¹þÈø¿Ë˹̹µÚÈý´ÎÇ¿ÔìÔÚÆä¹«ÃñÉ豸ÉÏ×°ÖøùÖ¤Ê飻£»£»£»£»£»NSAÖÒ¸æ¶íÂÞ˹ºÚ¿ÍÀûÓÃеÄVMware·ì϶ÇÔÈ¡Êý¾Ý
°ä²¼¹¦·ò 2020-12-081.¹þÈø¿Ë˹̹µÚÈý´ÎÇ¿ÔìÔÚÆä¹«ÃñÉ豸ÉÏ×°ÖøùÖ¤Êé

¹þÈø¿Ë˹̹µ±¾ÖÒÔÍøÂ簲ȫÑÝϰΪ»Ï×Ó£¬£¬£¬£¬£¬Ð²ÆÈÊ×¶¼Å¬¶ûËÕµ¤µÄ¹«ÃñÔÚÆäÉ豸ÉÏ×°ÖÃÊý×ÖÖ¤Êé¡£¡£¡£¡£¡£ÈôÊDz»×°Öõ±¾ÖµÄ¸ùÖ¤Ê飬£¬£¬£¬£¬¹«Ãñ½«ÎÞ·¨½Ó¼ûGoogle¡¢Twitter¡¢YouTube¡¢Facebook¡¢InstagramºÍNetflixµÈÍøÕ¾¡£¡£¡£¡£¡£Ò»µ©×°Ö㬣¬£¬£¬£¬¸ÃÖ¤Ê齫ÔÊÐíµ±¾Öͨ¹ýÒ»ÖÖ³ÆÎªMitM£¨ÖÐÑëÈË£©µÄ¼¼ÊõÀ´À¹½ØÓû§É豸·¢³öµÄËùÓÐHTTPSÁ÷Á¿¡£¡£¡£¡£¡£ÕâÊǹþÈø¿Ë˹̹µ±¾Ö×Ô2015ÄêÒÔÀ´µÚÈý´ÎÇ¿ÔìÔÚÆä¹«ÃñÉ豸ÉÏ×°ÖøùÖ¤Êé¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/kazakhstan-government-is-intercepting-https-traffic-in-its-capital/
2.×êÑÐÈËÔ±·¢ÏÖ¿ÉÓÃÌî³ä¼¼ÊõÈÆ¹ýCloudflare WAF

°²È«¹«Ë¾SwascanµÄ×êÑÐÈËÔ±·¢ÏÖ¿ÉÓÃÌî³ä¼¼ÊõÈÆ¹ýCloudflare WAF¡£¡£¡£¡£¡£Ä¬ÈÏÅäÖÃϵÄCloudflare£¬£¬£¬£¬£¬ ÔÚ±íµ¥Êý¾ÝPOSTÒªÇó֮ǰÔö³¤Ô¼128KBµÄÌî³ä½«µ¼ÖÂWAF½«Æä½Ø¶ÏΪ×î´ó£¬£¬£¬£¬£¬Ìø¹ýÓÐÓàµÄ²¿ÃŲ¢½«Æä·¢Ë͸øÖ¸±êÀûÓ÷¨Ê½¡£¡£¡£¡£¡£Õ⽫ÔÊÐíºÚ¿ÍÈÆ¹ýWAF²¢ÀûÓÃÆäËûÀûÓ÷¨Ê½·ì϶£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÔÚÉøÈë²âÊÔÖз¢ÏÖ¿ÉÀûÓø÷ì϶ÔÚÖ¸±êϵͳÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐнӼû¡£¡£¡£¡£¡£Cloudflare²úÆ·¾ÀíMichael Tremante½¨ÒéÆôÓÃrule 100048À´Ô¤·ÀÌî³ä¹¥»÷¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://latesthackingnews.com/2020/12/06/cloudflare-waf-bypass-via-padding-technique-discovered/
3.NSAÖÒ¸æ¶íÂÞ˹ºÚ¿ÍÀûÓÃеÄVMware·ì϶ÇÔÈ¡Êý¾Ý

