Ì©¹úÒÆ¶¯ÔËÓªÉÌAISй¶83ÒÚÌõÓû§¼Í¼£»£»£»£»£»Èý¸öºÚ¿ÍÂÛ̳Ôâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Êý¾Ý¿âй©
°ä²¼¹¦·ò 2020-05-271.Ì©¹úÒÆ¶¯ÔËÓªÉÌAIS´æÔÚ°²È«ÎÊÌ⣬£¬£¬£¬£¬£¬£¬Ð¹Â¶83ÒÚÌõÓû§¼Í¼
°²È«×êÑÐÈËÔ±Justin Paine·¢ÏÖÁËÌ©¹úÒÆ¶¯ÔËÓªÉÌAISµÄElasticSearchÊý¾Ý¿â¶³öÔÚ¹«ÍøÉÏ£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶83ÒÚÌõÓû§¼Í¼£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ÒѾÍÑ»ú¡£¡£¡£¡£¡£¡£¡£Õâ´Îй©ÊÂÎñÓ°ÏìÁËÊý°ÙÍòÃûÓû§£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶4.7 TBÊý¾Ý¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚ¹«¹²ÍøÂçÉÏ·¢ÏÖ¸ÃÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÎÞÐèÃÜÂë¼´¿É½Ó¼û£¬£¬£¬£¬£¬£¬£¬Ô̺¬²éÎÊDNSºÍNetflowÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Êý¾Ý¿âÓÚ2020Äê5ÔÂ1ÈÕ³õ´Î¶³ö£¬£¬£¬£¬£¬£¬£¬ÓÚ5ÔÂ7ÈÕ±»°²È«×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬½ØÖ¹µ½´Ë¿Ìй¶¹¦·ò³¤´ïÈýÖÜ£¬£¬£¬£¬£¬£¬£¬¾ùÔÈÿ24Ó×ʱÔö³¤2ÒÚÌõÐÂÊý¾Ý¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2020/05/24/thai-billions-internet-records-leak/
2.ºÚ¿Í´Ó¶à¸ö¹ú¶ÈµÄÔÚÏßÉ̳ÇÇÔÈ¡20¶à¸öÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬¹«¿ªÏúÊÛ
ºÚ¿ÍÇÔÈ¡Á˶à¸ö¹ú¶ÈµÄÔÚÏßÉ̳ÇÖг¬¹ý20¸öÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ¹«¿ªÍøÕ¾ÏúÊÛ£¬£¬£¬£¬£¬£¬£¬Ô̺¬µÂ¹ú¡¢°ÍÎ÷¡¢ÃÀ¹ú¡¢Òâ´óÀû¡¢Ó¡¶È¡¢Î÷°àÑÀºÍ°×¶íÂÞ˹µÄÉ̳ǣ¬£¬£¬£¬£¬£¬£¬ÆäÖдó°ëÊý¾ÝÀ´×Ե¹ú¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬Âô·½Ä¿Ç°×ܹ²ÌṩÁ˳¬¹ý150Íò±Ê¼Í¼£¬£¬£¬£¬£¬£¬£¬µ«ÊÇÏÖʵ±»µÁÊý¾ÝÊýÁ¿Òª´óµÃ¶à¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñÖУ¬£¬£¬£¬£¬£¬£¬ºÚ¿Íͨ¹ý¹«¹²ÍøÂçÈëÇÖ²»°²È«µÄ·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬¶øºó¸´ÔìÊý¾Ý¿â²¢ÁôÏÂÖҸ棬£¬£¬£¬£¬£¬£¬ÒªÇóÊܺ¦Õß10ÌìÖ®ÄÚÖ§¸¶0.06 BTC£¨Ô¼ºÏ525ÃÀÔª£©µÄÊê½ð£¬£¬£¬£¬£¬£¬£¬²»È»¾Í»á¹«¿ªÊý¾Ý¿â¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý±ÈÌØ±ÒÇ®°üÎļþ¼Í¼£¬£¬£¬£¬£¬£¬£¬¸Ã»î¶¯ÊÇ2019Äê9ÔÂ20ÈÕÆðÍ·µÄ£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ºÚ¿ÍÒÑʵÏÖÁ˳¬¹ý100±ÊÂòÂô£¬£¬£¬£¬£¬£¬£¬»ñÀû×ܼÆ5.8 BTC£¨³¬¹ý51000ÃÀÔª£©£¬£¬£¬£¬£¬£¬£¬×î½üµÄÒ»´ÎÂòÂô²úÉúÔÚ5ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬½ö5Ô¾ÍÓÐ9´ÎÂòÂô¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hacker-extorts-online-shops-sells-databases-if-ransom-not-paid/
3.Èý¸öºÚ¿ÍÂÛ̳Ôâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÆäÊý¾Ý¿âй©
CybleµÄ×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÂÛ̳Nulled.ch¡¢Sinfulsite.comºÍsuxx.to±»ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬ÆäÊý¾Ý¿âй©¡£¡£¡£¡£¡£¡£¡£ÕâЩÂÛ̳ÊǺڿͺÍÍøÂç·¸×ï·Ö×ÓµÄÜöÝ͵أ¬£¬£¬£¬£¬£¬£¬ËûÃÇͨ³£ÔÚÕâÀï½øÐлáÉ̲¢¹²ÏíÓйØ×ÊÔ´¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶Êý¾ÝÔ̺¬ÂÛ̳³ÉÔ±¹²ÏíºÍÏúÊÛµÄй©Êý¾Ý¡¢ºÚ¿Í¹¤¾ß¡¢¶ñÒâÈí¼þºÍ½Ì³ÌµÈ¡£¡£¡£¡£¡£¡£¡£SUXX.TOºÍNulledµÄÊý¾Ýй¶ÓÚ5ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶Êý¾ÝÔ̺¬ÆäÓû§µÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Sinful SiteµÄй¶²úÉúÓÚ5ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬£¬ÆäÆëÈ«Êý¾Ý¿â£¨Ô̺¬¸öÈËÐÂÎÅ£©Ô⵽й¶¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬CybleÒÑÔÚÆäÊý¾Ýй¶²éÎÊ·þÎñAmIBreachedÖÐΪÉÏÊöËùº±¼û¾Ý¿â³ÉÁ¢Ë÷Òý£¬£¬£¬£¬£¬£¬£¬ÒԱ㹩È˲éÎÊ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/103726/data-breach/3-hacking-forums-hacked.html
