Carding Action 2020Ðж¯ÆÆ»ñһ·´ó¹æÄ£Ú¿Æ­°¸¼þ£»£»£»£»£»£»£»£»×êÑÐÍŶӷ¢ÏÖStruxureWare´æÔÚ6¸öеÄ0day

°ä²¼¹¦·ò 2020-12-01
1.Carding Action 2020Ðж¯ÆÆ»ñһ·´ó¹æÄ£Ú¿Æ­°¸¼þ


1.jpg


ÍøÂ簲ȫ¹«Ë¾Group-IBÓëÅ·ÖÞµÄÐÙÑÀÀû¡¢Ó¢¹úºÍÒâ´óÀûµ±¾ÖºÏ×÷ £¬£¬£¬£¬£¬ÌáÒéCarding Action 2020Ðж¯ £¬£¬£¬£¬£¬ÆÆ»ñһ·´ó¹æÄ£ÐÅÓþ¿¨ÂòÂôÚ¿Æ­°¸¼þ¡£¡£¡£¡£¡£¸Ã»î¶¯Õë¶Ô¶à¸ö°µÍøÊг¡ £¬£¬£¬£¬£¬ÔÚÐÅÓþ¿¨ÂòÂôÉ̵êºÍ°µÍøÂòÂôƽ̨ÉϲéÕÒÓëÂòÂô±»µÁ¿¨¾ßÌåÐÅÏ¢ÓйصÄڲƭÕß £¬£¬£¬£¬£¬Ö¼ÔÚ¼õÇáºÍÔ¤·À½ðÈÚ»ú¹¹ºÍ³Ö¿¨ÈËÔâ·êËðʧ £¬£¬£¬£¬£¬Ä¿Ç°Ô¼×èÖ¹ÁË4000ÍòÅ·ÔªµÄËðʧ¡£¡£¡£¡£¡£¹ú¼ÊÐ̾¯×éÖ¯°ä·¢¿ÛÁôÁËÈýÃûÀ´×ÔÄáÈÕÀûÑǵÄÏÓÒÉÈË £¬£¬£¬£¬£¬¾ÝÐÅËûÃÇÊÇÒ»¸ö¹¥»÷ÁË150¸öµ±¾Ö×éÖ¯ºÍ¹«Ë¾µÄÍÅ»ïµÄ³ÉÔ±¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/authorities-disrupt-dark-web-credit-card-trading-scam/


2.×êÑÐÍŶӷ¢ÏÖStruxureWare´æÔÚ6¸öеÄ0day


2.jpg


TIMºì¶Ó×êÑÐÍŶӣ¨RTR£©·¢ÏÖStruxureWare´æÔÚ6¸öеÄ0day £¬£¬£¬£¬£¬Ä¿Ç°Òѱ»ÆäÔì×÷ÉÌÊ©ÄÍµÂµçÆø½¨¸´¡£¡£¡£¡£¡£Õâ´Î·¢Ïֵķì϶±ðÀëΪ²»ÊÜÏ޶ȵÄÎļþÉÏ´«·ì϶£¨CVE-2020-7569£© £¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ»£»£»£»£»£»£»£»XML±í²¿ÊµÌåÒýÓõÄÏ޶Ȳ»µ±£¨CVE-2020-7572£© £¬£¬£¬£¬£¬¿Éµ¼ÖÂÃô¸ÐÊý¾Ýй¶£»£»£»£»£»£»£»£»WindowsδÒýÓÃËÑË÷õè¾¶£¨CVE-2020-28209£©£»£»£»£»£»£»£»£»´æ´¢ÐÍ¿çÕ¾µã¾ç±¾·ì϶£¨CVE-2020-7570£©£»£»£»£»£»£»£»£»·´ÉäÐÍ¿çÕ¾µã¾ç±¾·ì϶£¨CVE-2020-7571£©ºÍ½Ó¼û½ÚÔì²»µ±£¨CVE-2020-7573£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/111692/hacking/schneider-electric-zero-days.html


