Apache°ä²¼°²È«¹«¸æ£¬£¬£¬£¬£¬£¬£¬½¨¸´ÆäTomcatÖеÄDoS·ì϶£»£»£»£»£»£»£»OneClass´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶³¬¹ý100ÍòѧÉúÐÅÏ¢
°ä²¼¹¦·ò 2020-06-291.Apache°ä²¼°²È«¹«¸æ£¬£¬£¬£¬£¬£¬£¬½¨¸´ÆäTomcatÖеÄDoS·ì϶
ApacheÈí¼þ»ù½ð»á°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬½¨¸´Apache TomcatÖеķì϶£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓô˷ì϶ÌáÒ黨¾ø·þÎñ¹¥»÷¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁËApache Tomcat 10.0.0-M1ÖÁ10.0.0-M5°æ±¾¡¢ 9.0.0.M1ÖÁ9.0.35°æ±¾ºÍ8.5.0ÖÁ8.5.55°æ±¾¡£¡£¡£¡£¡£ÔÚ佨¸´°æ±¾ÖУ¬£¬£¬£¬£¬£¬£¬ÌØÊâµÄHTTP/2ÒªÇóÐòÁпÉÄܻᵼÖ³¤´ï¼¸ÃëÖӵĸßCPUʹÓÃÂÊ£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÄܹ»Í¨¹ý·¢ËÍ×ã¹»ÊýÁ¿µÄ´ËÀàÒªÇ󣬣¬£¬£¬£¬£¬£¬Ê¹µÃ·þÎñÆ÷»Ø¾øÏìÓ¦£¬£¬£¬£¬£¬£¬£¬ÊµÏÖDoS¹¥»÷¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.us-cert.gov/ncas/current-activity/2020/06/26/apache-releases-security-advisory-apache-tomcat
2.·¨¹úµçÊǪ́T¨¦l¨¦visions¹ÙÍøÔâµ½¹¥»÷ £¬£¬£¬£¬£¬£¬£¬ËæºóÆôÓñ¸ÓÃÕ¾µã
·¨¹úµçÊǪ́T¨¦l¨¦visions GroupÓÚÉÏÖÜÎå°ä·¢£¬£¬£¬£¬£¬£¬£¬Æä¹ÙÍøÔâµ½ÁËÍøÂç¹¥»÷¡£¡£¡£¡£¡£¾Ý¸Ã¹«Ë¾³Æ£¬£¬£¬£¬£¬£¬£¬Æä¹ÙÍøÏ°È¾Á˶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬Ëæºó¸Ã¹«Ë¾ÆôÓÃÁËÆä±¸ÓÃÕ¾µã£¬£¬£¬£¬£¬£¬£¬²¢½«France 3ÆµÂ·×ªÒÆµ½ÁË·¨¹ú¹ã²¥µçÊǪ́×ܲ¿¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷»î¶¯²¢Ã»ÓÐÓ°Ïìµ½¸Ã¹«Ë¾µÄ¹ã²¥ÌìÏߣ¬£¬£¬£¬£¬£¬£¬²¢ÇÒ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Ä¿Ç°ÒѾ³ä·Ö²ÉÈ¡ÁËÓ¦¼±´ëÊ©£¬£¬£¬£¬£¬£¬£¬¹ã²¥ÔÚ¶ÌÆÚÄÚ²»»áÔÙÊܵ½Ó°Ïì¡£¡£¡£¡£¡£Õâ²¢²»ÊǵÚÒ»´ÎÕë¶Ô·¨¹úýÌåµÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬2019ÄêÀÕË÷Èí¼þÍŻ﹥»÷ÁËM6 ¡ª¡ª ·¨¹ú×î´óµÄµçÊÓÆµÂ·Ö®Ò»¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/105269/hacking/france-televisions-group-cyber-attack.html
3.½ø½¨Æ½Ì¨OneClass´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶³¬¹ý100ÍòѧÉúÐÅÏ¢
