2019ÄêÊý¾Ýй¶µ÷²é»ã±¨£»UCä¯ÀÀÆ÷佨¸´µÄµØÖ·À¸ºýŪ·ì϶£»2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼й¶

°ä²¼¹¦·ò 2019-05-09
1¡¢Verizon°ä²¼2019ÄêÊý¾Ýй¶µ÷²é»ã±¨

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
Verizon°ä²¼2019ÄêÊý¾Ýй¶µ÷²é»ã±¨£¨DBIR£© £¬¸Ã»ã±¨·ÖÎöÁË86¸ö¹ú¶È²úÉúµÄ41000¶àÆðÍøÂ簲ȫÊÂÎñºÍ2000¶àÆðÊý¾Ýй¶ÊÂÎñ¡£¸Ã»ã±¨Ö¸³ö £¬´Ó2018ÄêÆðÍ·ÔÆ´æ´¢ÅäÖÃÃýÎó¡¢BECºÍ֪ʶ²úȨ͵ÇÔ¶¼´¦ÓÚÉÏÉýÇ÷Ïò¡£ÒÔóÒ×¼äµý»î¶¯Îª¶¯»úµÄÍøÂç¹¥»÷ÓÐËùÔö³¤ £¬ÔÚ´ÓǰµÄ12¸öÔÂÀï £¬ÓÐ1/4µÄÍøÂçÈëÇÖÓë¿úËźÍÊý¾ÝÉøÂ©ÓйØ¡£×ÜÌå¶øÑÔ´óÎÞÊýÍøÂç¹¥»÷¶¼ÊÇÒÔ¾­¼ÃÀûÒæ×÷ΪÇý¶¯¡£²»ÐÒµÄÊÇ £¬ÓÐÒ»°ëµÄÆóÒµ±ØÒªÆÆ·ÑÊýÔÂÉõÖÁ¸ü³¤µÄ¹¦·òÀ´·¢ÏÖÈëÇÖÐÐΪ¡£

Ô­ÎÄÁ´½Ó£ºhttps://enterprise.verizon.com/resources/reports/2019-data-breach-investigations-report.pdf

2¡¢UCä¯ÀÀÆ÷±»ÆØ´æÔÚ佨¸´µÄµØÖ·À¸ºýŪ·ì϶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
°²È«×êÑÐÈËÔ±Arif Khan·¢ÏÖUCä¯ÀÀÆ÷´æÔÚÒ»¸öÉÐ佨¸´µÄµØÖ·À¸ºýŪ·ì϶¡£UCä¯ÀÀÆ÷Êǰ¢Àï°Í°ÍÆìϵÄUCWeb¿ª·¢µÄä¯ÀÀÆ÷ £¬ÔÚÖйúºÍÓ¡¶Å×µÓг¬¹ý5ÒÚÓû§¡£¸Ã·ì϶´æÔÚÓÚä¯ÀÀÆ÷µÄÓû§½çÃæ´¦ÖÃÌØÊâÄÚÖÃÖ°ÄÜ£¨¸ÃÖ°ÄÜÖ¼ÔÚ¸ÄÉÆÓû§µÄGoogleËÑË÷ÂÄÀú£©µÄ·½Ê½ £¬¿ÉÔÊÐí¹¥»÷Õß½ÚÔìµØÖ·À¸ÖÐÏÔʾµÄURL×Ö·û´® £¬ºýŪÓû§½Ó¼û¶ñÒâÍøÕ¾¡£¸Ã·ì϶ÉÐδ·ÖÅäCVE±àºÅ £¬UCä¯ÀÀÆ÷µÄ×îа汾12.11.2.1184ºÍUC Miniä¯ÀÀÆ÷µÄ×îа汾12.10.1.1192¾ùÊÜÓ°Ïì¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/05/uc-browser-url-spoofing.html

3¡¢Freedom MobileÒâ±íй¶½ü500ÍòÌõÓû§¼Í¼

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
¼ÓÄôóµçÐŹ«Ë¾Freedom MobileµÄÒ»¸öÔ̺¬¿Í»§Êý¾ÝµÄElasticSearchÊý¾Ý¿âÒòÅäÖÃÃýÎóÔÚÍøÉ϶³ö £¬µ¼Ö½ü500ÍòÌõ¿Í»§¼Í¼й¶¡£Æ¾¾Ý°²È«×êÑÐÔ±Noam RotemºÍRan LocarµÄ·¢ÏÖ £¬¸ÃÊý¾Ý¿âÊôÓÚFreedom MobileµÄµÚÈý·½·þÎñÌṩÉÌApptium¡£¸Ã¹«Ë¾½²»°È˰µÊ¾ £¬Ð¹Â¶ÊÂÎñÓ°ÏìÁË3ÔÂ25ÈÕÖÁ4ÔÂ15ÈÕÆÚ¼äÔÚ17¸öFreedom Mobile½»Ò×Ìü¿ªÉè»ò¸ü¸ÄÕË»§µÄÓû§ £¬Ô¼ÓÐ1.5ÍòÓû§Êܵ½Ó°Ï졣й¶µÄÐÅÏ¢²»½öÔ̺¬Óû§µÄÐÕÃû¡¢ÓÊÏäµÈÓ×ÎÒÐÅÏ¢ £¬»¹Ô̺¬ÐÅÓþ¿¨ºÅµÈÖ§¸¶ÐÅÏ¢¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/freedom-mobile-exposed-almost-5-million-customer-records-due-to-a-misconfigured-database-fddd4855

