Nusenu·¢Ã÷δ֪×éÖ¯Ð®ÖÆTor½üËÄ·ÖÖ®Ò»µÄ³ö¿Ú½Úµã£»Î¢ÈíÐû²¼8Ô·ÝÇå¾²¸üУ¬ÐÞ¸´2¸ö0dayÔÚÄÚµÄ120¸öÎó²î
Ðû²¼Ê±¼ä 2020-08-121.Nusenu·¢Ã÷δ֪×éÖ¯Ð®ÖÆTor½üËÄ·ÖÖ®Ò»µÄ³ö¿Ú½Úµã
Nusenu·¢Ã÷£¬×Ô2020Äê1ÔÂÒÔÀ´£¬Ò»¸öδ֪µÄºÚ¿Í×éÖ¯Ò»Ö±ÔÚÏòTorÍøÂçÌí¼Ó·þÎñÆ÷£¬ÒÔ±ã¶ÔʹÓÃTorä¯ÀÀÆ÷»á¼û¼ÓÃÜÇ®±ÒÏà¹ØÕ¾µãµÄÓû§¾ÙÐÐSSL°þÀ룬ÒÔÌᳫÖÐÐÄÈ˹¥»÷¡£´Ë´Î¹¥»÷Ô˶¯µÄ¹æÄ£ÖØ´ó£¬Ö±µ½2020Äê5Ô£¬¸Ã×éÖ¯Ð®ÖÆÁËTor½üËÄ·ÖÖ®Ò»µÄ³ö¿Ú½Úµã¡£NusenuÌåÏÖ£¬¸Ã×éÖ¯µÄÊÂÇé·½·¨ÉÐδ¿ÉÖª£¬µ«ËûÃǵÄÄ¿µÄËÆºõÊÇΪÁË׬Ǯ¡£ÔÚ2018ÄêÒ²±¬·¢¹ýÀàËÆµÄ¹¥»÷£¬µ«ºÚ¿ÍÕë¶ÔµÄ²»ÊÇTor³ö¿Ú½Úµã£¬¶øÊÇTor-to-web£¨Tor2Web£©ÉϵÄÃÅ»§ÍøÕ¾¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/a-mysterious-group-has-hijacked-tor-exit-nodes-to-perform-ssl-stripping-attacks/
2.Agent TeslaľÂíбäÌå¿É´Óä¯ÀÀÆ÷ºÍVPNÇÔÈ¡ÃÜÂë
SentinelOneÑо¿Ö°Ô±·¢Ã÷£¬Agent TeslaľÂíµÄбäÌå¿É´Óä¯ÀÀÆ÷ºÍVPNÇÔÈ¡ÃÜÂë¡£¸ÃбäÌå¾ßÓÐÓÃÓÚ´ÓÓ¦ÓóÌÐòÖÐÇÔȡƾ֤µÄÄ£¿é£¬Ê¹Ëü¿ÉÒÔÔÚÊ¢ÐеÄWebä¯ÀÀÆ÷¡¢VPNÈí¼þÒÔ¼°FTPºÍµç×ÓÓʼþ¿Í»§¶ËµÄ×¢²á±íÒÔ¼°Ïà¹ØÉèÖûòÖ§³ÖÎļþÖÐÌáȡƾ֤£¬ÆäÓ°ÏìÁËGoogle Chrome¡¢Chromium¡¢Safari¡¢Brave¡¢FileZilla¡¢Mozilla Firefox¡¢Mozilla Thunderbird¡¢OpenVPNºÍOutlookµÈÓ¦Óá£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/upgraded-agent-tesla-malware-steals-passwords-from-browsers-vpns/
3.TwitterÈ«Çò·þÎñÔÝʱÖÐÖ¹£¬Óû§ÎÞ·¨ÎüÊÕÕÊ»§ÑéÖ¤Âë
TwitterÈ«Çò·þÎñÔÝʱÖÐÖ¹£¬Óû§ÎÞ·¨Í¨¹ý¶ÌÐÅ»òµç»°ÎüÊÕÕÊ»§ÑéÖ¤Â룬ÕâʹµÃÉèÖÃÁËË«ÖØÉí·ÝÑéÖ¤£¨2FA£©µÄTwiterÓû§ÎÞ·¨¾ÙÐÐÉí·ÝÑéÖ¤¡£Í¨³££¬ÔÚTwitterÓû§Ê¹ÓÃ2FAµÇ¼Õ˺Åʱ»á×Ô¶¯ÌìÉú´ú±¸·ÝÂ룬ͬʱÓû§Ò²¿ÉÒÔÔÚÉèÖÃÖÐÊÖ¶¯ÌìÉú±¸·ÝÂ룬Õâ¿ÉÒÔ¹©Óû§ÔÚûÓÐÊÖ»úÐźŻòͨ¹ý2FA·þÎñÉϰ¶Ê§°ÜʱʹÓᣵ«´Ë´ÎÊÂÎñÖУ¬TwitterÏÔʾµÄÊǶԲ»Æð£¬ÇëÇóʧ°Ü£¬ÇëÉÔºóÖØÊÔ¡£ÏÖÔÚ£¬¸ÃÊÂÎñÕýÔÚÊÓ²ìÖС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/technology/twitter-experiencing-issues-sending-account-verification-codes/
4.΢ÈíÐû²¼8Ô·ÝÇå¾²¸üУ¬ÐÞ¸´2¸ö0dayÔÚÄÚµÄ120¸öÎó²î
