2019ÄêÊý¾Ýй¶µ÷²é»ã±¨£»UCä¯ÀÀÆ÷佨¸´µÄµØÖ·À¸ºýŪ·ì϶£»2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼й¶

°ä²¼¹¦·ò 2019-05-09
1¡¢Verizon°ä²¼2019ÄêÊý¾Ýй¶µ÷²é»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
Verizon°ä²¼2019ÄêÊý¾Ýй¶µ÷²é»ã±¨£¨DBIR£© £¬¸Ã»ã±¨·ÖÎöÁË86¸ö¹ú¶È²úÉúµÄ41000¶àÆðÍøÂ簲ȫÊÂÎñºÍ2000¶àÆðÊý¾Ýй¶ÊÂÎñ ¡£¸Ã»ã±¨Ö¸³ö £¬´Ó2018ÄêÆðÍ·ÔÆ´æ´¢ÅäÖÃÃýÎó¡¢BECºÍ֪ʶ²úȨ͵ÇÔ¶¼´¦ÓÚÉÏÉýÇ÷Ïò ¡£ÒÔóÒ×¼äµý»î¶¯Îª¶¯»úµÄÍøÂç¹¥»÷ÓÐËùÔö³¤ £¬ÔÚ´ÓǰµÄ12¸öÔÂÀï £¬ÓÐ1/4µÄÍøÂçÈëÇÖÓë¿úËźÍÊý¾ÝÉøÂ©ÓйØ ¡£×ÜÌå¶øÑÔ´óÎÞÊýÍøÂç¹¥»÷¶¼ÊÇÒÔ¾­¼ÃÀûÒæ×÷ΪÇý¶¯ ¡£²»ÐÒµÄÊÇ £¬ÓÐÒ»°ëµÄÆóÒµ±ØÒªÆÆ·ÑÊýÔÂÉõÖÁ¸ü³¤µÄ¹¦·òÀ´·¢ÏÖÈëÇÖÐÐΪ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://enterprise.verizon.com/resources/reports/2019-data-breach-investigations-report.pdf

2¡¢UCä¯ÀÀÆ÷±»ÆØ´æÔÚ佨¸´µÄµØÖ·À¸ºýŪ·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
°²È«×êÑÐÈËÔ±Arif Khan·¢ÏÖUCä¯ÀÀÆ÷´æÔÚÒ»¸öÉÐ佨¸´µÄµØÖ·À¸ºýŪ·ì϶ ¡£UCä¯ÀÀÆ÷Êǰ¢Àï°Í°ÍÆìϵÄUCWeb¿ª·¢µÄä¯ÀÀÆ÷ £¬ÔÚÖйúºÍÓ¡¶Å×µÓг¬¹ý5ÒÚÓû§ ¡£¸Ã·ì϶´æÔÚÓÚä¯ÀÀÆ÷µÄÓû§½çÃæ´¦ÖÃÌØÊâÄÚÖÃÖ°ÄÜ£¨¸ÃÖ°ÄÜÖ¼ÔÚ¸ÄÉÆÓû§µÄGoogleËÑË÷ÂÄÀú£©µÄ·½Ê½ £¬¿ÉÔÊÐí¹¥»÷Õß½ÚÔìµØÖ·À¸ÖÐÏÔʾµÄURL×Ö·û´® £¬ºýŪÓû§½Ó¼û¶ñÒâÍøÕ¾ ¡£¸Ã·ì϶ÉÐδ·ÖÅäCVE±àºÅ £¬UCä¯ÀÀÆ÷µÄ×îа汾12.11.2.1184ºÍUC Miniä¯ÀÀÆ÷µÄ×îа汾12.10.1.1192¾ùÊÜÓ°Ïì ¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/05/uc-browser-url-spoofing.html

3¡¢Freedom MobileÒâ±íй¶½ü500ÍòÌõÓû§¼Í¼

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
¼ÓÄôóµçÐŹ«Ë¾Freedom MobileµÄÒ»¸öÔ̺¬¿Í»§Êý¾ÝµÄElasticSearchÊý¾Ý¿âÒòÅäÖÃÃýÎóÔÚÍøÉ϶³ö £¬µ¼Ö½ü500ÍòÌõ¿Í»§¼Í¼й¶ ¡£Æ¾¾Ý°²È«×êÑÐÔ±Noam RotemºÍRan LocarµÄ·¢ÏÖ £¬¸ÃÊý¾Ý¿âÊôÓÚFreedom MobileµÄµÚÈý·½·þÎñÌṩÉÌApptium ¡£¸Ã¹«Ë¾½²»°È˰µÊ¾ £¬Ð¹Â¶ÊÂÎñÓ°ÏìÁË3ÔÂ25ÈÕÖÁ4ÔÂ15ÈÕÆÚ¼äÔÚ17¸öFreedom Mobile½»Ò×Ìü¿ªÉè»ò¸ü¸ÄÕË»§µÄÓû§ £¬Ô¼ÓÐ1.5ÍòÓû§Êܵ½Ó°Ïì ¡£Ð¹Â¶µÄÐÅÏ¢²»½öÔ̺¬Óû§µÄÐÕÃû¡¢ÓÊÏäµÈÓ×ÎÒÐÅÏ¢ £¬»¹Ô̺¬ÐÅÓþ¿¨ºÅµÈÖ§¸¶ÐÅÏ¢ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/freedom-mobile-exposed-almost-5-million-customer-records-due-to-a-misconfigured-database-fddd4855

