ºÚ¿ÍÈëÇÖ2gether·þÎñÆ÷£¬ÇÔÈ¡¼ÛÖµ120ÍòÅ·ÔªµÄ¼ÓÃÜÇ®±Ò£»ºÚ¿Íй¶900¶à¸öÆóÒµVPN·þÎñÆ÷µÄÐÅÏ¢ºÍÃ÷ÎÄÃÜÂë

Ðû²¼Ê±¼ä 2020-08-05

1.ºÚ¿ÍÈëÇÖ2gether·þÎñÆ÷£¬ÇÔÈ¡¼ÛÖµ120ÍòÅ·ÔªµÄ¼ÓÃÜÇ®±Ò



×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


7ÔÂ31ÈÕÏÂÖç6µã£¬ºÚ¿ÍÈëÇÖÁË2getherµÄ·þÎñÆ÷£¬²¢ÇÔÈ¡Á˼ÛÖµ118.3ÍòÅ·ÔªµÄ¼ÓÃÜÇ®±Ò£¬Õ¼×Ü×ʽðµÄ26.79£¥¡£2together CEOÌåÏÖ£¬´Ë´Î¹¥»÷²¢Î´Ó°ÏìͨÓÃÇ®°üºÍÅ·ÔªÕÊ»§£¬²¢ÇÒºÚ¿ÍûÓÐÇÔÈ¡Óû§ÐÅÓÿ¨µÄ²ÆÎñÐÅÏ¢¡£ÏÖÔÚ£¬¸Ã¹«Ë¾²¢Î´Ðû²¼¹¥»÷µÄÊÖÒÕϸ½Ú£¬Ö»ÊÇÌåÏÖÁËÏêϸÊÓ²ìÈÔÔÚ¾ÙÐÐÖС£¾Ý¹«Ë¾¸ß¹Ü³Æ£¬¸Ã¹«Ë¾Ã»ÓÐ×ã¹»µÄ×ʽðÀ´ÍË»¹ÆäÓû§£¬²¢ÇÒÕýÊÔͼͨ¹ýͶ×ʹ«Ë¾µÄ×¢×ʾÙÐе÷½â¡£¿ÉÊDz¢Î´Àֳɣ¬Òò´ËÖ»ÄÜÏòÓû§ÌṩÆä±»µÁµÄ¼ÓÃÜÇ®±ÒµÈÖµµÄÍâµØ2GT´ú±Ò¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/106726/hacking/2gether-hacked.html


2.°Í»ù˹̹ÐÂÎÅÆµµÀDawnÔâ¹¥»÷£¬¹ã¸æÊ±¼ä²¥·ÅÓ¡¶È¹úÆì


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


8ÔÂ2ÈÕÐÇÆÚÈÕÏÂÖç3:30×óÓÒ£¬°Í»ù˹̹Ö÷ÒªÐÂÎÅÆµµÀÖ®Ò»DawnÔâµ½ºÚ¿Í¹¥»÷£¬¹ã¸æÐÝϢʱ´úÔÚÆÁÄ»Éϲ¥·ÅÓ¡¶È¹úÆìºÍ×ÔÁ¦¼ÍÄîÈÕ¿ìÀÖµÄ×ÖÑù¡£DawnÌåÏÖ£¬Ôâµ½¹¥»÷ʱËûÃÇÏñÍù³£Ò»Ñù²¥·ÅÐÂÎÅºÍ¹ã¸æ¡£ÏÖÔÚ£¬ Ïà¹Ø»ú¹¹ÕýÔڶԴ˴ι¥»÷Õö¿ªÊӲ졣¾ÝϤ£¬Õâ²¢²»ÊǵÚÒ»´Î±¬·¢ºÚ¿Í¹¥»÷µçÊÓÆµµÀÊÂÎñ£¬ÒÔÉ«ÁеÄ˽ÈËÐÂÎÅÆµµÀµÚ2ƵµÀºÍµÚ10ƵµÀµÄ¾ÍÔøÔâµ½¹ýÈëÇÖ£¬ºÚ¿ÍÖÐÖ¹Á˽ÚÄ¿²¢²¥·ÅÄÂ˹ÁÖµÄÆíµ»Éù¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/pakistani-news-channel-transmission-hacked-indian-flag/


