SolarWinds¹©¸øÁ´¹¥»÷»î¶¯ÖдæÔÚеÄSUPERNOVAºóÃÅ£»¶à¹ú·¨Âɲ¿ÃŽáºÏµ·»ÙÈý¸öÌṩVPN·þÎñµÄÍøÕ¾?

°ä²¼¹¦·ò 2020-12-23

1.SolarWinds¹©¸øÁ´¹¥»÷»î¶¯ÖдæÔÚеÄSUPERNOVAºóÃÅ


1.jpg


×êÑÐÈËÔ±·¢ÏÖSolarWinds Orion¹©¸øÁ´¹¥»÷»î¶¯ÖдæÔÚеÄSUPERNOVAºóÃÅ £¬¿ÉÄÜÀ´×ÔÁíÒ»¸öºÚ¿Í×éÖ¯¡£SUPERNOVAÊÇÖ²ÈëOrionÍøÂçºÍÀûÓ÷¨Ê½¼à¶½Æ½Ì¨´úÂëÖеÄWeb shell £¬¹¥»÷Õß¿ÉÀûÓøöñÒâÈí¼þÔÚÍÆËã»úÉÏÔËÐÐËÁÒâ´úÂë¡£¸Ã¶ñÒâ´úÂë½öÔ̺¬Ò»ÖÖDynamicRun²½Öè £¬¿É½«²ÎÊý¶¯Ì¬±àÒëµ½ÄÚ´æÖеÄ.NET·¨Ê½¼¯ÖÐ £¬Òò¶ø²»»áÔÚÊÜϰȾÉ豸ÉÏÁôÏÂÈκκۼ£¡£¾­µ÷²é £¬SUPERNOVAûº±¼û×ÖÊðÃû £¬ÕâÓë×î³õ·¢ÏÖµÄSunBurst·ÖÆç £¬»òÐíÊôÓÚÁíÒ»ºÚ¿Í×éÖ¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/a-second-hacking-group-has-targeted-solarwinds-systems/


2.¶à¹ú·¨Âɲ¿ÃŽáºÏµ·»ÙÈý¸öÌṩVPN·þÎñµÄÍøÕ¾


2.jpg


À´×ÔÃÀ¹ú¡¢µÂ¹ú¡¢·¨¹ú¡¢ÈðÊ¿ºÍºÉÀ¼µÄ·¨ÂÉ»ú¹¹½áºÏ £¬³É¹¦µ·»ÙÁËÈý¸öVPN·þÎñµÄÍøÕ¾¡£Õâ´ÎÐж¯µÄ´úºÅΪNova £¬ÖØÒªÓÉÅ·ÖÞÐ̾¯×éÖ¯½øÐÐЭµ÷¡£±»²é·âµÄÈý¸öÍøÕ¾±ðÀëΪinsorg.org¡¢safe-inet.comºÍsafe-inet.net £¬¾ùÒÑ»îÔ¾ÁËÊ®¶àÄê £¬¿ÉÄÜÊôÓÚÒ»¸öÍŻÕâÐ©ÍøÕ¾¿ÉÌṩ¶à´ïÎå²ãµÄ´úÀíÍøÂç £¬Òò¶øÀÕË÷Èí¼þÍŻÐÅÓþ¿¨ÇÔÈ¡(Magecart)ÍÅ»ï¡¢ÍøÂç´¹µöºÚ¿ÍºÍ²Î¼ÓÕË»§ÊÕ¹ºµÄºÚ¿ÍʱʱÓÃÕâЩ·þÎñÆ÷À´°µ²ØÕæÊµÉí·Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/law-enforcement-take-down-three-bulletproof-vpn-providers/


3.¼ÓÃÜÇ®±ÒÂòÂôËùEXMOÔâµ½¹¥»÷ £¬Ëðʧ×Ü×ʲúµÄ5£¥


3.jpg


Ó¢¹ú¼ÓÃÜÇ®±ÒÂòÂôËùEXMO³ÆÆäÔâµ½ÁËÍøÂç¹¥»÷ £¬12ÔÂ21ÈÕºÚ¿ÍÔÚÈëÇÔìäÈÈÇ®°üºóµÁÈ¡ÁË´óÁ¿×ʲú¡£½ØÖÁĿǰ £¬EXMOÈÈÇ®°üÖв¿ÃŵÄBTC¡¢XRP¡¢ZEC¡¢USDTºÍETH¾ùÊܵ½ÁËÓ°Ïì¡£EXMOÔÚ·¢ÏÖ¹¥»÷ºóÁ¢¼´×ö³öÏìÓ¦ £¬ÔÝÍ£ËùÓÐÌá¿î²¢³Áв¿ÊðÈÈÇ®°ü¡£ÊÜÓ°ÏìµÄÈÈÇ®°ü×ʽðÕ¼×Ü×ʲúµÄ½ü5%¡£µ«ÀäÇ®°üÀïµÄËùÓÐÇ®±Ò¶¼Êǰ²È«µÄ¡£EXMO°µÊ¾ÊÜÓ°ÏìÓû§µÄËùÓÐËðʧ½«ÓÉÆäÆëÈ«Åâ³¥²¢Í˿


