2019ÄêÊý¾Ýй¶ÊӲ챨¸æ£»£»£»£»£»£»UCä¯ÀÀÆ÷δÐÞ¸´µÄµØµãÀ¸ÓÕÆ­Îó²î£»£»£»£»£»£»2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼й¶

Ðû²¼Ê±¼ä 2019-05-09
1¡¢VerizonÐû²¼2019ÄêÊý¾Ýй¶ÊӲ챨¸æ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
VerizonÐû²¼2019ÄêÊý¾Ýй¶ÊӲ챨¸æ£¨DBIR£©£¬£¬ £¬¸Ã±¨¸æÆÊÎöÁË86¸ö¹ú¼Ò±¬·¢µÄ41000¶àÆðÍøÂçÇå¾²ÊÂÎñºÍ2000¶àÆðÊý¾Ýй¶ÊÂÎñ¡£¡£¡£ ¡£¡£¡£¸Ã±¨¸æÖ¸³ö£¬£¬ £¬´Ó2018Äê×îÏÈÔÆ´æ´¢ÉèÖùýʧ¡¢BECºÍ֪ʶ²úȨ͵ÇÔ¶¼´¦ÓÚÉÏÉýÇ÷ÊÆ¡£¡£¡£ ¡£¡£¡£ÒÔÉÌÒµÌØ¹¤»î¶¯ÎªÄîÍ·µÄÍøÂç¹¥»÷ÓÐËùÔöÌí£¬£¬ £¬ÔÚÒÑÍùµÄ12¸öÔÂÀ£¬ £¬ÓÐ1/4µÄÍøÂçÈëÇÖÓëÕì̽ºÍÊý¾ÝÉøÂ©ÓйØ¡£¡£¡£ ¡£¡£¡£×ÜÌå¶øÑÔ´ó´ó¶¼ÍøÂç¹¥»÷¶¼ÊÇÒÔ¾­¼ÃÀûÒæ×÷ΪÇý¶¯¡£¡£¡£ ¡£¡£¡£²»ÐÒµÄÊÇ£¬£¬ £¬ÓÐÒ»°ëµÄÆóÒµÐè񻮮·ÑÊýÔÂÉõÖÁ¸ü³¤µÄʱ¼äÀ´·¢Ã÷ÈëÇÖÐÐΪ¡£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://enterprise.verizon.com/resources/reports/2019-data-breach-investigations-report.pdf

2¡¢UCä¯ÀÀÆ÷±»ÆØ±£´æÎ´ÐÞ¸´µÄµØµãÀ¸ÓÕÆ­Îó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
Çå¾²Ñо¿Ö°Ô±Arif Khan·¢Ã÷UCä¯ÀÀÆ÷±£´æÒ»¸öÉÐδÐÞ¸´µÄµØµãÀ¸ÓÕÆ­Îó²î¡£¡£¡£ ¡£¡£¡£UCä¯ÀÀÆ÷Êǰ¢Àï°Í°ÍÆìϵÄUCWeb¿ª·¢µÄä¯ÀÀÆ÷£¬£¬ £¬ÔÚÖйúºÍÓ¡¶ÈÓµÓÐÁè¼Ý5ÒÚÓû§¡£¡£¡£ ¡£¡£¡£¸ÃÎó²î±£´æÓÚä¯ÀÀÆ÷µÄÓû§½çÃæ´¦Öóͷ£ÌØÊâÄÚÖù¦Ð§£¨¸Ã¹¦Ð§Ö¼ÔÚ¸ÄÉÆÓû§µÄGoogleËÑË÷ÌåÑ飩µÄ·½·¨£¬£¬ £¬¿ÉÔÊÐí¹¥»÷Õß¿ØÖƵصãÀ¸ÖÐÏÔʾµÄURL×Ö·û´®£¬£¬ £¬ÓÕÆ­Óû§»á¼û¶ñÒâÍøÕ¾¡£¡£¡£ ¡£¡£¡£¸ÃÎó²îÉÐδ·ÖÅÉCVE±àºÅ£¬£¬ £¬UCä¯ÀÀÆ÷µÄ×îа汾12.11.2.1184ºÍUC Miniä¯ÀÀÆ÷µÄ×îа汾12.10.1.1192¾ùÊÜÓ°Ïì¡£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/05/uc-browser-url-spoofing.html

3¡¢Freedom MobileÒâÍâй¶½ü500ÍòÌõÓû§¼Í¼

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
¼ÓÄôóµçÐŹ«Ë¾Freedom MobileµÄÒ»¸ö°üÀ¨¿Í»§Êý¾ÝµÄElasticSearchÊý¾Ý¿âÒòÉèÖùýʧÔÚÍøÉÏ̻¶£¬£¬ £¬µ¼Ö½ü500ÍòÌõ¿Í»§¼Í¼й¶¡£¡£¡£ ¡£¡£¡£Æ¾Ö¤Çå¾²Ñо¿Ô±Noam RotemºÍRan LocarµÄ·¢Ã÷£¬£¬ £¬¸ÃÊý¾Ý¿âÊôÓÚFreedom MobileµÄµÚÈý·½Ð§ÀÍÌṩÉÌApptium¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾½²»°ÈËÌåÏÖ£¬£¬ £¬Ð¹Â¶ÊÂÎñÓ°ÏìÁË3ÔÂ25ÈÕÖÁ4ÔÂ15ÈÕʱ´úÔÚ17¸öFreedom MobileÓªÒµÌü¿ªÉè»ò¸ü¸ÄÕË»§µÄÓû§£¬£¬ £¬Ô¼ÓÐ1.5ÍòÓû§Êܵ½Ó°Ïì¡£¡£¡£ ¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢²»µ«°üÀ¨Óû§µÄÐÕÃû¡¢ÓÊÏäµÈСÎÒ˽¼ÒÐÅÏ¢£¬£¬ £¬»¹°üÀ¨ÐÅÓÿ¨ºÅµÈÖ§¸¶ÐÅÏ¢¡£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/freedom-mobile-exposed-almost-5-million-customer-records-due-to-a-misconfigured-database-fddd4855

