°µÍøEmpire MarkeÀëÏß36Ó×ʱ£¬»òÒòÔâµ½DDoS¹¥»÷£»REDTEAM.PLÅû¶SafariÖзì϶£¬¿É±»ÓÃÀ´ÇÔÈ¡Óû§Îļþ

°ä²¼¹¦·ò 2020-08-25

1.°µÍøEmpire MarkeÀëÏß36Ó×ʱ£¬»òÒòÔâµ½DDoS¹¥»÷


1.png


°µÍøEmpire MarkeÀëÏß³¬¹ý36Ó×ʱ£¬´ËÊÂÒÑÔÚ¸÷ÀàÔÚÏßÂÛ̳ÖÐÒýÆðÁ˼«´ó¹Ø×¢¡£Æ¾¾Ý·ÖÎöʦDark.failµÄ˵·¨£¬Empire MarkeµÄÍÑ»úÊÇÓÉÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷µ¼ÖµÄ£¬Æä·þÎñÆ÷Ôâµ½Á˱¨´ðÁ÷Á¿ºäÕ¨¡£Ö±ÖÁ8ÔÂ21ÈÕ£¬Dark.fail°ä²¼ÍÆÎݵʾ¸ÃÍøÕ¾ÈÔÔÚÔâ·êµ½´óÐÍDDoS¹¥»÷£¬µ¼Ö½Ӽû¿ìÂʼ«¶ÈÂý¡£´Ë±í£¬Æ¾¾Ý¶à¸ö¿ÉÐÅÈεÄÐÂÎÅÆðÔ´£¬MoneroµÄÖ°ÄÜËÆºõ²»ÄÜÖ§³ÖÁË£¬µ«±ÈÌØ±Ò»¹ÔÚÔËÐС£Ä¿Ç°ÓÉPGPÑéÖ¤url£¬µ¼ÖºܶഹµöÁ´½Ó³öÏÖ¡£


Ô­ÎÄÁ´½Ó£º

https://www.itsecurityguru.org/2020/08/24/darknet-empire-market-potentially-victim-of-ddos-attack/


2.REDTEAM.PLÅû¶SafariÖзì϶£¬¿É±»ÓÃÀ´ÇÔÈ¡Óû§Îļþ


2.png


²¨À¼°²È«¹«Ë¾REDTEAM.PLµÄPawel WylecialÅû¶Safariä¯ÀÀÆ÷Öзì϶£¬¿É±»ÓÃÀ´ÇÔÈ¡Óû§Îļþ¡£¸Ã·ì϶´æÔÚÓÚSafariµÄWeb Share APIÖ´ÐÐÖУ¬ÓÉÓÚSafariÖ§³Ö¹²Ïí´æ´¢ÔÚÓû§±¾µØÓ²ÅÌÉϵÄÎļþ£¬Õâ¿ÉÄܵ¼ÖºڿÍÀûÓöñÒâÍøÒ³ÒýÓÕÓû§Í¨¹ýµç×ÓÓʼþ·ÖÏíһƪÎÄÕ¸øÆäÀÏÓÑ£¬ÒÔÒñ±ÎµØ´ÓÆäÉ豸ÇÔÎļþ¡£Wylecial×î³õÓÚ2020Äê4Ô»㱨Á˸÷ì϶£¬µ«Apple½«²¹¶¡·¨Ê½ÍƳÙÁ˽«½üÒ»Ä꣨¼´2021Äê´º¼¾Ö®ºó£©°ä²¼£¬Òò¶øÆä¾ö¶¨µ±¼´¹«¿ª¸Ã·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/security-researcher-discloses-safari-bug-after-apples-delays-patch/


3.GoogleÔÆ¶ËÓ²ÅÌÖзì϶¿É±»ÓÃÀ´ÌáÒéÓã²æÊ½´¹µö¹¥»÷


3.png


GoogleÔÆ¶ËÓ²ÅÌÖдæÔÚ·ì϶£¬¿É±»ÓÃÀ´ÌáÒéÓã²æÊ½´¹µö¹¥»÷¡£¸Ã·ì϶´æÔÚÓÚGoogleÔÆ¶ËÓ²ÅÌÖеÄÖÎÀí°æÐÔ×ÓÄÜÖУ¬¸ÃÖ°ÄÜÔÊÐíÓû§ÉÏÔØºÍÖÎÀíÎļþµÄ·ÖÆç°æ±¾¡£×êÑÐÈËÔ±A. Nikoci·¢ÏÖ£¬¸ÃÖ°ÄÜÔÊÐíÓû§ÉÏ´«´æ´¢ÔڹȸèÇý¶¯Æ÷ÉϵÄËÁÒâÎļþÀ©´óÃûµÄа汾£¬´Ó¶øÔÊÐíÉÏ´«¶ñÒâ¿ÉÖ´ÐÐÎļþ¡£¼´±ãɱ¶¾Èí¼þ½«ÆäÏóÕ÷Ϊ¶ñÒâÈí¼þ£¬¹È¸èä¯ÀÀÆ÷ÒÀÈ»ÐÅÀµ´ÓGoogleÔÆ¶ËÓ²ÅÌÏÂÔØµÄËùÓÐÎļþ¡£Òò¶ø¹¥»÷Õß¿ÉÀûÓø÷ì϶£¬Ê¹ÓÃÔ̺¬ÁËÖ¸ÏòÍйÜÔÚGoogleÔÆ¶ËÓ²ÅÌÉϵĶñÒâÎļþÁ´½ÓµÄÓʼþÀ´ÌáÒéÓã²æÊ½´¹µö¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/107437/hacking/google-drive-weakness.html    


