Äþ¾²¹«Ë¾SafetyDetectives·¢ÏÖ°ÍÎ÷Èí¼þ¹«Ë¾WSpotÒÑй¶Áè¼Ý250ÍòÓû§µÄÐÅÏ¢¡£WSpotµÄ²úÎï¿ÉÓÃÓÚÆóÒµ±£»¤ÆäÄÚ²¿µÄWiFiÍøÂ磬²¢ÌṩÎÞÃÜÂëµÄÔÚÏß·ÃÎÊ£¬¸Ã¹«Ë¾µÄ¿Í»§°üÂÞSicredi¡¢±ØÊ¤¿ÍºÍUnimedµÈ¡£Ñо¿ÈËÔ±ÓÚ9ÔÂ2ÈÕ·¢ÏÖWSpotÅäÖôíÎóµÄAmazon Web Services S3´æ´¢Í°Ð¹Â¶ÁË10 GBµÄÊý¾Ý£¬²¢ÓÚ9ÔÂ7ÈÕ֪ͨWSpot¡£WSpotÌåÏÖ´ËʼþÓ°ÏìÁËÆä5%µÄ¿Í»§Èº£¬ÒÑÔÚ11ÔÂ18ÈÕÐÞ¸´Íê³É¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/wifi-software-firm-exposed-users-data/


NCSC·¢ÏÖ4000¶à¸öÔÚÏßÉ̵êÈÝÒ×Ôâµ½Magecart¹¥»÷


NCSC·¢ÏÖ4000¶à¸öÔÚÏßÉ̵êÈÝÒ×Ôâµ½Magecart¹¥»÷.png


Ó¢¹ú¹ú¼ÒÍøÂçÄþ¾²ÖÐÐÄ(NCSC)11ÔÂ22ÈÕÐû²¼Äþ¾²×ÊѶ£¬³Æ4151¸öÔÚÏßÉ̵êÈÝÒ×Ôâµ½Magecart¹¥»÷¡£Magecart¹¥»÷Ö¼ÔÚÇÔȡ֧¸¶ÐÅÏ¢£¬Í¨¹ýÏòÔÚÏßÉ̵ê×¢Èë½ÅÔ­À´ÊÕ¼¯Óû§ÔÚ½áÕËÒ³ÃæÌá½»µÄ¸öÈËÐÅÏ¢¡£NCSC³ÆËûÃÇ×Ô2020Äê4Ô¿ªÊ¼¼à¿ØÕâЩÉ̵꣬·¢ÏÖ´ó¶àÊýÉ̵궼ÊÜMagentoƽ̨ÖеÄÒ»¸ö©¶´µÄÓ°Ïì¡£´ËÍ⣬¸Ã×ÊѶ¸öÈ˺ͼÒÍ¥ÈçºÎÄþ¾²µØÔÚÏß¹ºÎïÌṩÁ˽¨ÒéºÍÌṩָµ¼¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/uk-govt-warns-thousands-of-smbs-their-online-stores-were-hacked/


KasperskyÐû²¼2021ÄêºÚÎåÆÚ¼äÕ©Æ­»î¶¯µÄ·ÖÎö³ÂËß


KasperskyÐû²¼2021ÄêºÚÎåÆÚ¼äÕ©Æ­»î¶¯µÄ·ÖÎö³ÂËß.png


11ÔÂ22ÈÕ£¬KasperskyÐû²¼2021ÄêºÚÎåÆÚ¼äÕ©Æ­»î¶¯µÄ·ÖÎö³ÂËß¡£³ÂËßÖ÷Òª·ÖÎöÁËÓëÈ«Çò·ÃÎÊÁ¿×î´óµÄÎå¸öÁãÊÛÆ½Ì¨£ºÎÖ¶ûÂê¡¢eBay¡¢ÑÇÂíÑ·¡¢°¢Àï°Í°ÍºÍ Mercado Libre¡£Ñо¿·¢ÏÖ£¬2021Äêǰ10¸öÔ¼ì²âµ½40584415ÆðÕë¶ÔµçÉÌÆ½Ì¨ÒÔ¼°ÒøÐлú¹¹µÄµöÓã¹¥»÷£»Õë¶Ôµç×ÓÖ§¸¶ÏµÍ³µÄµöÓã»î¶¯Ôö¼ÓÁË208%£»10ÔÂ27ÈÕÖÁ11ÔÂ19ÈÕ·¢ÏÖÁË221745·âÓëºÚÎåÓйصÄÓʼþ¡£³ÂËßÖ¸³ö£¬ºÚÉ«ÐÇÆÚÎå²»½ö¶Ô¹ºÎïÕßÀ´ËµÊÇÖØÒªµÄÒ»Ì죬¶Ô¹¥»÷ÕßÀ´ËµÒ²ÊÇÈç´Ë¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/black-friday-2021/104915/