Socialarksй¶400GBÊý¾Ý£¬Ó°ÏìÈ«Çò2ÒÚ¶àÓû§£»Î¢Èí°ä²¼1Ô·ݰ²È«¸üУ¬×ܼƽ¨¸´83¸ö·ì϶
°ä²¼¹¦·ò 2021-01-13
°²È«¹«Ë¾Safety Detectives·¢ÏÖ£¬Öйú²Ý´´¹«Ë¾Socialarks£¨±¿ÄñÉç½»£©Ð¹Â¶ÁË400GBÊý¾Ý¡£Õâ´ÎÊý¾Ýй¶ÊÇÓÉÓÚElasticSearchÊý¾Ý¿âÉèÖÃÃýÎó£¬Ð¹Â¶ÁË×ܼÆ408GB£¬³¬¹ý3.18ÒÚÌõÓû§¼Í¼£¬Éæ¼°µ½11651162¸öInstagramÓû§¡¢66117839¸öÁìÓ¢Óû§ºÍ81551567¸öFacebookÓû§¡£ÖµÍ×ÌùÐĵÄÊÇ£¬SocialarksÔÚ2020Äê8ÔÂÒ²²úÉúÁËÀàËÆµÄÊÂÎñ£¬Ð¹Â¶ÁË1.5ÒÚ¸öÓû§µÄÓ×ÎÒÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://www.safetydetectives.com/blog/socialarks-leak-report/
2.ÃÀ¹úUbiquitiÊý¾Ýй¶£¬½¨ÒéÓû§Åú¸ÄÃÜÂë

ÃÀ¹úÍøÂçÉ豸ÉÌUbiquitiÊý¾Ýй¶£¬½¨ÒéÓû§Åú¸ÄÃÜÂë²¢ÆôÓÃ2FA¡£¸Ã¹«Ë¾·¢ÏÖÓɵÚÈý·½ÔÆÌṩÉÌÍйܵÄijЩϵͳÔâµ½ÁËδ¾ÊÚȨµÄ½Ó¼û£¬¿ÉÄÜй¶ÁËÆäWebÃÅ»§ÍøÕ¾account.ui.comÉϵÄÓû§ÓйØÐÅÏ¢£¬ÀýÈçÓû§Ãû³Æ¡¢µç×ÓÓʼþµØÖ·¡¢¼ÓÑÎÃÜÂëºÍ¹þÏ£ÃÜÂ룬ÒÔ¼°²¿ÃÅÓû§µÄ¼ÒÍ¥µØÖ·ºÍµç»°ºÅÂëµÈ¡£Ubiquiti°µÊ¾Éв»Ã÷ÏÔй¶µÄ¾ßÌåÊý¾ÝÀàÐÍ£¬Ò²Ã»ÓÐÌṩÕâ´ÎÊÂÎñµÄ¾ßÌåÐÅÏ¢ºÍÊÜÓ°ÏìÓû§µÄÊýÁ¿¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/113296/data-breach/ubiquiti-discloses-data-breach.html
3.΢Èí°ä²¼1Ô·ݰ²È«¸üУ¬×ܼƽ¨¸´83¸ö·ì϶

΢Èí°ä²¼2021Äê1Ô·ݵݲȫ¸üУ¬×ܼƽ¨¸´83¸ö·ì϶¡£Õâ´Î½¨¸´µÄ×îΪÑϳÁµÄ·ì϶ΪMicrosoft DefenderÖеÄÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVEΪ202-1647£©¡¢Microsoft DTV-DVDÊÓÆµ½âÂëÆ÷Ô¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2021-1668£©¡¢Edge£¨»ùÓÚHTML£©µÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-1705£©¡¢GDI +Ô¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2021-1665£©¡¢HEVCÊÓÆÂ·©Õ¹Ô¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2021-1643£©ºÍÔ¶³Ì¹ý³ÌŲÓÃÔËÐÐʱԶ³ÌÖ´ÐдúÂë·ì϶£¨CVE-2021-1666£©µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-january-2021-patch-tuesday-fixes-83-flaws-1-zero-day/
4.CrowdStrikeÅû¶SolarWinds¹¥»÷ÖеĵÚÈýÖÖ¶ñÒâÈí¼þ

