2019ÄêÉϰëÄ곬¹ý34%µÄ·ì϶佨¸´£»1.45Íò¸öPulse VPNÒ×Êܹ¥»÷£»Æ»¹û½¨¸´Ô½Óü·ì϶

°ä²¼¹¦·ò 2019-08-27

1.2019ÄêÉϰëÄê»ã±¨µÄ·ì϶Öг¬¹ý34%佨¸´


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝRisk Based Security°ä²¼µÄ¡¶2019ÄêÄêÖзì϶»ØÊ׻㱨¡·£¬2019ÄêÉϰëÄê»ã±¨µÄËùÓзì϶Öг¬¹ý34£¥£¨3771¸ö£©µÄ·ì϶佨¸´¡£´Ë±í£¬Ôڻ㱨µÄ×ܹ²11092¸ö·ì϶ÖУ¬14.7%£¨1630¸ö£©µÄ·ì϶CVSS V2µÃ·Ö³¬¹ý9.0£¬54.5£¥£¨6045¸ö£©µÄ·ì϶ÓëWebÓйØ£¬Ô¼53%£¨5878¸ö£©µÄ·ì϶Äܹ»Ô¶³ÌÀûÓã¬66%µÄ·ì϶ÓëSQL×¢Èë¹¥»÷ÓйØ£¬Ô¼2.8%µÄ·ì϶ÓëSCADAÓйØ¡£


Ô­ÎÄÁ´½Ó£º

https://pages.riskbasedsecurity.com/2019-midyear-vulnerability-quickview-report


2.Binance֤ʵºÚ¿Í´ÓµÚÈý·½ÇÔÈ¡Óû§KYCÊý¾Ý


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¼ÓÃÜÇ®±ÒÂòÂôËùBinance£¨±Ò°²£©Ö¤ÊµºÚ¿Í´ÓµÚÈý·½¹©¸øÉÌÄÇÀïÇÔÈ¡ÁËÓû§KYCÊý¾Ý¡£±¾ÔÂÔçЩʱ³½ºÚ¿ÍÍþв¸ÃÂòÂôËù½«°ä²¼1ÍòÃû¿Í»§µÄKYCÊý¾Ý£¬³ý·Ç¸Ã¹«Ë¾Ö§¸¶300±ÈÌØ±Ò£¨¼ÛÖµ³¬¹ý300ÍòÃÀÔª£©µÄÊê½ð¡£±ÒºÎÔÚһƪ¹Ù·½²©¿ÍÖÐÌṩÁËÊÂÎñµ÷²éµÄ¸ü¶àϸ½Ú£¬Åúעй¶µÄ¿Í»§×ÊÁÏͼƬÀ´×ÔÓÚ2017Äê12ÔÂÖÁ2018Äê2ÔÂÆÚ¼äµÄÒ»¸öµÚÈý·½¹©¸øÉÌ¡£¾Ý±¨Â·ÕâЩKYCÊý¾ÝÒѱ»ÓÃÓÚ¸ü¸Ä»òÉèÖÃڲƭÐԵıҰ²ÕË»§¡£¹ÌÈ»µ÷²éÈÔÔÚ½øÐÐÖУ¬µ«¸ÃÂòÂôËù°µÊ¾ÒѾ­ÆðÍ·ÁªÏµËùÓÐDZÔÚÊܺ¦Õߣ¬²¢ÌṩÒþÖÔ±£»¤ºÍ¸´Ô­Áìµ¼ÒÔ¼°Æ½ÉúVIP»áÔ±×ʸñ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/08/binance-kyc-data-leak_26.html


3.³¬¹ý1.45Íò¸öPulse VPNÒ×ÊÜCVE-2019-11510¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


BadPackets°²È«×¨¼ÒÖҸ泬¹ý1.45Íò¸öPulse Secure VPNÖÕ¶ËÒ×ÊÜCVE-2019-11510·ì϶¹¥»÷¡£×êÑÐÈËÔ±ÔÚ8ÔÂ22Èչ۲쵽Õë¶Ô¸Ã·ì϶µÄ´ó¹æÄ£É¨Ãè»î¶¯£¬Æ¾¾ÝÃÛ¹Þ¼à²âµ½µÄÊý¾Ý£¬ÕâЩɨÃèÆðÔ´ÓÚÎ÷°àÑÀµÄÖ÷»ú£¬¹¥»÷ÕßµÄÖ¸±êÊÇ»ñÈ¡¸öÈËVPNµÄ½Ó¼ûȨÏÞ¡£×êÑÐÈËÔ±·¢ÏÖ41850¸öPulse Secure VPNÖÕ¶ËÔÚ»¥ÁªÍøÉ϶³ö£¬ÆäÖÐ14528¸öÒ×Êܹ¥»÷£¬´óÎÞÊýλÓÚÃÀ¹ú£¨5010£©£¬Æä´ÎÊÇÈÕ±¾£¨1511£©¡¢Ó¢¹ú£¨830£©ºÍµÂ¹ú£¨789£©¡£ÊÜÓ°ÏìµÄÐÐÒµÔ̺¬ÃÀ¹ú¾ü·½¼°Áª¹ú¡¢Öݺʹ¦Ëùµ±¾Ö»ú¹¹¡¢¹«Á¢´óѧ¡¢Ò½Ôº¡¢µçÁ¦ÉèÊ©¡¢½ðÈÚ»ú¹¹ÒÔ¼°²Æ¸»500Ç¿ÆóÒµµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/90356/hacking/pulse-secure-vpn-endpoints-cve-2019-11510.html


