Comparitech³ÆÄ³¿ª·ÅµÄÊý¾Ý¿âй¶ÃÀ¹ú3500Íò¹«ÃñÐÅÏ¢£»ZoomΪºÍ½âÃÀ¹úÓû§µÄ¼¯ÌåËßËÏÔ¸ÒâÖ§¸¶8600ÍòÃÀÔª

Ðû²¼Ê±¼ä 2021-08-04
1.Comparitech³ÆÄ³¿ª·ÅµÄÊý¾Ý¿âй¶ÃÀ¹ú3500Íò¹«ÃñÐÅÏ¢


1.jpg


Comparitech·¢ÏÖÒ»¸öδÊܱ£»¤µÄElasticsearchÊý¾Ý¿âй¶ÁËÖ¥¼Ó¸ç¡¢Ê¥µØÑǸçºÍÂåɼí¶Ô¼3500Íò¾ÓÃñµÄÏêϸÐÅÏ¢¡£Ñо¿ÈËÔ±»³ÒɸÃÊý¾Ý¿â¿ÉÄÜÊÇijӪÏú¹«Ë¾Êý¾ÝץȡµÄ½á¹û £¬´æ´¢ÔÚÁËÅäÖôíÎóµÄ·þÎñÆ÷ÉÏ¡£ÆäÓÚ2021Äê6ÔÂ26ÈÕ±»·¢ÏÖ £¬ÔÚ7ÔÂ27ÈÕÈÔÈ»¿ÉÒÔ·ÃÎÊ £¬Ä¿Ç°ÎÞ·¨È·¶¨¸ÃÊý¾Ý¿âµÄËùÓÐÕß £¬ÑÇÂíÑ·ÍøÂç·þÎñ(AWS)²»µÃ²»½øÐиÉÔ¤²¢½«ÆäÇ¿ÐйرÕ¡£´Ë´Îй¶µÄÐÅÏ¢°üÂÞÐÔ±ð¡¢ÐÕÃû¡¢ÖÖ×å¡¢³öÉúÈÕÆÚ¡¢»éÒö×´¿ö¡¢ÓʼþµØÖ·¡¢ÁªÏµÐÅÏ¢¡¢×ʲú¡¢¹ºÎïϰ¹ß¡¢Ã½Ì寫ºÃ¡¢³èÎϲºÃºÍÐËȤÒÔ¼°ÊÕÈëºÍ¾»×ʲúµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/household-data-database-us-residents-exposed/


2.ÉñÃØµÄ¿Õnpm°ü¡°-¡±ÏÂÔØÁ¿Áè¼Ý70Íò´Î £¬»òÒòƴд´íÎóËùÖÂ


2.jpg


Ñо¿ÈËÔ±·¢ÏÖ £¬×Ô2020ÄêÒÔÀ´ £¬Ò»¸öÃûΪ¡°-¡±µÄÉñÃØ¿Õnpm°üÔÚ×¢²á±íÖеÄÏÂÔØÁ¿ÒѸߴï½ü720000´Î¡£¸ÃÈí¼þ°üÖ»ÓÐÒ»¸ö°æ±¾0.0.1 £¬°üÂÞÈý¸öÎļþ£ºindex.js¡¢package.jsonºÍREADME.md¡£´ËÍâ £¬¸Ã°ü»¹ÊÇÁè¼Ý50¸önpm°üµÄÒÀÀµ £¬¶øÇÒ×÷ÕßûÓÐÃ÷È·µÄ½âÊÍ¡£Ñо¿ÈËÔ±³Æ £¬Õâ¿ÉÄÜÊÇÆ´Ð´´íÎóËùÖ £¬ÀýÈç°²×°npm°üsomepackageʱҪָ¶¨Ò»Ð©flag £¬´íÎóƴдµÄÖ¸Áînpm i - someFlag  somepackageÖÐ £¬¡°-¡±Óë¡°someFlag¡±Ö®¼äµÄ¿Õ¸ñ¾Í¿ÉÄܵ¼ÖÂnpmÏÂÔØ¡°-¡±°ü¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/empty-npm-package-has-over-700-000-downloads-heres-why/


3.ZoomΪºÍ½âÃÀ¹úÓû§µÄ¼¯ÌåËßËÏÔ¸ÒâÖ§¸¶8600ÍòÃÀÔª


3.jpg


ÊÓÆµ»áÒ鹫˾ZoomÒÑͬÒâÖ§¸¶8600ÍòÃÀÔª £¬À´ºÍ½âÃÀ¹úÓû§µÄ¼¯ÌåËßËÏ¡£¸ÃËßËÏÓÚ2020Äê3ÔÂÔÚ¼ÓÀû¸£ÄáÑDZ±ÇøµÄÃÀ¹úµØÒªÁìÔºÌá³ö £¬ÆäÖ¸¿ØZoomͨ¹ýÓëFacebook¡¢¹È¸èºÍLinkedIn¹²Ïí¸öÈËÊý¾ÝÇÖ·¸ÁËÊý°ÙÍòÓû§µÄÒþ˽ £¬»¹Ö¸ÔðZoom»Ñ³Æ×Ô¼ºÌṩ¶Ëµ½¶Ë¼ÓÃÜ £¬²¢Î´ÄÜ×èÖ¹ºÚ¿ÍÌᳫ¡°Zoombomb¡±»á»°¡£Èç¹û´Ë´ÎÌáÒéµÄºÍ½â»ñµÃÅú×¼ £¬Zoom½«Ö§¸¶¼ÓÈëËßËϵĶ©ÔÄÕß15%µÄ¶©ÔÄÍË¿î»ò25ÃÀÔª£¨ÒÔÊý¶î½Ï´óÕßΪ׼£© £¬¶øÆäËûÓû§¿É»ñµÃ15ÃÀÔª¡£


