ºÚ¿ÍÈëÇÖ2getherЧÀÍÆ÷£¬£¬£¬ÇÔÈ¡¼ÛÖµ120ÍòÅ·ÔªµÄ¼ÓÃÜÇ®±Ò£»£»£»£»£»£»ºÚ¿Íй¶900¶à¸öÆóÒµVPNЧÀÍÆ÷µÄÐÅÏ¢ºÍÃ÷ÎÄÃÜÂë
Ðû²¼Ê±¼ä 2020-08-051.ºÚ¿ÍÈëÇÖ2getherЧÀÍÆ÷£¬£¬£¬ÇÔÈ¡¼ÛÖµ120ÍòÅ·ÔªµÄ¼ÓÃÜÇ®±Ò
7ÔÂ31ÈÕÏÂÖç6µã£¬£¬£¬ºÚ¿ÍÈëÇÖÁË2getherµÄЧÀÍÆ÷£¬£¬£¬²¢ÇÔÈ¡Á˼ÛÖµ118.3ÍòÅ·ÔªµÄ¼ÓÃÜÇ®±Ò£¬£¬£¬Õ¼×Ü×ʽðµÄ26.79£¥¡£¡£¡£¡£¡£¡£¡£2together CEOÌåÏÖ£¬£¬£¬´Ë´Î¹¥»÷²¢Î´Ó°ÏìͨÓÃÇ®°üºÍÅ·ÔªÕÊ»§£¬£¬£¬²¢ÇÒºÚ¿ÍûÓÐÇÔÈ¡Óû§ÐÅÓÿ¨µÄ²ÆÎñÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬¸Ã¹«Ë¾²¢Î´Ðû²¼¹¥»÷µÄÊÖÒÕϸ½Ú£¬£¬£¬Ö»ÊÇÌåÏÖÁËÏêϸÊÓ²ìÈÔÔÚ¾ÙÐÐÖС£¡£¡£¡£¡£¡£¡£¾Ý¹«Ë¾¸ß¹Ü³Æ£¬£¬£¬¸Ã¹«Ë¾Ã»ÓÐ×ã¹»µÄ×ʽðÀ´ÍË»¹ÆäÓû§£¬£¬£¬²¢ÇÒÕýÊÔͼͨ¹ýͶ×ʹ«Ë¾µÄ×¢×ʾÙÐе÷½â¡£¡£¡£¡£¡£¡£¡£¿ÉÊDz¢Î´Àֳɣ¬£¬£¬Òò´ËÖ»ÄÜÏòÓû§ÌṩÆä±»µÁµÄ¼ÓÃÜÇ®±ÒµÈÖµµÄÍâµØ2GT´ú±Ò¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/106726/hacking/2gether-hacked.html
2.°Í»ù˹̹ÐÂÎÅÆµµÀDawnÔâ¹¥»÷£¬£¬£¬¹ã¸æÊ±¼ä²¥·ÅÓ¡¶È¹úÆì
8ÔÂ2ÈÕÐÇÆÚÈÕÏÂÖç3:30×óÓÒ£¬£¬£¬°Í»ù˹̹Ö÷ÒªÐÂÎÅÆµµÀÖ®Ò»DawnÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬¹ã¸æÐÝϢʱ´úÔÚÆÁÄ»Éϲ¥·ÅÓ¡¶È¹úÆìºÍ×ÔÁ¦¼ÍÄîÈÕ¿ìÀÖµÄ×ÖÑù¡£¡£¡£¡£¡£¡£¡£DawnÌåÏÖ£¬£¬£¬Ôâµ½¹¥»÷ʱËûÃÇÏñÍù³£Ò»Ñù²¥·ÅÐÂÎÅºÍ¹ã¸æ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬ Ïà¹Ø»ú¹¹ÕýÔڶԴ˴ι¥»÷Õö¿ªÊӲ졣¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬Õâ²¢²»ÊǵÚÒ»´Î±¬·¢ºÚ¿Í¹¥»÷µçÊÓÆµµÀÊÂÎñ£¬£¬£¬ÒÔÉ«ÁеÄ˽ÈËÐÂÎÅÆµµÀµÚ2ƵµÀºÍµÚ10ƵµÀµÄ¾ÍÔøÔâµ½¹ýÈëÇÖ£¬£¬£¬ºÚ¿ÍÖÐÖ¹Á˽ÚÄ¿²¢²¥·ÅÄÂ˹ÁÖµÄÆíµ»Éù¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/pakistani-news-channel-transmission-hacked-indian-flag/
3.ºÚ¿Íй¶900¶à¸öÆóÒµVPNЧÀÍÆ÷µÄÐÅÏ¢ºÍÃ÷ÎÄÃÜÂë
