CitrixËùÓвúÆ·±£´æ´úÂëÖ´ÐÐÎó²î£¨CVE-2019-19781£©£»£»£»£»ÓÎÏ·¿ª·¢ÉÌZyngaй¶½ü1.73ÒÚÓû§ÕË»§ÐÅÏ¢

Ðû²¼Ê±¼ä 2019-12-24


1.ÓÎÏ·¿ª·¢ÉÌZyngaй¶½ü1.73ÒÚÓû§ÕË»§ÐÅÏ¢


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÓÎÏ·¿ª·¢ÉÌZyngaÔÚ9Ô·ÝÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬ £¬½ü1.73ÒÚ¸öÓû§ÃûºÍÃÜÂëй¶¡£¡£¡£¡£¡£¡£ËäÈ»ZyngaÓÚ9ÔÂβÈÏ¿ÉÁËÕâÒ»ÊÂÎñ£¬£¬£¬£¬ £¬µ«Êý¾ÝÐ¹Â¶Í¨ÖªÍøÕ¾HaveIBeenPwnedÏÖÔÚÍøÂçµ½ÁËÓйØÊÜÓ°ÏìÕË»§ÊýÄ¿µÄ¹Ù·½Êý×Ö¡£¡£¡£¡£¡£¡£Æ¾Ö¤¸ÃÍøÕ¾µÄ¸üУ¬£¬£¬£¬ £¬¹²ÓÐ1.729ÒÚ¸ö²î±ðµÄµç×ÓÓʼþµØµãÒÔ¼°Óû§ÃûºÍÃÜÂëÔڴ˴ι¥»÷ÖÐй¶£¬£¬£¬£¬ £¬ºÃÐÂÎÅÊÇÕâЩÃÜÂëÒÔ¼ÓÑεÄSHA-1É¢ÁÐÐÎʽ´æ´¢£¬£¬£¬£¬ £¬Ê¹ÆäÄÑÒÔ±»ÆÆ½â¡£¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/zynga-breach-hit-173-million/


2.ST Logisticsй¶Լ2400ÃûMindefºÍSAFÖ°Ô±ÐÅÏ¢


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÐÂ¼ÓÆÂ¹ú·À²¿£¨Mindef£©ºÍÎä×°²½¶Ó£¨SAF£©Ô¼2400ÃûÊÂÇéÖ°Ô±µÄСÎÒ˽¼ÒÊý¾Ý¿ÉÄÜÔÚ´¹ÂÚ¹¥»÷ÖÐй¶¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÓëSAFºÍMindefµÄ˽È˹©Ó¦ÉÌST LogisticsÓйØ£¬£¬£¬£¬ £¬ST LogisticsÖ÷ÒªÌṩµÚÈý·½ºóÇÚЧÀÍ£¬£¬£¬£¬ £¬ÀýÈçeMartÁãÊÛºÍ×°±¸Ð§ÀÍ¡£¡£¡£¡£¡£¡£MindefÔÚÒ»·ÝÉùÃ÷ÖÐÌåÏÖй¶µÄÊý¾Ý°üÀ¨ÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢ÁªÏµµç»°¡¢µç×ÓÓʼþºÍסլµØµãµÄ×éºÏ¡£¡£¡£¡£¡£¡£ST LogisticsÌåÏÖÊÂÎñ±¬·¢µÄÔµ¹ÊÔ­ÓÉÊÇÆäÔ±¹¤Ôâµ½´¹ÂÚÓʼþ¹¥»÷£¬£¬£¬£¬ £¬µ«Î´Ìṩ¹¥»÷±¬·¢µÄʱ¼äµÈÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.straitstimes.com/singapore/personal-data-of-2400-mindef-saf-staff-may-have-been-leaked


3.Champagne Bakery Cafe²ÍÌüÔâµ½PoS¶ñÒâÈí¼þ¹¥»÷


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Champagne French Bakery Caf¨¦²ÍÌüÔâµ½PoS¶ñÒâÈí¼þ¹¥»÷£¬£¬£¬£¬ £¬¿Í»§µÄÐÅÓÿ¨Êý¾Ý±»ÇÔ¡£¡£¡£¡£¡£¡£Æ¾Ö¤¸Ã²ÍÌüÐû²¼µÄÊý¾Ýй¶֪ͨ£¬£¬£¬£¬ £¬ÔÚ2019Äê2ÔÂ13ÈÕµ½2019Äê9ÔÂ27ÈÕµÄʱ¼ä¶ÎÄÚ£¬£¬£¬£¬ £¬ÓÐ8¼Ò²ÍÌüµÄPoSϵͳѬȾÁ˶ñÒâÈí¼þ£¬£¬£¬£¬ £¬ÏêϸµÄѬȾʱ¼ä¹æÄ£Òò²ÍÌü¶øÒì¡£¡£¡£¡£¡£¡£ÆäÖÐ7¼Ò²ÍÌüѬȾµÄ¶ñÒâÈí¼þÔÚ3Ô·ݵÄijЩÐÇÆÚûÓÐÀֳɻñÈ¡Óû§ÐÅÓÿ¨Êý¾Ý¡£¡£¡£¡£¡£¡£¿£¿ÉÄܱ»ÇÔµÄÊý¾Ý°üÀ¨³Ö¿¨ÈËÐÕÃû¡¢¿¨ºÅ¡¢ÓÐÓÃÆÚºÍÄÚ²¿ÑéÖ¤Â룬£¬£¬£¬ £¬Ä³Ð©ÇéÐÎÏÂÒ²¿ÉÄܲ»°üÀ¨³Ö¿¨ÈËÐÕÃû¡£¡£¡£¡£¡£¡£¸Ã²ÍÌüÒÑ´ÓËùÓÐÊÜѬȾµÄËùÔÚɨ³ýÁ˶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.champagnebakery.com/champagne-french-bakery-cafe-substitute-notice/