4¡¢ºº±¤Íõ¶ùͯÊÐËÁÒâÍâй¶½ü4ÍòÌõÓû§¼Í¼

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
Çå¾²Ñо¿Ô±Bob Diachenko·¢Ã÷ºº±¤ÍõµÄÒ»¸öרΪ¶ùͯЧÀ͵퍹úÍøÉÏÊÐËÁÒâÍâй¶ÁË37900Ìõ¿Í»§¼Í¼¡£¡£¡£ ¡£¡£¡£ÕâЩ¼Í¼°üÀ¨ÔÚÒ»¸öδÊܱ£»£»£»£»£»£»¤µÄElasticsearch¼¯ÈºÖУ¬£¬ £¬¸ÃÊý¾Ý¿âÖÁÉÙ´Ó4ÔÂ24ÈÕ×îÏÈÔÚÍøÉÏ̻¶¡£¡£¡£ ¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢²»µ«°üÀ¨Óû§µÄÐÕÃû¡¢µç»°µÈPIIÐÅÏ¢£¬£¬ £¬»¹°üÀ¨²¿·ÖÔ±¹¤µÄÓÊÏ䵨µã¡¢CRMºó¶ËÈÕÖ¾µÈÐÅÏ¢¡£¡£¡£ ¡£¡£¡£Î´Êܱ£»£»£»£»£»£»¤µÄElasticSearchÊý¾Ý¿âÕýÔÚ³ÉΪ³£Ì¬¡£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/burger-kings-online-store-for-kids-exposes-customers-info/

5¡¢AWSÉÏδÊܱ£»£»£»£»£»£»¤µÄMongoDBй¶Áè¼Ý2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
Çå¾²Ñо¿Ô±Bob DiachenkoʹÓÃShodan·¢Ã÷ÔÚAmazon AWSÉÏÍйܵÄÒ»¸ö¿É¹ûÕæ»á¼ûµÄMongoDBÊý¾Ý¿â£¬£¬ £¬¸ÃÊý¾Ý¿âй¶ÁËÁè¼Ý2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼¡£¡£¡£ ¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢ÓÊÏä¡¢ÊÖ»úºÅÂë¡¢Ö°ÒµºÍнˮµÈPII£¬£¬ £¬µ«DiachenkoûÓз¢Ã÷¸ÃÊý¾Ý¿âµÄ¹éÊô×éÖ¯¡£¡£¡£ ¡£¡£¡£¸ÃÊý¾Ý¿âÓÚ4ÔÂ23ÈÕ×îÏÈÔÚÍøÉÏ̻¶¡£¡£¡£ ¡£¡£¡£Diachenko֪ͨÁËÓ¡¶ÈCERT£¬£¬ £¬µ«¸ÃÊý¾Ý¿â²¢Î´Êܵ½±£»£»£»£»£»£»¤£¬£¬ £¬Ö±µ½5ÔÂ8ÈÕ·¸·¨ÍÅ»ïUnistellarɾ³ýÁ˸ÃÊý¾Ý¿â²¢ÁôÏÂÁËÁªÏµ·½·¨¡£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/over-275-million-records-exposed-by-unsecured-mongodb-database/

6¡¢°Í¶ûµÄĦÊÐÕþÌüºÍ²¨ÌØÏؾùÔâÀÕË÷Èí¼þ¹¥»÷

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
µÂ¿ËÈøË¹Öݲ¨ÌØÏؼ°ÂíÀïÀ¼ÖݰͶûµÄĦÊÐÕþÌü¾ùÔâÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£ ¡£¡£¡£Æ¾Ö¤°Í¶ûµÄĦÊг¤Jack YoungµÄ¹Ù·½ÉùÃ÷£¬£¬ £¬¸ÃÊеĽ¹µãЧÀÍ£¨¾¯Ô±¡¢Ïû·À¡¢EMSºÍ311£©ÈÔÔÚÔË×÷£¬£¬ £¬µ«ÒÑÈ·½¨¶¼»áÍøÂçѬȾÁËÀÕË÷²¡¶¾£¬£¬ £¬³öÓÚÔ¤·À¸ÃÊÐÒѾ­¹Ø±ÕÁ˴󲿷ÖЧÀÍÆ÷¡£¡£¡£ ¡£¡£¡£¶øÆ¾Ö¤NewsChannel 10µÄ˵·¨£¬£¬ £¬²¨ÌØÏØÔÚ4ÔÂ22ÈÕÔâµ½¶ñÒâÈí¼þ¹¥»÷ºó£¬£¬ £¬ÒѾ­Ïë·¨½«²¿·ÖÅÌËã»úÏµÍ³ÖØÐÂÉÏÏß¡£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/local-authorities-in-texas-and-maryland-hit-by-ransomware/