Area1»ã±¨¶íÂÞ˹ͨ¹ýEximÖзì϶×ÌÈÅÃÀ¹ú´óÑ¡£¡£¡£¡£¡£ ¡£¡£¡£»£»£»£»£»Naval Dome·¢ÏÖ×Ô2ÔÂÒÔÀ´Õë¶Ôº½Ô˵Ĺ¥»÷¼¤Ôö400%

°ä²¼¹¦·ò 2020-06-09

1.Area1°ä²¼»ã±¨ £¬£¬£¬£¬£¬£¬¶íÂÞ˹ͨ¹ýExim´úÀí(MTA)Öзì϶×ÌÈÅÃÀ¹ú´óÑ¡


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Area1°ä²¼»ã±¨ £¬£¬£¬£¬£¬£¬°µÊ¾¶íÂÞ˹ͨ¹ýExim´úÀí(MTA)Öзì϶×ÌÈÅÃÀ¹ú´óÑ¡¡£¡£¡£¡£¡£ ¡£¡£¡£ÃÀ¹úÍøÂ簲ȫÕ÷ѯÖÒ¸æ³Æ £¬£¬£¬£¬£¬£¬×Ô2019Äê8ÔÂÒÔÀ´ £¬£¬£¬£¬£¬£¬Óë¶íÂÞ˹¾ü·½ÓйصĺڿÍÒ»ÏòÔÚÀûÓÃÃÀ¹úEximÓʼþ´«Êä´úÀí(MTA)Èí¼þÖеķì϶(CVE-2019-10149)¡£¡£¡£¡£¡£ ¡£¡£¡£¸Ã·ì϶Äܹ»Ó°ÏìEximµÄ4.87µ½4.91°æ±¾ £¬£¬£¬£¬£¬£¬ÀûÓÃËüÄܹ»Ôö³¤ÌØÈ¨Óû§¡¢½ûÓÃÍøÂ簲ȫÉèÖá¢ÌáÒéBEC´¹µö»î¶¯µÈ¡£¡£¡£¡£¡£ ¡£¡£¡£¶øÏÖÒÑÈ·¶¨2018ÄêÃÀ¹ú´óÑ¡ÖÐÖÁÉÙ44ÃûºòÑ¡ÈËʹÓÃÁËExim·þÎñÆ÷ £¬£¬£¬£¬£¬£¬¶ø2020ÄêÃÀ¹ú´óÑ¡ÖÁÉÙ50ÃûºòÑ¡ÈËʹÓÃExim·þÎñÆ÷¡£¡£¡£¡£¡£ ¡£¡£¡£Òò¶ø £¬£¬£¬£¬£¬£¬Area1È·ÐÅ2020ÄêÑ¡¾ÙÖеÄÏÖÈκòÑ¡ÈËÔÚ2018ÄêÑ¡¾Ùµ½2019Äê2ÔÂÖ®¼ä×¢¶¨»áÊܵ½CVE-2019-10149µÄÓ°Ïì¡£¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cdn.area1security.com/reports/Area-1-Security-EximReport.pdf


