SAP°²È«¸üн¨¸´NetWeaverÖеÄÑϳÁ·ì϶£»£»£»£»£»£»£»£»Î¢Èí7Ô·ݰ²È«¸üн¨¸´¶à¸ö²úÆ·ÖÐ123¸ö·ì϶
°ä²¼¹¦·ò 2020-07-151.SAP°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´NetWeaverÖеÄÑϳÁ·ì϶
2020Äê7ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬SAP°ä²¼ÁËÒ»¸ö°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´ÁËÒ»¸öSAP NetWeaverÖеÄÑϳÁ·ì϶£¨CVE-2020-6287£©£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ10·Ö¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚSAP NetWeaver AS JavaµÄWeb×é¼þÖжÌȱÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬´Ë°²È«·ì϶Ŀǰ¿ÉÄÜ»áÓ°Ïì40000¶à¸öSAPϵͳ¡£¡£¡£¡£¡£¡£SPA¹«Ë¾»¹·¢ÏÖÖÁÉÙÓÐ2500¸öÒ×Êܹ¥»÷µÄSAPϵͳֱ½Ó¶³öÓÚ»¥ÁªÍø£¬£¬£¬£¬£¬£¬ÆäÖб±ÃÀÕ¼33%£¬£¬£¬£¬£¬£¬Å·ÖÞÕ¼29%ºÍÑÇ̫ռ27%¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/alerts/aa20-195a
2.΢Èí°ä²¼7Ô·ݰ²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´¶à¸ö²úÆ·ÖÐ123¸ö·ì϶
΢Èí°ä²¼ÁË7Ô·ݵÄÖܶþ²¹¶¡·¨Ê½£¬£¬£¬£¬£¬£¬½¨¸´¶à¸ö²úÆ·ÖÐ123¸ö·ì϶£¬£¬£¬£¬£¬£¬ÆäÖÐ18¸öΪÑϳÁ·ì϶¡£¡£¡£¡£¡£¡£Õâ´Î°²È«¸üÐÂÖн¨¸´µÄ×îÑϳÁµÄ·ì϶ΪÑϳÁµÈ¼¶Îª10.0µÄ·ì϶£¨CVE-2020-1350£©£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶½øÐÐÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬¸Ã·ì϶Òѱ»Check Point¶¨ÃûΪSigRed¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬»¹½¨¸´ÁËMicrosoft EdgeºÍVBScriptÒýÇæÖдæÔڵö½ÏΪÑϳÁµÄ·ì϶£¬£¬£¬£¬£¬£¬±ðÀëΪWindows×ÖÌå¿âÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-1436£©ºÍGDIÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-1435£©£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓÃÆä½øÐкÅÁîÖ´ÐС£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/07/14/microsoft-releases-july-2020-security-updates
3.еÄMirai±äÌåÕë¶ÔComtrend·ÓÉÆ÷ÖеĺÅÁî×¢Èë·ì϶
Ç÷Ïò¿Æ¼¼µÄ°²È«×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬IoT½©Ê¬ÍøÂçMiraiµÄбäÌåÕë¶ÔComtrend·ÓÉÆ÷ÖеĺÅÁî×¢Èë·ì϶£¨CVE-2020-10173£©¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊǾ¹ýÉí·ÝÑéÖ¤µÄºÅÁî×¢Èë·ì϶£¬£¬£¬£¬£¬£¬¿É±»Ô¶³Ì¹¥»÷ÕßÀûÓ÷ÛËé·ÓÉÆ÷ÖÎÀíµÄÍøÂç¡£¡£¡£¡£¡£¡£Õë¶Ô¸Ã·ì϶µÄPoCÒѹ«¿ª°ä²¼£¬£¬£¬£¬£¬£¬µ«Mirai±äÌåÊǵÚÒ»¸ö³¢ÊÔÀûÓô˷ì϶µÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬¸ÃбäÌå×ܹ²ÀûÓÃÁË9¸ö·ì϶£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Netlink GPON·ÓÉÆ÷ÖÐÏà¶Ô½Ïеķì϶¡£¡£¡£¡£¡£¡£¸Ã±äÌå¿ÉÓ°ÏìLG SuperSign EZ CMS¡¢AVTECH devices¡¢D-Link devices¡¢MVPower DVR¡¢Symantec Web Gateway 5.0.2.8ºÍThinkPHP¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/new-mirai-variant-targets-vulnerability-comtrend-routers?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Securityweek+%28SecurityWeek+RSS+Feed%29
