¹þÈø¿Ë˹̹µÚÈý´ÎÇ¿ÔìÔÚÆä¹«ÃñÉ豸ÉÏ×°ÖøùÖ¤Ê飻NSAÖÒ¸æ¶íÂÞ˹ºÚ¿ÍÀûÓÃеÄVMware·ì϶ÇÔÈ¡Êý¾Ý
°ä²¼¹¦·ò 2020-12-081.¹þÈø¿Ë˹̹µÚÈý´ÎÇ¿ÔìÔÚÆä¹«ÃñÉ豸ÉÏ×°ÖøùÖ¤Êé

¹þÈø¿Ë˹̹µ±¾ÖÒÔÍøÂ簲ȫÑÝϰΪ»Ï×Ó£¬Ð²ÆÈÊ×¶¼Å¬¶ûËÕµ¤µÄ¹«ÃñÔÚÆäÉ豸ÉÏ×°ÖÃÊý×ÖÖ¤Êé¡£ÈôÊDz»×°Öõ±¾ÖµÄ¸ùÖ¤Ê飬¹«Ãñ½«ÎÞ·¨½Ó¼ûGoogle¡¢Twitter¡¢YouTube¡¢Facebook¡¢InstagramºÍNetflixµÈÍøÕ¾¡£Ò»µ©×°Ö㬸ÃÖ¤Ê齫ÔÊÐíµ±¾Öͨ¹ýÒ»ÖÖ³ÆÎªMitM£¨ÖÐÑëÈË£©µÄ¼¼ÊõÀ´À¹½ØÓû§É豸·¢³öµÄËùÓÐHTTPSÁ÷Á¿¡£ÕâÊǹþÈø¿Ë˹̹µ±¾Ö×Ô2015ÄêÒÔÀ´µÚÈý´ÎÇ¿ÔìÔÚÆä¹«ÃñÉ豸ÉÏ×°ÖøùÖ¤Êé¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/kazakhstan-government-is-intercepting-https-traffic-in-its-capital/
2.×êÑÐÈËÔ±·¢ÏÖ¿ÉÓÃÌî³ä¼¼ÊõÈÆ¹ýCloudflare WAF

°²È«¹«Ë¾SwascanµÄ×êÑÐÈËÔ±·¢ÏÖ¿ÉÓÃÌî³ä¼¼ÊõÈÆ¹ýCloudflare WAF¡£Ä¬ÈÏÅäÖÃϵÄCloudflare£¬ ÔÚ±íµ¥Êý¾ÝPOSTÒªÇó֮ǰÔö³¤Ô¼128KBµÄÌî³ä½«µ¼ÖÂWAF½«Æä½Ø¶ÏΪ×î´ó£¬Ìø¹ýÓÐÓàµÄ²¿ÃŲ¢½«Æä·¢Ë͸øÖ¸±êÀûÓ÷¨Ê½¡£Õ⽫ÔÊÐíºÚ¿ÍÈÆ¹ýWAF²¢ÀûÓÃÆäËûÀûÓ÷¨Ê½·ì϶£¬×êÑÐÈËÔ±ÔÚÉøÈë²âÊÔÖз¢ÏÖ¿ÉÀûÓø÷ì϶ÔÚÖ¸±êϵͳÉÏʵÏÖÔ¶³Ì´úÂëÖ´ÐнӼû¡£Cloudflare²úÆ·¾ÀíMichael Tremante½¨ÒéÆôÓÃrule 100048À´Ô¤·ÀÌî³ä¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://latesthackingnews.com/2020/12/06/cloudflare-waf-bypass-via-padding-technique-discovered/
3.NSAÖÒ¸æ¶íÂÞ˹ºÚ¿ÍÀûÓÃеÄVMware·ì϶ÇÔÈ¡Êý¾Ý

¹ú¶È°²È«¾Ö£¨NSA£©ÖҸ棬¶íÂÞ˹ºÚ¿ÍÔÚÀûÓÃеÄVMware·ì϶£¨CVE-2020-4006£©ÔÚÒ×Êܹ¥»÷µÄ·þÎñÆ÷Éϲ¿ÊðWeb Shell£¬ÒÔÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¸Ã·ì϶ΪºÅÁî×¢Èë·ì϶£¬ÒÑÓÚ12ÔÂ3ÈÕ±»½¨¸´¡£NSA·¢´Ë¿ÌÕâ´Î¹¥»÷»î¶¯ÖУ¬ºÚ¿ÍÊ×ÏÈÏνӵ½VMware²úƷ¶³öµÄwebÖÎÀí½çÃæ£¬Í¨¹ýºÅÁî×¢ÈëÀ´ÈëÇÖ×éÖ¯ÍøÂç²¢×°ÖÃweb shell¡£Ö®ºó£¬¹¥»÷ÕßʹÓÃSAMLƾ֤ÇÔÈ¡Ãô¸ÐÊý¾Ý£¬ÒÔ»ñµÃ¶ÔADFS·þÎñÆ÷µÄ½Ó¼ûȨ£¬²¢ÔÚ±»¹¥»÷µÄÉ豸ÉÏÖ´ÐÐLinuxºÅÁÒÔ»ñµÃÓÆ¾ÃÐÔ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/nsa-russian-state-hackers-exploit-new-vmware-vulnerability-to-steal-data/
4.McAfee°ä²¼ÍøÂç·¸×ïµÄÒþÐԳɱ¾µÄ·ÖÎö»ã±¨

