Cyble·¢ÏÖºÚ¿ÍÔÚ°µÍøÏúÊÛÁ½ÒÚ¶àÖйú¹«ÃñµÄÐÅÏ¢£»×êÑÐÈËÔ±Åû¶Zend FrameworkÖÐÔ¶³Ì´úÂëÖ´Ðзì϶
°ä²¼¹¦·ò 2021-01-05
CybleµÄ×êÑÐÍŶӷ¢ÏÖºÚ¿ÍÔÚ°µÍøÏúÊÛÁ½ÒÚ¶àÖйú¹«ÃñµÄÐÅÏ¢¡£Õâ´Îй¶µÄÊý¾ÝÀ´×Ô¶à¸öƽ̨ºÍÈí¼þ£¬ÆäÖÐÔ̺¬730Íòºþ±±Ê¡¾£ÖÝÊй«°²ÏؾÓÃñµÄÉí·ÝÖ¤ºÅ¡¢ÐÔ±ð¡¢ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢ÊÖ»ú¡¢µØÖ·ºÍ´úÂëµÈÐÅÏ¢£¬4180Íò¸ö΢²©Óû§µÄÕ˺źÍÏàÓ¦µÄÊÖ»úºÅÂ룬ÒÔ¼°1.92ÒÚQQÓû§µÄÕ˺źÍÏàÓ¦µÄÊÖ»úºÅÂë¡£Õâ´Îй¶µÄÓëÖйú¹«ÃñÓйصļͼ×ÜÊý³¬¹ý2ÒÚ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/112966/deep-web/chinese-citizens-data-darkweb.html
2.д¹µö»î¶¯ÒÔÕÊ»§ÊÜÏÞ¶ÌÐÅΪµö¶üÇÔÈ¡PayPalÍ´´¦

еĴ¹µö»î¶¯ÒÔÕÊ»§ÊÜÏÞ¶ÌÐÅΪµö¶üÇÔÈ¡PayPalµÇ¼ʹ´¦¡£Õâ´Î¹¥»÷»î¶¯¼ÙÒâPayPal·¢ËÍڿƶÌÐÅ£¬Ðû³ÆÓû§µÄÕÊ»§Êܵ½ÓÀÔ¶ÏÞ¶È£¬Ðèµã»÷Á´½ÓÀ´ÑéÖ¤ÕÊ»§¡£¸ÃÁ´½Ó½«Óû§³Á¶¨Ïòµ½´¹µöÒ³Ãæ£¬ÒÔÇÔÈ¡Óû§µÇ¼ƾ֤¡£´Ë±í£¬ÔÚÓû§ÊäÈëµÇ¼ƾ֤ºó¸ÃÍøÕ¾»¹»á½øÒ»²½ÍøÂç¸ü¶à¾ßÌåÐÅÏ¢£¬ÀýÈçÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·ºÍÒøÐоßÌåÐÅÏ¢µÈµÈ£¬ÒÔÓÃÓÚ½«À´µÄÉí·ÝµÁÓù¥»÷£¬Õë¶ÔÐÔµÄÓã²æÊ½´¹µö¹¥»÷»ò½Ó¼ûÓû§µÄÆäËûÕÊ»§¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/beware-paypal-phishing-texts-state-your-account-is-limited/
3.Ò½ÁÆ»ú¹¹GenRxÔâµ½ÀÕË÷¹¥»÷£¬»¼Õß½¡È«Êý¾Ýй¶

ÃÀ¹úµÄÒ½ÁÆ»ú¹¹GenRx PharmacyÔâµ½ÀÕË÷¹¥»÷£¬»¼Õß½¡È«Êý¾Ýй¶¡£¹¥»÷²úÉúÔÚ2020Äê9ÔÂ27ÈÕ£¬ºÚ¿ÍÌáÒéÀÕË÷Èí¼þ¹¥»÷¡£¸Ã¹«Ë¾ÓÚµÚ¶þÌ죨9ÔÂ28ÈÕ£©·¢ÏÖÁ˸û²¢×èÖ¹ÁËºÚ¿Í¶ÔÆäϵͳµÄ½Ó¼û¡£¸Ã¹«Ë¾³ÆÕâ´ÎÍøÂç¹¥»÷²¢Î´³É¹¦£¬ÆäÒµÎñ²¢Î´Êܵ½Ó°Ï죬µ«ºÚ¿ÍÒѾ½Ó¼û²¢É¾³ýÁËijЩ»¼ÕßÊý¾Ý£¬Ô̺¬»¼ÕßID¡¢ÂòÂôID¡¢ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢ÐԱ𡢹ýÃô¡¢ÓÃÒ©Çåµ¥¡¢½¡È«´òËãÐÅÏ¢ºÍ´¦·½ÐÅÏ¢µÈ¡£
ÔÎÄÁ´½Ó£º
https://latesthackingnews.com/2021/01/04/genrx-pharmacy-ransomware-attack-resulted-in-data-breach/
4.ÓÊÂÖ¹«Ë¾AIDAÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Í¨ÕÛ·þÎñÁÙʱÖжÏ