¹ú¶È°²È«¾Ö£¨NSA£©ÖҸ棬£¬£¬£¬£¬¶íÂÞ˹ºÚ¿ÍÔÚÀûÓÃеÄVMware·ì϶£¨CVE-2020-4006£©ÔÚÒ×Êܹ¥»÷µÄ·þÎñÆ÷Éϲ¿ÊðWeb Shell£¬£¬£¬£¬£¬ÒÔÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¸Ã·ì϶ΪºÅÁî×¢Èë·ì϶£¬£¬£¬£¬£¬ÒÑÓÚ12ÔÂ3ÈÕ±»½¨¸´¡£¡£¡£¡£¡£NSA·¢´Ë¿ÌÕâ´Î¹¥»÷»î¶¯ÖУ¬£¬£¬£¬£¬ºÚ¿ÍÊ×ÏÈÏνӵ½VMware²úƷ¶³öµÄwebÖÎÀí½çÃæ£¬£¬£¬£¬£¬Í¨¹ýºÅÁî×¢ÈëÀ´ÈëÇÖ×éÖ¯ÍøÂç²¢×°ÖÃweb shell¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃSAMLƾ֤ÇÔÈ¡Ãô¸ÐÊý¾Ý£¬£¬£¬£¬£¬ÒÔ»ñµÃ¶ÔADFS·þÎñÆ÷µÄ½Ó¼ûȨ£¬£¬£¬£¬£¬²¢ÔÚ±»¹¥»÷µÄÉ豸ÉÏÖ´ÐÐLinuxºÅÁ£¬£¬£¬£¬ÒÔ»ñµÃÓÆ¾ÃÐÔ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/nsa-russian-state-hackers-exploit-new-vmware-vulnerability-to-steal-data/
4.McAfee°ä²¼ÍøÂç·¸×ïµÄÒþÐԳɱ¾µÄ·ÖÎö»ã±¨

McAfee°ä²¼ÁËÓйØÍøÂç·¸×ïµÄÒþÐԳɱ¾µÄ·ÖÎö»ã±¨£¬£¬£¬£¬£¬³Áµã×êÑÐÍøÂç·¸×ïÔÚÈ«ÇòÁìÓòÄÚÔì³ÉµÄ³Á´ó²ÆÕþÓ°ÏìºÍδÏÔ¶µÄÓ°Ïì¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬ÍøÂç·¸×ï¸øÊÀ½ç¾¼ÃÔì³ÉµÄËðʧ³¬¹ý1ÍòÒÚÃÀÔª£¬£¬£¬£¬£¬Õ¼È«ÇòGDPµÄ1£¥ÒÔÉÏ£¬£¬£¬£¬£¬±È2018Äê½ü6000ÒÚÃÀÔªµÄËðʧÔö³¤ÁË50£¥¡£¡£¡£¡£¡£¸Ãµ÷²éÏÔʾ£¬£¬£¬£¬£¬ÓÐ92£¥µÄÆóÒµÒÔΪ£¬£¬£¬£¬£¬³ýÁ˲ÆÕþ³É±¾ºÍÍøÂçÊÂÎñºóµÄ¹¤×÷¹¦·òËðʧ֮±í£¬£¬£¬£¬£¬»¹ÓÐÆäËû¸ºÃæÓ°Ï죬£¬£¬£¬£¬Èçϵͳͣ»£»£»£»£»£»ú¡¢Ð§ÄܽµµÍ¡¢Í»·¢ÊÂÎñÏìÓ¦³É±¾ÒÔ¼°Æ·ÅƺÍÃûÓþÊÜË𡣡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.mcafee.com/enterprise/en-us/assets/reports/rp-hidden-costs-of-cybercrime.pdf
5.Ç÷Ïò¿Æ¼¼°ä²¼2020ÄêÍøÂç·çÏÕÖ¸ÊýµÄ·ÖÎö»ã±¨

