Cyble·¢ÏÖºÚ¿ÍÔÚ°µÍøÏúÊÛÁ½ÒÚ¶àÖйú¹«ÃñµÄÐÅÏ¢ £»×êÑÐÈËÔ±Åû¶Zend FrameworkÖÐÔ¶³Ì´úÂëÖ´Ðзì϶

°ä²¼¹¦·ò 2021-01-05
1.Cyble·¢ÏÖºÚ¿ÍÔÚ°µÍøÏúÊÛÁ½ÒÚ¶àÖйú¹«ÃñµÄÐÅÏ¢


1.jpg


CybleµÄ×êÑÐÍŶӷ¢ÏÖºÚ¿ÍÔÚ°µÍøÏúÊÛÁ½ÒÚ¶àÖйú¹«ÃñµÄÐÅÏ¢¡£Õâ´Îй¶µÄÊý¾ÝÀ´×Ô¶à¸öƽ̨ºÍÈí¼þ£¬ÆäÖÐÔ̺¬730Íòºþ±±Ê¡¾£ÖÝÊй«°²ÏؾÓÃñµÄÉí·ÝÖ¤ºÅ¡¢ÐÔ±ð¡¢ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢ÊÖ»ú¡¢µØÖ·ºÍ´úÂëµÈÐÅÏ¢£¬4180Íò¸ö΢²©Óû§µÄÕ˺źÍÏàÓ¦µÄÊÖ»úºÅÂ룬ÒÔ¼°1.92ÒÚQQÓû§µÄÕ˺źÍÏàÓ¦µÄÊÖ»úºÅÂë¡£Õâ´Îй¶µÄÓëÖйú¹«ÃñÓйصļͼ×ÜÊý³¬¹ý2ÒÚ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/112966/deep-web/chinese-citizens-data-darkweb.html


2.д¹µö»î¶¯ÒÔÕÊ»§ÊÜÏÞ¶ÌÐÅΪµö¶üÇÔÈ¡PayPalÍ´´¦


2.jpg


еĴ¹µö»î¶¯ÒÔÕÊ»§ÊÜÏÞ¶ÌÐÅΪµö¶üÇÔÈ¡PayPalµÇ¼ʹ´¦¡£Õâ´Î¹¥»÷»î¶¯¼ÙÒâPayPal·¢ËÍÚ¿Æ­¶ÌÐÅ£¬Ðû³ÆÓû§µÄÕÊ»§Êܵ½ÓÀÔ¶ÏÞ¶È£¬Ðèµã»÷Á´½ÓÀ´ÑéÖ¤ÕÊ»§¡£¸ÃÁ´½Ó½«Óû§³Á¶¨Ïòµ½´¹µöÒ³Ãæ£¬ÒÔÇÔÈ¡Óû§µÇ¼ƾ֤¡£´Ë±í£¬ÔÚÓû§ÊäÈëµÇ¼ƾ֤ºó¸ÃÍøÕ¾»¹»á½øÒ»²½ÍøÂç¸ü¶à¾ßÌåÐÅÏ¢£¬ÀýÈçÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·ºÍÒøÐоßÌåÐÅÏ¢µÈµÈ£¬ÒÔÓÃÓÚ½«À´µÄÉí·ÝµÁÓù¥»÷£¬Õë¶ÔÐÔµÄÓã²æÊ½´¹µö¹¥»÷»ò½Ó¼ûÓû§µÄÆäËûÕÊ»§¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/beware-paypal-phishing-texts-state-your-account-is-limited/


3.Ò½ÁÆ»ú¹¹GenRxÔâµ½ÀÕË÷¹¥»÷£¬»¼Õß½¡È«Êý¾Ýй¶


3.jpg


ÃÀ¹úµÄÒ½ÁÆ»ú¹¹GenRx PharmacyÔâµ½ÀÕË÷¹¥»÷£¬»¼Õß½¡È«Êý¾Ýй¶¡£¹¥»÷²úÉúÔÚ2020Äê9ÔÂ27ÈÕ£¬ºÚ¿ÍÌáÒéÀÕË÷Èí¼þ¹¥»÷¡£¸Ã¹«Ë¾ÓÚµÚ¶þÌ죨9ÔÂ28ÈÕ£©·¢ÏÖÁ˸û²¢×èÖ¹ÁËºÚ¿Í¶ÔÆäϵͳµÄ½Ó¼û¡£¸Ã¹«Ë¾³ÆÕâ´ÎÍøÂç¹¥»÷²¢Î´³É¹¦£¬ÆäÒµÎñ²¢Î´Êܵ½Ó°Ï죬µ«ºÚ¿ÍÒѾ­½Ó¼û²¢É¾³ýÁËijЩ»¼ÕßÊý¾Ý£¬Ô̺¬»¼ÕßID¡¢ÂòÂôID¡¢ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢ÐԱ𡢹ýÃô¡¢ÓÃÒ©Çåµ¥¡¢½¡È«´òËãÐÅÏ¢ºÍ´¦·½ÐÅÏ¢µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2021/01/04/genrx-pharmacy-ransomware-attack-resulted-in-data-breach/


