˼¿Æ°²È«¸üн¨¸´ASAºÍFTDÖжà¸ö³ÁÒª·ì϶£»1.15ÒÚ°Í»ù˹̹µç»°Óû§µÄ¾ßÌåÐÅϢй¶
°ä²¼¹¦·ò 2020-05-091.˼¿Æ°ä²¼°²È«¸üУ¬½¨¸´¶à¸ö²úÆ·ÖеÄ12¸ö·ì϶
˼¿Æ°ä²¼Á˰²È«¸üУ¬½¨¸´ÁËÆä×ÔÊÊÓ¦°²È«É豸Èí¼þ£¨ASA£©ºÍFirepowerÍþв·ÀÓùÈí¼þ£¨FTD£©ÖеÄ12¸ö·ì϶£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶ÌáÒéһϵÁй¥»÷£¬ÀýÈçDoS¹¥»÷¡¢Ðá̽Ãô¸ÐÊý¾ÝµÈ¡£Õâ´Î½¨¸´µÄ×îÑϳÁµÄ·ì϶£¨CVE-2020-3187£¬CVSS 9.1£©ÔÚASAºÍFTDµÄWeb·þÎñ½Ó¿ÚÖУ¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÌáÒéĿ¼±éÀú¹¥»÷¡£»¹ÓÐASAºÍFTDÖÐµÄÆäËû·ì϶£¬Ô̺¬·ì϶£¨CVE-2020-3125£©ÔÊÐí¹¥»÷Õß¼ÙÒâKerberosÃÜÔ¿·Ö·¢ÖÐÐÄ£¨KDC£©¡¢»Ø¾ø·þÎñ·ì϶£¨CVE-2020-3298¡¢CVE-2020-3191¡¢CVE-2020-3254ºÍCVE-2020-3196£©¡¢ÄÚ´æÐ¹Â©·ì϶£¨CVE-2020-3195£©¡¢ÐÅϢй¶·ì϶£¨CVE-2020-3259£©µÈ¡£Áí±í£¬Õâ´Î°²È«¸üл¹½¨¸´ÁË22¸öÖеÍΣ·ì϶¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/cisco-fixes-high-severity-flaws-in-firepower-security-software-asa/155568/
2.ÃÀ¹ú¹«Ë¾SparboeÔâMAZEÍÅ»ïÀÕË÷²¡¶¾¹¥»÷£¬Êý¾Ýй¶
ºÚ¿Í×éÖ¯MAZE°ä·¢ÆäÓÚ5ÔÂ1ÈÕ¶ÔÃÀ¹ú¹«Ë¾SparboeÌáÒéÁËÀÕË÷²¡¶¾¹¥»÷£¬²¢°ä²¼ÁËÔ̺¬ÓÐ17¸öÎļþ¼ÐµÄzipÎļþ£¬Ðû³Æ¸ÃÊý¾ÝÊÇ´ÓSparboeµÄϵͳÖÐÇÔÈ¡µÄ¡£¸ÃÎļþ¼ÐÖÐÓÐÏÖÈκÍǰ¹ÍÔ±ÐÅÏ¢¡¢¿â´æ¡¢ÓöȻ㱨¡¢ÖÐÉ˻㱨¡¢Í£¿¿¹¦·ò±íºÍÆäËûÊý¾Ý¡£Ä¿Ç°¸ÃzipÎļþ±»¶¨ÃûΪ¡° part1¡±£¬ÒÔʾMAZE´ÓSparboe¹«Ë¾ÇÔÈ¡Á˸ü¶àµÄÊý¾Ý¡£Ä¿Ç°£¬Sparboe ¹«Ë¾ÉÐδ¶Ô´ËÊÂ×ö³ö»Ø¸´£¬Î´È·ÈÏ»ò·ñ¶¨Õâ´ÎµÄÀÕË÷Èí¼þ¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/maze-claims-ransomware-attack-on-us/
3.Ô¼»áÀûÓÃMobiFriends´æÔÚ·ì϶£¬Ð¹Â¶360ÍòÓû§ÐÅÏ¢
Ô¼»áÀûÓÃMobiFriends´æÔÚ·ì϶£¬Æä3688060Óû§µÄÓ×ÎÒ¾ßÌåÐÅϢй¶¡£¾ÝϤ£¬ÕâЩÊý¾ÝÊÇ2019Äê1ÔºڿÍÀûÓÃÁËÍøÕ¾µÄ°²È«·ì϶ÇÔÈ¡µÄ£¬²¢ÇÒ×î³õÔÚ°µÍøÏúÊÛ¡£×î½ü£¬ÕâЩÊý¾ÝÔÚ¹«ÍøÉÏй¶£¬²¢ÔÚÂÛ̳ÉÏÃâ·Ñ¹²Ïí´«²¼¡£Ð¹Â¶Êý¾ÝÔ̺¬Óû§Ãô¸ÐÐÅÏ¢£¬ÀýÈçMD5¼ÓÃܵÄÃÜÂë¡¢µç×ÓÓʼþµØÖ·¡¢ÊÖ»úºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢ÐÔ±ðÐÅÏ¢¡¢Óû§ÃûºÍÀûÓ÷¨Ê½»òÍøÕ¾»î¶¯¡£Ä¿Ç°£¬MobiFriends¹«Ë¾¶Ô´ËÊÂÎñÒ»Ïòά³Ö¹ÑÑÔ£¬Ò²Ã»Óлظ´ZDNetºÍRBSµÄÖÃÆÀÒªÇó¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/dating-app-mobifriends-silent-on-security-breach-impacting-3-6-million-users/
