SonicWallÖÒ¸æÀûÓÃÆäVPN²úÆ·ÖÐ0dayµÄ¹¥»÷»î¶¯£»ÌØË¹À¸æ×´Ç°Ô±¹¤ÇÔÈ¡¹«Ë¾µÄ6ǧ¶à¸ö´úÂëÎļþ
°ä²¼¹¦·ò 2021-01-25
°²È«³§ÉÌSonicWal°ä²¼´¹Î£Í¨Öª£¬ÖÒ¸æÀûÓÃÆäVPN²úÆ·ÖÐ0dayµÄ¹¥»÷»î¶¯¡£¸Ã·ì϶λÓÚSecure Mobile Access£¨SMA£©VPNÉ豸¼°NetExtender VPN¿Í»§¶ËÖУ¬¿É±»ÓÃÀ´¶Ô¹«Ë¾µÄÄÚ²¿ÏµÍ³½øÐÐÐͬ¹¥»÷¡£SonicWallÉÐδ°ä²¼Óйظ÷ì϶µÄ¾ßÌåÐÅÏ¢£¬µ«Æ¾¾Ý»º½â´ëÊ©Åжϣ¬Æä¿ÉÄÜÊÇÊÇÉí·ÝÑéÖ¤·ì϶£¬¿É±»ÓÃÀ´Ôڿɹ«¿ª½Ó¼ûµÄÉ豸ÉÏÔ¶³ÌÀûÓá£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/sonicwall-firewall-maker-hacked-using-zero-day-in-its-vpn-device/
2.ÒôÀÖÀûÓÃShazam´æÔÚ2¸öÒþÖÔ·ì϶£¬Ó°Ïì1ÒÚ¶àÓû§

ÒôÀÖÀûÓÃShazam´æÔÚ2¸ö·ì϶CVE-2019-8791ºÍCVE-2019-8792£¬¿É±»ÓÃÀ´»ñÈ¡AndroidºÍiOSÓû§µÄµØÎ»£¬Ó°ÏìÁË1ÒÚ¶à¸öÓû§¡£ShazamÔÚµ¼º½ÖÐʹÓÃÁËÉî²ãÁ´½Ó£¬¶øÕƹÜÔÚWeb viewÖмÓÔØÍøÕ¾µÄÉî²ãÁ´½ÓûÓÐÑéÖ¤²ÎÊý£¬´Ó¶øµ¼ÖÂ±í²¿×ÊÔ´Äܹ»¶ÔÆä½øÐнÚÔì¡£¸Ãweb viewÄܹ»»ñÈ¡Éè±¸ÌØ¶¨µÄÐÅÏ¢ºÍÓû§µÄ¾«È·µØÎ»£¬Òò¶øºÚ¿Í¿ÉÓõ¥¸ö¶ñÒâURLÀ´»ñÈ¡Êܺ¦ÕßµØÎ»¡£Ä¿Ç°£¬¸Ã·ì϶Òѱ»½¨¸´¡£
ÔÎÄÁ´½Ó£º
https://www.ehackingnews.com/2021/01/location-data-of-more-than-100-million.html
3.ÌØË¹À¸æ×´Ç°Ô±¹¤ÇÔÈ¡¹«Ë¾µÄ6ǧ¶à¸ö´úÂëÎļþ

ÌØË¹À¸æ×´ÆäǰԱ¹¤Alex KhatilovÇÔÈ¡¹«Ë¾µÄ6ǧ¶à¸ö¾ç±¾ºÍ´úÂëÎļþ¡£ÌØË¹À³Æ¸ÃÔ±¹¤ÔÚÈëÖ°ÈýÌìºó¾ÍÆðÍ·ÇÔÈ¡»úÃÜÎļþ£¬²¢½«Æäת´¢ÖÁÓ×ÎÒ´æ´¢ÕÊ»§¡£½ØÖÁ1ÔÂ6ÈÕ£¬Alex KhatilovÔÚΪÆÚÁ½ÖܵŤ×÷ÖÐ×ܹ²ÇÔÈ¡ÁË6000¶à¸ö¾ç±¾»ò´úÂëÎļþ¡£ÌØË¹À°µÊ¾±»µÁÊý¾Ý¶ÔÌØË¹ÀºÍ¾ºÕùµÐÊÖÀ´À´Ëµ¶¼¼«ÓмÛÖµ£¬ËüÃÇÄܹ»Ô®ÊÔìäËû¹«Ë¾µÄ¹¤³Ìʦ¶ÔÌØË¹ÀµÄÁ÷³Ì½øÐÐÄæÏò¹¤³Ì£¬¶øºóÔڶ̹¦·òÄÚÒÔ¸üÉÙµÄÓöȴ´½¨Ò»¸öÀàËÆµÄϵͳ¡£
ÔÎÄÁ´½Ó£º
https://www.bloomberg.com/news/articles/2021-01-23/tesla-claims-engineer-stole-secrets-just-three-days-on-the-job?srnd=technology-vp
4.ºÚ¿Í¹«¿ª½»ÓÑÍøÕ¾MeetMindfulµÄ228ÍòÓû§µÄÊý¾Ý

