WSpot¹«Ë¾ÒòAWS´æ´¢Í°ÅäÖÃÃýÎóй¶250ÍòÓû§ÐÅÏ¢
°ä²¼¹¦·ò 2021-11-26CloudLinux½¨¸´Imunify360ÖеÄPHP·´ÐòÁл¯·ì϶

Cisco TaloÔÚ11ÔÂ22ÈÕÅû¶ÁËCloudLinuxµÄ²úÆ·Imunify360ÖеÄPHP·´ÐòÁл¯·ì϶¡£¡£¡£¡£¡£¡£¸Ã²úÆ·ÊÇ»ùÓÚLinuxµÄWeb·þÎñÆ÷µÄ°²È«Æ½Ì¨£¬£¬£¬£¬£¬£¬Óû§¿ÉÀûÓÃÆäͨ¹ý¸÷ÀàÅäÖÃÀ´ÊµÊ±±£»£»£»£»£»£»£»¤ÍøÕ¾ºÍWeb·þÎñÆ÷µÄ°²È«¡£¡£¡£¡£¡£¡£¸Ã·ì϶(CVE-2021-21956)CVSSÆÀ·ÖΪ8.2£¬£¬£¬£¬£¬£¬´æÔÚÓÚAi-BolitÖ°ÄÜÖУ¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ý¸Ã·ì϶ÔÚÖ¸±êϵͳÖÐÖ´ÐÐËÁÒâ´úÂ룬£¬£¬£¬£¬£¬»òÆëÈ«½ÚÔì·þÎñÆ÷¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬CloudLinuxÒѽ¨¸´¸Ã·ì϶¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/11/vulnerability-spotlight-php-deserialize.html
Vestas¹«Ë¾ÒÉËÆÔâµ½ÀÕË÷¹¥»÷µ¼Ö²¿ÃÅÒµÎñÁÙʱÖжÏ

È«Çò×î´óµÄ·çÁ¦ÎÐÂÖ»úÔì×÷ÉÌVestasÔÚÉÏÖÜÁù°ä²¼¹«¸æ£¬£¬£¬£¬£¬£¬³ÆÆäÔâµ½ÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¹¥»÷²úÉúÔÚ11ÔÂ19ÈÕ£¬£¬£¬£¬£¬£¬Æä¶à¸öÒµÎñ²¿ÃŵÄITϵͳ±»ÆÈ¹Ø¹Ø£¬£¬£¬£¬£¬£¬Ó°ÏìÁËÆä¿Í»§¡¢Ô±¹¤ºÍÆäËûÀûÒæÓйØÕß¡£¡£¡£¡£¡£¡£11ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÓÖ°ä²¼¹«¸æ³Æ³õ´ëÊ©²éÁ˾ÖÏÔʾ£¬£¬£¬£¬£¬£¬²¿ÃÅÊý¾ÝÒѱ»Ð¹Â¶¡£¡£¡£¡£¡£¡£¹ÌÈ»VestasûÓÐй©ËûÃÇÔâµ½¹¥»÷µÄÀàÐÍ£¬£¬£¬£¬£¬£¬µ«Í¨¹ýÆäÃèÊö·ÖÎöËÆºõÊÇÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£Õâ¼Òµ¤Âó¹«Ë¾ÔÚ2020ÄêµÄÊÕÈë¿¿½ü150ÒÚÅ·Ôª£¬£¬£¬£¬£¬£¬Ê¹Æä³ÉΪÓÐÀû¿ÉͼµÄÖ¸±ê¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/wind-turbine-giant-offline-after/
Hooshyarane VatanÐû³Æ¶ÔÂíººº½¿Õ¹«Ë¾µÄ¹¥»÷ÕÆ¹Ü

ºÚ¿ÍÍÅ»ïÔÚ11ÔÂ21ÈÕ·¢ÎÄ³ÆÆäÒѳɹ¦¹¥»÷Mahan Air£¬£¬£¬£¬£¬£¬²¢ÒÑÇÔÈ¡¸Ã¹«Ë¾ÓëIRGCÓйصÄÄÚ²¿Îļþ¡¢µç×ÓÓʼþºÍ»ã±¨¡£¡£¡£¡£¡£¡£Mahan AirÊÇÒÁÀÊ×î´óµÄ˽Ӫº½¿Õ¹«Ë¾£¬£¬£¬£¬£¬£¬Æä°µÊ¾ÔÚÖÜÄ©Ôâµ½¹¥»÷£¬£¬£¬£¬£¬£¬ËùÓйú¼ÊºÍ¹úÄÚº½°àûÓÐÊܵ½ÈκÎÓ°Ï죬£¬£¬£¬£¬£¬ÒÀÈ»ÕÕ³£ÔËÐУ¬£¬£¬£¬£¬£¬µ«Óû§ÎÞ·¨½Ó¼ûMahanµÄÍøÕ¾¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾»¹°µÊ¾ÓÉÓÚÆäÔÚÒÁÀʺ½¿ÕÒµµÄְλµ¼ÖÂÆäÔâµ½ÂŴι¥»÷£¬£¬£¬£¬£¬£¬ÕâÊôÓÚÕý³£¾°Ï󣬣¬£¬£¬£¬£¬²¢ÇÒËûÃÇÒѾÔڶ̹¦·òÄڳɹ¦×èÖ¹ÁËÕâ´Î¹¥»÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/124880/hacking/mahan-air-cyberattack.html
WSpot¹«Ë¾ÒòAWS´æ´¢Í°ÅäÖÃÃýÎóй¶250ÍòÓû§ÐÅÏ¢

