Area1»ã±¨¶íÂÞ˹ͨ¹ýEximÖзì϶×ÌÈÅÃÀ¹ú´óÑ¡£¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»Naval Dome·¢ÏÖ×Ô2ÔÂÒÔÀ´Õë¶Ôº½Ô˵Ĺ¥»÷¼¤Ôö400%
°ä²¼¹¦·ò 2020-06-091.Area1°ä²¼»ã±¨£¬£¬£¬£¬£¬£¬¶íÂÞ˹ͨ¹ýExim´úÀí(MTA)Öзì϶×ÌÈÅÃÀ¹ú´óÑ¡
Area1°ä²¼»ã±¨£¬£¬£¬£¬£¬£¬°µÊ¾¶íÂÞ˹ͨ¹ýExim´úÀí(MTA)Öзì϶×ÌÈÅÃÀ¹ú´óÑ¡¡£¡£¡£¡£¡£¡£¡£¡£ÃÀ¹úÍøÂ簲ȫÕ÷ѯÖÒ¸æ³Æ£¬£¬£¬£¬£¬£¬×Ô2019Äê8ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬Óë¶íÂÞ˹¾ü·½ÓйصĺڿÍÒ»ÏòÔÚÀûÓÃÃÀ¹úEximÓʼþ´«Êä´úÀí(MTA)Èí¼þÖеķì϶(CVE-2019-10149)¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶Äܹ»Ó°ÏìEximµÄ4.87µ½4.91°æ±¾£¬£¬£¬£¬£¬£¬ÀûÓÃËüÄܹ»Ôö³¤ÌØÈ¨Óû§¡¢½ûÓÃÍøÂ簲ȫÉèÖá¢ÌáÒéBEC´¹µö»î¶¯µÈ¡£¡£¡£¡£¡£¡£¡£¡£¶øÏÖÒÑÈ·¶¨2018ÄêÃÀ¹ú´óÑ¡ÖÐÖÁÉÙ44ÃûºòÑ¡ÈËʹÓÃÁËExim·þÎñÆ÷£¬£¬£¬£¬£¬£¬¶ø2020ÄêÃÀ¹ú´óÑ¡ÖÁÉÙ50ÃûºòÑ¡ÈËʹÓÃExim·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬£¬Area1È·ÐÅ2020ÄêÑ¡¾ÙÖеÄÏÖÈκòÑ¡ÈËÔÚ2018ÄêÑ¡¾Ùµ½2019Äê2ÔÂÖ®¼ä×¢¶¨»áÊܵ½CVE-2019-10149µÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cdn.area1security.com/reports/Area-1-Security-EximReport.pdf
2.Bolster°ä²¼2020ÄêµÚÒ»¼¾¶ÈÍøÂç´¹µöºÍÔÚÏßڲƻ㱨
·Àڲƹ«Ë¾Bolster°ä²¼ÁË2020ÄêµÚÒ»¼¾¶ÈÍøÂç´¹µöºÍÔÚÏßڲƻ㱨£¬£¬£¬£¬£¬£¬·¢ÏÖÓëCOVID-19ÓйصÄÚ²ÆÍøÕ¾¼¤Ôö¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ2020ÄêµÚÒ»¼¾¶È£¬£¬£¬£¬£¬£¬Bolster×ܹ²¼ì²âµ½854441¸öÍøÂç´¹µöºÍÚ¿ÆÍøÕ¾ºÍԼĪ400Íò¸ö¿ÉÒÉÍøÕ¾£¬£¬£¬£¬£¬£¬ÆäÖÐÔ¼30£¥ÓëCOVID-19Óйء£¡£¡£¡£¡£¡£¡£¡£³ý´ËÖ®±í£¬£¬£¬£¬£¬£¬´ËÀàÍøÕ¾µÄÔö³¤Á¿Ò²ÔÚ²»ÐÝÔö³¤£¬£¬£¬£¬£¬£¬´ÓÒ»Ô·ÝÿÌì3142¸öеÄÍøÒ³Ôö³¤µ½ÈýÔ·Ý8342¸öÍøÒ³£¬£¬£¬£¬£¬£¬Ö±µ½3ÔÂ19ÈÕ´ïµ½¶¥·å£¬£¬£¬£¬£¬£¬Ò»ÌìÄÚ´´½¨Á˳¬¹ý25000¸öеÄÍøÒ³¡£¡£¡£¡£¡£¡£¡£¡£SaaSºÍµçÐÅÐÐÒµÊÇÊÜÍøÂç´¹µöÚ¿ÆÓ°Ïì×î´óµÄÐÐÒµ£¬£¬£¬£¬£¬£¬Æä´ÎÊǽðÈÚ¡¢ÁãÊÛºÍÁ÷ýÌåÐÐÒµ¡£¡£¡£¡£¡£¡£¡£¡£Bolster»¹·¢ÏÖÁ˶à¸öÚ¿ÆÍøÕ¾ÊÛÂôαÔìµÄCOVID-19¼ÓÃÜÇ®±ÒºÍ¼ÓÃÜÇ®°ü£¬£¬£¬£¬£¬£¬ÆäÖ÷ÕÅÊÇÇÔÈ¡Êý¾ÝÒÔÓÃÓÚ½«À´µÄÍøÂç´¹µö¡¢¶ñÒâÈí¼þ·Ö·¢ºÍÇÔȡƾ֤¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.businesswire.com/news/home/20200513005152/en/Bolster%E2%80%99s-Q1-2020-State-Phishing-Online-Fraud
