˼¿Æ2020ÄêCISO»ù×¼±¨¸æ£»£»£»£»4G LTEÐÂÎó²îÔÊÐí¹¥»÷Õß×¢²á¸¶·ÑµÄ¶©ÔÄ»òÍøÕ¾Ð§ÀÍ

Ðû²¼Ê±¼ä 2020-02-25

1.˼¿ÆÐû²¼2020ÄêCISO»ù×¼±¨¸æ£¬£¬Õ¹ÏÖ½ñÄêÍøÂçÇå¾²Ô¸¾°


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


˼¿ÆµÄ2020ÄêCISO»ù×¼±¨¸æ°üÀ¨Á˶ÔÇå¾²Ïòµ¼ÕßÓÐÓõÄÈκÎÉÏÏÂÎÄÐÅÏ¢£¬£¬´ÓÔõÑùÓ°Ïì¶­Ê»ᵽÄÄЩ±¨¸æÖ¸±ê¶ÔÆäÓÐÓ㬣¬ÔÙµ½Í£»£»£»£»úµÄÔµ¹ÊÔ­ÓÉÒÔ¼°ÈçÄÇÀïÖÃÖØ´óÐԵȡ£¡£¡£¡£¡£¡£ÎªÁË×ÊÖúÇå¾²Ïòµ¼ÕßʵÏÖËûÃǶÔ×éÖ¯µÄÆÚÍû£¬£¬¸Ã±¨¸æÕë¶Ô2020ÄêÌá³öÁË20Ìõ½¨Òé¡£¡£¡£¡£¡£¡£±¨¸æµÄһЩ·¢Ã÷°üÀ¨£ºÔÚÊÜÇå¾²ÊÂÎñÓ°ÏìµÄÓªÒµÁìÓòÖУ¬£¬Æ·ÅÆÉùÓþÒѳÉΪ½ö´ÎÓÚÔËÓªµÄµÚ¶þ´óÊÜÓ°ÏìÁìÓò£»£»£»£»×ÔÔ¸Åû¶µÄÇå¾²ÊÂÎñÒÑ´ïÀúÊ·×î¸ßÖµ£»£»£»£»ÔÚÇå¾²ÐÔºÍÍøÂ磬£¬»ò¶ËµãÖÎÀíºÍÇ徲С×éÖ®¼ä¾ÙÐÐÁ˺ÜÊÇ/¼«ÆäЭ×÷µÄÆóҵΥ¹æ±¾Ç®ÏÔÖø½µµÍ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blogs.cisco.com/security/a-20-20-vision-for-cybersecurity


2.4G LTEÐÂÎó²îÔÊÐí¹¥»÷Õß×¢²á¸¶·ÑµÄ¶©ÔÄ»òÍøÕ¾Ð§ÀÍ


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


²¨ºè³¶û´óѧµÄÒ»ÏîÐÂÑо¿Åú×¢£¬£¬4GÒÆ¶¯Í¨Ñ¶±ê×¼ÖеÄÒ»¸öÎó²î¿ÉÄÜʹ¹¥»÷Õßð³äÓû§À´×¢²á¶©ÔÄ»ò¸¶·ÑÍøÕ¾Ð§ÀÍ¡£¡£¡£¡£¡£¡£ÕâÏî¹¥»÷ÊÖÒÕ±»³ÆÎªIMP4GT£¬£¬Ñо¿Ö°Ô±³ÆÆäÓ°ÏìÁËËùÓеÄLTEͨѶװ±¸£¬£¬Õâ°üÀ¨¡°ÏÕЩËùÓеġ±ÖÇÄÜÊÖ»ú¡¢Æ½°åµçÄԺͲ¿·ÖIoT×°±¸¡£¡£¡£¡£¡£¡£IMP4GTµÄÒªº¦ÒªËØÊÇʹÓÃÈí¼þ½ç˵µÄÎÞÏßµçÀ´×èµ²ºÍÓÕÆ­Òƶ¯×°±¸Óë»ùÕ¾Ö®¼äµÄͨѶÐŵÀ¡£¡£¡£¡£¡£¡£ËäÈ»Êý¾Ý°üÔÚÊÖ»úºÍ»ùÕ¾Ö®¼äÒÔ¼ÓÃÜ·½·¨´«Ê䣬£¬µ«ÓÉÓÚȱ·¦ÍêÕûÐÔ±£»£»£»£»¤£¬£¬¿ÉÒÔͨ¹ýÐÞ¸ÄÊý¾Ý°üÀ´´¥·¢¹ýʧ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/lte-security-flaw-can-be-abused-to-take-out-subscriptions-at-your-expense/?&web_view=true


3.Foxmail¸ßΣDllÐ®ÖÆÎó²î£¬£¬²¹¶¡ÉÐδÐû²¼


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾



Foxmail±£´æDLLÐ®ÖÆÎó²î£¨CNVD-2020-12839£©£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¸ÃÎó²îµÄΣº¦¼¶±ð±»½ç˵Ϊ¸ß£¬£¬ÊÜÓ°ÏìµÄ°æ±¾ÎªFoxmail 7.2.15.65¡£¡£¡£¡£¡£¡£ÏÖÔÚ³§ÉÌÉÐδÌṩÎó²îÐÞ¸´¼Æ»®£¬£¬½¨ÒéÓû§¹Ø×¢³§É̵ÄÖ÷Ò³¸üв¢ÔÚ²¹¶¡Ðû²¼ºóʵʱ¸üС£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cnvd.org.cn/flaw/show/CNVD-2020-12839


