CiscoǰԱ¹¤ÈÏ×ïɾ³ýWebEx TeamsµÄ400¶ą̀Ðé¹¹»ú £»£»£» £»£»£»£»£»ÐÂÎ÷À¼Ö¤È¯ÂòÂôËùÔâµ½DDoS¹¥»÷£¬£¬ £¬£¬£¬ÁÙʱÖÕ³¡ÂòÂô

°ä²¼¹¦·ò 2020-08-28

1.CiscoǰԱ¹¤ÈÏ×ïɾ³ýWebEx TeamsµÄ400¶ą̀Ðé¹¹»ú


1.jpg


˼¿ÆÇ°Ô±¹¤Sudhish Kasaba RameshÈÏ×ïÆäɾ³ýÁËWebEx TeamsµÄ400¶ą̀Ðé¹¹»ú¡£¡£¡£¡£¡£¡£¾ÝÆäÈÏ×ïºÍ̸ÖгÆ£¬£¬ £¬£¬£¬ÆäÈÏ¿ÉÔÚÈ¥Ö°5¸öÔºóµÄ2018Äê9ÔÂ24ÈÕ£¬£¬ £¬£¬£¬Î´¾­¹«Ë¾µÄÐí¿ÉÓÐÒâ½Ó¼û˼¿ÆµÄÔÆ»ù´¡¼Ü¹¹£¬£¬ £¬£¬£¬²¢´ÓÆä×Ô¼ºµÄGoogle Cloud ProjectÕÊ»§Öв¿ÊðÁËÒ»¸ö´úÂ룬£¬ £¬£¬£¬É¾³ýÁË˼¿ÆWebEx TeamsÀûÓ÷¨Ê½µÄ456¸öÐé¹¹»ú¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬ £¬£¬£¬¸ÃÊÂÎñµ¼ÖÂ16000¸öWebEx TeamsÕÊ»§±»¹Ø¹ØÁ˳¤´ïÁ½¸öÐÇÆÚ£¬£¬ £¬£¬£¬CiscoÆÆ·ÑÁËԼĪ140ÍòÃÀÔªÀ´¸´Ô­ÆäÀûÓÃÊܵ½µÄÇÖº¦£¬£¬ £¬£¬£¬²¢ÏòÊÜÓ°ÏìµÄ¿Í»§ÍË»¹Á˳¬¹ý100ÍòÃÀÔªµÄ¿î×Ó¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/ex-cisco-employee-pleads-guilty-to-deleting-16k-webex-teams-accounts/158748/    


2.Twitterµ·»Ù°ä²¼ÕþÖÎÀ¬»øÓʼþµÄ½©Ê¬ÍøÂçDracula


2.jpg


Twitter³É¹¦µ·»ÙÁËÓÃÀ´°ä²¼ÕþÖÎÀ¬»øÓʼþµÄ½©Ê¬ÍøÂçDracula¡£¡£¡£¡£¡£¡£É罻ýÌå×êÑÐ×éÖ¯Graphika°µÊ¾£¬£¬ £¬£¬£¬Æä·¢ÏÖÒ»¸öÓÉԼĪ3000¸ö½©Ê¬·¨Ê½×é³ÉµÄTwitter½©Ê¬ÍøÂ磬£¬ £¬£¬£¬ÖØÒªÓÃÀ´²¼ÕþÖÎÀ¬»øÓʼþ£¬£¬ £¬£¬£¬ÆäÖÐ×îÔçµÄÕË»§Ö»ÄÜ×·Òäµ½Ò»¸öÔÂǰ£¬£¬ £¬£¬£¬¼´2020Äê7Ô¡£¡£¡£¡£¡£¡£Graphikaµ÷²éÈËÔ±Ben Nimmo°µÊ¾£¬£¬ £¬£¬£¬TwitterÒѾ­¹ýÎʲ¢ÔÝÍ£Á˾ø´óÎÞÊýTwitter Dracula½©Ê¬ÍøÂçµÄÕÊ»§£¬£¬ £¬£¬£¬Í¬Ê±»¹½«Î´±»É¾³ýµÄÆäËûÕÊ»§ÏóÕ÷ΪÊÜÏÞ£¬£¬ £¬£¬£¬ÒÔ×èÖ¹Æä°ä²¼ÐÂÄÚÈÝ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/twitter-takes-down-dracula-botnet-pushing-pro-chinese-propaganda/


