2019ÄêÉϰëÄêÁè¼Ý34%µÄÎó²îδÐÞ¸´£»£»£»£»£»1.45Íò¸öPulse VPNÒ×Êܹ¥»÷£»£»£»£»£»Æ»¹ûÐÞ¸´Ô½ÓüÎó²î

Ðû²¼Ê±¼ä 2019-08-27

1.2019ÄêÉϰëÄ걨¸æµÄÎó²îÖÐÁè¼Ý34%δÐÞ¸´


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤Risk Based SecurityÐû²¼µÄ¡¶2019ÄêÄêÖÐÎó²î»ØÊ×±¨¸æ¡· £¬£¬£¬£¬£¬£¬2019ÄêÉϰëÄ걨¸æµÄËùÓÐÎó²îÖÐÁè¼Ý34£¥£¨3771¸ö£©µÄÎó²îδÐÞ¸´¡£¡£¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬ÔÚ±¨¸æµÄ×ܹ²11092¸öÎó²îÖÐ £¬£¬£¬£¬£¬£¬14.7%£¨1630¸ö£©µÄÎó²îCVSS V2µÃ·ÖÁè¼Ý9.0 £¬£¬£¬£¬£¬£¬54.5£¥£¨6045¸ö£©µÄÎó²îÓëWebÓÐ¹Ø £¬£¬£¬£¬£¬£¬Ô¼53%£¨5878¸ö£©µÄÎó²î¿ÉÒÔÔ¶³ÌʹÓà £¬£¬£¬£¬£¬£¬66%µÄÎó²îÓëSQL×¢Èë¹¥»÷ÓÐ¹Ø £¬£¬£¬£¬£¬£¬Ô¼2.8%µÄÎó²îÓëSCADAÓйØ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://pages.riskbasedsecurity.com/2019-midyear-vulnerability-quickview-report


2.Binance֤ʵºÚ¿Í´ÓµÚÈý·½ÇÔÈ¡Óû§KYCÊý¾Ý


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¼ÓÃÜÇ®±ÒÉúÒâËùBinance£¨±Ò°²£©Ö¤ÊµºÚ¿Í´ÓµÚÈý·½¹©Ó¦ÉÌÄÇÀïÇÔÈ¡ÁËÓû§KYCÊý¾Ý¡£¡£¡£¡£¡£¡£¡£±¾ÔÂÔçЩʱ¼äºÚ¿ÍÍþв¸ÃÉúÒâËù½«Ðû²¼1ÍòÃû¿Í»§µÄKYCÊý¾Ý £¬£¬£¬£¬£¬£¬³ý·Ç¸Ã¹«Ë¾Ö§¸¶300±ÈÌØ±Ò£¨¼ÛÖµÁè¼Ý300ÍòÃÀÔª£©µÄÊê½ð¡£¡£¡£¡£¡£¡£¡£±ÒºÎÔÚһƪ¹Ù·½²©¿ÍÖÐÌṩÁËÊÂÎñÊÓ²ìµÄ¸ü¶àϸ½Ú £¬£¬£¬£¬£¬£¬Åúעй¶µÄ¿Í»§×ÊÁÏͼƬÀ´×ÔÓÚ2017Äê12ÔÂÖÁ2018Äê2ÔÂʱ´úµÄÒ»¸öµÚÈý·½¹©Ó¦ÉÌ¡£¡£¡£¡£¡£¡£¡£¾Ý±¨µÀÕâЩKYCÊý¾ÝÒѱ»ÓÃÓÚ¸ü¸Ä»òÉèÖÃڲƭÐԵıҰ²ÕË»§¡£¡£¡£¡£¡£¡£¡£ËäÈ»ÊÓ²ìÈÔÔÚ¾ÙÐÐÖÐ £¬£¬£¬£¬£¬£¬µ«¸ÃÉúÒâËùÌåÏÖÒѾ­×îÏÈÁªÏµËùÓÐDZÔÚÊܺ¦Õß £¬£¬£¬£¬£¬£¬²¢ÌṩÒþ˽±£»£»£»£»£»¤ºÍ»Ö¸´Ö¸µ¼ÒÔ¼°ÖÕÉíVIP»áÔ±×ʸñ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/08/binance-kyc-data-leak_26.html


