Rockwell AutomationµÄPLC±£´æÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£»£»£»Ó¡¶ÈZee5ÔÙ´ÎÊý¾Ýй¶ £¬£¬£¬£¬ £¬£¬Éæ¼°900ÍòÓû§µÄPII

Ðû²¼Ê±¼ä 2021-03-01

1.Rockwell AutomationµÄPLC±£´æÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î


1.jpg


Ñо¿Ö°Ô±·¢Ã÷Rockwell AutomationµÄ¿É±à³ÌÂß¼­¿ØÖÆÆ÷£¨PLC£©Öб£´æÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2021-22681 £¬£¬£¬£¬ £¬£¬CVSSÆÀ·ÖΪ10 £¬£¬£¬£¬ £¬£¬Æä±£´æÓÚLogix DesignerÈí¼þÖÐ £¬£¬£¬£¬ £¬£¬ÊÇÓÉÓÚÑéÖ¤¿ØÖÆÆ÷ͨѶµÄ˽ÓÐÃÜÔ¿±£»£»£»¤È±·¦µ¼ÖµÄ¡£¡£¡£¡£¡£¡£Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÈÆ¹ýÑéÖ¤»úÖÆÀ´ÅþÁ¬Logix¿ØÖÆÆ÷¡£¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬ £¬£¬Ê¹ÓôËÎó²îºÍµÚÈý·½¹¤¾ß»¹Äܸü¸Ä¿ØÖÆÆ÷µÄÉèÖúÍÓ¦ÓóÌÐò´úÂë¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115085/ics-scada/rockwell-automation-software-flaw.html


2.Amazon AlexaÖб£´æ¿ÉÈÆ¹ýÉóºËÁ÷³ÌµÄÎó²î


2.jpg


Ñо¿ÍŶÓÔÚÍøÂçºÍÂþÑÜʽϵͳÇå¾²×êÑлᣨNDSS£©ÉÏÌá³ö AlexaÖб£´æ¿ÉÈÆ¹ýÉóºËÁ÷³ÌµÄÎó²î¡£¡£¡£¡£¡£¡£ºÚ¿Í¿ÉʹÓøÃÎó²îÒÔí§Ò⿪·¢ÕßµÄÃûÒåÐû²¼¶ñÒâÓ¦Óà £¬£¬£¬£¬ £¬£¬ÉõÖÁÔÚÉóºËͨʺó¸ü¸Äºó¶Ë´úÂë £¬£¬£¬£¬ £¬£¬À´ÇÔÈ¡Óû§µÄÃô¸ÐÐÅÏ¢ £¬£¬£¬£¬ £¬£¬ÀýÈçµç»°ºÅÂëºÍµØµã¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ú¹ÊÍÕâÊÇÓÉÓÚAmazon²»½ÓÄÉÈκÎ×Ô¶¯»¯µÄÒªÁìÀ´¼ì²â¶ñÒâÈí¼þ £¬£¬£¬£¬ £¬£¬¶øÒÀÀµÓÚÈ˹¤ÉóºËÔòÈÝÒ×·ºÆðÈËΪ¹ýʧ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/02/alert-malicious-amazon-alexa-skills-can.html


3.Ó¡¶ÈZee5ÔÙ´ÎÊý¾Ýй¶ £¬£¬£¬£¬ £¬£¬Éæ¼°900ÍòÓû§µÄPII


3.jpg


Ñо¿Ö°Ô±Rajshekhar Rajaharia·¢Ã÷Zee5Ôٴα¬·¢Êý¾Ýй¶ÊÂÎñ £¬£¬£¬£¬ £¬£¬Éæ¼°900ÍòÓû§µÄPII¡£¡£¡£¡£¡£¡£Zee5ÊÇÓ¡¶ÈOTTƽ̨ £¬£¬£¬£¬ £¬£¬ÓµÓÐÁè¼Ý1.5ÒÚÓû§¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñй¶ÁËÁè¼Ý900ÍòÓû§µÄСÎÒ˽¼ÒÊý¾Ý £¬£¬£¬£¬ £¬£¬°üÀ¨Óû§µÄÃû×Ö¡¢µç×ÓÓʼþµØµã¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢Óû§ÃûÒÔ¼°ÉϴθüÐÂʱ¼äµÄ¼Í¼ʱ¼ä´Á¡£¡£¡£¡£¡£¡£ÕâÊÇZee5µÚ¶þ´ÎÐû²¼ÓйØÊý¾Ýй¶µÄÐÂÎÅ £¬£¬£¬£¬ £¬£¬µÚÒ»´Î±¬·¢È¥Äê5ÔÂ·Ý £¬£¬£¬£¬ £¬£¬ÔøÐ¹Â¶ÁËÉÏǧ¸öÓû§µÄÓû§ÃûºÍ´¿Îı¾ÃÜÂë¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://techdator.net/zee5-data-breach-pii-of-9-million-zee5-users-allegedly-leaked-online/