2.Bolster°ä²¼2020ÄêµÚÒ»¼¾¶ÈÍøÂç´¹µöºÍÔÚÏßڲƭ»ã±¨


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


·Àڲƭ¹«Ë¾Bolster°ä²¼ÁË2020ÄêµÚÒ»¼¾¶ÈÍøÂç´¹µöºÍÔÚÏßڲƭ»ã±¨ £¬£¬£¬£¬£¬£¬·¢ÏÖÓëCOVID-19ÓйصÄÚ²Æ­ÍøÕ¾¼¤Ôö¡£¡£¡£¡£¡£ ¡£¡£¡£ÔÚ2020ÄêµÚÒ»¼¾¶È £¬£¬£¬£¬£¬£¬Bolster×ܹ²¼ì²âµ½854441¸öÍøÂç´¹µöºÍÚ¿Æ­ÍøÕ¾ºÍԼĪ400Íò¸ö¿ÉÒÉÍøÕ¾ £¬£¬£¬£¬£¬£¬ÆäÖÐÔ¼30£¥ÓëCOVID-19Óйء£¡£¡£¡£¡£ ¡£¡£¡£³ý´ËÖ®±í £¬£¬£¬£¬£¬£¬´ËÀàÍøÕ¾µÄÔö³¤Á¿Ò²ÔÚ²»ÐÝÔö³¤ £¬£¬£¬£¬£¬£¬´ÓÒ»Ô·ÝÿÌì3142¸öеÄÍøÒ³Ôö³¤µ½ÈýÔ·Ý8342¸öÍøÒ³ £¬£¬£¬£¬£¬£¬Ö±µ½3ÔÂ19ÈÕ´ïµ½¶¥·å £¬£¬£¬£¬£¬£¬Ò»ÌìÄÚ´´½¨Á˳¬¹ý25000¸öеÄÍøÒ³¡£¡£¡£¡£¡£ ¡£¡£¡£SaaSºÍµçÐÅÐÐÒµÊÇÊÜÍøÂç´¹µöÚ¿Æ­Ó°Ïì×î´óµÄÐÐÒµ £¬£¬£¬£¬£¬£¬Æä´ÎÊǽðÈÚ¡¢ÁãÊÛºÍÁ÷ýÌåÐÐÒµ¡£¡£¡£¡£¡£ ¡£¡£¡£Bolster»¹·¢ÏÖÁ˶à¸öÚ¿Æ­ÍøÕ¾ÊÛÂôαÔìµÄCOVID-19¼ÓÃÜÇ®±ÒºÍ¼ÓÃÜÇ®°ü £¬£¬£¬£¬£¬£¬ÆäÖ÷ÕÅÊÇÇÔÈ¡Êý¾ÝÒÔÓÃÓÚ½«À´µÄÍøÂç´¹µö¡¢¶ñÒâÈí¼þ·Ö·¢ºÍÇÔȡƾ֤¡£¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.businesswire.com/news/home/20200513005152/en/Bolster%E2%80%99s-Q1-2020-State-Phishing-Online-Fraud


3.Naval Dome·¢ÏÖ £¬£¬£¬£¬£¬£¬×Ô2ÔÂÒÔÀ´Õë¶Ôº½Ô˵ĺڿ͹¥»÷¼¤Ôö400%


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÒÔÉ«Áк£ÉÏÍøÂ簲ȫר¼ÒNaval Dome³Æ £¬£¬£¬£¬£¬£¬×Ô2020Äê2ÔÂÒÔÀ´ £¬£¬£¬£¬£¬£¬Õë¶Ôº½Ô˵ĺڿ͹¥»÷¼¤ÔöÁË400%¡£¡£¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾ÒÔΪCOVID-19ʹµÃº£ÉÏÄÜÔ´²¿ÃűÈÒÔǰ¸üÈÝÒ×Êܵ½ÍøÂç¹¥»÷ £¬£¬£¬£¬£¬£¬Í¬Ê±Ê¹¶ñÒâÈí¼þ¡¢ÀÕË÷Èí¼þºÍ´¹µöÓʼþ¼¤Ôö¡£¡£¡£¡£¡£ ¡£¡£¡£Naval DomeµÄCEO Itai Sela°µÊ¾ £¬£¬£¬£¬£¬£¬ÓÉÓÚCovid-19µ¼ÖµÄÉç½»Ï޶Ⱥ͸ôÀë´ëÊ© £¬£¬£¬£¬£¬£¬ÆÈʹԭʼÉ豸Ôì×÷ÉÌ£¨OEM£©¡¢¼¼ÊõÈËÔ±ºÍ¹©¸øÉ̽«Õý±¾¶ÀÁ¢µÄϵÍÂ䬽ӵ½InternetÉÏ £¬£¬£¬£¬£¬£¬OEM¼¼ÊõÈËÔ±ÎÞ·¨µ½´¬Ö»ºÍ×ê»úÉÏÉý¼¶OTϵͳ £¬£¬£¬£¬£¬£¬ÕâЩ¶¼µ¼Ö¸ÃÐÐÒµ¸üÒ×ÓÚ±»¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.offshore-energy.biz/naval-dome-400-increase-in-attempted-hacks-since-february-2020/


