WSpot¹«Ë¾ÒòAWS´æ´¢Í°ÅäÖôíÎóй¶250ÍòÓû§ÐÅÏ¢
Ðû²¼Ê±¼ä 2021-11-26CloudLinuxÐÞ¸´Imunify360ÖеÄPHP·´ÐòÁл¯Â©¶´
Cisco TaloÔÚ11ÔÂ22ÈÕÅû¶ÁËCloudLinuxµÄ²úÎïImunify360ÖеÄPHP·´ÐòÁл¯Â©¶´¡£¸Ã²úÎïÊÇ»ùÓÚLinuxµÄWeb·þÎñÆ÷µÄÄþ¾²Æ½Ì¨£¬Óû§¿ÉÀûÓÃÆäͨ¹ýÖÖÖÖÅäÖÃÀ´ÊµÊ±±£»¤ÍøÕ¾ºÍWeb·þÎñÆ÷µÄÄþ¾²¡£¸Ã©¶´(CVE-2021-21956)CVSSÆÀ·ÖΪ8.2£¬´æÔÚÓÚAi-Bolit¹¦Ð§ÖУ¬¹¥»÷Õß¿ÉÒÔͨ¹ý¸Ã©¶´ÔÚÄ¿±êϵͳÖÐÖ´ÐÐÈÎÒâ´úÂ룬»òÍêÈ«¿ØÖÆ·þÎñÆ÷¡£Ä¿Ç°£¬CloudLinuxÒÑÐÞ¸´¸Ã©¶´¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/11/vulnerability-spotlight-php-deserialize.html
Vestas¹«Ë¾ÒÉËÆÔâµ½ÀÕË÷¹¥»÷µ¼Ö²¿ÃÅÒµÎñÔÝʱÖжÏ
È«Çò×î´óµÄ·çÁ¦ÎÐÂÖ»úÖÆÔìÉÌVestasÔÚÉÏÖÜÁùÐû²¼Í¨¸æ£¬³ÆÆäÔâµ½ÍøÂç¹¥»÷¡£¹¥»÷·¢ÉúÔÚ11ÔÂ19ÈÕ£¬Æä¶à¸öÒµÎñ²¿ÃŵÄITϵͳ±»ÆÈ¹Ø±Õ£¬Ó°ÏìÁËÆä¿Í»§¡¢Ô±¹¤ºÍÆäËûÀûÒæÏà¹ØÕß¡£11ÔÂ22ÈÕ£¬¸Ã¹«Ë¾ÓÖÐû²¼Í¨¸æ³Æ³õ·¨Ê½²é½á¹ûÏÔʾ£¬²¿ÃÅÊý¾ÝÒѱ»Ð¹Â¶¡£ËäÈ»VestasûÓÐ͸¶ËûÃÇÔâµ½¹¥»÷µÄÀàÐÍ£¬µ«Í¨¹ýÆäÃèÊö·ÖÎöËÆºõÊÇÀÕË÷¹¥»÷¡£Õâ¼Òµ¤Âó¹«Ë¾ÔÚ2020ÄêµÄÊÕÈë½Ó½ü150ÒÚÅ·Ôª£¬Ê¹Æä³ÉΪÓÐÀû¿ÉͼµÄÄ¿±ê¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/wind-turbine-giant-offline-after/
Hooshyarane VatanÐû³Æ¶ÔÂíººº½¿Õ¹«Ë¾µÄ¹¥»÷ÂôÁ¦
ºÚ¿ÍÍÅ»ïÔÚ11ÔÂ21ÈÕ·¢ÎÄ³ÆÆäÒÑÀֳɹ¥»÷Mahan Air£¬²¢ÒÑÇÔÈ¡¸Ã¹«Ë¾ÓëIRGCÏà¹ØµÄÄÚ²¿Îļþ¡¢µç×ÓÓʼþºÍ³ÂËß¡£Mahan AirÊÇÒÁÀÊ×î´óµÄ˽Ӫº½¿Õ¹«Ë¾£¬ÆäÌåÏÖÔÚÖÜÄ©Ôâµ½¹¥»÷£¬ËùÓйú¼ÊºÍ¹úÄÚº½°àûÓÐÊܵ½ÈκÎÓ°Ï죬ÒÀÈ»ÕÕ³£ÔËÐУ¬µ«Óû§ÎÞ·¨·ÃÎÊMahanµÄÍøÕ¾¡£¸Ã¹«Ë¾»¹ÌåÏÖÒòΪÆäÔÚÒÁÀʺ½¿ÕÒµµÄְλµ¼ÖÂÆäÔâµ½¶à´Î¹¥»÷£¬ÕâÊôÓÚÕý³£ÏÖÏ󣬶øÇÒËûÃÇÒѾÔÚ¶Ìʱ¼äÄÚÀÖ³É×èÖ¹Á˴˴ι¥»÷¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/124880/hacking/mahan-air-cyberattack.html