°²È«¹«Ë¾SafetyDetectives·¢ÏÖ°ÍÎ÷Èí¼þ¹«Ë¾WSpotÒÑй¶³¬¹ý250ÍòÓû§µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£WSpotµÄ²úÆ·¿ÉÓÃÓÚÆóÒµ±£»£»£»£»£»£»£»¤ÆäÄÚ²¿µÄWiFiÍøÂ磬£¬£¬£¬£¬£¬²¢ÌṩÎÞÃÜÂëµÄÔÚÏß½Ó¼û£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄ¿Í»§Ô̺¬Sicredi¡¢±ØÊ¤¿ÍºÍUnimedµÈ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÓÚ9ÔÂ2ÈÕ·¢ÏÖWSpotÅäÖÃÃýÎóµÄAmazon Web Services S3´æ´¢Í°Ð¹Â¶ÁË10 GBµÄÊý¾Ý£¬£¬£¬£¬£¬£¬²¢ÓÚ9ÔÂ7ÈÕ֪ͨWSpot¡£¡£¡£¡£¡£¡£WSpot°µÊ¾´ËÊÂÎñÓ°ÏìÁËÆä5%µÄ¿Í»§Èº£¬£¬£¬£¬£¬£¬ÒÑÔÚ11ÔÂ18ÈÕ½¨¸´ÊµÏÖ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/wifi-software-firm-exposed-users-data/
NCSC·¢ÏÖ4000¶à¸öÔÚÏßÉ̵êÈÝÒ×Ôâµ½Magecart¹¥»÷

Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ(NCSC)11ÔÂ22ÈÕ°ä²¼°²È«×ÊѶ£¬£¬£¬£¬£¬£¬³Æ4151¸öÔÚÏßÉ̵êÈÝÒ×Ôâµ½Magecart¹¥»÷¡£¡£¡£¡£¡£¡£Magecart¹¥»÷Ö¼ÔÚÇÔȡ֧¸¶ÐÅÏ¢£¬£¬£¬£¬£¬£¬Í¨¹ýÏòÔÚÏßÉ̵ê×¢Èë½ÅÕý±¾ÍøÂçÓû§ÔÚ½áÕËÒ³ÃæÌá½»µÄÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£¡£NCSC³ÆËûÃÇ×Ô2020Äê4ÔÂÆðÍ·¼à¿ØÕâЩÉ̵꣬£¬£¬£¬£¬£¬·¢ÏÖ´óÎÞÊýÉ̵궼ÊÜMagentoƽ̨ÖеÄÒ»¸ö·ì϶µÄÓ°Ïì¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬¸Ã×ÊѶÓ×ÎҺͼÒÍ¥ÈôºÎ°²È«µØÔÚÏß¹ºÎïÌṩÁ˽¨ÒéºÍÌṩÁìµ¼¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/uk-govt-warns-thousands-of-smbs-their-online-stores-were-hacked/
Kaspersky°ä²¼2021ÄêºÚÎåÆÚ¼äڿƻµÄ·ÖÎö»ã±¨

11ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬Kaspersky°ä²¼2021ÄêºÚÎåÆÚ¼äڿƻµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£»ã±¨ÖØÒª·ÖÎöÁËÓëÈ«Çò½Ó¼ûÁ¿×î´óµÄÎå¸öÁãÊÛÆ½Ì¨£ºÎÖ¶ûÂê¡¢eBay¡¢ÑÇÂíÑ·¡¢°¢Àï°Í°ÍºÍ Mercado Libre¡£¡£¡£¡£¡£¡£×êÑз¢ÏÖ£¬£¬£¬£¬£¬£¬2021Äêǰ10¸öÔ¼ì²âµ½40584415ÆðÕë¶ÔµçÉÌÆ½Ì¨ÒÔ¼°ÒøÐлú¹¹µÄ´¹µö¹¥»÷£»£»£»£»£»£»£»Õë¶Ôµç×ÓÖ§¸¶ÏµÍ³µÄ´¹µö»î¶¯Ôö³¤ÁË208%£»£»£»£»£»£»£»10ÔÂ27ÈÕÖÁ11ÔÂ19ÈÕ·¢ÏÖÁË221745·âÓëºÚÎåÓйصÄÓʼþ¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬ÐþÉ«ÐÇÆÚÎå²»½ö¶Ô¹ºÎïÕßÀ´ËµÊdzÁÒªµÄÒ»Ì죬£¬£¬£¬£¬£¬¶Ô¹¥»÷ÕßÀ´ËµÒ²ÊÇÈç´Ë¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/black-friday-2021/104915/


¾©¹«Íø°²±¸11010802024551ºÅ