ºÚ¿ÍÈëÇÖ2gether·þÎñÆ÷£¬£¬£¬£¬£¬ÇÔÈ¡¼ÛÖµ120ÍòÅ·ÔªµÄ¼ÓÃÜÇ®±Ò£»£»£»£»£»£»ºÚ¿Íй¶900¶à¸öÆóÒµVPN·þÎñÆ÷µÄÐÅÏ¢ºÍÃ÷ÎÄÃÜÂë
°ä²¼¹¦·ò 2020-08-051.ºÚ¿ÍÈëÇÖ2gether·þÎñÆ÷£¬£¬£¬£¬£¬ÇÔÈ¡¼ÛÖµ120ÍòÅ·ÔªµÄ¼ÓÃÜÇ®±Ò
7ÔÂ31ÈÕÏÂÎç6µã£¬£¬£¬£¬£¬ºÚ¿ÍÈëÇÖÁË2getherµÄ·þÎñÆ÷£¬£¬£¬£¬£¬²¢ÇÔÈ¡Á˼ÛÖµ118.3ÍòÅ·ÔªµÄ¼ÓÃÜÇ®±Ò£¬£¬£¬£¬£¬Õ¼×Ü×ʽðµÄ26.79£¥¡£¡£¡£¡£¡£¡£¡£¡£2together CEO°µÊ¾£¬£¬£¬£¬£¬Õâ´Î¹¥»÷²¢Î´Ó°Ïìͨ·ÑÇ®°üºÍÅ·ÔªÕÊ»§£¬£¬£¬£¬£¬²¢ÇÒºÚ¿ÍûÓÐÇÔÈ¡Óû§ÐÅÓþ¿¨µÄ²ÆÕþÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬¸Ã¹«Ë¾²¢Î´°ä²¼¹¥»÷µÄ¼¼Êõϸ½Ú£¬£¬£¬£¬£¬Ö»ÊǰµÊ¾Á˾ßÌåµ÷²éÈÔÔÚ½øÐÐÖС£¡£¡£¡£¡£¡£¡£¡£¾Ý¹«Ë¾¸ß¹Ü³Æ£¬£¬£¬£¬£¬¸Ã¹«Ë¾Ã»ÓÐ×ã¹»µÄ×ʽðÀ´ÍË»¹ÆäÓû§£¬£¬£¬£¬£¬²¢ÇÒÕýÊÔͼͨ¹ýͶ×ʹ«Ë¾µÄ×¢×ʽøÐв¹¾È¡£¡£¡£¡£¡£¡£¡£¡£µ«ÊDz¢Î´³É¹¦£¬£¬£¬£¬£¬Òò¶øÖ»ÄÜÏòÓû§ÌṩÆä±»µÁµÄ¼ÓÃÜÇ®±ÒµÈÖµµÄ±¾µØ2GT´ú±Ò¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/106726/hacking/2gether-hacked.html
2.°Í»ù˹̹ÐÂÎÅÆµÂ·DawnÔâ¹¥»÷£¬£¬£¬£¬£¬¸æ°×¹¦·ò²¥·ÅÓ¡¶È¹úÆì
8ÔÂ2ÈÕÐÇÆÚÈÕÏÂÎç3:30×óÓÒ£¬£¬£¬£¬£¬°Í»ùË¹Ì¹ÖØÒªÐÂÎÅÆµÂ·Ö®Ò»DawnÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬¸æ°×ÐÝÏ¢ÆÚ¼äÔÚÆÁÄ»Éϲ¥·ÅÓ¡¶È¹úÆìºÍ¶ÀÁ¢ÁôÏëÈÕ»¶ÀÖµÄ×ÖÑù¡£¡£¡£¡£¡£¡£¡£¡£Dawn°µÊ¾£¬£¬£¬£¬£¬Ôâµ½¹¥»÷ʱËûÃÇÏñƽ·²Ò»Ñù²¥·ÅÐÂÎź͸æ°×¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ Óйػú¹¹ÔÚ¶ÔÕâ´Î¹¥»÷·¢Õ¹µ÷²é¡£¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬Õâ²¢²»ÊǵÚÒ»´Î²úÉúºÚ¿Í¹¥»÷µçÊÓÆµÂ·ÊÂÎñ£¬£¬£¬£¬£¬ÒÔÉ«ÁеĸöÈËÐÂÎÅÆµÂ·µÚ2Ƶ·ºÍµÚ10Ƶ·µÄ¾ÍÔøÔâµ½¹ýÈëÇÖ£¬£¬£¬£¬£¬ºÚ¿ÍÖжÏÁ˽ÚÄ¿²¢²¥·ÅÄÂ˹Áֵĵ»¸æÉù¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/pakistani-news-channel-transmission-hacked-indian-flag/
3.ºÚ¿Íй¶900¶à¸öÆóÒµVPN·þÎñÆ÷µÄÐÅÏ¢ºÍÃ÷ÎÄÃÜÂë
