MicrosoftµÄHaloÓÎÏ·¿ª·¢ÍøÕ¾Ôâµ½ÒÀÀµ»ìÏý¹¥»÷£»£» £» £»ÁªºÏ¹ú¹ú¼ÊµçÐÅͬÃËÐû²¼2020ÄêÈ«ÇòÍøÂçÇå¾²Ö¸Êý

Ðû²¼Ê±¼ä 2021-07-01

1.MicrosoftµÄHaloÓÎÏ·¿ª·¢ÍøÕ¾Ôâµ½ÒÀÀµ»ìÏý¹¥»÷


1.jpg


Ñо¿Ö°Ô±·¢Ã÷MicrosoftµÄHaloÓÎÏ·¿ª·¢ÍøÕ¾Ôâµ½ÒÀÀµ¹ØÏµ»ìÏý¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£Ricardo Iramar dos SantosÔÚÉó¼Æ¿ªÔ´°üSymphonyElectronʱ·¢Ã÷Á˸ðüʹÓõÄÒ»¸ö¿ÉÒɵÄÒÀÀµÏîswift-search£¬£¬£¬£¬£¬ £¬£¬£¬²¢²»±£´æÓÚ¹«¹²npmjs.com×¢²á±íÖС£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±½«°ü·¢Ë͵½npm×¢²á±íºóÊÕµ½ÁËÀ´×Ô΢ÈíЧÀÍÆ÷µÄping-back£¬£¬£¬£¬£¬ £¬£¬£¬»á¼ûhttps://51.141.173.203ʱ£¬£¬£¬£¬£¬ £¬£¬£¬SSLÖ¤ÊéµÄCN×Ö¶ÎÖ¸Ïò*.test.svc.halowaypoint.com£¬£¬£¬£¬£¬ £¬£¬£¬Õâ½øÒ»²½Ö¤ÊµÎú΢ÈíЧÀÍÆ÷Ôâµ½ÁËÒÀÀµ»ìÏý¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsofts-halo-dev-site-breached-using-dependency-hijacking/


2.Ö´·¨²¿·Ö²é»ñË«ÖØ¼ÓÃÜЧÀÍDoubleVPNµÄЧÀÍÆ÷ºÍÈÕÖ¾


2.jpg


2021Äê6ÔÂ29ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬¶à¹úÖ´·¨²¿·ÖÀֳɲé»ñÁ˶íÂÞ˹DoubleVPNµÄЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£¡£DoubleVPN¿É¶ÔÊý¾Ý¾ÙÐÐË«ÖØ¡¢ÈýÖØÉõÖÁËÄÖØ¼ÓÃÜ£¬£¬£¬£¬£¬ £¬£¬£¬Í¨³£±»¹¥»÷ÕßÓÃÀ´ÔÚÖ´ÐжñÒâ»î¶¯Ê±Èƹý¼ì²â¡£¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÐж¯ÊÇÓɵ¹úBKA¡¢ºÉÀ¼ÕþÖξ֡¢Áª°îÊÓ²ì¾Ö¡¢Ó¢¹ú¹ú¼Ò·¸·¨¾Ö¡¢ÃÀ¹úÌØÇھֺͼÓÄôó»Ê¼ÒÆï¾¯µÈ×éÖ¯ÁªºÏ·¢¶¯µÄ£¬£¬£¬£¬£¬ £¬£¬£¬ÀֳɻñµÃÁËDoubleVPNЧÀÍÆ÷µÄ»á¼ûȨ£¬£¬£¬£¬£¬ £¬£¬£¬²¢²é»ñÁËÆäËùÓпͻ§µÄСÎÒ˽¼ÒÐÅÏ¢¡¢ÈÕÖ¾ºÍͳ¼ÆÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£Å·ÖÞÐ̾¯×éÖ¯ÌåÏÖÎÞ·¨·ÖÏí¸ü¶àϸ½Ú¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/doublevpn-servers-logs-and-account-info-seized-by-law-enforcement/


3.FacebookÆðËß4¸öÔ½ÄϺڿÍÐ®ÖÆÆä¶à¸öÓû§µÄÕË»§


3.jpg


FacebookÆðËßÁË4¸öÔ½ÄϺڿÍÐ®ÖÆÆäÓû§ÕË»§¡£¡£¡£¡£¡£¡£¡£¡£Facebook³ÆÕâÕâЩºÚ¿ÍʹÓûỰ͵ÇÔ»òcookie͵ÇÔÊÖÒÕ»á¼û¶à¸ö¹ã¸æºÍÓªÏú¹«Ë¾Ô±¹¤µÄFacebookÕÊ»§£¬£¬£¬£¬£¬ £¬£¬£¬²¢Ê¹Óñ»ºÚµÄÕÊ»§Ðû´«ÃûΪAd Manager for FacebookµÄ¶ñÒâAndroidÓ¦Óᣡ£¡£¡£¡£¡£¡£¡£¸ÃÓ¦ÓóÌÐòÍйÜÔÚ¹Ù·½Google PlayÊÐËÁÖУ¬£¬£¬£¬£¬ £¬£¬£¬ÔÚ2020Äê12ÔÂÖÁ2021Äê5ÔÂÒѱ»×°ÖÃÁË10000¶à´Î¡£¡£¡£¡£¡£¡£¡£¡£Facebookͬʱ»¹ÆðËßÁ˼ÓÀû¸£ÄáÑǹ«Ë¾N&J USA Incorporated£¬£¬£¬£¬£¬ £¬£¬£¬¸Ã¹«Ë¾ÔÚFacebookÉÏͶ·ÅÁËÓйشò°ç¡¢ÊÖ±íºÍÍæ¾ßµÄÕ©Æ­¹ã¸æ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/facebook-sues-four-vietnamese-nationals-for-account-hijacks/