Ô­ÎÄÁ´½Ó£º

https://www.bbc.com/news/business-58050391


4.Sygnia³ÆÐÂAPTÍÅ»ïPraying MantisÃé×¼ÃÀ¹úÖªÃû¹«Ë¾


4.jpg


ÒÔÉ«ÁÐÍøÂçÄþ¾²¹«Ë¾Sygnia·¢ÏÖÐÂAPTÍÅ»ïPraying Mantis£¨ÓÖ³ÆTG2021£©Ãé×¼ÃÀ¹úÖªÃû¹«Ë¾¡£Ñо¿ÈËÔ±Ö¸³ö £¬TG1021ʹÓÃÁËÌØÖÆµÄ¶ñÒâÈí¼þ¿ò¼Ü £¬Ö÷ÒªÕë¶ÔMicrosoft IIS ·þÎñÆ÷¡£´ËÍâ £¬¸ÃÍŻﻹÊÇÀûÓÃÁËASP.NETÖеĶà¸ö©¶´ £¬°üÂÞRCE©¶´CVE-2021-27852¡¢VIEWSTATE·´ÐòÁл¯Â©¶´¡¢Altserialization·´ÐòÁл¯Â©¶´ÒÔ¼°Telerik-UIÖеÄ©¶´CVE-2019-18935ºÍCVE-2017-11317¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/08/new-apt-hacking-group-targets-microsoft.html


5.CiscoÐÞ¸´Firepower FDM On-BoxÖеĴúÂëÖ´ÐЩ¶´


5.jpg


CiscoÐÞ¸´ÁËFirepowerÉ豸¹ÜÀíÆ÷(FDM)On-BoxÈí¼þÖеÄÈÎÒâ´úÂëÖ´ÐЩ¶´¡£FDM On-BoxÔÊÐí¹ÜÀíÔ±ÔÚûÓÐFMCµÈ¼¯ÖйÜÀíÆ÷µÄÇé¿öϹÜÀí·À»ðǽ £¬²¢ÌṩÕï¶Ï¹¦Ð§¡£¸Ã©¶´×·×ÙΪCVE-2021-1518 £¬ÊÇÓÉÓÚ¶ÔÌØ¶¨REST APIÃüÁîµÄÓû§ÊäÈëûÓнøÐгäʵµÄÇåÀíËùÖ¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿±êÉ豸µÄAPI×Óϵͳ·¢ËÍÌØÖÆµÄHTTPÇëÇóÀ´ÀûÓôË©¶´ £¬ÀֳɵÄÀûÓúó¿ÉÒÔÔÚϵͳÉÏÖ´ÐÐÈÎÒâ´úÂë £¬µ«Ç°ÌáÊǹ¥»÷ÕßÐèÒª»ñµÃµÍȨÏÞÓû§Æ¾¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120761/security/cisco-firepower-device-manager.html


6.CybereasonÐû²¼ÓйØDeadRinger¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß


6.jpg


CybereasonÐû²¼ÁËÓйØDeadRinger¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£³ÂËßÅû¶ÁË3ÆðÖ÷ÒªÕë¶ÔµçÐŹ«Ë¾µÄ¼äµý»î¶¯ £¬Í³³ÆÎªDeadRinger¡£Ñо¿ÈËÔ±·ÖÎö £¬Õâ3Æð¹¥»÷»î¶¯·Ö±ðÀ´×ÔSoft Cell APT¡¢Naikon APTºÍEmissary Panda£¨APT27£©¡£CybereasonÌåÏÖ £¬ÕâЩ¹¥»÷»î¶¯Õë¶ÔµçÐŹ«Ë¾µÄÄ¿µÄ¶¼ÊÇÊÕ¼¯Ãô¸ÐÐÅÏ¢ºÍÆÆ»µÉÌÒµ×ʲú£¨ÈçCDRÊý¾ÝÒÔ¼°Óò¿ØÖÆÆ÷µÈÍøÂç×é¼þ£©¡£´ËÍâ £¬ÕâЩ¹¥»÷»î¶¯¶¼ÓÐËùÖØµþ £¬µ«ÈÔÎÞ·¨Ã÷È·ËûÃÇÊǶÀÁ¢ÊÂÇ黹ÊǶ¼ÔÚͬһÖÐÑëС×éµÄÖ¸µ¼ÏÂÊÂÇé¡£


Ô­ÎÄÁ´½Ó£º

https://www.cybereason.com/blog/deadringer-exposing-chinese-threat-actors-targeting-major-telcos