ºÚ¿ÍÔÚ°µÍøÉϰ䲼ÁË900¶à¸öPulse Secure VPNÆóÒµ·þÎñÆ÷µÄÐÅÏ¢ºÍÃ÷ÎÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Îй¶ÐÅÏ¢Ô̺¬·þÎñÆ÷µÄIPµØÖ·¡¢¹Ì¼þ°æ±¾ºÅ¡¢Ã¿¸ö·þÎñÆ÷µÄSSHÃÜÔ¿¡¢ËùÓб¾µØÓû§¼°ÆäÃÜÂë¹þÏ£µÄÁÐ±í¡¢ÖÎÀíÔ¹ØÊ»§¾ßÌåÐÅÏ¢¡¢×î½üµÄVPNµÇ¼Ãû£¨Ô̺¬Óû§ÃûºÍÃ÷ÎÄÃÜÂ룩ÒÔ¼°VPN»á»°cookie¡£¡£¡£¡£¡£¡£¡£¡£Íþвµý±¨·ÖÎö¹«Ë¾Bank Security·¢ÏÖÁбíÖеķþÎñÆ÷¶¼ÔËÐÐÁË´æÔÚCVE-2019-11510·ì϶°æ±¾µÄ¹Ì¼þ¡£¡£¡£¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬ÆäÒÔΪºÚ¿ÍÊÇɨÃèÁË·þÎñÆ÷µÄÕû¸öInternet IPv4µØÖ·¿Õ¼ä£¬£¬£¬£¬£¬²¢ÀûÓø÷ì϶À´½Ó¼ûϵͳ£¬£¬£¬£¬£¬×ª´¢·þÎñÓþßÌåÐÅÏ¢²¢½«ËùÓÐÐÅÏ¢ÍøÂçµ½Ò»¸öÖÐÑë´æ´¢¿âÖС£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hacker-leaks-passwords-for-900-enterprise-vpn-servers/
4.Ò»¼üͨÀûÓÃZello²úÉúÊý¾Ýй¶£¬£¬£¬£¬£¬ÒѳÁÖÃËùÓÐЧ»§ÃÜÂë
Ò»¼üͨÀûÓÃZello²úÉúÊý¾Ýй¶£¬£¬£¬£¬£¬ÆäÒѳÁÖÃËùÓÐЧ»§ÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£ZelloÖ¸³ö£¬£¬£¬£¬£¬ËûÃÇÓÚ2020Äê7ÔÂ8ÈÕÔÚÆäÖÐһ̨·þÎñÆ÷ÉÏ·¢ÏÖÁËÕâ´Î¹¥»÷£¬£¬£¬£¬£¬Í¨¹ý½øÒ»´ëÊ©²é£¬£¬£¬£¬£¬·¢ÏÖδ¾ÊÚȨµÄºÚ¿Í¿ÉÄÜÒѾ½Ó¼ûÁËÆäÓû§ÔÚÆäZelloÕÊ»§ÉÏʹÓõĵç×ÓÓʼþµØÖ·ºÍ¹þÏ£ÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬£¬£¬£¬Õâ´Îй¶ÊÂÎñ²¢²»»áÓ°ÏìZello WorkºÍZello for First RespondersÓû§¡£¡£¡£¡£¡£¡£¡£¡£ºÚ¿Í¿ÉÀûÓÃй¶ÐÅÏ¢½øÐÐÍ´´¦Ìî³ä¹¥»÷£¬£¬£¬£¬£¬²¢µÇ¼Óû§ÆäËûÕ¾µãµÄÕË»§¡£¡£¡£¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬ZelloÒÑÇ¿Ôì³ÁÖÃÓû§ÃÜÂ룬£¬£¬£¬£¬²¢½¨ÒéÓû§¸ü¸ÄÆäËûÕ¾µãÉÏÒ»ÑùµÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/zello-resets-all-user-passwords-after-data-breach/
5.ÈýÁâ°ä²¼¶à¸ö²úÆ·µÄ¸üУ¬£¬£¬£¬£¬»¹ÌṩÁËһʱ½â¾ö¹æ»®