4.RallyhoodÔÆÊý¾Ý¿âй¶4.1TBÎļþ£¬£¬Éæ¼°Êý°ÙÍòÓû§


Éç½»ÍøÂçÆ½Ì¨RallyhoodÔÚÒ»¸ö¹ûÕæÌ»Â¶µÄAWS´æ´¢Í°Öд洢Á˳¤´ïÊ®ÄêµÄÓû§Îļþ¡£¡£¡£¡£¡£¡£¸Ã´æ´¢Í°ÖаüÀ¨µÄÊý¾Ý¿É×·Ëݵ½2011Ä꣬£¬¹²ÓÐ4.1TBµÄÎļþ£¬£¬Éæ¼°Êý°ÙÍòÓû§¡£¡£¡£¡£¡£¡£ÕâЩÎļþÖаüÀ¨µÄÃô¸ÐÊý¾Ý°üÀ¨¹²ÏíÃÜÂëÁÐ±í¡¢ÌõÔ¼»òÆäËûÔÊÐíÇåµ¥ºÍЭÒé¡¢±£ÃÜЭÒéµÈ¡£¡£¡£¡£¡£¡£RallyhoodÉÐδÔÚÆäÍøÕ¾»òÈκÎÉ罻ýÌåÉÏÐû²¼ÈκÎÊÂÎñÉùÃ÷¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2020/02/23/rallyhood-exposed-decade-data/


5.Tetrad¹«Ë¾ÔÆÊý¾Ý¿âй¶1.2ÒÚÃÀ¹úÏûºÄÕßÊý¾Ý


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


UpGuardÔÚ2ÔÂ3ÈÕ·¢Ã÷Êг¡ÆÊÎö¹«Ë¾TetradµÄAmazon S3´æ´¢Í°¿É¹ûÕæ»á¼û£¬£¬ÆäÖаüÀ¨1.2ÒÚÃÀ¹úÏûºÄÕßµÄСÎÒ˽¼ÒÊý¾ÝºÍÐÐΪÆÊÎö¡£¡£¡£¡£¡£¡£¸Ã´æ´¢¿â°üÀ¨Ô¼747GBÊý¾Ý£¬£¬ÆäÖÐÔ¼ÓÐÒ»°ëÀ´×ÔÓÚ¿Í»§ÆóÒµ£¬£¬°üÀ¨ChipotleÔ±¹¤µÄÒÆ¶¯µç»°Êý¾Ý¡¢70ÍòKate Spade¿Í»§µÄ¼ÒÍ¥µØµã¡¢ÒûÁÏÁãÊÛÉÌBevmoµÄ350Íò»áÔ±¿¨ÕÊ»§¼°µØµãµÈ¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â»¹°üÀ¨À´×ÔExperian MosaicÏûºÄÕßÐÐΪÆÊÎö²úÆ·µÄ10GBÊý¾Ý£¬£¬ÆäÖаüÀ¨1.2ÒÚÏûºÄÕߵļÒÍ¥µØµã¡¢ÐÕÃû¡¢ÐÔ±ðºÍÆäËûÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎú¸Ã´æ´¢Í°µÄ̻¶ʱ¼äÓж೤¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/120-million-us-consumers-exposed/


6.MoxaÐÞ¸´AWK-3131A¹¤ÒµÍøÂç×°±¸ÖеÄ12¸öÎó²î


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ƾ֤MoxaºÍ˼¿ÆTalosÐû²¼µÄͨ¸æ£¬£¬Moxa AWK-3131A¹¤ÒµAP /ÍøÇÅ/¿Í»§¶Ë×°±¸Êܵ½12¸öÎó²îµÄÓ°Ï죬£¬¹¥»÷Õß¿ÉÄÜʹÓÃÕâЩÎó²îÔÚ×éÖ¯µÄ¹¤ÒµÏµÍ³ÖоÙÐжñÒâ»î¶¯¡£¡£¡£¡£¡£¡£ËùÓÐÎó²î¶¼±»ÁÐΪÖ÷Òª»ò¸ßÑÏÖØÐÔ£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃËüÃÇÌáȨΪrootÓû§¡¢Ê¹ÓÃÓ²±àÂëµÄ¼ÓÃÜÃÜÔ¿½âÃÜÁ÷Á¿¡¢×¢ÈëÏÂÁî²¢Ô¶³Ì¿ØÖÆ×°±¸¡¢ÔÚ×°±¸ÉÏÔËÐÐ×Ô½ç˵Õï¶Ï¾ç±¾¡¢Ô¶³ÌÖ´ÐÐí§Òâ´úÂë¡¢µ¼Ö¾ܾøÐ§ÀÍ£¨DoS£©×´Ì¬²¢»ñµÃ¶Ô×°±¸µÄÔ¶³ÌShell»á¼û¡£¡£¡£¡£¡£¡£Ö»¹ÜÔÚ´ó´ó¶¼ÇéÐÎÏÂÎó²îʹÓÃÐèÒªµÍÌØÈ¨µÄÉí·ÝÑéÖ¤£¬£¬µ«²¿·ÖÎó²î¿ÉÒÔÓÉδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßʹÓᣡ£¡£¡£¡£¡£MoxaÔÚ2ÔÂ24ÈÕÐû²¼ÁËÏà¹ØÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/vulnerabilities-moxa-networking-device-expose-industrial-environments-attacks