CNNIC°ä²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂç·¢Õ¹Çé¿öͳ¼Æ»ã±¨¡·£ºDeFiƽ̨Cream FinanceÔâµ½¹¥»÷

°ä²¼¹¦·ò 2021-09-02

CNNIC°ä²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂç·¢Õ¹Çé¿öͳ¼Æ»ã±¨¡·


CNNIC°ä²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂç·¢Õ¹Çé¿öͳ¼Æ»ã±¨¡·.jpg


Öйú»¥ÁªÍøÂçÐÅÏ¢ÖÐÐÄ£¨CNNIC£©ÓÚ8ÔÂ27ÈÕÔÚ¾©°ä²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂç·¢Õ¹Çé¿öͳ¼Æ»ã±¨¡·¡£»ã±¨ÏÔʾ£¬½ØÖÁ½ñÄê6Ô£¬ÖйúÍøÃñ¹æÄ£´ï10.11ÒÚ£¬½Ï2020Äê12ÔÂÔö³¤2175Íò£¬»¥ÁªÍø±é¼°ÂÊ´ï71.6%£»»¥ÁªÍø»ù´¡×ÊÔ´¼Ó¿ì½¨É裬½ØÖÁ6Ô£¬ÖйúIPv6µØÖ·ÊýÁ¿´ï62023¿é/32£»Öйú´åÂäÍøÃñ¹æÄ£Îª2.97ÒÚ£¬´åÂ䵨Óò»¥ÁªÍø±é¼°ÂÊΪ59.2%£¬½Ï2020Äê12Ô£¬³ÇÏ绥ÁªÍø±é¼°Âʲî¾àËõÓ×4.8%¡£


Ô­ÎÄÁ´½Ó£º

http://finance.people.com.cn/n1/2021/0828/c1004-32210949.html


Unit42°ä²¼MiraiÔÚÒ°ÀûÓÃWebSVNÖкÅÁî×¢Èë·ì϶µÄ»ã±¨


Unit42°ä²¼MiraiÔÚÒ°ÀûÓÃWebSVNÖкÅÁî×¢Èë·ì϶µÄ»ã±¨.jpg


Unit42ÔÚ8ÔÂ30ÈÕ°ä²¼ÁËÓйØMiraiµÄбäÌåÔÚÒ°ÀûÓÃWebSVNÖкÅÁî×¢Èë·ì϶µÄ·ÖÎö»ã±¨¡£¸Ã·ì϶׷×ÙΪCVE-2021-32305£¬ÓÚ2021Äê5Ô±»·¢ÏÖ²¢½¨¸´¡£ÔÚÆä¸ÅÏëÖ¤Ã÷°ä²¼ºóµÄÒ»ÖÜÄÚ£¬¼´2021Äê6ÔÂ26ÈÕ£¬×êÑÐÈËÔ±·¢ÏÖ¹¥»÷ÕßÀûÓø÷ì϶װÖöñÒâÈí¼þMiraiµÄ±äÌåµÄ»î¶¯¡£´Ë±í£¬»ã±¨»¹ÁгöÁËÓйظûµÄIoCµÈ¼¼ÊõÓйØÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/cve-2021-32305-websvn/


×êÑÐÈËÔ±Åû¶ExchangeÖÐзì϶ProxyTokenµÄϸ½Ú


×êÑÐÈËÔ±Åû¶ExchangeÖÐзì϶ProxyTokenµÄϸ½Ú.jpg


Zero Day InitiativeÓÚ½ñÄê8ÔÂ30ÈÕ¹«¿ªÁËMicrosoft ExchangeÖÐзì϶ProxyTokenµÄϸ½Ú¡£¸Ã·ì϶ÓÉÔ½ÄÏÓʵ缯ÍÅVNPT-ISCµÄ×êÑÐÈËÔ±ÓÚ2021Äê3Ô·¢ÏÖ£¬²¢ÒÑÓÉMicrosoftÔÚ2021Äê7ÔµÄÖܶþ²¹¶¡¸üÐÂÖнâ¾ö¡£¸Ã·ì϶׷×ÙΪCVE-2021-33766£¬CVSSÆÀ·ÖΪ7.3¡£·ì϶´æÔÚÓÚExchangeµÄίÍÐÉí·ÝÑéÖ¤Ö°ÄÜÖУ¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ÅäÖÃÓû§µÄÓÊÏä¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/08/new-microsoft-exchange-proxytoken-flaw.html


