ºÚ¿ÍÈëÇÖ2gether·þÎñÆ÷£¬ÇÔÈ¡¼ÛÖµ120ÍòÅ·ÔªµÄ¼ÓÃÜÇ®±Ò£»ºÚ¿Íй¶900¶à¸öÆóÒµVPN·þÎñÆ÷µÄÐÅÏ¢ºÍÃ÷ÎÄÃÜÂë
°ä²¼¹¦·ò 2020-08-051.ºÚ¿ÍÈëÇÖ2gether·þÎñÆ÷£¬ÇÔÈ¡¼ÛÖµ120ÍòÅ·ÔªµÄ¼ÓÃÜÇ®±Ò
7ÔÂ31ÈÕÏÂÎç6µã£¬ºÚ¿ÍÈëÇÖÁË2getherµÄ·þÎñÆ÷£¬²¢ÇÔÈ¡Á˼ÛÖµ118.3ÍòÅ·ÔªµÄ¼ÓÃÜÇ®±Ò£¬Õ¼×Ü×ʽðµÄ26.79£¥¡£2together CEO°µÊ¾£¬Õâ´Î¹¥»÷²¢Î´Ó°Ïìͨ·ÑÇ®°üºÍÅ·ÔªÕÊ»§£¬²¢ÇÒºÚ¿ÍûÓÐÇÔÈ¡Óû§ÐÅÓþ¿¨µÄ²ÆÕþÐÅÏ¢¡£Ä¿Ç°£¬¸Ã¹«Ë¾²¢Î´°ä²¼¹¥»÷µÄ¼¼Êõϸ½Ú£¬Ö»ÊǰµÊ¾Á˾ßÌåµ÷²éÈÔÔÚ½øÐÐÖС£¾Ý¹«Ë¾¸ß¹Ü³Æ£¬¸Ã¹«Ë¾Ã»ÓÐ×ã¹»µÄ×ʽðÀ´ÍË»¹ÆäÓû§£¬²¢ÇÒÕýÊÔͼͨ¹ýͶ×ʹ«Ë¾µÄ×¢×ʽøÐв¹¾È¡£µ«ÊDz¢Î´³É¹¦£¬Òò¶øÖ»ÄÜÏòÓû§ÌṩÆä±»µÁµÄ¼ÓÃÜÇ®±ÒµÈÖµµÄ±¾µØ2GT´ú±Ò¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/106726/hacking/2gether-hacked.html
2.°Í»ù˹̹ÐÂÎÅÆµÂ·DawnÔâ¹¥»÷£¬¸æ°×¹¦·ò²¥·ÅÓ¡¶È¹úÆì
8ÔÂ2ÈÕÐÇÆÚÈÕÏÂÎç3:30×óÓÒ£¬°Í»ùË¹Ì¹ÖØÒªÐÂÎÅÆµÂ·Ö®Ò»DawnÔâµ½ºÚ¿Í¹¥»÷£¬¸æ°×ÐÝÏ¢ÆÚ¼äÔÚÆÁÄ»Éϲ¥·ÅÓ¡¶È¹úÆìºÍ¶ÀÁ¢ÁôÏëÈÕ»¶ÀÖµÄ×ÖÑù¡£Dawn°µÊ¾£¬Ôâµ½¹¥»÷ʱËûÃÇÏñƽ·²Ò»Ñù²¥·ÅÐÂÎź͸æ°×¡£Ä¿Ç°£¬ Óйػú¹¹ÔÚ¶ÔÕâ´Î¹¥»÷·¢Õ¹µ÷²é¡£¾ÝϤ£¬Õâ²¢²»ÊǵÚÒ»´Î²úÉúºÚ¿Í¹¥»÷µçÊÓÆµÂ·ÊÂÎñ£¬ÒÔÉ«ÁеĸöÈËÐÂÎÅÆµÂ·µÚ2Ƶ·ºÍµÚ10Ƶ·µÄ¾ÍÔøÔâµ½¹ýÈëÇÖ£¬ºÚ¿ÍÖжÏÁ˽ÚÄ¿²¢²¥·ÅÄÂ˹Áֵĵ»¸æÉù¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/pakistani-news-channel-transmission-hacked-indian-flag/
3.ºÚ¿Íй¶900¶à¸öÆóÒµVPN·þÎñÆ÷µÄÐÅÏ¢ºÍÃ÷ÎÄÃÜÂë