3.ºÚ¿Íй¶900¶à¸öÆóÒµVPN·þÎñÆ÷µÄÐÅÏ¢ºÍÃ÷ÎÄÃÜÂë


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ºÚ¿ÍÔÚ°µÍøÉÏÐû²¼ÁË900¶à¸öPulse Secure VPNÆóÒµ·þÎñÆ÷µÄÐÅÏ¢ºÍÃ÷ÎÄÃÜÂë¡£´Ë´Îй¶ÐÅÏ¢°üÀ¨·þÎñÆ÷µÄIPµØµã¡¢¹Ì¼þ°æ±¾ºÅ¡¢Ã¿¸ö·þÎñÆ÷µÄSSHÃÜÔ¿¡¢ËùÓÐÍâµØÓû§¼°ÆäÃÜÂë¹þÏ£µÄÁÐ±í¡¢ÖÎÀíÔ±ÕÊ»§ÏêϸÐÅÏ¢¡¢×î½üµÄVPNµÇ¼Ãû£¨°üÀ¨Óû§ÃûºÍÃ÷ÎÄÃÜÂ룩ÒÔ¼°VPN»á»°cookie¡£ÍþвÇ鱨ÆÊÎö¹«Ë¾Bank Security·¢Ã÷ÁбíÖеķþÎñÆ÷¶¼ÔËÐÐÁ˱£´æCVE-2019-11510Îó²î°æ±¾µÄ¹Ì¼þ¡£Òò´Ë£¬ÆäÒÔΪºÚ¿ÍÊÇɨÃèÁË·þÎñÆ÷µÄÕû¸öInternet IPv4µØµã¿Õ¼ä£¬²¢Ê¹ÓøÃÎó²îÀ´»á¼ûϵͳ£¬×ª´¢·þÎñÆ÷ÏêϸÐÅÏ¢²¢½«ËùÓÐÐÅÏ¢ÍøÂçµ½Ò»ÆäÖÐÑë´æ´¢¿âÖС£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-leaks-passwords-for-900-enterprise-vpn-servers/


4.Ò»¼üͨӦÓÃZello±¬·¢Êý¾Ýй¶£¬ÒÑÖØÖÃËùÓÐÓû§ÃÜÂë


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Ò»¼üͨӦÓÃZello±¬·¢Êý¾Ýй¶£¬ÆäÒÑÖØÖÃËùÓÐÓû§ÃÜÂë¡£ZelloÖ¸³ö£¬ËûÃÇÓÚ2020Äê7ÔÂ8ÈÕÔÚÆäÖÐһ̨·þÎñÆ÷ÉÏ·¢Ã÷Á˴˴ι¥»÷£¬Í¨¹ý½øÒ»³ÌÐò²é£¬·¢Ã÷δ¾­ÊÚȨµÄºÚ¿Í¿ÉÄÜÒѾ­»á¼ûÁËÆäÓû§ÔÚÆäZelloÕÊ»§ÉÏʹÓõĵç×ÓÓʼþµØµãºÍ¹þÏ£ÃÜÂë¡£¿ÉÊÇ£¬´Ë´Îй¶ÊÂÎñ²¢²»»áÓ°ÏìZello WorkºÍZello for First RespondersÓû§¡£ºÚ¿Í¿ÉʹÓÃй¶ÐÅÏ¢¾ÙÐÐÆ¾Ö¤Ìî³ä¹¥»÷£¬²¢µÇÈÎÃü»§ÆäËûÕ¾µãµÄÕË»§¡£Òò´Ë£¬ZelloÒÑÇ¿ÖÆÖØÖÃÓû§ÃÜÂ룬²¢½¨ÒéÓû§¸ü¸ÄÆäËûÕ¾µãÉÏÏàͬµÄÃÜÂë¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/zello-resets-all-user-passwords-after-data-breach/


