Apple iCloudÖжÏ36Ó×ʱ£¬Éв»Ã÷ÏÔ¹ÊÕÏÔÒò£»Nintendo 3DS´æÔڿɵ¼ÖÂMiTM¹¥»÷µÄ·ì϶
°ä²¼¹¦·ò 2020-12-28
Apple iCloud·þÎñ³öÏÖ¹ÊÕÏ£¬Ê¹Óû§ÎÞ·¨µÇ¼¸Ã·þÎñ½Ó¼ûÎļþ»òÉèÖÃÐÂÉ豸¡£Õâ´ÎÖжϴÓÃÀ¹ú¶«²¿¹¦·ò12ÔÂ25ÈÕÉÏÎç4:45ÆðÍ·£¬Ö±µ½12ÔÂ26ÈÕÏÂÎç4:35²Å±»½¨¸´£¬Àúʱ36Ó×ʱ¡£ÖÐ¶ÏÆÚ¼ä£¬AppleµÄϵͳ״̬ҳÉϽöÏÔʾ¡°Óû§¿ÉÄÜÓöµ½´Ë·þÎñµÄÎÊÌ⡱µÄÌáÐÑ£¬Ã»Óиü¶àÓÐ¹ØÆäÖжϵÄÐÅÏ¢¡£Ä¿Ç°£¬Apple¹«Ë¾Ã»ÓÐÌṩÈκÎÒÔÕÏÔÒò¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/apple/apple-icloud-outage-prevents-device-activations-access-to-data/
2.ºÚ¿ÍÏúÊÛÓÎÏ·¹«Ë¾Koei TecmoµÄÊý¾ÝºÍ½Ó¼ûȨ

ºÚ¿ÍÔÚ°µÍøÏúÊÛÓÎÏ·¹«Ë¾Koei TecmoµÄÊý¾ÝºÍ½Ó¼ûȨ¡£12ÔÂ20ÈÕ£¬ºÚ¿ÍÐû³ÆÆäÓÚ12ÔÂ18ÈÕÀûÓÃÓã²æÊ½´¹µö¹¥»÷ÈëÇÖÁËkoeitecmoeurope.comÍøÕ¾£¬ÇÔÈ¡ÁËÂÛ̳Êý¾Ý¿â²¢Ö²ÈëÁËWeb ShellÒÔ±ãºóÐø½Ó¼û¡£Ö®ºóºÚ¿ÍÔÚ°µÍøÉÏÒÔ0.05±ÈÌØ±Ò£¨Ô¼ºÏ1300ÃÀÔª£©µÄ¼ÛÖµÏúÊÛÊý¾Ý¿â£¬²¢ÒÔ0.25£¨Ô¼ºÏ6500ÃÀÔª£©µÄ¼ÛÖµÏúÊÛWeb shell½Ó¼ûȨÏÞ¡£¸Ã±»µÁÊý¾Ý¿âÔ̺¬ÁË65000¸öÓû§µÄÊý¾Ý£¬Ô̺¬µç×ÓÓʼþµØÖ·¡¢IPµØÖ·¡¢¹þÏ£ÃÜÂë¡¢Óû§Ãû¡¢µ®ÉúÈÕÆÚºÍ¹ú¶È¡£Ä¿Ç°£¬Koei TecmoÒѹعØÃÀ¹úºÍÅ·ÖÞµÄÍøÕ¾£¬ÒÔÔ¤·À¿ÉÄܲúÉúµÄ¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/koei-tecmo-discloses-data-breach-after-hacker-leaks-stolen-data/
3.Nintendo 3DS´æÔڿɵ¼ÖÂMiTM¹¥»÷µÄ·ì϶

×êÑÐÈËÔ±·¢ÏÖNintendo 3DS´æÔÚÑϳÁµÄ·ì϶£¬¿ÉÄܵ¼ÖÂMiTM¹¥»÷¡£¸Ã·ì϶λÓÚNintendo 3DS¶ÔÊý×ÖÖ¤ÊéµÄ´¦ÖÃÖУ¬ ³ÉÁ¢SSL/TLSÏνÓʱSSLϵͳģ¿éδÕýÈ·ÑéÖ¤x509Ö¤Ê飬´Ó¶øÔÊÐí¹¥»÷ÕßαÔìαÔìÖ¤ÊéÀ´Ö´ÐÐMitM¹¥»÷£¬»òºýŪÊÜÐÅÀµµÄ·þÎñÆ÷£¬ÀýÈçºýŪeShop·þÎñÆ÷²¢ÇÔÈ¡Óû§ÐÅÏ¢£¬ºýŪÓëÓÎÏ··þÎñÆ÷µÄÏνӵȡ£¸Ã·ì϶ӰÏìÁËËùÓй̼þ°æ±¾Îª11.13»ò¸üµÍµÄNintendo 3DS½ÚÔį̀£¬Ä¿Ç°Òѱ»½¨¸´¡£
ÔÎÄÁ´½Ó£º
https://latesthackingnews.com/2020/12/27/critical-vulnerability-in-nintendo-3ds-console-could-allow-mitm-attacks/
4.ËÕ¸ñÀ¼»·±£¾ÖÊܵ½¹¥»÷£¬ÁªÏµÖÐÐĵȲ¿ÃÅÊܵ½Ó°Ïì

