Comparitech³ÆÄ³¿ª·ÅµÄÊý¾Ý¿âй¶ÃÀ¹ú3500Íò¹«ÃñÐÅÏ¢£»£»£»£»£»ZoomΪϢÕùÃÀ¹úÓû§µÄÕûÌåËßËÏÔ¸ÒâÖ§¸¶8600ÍòÃÀÔª

Ðû²¼Ê±¼ä 2021-08-04
1.Comparitech³ÆÄ³¿ª·ÅµÄÊý¾Ý¿âй¶ÃÀ¹ú3500Íò¹«ÃñÐÅÏ¢


1.jpg


Comparitech·¢Ã÷Ò»¸öδÊܱ£»£»£»£»£»¤µÄElasticsearchÊý¾Ý¿âй¶ÁËÖ¥¼Ó¸ç¡¢Ê¥µØÑǸçºÍÂåɼí¶Ô¼3500ÍòסÃñµÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÏÓÒɸÃÊý¾Ý¿â¿ÉÄÜÊÇijӪÏú¹«Ë¾Êý¾ÝץȡµÄЧ¹û£¬£¬£¬ £¬ £¬£¬£¬´æ´¢ÔÚÁËÉèÖùýʧµÄЧÀÍÆ÷ÉÏ¡£¡£¡£¡£¡£ÆäÓÚ2021Äê6ÔÂ26ÈÕ±»·¢Ã÷£¬£¬£¬ £¬ £¬£¬£¬ÔÚ7ÔÂ27ÈÕÈÔÈ»¿ÉÒÔ»á¼û£¬£¬£¬ £¬ £¬£¬£¬ÏÖÔÚÎÞ·¨È·¶¨¸ÃÊý¾Ý¿âµÄËùÓÐÕߣ¬£¬£¬ £¬ £¬£¬£¬ÑÇÂíÑ·ÍøÂçЧÀÍ(AWS)²»µÃ²»¾ÙÐиÉÔ¤²¢½«ÆäÇ¿ÐйرÕ¡£¡£¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨ÐÔ±ð¡¢ÐÕÃû¡¢ÖÖ×å¡¢³öÉúÈÕÆÚ¡¢»éÒö״̬¡¢ÓʼþµØµã¡¢ÁªÏµÐÅÏ¢¡¢×ʲú¡¢¹ºÎïϰ¹ß¡¢Ã½Ì寫ºÃ¡¢³èÎϲ»¶ºÍÐËȤÒÔ¼°ÊÕÈëºÍ¾»×ʲúµÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/household-data-database-us-residents-exposed/


2.ÉñÃØµÄ¿Õnpm°ü¡°-¡±ÏÂÔØÁ¿Áè¼Ý70Íò´Î£¬£¬£¬ £¬ £¬£¬£¬»òÒòƴд¹ýʧËùÖÂ


2.jpg


Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬ £¬ £¬£¬£¬×Ô2020ÄêÒÔÀ´£¬£¬£¬ £¬ £¬£¬£¬Ò»¸öÃûΪ¡°-¡±µÄÉñÃØ¿Õnpm°üÔÚ×¢²á±íÖеÄÏÂÔØÁ¿ÒѸߴï½ü720000´Î¡£¡£¡£¡£¡£¸ÃÈí¼þ°üÖ»ÓÐÒ»¸ö°æ±¾0.0.1£¬£¬£¬ £¬ £¬£¬£¬°üÀ¨Èý¸öÎļþ£ºindex.js¡¢package.jsonºÍREADME.md¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬ £¬£¬£¬¸Ã°üÕÕ¾ÉÁè¼Ý50¸önpm°üµÄÒÀÀµ£¬£¬£¬ £¬ £¬£¬£¬²¢ÇÒ×÷ÕßûÓÐÃ÷È·µÄÚ¹ÊÍ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬ £¬ £¬£¬£¬Õâ¿ÉÄÜÊÇÆ´Ð´¹ýʧËùÖ£¬£¬£¬ £¬ £¬£¬£¬ÀýÈç×°ÖÃnpm°üsomepackageʱҪָ¶¨Ò»Ð©flag£¬£¬£¬ £¬ £¬£¬£¬¹ýʧƴдµÄÖ¸Áînpm i - someFlag  somepackageÖУ¬£¬£¬ £¬ £¬£¬£¬¡°-¡±Óë¡°someFlag¡±Ö®¼äµÄ¿Õ¸ñ¾Í¿ÉÄܵ¼ÖÂnpmÏÂÔØ¡°-¡±°ü¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/empty-npm-package-has-over-700-000-downloads-heres-why/


