ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ28ÖÜ
Ðû²¼Ê±¼ä 2019-07-22±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2019Äê7ÔÂ15ÈÕÖÁ21ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´50¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇNGINX njs nxt_vsprintf»º³åÇøÒç³ö©¶´£»SolarWinds Orion Network Performance MonitorÔ¶³Ì´úÂëÖ´ÐЩ¶´£»CentOS Web PanelδÊÚȨ·ÃÎÊ©¶´£»Palo Alto Networks PAN-OS CVE-2019-1576ÃüÁî×¢È멶´£»Linaro OP-TEE optee_os»º³åÇøÒç³ö©¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǹ㲥µç̨KHSUÒòÀÕË÷Èí¼þ¹¥»÷µ¼Ö½ÚÄ¿Öжϣ»Evite½ü1.01ÒÚÕË»§ÐÅϢй¶£¬Òѱ»HIBPÊÕ¼£»±£¼ÓÀûÑǹú¼ÒË°Îñ¾ÖÔâºÚ¿ÍÈëÇÖ£¬500¶àÍò¹«ÃñÐÅÏ¢±»µÁ£»¾Æµê¹ÜÀí¹«Ë¾AavGoÒâÍâй¶800Íò¿Í»§ÐÅÏ¢£»¹þÈø¿Ë˹̹Õþ¸®À¹½Ø¾³ÄÚËùÓеÄHTTPSÁ÷Á¿¡£
ÖØÒªÄþ¾²Â©¶´Áбí
1. NGINX njs nxt_vsprintf»º³åÇøÒç³ö©¶´
https://github.com/torvalds/linux/commit/6994eefb0053799d2e07cd140df6c2ea106c41ee
2. SolarWinds Orion Network Performance MonitorÔ¶³Ì´úÂëÖ´ÐЩ¶´
http://www.securityfocus.com/bid/107061
3. CentOS Web PanelδÊÚȨ·ÃÎÊ©¶´
https://github.com/i3umi3iei3ii/CentOS-Control-Web-Panel-CVE/blob/master/CVE-2019-13360.md
4. Palo Alto Networks PAN-OS CVE-2019-1576ÃüÁî×¢È멶´
https://securityadvisories.paloaltonetworks.com/Home/Detail/156
5. Linaro OP-TEE optee_os»º³åÇøÒç³ö©¶´
https://github.com/OP-TEE/optee_os/commit/70697bf3c5dc3d201341b01a1a8e5bc6d2fb48f8
ÖØÒªÄþ¾²Ê¼þ×ÛÊö
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/khsu-radio-stations-regular-programming-interrupted-due-to-ransomware-attack-e39dbd3d
2¡¢Evite½ü1.01ÒÚÕË»§ÐÅϢй¶£¬Òѱ»HIBPÊÕ¼
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/evite-invites-over-100-million-people-to-their-data-breach/
3¡¢±£¼ÓÀûÑǹú¼ÒË°Îñ¾ÖÔâºÚ¿ÍÈëÇÖ£¬500¶àÍò¹«ÃñÐÅÏ¢±»µÁ
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/bulgarias-national-revenue-agency-hacked-to-steal-over-five-million-peoples-data-8e64c8d9
4¡¢¾Æµê¹ÜÀí¹«Ë¾AavGoÒâÍâй¶800Íò¿Í»§ÐÅÏ¢
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/unprotected-elasticsearch-database-belonging-to-aavgo-exposed-8-million-records-of-guest-details-f5fb1eac
5¡¢¹þÈø¿Ë˹̹Õþ¸®À¹½Ø¾³ÄÚËùÓеÄHTTPSÁ÷Á¿
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/kazakhstan-government-is-now-intercepting-all-https-traffic/