ÈýÁâµç»úµÄÊýÊ®ÖÖ¹¤³§×Ô¶¯»¯²úÆ·´æÔÚÈý¸ö·ì϶£¬£¬£¬£¬£¬ÕâЩ·ì϶¿É±»ÀûÓýøÐÐÌáȨ¡¢ËÁÒâ´úÂëÖ´ÐкÍDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ÈýÁâÒѾΪÊÜÓ°ÏìµÄ²úÆ·°ä²¼Á˲¹¶¡£¬£¬£¬£¬£¬»¹ÎªÆäÓà²úÆ·ºÍÎÞ·¨Á¢¼´×°Öò¹¶¡·¨Ê½µÄ¿Í»§ÌṩÁË»º½â´ëÊ©¡£¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸ö·ì϶ΪȨÏÞÎÊÌ⣨CVE-2020-14496£©£¬£¬£¬£¬£¬ËüÔÊÐíºÎÓû§ÔÚÌØ¶¨Ä¿Â¼Ð´ÈëÎļþ£¬£¬£¬£¬£¬Õ¼ÓÐдȨÏ޵Ĺ¥»÷ÕßÄܹ»¸²¸Ç´ËĿ¼ÖеĺϷ¨Îļþ¡£¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¸öÊÇzip·ì϶£¨CVE-2020-14523£©£¬£¬£¬£¬£¬²úƷʹÓÃzip¹éµµÎļþÀ´´æ´¢ÅäÖ㬣¬£¬£¬£¬ÌáÈ¡¶ñÒâzip¹éµµÎļþ¿ÉÄܵ¼Ö½«ÎļþдÈëÖ¸±êĿ¼֮±íµÄËÁÒâµØÎ»¡£¡£¡£¡£¡£¡£¡£¡£µÚÈý¸ö·ì϶±»×·×ÙΪCVE-2020-14521£¬£¬£¬£¬£¬¶ÔijЩWindows apiµÄŲÓÃÖÐʹÓÃÁËδÒýÓõÄõè¾¶£¬£¬£¬£¬£¬¿É±»ÀûÓüÓÔØ¶ñÒâ¿ÉÖ´ÐÐÎļþ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/hackers-could-target-organizations-flaws-mitsubishi-factory-automation-products
6.×êÑÐÈËÔ±·¢ÏÖMeetupµÄ·ì϶£¬£¬£¬£¬£¬¿Éµ¼ÖÂÓû§×ʽð±»ÇÔÈ¡
Checkmarx×êÑÐÈËÔ±·¢ÏÖMeetupƽ̨´æÔÚÑϳÁµÄ·ì϶£¬£¬£¬£¬£¬¿Éµ¼ÖÂÓû§×ʽð±»ÇÔÈ¡¡£¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸öΪ´æ´¢µÄXSS·ì϶£¬£¬£¬£¬£¬Ö»ÐèÔÚ»áÉÌÇøµÄÐÂÎÅÖа䲼JavaScript´úÂë¾ÍÄܹ»½øÐÐÌáȨ¡£¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¸ö·ì϶ΪÉèÖò˵¥µÄ¸¶¿î²¿ÃÅÖеÄCSRF£¬£¬£¬£¬£¬¿ÉÓëµÚÒ»¸öXSS·ì϶½áºÏʹÓ㬣¬£¬£¬£¬¸ü¸ÄÓû§ÔÚMeetupÅäÖÃÎļþÖеÄPayPalµØÖ·¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÖ»ÐèÔÚ»áÉÌÇøÖа䲼һÌõÐÂÎÅ£¬£¬£¬£¬£¬²¢Ö¸ÏòÆä·þÎñÆ÷ÉÏÀûÓÃCSRFÎÊÌâµÄÎļþ±ãÄܹ»ÀûÓø÷ì϶¡£¡£¡£¡£¡£¡£¡£¡£³ýÁËÕâÁ½¸ö·ì϶±í£¬£¬£¬£¬£¬Checkmarx»¹·¢ÏÖÁËÆäËû°²È«Òþ»¼£¬£¬£¬£¬£¬api.meetup.comµÄ³ÉÔ±¶ËµãÖв»×ã×ÊÔ´ºÍËÙ¶ÈÏÞ¶È£¬£¬£¬£¬£¬Äܹ»ÀûÓÃÐòÁÐÕûÊýÀ´ÀûÓôËö¾Ùö¾ÙMeetupÓû§¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-could-have-stolen-paypal-funds-from-meetup-users/


¾©¹«Íø°²±¸11010802024551ºÅ