SolarWinds¹©¸øÁ´¹¥»÷»î¶¯ÖдæÔÚеÄSUPERNOVAºóÃÅ£»£»£»£»£»£»£» £»¶à¹ú·¨Âɲ¿ÃŽáºÏµ·»ÙÈý¸öÌṩVPN·þÎñµÄÍøÕ¾?

°ä²¼¹¦·ò 2020-12-23

1.SolarWinds¹©¸øÁ´¹¥»÷»î¶¯ÖдæÔÚеÄSUPERNOVAºóÃÅ


1.jpg


×êÑÐÈËÔ±·¢ÏÖSolarWinds Orion¹©¸øÁ´¹¥»÷»î¶¯ÖдæÔÚеÄSUPERNOVAºóÃÅ£¬ £¬£¬£¬£¬£¬£¬£¬¿ÉÄÜÀ´×ÔÁíÒ»¸öºÚ¿Í×éÖ¯¡£¡£¡£¡£¡£¡£¡£SUPERNOVAÊÇÖ²ÈëOrionÍøÂçºÍÀûÓ÷¨Ê½¼à¶½Æ½Ì¨´úÂëÖеÄWeb shell£¬ £¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓøöñÒâÈí¼þÔÚÍÆËã»úÉÏÔËÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâ´úÂë½öÔ̺¬Ò»ÖÖDynamicRun²½Ö裬 £¬£¬£¬£¬£¬£¬£¬¿É½«²ÎÊý¶¯Ì¬±àÒëµ½ÄÚ´æÖеÄ.NET·¨Ê½¼¯ÖУ¬ £¬£¬£¬£¬£¬£¬£¬Òò¶ø²»»áÔÚÊÜϰȾÉ豸ÉÏÁôÏÂÈκκۼ£¡£¡£¡£¡£¡£¡£¡£¾­µ÷²é£¬ £¬£¬£¬£¬£¬£¬£¬SUPERNOVAûº±¼û×ÖÊðÃû£¬ £¬£¬£¬£¬£¬£¬£¬ÕâÓë×î³õ·¢ÏÖµÄSunBurst·ÖÆç£¬ £¬£¬£¬£¬£¬£¬£¬»òÐíÊôÓÚÁíÒ»ºÚ¿Í×éÖ¯¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/a-second-hacking-group-has-targeted-solarwinds-systems/


2.¶à¹ú·¨Âɲ¿ÃŽáºÏµ·»ÙÈý¸öÌṩVPN·þÎñµÄÍøÕ¾


2.jpg


À´×ÔÃÀ¹ú¡¢µÂ¹ú¡¢·¨¹ú¡¢ÈðÊ¿ºÍºÉÀ¼µÄ·¨ÂÉ»ú¹¹½áºÏ£¬ £¬£¬£¬£¬£¬£¬£¬³É¹¦µ·»ÙÁËÈý¸öVPN·þÎñµÄÍøÕ¾¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÐж¯µÄ´úºÅΪNova£¬ £¬£¬£¬£¬£¬£¬£¬ÖØÒªÓÉÅ·ÖÞÐ̾¯×éÖ¯½øÐÐЭµ÷¡£¡£¡£¡£¡£¡£¡£±»²é·âµÄÈý¸öÍøÕ¾±ðÀëΪinsorg.org¡¢safe-inet.comºÍsafe-inet.net£¬ £¬£¬£¬£¬£¬£¬£¬¾ùÒÑ»îÔ¾ÁËÊ®¶àÄ꣬ £¬£¬£¬£¬£¬£¬£¬¿ÉÄÜÊôÓÚÒ»¸öÍŻ¡£¡£¡£¡£¡£¡£ÕâÐ©ÍøÕ¾¿ÉÌṩ¶à´ïÎå²ãµÄ´úÀíÍøÂ磬 £¬£¬£¬£¬£¬£¬£¬Òò¶øÀÕË÷Èí¼þÍŻÐÅÓþ¿¨ÇÔÈ¡(Magecart)ÍÅ»ï¡¢ÍøÂç´¹µöºÚ¿ÍºÍ²Î¼ÓÕË»§ÊÕ¹ºµÄºÚ¿ÍʱʱÓÃÕâЩ·þÎñÆ÷À´°µ²ØÕæÊµÉí·Ý¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/law-enforcement-take-down-three-bulletproof-vpn-providers/


3.¼ÓÃÜÇ®±ÒÂòÂôËùEXMOÔâµ½¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬Ëðʧ×Ü×ʲúµÄ5£¥


3.jpg


Ó¢¹ú¼ÓÃÜÇ®±ÒÂòÂôËùEXMO³ÆÆäÔâµ½ÁËÍøÂç¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬12ÔÂ21ÈÕºÚ¿ÍÔÚÈëÇÔìäÈÈÇ®°üºóµÁÈ¡ÁË´óÁ¿×ʲú¡£¡£¡£¡£¡£¡£¡£½ØÖÁĿǰ£¬ £¬£¬£¬£¬£¬£¬£¬EXMOÈÈÇ®°üÖв¿ÃŵÄBTC¡¢XRP¡¢ZEC¡¢USDTºÍETH¾ùÊܵ½ÁËÓ°Ïì¡£¡£¡£¡£¡£¡£¡£EXMOÔÚ·¢ÏÖ¹¥»÷ºóÁ¢¼´×ö³öÏìÓ¦£¬ £¬£¬£¬£¬£¬£¬£¬ÔÝÍ£ËùÓÐÌá¿î²¢³Áв¿ÊðÈÈÇ®°ü¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÈÈÇ®°ü×ʽðÕ¼×Ü×ʲúµÄ½ü5%¡£¡£¡£¡£¡£¡£¡£µ«ÀäÇ®°üÀïµÄËùÓÐÇ®±Ò¶¼Êǰ²È«µÄ¡£¡£¡£¡£¡£¡£¡£EXMO°µÊ¾ÊÜÓ°ÏìÓû§µÄËùÓÐËðʧ½«ÓÉÆäÆëÈ«Åâ³¥²¢Í˿¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/exmo-cryptocurrency-exchange-hacked-loses-5-percent-of-total-assets/