µÂ¹úÓÊÂÖ¹«Ë¾AIDAÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Í¨ÕÛ·þÎñÁÙʱÖжϡ£AIDA³ÆÆäµç»°ÏµÍ³ºÍµç×ÓÓʼþϵͳÖжϣ¬±»ÆÈÈ¡µÞ2020Äê12ÔÂ26ÈÕ´ïµ½µÄÓÊÂÖµÄÐг̡£Ö»¹ÜAIDA²¢Î´Ð¹Â©ºÃ¶àϸ½Ú£¬µ«µÂ¹úýÌ屨·ÆäÔâµ½ÁËÍøÂç¹¥»÷£¬Ò»Ð©´¬Éϵij˿ÍÒ²°µÊ¾´¬²°Óë×ܲ¿Ö®¼äµÄͨѶÖжϡ£Õâ´Î¹¥»÷ÊÂÎñ»¹Ó°ÏìÁËCosta CruiseºÍCarnival Maritime¡£´Ë±í£¬Databreaches.net²Â²âAIDAÔâµ½ÁËDoppelpaymerÀÕË÷Èí¼þ¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://latesthackingnews.com/2021/01/03/aida-ships-face-service-disruptions-ransomware-attack-suspected/
5.×êÑÐÈËÔ±Åû¶Zend FrameworkÖÐÔ¶³Ì´úÂëÖ´Ðзì϶

×êÑÐÈËÔ±Ling YizhouÅû¶Zend Framework3.0.0ÖеÄÒ»¸ö²»³ÉÐŵķ´ÐòÁл¯·ì϶£¨CVE-2021-3007£©¡£Zend FrameworkµÄ×°ÖÃÁ¿³¬¹ý5.7ÒڴΣ¬±»ÓÃÀ´¹¹½¨ÃæÏò¶ÔÏóµÄwebÀûÓ÷¨Ê½¡£¸Ã·ì϶´æÔÚÓÚStreamÀàµÄÎö¹¹º¯ÊýÖУ¬¿É±»ÓÃÀ´¶ÔÒ×Êܹ¥»÷µÄPHPÀûÓýøÐÐÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷¡£´Ë±í£¬ZendÓÚ2020Äê1ÔÂǨáãµ½LaminasÏîÄ¿£¬ÔÚijЩ°æ±¾µÄLaminasÖÐÒ²´æÔÚÉÏÊöStream.phpÀ࣬Òò¶ø²¿ÃÅʹÓÃLaminas¹¹½¨µÄÀûÓÃÒ²¿ÉÄÜ»áÊܵ½Ó°Ïì¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/zend-framework-remote-code-execution-vulnerability-revealed/
6.IDG°ä²¼2020Ä갲ȫ³Áµã×êÑеķÖÎö»ã±¨

IDG°ä²¼ÁË2020Ä갲ȫ³Áµã×êÑеķÖÎö»ã±¨£¬Ö¼ÔÚ¸üºÃµØÏàʶ×éÖ¯´Ë¿ÌºÍÀ´Äê¹Ø×¢µÄ¸÷ÀలȫÏîÄ¿¡£¸Ã»ã±¨Ö¸³ö£¬³¬¹ýÈý·ÖÖ®Ò»£¨37£¥£©µÄÈËÒÔΪ£¬COVID-19ºÍÀͶ¯Á¦¸Ä¹ÛµÈÒâ±íÕýÆÈʹËûÃǽ«³Áµã´ÓÕ½Êõ°²È«¹¤×÷ÖÐ×ªÒÆ³öÀ´£»Èý·ÖÖ®Ò»µÄ¾ö²ßÕß°µÊ¾£¬ËûÃÇ2021Ä갲ȫԤË㽫¸ßÓÚCOVID-19֮ǰµÄÔ¤Ë㣬41£¥µÄÈ˰µÊ¾×ÜÌ尲ȫԤË㽫ÔÚ½«À´12¸öÔÂÄÚÔö³¤£»´óÎÞÊý£¨87£¥£©ÊÜ·ÃÕßÃ÷È·ÔÚ´ÓǰһÄêÖÐÔì³É°²È«ÊÂÎñµÄÔÒò¡£
ÔÎÄÁ´½Ó£º
https://www.idg.com/tools-for-marketers/2020-security-priorities-study/


¾©¹«Íø°²±¸11010802024551ºÅ