ºÚ¿ÍÔÚ°µÍøÉÏÐû²¼ÁË900¶à¸öPulse Secure VPNÆóҵЧÀÍÆ÷µÄÐÅÏ¢ºÍÃ÷ÎÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£´Ë´Îй¶ÐÅÏ¢°üÀ¨Ð§ÀÍÆ÷µÄIPµØµã¡¢¹Ì¼þ°æ±¾ºÅ¡¢Ã¿¸öЧÀÍÆ÷µÄSSHÃÜÔ¿¡¢ËùÓÐÍâµØÓû§¼°ÆäÃÜÂë¹þÏ£µÄÁÐ±í¡¢ÖÎÀíÔ±ÕÊ»§ÏêϸÐÅÏ¢¡¢×î½üµÄVPNµÇ¼Ãû£¨°üÀ¨Óû§ÃûºÍÃ÷ÎÄÃÜÂ룩ÒÔ¼°VPN»á»°cookie¡£¡£¡£¡£¡£¡£¡£ÍþвÇ鱨ÆÊÎö¹«Ë¾Bank Security·¢Ã÷ÁбíÖеÄЧÀÍÆ÷¶¼ÔËÐÐÁ˱£´æCVE-2019-11510Îó²î°æ±¾µÄ¹Ì¼þ¡£¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬ÆäÒÔΪºÚ¿ÍÊÇɨÃèÁËЧÀÍÆ÷µÄÕû¸öInternet IPv4µØµã¿Õ¼ä£¬£¬£¬²¢Ê¹ÓøÃÎó²îÀ´»á¼ûϵͳ£¬£¬£¬×ª´¢Ð§ÀÍÆ÷ÏêϸÐÅÏ¢²¢½«ËùÓÐÐÅÏ¢ÍøÂçµ½Ò»ÆäÖÐÑë´æ´¢¿âÖС£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hacker-leaks-passwords-for-900-enterprise-vpn-servers/
4.Ò»¼üͨӦÓÃZello±¬·¢Êý¾Ýй¶£¬£¬£¬ÒÑÖØÖÃËùÓÐÓû§ÃÜÂë
Ò»¼üͨӦÓÃZello±¬·¢Êý¾Ýй¶£¬£¬£¬ÆäÒÑÖØÖÃËùÓÐÓû§ÃÜÂë¡£¡£¡£¡£¡£¡£¡£ZelloÖ¸³ö£¬£¬£¬ËûÃÇÓÚ2020Äê7ÔÂ8ÈÕÔÚÆäÖÐһ̨ЧÀÍÆ÷ÉÏ·¢Ã÷Á˴˴ι¥»÷£¬£¬£¬Í¨¹ý½øÒ»³ÌÐò²é£¬£¬£¬·¢Ã÷δ¾ÊÚȨµÄºÚ¿Í¿ÉÄÜÒѾ»á¼ûÁËÆäÓû§ÔÚÆäZelloÕÊ»§ÉÏʹÓõĵç×ÓÓʼþµØµãºÍ¹þÏ£ÃÜÂë¡£¡£¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬´Ë´Îй¶ÊÂÎñ²¢²»»áÓ°ÏìZello WorkºÍZello for First RespondersÓû§¡£¡£¡£¡£¡£¡£¡£ºÚ¿Í¿ÉʹÓÃй¶ÐÅÏ¢¾ÙÐÐÆ¾Ö¤Ìî³ä¹¥»÷£¬£¬£¬²¢µÇÈÎÃü»§ÆäËûÕ¾µãµÄÕË»§¡£¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬ZelloÒÑÇ¿ÖÆÖØÖÃÓû§ÃÜÂ룬£¬£¬²¢½¨ÒéÓû§¸ü¸ÄÆäËûÕ¾µãÉÏÏàͬµÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/zello-resets-all-user-passwords-after-data-breach/
5.ÈýÁâÐû²¼¶à¸ö²úÆ·µÄ¸üУ¬£¬£¬»¹ÌṩÁËÔÝʱ½â¾ö¼Æ»®