4.ºÚ¿ÍÔÚ°µÍøÉÏÏúÊÛ1.42ÒÚÌõÃ׸ß÷¾Æµê¿Í»§µÄ¾ßÌåÐÅÏ¢
ºÚ¿ÍÔÚ°µÍøÉϰ䲼¸æ°×£¬£¬£¬£¬£¬£¬ÒÔ2939.76ÃÀÔªµÄ¼ÛÖµÏúÊÛ142479937ÃûÃ׸ß÷¾Æµê£¨MGM£©¿Í»§µÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬¸Ãй¶ÊýÁ¿Ô¶ºëÔ¶ÓÚ×î³õ»ã±¨µÄ1060Íò¡£¡£¡£¡£¡£¡£ºÚ¿ÍÐû³ÆÔÚËûÃÇ·ÛËéÁËÓÉNight Lion SecurityÔËÓªµÄÊý¾Ýй©¼à¶½·þÎñDataViperÖ®ºó»ñµÃÁ˾ƵêµÄÊý¾Ý£¬£¬£¬£¬£¬£¬µ«Night LionÊ×´´ÈËVinny TroiaÔò°µÊ¾Æä²¢Ã»ÓÐMGMµÄÊý¾Ý¡£¡£¡£¡£¡£¡£MGM°µÊ¾£¬£¬£¬£¬£¬£¬Õâ´Îй¶²úÉúÔÚ2019ÄêÏÄÌ죬£¬£¬£¬£¬£¬ÆäʱºÚ¿ÍÈëÇÖÁ˾ƵêµÄÒ»Ì¨ÔÆ·þÎñÆ÷²¢ÇÔÈ¡Á˾Ƶê´ÓǰµÄ¿ÍÈËÐÅÏ¢£¬£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾Ã»ÓÐй©¹¥»÷µÄÁìÓò¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/a-hacker-is-selling-details-of-142-million-mgm-hotel-guests-on-the-dark-web/#ftag=RSSbaffb68
5.ºÚ¿ÍÔÚ°µÍøÏúÊÛ4Íò¶àÃûÃÀ¹ú¹«ÃñµÄÓ×ÎÒ¾ßÌåÐÅÏ¢ºÍSSN
Íþвµý±¨¹«Ë¾Cyble·¢ÏÖ£¬£¬£¬£¬£¬£¬ºÚ¿ÍÔÚ°µÍøÉÏÏúÊÛԼĪ40000ÃûÃÀ¹ú¹«ÃñµÄÓ×ÎÒ¾ßÌåÐÅÏ¢ÒÔ¼°ËûÃǵÄÉç»á°²È«ºÅÂ루SSN£©¡£¡£¡£¡£¡£¡£Õâ´Îй©µÄÊý¾ÝÔ̺¬Ãû×Ö¡¢ÐÕÊÏ¡¢µØÖ·¡¢ÊÓ×¢ÖÝ¡¢ÓʱࡢÉç»á°²È«ºÅÂ루SSN£©ºÍµ®ÉúÈÕÆÚ£¨DOB£©µÈÐÅÏ¢¡£¡£¡£¡£¡£¡£´ËÀàÊý¾Ý¿ÉÄܸøÃÀ¹ú¹«Ãñ´øÀ´ÑϳÁµÄ·çÏÕ£¬£¬£¬£¬£¬£¬¸Ãй¶Êý¾Ý¿É±»ÓÃÓÚ´ó¹æÄ£ÍøÂç´¹µö»î¶¯»ò½ðÈÚڲƻ¡£¡£¡£¡£¡£¡£CybleÒѾÔÚÆäÊý¾Ýй¶¼à¶½ºÍ֪ͨƽ̨AmiBreached.comÉÏΪ¸ÃÊý¾Ý¿â³ÉÁ¢ÁËË÷Òý£¬£¬£¬£¬£¬£¬ÒÔ¹©²»°²ÆäÐÅϢй¶µÄÈ˲éÎÊ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/105837/malware/40000-us-citizens-darkweb.html?utm_source=rss&utm_medium=rss&utm_campaign=40000-us-citizens-darkweb
6.ÅÄÂôÍøÕ¾LiveAuctioneersÔâ¹¥»÷£¬£¬£¬£¬£¬£¬Ð¹Â¶340ÍòÌõÓû§¼Í¼
ÅÄÂôÍøÕ¾LiveAuctioneersÈÏ¿ÉÆäÔâµ½ÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£7ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬Ò»ÃûºÚ¿ÍÔÚ°µÍøÏúÊÛ´ÓLiveAuctioneersµÄÍøÕ¾ÉÏÇÔÈ¡µÄ340ÍòÌõÓû§¼Í¼£¬£¬£¬£¬£¬£¬²¢±ê¼ÛΪ2500ÃÀÔª¡£¡£¡£¡£¡£¡£¾Ý³Æ£¬£¬£¬£¬£¬£¬´ËÊý¾Ý¿âÔ̺¬Óû§µÄµç×ÓÓʼþµØÖ·¡¢Óû§Ãû¡¢MD5¹þÏ£ÃÜÂë¡¢Ãû³Æ¡¢µç»°ºÅÂë¡¢µØÖ·¡¢IPµØÖ·ºÍÉ罻ýÌåÅäÖÃÎļþ¡£¡£¡£¡£¡£¡£³ý´ËÖ®±í£¬£¬£¬£¬£¬£¬¸ÃºÚ¿Í»¹°µÊ¾ÆäÖÐÓÐ300Íò¸öÕÊ»§µÄÃÜÂëÒѱ»ÆÆ½â¡£¡£¡£¡£¡£¡£7ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬LiveAuctioneers°ä²¼Á˰²È«Í¨Öª£¬£¬£¬£¬£¬£¬°µÊ¾ËûÃÇÔâµ½Á˹¥»÷µ¼ÖÂÊý¾Ýй¶£¬£¬£¬£¬£¬£¬²¢Ö¸³öºÚ¿ÍÊÇÓÚ6ÔÂ19ÈÕÔÚÆäÊý¾Ý´¦ÖúÏ×÷¹«Ë¾´¦½Ó¼ûµÄÕâЩÊý¾Ý¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/liveauctioneers-reports-data-breach-after-user-records-sold-online/


¾©¹«Íø°²±¸11010802024551ºÅ