McAfee°ä²¼ÁËÓйØÍøÂç·¸×ïµÄÒþÐԳɱ¾µÄ·ÖÎö»ã±¨£¬³Áµã×êÑÐÍøÂç·¸×ïÔÚÈ«ÇòÁìÓòÄÚÔì³ÉµÄ³Á´ó²ÆÕþÓ°ÏìºÍδÏÔ¶µÄÓ°Ïì¡£»ã±¨Ö¸³ö£¬ÍøÂç·¸×ï¸øÊÀ½ç¾¼ÃÔì³ÉµÄËðʧ³¬¹ý1ÍòÒÚÃÀÔª£¬Õ¼È«ÇòGDPµÄ1£¥ÒÔÉÏ£¬±È2018Äê½ü6000ÒÚÃÀÔªµÄËðʧÔö³¤ÁË50£¥¡£¸Ãµ÷²éÏÔʾ£¬ÓÐ92£¥µÄÆóÒµÒÔΪ£¬³ýÁ˲ÆÕþ³É±¾ºÍÍøÂçÊÂÎñºóµÄ¹¤×÷¹¦·òËðʧ֮±í£¬»¹ÓÐÆäËû¸ºÃæÓ°Ï죬Èçϵͳͣ»ú¡¢Ð§ÄܽµµÍ¡¢Í»·¢ÊÂÎñÏìÓ¦³É±¾ÒÔ¼°Æ·ÅƺÍÃûÓþÊÜËð¡£
ÔÎÄÁ´½Ó£º
https://www.mcafee.com/enterprise/en-us/assets/reports/rp-hidden-costs-of-cybercrime.pdf
5.Ç÷Ïò¿Æ¼¼°ä²¼2020ÄêÍøÂç·çÏÕÖ¸ÊýµÄ·ÖÎö»ã±¨

Ç÷Ïò¿Æ¼¼°ä²¼ÁË2020ÄêÓйØÍøÂç·çÏÕÖ¸ÊýµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬ÔÚ´ÓǰһÄ꣬ȫÇò23£¥µÄ×éÖ¯Ôâµ½Æß´Î»ò¸ü¶àµÄ¹¥»÷¡£Êý¾ÝÏÔʾ£¬È«Çò×î´óµÄÍøÂçÍþв·çÏÕÊÇÍøÂç´¹µöºÍÉç»á¹¤³Ì¡¢µã»÷½Ù³Ö£¨Clickjacking£©¡¢ÀÕË÷Èí¼þ¡¢ÎÞÎļþ¹¥»÷¡¢½©Ê¬ÍøÂçºÍÖÐÑëÈ˹¥»÷£¬×éÖ¯µÄÖØÒª¹Ø×¢µãÊǿͻ§Êý¾ÝÃÔʧ¡¢»ñȡ֪ʶ²úȨºÍ²ÆÕþÐÅÏ¢¡¢¿Í»§Á÷ʧºÍÉ豸ʧÇÔ»ò°Ü»µ£¬IT»ù´¡¼Ü¹¹ÖеÄÖØÒª·çÏÕΪ×é֯ʧºÍг¸´ÔÓÐÔ¡¢ÄÚ²¿È˺öÂÔ´óÒâ¡¢ÔÆÍÆËã»ù´¡¼Ü¹¹ºÍÌṩÉÌ¡¢È˲ÅǷȱºÍ¶ñÒâÄÚ²¿ÈËÔ±¡£
ÔÎÄÁ´½Ó£º
https://newsroom.trendmicro.com/2020-12-02-A-Quarter-of-Global-Organizations-Were-Hit-by-Seven-or-More-Cyber-Attacks-in-The-Last-Year
6.°ÍÎ÷EmbraerϰȾRansomExx£¬»úÃÜÊý¾Ýй¶

°ÍÎ÷EmbraerϰȾÀÕË÷Èí¼þRansomExx£¬»úÃÜÊý¾Ýй¶¡£EmbraerÊǽö´ÎÓÚ²¨ÒôºÍ¿ÕÖпͳµ¹«Ë¾µÄµÚÈý´ó·É»úÔì×÷ÉÌ£¬ÓÉÓڻؾøÖ§¸¶Êê½ð£¬ºÚ¿ÍÒÑй¶Æä²¿ÃÅ»úÃÜÊý¾Ý¡£Õâ´Îй¶µÄÊý¾ÝÔ̺¬Ô±¹¤¾ßÌåÐÅÏ¢µÄÑù±¾¡¢Ã³Ò׺Ïͬ¡¢·ÉÐзÂÕÕÕÕÆ¬ºÍÔ´´úÂëµÈ¡£¸Ã¹«Ë¾ÔÚ֮ǰ°µÊ¾£¬¹¥»÷ÕßÖ»ÄܽøÈëÆä²¿ÃÅϵͳ£¬²¢½ö¶ÔÆäijЩÐж¯Ôì³ÉÁÙʱµÄÓ°Ïì¡£µ«ÔÚ´ËÊý¾Ýй¶ÊÂÎñ²úÉúºó£¬¸Ã¹«Ë¾²¢Î´»Ø¸´ÖÃÆÀÒªÇó¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hackers-leak-data-from-embraer-worlds-third-largest-airplane-maker


¾©¹«Íø°²±¸11010802024551ºÅ