2019ÄêÊý¾Ýй¶µ÷²é»ã±¨£»UCä¯ÀÀÆ÷佨¸´µÄµØÖ·À¸ºýŪ·ì϶£»2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼й¶
°ä²¼¹¦·ò 2019-05-09
Verizon°ä²¼2019ÄêÊý¾Ýй¶µ÷²é»ã±¨£¨DBIR£©£¬¸Ã»ã±¨·ÖÎöÁË86¸ö¹ú¶È²úÉúµÄ41000¶àÆðÍøÂ簲ȫÊÂÎñºÍ2000¶àÆðÊý¾Ýй¶ÊÂÎñ¡£¸Ã»ã±¨Ö¸³ö£¬´Ó2018ÄêÆðÍ·ÔÆ´æ´¢ÅäÖÃÃýÎó¡¢BECºÍ֪ʶ²úȨ͵ÇÔ¶¼´¦ÓÚÉÏÉýÇ÷Ïò¡£ÒÔóÒ×¼äµý»î¶¯Îª¶¯»úµÄÍøÂç¹¥»÷ÓÐËùÔö³¤£¬ÔÚ´ÓǰµÄ12¸öÔÂÀÓÐ1/4µÄÍøÂçÈëÇÖÓë¿úËźÍÊý¾ÝÉøÂ©Óйء£×ÜÌå¶øÑÔ´óÎÞÊýÍøÂç¹¥»÷¶¼ÊÇÒÔ¾¼ÃÀûÒæ×÷ΪÇý¶¯¡£²»ÐÒµÄÊÇ£¬ÓÐÒ»°ëµÄÆóÒµ±ØÒªÆÆ·ÑÊýÔÂÉõÖÁ¸ü³¤µÄ¹¦·òÀ´·¢ÏÖÈëÇÖÐÐΪ¡£
ÔÎÄÁ´½Ó£ºhttps://enterprise.verizon.com/resources/reports/2019-data-breach-investigations-report.pdf
2¡¢UCä¯ÀÀÆ÷±»ÆØ´æÔÚ佨¸´µÄµØÖ·À¸ºýŪ·ì϶
°²È«×êÑÐÈËÔ±Arif Khan·¢ÏÖUCä¯ÀÀÆ÷´æÔÚÒ»¸öÉÐ佨¸´µÄµØÖ·À¸ºýŪ·ì϶¡£UCä¯ÀÀÆ÷Êǰ¢Àï°Í°ÍÆìϵÄUCWeb¿ª·¢µÄä¯ÀÀÆ÷£¬ÔÚÖйúºÍÓ¡¶Å×µÓг¬¹ý5ÒÚÓû§¡£¸Ã·ì϶´æÔÚÓÚä¯ÀÀÆ÷µÄÓû§½çÃæ´¦ÖÃÌØÊâÄÚÖÃÖ°ÄÜ£¨¸ÃÖ°ÄÜÖ¼ÔÚ¸ÄÉÆÓû§µÄGoogleËÑË÷ÂÄÀú£©µÄ·½Ê½£¬¿ÉÔÊÐí¹¥»÷Õß½ÚÔìµØÖ·À¸ÖÐÏÔʾµÄURL×Ö·û´®£¬ºýŪÓû§½Ó¼û¶ñÒâÍøÕ¾¡£¸Ã·ì϶ÉÐδ·ÖÅäCVE±àºÅ£¬UCä¯ÀÀÆ÷µÄ×îа汾12.11.2.1184ºÍUC Miniä¯ÀÀÆ÷µÄ×îа汾12.10.1.1192¾ùÊÜÓ°Ïì¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/05/uc-browser-url-spoofing.html
3¡¢Freedom MobileÒâ±íй¶½ü500ÍòÌõÓû§¼Í¼
¼ÓÄôóµçÐŹ«Ë¾Freedom MobileµÄÒ»¸öÔ̺¬¿Í»§Êý¾ÝµÄElasticSearchÊý¾Ý¿âÒòÅäÖÃÃýÎóÔÚÍøÉ϶³ö£¬µ¼Ö½ü500ÍòÌõ¿Í»§¼Í¼й¶¡£Æ¾¾Ý°²È«×êÑÐÔ±Noam RotemºÍRan LocarµÄ·¢ÏÖ£¬¸ÃÊý¾Ý¿âÊôÓÚFreedom MobileµÄµÚÈý·½·þÎñÌṩÉÌApptium¡£¸Ã¹«Ë¾½²»°È˰µÊ¾£¬Ð¹Â¶ÊÂÎñÓ°ÏìÁË3ÔÂ25ÈÕÖÁ4ÔÂ15ÈÕÆÚ¼äÔÚ17¸öFreedom Mobile½»Ò×Ìü¿ªÉè»ò¸ü¸ÄÕË»§µÄÓû§£¬Ô¼ÓÐ1.5ÍòÓû§Êܵ½Ó°Ï졣й¶µÄÐÅÏ¢²»½öÔ̺¬Óû§µÄÐÕÃû¡¢ÓÊÏäµÈÓ×ÎÒÐÅÏ¢£¬»¹Ô̺¬ÐÅÓþ¿¨ºÅµÈÖ§¸¶ÐÅÏ¢¡£