4.ºÚ¿ÍÔÚ°µÍøÐ¹Â¶27Íò¸öLedgerÓû§µÄÃô¸ÐÐÅÏ¢


4.jpg


ºÚ¿ÍÔÚ°µÍøÐ¹Â¶ÁË27Íò¸öLedgerÓû§µÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£LedgerÊÇÓÃÓÚ´æ´¢¡¢ÖÎÀíºÍÏúÊÛ¼ÓÃÜÇ®±ÒµÄÓ²¼þ¼ÓÃÜÇ®±ÒÇ®°ü¡£¡£¡£¡£¡£¡£¡£Õâ´ÎºÚ¿Íй¶ÁËÁ½¸öTXTÎļþ£¬ £¬£¬£¬£¬£¬£¬£¬±ðÀëΪÔ̺¬¶©ÔÄÁËLedgerͨѶµÄ1075382¸öÓû§µÄµç×ÓÓʼþµØÖ·µÄ¡°All Emails (Subscription).txt¡±£¬ £¬£¬£¬£¬£¬£¬£¬ºÍÔ̺¬272853λ²É°ìÕßÐÕÃû¡¢ÓʼĵØÖ·ºÍµç»°ºÅÂëµÄ¡°Ledger Orders (Buyers) only.txt¡±¡£¡£¡£¡£¡£¡£¡£ÕâЩй¶Êý¾Ý»òÐíÊÇÓÉ2020Äê6ÔµÄÊý¾Ýй¶ÊÂÎñµ¼Öµģ¬ £¬£¬£¬£¬£¬£¬£¬¿É±»ÓÃÀ´½øÐÐÍøÂç´¹µö¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬ÒÔÇÔÈ¡Óû§¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/physical-addresses-of-270k-ledger-owners-leaked-on-hacker-forum/


5.Jumio°ä²¼2020Äê¼ÙÈÕÐÂÕË»§Ú²Æ­»î¶¯µÄ·ÖÎö»ã±¨


5.jpg


Jumio°ä²¼ÁË2020Äê¼ÙÈÕÐÂÕË»§Ú²Æ­»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬ £¬£¬£¬£¬£¬£¬£¬Óë2019ÄêµÄÏà±È£¬ £¬£¬£¬£¬£¬£¬£¬2020Äê»ùÓÚIDÑéÖ¤µÄÐÂÕÊ»§Ú²Æ­»î¶¯ÔÚÈ«ÇòÁìÓòÄÚͬ±È½µÂä23.2£¥¡£¡£¡£¡£¡£¡£¡£Í¬Ê±£¬ £¬£¬£¬£¬£¬£¬£¬»ùÓÚ×ÔÅÄÕÕµÄڲƭÂÊ£¨7.15£¥£©±È»ùÓÚIDµÄڲƭÂÊ£¨1.41£¥£©¸ß5±¶£¬ £¬£¬£¬£¬£¬£¬£¬Õâ˵ÁËÈ»ÔÚ°µÍøÉÏÄܹ»Âòµ½µÄ±»µÁÉí·ÝÖ¤¼þµÄÊýÁ¿ÔÚ²»ÐÝÔö³¤¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬ £¬£¬£¬£¬£¬£¬£¬µ±ÔÚÉí·ÝÑéÖ¤ÖÐʹÓÃSDKʱ£¬ £¬£¬£¬£¬£¬£¬£¬Ú²Æ­ÂÊÏÔÖøµÍÓÚÆäËûÇþ·(ÈçAPIºÍweb)¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://go.jumio.com/2020-holiday-fraud-report


6.Cisco Talos°ä²¼2020ÄêËùÅû¶µÄ·ì϶µÄ»ØÊ׻㱨


6.jpg


Cisco Talos°ä²¼ÁË2020ÄêËùÅû¶µÄ·ì϶µÄ»ØÊ׻㱨¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬ £¬£¬£¬£¬£¬£¬£¬ÔÚ2020Ä꣬ £¬£¬£¬£¬£¬£¬£¬Talos×ܹ²°ä²¼ÁË231·ÝÕ÷ѯ»ã±¨£¬ £¬£¬£¬£¬£¬£¬£¬Éæ¼°277¸öCVE£¬ £¬£¬£¬£¬£¬£¬£¬ÁìÓòÔ̺¬²Ù×÷ϵͳ¡¢IoTÉ豸¡¢Microsoft Office²úÆ·¡¢ä¯ÀÀÆ÷ºÍPDFÔĶÁÆ÷µÈ¡£¡£¡£¡£¡£¡£¡£½ÏΪ³ÁÒªµÄÊÇ£¬ £¬£¬£¬£¬£¬£¬£¬ÖØÒªPDFÀûÓ÷¨Ê½£¨Ô̺¬Adobe PDF¡¢Foxit PDF¡¢NitroPDFºÍGoogle PDFium£©ÖдæÔÚ¶à¸ö·ì϶£¬ £¬£¬£¬£¬£¬£¬£¬Intel¡¢NvidiaºÍAMDµÄͼÐÎÇý¶¯·¨Ê½ÖеĶà¸ö·ì϶£¬ £¬£¬£¬£¬£¬£¬£¬Firefox¡¢ChromeºÍSafariµÈÖØÒªWebä¯ÀÀÆ÷ÖдæÔÚ¶à¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2020/12/vulnerability-discovery-2020.html