3.Naval Dome·¢ÏÖ£¬£¬£¬£¬£¬£¬×Ô2ÔÂÒÔÀ´Õë¶Ôº½Ô˵ĺڿ͹¥»÷¼¤Ôö400%
ÒÔÉ«Áк£ÉÏÍøÂ簲ȫר¼ÒNaval Dome³Æ£¬£¬£¬£¬£¬£¬×Ô2020Äê2ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬Õë¶Ôº½Ô˵ĺڿ͹¥»÷¼¤ÔöÁË400%¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÒÔΪCOVID-19ʹµÃº£ÉÏÄÜÔ´²¿ÃűÈÒÔǰ¸üÈÝÒ×Êܵ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬Í¬Ê±Ê¹¶ñÒâÈí¼þ¡¢ÀÕË÷Èí¼þºÍ´¹µöÓʼþ¼¤Ôö¡£¡£¡£¡£¡£¡£¡£¡£Naval DomeµÄCEO Itai Sela°µÊ¾£¬£¬£¬£¬£¬£¬ÓÉÓÚCovid-19µ¼ÖµÄÉç½»Ï޶Ⱥ͸ôÀë´ëÊ©£¬£¬£¬£¬£¬£¬ÆÈʹÔʼÉ豸Ôì×÷ÉÌ£¨OEM£©¡¢¼¼ÊõÈËÔ±ºÍ¹©¸øÉ̽«Õý±¾¶ÀÁ¢µÄϵÍÂ䬽ӵ½InternetÉÏ£¬£¬£¬£¬£¬£¬OEM¼¼ÊõÈËÔ±ÎÞ·¨µ½´¬Ö»ºÍ×ê»úÉÏÉý¼¶OTϵͳ£¬£¬£¬£¬£¬£¬ÕâЩ¶¼µ¼Ö¸ÃÐÐÒµ¸üÒ×ÓÚ±»¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.offshore-energy.biz/naval-dome-400-increase-in-attempted-hacks-since-february-2020/
4.WordPress²å¼þPageLayer´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬Ó°Ï쳬¹ý20Íò¸öÍøÕ¾
WordfenceÍŶӷ¢ÏÖWordPress²å¼þPageLayer´æÔÚÁ½¸ö·ì϶£¬£¬£¬£¬£¬£¬¿ÉÄÜ»áÓ°Ï쳬¹ý20Íò¸öÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸ö·ì϶µÄCVSSµÄÆÀ·ÖΪ7.4£¬£¬£¬£¬£¬£¬¸Ã·ì϶µÄ´æÔÚÊÇÓÉÓÚ²å¼þµÄAJAX¶ËµãÖ»ÊÇͨ¹ýÒ»¸öÉí·ÝÑéÖ¤µÄ»á»°²é³ÒªÇóÊÇ·ñÀ´×Ô /wp-admin£¬£¬£¬£¬£¬£¬¶ø²»²é³·¢ËÍÒªÇóµÄÓû§µÄȨÏÞ£¬£¬£¬£¬£¬£¬Òò¶øÈκνӼûȨÏÞµÄÓû§¶¼Äܹ»Ö´ÐÐÈκβÙ×÷£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿É±»ÀûÓÃɾ³ýÄÚÈÝ»òÏòÏÖÓÐÒ³Ãæ×¢Èë¶ñÒâÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¸ö·ì϶µÄCVSSÆÀ·ÖΪ8.8·Ö£¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚ¶ÌȱCSRF±£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬ºÚ¿ÍÄܹ»ÀûÓø÷ì϶ÏòÕ¾µãÒ³Ãæ×¢Èë¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬¿ª·¢ÈËÔ±ÒѾ°ä²¼Á˰²È«²¹¶¡ÒÔ¶Ô·ì϶½øÐн¨¸´¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://latesthackingnews.com/2020/06/07/pagelayer-wordpress-plugin-vulnerabilities-risked-over-200k-websites/