4.Claroty°ä²¼2020ÄêÉϰëÄêICS·ì϶·ÖÎö»ã±¨


4.jpg


¹¤ÒµÍøÂ簲ȫ¹«Ë¾Claroty°ä²¼2020ÄêÉϰëÄêICS·ì϶·ÖÎö»ã±¨¡£Claroty·ÖÎöÁËÐÂÔö³¤µ½¹ú¶È·ì϶Êý¾Ý¿â£¨NVD£©ÖеÄ365¸öICS·ì϶ÒÔ¼°ICS-CERT£¨CISA£©°ä²¼µÄ´«µÝÖк­¸ÇµÄ385¸ö·ì϶¡£Óë2019ÄêͬÆÚÅû¶µÄ·ì϶ÊýÁ¿Ïà±È£¬2020ÄêÉϰëÄêÐÂÔöµ½NVDÖеķì϶ÊýÁ¿Ô¼Äª¶à³ö10£¥¡£ÔÚËùʶ´ËÍâ·ì϶ÖУ¬ÓÐ70£¥ÒÔÉϵķì϶¿É±»Ô¶³ÌÀûÓã¬Óн«½üÒ»°ë¿ÉÓÃÓÚÔ¶³ÌÖ´ÐдúÂ룬ÆäÖÐ41£¥µÄ·ì϶¿ÉÈù¥»÷Õß¶ÁÈ¡ÀûÓ÷¨Ê½Êý¾Ý£¬39£¥µÄ·ì϶¿ÉÓÃÓÚDoS¹¥»÷£¬37£¥µÄ·ì϶¿ÉÈÆ¹ý°²È«»úÔì¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/over-70-ics-vulnerabilities-disclosed-first-half-2020-remotely-exploitable


5.¾Ýͳ¼Æ£¬RDPʼÖÕΪ2020ÄêÀÕË÷Èí¼þ¹¥»÷µÄÖØÒªÃ½½é


5.jpg


ƾ¾Ý Coveware¡¢EmsisoftºÍRecorded Future µÄ»ã±¨£¬RDPʼÖÕΪ2020ÄêÀÕË÷Èí¼þ¹¥»÷µÄÖØÒªÃ½½é¡£RDPÊǵ±½ñÓÃÓÚÏνÓÔ¶³ÌϵͳµÄ¶¥¼¶¼¼Êõ£¬ÍøÂçÉϺ±¼û°ÙÍǫ̀RDP¶Ë¿Ú¶³öµÄÍÆËã»ú£¬ÕâʹRDP³ÉΪ¶Ô¸÷ÀàÍøÂç·¸×ï·Ö×ÓµÄÖØÒª¹¥»÷ý½é¡£´Ë±í£¬2020ÄêÓÖ³öÏÖÁËеÄÀÕË÷Èí¼þ¹¥»÷ý½é£¬¼´±ãÓÃVPNºÍÆäËûÀàËÆµÄÍøÂçÉ豸ÈëÇÖ¹«Ë¾ÍøÂ硣ƾ¾ÝSenseCyµÄ»ã±¨£¬2020ÄêÆÚ¼äVPNѸ¿ì³ÉΪÀÕË÷Èí¼þ×éÖ¯ÖÐеÄÈȵ㹥»÷ý½é£¬CitrixÍøÂçÍø¹ØºÍPulse Secure VPN·þÎñÆ÷³ÉΪËûÃǵÄÖØÒªÖ¸±ê¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/top-exploits-used-by-ransomware-gangs-are-vpn-bugs-but-rdp-still-reigns-supreme/


6.Maze×éÖ¯Ðû³ÆÒѾ­ÈëÇÖSK hynix¹«Ë¾²¢ÇÔÈ¡11GBÊý¾Ý


6.jpg


Maze×éÖ¯Ðû³ÆÒѾ­ÈëÇÖÄÚ´æÔì×÷ÉÌSK hynix²¢ÇÔÈ¡11GBÊý¾Ý¡£MazeÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾°ä²¼ÁË570MBµÄZIP´æµµ£¬²¢Åú×¢Õâ½öΪ´ÓSK hynixÇÔÈ¡µÄ×ÜÊý¾ÝµÄ5%¡£¾ÝÐÂÎÅÈËÊ¿³Æ£¬Õâ´Îй¶µÄÊý¾ÝËÆºõÔ̺¬ÆäÓëÆ»¹û¹«Ë¾Ç©¶¨µÄ»úÃÜNANDÉÁ´æ¹©¸øºÍ̸£¬ÒÔ¼°Ó×ÎÒÎļþºÍ¹«Ë¾µÄÎļþ¡£Ä¿Ç°£¬¸Ã¹«Ë¾ÉÐδ¶Ô´ËÊÂÖÃÆÀ¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2020/08/20/maze_crew_sk_hynix/