4.ÃÀ¹ú¼ÓÖÝMLM¹«Ë¾ArbonneÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÊýǧÈËÐÅÏ¢
λÓÚÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖݵĹú¼Ê¶àµµ´ÎÓªÏú£¨MLM£©¹«Ë¾Arbonne·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬ÆäϵͳÓÚÉϸöÔÂÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÁËÊýǧÓû§µÄÓ×ÎÒÐÅÏ¢ºÍƾ֤¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝArbonneµÄ֪ͨ£¬£¬£¬£¬£¬£¬£¬Õâ´Îй¶ÊÂÎñ×ܹ²Ó°ÏìÁËÓÐ3527Ãû¼ÓÀû¸£ÄáÑÇÖݾÓÃñ£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÁËÓû§Ãû³Æ¡¢µç×ÓÓʼþºÍÓʼĵØÖ·¡¢¶©µ¥²É°ìº¹Çà¼Í¼¡¢µç»°ºÅÂëºÍArbonneÕÊ»§ÃÜÂëµÈ¡£¡£¡£¡£¡£¡£¡£Arbonne°µÊ¾£¬£¬£¬£¬£¬£¬£¬ÒÑÇ¿Ôì³ÁÖÃÊÜÓ°ÏìÓû§µÄÃÜÂ룬£¬£¬£¬£¬£¬£¬²¢½«ÎªËùÓÐÊÜÓ°ÏìÓû§ÌṩKroll¹«Ë¾µÄÒ»ÄêÃâ·ÑÐÅÓþ¼à¿Ø¡¢Ú²ÆÕ÷ѯºÍÉí·Ý͵ÇÔ¸´Ô·þÎñ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/arbonne-mlm-data-breach-exposes-user-passwords-personal-info/
5.ÉÏǧÆóҵϵͳÔâµ½Blue Mockingbird¶ñÒâÈí¼þ¹¥»÷
ÔÆ°²È«¹«Ë¾Red Canary·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬ÊýÒÔǧ¼ÆµÄÆóҵϵͳϰȾÁ˺ڿÍ×éÖ¯Blue MockingbirdµÄ¼ÓÃÜÇ®±ÒÍÚ¾ò¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËԱ˵£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í¹¥»÷µÄÊÇÃæÏò¹«¼ÒµÄ·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬ËûÃǶ¼ÔËÐÐ×ÅʹÓÃÁËTelerik¿ò¼ÜµÄASP.NETÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍÀûÓñ»×·×ÙΪCVE-2019-18935µÄ·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÚÖ¸±ê·þÎñÆ÷ÉÏÖ²Èë Web Shell£¬£¬£¬£¬£¬£¬£¬¶øºóʹÓÃJuicy Potato»ñÈ¡ÖÎÀíÔ±¼¶´ËÍâ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬²¢Åú¸Ä·þÎñÆ÷ÉèÖÃÒÔά³Ôìä³ÖÐøÐÔ¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÒ»µ©»ñµÃ¶ÔϵͳµÄÆëÈ«½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬±ã»áÏÂÔØ²¢×°ÖÃÓÃÓÚÍÚ¾òMonero£¨XMR£©¼ÓÃÜÇ®±ÒµÄÀûÓ÷¨Ê½XMRRig¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/thousands-of-enterprise-systems-infected-by-new-blue-mockingbird-malware-gang/
6.˼¿ÆÕë¶ÔÆäºô½ÐÖÐÐÄÈí¼þ°ä²¼¶à¸ö°²È«²¹¶¡£¬£¬£¬£¬£¬£¬£¬½¨¸´´úÂëÖ´Ðзì϶
˼¿Æ°ä²¼Á˰²È«²¹¶¡£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËÆäºô½ÐÖÐÐÄÈí¼þUnified Contact Center ExpressÖжà¸÷·ì϶£¬£¬£¬£¬£¬£¬£¬Ô̺¬Ò»¸ö´úÂëÖ´Ðзì϶£¨CVE-2020-3280£©¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚUnified CCEµÄJavaÔ¶³ÌÖÎÀí½çÃæÖУ¬£¬£¬£¬£¬£¬£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚ´æÔڸ÷ì϶µÄÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÓÉÓÚûÓа²È«µÄ·´ÐòÁл¯Óû§ÊäÈëÄÚÈݶø´æÔڵ쬣¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâµÄÐòÁл¯Java¶ÔÏóµ½Ìض¨ÕìÌýÆ÷À´ÀûÓô˷ì϶¡£¡£¡£¡£¡£¡£¡£Ë¼¿Æ°µÊ¾£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°¸Ã·ì϶»¹Ã»Óб»ÀûÓᣡ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/103765/security/cisco-unified-contact-center-express-flaw.html


¾©¹«Íø°²±¸11010802024551ºÅ