Cisco TalosÅû¶WebKitÖжà¸öÑϳÁµÄ·ì϶£»£»£»£»£»Apodis PharmaÊý¾Ý¿âÅäÖÃÃýÎóй¶1.7TB»úÃÜÊý¾Ý
°ä²¼¹¦·ò 2020-12-02
Cisco TalosÅû¶WebKitä¯ÀÀÆ÷ÒýÇæ´æÔÚ¶à¸öÑϳÁµÄ·ì϶¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶ÓëWebKitµÄWebSocket¡¢AudioSourceProviderGStreamerºÍImageDecoderGStreamerÖ°ÄÜÓйء£¡£¡£¡£¡£¡£¡£±ðÀëΪWebSocket´úÂëÖ´Ðзì϶£¨CVE-2020-13543£©£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ý´¥·¢¿ªÊͺóʹÓ÷ì϶À´Ô¶³ÌÖ´ÐдúÂ룻£»£»£»£»ImageDecoderGStreamer¿ªÊͺóʹÓ÷ì϶£¨CVE-2020-13584£©£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³ÌÖ´ÐдúÂ룬£¬£¬£¬£¬£¬£¬ÒÔ¼°±»×·×ÙΪCVE-2020-13543µÄ·ì϶¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/webkit-vulnerabilities-allow-remote-code-execution-malicious-websites
2.Ô½ÄÏ×éÖ¯Bismuth¶Ô×¼·¨¹úºÍÔ½ÄÏÈ·µ±¾Ö»ú¹¹ºÍ¹«Ë¾

΢Èí·¢ÏÖÔ½ÄϺڿÍ×éÖ¯Bismuth¶Ô×¼·¨¹úºÍÔ½ÄÏÈ·µ±¾Ö»ú¹¹ºÍ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ï×Ô2012ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬£¬£¬²¢ÒÔ´úºÅAPT32ºÍOceanLotusµÈΪÈËËùÖª¡£¡£¡£¡£¡£¡£¡£ÆäÖØÒª·¢Õ¹Õë¶Ô¹úÄÚ±íµÄ¸´ÔӺڿͻ£¬£¬£¬£¬£¬£¬£¬Ö÷ÕÅÊÇÍøÂçÐÅÏ¢ÒÔÔ®ÊÔìäµ±¾Ö´¦ÖÃÕþÖΡ¢¾¼ÃºÍ±í½»Õþ²ß¾ö²ß¡£¡£¡£¡£¡£¡£¡£µ«Î¢Èí·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬ÔÚ2020Äê7ÔÂÖÁ2020Äê8Ô£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ÔÚÕë¶Ô·¨¹úºÍÔ½ÄÏÈ·µ±¾Ö»ú¹¹ºÍ¹«Ë¾µÄ¹¥»÷ÖÐÆðͷʹÓÃMoneroÍÚ¿óÈí¼þ£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°Éв»Ã÷ÏÔÆäΪºÎ½øÐд˸ü¸Ä¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-links-vietnamese-state-hackers-to-crypto-mining-malware-campaign/
3.×êÑÐÍŶӷ¢ÏÖGotkitÓëREvilµÄºÏ×÷ͬ°é¹ØÏµ³ÁÉú

×êÑÐÍŶӷ¢ÏÖ£¬£¬£¬£¬£¬£¬£¬ÔÚ³¤´ïÒ»ÄêµÄÐÝÏ¢ºó£¬£¬£¬£¬£¬£¬£¬ÐÅÏ¢ÇÔȡľÂíGootkitÓëREvilһ·ÔÚÕë¶ÔµÂ¹úµÄÐÂÕ½ÕùÖгÁÉú¡£¡£¡£¡£¡£¡£¡£ÔÚÕâ´Î¹¥»÷»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬ºÚ¿Í¹¥»÷WordPressÍøÕ¾£¬£¬£¬£¬£¬£¬£¬²¢ÀûÓÃSEO²¡¶¾Ïò½Ó¼ûÕßչʾαÔìµÄÂÛ̳Ìû×Ó£¬£¬£¬£¬£¬£¬£¬²¢¸½ÓжñÒâ±í¸ñ»òÏÂÔØµÄÁ´½Ó¡£¡£¡£¡£¡£¡£¡£µ±Óû§µã»÷Á´½Óʱ£¬£¬£¬£¬£¬£¬£¬½«ÏÂÔØÒ»¸ö°ü·Ñ½âÏýµÄJSÎļþµÄZIPÎļþ£¬£¬£¬£¬£¬£¬£¬¸ÃÎļþ½«×°ÖÃGootkit¶ñÒâÈí¼þ»òREvilÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÁË»ìºÏµÄÓÐÐ§ÔØºÉ¿É½«Æä·Ö»¯³ÉƬ¶Î´æ´¢ÔÚ×¢²á±íÖУ¬£¬£¬£¬£¬£¬£¬Ê¹µÃ°²È«Èí¼þ¸üÄѼì²âµ½¸Ã¶ñÒâ¸ºÔØ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/gootkit-malware-returns-to-life-alongside-revil-ransomware/
4.×êÑÐÍŶӷ¢ÏÖ¿Éͨ¹ýαÔìPayPal±íµ¥ÇÔÈ¡Óû§ÐÅÏ¢

