ºÚ¿ÍÀûÓõç×ÓÒøÐÐDaveÖзì϶ÇÔÈ¡750ÍòÓû§Êý¾Ý £»Ó¢¹úNCSCÖÒ¸æÕë¶ÔÌåÓý×éÖ¯µÄBECºÍÀÕË÷¹¥»÷

°ä²¼¹¦·ò 2020-07-27

1.ºÚ¿ÍÀûÓõç×ÓÒøÐÐDaveÖзì϶£¬ÇÔÈ¡750ÍòÓû§Êý¾Ý



GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µç×ÓÒøÐÐDaveÈÏ¿ÉÆäÀûÓôæÔÚ°²È«·ì϶£¬²¢±»ºÚ¿ÍÀûÓõ¼ÖÂ7516625Óû§¾ßÌåй¶¡£Dave°µÊ¾£¬¸Ã·ì϶ԴÓÚÆä¹¤³ÌÍŶÓ֮ǰʹÓõķÖÎöƽ̨Waydev¡£Ä¿Ç°£¬DaveµÄй¶ÐÅÏ¢¿ÉÔÚ°µÍøÖÐÃâ·Ñ½øÐнӼû£¬Ô̺¬ÕæÊµÐÕÃû¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþ¡¢µ®ÉúÈÕÆÚ¡¢¼ÒͥסַÒÔ¼°bcrypt¼ÓÃܵÄÃÜÂ룬ijЩÐÅÏ¢Öл¹Ô̺¬ÒøÐп¨ÐÅÏ¢ºÍÉç»á°²È«ºÅÂë¡£¸Ã¹«Ë¾°µÊ¾£¬´Ë¿ÌËûÃÇÒѾ­½¨¸´Á˺ڿÍÀûÓõķì϶£¬²¢½«´ËÊÂÎñ֪ͨ¿Í»§£¬DaveÀûÓõÄÃÜÂëÒ²½«±»³ÁÖá£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/tech-unicorn-dave-admits-to-security-breach-impacting-7-5-million-users/#ftag=RSSbaffb68


2.ÓÌËû´óѧ½¡È«ÖÐÐÄÔâ´¹µö¹¥»÷£¬»¼ÕßÊý¾Ýй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÓÌËû´óѧ½¡È«ÖÐÐÄ£¨U of U Health£©Ôâµ½´¹µö¹¥»÷£¬µ¼Ö»¼ÕßÊý¾Ýй¶¡£2020Äê4ÔÂ6ÈÕÖÁ5ÔÂ22ÈÕ£¬ºÚ¿Í¶ÔÓÌËû´óѧ½¡È«ÖÐÐĵÄÔ±¹¤µç×ÓÓʼþÕÊ»§ÌáÒéÍøÂç´¹µö¹¥»÷£¬²¢¶ÔÕâЩÕË»§½øÐз¸·¨½Ó¼û¡£¾­¹ýµ÷²é£¬Õâ´Î¹¥»÷й¶ÁË»¼ÕßÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢²¡ÀúºÅÒÔ¼°Ó벿ÃÅÁÙ´²ÐÅÏ¢¡£U of U HealthÓÚ½ñÄêÔçЩʱҲÔâµ½¹ýÀàËÆµÄ¹¥»÷ÊÂÎñ£¬×ÔÄÇʱÒÔÀ´Ò»ÏòÖÂÁ¦ÓÚ°²È«ÐԵļÓÇ¿¡£¸Ã´óѧ¶Ô´ËÊÂÎñµÄµ÷²éÔÚ½øÐÐÖУ¬²¢°µÊ¾»á¼ÓÇ¿ÐÅÏ¢°²È«·¨Ê½¡£


Ô­ÎÄÁ´½Ó£º

https://healthcare.utah.edu/publicaffairs/news/2020/06/data-breach.php


3.Ó¢¹úNCSCÖÒ¸æÕë¶ÔÌåÓý×éÖ¯µÄBECºÍÀÕË÷¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©ÖÒ¸æÕë¶ÔÌåÓý×éÖ¯ºÍÇò¶Ó£¨Ô̺¬Ó¢³¬×ãÇò¾ãÀÖ²¿£©µÄÀÕË÷Èí¼þ¹¥»÷¡¢ÍøÂç´¹µö¹¥»÷ÒÔ¼°Ã³Ò×µç×ÓÓʼþÍ×Э£¨BEC£©Ú²Æ­´øÀ´µÄÈÕÒæÔö³¤µÄ·çÏÕ¡£¾ÝIpsos MORIµ÷²éµÃ³öµÄÊý¾Ý£¬ÖÁÉÙ70£¥µÄÌåÓý×éÖ¯ÔÚÈ¥Äê¾­ÀúÁËÊý¾Ýй¶»òÍøÂç¹¥»÷ÊÂÎñ£¬ÆäÖеÄ30£¥ÔÚ´ËÆÚ¼ä¼Í¼ÁË5´ÎÒÔÉϹ¥»÷£¬±Å×¢¹úÆóÒµµÄ¾ùÔÈÖµÓâÔ½Ò»±¶¡£ÔÚÕâЩ¹¥»÷ÊÂÎñÖУ¬Ô¼Äª30£¥µÄ×éÖ¯¾ùÔȾ­¼ÃËðʧҲ´ïµ½ÁË10000Ó¢°÷£¨12700ÃÀÔª£©£¬ÆäÖÐ×î´óµÄµ¥ÏîËðʧ³¬¹ý400ÍòÓ¢°÷£¨½«½ü5100000ÃÀÔª£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/uk-govt-warns-of-ransomware-bec-attacks-against-sports-sector/