3.Basecamp½¨¸´¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеÄÑϳÁ·ì϶


3.jpg


BasecampÅû¶Æä´æÔڿɵ¼ÖÂÔ¶³Ì´úÂëÖ´Ðеķì϶ £¬£¬£¬£¬£¬ÏÖÒѽ¨¸´¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚͼƬÉÏ´«Ö°ÄÜÖÐ £¬£¬£¬£¬£¬·þÎñÆ÷¶ËÔÚת»»Í¼Ïñʱ £¬£¬£¬£¬£¬²»½ö½ÓÊÜͼÏñÎļþ £¬£¬£¬£¬£¬»¹½ÓÊܳÁ¶¨ÃûΪ.gifµÄPostScript¡¢EPSÎļþ¡£¡£¡£¡£¡£Òò¶ø £¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÉÏ´«´øÓиü¸ÄΪͼÏñÀ©´óÃûµÄ¶ñÒâÎļþÀ´Ö´ÐкÅÁî¡£¡£¡£¡£¡£Õâ¿ÉÄÜÊÇÓÉÓÚʹÓÃÁËImageMagick»òGraphicsMagick½øÐÐͼÏñת»» £¬£¬£¬£¬£¬ÔÚÊäÈëÒÔ'£¥£¡'Ϊ¿ªÍ·µÄÎļþʱ £¬£¬£¬£¬£¬Ôò»áŲÓÃPostScriptÚ¹ÊÍÆ÷£¨Ghostscript£© £¬£¬£¬£¬£¬¶øGhostscript×ÔÉí´æÔÚ°²È«·ì϶¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/11/29/critical-vulnerability-in-basecamp-could-allow-remote-code-execution-attacks/


4.Unit4°ä²¼ÓйØÈ«ÇòÆóÒµ½øÐÐÊý×Ö»¯×ªÐ͵ķÖÎö»ã±¨


4.jpg


ÆóÒµÔÆÀûÓù«Ë¾Unit4°ä²¼ÓйØÈ«ÇòÆóÒµ½øÐÐÊý×Ö»¯×ªÐ͵ķÖÎö»ã±¨¡£¡£¡£¡£¡£»ã±¨Ö¸³ö £¬£¬£¬£¬£¬ÎªÏìÀûÓû§²»ÐÝÔö³¤µÄÐèÒª £¬£¬£¬£¬£¬È«Çò84£¥µÄ¾ö²ßÕßÔÚ¼Ó¿ìÆäÊý×Ö»¯×ªÐÍ´òËã £¬£¬£¬£¬£¬²¢µ«Ô¸ÔÚ½«À´Óиü¶àµÄ½Ã½ÝÐÔÀ´Ô¶³Ì¹¤×÷¡£¡£¡£¡£¡£ÔÚCovid-19ÆÚ¼ä £¬£¬£¬£¬£¬49%µÄ¾ö²ßÕß³ÆÔڹ滮·½Ãæ±äµÃÔ½·¢½Ã½Ý £¬£¬£¬£¬£¬42%ÈϿɴ´ÐµĴëÊ©ÒѾ­¼Ó¿ì £¬£¬£¬£¬£¬35%µÄÈ˰µÊ¾Õâ¼Ó¿ìÁËËûÃÇÏòÔÆÍÆËã×ªÒÆµÄͶ×Ê¡£¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬£¬Ëæ×ÅÔ¶³Ì¹¤×÷µÄ¹ý¶È £¬£¬£¬£¬£¬60£¥µÄÊÜ·ÃÕß°µÊ¾ËûÃÇÔÚ¹Ø±ÕÆÚ¼ä³ö²úÁ¦¸ü¸ß¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.unit4.com/news/unit4-study-reveals-organizations-are-accelerating-digital-strategies-people-led