4.½üÆÚµÄAOLÓʼþ´¹ÂڻÕë¶ÔÖÐÍíÄêÈËÇÔȡƾ֤


4.jpg


BleepingComputerÖÒÑÔ½üÆÚµÄAOLÓʼþ´¹ÂڻÕë¶ÔÖÐÍíÄêÈËÇÔȡƾ֤¡£¡£¡£¡£¡£¡£µ±´ó´ó¶¼ÈËʹÓÃGmail¡¢Outlook»òÆäËûÏÖ´úÃâ·ÑÓʼþЧÀÍʱ £¬£¬£¬£¬ £¬£¬Ðí¶àÍíÄêÈËÈÔÔÚʹÓÃAOL¡£¡£¡£¡£¡£¡£¶ø´Ë´Î´¹ÂڻÖ÷ÒªÕë¶ÔÕâһȺÈË £¬£¬£¬£¬ £¬£¬ÒÔÓÊÏ佫ÔÚ3ÌìÄڹرÕΪÖ÷Ìâ £¬£¬£¬£¬ £¬£¬ÓÕʹÓû§ÔÚ´¹ÂÚÒ³ÃæµÇ¼ÕÊ»§À´¾ÙÐÐÑéÖ¤ £¬£¬£¬£¬ £¬£¬ÇÔÈ¡Æäƾ֤¡£¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬ £¬£¬Ïà±ÈÓÚÕë¶ÔÆäËûЧÀÍ£¨ÀýÈçGmail£©µÄ»î¶¯ £¬£¬£¬£¬ £¬£¬´Ë´Î¹¥»÷¸üÈÝÒ×ͨ¹ýAOLµÄµç×ÓÓʼþ¹ýÂËÆ÷¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/beware-aol-phishing-email-states-your-account-will-be-closed/


5.FortiGuard LabsÐû²¼2020ÄêÍþÐ²Ì¬ÊÆµÄ»ØÊ×±¨¸æ


5.jpg


FortiGuard LabsÐû²¼ÁË2020ÄêÍþÐ²Ì¬ÊÆµÄ»ØÊ×±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö £¬£¬£¬£¬ £¬£¬Õë¶ÔÎïÁªÍø£¨IoT£©×°±¸£¨ÀýÈç¼ÒÍ¥ÓéÀÖϵͳ¡¢¼Òͥ·ÓÉÆ÷ºÍÅþÁ¬µÄÇå¾²×°±¸£©µÄ¹¥»÷³ÉΪÖ÷ÒªÍþв£»£»£»¹©Ó¦Á´¹¥»÷³ÉΪ½¹µã £¬£¬£¬£¬ £¬£¬SolarWinds¹¥»÷ÊÂÎñ½«¸ÃÎÊÌâÍÆÏòÁËи߶È£»£»£»ÀÕË÷Èí¼þ»î¶¯ÔÚ2020ÄêϰëÄêÔöÌíÁËÆß±¶ £¬£¬£¬£¬ £¬£¬Ö÷ҪĿµÄÐÐÒµ°üÀ¨Ò½ÁƱ£½¡¡¢×¨ÒµÐ§À͹«Ë¾¡¢ÏûºÄÕßЧÀ͹«Ë¾¡¢¹«¹²²¿·ÖºÍ½ðÈÚЧÀ͹«Ë¾¡£¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.fortinet.com/blog/industry-trends/fortiguard-labs-global-threat-landscape-report-2021


6.DragosÐû²¼2020ÄêICSÍøÂçÇå¾²µÄ»ØÊ×±¨¸æ


6.jpg


DragosÐû²¼ÁË2020ÄêICSÍøÂçÇå¾²µÄ»ØÊ×±¨¸æ £¬£¬£¬£¬ £¬£¬Õë¶ÔICS/OTµÄÍøÂçÍþв¡¢Îó²î¡¢ÆÀ¹ÀºÍÊÂÎñÏìÓ¦¾ÙÐÐÁËÆÊÎö¡£¡£¡£¡£¡£¡£2020ÄêÓÐ703¸öICS/OTÎó²î £¬£¬£¬£¬ £¬£¬±È2019ÄêÔöÌíÁË29£¥¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÁËËĸöÖ÷ÒªÕë¶ÔÄÜÔ´ºÍÖÆÔìÒµµÄÐÂICSÍÅ»ï £¬£¬£¬£¬ £¬£¬»®·ÖÊÇKAMACITE¡¢STIBNITE¡¢TALONITEºÍVANADINITE¡£¡£¡£¡£¡£¡£±¨¸æ»¹Ìá³öÁËÔöÇ¿ICSÇéÐÎÇå¾²ÐÔ½¨Òé £¬£¬£¬£¬ £¬£¬°üÀ¨ÔöÌíOTÍøÂçµÄ¿É¼ûÐÔ¡¢È·¶¨Ö÷ÒªÐÔ¼°ÓÅÏȼ¶¡¢ÔöÇ¿ÊÂÎñÏìÓ¦ÄÜÁ¦¡¢ÍøÂç¸ôÀëÑéÖ¤ºÍÇå¾²Ö¤ÊéÖÎÀíµÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.dragos.com/year-in-review/