UniswapºÍLendf.meÔâºÚ¿Í¹¥»÷£¬Ëðʧ2500ÍòÃÀÔª£»µÂ¹úµ±¾ÖÔâCOVID-19´¹µö¹¥»÷ËðʧÊýǧÍòÅ·Ôª
°ä²¼¹¦·ò 2020-04-211.FPGAоƬStarbleed·ì϶£¬Ó°ÏìÈüÁé˼¶à¸ö²úÆ·
×êÑÐÈËÔ±·¢ÏÖFPGAоƬ´æÔÚStarbleed·ì϶£¬Ó°ÏìÁËÈüÁé˼7ϵÁеÄSpartan¡¢Artix¡¢Kintex¡¢Virtex×ÓϵÁжà¸ö²úÆ·¡£ÓÉÓÚ·ì϶ΪӲ¼þ¼¶±ð·ì϶£¬Òò¶øÖ»ÄÜͨ¹ý¸ü»»Ð¾Æ¬À´½¨¸´·ì϶¡£°²È«×êÑÐÈËÔ±·¢ÏÖÄܹ»Í¨¹ý½âÃܱ»¼ÓÃܵıÈÌØÁ÷À´½Ó¼ûºÍÅú¸ÄÓÃÓÚ±à³ÌµÄÎļþ¡£Òò¶ø£¬ºÚ¿ÍÄܹ»ÀûÓø÷ì϶ÆëÈ«½ÚÔìFPGAоƬ£¬²¢ÇÒ¿ÉÄܵÁÈ¡±ÈÌØÁ÷ÖеÄ֪ʶ²úȨ¡£µÂ¹úMax Planck×êÑÐËùµÄChristof Paar½ÌÊÚ°µÊ¾£¬¹¥»÷ÕßÉõÖÁÄܹ»½øÐÐÔ¶³Ì¹¥»÷£¬»òÊÇÏòFPGAоƬֲÈëÓ²¼þľÂí¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/04/20/starbleed-vulnerability/
2.UniswapºÍLendf.meÔâºÚ¿Í¹¥»÷£¬Ëðʧ2500ÍòÃÀÔª
ºÚ¿Í¹¥»÷ÁËUniswapÂòÂôËùºÍLendf.me½è´ûƽ̨£¬µÁÈ¡Á˼ÛÖµ³¬¹ý2500ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò¡£Õâ´Î¹¥»÷±ðÀë²úÉúÔÚÖÜÁùºÍÖÜÈÕ£¬µ÷²éÈËÔ±ÒÔΪÕâÁ½´Î¹¥»÷ºÜ¿ÉÄÜÊÇͳһ¸öÍÅ»ïÌáÒéµÄ¡£¾Ýµ÷²é£¬ºÚ¿Í½áºÏÁË·ÖÆçÇø¿éÁ´¼¼ÊõÖеĶà¸ö·ì϶×é³ÉÁËÒ»´Î¸´ÔӵijÁÈë¹¥»÷£¬ÔÚÔʼÂòÂô±»ºË×¼»ò»Ø¾øÖ®Ç°²»ÐݵØÈ¡Ç®¡£¾Ý³ÆºÚ¿ÍÔÚÕâ´Î¹¥»÷ÖÐʹÓÃÁËOpenZeppelin¹«Ë¾ÓÚ2019Äê7ÔÂÔÚGitHubÉϰ䲼µÄ·ì϶ÀûÓá£Ö±µ½±¾Îİ䲼ʱ£¬Uniswap×ܹ²ËðʧÁË30ÍòÃÀÔªÖÁ110ÍòÃÀÔª£¬¶øLendf.meËðʧÁ˳¬¹ý2450ÍòÃÀÔª¡£Ä¿Ç°£¬ÕâÁ½¸öÍøÕ¾¾ùÒѹعأ¬ÒÔÔ¤·À½øÒ»²½µÄ¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hackers-steal-25-million-worth-of-cryptocurrency-from-uniswap-and-lendf-me/
