Apple iCloudÖжÏ36Ó×ʱ£¬Éв»Ã÷ÏÔ¹ÊÕÏÔ­Òò£»Nintendo 3DS´æÔڿɵ¼ÖÂMiTM¹¥»÷µÄ·ì϶

°ä²¼¹¦·ò 2020-12-28
1.Apple iCloudÖжÏ36Ó×ʱ£¬Éв»Ã÷ÏÔ¹ÊÕÏÔ­Òò


1.jpg


Apple iCloud·þÎñ³öÏÖ¹ÊÕÏ£¬Ê¹Óû§ÎÞ·¨µÇ¼¸Ã·þÎñ½Ó¼ûÎļþ»òÉèÖÃÐÂÉ豸¡£Õâ´ÎÖжϴÓÃÀ¹ú¶«²¿¹¦·ò12ÔÂ25ÈÕÉÏÎç4:45ÆðÍ·£¬Ö±µ½12ÔÂ26ÈÕÏÂÎç4:35²Å±»½¨¸´£¬Àúʱ36Ó×ʱ¡£ÖÐ¶ÏÆÚ¼ä£¬AppleµÄϵͳ״̬ҳÉϽöÏÔʾ¡°Óû§¿ÉÄÜÓöµ½´Ë·þÎñµÄÎÊÌ⡱µÄÌáÐÑ£¬Ã»Óиü¶àÓÐ¹ØÆäÖжϵÄÐÅÏ¢¡£Ä¿Ç°£¬Apple¹«Ë¾Ã»ÓÐÌṩÈκÎÒÔÕÏÔ­Òò¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/apple/apple-icloud-outage-prevents-device-activations-access-to-data/


2.ºÚ¿ÍÏúÊÛÓÎÏ·¹«Ë¾Koei TecmoµÄÊý¾ÝºÍ½Ó¼ûȨ


2.png


ºÚ¿ÍÔÚ°µÍøÏúÊÛÓÎÏ·¹«Ë¾Koei TecmoµÄÊý¾ÝºÍ½Ó¼ûȨ¡£12ÔÂ20ÈÕ£¬ºÚ¿ÍÐû³ÆÆäÓÚ12ÔÂ18ÈÕÀûÓÃÓã²æÊ½´¹µö¹¥»÷ÈëÇÖÁËkoeitecmoeurope.comÍøÕ¾£¬ÇÔÈ¡ÁËÂÛ̳Êý¾Ý¿â²¢Ö²ÈëÁËWeb ShellÒÔ±ãºóÐø½Ó¼û¡£Ö®ºóºÚ¿ÍÔÚ°µÍøÉÏÒÔ0.05±ÈÌØ±Ò£¨Ô¼ºÏ1300ÃÀÔª£©µÄ¼ÛÖµÏúÊÛÊý¾Ý¿â£¬²¢ÒÔ0.25£¨Ô¼ºÏ6500ÃÀÔª£©µÄ¼ÛÖµÏúÊÛWeb shell½Ó¼ûȨÏÞ¡£¸Ã±»µÁÊý¾Ý¿âÔ̺¬ÁË65000¸öÓû§µÄÊý¾Ý£¬Ô̺¬µç×ÓÓʼþµØÖ·¡¢IPµØÖ·¡¢¹þÏ£ÃÜÂë¡¢Óû§Ãû¡¢µ®ÉúÈÕÆÚºÍ¹ú¶È¡£Ä¿Ç°£¬Koei TecmoÒѹعØÃÀ¹úºÍÅ·ÖÞµÄÍøÕ¾£¬ÒÔÔ¤·À¿ÉÄܲúÉúµÄ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/koei-tecmo-discloses-data-breach-after-hacker-leaks-stolen-data/


3.Nintendo 3DS´æÔڿɵ¼ÖÂMiTM¹¥»÷µÄ·ì϶


3.png


×êÑÐÈËÔ±·¢ÏÖNintendo 3DS´æÔÚÑϳÁµÄ·ì϶£¬¿ÉÄܵ¼ÖÂMiTM¹¥»÷¡£¸Ã·ì϶λÓÚNintendo 3DS¶ÔÊý×ÖÖ¤ÊéµÄ´¦ÖÃÖУ¬ ³ÉÁ¢SSL/TLSÏνÓʱSSLϵͳÄ£¿éδÕýÈ·ÑéÖ¤x509Ö¤Ê飬´Ó¶øÔÊÐí¹¥»÷ÕßαÔìαÔìÖ¤ÊéÀ´Ö´ÐÐMitM¹¥»÷£¬»òºýŪÊÜÐÅÀµµÄ·þÎñÆ÷£¬ÀýÈçºýŪeShop·þÎñÆ÷²¢ÇÔÈ¡Óû§ÐÅÏ¢£¬ºýŪÓëÓÎÏ··þÎñÆ÷µÄÏνӵÈ¡£¸Ã·ì϶ӰÏìÁËËùÓй̼þ°æ±¾Îª11.13»ò¸üµÍµÄNintendo 3DS½ÚÔį̀£¬Ä¿Ç°Òѱ»½¨¸´¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/12/27/critical-vulnerability-in-nintendo-3ds-console-could-allow-mitm-attacks/