5.ÈýÁâÐû²¼¶à¸ö²úÆ·µÄ¸üУ¬»¹ÌṩÁËÔÝʱ½â¾ö¼Æ»®


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÈýÁâµç»úµÄÊýÊ®ÖÖ¹¤³§×Ô¶¯»¯²úÆ·±£´æÈý¸öÎó²î£¬ÕâЩÎó²î¿É±»Ê¹ÓþÙÐÐÌáȨ¡¢í§Òâ´úÂëÖ´ÐкÍDoS¹¥»÷¡£ÏÖÔÚ£¬ÈýÁâÒѾ­ÎªÊÜÓ°ÏìµÄ²úÆ·Ðû²¼Á˲¹¶¡£¬»¹ÎªÆäÓà²úÆ·ºÍÎÞ·¨Á¬Ã¦×°Öò¹¶¡³ÌÐòµÄ¿Í»§ÌṩÁË»º½â²½·¥¡£µÚÒ»¸öÎó²îΪȨÏÞÎÊÌ⣨CVE-2020-14496£©£¬ËüÔÊÐíºÎÓû§ÔÚÌØ¶¨Ä¿Â¼Ð´ÈëÎļþ£¬ÓµÓÐдȨÏ޵Ĺ¥»÷Õß¿ÉÒÔÁýÕÖ´ËĿ¼ÖеÄÕýµ±Îļþ¡£µÚ¶þ¸öÊÇzipÎó²î£¨CVE-2020-14523£©£¬²úƷʹÓÃzip¹éµµÎļþÀ´´æ´¢ÉèÖã¬ÌáÈ¡¶ñÒâzip¹éµµÎļþ¿ÉÄܵ¼Ö½«ÎļþдÈëÄ¿µÄĿ¼֮ÍâµÄí§ÒâλÖᣵÚÈý¸öÎó²î±»×·×ÙΪCVE-2020-14521£¬¶ÔijЩWindows apiµÄŲÓÃÖÐʹÓÃÁËδÒýÓõÄ·¾¶£¬¿É±»Ê¹ÓüÓÔØ¶ñÒâ¿ÉÖ´ÐÐÎļþ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/hackers-could-target-organizations-flaws-mitsubishi-factory-automation-products


6.Ñо¿Ö°Ô±·¢Ã÷MeetupµÄÎó²î£¬¿Éµ¼ÖÂÓû§×ʽð±»ÇÔÈ¡


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


CheckmarxÑо¿Ö°Ô±·¢Ã÷Meetupƽ̨±£´æÑÏÖØµÄÎó²î£¬¿Éµ¼ÖÂÓû§×ʽð±»ÇÔÈ¡¡£µÚÒ»¸öΪ´æ´¢µÄXSSÎó²î£¬Ö»ÐèÔÚÌÖÂÛÇøµÄÐÂÎÅÖÐÐû²¼JavaScript´úÂë¾Í¿ÉÒÔ¾ÙÐÐÌáȨ¡£µÚ¶þ¸öÎó²îΪÉèÖò˵¥µÄ¸¶¿î²¿·ÖÖеÄCSRF£¬¿ÉÓëµÚÒ»¸öXSSÎó²îÍŽáʹÓ㬸ü¸ÄÓû§ÔÚMeetupÉèÖÃÎļþÖеÄPayPalµØµã¡£¹¥»÷ÕßÖ»ÐèÔÚÌÖÂÛÇøÖÐÐû²¼Ò»ÌõÐÂÎÅ£¬²¢Ö¸ÏòÆä·þÎñÆ÷ÉÏʹÓÃCSRFÎÊÌâµÄÎļþ±ã¿ÉÒÔʹÓøÃÎó²î¡£³ýÁËÕâÁ½¸öÎó²îÍ⣬Checkmarx»¹·¢Ã÷ÁËÆäËûÇå¾²Òþ»¼£¬api.meetup.comµÄ³ÉÔ±¶ËµãÖÐȱ·¦×ÊÔ´ºÍËÙÂÊÏÞÖÆ£¬¿ÉÒÔʹÓÃÐòÁÐÕûÊýÀ´Ê¹ÓôËö¾Ùö¾ÙMeetupÓû§¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-could-have-stolen-paypal-funds-from-meetup-users/