ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ47ÖÜ
°ä²¼¹¦·ò 2020-11-23> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê11ÔÂ16ÈÕÖÁ11ÔÂ22ÈÕ¹²ÊÕ¼°²È«·ì϶61¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAviatrix Systems Controller APIËÁÒâÎļþÖ´Ðзì϶£»£»£»£»£»Google Go CVE-2020-28366´úÂë×¢Èë·ì϶£»£»£»£»£»Paradox IP150 CVE-2020-25189»º³åÇøÒç¶Âí½Å£»£»£»£»£»QNAP QTS CVE-2020-2492ºÅÁî×¢Èë·ì϶£»£»£»£»£»Real Time Automation 499ES EtherNet/IPÕ»»º³åÇøÒç¶Âí½Å¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǺڿÍÔÚ°µÍø¹«¿ª320Íò¸öPluto TVÓû§µÄÐÅÏ¢£»£»£»£»£»Snow Software°ä²¼2021ÄêÓйØITÖÎÀíµÄ·ÖÎö»ã±¨£»£»£»£»£»Intel 471°ä²¼°µÍøÖÐ25ÖÖÖØÒªRaaS²úÆ·µÄ·ÖÎö»ã±¨£»£»£»£»£»Google Nest·þÎñÖжϵ¼ÖÂÅ·ÃÀÓû§ÖÇÄܼҾÓʧÁ飻£»£»£»£»×êÑÐÈËÔ±·¢ÏÖÊýÊ®¸öAWS API¿É±»ÓÃÀ´ÇÔÊØÐÅÏ¢¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£
> ³ÁÒª°²È«·ì϶Áбí
1.Aviatrix Systems Controller APIËÁÒâÎļþÖ´Ðзì϶
Aviatrix Systems Controller APIʵÏֵĿÉÖ´ÐÐÎļþ´æÔÚδÊÚȨ·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£
https://www.criticalstart.com/multiple-vulnerabilities-discovered-in-aviatrix/
2.Google Go CVE-2020-28366´úÂë×¢Èë·ì϶
Google Go´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿É×¢Èë´úÂë²¢ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐС£¡£¡£¡£¡£¡£
https://www.vuxml.org/freebsd/db4b2f27-252a-11eb-865c-00155d646400.html
3.Paradox IP150 CVE-2020-25189»º³åÇøÒç¶Âí½Å
Paradox IP150´æÔÚÕ»»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë»òʹÀûÓ÷¨Ê½±ÀÀ£¡£¡£¡£¡£¡£¡£
https://us-cert.cisa.gov/ics/advisories/icsa-20-324-02
4.QNAP QTS CVE-2020-2492ºÅÁî×¢Èë·ì϶
QNAP QTS´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£
https://www.qnap.com/en/security-advisory/qsa-20-09
5.Real Time Automation 499ES EtherNet/IPÕ»»º³åÇøÒç¶Âí½Å
Real Time Automation 499ES EtherNet/IP´æÔÚÕ»»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë»òʹÀûÓ÷¨Ê½±ÀÀ£¡£¡£¡£¡£¡£¡£
https://us-cert.cisa.gov/ics/advisories/icsa-20-324-03
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ºÚ¿ÍÔÚ°µÍø¹«¿ª320Íò¸öPluto TVÓû§µÄÐÅÏ¢

