SonicWallÖÒ¸æÀûÓÃÆäVPN²úÆ·ÖÐ0dayµÄ¹¥»÷»î¶¯£»ÌØË¹À­¸æ×´Ç°Ô±¹¤ÇÔÈ¡¹«Ë¾µÄ6ǧ¶à¸ö´úÂëÎļþ

°ä²¼¹¦·ò 2021-01-25
1.SonicWallÖÒ¸æÀûÓÃÆäVPN²úÆ·ÖÐ0dayµÄ¹¥»÷»î¶¯


1.jpg


°²È«³§ÉÌSonicWal°ä²¼´¹Î£Í¨Öª £¬ÖÒ¸æÀûÓÃÆäVPN²úÆ·ÖÐ0dayµÄ¹¥»÷»î¶¯¡£¸Ã·ì϶λÓÚSecure Mobile Access£¨SMA£©VPNÉ豸¼°NetExtender VPN¿Í»§¶ËÖÐ £¬¿É±»ÓÃÀ´¶Ô¹«Ë¾µÄÄÚ²¿ÏµÍ³½øÐÐЭͬ¹¥»÷¡£SonicWallÉÐδ°ä²¼Óйظ÷ì϶µÄ¾ßÌåÐÅÏ¢ £¬µ«Æ¾¾Ý»º½â´ëÊ©ÅÐ¶Ï £¬Æä¿ÉÄÜÊÇÊÇÉí·ÝÑéÖ¤·ì϶ £¬¿É±»ÓÃÀ´Ôڿɹ«¿ª½Ó¼ûµÄÉ豸ÉÏÔ¶³ÌÀûÓá£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/sonicwall-firewall-maker-hacked-using-zero-day-in-its-vpn-device/


2.ÒôÀÖÀûÓÃShazam´æÔÚ2¸öÒþÖÔ·ì϶ £¬Ó°Ïì1ÒÚ¶àÓû§


2.png


ÒôÀÖÀûÓÃShazam´æÔÚ2¸ö·ì϶CVE-2019-8791ºÍCVE-2019-8792 £¬¿É±»ÓÃÀ´»ñÈ¡AndroidºÍiOSÓû§µÄµØÎ» £¬Ó°ÏìÁË1ÒÚ¶à¸öÓû§¡£ShazamÔÚµ¼º½ÖÐʹÓÃÁËÉî²ãÁ´½Ó £¬¶øÕƹÜÔÚWeb viewÖмÓÔØÍøÕ¾µÄÉî²ãÁ´½ÓûÓÐÑéÖ¤²ÎÊý £¬´Ó¶øµ¼ÖÂ±í²¿×ÊÔ´Äܹ»¶ÔÆä½øÐнÚÔì¡£¸Ãweb viewÄܹ»»ñÈ¡Éè±¸ÌØ¶¨µÄÐÅÏ¢ºÍÓû§µÄ¾«È·µØÎ» £¬Òò¶øºÚ¿Í¿ÉÓõ¥¸ö¶ñÒâURLÀ´»ñÈ¡Êܺ¦ÕßµØÎ»¡£Ä¿Ç° £¬¸Ã·ì϶Òѱ»½¨¸´¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/01/location-data-of-more-than-100-million.html


3.ÌØË¹À­¸æ×´Ç°Ô±¹¤ÇÔÈ¡¹«Ë¾µÄ6ǧ¶à¸ö´úÂëÎļþ


3.png


ÌØË¹À­¸æ×´ÆäǰԱ¹¤Alex KhatilovÇÔÈ¡¹«Ë¾µÄ6ǧ¶à¸ö¾ç±¾ºÍ´úÂëÎļþ¡£ÌØË¹À­³Æ¸ÃÔ±¹¤ÔÚÈëÖ°ÈýÌìºó¾ÍÆðÍ·ÇÔÈ¡»úÃÜÎļþ £¬²¢½«Æäת´¢ÖÁÓ×ÎÒ´æ´¢ÕÊ»§¡£½ØÖÁ1ÔÂ6ÈÕ £¬Alex KhatilovÔÚΪÆÚÁ½ÖܵŤ×÷ÖÐ×ܹ²ÇÔÈ¡ÁË6000¶à¸ö¾ç±¾»ò´úÂëÎļþ¡£ÌØË¹À­°µÊ¾±»µÁÊý¾Ý¶ÔÌØË¹À­ºÍ¾ºÕùµÐÊÖÀ´À´Ëµ¶¼¼«ÓмÛÖµ £¬ËüÃÇÄܹ»Ô®ÊÔìäËû¹«Ë¾µÄ¹¤³Ìʦ¶ÔÌØË¹À­µÄÁ÷³Ì½øÐÐÄæÏò¹¤³Ì £¬¶øºóÔڶ̹¦·òÄÚÒÔ¸üÉÙµÄÓöȴ´½¨Ò»¸öÀàËÆµÄϵͳ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bloomberg.com/news/articles/2021-01-23/tesla-claims-engineer-stole-secrets-just-three-days-on-the-job?srnd=technology-vp


