ºÚ¿ÍÈëÇÖ2gether·þÎñÆ÷ £¬ÇÔÈ¡¼ÛÖµ120ÍòÅ·ÔªµÄ¼ÓÃÜÇ®±Ò£»ºÚ¿Íй¶900¶à¸öÆóÒµVPN·þÎñÆ÷µÄÐÅÏ¢ºÍÃ÷ÎÄÃÜÂë

°ä²¼¹¦·ò 2020-08-05

1.ºÚ¿ÍÈëÇÖ2gether·þÎñÆ÷ £¬ÇÔÈ¡¼ÛÖµ120ÍòÅ·ÔªµÄ¼ÓÃÜÇ®±Ò



GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


7ÔÂ31ÈÕÏÂÎç6µã £¬ºÚ¿ÍÈëÇÖÁË2getherµÄ·þÎñÆ÷ £¬²¢ÇÔÈ¡Á˼ÛÖµ118.3ÍòÅ·ÔªµÄ¼ÓÃÜÇ®±Ò £¬Õ¼×Ü×ʽðµÄ26.79£¥¡£2together CEO°µÊ¾ £¬Õâ´Î¹¥»÷²¢Î´Ó°Ïìͨ·ÑÇ®°üºÍÅ·ÔªÕÊ»§ £¬²¢ÇÒºÚ¿ÍûÓÐÇÔÈ¡Óû§ÐÅÓþ¿¨µÄ²ÆÕþÐÅÏ¢¡£Ä¿Ç° £¬¸Ã¹«Ë¾²¢Î´°ä²¼¹¥»÷µÄ¼¼Êõϸ½Ú £¬Ö»ÊǰµÊ¾Á˾ßÌåµ÷²éÈÔÔÚ½øÐÐÖС£¾Ý¹«Ë¾¸ß¹Ü³Æ £¬¸Ã¹«Ë¾Ã»ÓÐ×ã¹»µÄ×ʽðÀ´ÍË»¹ÆäÓû§ £¬²¢ÇÒÕýÊÔͼͨ¹ýͶ×ʹ«Ë¾µÄ×¢×ʽøÐв¹¾È¡£µ«ÊDz¢Î´³É¹¦ £¬Òò¶øÖ»ÄÜÏòÓû§ÌṩÆä±»µÁµÄ¼ÓÃÜÇ®±ÒµÈÖµµÄ±¾µØ2GT´ú±Ò¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/106726/hacking/2gether-hacked.html


2.°Í»ù˹̹ÐÂÎÅÆµÂ·DawnÔâ¹¥»÷ £¬¸æ°×¹¦·ò²¥·ÅÓ¡¶È¹úÆì


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


8ÔÂ2ÈÕÐÇÆÚÈÕÏÂÎç3:30×óÓÒ £¬°Í»ùË¹Ì¹ÖØÒªÐÂÎÅÆµÂ·Ö®Ò»DawnÔâµ½ºÚ¿Í¹¥»÷ £¬¸æ°×ÐÝÏ¢ÆÚ¼äÔÚÆÁÄ»Éϲ¥·ÅÓ¡¶È¹úÆìºÍ¶ÀÁ¢ÁôÏëÈÕ»¶ÀÖµÄ×ÖÑù¡£Dawn°µÊ¾ £¬Ôâµ½¹¥»÷ʱËûÃÇÏñƽ·²Ò»Ñù²¥·ÅÐÂÎź͸æ°×¡£Ä¿Ç° £¬ Óйػú¹¹ÔÚ¶ÔÕâ´Î¹¥»÷·¢Õ¹µ÷²é¡£¾ÝϤ £¬Õâ²¢²»ÊǵÚÒ»´Î²úÉúºÚ¿Í¹¥»÷µçÊÓÆµÂ·ÊÂÎñ £¬ÒÔÉ«ÁеĸöÈËÐÂÎÅÆµÂ·µÚ2Ƶ·ºÍµÚ10Ƶ·µÄ¾ÍÔøÔâµ½¹ýÈëÇÖ £¬ºÚ¿ÍÖжÏÁ˽ÚÄ¿²¢²¥·ÅÄÂ˹Áֵĵ»¸æÉù¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/pakistani-news-channel-transmission-hacked-indian-flag/


