1¡¢Equifax½«¶Ô2017ÄêÊý¾Ýй¶ÊÂÎñÖ§¸¶7ÒÚÃÀÔªºÍ½â½ð
ƾ¾Ý»ª¶û½ÖÈÕ±¨±¨Â·£¬Equifax½«Ö§¸¶½ü7ÒÚÃÀÔªµÄºÍ½â½ð£¬ÒÔ¸æÖÕÁª¹úÒµÎñίԱ»á£¨FTC£©¶Ô2017ÄêÊý¾Ýй¶ÊÂÎñµÄµ÷²é¡£Æ¾¾ÝºÍ½âºÍ̸£¬Equifax½«ÏòÃÀ¹úµ±¾ÖÖ§¸¶1.75ÒÚÃÀÔª·£¿î£¬²¢ÏòÏû·ÑÕß½ðÈÚ±£»¤¾Ö£¨CFPB£©Ö§¸¶1ÒÚÃÀÔªÃñÊ·£¿î¡£Equifax»¹½«ÉèÁ¢Ò»¸ö3ÒÚÃÀÔªµÄÅâ³¥»ù½ð£¬ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩÐÅÓþ¼à¿Ø·þÎñ£¬²¢ÔÚ±ØÒªÊ±½«½ð¶îÉýÖÁ4.25ÒÚÃÀÔª¡£×÷ΪºÍ½âºÍ̸µÄÒ»²¿ÃÅ£¬EquifaxÔ޳ɼÓÇ¿Æä°²È«´ëÊ©£¬²¢ÈõÚÈý·½¶¨ÆÚÆÀ¹ÀÆäÕþ²ß¡£
ÔÎÄÁ´½Ó£ºhttps://www.voanews.com/economy-business/report-equifax-pay-700-million-breach-settlement
2¡¢ÃÀGAOл㱨³Æ¹ú˰¾Ö°²È«´ëÊ©²»¼°£¬ÄÉ˰ÈËÊý¾Ý´æÔÚ·çÏÕ
ÃÀ¹úµ±¾ÖÎÊÔð¾Ö£¨GAO£©µÄл㱨ָ³ö£¬ÃÀ¹ú¹ú˰¾Ö£¨IRS£©Î´ÄÜÖ´ÐÐÆä¶àÄêÀ´½¨ÒéµÄ´óÁ¿°²È«½ÚÔì´ëÊ©£¬Ê¹µÃÄÉ˰ÈËÊý¾ÝºÍ²ÆÕþ»ã±¨Ãæ¶Ô¡°²»Êʵ±/δ±»¼ì²âµ½µÄʹÓᢴ۸Ļòй¶¡±·çÏÕ¡£ÔÚ¶ÔIRSϵͳ½øÐÐ2018²ÆÕþÄê¶ÈÉó¼ÆÖ®ºó£¬GAOµÃ³ö½áÂÛÒÔΪ£¬IRSÈÔÓÐ127ÏÒé´ëÊ©±ØÒª½â¾ö£¬ÆäÖÐ107ÏÒéÀ´×ÔÏÈǰµÄÉ󼯣¬´ó²¿ÃލÒéÓë½Ó¼û½ÚÔìÓйأ¬ÆäËü½¨Ò麸ÇÅäÖÃÖÎÀí¡¢Ö°Ôð·ÖÀëºÍÓ¦¼±´òËã¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/irs-improved-security-but-taxpayer-data-is-still-at-risk/
3¡¢ºÚ¿ÍÔÚÍøÉϰ䲼Լ2500¸öDiscordÓû§µÄµÇ¼ʹ´¦
ºÚ¿ÍÔÚÍøÉϰ䲼ÁËÔ¼2500¸öDiscordÓû§µÇ¼ʹ´¦µÄÁÐ±í£¬ÁбíÖÐÔ̺¬Óû§µÄµç×ÓÓʼþµØÖ·ºÍÃÜÂë¡£DiscordÊÇÒ»¸öÓÎϷ̸ÌìÆ½Ì¨£¬Æ¾¾ÝºÚ¿ÍµÄ±íÊö£¬ÕâЩʹ´¦ÊÇͨ¹ýÒ»¸öµ¥Ò»µÄ´¹µöÍøÕ¾´¹µöµÃÀ´¡£¸ÃÍøÕ¾Äܹ»ÀûÓÃDiscordµÄAPIÀ´½Ù³ÖÕâЩÕÊ»§¡£DiscordÉÐδ¶Ô´ËÊÂÎñ°ä²¼ÉêÃ÷¡£
ÔÎÄÁ´½Ó£ºhttps://www.vice.com/en_us/article/evye3a/hackers-publish-list-of-discord-email-addresses-passwords-login-credentials