½ø½¨Æ½Ì¨OneClassµÄWebÓ³É䲿ÃÅ´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶³¬¹ý100ÍòѧÉúÐÅÏ¢¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñй¶ÁË27 GBµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬×ܼÆ890Íò±Ê¼Í¼£¬£¬£¬£¬£¬£¬£¬Éæ¼°µ½Á˳¬¹ý100Íò¸öOneClassÓ×ÎÒÓû§ÐÅÏ¢¡£¡£¡£¡£¡£vpnMentorµÄ°²È«×êÑÐÍŶӷ¢ÏÖÁËOneClassµÄWebÓ³É䲿ÃÅ´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬£¬²¢°µÊ¾£¬£¬£¬£¬£¬£¬£¬¸Ãƽ̨µÄÓû§Êý¾Ý¿âÒ²ÊÇδ¼ÓÃÜÇÒÆëÈ«²»°²È«µÄ£¬£¬£¬£¬£¬£¬£¬ËûÃǴ˿̾ͿÉÄܽӼû´ËÊý¾Ý¿â¡£¡£¡£¡£¡£Õâ´Îй¶ÊÂÎñ¿ÉÄܵ¼ÖÂOneClassµÄδ³ÉÄêÓû§Ôâµ½ÍøÉÏڲƵȹ¥»÷£¬£¬£¬£¬£¬£¬£¬Í¬Ê±Æä¸¸Ä¸µÄÐÅÓþ¿¨Ö§¸¶ÐÅÏ¢Ò²½«Êܵ½Íþв¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.breitbart.com/tech/2020/06/26/report-e-learning-data-breach-exposes-1-million-college-students-data/
4.ºÚ¿ÍÔÚ°µÍøÊÛÂôÊý°ÙÍò¶íÂÞ˹ºÍÒÁÀʵÄTelegramÓû§ÐÅÏ¢
ºÚ¿ÍÔÚ°µÍøÊÛÂôÊý°ÙÍò¶íÂÞ˹ºÍÒÁÀʵÄTelegram MessengerÓû§ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Telegram¹«Ë¾ÒÑÈ·ÈÏÁ˸ÃÊý¾ÝµÄÕæÊµÐÔ¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾Õâ¸öÊý¾Ý¿âÊÇÒÔǰ´Ó·ÖÆç¹ú¶È£¬£¬£¬£¬£¬£¬£¬Í¨¹ý·ÖÆç²½ÖèÍøÂçµÄ¸÷ÀàÊý¾Ý¿â½øÐеĻã±à£¬£¬£¬£¬£¬£¬£¬ÖØÒªµÄ²½ÖèΪͨ¹ýÊ¢¿ªÏµÍ³¡¢Ì¸Ìì»úеÈË¡¢ÊÚȨºÍÓ×ÎÒ×¢²áÐÅÏ¢µÄºÅÂëÍøÂç¡£¡£¡£¡£¡£¼´±ãÊý¾Ý¿âÖдæÔÚ³Á¸´ºÍÃýÎóÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ÕâÒ²ÊÇÊýÒÔǧÍò¼ÆµÄÓû§¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÔ̺¬ÁËÓû§id¡¢Óû§Ãû¡¢Ãû¡¢ÐÕ¡¢ÕÕÆ¬¡¢ÊÖ»ú¡¢Ó×ÎÒ¼ò½éºÍÍøÕ¾£¬£¬£¬£¬£¬£¬£¬ÓÐЩ»¹Ô̺¬Óû§ÔÚÏßʱµÄÐÅÏ¢¡¢¹ú¶È/µØÓòµÈ£¬£¬£¬£¬£¬£¬£¬ÕâЩÊý¾Ýͨ³£¿£¿£¿£¿£¿£¿£¿£¿É±»ÓÃÓÚÎÞÖ¸±êµÄÀ¬»øÓʼþ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.ehackingnews.com/2020/06/the-database-of-millions-of-telegram.html
5.Adobe£¬£¬£¬£¬£¬£¬£¬MastercardºÍVisa½¨ÒéÖÕ³¡Ê¹ÓÃMagento 1.x