×êÑÐÍŶӷ¢ÏÖеÄÐÅÓþ¿¨ÇÔÈ¡Æ÷¿Éͨ¹ýαÔìPayPal±íµ¥ÇÔÈ¡Óû§ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¸ÃÇÔÈ¡Æ÷ÊÇ»ùÓÚJavaScriptµÄ¾ç±¾£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ×¢Èëµ½µçÉÌÆ½Ì¨µÄ½áÕÊÒ³ÃæÖС£¡£¡£¡£¡£¡£¡£¸Ã¾ç±¾Í¨¹ýÒþдÊõ±»°µ²ØÔÚ±»Íйܵ½ÊÜϰȾÉ̵êµÄ·þÎñÆ÷ÉϵÄÓ³ÏñÖС£¡£¡£¡£¡£¡£¡£¶øºó£¬£¬£¬£¬£¬£¬£¬Ëü»áʹÓÃÖ®Ç°ÍøÂçµÄ¶©µ¥Êý¾ÝÀ´Ô¤ÌîαÔìµÄPayPalÖ§¸¶±íµ¥£¬£¬£¬£¬£¬£¬£¬ÔÙ½«Êܺ¦Õß³Á¶¨Ïòµ½PayPalµÄ¶©µ¥Ò³Ãæ¡£¡£¡£¡£¡£¡£¡£Ò»µ©Êܺ¦ÕßÊäÈëÁ˸¶¿îÐÅÏ¢²¢µã»÷ÁËÌá½»°´Å¥£¬£¬£¬£¬£¬£¬£¬¸ÃÇÔÈ¡Æ÷»á½«ÆäÈ«ÊýÐÅÏ¢´«»Øµ½¹¥»÷ÕߵķþÎñÆ÷¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/credit-card-skimmer-fills-fake-paypal-forms-with-stolen-order-info/
5.ResearchAndMarkets°ä²¼½«À´5ÄêSD-WANÊг¡Ô¤²â»ã±¨

ResearchAndMarkets°ä²¼Á˽«À´5ÄêSD-WANÊг¡Ô¤²â»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨Ô¤¼Æ£¬£¬£¬£¬£¬£¬£¬È«ÇòSD-WANÊг¡¹æÄ£½«´Ó2020ÄêµÄ19ÒÚÃÀÔªÔö³¤µ½2025ÄêµÄ84ÒÚÃÀÔª£¬£¬£¬£¬£¬£¬£¬ÔÚ´ËÆÚ¼äµÄ¸´ºÏÄêÔö³¤ÂÊ£¨CAGR£©Îª34.5£¥¡£¡£¡£¡£¡£¡£¡£°´×éÖ¯¹æÄ£»£»£»£»£»®·Ö£¬£¬£¬£¬£¬£¬£¬ÖÐÓ×ÐÍÆóÒµ½«Õ¼¾Ý¸ü¸ßµÄÊг¡·Ý¶î¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ¸ü¶àµÄSD-WAN½â¾ö¹æ»®»ùÓÚÔÆ£¬£¬£¬£¬£¬£¬£¬Ìá¸ßÁËÆä¿É½ÓÊÜÐÔ£¬£¬£¬£¬£¬£¬£¬Ê¹ÖÐÓׯóÒµ¶ÔSD-WAN½â¾ö¹æ»®µÄÐèÒªÔö³¤¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬ÆóÒµÕýתÏò»ùÓÚÔÆµÄÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬£¬Òò¶øÔ¤¼ÆÔƲ¿Êð½«ÔÚ½«À´Ö÷µ¼Êг¡¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.researchandmarkets.com/reports/5137053/software-defined-wide-area-network-sd-wan
6.Apodis PharmaÊý¾Ý¿âÅäÖÃÃýÎóй¶1.7TB»úÃÜÊý¾Ý

CyberNews·¢ÏÖApodis PharmaµÄElasticSearchÊý¾Ý¿âÅäÖÃÃýÎ󣬣¬£¬£¬£¬£¬£¬Ð¹Â¶³¬¹ý1.7TBµÄ»úÃÜÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Apodis PharmaÊÇÒ»¼ÒΪҩ·¿¡¢Ò½ÁÆ»ú¹¹µÈ¹«Ë¾ÌṩÊý×Ö¹©¸øÁ´ÖÎÀíÆ½Ì¨ºÍÈí¼þ½â¾ö¹æ»®µÄ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÔ̺¬´óÁ¿ÓëÒµÎñÓйصĻúÃÜÊý¾Ý£¬£¬£¬£¬£¬£¬£¬Ô̺¬Ò©Æ·×°ÔËÊý¾ÝºÍ´æ´¢×´Ì¬¡¢Æä25000¶à¸öºÏ×÷ͬ°éºÍ¿Í»§µÄµµ°¸¡¢²úÆ·ÊýÁ¿ºÍIDµÈ²úÆ·Êý¾Ý¡¢ÏúÊÛÈÕÆÚºÍ¼ÛÖµµÈÏúÊÛÐÅÏ¢¡¢¿Í»§¼°Ô±¹¤ÐÕÃûµÅ×û§Êý¾Ý¡¢Ïû·ÑÕߺͿͻ§Êý¾ÝµÄ¿ÉÊÓ»¯ºÍ·ÖÎöÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÒÑÓÚ11ÔÂ17ÈÕ±»±£»£»£»£»£»¤ÆðÀ´¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/111756/data-breach/apodis-pharma-data-leak.html


¾©¹«Íø°²±¸11010802024551ºÅ