WSpot¹«Ë¾ÒòAWS´æ´¢Í°ÉèÖùýʧй¶250ÍòÓû§ÐÅÏ¢

Ðû²¼Ê±¼ä 2021-11-26

CloudLinuxÐÞ¸´Imunify360ÖеÄPHP·´ÐòÁл¯Îó²î


CloudLinuxÐÞ¸´Imunify360ÖеÄPHP·´ÐòÁл¯Îó²î.png


Cisco TaloÔÚ11ÔÂ22ÈÕÅû¶ÁËCloudLinuxµÄ²úÆ·Imunify360ÖеÄPHP·´ÐòÁл¯Îó²î¡£¡£¡£¡£¡£¸Ã²úÆ·ÊÇ»ùÓÚLinuxµÄWebЧÀÍÆ÷µÄÇ徲ƽ̨£¬£¬£¬£¬£¬£¬£¬Óû§¿ÉʹÓÃÆäͨ¹ýÖÖÖÖÉèÖÃÀ´ÊµÊ±±£»£»£»¤ÍøÕ¾ºÍWebЧÀÍÆ÷µÄÇå¾²¡£¡£¡£¡£¡£¸ÃÎó²î(CVE-2021-21956)CVSSÆÀ·ÖΪ8.2£¬£¬£¬£¬£¬£¬£¬±£´æÓÚAi-Bolit¹¦Ð§ÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý¸ÃÎó²îÔÚÄ¿µÄϵͳÖÐÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬£¬»òÍêÈ«¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬CloudLinuxÒÑÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/11/vulnerability-spotlight-php-deserialize.html


Vestas¹«Ë¾ÒÉËÆÔâµ½ÀÕË÷¹¥»÷µ¼Ö²¿·ÖÓªÒµÔÝʱÖÐÖ¹


Vestas¹«Ë¾ÒÉËÆÔâµ½ÀÕË÷¹¥»÷µ¼Ö²¿·ÖÓªÒµÔÝʱÖÐÖ¹.png


È«Çò×î´óµÄ·çÁ¦ÎÐÂÖ»úÖÆÔìÉÌVestasÔÚÉÏÖÜÁùÐû²¼Í¨¸æ£¬£¬£¬£¬£¬£¬£¬³ÆÆäÔâµ½ÍøÂç¹¥»÷¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ11ÔÂ19ÈÕ£¬£¬£¬£¬£¬£¬£¬Æä¶à¸öÓªÒµ²¿·ÖµÄITϵͳ±»ÆÈ¹Ø±Õ£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËÆä¿Í»§¡¢Ô±¹¤ºÍÆäËûÀûÒæÏà¹ØÕß¡£¡£¡£¡£¡£11ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÓÖÐû²¼Í¨¸æ³Æ³õ³ÌÐò²éЧ¹ûÏÔʾ£¬£¬£¬£¬£¬£¬£¬²¿·ÖÊý¾ÝÒѱ»Ð¹Â¶¡£¡£¡£¡£¡£ËäÈ»VestasûÓÐ͸¶ËûÃÇÔâµ½¹¥»÷µÄÀàÐÍ£¬£¬£¬£¬£¬£¬£¬µ«Í¨¹ýÆäÐÎòÆÊÎöËÆºõÊÇÀÕË÷¹¥»÷¡£¡£¡£¡£¡£Õâ¼Òµ¤Âó¹«Ë¾ÔÚ2020ÄêµÄÊÕÈë¿¿½ü150ÒÚÅ·Ôª£¬£¬£¬£¬£¬£¬£¬Ê¹Æä³ÉΪÓÐÀû¿ÉͼµÄÄ¿µÄ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/wind-turbine-giant-offline-after/


Hooshyarane VatanÐû³Æ¶ÔÂíººº½¿Õ¹«Ë¾µÄ¹¥»÷ÈÏÕæ


Hooshyarane VatanÐû³Æ¶ÔÂíººº½¿Õ¹«Ë¾µÄ¹¥»÷ÈÏÕæ.png


ºÚ¿ÍÍÅ»ïÔÚ11ÔÂ21ÈÕ·¢ÎÄ³ÆÆäÒÑÀֳɹ¥»÷Mahan Air£¬£¬£¬£¬£¬£¬£¬²¢ÒÑÇÔÈ¡¸Ã¹«Ë¾ÓëIRGCÏà¹ØµÄÄÚ²¿Îļþ¡¢µç×ÓÓʼþºÍ±¨¸æ¡£¡£¡£¡£¡£Mahan AirÊÇÒÁÀÊ×î´óµÄ˽Ӫº½¿Õ¹«Ë¾£¬£¬£¬£¬£¬£¬£¬ÆäÌåÏÖÔÚÖÜÄ©Ôâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬ËùÓйú¼ÊºÍº£ÄÚº½°àûÓÐÊܵ½ÈκÎÓ°Ï죬£¬£¬£¬£¬£¬£¬ÒÀÈ»ÕÕ³£ÔËÐУ¬£¬£¬£¬£¬£¬£¬µ«Óû§ÎÞ·¨»á¼ûMahanµÄÍøÕ¾¡£¡£¡£¡£¡£¸Ã¹«Ë¾»¹ÌåÏÖÓÉÓÚÆäÔÚÒÁÀʺ½¿ÕÒµµÄְλµ¼ÖÂÆäÔâµ½¶à´Î¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÕâÊôÓÚÕý³£Õ÷Ï󣬣¬£¬£¬£¬£¬£¬²¢ÇÒËûÃÇÒѾ­ÔÚ¶Ìʱ¼äÄÚÀÖ³É×èÖ¹Á˴˴ι¥»÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/124880/hacking/mahan-air-cyberattack.html