3.ALEXAǰ1Íò¸ö¶¥¼¶ÓòÃûÖÐÓÐ10£¥Ê¹ÓÃä¯ÀÀÆ÷Ö¸ÎÆ¾ç±¾


3.jpg

°®ºÉ»ªÖÝMozilla´óѧºÍ¼ÓÀû¸£ÄáÑÇ´óѧ´÷ά˹·ÖУµÄ×êÑÐÈËÔ±·¢ÏÖ£¬£¬ £¬£¬£¬ALEXAǰ1Íò¸ö¶¥¼¶ÓòÃûÖÐÓÐ10£¥ÔÚʹÓÃä¯ÀÀÆ÷Ö¸ÎÆ¾ç±¾¡£¡£¡£¡£¡£¡£ä¯ÀÀÆ÷Ö¸ÎÆ¾ç±¾ÊÇÒ»¶ÎJavaScript´úÂ룬£¬ £¬£¬£¬¸æ°×¹«Ë¾Í¨³£ÓÃÆäÀ´¸ú×ÙÓû§¡£¡£¡£¡£¡£¡£ÓÉÓÚÕâÖÖ·½Ê½¼Óº¦ÁËÓû§ÒþÖÔ£¬£¬ £¬£¬£¬Òò¶øFirefox¡¢Chrome¡¢Opera¡¢BraveºÍTorµÈ¶à¼Òä¯ÀÀÆ÷¹«Ë¾ÒѲ¿ÊðÁ˼ì²âºÍ×èÖ¹ÕâЩ¶ñÒâ´úÂëµÄÖ°ÄÜ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚÕâ´Î×êÑÐÖл¹·¢ÏÖÁ˺ܶàÐÂÖ¸ÎÆ¼¼Êõ£¬£¬ £¬£¬£¬Ô̺¬È¨ÏÞÖ¸ÎÆ¼ø±ð¡¢±íÎ§Ö¸ÎÆ¼ø±ð¡¢APIÖ¸ÎÆ¼ø±ð¡¢°´Ê±Ö¸ÎƼø±ð¡¢¶¯»­Ö¸ÎƼø±ðºÍ´«¸ÐÆ÷Ö¸ÎÆ¼ø±ð¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/a-quarter-of-the-alexa-top-10k-websites-are-using-browser-fingerprinting-scripts/


4.ÐÂÎ÷À¼Ö¤È¯ÂòÂôËù£¨NZX£©Ôâµ½DDoS¹¥»÷£¬£¬ £¬£¬£¬ÁÙʱÖÕ³¡ÂòÂô


4.jpg


ÐÂÎ÷À¼Ö¤È¯ÂòÂôËù£¨NZX£©Ô⵽ɢ²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷£¬£¬ £¬£¬£¬ÁÙʱÖÕ³¡ÂòÂô¡£¡£¡£¡£¡£¡£¾ÝϤÕâÆðÏ®»÷ÊÂÎñÀ´×Ô¹ú±í£¬£¬ £¬£¬£¬NZXÓÚ±¾µØ¹¦·òÖܶþÏÂÎç4µãÆðÍ·ÖÕ³¡ÁË¹ÉÆ±ÂòÂô¡£¡£¡£¡£¡£¡£Ëæºó£¬£¬ £¬£¬£¬ÔÚÖÜÈýºÍÖÜËĵĴó²¿Ãʦ·òÀ£¬ £¬£¬£¬Õ®ÎñºÍ¹ÉȨÂòÂôÖÕ³¡£¬£¬ £¬£¬£¬ÖÜËÄÏÂÎç4µãÆðÍ·£¬£¬ £¬£¬£¬ÑÜÉúÆ·ÂòÂôÖÕ³¡¡£¡£¡£¡£¡£¡£Ö»¹ÜNZXµÄ¾¯±¨Öв¢Î´×¢Ã÷¹¥»÷ÕßÉí·ÝÒÔ¼°¹¥»÷²½Ö裬£¬ £¬£¬£¬µ«×êÑÐÈËÔ±²Â²âËüÃǺÜÓпÉÄÜʹÓÃÁËÌṩDDoS×âÓ÷þÎñÕ¾µãµÄ·þÎñ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-zealand-stock-exchange-halted-trading-after-ddos-attacks/


