±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2019Äê7ÔÂ15ÈÕÖÁ21ÈÕ¹²ÊÕ¼Çå¾²Îó²î50¸ö£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇNGINX njs nxt_vsprintf»º³åÇøÒç³öÎó²î£»£»£»£»£»SolarWinds Orion Network Performance MonitorÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»CentOS Web PanelδÊÚȨ»á¼ûÎó²î£»£»£»£»£»Palo Alto Networks PAN-OS CVE-2019-1576ÏÂÁî×¢ÈëÎó²î£»£»£»£»£»Linaro OP-TEE optee_os»º³åÇøÒç³öÎó²î¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǹ㲥µç̨KHSUÒòÀÕË÷Èí¼þ¹¥»÷µ¼Ö½ÚÄ¿ÖÐÖ¹£»£»£»£»£»Evite½ü1.01ÒÚÕË»§ÐÅϢй¶£¬£¬£¬£¬Òѱ»HIBPÊÕ¼£»£»£»£»£»±£¼ÓÀûÑǹú¼Ò˰Îñ¾ÖÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬500¶àÍò¹«ÃñÐÅÏ¢±»µÁ£»£»£»£»£»ÂùÝÖÎÀí¹«Ë¾AavGoÒâÍâй¶800Íò¿Í»§ÐÅÏ¢£»£»£»£»£»¹þÈø¿Ë˹̹Õþ¸®×èµ²¾³ÄÚËùÓеÄHTTPSÁ÷Á¿¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£
Ö÷ÒªÇå¾²Îó²îÁбí
1. NGINX njs nxt_vsprintf»º³åÇøÒç³öÎó²î
NGINX njs nxt/nxt_sprintf.cÎļþµÄnxt_vsprintf±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://github.com/torvalds/linux/commit/6994eefb0053799d2e07cd140df6c2ea106c41ee
2. SolarWinds Orion Network Performance MonitorÔ¶³Ì´úÂëÖ´ÐÐÎó²î
SolarWinds Orion Network Performance Monitor OrionModuleEngineЧÀͱ£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÒÔSYSTEMÓû§Ö´ÐÐí§Òâ´úÂë¡£¡£¡£
http://www.securityfocus.com/bid/107061
3. CentOS Web PanelδÊÚȨ»á¼ûÎó²î
CentOS Web Panel±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ÒÔÆäËûÓû§ÃûÈÆ¹ýÑé֤δÊÚȨ»á¼û¡£¡£¡£
https://github.com/i3umi3iei3ii/CentOS-Control-Web-Panel-CVE/blob/master/CVE-2019-13360.md
4. Palo Alto Networks PAN-OS CVE-2019-1576ÏÂÁî×¢ÈëÎó²î
Palo Alto Networks PAN-OS±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÖ´ÐÐí§ÒâOSÏÂÁî¡£¡£¡£
