ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ49ÖÜ
°ä²¼¹¦·ò 2021-12-06>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
±¾Öܹ²ÊÕ¼°²È«·ì϶58¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇDell Emc Streaming Data Platform sql×¢Èë·ì϶£»£»EFM ipTIME C200 IP CameraËÁÒâºÅÁîÖ´Ðзì϶£»£»ohmyzsh rand-quoteºÍhitokoto²å¼þËÁÒâºÅÁîÖ´Ðзì϶£»£»Open Solutions For Education openSIS GetStuListFnc.php SQL×¢Èë·ì϶£»£»Sunnet eHRD½Ó¼û½ÚÖÆ´úÂëÖ´Ðзì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇTP-LinkÐÞ¸´ÆäWi-Fi 6·ÓÉÆ÷ÖеĴúÂëÖ´Ðзì϶£»£»IEEE°ä²¼2022Äê¼°½«À´Ê®Äê¹Ø¼ü¼¼ÊõµÄÔ¤²â»ã±¨£»£»ÈÕ±¾µçÆ÷¹«Ë¾ËÉÏÂÈ·Èϳ¤´ï4¸öÔÂÖ®¾ÃÊý¾Ýй¶ÊÂÎñ£»£»°µÍøÊг¡CannazonÔâµ½´ó¹æÄ£DDoS¹¥»÷ºóÓÀÔ¶¹Ø±Õ£»£»KasperskyÅû¶APT37ÀûÓÃChinotto¹¥»÷º«¹úµÄ»î¶¯¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
>ÖØÒª°²È«·ì϶Áбí
1. Dell Emc Streaming Data Platform sql×¢Èë·ì϶
Dell Emc Streaming Data Platform´æÔÚsql×¢Èë·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄSQLÒªÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐËÁÒâ´úÂë¡£
https://www.dell.com/support/kbdoc/zh-cn/000193697/dsa-2021-205-dell-emc-streaming-data-platform-security-update-for-third-party-vulnerabilities
2. EFM ipTIME C200 IP CameraËÁÒâºÅÁîÖ´Ðзì϶
EFM ipTIME C200 IP CameraÓëipTIME NASͬ²½Ê±´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
http://iptime.com/iptime/?page_id=126&diffid=&dfsid=19&dftid=541
3. ohmyzsh rand-quoteºÍhitokoto²å¼þËÁÒâºÅÁîÖ´Ðзì϶
ohmyzsh rand-quoteºÍhitokoto²å¼þ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://github.com/ohmyzsh/ohmyzsh/commit/72928432
