2019ÄêÊý¾Ýй¶ÊӲ챨¸æ£»£»£»£»UCä¯ÀÀÆ÷δÐÞ¸´µÄµØµãÀ¸ÓÕÆÎó²î£»£»£»£»2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼й¶
Ðû²¼Ê±¼ä 2019-05-09
VerizonÐû²¼2019ÄêÊý¾Ýй¶ÊӲ챨¸æ£¨DBIR£©£¬£¬£¬£¬£¬£¬£¬¸Ã±¨¸æÆÊÎöÁË86¸ö¹ú¼Ò±¬·¢µÄ41000¶àÆðÍøÂçÇå¾²ÊÂÎñºÍ2000¶àÆðÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¸Ã±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬´Ó2018Äê×îÏÈÔÆ´æ´¢ÉèÖùýʧ¡¢BECºÍ֪ʶ²úȨ͵ÇÔ¶¼´¦ÓÚÉÏÉýÇ÷ÊÆ¡£¡£¡£¡£¡£ÒÔÉÌÒµÌØ¹¤»î¶¯ÎªÄîÍ·µÄÍøÂç¹¥»÷ÓÐËùÔöÌí£¬£¬£¬£¬£¬£¬£¬ÔÚÒÑÍùµÄ12¸öÔÂÀ£¬£¬£¬£¬£¬£¬ÓÐ1/4µÄÍøÂçÈëÇÖÓëÕì̽ºÍÊý¾ÝÉøÂ©Óйء£¡£¡£¡£¡£×ÜÌå¶øÑÔ´ó´ó¶¼ÍøÂç¹¥»÷¶¼ÊÇÒÔ¾¼ÃÀûÒæ×÷ΪÇý¶¯¡£¡£¡£¡£¡£²»ÐÒµÄÊÇ£¬£¬£¬£¬£¬£¬£¬ÓÐÒ»°ëµÄÆóÒµÐè񻮮·ÑÊýÔÂÉõÖÁ¸ü³¤µÄʱ¼äÀ´·¢Ã÷ÈëÇÖÐÐΪ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://enterprise.verizon.com/resources/reports/2019-data-breach-investigations-report.pdf
2¡¢UCä¯ÀÀÆ÷±»ÆØ±£´æÎ´ÐÞ¸´µÄµØµãÀ¸ÓÕÆÎó²î
Çå¾²Ñо¿Ö°Ô±Arif Khan·¢Ã÷UCä¯ÀÀÆ÷±£´æÒ»¸öÉÐδÐÞ¸´µÄµØµãÀ¸ÓÕÆÎó²î¡£¡£¡£¡£¡£UCä¯ÀÀÆ÷Êǰ¢Àï°Í°ÍÆìϵÄUCWeb¿ª·¢µÄä¯ÀÀÆ÷£¬£¬£¬£¬£¬£¬£¬ÔÚÖйúºÍÓ¡¶ÈÓµÓÐÁè¼Ý5ÒÚÓû§¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚä¯ÀÀÆ÷µÄÓû§½çÃæ´¦Öóͷ£ÌØÊâÄÚÖù¦Ð§£¨¸Ã¹¦Ð§Ö¼ÔÚ¸ÄÉÆÓû§µÄGoogleËÑË÷ÌåÑ飩µÄ·½·¨£¬£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷Õß¿ØÖƵصãÀ¸ÖÐÏÔʾµÄURL×Ö·û´®£¬£¬£¬£¬£¬£¬£¬ÓÕÆÓû§»á¼û¶ñÒâÍøÕ¾¡£¡£¡£¡£¡£¸ÃÎó²îÉÐδ·ÖÅÉCVE±àºÅ£¬£¬£¬£¬£¬£¬£¬UCä¯ÀÀÆ÷µÄ×îа汾12.11.2.1184ºÍUC Miniä¯ÀÀÆ÷µÄ×îа汾12.10.1.1192¾ùÊÜÓ°Ïì¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/05/uc-browser-url-spoofing.html
3¡¢Freedom MobileÒâÍâй¶½ü500ÍòÌõÓû§¼Í¼
¼ÓÄôóµçÐŹ«Ë¾Freedom MobileµÄÒ»¸ö°üÀ¨¿Í»§Êý¾ÝµÄElasticSearchÊý¾Ý¿âÒòÉèÖùýʧÔÚÍøÉÏ̻¶£¬£¬£¬£¬£¬£¬£¬µ¼Ö½ü500ÍòÌõ¿Í»§¼Í¼й¶¡£¡£¡£¡£¡£Æ¾Ö¤Çå¾²Ñо¿Ô±Noam RotemºÍRan LocarµÄ·¢Ã÷£¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÊôÓÚFreedom MobileµÄµÚÈý·½Ð§ÀÍÌṩÉÌApptium¡£¡£¡£¡£¡£¸Ã¹«Ë¾½²»°ÈËÌåÏÖ£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÊÂÎñÓ°ÏìÁË3ÔÂ25ÈÕÖÁ4ÔÂ15ÈÕʱ´úÔÚ17¸öFreedom MobileÓªÒµÌü¿ªÉè»ò¸ü¸ÄÕË»§µÄÓû§£¬£¬£¬£¬£¬£¬£¬Ô¼ÓÐ1.5ÍòÓû§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢²»µ«°üÀ¨Óû§µÄÐÕÃû¡¢ÓÊÏäµÈСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬»¹°üÀ¨ÐÅÓÿ¨ºÅµÈÖ§¸¶ÐÅÏ¢¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/freedom-mobile-exposed-almost-5-million-customer-records-due-to-a-misconfigured-database-fddd4855
