SonicWallÖÒÑÔʹÓÃÆäVPN²úÆ·ÖÐ0dayµÄ¹¥»÷»î¶¯£»£»£»£»£»£»ÌØË¹À­ÆðËßǰԱ¹¤ÇÔÈ¡¹«Ë¾µÄ6ǧ¶à¸ö´úÂëÎļþ

Ðû²¼Ê±¼ä 2021-01-25
1.SonicWallÖÒÑÔʹÓÃÆäVPN²úÆ·ÖÐ0dayµÄ¹¥»÷»î¶¯


1.jpg


Çå¾²³§ÉÌSonicWalÐû²¼½ôÆÈ֪ͨ£¬£¬ £¬£¬£¬ÖÒÑÔʹÓÃÆäVPN²úÆ·ÖÐ0dayµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îλÓÚSecure Mobile Access£¨SMA£©VPN×°±¸¼°NetExtender VPN¿Í»§¶ËÖУ¬£¬ £¬£¬£¬¿É±»ÓÃÀ´¶Ô¹«Ë¾µÄÄÚ²¿ÏµÍ³¾ÙÐÐЭͬ¹¥»÷¡£¡£¡£¡£¡£¡£¡£SonicWallÉÐδÐû²¼ÓйظÃÎó²îµÄÏêϸÐÅÏ¢£¬£¬ £¬£¬£¬µ«Æ¾Ö¤»º½â²½·¥ÅжÏ£¬£¬ £¬£¬£¬Æä¿ÉÄÜÊÇÊÇÉí·ÝÑéÖ¤Îó²î£¬£¬ £¬£¬£¬¿É±»ÓÃÀ´ÔڿɹûÕæ»á¼ûµÄ×°±¸ÉÏÔ¶³ÌʹÓᣡ£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/sonicwall-firewall-maker-hacked-using-zero-day-in-its-vpn-device/


2.ÒôÀÖÓ¦ÓÃShazam±£´æ2¸öÒþ˽Îó²î£¬£¬ £¬£¬£¬Ó°Ïì1ÒÚ¶àÓû§


2.png


ÒôÀÖÓ¦ÓÃShazam±£´æ2¸öÎó²îCVE-2019-8791ºÍCVE-2019-8792£¬£¬ £¬£¬£¬¿É±»ÓÃÀ´»ñÈ¡AndroidºÍiOSÓû§µÄλÖ㬣¬ £¬£¬£¬Ó°ÏìÁË1ÒÚ¶à¸öÓû§¡£¡£¡£¡£¡£¡£¡£ShazamÔÚµ¼º½ÖÐʹÓÃÁËÉî²ãÁ´½Ó£¬£¬ £¬£¬£¬¶øÈÏÕæÔÚWeb viewÖмÓÔØÍøÕ¾µÄÉî²ãÁ´½ÓûÓÐÑéÖ¤²ÎÊý£¬£¬ £¬£¬£¬´Ó¶øµ¼ÖÂÍⲿ×ÊÔ´¿ÉÒÔ¶ÔÆä¾ÙÐпØÖÆ¡£¡£¡£¡£¡£¡£¡£¸Ãweb view¿ÉÒÔ»ñȡװ±¸Ìض¨µÄÐÅÏ¢ºÍÓû§µÄ׼ȷλÖ㬣¬ £¬£¬£¬Òò´ËºÚ¿Í¿ÉÓõ¥¸ö¶ñÒâURLÀ´»ñÈ¡Êܺ¦ÕßλÖᣡ£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬ £¬£¬£¬¸ÃÎó²îÒѱ»ÐÞ¸´¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/01/location-data-of-more-than-100-million.html


3.ÌØË¹À­ÆðËßǰԱ¹¤ÇÔÈ¡¹«Ë¾µÄ6ǧ¶à¸ö´úÂëÎļþ


3.png


ÌØË¹À­ÆðË߯äǰԱ¹¤Alex KhatilovÇÔÈ¡¹«Ë¾µÄ6ǧ¶à¸ö¾ç±¾ºÍ´úÂëÎļþ¡£¡£¡£¡£¡£¡£¡£ÌØË¹À­³Æ¸ÃÔ±¹¤ÔÚÈëÖ°ÈýÌìºó¾Í×îÏÈÇÔÈ¡ÉñÃØÎļþ£¬£¬ £¬£¬£¬²¢½«Æäת´¢ÖÁСÎÒ˽¼Ò´æ´¢ÕÊ»§¡£¡£¡£¡£¡£¡£¡£×èÖ¹1ÔÂ6ÈÕ£¬£¬ £¬£¬£¬Alex KhatilovÔÚΪÆÚÁ½ÖܵÄÊÂÇéÖÐ×ܹ²ÇÔÈ¡ÁË6000¶à¸ö¾ç±¾»ò´úÂëÎļþ¡£¡£¡£¡£¡£¡£¡£ÌØË¹À­ÌåÏÖ±»µÁÊý¾Ý¶ÔÌØË¹À­ºÍ¾ºÕùµÐÊÖÀ´À´Ëµ¶¼¼«ÓмÛÖµ£¬£¬ £¬£¬£¬ËüÃÇ¿ÉÒÔ×ÊÖúÆäËû¹«Ë¾µÄ¹¤³Ìʦ¶ÔÌØË¹À­µÄÁ÷³Ì¾ÙÐÐÄæÏò¹¤³Ì£¬£¬ £¬£¬£¬È»ºóÔÚ¶Ìʱ¼äÄÚÒÔ¸üÉÙµÄÓöȽ¨ÉèÒ»¸öÀàËÆµÄϵͳ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bloomberg.com/news/articles/2021-01-23/tesla-claims-engineer-stole-secrets-just-three-days-on-the-job?srnd=technology-vp


