MicrosoftµÄHaloÓÎÏ·¿ª·¢ÍøÕ¾Ôâµ½ÒÀÀµ»ìºÏ¹¥»÷£»½áºÏ¹ú¹ú¼ÊµçÐÅͬÃ˰䲼2020ÄêÈ«ÇòÍøÂ簲ȫָÊý

°ä²¼¹¦·ò 2021-07-01

1.MicrosoftµÄHaloÓÎÏ·¿ª·¢ÍøÕ¾Ôâµ½ÒÀÀµ»ìºÏ¹¥»÷


1.jpg


×êÑÐÈËÔ±·¢ÏÖMicrosoftµÄHaloÓÎÏ·¿ª·¢ÍøÕ¾Ôâµ½ÒÀÀµ¹ØÏµ»ìºÏ¹¥»÷¡£Ricardo Iramar dos SantosÔÚÉó¼Æ¿ªÔ´°üSymphonyElectronʱ·¢ÏÖÁ˸ðüʹÓõÄÒ»¸ö¿ÉÒɵÄÒÀÀµÏîswift-search£¬²¢²»´æÔÚÓÚ¹«¹²npmjs.com×¢²á±íÖС£×êÑÐÈËÔ±½«°ü·¢Ë͵½npm×¢²á±íºóÊÕµ½ÁËÀ´×Ô΢Èí·þÎñÆ÷µÄping-back£¬½Ó¼ûhttps://51.141.173.203ʱ£¬SSLÖ¤ÊéµÄCN×Ö¶ÎÖ¸Ïò*.test.svc.halowaypoint.com£¬Õâ½øÒ»²½Ö¤ÁËȻ΢Èí·þÎñÆ÷Ôâµ½ÁËÒÀÀµ»ìºÏ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsofts-halo-dev-site-breached-using-dependency-hijacking/


2.·¨Âɲ¿ÃŲé»ñË«³Á¼ÓÃÜ·þÎñDoubleVPNµÄ·þÎñÆ÷ºÍÈÕÖ¾


2.jpg


2021Äê6ÔÂ29ÈÕ£¬¶à¹ú·¨Âɲ¿Ãųɹ¦²é»ñÁ˶íÂÞ˹DoubleVPNµÄ·þÎñÆ÷¡£DoubleVPN¿É¶ÔÊý¾Ý½øÐÐË«³Á¡¢Èý³ÁÉõÖÁËijÁ¼ÓÃÜ£¬Í¨³£±»¹¥»÷ÕßÓÃÀ´ÔÚÖ´ÐжñÒâ»î¶¯Ê±Èƹý¼ì²â¡£Õâ´ÎÐж¯ÊÇÓɵ¹úBKA¡¢ºÉÀ¼ÕþÖξ֡¢Áª¹úµ÷²é¾Ö¡¢Ó¢¹ú¹ú¶È·¸×ï¾Ö¡¢ÃÀ¹úÌØÇھֺͼÓÄôó»Ê¼ÒÆï¾¯µÈ×éÖ¯½áºÏ·¢ÆðµÄ£¬³É¹¦»ñµÃÁËDoubleVPN·þÎñÆ÷µÄ½Ó¼ûȨ£¬²¢²é»ñÁËÆäËùÓпͻ§µÄÓ×ÎÒÐÅÏ¢¡¢ÈÕÖ¾ºÍͳ¼ÆÊý¾Ý¡£Å·ÖÞÐ̾¯×éÖ¯°µÊ¾ÎÞ·¨·ÖÏí¸ü¶àϸ½Ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/doublevpn-servers-logs-and-account-info-seized-by-law-enforcement/


3.Facebook¸æ×´4¸öÔ½ÄϺڿͽٳÔìä¶à¸öÓû§µÄÕË»§


3.jpg


Facebook¸æ×´ÁË4¸öÔ½ÄϺڿͽٳÔìäÓû§ÕË»§¡£Facebook³ÆÕâÕâЩºÚ¿ÍÀûÓûỰ͵ÇÔ»òcookie͵ÇÔ¼¼Êõ½Ó¼û¶à¸ö¸æ°×ºÍÓªÏú¹«Ë¾Ô±¹¤µÄFacebookÕÊ»§£¬²¢Ê¹Óñ»ºÚµÄÕÊ»§Ðû´«ÃûΪAd Manager for FacebookµÄ¶ñÒâAndroidÀûÓ᣸ÃÀûÓ÷¨Ê½ÍйÜÔÚ¹Ù·½Google PlayÉ̵êÖУ¬ÔÚ2020Äê12ÔÂÖÁ2021Äê5ÔÂÒѱ»×°ÖÃÁË10000ÂŴΡ£Facebookͬʱ»¹¸æ×´Á˼ÓÀû¸£ÄáÑǹ«Ë¾N&J USA Incorporated£¬¸Ã¹«Ë¾ÔÚFacebookÉÏͶ·ÅÁËÓйطþ×°¡¢Íó±íºÍÍæ¾ßµÄÚ¿Æ­¸æ°×¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/facebook-sues-four-vietnamese-nationals-for-account-hijacks/


