Google Nest·þÎñÖжϵ¼ÖÂÅ·ÃÀÓû§ÖÇÄܼҾÓʧÁ飻ºÚ¿Í¿ÉÀûÓÃ˼¿ÆWebexÖзì϶Òñ±ÎµØ²ÎÓë»áÒé
°ä²¼¹¦·ò 2020-11-19
±¾ÖܶþGoogle Nest·þÎñ´ó¹æÄ£Öжϣ¬µ¼Ö±±ÃÀºÍÅ·ÖÞÓû§ÖÇÄܼҾÓʧÁé¡£ÖܶþÁ賿£¬¹È¸è×ܲ¿°ä²¼ÐÂÎųƣ¬Æä·¢ÏÖÒ»¸öÎÊÌâ»áÓ°Ïì¹È¸èNestÉ豸ºÍNestÀûÓ᣸ÃÎÊÌâµ¼ÖÂÖÇÄܼҾÓÓû§ÎÞ·¨µÇ¼ÆäÕË»§£¬ÎÞ·¨Ê¹ÓÃÖÇÄÜÊÖ»úÅÔ¹ÛÊÓÆµÖ±²¥£¬ÎÞ·¨µ÷ÕûºãνÚÔìÆ÷£¬Ò²ÎÞ·¨ÓëNestµÄÈκÎϵÁвúÆ·»¥¶¯£¬ÆäÖб±ÃÀºÍ±±Å·µÄÓû§Êܵ½µÄÓ°Ïì×î´ó¡£Æäʵ£¬¸Ã·þÎñÔÚ2ÔÂÒ²²úÉúÁËÀàËÆµÄÖжϣ¬³ÖÐøÁË16¸öÓ×ʱ¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.com/2020/11/17/google_nest_outage/
2.ºÚ¿Í¿ÉÀûÓÃ˼¿ÆWebexÖзì϶Òñ±ÎµØ²ÎÓë»áÒé

ºÚ¿Í¿ÉÀûÓÃ˼¿ÆWebexÊÓÆµ»áÒéÀûÓÃÖеÄÈý¸ö·ì϶£¬ÒÔÐéαÓû§µÄÉí·ÝDZÈë²¢²ÎÓëWebex»áÒ飬¶øÆäËû²Î¼ÓÕß¿´²»µ½¡£IBM×êÑÐÈËÔ±°µÊ¾£¬ÕâЩ·ì϶´æÔÚÓÚ³ÉÁ¢ÐµÄWebex»áÒéʱµÄÎÕÊÖ¹ý³ÌÖУ¬±»×·×ÙΪCVE-2020-3441¡¢CVE-2020-3471ºÍCVE-2020-3419¡£¹¥»÷Õß½áºÏʹÓÃÄܹ»¹í»êÓû§Éí·Ý²ÎÓëWebex»áÒ飬²¢¶ÔÆäËûÓë»áÕß²»Ë½¼û£»ÔÚ±»ÌߺóÈÔÁôÔÚ·¿¼äÄÚ£»»ñÈ¡ÓйػáÒé²Î¼ÓÕßµÄÐÅÏ¢£¬ÀýÈçÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍIPµØÖ·¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/cisco-webex-bugs-allow-attackers-to-join-meetings-as-ghost-users/
3.жñÒâÈí¼þChaes¶Ô×¼MercadoLivreÇÔÈ¡²ÆÕþÐÅÏ¢

Cybereason Nocturnus×êÑÐÈËÔ±·¢ÏÖжñÒâÈí¼þChaes¶Ô×¼ÁËÀ¶¡ÃÀÖ޵ĵçÉÌÆ½Ì¨MercadoLivre£¬Ö¼ÔÚÇÔÈ¡²ÆÕþÐÅÏ¢¡£ChaesÓÚ2020Ëêĺ³õ´Î±»·¢ÏÖ£¬ÆäÒÔMercadoLivre²É°ì³É¹¦ÎªÖ÷Ìâͨ¹ýÍøÂç´¹µö»î¶¯½øÐд«²¼¡£´Ë±í£¬ÎªÁËÔö³¤µç×ÓÓʼþµÄºÏ·¨ÐÔ£¬ºÚ¿Í»¹Ôö³¤ÁËAvastɨÃè½Å×¢¡£¸Ã¶ñÒâÈí¼þ¼Ù×°³ÉºÏ·¨¹ý³ÌµÄÄ£¿éÒÔÇÔȡϵͳÐÅÏ¢£¬²¢´ÓGoogle Chromeä¯ÀÀÆ÷»á»°ÖÐÌáÈ¡Ãô¸ÐÐÅÏ¢£¬Ö¼ÔÚÇÔÈ¡ÔÚÏßÕÊ»§µÄµÇ¼ʹ´¦ºÍ²ÆÕþÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/chaes-malware-strikes-customers-of-latin-americas-largest-e-commerce-platform/
4.ÐÂAPT FunnyDreamÕë¶Ô¶«ÄÏÑÇ£¬ÒÑϰȾ200¶à¸öϵͳ