Adobe£¬£¬£¬£¬£¬£¬£¬MastercardºÍVisa½¨ÒéÖÕ³¡Ê¹ÓÃMagento 1.x£¬£¬£¬£¬£¬£¬£¬µ«Ä¿Ç°ÈÔÓнü11Íò¸öÔÚÏßÉ̵êÔÚÔËÐÐMagento 1.x CMS¡£¡£¡£¡£¡£Magento 1.x¼«¶È²»°²È«£¬£¬£¬£¬£¬£¬£¬ÔÚ´ÓǰÈýÄêÖУ¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÒ»ÏòÔÚÀûÓÃMagento·ì϶À´¹¥»÷ÍøÉÏÉ̳ǣ¬£¬£¬£¬£¬£¬£¬½øÐÐMagecart¹¥»÷¡£¡£¡£¡£¡£ÔÚ6ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬£¬Magento 1.xƽ̨½«´ïµ½ÆäÕýʽµÄÊÙÃüÖÕÖ¹£¨EOL£©ÈÕÆÚ£¬£¬£¬£¬£¬£¬£¬¶ûºóAdobe´òËãÖÕ³¡Ìṩ°²È«¸üС£¡£¡£¡£¡£Mastercard·¢³öÖҸ棬£¬£¬£¬£¬£¬£¬77%É̳ÇûÓÐ×ñÊØPCI DSSµÄÌõ¿î6£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃ×îÐµĶøÏµÍ³¡£¡£¡£¡£¡£¶øVisaÔçÔÚ4Ô·ݾͷ¢³öÁËÖҸ棬£¬£¬£¬£¬£¬£¬ÒªÇóµê¶«¸üе½Magento 2.3¡£¡£¡£¡£¡£6ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬Adobe°ä²¼ÁËMagento 1.xµÄ×îÖÕ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬²¢°µÊ¾Õ⽫ÊÇ×îºóÒ»´Î¸üУ¬£¬£¬£¬£¬£¬£¬ÒªÇóËùÓÐÉ̵ê¸üе½Magento2.x¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/adobe-mastercard-visa-warn-online-store-owners-of-magento-1-x-eol/
6.ºÚ¿ÍÀûÓÃMagecartÕë¶ÔÃÀ¹úÊÐÕþÖ§¸¶Èí¼þClick2Gov
×êÑÐÈËÔ±ÖÒ¸æËµ£¬£¬£¬£¬£¬£¬£¬ÃÀ¹ú8¸ö³ÇÊУ¨ºá¿ç3¸öÖÝ£©µÄÍøÕ¾Ôâµ½ÁËMagecart¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÕâÐ©ÍøÕ¾¶¼Ê¹ÓÃÁËÊÐÕþÖ§¸¶Èí¼þClick2Gov¡£¡£¡£¡£¡£Æ¾¾ÝÇ÷Ïò¿Æ¼¼µÄ×êÑÐÈËÔ±·ÖÎö£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÊÇÔÚÊܺ¦Õßͨ¹ýÊÜϰȾµÄClick2GovÍøÕ¾ÉϽøÐÐÔÚÏ߸¶¿îʱÌáÒé¹¥»÷µÄ¡£¡£¡£¡£¡£ÔÚÕâ´Î¹¥»÷ÖкڿÍʹÓÃÁËÁ½Ì¨exfiltering·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬Á½Õß¶¼ÍйÜÁËJavaScript skimmer£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÓÃÓÚ½Ó¹Üй©Êý¾ÝµÄ. jspÎļþ¡£¡£¡£¡£¡£ÆäÖÐһ̨·þÎñÆ÷ÓÃÓÚ¹¥»÷Èý¸öÕ¾µã£¬£¬£¬£¬£¬£¬£¬¶øÁíһ̨·þÎñÆ÷ÓÃÓÚ¹¥»÷ÆäÓàÎå¸öÕ¾µã¡£¡£¡£¡£¡£Click2GovÒÔÇ°Ò²ÔøÊܵ½·ì϶µÄÓ°Ï죬£¬£¬£¬£¬£¬£¬µ¼ÖÂÁËÁ½´ÎÊý¾Ýй¶¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/8-city-gov-websites-magecart/156954/


¾©¹«Íø°²±¸11010802024551ºÅ