4¡¢ºº±¤Íõ¶ùͯÉ̵êÒâ±íй¶½ü4ÍòÌõÓû§¼Í¼

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
°²È«×êÑÐÔ±Bob Diachenko·¢ÏÖºº±¤ÍõµÄÒ»¸öרΪ¶ùͯ·þÎñµÄ·¨¹úÍøÉÏÉ̵êÒâ±íй¶ÁË37900Ìõ¿Í»§¼Í¼¡£ÕâЩ¼Í¼Ô̺¬ÔÚÒ»¸öδÊܱ£»¤µÄElasticsearch¼¯ÈºÖÐ £¬¸ÃÊý¾Ý¿âÖÁÉÙ´Ó4ÔÂ24ÈÕÆðÍ·ÔÚÍøÉ϶³ö¡£Ð¹Â¶µÄÐÅÏ¢²»½öÔ̺¬Óû§µÄÐÕÃû¡¢µç»°µÈPIIÐÅÏ¢ £¬»¹Ô̺¬²¿ÃÅÔ±¹¤µÄÓÊÏ䵨ַ¡¢CRMºó¶ËÈÕÖ¾µÈÐÅÏ¢¡£Î´Êܱ£»¤µÄElasticSearchÊý¾Ý¿âÔÚ³ÉΪ³£Ì¬¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/burger-kings-online-store-for-kids-exposes-customers-info/

5¡¢AWSÉÏδÊܱ£»¤µÄMongoDBй¶³¬¹ý2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
°²È«×êÑÐÔ±Bob DiachenkoʹÓÃShodan·¢´Ë¿ÌAmazon AWSÉÏÍйܵÄÒ»¸ö¿É¹«¿ª½Ó¼ûµÄMongoDBÊý¾Ý¿â £¬¸ÃÊý¾Ý¿âй¶Á˳¬¹ý2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢ÓÊÏä¡¢ÊÖ»úºÅÂë¡¢Ö°ÒµºÍнˮµÈPII £¬µ«DiachenkoûÓз¢ÏÖ¸ÃÊý¾Ý¿âµÄ¹éÊô×éÖ¯¡£¸ÃÊý¾Ý¿âÓÚ4ÔÂ23ÈÕÆðÍ·ÔÚÍøÉ϶³ö¡£Diachenko֪ͨÁËÓ¡¶ÈCERT £¬µ«¸ÃÊý¾Ý¿â²¢Î´Êܵ½±£»¤ £¬Ö±µ½5ÔÂ8ÈÕ·¸×ïÍÅ»ïUnistellarɾ³ýÁ˸ÃÊý¾Ý¿â²¢ÁôÏÂÁËÁªÏµ·½Ê½¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/over-275-million-records-exposed-by-unsecured-mongodb-database/

6¡¢°Í¶ûµÄĦÊÐÕþÌüºÍ²¨ÌØÏؾùÔâÀÕË÷Èí¼þ¹¥»÷

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 
µÂ¿ËÈøË¹Öݲ¨ÌØÏؼ°ÂíÀïÀ¼ÖݰͶûµÄĦÊÐÕþÌü¾ùÔâÀÕË÷Èí¼þ¹¥»÷¡£Æ¾¾Ý°Í¶ûµÄĦÊг¤Jack YoungµÄ¹Ù·½ÉêÃ÷ £¬¸ÃÊеÄÖ÷Ìâ·þÎñ£¨¾¯Ô±¡¢Ïû·À¡¢EMSºÍ311£©ÈÔÔÚÔË×÷ £¬µ«ÒÑÈ·¶¨³ÇÊÐÍøÂçϰȾÁËÀÕË÷²¡¶¾ £¬³öÓÚÔ¤·À¸ÃÊÐÒѾ­¹Ø¹ØÁË´ó²¿ÃÅ·þÎñÆ÷¡£¶øÆ¾¾ÝNewsChannel 10µÄ˵·¨ £¬²¨ÌØÏØÔÚ4ÔÂ22ÈÕÔâµ½¶ñÒâÈí¼þ¹¥»÷ºó £¬ÒѾ­Éè·¨½«²¿ÃÅÍÆËã»úϵͳ³ÁÐÂÉÏÏß¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/local-authorities-in-texas-and-maryland-hit-by-ransomware/