ÂùÝÖÎÀí¹«Ë¾AavGoÒâÍâй¶800Íò¿Í»§ÐÅÏ¢£»£»£»£»£»£»£»Î¢ÈíÐÞ¸´PowerShell½¹µãÖеÄWDACÈÆ¹ýÎó²î
Ðû²¼Ê±¼ä 2019-07-181¡¢ÂùÝÖÎÀí¹«Ë¾AavGoÒâÍâй¶800Íò¿Í»§ÐÅÏ¢
WizcaseÇå¾²Ñо¿Ô±Daniel Brown·¢Ã÷ÂùÝÖÎÀíÉÌAavGoµÄÒ»¸öElasticsearchÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨800ÍòÌõ¿Í»§ÐÅÏ¢£¬£¬£¬£¬£¬°üÀ¨Ô¤¶©ÐÅÏ¢¡¢¿Í»§Í¶Ëß¡¢·¢Æ±¡¢¹¤µ¥¡¢Ô±¹¤±¸Íü¼ºÍÐÂÎÅ¡¢Âùݷ¿¼äͼƬ¡¢ÎïÆ·Ëð»µÍ¼Æ¬ÒÔ¼°¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢£¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢ÓÊÏ䵨µã¡¢×¡Ö·¡¢»éÒö״̬¡¢µÇ¼ÐÅÏ¢ºÍ¸¶¿î·½·¨£©¡£¡£¡£Ð¹Â¶µÄÊý¾Ý»¹°üÀ¨ÂùÝÖÎÀíÔ±µÄÏêϸµÇ¼ÐÅÏ¢£¬£¬£¬£¬£¬ÀýÈçÖÎÀíÃæ°å¡¢Ô¤¶©ÏµÍ³ºÍÄÚ²¿Êý¾Ý¿âµÄÓû§ÃûºÍÃÜÂë¡£¡£¡£ÊÜÓ°ÏìµÄÂùݰüÀ¨The Row Hotel¡¢Stay Cal HotelsµÈÊ®¶à¼ÒÂùݡ£¡£¡£¸Ã¹«Ë¾ÒÑÔÚ7ÔÂ16ÈÕ¶ÔÊý¾Ý¿â½ÓÄÉÁ˱£»£»£»£»£»£»£»¤²½·¥¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/unprotected-elasticsearch-database-belonging-to-aavgo-exposed-8-million-records-of-guest-details-f5fb1eac
2¡¢CPL³Æ220Íò»¼ÕßÐÅÏ¢ÊÜAMCAÊý¾Ýй¶ÊÂÎñÓ°Ïì
ÁÙ´²²¡ÀíѧʵÑéÊÒ£¨CPL£©³ÉΪAMCAÊý¾Ýй¶ÊÂÎñµÄ×îÐÂÊܺ¦Õß¡£¡£¡£AMCAÒÑÏò3.45ÍòCPL»¼Õß·¢ËÍÁËÊý¾Ýй¶֪ͨ£¬£¬£¬£¬£¬Æ¾Ö¤AMCAÌṩµÄÐÅÏ¢£¬£¬£¬£¬£¬CPLÔ¤¼ÆÉÐÓÐ220Íò»¼ÕßÊܵ½´ËÊÂÎñµÄÓ°Ïì¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨CPL»¼ÕßµÄÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¡¢³öÉúÈÕÆÚ¡¢Ð§ÀÍÈÕÆÚ¡¢Óà¶î¡¢ÐÅÓÿ¨ÐÅÏ¢ºÍÒ½ÉúÐÅÏ¢¡£¡£¡£AMCAÈ·ÈÏ»¼ÕßµÄÉç»áÇå¾²ºÅÂëδÊÜÓ°Ïì¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/clinical-pathology-laboratories-notifies-patients-of-security-incident-caused-by-amca-data-breach-37f8382c
3¡¢Sprint³ÆºÚ¿Íͨ¹ýÈýÐÇÍøÕ¾ÈëÇÖÆä¿Í»§ÕË»§
ÃÀ¹úµçÐŹ«Ë¾SprintÌåÏÖºÚ¿ÍÏ뷨ʹÓÃÈýÐÇÍøÕ¾Samsung.comÉϵÄаìºÅÂë¡°Add a line¡±Ò³Ãæ×÷Ϊ¹¥»÷Ìø°å£¬£¬£¬£¬£¬ÈëÇÖÆä¿Í»§ÕË»§¡£¡£¡£ÔÚ·¢¸ø¿Í»§µÄ֪ͨº¯ÖÐSprintÌåÏÖ¹²±¬·¢ÁËÁ½ÆðÎ¥¹æÐÐΪ£¬£¬£¬£¬£¬Ò»Æð±¬·¢ÔÚ6ÔÂ8ÈÕ£¬£¬£¬£¬£¬ÁíÒ»Æð±¬·¢ÔÚ6ÔÂ22ÈÕ¡£¡£¡£ºÚ¿Í¿ÉÒÔ»á¼ûµÄ¿Í»§ÐÅÏ¢°üÀ¨Óû§ID¡¢Õʺš¢ÕÊ»§½¨ÉèÈÕÆÚ¡¢ÐÕÃû¡¢Õʵ¥µØµã¡¢µç»°ºÅÂë¡¢×°±¸ÀàÐÍ¡¢×°±¸ID¡¢Ã¿ÔÂÓöȵȡ£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/sprint-accounts-breached-by-hackers-using-samsung-site/
