2019ÄêÉϰëÄ곬¹ý34%µÄ·ì϶佨¸´£»1.45Íò¸öPulse VPNÒ×Êܹ¥»÷£»Æ»¹û½¨¸´Ô½Óü·ì϶
°ä²¼¹¦·ò 2019-08-271.2019ÄêÉϰëÄê»ã±¨µÄ·ì϶Öг¬¹ý34%佨¸´
ƾ¾ÝRisk Based Security°ä²¼µÄ¡¶2019ÄêÄêÖзì϶»ØÊ׻㱨¡·£¬2019ÄêÉϰëÄê»ã±¨µÄËùÓзì϶Öг¬¹ý34£¥£¨3771¸ö£©µÄ·ì϶佨¸´¡£´Ë±í£¬Ôڻ㱨µÄ×ܹ²11092¸ö·ì϶ÖУ¬14.7%£¨1630¸ö£©µÄ·ì϶CVSS V2µÃ·Ö³¬¹ý9.0£¬54.5£¥£¨6045¸ö£©µÄ·ì϶ÓëWebÓйأ¬Ô¼53%£¨5878¸ö£©µÄ·ì϶Äܹ»Ô¶³ÌÀûÓã¬66%µÄ·ì϶ÓëSQL×¢Èë¹¥»÷Óйأ¬Ô¼2.8%µÄ·ì϶ÓëSCADAÓйء£
ÔÎÄÁ´½Ó£º
https://pages.riskbasedsecurity.com/2019-midyear-vulnerability-quickview-report
2.Binance֤ʵºÚ¿Í´ÓµÚÈý·½ÇÔÈ¡Óû§KYCÊý¾Ý
¼ÓÃÜÇ®±ÒÂòÂôËùBinance£¨±Ò°²£©Ö¤ÊµºÚ¿Í´ÓµÚÈý·½¹©¸øÉÌÄÇÀïÇÔÈ¡ÁËÓû§KYCÊý¾Ý¡£±¾ÔÂÔçЩʱ³½ºÚ¿ÍÍþв¸ÃÂòÂôËù½«°ä²¼1ÍòÃû¿Í»§µÄKYCÊý¾Ý£¬³ý·Ç¸Ã¹«Ë¾Ö§¸¶300±ÈÌØ±Ò£¨¼ÛÖµ³¬¹ý300ÍòÃÀÔª£©µÄÊê½ð¡£±ÒºÎÔÚһƪ¹Ù·½²©¿ÍÖÐÌṩÁËÊÂÎñµ÷²éµÄ¸ü¶àϸ½Ú£¬Åúעй¶µÄ¿Í»§×ÊÁÏͼƬÀ´×ÔÓÚ2017Äê12ÔÂÖÁ2018Äê2ÔÂÆÚ¼äµÄÒ»¸öµÚÈý·½¹©¸øÉÌ¡£¾Ý±¨Â·ÕâЩKYCÊý¾ÝÒѱ»ÓÃÓÚ¸ü¸Ä»òÉèÖÃÚ²ÆÐԵıҰ²ÕË»§¡£¹ÌÈ»µ÷²éÈÔÔÚ½øÐÐÖУ¬µ«¸ÃÂòÂôËù°µÊ¾ÒѾÆðÍ·ÁªÏµËùÓÐDZÔÚÊܺ¦Õߣ¬²¢ÌṩÒþÖÔ±£»¤ºÍ¸´ÔÁìµ¼ÒÔ¼°Æ½ÉúVIP»áÔ±×ʸñ¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/08/binance-kyc-data-leak_26.html
3.³¬¹ý1.45Íò¸öPulse VPNÒ×ÊÜCVE-2019-11510¹¥»÷
BadPackets°²È«×¨¼ÒÖҸ泬¹ý1.45Íò¸öPulse Secure VPNÖÕ¶ËÒ×ÊÜCVE-2019-11510·ì϶¹¥»÷¡£×êÑÐÈËÔ±ÔÚ8ÔÂ22Èչ۲쵽Õë¶Ô¸Ã·ì϶µÄ´ó¹æÄ£É¨Ãè»î¶¯£¬Æ¾¾ÝÃÛ¹Þ¼à²âµ½µÄÊý¾Ý£¬ÕâЩɨÃèÆðÔ´ÓÚÎ÷°àÑÀµÄÖ÷»ú£¬¹¥»÷ÕßµÄÖ¸±êÊÇ»ñÈ¡¸öÈËVPNµÄ½Ó¼ûȨÏÞ¡£×êÑÐÈËÔ±·¢ÏÖ41850¸öPulse Secure VPNÖÕ¶ËÔÚ»¥ÁªÍøÉ϶³ö£¬ÆäÖÐ14528¸öÒ×Êܹ¥»÷£¬´óÎÞÊýλÓÚÃÀ¹ú£¨5010£©£¬Æä´ÎÊÇÈÕ±¾£¨1511£©¡¢Ó¢¹ú£¨830£©ºÍµÂ¹ú£¨789£©¡£ÊÜÓ°ÏìµÄÐÐÒµÔ̺¬ÃÀ¹ú¾ü·½¼°Áª¹ú¡¢Öݺʹ¦Ëùµ±¾Ö»ú¹¹¡¢¹«Á¢´óѧ¡¢Ò½Ôº¡¢µçÁ¦ÉèÊ©¡¢½ðÈÚ»ú¹¹ÒÔ¼°²Æ¸»500Ç¿ÆóÒµµÈ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/90356/hacking/pulse-secure-vpn-endpoints-cve-2019-11510.html