Ç÷Ïò¿Æ¼¼°ä²¼ÁË2020ÄêÓйØÍøÂç·çÏÕÖ¸ÊýµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬ÔÚ´ÓǰһÄ꣬£¬£¬£¬£¬È«Çò23£¥µÄ×éÖ¯Ôâµ½Æß´Î»ò¸ü¶àµÄ¹¥»÷¡£¡£¡£¡£¡£Êý¾ÝÏÔʾ£¬£¬£¬£¬£¬È«Çò×î´óµÄÍøÂçÍþв·çÏÕÊÇÍøÂç´¹µöºÍÉç»á¹¤³Ì¡¢µã»÷½Ù³Ö£¨Clickjacking£©¡¢ÀÕË÷Èí¼þ¡¢ÎÞÎļþ¹¥»÷¡¢½©Ê¬ÍøÂçºÍÖÐÑëÈ˹¥»÷£¬£¬£¬£¬£¬×éÖ¯µÄÖØÒª¹Ø×¢µãÊǿͻ§Êý¾ÝÃÔʧ¡¢»ñȡ֪ʶ²úȨºÍ²ÆÕþÐÅÏ¢¡¢¿Í»§Á÷ʧºÍÉ豸ʧÇÔ»ò°Ü»µ£¬£¬£¬£¬£¬IT»ù´¡¼Ü¹¹ÖеÄÖØÒª·çÏÕΪ×é֯ʧºÍг¸´ÔÓÐÔ¡¢ÄÚ²¿È˺öÂÔ´óÒâ¡¢ÔÆÍÆËã»ù´¡¼Ü¹¹ºÍÌṩÉÌ¡¢È˲ÅǷȱºÍ¶ñÒâÄÚ²¿ÈËÔ±¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://newsroom.trendmicro.com/2020-12-02-A-Quarter-of-Global-Organizations-Were-Hit-by-Seven-or-More-Cyber-Attacks-in-The-Last-Year
6.°ÍÎ÷EmbraerϰȾRansomExx£¬£¬£¬£¬£¬»úÃÜÊý¾Ýй¶

°ÍÎ÷EmbraerϰȾÀÕË÷Èí¼þRansomExx£¬£¬£¬£¬£¬»úÃÜÊý¾Ýй¶¡£¡£¡£¡£¡£EmbraerÊǽö´ÎÓÚ²¨ÒôºÍ¿ÕÖпͳµ¹«Ë¾µÄµÚÈý´ó·É»úÔì×÷ÉÌ£¬£¬£¬£¬£¬ÓÉÓڻؾøÖ§¸¶Êê½ð£¬£¬£¬£¬£¬ºÚ¿ÍÒÑй¶Æä²¿ÃÅ»úÃÜÊý¾Ý¡£¡£¡£¡£¡£Õâ´Îй¶µÄÊý¾ÝÔ̺¬Ô±¹¤¾ßÌåÐÅÏ¢µÄÑù±¾¡¢Ã³Ò׺Ïͬ¡¢·ÉÐÐÄ£ÄâÕÕÆ¬ºÍÔ´´úÂëµÈ¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ֮ǰ°µÊ¾£¬£¬£¬£¬£¬¹¥»÷ÕßÖ»ÄܽøÈëÆä²¿ÃÅϵͳ£¬£¬£¬£¬£¬²¢½ö¶ÔÆäijЩÐж¯Ôì³ÉÁÙʱµÄÓ°Ïì¡£¡£¡£¡£¡£µ«ÔÚ´ËÊý¾Ýй¶ÊÂÎñ²úÉúºó£¬£¬£¬£¬£¬¸Ã¹«Ë¾²¢Î´»Ø¸´ÖÃÆÀÒªÇ󡣡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hackers-leak-data-from-embraer-worlds-third-largest-airplane-maker


¾©¹«Íø°²±¸11010802024551ºÅ