SolarWinds¹©Ó¦Á´¹¥»÷»î¶¯Öб£´æÐµÄSUPERNOVAºóÃÅ£»£»£»£»¶à¹úÖ´·¨²¿·ÖÁªºÏµ·»ÙÈý¸öÌṩVPNЧÀ͵ÄÍøÕ¾?

Ðû²¼Ê±¼ä 2020-12-23

1.SolarWinds¹©Ó¦Á´¹¥»÷»î¶¯Öб£´æÐµÄSUPERNOVAºóÃÅ


1.jpg


Ñо¿Ö°Ô±·¢Ã÷SolarWinds Orion¹©Ó¦Á´¹¥»÷»î¶¯Öб£´æÐµÄSUPERNOVAºóÃÅ£¬£¬£¬£¬ £¬£¬£¬¿ÉÄÜÀ´×ÔÁíÒ»¸öºÚ¿Í×éÖ¯¡£¡£¡£¡£¡£¡£SUPERNOVAÊÇÖ²ÈëOrionÍøÂçºÍÓ¦ÓóÌÐò¼àÊÓÆ½Ì¨´úÂëÖеÄWeb shell£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉʹÓøöñÒâÈí¼þÔÚÅÌËã»úÉÏÔËÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâ´úÂë½ö°üÀ¨Ò»ÖÖDynamicRunÒªÁ죬£¬£¬£¬ £¬£¬£¬¿É½«²ÎÊý¶¯Ì¬±àÒëµ½ÄÚ´æÖеÄ.NET³ÌÐò¼¯ÖУ¬£¬£¬£¬ £¬£¬£¬Òò´Ë²»»áÔÚÊÜѬȾװ±¸ÉÏÁôÏÂÈκκۼ£¡£¡£¡£¡£¡£¡£¾­ÊӲ죬£¬£¬£¬ £¬£¬£¬SUPERNOVAûÓÐÊý×ÖÊðÃû£¬£¬£¬£¬ £¬£¬£¬ÕâÓë×î³õ·¢Ã÷µÄSunBurst²î±ð£¬£¬£¬£¬ £¬£¬£¬»òÐíÊôÓÚÁíÒ»ºÚ¿Í×éÖ¯¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/a-second-hacking-group-has-targeted-solarwinds-systems/


2.¶à¹úÖ´·¨²¿·ÖÁªºÏµ·»ÙÈý¸öÌṩVPNЧÀ͵ÄÍøÕ¾


2.jpg


À´×ÔÃÀ¹ú¡¢µÂ¹ú¡¢·¨¹ú¡¢ÈðÊ¿ºÍºÉÀ¼µÄÖ´·¨»ú¹¹ÁªºÏ£¬£¬£¬£¬ £¬£¬£¬Àֳɵ·»ÙÁËÈý¸öVPNЧÀ͵ÄÍøÕ¾¡£¡£¡£¡£¡£¡£´Ë´ÎÐж¯µÄ´úºÅΪNova£¬£¬£¬£¬ £¬£¬£¬Ö÷ÒªÓÉÅ·ÖÞÐ̾¯×éÖ¯¾ÙÐÐЭµ÷¡£¡£¡£¡£¡£¡£±»²é·âµÄÈý¸öÍøÕ¾»®·ÖΪinsorg.org¡¢safe-inet.comºÍsafe-inet.net£¬£¬£¬£¬ £¬£¬£¬¾ùÒÑ»îÔ¾ÁËÊ®¶àÄ꣬£¬£¬£¬ £¬£¬£¬¿ÉÄÜÊôÓÚÒ»¸öÍŻ¡£¡£¡£¡£¡£ÕâÐ©ÍøÕ¾¿ÉÌṩ¶à´ïÎå²ãµÄÊðÀíÍøÂ磬£¬£¬£¬ £¬£¬£¬Òò´ËÀÕË÷Èí¼þÍŻÐÅÓÿ¨ÇÔÈ¡(Magecart)ÍÅ»ï¡¢ÍøÂç´¹ÂںڿͺͼÓÈëÕË»§ÊÕ¹ºµÄºÚ¿Í¾­³£ÓÃÕâЩЧÀÍÆ÷À´Òþ²ØÕæÊµÉí·Ý¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/law-enforcement-take-down-three-bulletproof-vpn-providers/


3.¼ÓÃÜÇ®±ÒÉúÒâËùEXMOÔâµ½¹¥»÷£¬£¬£¬£¬ £¬£¬£¬Ëðʧ×Ü×ʲúµÄ5£¥


3.jpg


Ó¢¹ú¼ÓÃÜÇ®±ÒÉúÒâËùEXMO³ÆÆäÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬ £¬£¬£¬12ÔÂ21ÈÕºÚ¿ÍÔÚÈëÇÖÆäÈÈÇ®°üºó͵ȡÁË´ó×Ú×ʲú¡£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬ £¬£¬£¬EXMOÈÈÇ®°üÖв¿·ÖµÄBTC¡¢XRP¡¢ZEC¡¢USDTºÍETH¾ùÊܵ½ÁËÓ°Ïì¡£¡£¡£¡£¡£¡£EXMOÔÚ·¢Ã÷¹¥»÷ºóÁ¬Ã¦×ö³öÏìÓ¦£¬£¬£¬£¬ £¬£¬£¬ÔÝÍ£ËùÓÐÌá¿î²¢ÖØÐ°²ÅÅÈÈÇ®°ü¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÈÈÇ®°ü×ʽðÕ¼×Ü×ʲúµÄ½ü5%¡£¡£¡£¡£¡£¡£µ«ÀäÇ®°üÀïµÄËùÓÐÇ®±Ò¶¼ÊÇÇå¾²µÄ¡£¡£¡£¡£¡£¡£EXMOÌåÏÖÊÜÓ°ÏìÓû§µÄËùÓÐËðʧ½«ÓÉÆäÍêÈ«Åâ³¥²¢Í˿¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/exmo-cryptocurrency-exchange-hacked-loses-5-percent-of-total-assets/