4¡¢ºº±¤Íõ¶ùͯÊÐËÁÒâÍâй¶½ü4ÍòÌõÓû§¼Í¼
Çå¾²Ñо¿Ô±Bob Diachenko·¢Ã÷ºº±¤ÍõµÄÒ»¸öרΪ¶ùͯЧÀ͵퍹úÍøÉÏÊÐËÁÒâÍâй¶ÁË37900Ìõ¿Í»§¼Í¼¡£¡£¡£¡£¡£ÕâЩ¼Í¼°üÀ¨ÔÚÒ»¸öδÊܱ£»£»£»£»¤µÄElasticsearch¼¯ÈºÖУ¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÖÁÉÙ´Ó4ÔÂ24ÈÕ×îÏÈÔÚÍøÉÏ̻¶¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢²»µ«°üÀ¨Óû§µÄÐÕÃû¡¢µç»°µÈPIIÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬»¹°üÀ¨²¿·ÖÔ±¹¤µÄÓÊÏ䵨µã¡¢CRMºó¶ËÈÕÖ¾µÈÐÅÏ¢¡£¡£¡£¡£¡£Î´Êܱ£»£»£»£»¤µÄElasticSearchÊý¾Ý¿âÕýÔÚ³ÉΪ³£Ì¬¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/burger-kings-online-store-for-kids-exposes-customers-info/
5¡¢AWSÉÏδÊܱ£»£»£»£»¤µÄMongoDBй¶Áè¼Ý2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼
Çå¾²Ñо¿Ô±Bob DiachenkoʹÓÃShodan·¢Ã÷ÔÚAmazon AWSÉÏÍйܵÄÒ»¸ö¿É¹ûÕæ»á¼ûµÄMongoDBÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âй¶ÁËÁè¼Ý2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢ÓÊÏä¡¢ÊÖ»úºÅÂë¡¢Ö°ÒµºÍнˮµÈPII£¬£¬£¬£¬£¬£¬£¬µ«DiachenkoûÓз¢Ã÷¸ÃÊý¾Ý¿âµÄ¹éÊô×éÖ¯¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÓÚ4ÔÂ23ÈÕ×îÏÈÔÚÍøÉÏ̻¶¡£¡£¡£¡£¡£Diachenko֪ͨÁËÓ¡¶ÈCERT£¬£¬£¬£¬£¬£¬£¬µ«¸ÃÊý¾Ý¿â²¢Î´Êܵ½±£»£»£»£»¤£¬£¬£¬£¬£¬£¬£¬Ö±µ½5ÔÂ8ÈÕ·¸·¨ÍÅ»ïUnistellarɾ³ýÁ˸ÃÊý¾Ý¿â²¢ÁôÏÂÁËÁªÏµ·½·¨¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/over-275-million-records-exposed-by-unsecured-mongodb-database/
6¡¢°Í¶ûµÄĦÊÐÕþÌüºÍ²¨ÌØÏؾùÔâÀÕË÷Èí¼þ¹¥»÷
µÂ¿ËÈøË¹Öݲ¨ÌØÏؼ°ÂíÀïÀ¼ÖݰͶûµÄĦÊÐÕþÌü¾ùÔâÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£Æ¾Ö¤°Í¶ûµÄĦÊг¤Jack YoungµÄ¹Ù·½ÉùÃ÷£¬£¬£¬£¬£¬£¬£¬¸ÃÊеĽ¹µãЧÀÍ£¨¾¯Ô±¡¢Ïû·À¡¢EMSºÍ311£©ÈÔÔÚÔË×÷£¬£¬£¬£¬£¬£¬£¬µ«ÒÑÈ·½¨¶¼»áÍøÂçѬȾÁËÀÕË÷²¡¶¾£¬£¬£¬£¬£¬£¬£¬³öÓÚÔ¤·À¸ÃÊÐÒѾ¹Ø±ÕÁ˴󲿷ÖЧÀÍÆ÷¡£¡£¡£¡£¡£¶øÆ¾Ö¤NewsChannel 10µÄ˵·¨£¬£¬£¬£¬£¬£¬£¬²¨ÌØÏØÔÚ4ÔÂ22ÈÕÔâµ½¶ñÒâÈí¼þ¹¥»÷ºó£¬£¬£¬£¬£¬£¬£¬ÒѾÏë·¨½«²¿·ÖÅÌËã»úÏµÍ³ÖØÐÂÉÏÏß¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/local-authorities-in-texas-and-maryland-hit-by-ransomware/


¾©¹«Íø°²±¸11010802024551ºÅ