EquifaxÒòÊý¾Ýй¶֧¸¶7ÒÚÃÀÔª£»£»£»£»£»£»£»£»ProFTPD RCE·ì϶£¬£¬£¬£¬ £¬£¬³¬¹ý100Íǫ̀·þÎñÆ÷ÊÜÓ°Ïì

°ä²¼¹¦·ò 2019-07-23
1¡¢Equifax½«¶Ô2017ÄêÊý¾Ýй¶ÊÂÎñÖ§¸¶7ÒÚÃÀÔªºÍ½â½ð


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾Ý»ª¶û½ÖÈÕ±¨±¨Â·£¬£¬£¬£¬ £¬£¬Equifax½«Ö§¸¶½ü7ÒÚÃÀÔªµÄºÍ½â½ð£¬£¬£¬£¬ £¬£¬ÒÔ¸æÖÕÁª¹úÒµÎñίԱ»á£¨FTC£©¶Ô2017ÄêÊý¾Ýй¶ÊÂÎñµÄµ÷²é¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝºÍ½âºÍ̸£¬£¬£¬£¬ £¬£¬Equifax½«ÏòÃÀ¹úµ±¾ÖÖ§¸¶1.75ÒÚÃÀÔª·£¿£¿£¿£¿£¿£¿£¿î£¬£¬£¬£¬ £¬£¬²¢ÏòÏû·ÑÕß½ðÈÚ±£»£»£»£»£»£»£»£»¤¾Ö£¨CFPB£©Ö§¸¶1ÒÚÃÀÔªÃñÊ·£¿£¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£¡£¡£Equifax»¹½«ÉèÁ¢Ò»¸ö3ÒÚÃÀÔªµÄÅâ³¥»ù½ð£¬£¬£¬£¬ £¬£¬ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩÐÅÓþ¼à¿Ø·þÎñ£¬£¬£¬£¬ £¬£¬²¢ÔÚ±ØÒªÊ±½«½ð¶îÉýÖÁ4.25ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£×÷ΪºÍ½âºÍ̸µÄÒ»²¿ÃÅ£¬£¬£¬£¬ £¬£¬EquifaxÔ޳ɼÓÇ¿Æä°²È«´ëÊ©£¬£¬£¬£¬ £¬£¬²¢ÈõÚÈý·½¶¨ÆÚÆÀ¹ÀÆäÕþ²ß¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.voanews.com/economy-business/report-equifax-pay-700-million-breach-settlement


2¡¢ÃÀGAOл㱨³Æ¹ú˰¾Ö°²È«´ëÊ©²»¼°£¬£¬£¬£¬ £¬£¬ÄÉ˰ÈËÊý¾Ý´æÔÚ·çÏÕ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÃÀ¹úµ±¾ÖÎÊÔð¾Ö£¨GAO£©µÄл㱨ָ³ö£¬£¬£¬£¬ £¬£¬ÃÀ¹ú¹ú˰¾Ö£¨IRS£©Î´ÄÜÖ´ÐÐÆä¶àÄêÀ´½¨ÒéµÄ´óÁ¿°²È«½ÚÔì´ëÊ©£¬£¬£¬£¬ £¬£¬Ê¹µÃÄÉ˰ÈËÊý¾ÝºÍ²ÆÕþ»ã±¨Ãæ¶Ô¡°²»Êʵ±/δ±»¼ì²âµ½µÄʹÓᢴ۸Ļòй¶¡±·çÏÕ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ¶ÔIRSϵͳ½øÐÐ2018²ÆÕþÄê¶ÈÉó¼ÆÖ®ºó£¬£¬£¬£¬ £¬£¬GAOµÃ³ö½áÂÛÒÔΪ£¬£¬£¬£¬ £¬£¬IRSÈÔÓÐ127ÏÒé´ëÊ©±ØÒª½â¾ö£¬£¬£¬£¬ £¬£¬ÆäÖÐ107ÏÒéÀ´×ÔÏÈǰµÄÉ󼯣¬£¬£¬£¬ £¬£¬´ó²¿ÃލÒéÓë½Ó¼û½ÚÔìÓйأ¬£¬£¬£¬ £¬£¬ÆäËü½¨Ò麭¸ÇÅäÖÃÖÎÀí¡¢Ö°Ôð·ÖÀëºÍÓ¦¼±´òËã¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/irs-improved-security-but-taxpayer-data-is-still-at-risk/


3¡¢ºÚ¿ÍÔÚÍøÉϰ䲼Լ2500¸öDiscordÓû§µÄµÇ¼ʹ´¦


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ºÚ¿ÍÔÚÍøÉϰ䲼ÁËÔ¼2500¸öDiscordÓû§µÇ¼ʹ´¦µÄÁÐ±í£¬£¬£¬£¬ £¬£¬ÁбíÖÐÔ̺¬Óû§µÄµç×ÓÓʼþµØÖ·ºÍÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£DiscordÊÇÒ»¸öÓÎϷ̸ÌìÆ½Ì¨£¬£¬£¬£¬ £¬£¬Æ¾¾ÝºÚ¿ÍµÄ±íÊö£¬£¬£¬£¬ £¬£¬ÕâЩʹ´¦ÊÇͨ¹ýÒ»¸öµ¥Ò»µÄ´¹µöÍøÕ¾´¹µöµÃÀ´¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍøÕ¾Äܹ»ÀûÓÃDiscordµÄAPIÀ´½Ù³ÖÕâЩÕÊ»§¡£¡£¡£¡£¡£¡£¡£¡£DiscordÉÐδ¶Ô´ËÊÂÎñ°ä²¼ÉêÃ÷¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.vice.com/en_us/article/evye3a/hackers-publish-list-of-discord-email-addresses-passwords-login-credentials