4.RavnAirº½¿Õ¹«Ë¾ÔâÍøÂç¹¥»÷±»ÆÈ×÷·Ï6´Îº½°à


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


RavnAirº½¿Õ¹«Ë¾ÔÚÔâµ½ÍøÂç¹¥»÷Ö®ºóÓÚÖÜÁù±»ÆÈ×÷·ÏÖÁÉÙ6´Î°¢À­Ë¹¼Óº½°à£¬£¬£¬£¬ £¬Ó°ÏìÁËԼĪ260ÃûÂÿ͡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬ £¬ÍøÂç¹¥»÷ÆÈʹÆä¶Ï¿ªÁËDash 8·É»úµÄά»¤ÏµÍ³ºÍºó±¸ÏµÍ³µÄÅþÁ¬£¬£¬£¬£¬ £¬¸ÃµØÇø±»ÆÈ×÷·ÏÁËËùÓÐÉæ¼°Dash 8·É»úµÄº½°à¡£¡£¡£¡£¡£¡£µ±ÌìÏÂÖçÆäº½°àʱ¼ä±íÒѻָ´Õý³£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÒÑÏòFBIºÍÆäËüÊÓ²ìÕþ¸®±¨¸æÁËÕâÒ»ÊÂÎñ£¬£¬£¬£¬ £¬²¢ÕÐÆ¸ÁËÒ»¼ÒÍøÂçÇå¾²¹«Ë¾À´»Ö¸´ÏµÍ³¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95530/cyber-crime/ravnair-alaska-airline-cyberattack.html


5.Ñо¿ÍŶÓÅû¶Õë¶Ô¼ÓÄôóÒøÐеĴó¹æÄ£´¹Âڻ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


½üÆÚCheck Point¼ì²âµ½Ò»¸öð³ä¼ÓÄôó»Ê¼ÒÒøÐУ¨RBC£©Ïò¶à¸ö×éÖ¯ºÍÊܺ¦Õß·¢ËͶñÒâPDF¸½¼þµÄ´¹ÂÚÓʼþ¹¥»÷¡£¡£¡£¡£¡£¡£¶ÔÆä¶ñÒâÑù±¾¾ÙÐÐÊÓ²ìºó·¢Ã÷£¬£¬£¬£¬ £¬¸Ã¹¥»÷»î¶¯Ö÷ÒªÕë¶Ô¼ÓÄôóÒøÐÐÓû§£¬£¬£¬£¬ £¬²¢ÇÒÖÁÉÙÒѾ­Ò»Á¬ÁËÁ½Äê¡£¡£¡£¡£¡£¡£×ÜÌå¶øÑÔ£¬£¬£¬£¬ £¬Ñо¿Ö°Ô±¼ì²âµ½300¶à¸öÀàËÆµÄ´¹ÂÚÓòÃû£¬£¬£¬£¬ £¬ÕâЩÓòÃûÍйÜÁËÕë¶ÔÒÔÏÂÒøÐеĴ¹ÂÚÍøÕ¾£º¼ÓÄôó»Ê¼ÒÒøÐС¢·áÒµÒøÐС¢ÃÉÌØÀû¶ûÒøÐС¢¼ÓÄôóµÛ¹úÉÌÒµÒøÐС¢ÃÀ¹úÔËͨ¡¢¸»¹úÒøÐеȡ£¡£¡£¡£¡£¡£ÏêϸIoCÖ¸±êÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://research.checkpoint.com/2019/canadian-banks-targeted-in-a-massive-phishing-campaign/


6.CitrixËùÓвúÆ·±£´æ´úÂëÖ´ÐÐÎó²î£¨CVE-2019-19781£©


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Ç徲ר¼ÒMikhail KlyuchnikovÔÚCitrix Application Delivery ControllerºÍCitrix Gateway²úÆ·Öз¢Ã÷Ò»¸öÑÏÖØµÄ´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬ £¬¸ÃÎó²î£¨CVE-2019-19781£©Ê¹158¸ö¹ú¼ÒµÄÁè¼Ý8Íò¼Ò¹«Ë¾ÃæÁÙΣº¦¡£¡£¡£¡£¡£¡£ÓÉÓÚʹÓøÃÎó²îµÄ¹¥»÷ÕßÎÞÐèÉí·ÝÑéÖ¤¼´¿É»á¼û¹«Ë¾µÄÄÚ²¿ÍøÂ磬£¬£¬£¬ £¬Òò´Ë¸ÃÎó²îÓÈÆäΣÏÕ¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓøÃÎó²î¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£Æ¾Ö¤Citrix£¬£¬£¬£¬ £¬¸ÃÎó²îÓ°ÏìÁËËùÓÐÊÜÖ§³ÖµÄ²úÆ·°æ±¾Ç徲̨£¬£¬£¬£¬ £¬Ö»¹ÜCitrixÉÐδÐû²¼Ð¹̼þÀ´½â¾ö¸ÃÎÊÌ⣬£¬£¬£¬ £¬µ«¸Ã¹«Ë¾ÒÑÐû²¼ÁËÒ»Ì×Õë¶Ô×ÔÁ¦ÏµÍ³ºÍ¼¯ÈºµÄ»º½â²½·¥£¬£¬£¬£¬ £¬²¢Ç¿ÁÒ½¨ÒéÊÜÓ°ÏìµÄ¿Í»§½ÓÄÉËüÃÇ¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-citrix-flaw-may-expose-thousands-of-firms-to-attacks/