°²È«¹«Ë¾CrowdStrikeÅû¶ÁËSolarWinds¹©¸øÁ´¹¥»÷ÖдæÔÚµÚÈýÖÖ¶ñÒâÈí¼þSunspot¡£CrowdStrike°µÊ¾Ö»¹ÜSunspotÊÇ×îб»·¢Ïֵ쬵«ÏÖʵÉÏÊǺڿÍʹÓõĵÚÒ»¸ö¶ñÒâÈí¼þ£¬ÓÚ2019Äê9Ô±»²¿Êð¡£SunspotΨһµÄÖ÷ÕÅÊǼල¹¹½¨·þÎñÆ÷£¬»ñÈ¡±àÒëOrionµÄ¹¹½¨ºÅÁî¡£Ò»µ©¼ì²âµ½¹¹½¨ºÅÁÆä¾Í»áʹÓüÓÔØÁËSunburst¶ñÒâÈí¼þµÄÎļþÀ´´úÌæOrionÀûÓÃÄÚµÄÔ´´úÂëÎļþ£¬À´×°ÖÃSunburst¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/third-malware-strain-discovered-in-solarwinds-supply-chain-attack/
5.Bitdefender°ä²¼Ãâ·ÑµÄDarkSideÀÕË÷Èí¼þ½âÃÜÆ÷

ÂÞÂíÄáÑǵÄÍøÂ簲ȫ¹«Ë¾Bitdefender°ä²¼ÁËÃâ·ÑµÄDarkSideÀÕË÷Èí¼þ½âÃÜÆ÷¡£DarkSideÀÕË÷Èí¼þ×Ô2020Äê8ÔÂÆðÍ·»îÔ¾£¬Êê½ðÁìÓò´Ó20ÍòÃÀÔªµ½200ÍòÃÀÔª²»µÈ£¬ÒѾ»ñµÃÁËÊý°ÙÍòÃÀÔªµÄÀûÈ󡣸ýâÃÜÆ÷½«×Ô¶¯½âÃÜËüÔÚÍÆËã»úÉÏɨÃèµ½µÄËùÓмÓÃÜÎĵµ£¬ÊµÏÖºó»¹»áÌáÐÑÓû§±¸·ÝÊý¾Ý¡£Bitdefender°µÊ¾ÔÚ¸´ÔÎļþºó£¬Äܹ»Í¨¹ýËÑË÷À©´óÃûµÄ·½Ê½À´ÅúÁ¿É¾³ýÒѱ»¼ÓÃܵÄÎļþ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/darkside-ransomware-decryptor-recovers-victims-files-for-free/
6.NSA°ä²¼2020ÄêÍøÂ簲ȫµÄÄê¶È»ØÊ׻㱨

ÃÀ¹ú¹ú¶È°²È«¾Ö£¨NSA£©°ä²¼ÁË2020ÄêÍøÂ簲ȫµÄÄê¶È»ØÊ׻㱨¡£»ã±¨Ö¸³ö£¬NSA 2020ÄêÔ®ÊÖ¹ú·À²¿ÏòÔ¶³Ì¹¤×÷¹ý¶É£¬ÎªÔ¼Äª100000ÃûÓû§ÌṩÁËÔ¶³Ì°²È«¹¤×÷µÄ½â¾ö¹æ»®£¬»¹²Î¼ÓÁËÖ¼Ôڼӿ쿪·¢COVID-19ÒßÃçµÄOWSÐж¯¡£2020Äê°ä²¼µÄ³ÁÒªµý±¨Ô̺¬ÓйØWindows 10µÄ·ì϶ºÍDrovorub¶ñÒâÈí¼þµÄ¾ßÌåÐÅÏ¢¡¢Óë¶íÂÞ˹ÓйصÄɳ³æÍÅ»ïÕë¶ÔEximÓʼþ·þÎñÆ÷µÄIOCºÍÀÄÓÃÔÚweb·þÎñÆ÷ÉÏ×°ÖÃweb shellµÄ¶ñÒâÈí¼þµÈ¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/nsa-publishes-cybersecurity-year-review-report


¾©¹«Íø°²±¸11010802024551ºÅ