SolarWinds¹©¸øÁ´¹¥»÷»î¶¯ÖдæÔÚеÄSUPERNOVAºóÃÅ£»¶à¹ú·¨Âɲ¿ÃŽáºÏµ·»ÙÈý¸öÌṩVPN·þÎñµÄÍøÕ¾?
°ä²¼¹¦·ò 2020-12-231.SolarWinds¹©¸øÁ´¹¥»÷»î¶¯ÖдæÔÚеÄSUPERNOVAºóÃÅ

×êÑÐÈËÔ±·¢ÏÖSolarWinds Orion¹©¸øÁ´¹¥»÷»î¶¯ÖдæÔÚеÄSUPERNOVAºóÃÅ£¬¿ÉÄÜÀ´×ÔÁíÒ»¸öºÚ¿Í×éÖ¯¡£SUPERNOVAÊÇÖ²ÈëOrionÍøÂçºÍÀûÓ÷¨Ê½¼à¶½Æ½Ì¨´úÂëÖеÄWeb shell£¬¹¥»÷Õß¿ÉÀûÓøöñÒâÈí¼þÔÚÍÆËã»úÉÏÔËÐÐËÁÒâ´úÂë¡£¸Ã¶ñÒâ´úÂë½öÔ̺¬Ò»ÖÖDynamicRun²½Ö裬¿É½«²ÎÊý¶¯Ì¬±àÒëµ½ÄÚ´æÖеÄ.NET·¨Ê½¼¯ÖУ¬Òò¶ø²»»áÔÚÊÜϰȾÉ豸ÉÏÁôÏÂÈκκۼ£¡£¾µ÷²é£¬SUPERNOVAûº±¼û×ÖÊðÃû£¬ÕâÓë×î³õ·¢ÏÖµÄSunBurst·ÖÆç£¬»òÐíÊôÓÚÁíÒ»ºÚ¿Í×éÖ¯¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/a-second-hacking-group-has-targeted-solarwinds-systems/
2.¶à¹ú·¨Âɲ¿ÃŽáºÏµ·»ÙÈý¸öÌṩVPN·þÎñµÄÍøÕ¾

À´×ÔÃÀ¹ú¡¢µÂ¹ú¡¢·¨¹ú¡¢ÈðÊ¿ºÍºÉÀ¼µÄ·¨ÂÉ»ú¹¹½áºÏ£¬³É¹¦µ·»ÙÁËÈý¸öVPN·þÎñµÄÍøÕ¾¡£Õâ´ÎÐж¯µÄ´úºÅΪNova£¬ÖØÒªÓÉÅ·ÖÞÐ̾¯×éÖ¯½øÐÐе÷¡£±»²é·âµÄÈý¸öÍøÕ¾±ðÀëΪinsorg.org¡¢safe-inet.comºÍsafe-inet.net£¬¾ùÒÑ»îÔ¾ÁËÊ®¶àÄ꣬¿ÉÄÜÊôÓÚÒ»¸öÍŻÕâÐ©ÍøÕ¾¿ÉÌṩ¶à´ïÎå²ãµÄ´úÀíÍøÂ磬Òò¶øÀÕË÷Èí¼þÍŻÐÅÓþ¿¨ÇÔÈ¡(Magecart)ÍÅ»ï¡¢ÍøÂç´¹µöºÚ¿ÍºÍ²Î¼ÓÕË»§ÊÕ¹ºµÄºÚ¿ÍʱʱÓÃÕâЩ·þÎñÆ÷À´°µ²ØÕæÊµÉí·Ý¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/law-enforcement-take-down-three-bulletproof-vpn-providers/
3.¼ÓÃÜÇ®±ÒÂòÂôËùEXMOÔâµ½¹¥»÷£¬Ëðʧ×Ü×ʲúµÄ5£¥

Ó¢¹ú¼ÓÃÜÇ®±ÒÂòÂôËùEXMO³ÆÆäÔâµ½ÁËÍøÂç¹¥»÷£¬12ÔÂ21ÈÕºÚ¿ÍÔÚÈëÇÔìäÈÈÇ®°üºóµÁÈ¡ÁË´óÁ¿×ʲú¡£½ØÖÁĿǰ£¬EXMOÈÈÇ®°üÖв¿ÃŵÄBTC¡¢XRP¡¢ZEC¡¢USDTºÍETH¾ùÊܵ½ÁËÓ°Ïì¡£EXMOÔÚ·¢ÏÖ¹¥»÷ºóµ±¼´×ö³öÏìÓ¦£¬ÔÝÍ£ËùÓÐÌá¿î²¢³Áв¿ÊðÈÈÇ®°ü¡£ÊÜÓ°ÏìµÄÈÈÇ®°ü×ʽðÕ¼×Ü×ʲúµÄ½ü5%¡£µ«ÀäÇ®°üÀïµÄËùÓÐÇ®±Ò¶¼Êǰ²È«µÄ¡£EXMO°µÊ¾ÊÜÓ°ÏìÓû§µÄËùÓÐËðʧ½«ÓÉÆäÆëÈ«Åâ³¥²¢Í˿
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/exmo-cryptocurrency-exchange-hacked-loses-5-percent-of-total-assets/
4.ºÚ¿ÍÔÚ°µÍøÐ¹Â¶27Íò¸öLedgerÓû§µÄÃô¸ÐÐÅÏ¢