4.Ñо¿Ö°Ô±Åû¶Google Compute EngineδÐÞ¸´µÄÎó²î


4.jpg


Ñо¿Ö°Ô±Åû¶ÁËÒ»¸öÓ°ÏìGoogle Compute EngineµÄδÐÞ¸´µÄÎó²î¡£¡£¡£¡£¡£¡£¡£¡£Google Compute Engine(GCE)ÊÇGoogle Cloud PlatformµÄ»ù´¡ÉèÊ©¼´Ð§ÀÍ(IaaS) ×é¼þ£¬£¬£¬£¬£¬ £¬£¬£¬Ê¹Óû§Äܹ»°´Ð轨ÉèºÍÆô¶¯ÐéÄâ»ú (VM)¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚISC DHCP¿Í»§¶ËʹÓÃÈõµÄÎ±Ëæ»úÊýµÄµ¼ÖµÄ£¬£¬£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßʹÓÃÕâ¸öÎó²î£¬£¬£¬£¬£¬ £¬£¬£¬¿ÉÒÔͨ¹ýSSHÊÚÓè×Ô¼º»á¼ûȨÏÞ£¬£¬£¬£¬£¬ £¬£¬£¬È»ºóÒÔrootÓû§Éí·ÝµÇ¼¡£¡£¡£¡£¡£¡£¡£¡£¹È¸èÓÚ2020Äê9ÔÂ27ÈÕ»ñϤ¸ÃÎÊÌ⣬£¬£¬£¬£¬ £¬£¬£¬µ«ÖÁ½ñÉÐδÐû²¼²¹¶¡¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/06/unpatched-virtual-machine-takeover-bug.html


5.ÈÕ±¾¹«Ë¾Airport Refueling³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷


5.jpg


ÈÕ±¾Îª·É»úÌṩ¼ÓÓÍЧÀ͵ÄJapan Airport Refueling³ÆÆäÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ2021Äê6ÔÂ21ÈÕÆÆÏþ£¬£¬£¬£¬£¬ £¬£¬£¬¹«Ë¾ÄÚ²¿µÄÍøÂçϵͳ±¬·¢¹ÊÕÏ¡£¡£¡£¡£¡£¡£¡£¡£ÊÓ²ì֤ʵÊÇÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬ £¬£¬£¬¸Ã¹«Ë¾ÊÕµ½ÏàʶÃÜЧÀÍÆ÷Êý¾ÝµÄÊê½ðÒªÇ󣬣¬£¬£¬£¬ £¬£¬£¬µ«ËƺõûÓÐÈκÎÊý¾Ý±»Ð¹Â¶¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³Æ£¬£¬£¬£¬£¬ £¬£¬£¬ÆäÕýÔÚÓ뾯·½ÏàÖú¶Ô´ËÊÂÕö¿ªÊӲ죬£¬£¬£¬£¬ £¬£¬£¬²¢ÇҴ˴ι¥»÷²¢Î´Ó°ÏìÆä¼ÓÓÍÊÂÇéºÍÆäËûÓªÒµ¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚÉÐÎÞÓйØÀÕË÷Èí¼þÀàÐͺÍÊÜÓ°ÏìµÄÊý¾ÝÀàÐ͵ÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/jp-japan-airport-refueling-co-discloses-ransomware-incident-refueling-work-not-impacted/


6.ÁªºÏ¹ú¹ú¼ÊµçÐÅͬÃËÐû²¼2020ÄêÈ«ÇòÍøÂçÇå¾²Ö¸Êý


6.jpg


ÁªºÏ¹ú¹ú¼ÊµçÐÅͬÃË (ITU) Ðû²¼ÁË2020ÄêÈ«ÇòÍøÂçÇå¾²Ö¸Êý(GCI)¡£¡£¡£¡£¡£¡£¡£¡£GCIÊÇÒ»¸öÖµµÃÐÅÈεIJο¼£¬£¬£¬£¬£¬ £¬£¬£¬ËüȨºâÁ˸÷¹úÔÚÈ«Çò²ãÃæÉ϶ÔÍøÂçÇå¾²µÄͶÈ룬£¬£¬£¬£¬ £¬£¬£¬Éæ¼°Ðí¶àÐÐÒµºÍ²¿·Ö¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÖ¸ÊýÆÀ¹ÀÁË5¸ö·½Ãæ:Ö´·¨²½·¥¡¢ÊÖÒÕ²½·¥¡¢×éÖ¯²½·¥¡¢ÄÜÁ¦Éú³¤ºÍÏàÖú£¬£¬£¬£¬£¬ £¬£¬£¬È»ºó»ã×ܵóöÒ»¸ö×ۺϷÖÊý¡£¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬ £¬£¬£¬2020Äê¸ÃÖ¸ÊýµÄÖÐλÊý±È2018Äê¸ß9.5%£¬£¬£¬£¬£¬ £¬£¬£¬ÆäÖÐÃÀ¹úÅÅÃûµÚÒ»£¬£¬£¬£¬£¬ £¬£¬£¬Ó¢¹úÓëÉ³ÌØ°¢À­²®²¢Áеڶþ¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.itu.int/en/ITU-D/Cybersecurity/Pages/global-cybersecurity-index.aspx