3.CISI¹ÙÍø±»Ö²Èë¶ñÒâ´úÂ룬Óû§²ÆÕþÐÅÏ¢±»ÇÔ
Ó¢¹úÌØÐí֤ȯͶ×ÊлᣨCISI£©ÒÑÈ·ÈÏÆä¹ÙÍø±»Ö²Èë¶ñÒâ´úÂ룬Óû§µÄ²ÆÕþÐÅÏ¢¿ÉÄܱ»ÇÔ¡£CISIÔÚÕ÷ѯ¹«Ë¾±ÏÂíÍþ£¨KPMG£©µÄÔ®ÊÖ϶ԴËÊ·¢Õ¹Á˵÷²é£¬·¢ÏÖ¹¥»÷Õßͨ¹ýµÚÈý·½ÀûÓ÷¨Ê½µÃµ½ÁËCISIÍøÕ¾µÄ½Ó¼ûȨÏÞ²¢ÏòÍøÕ¾Ö²ÈëÁ˶ñÒâ´úÂ룬¶øºóÔÚÓû§ÔÚÏßÖ§¸¶Ê±µÁÈ¡Æä²ÆÕþÐÅÏ¢¡£CISI°µÊ¾¹¥»÷¿ÉÄܲúÉúÔÚ2020Äê2ÔÂÖÐÑ®£¬ËûÃÇÒѾÁªÏµÁË5785¸öÔÚ2020Äê2ÔÂ1ÈÕÖÁ2020Äê4ÔÂ15ÈÕÖ®¼ä²úÉú¹ýÂòÂôµÄ¿Í»§£¬²¢Ô¤¼Æ´ËÊÂÎñ»áÓ°Ïìµ½½ü1000ÃûÓû§¡£
ÔÎÄÁ´½Ó£º
https://international-adviser.com/cisi-payment-breach-leaves-members-vulnerable-to-fraud/
4.µÂ¹úµ±¾ÖÔâCOVID-19´¹µö¹¥»÷ËðʧÊýǧÍòÅ·Ôª
µÂ¹ú±±ÍþÖݵ±¾ÖÓÉÓÚÆäÓÃÀ´·Ö·¢Covid19¾ÈÖú½ðµÄÍøÕ¾µÄ²»°²È«ÐÔ£¬ËðʧÁËÊýǧÍòÅ·Ôª¡£ÓÉÓÚ¸ÃÍøÕ¾½öÒªÇ󱾵ؾÓÃñºÍ¹«Ë¾Ìîд±í¸ñ£¬¶øÃ»ÓÐѡȡÈκζî±íµÄÉí·ÝÑéÖ¤£¬Ê¹µÃºÚ¿ÍÄܹ»½øÐд¹µö¹¥»÷¡£¾ÝϤ£¬ºÚ¿ÍαÔìÁ˸ùٷ½ÍøÕ¾£¬²¢Í¨¹ý·¢Ë͵ç×ÓÓʼþµÄ·½Ê½ÓÕʹÓû§µÇ½´ËαÔìÍøÕ¾ÒÔÇÔÈ¡ÆäÓ×ÎÒÐÅÏ¢¡£Ö®ºóÀûÓÃÕæÊµÓû§µÄÓ×ÎÒÐÅÏ¢Ïòµ±¾ÖÌá³öÉêÇë¾ÈÖú½ðµÄÒªÇ󣬲¢½«»ãÈë×ʽðµÄÒøÐÐÕÊ»§Åú¸Ä³ÉËûÃÇ×Ô¼ºµÄÕË»§¡£¾ÝHandelsblatt±¨Â·£¬µ±¾ÖÒÑÊÕµ½38Íò·ÝÒªÔöÔ®ÉêÇ룬²¢ÒѾÔÞ³ÉΪÆäÖеÄ36Íò·Ý¸¶¿î¡£¾ÝµÂ¹úµçÊǪ́Tagesschau±¨Â·£¬ÆäÖÐÓÐ3500ÖÁ4000·ÝÉêÇëÊǼٵ쬴ÖÂÔ¹À¼Æ±±ÍþÖݵ±¾ÖĿǰµÄËðʧÖÁÉÙΪ3150ÍòÅ·Ôª£¨3425ÍòÃÀÔª£©£¬×î¸ß¿ÉÄÜΪ1ÒÚÅ·Ôª£¨1.09ÒÚÃÀÔª£©¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/german-government-might-have-lost-tens-of-millions-of-euros-in-covid-19-phishing-attack/
5.ºÉÀ¼COVID-19¸ú×ÙÀûÓÃCovid19 Alertй¶»¼ÕßÐÅÏ¢