4¡¢BlackBerry Cylance½¨¸´Æä·´²¡¶¾ÒýÇæÖеÄÈÆ¹ý·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

°Ä´óÀûÑǰ²È«³§ÉÌSkylightÕÒµ½ÁËÒ»ÖÖ²½ÖèÀ´ÈƹýBlackBerry CylanceµÄAI·´²¡¶¾ÒýÇæ£¬£¬£¬£¬ £¬£¬¸Ã²½ÖèÊÇ´Óij¸öÊÓÆµÓÎÏ·ÖлñÈ¡×Ö·û´®£¬£¬£¬£¬ £¬£¬¶øºó¸½¼Óµ½ÒÑÖªµÄ¶ñÒâÈí¼þÖС£¡£¡£¡£¡£¡£¡£¡£Cylance·´²¡¶¾ÒýÇæËÆºõ¶Ô¸ÃÓÎÏ·µÄÎļþ½øÐÐÁËÌØÊâ´¦Öᣡ£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±Ðû³Æ²âÊÔÁË384¸ö¶ñÒâÎļþ£¬£¬£¬£¬ £¬£¬»ñµÃÁ˳¬¹ý83%µÄ³É¹¦ÂÊ¡£¡£¡£¡£¡£¡£¡£¡£ÎªÏàʶ¾öÕâ¸öÎÊÌ⣬£¬£¬£¬ £¬£¬CylanceÒѾ­¶ÔÔÆÏµÍ³½øÐÐÁ˸üУ¬£¬£¬£¬ £¬£¬²¢½«ÔÚ½ÓÏÂÀ´µÄ¼¸ÌìÄÚÍÆ¹ãµ½¿Í»§¶Ëµã¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/blackberry-cylance-downplays-patches-antivirus-bypass


5¡¢Palo Alto Networks½¨¸´SSL VPNÖеÄRCE·ì϶£¬£¬£¬£¬ £¬£¬PoCÒѹ«¿ª


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Palo Alto Networks½¨¸´ÆäÆóÒµGlobalProtect SSL VPNÖеÄÒ»¸öRCE·ì϶£¬£¬£¬£¬ £¬£¬¸Ã·ì϶£¨CVE-2019-1579£©Ó°ÏìÁËGlobalProtectÃÅ»§ºÍGlobalProtectÍø¹Ø½Ó¿Ú²úÆ·£¬£¬£¬£¬ £¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ°æ±¾Ô̺¬PAN-OS 7.1.18¡¢8.0.11¡¢8.1.2ÒÔ¼°¸üÔçµÄ°æ±¾£¬£¬£¬£¬ £¬£¬ÓÉÓÚ×êÑÐÈËÔ±ÒѾ­°ä²¼ÁËPoC´úÂ룬£¬£¬£¬ £¬£¬½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±»¹É¨Ãèµ½ÓŲ½Ê¹ÓÃÁËÒ×Êܹ¥»÷µÄ²úÆ·£¬£¬£¬£¬ £¬£¬²¢ÏòÓŲ½½øÐÐÁ˻㱨¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.helpnetsecurity.com/2019/07/22/cve-2019-1579-poc/


6¡¢ProFTPD RCE·ì϶£¬£¬£¬£¬ £¬£¬³¬¹ý100Íǫ̀·þÎñÆ÷ÊÜÓ°Ïì


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ProFTPD°ä²¼Ð°汾1.3.6£¬£¬£¬£¬ £¬£¬½¨¸´Ò»¸ö¿Éµ¼ÖÂRCEµÄ·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶£¨CVE-2019- 12815£©ÓëProFTPDµÄmod_copyÄ£¿£¿£¿£¿£¿£¿£¿éÓйأ¬£¬£¬£¬ £¬£¬·ì϶ԭÒòÊÇmod_copyÄ£¿£¿£¿£¿£¿£¿£¿éµÄ×Ô½ç˵SITE CPFRºÍSITE CPTOºÅÁîûÓа´Ô¤ÆÚÅäÖù¤×÷¡£¡£¡£¡£¡£¡£¡£¡£ÖÎÀíÔ±¿Éͨ¹ý½ûÓÃmod_copyÄ£¿£¿£¿£¿£¿£¿£¿éÀ´»º½â¸Ã·ì϶¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝShodanµÄËÑË÷Á˾֣¬£¬£¬£¬ £¬£¬Ä¿Ç°Óг¬¹ý100Íò¸öProFTPd·þÎñÆ÷ÉÐδÉý¼¶½¨¸´²¹¶¡¡£¡£¡£¡£¡£¡£¡£¡£µÂ¹úCERT-BundÒ²Õë¶Ô¸Ã·ì϶ÏòÓû§·¢³ö¾¯±¨¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/proftpd-remote-code-execution-bug-exposes-over-1-million-servers/