NSAÅû¶ºÚ¿Í³£ÓÃÓÚÖ²ÈëWeb ShellµÄ·ì϶Áбí£»Ó¢¹ú3¼Ò˽ļ¹«Ë¾ÔâBECڲƭ¹¥»÷

°ä²¼¹¦·ò 2020-04-25

¡¾°²È«²¥±¨¡¿


NSAÅû¶ºÚ¿Í³£ÓÃÓÚÖ²ÈëWeb ShellµÄ·ì϶Áбí

https://www.zdnet.com/article/nsa-shares-list-of-vulnerabilities-commonly-exploited-to-plant-web-shells/


¡¾Íþвµý±¨¡¿


½©Ê¬ÍøÂçVictoryGateÕë¶ÔÀ­¶¡ÃÀÖÞ£¬ÒÑϰȾ3.5Íǫ̀É豸

https://www.welivesecurity.com/2020/04/23/eset-discovery-monero-mining-botnet-disrupted/


Ó¢¹ú3¼Ò˽ļ¹«Ë¾ÔâBECڲƭ¹¥»÷£¬Ëðʧ130ÍòÃÀÔª

https://thehackernews.com/2020/04/bec-scam-wire-transfer-money.html


¡¾Êý¾Ýй¶¡¿


ŦԼPaayÒò·þÎñÆ÷ÅäÖò»µ±Ð¹Â¶250Íò±ÊÂòÂô¼Í¼

https://www.darkreading.com/application-security/paay-misconfiguration-leaves-transaction-data-exposed/d/d-id/1337643


½¡ÉíÀûÓÃKinomap´æÔÚ·ì϶£¬Ð¹Â¶4200ÍòÓû§Êý¾Ý

https://nakedsecurity.sophos.com/2020/04/23/password-free-database-of-exercise-app-kinomap-leaks-42m-user-records/