¾ÝRTL NieuwsÍøÕ¾±¨Â·£¬ºÉÀ¼ÄâÓÃÀ´¸ú×ÙCOVID-19»¼ÕßµÄÀûÓ÷¨Ê½Covid19 AlertÒâ±íй¶Óû§ÐÅÏ¢¡£Covid 19 AlertµÄ½²»°È˰µÊ¾£¬ÔÚËûÃǽ«Ô´´úÂë·¢Ë͸ø×¨¼Ò½øÐзÖÎöʱ£¬²»Ó×ÐĽ«Óû§Êý¾Ý·ÅÔÚÁËÍøÉÏ¡£ÕâЩԴÎļþÖÐÔ̺¬ImmotefÀûÓõÄÊý¾Ý¿â£¬ÀïÃæ´æ·ÅÓкÉÀ¼Óû§µÄÊý¾Ý£¬Ô̺¬½ü200¸öÓû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍ¹þÏ£ÃÜÂë¡£Covid19 Alert¿ª·¢ÍŶӰµÊ¾¸ÃÊÂÎñÒѻ㱨¸øºÉÀ¼Êý¾Ý±£»¤¾Ö£¬²¢ÇÒÔÚÖÂÁ¦½â¾ö´Ë°²È«ºÍÒþÖÔÎÊÌâ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/101914/digital-id/coronavirus-contact-tracing-app-data-leak.html
6.×êÑлú¹¹·¢ÏÖÕë¶Ôµ±¾Ö¾¼Ã´Ì¼¤´òËãµÄ¶ñÒâÓòÃû¼¤Ôö
Check PointµÄ×êÑÐÈËÔ±°µÊ¾£¬½ü¼¸ÖÜÕë¶Ôµ±¾Ö¾¼Ã´Ì¼¤´òËãºÍ¾ÈÖú´òËãµÄ¶ñÒâÓòÃû¼±¾çÔö³¤£¬Ö¼ÔÚÆÈ¡Óû§µÄÓ×ÎÒÐÅÏ¢½øÐÐڲơ£´Ó3ÔÂ16ÈÕÃÀ¹úµ±¾ÖÌá³öÁ˾¼Ã´Ì¼¤´òËãÆðÍ·£¬Ð¶ñÒâÓòÃûµÄ×¢²áÊýÁ¿ËæÖ®Ôö³¤µ½Ç°¼¸ÖܵÄ3.5±¶£¬¶ø´¹µö¹¥»÷µÄ´ÎÊýÃÍÔöÖÁÖðÈÕ14000´Î£¬Ô¼ÎªÖ®Ç°µÄ6±¶£¬4ÔÂ7-14ÈÕ¸üÊǼ¤ÔöÖÁÖðÈÕ20000´Î¡£×Ô1Ô·ÝCOVID-19·¢×÷ÒÔÀ´£¬ÒѾÓÐÔ¼68000¸öÓë¹Ú×´²¡¶¾ÓйصÄÐÂÓòÃû±»×¢²á£¬ÆäÖÐ4ÔÂ2ÈÕºóÐÂ×¢²áÁË17000¸öÓò£¬ÆäÖÐ2£¥ÊǶñÒâÓòÃû£¬¶ø21£¥Îª¿ÉÒÉÓòÃû¡£×êÑÐÈËÔ±°µÊ¾£¬ÕâЩ¶ñÒâÍøÕ¾ÆóIJÀûÓÃCovid-19¾¼Ã´Ì¼¤´òËãµÄÐÂÎÅÀ´ÓÕʹÓû§µÇ½¸ÃÍøÕ¾£¬²¢ÇÒÇÔÈ¡Êܺ¦ÕßµÄÓ×ÎÒÐÅÏ¢²¢ÇÒÌáÒ鲯ÕþڲƵȹ¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.jpost.com/israel-news/israeli-researchers-hackers-aiming-to-exploit-government-financial-aid-625218


¾©¹«Íø°²±¸11010802024551ºÅ