3.Áè¼Ý1.45Íò¸öPulse VPNÒ×ÊÜCVE-2019-11510¹¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


BadPacketsÇ徲ר¼ÒÖÒÑÔÁè¼Ý1.45Íò¸öPulse Secure VPNÖÕ¶ËÒ×ÊÜCVE-2019-11510Îó²î¹¥»÷¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ8ÔÂ22ÈÕÊӲ쵽Õë¶Ô¸ÃÎó²îµÄ´ó¹æÄ£É¨Ãè»î¶¯ £¬£¬£¬£¬£¬£¬Æ¾Ö¤ÃÛ¹Þ¼à²âµ½µÄÊý¾Ý £¬£¬£¬£¬£¬£¬ÕâЩɨÃèȪԴÓÚÎ÷°àÑÀµÄÖ÷»ú £¬£¬£¬£¬£¬£¬¹¥»÷ÕßµÄÄ¿µÄÊÇ»ñȡ˽ÈËVPNµÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷41850¸öPulse Secure VPNÖÕ¶ËÔÚ»¥ÁªÍøÉÏ̻¶ £¬£¬£¬£¬£¬£¬ÆäÖÐ14528¸öÒ×Êܹ¥»÷ £¬£¬£¬£¬£¬£¬´ó´ó¶¼Î»ÓÚÃÀ¹ú£¨5010£© £¬£¬£¬£¬£¬£¬Æä´ÎÊÇÈÕ±¾£¨1511£©¡¢Ó¢¹ú£¨830£©ºÍµÂ¹ú£¨789£©¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÐÐÒµ°üÀ¨ÃÀ¹ú¾ü·½¼°Áª°î¡¢Öݺ͵ط½Õþ¸®»ú¹¹¡¢¹«Á¢´óѧ¡¢Ò½Ôº¡¢µçÁ¦ÉèÊ©¡¢½ðÈÚ»ú¹¹ÒÔ¼°²Æ²ú500Ç¿ÆóÒµµÈ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/90356/hacking/pulse-secure-vpn-endpoints-cve-2019-11510.html


4.SophosLabsÖÒÑÔBaldrÒÔÐµķ½·¨¾ÙÐй¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


BaldrÊÇÒ»ÖÖÐÂÐͶñÒâÈí¼þ £¬£¬£¬£¬£¬£¬ÓÚ1Ô·ÝÔÚDeep WebÉÏÊ״ηºÆð £¬£¬£¬£¬£¬£¬²¢ÔÚ6Ô·Ý×èÖ¹Á÷ͨ¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ±»ÓÃÓÚÃé׼ȫÌìϵÄPCÓÎÏ·Íæ¼Ò¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤SophosLabsµÄ±¨¸æ £¬£¬£¬£¬£¬£¬ÊÜÓ°Ïì×îÑÏÖØµÄ¹ú¼Ò°üÀ¨Ó¡¶ÈÄáÎ÷ÑÇ£¨21£¥£©¡¢ÃÀ¹ú£¨10.52£¥£©¡¢°ÍÎ÷£¨14.14£¥£©¡¢¶íÂÞ˹£¨13.68£¥£©¡¢Ó¡¶È£¨8.77£¥£©ºÍµÂ¹ú£¨5.43£¥£©¡£¡£¡£¡£¡£¡£¡£BaldrɨÃèÄ¿µÄϵͳÉϵÄËùÓÐAppDataºÍÔÝʱÎļþ¼Ð £¬£¬£¬£¬£¬£¬ÇÔÈ¡Ãô¸ÐÊý¾Ý²¢·¢Ë͸ø¹¥»÷Õß¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³ÆËäÈ»BaldrÒѲ»ÔÚÊг¡ÉÏ·ºÆð £¬£¬£¬£¬£¬£¬µ«ËüÈÔÈ»¿É±»Ö®Ç°¹ºÖÃËüµÄ·¸·¨·Ö×ÓʹÓà £¬£¬£¬£¬£¬£¬²¢ÇÒÈÔÈ»ÊÇDZÔÚµÄÍþв¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.livemint.com/technology/tech-news/the-evasive-baldr-malware-may-hit-back-in-new-forms-warns-sophoslabs-1566813441778.html