4.WordPress²å¼þPageLayer´æÔÚ·ì϶ £¬£¬£¬£¬£¬£¬Ó°Ï쳬¹ý20Íò¸öÍøÕ¾


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


WordfenceÍŶӷ¢ÏÖWordPress²å¼þPageLayer´æÔÚÁ½¸ö·ì϶ £¬£¬£¬£¬£¬£¬¿ÉÄÜ»áÓ°Ï쳬¹ý20Íò¸öÍøÕ¾¡£¡£¡£¡£¡£ ¡£¡£¡£µÚÒ»¸ö·ì϶µÄCVSSµÄÆÀ·ÖΪ7.4 £¬£¬£¬£¬£¬£¬¸Ã·ì϶µÄ´æÔÚÊÇÓÉÓÚ²å¼þµÄAJAX¶ËµãÖ»ÊÇͨ¹ýÒ»¸öÉí·ÝÑéÖ¤µÄ»á»°²é³­ÒªÇóÊÇ·ñÀ´×Ô /wp-admin £¬£¬£¬£¬£¬£¬¶ø²»²é³­·¢ËÍÒªÇóµÄÓû§µÄȨÏÞ £¬£¬£¬£¬£¬£¬Òò¶øÈκνӼûȨÏÞµÄÓû§¶¼Äܹ»Ö´ÐÐÈκβÙ×÷ £¬£¬£¬£¬£¬£¬¸Ã·ì϶¿É±»ÀûÓÃɾ³ýÄÚÈÝ»òÏòÏÖÓÐÒ³Ãæ×¢Èë¶ñÒâÄÚÈÝ¡£¡£¡£¡£¡£ ¡£¡£¡£µÚ¶þ¸ö·ì϶µÄCVSSÆÀ·ÖΪ8.8·Ö £¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚ¶ÌȱCSRF±£»£»£»£»£»¤ £¬£¬£¬£¬£¬£¬ºÚ¿ÍÄܹ»ÀûÓø÷ì϶ÏòÕ¾µãÒ³Ãæ×¢Èë¶ñÒâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£¡£Ä¿Ç° £¬£¬£¬£¬£¬£¬¿ª·¢ÈËÔ±ÒѾ­°ä²¼Á˰²È«²¹¶¡ÒÔ¶Ô·ì϶½øÐн¨¸´¡£¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/06/07/pagelayer-wordpress-plugin-vulnerabilities-risked-over-200k-websites/