ËÕ¸ñÀ¼»·¾³±£»¤¾Ö£¨Sepa£©Ôâµ½¹¥»÷£¬ÁªÏµÖÐÐĵȲ¿ÃÅÊܵ½Ó°Ïì¡£¸Ã¹«Ë¾CEO David Pirie³ÆÔÚ°²È»Ò¹µÄÎçÒ¹£¬SepaµÄϵͳÔâ·êÁ˳Á´óÇÒ³ÖÐøµÄÍøÂç¹¥»÷¡£¹¥»÷Ó°ÏìÁ˸ù«Ë¾µÄÁªÏµÖÐÐÄ¡¢ÄÚ²¿ÏµÍ³¡¢Á÷³ÌºÍÄÚ²¿Í¨Ñ¶¡£µ«ÊÇÆäÖ÷Ìâ¼à¿ØÏµÍ³ºÍ¾¯±¨·þÎñûÓÐÊܵ½Ì«´óµÄÓ°Ï졣Ŀǰ£¬SepaÕýÓëËÕ¸ñÀ¼µ±¾ÖºÏ×÷£¬ÒÔµ÷²é²¢½â¾öÕâ´Î¹¥»÷ÊÂÎñ¡£
ÔÎÄÁ´½Ó£º
https://news.stv.tv/scotland/scottish-environment-protection-agency-targeted-in-cyberattack?top
5.Rapid7°ä²¼2020Äê¶ÈÍøÂç¹¥»÷µÄÌ¬ÊÆ»ã±¨

Rapid7°ä²¼ÁË2020Äê¶ÈÍøÂç¹¥»÷µÄÌ¬ÊÆ»ã±¨¡£¸Ã»ã±¨ÖØÒª·ÖÎöÁ˶ñÒâµÄMicrosoft SQL Server¹¥»÷¡¢Î¢ÈíÔ¶³Ì×ÀÃæºÍ̸(RDP)¹¥»÷ºÍ΢ÈíSMB¹¥»÷¡£»ã±¨·¢ÏÖ£¬´ó¹æÄ£µÄ½©Ê¬ÍøÂçÔÚ½ñÄêÏÄÌì֮ǰºöÈ»Òþû£¬¶øMS SQL serverÍ´´¦ºÍ²éÎʹ¥»÷´ïµ½ÁËÒÔÍùµÄ¾ùÔÈˮƽ¡£´Ë±í£¬Õë¶ÔRDPµÄÀÕË÷Èí¼þ¹¥»÷ÊÇÒ»¸ö´óÎÊÌ⣬ºÜ¶à¹¥»÷Õß¶Ô×¼ÁË×ÊÔ´²»¼°µÄÒ½ÁÆÐÐÒµ¡¢½ÌÓýºÍµ±¾Ö×éÖ¯¡£Õë¶ÔMicrosoft SMB·þÎñÆ÷µÄ×¢ÈëEternalBlueµÄ¹¥»÷Ò²ÓÐËùÔö³¤¡£
ÔÎÄÁ´½Ó£º
https://blog.rapid7.com/2020/12/25/rapid7-labs-2020-naughty-list-summary-report-to-santa/
6.Aspen°ä²¼ÓйØÊý×Ö»ù´¡ÉèÊ©µÄ·ÖÎö»ã±¨

Aspen°ä²¼ÁËÓйØÊý×Ö»ù´¡ÉèÊ©µÄ·ÖÎö»ã±¨¡£2020Äê£¬ÍøÂ簲ȫÒѳÉΪÿ¸öÐÐÒµÒÔ¼°ÃÀ¹úµ±¾ÖµÄÄÑÌ⣬¸Ã»ã±¨Ö¸³öÁËÐÂÈÎ×Üͳµ±¾ÖÓкܶà»úÓöÄܹ»Ôö³¤ÍøÂ簲ȫ¹¤×÷²¢Ìá¸ßÈËÃǵÄÒâʶ£¬ÒÔ´´½¨¸ü¾ßµ¯ÐÔµÄÊý×Ö»ù´¡¼Ü¹¹¡£¸Ã»ã±¨Ö¼ÔÚÔ®ÊÖ¾ö²ßÕßÈ·¶¨ÓÅÏȼ¶¡¢¹æ»®ºÍÖ´ÐпɲÙ×÷µÄÍøÂ簲ȫ´òË㣬´Ó½ÌÓýºÍÀͶ¯Á¦¡¢±£»¤»ù´¡ÉèÊ©¡¢¹©¸øÁ´°²È«¡¢²âÆÀÍøÂ簲ȫºÍÍÆ½øÒµÎñºÏ×÷¼¸¸ö·½Ãæ½øÐзÖÎö¡£
ÔÎÄÁ´½Ó£º
https://www.aspeninstitute.org/publications/a-national-cybersecurity-agenda-for-resilient-digital-infrastructure/


¾©¹«Íø°²±¸11010802024551ºÅ