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/freedom-mobile-exposed-almost-5-million-customer-records-due-to-a-misconfigured-database-fddd4855
4¡¢ºº±¤Íõ¶ùͯÉ̵êÒâ±íй¶½ü4ÍòÌõÓû§¼Í¼
°²È«×êÑÐÔ±Bob Diachenko·¢ÏÖºº±¤ÍõµÄÒ»¸öרΪ¶ùͯ·þÎñµÄ·¨¹úÍøÉÏÉ̵êÒâ±íй¶ÁË37900Ìõ¿Í»§¼Í¼¡£ÕâЩ¼Í¼Ô̺¬ÔÚÒ»¸öδÊܱ£»¤µÄElasticsearch¼¯ÈºÖУ¬¸ÃÊý¾Ý¿âÖÁÉÙ´Ó4ÔÂ24ÈÕÆðÍ·ÔÚÍøÉ϶³ö¡£Ð¹Â¶µÄÐÅÏ¢²»½öÔ̺¬Óû§µÄÐÕÃû¡¢µç»°µÈPIIÐÅÏ¢£¬»¹Ô̺¬²¿ÃÅÔ±¹¤µÄÓÊÏ䵨ַ¡¢CRMºó¶ËÈÕÖ¾µÈÐÅÏ¢¡£Î´Êܱ£»¤µÄElasticSearchÊý¾Ý¿âÔÚ³ÉΪ³£Ì¬¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/burger-kings-online-store-for-kids-exposes-customers-info/
5¡¢AWSÉÏδÊܱ£»¤µÄMongoDBй¶³¬¹ý2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼
°²È«×êÑÐÔ±Bob DiachenkoʹÓÃShodan·¢´Ë¿ÌAmazon AWSÉÏÍйܵÄÒ»¸ö¿É¹«¿ª½Ó¼ûµÄMongoDBÊý¾Ý¿â£¬¸ÃÊý¾Ý¿âй¶Á˳¬¹ý2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢ÓÊÏä¡¢ÊÖ»úºÅÂë¡¢Ö°ÒµºÍнˮµÈPII£¬µ«DiachenkoûÓз¢ÏÖ¸ÃÊý¾Ý¿âµÄ¹éÊô×éÖ¯¡£¸ÃÊý¾Ý¿âÓÚ4ÔÂ23ÈÕÆðÍ·ÔÚÍøÉ϶³ö¡£Diachenko֪ͨÁËÓ¡¶ÈCERT£¬µ«¸ÃÊý¾Ý¿â²¢Î´Êܵ½±£»¤£¬Ö±µ½5ÔÂ8ÈÕ·¸×ïÍÅ»ïUnistellarɾ³ýÁ˸ÃÊý¾Ý¿â²¢ÁôÏÂÁËÁªÏµ·½Ê½¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/over-275-million-records-exposed-by-unsecured-mongodb-database/
6¡¢°Í¶ûµÄĦÊÐÕþÌüºÍ²¨ÌØÏؾùÔâÀÕË÷Èí¼þ¹¥»÷
µÂ¿ËÈøË¹Öݲ¨ÌØÏؼ°ÂíÀïÀ¼ÖݰͶûµÄĦÊÐÕþÌü¾ùÔâÀÕË÷Èí¼þ¹¥»÷¡£Æ¾¾Ý°Í¶ûµÄĦÊг¤Jack YoungµÄ¹Ù·½ÉêÃ÷£¬¸ÃÊеÄÖ÷Ìâ·þÎñ£¨¾¯Ô±¡¢Ïû·À¡¢EMSºÍ311£©ÈÔÔÚÔË×÷£¬µ«ÒÑÈ·¶¨³ÇÊÐÍøÂçϰȾÁËÀÕË÷²¡¶¾£¬³öÓÚÔ¤·À¸ÃÊÐÒѾ¹Ø¹ØÁË´ó²¿ÃÅ·þÎñÆ÷¡£¶øÆ¾¾ÝNewsChannel 10µÄ˵·¨£¬²¨ÌØÏØÔÚ4ÔÂ22ÈÕÔâµ½¶ñÒâÈí¼þ¹¥»÷ºó£¬ÒѾÉè·¨½«²¿ÃÅÍÆËã»úϵͳ³ÁÐÂÉÏÏß¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/local-authorities-in-texas-and-maryland-hit-by-ransomware/


¾©¹«Íø°²±¸11010802024551ºÅ