5.Threatpost°ä²¼CovidÆÚ¼äÒ½ÁÆÐÐÒµµÄÍþв·ÖÎö»ã±¨


5.jpg


Threatpost°ä²¼ÁËÓйØCovidÆÚ¼äÒ½ÁÆÐÐÒµµÄÍþв·ÖÎö»ã±¨¡£¡£¡£¡£¡£¸Ã»ã±¨Ì½ÇóÁËÒ½ÁÆÉ豸µÄ°²È«ÐÔ¡¢ÀÕË÷Èí¼þµÄ·çÏÕÒÔ¼°Ò½ÁƼäµý»î¶¯µÄ¹ÄÆð £¬£¬£¬£¬£¬ÀýÈçºÚ¿Í×éÖ¯ÔÚÍøÂçÓйØCOVID-19ÒßÃçºÍÒ½ÖÎÇé¿öµÄµý±¨¡£¡£¡£¡£¡£»ã±¨Ö¸³ö £¬£¬£¬£¬£¬2020ÄêÓÉÓÚCOVID-19µÄÊæÕ¹ £¬£¬£¬£¬£¬ÒÅÁôµÄÍøÂ簲ȫÎÊÌâÓëÐµİ²È«ÌôÕ½ÈÚºÏ £¬£¬£¬£¬£¬Ò½ÁÆÐÐÒµÆðÍ·Á˾޴óµÄת±ä¡£¡£¡£¡£¡£COVID-19ÆÈʹԤËãÑÏÖØµÄÒ½Ôº½â¾öÕâЩϵͳÐÔÎÊÌâ £¬£¬£¬£¬£¬Óë´Ëͬʱ £¬£¬£¬£¬£¬ÝÓÈÆÒ½ÁÆ·þÎñµÄÊý×Ö»¯¡¢Ô¶³ÌÒ½ÁƵÄÍÆ³öºÍÕмÜÀÕË÷Èí¼þ¹¥»÷µÄÉÏÉý¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/ebooks/healthcare-security-woes-balloon-in-a-covid-era-world/


6.±öϦ·¨ÄáÑÇÖÝÌØÀ­»ªÏØÒÑÏòDoppelÖ§¸¶50ÍòÃÀÔªµÄÊê½ð


6.jpg


ÉÏÖÜÄ© £¬£¬£¬£¬£¬±öϦ·¨ÄáÑÇÖÝÌØÀ­»ªÏصÄϵͳÔâµ½DoppelPaymerÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬£¬£¬ÏÖÒÑÖ§¸¶500000ÃÀÔªµÄÊê½ð¡£¡£¡£¡£¡£ÌØÀ­»ªÏذ䲼¾¯±¨³Æ £¬£¬£¬£¬£¬¹¥»÷µ¼Ö²¿ÃÅϵͳÖÐ¶Ï £¬£¬£¬£¬£¬µ«¸ÃÏØµÄÑ¡¾Ù¾ÖºÍ´¹Î£·þÎñ²¿ÃŲ¢Ã»ÓÐÊܵ½Ó°Ïì¡£¡£¡£¡£¡£±¾µØÃ½Ì峯 £¬£¬£¬£¬£¬ÀÕË÷Èí¼þÍÅ»ïÄܹ»½Ó¼ûÔ̺¬¾¯·½»ã±¨¡¢¹¤×Ê¡¢²É¹ººÍÆäËûÊý¾Ý¿âµÄϵͳ £¬£¬£¬£¬£¬²¢Ë÷Òª50ÍòÃÀÔªµÄÊê½ð¡£¡£¡£¡£¡£·Ñ³Ç6abcµç̨³Æ¸ÃÏØÒѳﱸ֧¸¶Êê½ð £¬£¬£¬£¬£¬ÓÉÓÚÆäÒѾ­Îª´ËÀ๥»÷Ͷ±£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/pennsylvania-county-pays-500k-ransom-to-doppelpaymer-ransomware/