°ÍÎ÷¹«Ë¾NaturaÊý¾Ý¿â¶³öй¶1.92ÒÚÌõÓû§ÐÅÏ¢£»Adobe°ä²¼´¹Î£´ø±í¸üн¨¸´Ô¶³ÌÖ´ÐдúÂë·ì϶

°ä²¼¹¦·ò 2020-05-21

1.°ÍÎ÷¹«Ë¾NaturaÊý¾Ý¿â¶³ö £¬Ð¹Â¶1.92ÒÚÌõÓû§ÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°ÍÎ÷Ê¥±£Â޵Ļ¯×±Æ·¹«Ë¾Natura¶³öÁËÁ½¸öÅäÖÃÃýÎóµÄAWSÊý¾Ý¿â³¤´ïÊýÖÜÖ®¾Ã £¬Ð¹Â¶ÁË1.92ÒÚÌõÓû§ÐÅÏ¢¡£Æ¾¾ÝHackread.comµÄµ÷²é £¬Õâ´Îй¶µÄÊÇÔڸù«Ë¾ÍøÕ¾¹ºÎïµÄ³¬¹ý25ÍòÃû¿Í»§µÄÐÅÏ¢ £¬Ô̺¬Óû§ÐÔ±ð¡¢ÐÕÃû¡¢¹ú¼®¡¢µ®ÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢ÒÔǰ²É°ì¼Í¼¡¢MOIPÕÊ»§¾ßÌåÐÅÏ¢¡¢Ä¸Ç×µÄÐÕ¡¢ÓʼþÓ­½ÓÄ£°å¡¢Óû§ÃûºÍêdzơ¢µç×ÓÓʼþµØÖ·¡¢ÏÖʵµØÖ·¡¢ÓÃÓÚwirecard.com.brµÄ½Ó¼ûÁîÅÆ¡¢APIƾ֤£¨Ô̺¬Î´¼ÓÃܵÄÃÜÂ룩¡¢Natura.com.brµÇ¼ƾ֤£¨Ô̺¬¹þÏ£ÃÜÂ룩¡£´Ë±í £¬×êÑÐÈËÔ±·¢ÏÖÕâ´ÎÊÂÎñ»¹Ð¹Â¶ÁËÓë¹«Ë¾ÍøÂç»ù´¡ÉèÊ©ÓйصĻúÃÜÐÅÏ¢ £¬Èç.pemÖ¤ÊéÃÜÔ¿¡£Ä¿Ç° £¬Á½¸öÊý¾Ý¿âÔÚ¶³öÊýÖܺó¾ùÒѵõ½±£»¤¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/brazis-cosmetic-giant-natura-leaked-192m-records/


2.Å·ÃËÒé»áй¶ÊýǧÈËÊý¾Ý £¬ÉÐδ¶Ô´ËÊÂ×÷³ö»ØÓ¦


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×î½ü £¬Ó¡¶ÈÍøÂçµý±¨¹«Ë¾ShadowMapTechÔÚÅ·ÃËÒé»á·¢ÏÖÁËÊý¾Ýй¶ÊÂÎñ £¬ÆäÖÐÔ̺¬200¶à¸öÅ·ÃËÒé»á¡¢Å·ÃËÀíÊ»áºÍÅ·ÃËίԱ»á³ÉÔ±µÄÊý¾ÝºÍÃÜÂë £¬½«Ó°ÏìÅ·ÃËÒé»áµÄ1000¶àÃû¹¤×÷ÈËÔ±¡£Ð¹Â¶Êý¾ÝÔ̺¬Ê¹ÓÃÕß±àºÅ¡¢Ãû×Ö¡¢¼ÓÃÜÃÜÂë¡¢µç×ÓÓʼþµØÖ·ºÍÊ±Çø¡£Õâ´Îй¶ÊÂÎñ¿ÉÄÜ»¹»áÓ°ÏìÐÂÎżÇÕß¡¢ÕþÖÎÈËÎïÒÔ¼°Å·ÃËÁí±í¼¸¸ö»ú¹¹µÄ³ÉÔ± £¬ÀýÈçÅ·ÖÞÐ̾¯×éÖ¯¡¢Å·ÖÞÊý¾Ý±£»¤Ö÷¹Ü¡¢EUIPOºÍFrontex £¬ÕâÅú×¢ÊÜÓ°ÏìÓû§×ÜÊý³¬¹ý15000¡£Ä¿Ç° £¬Å·ÃËÒé»áûÓжԴËÊÂ×ö³öÈκλظ´ £¬¶øÆäIT²¿ÃŸ±Ö÷ϯMarcel KolajaÔò·ñ¶¨ÁË´ËÊÂÎñ £¬°µÊ¾¸Ãй©ÓëÅ·ÃË»ú¹¹ÔËÐеÄϵͳ²»ÓйØ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/gdpr-european-parliament-data-breach-data-leak/