WSpot¹«Ë¾ÒòAWS´æ´¢Í°ÉèÖùýʧй¶250ÍòÓû§ÐÅÏ¢


WSpot¹«Ë¾ÒòAWS´æ´¢Í°ÉèÖùýʧй¶250ÍòÓû§ÐÅÏ¢.png


Çå¾²¹«Ë¾SafetyDetectives·¢Ã÷°ÍÎ÷Èí¼þ¹«Ë¾WSpotÒÑй¶Áè¼Ý250ÍòÓû§µÄÐÅÏ¢¡£¡£¡£¡£¡£WSpotµÄ²úÆ·¿ÉÓÃÓÚÆóÒµ±£»£»£»¤ÆäÄÚ²¿µÄWiFiÍøÂ磬£¬£¬£¬£¬£¬£¬²¢ÌṩÎÞÃÜÂëµÄÔÚÏß»á¼û£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄ¿Í»§°üÀ¨Sicredi¡¢±ØÊ¤¿ÍºÍUnimedµÈ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÓÚ9ÔÂ2ÈÕ·¢Ã÷WSpotÉèÖùýʧµÄAmazon Web Services S3´æ´¢Í°Ð¹Â¶ÁË10 GBµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢ÓÚ9ÔÂ7ÈÕ֪ͨWSpot¡£¡£¡£¡£¡£WSpotÌåÏÖ´ËÊÂÎñÓ°ÏìÁËÆä5%µÄ¿Í»§Èº£¬£¬£¬£¬£¬£¬£¬ÒÑÔÚ11ÔÂ18ÈÕÐÞ¸´Íê³É¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/wifi-software-firm-exposed-users-data/


NCSC·¢Ã÷4000¶à¸öÔÚÏßÊÐËÁÈÝÒ×Ôâµ½Magecart¹¥»÷


NCSC·¢Ã÷4000¶à¸öÔÚÏßÊÐËÁÈÝÒ×Ôâµ½Magecart¹¥»÷.png


Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ(NCSC)11ÔÂ22ÈÕÐû²¼Çå¾²×ÊѶ£¬£¬£¬£¬£¬£¬£¬³Æ4151¸öÔÚÏßÊÐËÁÈÝÒ×Ôâµ½Magecart¹¥»÷¡£¡£¡£¡£¡£Magecart¹¥»÷Ö¼ÔÚÇÔȡ֧¸¶ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÏòÔÚÏßÊÐËÁ×¢Èë½ÅÔ­À´ÍøÂçÓû§ÔÚ½áÕËÒ³ÃæÌá½»µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£NCSC³ÆËûÃÇ×Ô2020Äê4ÔÂ×îÏÈ¼à¿ØÕâЩÊÐËÁ£¬£¬£¬£¬£¬£¬£¬·¢Ã÷´ó´ó¶¼ÊÐËÁ¶¼ÊÜMagentoƽ̨ÖеÄÒ»¸öÎó²îµÄÓ°Ïì¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬¸Ã×ÊѶСÎÒ˽¼ÒºÍ¼ÒÍ¥ÔõÑùÇå¾²µØÔÚÏß¹ºÎïÌṩÁ˽¨æÅºÍÌṩָµ¼¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/uk-govt-warns-thousands-of-smbs-their-online-stores-were-hacked/


KasperskyÐû²¼2021ÄêºÚÎåʱ´úÕ©Æ­»î¶¯µÄÆÊÎö±¨¸æ


KasperskyÐû²¼2021ÄêºÚÎåʱ´úÕ©Æ­»î¶¯µÄÆÊÎö±¨¸æ.png


11ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬KasperskyÐû²¼2021ÄêºÚÎåʱ´úÕ©Æ­»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£±¨¸æÖ÷ÒªÆÊÎöÁËÓëÈ«Çò»á¼ûÁ¿×î´óµÄÎå¸öÁãÊÛÆ½Ì¨£ºÎÖ¶ûÂê¡¢eBay¡¢ÑÇÂíÑ·¡¢°¢Àï°Í°ÍºÍ Mercado Libre¡£¡£¡£¡£¡£Ñо¿·¢Ã÷£¬£¬£¬£¬£¬£¬£¬2021Äêǰ10¸öÔ¼ì²âµ½40584415ÆðÕë¶ÔµçÉÌÆ½Ì¨ÒÔ¼°ÒøÐлú¹¹µÄ´¹ÂÚ¹¥»÷£»£»£»Õë¶Ôµç×ÓÖ§¸¶ÏµÍ³µÄ´¹ÂڻÔöÌíÁË208%£»£»£»10ÔÂ27ÈÕÖÁ11ÔÂ19ÈÕ·¢Ã÷ÁË221745·âÓëºÚÎåÓйصÄÓʼþ¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬ÐþÉ«ÐÇÆÚÎå²»µ«¶Ô¹ºÎïÕßÀ´ËµÊÇÖ÷ÒªµÄÒ»Ì죬£¬£¬£¬£¬£¬£¬¶Ô¹¥»÷ÕßÀ´ËµÒ²ÊÇÔÆÔÆ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/black-friday-2021/104915/