ÈýÁâµç»úµÄÊýÊ®ÖÖ¹¤³§×Ô¶¯»¯²úÆ·±£´æÈý¸öÎó²î£¬£¬£¬ÕâЩÎó²î¿É±»Ê¹ÓþÙÐÐÌáȨ¡¢í§Òâ´úÂëÖ´ÐкÍDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬ÈýÁâÒѾΪÊÜÓ°ÏìµÄ²úÆ·Ðû²¼Á˲¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬»¹ÎªÆäÓà²úÆ·ºÍÎÞ·¨Á¬Ã¦×°Öò¹¶¡³ÌÐòµÄ¿Í»§ÌṩÁË»º½â²½·¥¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸öÎó²îΪȨÏÞÎÊÌ⣨CVE-2020-14496£©£¬£¬£¬ËüÔÊÐíºÎÓû§ÔÚÌØ¶¨Ä¿Â¼Ð´ÈëÎļþ£¬£¬£¬ÓµÓÐдȨÏ޵Ĺ¥»÷Õß¿ÉÒÔÁýÕÖ´ËĿ¼ÖеÄÕýµ±Îļþ¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¸öÊÇzipÎó²î£¨CVE-2020-14523£©£¬£¬£¬²úƷʹÓÃzip¹éµµÎļþÀ´´æ´¢ÉèÖ㬣¬£¬ÌáÈ¡¶ñÒâzip¹éµµÎļþ¿ÉÄܵ¼Ö½«ÎļþдÈëÄ¿µÄĿ¼֮ÍâµÄí§ÒâλÖᣡ£¡£¡£¡£¡£¡£µÚÈý¸öÎó²î±»×·×ÙΪCVE-2020-14521£¬£¬£¬¶ÔijЩWindows apiµÄŲÓÃÖÐʹÓÃÁËδÒýÓõÄ·¾¶£¬£¬£¬¿É±»Ê¹ÓüÓÔØ¶ñÒâ¿ÉÖ´ÐÐÎļþ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/hackers-could-target-organizations-flaws-mitsubishi-factory-automation-products
6.Ñо¿Ö°Ô±·¢Ã÷MeetupµÄÎó²î£¬£¬£¬¿Éµ¼ÖÂÓû§×ʽð±»ÇÔÈ¡
CheckmarxÑо¿Ö°Ô±·¢Ã÷Meetupƽ̨±£´æÑÏÖØµÄÎó²î£¬£¬£¬¿Éµ¼ÖÂÓû§×ʽð±»ÇÔÈ¡¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸öΪ´æ´¢µÄXSSÎó²î£¬£¬£¬Ö»ÐèÔÚÌÖÂÛÇøµÄÐÂÎÅÖÐÐû²¼JavaScript´úÂë¾Í¿ÉÒÔ¾ÙÐÐÌáȨ¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¸öÎó²îΪÉèÖò˵¥µÄ¸¶¿î²¿·ÖÖеÄCSRF£¬£¬£¬¿ÉÓëµÚÒ»¸öXSSÎó²îÁ¬ÏµÊ¹Ó㬣¬£¬¸ü¸ÄÓû§ÔÚMeetupÉèÖÃÎļþÖеÄPayPalµØµã¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÖ»ÐèÔÚÌÖÂÛÇøÖÐÐû²¼Ò»ÌõÐÂÎÅ£¬£¬£¬²¢Ö¸ÏòÆäЧÀÍÆ÷ÉÏʹÓÃCSRFÎÊÌâµÄÎļþ±ã¿ÉÒÔʹÓøÃÎó²î¡£¡£¡£¡£¡£¡£¡£³ýÁËÕâÁ½¸öÎó²îÍ⣬£¬£¬Checkmarx»¹·¢Ã÷ÁËÆäËûÇå¾²Òþ»¼£¬£¬£¬api.meetup.comµÄ³ÉÔ±¶ËµãÖÐȱ·¦×ÊÔ´ºÍËÙÂÊÏÞÖÆ£¬£¬£¬¿ÉÒÔʹÓÃÐòÁÐÕûÊýÀ´Ê¹ÓôËö¾Ùö¾ÙMeetupÓû§¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-could-have-stolen-paypal-funds-from-meetup-users/