΢ÈíÐû²¼ÁË8Ô·ÝÇå¾²¸üУ¬ÐÞ¸´°üÀ¨2¸ö0dayÔÚÄÚµÄ120¸öÎó²î£¬ÆäÖÐ17¸öÎó²î½ÏΪÑÏÖØ¡£´Ë´ÎÐÞ¸´µÄµÄµÚÒ»¸ö0dayΪ¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î£¨CVE-2020-1380£©£¬ÕâÊÇInternet Explorer 11ÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£Î¢ÈíÌåÏÖ£¬¸ÃÎó²î»òÒѱ»Ê¹Ó㬺ܿÉÄÜÔÚÍøÂç´¹ÂÚÔ˶¯Öб»·¢Ã÷¡£µÚ¶þ¸ö0dayΪWindowsÓÕÆÎó²î£¨CVE-2020-1464£©£¬¹¥»÷Õß¿ÉʹÓÃÆä¶Ô¿ÉÖ´ÐÐÎļþ¾ÙÐÐÊý×ÖÊðÃû£¬ÒÔÓÕÆÆäËû¹«Ë¾¡£´Ë´ÎÇå¾²¸üÐÂΪ΢ÈíÓÐÊ·ÒÔÀ´Ðû²¼µÄµÚÈý´óÖܶþ¸üУ¬Ç°Á½´Î»®·ÖΪ2020Äê6ÔµÄ129¸öºÍ2020Äê7ÔµÄ123¸ö¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2020-patch-tuesday-fixes-2-zero-days-120-flaws/
5.ºÚ¿Í¹¥»÷ÃÜЪ¸ùÖÝÁ¢´óѧÔÚÏßÊÐËÁ£¬ÍµÈ¡ÊýǧÈËÐÅÓÿ¨ÐÅÏ¢
ÃÜЪ¸ùÖÝÁ¢´óѧ£¨MSU£©Ðû²¼£¬¹¥»÷ÕßÏòÆäÔÚÏßÊÐËÁshop.msu.edu×¢ÈëÁËÓÃÀ´ÍøÂçºÍÇÔÈ¡Óû§Ö§¸¶¿¨ÐÅÏ¢µÄ¶ñÒâ¾ç±¾£¬ÇÔÈ¡ÁËÔ¼2600λÓû§µÄÐÅÓÿ¨ºÍСÎÒ˽¼ÒÐÅÏ¢¡£MSUÔÚÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬ºÚ¿ÍÊÇÔÚ2019Äê10ÔÂ19ÈÕÖÁ2020Äê6ÔÂ26ÈÕÖ®¼äÌᳫµÄ¹¥»÷£¬ÇÔÈ¡ÁËÓû§µÄÐÕÃû¡¢µØµãºÍÐÅÓÿ¨ºÅ£¬¿ÉÊÇûÓÐÈκÎÉç»á°ü¹ÜºÅ±»µÁ¡£¸Ã´óѧ»¹ÌåÏÖ£¬ÆäÇå¾²ÍŶÓÒÑÐÞ¸´ÁËÔÚÏßÊÐËÁµÄÖеÄÎó²î£¬²¢ÇÒÕýÔÚÓëÖ´·¨²¿·ÖÏàÖú£¬¶Ô´Ë´ÎÊÂÎñÕö¿ªÁËÊӲ졣
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/michigan-state-university-discloses-credit-card-theft-incident/
6.ºÚ¿Í¹¥»÷ÑÇÌØÀ¼´ó¹Ç¿ÆÒ½Ôº£¬ÇÔÈ¡Áè¼Ý3.5 GBÊý¾Ý
ºÚ¿Í¹¥»÷ÑÇÌØÀ¼´ó¹Ç¿ÆÒ½ÔºOredAtlanta£¬²¢Éù³ÆÒѾÇÔÈ¡Áè¼Ý3.5 GBÊý¾Ý¡£´Ë´Îй¶µÄÊý¾ÝÖд󲿷ÖÊǹØÓÚ×â½ðºÍÓªÒµ·½ÃæµÄÐÅÏ¢£¬¿ÉÊÇÒ²Óл¼ÕßÏêϸ²¡Àú£¬°üÀ¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µØµãºÍÁªÏµ·½·¨¡¢Õï¶Ï¡¢ÊÖÊõϸ½Ú¡¢ÊµÑéÊÒ¼ì²é¡¢ÐĵçͼºÍ°ü¹ÜÐÅÏ¢¡£Æ¾Ö¤×ªÖü´æµµÖеÄʱ¼ä´Á£¬Îļþ¿ÉÄÜÓÚ7ÔÂ11ÈÕ¾ÍÒѱ»ÇÔÌý¡£±ðµÄ£¬¼ÓÀû¸£ÄáÑÇÖݵÄÁ½¸öÒ½ÁÆ»ú¹¹Ò²Ôâµ½Á˹¥»÷£¬µ«ÏÖÔÚ»¹Ã»ÓÐÈκÎÓйع¥»÷µÄ֪ͨ»òÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/three-more-medical-practices-hit-by-ransomware/


¾©¹«Íø°²±¸11010802024551ºÅ