https://securityadvisories.paloaltonetworks.com/Home/Detail/156
5. Linaro OP-TEE optee_os»º³åÇøÒç³öÎó²î
Linaro OP-TEE optee_os±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://github.com/OP-TEE/optee_os/commit/70697bf3c5dc3d201341b01a1a8e5bc6d2fb48f8
Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢¹ã²¥µç̨KHSUÒòÀÕË÷Èí¼þ¹¥»÷µ¼Ö½ÚÄ¿ÖÐÖ¹
ÃÀ¹ú¼ÓÖݺ鱤ÖÝÁ¢´óѧӵÓеÄKHSU¹ã²¥µç̨Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬µ¼Ö¸õç̨µÄËùÓÐϵͳºÍ´æ´¢Ð§ÀÍÆ÷̱»¾£¬£¬£¬£¬½ÚÄ¿±»ÆÈÖÐÖ¹¡£¡£¡£µ«KHSUÈ·ÈϳÆÊÜѬȾµÄЧÀÍÆ÷²¢Î´°üÀ¨ÈκÎÃô¸ÐÐÅÏ¢¡£¡£¡£KHSUÔÚ7ÔÂ1ÈÕ·¢Ã÷´Ë´Î¹¥»÷£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËKHSUϵͳÖеÄÇå¾²Îó²î¡£¡£¡£KHSUÌåÏÖûÓÐÊÕµ½Êê½ðÒªÇ󣬣¬£¬£¬Ò²²»ÖªµÀ¹¥»÷µÄȪԴ¡£¡£¡£ÔÚ·¢Ã÷ÊÂÎñºó£¬£¬£¬£¬KHSUÏòÁª°îÖ´·¨²¿·ÖºÍÁª°îͨѶίԱ»á±¨¸æÁËÕâÒ»ÊÂÎñ¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/khsu-radio-stations-regular-programming-interrupted-due-to-ransomware-attack-e39dbd3d
2¡¢Evite½ü1.01ÒÚÕË»§ÐÅϢй¶£¬£¬£¬£¬Òѱ»HIBPÊÕ¼
2019Äê5ÔÂEviteÐû²¼Êý¾Ýй¶֪ͨ£¬£¬£¬£¬ÌåÏÖÆäЧÀÍÆ÷´Ó2ÔÂ22ÈÕ·¢Ã÷δÊÚȨ»á¼û£¬£¬£¬£¬Ô¼1000ÍòÓû§ÐÅϢй¶¡£¡£¡£µ«Æ¾Ö¤Have I Been PwnedÍøÕ¾ÊÕ¼µÄÊý¾Ý¿â£¬£¬£¬£¬ÕâÒ»Êý×ÖÒª´óµÃ¶à£¬£¬£¬£¬¹²Óнü1.01ÒÚÓû§ÐÅÏ¢±»µÁ¡£¡£¡£ÕâЩÊý¾Ý×îÔç¿É×·ËÝÖÁ2013Ä꣬£¬£¬£¬Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µç»°ºÅÂë¡¢ÏÖʵµØµã¡¢³öÉúÈÕÆÚ¡¢ÐÔ±ð¡¢Ã÷ÎÄÃÜÂëºÍµç×ÓÓʼþµØµã¡£¡£¡£×î³õ±»Ð¹Â¶µÄÊý¾Ý¿âÔÚDream MarketÉϳöÊÛ£¬£¬£¬£¬µ«¸ÃÍøÕ¾Òѱ»¾¯·½¹Ø±Õ£¬£¬£¬£¬Òò´ËÏÖÔÚÉв»ÇåÎúÕâ¸ö¸ü´óµÄÊý¾Ý¿âÊÇ·ñÒ²ÔÚ³öÊÛ¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/evite-invites-over-100-million-people-to-their-data-breach/
3¡¢±£¼ÓÀûÑǹú¼Ò˰Îñ¾ÖÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬500¶àÍò¹«ÃñÐÅÏ¢±»µÁ
