Nusenu·¢ÏÖδ֪×éÖ¯½Ù³ÖTor½üËÄ·ÖÖ®Ò»µÄ³ö¿Ú½Úµã£»Î¢Èí°ä²¼8Ô·ݰ²È«¸üР£¬½¨¸´2¸ö0dayÔÚÄÚµÄ120¸ö·ì϶

°ä²¼¹¦·ò 2020-08-12

1.Nusenu·¢ÏÖδ֪×éÖ¯½Ù³ÖTor½üËÄ·ÖÖ®Ò»µÄ³ö¿Ú½Úµã


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Nusenu·¢ÏÖ £¬×Ô2020Äê1ÔÂÒÔÀ´ £¬Ò»¸öδ֪µÄºÚ¿Í×éÖ¯Ò»ÏòÔÚÏòTorÍøÂçÔö³¤·þÎñÆ÷ £¬ÒÔ±ã¶ÔʹÓÃTorä¯ÀÀÆ÷½Ó¼û¼ÓÃÜÇ®±ÒÓйØÕ¾µãµÄÓû§½øÐÐSSL°þÀë £¬ÒÔÌáÒéÖÐÑëÈ˹¥»÷¡£Õâ´Î¹¥»÷»î¶¯µÄ¹æÄ£ÖØ´ó £¬Ö±µ½2020Äê5Ô £¬¸Ã×éÖ¯½Ù³ÖÁËTor½üËÄ·ÖÖ®Ò»µÄ³ö¿Ú½Úµã¡£Nusenu°µÊ¾ £¬¸Ã×éÖ¯µÄ¹¤×÷·½Ê½ÉÐδ¿ÉÖª £¬µ«ËûÃǵÄÖ÷ÕÅËÆºõÊÇΪÁË»ñÀû¡£ÔÚ2018ÄêÒ²²úÉú¹ýÀàËÆµÄ¹¥»÷ £¬µ«ºÚ¿ÍÕë¶ÔµÄ²»ÊÇTor³ö¿Ú½Úµã £¬¶øÊÇTor-to-web£¨Tor2Web£©ÉϵÄÃÅ»§ÍøÕ¾¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/a-mysterious-group-has-hijacked-tor-exit-nodes-to-perform-ssl-stripping-attacks/


2.Agent TeslaľÂíбäÌå¿É´Óä¯ÀÀÆ÷ºÍVPNÇÔÈ¡ÃÜÂë


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


SentinelOne×êÑÐÈËÔ±·¢ÏÖ £¬Agent TeslaľÂíµÄбäÌå¿É´Óä¯ÀÀÆ÷ºÍVPNÇÔÈ¡ÃÜÂë¡£¸ÃбäÌåÓµÓÐЧÓÚ´ÓÀûÓ÷¨Ê½ÖÐÇÔȡʹ´¦µÄÄ£¿é £¬Ê¹ËüÄܹ»ÔÚÊ¢ÐеÄWebä¯ÀÀÆ÷¡¢VPNÈí¼þÒÔ¼°FTPºÍµç×ÓÓʼþ¿Í»§¶ËµÄ×¢²á±íÒÔ¼°ÓйØÅäÖûòÖ§³ÖÎļþÖÐÌáȡƾ֤ £¬ÆäÓ°ÏìÁËGoogle Chrome¡¢Chromium¡¢Safari¡¢Brave¡¢FileZilla¡¢Mozilla Firefox¡¢Mozilla Thunderbird¡¢OpenVPNºÍOutlookµÅצÓá£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/upgraded-agent-tesla-malware-steals-passwords-from-browsers-vpns/


3.TwitterÈ«Çò·þÎñÁÙʱÖÐ¶Ï £¬Óû§ÎÞ·¨½Ó¹ÜÕÊ»§ÑéÖ¤Âë


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


TwitterÈ«Çò·þÎñÁÙʱÖÐ¶Ï £¬Óû§ÎÞ·¨Í¨¹ý¶ÌÐÅ»òµç»°½Ó¹ÜÕÊ»§ÑéÖ¤Âë £¬ÕâʹµÃÉèÖÃÁËË«³ÁÉí·ÝÑéÖ¤£¨2FA£©µÄTwiterÓû§ÎÞ·¨½øÐÐÉí·ÝÑéÖ¤¡£Í¨³£ £¬ÔÚTwitterÓû§Ê¹ÓÃ2FAµÇ¼Õ˺Åʱ»á×Ô¶¯ÌìÉú´ú±¸·ÝÂë £¬Í¬Ê±Óû§Ò²Äܹ»ÔÚÉèÖÃÖÐÊÖ¶¯ÌìÉú±¸·ÝÂë £¬ÕâÄܹ»¹©Óû§ÔÚûÓÐÊÖ»úÐźŻòͨ¹ý2FA·þÎñµÇ½ʧ°ÜʱʹÓᣵ«Õâ´ÎÊÂÎñÖÐ £¬TwitterÏÔʾµÄÊǶԲ»Æð £¬ÒªÇóʧ°Ü £¬ÇëÉÔºó³ÁÊÔ¡£Ä¿Ç° £¬¸ÃÊÂÎñÔÚµ÷²éÖС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/twitter-experiencing-issues-sending-account-verification-codes/