4.ºÚ¿Í¹ûÕæ½á½»ÍøÕ¾MeetMindfulµÄ228ÍòÓû§µÄÊý¾Ý


4.png


ShinyHunters¹ûÕæÁËÈ´½»ÍøÕ¾MeetMindfulµÄ1.2 GBÊý¾Ý£¬£¬ £¬£¬£¬Éæ¼°Ô¼228Íò¸öÓû§¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶Êý¾Ý°üÀ¨Óû§µÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢¶¼»á¡¢ÖݺÍÓÊÕþ±àÂëµÄÏêϸÐÅÏ¢¡¢ÉíÌåϸ½Ú¡¢Ô¼»áÆ«ºÃ¡¢»éÒö״̬¡¢³öÉúÈÕÆÚ¡¢Î³¶ÈºÍ¾­¶È¡¢IPµØµã¡¢¹þÏ£ÃÜÂë¡¢FacebookÓû§IDºÍFacebookÉí·ÝÑéÖ¤ÁîÅÆµÈ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³ÆÕâЩÊý¾ÝÒѱ»Éó²éÁË1500´ÎÒÔÉÏ£¬£¬ £¬£¬£¬²¢ÇҺܿÉÄÜÒѱ»ÏÂÔØ¡£¡£¡£¡£¡£¡£¡£MeetMindfulÉÐδ¶Ô´Ë´Îй¶ÊÂÎñ×ö³ö»ØÓ¦¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-leaks-data-of-2-28-million-dating-site-users/


5.·¨¹úµÄVienneÔâµ½¹¥»÷£¬£¬ £¬£¬£¬ÅÌËã»úºÍͨѶϵͳ±»ÆÆËð


5.png


·¨¹úµÄVienneÓÚ1ÔÂ21ÈÕ£¨ÐÇÆÚËÄ£©Ôâµ½¹¥»÷£¬£¬ £¬£¬£¬µ¼ÖÂÅÌËã»úºÍͨѶϵͳ±»ÆÆË𡣡£¡£¡£¡£¡£¡£ÀíÊ»áÖ÷ϯAlain Pichon³Æ¹¥»÷±¬·¢ºó£¬£¬ £¬£¬£¬Æä¹Ø±ÕÁËÕû¸öITϵͳ£¬£¬ £¬£¬£¬²¢ÇÒËùÓÐÅÌËã»ú¶¼½«ÔÚÖÜÒ»×èÖ¹ÔËÐС£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬¸Ãʡ͸¶´Ë´Î¹¥»÷Ó뼸ÖÜǰLa RochelleÔâµ½µÄ¹¥»÷ÊÇͬÀàÐ͵Ä£¬£¬ £¬£¬£¬ºÚ¿ÍʹÓò¡¶¾Ñ¬È¾ÉçÇø¡¢Õþ¸®²¿·ÖÒÔ¼°Ë½Óª¹«Ë¾µÄϵͳ£¬£¬ £¬£¬£¬ÒÔÀÕË÷Êê½ð¡£¡£¡£¡£¡£¡£¡£¸ÃÊ¡²»ÍýÏëÖ§¸¶ÈκÎÓöÈ£¬£¬ £¬£¬£¬²¢ÌåÏÖÕâÖÖ¹¥»÷´Ó¾ÃÔ¶À´¿´²»»á¶ÔÆä±¬·¢ÈκÎÓ°Ïì¡£¡£¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.francebleu.fr/infos/societe/le-departement-de-la-vienne-victime-d-un-piratage-informatique-1611327525


6.Unit42Ðû²¼ÍøÂç¹¥»÷µÄÇ÷ÊÆÆÊÎö±¨¸æ


6.png


Unit42Ðû²¼ÁËÍøÂç¹¥»÷µÄÇ÷ÊÆÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£±¨¸æ·¢Ã÷2020Äê8Ôµ½10Ô£¬£¬ £¬£¬£¬É¨Ãè³ÌÐò»î¶¯ºÍHTTPĿ¼±éÀúʹÓÃʵÑ鼤Ôö¡£¡£¡£¡£¡£¡£¡£2020ÄêÏÄÈÕÔÚÒ°Íâ×î³£±»Ê¹ÓõÄÎó²îÊÇCVE-2012-2311ºÍCVE-2012-1823£¬£¬ £¬£¬£¬¿ÉÊǵ½ÁËÇï¼¾·ºÆðÁËCVE-2020-17496ºÍCVE-2020-25213µÈеÄÎó²î¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬8ÔÂÖÁ10ÔÂÔÚÒ°·¢Ã÷ÁËÎå¸öÐÂÎó²îvBulletinÔ¶³ÌÖ´ÐдúÂëÎó²î¡¢WordPressÎļþÖÎÀíÆ÷²å¼þÔ¶³ÌÖ´ÐдúÂëÎó²î¡¢Nette´úÂë×¢ÈëÎó²î¡¢Artica WebÊðÀíSQL×¢ÈëÎó²îºÍOracle WebLogic ServerÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/network-attack-trends-internet-threats/