ºÚ¿ÍÔÚ°µÍøÉϰ䲼ÁË900¶à¸öPulse Secure VPNÆóÒµ·þÎñÆ÷µÄÐÅÏ¢ºÍÃ÷ÎÄÃÜÂë¡£Õâ´Îй¶ÐÅÏ¢Ô̺¬·þÎñÆ÷µÄIPµØÖ·¡¢¹Ì¼þ°æ±¾ºÅ¡¢Ã¿¸ö·þÎñÆ÷µÄSSHÃÜÔ¿¡¢ËùÓб¾µØÓû§¼°ÆäÃÜÂë¹þÏ£µÄÁÐ±í¡¢ÖÎÀíÔ¹ØÊ»§¾ßÌåÐÅÏ¢¡¢×î½üµÄVPNµÇ¼Ãû£¨Ô̺¬Óû§ÃûºÍÃ÷ÎÄÃÜÂ룩ÒÔ¼°VPN»á»°cookie¡£Íþвµý±¨·ÖÎö¹«Ë¾Bank Security·¢ÏÖÁбíÖеķþÎñÆ÷¶¼ÔËÐÐÁË´æÔÚCVE-2019-11510·ì϶°æ±¾µÄ¹Ì¼þ¡£Òò¶ø£¬ÆäÒÔΪºÚ¿ÍÊÇɨÃèÁË·þÎñÆ÷µÄÕû¸öInternet IPv4µØÖ·¿Õ¼ä£¬²¢ÀûÓø÷ì϶À´½Ó¼ûϵͳ£¬×ª´¢·þÎñÓþßÌåÐÅÏ¢²¢½«ËùÓÐÐÅÏ¢ÍøÂçµ½Ò»¸öÖÐÑë´æ´¢¿âÖС£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hacker-leaks-passwords-for-900-enterprise-vpn-servers/
4.Ò»¼üͨÀûÓÃZello²úÉúÊý¾Ýй¶£¬ÒѳÁÖÃËùÓÐЧ»§ÃÜÂë
Ò»¼üͨÀûÓÃZello²úÉúÊý¾Ýй¶£¬ÆäÒѳÁÖÃËùÓÐЧ»§ÃÜÂë¡£ZelloÖ¸³ö£¬ËûÃÇÓÚ2020Äê7ÔÂ8ÈÕÔÚÆäÖÐһ̨·þÎñÆ÷ÉÏ·¢ÏÖÁËÕâ´Î¹¥»÷£¬Í¨¹ý½øÒ»´ëÊ©²é£¬·¢ÏÖδ¾ÊÚȨµÄºÚ¿Í¿ÉÄÜÒѾ½Ó¼ûÁËÆäÓû§ÔÚÆäZelloÕÊ»§ÉÏʹÓõĵç×ÓÓʼþµØÖ·ºÍ¹þÏ£ÃÜÂë¡£µ«ÊÇ£¬Õâ´Îй¶ÊÂÎñ²¢²»»áÓ°ÏìZello WorkºÍZello for First RespondersÓû§¡£ºÚ¿Í¿ÉÀûÓÃй¶ÐÅÏ¢½øÐÐÍ´´¦Ìî³ä¹¥»÷£¬²¢µÇ¼Óû§ÆäËûÕ¾µãµÄÕË»§¡£Òò¶ø£¬ZelloÒÑÇ¿Ôì³ÁÖÃÓû§ÃÜÂ룬²¢½¨ÒéÓû§¸ü¸ÄÆäËûÕ¾µãÉÏÒ»ÑùµÄÃÜÂë¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/zello-resets-all-user-passwords-after-data-breach/
5.ÈýÁâ°ä²¼¶à¸ö²úÆ·µÄ¸üУ¬»¹ÌṩÁËһʱ½â¾ö¹æ»®