4.ºÚ¿Í¹«¿ª½»ÓÑÍøÕ¾MeetMindfulµÄ228ÍòÓû§µÄÊý¾Ý


4.png


ShinyHunters¹«¿ªÁ˽»ÓÑÍøÕ¾MeetMindfulµÄ1.2 GBÊý¾Ý £¬Éæ¼°Ô¼228Íò¸öÓû§¡£Ð¹Â¶Êý¾ÝÔ̺¬Óû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢³ÇÊÓ×¢ÖݺÍÓÊÕþ±àÂëµÄ¾ßÌåÐÅÏ¢¡¢Éí¶Îϸ½Ú¡¢Ô¼»áÆ«ºÃ¡¢»éÒöÇé¿ö¡¢µ®ÉúÈÕÆÚ¡¢Î³¶ÈºÍ¾­¶È¡¢IPµØÖ·¡¢¹þÏ£ÃÜÂë¡¢FacebookÓû§IDºÍFacebookÉí·ÝÑéÖ¤ÁîÅÆµÈ¡£×êÑÐÈËÔ±³ÆÕâЩÊý¾ÝÒѱ»²é¿´ÁË1500´ÎÒÔÉÏ £¬²¢ÇҺܿÉÄÜÒѱ»ÏÂÔØ¡£MeetMindfulÉÐδ¶ÔÕâ´Îй¶ÊÂÎñ×ö³ö»ØÓ¦¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-leaks-data-of-2-28-million-dating-site-users/


5.·¨¹úµÄVienneÔâµ½¹¥»÷ £¬ÍÆËã»úºÍͨѶϵͳ±»·ÛËé


5.png


·¨¹úµÄVienneÓÚ1ÔÂ21ÈÕ£¨ÐÇÆÚËÄ£©Ôâµ½¹¥»÷ £¬µ¼ÖÂÍÆËã»úºÍͨѶϵͳ±»·ÛËé¡£ÀíÊ»áÖ÷ϯAlain Pichon³Æ¹¥»÷²úÉúºó £¬Æä¹Ø¹ØÁËÕû¸öITϵͳ £¬²¢ÇÒËùÓÐÍÆËã»ú¶¼½«ÔÚÖÜÒ»ÖÕ³¡ÔËÐС£´Ë±í £¬¸Ãʡй©Õâ´Î¹¥»÷Ó뼸ÖÜǰLa RochelleÔâµ½µÄ¹¥»÷ÊÇͬÀàÐ굀 £¬ºÚ¿ÍÀûÓò¡¶¾Ï°È¾ÉçÇø¡¢µ±²¿ÃÅÃÅÒÔ¼°Ë½Óª¹«Ë¾µÄϵͳ £¬ÒÔÀÕË÷Êê½ð¡£¸ÃÊ¡²»³ïËãÖ§¸¶ÈκÎÓÃ¶È £¬²¢°µÊ¾ÕâÖÖ¹¥»÷´Ó³¤Ô¶À´¿´²»»á¶ÔÆä²úÉúÈκÎÓ°Ïì¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.francebleu.fr/infos/societe/le-departement-de-la-vienne-victime-d-un-piratage-informatique-1611327525


6.Unit42°ä²¼ÍøÂç¹¥»÷µÄÇ÷Ïò·ÖÎö»ã±¨


6.png


Unit42°ä²¼ÁËÍøÂç¹¥»÷µÄÇ÷Ïò·ÖÎö»ã±¨¡£»ã±¨·¢ÏÖ2020Äê8Ôµ½10Ô £¬É¨Ã跨ʽ»î¶¯ºÍHTTPĿ¼±éÀúÀûÓó¢ÊÔ¼¤Ôö¡£2020ÄêÏļ¾ÔÚÒ°±í×î³£±»ÀûÓõķì϶ÊÇCVE-2012-2311ºÍCVE-2012-1823 £¬µ«Êǵ½ÁËÇï¼¾³öÏÖÁËCVE-2020-17496ºÍCVE-2020-25213µÈеķì϶¡£´Ë±í £¬8ÔÂÖÁ10ÔÂÔÚÒ°·¢ÏÖÁËÎå¸öзì϶vBulletinÔ¶³ÌÖ´ÐдúÂë·ì϶¡¢WordPressÎļþÖÎÀíÆ÷²å¼þÔ¶³ÌÖ´ÐдúÂë·ì϶¡¢Nette´úÂë×¢Èë·ì϶¡¢Artica Web´úÀíSQL×¢Èë·ì϶ºÍOracle WebLogic ServerÔ¶³ÌÖ´ÐдúÂë·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/network-attack-trends-internet-threats/