3.ºÚ¿Íй¶900¶à¸öÆóÒµVPN·þÎñÆ÷µÄÐÅÏ¢ºÍÃ÷ÎÄÃÜÂë


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ºÚ¿ÍÔÚ°µÍøÉϰ䲼ÁË900¶à¸öPulse Secure VPNÆóÒµ·þÎñÆ÷µÄÐÅÏ¢ºÍÃ÷ÎÄÃÜÂë¡£Õâ´Îй¶ÐÅÏ¢Ô̺¬·þÎñÆ÷µÄIPµØÖ·¡¢¹Ì¼þ°æ±¾ºÅ¡¢Ã¿¸ö·þÎñÆ÷µÄSSHÃÜÔ¿¡¢ËùÓб¾µØÓû§¼°ÆäÃÜÂë¹þÏ£µÄÁÐ±í¡¢ÖÎÀíÔ¹ØÊ»§¾ßÌåÐÅÏ¢¡¢×î½üµÄVPNµÇ¼Ãû£¨Ô̺¬Óû§ÃûºÍÃ÷ÎÄÃÜÂ룩ÒÔ¼°VPN»á»°cookie¡£Íþвµý±¨·ÖÎö¹«Ë¾Bank Security·¢ÏÖÁбíÖеķþÎñÆ÷¶¼ÔËÐÐÁË´æÔÚCVE-2019-11510·ì϶°æ±¾µÄ¹Ì¼þ¡£Òò¶ø £¬ÆäÒÔΪºÚ¿ÍÊÇɨÃèÁË·þÎñÆ÷µÄÕû¸öInternet IPv4µØÖ·¿Õ¼ä £¬²¢ÀûÓø÷ì϶À´½Ó¼ûϵͳ £¬×ª´¢·þÎñÓþßÌåÐÅÏ¢²¢½«ËùÓÐÐÅÏ¢ÍøÂçµ½Ò»¸öÖÐÑë´æ´¢¿âÖС£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-leaks-passwords-for-900-enterprise-vpn-servers/


4.Ò»¼üͨÀûÓÃZello²úÉúÊý¾Ýй¶ £¬ÒѳÁÖÃËùÓÐЧ»§ÃÜÂë


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ò»¼üͨÀûÓÃZello²úÉúÊý¾Ýй¶ £¬ÆäÒѳÁÖÃËùÓÐЧ»§ÃÜÂë¡£ZelloÖ¸³ö £¬ËûÃÇÓÚ2020Äê7ÔÂ8ÈÕÔÚÆäÖÐһ̨·þÎñÆ÷ÉÏ·¢ÏÖÁËÕâ´Î¹¥»÷ £¬Í¨¹ý½øÒ»´ëÊ©²é £¬·¢ÏÖδ¾­ÊÚȨµÄºÚ¿Í¿ÉÄÜÒѾ­½Ó¼ûÁËÆäÓû§ÔÚÆäZelloÕÊ»§ÉÏʹÓõĵç×ÓÓʼþµØÖ·ºÍ¹þÏ£ÃÜÂë¡£µ«ÊÇ £¬Õâ´Îй¶ÊÂÎñ²¢²»»áÓ°ÏìZello WorkºÍZello for First RespondersÓû§¡£ºÚ¿Í¿ÉÀûÓÃй¶ÐÅÏ¢½øÐÐÍ´´¦Ìî³ä¹¥»÷ £¬²¢µÇ¼Óû§ÆäËûÕ¾µãµÄÕË»§¡£Òò¶ø £¬ZelloÒÑÇ¿Ôì³ÁÖÃÓû§ÃÜÂë £¬²¢½¨ÒéÓû§¸ü¸ÄÆäËûÕ¾µãÉÏÒ»ÑùµÄÃÜÂë¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/zello-resets-all-user-passwords-after-data-breach/