4.SophosLabsÖÒ¸æBaldrÒÔеķ½Ê½½øÐй¥»÷
BaldrÊÇÒ»ÖÖÐÂÐͶñÒâÈí¼þ£¬ÓÚ1Ô·ÝÔÚDeep WebÉϳõ´Î³öÏÖ£¬²¢ÔÚ6Ô·ÝÖÕ³¡Á÷ͨ¡£¸Ã¶ñÒâÈí¼þ±»ÓÃÓÚ¶Ô׼ȫÊÀ½çµÄPCÓÎÏ·Íæ¼Ò¡£Æ¾¾ÝSophosLabsµÄ»ã±¨£¬ÊÜÓ°Ïì×îÑϳÁµÄ¹ú¶ÈÔ̺¬Ó¡¶ÈÄáÎ÷ÑÇ£¨21£¥£©¡¢ÃÀ¹ú£¨10.52£¥£©¡¢°ÍÎ÷£¨14.14£¥£©¡¢¶íÂÞ˹£¨13.68£¥£©¡¢Ó¡¶È£¨8.77£¥£©ºÍµÂ¹ú£¨5.43£¥£©¡£BaldrɨÃèÖ¸±êϵͳÉϵÄËùÓÐAppDataºÍһʱÎļþ¼Ð£¬ÇÔÈ¡Ãô¸ÐÊý¾Ý²¢·¢Ë͸ø¹¥»÷Õß¡£×êÑÐÈËÔ±³Æ¹ÌÈ»BaldrÒѲ»ÔÚÊг¡ÉϳöÏÖ£¬µ«ËüÒÀÈ»¿É±»Ö®Ç°²É°ìËüµÄ·¸×ï·Ö×ÓʹÓ㬲¢ÇÒÒÀÈ»ÊÇDZÔÚµÄÍþв¡£
ÔÎÄÁ´½Ó£º
https://www.livemint.com/technology/tech-news/the-evasive-baldr-malware-may-hit-back-in-new-forms-warns-sophoslabs-1566813441778.html
5.ÐÂÀÕË÷Èí¼þNemtyÀûÓñ»µÁRDPÍ´´¦´«²¼
ÖÜÄ©ÆÚ¼ä×êÑÐÈËÔ±·¢ÏÖÒ»¸öÃûΪNemtyµÄÐÂÀÕË÷Èí¼þ£¬¹¥»÷ÕßÒªÇóÊܺ¦Õßͨ¹ýTorÍøÂçÉÏÍйܵÄÃÅ»§ÍøÕ¾Ö§¸¶0.09981±ÈÌØ±ÒµÄÊê½ð£¨Ô¼1ǧÃÀÔª£©¡£Êܺ¦ÕßÄܹ»ÉÏ´«ËûÃǵÄÅäÖÃÎļþ£¬¶øºó¹¥»÷Õß½«»áÌṩÁíÒ»¸ö´øÓÐ̸ÌìÖ°ÄܵÄÍøÕ¾Á´½ÓÒÔ¼°ÓйØÐèÒªµÄ¸ü¶àÐÅÏ¢¡£NemtyµÄ´úÂëÖÐÔ̺¬ÆÕ¾©µÄͼƬÁ´½Ó£¬»¹Ô̺¬¶Ô°²È«×êÑÐÈËÔ±·¢³öµÄÐÅÏ¢¡£¸Ã¶ñÒâÈí¼þ»¹»á²é³Ö¸±êÊÇ·ñλÓÚ¶íÂÞ˹¡¢°×¶íÂÞ˹¡¢¹þÈø¿Ë˹̹¡¢Ëþ¼ª¿Ë˹̹ºÍÎÚ¿ËÀ¼£¬µ«ÓëÆäËüÍþв·ÖÆç£¬Ëü²»»áÖÕ³¡ÔÚÕâЩµØÓòµÄ¼ÓÃܹý³Ì¡£Æ¾¾Ý×êÑÐÈËÔ±KremezµÄ˵·¨£¬NemtyÊÇͨ¹ý±»ÇÔµÄRDPÍ´´¦´«²¼µÄ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-nemty-ransomware-may-spread-via-compromised-rdp-connections/
6.Apple°ä²¼iOS 12.4.1¸üУ¬½¨²¹Ô½Óü·ì϶
Apple½ñÌì°ä²¼ÁËiOS 12.4.1¸üУ¬½¨¸´iOS 12.4°æ±¾³ÁÐÂÒýÈëµÄ°²È«·ì϶¡£¸Ã·ì϶£¨CVE-2019-8605£©±»°²È«×êÑÐÈËÔ±Pwn20wndÓÃÓÚ¿ª·¢ºÍ°ä²¼Ô½Óü¹¤¾ß¡£Æ¾¾ÝAppleÖ§³ÖÎĵµÖеÄÃèÊö£¬¸Ã·ì϶¿ÉÄܱ»¶ñÒâÀûÓ÷¨Ê½ÀÄÓ㬲¢ÇÒÒÔϵͳȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£Appleͬʱ»¹ÍÆËÍÁËwatchOS 5.3.1¡¢tvOS 12.4.1ºÍmacOS 10.14.6¸üС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/apple-releases-ios-1241-to-patch-security-flaw-behind-jailbreak/


¾©¹«Íø°²±¸11010802024551ºÅ