ºÚ¿ÍÔÚ°µÍøÐ¹Â¶ÁË27Íò¸öLedgerÓû§µÄÃô¸ÐÐÅÏ¢¡£LedgerÊÇÓÃÓÚ´æ´¢¡¢ÖÎÀíºÍÏúÊÛ¼ÓÃÜÇ®±ÒµÄÓ²¼þ¼ÓÃÜÇ®±ÒÇ®°ü¡£Õâ´ÎºÚ¿Íй¶ÁËÁ½¸öTXTÎļþ£¬±ðÀëΪÔ̺¬¶©ÔÄÁËLedgerͨѶµÄ1075382¸öÓû§µÄµç×ÓÓʼþµØÖ·µÄ¡°All Emails (Subscription).txt¡±£¬ºÍÔ̺¬272853λ²É°ìÕßÐÕÃû¡¢ÓʼĵØÖ·ºÍµç»°ºÅÂëµÄ¡°Ledger Orders (Buyers) only.txt¡±¡£ÕâЩй¶Êý¾Ý»òÐíÊÇÓÉ2020Äê6ÔµÄÊý¾Ýй¶ÊÂÎñµ¼Öµģ¬¿É±»ÓÃÀ´½øÐÐÍøÂç´¹µö¹¥»÷£¬ÒÔÇÔÈ¡Óû§¼ÓÃÜÇ®±Ò¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/physical-addresses-of-270k-ledger-owners-leaked-on-hacker-forum/
5.Jumio°ä²¼2020Äê¼ÙÈÕÐÂÕË»§Ú²Æ»î¶¯µÄ·ÖÎö»ã±¨

Jumio°ä²¼ÁË2020Äê¼ÙÈÕÐÂÕË»§Ú²Æ»î¶¯µÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬Óë2019ÄêµÄÏà±È£¬2020Äê»ùÓÚIDÑéÖ¤µÄÐÂÕÊ»§Ú²Æ»î¶¯ÔÚÈ«ÇòÁìÓòÄÚͬ±È½µÂä23.2£¥¡£Í¬Ê±£¬»ùÓÚ×ÔÅÄÕÕµÄÚ²ÆÂÊ£¨7.15£¥£©±È»ùÓÚIDµÄÚ²ÆÂÊ£¨1.41£¥£©¸ß5±¶£¬Õâ˵ÁËÈ»ÔÚ°µÍøÉÏÄܹ»Âòµ½µÄ±»µÁÉí·ÝÖ¤¼þµÄÊýÁ¿ÔÚ²»ÐÝÔö³¤¡£´Ë±í£¬µ±ÔÚÉí·ÝÑéÖ¤ÖÐʹÓÃSDKʱ£¬Ú²ÆÂÊÏÔÖøµÍÓÚÆäËûÇþ·(ÈçAPIºÍweb)¡£
ÔÎÄÁ´½Ó£º
https://go.jumio.com/2020-holiday-fraud-report
6.Cisco Talos°ä²¼2020ÄêËùÅû¶µÄ·ì϶µÄ»ØÊ׻㱨

Cisco Talos°ä²¼ÁË2020ÄêËùÅû¶µÄ·ì϶µÄ»ØÊ׻㱨¡£»ã±¨Ö¸³ö£¬ÔÚ2020Ä꣬Talos×ܹ²°ä²¼ÁË231·ÝÕ÷ѯ»ã±¨£¬Éæ¼°277¸öCVE£¬ÁìÓòÔ̺¬²Ù×÷ϵͳ¡¢IoTÉ豸¡¢Microsoft Office²úÆ·¡¢ä¯ÀÀÆ÷ºÍPDFÔĶÁÆ÷µÈ¡£½ÏΪ³ÁÒªµÄÊÇ£¬ÖØÒªPDFÀûÓ÷¨Ê½£¨Ô̺¬Adobe PDF¡¢Foxit PDF¡¢NitroPDFºÍGoogle PDFium£©ÖдæÔÚ¶à¸ö·ì϶£¬Intel¡¢NvidiaºÍAMDµÄͼÐÎÇý¶¯·¨Ê½ÖеĶà¸ö·ì϶£¬Firefox¡¢ChromeºÍSafariµÈÖØÒªWebä¯ÀÀÆ÷ÖдæÔÚ¶à¸ö·ì϶¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2020/12/vulnerability-discovery-2020.html


¾©¹«Íø°²±¸11010802024551ºÅ