3.Ó¢¹úÈí¼þ¹«Ë¾Advanced´æÔÚ·ì϶ £¬Ð¹Â¶190¶à¼ÒÂÉËùÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢¹úÈí¼þ¹«Ë¾Advanced´æÔÚ·ì϶µ¼ÖÂÊý¾Ý¿â±©Â© £¬Ð¹Â¶190¶à¼ÒÂÉËùÐÅÏ¢¡£¾ÝÓ¢¹ú½ðÈÚʱ±¨±¨Â· £¬Õâ´ÎÊÂÎñй©ÁËԼĪ190¼ÒÂÉʦÊÂÎñËùµÄ10000¸ö˾·¨Îļþ £¬Ô̺¬³ÛÃûÂÉËùClifford Chance £¬SlaughterºÍMay¡£Õâ´Îй¶µÄÐÅÏ¢ÖÐÓÐЧ»§Ãô¸ÐÐÅÏ¢ £¬Èç¹þÏ£ÃÜÂ롢˾·¨Îļþ¡¢»¤ÕÕºÅÂ롢ĸÇ×µÄÄï¼ÒÐÕºÍÑÛ¾¦É«²ÊÖ®ÀàµÄ¾ßÌåÐÅÏ¢ £¬»¹Ô̺¬ÖîÈçÓû§Ãû¡¢IDºÍ¹þÏ£ÃÜÂë¡¢ÑéÖ¤Âë¡¢¹«Ë¾¾ßÌåÐÅÏ¢ºÍ·þÎñÓöÈÖ®ÀàµÄÊý¾Ý¡£Advanced°²È«×ܼàÔò°µÊ¾ £¬¸ÃÊÂÎñй©µÄÊý¾ÝÕý±¾¾ÍÊǹ«¿ªµÄ £¬ÔÚй¶µÄ˾·¨ÎļþÖÐÏÕЩûÓпɷֱæµÄÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.cpomagazine.com/cyber-security/over-190-law-firms-affected-by-advanced-data-leak-that-exposed-over-10000-legal-documents/


4.Adobe°ä²¼´¹Î£´ø±í¸üР£¬½¨¸´Ô¶³ÌÖ´ÐдúÂë·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


5ÔÂ19ÈÕ £¬Adobe°ä²¼ÁËËĸö°²È«¸üР£¬ÆäÖÐÒ»¸ö½¨¸´ÁËÑϳÁµÄÔ¶³ÌÖ´ÐдúÂë·ì϶¡£Õâ´Î°²È«¸üн¨¸´µÄ±ðÀëÊÇCharacter AnimatorÖеĻùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å£¨CVE-2020-9586£© £¬¿Éµ¼ÖÂÔ¶³ÌÖ´ÐÐËÁÒâ´úÂ룻Adobe Premiere ProÖеÄÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2020-9616£© £¬¿Éµ¼ÖÂÐÅϢй¶£»Adobe AuditionÖеÄÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2020-9618£© £¬¿Éµ¼ÖÂÐÅϢй¶£»Premiere RushÖеÄÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2020-9617£©¿Éµ¼ÖÂÐÅϢй¶¡£Ç÷Ïò¿Æ¼¼ÌáÐÑÓû§ £¬¼´±ãÕâЩ²¹¶¡Ôڰ䲼ʱ²¢Î´ÔÚҰʹÓà £¬µ«ÊÇÓû§ÈÔÓ¦¾¡¿ìÉý¼¶µ½×îа汾¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/adobe-releases-critical-out-of-band-security-update/