4. Open Solutions For Education openSIS GetStuListFnc.php SQL×¢Èë·ì϶
Open Solutions For Education openSIS GetStuListFnc.php´æÔÚsql×¢Èë·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄSQLÒªÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐËÁÒâ´úÂë¡£
https://github.com/OS4ED/openSIS-Classic/issues/202
5. Sunnet eHRD½Ó¼û½ÚÖÆ´úÂëÖ´Ðзì϶
Sunnet eHRDδÕýÈ·ÏÞ¶ÈÀ´×ÔδÊÚȨ½ÇÉ«µÄ×ÊÔ´½Ó¼û£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://www.twcert.org.tw/tw/cp-132-5354-0aac0-1.html
>ÖØÒª°²È«ÊÂÎñ×ÛÊö
1¡¢¡¢TP-LinkÐÞ¸´ÆäWi-Fi 6·ÓÉÆ÷ÖеĴúÂëÖ´Ðзì϶
Resecurity×êÑÐÈËÔ±TP-LinkµÄÉ豸ÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£ÊÜÓ°ÏìÉ豸µÄÐͺÅΪTL-XVR1800L£¬ÊÇÆóÒµ¼¶AX1800˫ƵǧÕ×Wi-Fi 6ÎÞÏßVPN·ÓÉÆ÷¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÆëÈ«½ÚÖÆÉ豸»òÇÔÈ¡Ãô¸ÐÊý¾Ý£¬Ëü¿ÉÄÜ»¹´æÔÚÓÚͳһϵÁÐµÄÆäËûÉ豸ÖС£ResecurityÔÚ10ÔÂÉÏÑ®·¢ÏÖÁËÕë¶Ô¸ÃÉ豸µÄ¹¥»÷»î¶¯£¬²¢ÓÚ11ÔÂ19ÈÕ֪ͨÁËTP-Link£¬TP-LinkÔÚµÚ¶þÌìÈ·ÈÏÁ˸÷ì϶²¢³Ðŵ»áÔÚÒ»ÖÜÄÚ°ä²¼²¹¶¡¡£
ÔÎÄÁ´½Ó£º£º£º
https://securityaffairs.co/wordpress/125016/hacking/0-day-tp-link-wi-fi-6.html
2¡¢¡¢IEEE°ä²¼2022Äê¼°½«À´Ê®Äê¹Ø¼ü¼¼ÊõµÄÔ¤²â»ã±¨
IEEEÔÚ½üÆÚ°ä²¼Á˽«À´¹Ø¼ü¼¼ÊõµÄÔ¤²â»ã±¨¡£»ã±¨µ÷²éÁËÀ´×ÔÃÀ¹ú¡¢¡¢Ó¢¹ú¡¢¡¢Öйú¡¢¡¢Ó¡¶ÈºÍ°ÍÎ÷µÄ350λCTO¡¢¡¢CIOºÍIT×ܼ࣬Ԥ²âÁË2022Äê×îÖØÒªµÄ¼¼Êõ¡¢¡¢À´ÄêÊܼ¼ÊõÓ°Ïì×î´óµÄÐÐÒµÒÔ¼°½«À´Ê®ÄêµÄ¼¼ÊõÇ÷Ïò¡£21%µÄÊÜ·ÃÕßÒÔΪÈËΪÖÇÄܺͻúеѧϰ½«³ÉΪÃ÷Äê×îÖØÒªµÄ¼¼Êõ£¬Æä´ÎÎªÔÆÍÆËã(20%)ºÍ5G(17%)£»£»25%µÄÈËÒÔÎªÖÆ×÷Òµ»áÊÇ2022ÄêÊܼ¼ÊõÓ°Ïì×î´óµÄÐÐÒµ£¬Æä´ÎΪ½ðÈÚ·þÎñ(19%)¡¢¡¢Ò½ÁƱ£½¡(16%)ºÍÄÜÔ´(13%)ÐÐÒµ¡£
ÔÎÄÁ´½Ó£º£º£º
https://transmitter.ieee.org/impact-of-technology-2022/
3¡¢¡¢ÈÕ±¾µçÆ÷¹«Ë¾ËÉÏÂÈ·Èϳ¤´ï4¸öÔÂÖ®¾ÃÊý¾Ýй¶ÊÂÎñ
