LightInTheBoxй¶1.3TB Web·þÎñÆ÷ÈÕÖ¾£»Bitglass°ä²¼2019Äê½ðÈÚÐÐÒµÊý¾Ýй¶»ã±¨

°ä²¼¹¦·ò 2019-12-18



1.LightInTheBoxй¶1.3TB Web·þÎñÆ÷ÈÕÖ¾


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


vpnMentor×êÑÐÈËÔ±·¢´Ë¿ÌÏßÁãÊÛÉÌLightInTheBoxµÄElasticsearchÊý¾Ý¿â¿É¹«¿ª½Ó¼û  £¬ÆäÖÐÔ̺¬1.3TB Web·þÎñÆ÷ÈÕÖ¾¡£LightInTheBoxרһÓÚÓ×Åä¼þ¡¢·þ×°ºÍÅäÊεÄÏúÊÛ  £¬Æä´ó²¿Ãſͻ§Î»ÓÚ±±ÃÀºÍÅ·ÖÞ¡£×êÑÐÈËÔ±ÔÚ11ÔÂÏÂÑ®·¢ÏÖÁ˸ÃÊý¾Ý¿â  £¬Êý¾Ý¿âÖеļͼ×ܼƳ¬¹ý15ÒÚÌõ  £¬»¹Ô̺¬Æä×ÓÍøÕ¾MiniInTheBox.comµÄÊý¾Ý¡£ÈÕÖ¾Ô̺¬8ÔÂ9ÈÕÖÁ10ÔÂ11ÈÕÖ®¼äµÄÍøÕ¾»î¶¯  £¬Ô̺¬µç×ÓÓʼþµØÖ·¡¢IPµØÖ·¡¢¾Óס¹ú¶È/µØÓòÒÔ¼°Ã¿¸ö·Ã¿Í½Ó¼ûµÄÒ³ÃæµÈÐÅÏ¢¡£


  Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95231/data-breach/lightinthebox-data-leak.html


2.¼ÓÄôóÁÙ´²³¢ÊÔÊÒ·þÎñÉÌLifeLabsй¶1500Íò¿Í»§ÐÅÏ¢


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¼ÓÄôóÁÙ´²³¢ÊÔÊÒ·þÎñÌṩÉÌLifeLabsй¶¶à´ï1500Íò¼ÓÄôó¹«ÃñµÄÓ×ÎÒÐÅÏ¢¡£Æ¾¾ÝÆä°ä²¼µÄÊý¾Ýй¶֪ͨ  £¬Î´¾­ÊÚȨµÄ¹¥»÷Õß½Ó¼ûÁË1500Íò¿Í»§µÄÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþ¡¢µÇ¼Ãû¡¢ÃÜÂë¡¢µ®ÉúÈÕÆÚºÍÒ½ÁÆ¿¨ºÅÂë¡£ÆäÖÐÔ¼8.5Íò¿Í»§µÄ³¢ÊÔÊÒÁ˾ÖÒ²Ôâй¶¡£¾Ý±¨Â·Ð¹Â¶µÄÊý¾ÝÖØÒªÎª2016Ä꼰֮ǰµÄÊý¾Ý  £¬Éæ¼°µÄ¿Í»§¾ø´óÎÞÊýÀ´×ÔÓÚ±°Ê«Ê¡ºÍ°²´ÖÂÔÊ¡¡£ÔÚ·¢ÏÖй¶ºó  £¬LifeLabs´ÓºÚ¿ÍÄÇÀï²É°ìÁ˱»µÁµÄÊý¾Ý  £¬µ«²»ÖªÂ·ËûÃÇΪ´ËÖ§¸¶Á˼¸¶àÊê½ð¡£LifeLabs½«ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩһÄêµÄÃâ·ÑÉí·Ý͵ÇÔ±£»¤·þÎñ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/lifelabs-data-breach-exposes-personal-info-of-15-million-customers/


3.Ó¢ÌØ¶û¼±¾ç´æ´¢Èí¼þÖдæÔÚDLL½Ù³Ö·ì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ó¢ÌØ¶û¼±¾ç´æ´¢¼¼Êõ£¨Intel RST£©Èí¼þÖдæÔÚÒ»¸öDLL½Ù³Ö·ì϶  £¬¸Ã·ì϶¿ÉÔÊÐí¶ñÒⷨʽÏÔʾΪÊÜÐÅÀµ·¨Ê½  £¬´Ó¶øÈƹý·À²¡¶¾ÒýÇæ¡£SafeBreachµÄ×êÑÐÈËÔ±·¢ÏÖIAStorDataMgrSvc.exe½«³¢ÊÔ´ÓC:\Program Files\Intel\Intel(R) Rapid Storage Technology\Îļþ¼ÐϼÓÔØ4¸öDLL£¨IoctlLog.dll¡¢IoctlNet.dll¡¢IoctlSim.dll¡¢DriverSim.dll£©  £¬µ«ÕâЩDLLÔÚ¸Ãõ辶ϲ¢²»´æÔÚ  £¬Òò¶ø×êÑÐÈËÔ±Äܹ»´´½¨×Ô¼ºµÄDLLʹIAStorDataMgrSvc.exeÔÚÆô¶¯Ê±¼ÓÔØ  £¬¸ÃDLL½«ÒÔSYSTEMÌØÈ¨¼ÓÔØ²¢ÄÚÈÝÉÏÓµÓжÔÍÆËã»úµÄÆëÈ«½Ó¼ûȨÏÞ¡£Ó¢ÌضûÒÑÓÚ12ÔÂ10ÈÕ°ä²¼Á˼±¾ç´æ´¢Èí¼þµÄ¸üаæÕý±¾½â¾ö¸Ã·ì϶¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/update-intels-rapid-storage-app-to-fix-bug-letting-malware-evade-av/