ÉÏÖÜÈý£¬£¬£¬£¬£¬ºÚ¿ÍÔÚ°µÍø¹«¿ªÁËÔ̺¬320Íò¸öPluto TVÓû§ÐÅÏ¢µÄÊý¾Ý¿â¡£¡£¡£¡£¡£¡£Í¨¹ýÊý¾Ý¿âÑù±¾¿ÉÖª£¬£¬£¬£¬£¬Ð¹Â¶Êý¾ÝÔ̺¬Óû§Ãû¡¢µç×ÓÓʼþµØÖ·¡¢bcrypt¹þÏ£ÃÜÂë¡¢ÉúÈÕ¡¢É豸ƽ̨ºÍIPµØÖ·¡£¡£¡£¡£¡£¡£ºÚ¿ÍÐû³ÆÕâ´ÎÊý¾Ýй¶ÊÇÓÉShinyHuntersµ¼Öµģ¬£¬£¬£¬£¬¶ø¸ÃÊý¾Ý¿â¿ÉÄÜÊÇÁ½Äêǰй¶µÄ£¬£¬£¬£¬£¬×îмͼÊÇÔÚ2018Äê10ÔÂ12ÈÕ´´½¨µÄ¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬Pluto TVÉÐδ֤ʵÊÇ·ñ²úÉúÁËÊý¾Ýй¶£¬£¬£¬£¬£¬½ö°µÊ¾ËûÃÇÔÚµ÷²éÖС£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hacker-shares-32-million-pluto-tv-accounts-for-free-on-forum/
2¡¢Snow Software°ä²¼2021ÄêÓйØITÖÎÀíµÄ·ÖÎö»ã±¨

Snow Software°ä²¼2021ÄêÓйØITÖÎÀíµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬63£¥µÄÊÜ·ÃÕ߳Ƽ¼ÊõÖÎÀí±äµÃÔ½À´Ô½ÄÑÌ⣬£¬£¬£¬£¬ÆóÒµÔÚÈí¼þ¡¢Ó²¼þ¡¢SaaSºÍÔÆÉϵļ¼ÊõÖ§³öÈ«ÃæÔö³¤¡£¡£¡£¡£¡£¡£87£¥µÄIT¸¨µ¼Õß°µÊ¾£¬£¬£¬£¬£¬´ÓǰһÄêÖÐËûÃÇÒѾ¹ýMicrosoft¡¢IBM¡¢Oracle¡¢AdobeºÍSAPµÈÈí¼þ¹©¸øÉ̵ÄÉ󼯣¬£¬£¬£¬£¬Ö»ÓÐ51£¥µÄÈ˲»°²ÏÂÒ»ÄêµÄÉ󼯡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬×³´óµÄ¼¼Êõµý±¨Ê¹IT¸¨µ¼ÕßÄܸüÓÐЧµØ½â¾öËûÃǵÄÊ×Òª¹¤×÷£¬£¬£¬£¬£¬µ«Ö»ÓÐ14%µÄIT¸¨µ¼Õß´ïµ½Á˳ÉÊì¼¼ÊõÖÇÄܵij߶ȡ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.snowsoftware.com/company/news/cios-face-competing-and-complex-priorities-2021-finds-new-snow-software-report
3¡¢Intel 471°ä²¼°µÍøÖÐ25ÖÖÖØÒªRaaS²úÆ·µÄ·ÖÎö»ã±¨

Intel 471°ä²¼ÁËÓйذµÍøÖеÄ25ÖÖÖØÒªRaaS²úÆ·µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£Intel 471°µÊ¾£¬£¬£¬£¬£¬Ëüƾ¾ÝRaaSµÄ¸´ÔÓˮƽ¡¢Ö°Äܺͺ¹ÇཫÕâЩÀÕË÷Èí¼þ·ÖΪÈý¸öµµ´Î¡£¡£¡£¡£¡£¡£µÚÒ»²ãΪµ±½ñ×î³ÛÃûµÄÀÕË÷Èí¼þ£¬£¬£¬£¬£¬Ô̺¬REvil¡¢Netwalker¡¢DopplePaymer¡¢Egregor£¨Maze£©ºÍRyuk¡£¡£¡£¡£¡£¡£µÚ¶þ²ãΪÀÕË÷Èí¼þÊÀ½çµÄÐÂÐË´ú±í£¬£¬£¬£¬£¬Ô̺¬Avaddon¡¢Conti¡¢Clop¡¢DarkSide¡¢Mespinoza£¨Pysa£©¡¢RagnarLocker¡¢Ranzy£¨Ako£©¡¢SunCryptºÍThanos¡£¡£¡£¡£¡£¡£µÚÈý²ãΪа䲼µÄRaaS²úÆ·£¬£¬£¬£¬£¬Ô̺¬CVartek.u45¡¢Exorcist¡¢Gothmog¡¢Lolkek¡¢Muchlove¡¢Nemty¡¢Rush¡¢Wally¡¢Xinof¡¢ZeoticusºÍZagreuS¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://public.intel471.com/blog/ransomware-as-a-service-2020-ryuk-maze-revil-egregor-doppelpaymer/
4¡¢Google Nest·þÎñÖжϵ¼ÖÂÅ·ÃÀÓû§ÖÇÄܼҾÓʧÁé