4.ÓÊÂÖ¹«Ë¾AIDAÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Í¨ÕÛ·þÎñÁÙʱÖжÏ


4.jpg


µÂ¹úÓÊÂÖ¹«Ë¾AIDAÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Í¨ÕÛ·þÎñÁÙʱÖжÏ¡£AIDA³ÆÆäµç»°ÏµÍ³ºÍµç×ÓÓʼþϵͳÖжÏ£¬±»ÆÈÈ¡µÞ2020Äê12ÔÂ26ÈÕ´ïµ½µÄÓÊÂÖµÄÐгÌ¡£Ö»¹ÜAIDA²¢Î´Ð¹Â©ºÃ¶àϸ½Ú£¬µ«µÂ¹úýÌ屨·ÆäÔâµ½ÁËÍøÂç¹¥»÷£¬Ò»Ð©´¬Éϵij˿ÍÒ²°µÊ¾´¬²°Óë×ܲ¿Ö®¼äµÄͨѶÖжÏ¡£Õâ´Î¹¥»÷ÊÂÎñ»¹Ó°ÏìÁËCosta CruiseºÍCarnival Maritime¡£´Ë±í£¬Databreaches.net²Â²âAIDAÔâµ½ÁËDoppelpaymerÀÕË÷Èí¼þ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2021/01/03/aida-ships-face-service-disruptions-ransomware-attack-suspected/


5.×êÑÐÈËÔ±Åû¶Zend FrameworkÖÐÔ¶³Ì´úÂëÖ´Ðзì϶


5.jpg


×êÑÐÈËÔ±Ling YizhouÅû¶Zend Framework3.0.0ÖеÄÒ»¸ö²»³ÉÐŵķ´ÐòÁл¯·ì϶£¨CVE-2021-3007£©¡£Zend FrameworkµÄ×°ÖÃÁ¿³¬¹ý5.7ÒڴΣ¬±»ÓÃÀ´¹¹½¨ÃæÏò¶ÔÏóµÄwebÀûÓ÷¨Ê½¡£¸Ã·ì϶´æÔÚÓÚStreamÀàµÄÎö¹¹º¯ÊýÖУ¬¿É±»ÓÃÀ´¶ÔÒ×Êܹ¥»÷µÄPHPÀûÓýøÐÐÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷¡£´Ë±í£¬ZendÓÚ2020Äê1ÔÂǨáãµ½LaminasÏîÄ¿£¬ÔÚijЩ°æ±¾µÄLaminasÖÐÒ²´æÔÚÉÏÊöStream.phpÀ࣬Òò¶ø²¿ÃÅʹÓÃLaminas¹¹½¨µÄÀûÓÃÒ²¿ÉÄÜ»áÊܵ½Ó°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/zend-framework-remote-code-execution-vulnerability-revealed/


6.IDG°ä²¼2020Ä갲ȫ³Áµã×êÑеķÖÎö»ã±¨


6.jpg


IDG°ä²¼ÁË2020Ä갲ȫ³Áµã×êÑеķÖÎö»ã±¨£¬Ö¼ÔÚ¸üºÃµØÏàʶ×éÖ¯´Ë¿ÌºÍÀ´Äê¹Ø×¢µÄ¸÷ÀలȫÏîÄ¿¡£¸Ã»ã±¨Ö¸³ö£¬³¬¹ýÈý·ÖÖ®Ò»£¨37£¥£©µÄÈËÒÔΪ£¬COVID-19ºÍÀͶ¯Á¦¸Ä¹ÛµÈÒâ±íÕýÆÈʹËûÃǽ«³Áµã´ÓÕ½Êõ°²È«¹¤×÷ÖÐ×ªÒÆ³öÀ´ £»Èý·ÖÖ®Ò»µÄ¾ö²ßÕß°µÊ¾£¬ËûÃÇ2021Ä갲ȫԤË㽫¸ßÓÚCOVID-19֮ǰµÄÔ¤Ë㣬41£¥µÄÈ˰µÊ¾×ÜÌ尲ȫԤË㽫ÔÚ½«À´12¸öÔÂÄÚÔö³¤ £»´óÎÞÊý£¨87£¥£©ÊÜ·ÃÕßÃ÷È·ÔÚ´ÓǰһÄêÖÐÔì³É°²È«ÊÂÎñµÄÔ­Òò¡£


Ô­ÎÄÁ´½Ó£º

https://www.idg.com/tools-for-marketers/2020-security-priorities-study/