WordPress Jetpack²å¼þÎó²îÓ°ÏìÊý°ÙÍòÍøÕ¾£»£»£»T-MobileÔâºÚ¿Í¹¥»÷¿Í»§ÕË»§ÐÅϢй¶

Ðû²¼Ê±¼ä 2019-11-22
1¡¢WordPress Jetpack²å¼þÎó²îÓ°ÏìÊý°ÙÍòÍøÕ¾

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Jetpack¿ª·¢ÍŶӱ޲ßWordPressÍøÕ¾ÖÎÀíÔ±Á¬Ã¦Ó¦ÓÃJetpack 7.9.1Òªº¦Çå¾²¸üУ¬£¬£¬£¬ÒÔÐÞ¸´Ò»¸öÒªº¦Îó²î¡£¡£¡£¡£¡£ËäÈ»¸ÃÍŶÓûÓÐÅû¶ÓйظÃÎó²îµÄÏêϸÐÅÏ¢£¬£¬£¬£¬µ«Æ¾Ö¤JetpackµÄͨ¸æ£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁË´Ó5.1µ½2017Äê7ÔÂÒÔÀ´µÄËùÓа汾¡£¡£¡£¡£¡£¿£¿£¿£¿£¿ª·¢Ö°Ô±ÌåÏÖûÓз¢Ã÷¸ÃÎó²î±»Ò°ÍâʹÓõÄÖ¤¾Ý¡£¡£¡£¡£¡£JetpackÊÇÒ»¸öÊܽӴýµÄWordPress²å¼þ£¬£¬£¬£¬ËüΪÖÎÀíÔ±ÌṩÃâ·ÑµÄÇå¾²ÐÔºÍÕ¾µãÖÎÀí¹¦Ð§£¬£¬£¬£¬¸Ã²å¼þµÄ»îÔ¾×°ÖÃÁ¿ÎªÁè¼Ý500Íò£¬£¬£¬£¬¿ª·¢ÍŶÓÌåÏÖÒÑÓÐÁè¼Ý400ÍòÍøÕ¾×°ÖÃÁ˸üС£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/millions-of-sites-exposed-by-flaw-in-jetpack-wordpress-plugin/

2¡¢Oracle EBS»á¼û¿ØÖƲ»µ±Îó²îÓ°ÏìÉÏÍò¼ÒÆóÒµ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Oracleµç×ÓÉÌÎñÌ×¼þ£¨EBS£©ÖеÄÁ½¸öÒªº¦Îó²î¿Éµ¼Ö¹¥»÷ÕßÍêÈ«¿ØÖƹ«Ë¾µÄERP½â¾ö¼Æ»®¡£¡£¡£¡£¡£¸ÃÎó²î±»¹éÀàΪCWE-284£º»á¼û¿ØÖƲ»µ±£¬£¬£¬£¬ÆäCVSSµÃ·ÖΪ9.9·Ö£¬£¬£¬£¬±»¸ú×ÙΪCVE-2019-2638ºÍCVE-2019-2633¡£¡£¡£¡£¡£ÈôÊÇÀÖ³ÉʹÓÃÕâÁ½¸öÎó²î£¬£¬£¬£¬Î´¾­ÊÚȨµÄ¹¥»÷Õß¿ÉʹÓõç×Ó»ã¿îÁ÷³Ì²¢´òÓ¡ÒøÐÐ֧Ʊ¶ø²»±»·¢Ã÷¡£¡£¡£¡£¡£OracleÔÚ4ÔÂÖ÷Òª²¹¶¡¸üÐÂÖÐÐÞ¸´Á˸ÃÎó²î£¬£¬£¬£¬µ«Æ¾Ö¤OnapsisÑо¿ÍŶӵÄÔ¤¼Æ£¬£¬£¬£¬Ä¿½ñÔ¼ÓÐ50£¥µÄOracle EBS¿Í»§ÉÐδ°²ÅŲ¹¶¡£¡£¡£¡£¡£¨¿ÉÄܶà´ï1Íò¸öÆóÒµ£©¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/thousands-of-enterprises-at-risk-due-to-oracle-ebs-critical-flaws/

3¡¢Ñо¿Ö°Ô±Åû¶Windows UACÖÐÌáȨÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ZDIÑо¿Ö°Ô±Åû¶WindowsÖеÄÒ»¸ö¸ßΣÎó²îµÄÏêϸÐÅÏ¢£¬£¬£¬£¬¸ÃÎó²îÔ´×ÔÓû§ÕÊ»§¿ØÖÆ£¨UAC£©¹¦Ð§£¬£¬£¬£¬Í¨¹ýÓëUACµÄÓû§½çÃæ¾ÙÐн»»¥£¬£¬£¬£¬ÎÞÌØÈ¨µÄ¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÔÚͨË××ÀÃæÉÏÆô¶¯¸ßÌØÈ¨µÄWebä¯ÀÀÆ÷£¬£¬£¬£¬½ø¶ø¿ÉÒÔ×°ÖöñÒâ´úÂë»òÖ´ÐÐÆäËü¶ñÒâ»î¶¯¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ¹¥»÷Õß±ØÐèÊ×ÏȾßÓÐÄ¿µÄϵͳÉϵĵÍÌØÈ¨Óû§Éí·Ý£¬£¬£¬£¬²¢¿ÉÒÔ»á¼û½»»¥Ê½×ÀÃæ¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-1388£©µÄCVSSÆÀ·ÖΪ7.8·Ö£¬£¬£¬£¬Î¢ÈíÔÚÉÏÖÜÐû²¼µÄÇå¾²¸üÐÂÖÐÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/windows-uac-flaw-privilege-escalation/150463/