4.ºÚ¿ÍÔÚ°µÍøÐ¹Â¶27Íò¸öLedgerÓû§µÄÃô¸ÐÐÅÏ¢


4.jpg


ºÚ¿ÍÔÚ°µÍøÐ¹Â¶ÁË27Íò¸öLedgerÓû§µÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£LedgerÊÇÓÃÓÚ´æ´¢¡¢ÖÎÀíºÍ³öÊÛ¼ÓÃÜÇ®±ÒµÄÓ²¼þ¼ÓÃÜÇ®±ÒÇ®°ü¡£¡£¡£¡£¡£¡£´Ë´ÎºÚ¿Íй¶ÁËÁ½¸öTXTÎļþ£¬£¬£¬£¬ £¬£¬£¬»®·ÖΪ°üÀ¨¶©ÔÄÁËLedgerͨѶµÄ1075382¸öÓû§µÄµç×ÓÓʼþµØµãµÄ¡°All Emails (Subscription).txt¡±£¬£¬£¬£¬ £¬£¬£¬ºÍ°üÀ¨272853λ¹ºÖÃÕßÐÕÃû¡¢ÓʼĵصãºÍµç»°ºÅÂëµÄ¡°Ledger Orders (Buyers) only.txt¡±¡£¡£¡£¡£¡£¡£ÕâЩй¶Êý¾Ý»òÐíÊÇÓÉ2020Äê6ÔµÄÊý¾Ýй¶ÊÂÎñµ¼Öµģ¬£¬£¬£¬ £¬£¬£¬¿É±»ÓÃÀ´¾ÙÐÐÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬ £¬£¬£¬ÒÔÇÔÈ¡Óû§¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/physical-addresses-of-270k-ledger-owners-leaked-on-hacker-forum/


5.JumioÐû²¼2020ÄêãåÈÕÐÂÕË»§Ú²Æ­»î¶¯µÄÆÊÎö±¨¸æ


5.jpg


JumioÐû²¼ÁË2020ÄêãåÈÕÐÂÕË»§Ú²Æ­»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬ £¬£¬£¬Óë2019ÄêµÄÏà±È£¬£¬£¬£¬ £¬£¬£¬2020Äê»ùÓÚIDÑéÖ¤µÄÐÂÕÊ»§Ú²Æ­»î¶¯ÔÚÈ«Çò¹æÄ£ÄÚͬ±ÈϽµ23.2£¥¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬ £¬£¬£¬»ùÓÚ×ÔÕÕÏàµÄڲƭÂÊ£¨7.15£¥£©±È»ùÓÚIDµÄڲƭÂÊ£¨1.41£¥£©¸ß5±¶£¬£¬£¬£¬ £¬£¬£¬Õâ˵Ã÷ÎúÔÚ°µÍøÉÏ¿ÉÒÔÂòµ½µÄ±»µÁÉí·ÝÖ¤¼þµÄÊýÄ¿ÔÚÒ»Ö±ÔöÌí¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬£¬µ±ÔÚÉí·ÝÑéÖ¤ÖÐʹÓÃSDKʱ£¬£¬£¬£¬ £¬£¬£¬Ú²Æ­ÂÊÏÔ×ŵÍÓÚÆäËûÇþµÀ(ÈçAPIºÍweb)¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://go.jumio.com/2020-holiday-fraud-report


6.Cisco TalosÐû²¼2020ÄêËùÅû¶µÄÎó²îµÄ»ØÊ×±¨¸æ


6.jpg


Cisco TalosÐû²¼ÁË2020ÄêËùÅû¶µÄÎó²îµÄ»ØÊ×±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬ £¬£¬£¬ÔÚ2020Ä꣬£¬£¬£¬ £¬£¬£¬Talos×ܹ²Ðû²¼ÁË231·Ý×Éѯ±¨¸æ£¬£¬£¬£¬ £¬£¬£¬Éæ¼°277¸öCVE£¬£¬£¬£¬ £¬£¬£¬¹æÄ£°üÀ¨²Ù×÷ϵͳ¡¢IoT×°±¸¡¢Microsoft Office²úÆ·¡¢ä¯ÀÀÆ÷ºÍPDFÔĶÁÆ÷µÈ¡£¡£¡£¡£¡£¡£½ÏΪÖ÷ÒªµÄÊÇ£¬£¬£¬£¬ £¬£¬£¬Ö÷ÒªPDFÓ¦ÓóÌÐò£¨°üÀ¨Adobe PDF¡¢Foxit PDF¡¢NitroPDFºÍGoogle PDFium£©Öб£´æ¶à¸öÎó²î£¬£¬£¬£¬ £¬£¬£¬Intel¡¢NvidiaºÍAMDµÄͼÐÎÇý¶¯³ÌÐòÖеĶà¸öÎó²î£¬£¬£¬£¬ £¬£¬£¬Firefox¡¢ChromeºÍSafariµÈÖ÷ÒªWebä¯ÀÀÆ÷Öб£´æ¶à¸öÎó²î¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2020/12/vulnerability-discovery-2020.html