ÈýÁâµç»úµÄÊýÊ®ÖÖ¹¤³§×Ô¶¯»¯²úÆ·´æÔÚÈý¸ö·ì϶£¬ÕâЩ·ì϶¿É±»ÀûÓýøÐÐÌáȨ¡¢ËÁÒâ´úÂëÖ´ÐкÍDoS¹¥»÷¡£Ä¿Ç°£¬ÈýÁâÒѾΪÊÜÓ°ÏìµÄ²úÆ·°ä²¼Á˲¹¶¡£¬»¹ÎªÆäÓà²úÆ·ºÍÎÞ·¨µ±¼´×°Öò¹¶¡·¨Ê½µÄ¿Í»§ÌṩÁË»º½â´ëÊ©¡£µÚÒ»¸ö·ì϶ΪȨÏÞÎÊÌ⣨CVE-2020-14496£©£¬ËüÔÊÐíºÎÓû§ÔÚÌØ¶¨Ä¿Â¼Ð´ÈëÎļþ£¬Õ¼ÓÐдȨÏ޵Ĺ¥»÷ÕßÄܹ»¸²¸Ç´ËĿ¼ÖеĺϷ¨Îļþ¡£µÚ¶þ¸öÊÇzip·ì϶£¨CVE-2020-14523£©£¬²úƷʹÓÃzip¹éµµÎļþÀ´´æ´¢ÅäÖã¬ÌáÈ¡¶ñÒâzip¹éµµÎļþ¿ÉÄܵ¼Ö½«ÎļþдÈëÖ¸±êĿ¼֮±íµÄËÁÒâµØÎ»¡£µÚÈý¸ö·ì϶±»×·×ÙΪCVE-2020-14521£¬¶ÔijЩWindows apiµÄŲÓÃÖÐʹÓÃÁËδÒýÓõÄõè¾¶£¬¿É±»ÀûÓüÓÔØ¶ñÒâ¿ÉÖ´ÐÐÎļþ¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/hackers-could-target-organizations-flaws-mitsubishi-factory-automation-products
6.×êÑÐÈËÔ±·¢ÏÖMeetupµÄ·ì϶£¬¿Éµ¼ÖÂÓû§×ʽð±»ÇÔÈ¡
Checkmarx×êÑÐÈËÔ±·¢ÏÖMeetupƽ̨´æÔÚÑϳÁµÄ·ì϶£¬¿Éµ¼ÖÂÓû§×ʽð±»ÇÔÈ¡¡£µÚÒ»¸öΪ´æ´¢µÄXSS·ì϶£¬Ö»ÐèÔÚ»áÉÌÇøµÄÐÂÎÅÖа䲼JavaScript´úÂë¾ÍÄܹ»½øÐÐÌáȨ¡£µÚ¶þ¸ö·ì϶ΪÉèÖò˵¥µÄ¸¶¿î²¿ÃÅÖеÄCSRF£¬¿ÉÓëµÚÒ»¸öXSS·ì϶½áºÏʹÓ㬸ü¸ÄÓû§ÔÚMeetupÅäÖÃÎļþÖеÄPayPalµØÖ·¡£¹¥»÷ÕßÖ»ÐèÔÚ»áÉÌÇøÖа䲼һÌõÐÂÎÅ£¬²¢Ö¸ÏòÆä·þÎñÆ÷ÉÏÀûÓÃCSRFÎÊÌâµÄÎļþ±ãÄܹ»ÀûÓø÷ì϶¡£³ýÁËÕâÁ½¸ö·ì϶±í£¬Checkmarx»¹·¢ÏÖÁËÆäËû°²È«Òþ»¼£¬api.meetup.comµÄ³ÉÔ±¶ËµãÖв»×ã×ÊÔ´ºÍ¿ìÂÊÏÞ¶È£¬Äܹ»ÀûÓÃÐòÁÐÕûÊýÀ´ÀûÓôËö¾Ùö¾ÙMeetupÓû§¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-could-have-stolen-paypal-funds-from-meetup-users/


¾©¹«Íø°²±¸11010802024551ºÅ