Amcrest¼ÒÓÃÉãÏñÍ·ÑÏÖØÎó²î £»±¾ÌïÒâÍâй¶40GBÊý¾Ý £»DHSÖÒÑÔСÐÍ·É»úCAN×ÜÏßÑÏÖØÎó²î

Ðû²¼Ê±¼ä 2019-08-01
1¡¢±±¿¨ÂÞÀ´ÄÉÖÝÔâBECڲƭ¹¥»÷ £¬Ëðʧ170ÍòÃÀÔª


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


±±¿¨ÂÞÀ´ÄÉÖÝ¿¨°ÍÂ³Ë¹ÏØ£¨Cabarrus County£©ÔâBECÕ©Æ­ £¬Ëðʧ³¬170ÍòÃÀÔª¡£¹¥»÷Õßαװ³É¸ÃÏØÐ¸ßÖеÄÐÞ½¨³Ð°üÉÌ £¬Í¨¹ýÓʼþ¼û¸æÆäÒøÐÐÕË»§ÒѾ­¸ü¸Ä £¬¸ÃÏØÒò´ËÏòÕ©Æ­ÕßµÄÕË»§Ö§¸¶ÁË250ÍòÃÀÔª¡£Ö±µ½Èý¸öÐÇÆÚºó³Ð°üÉÌѯÎÊÇ·¿îµÄÎÊÌâ £¬¸ÃÏØ²Å·¢Ã÷Ôâµ½Õ©Æ­ £¬´ËÊ±ÒøÐÐÖ»ÄÜ×·»Ø77ÍòÃÀÔªµÄ×ʽð¡£FinCEN×î½üµÄÒ»·Ý±¨¸æÖ¸³ö £¬BECڲƭ´Ó2016ÄêµÄÿÔÂÆ½¾ù1.1ÒÚÃÀÔªÔöÌíµ½ÁË2018ÄêµÄÿÔÂ3.01ÒÚÃÀÔª¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/north-carolina-county-lost-17-million-in-bec-scam/


2¡¢±¾ÌïÒâÍâй¶40GBÊý¾Ý £¬°üÀ¨È«Çò30ÍòÔ±¹¤Òþ˽ÐÅÏ¢


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


Çå¾²Ñо¿Ô±Justin Paine·¢Ã÷±¾ÌïµÄÒ»¸öElasticSearchÊý¾Ý¿âûÓÐÃÜÂë± £»¤ £¬µ¼ÖÂ40GBÄÚ²¿ÎĵµÐ¹Â¶¡£¸ÃÊý¾Ý¿â°üÀ¨Ô¼1.34ÒÚ·ÝÎĵµ £¬²»µ«Ð¹Â¶ÁË30ÍòÔ±¹¤µÄСÎÒ˽¼ÒÐÅÏ¢£¨ÐÕÃû¡¢µç×ÓÓʼþµÈ£© £¬»¹Ð¹Â¶Á˱¾ÌïÄÚ²¿ÍøÂçµÄÏà¹ØÐÅÏ¢ £¬ÀýÈçÖ÷»úÃû¡¢MACµØÖ·¡¢ÄÚ²¿IP¡¢²Ù×÷ϵͳ°æ±¾¡¢ÒÑÓ¦ÓõIJ¹¶¡ÒÔ¼°ÖÕ¶ËÇå¾²Èí¼þµÄ״̬µÈ¡£¸ÃÊý¾Ý¿âÔÚ¹«ÍøÉÏ̻¶ÁËÔ¼6ÌìµÄʱ¼ä £¬ÔÚ½Óµ½±¨¸æºó±¾ÌïÒѾ­¶ÔÊý¾Ý¿â¾ÙÐÐÁ˱ £»¤¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/unsecured-database-exposes-security-risks-in-hondas-network/


3¡¢À¼¿¨Ë¹ÌØ´óѧÔâºÚ¿ÍÈëÇÖ £¬Áè¼Ý1.2ÍòѧÉúÐÅÏ¢±»µÁ


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


Ó¢¸ñÀ¼Î÷±±²¿µÄÀ¼¿¨Ë¹ÌØ´óѧÔâºÚ¿ÍÈëÇÖ £¬Ñ§ÉúÒþ˽ÐÅÏ¢±»µÁ¡£ÕâÒ»ÊÂÎñ±¬·¢ÔÚ7ÔÂ19ÈÕ £¬Ó°ÏìÁË1.2ÍòÖÁ2ÍòѧÉú £¬Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·ºÍµç»°ºÅÂë¡£²¿·ÖѧÉúÊÕµ½ÁËڲƭÐÔµÄÖ§¸¶ÇëÇó £¬¾Ý±¨µÀÒÑÓÐ6ÃûѧÉúÊÜÆ­¡£¸Ã´óѧÒѾ­×÷·ÏÁËÊÜÓ°ÏìѧÉúÕË»§¶ÔӪҵϵͳµÄ»á¼ûȨÏÞ £¬²¢½ÓÄɲ½·¥ÔöǿϵͳµÄÇå¾²ÐÔ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.theregister.co.uk/2019/07/31/lancaster_uni/