5.AndroidľÂíDenDroidµÄбäÖÖWolfRAT £¬Õë¶ÔÌ©¹úÓû§


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Talos×êÑÐÈËÔ±·¢ÏÖÒ»ÖÖÐÂÐÍľÂíWolfRAT £¬¸ÃľÂíÊÇÒÆ¶¯Ô¶³Ì½Ó¼ûľÂí£¨RAT£©DenDroidµÄбäÖÖ £¬Õë¶ÔµÄÊÇʹÓÃAndroidƽ̨ÉϵÄWhatsapp¡¢Facebook MessengerºÍLineµÅצÓ÷¨Ê½µÄÌ©¹úÓû§¡£WolfRATͨ¹ýαÔì¸üÐÂÓÕʹÓû§Ê¹ÓÃFlashºÍGoogle PlayµÈºÏ·¨·þÎñ £¬´Ó¶øÆðÍ·ÆäϰȾÁ´¡£Ò»µ©Óû§ÊÜÆ­ £¬WolfRATÔò½«×Ô¼º×°ÖÃÔÚÖ¸±êAndroidÉ豸Éϲ¢ÆðÍ·¼äµý»î¶¯ £¬Ô̺¬ÍøÂçÉ豸Êý¾Ý¡¢ÅÄÉãÕÕÆ¬ºÍÊÓÆµ £¬·ÛËéSMSÐÂÎÅ´«µÝ £¬¼Í¹àÒôƵÒÔ¼°ÇÔÈ¡Îļþ²¢½«Æä´«Êäµ½C2¡£×êÑÐÈËÔ±»¹·¢ÏÖ²¿ÃÅC2λÓÚÌ©¹ú £¬Ê¹ÓõÄÓòºÍÌ©¹úʳƷÓйØ £¬»¹·¢ÏÖÁËÓÃÌ©Óï±àдµÄJavaScriptºÅÁî¡£Talos°µÊ¾ £¬¸Ã¶ñÒâÈí¼þ»¹ÔÚ²»ÐݵĿª·¢ÖС£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/wolfrat-targets-users-of-whatsapp-facebook-messenger-apps-on-android-devices/


6.ÒÁÀʺڿÍ×éÖ¯Greenbug¹¥»÷Á˰ͻù˹̹µÄ3¼ÒµçÐŹ«Ë¾


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾ÝÍøÂ簲ȫ¹«Ë¾Symantec³Æ £¬ÔÚ´ÓǰµÄ¼¸¸öÔÂÖÐ £¬ÒÁÀʺڿÍ×éÖ¯GreenbugÒ»ÏòÂñ·üÔÚ°Í»ù˹̹ÖÁÉÙ3¼ÒµçÐŹ«Ë¾µÄITϵͳÖС£¸ÃºÚ¿Í×éÖ¯Ò»ÏòÔÚʹÓÃÐé¹¹Ëí·ά³ÖÓëÊܺ¦»úеµÄÏνÓ £¬²¢Ñ°ÕÒÏàÒ˵ĻúÓö½Ó¼ûÆäϵͳÖÐÊý¾Ý¡£¶øGreenbugÔÚ±»·¢ÏÖºóÒ²Ò»ÏòÖÂÁ¦³ÖÐøÂñ·üÔÚÔÚ°Í»ù˹̹µçÐŹ«Ë¾ÍøÂçÖС£Symantec¸ß¼¶·ÖÎöʦÇǶ÷¡¤Jon DiMaggio°µÊ¾ £¬ºÚ¿ÍÖ®ËùÒÔÈëÇÖ²¢Âñ·üÔÚÕâЩ¹«Ë¾µÄÍøÂç £¬ÊÇÓÉÓÚµçÐÅÊý¾Ý¿ÉÒÔΪÆäÌṩ´óÁ¿ÐÅÏ¢ÒÔʵÏּල°Í»ù˹̹µÄÖ¸±ê¡£Symantec°µÊ¾ £¬2019ÄêÒ»¹²ÓÐ18¸ö·ÖÆçµÄÓëÁйúµ±¾ÖÓйصĺڿÍ×éÖ¯ £¬¶ÔµçÐŹ«Ë¾·¢Õ¹Á˹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.cyberscoop.com/greenbug-symantec-iran-hacking-pakistan/