QNAP³ÆÆäNAS²úÆ·ÊÜOpenSSLÖеÄRCEºÍDoS·ì϶ӰÏì


QNAP³ÆÆäNAS²úÆ·ÊÜOpenSSLÖеÄRCEºÍDoS·ì϶ӰÏì.jpg


NASÔì×÷ÉÌÓÚ±¾ÖÜÒ»°ä²¼ÁËÁ½·Ý¹ØÓÚOpenSSLÔ¶³Ì´úÂëÖ´Ðкͻؾø·þÎñ·ì϶µÄ°²È«²¼¸æ¡£ÕâÁ½¸ö·ì϶׷×ÙΪCVE-2021-3711ºÍCVE-2021-3712£¬ÒÑÔÚÉÏÖÜÓÉOpenSSL½¨¸´£¬ËüÃÇÓ°ÏìÁËÔËÐÐQTS¡¢QuTS hero¡¢QuTScloudºÍHBS 3 Hybrid Backup SyncµÄQNAP NASÉ豸¡£QNAP°µÊ¾ÆäĿǰÔÚ³¹µ×µ÷²é´Ë°¸£¬²¢´òË㾡¿ì°ä²¼°²È«¸üС£ÉÏÖÜ£¬Öйų́ÍåµÄNASÔì×÷ÉÌSynologyÒ²°µÊ¾Æä²¿ÃÅNAS²úÆ·Êܵ½ÕâЩ·ì϶µÄÓ°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/qnap-works-on-patches-for-openssl-bugs-impacting-its-nas-devices/


ÒòGoogleÀûÓÃbug£¬²¿ÃŰ²×¿Óû§ÎÞ·¨²¦´òºÍ½ÓÌýµç»°


ÒòGoogleÀûÓÃbug£¬²¿ÃŰ²×¿Óû§ÎÞ·¨²¦´òºÍ½ÓÌýµç»°.jpg


Google°µÊ¾£¬²¿ÃÅAndroidÊÖ»úÐͺŵÄÓû§Êܵ½GoogleÀûÓÃÖÐbugµÄÓ°Ï죬ÎÞ·¨²¦´òºÍ½ÓÌýµç»°¡£Ä¿Ç°GoogleûÓй«¿ªÊÜÓ°ÏìÊÖ»úµÄÐͺÅ£¬µ«±¾ÖÜÄ©ÊÜÓ°ÏìÓû§Ìáµ½ÁËLGµÄÉ豸£¬ÈçLG G7¡¢LG G7 ThinQ¡¢LG V40 ThinQºÍLG Q70µÈ¡£Google³ÆÆäÔÚµ÷²é´ËÊ£¬²¢ÒѰ䲼ÁË×îиüÐÂÀ´½¨¸´¸Ãbug£¬½¨ÒéÓû§ÊÖ¶¯×°ÖÃ×îиüС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/google/google-app-bug-blocks-android-users-from-receiving-making-calls/


DeFiƽ̨Cream FinanceÔâµ½¹¥»÷Ëðʧ³¬¹ý2900ÍòÃÀÔª


DeFiƽ̨Cream FinanceÔâµ½¹¥»÷Ëðʧ³¬¹ý2900ÍòÃÀÔª.jpg


È¥ÖÐÐÄ»¯½ðÈÚ(DeFi)ƽ̨Cream FinanceÓÚ8ÔÂ30ÈÕ³ÆÆäÔâµ½¹¥»÷£¬¹À¼ÆËðʧ³¬¹ý2900ÍòÃÀÔª¡£¸Ã¹«Ë¾³Æ£¬¹¥»÷ÕßÀûÓá°reentrancy attack¡±¹¥»÷ÁËÆä¡°flash loan¡±Ö°ÄÜ£¬ÇÔÈ¡ÁË418311571¸öAMP±Ò£¨Ô¼Îª2510ÍòÃÀÔª£©ºÍ1308.09¸öETH±Ò£¨Ô¼Îª415ÍòÃÀÔª£©¡£Æ¾¾ÝCipherTraceµÄÊý¾Ý£¬2021ÄêÓëDeFiÓйصĹ¥»÷»î¶¯Õ¼ËùÓÐÖØÒª¹¥»÷»î¶¯µÄ76%£¬¶ÔDeFiƽ̨µÄ¹¥»÷Ôì³ÉµÄËðʧ³¬¹ý4.74ÒÚÃÀÔª¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/hackers-steal-29-million-from-crypto-platform-cream-finance/