¾Ýzdnet±¨µÀ£¬£¬£¬£¬Ò»ºÚ¿Í×éÖ¯´Ó±£¼ÓÀûÑǹú¼Ò˰Îñ¾Ö£¨NRA£©ÖÐÇÔÈ¡ÁËÔ¼110¸öÊý¾Ý¿â£¬£¬£¬£¬ÆäÖаüÀ¨½ü21GBµÄСÎÒ˽¼ÒÊý¾Ý£¬£¬£¬£¬ÊÜÓ°ÏìÈËÊýÁè¼Ý500Íò¡£¡£¡£ºÚ¿Í½«²¿·Ö±»µÁÊý¾Ýͨ¹ýµç×ÓÓʼþ·¢Ë͸øÍâµØÃ½Ì壬£¬£¬£¬µ¼ÖÂÊÂÎñÆØ¹â¡£¡£¡£¸Ã¹úÓйز¿·ÖÒѾÈÏ¿ÉÕâÒ»ÊÂÎñ£¬£¬£¬£¬²¢ÕýÓë±£¼ÓÀûÑǹú¼ÒÇå¾²¾ÖÏàÖúÊӲ졣¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨±£¼ÓÀûÑǹ«ÃñµÄСÎÒ˽¼Òʶ±ðÂ루PIN£©¡¢ÐÕÃû¡¢¼ÒͥסַºÍ²ÆÎñÊÕÈ룬£¬£¬£¬ÕâЩÊý¾Ý×îÔç¿É×·Ëݵ½2007Äê¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/bulgarias-national-revenue-agency-hacked-to-steal-over-five-million-peoples-data-8e64c8d9
4¡¢ÂùÝÖÎÀí¹«Ë¾AavGoÒâÍâй¶800Íò¿Í»§ÐÅÏ¢
WizcaseÇå¾²Ñо¿Ô±Daniel Brown·¢Ã÷ÂùÝÖÎÀíÉÌAavGoµÄÒ»¸öElasticsearchÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨800ÍòÌõ¿Í»§ÐÅÏ¢£¬£¬£¬£¬°üÀ¨Ô¤¶©ÐÅÏ¢¡¢¿Í»§Í¶Ëß¡¢·¢Æ±¡¢¹¤µ¥¡¢Ô±¹¤±¸Íü¼ºÍÐÂÎÅ¡¢Âùݷ¿¼äͼƬ¡¢ÎïÆ·Ëð»µÍ¼Æ¬ÒÔ¼°¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢£¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢ÓÊÏ䵨µã¡¢×¡Ö·¡¢»éÒö״̬¡¢µÇ¼ÐÅÏ¢ºÍ¸¶¿î·½·¨£©¡£¡£¡£Ð¹Â¶µÄÊý¾Ý»¹°üÀ¨ÂùÝÖÎÀíÔ±µÄÏêϸµÇ¼ÐÅÏ¢£¬£¬£¬£¬ÀýÈçÖÎÀíÃæ°å¡¢Ô¤¶©ÏµÍ³ºÍÄÚ²¿Êý¾Ý¿âµÄÓû§ÃûºÍÃÜÂë¡£¡£¡£ÊÜÓ°ÏìµÄÂùݰüÀ¨The Row Hotel¡¢Stay Cal HotelsµÈÊ®¶à¼ÒÂùݡ£¡£¡£¸Ã¹«Ë¾ÒÑÔÚ7ÔÂ16ÈÕ¶ÔÊý¾Ý¿â½ÓÄÉÁ˱£»£»£»£»£»¤²½·¥¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/unprotected-elasticsearch-database-belonging-to-aavgo-exposed-8-million-records-of-guest-details-f5fb1eac
5¡¢¹þÈø¿Ë˹̹Õþ¸®×èµ²¾³ÄÚËùÓеÄHTTPSÁ÷Á¿
¹þÈø¿Ë˹̹Õþ¸®ÒÑ´Ó7ÔÂ17ÈÕ×îÏÈ×èµ²Æä¾³ÄÚµÄËùÓÐHTTPSÁ÷Á¿¡£¡£¡£ÔÚÍâµØÕþ¸®µÄָʾÏ£¬£¬£¬£¬ÍâµØISPÇ¿ÖÆÓû§ÔÚÿ¸ö×°±¸ºÍä¯ÀÀÆ÷ÖÐ×°ÖÃÕþ¸®½ÒÏþµÄÖ¤Êé¡£¡£¡£¸ÃÖ¤Ê齫ÔÊÐíÕþ¸®»ú¹¹½âÃÜÓû§µÄHTTPSÁ÷Á¿²¢Éó²éÆäÄÚÈÝ¡£¡£¡£ÔÚÓû§×°ÖøÃÖ¤Êé֮ǰ£¬£¬£¬£¬ËûÃǽ«ÎÞ·¨»á¼û»¥ÁªÍø¡£¡£¡£Õþ¸®¹ÙÔ±ÌåÏִ˾ÙÖ¼ÔÚÔöÇ¿¶Ô¹«Ãñ¡¢Õþ¸®»ú¹¹ºÍ˽ӪÆóÒµµÄ±£»£»£»£»£»¤£¬£¬£¬£¬Ê¹ÆäÃâÔâºÚ¿Í¹¥»÷¡¢»¥ÁªÍøÚ²ÆµÈÍøÂçÍþв¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/kazakhstan-government-is-now-intercepting-all-https-traffic/