5.ºÚ¿ÍÀûÓÃÍøÂç´¹µö¹¥»÷µÂ¹úÓ×ÎÒ·À»¤É豸¹©¸øÁ´


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


IBM X-Force×êÑÐÈËÔ±°ä²¼»ã±¨°µÊ¾ £¬£¬£¬£¬£¬£¬ºÚ¿ÍÔÚÀûÓÃÍøÂç´¹µö¹¥»÷Ò»¼ÒµÂ¹ú¹«Ë¾µÄ¸ß²ãÖÎÀíÈËÔ± £¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄÖØÒª¹¤×÷ÊDzɹºÓ×ÎÒ·À»¤É豸£¨PPE£© £¬£¬£¬£¬£¬£¬Ä¿Ç°ºÚ¿ÍÒÑÊÔͼÇÔÈ¡100¶àλ¸ß¹ÜµÄƾ֤¡£¡£¡£¡£¡£ ¡£¡£¡£3ÔÂ30ÈÕ £¬£¬£¬£¬£¬£¬µÂ¹úµ±¾ÖÓë¸Ã¹ú´óÐ͹«Ë¾½øÐлáÒé £¬£¬£¬£¬£¬£¬ÒªÇóÆäЭÖúµÂ¹ú²É°ìPPEÖ®ºó £¬£¬£¬£¬£¬£¬Ï®»÷¾ÍÆðÍ·ÁË¡£¡£¡£¡£¡£ ¡£¡£¡£Í³Ò»Ìì £¬£¬£¬£¬£¬£¬ÕâЩ´óÐ͹«Ë¾ÖеÄÒ»¸ö¹«Ë¾µÄ¸ß¹ÜÊÕµ½ÁËÀ´×Ô¶íÂÞ˹IPµØÖ·µÄÍøÂç´¹µö¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£¡£Êܺ¦ÕßÖдó°ëΪָ±ê¹«Ë¾ÖÐÓëÔËÓª¡¢²ÆÕþºÍ²É¹ºÓÐ¹ØµÄ¸ß¹Ü £¬£¬£¬£¬£¬£¬ÁíÒ»°ëÊôÓڸù«Ë¾µÄºÏ×÷¹«Ë¾µÄ¸ß¹Ü¡£¡£¡£¡£¡£ ¡£¡£¡£¾Ýµ÷²é £¬£¬£¬£¬£¬£¬ºÚ¿ÍÀûÓÃǶÈëʽ³¬Á´½Ó £¬£¬£¬£¬£¬£¬½«Êܺ¦Õß³Á¶¨Ïòµ½¼Ù×°³ÉMicrosoftµÇ¼±íµ¥µÄÍøÂç´¹µöµÇÂ¼Ò³Ãæ £¬£¬£¬£¬£¬£¬²¢½«ÍøÂçµ½µÄÊý¾Ý·¢Ë͵½¶à¸öYandexµç×ÓÓʼþÕÊ»§¡£¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-are-attacking-the-german-ppe-supply-chain/


6.еÄÍøÂç´¹µö»î¶¯Í¨¹ýStackBlitz¹¤¾ßÍйܴ¹µöÒ³Ãæ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Zscaler ThreatLabzÍŶӷ¢ÏÖ £¬£¬£¬£¬£¬£¬´Ë¿Ì´æÔÚ¶àÖÖÀûÓÃStackBlitz¹¤¾ßµÄÍøÂç´¹µö»î¶¯ £¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃÁËÔ¤Êèµ¼¿âÖ°Äܽ«ÍйܵÄÍøÒ³´Ó·þÎñÆ÷¶ËÖ±½Ó¹ý¶Éµ½¿Í»§¶Ë¡£¡£¡£¡£¡£ ¡£¡£¡£ÔÚµÚÒ»ÖÖ´¹µö»î¶¯ÖÐ £¬£¬£¬£¬£¬£¬ºÚ¿Í¼Ù×°³ÉÒ½ÁÆÎÀÉú×éÖ¯ £¬£¬£¬£¬£¬£¬Í¨¹ýOneDrive¹²Ïí·þÎñ·¢ËÍÎĵµ £¬£¬£¬£¬£¬£¬Óû§Ò»µ©µã»÷ÏÂÔØÁ´½Ó £¬£¬£¬£¬£¬£¬¾Í»á±»³Á¶¨Ïòµ½Outlook´¹µöÒ³Ãæ¡£¡£¡£¡£¡£ ¡£¡£¡£ÔÚÁíÒ»ÖÖ´¹µö»î¶¯ÖÐ £¬£¬£¬£¬£¬£¬´¹µöÓʼþÖеÄÁ´½ÓÖ¸ÏòÒ»¸öÍøÒ³ £¬£¬£¬£¬£¬£¬²¢Ô̺¬Ò»ÌõÐÂÎÅ×¢Ã÷ÄúÊÕµ½ÁË´øÓÐÓйØÎĵµÏÂÔØÁ´½ÓµÄ¹²ÏíÎĵµ £¬£¬£¬£¬£¬£¬Óû§µ¥»÷ÏÂÔØÁ´½Óºó±ã»á±»³Á¶¨Ïòµ½OneDriveÍøÂç´¹µöÍøÒ³¡£¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zscaler.com/blogs/research/new-campaign-abusing-stackblitz-tool-host-phishing-pages