4¡¢BlackBerry Cylance½¨¸´Æä·´²¡¶¾ÒýÇæÖеÄÈÆ¹ý·ì϶
°Ä´óÀûÑǰ²È«³§ÉÌSkylightÕÒµ½ÁËÒ»ÖÖ²½ÖèÀ´ÈƹýBlackBerry CylanceµÄAI·´²¡¶¾ÒýÇæ£¬¸Ã²½ÖèÊÇ´Óij¸öÊÓÆµÓÎÏ·ÖлñÈ¡×Ö·û´®£¬¶øºó¸½¼Óµ½ÒÑÖªµÄ¶ñÒâÈí¼þÖС£Cylance·´²¡¶¾ÒýÇæËÆºõ¶Ô¸ÃÓÎÏ·µÄÎļþ½øÐÐÁËÌØÊâ´¦Öá£×êÑÐÈËÔ±Ðû³Æ²âÊÔÁË384¸ö¶ñÒâÎļþ£¬»ñµÃÁ˳¬¹ý83%µÄ³É¹¦ÂÊ¡£ÎªÏàʶ¾öÕâ¸öÎÊÌ⣬CylanceÒѾ¶ÔÔÆÏµÍ³½øÐÐÁ˸üУ¬²¢½«ÔÚ½ÓÏÂÀ´µÄ¼¸ÌìÄÚÍÆ¹ãµ½¿Í»§¶Ëµã¡£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/blackberry-cylance-downplays-patches-antivirus-bypass
5¡¢Palo Alto Networks½¨¸´SSL VPNÖеÄRCE·ì϶£¬PoCÒѹ«¿ª
Palo Alto Networks½¨¸´ÆäÆóÒµGlobalProtect SSL VPNÖеÄÒ»¸öRCE·ì϶£¬¸Ã·ì϶£¨CVE-2019-1579£©Ó°ÏìÁËGlobalProtectÃÅ»§ºÍGlobalProtectÍø¹Ø½Ó¿Ú²úÆ·£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£ÊÜÓ°ÏìµÄ°æ±¾Ô̺¬PAN-OS 7.1.18¡¢8.0.11¡¢8.1.2ÒÔ¼°¸üÔçµÄ°æ±¾£¬ÓÉÓÚ×êÑÐÈËÔ±ÒѾ°ä²¼ÁËPoC´úÂ룬½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾¡£×êÑÐÈËÔ±»¹É¨Ãèµ½ÓŲ½Ê¹ÓÃÁËÒ×Êܹ¥»÷µÄ²úÆ·£¬²¢ÏòÓŲ½½øÐÐÁ˻㱨¡£
ÔÎÄÁ´½Ó£ºhttps://www.helpnetsecurity.com/2019/07/22/cve-2019-1579-poc/
6¡¢ProFTPD RCE·ì϶£¬³¬¹ý100Íǫ̀·þÎñÆ÷ÊÜÓ°Ïì
ProFTPD°ä²¼Ð°汾1.3.6£¬½¨¸´Ò»¸ö¿Éµ¼ÖÂRCEµÄ·ì϶¡£¸Ã·ì϶£¨CVE-2019- 12815£©ÓëProFTPDµÄmod_copyÄ£¿éÓйأ¬·ì϶ÔÒòÊÇmod_copyÄ£¿éµÄ×Ô½ç˵SITE CPFRºÍSITE CPTOºÅÁîûÓа´Ô¤ÆÚÅäÖù¤×÷¡£ÖÎÀíÔ±¿Éͨ¹ý½ûÓÃmod_copyÄ£¿éÀ´»º½â¸Ã·ì϶¡£Æ¾¾ÝShodanµÄËÑË÷Á˾֣¬Ä¿Ç°Óг¬¹ý100Íò¸öProFTPd·þÎñÆ÷ÉÐδÉý¼¶½¨¸´²¹¶¡¡£µÂ¹úCERT-BundÒ²Õë¶Ô¸Ã·ì϶ÏòÓû§·¢³ö¾¯±¨¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/proftpd-remote-code-execution-bug-exposes-over-1-million-servers/