4.еÄShadow¹¥»÷¿É¸ü¸Ä¾­¹ýÊý×ÖÊðÃûµÄPDFÎļþ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µÂ¹ú²¨ºè´óѧ£¨Ruhr-University Bochum£©µÄ×êÑÐÈËÔ±°ä²¼»ã±¨£¬·¢ÏÖеÄShadow¹¥»÷¿É¸ü¸Ä¾­¹ýÊý×ÖÊðÃûµÄPDFÎļþ£¬¸Ã¹¥»÷·½Ê½¿ÉÓ°ÏìAdobe Acrobat Pro¡¢Adobe Acrobat Reader¡¢Perfect PDF¡¢Foxit Reader¡¢PDFelementµÅצÓ᣸ù¥»÷±³ºóµÄÖØÒªË¼ÏëÊÇÊÓͼ²ãµÄ¸ÅÏ룬¼´ÔÚPDFÎĵµÖб˴˳ÁµþµÄ·ÖÆçÄÚÈݼ¯¡£ºÚ¿Í½«ÓµÓÐ·ÖÆç²ãµÄÎĵµ·¢Ë͸øÊܺ¦Õߣ¬Êܺ¦Õß»áÔÚÎĵµµÄ×îÉÏÃæÒ»²ã½øÐÐÊý×ÖÊðÃû£¬µ«Êǵ±¹¥»÷ÕßÊÕµ½Ëüʱ£¬»á½«ÁíÒ»²ã¸ü¸ÄΪ¿É¼û²ã¡£¸Ã¹¥»÷ÔÊÐí¹¥»÷ÕßÔÚ²»Í»ÆÆ¼ÓÃÜÊðÃûµÄÇé¿ö϶ÔÓµÓÐ˾·¨Ô¼ÊøÁ¦µÄÎļþ½øÐжñÒâ²Ù×÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-shadow-attack-can-replace-content-in-digitally-signed-pdf-files/


5.×êÑÐÈËÔ±·¢ÏÖ¿ÉÔÚAlexaÉ̵êÉÏ´«234ÏîÎ¥·´Õþ²ßµÄÀûÓÃ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚΪÆÚ12¸öÔµÄAlexaÀûÓÃÉ̵êÉó²éÖУ¬×êÑÐÈËÔ±×ܹ²³¢ÊÔÉÏ´«234ÏîÎ¥·´Õþ²ßµÄAlexaÀûÓ÷¨Ê½£¬×îÖյõ½³É¹¦²¢Î´Óöµ½ºÜ´óµÄÄÑÌâ¡£¸Ã×êÑÐÓ××鰵ʾ£¬ÔÚ³õ´ÎÌύʱ³É¹¦ÈÏÖ¤ÁË193ÖÖÀûÓ㬲¢ÓÐ41ÖÖ±»»Ø¾ø¡£µ«ËæºóÔÚµÚ¶þ´Î³¢ÊÔÖ®ºó£¬ÕâЩÀûÓÃÈ«ÊýÉÏ´«³É¹¦¡£ÔÚÕâ´Î³¢ÊÔÖУ¬×êÑÐÈËÔ±ÉÏ´«µÄÀûÓÿÉÓÃÀ´ÍøÂç¸öÈËÐÅÏ¢£¬²¢ÁоÙÁ˲¿ÃÅ¿ÉÄܵ¼Ö¶ñÒâÀûÓÃÉÏ´«µÄÔ­Òò£¬Ô̺¬²é³­²»Ò»Ö¡¢ÓÐÏÞµÄÓïÒô²é³­¡¢¶Ô¿ª·¢ÈËÔ±µÄ¹ý¶ÈÐÅÀµ¡¢ÈÏÖ¤¹ý³ÌÉæ¼°µ½ÈËÀàºÍÉó²é¹ý³Ì²»¹»³¹µ×µÈÎÊÌâ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/academics-smuggle-234-policy-violating-skills-on-the-alexa-skills-store/#ftag=RSSbaffb68


6.TransUnionͳ¼ÆÓÐ27£¥Ïû·ÑÕßÔâµ½COVID-19Ö÷Ìâ´¹µö¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


TransUnion°ä²¼»ã±¨£¬´¹µö¹¥»÷ÊÇÓëCOVID-19ÓйصÄ×îÑϳÁµÄÊý×ÔìÛÕ©¼¿Á©£¬¾Ýͳ¼ÆÓÐ27£¥Ïû·ÑÕßÔâµ½ÒÔCOVID-19ΪÖ÷Ìâ´¹µö¹¥»÷¡£TransUnion¸ß¼¶¸±×ܲÃShai Cohen°µÊ¾£¬Éí·ÝڲƭÊǹ¥»÷ÕßÀûÓÃÍøÂç´¹µöºÍÆäËûÉç»á¹¤³Ì¹¥»÷ÇÔÈ¡µÞ·ÑÕßÊý¾ÝµÄÖØÒª·½Ê½¡£ÔÚ2020Äê6ÔÂ30ÈÕÖÁ7ÔÂ6ÈÕÖ®¼ä¶Ô¼ÓÄô󡢸çÂ×±ÈÑÇ¡¢Ïã¸Û¡¢ÄÏ·Ç¡¢Ó¢¹úºÍÃÀ¹úµÄ7384ÃûÊÜ·ÃÕß½øÐе÷²é£¬ÆäÖÐÓÐ32£¥µÄÈ˰µÊ¾ËûÃÇÒÑÔâµ½ÓëCOVID-19ÓйصÄÊý×ÔìÛÕ©£¬ÖØÒª·½Ê½Îª´¹µö¹¥»÷¡¢ÍøÉÏÉ̵êڲƭºÍ´È±¯Ú²Æ­µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/07/24/pandemic-themed-phishing-scams/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+HelpNetSecurity+%28Help+Net+Security%29