4¡¢ºº±¤Íõ¶ùͯÉ̵êÒâ±íй¶½ü4ÍòÌõÓû§¼Í¼

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
°²È«×êÑÐÔ±Bob Diachenko·¢ÏÖºº±¤ÍõµÄÒ»¸öרΪ¶ùͯ·þÎñµÄ·¨¹úÍøÉÏÉ̵êÒâ±íй¶ÁË37900Ìõ¿Í»§¼Í¼ ¡£ÕâЩ¼Í¼Ô̺¬ÔÚÒ»¸öδÊܱ£»¤µÄElasticsearch¼¯ÈºÖÐ £¬¸ÃÊý¾Ý¿âÖÁÉÙ´Ó4ÔÂ24ÈÕÆðÍ·ÔÚÍøÉ϶³ö ¡£Ð¹Â¶µÄÐÅÏ¢²»½öÔ̺¬Óû§µÄÐÕÃû¡¢µç»°µÈPIIÐÅÏ¢ £¬»¹Ô̺¬²¿ÃÅÔ±¹¤µÄÓÊÏ䵨ַ¡¢CRMºó¶ËÈÕÖ¾µÈÐÅÏ¢ ¡£Î´Êܱ£»¤µÄElasticSearchÊý¾Ý¿âÔÚ³ÉΪ³£Ì¬ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/burger-kings-online-store-for-kids-exposes-customers-info/

5¡¢AWSÉÏδÊܱ£»¤µÄMongoDBй¶³¬¹ý2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
°²È«×êÑÐÔ±Bob DiachenkoʹÓÃShodan·¢´Ë¿ÌAmazon AWSÉÏÍйܵÄÒ»¸ö¿É¹«¿ª½Ó¼ûµÄMongoDBÊý¾Ý¿â £¬¸ÃÊý¾Ý¿âй¶Á˳¬¹ý2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼ ¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢ÓÊÏä¡¢ÊÖ»úºÅÂë¡¢Ö°ÒµºÍнˮµÈPII £¬µ«DiachenkoûÓз¢ÏÖ¸ÃÊý¾Ý¿âµÄ¹éÊô×éÖ¯ ¡£¸ÃÊý¾Ý¿âÓÚ4ÔÂ23ÈÕÆðÍ·ÔÚÍøÉ϶³ö ¡£Diachenko֪ͨÁËÓ¡¶ÈCERT £¬µ«¸ÃÊý¾Ý¿â²¢Î´Êܵ½±£»¤ £¬Ö±µ½5ÔÂ8ÈÕ·¸×ïÍÅ»ïUnistellarɾ³ýÁ˸ÃÊý¾Ý¿â²¢ÁôÏÂÁËÁªÏµ·½Ê½ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/over-275-million-records-exposed-by-unsecured-mongodb-database/

6¡¢°Í¶ûµÄĦÊÐÕþÌüºÍ²¨ÌØÏؾùÔâÀÕË÷Èí¼þ¹¥»÷

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
µÂ¿ËÈøË¹Öݲ¨ÌØÏؼ°ÂíÀïÀ¼ÖݰͶûµÄĦÊÐÕþÌü¾ùÔâÀÕË÷Èí¼þ¹¥»÷ ¡£Æ¾¾Ý°Í¶ûµÄĦÊг¤Jack YoungµÄ¹Ù·½ÉêÃ÷ £¬¸ÃÊеÄÖ÷Ìâ·þÎñ£¨¾¯Ô±¡¢Ïû·À¡¢EMSºÍ311£©ÈÔÔÚÔË×÷ £¬µ«ÒÑÈ·¶¨³ÇÊÐÍøÂçϰȾÁËÀÕË÷²¡¶¾ £¬³öÓÚÔ¤·À¸ÃÊÐÒѾ­¹Ø¹ØÁË´ó²¿ÃÅ·þÎñÆ÷ ¡£¶øÆ¾¾ÝNewsChannel 10µÄ˵·¨ £¬²¨ÌØÏØÔÚ4ÔÂ22ÈÕÔâµ½¶ñÒâÈí¼þ¹¥»÷ºó £¬ÒѾ­Éè·¨½«²¿ÃÅÍÆËã»úϵͳ³ÁÐÂÉÏÏß ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/local-authorities-in-texas-and-maryland-hit-by-ransomware/