5.ºÚ¿ÍÀûÓÃÍøÂç´¹µö¹¥»÷µÂ¹úÓ×ÎÒ·À»¤É豸¹©¸øÁ´
IBM X-Force×êÑÐÈËÔ±°ä²¼»ã±¨°µÊ¾£¬£¬£¬£¬£¬£¬ºÚ¿ÍÔÚÀûÓÃÍøÂç´¹µö¹¥»÷Ò»¼ÒµÂ¹ú¹«Ë¾µÄ¸ß²ãÖÎÀíÈËÔ±£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄÖØÒª¹¤×÷ÊDzɹºÓ×ÎÒ·À»¤É豸£¨PPE£©£¬£¬£¬£¬£¬£¬Ä¿Ç°ºÚ¿ÍÒÑÊÔͼÇÔÈ¡100¶àλ¸ß¹ÜµÄƾ֤¡£¡£¡£¡£¡£¡£¡£¡£3ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬µÂ¹úµ±¾ÖÓë¸Ã¹ú´óÐ͹«Ë¾½øÐлáÒ飬£¬£¬£¬£¬£¬ÒªÇóÆäÐÖúµÂ¹ú²É°ìPPEÖ®ºó£¬£¬£¬£¬£¬£¬Ï®»÷¾ÍÆðÍ·ÁË¡£¡£¡£¡£¡£¡£¡£¡£Í³Ò»Ì죬£¬£¬£¬£¬£¬ÕâЩ´óÐ͹«Ë¾ÖеÄÒ»¸ö¹«Ë¾µÄ¸ß¹ÜÊÕµ½ÁËÀ´×Ô¶íÂÞ˹IPµØÖ·µÄÍøÂç´¹µö¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£Êܺ¦ÕßÖдó°ëΪָ±ê¹«Ë¾ÖÐÓëÔËÓª¡¢²ÆÕþºÍ²É¹ºÓйصĸ߹ܣ¬£¬£¬£¬£¬£¬ÁíÒ»°ëÊôÓڸù«Ë¾µÄºÏ×÷¹«Ë¾µÄ¸ß¹Ü¡£¡£¡£¡£¡£¡£¡£¡£¾Ýµ÷²é£¬£¬£¬£¬£¬£¬ºÚ¿ÍÀûÓÃǶÈëʽ³¬Á´½Ó£¬£¬£¬£¬£¬£¬½«Êܺ¦Õß³Á¶¨Ïòµ½¼Ù×°³ÉMicrosoftµÇ¼±íµ¥µÄÍøÂç´¹µöµÇÂ¼Ò³Ãæ£¬£¬£¬£¬£¬£¬²¢½«ÍøÂçµ½µÄÊý¾Ý·¢Ë͵½¶à¸öYandexµç×ÓÓʼþÕÊ»§¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-are-attacking-the-german-ppe-supply-chain/
6.еÄÍøÂç´¹µö»î¶¯Í¨¹ýStackBlitz¹¤¾ßÍйܴ¹µöÒ³Ãæ
Zscaler ThreatLabzÍŶӷ¢ÏÖ£¬£¬£¬£¬£¬£¬´Ë¿Ì´æÔÚ¶àÖÖÀûÓÃStackBlitz¹¤¾ßµÄÍøÂç´¹µö»î¶¯£¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃÁËÔ¤Êèµ¼¿âÖ°Äܽ«ÍйܵÄÍøÒ³´Ó·þÎñÆ÷¶ËÖ±½Ó¹ý¶Éµ½¿Í»§¶Ë¡£¡£¡£¡£¡£¡£¡£¡£ÔÚµÚÒ»ÖÖ´¹µö»î¶¯ÖУ¬£¬£¬£¬£¬£¬ºÚ¿Í¼Ù×°³ÉÒ½ÁÆÎÀÉú×éÖ¯£¬£¬£¬£¬£¬£¬Í¨¹ýOneDrive¹²Ïí·þÎñ·¢ËÍÎĵµ£¬£¬£¬£¬£¬£¬Óû§Ò»µ©µã»÷ÏÂÔØÁ´½Ó£¬£¬£¬£¬£¬£¬¾Í»á±»³Á¶¨Ïòµ½Outlook´¹µöÒ³Ãæ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÁíÒ»ÖÖ´¹µö»î¶¯ÖУ¬£¬£¬£¬£¬£¬´¹µöÓʼþÖеÄÁ´½ÓÖ¸ÏòÒ»¸öÍøÒ³£¬£¬£¬£¬£¬£¬²¢Ô̺¬Ò»ÌõÐÂÎÅ×¢Ã÷ÄúÊÕµ½ÁË´øÓÐÓйØÎĵµÏÂÔØÁ´½ÓµÄ¹²ÏíÎĵµ£¬£¬£¬£¬£¬£¬Óû§µ¥»÷ÏÂÔØÁ´½Óºó±ã»á±»³Á¶¨Ïòµ½OneDriveÍøÂç´¹µöÍøÒ³¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zscaler.com/blogs/research/new-campaign-abusing-stackblitz-tool-host-phishing-pages


¾©¹«Íø°²±¸11010802024551ºÅ