°²È«¹«Ë¾BitdefenderÅû¶ÐÂAPT×éÖ¯FunnyDreamÕë¶Ô¶«ÄÏÑÇ£¬ÒÑϰȾ200¶à¸öϵͳ¡£¸Ã×éÖ¯ÖØÒªÕë¶Ô¶«ÄÏÑǹú¶Èµ±¾Ö£¬ÖØÒª´ÓÊÂÉæ¼°µ½¹ú¶È°²È«ºÍ¹¤ÒµµÄÍøÂç¼äµý»î¶¯¡£Æ¾¾ÝBitdefenderÊý¾Ý£¬¸Ã×éÖ¯×ܹ²Ê¹ÓÃÁËÈýÖÖ¶ñÒâÈí¼þ£¬Ê×ÏȲ¿ÊðChinoxy×÷Ϊ³õʼ½Ó¼ûµÄÒ»¸öµ¥Ò»ºóÃÅ£¬¶øºóͨ¹ýÆä²¿Êð¿ªÔ´Ô¶³Ì½Ó¼ûľÂíPCShare£¬ÓÃÓÚ̽²âÊÜϰȾµÄÖ÷»ú£¬×îºó²¿ÊðÓÃÓÚÊý¾ÝÍøÂçºÍÊý¾Ýй©FunnyDream¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/more-than-200-systems-infected-by-new-chinese-apt-funnydream/
5.¶íÂÞ˹Sberbank³Æ2020Äê¸Ã¹ú½«ÒòÍøÂç·¸×ïËðʧ440ÒÚÃÀÔª

¶íÂÞ˹¹úÓÐÒøÐÐSberbank³Æ2020Äê¸Ã¹ú½«ÒòÍøÂç·¸×ïËðʧ440ÒÚÃÀÔª¡£¸ÃÐаµÊ¾£¬ÓÉCOVID-19Òý·¢µÄ´ÓÉ̵êÏÖ½ðÂòÂôÏòÊý×ÖÖ§¸¶µÄת±ä£¬¼Ó¾çÁ˰²È«Òþ»¼¡£ÄÚÕþ²¿Ê®Ô°䲼µÄÊý¾ÝÏÔʾ£¬¶íÂÞ˹ÓëÒøÐп¨Óйصķ¸×ïÊýÁ¿ÔÚ2020ÄêÔö³¤ÁË500£¥¡£Sberbank¸±Ö÷ϯ³ÆÆä¾ùÔÈÿÌì±ØÐë´¦ÖÃ260ÒÚ´ÎÍøÂ簲ȫÊÂÎñ£¬²¢·ÖÎöÂ·ÍøÂç·¸×ïµÄÔö³¤¿ÉÄÜÊÇÓÉÓÚ¶íÂÞ˹ÈõÊÆ¹«Ãñ¶ÔÔÚÏßڲƺÍڲƼ¿Á©ÈÏÖª²»×ã¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/sberbank-prediction-2020/
6.Managed.comϰȾÀÕË÷Èí¼þµ¼Ö²¿ÃÅ·þÎñÆ÷å´»ú

11ÔÂ16ÈÕ£¬WebÍйܷþÎñÌṩÉÌManaged.comϰȾÀÕË÷Èí¼þµ¼Ö²¿ÃÅ·þÎñÆ÷å´»ú¡£Õâ´Î¹¥»÷Ó°ÏìÁ˸ù«Ë¾ÃæÏò¹«¼ÒµÄWebÍйÜϵͳ£¬µ¼ÖÂijЩ¿Í»§Õ¾µãµÄÊý¾Ý±»¼ÓÃÜ¡£Õû¸öÍøÂçÍйܻù´¡ÉèÊ©ÔÚ¹¥»÷²úÉúÊýÓ×ʱºó±»·ÛË飬ÆäÖÐÕâÔ̺¬WordPressºÍDotNetNukeÖÎÀíÖ÷»ú½â¾ö¹æ»®¡¢µç×ÓÓʼþ·þÎñÆ÷¡¢DNS·þÎñÆ÷¡¢RDP½Ó¼ûµã¡¢FTP·þÎñÆ÷ºÍÔÚÏßÊý¾Ý¿â£¬¸Ã¹«Ë¾Ä¿Ç°ÔÚÖÂÁ¦¸´Ô¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/web-hosting-provider-managed-shuts-down-after-ransomware-attack/


¾©¹«Íø°²±¸11010802024551ºÅ