5.ÐÂÀÕË÷Èí¼þNemtyʹÓñ»µÁRDPƾ֤Èö²¥


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ÖÜĩʱ´úÑо¿Ö°Ô±·¢Ã÷Ò»¸öÃûΪNemtyµÄÐÂÀÕË÷Èí¼þ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒªÇóÊܺ¦Õßͨ¹ýTorÍøÂçÉÏÍйܵÄÃÅ»§ÍøÕ¾Ö§¸¶0.09981±ÈÌØ±ÒµÄÊê½ð£¨Ô¼1ǧÃÀÔª£©¡£¡£¡£¡£¡£¡£¡£Êܺ¦Õß¿ÉÒÔÉÏ´«ËûÃǵÄÉèÖÃÎļþ £¬£¬£¬£¬£¬£¬È»ºó¹¥»÷Õß½«»áÌṩÁíÒ»¸ö´øÓÐ̸Ì칦ЧµÄÍøÕ¾Á´½ÓÒÔ¼°ÓйØÐèÇóµÄ¸ü¶àÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£NemtyµÄ´úÂëÖаüÀ¨ÆÕ¾©µÄͼƬÁ´½Ó £¬£¬£¬£¬£¬£¬»¹°üÀ¨¶ÔÇå¾²Ñо¿Ö°Ô±·¢³öµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»¹»á¼ì²éÄ¿µÄÊÇ·ñλÓÚ¶íÂÞ˹¡¢°×¶íÂÞ˹¡¢¹þÈø¿Ë˹̹¡¢Ëþ¼ª¿Ë˹̹ºÍÎÚ¿ËÀ¼ £¬£¬£¬£¬£¬£¬µ«ÓëÆäËüÍþв²î±ð £¬£¬£¬£¬£¬£¬Ëü²»»á×èÖ¹ÔÚÕâЩµØÇøµÄ¼ÓÃÜÀú³Ì¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±KremezµÄ˵·¨ £¬£¬£¬£¬£¬£¬NemtyÊÇͨ¹ý±»ÇÔµÄRDPƾ֤Èö²¥µÄ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-nemty-ransomware-may-spread-via-compromised-rdp-connections/


6.AppleÐû²¼iOS 12.4.1¸üР£¬£¬£¬£¬£¬£¬ÐÞ²¹Ô½ÓüÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Apple½ñÌìÐû²¼ÁËiOS 12.4.1¸üР£¬£¬£¬£¬£¬£¬ÐÞ¸´iOS 12.4°æ±¾ÖØÐÂÒýÈëµÄÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-8605£©±»Çå¾²Ñо¿Ö°Ô±Pwn20wndÓÃÓÚ¿ª·¢ºÍÐû²¼Ô½Óü¹¤¾ß¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤AppleÖ§³ÖÎĵµÖеÄÐÎò £¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÄܱ»¶ñÒâÓ¦ÓóÌÐòÀÄÓà £¬£¬£¬£¬£¬£¬²¢ÇÒÒÔϵͳȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£Appleͬʱ»¹ÍÆËÍÁËwatchOS 5.3.1¡¢tvOS 12.4.1ºÍmacOS 10.14.6¸üС£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/apple-releases-ios-1241-to-patch-security-flaw-behind-jailbreak/