4.ËÕ¸ñÀ¼»·±£¾ÖÊܵ½¹¥»÷£¬ÁªÏµÖÐÐĵȲ¿ÃÅÊܵ½Ó°Ïì


4.png


ËÕ¸ñÀ¼»·¾³±£»¤¾Ö£¨Sepa£©Ôâµ½¹¥»÷£¬ÁªÏµÖÐÐĵȲ¿ÃÅÊܵ½Ó°Ïì¡£¸Ã¹«Ë¾CEO David Pirie³ÆÔÚ°²È»Ò¹µÄÎçÒ¹£¬SepaµÄϵͳÔâ·êÁ˳Á´óÇÒ³ÖÐøµÄÍøÂç¹¥»÷¡£¹¥»÷Ó°ÏìÁ˸ù«Ë¾µÄÁªÏµÖÐÐÄ¡¢ÄÚ²¿ÏµÍ³¡¢Á÷³ÌºÍÄÚ²¿Í¨Ñ¶¡£µ«ÊÇÆäÖ÷Ìâ¼à¿ØÏµÍ³ºÍ¾¯±¨·þÎñûÓÐÊܵ½Ì«´óµÄÓ°Ï졣Ŀǰ£¬SepaÕýÓëËÕ¸ñÀ¼µ±¾ÖºÏ×÷£¬ÒÔµ÷²é²¢½â¾öÕâ´Î¹¥»÷ÊÂÎñ¡£


Ô­ÎÄÁ´½Ó£º

https://news.stv.tv/scotland/scottish-environment-protection-agency-targeted-in-cyberattack?top


5.Rapid7°ä²¼2020Äê¶ÈÍøÂç¹¥»÷µÄÌ¬ÊÆ»ã±¨


5.png


Rapid7°ä²¼ÁË2020Äê¶ÈÍøÂç¹¥»÷µÄÌ¬ÊÆ»ã±¨¡£¸Ã»ã±¨ÖØÒª·ÖÎöÁ˶ñÒâµÄMicrosoft SQL Server¹¥»÷¡¢Î¢ÈíÔ¶³Ì×ÀÃæºÍ̸(RDP)¹¥»÷ºÍ΢ÈíSMB¹¥»÷¡£»ã±¨·¢ÏÖ£¬´ó¹æÄ£µÄ½©Ê¬ÍøÂçÔÚ½ñÄêÏÄÌì֮ǰºöÈ»Òþû£¬¶øMS SQL serverÍ´´¦ºÍ²éÎʹ¥»÷´ïµ½ÁËÒÔÍùµÄ¾ùÔÈˮƽ¡£´Ë±í£¬Õë¶ÔRDPµÄÀÕË÷Èí¼þ¹¥»÷ÊÇÒ»¸ö´óÎÊÌ⣬ºÜ¶à¹¥»÷Õß¶Ô×¼ÁË×ÊÔ´²»¼°µÄÒ½ÁÆÐÐÒµ¡¢½ÌÓýºÍµ±¾Ö×éÖ¯¡£Õë¶ÔMicrosoft SMB·þÎñÆ÷µÄ×¢ÈëEternalBlueµÄ¹¥»÷Ò²ÓÐËùÔö³¤¡£


Ô­ÎÄÁ´½Ó£º

https://blog.rapid7.com/2020/12/25/rapid7-labs-2020-naughty-list-summary-report-to-santa/


6.Aspen°ä²¼ÓйØÊý×Ö»ù´¡ÉèÊ©µÄ·ÖÎö»ã±¨


6.png


Aspen°ä²¼ÁËÓйØÊý×Ö»ù´¡ÉèÊ©µÄ·ÖÎö»ã±¨¡£2020Äê£¬ÍøÂ簲ȫÒѳÉΪÿ¸öÐÐÒµÒÔ¼°ÃÀ¹úµ±¾ÖµÄÄÑÌ⣬¸Ã»ã±¨Ö¸³öÁËÐÂÈÎ×Üͳµ±¾ÖÓкܶà»úÓöÄܹ»Ôö³¤ÍøÂ簲ȫ¹¤×÷²¢Ìá¸ßÈËÃǵÄÒâʶ£¬ÒÔ´´½¨¸ü¾ßµ¯ÐÔµÄÊý×Ö»ù´¡¼Ü¹¹¡£¸Ã»ã±¨Ö¼ÔÚÔ®ÊÖ¾ö²ßÕßÈ·¶¨ÓÅÏȼ¶¡¢¹æ»®ºÍÖ´ÐпɲÙ×÷µÄÍøÂ簲ȫ´òË㣬´Ó½ÌÓýºÍÀͶ¯Á¦¡¢±£»¤»ù´¡ÉèÊ©¡¢¹©¸øÁ´°²È«¡¢²âÆÀÍøÂ簲ȫºÍÍÆ½øÒµÎñºÏ×÷¼¸¸ö·½Ãæ½øÐзÖÎö¡£


Ô­ÎÄÁ´½Ó£º

https://www.aspeninstitute.org/publications/a-national-cybersecurity-agenda-for-resilient-digital-infrastructure/