ÈÕ±¾¿ç¹ú¹«Ë¾ËÉÏÂPanasonicÔÚÉÏÖÜÎå°ä²¼ÉêÃ÷£¬È·ÈÏÆä²¿ÃÅÊý¾ÝÒѾй¶¡£¹¥»÷²úÉúÔÚ6ÔÂ22ÈÕ£¬µ«Ö±µ½11ÔÂ11Èղű»·¢ÏÖ¡£¾¹ýÄÚ²¿µ÷²éÈ·¶¨£¬¹¥»÷ÕßÒÑÔÚÕâ4¸öÔÂÖнӼûÁË·þÎñÆ÷ÉϵIJ¿ÃÅÊý¾Ý¡£¸Ã¹«Ë¾Ã»ÓÐÌṩÆäËü¾ßÌåÐÅÏ¢£¬µ«ÈÕ±¾ÐÂÎÅÍøÕ¾MainichiºÍNHK±¨µÀ³Æ£¬¹¥»÷ÕßÒѾ»ñµÃÁ˹«Ë¾¼¼Êõ¡¢¡¢ºÏ×÷ͬ°é¼°¹«Ë¾Ô±¹¤µÈÓйØÐÅÏ¢¡£ÔçÔÚ2020Äê11Ô£¬ËÉÏÂÓ¡¶È·Ö¹«Ë¾ÔøÒòÍøÂç¹¥»÷й¶Á˲ÆÕþµÈÓйØÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º£º£º
https://www.bleepingcomputer.com/news/security/panasonic-discloses-data-breach-after-network-hack/
4¡¢¡¢°µÍøÊг¡CannazonÔâµ½´ó¹æÄ£DDoS¹¥»÷ºóÓÀÔ¶¹Ø±Õ
2021Äê11ÔÂ23ÈÕ£¬°µÍøÊг¡CannazonµÄÖÎÀíÔ±°ä·¢½«ÓÀÔ¶¹Ø±Õ¸ÃÍøÕ¾¡£¾ÝϤ£¬¸ÃÍøÕ¾ÔÚ11Ô³õÔâµ½ÁË´ó¹æÄ£DDoS¹¥»÷£¬ÖÎÀíԱͨ¹ýÏ÷¼õ¶©µ¥ÊýÁ¿ºÍ¹Ø±Õ²¿ÃÅϵͳÒÔ»º½âÎÊÌâ¡£µ«ÕâÔÚÉçÇøÖÐÒýÆðÁ˺䶯£¬Óû§²»°²ÕâÊÇÒ»³¡Í˳öȦÌס£ÖÎÀíÔ±ÔÚ°ä²¼¹Ø±Õ¹«¸æÊ±£¬¶ÔÓÚÕâÖÖ´¦Öò½Ö谵ʾǸÒ⣬³ÆÃ»Óй«¿ª¹¥»÷»î¶¯ÊÇΪÁ˱£»£»¤Óû§ºÍÉçÇø£¬ÒÔÔ¤·À¹©¸øÉÌÊÔͼ·¢Æð¼ÓÃÜÇ®±ÒÍ˳öȦÌס£
ÔÎÄÁ´½Ó£º£º£º
https://www.bleepingcomputer.com/news/security/dark-web-market-cannazon-shuts-down-after-massive-ddos-attack/
5¡¢¡¢KasperskyÅû¶APT37ÀûÓÃChinotto¹¥»÷º«¹úµÄ»î¶¯
KasperskyÔÚ11ÔÂ29ÈÕÅû¶³¯ÏʺڿÍ×éÖ¯APT37£¨ÓÖ³ÆScarCruft»òTemp.Reaper£©ÔÚ½üÆÚµÄ¹¥»÷»î¶¯¡£ScarCruft´Ó2012ÄêÆðÍ·»îÔ¾£¬ÖØÒªÕë¶Ôº«¹úµÄ¹Ù·½»ú¹¹»ò¹«Ë¾¡£Õâ´Î»î¶¯ÆðÍ·ÓÚ2021Äê8Ô£¬³õʼϰȾý½éÊÇÓã²æÊ½´¹µö»î¶¯£¬Ö®ºóÀûÓÃIEä¯ÀÀÆ÷ÖеÄÁ½¸ö·ì϶ÔÚº«¹úµÄÍøÕ¾ÖÐ×°ÖÃ×Ô½ç˵¶ñÒâÈí¼þBLUELIGHT£¬ÌáÒéË®¿Ó¹¥»÷¡£»£»î¶¯»¹ÀûÓÃÁ˶ñÒâÈí¼þChinotto£¬ËüÓµÓÐÕë¶ÔPowerShell¡¢¡¢WindowsºÍAndroidµÄ¶à¸ö±äÌå¡£
ÔÎÄÁ´½Ó£º£º£º
https://securelist.com/scarcruft-surveilling-north-korean-defectors-and-human-rights-activists/105074/


¾©¹«Íø°²±¸11010802024551ºÅ