3.ZoomΪϢÕùÃÀ¹úÓû§µÄÕûÌåËßËÏÔ¸ÒâÖ§¸¶8600ÍòÃÀÔª


3.jpg


ÊÓÆµ¾Û»á¹«Ë¾ZoomÒÑÔÞ³ÉÖ§¸¶8600ÍòÃÀÔª£¬£¬£¬ £¬ £¬£¬£¬À´Ï¢ÕùÃÀ¹úÓû§µÄÕûÌåËßËÏ¡£¡£¡£¡£¡£¸ÃËßËÏÓÚ2020Äê3ÔÂÔÚ¼ÓÀû¸£ÄáÑDZ±ÇøµÄÃÀ¹úµØÒªÁìÔºÌá³ö£¬£¬£¬ £¬ £¬£¬£¬ÆäÖ¸¿ØZoomͨ¹ýÓëFacebook¡¢¹È¸èºÍLinkedIn¹²ÏíСÎÒ˽¼ÒÊý¾ÝÇÖÕ¼ÁËÊý°ÙÍòÓû§µÄÒþ˽£¬£¬£¬ £¬ £¬£¬£¬»¹Ö¸ÔðZoom»Ñ³Æ×Ô¼ºÌṩ¶Ëµ½¶Ë¼ÓÃÜ£¬£¬£¬ £¬ £¬£¬£¬²¢Î´ÄÜ×èÖ¹ºÚ¿ÍÌᳫ¡°Zoombomb¡±»á»°¡£¡£¡£¡£¡£ÈôÊÇ´Ë´ÎÌáÒéµÄÏ¢Õù»ñµÃÅú×¼£¬£¬£¬ £¬ £¬£¬£¬Zoom½«Ö§¸¶¼ÓÈëËßËϵĶ©ÔÄÕß15%µÄ¶©ÔÄÍË¿î»ò25ÃÀÔª£¨ÒÔÊý¶î½Ï´óÕßΪ׼£©£¬£¬£¬ £¬ £¬£¬£¬¶øÆäËûÓû§¿É»ñµÃ15ÃÀÔª¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bbc.com/news/business-58050391


4.Sygnia³ÆÐÂAPTÍÅ»ïPraying MantisÃé×¼ÃÀ¹ú×ÅÃû¹«Ë¾


4.jpg


ÒÔÉ«ÁÐÍøÂçÇå¾²¹«Ë¾Sygnia·¢Ã÷ÐÂAPTÍÅ»ïPraying Mantis£¨ÓÖ³ÆTG2021£©Ãé×¼ÃÀ¹ú×ÅÃû¹«Ë¾¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ö¸³ö£¬£¬£¬ £¬ £¬£¬£¬TG1021ʹÓÃÁËÌØÖÆµÄ¶ñÒâÈí¼þ¿ò¼Ü£¬£¬£¬ £¬ £¬£¬£¬Ö÷ÒªÕë¶ÔMicrosoft IIS ЧÀÍÆ÷¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬ £¬£¬£¬¸ÃÍÅ»ïÕÕ¾ÉʹÓÃÁËASP.NETÖеĶà¸öÎó²î£¬£¬£¬ £¬ £¬£¬£¬°üÀ¨RCEÎó²îCVE-2021-27852¡¢VIEWSTATE·´ÐòÁл¯Îó²î¡¢Altserialization·´ÐòÁл¯Îó²îÒÔ¼°Telerik-UIÖеÄÎó²îCVE-2019-18935ºÍCVE-2017-11317¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/08/new-apt-hacking-group-targets-microsoft.html


5.CiscoÐÞ¸´Firepower FDM On-BoxÖеĴúÂëÖ´ÐÐÎó²î


5.jpg


CiscoÐÞ¸´ÁËFirepower×°±¸ÖÎÀíÆ÷(FDM)On-BoxÈí¼þÖеÄí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£FDM On-BoxÔÊÐíÖÎÀíÔ±ÔÚûÓÐFMCµÈ¼¯ÖÐÖÎÀíÆ÷µÄÇéÐÎÏÂÖÎÀí·À»ðǽ£¬£¬£¬ £¬ £¬£¬£¬²¢ÌṩÕï¶Ï¹¦Ð§¡£¡£¡£¡£¡£¸ÃÎó²î×·×ÙΪCVE-2021-1518£¬£¬£¬ £¬ £¬£¬£¬ÊÇÓÉÓÚ¶ÔÌØ¶¨REST APIÏÂÁîµÄÓû§ÊäÈëûÓоÙÐгä·ÖµÄÕûÀíËùÖ¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿µÄ×°±¸µÄAPI×Óϵͳ·¢ËÍÌØÖÆµÄHTTPÇëÇóÀ´Ê¹ÓôËÎó²î£¬£¬£¬ £¬ £¬£¬£¬ÀֳɵÄʹÓúó¿ÉÒÔÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂ룬£¬£¬ £¬ £¬£¬£¬µ«Ìõ¼þÊǹ¥»÷ÕßÐèÒª»ñµÃµÍȨÏÞÓû§Æ¾Ö¤¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120761/security/cisco-firepower-device-manager.html


6.CybereasonÐû²¼ÓйØDeadRinger¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ


6.jpg


CybereasonÐû²¼ÁËÓйØDeadRinger¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£±¨¸æÅû¶ÁË3ÆðÖ÷ÒªÕë¶ÔµçÐŹ«Ë¾µÄÌØ¹¤»î¶¯£¬£¬£¬ £¬ £¬£¬£¬Í³³ÆÎªDeadRinger¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÆÊÎö£¬£¬£¬ £¬ £¬£¬£¬Õâ3Æð¹¥»÷»î¶¯»®·ÖÀ´×ÔSoft Cell APT¡¢Naikon APTºÍEmissary Panda£¨APT27£©¡£¡£¡£¡£¡£CybereasonÌåÏÖ£¬£¬£¬ £¬ £¬£¬£¬ÕâЩ¹¥»÷»î¶¯Õë¶ÔµçÐŹ«Ë¾µÄÄ¿µÄ¶¼ÊÇÍøÂçÃô¸ÐÐÅÏ¢ºÍÆÆËðÉÌÒµ×ʲú£¨ÈçCDRÊý¾ÝÒÔ¼°Óò¿ØÖÆÆ÷µÈÍøÂç×é¼þ£©¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬ £¬£¬£¬ÕâЩ¹¥»÷»î¶¯¶¼ÓÐËùÖØµþ£¬£¬£¬ £¬ £¬£¬£¬µ«ÈÔÎÞ·¨Ã÷È·ËûÃÇÊÇ×ÔÁ¦ÊÂÇéÕվɶ¼ÔÚͳһÖÐÑëС×éµÄÖ¸µ¼ÏÂÊÂÇé¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cybereason.com/blog/deadringer-exposing-chinese-threat-actors-targeting-major-telcos