4.΢Èí°ä²¼8Ô·ݰ²È«¸üР£¬½¨¸´2¸ö0dayÔÚÄÚµÄ120¸ö·ì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


΢Èí°ä²¼ÁË8Ô·ݰ²È«¸üР£¬½¨¸´Ô̺¬2¸ö0dayÔÚÄÚµÄ120¸ö·ì϶ £¬ÆäÖÐ17¸ö·ì϶½ÏΪÑϳÁ¡£Õâ´Î½¨¸´µÄµÄµÚÒ»¸ö0dayΪ¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶£¨CVE-2020-1380£© £¬ÕâÊÇInternet Explorer 11ÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡£Î¢Èí°µÊ¾ £¬¸Ã·ì϶»òÒѱ»ÀûÓà £¬ºÜ¿ÉÄÜÔÚÍøÂç´¹µö»î¶¯Öб»·¢ÏÖ¡£µÚ¶þ¸ö0dayΪWindowsºýŪ·ì϶£¨CVE-2020-1464£© £¬¹¥»÷Õß¿ÉÀûÓÃÆä¶Ô¿ÉÖ´ÐÐÎļþ½øÐÐÊý×ÖÊðÃû £¬ÒÔºýŪÆäËû¹«Ë¾¡£Õâ´Î°²È«¸üÐÂΪ΢ÈíÓÐÊ·ÒÔÀ´°ä²¼µÄµÚÈý´óÖܶþ¸üР£¬Ç°Á½´Î±ðÀëΪ2020Äê6ÔµÄ129¸öºÍ2020Äê7ÔµÄ123¸ö¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2020-patch-tuesday-fixes-2-zero-days-120-flaws/


5.ºÚ¿Í¹¥»÷ÃÜЪ¸ùÖÝÁ¢´óѧÔÚÏßÉ̵ê £¬µÁÈ¡ÊýǧÈËÐÅÓþ¿¨ÐÅÏ¢


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÃÜЪ¸ùÖÝÁ¢´óѧ£¨MSU£©°ä·¢ £¬¹¥»÷ÕßÏòÆäÔÚÏßÉ̵êshop.msu.edu×¢ÈëÁËÓÃÀ´ÍøÂçºÍÇÔÈ¡Óû§Ö§¸¶¿¨ÐÅÏ¢µÄ¶ñÒâ¾ç±¾ £¬ÇÔÈ¡ÁËÔ¼2600λÓû§µÄÐÅÓþ¿¨ºÍÓ×ÎÒÐÅÏ¢¡£MSUÔÚÒ»·ÝÉêÃ÷ÖаµÊ¾ £¬ºÚ¿ÍÊÇÔÚ2019Äê10ÔÂ19ÈÕÖÁ2020Äê6ÔÂ26ÈÕÖ®¼äÌáÒéµÄ¹¥»÷ £¬ÇÔÈ¡ÁËÓû§µÄÐÕÃû¡¢µØÖ·ºÍÐÅÓþ¿¨ºÅ £¬µ«ÊÇûÓÐÈκÎÉç»á±£Ïպű»µÁ¡£¸Ã´óѧ»¹°µÊ¾ £¬Æä°²È«ÍŶÓÒѽ¨¸´ÁËÔÚÏßÉ̵êµÄÖеķì϶ £¬²¢ÇÒÔÚÓë·¨Âɲ¿ÃźÏ×÷ £¬¶ÔÕâ´ÎÊÂÎñ·¢Õ¹Á˵÷²é¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/michigan-state-university-discloses-credit-card-theft-incident/


6.ºÚ¿Í¹¥»÷ÑÇÌØÀ¼´ó¹Ç¿ÆÒ½Ôº £¬ÇÔÈ¡³¬¹ý3.5 GBÊý¾Ý


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ºÚ¿Í¹¥»÷ÑÇÌØÀ¼´ó¹Ç¿ÆÒ½ÔºOredAtlanta £¬²¢Ðû³ÆÒѾ­ÇÔÈ¡³¬¹ý3.5 GBÊý¾Ý¡£Õâ´Îй¶µÄÊý¾ÝÖдó²¿ÃÅÊǹØÓÚ×â½ðºÍÒµÎñ·½ÃæµÄÐÅÏ¢ £¬µ«ÊÇÒ²Óл¼Õß¾ßÌ岡Àú £¬Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·ºÍÁªÏµ·½Ê½¡¢Õï¶Ï¡¢ÊÖÊõϸ½Ú¡¢³¢ÊÔÊҲ鳭¡¢ÐĵçͼºÍ±£ÏÕÐÅÏ¢¡£Æ¾¾ÝתÖü´æµµÖеŦ·ò´Á £¬Îļþ¿ÉÄÜÓÚ7ÔÂ11ÈÕ¾ÍÒѱ»ÇÔÌý¡£´Ë±í £¬¼ÓÀû¸£ÄáÑÇÖݵÄÁ½¸öÒ½ÁÆ»ú¹¹Ò²Ôâµ½Á˹¥»÷ £¬µ«Ä¿Ç°»¹Ã»ÓÐÈκÎÓйع¥»÷µÄ֪ͨ»òÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/three-more-medical-practices-hit-by-ransomware/