WSpot¹«Ë¾ÒòAWS´æ´¢Í°ÅäÖôíÎóй¶250ÍòÓû§ÐÅÏ¢
Äþ¾²¹«Ë¾SafetyDetectives·¢ÏÖ°ÍÎ÷Èí¼þ¹«Ë¾WSpotÒÑй¶Áè¼Ý250ÍòÓû§µÄÐÅÏ¢¡£WSpotµÄ²úÎï¿ÉÓÃÓÚÆóÒµ±£»¤ÆäÄÚ²¿µÄWiFiÍøÂ磬²¢ÌṩÎÞÃÜÂëµÄÔÚÏß·ÃÎÊ£¬¸Ã¹«Ë¾µÄ¿Í»§°üÂÞSicredi¡¢±ØÊ¤¿ÍºÍUnimedµÈ¡£Ñо¿ÈËÔ±ÓÚ9ÔÂ2ÈÕ·¢ÏÖWSpotÅäÖôíÎóµÄAmazon Web Services S3´æ´¢Í°Ð¹Â¶ÁË10 GBµÄÊý¾Ý£¬²¢ÓÚ9ÔÂ7ÈÕ֪ͨWSpot¡£WSpotÌåÏÖ´ËʼþÓ°ÏìÁËÆä5%µÄ¿Í»§Èº£¬ÒÑÔÚ11ÔÂ18ÈÕÐÞ¸´Íê³É¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/wifi-software-firm-exposed-users-data/
NCSC·¢ÏÖ4000¶à¸öÔÚÏßÉ̵êÈÝÒ×Ôâµ½Magecart¹¥»÷
Ó¢¹ú¹ú¼ÒÍøÂçÄþ¾²ÖÐÐÄ(NCSC)11ÔÂ22ÈÕÐû²¼Äþ¾²×ÊѶ£¬³Æ4151¸öÔÚÏßÉ̵êÈÝÒ×Ôâµ½Magecart¹¥»÷¡£Magecart¹¥»÷Ö¼ÔÚÇÔȡ֧¸¶ÐÅÏ¢£¬Í¨¹ýÏòÔÚÏßÉ̵ê×¢Èë½ÅÔÀ´ÊÕ¼¯Óû§ÔÚ½áÕËÒ³ÃæÌá½»µÄ¸öÈËÐÅÏ¢¡£NCSC³ÆËûÃÇ×Ô2020Äê4Ô¿ªÊ¼¼à¿ØÕâЩÉ̵꣬·¢ÏÖ´ó¶àÊýÉ̵궼ÊÜMagentoƽ̨ÖеÄÒ»¸ö©¶´µÄÓ°Ïì¡£´ËÍ⣬¸Ã×ÊѶ¸öÈ˺ͼÒÍ¥ÈçºÎÄþ¾²µØÔÚÏß¹ºÎïÌṩÁ˽¨ÒéºÍÌṩָµ¼¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/uk-govt-warns-thousands-of-smbs-their-online-stores-were-hacked/
KasperskyÐû²¼2021ÄêºÚÎåÆÚ¼äթƻµÄ·ÖÎö³ÂËß
11ÔÂ22ÈÕ£¬KasperskyÐû²¼2021ÄêºÚÎåÆÚ¼äթƻµÄ·ÖÎö³ÂËß¡£³ÂËßÖ÷Òª·ÖÎöÁËÓëÈ«Çò·ÃÎÊÁ¿×î´óµÄÎå¸öÁãÊÛÆ½Ì¨£ºÎÖ¶ûÂê¡¢eBay¡¢ÑÇÂíÑ·¡¢°¢Àï°Í°ÍºÍ Mercado Libre¡£Ñо¿·¢ÏÖ£¬2021Äêǰ10¸öÔ¼ì²âµ½40584415ÆðÕë¶ÔµçÉÌÆ½Ì¨ÒÔ¼°ÒøÐлú¹¹µÄµöÓã¹¥»÷£»Õë¶Ôµç×ÓÖ§¸¶ÏµÍ³µÄµöÓã»î¶¯Ôö¼ÓÁË208%£»10ÔÂ27ÈÕÖÁ11ÔÂ19ÈÕ·¢ÏÖÁË221745·âÓëºÚÎåÓйصÄÓʼþ¡£³ÂËßÖ¸³ö£¬ºÚÉ«ÐÇÆÚÎå²»½ö¶Ô¹ºÎïÕßÀ´ËµÊÇÖØÒªµÄÒ»Ì죬¶Ô¹¥»÷ÕßÀ´ËµÒ²ÊÇÈç´Ë¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/black-friday-2021/104915/