4¡¢Î¢ÈíÐÞ¸´PowerShell½¹µãÖеÄWDACÈÆ¹ýÎó²î
΢ÈíÐû²¼Ð°汾PowerShell Core£¬£¬£¬£¬£¬ÐÞ¸´Ò»¸ö¿ÉÔÊÐíÍâµØ¹¥»÷ÕßÈÆ¹ýWindows DefenderÓ¦ÓóÌÐò¿ØÖÆ£¨WDAC£©µÄÎó²î£¬£¬£¬£¬£¬¸ÃÎó²î±»±ê¼ÇΪCVE-2019-1167¡£¡£¡£ÔÚÆôÓÃWDACʱ£¬£¬£¬£¬£¬PowerShell½«×Ô¶¯½øÈëÔ¼ÊøÓïÑÔģʽÒÔÏÞÖÆ¶ÔijЩWindows APIµÄ»á¼û£¬£¬£¬£¬£¬µ«¸ÃÎó²î¿ÉÈÆ¹ýPowerShellÔ¼ÊøÓïÑÔģʽºÍWDAC¡£¡£¡£¸ÃÎó²îÓ°ÏìÁË6.1.5֮ǰµÄËùÓÐPowerShell Core 6.0¡¢6.1°æ±¾ºÍ6.2.2֮ǰµÄPowerShell Core 6.2°æ±¾£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/microsoft/microsoft-patches-powershell-core-security-bug-to-fix-wdac-bypass/
5¡¢LenovoEMC/Iomega NAS±»ÆØ±£´æÐÅϢй¶Îó²î
Ñо¿Ö°Ô±ÖÒÑԳƣ¬£¬£¬£¬£¬LenovoEMC/IomegaÆ·ÅÆµÄNAS×°±¸Öб£´æÐÅϢй¶Îó²î£¬£¬£¬£¬£¬µ¼Ö´ó×ÚÃô¸ÐÊý¾ÝÔÚ¹«ÍøÉÏ̻¶¡£¡£¡£LenovoEMCºÍIomegaµÄNAS²úÆ·Ö÷ÒªÃæÁÙÖÐСÐÍÆóÒµ¡£¡£¡£¸ÃÎó²î£¨CVE-2019-6160£©Ô´ÓÚδÊܱ£»£»£»£»£»£»£»¤µÄAPIŲÓ㬣¬£¬£¬£¬ÈκÎÈ˶¼¿ÉÒÔͨ¹ýShodan²éÕÒÒ×Êܹ¥»÷µÄNAS×°±¸£¬£¬£¬£¬£¬È»ºóͨ¹ý·¢ËͶñÒâÇëÇóÏÂÔØÉè±¹ØÁ¬ÄÎļþ¡£¡£¡£Ñо¿Ö°Ô±ÔÚshodanÉÏ·¢Ã÷ÁË̻¶ÔÚ¹«ÍøµÄ36TBÊý¾Ý£¬£¬£¬£¬£¬Éæ¼°5114¸ö×°±¸¡£¡£¡£¸ÃÎó²îÏÖÔÚ»¹Ã»ÓÐÐû²¼ÏêϸµÄÐÞ¸´Ê±¼ä¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.helpnetsecurity.com/2019/07/17/lenovoemc-nas-devices-flaw/
6¡¢Drupal CMSÐÞ¸´¿Éµ¼ÖÂÍøÕ¾±»½ÓÊܵÄÑÏÖØÎó²î
Drupal CMS¿ª·¢ÍŶÓÐû²¼8.7.5°æ±¾£¬£¬£¬£¬£¬ÐÞ¸´»á¼ûÈÆ¹ýÎó²î£¨CVE-2019-6342£©¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËDrupal 8.7.4 ¡¢8.7.3¼°¸üÔç°æ±¾¡¢8.6.x¼°¸üÔç°æ±¾£¬£¬£¬£¬£¬¶øDrupal 7.x²»ÊÜÓ°Ïì¡£¡£¡£¸ÃÎó²îÉÐÎÞ¿ÉÓõÄexp£¬£¬£¬£¬£¬ÃÀ¹úCISAÒ²·¢³öÖÒÑÔ£¬£¬£¬£¬£¬±Þ²ßDrupalÖÎÀíÔ±ºÍÓû§Éý¼¶µ½Drupal 8.7.5°æ±¾¡£¡£¡£Æ¾Ö¤Drupal CoreʹÓÃÇéÐÎͳ¼ÆÊý¾Ý£¬£¬£¬£¬£¬¹²ÓÐÔ¼29Íò¸öÍøÕ¾ÕýÔÚʹÓÃDrupal 8.x¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/drupal-patches-critical-bug-that-lets-hackers-take-over-sites/