5.ºÚ¿ÍÀûÓÃAutodeskÖзì϶¶Ô¹ú¼Ê¹¹Öþ¹«Ë¾ÌáÒé¹¥»÷


5.jpg

ºÚ¿ÍÀûÓÃ3DÍÆËã»úͼÐÎÈí¼þAutodeskÖеķì϶£¬£¬ £¬£¬£¬¶Ô¹ú¼Ê¹¹Öþ¹«Ë¾ÌáÒéÁËÍøÂç¼äµý¹¥»÷¡£¡£¡£¡£¡£¡£ºÚ¿ÍÕâ´ÎʹÓõĶñÒâÈí¼þÊÇAutodesk 3ds MaxÖеĶñÒâ²å¼þPhysXPluginMfx¡£¡£¡£¡£¡£¡£ËüÄܹ»·ÛËé3ds MaxÈí¼þµÄÉèÖÃÀ´ÔËÐжñÒâ´úÂ룬£¬ £¬£¬£¬²¢×îÖÕ´«²¼µ½WindowsϵͳÉÏµÄÆäËûÎļþ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬×êÑÐÈËÔ±·¢ÏÖºÚ¿Í»¹Ê¹ÓÃÁË´óÁ¿¼äµý¹¤¾ß£¬£¬ £¬£¬£¬ÆäÖÐÔ̺¬ÓÃÀ´Áгö¡¢Ñ¹Ëõ²¢½«Ìض¨ÎļþÉÏ´«µ½C2µÄHdCrawler£¬£¬ £¬£¬£¬ºÍÄܹ»½ØÆÁ²¢ÍøÂçÓû§Ãû¡¢ÍøÂçÊÊÅäÆ÷µÄIPµØÖ·µÄInfoStealer¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/hackers-exploit-autodesk-flaw-in-recent-cyberespionage-attack/158669/


6.Cisco°ä²¼°²È«¸üУ¬£¬ £¬£¬£¬½¨¸´ÆäÍøÂçÉ豸Öжà¸öÑϳÁµÄ·ì϶


6.jpg

Cisco°ä²¼°²È«¸üУ¬£¬ £¬£¬£¬½¨¸´Æä»¥»»»úºÍ¹âÏË´æ´¢½â¾ö¹æ»®ÖеÄ9¸ö·ì϶£¬£¬ £¬£¬£¬ÆäÖÐ8¸ö±»ÆÀΪ¸ßÑϳÁÐÔ¡£¡£¡£¡£¡£¡£Õâ´Î¸üÐÂÖУ¬£¬ £¬£¬£¬Ë¼¿ÆµÄNX-OSÊܵ½µÄÓ°Ïì×îΪÑϳÁ£¬£¬ £¬£¬£¬×ܹ²½¨¸´ÁË6¸ö·ì϶£¬£¬ £¬£¬£¬Ô̺¬Á½¸öCisco NX-OSÈí¼þÌìÇµÍø¹ØºÍ̸¶à²¥VPNÖеĻؾø·þÎñ·ì϶£¨CVE-2020-3397ºÍCVE-2020-3398£©£¬£¬ £¬£¬£¬»ùÓÚIPv6ºÍ̸¶ÀÁ¢×é²¥(PIM)ÖеĻؾø·þÎñ·ì϶(CVE-2020-3338)£¬£¬ £¬£¬£¬ÒÔ¼°·ì϶CVE-2020-3415£¬£¬ £¬£¬£¬CVE-2020-3517ºÍCVE-2020-3454¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/cisco-high-severity-bugs-impact-switches-fibre-storage/158691/