4¡¢Ñо¿ÍŶӷ¢Ã÷11.9ÒÚÕÅÒ½ÁÆÍ¼ÏñÔÚÍøÉÏй¶

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


GreenboneµÄ×îÐÂÑо¿Åú×¢£¬£¬£¬£¬Î´Êܱ£»£»£»¤µÄͼƬ´æµµºÍͨѶϵͳ£¨PACS£©ÔÚÍøÉÏ̻¶Á˶à´ï11.9ÒÚ¸öÒ½ÁÆÍ¼Ïñ£¬£¬£¬£¬°üÀ¨XÉäÏßͼÏñÒÔ¼°CT¡¢MRIºÍÆäËûҽѧɨÃèЧ¹ûµÈ¡£¡£¡£¡£¡£´ó´ó¶¼Ò½ÁÆ»ú¹¹¶¼Ê¹ÓÃPACSЧÀÍÆ÷À´´æ´¢Ò½ÁÆÍ¼Ïñ²¢ÓëÆäËüÒ½ÁÆ»ú¹¹¹²Ïí£¬£¬£¬£¬µ«Î´Êܱ£»£»£»¤µÄPACSЧÀÍÆ÷¿ÉÄÜ»áÔì³É»¼ÕßÊý¾Ýй¶¡£¡£¡£¡£¡£ÕâÒ»Êý¾ÝÓë2019Äê7ÔÂÖÁ9ÔÂÖ®¼äÊӲ쵽µÄЧ¹ûÔöÌíÁË60%¡£¡£¡£¡£¡£ÔÚÆØ¹âµÄͼÏñ×ÜÊýÖУ¬£¬£¬£¬ÃÀ¹ú¡¢Ó¡¶È¡¢ÄÏ·Ç¡¢°ÍÎ÷ºÍ¶ò¹Ï¶à¶ûÕ¼75£¥£¬£¬£¬£¬ÆäÖÐÔ¼ÓÐ7.86ÒÚÕÅͼÏñÈ·ÈÏÀ´×ÔÃÀ¹ú£¬£¬£¬£¬Ô¼ÓÐ1.21ÒÚÕÅÀ´×ÔÓ¡¶È¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/11/20/confidential-medical-images/

5¡¢ÐÂP2P½©Ê¬ÍøÂçRobotoÕë¶ÔLinux WebminЧÀÍÆ÷

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Ñо¿Ö°Ô±·¢Ã÷Ò»¸öеÄP2P½©Ê¬ÍøÂçRoboto£¬£¬£¬£¬¸Ã½©Ê¬ÍøÂçÖ÷ÒªÕë¶ÔLinux WebminЧÀÍÆ÷¡£¡£¡£¡£¡£RobotoʹÓÃWebminÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-15107£©ÊµÑéÈëÇÖ£¬£¬£¬£¬¸ÃÎó²îÔÚ8ÔÂ17ÈÕ±»ÐÞ¸´£¬£¬£¬£¬ÖÎÀíÔ±¿É¸üÐÂÖÁа汾Webmin 1.930½â¾ö¸ÃÎÊÌâ¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎúÓм¸¶ą̀WebminЧÀÍÆ÷Êܵ½¹¥»÷¡£¡£¡£¡£¡£RobotoÖ§³Ö7ÖÖ¹¦Ð§£¬£¬£¬£¬°üÀ¨·´µ¯shell¡¢×ÔÎÒÐ¶ÔØ¡¢ÍøÂçÀú³ÌÓëÍøÂçÐÅÏ¢¡¢ÍøÂçbotÐÅÏ¢¡¢Ö´ÐÐϵͳÏÂÁî¡¢ÔËÐÐURLÖÐÖ¸¶¨µÄ¼ÓÃÜÎļþÒÔ¼°ÌᳫDDoS¹¥»÷¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/linux-webmin-servers-being-attacked-by-new-p2p-roboto-botnet/

6¡¢T-MobileÔâºÚ¿Í¹¥»÷¿Í»§ÕË»§ÐÅϢй¶

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ÒÆ¶¯ÔËÓªÉÌT-MobileÐû²¼Êý¾Ýй¶֪ͨÌåÏÖ£¬£¬£¬£¬Î´¾­ÊÚȨµÄµÚÈý·½»á¼ûÁ˸ù«Ë¾²¿·ÖʹÓÃÔ¤¸¶·ÑЧÀ͵Ŀͻ§ÕË»§ÐÅÏ¢¡£¡£¡£¡£¡£T-MobileûÓÐÅû¶ÊÜÓ°ÏìµÄ¿Í»§ÊýÄ¿£¬£¬£¬£¬µ«ÌåÏÖ¿ÉÄÜÔâµ½»á¼ûµÄÊý¾Ý°üÀ¨ÐÕÃû¡¢Õ˵¥Óʼĵص㡢µç»°ºÅÂë¡¢Õ˺š¢ÌײÍÓöȺÍÓªÒµ¹¦Ð§µÈ£¬£¬£¬£¬µ«²»°üÀ¨²ÆÎñÊý¾Ý£¨ÐÅÓÿ¨ÐÅÏ¢£©¡¢Éç»áÇå¾²ºÅÂë¼°ÃÜÂë¡£¡£¡£¡£¡£¸Ã¹«Ë¾µÄÍøÂçÇå¾²ÍŶÓÒѾ­×èÖ¹Á˲»·¨»á¼û¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/t-mobile-discloses-data-breach-impacting-prepaid-customers/