SonicWallÖÒ¸æÀûÓÃÆäVPN²úÆ·ÖÐ0dayµÄ¹¥»÷»î¶¯£»£»£»£»£»£»ÌØË¹À­¸æ×´Ç°Ô±¹¤ÇÔÈ¡¹«Ë¾µÄ6ǧ¶à¸ö´úÂëÎļþ

°ä²¼¹¦·ò 2021-01-25
1.SonicWallÖÒ¸æÀûÓÃÆäVPN²úÆ·ÖÐ0dayµÄ¹¥»÷»î¶¯


1.jpg


°²È«³§ÉÌSonicWal°ä²¼´¹Î£Í¨Öª£¬£¬£¬£¬ £¬£¬£¬£¬ÖÒ¸æÀûÓÃÆäVPN²úÆ·ÖÐ0dayµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶λÓÚSecure Mobile Access£¨SMA£©VPNÉ豸¼°NetExtender VPN¿Í»§¶ËÖУ¬£¬£¬£¬ £¬£¬£¬£¬¿É±»ÓÃÀ´¶Ô¹«Ë¾µÄÄÚ²¿ÏµÍ³½øÐÐЭͬ¹¥»÷¡£¡£¡£¡£¡£¡£¡£SonicWallÉÐδ°ä²¼Óйظ÷ì϶µÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬ £¬£¬£¬£¬µ«Æ¾¾Ý»º½â´ëÊ©Åжϣ¬£¬£¬£¬ £¬£¬£¬£¬Æä¿ÉÄÜÊÇÊÇÉí·ÝÑéÖ¤·ì϶£¬£¬£¬£¬ £¬£¬£¬£¬¿É±»ÓÃÀ´Ôڿɹ«¿ª½Ó¼ûµÄÉ豸ÉÏÔ¶³ÌÀûÓᣡ£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/sonicwall-firewall-maker-hacked-using-zero-day-in-its-vpn-device/


2.ÒôÀÖÀûÓÃShazam´æÔÚ2¸öÒþÖÔ·ì϶£¬£¬£¬£¬ £¬£¬£¬£¬Ó°Ïì1ÒÚ¶àÓû§


2.png


ÒôÀÖÀûÓÃShazam´æÔÚ2¸ö·ì϶CVE-2019-8791ºÍCVE-2019-8792£¬£¬£¬£¬ £¬£¬£¬£¬¿É±»ÓÃÀ´»ñÈ¡AndroidºÍiOSÓû§µÄµØÎ»£¬£¬£¬£¬ £¬£¬£¬£¬Ó°ÏìÁË1ÒÚ¶à¸öÓû§¡£¡£¡£¡£¡£¡£¡£ShazamÔÚµ¼º½ÖÐʹÓÃÁËÉî²ãÁ´½Ó£¬£¬£¬£¬ £¬£¬£¬£¬¶øÕƹÜÔÚWeb viewÖмÓÔØÍøÕ¾µÄÉî²ãÁ´½ÓûÓÐÑéÖ¤²ÎÊý£¬£¬£¬£¬ £¬£¬£¬£¬´Ó¶øµ¼ÖÂ±í²¿×ÊÔ´Äܹ»¶ÔÆä½øÐнÚÔì¡£¡£¡£¡£¡£¡£¡£¸Ãweb viewÄܹ»»ñÈ¡Éè±¸ÌØ¶¨µÄÐÅÏ¢ºÍÓû§µÄ¾«È·µØÎ»£¬£¬£¬£¬ £¬£¬£¬£¬Òò¶øºÚ¿Í¿ÉÓõ¥¸ö¶ñÒâURLÀ´»ñÈ¡Êܺ¦ÕßµØÎ»¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬ £¬£¬£¬£¬¸Ã·ì϶Òѱ»½¨¸´¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/01/location-data-of-more-than-100-million.html


3.ÌØË¹À­¸æ×´Ç°Ô±¹¤ÇÔÈ¡¹«Ë¾µÄ6ǧ¶à¸ö´úÂëÎļþ


3.png


ÌØË¹À­¸æ×´ÆäǰԱ¹¤Alex KhatilovÇÔÈ¡¹«Ë¾µÄ6ǧ¶à¸ö¾ç±¾ºÍ´úÂëÎļþ¡£¡£¡£¡£¡£¡£¡£ÌØË¹À­³Æ¸ÃÔ±¹¤ÔÚÈëÖ°ÈýÌìºó¾ÍÆðÍ·ÇÔÈ¡»úÃÜÎļþ£¬£¬£¬£¬ £¬£¬£¬£¬²¢½«Æäת´¢ÖÁÓ×ÎÒ´æ´¢ÕÊ»§¡£¡£¡£¡£¡£¡£¡£½ØÖÁ1ÔÂ6ÈÕ£¬£¬£¬£¬ £¬£¬£¬£¬Alex KhatilovÔÚΪÆÚÁ½ÖܵŤ×÷ÖÐ×ܹ²ÇÔÈ¡ÁË6000¶à¸ö¾ç±¾»ò´úÂëÎļþ¡£¡£¡£¡£¡£¡£¡£ÌØË¹À­°µÊ¾±»µÁÊý¾Ý¶ÔÌØË¹À­ºÍ¾ºÕùµÐÊÖÀ´À´Ëµ¶¼¼«ÓмÛÖµ£¬£¬£¬£¬ £¬£¬£¬£¬ËüÃÇÄܹ»Ô®ÊÔìäËû¹«Ë¾µÄ¹¤³Ìʦ¶ÔÌØË¹À­µÄÁ÷³Ì½øÐÐÄæÏò¹¤³Ì£¬£¬£¬£¬ £¬£¬£¬£¬¶øºóÔڶ̹¦·òÄÚÒÔ¸üÉÙµÄÓöȴ´½¨Ò»¸öÀàËÆµÄϵͳ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bloomberg.com/news/articles/2021-01-23/tesla-claims-engineer-stole-secrets-just-three-days-on-the-job?srnd=technology-vp