4.˼¿ÆTalosÅû¶WAGO PLCÖеĶà¸ö·ì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


˼¿ÆTalos×êÑÐÈËÔ±ÔÚWAGOÔì×÷µÄ¿É±à³ÌÂß¼­½ÚÔìÆ÷£¨PLC£©Öз¢ÏÖ¶à¸öÑϳÁ·ì϶  £¬ÕâЩ·ì϶¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐÓ×¢»Ø¾ø·þÎñ¹¥»÷»ò»ñÈ¡É豸µÄµÇ¼ʹ´¦¡£ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬WAGO PFC200ºÍPFC100½ÚÔìÆ÷  £¬ËüÃDZ»¿í·ºÓÃÓÚÆû³µ¡¢Ìú·¡¢µçÁ¦¹¤³Ì¡¢Ôì×÷ºÍ¹¹ÖþÎïÖÎÀíµÈÐÐÒµÖС£Õâ9¸ö·ì϶£¨CVE-2019-5073~CVE-2019-5075  £¬CVE-2019-5077~CVE-2019-5082£©µÄµ××ÓÔ­ÒòÔÚÓÚ½ÚÔìÆ÷ʹÓõÄÊäÈë/Êä³ö²é³­ÅäÖ÷þÎñµÄºÍ̸´¦ÖôúÂëÖдæÔÚÎÊÌâ¡£Talos°µÊ¾Ã»ÓÐÖ¤¾ÝÅú×¢ÕâЩ·ì϶ÒÑÔÚÒ°±í±»ÀûÓá£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/several-critical-vulnerabilities-found-wago-controllers


5.F-SecureÔÚClickShareÎÞÏßÑÝʾϵͳÖз¢ÏÖ¶à¸ö·ì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


F-Secure×êÑÐÈËÔ±·¢ÏְͿɣ¨Barco£©¹«Ë¾ClickShareÎÞÏßÑÝʾϵͳ´æÔÚ¶à¸ö¿É±»ÀûÓõݲȫ·ì϶  £¬¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶À¹½ØºÍ´Û¸ÄÑÝʾ¹ý³ÌÖеÄÐÅÏ¢¡¢ÇÔÈ¡ÃÜÂëµÈ»úÃÜÐÅÏ¢ÒÔ¼°×°ÖúóÃÅºÍÆäËü¶ñÒâÈí¼þµÈ¡£ÕâЩ·ì϶µÄCVE IDΪCVE-2017-7936¡¢CVE-2017-7932ÒÔ¼°CVE-2019-18824~CVE-2019-18833¡£×êÑÐÈËÔ±ÓÚ10ÔÂ9ÈÕÓë°Í¿É·ÖÏíÁËÕâЩ·¢ÏÖ  £¬°Í¿ÉÒÑÔÚÆäÍøÕ¾Éϰ䲼Á˹̼þ°æÕý±¾»º½â²¿ÃÅ·ì϶  £¬ÁíÒ»Ð©Éæ¼°ÎïÀíÊØ»¤µÄÓ²¼þ×é¼þÖеķì϶¿ÉÄܲ»»á±»½¨¸´¡£


 Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2019/12/17/wireless-presentation-system-vulnerabilities/


6.Bitglass°ä²¼2019Äê½ðÈÚÐÐÒµÊý¾Ýй¶»ã±¨


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¾ÝBitglass³Æ  £¬2019ÄêËùº±¼û¾Ýй¶ÊÂÎñÖÐÖ»ÓÐ6£¥Éæ¼°µ½½ðÈÚ·þÎñ¹«Ë¾  £¬µ«ÊÇÓëÆäËûÐÐÒµÏà±È  £¬ÕâЩÊÂÎñÇÖº¦Á˸ü¶àµÄ¼Í¼¡£2019ÄêËùÓÐй©¼Í¼ÖÐ×ܼÆÓÐ60£¥ÒÔÉÏÊÇÓɽðÈÚ·þÎñ»ú¹¹Ð¹Â¶µÄ  £¬ÕâÖÁÉÙ²¿ÃÅÓëCapital OneÌØ´óÊý¾Ýй¶ÊÂÎñÓÐ¹Ø  £¬¸ÃÊÂÎñй¶Á˳¬¹ý1Òڱʼͼ¡£2019ÄêºÚ¿ÍºÍ¶ñÒâÈí¼þÒÀÈ»ÊǽðÈÚ·þÎñÊý¾Ýй¶µÄÖØÒªÔ­Òò  £¬Õ¼74.5£¥£¨ÂÔ¸ßÓÚ2018ÄêµÄ73.5£¥£©¡£ÄÚ²¿Íþв´Ó2018ÄêµÄ2.9£¥Ôö³¤µ½½ñÄêµÄ5.5£¥  £¬¶øÒâ±íй¶´Ó14.7£¥Ôö³¤µ½18.2£¥¡£ÔÚ´Óǰ¼¸ÄêÖÐ  £¬½ðÈÚ·þÎñ¾ùÔÈÿÌõй¶¼Í¼µÄ³É±¾ÓÐËùÔö³¤£¨210ÃÀÔª£©  £¬³¬¹ýÁËÒ½ÁƱ£½¡ÐÐÒµ£¨429ÃÀÔª£©Ö®±íµÄËùÓÐÆäËüÐÐÒµ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2019/12/17/data-breaches-financial-services/