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/exmo-cryptocurrency-exchange-hacked-loses-5-percent-of-total-assets/


4.ºÚ¿ÍÔÚ°µÍøÐ¹Â¶27Íò¸öLedgerÓû§µÄÃô¸ÐÐÅÏ¢


4.jpg


ºÚ¿ÍÔÚ°µÍøÐ¹Â¶ÁË27Íò¸öLedgerÓû§µÄÃô¸ÐÐÅÏ¢¡£LedgerÊÇÓÃÓÚ´æ´¢¡¢ÖÎÀíºÍÏúÊÛ¼ÓÃÜÇ®±ÒµÄÓ²¼þ¼ÓÃÜÇ®±ÒÇ®°ü¡£Õâ´ÎºÚ¿Íй¶ÁËÁ½¸öTXTÎļþ £¬±ðÀëΪÔ̺¬¶©ÔÄÁËLedgerͨѶµÄ1075382¸öÓû§µÄµç×ÓÓʼþµØÖ·µÄ¡°All Emails (Subscription).txt¡± £¬ºÍÔ̺¬272853λ²É°ìÕßÐÕÃû¡¢ÓʼĵØÖ·ºÍµç»°ºÅÂëµÄ¡°Ledger Orders (Buyers) only.txt¡±¡£ÕâЩй¶Êý¾Ý»òÐíÊÇÓÉ2020Äê6ÔµÄÊý¾Ýй¶ÊÂÎñµ¼ÖµÄ £¬¿É±»ÓÃÀ´½øÐÐÍøÂç´¹µö¹¥»÷ £¬ÒÔÇÔÈ¡Óû§¼ÓÃÜÇ®±Ò¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/physical-addresses-of-270k-ledger-owners-leaked-on-hacker-forum/


5.Jumio°ä²¼2020Äê¼ÙÈÕÐÂÕË»§Ú²Æ­»î¶¯µÄ·ÖÎö»ã±¨


5.jpg


Jumio°ä²¼ÁË2020Äê¼ÙÈÕÐÂÕË»§Ú²Æ­»î¶¯µÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö £¬Óë2019ÄêµÄÏà±È £¬2020Äê»ùÓÚIDÑéÖ¤µÄÐÂÕÊ»§Ú²Æ­»î¶¯ÔÚÈ«ÇòÁìÓòÄÚͬ±È½µÂä23.2£¥¡£Í¬Ê± £¬»ùÓÚ×ÔÅÄÕÕµÄڲƭÂÊ£¨7.15£¥£©±È»ùÓÚIDµÄڲƭÂÊ£¨1.41£¥£©¸ß5±¶ £¬Õâ˵ÁËÈ»ÔÚ°µÍøÉÏÄܹ»Âòµ½µÄ±»µÁÉí·ÝÖ¤¼þµÄÊýÁ¿ÔÚ²»ÐÝÔö³¤¡£´Ë±í £¬µ±ÔÚÉí·ÝÑéÖ¤ÖÐʹÓÃSDKʱ £¬Ú²Æ­ÂÊÏÔÖøµÍÓÚÆäËûÇþ·(ÈçAPIºÍweb)¡£


Ô­ÎÄÁ´½Ó£º

https://go.jumio.com/2020-holiday-fraud-report


6.Cisco Talos°ä²¼2020ÄêËùÅû¶µÄ·ì϶µÄ»ØÊ׻㱨


6.jpg


Cisco Talos°ä²¼ÁË2020ÄêËùÅû¶µÄ·ì϶µÄ»ØÊ׻㱨¡£»ã±¨Ö¸³ö £¬ÔÚ2020Äê £¬Talos×ܹ²°ä²¼ÁË231·ÝÕ÷ѯ»ã±¨ £¬Éæ¼°277¸öCVE £¬ÁìÓòÔ̺¬²Ù×÷ϵͳ¡¢IoTÉ豸¡¢Microsoft Office²úÆ·¡¢ä¯ÀÀÆ÷ºÍPDFÔĶÁÆ÷µÈ¡£½ÏΪ³ÁÒªµÄÊÇ £¬ÖØÒªPDFÀûÓ÷¨Ê½£¨Ô̺¬Adobe PDF¡¢Foxit PDF¡¢NitroPDFºÍGoogle PDFium£©ÖдæÔÚ¶à¸ö·ì϶ £¬Intel¡¢NvidiaºÍAMDµÄͼÐÎÇý¶¯·¨Ê½ÖеĶà¸ö·ì϶ £¬Firefox¡¢ChromeºÍSafariµÈÖØÒªWebä¯ÀÀÆ÷ÖдæÔÚ¶à¸ö·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2020/12/vulnerability-discovery-2020.html