4.ºÚ¿Í¹«¿ª½»ÓÑÍøÕ¾MeetMindfulµÄ228ÍòÓû§µÄÊý¾Ý


4.png


ShinyHunters¹«¿ªÁ˽»ÓÑÍøÕ¾MeetMindfulµÄ1.2 GBÊý¾Ý£¬£¬£¬£¬ £¬£¬£¬£¬Éæ¼°Ô¼228Íò¸öÓû§¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶Êý¾ÝÔ̺¬Óû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢³ÇÊÓ×¢ÖݺÍÓÊÕþ±àÂëµÄ¾ßÌåÐÅÏ¢¡¢Éí¶Îϸ½Ú¡¢Ô¼»áÆ«ºÃ¡¢»éÒöÇé¿ö¡¢µ®ÉúÈÕÆÚ¡¢Î³¶ÈºÍ¾­¶È¡¢IPµØÖ·¡¢¹þÏ£ÃÜÂë¡¢FacebookÓû§IDºÍFacebookÉí·ÝÑéÖ¤ÁîÅÆµÈ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³ÆÕâЩÊý¾ÝÒѱ»²é¿´ÁË1500´ÎÒÔÉÏ£¬£¬£¬£¬ £¬£¬£¬£¬²¢ÇҺܿÉÄÜÒѱ»ÏÂÔØ¡£¡£¡£¡£¡£¡£¡£MeetMindfulÉÐδ¶ÔÕâ´Îй¶ÊÂÎñ×ö³ö»ØÓ¦¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-leaks-data-of-2-28-million-dating-site-users/


5.·¨¹úµÄVienneÔâµ½¹¥»÷£¬£¬£¬£¬ £¬£¬£¬£¬ÍÆËã»úºÍͨѶϵͳ±»·ÛËé


5.png


·¨¹úµÄVienneÓÚ1ÔÂ21ÈÕ£¨ÐÇÆÚËÄ£©Ôâµ½¹¥»÷£¬£¬£¬£¬ £¬£¬£¬£¬µ¼ÖÂÍÆËã»úºÍͨѶϵͳ±»·ÛËé¡£¡£¡£¡£¡£¡£¡£ÀíÊ»áÖ÷ϯAlain Pichon³Æ¹¥»÷²úÉúºó£¬£¬£¬£¬ £¬£¬£¬£¬Æä¹Ø¹ØÁËÕû¸öITϵͳ£¬£¬£¬£¬ £¬£¬£¬£¬²¢ÇÒËùÓÐÍÆËã»ú¶¼½«ÔÚÖÜÒ»ÖÕ³¡ÔËÐС£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬£¬£¬¸Ãʡй©Õâ´Î¹¥»÷Ó뼸ÖÜǰLa RochelleÔâµ½µÄ¹¥»÷ÊÇͬÀàÐ͵쬣¬£¬£¬ £¬£¬£¬£¬ºÚ¿ÍÀûÓò¡¶¾Ï°È¾ÉçÇø¡¢µ±²¿ÃÅÃÅÒÔ¼°Ë½Óª¹«Ë¾µÄϵͳ£¬£¬£¬£¬ £¬£¬£¬£¬ÒÔÀÕË÷Êê½ð¡£¡£¡£¡£¡£¡£¡£¸ÃÊ¡²»³ïËãÖ§¸¶ÈκÎÓöȣ¬£¬£¬£¬ £¬£¬£¬£¬²¢°µÊ¾ÕâÖÖ¹¥»÷´Ó³¤Ô¶À´¿´²»»á¶ÔÆä²úÉúÈκÎÓ°Ïì¡£¡£¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.francebleu.fr/infos/societe/le-departement-de-la-vienne-victime-d-un-piratage-informatique-1611327525


6.Unit42°ä²¼ÍøÂç¹¥»÷µÄÇ÷Ïò·ÖÎö»ã±¨


6.png


Unit42°ä²¼ÁËÍøÂç¹¥»÷µÄÇ÷Ïò·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨·¢ÏÖ2020Äê8Ôµ½10Ô£¬£¬£¬£¬ £¬£¬£¬£¬É¨Ã跨ʽ»î¶¯ºÍHTTPĿ¼±éÀúÀûÓó¢ÊÔ¼¤Ôö¡£¡£¡£¡£¡£¡£¡£2020ÄêÏļ¾ÔÚÒ°±í×î³£±»ÀûÓõķì϶ÊÇCVE-2012-2311ºÍCVE-2012-1823£¬£¬£¬£¬ £¬£¬£¬£¬µ«Êǵ½ÁËÇï¼¾³öÏÖÁËCVE-2020-17496ºÍCVE-2020-25213µÈеķì϶¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬£¬£¬8ÔÂÖÁ10ÔÂÔÚÒ°·¢ÏÖÁËÎå¸öзì϶vBulletinÔ¶³ÌÖ´ÐдúÂë·ì϶¡¢WordPressÎļþÖÎÀíÆ÷²å¼þÔ¶³ÌÖ´ÐдúÂë·ì϶¡¢Nette´úÂë×¢Èë·ì϶¡¢Artica Web´úÀíSQL×¢Èë·ì϶ºÍOracle WebLogic ServerÔ¶³ÌÖ´ÐдúÂë·ì϶¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/network-attack-trends-internet-threats/