ShinyHunters¹«¿ªÁ˽»ÓÑÍøÕ¾MeetMindfulµÄ1.2 GBÊý¾Ý£¬Éæ¼°Ô¼228Íò¸öÓû§¡£Ð¹Â¶Êý¾ÝÔ̺¬Óû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢³ÇÊÓ×¢ÖݺÍÓÊÕþ±àÂëµÄ¾ßÌåÐÅÏ¢¡¢Éí¶Îϸ½Ú¡¢Ô¼»áÆ«ºÃ¡¢»éÒöÇé¿ö¡¢µ®ÉúÈÕÆÚ¡¢Î³¶ÈºÍ¾¶È¡¢IPµØÖ·¡¢¹þÏ£ÃÜÂë¡¢FacebookÓû§IDºÍFacebookÉí·ÝÑéÖ¤ÁîÅÆµÈ¡£×êÑÐÈËÔ±³ÆÕâЩÊý¾ÝÒѱ»²é¿´ÁË1500´ÎÒÔÉÏ£¬²¢ÇҺܿÉÄÜÒѱ»ÏÂÔØ¡£MeetMindfulÉÐδ¶ÔÕâ´Îй¶ÊÂÎñ×ö³ö»ØÓ¦¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hacker-leaks-data-of-2-28-million-dating-site-users/
5.·¨¹úµÄVienneÔâµ½¹¥»÷£¬ÍÆËã»úºÍͨѶϵͳ±»·ÛËé

·¨¹úµÄVienneÓÚ1ÔÂ21ÈÕ£¨ÐÇÆÚËÄ£©Ôâµ½¹¥»÷£¬µ¼ÖÂÍÆËã»úºÍͨѶϵͳ±»·ÛËé¡£ÀíÊ»áÖ÷ϯAlain Pichon³Æ¹¥»÷²úÉúºó£¬Æä¹Ø¹ØÁËÕû¸öITϵͳ£¬²¢ÇÒËùÓÐÍÆËã»ú¶¼½«ÔÚÖÜÒ»ÖÕ³¡ÔËÐС£´Ë±í£¬¸Ãʡй©Õâ´Î¹¥»÷Ó뼸ÖÜǰLa RochelleÔâµ½µÄ¹¥»÷ÊÇͬÀàÐ͵ģ¬ºÚ¿ÍÀûÓò¡¶¾Ï°È¾ÉçÇø¡¢µ±²¿ÃÅÃÅÒÔ¼°Ë½Óª¹«Ë¾µÄϵͳ£¬ÒÔÀÕË÷Êê½ð¡£¸ÃÊ¡²»³ïËãÖ§¸¶ÈκÎÓöȣ¬²¢°µÊ¾ÕâÖÖ¹¥»÷´Ó³¤Ô¶À´¿´²»»á¶ÔÆä²úÉúÈκÎÓ°Ïì¡£
ÔÎÄÁ´½Ó£º
https://www.francebleu.fr/infos/societe/le-departement-de-la-vienne-victime-d-un-piratage-informatique-1611327525
6.Unit42°ä²¼ÍøÂç¹¥»÷µÄÇ÷Ïò·ÖÎö»ã±¨

Unit42°ä²¼ÁËÍøÂç¹¥»÷µÄÇ÷Ïò·ÖÎö»ã±¨¡£»ã±¨·¢ÏÖ2020Äê8Ôµ½10Ô£¬É¨Ã跨ʽ»î¶¯ºÍHTTPĿ¼±éÀúÀûÓó¢ÊÔ¼¤Ôö¡£2020ÄêÏļ¾ÔÚÒ°±í×î³£±»ÀûÓõķì϶ÊÇCVE-2012-2311ºÍCVE-2012-1823£¬µ«Êǵ½ÁËÇï¼¾³öÏÖÁËCVE-2020-17496ºÍCVE-2020-25213µÈеķì϶¡£´Ë±í£¬8ÔÂÖÁ10ÔÂÔÚÒ°·¢ÏÖÁËÎå¸öзì϶vBulletinÔ¶³ÌÖ´ÐдúÂë·ì϶¡¢WordPressÎļþÖÎÀíÆ÷²å¼þÔ¶³ÌÖ´ÐдúÂë·ì϶¡¢Nette´úÂë×¢Èë·ì϶¡¢Artica Web´úÀíSQL×¢Èë·ì϶ºÍOracle WebLogic ServerÔ¶³ÌÖ´ÐдúÂë·ì϶¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/network-attack-trends-internet-threats/


¾©¹«Íø°²±¸11010802024551ºÅ