±¾ÖܶþGoogle Nest·þÎñ´ó¹æÄ£Öжϣ¬£¬£¬£¬£¬µ¼Ö±±ÃÀºÍÅ·ÖÞÓû§ÖÇÄܼҾÓʧÁé¡£¡£¡£¡£¡£¡£ÖܶþÁ賿£¬£¬£¬£¬£¬¹È¸è×ܲ¿°ä²¼ÐÂÎųƣ¬£¬£¬£¬£¬Æä·¢ÏÖÒ»¸öÎÊÌâ»áÓ°Ïì¹È¸èNestÉ豸ºÍNestÀûÓᣡ£¡£¡£¡£¡£¸ÃÎÊÌâµ¼ÖÂÖÇÄܼҾÓÓû§ÎÞ·¨µÇ¼ÆäÕË»§£¬£¬£¬£¬£¬ÎÞ·¨Ê¹ÓÃÖÇÄÜÊÖ»úÅÔ¹ÛÊÓÆµÖ±²¥£¬£¬£¬£¬£¬ÎÞ·¨µ÷ÕûºãνÚÔìÆ÷£¬£¬£¬£¬£¬Ò²ÎÞ·¨ÓëNestµÄÈκÎϵÁвúÆ·»¥¶¯£¬£¬£¬£¬£¬ÆäÖб±ÃÀºÍ±±Å·µÄÓû§Êܵ½µÄÓ°Ïì×î´ó¡£¡£¡£¡£¡£¡£Æäʵ£¬£¬£¬£¬£¬¸Ã·þÎñÔÚ2ÔÂÒ²²úÉúÁËÀàËÆµÄÖжϣ¬£¬£¬£¬£¬³ÖÐøÁË16¸öÓ×ʱ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.com/2020/11/17/google_nest_outage/
5¡¢×êÑÐÈËÔ±·¢ÏÖÊýÊ®¸öAWS API¿É±»ÓÃÀ´ÇÔÊØÐÅÏ¢

Palo Alto Networks×êÑÐÈËÔ±·¢ÏÖÁË16¸ö·ÖÆçAmazon Web Services£¨AWS£©ÖеÄ22¸öAPI£¬£¬£¬£¬£¬¿É±»ÀÄÓÃÀ´»ñÊØÐÅÏ¢¡£¡£¡£¡£¡£¡£¸ÃÎÊÌâÊÇÓÉÓÚAWSºó¶Ë»á×Ô¶¯ÑéÖ¤¸½¼Óµ½×ÊÔ´µÄËùÓлùÓÚ×ÊÔ´µÄÕ½ÊõËùµ¼Öµġ£¡£¡£¡£¡£¡£ÈôÊÇÕ½ÊõÖÐÔ̺¬²»´æÔÚµÄÉí·Ý£¬£¬£¬£¬£¬Ôò´´½¨»ò¸üÐÂÕ½ÊõµÄAPIŲÓý«Ê§°Ü£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀÄÓôËÖ°ÄÜÀ´²é³AWSÕË»§ÖеÄÏÖÓÐÉí·Ý¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬¸Ã¹¥»÷¿ÉÔÚaws¡¢aws-us-govºÍaws-cn·ÖÇøÉϽøÐУ¬£¬£¬£¬£¬Ò×Êܹ¥»÷µÄAWS·þÎñÔ̺¬AWS S3¡¢AWS KMSºÍAWS SQS¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/researchers-find-tens-aws-apis-leaking-sensitive-data


¾©¹«Íø°²±¸11010802024551ºÅ