4¡¢DHSÖÒÑÔСÐÍ·É»úCAN×ÜÏßÑÏÖØÎó²î £¬¿Éµ¼Ö·ɻúʧ¿Ø


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


ÃÀ¹úÁìÍÁÇå¾²²¿Ðû²¼ÁËÒ»·ÝÇå¾²¾¯±¨ £¬ÖÒÑÔСÐÍ·É»ú¿ÉÄÜÊܵ½CAN×ÜÏßÖеÄÑÏÖØÎó²îµÄÓ°Ïì¡£¿ÉÎïÆÊÎö¼û·É»úµÄ¹¥»÷Õß¿ÉÒÔ½«×°±¸ÅþÁ¬µ½CAN×ÜÏß £¬×¢ÈëÐéαÊý¾ÝÔì³Éµç×Ó×°±¸µÄ¶ÁÊý²»×¼È· £¬×îÖÕ¿ÉÄܵ¼Öº½ÐÐÔ±×öÍÉ»¯ÎóµÄÅжÏÒÔ¼°×¹»úµÈÑÏÖØÐ§¹û¡£¹¥»÷Õß¿ÉÒԸ͝µÄÊý¾Ý°üÀ¨·¢ÄîÍ·Ò£²â¶ÁÊý¡¢Ö¸ÄÏÕëºÍº½ÐÐ×ËÊÆÊý¾Ý¡¢º£°Î¸ß¶È¡¢º½ÐÐËÙÂÊÒÔ¼°AoAÊý¾ÝµÈ¡£ÃÀ¹úCISAÕýÔڱ޲߷ɻúÖÆÔìÉÌÎ§ÈÆCAN×ÜÏßϵͳʵÑé± £»¤ £¬²¢¾¡¿ÉÄÜÑÏ¿áÏÞÖÆÆä¶Ô·É»úµÄ»á¼û¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/airplane-can-bus-hacking.html


5¡¢Î÷²¿Êý¾ÝSSD¹¤¾ß°ü±£´æÁ½¸öÎó²î £¬¿Éµ¼ÖÂMitM¹¥»÷


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


Ñо¿Ö°Ô±Åû¶Î÷²¿Êý¾ÝÉÁµÏSSD¹¤¾ß°üÖеÄÁ½¸öÎó²î £¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâÁ½¸öÎó²îʵÑéÖÐÐÄÈ˹¥»÷¡£¸Ã¹¤¾ß°üÓÃÓÚ×ÊÖúÓû§¼à¿ØSSDÐÔÄÜ £¬²¢Õï¶ÏÎÊÌâºÍÍøÂç¹ÊÕÏÐÅÏ¢¡£TrustwaveÑо¿Ö°Ô±Martin RakhmanovÌåÏÖ £¬ºÚ¿Í¿ÉÒÔͨ¹ýMitM¹¥»÷À´ÇÔȡϵͳÐÅÏ¢»òͨ¹ý´¥·¢Ó¦ÓóÌÐò¸üÐÂÀ´·Ö·¢¶ñÒâÈí¼þ¡£±¾Ô³õÎ÷ÊýÐû²¼Èí¼þ¸üÐÂÐÞ¸´ÁËÕâÁ½¸öÎó²î¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/trivial-bugs-in-western-digital-ssd-utility-puts-owners-at-risk/


6¡¢Amcrest¼ÒÓÃÉãÏñÍ·ÑÏÖØÎó²î £¬¿ÉÔÊÐí¹¥»÷ÕßÔ¶³Ì¼àÌýÓû§


Ò«ÊÀÓéÀÖ-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ¡£


Çå¾²³§ÉÌTenable·¢Ã÷Amcrest IP2M-841B¼ÒÓÃÉãÏñÍ·±£´æÒ»¸öÑÏÖØÎó²î £¬¿ÉÔÊÐí¹¥»÷Õßͨ¹ýHTTPÔ¶³Ì¼àÌýÉãÏñÍ·µÄÒôƵÊäÈë¡£¸ÃÎó²î±»±ê¼ÇΪCVE-2019-3948 £¬Ó°ÏìÁËÉãÏñÍ·¹Ì¼þ°æ±¾V2.520.AC00.18.R £¬²¢ÇÒÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉʹÓᣱðµÄ £¬¸Ã²úÆ·Ò²Ò×ÊÜÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2017-7927£©¹¥»÷¡£AmcrestÒѾ­Ðû²¼Ïà¹ØÐÞ¸´²¹¶¡¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/iot-home-security-camera-allows-hackers-to-listen-in-over-http/