4.µçÉ̹«Ë¾StorEnvyÔâºÚ¿ÍÈëÇÖ£¬Ð¹Â¶150ÍòÓû§ÐÅÏ¢
µçÉ̹«Ë¾StorEnvyÔâºÚ¿ÍÈëÇÖ,Æä³¬¹ý150Íò¿Í»§ºÍÉ̼ҵÄÐÅÏ¢±»ºÚ¿Í·ÅÔÚ°µÍøÉÏ´«²¼¡£Õâ´Îй¶Êý¾ÝÔ̺¬µç×ÓÓʼþ¡¢ÃÜÂ롢ȫÃû¡¢Óû§Ãû¡¢IPµØÖ·¡¢³ÇÊÓ×¢ÐÔ±ðÒÔ¼°É罻ýÌå×ÊÁÏÁ´½Ó£¬²¢ÇÒËùº±¼û¾Ý£¨ÀýÈçÃÜÂ룩¶¼ÊÇ´¿Îı¾ÌåʽµÄ£¬ÔÚijЩÇé¿öÏ£¬»¹Äܹ»¿´µ½¶©µ¥¾ßÌåÐÅÏ¢£¬ÀýÈç¶©µ¥ÈÕÆÚ¡¢¶©µ¥ºÅºÍ²É°ìÖÐʹÓõĸ¶¿î·½Ê½¡£¾ÝHackread.com·ÖÎö£¬Õâ´ÎÊý¾Ýй¶ÊǺڿÍÀûÓô¹µö¹¥»÷ºÍÉí·ÝµÁÓõ¼Öµġ£Ä¿Ç°Éв»Ã÷ÏÔÊý¾Ýй¶¼òÖ±Çй¦·ò£¬Storenvy¹«Ë¾Ò²ÉÐδ¶Ô´ËÊÂ×ö³ö»Ø¸´¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/e-commerce-firm-storenvy-hacked-accounts-leaked/
5.ºÚ¿ÍÏúÊÛ1.15ÒÚ°Í»ù˹̹µç»°Óû§µÄÐÅÏ¢£¬±ê¼Û210ÍòÃÀÔª
¾ÝZDNet±¨Â·£¬½üÈÕ£¬ºÚ¿ÍÕýÒÔ210ÍòÃÀÔªµÄ±ÈÌØ±ÒµÄ¼ÛÖµÏúÊÛ1.15ÒÚ°Í»ù˹̹µç»°Óû§µÄÐÅÏ¢£¬¶ø±¾ÖÜÔçÆÚй¶µÄ4400ÍòÐÅÏ¢Ö»ÊÇÆäÖеÄÒ»²¿ÃÅ¡£Õâ´Îй¶Êý¾ÝÔ̺¬¿Í»§È«Ãû¡¢¼Òͥסַ£¨³ÇÊÓ×¢µØÓò¡¢½Ö·Ãû³Æ£©¡¢¹ú¶ÈÉí·ÝÖ¤ºÅ£¨CNIC£©¡¢ÊÖ»úºÅÂë¡¢×ù»úºÅÂëºÍ¶©ÔÄÈÕÆÚ¡£¾ø´ó¶àй©Êý¾Ý¶¼ÊôÓÚ°Í»ùË¹Ì¹ÒÆ¶¯ÔËÓªÉÌJazzµÄÊÖ»úºÅÂ룬µ«ZDNet»¹È·¶¨Ò²ÓÐÊôÓÚÆäËûÒÆ¶¯ÔËÓªÉ̵ĵ绰ºÅÂ룬ËùÒÔÉÐÎÞ·¨Ö¤Ã÷ÕâЩÊý¾ÝÊÇ´ÓJazz·þÎñÆ÷ÖÐй¶µÄ£¬¶øJazz½²»°ÈËҲδ»Ø¸´ÖÃÆÀÒªÇó¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/details-of-44m-pakistani-mobile-users-leaked-online-part-of-bigger-115m-cache/#ftag=RSSbaffb68
6.ºÚ¿ÍÇÔÈ¡Èý¼Ò¹«Ë¾µÄ2600ÍòÌõÓû§ÐÅÏ¢£¬²¢ÔÚ°µÍøÏúÊÛ
ºÚ¿Í×éÖ¯Shiny HuntersÇÔÈ¡Á˲ͰüÅäËÍ·þÎñƽ̨HomeChef¡¢ÕÕÆ¬´òÓ¡·þÎñƽ̨ChatBooksºÍ¸ßµµ½ÌÓýÐÂÎÅÍøÕ¾Chronicle.comÈý¼Ò¹«Ë¾ÖеÄ2600ÍòÌõÓû§ÐÅÏ¢£¬²¢ÔÚ°µÍøÉϱê¼ÛÏúÊÛ¡£HomeChefƽ̨Êý¾Ý¿âÔ̺¬800Íò±Ê¼Í¼£¬Ô̺¬bcrypt¹þÏ£ÃÜÂë¡¢IPµØÖ·¡¢µç»°ºÅÂë¡¢ÓÊÕþ±àÂëºÍÓ×ÎÒÉí·ÝÐÅÏ¢£¨PII£©£¬±ê¼ÛΪ2500ÃÀÔª¡£ChatBooksƽ̨Êý¾Ý¿âÔ̺¬1500ÍòÌõÊý¾Ý£¬Ô̺¬ÓʼþµØÖ·¡¢SHA-512ÃÜÂë¡¢É罻ýÌå½Ó¼ûÁîÅÆºÍһЩPII£¬±ê¼ÛΪ2500ÃÀÔª¡£Chronicle.comÍøÕ¾Êý¾Ý¿âÔ̺¬300ÍòÌõÓû§¼Í¼£¬±ê¼ÛΪ1500ÃÀÔª¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-sell-stolen-user-data-from-homechef-chatbooks-and-chronicle/


¾©¹«Íø°²±¸11010802024551ºÅ