4.SophosLabsÖÒ¸æBaldrÒÔеķ½Ê½½øÐй¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


BaldrÊÇÒ»ÖÖÐÂÐͶñÒâÈí¼þ£¬ÓÚ1Ô·ÝÔÚDeep WebÉϳõ´Î³öÏÖ£¬²¢ÔÚ6Ô·ÝÖÕ³¡Á÷ͨ¡£¸Ã¶ñÒâÈí¼þ±»ÓÃÓÚ¶Ô׼ȫÊÀ½çµÄPCÓÎÏ·Íæ¼Ò¡£Æ¾¾ÝSophosLabsµÄ»ã±¨£¬ÊÜÓ°Ïì×îÑϳÁµÄ¹ú¶ÈÔ̺¬Ó¡¶ÈÄáÎ÷ÑÇ£¨21£¥£©¡¢ÃÀ¹ú£¨10.52£¥£©¡¢°ÍÎ÷£¨14.14£¥£©¡¢¶íÂÞ˹£¨13.68£¥£©¡¢Ó¡¶È£¨8.77£¥£©ºÍµÂ¹ú£¨5.43£¥£©¡£BaldrɨÃèÖ¸±êϵͳÉϵÄËùÓÐAppDataºÍһʱÎļþ¼Ð£¬ÇÔÈ¡Ãô¸ÐÊý¾Ý²¢·¢Ë͸ø¹¥»÷Õß¡£×êÑÐÈËÔ±³Æ¹ÌÈ»BaldrÒѲ»ÔÚÊг¡ÉϳöÏÖ£¬µ«ËüÒÀÈ»¿É±»Ö®Ç°²É°ìËüµÄ·¸×ï·Ö×ÓʹÓ㬲¢ÇÒÒÀÈ»ÊÇDZÔÚµÄÍþв¡£


Ô­ÎÄÁ´½Ó£º

https://www.livemint.com/technology/tech-news/the-evasive-baldr-malware-may-hit-back-in-new-forms-warns-sophoslabs-1566813441778.html


5.ÐÂÀÕË÷Èí¼þNemtyÀûÓñ»µÁRDPÍ´´¦´«²¼


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÖÜÄ©ÆÚ¼ä×êÑÐÈËÔ±·¢ÏÖÒ»¸öÃûΪNemtyµÄÐÂÀÕË÷Èí¼þ£¬¹¥»÷ÕßÒªÇóÊܺ¦Õßͨ¹ýTorÍøÂçÉÏÍйܵÄÃÅ»§ÍøÕ¾Ö§¸¶0.09981±ÈÌØ±ÒµÄÊê½ð£¨Ô¼1ǧÃÀÔª£©¡£Êܺ¦ÕßÄܹ»ÉÏ´«ËûÃǵÄÅäÖÃÎļþ£¬¶øºó¹¥»÷Õß½«»áÌṩÁíÒ»¸ö´øÓÐ̸ÌìÖ°ÄܵÄÍøÕ¾Á´½ÓÒÔ¼°ÓйØÐèÒªµÄ¸ü¶àÐÅÏ¢¡£NemtyµÄ´úÂëÖÐÔ̺¬ÆÕ¾©µÄͼƬÁ´½Ó£¬»¹Ô̺¬¶Ô°²È«×êÑÐÈËÔ±·¢³öµÄÐÅÏ¢¡£¸Ã¶ñÒâÈí¼þ»¹»á²é³­Ö¸±êÊÇ·ñλÓÚ¶íÂÞ˹¡¢°×¶íÂÞ˹¡¢¹þÈø¿Ë˹̹¡¢Ëþ¼ª¿Ë˹̹ºÍÎÚ¿ËÀ¼£¬µ«ÓëÆäËüÍþв·ÖÆç£¬Ëü²»»áÖÕ³¡ÔÚÕâЩµØÓòµÄ¼ÓÃܹý³Ì¡£Æ¾¾Ý×êÑÐÈËÔ±KremezµÄ˵·¨£¬NemtyÊÇͨ¹ý±»ÇÔµÄRDPÍ´´¦´«²¼µÄ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-nemty-ransomware-may-spread-via-compromised-rdp-connections/


6.Apple°ä²¼iOS 12.4.1¸üУ¬½¨²¹Ô½Óü·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Apple½ñÌì°ä²¼ÁËiOS 12.4.1¸üУ¬½¨¸´iOS 12.4°æ±¾³ÁÐÂÒýÈëµÄ°²È«·ì϶¡£¸Ã·ì϶£¨CVE-2019-8605£©±»°²È«×êÑÐÈËÔ±Pwn20wndÓÃÓÚ¿ª·¢ºÍ°ä²¼Ô½Óü¹¤¾ß¡£Æ¾¾ÝAppleÖ§³ÖÎĵµÖеÄÃèÊö£¬¸Ã·ì϶¿ÉÄܱ»¶ñÒâÀûÓ÷¨Ê½ÀÄÓ㬲¢ÇÒÒÔϵͳȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£Appleͬʱ»¹ÍÆËÍÁËwatchOS 5.3.1¡¢tvOS 12.4.1ºÍmacOS 10.14.6¸üС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/apple-releases-ios-1241-to-patch-security-flaw-behind-jailbreak/