4.×êÑÐÈËÔ±Åû¶Google Compute Engine佨¸´µÄ·ì϶


4.jpg


×êÑÐÈËÔ±Åû¶ÁËÒ»¸öÓ°ÏìGoogle Compute EngineµÄ佨¸´µÄ·ì϶¡£Google Compute Engine(GCE)ÊÇGoogle Cloud PlatformµÄ»ù´¡ÉèÊ©¼´·þÎñ(IaaS) ×é¼þ£¬Ê¹Óû§¿ÉÄܰ´Ðè´´½¨ºÍÆô¶¯Ðé¹¹»ú (VM)¡£¸Ã·ì϶ÊÇÓÉÓÚISC DHCP¿Í»§¶ËʹÓÃÈõµÄÎ±Ëæ»úÊýµÄµ¼ÖµÄ£¬¹¥»÷ÕßÀûÓÃÕâ¸ö·ì϶£¬Äܹ»Í¨¹ýSSHÊÚÓè×Ô¼º½Ó¼ûȨÏÞ£¬¶øºóÒÔrootÓû§Éí·ÝµÇ¼¡£¹È¸èÓÚ2020Äê9ÔÂ27ÈÕ»ñϤ¸ÃÎÊÌ⣬µ«ÖÁ½ñÉÐδ°ä²¼²¹¶¡¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/06/unpatched-virtual-machine-takeover-bug.html


5.ÈÕ±¾¹«Ë¾Airport Refueling³ÆÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷


5.jpg


ÈÕ±¾Îª·É»úÌṩ¼ÓÓÍ·þÎñµÄJapan Airport Refueling³ÆÆäÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷¡£¹¥»÷²úÉúÔÚ2021Äê6ÔÂ21ÈÕÁ賿£¬¹«Ë¾ÄÚ²¿µÄÍøÂçϵͳ²úÉú¹ÊÕÏ¡£µ÷²é֤ʵÊÇÀÕË÷Èí¼þ¹¥»÷£¬¸Ã¹«Ë¾ÊÕµ½ÏàʼûÜ·þÎñÆ÷Êý¾ÝµÄÊê½ðÒªÇ󣬵«ËƺõûÓÐÈκÎÊý¾Ý±»Ð¹Â¶¡£¸Ã¹«Ë¾³Æ£¬ÆäÔÚÓ뾯·½ºÏ×÷¶Ô´ËÊ·¢Õ¹µ÷²é£¬²¢ÇÒÕâ´Î¹¥»÷²¢Î´Ó°ÏìÆä¼ÓÓ͹¤×÷ºÍÆäËûÒµÎñ¡£Ä¿Ç°ÉÐÎÞÓйØÀÕË÷Èí¼þÀàÐͺÍÊÜÓ°ÏìµÄÊý¾ÝÀàÐ͵ľßÌåÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/jp-japan-airport-refueling-co-discloses-ransomware-incident-refueling-work-not-impacted/


6.½áºÏ¹ú¹ú¼ÊµçÐÅͬÃ˰䲼2020ÄêÈ«ÇòÍøÂ簲ȫָÊý


6.jpg


½áºÏ¹ú¹ú¼ÊµçÐÅͬÃË (ITU) °ä²¼ÁË2020ÄêÈ«ÇòÍøÂ簲ȫָÊý(GCI)¡£GCIÊÇÒ»¸öÖµµÃÐÅÈεIJο¼£¬ËüºâÁ¿ÁËÁйúÔÚÈ«Çò²ãÃæÉ϶ÔÍøÂ簲ȫµÄͶÈë£¬Éæ¼°ºÜ¶àÐÐÒµºÍ²¿ÃÅ¡£¸ÃÖ¸ÊýÆÀ¹ÀÁË5¸ö·½Ãæ:˾·¨´ëÊ©¡¢¼¼Êõ´ëÊ©¡¢×éÖ¯´ëÊ©¡¢ÄÜÁ¦·¢Õ¹ºÍºÏ×÷£¬¶øºó»ã×ܵóöÒ»¸ö×ۺϷÖÊý¡£»ã±¨Ö¸³ö£¬2020Äê¸ÃÖ¸ÊýµÄÖÐλÊý±È2018Äê¸ß9.5%£¬ÆäÖÐÃÀ¹úÅÅÃûµÚÒ»£¬Ó¢¹úÓëÉ³ÌØ°¢À­²®²¢Áеڶþ¡£


Ô­ÎÄÁ´½Ó£º

https://www.itu.int/en/ITU-D/Cybersecurity/Pages/global-cybersecurity-index.aspx