5.ÈýÁâ°ä²¼¶à¸ö²úÆ·µÄ¸üР£¬»¹ÌṩÁËһʱ½â¾ö¹æ»®


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÈýÁâµç»úµÄÊýÊ®ÖÖ¹¤³§×Ô¶¯»¯²úÆ·´æÔÚÈý¸ö·ì϶ £¬ÕâЩ·ì϶¿É±»ÀûÓýøÐÐÌáȨ¡¢ËÁÒâ´úÂëÖ´ÐкÍDoS¹¥»÷¡£Ä¿Ç° £¬ÈýÁâÒѾ­ÎªÊÜÓ°ÏìµÄ²úÆ·°ä²¼Á˲¹¶¡ £¬»¹ÎªÆäÓà²úÆ·ºÍÎÞ·¨µ±¼´×°Öò¹¶¡·¨Ê½µÄ¿Í»§ÌṩÁË»º½â´ëÊ©¡£µÚÒ»¸ö·ì϶ΪȨÏÞÎÊÌ⣨CVE-2020-14496£© £¬ËüÔÊÐíºÎÓû§ÔÚÌØ¶¨Ä¿Â¼Ð´ÈëÎļþ £¬Õ¼ÓÐдȨÏ޵Ĺ¥»÷ÕßÄܹ»¸²¸Ç´ËĿ¼ÖеĺϷ¨Îļþ¡£µÚ¶þ¸öÊÇzip·ì϶£¨CVE-2020-14523£© £¬²úƷʹÓÃzip¹éµµÎļþÀ´´æ´¢ÅäÖà £¬ÌáÈ¡¶ñÒâzip¹éµµÎļþ¿ÉÄܵ¼Ö½«ÎļþдÈëÖ¸±êĿ¼֮±íµÄËÁÒâµØÎ»¡£µÚÈý¸ö·ì϶±»×·×ÙΪCVE-2020-14521 £¬¶ÔijЩWindows apiµÄŲÓÃÖÐʹÓÃÁËδÒýÓõÄõè¾¶ £¬¿É±»ÀûÓüÓÔØ¶ñÒâ¿ÉÖ´ÐÐÎļþ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/hackers-could-target-organizations-flaws-mitsubishi-factory-automation-products


6.×êÑÐÈËÔ±·¢ÏÖMeetupµÄ·ì϶ £¬¿Éµ¼ÖÂÓû§×ʽð±»ÇÔÈ¡


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Checkmarx×êÑÐÈËÔ±·¢ÏÖMeetupƽ̨´æÔÚÑϳÁµÄ·ì϶ £¬¿Éµ¼ÖÂÓû§×ʽð±»ÇÔÈ¡¡£µÚÒ»¸öΪ´æ´¢µÄXSS·ì϶ £¬Ö»ÐèÔÚ»áÉÌÇøµÄÐÂÎÅÖа䲼JavaScript´úÂë¾ÍÄܹ»½øÐÐÌáȨ¡£µÚ¶þ¸ö·ì϶ΪÉèÖò˵¥µÄ¸¶¿î²¿ÃÅÖеÄCSRF £¬¿ÉÓëµÚÒ»¸öXSS·ì϶½áºÏʹÓà £¬¸ü¸ÄÓû§ÔÚMeetupÅäÖÃÎļþÖеÄPayPalµØÖ·¡£¹¥»÷ÕßÖ»ÐèÔÚ»áÉÌÇøÖа䲼һÌõÐÂÎÅ £¬²¢Ö¸ÏòÆä·þÎñÆ÷ÉÏÀûÓÃCSRFÎÊÌâµÄÎļþ±ãÄܹ»ÀûÓø÷ì϶¡£³ýÁËÕâÁ½¸ö·ì϶±í £¬Checkmarx»¹·¢ÏÖÁËÆäËû°²È«Òþ»¼ £¬api.meetup.comµÄ³ÉÔ±¶ËµãÖв»×ã×ÊÔ´ºÍ¿ìÂÊÏÞ¶È £¬Äܹ»ÀûÓÃÐòÁÐÕûÊýÀ´ÀûÓôËö¾Ùö¾ÙMeetupÓû§¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-could-have-stolen-paypal-funds-from-meetup-users/