Pradeo°ä²¼¡¶ÊÖ»úÒøÐУºÂÉÀý¡¢ÍþвºÍÚ²ÆÔ¤·À¡·°×ƤÊ飻£»£»£»£»×êÑÐÈËÔ±Åû¶ʢÐеÄRuby GemÖÐXSS·ì϶
°ä²¼¹¦·ò 2020-09-221.Pradeo°ä²¼¡¶ÊÖ»úÒøÐУºÂÉÀý¡¢ÍþвºÍÚ²ÆÔ¤·À¡·°×ƤÊé

Pradeo°ä²¼ÁË¡¶ÊÖ»úÒøÐУºÂÉÀý¡¢ÍþвºÍÚ²ÆÔ¤·À¡·°×ƤÊ飬£¬£¬£¬£¬£¬£¬½éÉÜÁËÓйØÒƶ¯ÒøÐеÄʹÓá¢Ë¾·¨¿ò¼Ü¡¢·çÏÕÒÔ¼°±£»£»£»£»£»¤Òƶ¯ÒøÐÐÀûÓ÷¨Ê½°²È«µÄ½â¾ö¹æ»®£¨´Ó¿ª·¢µ½Ö´ÐУ©µÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£ÆäÖÐд·£¬£¬£¬£¬£¬£¬£¬Òƶ¯ÒøÐзþÎñѸËÙÊܵ½Ïû·ÑÕßµÄϲ»¶£¬£¬£¬£¬£¬£¬£¬µ½2019Äêµ×£¬£¬£¬£¬£¬£¬£¬74%µÄÓ¢¹úÈ˺Í75%µÄÃÀ¹úÈËʹÓÃÒÆ¶¯É豸À´ÖÎÀíÆä²ÆÕþ¡£¡£¡£¡£¡£¡£µ«ÊÇ×êÑÐÅú×¢£¬£¬£¬£¬£¬£¬£¬ÊÖ»úÒøÐÐÀûÓÃÍùÍùûÓÐÔ¤ÆÚµÄÄÇô°²È«£¬£¬£¬£¬£¬£¬£¬¾ÝRSAµÄÚ²ÆÎ¢·çÏÕµý±¨ÍŶÓ×î½üÍøÂçµÄÊý¾Ý·ÖÎöÏÔʾ£¬£¬£¬£¬£¬£¬£¬ÓëÊÖ»úÀûÓÃÓйصÄÚ²ÆÐÐΪÔÚ2020ÄêµÚÒ»¼¾¶È·ÁËÒ»·¬¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/09/21/whitepaper-mobile-banking-regulations-threats-and-fraud-prevention/
2.F-Secure°ä²¼2020ÄêÉϰëÄêÍøÂ簲ȫµÄ×êÑл㱨

F-Secureµ÷²éÁ˽ñÄêÉϰëÄêÍøÂçÍþвµÄ·¢Õ¹Çé¿ö£¬£¬£¬£¬£¬£¬£¬²¢°ä²¼ÁË2020ÄêÉϰëÄêÍøÂ簲ȫµÄ×êÑл㱨¡£¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬£¬£¬´Ó½ñÄê3ÔÂÆðÍ·£¬£¬£¬£¬£¬£¬£¬ÀûÓø÷ÀàCOVID-19ÎÊÌâµÄ¶ñÒâµç×ÓÓʼþÏÔ×ÅÔö³¤£¬£¬£¬£¬£¬£¬£¬ÒÔÓÕʹÓû§Â¶³öÓÚ¸÷Ààµç×ÓÓʼþ¹¥»÷ºÍÚ²ÆÖУ¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓÐËÄ·ÖÖ®ÈýµÄµç×ÓÓʼþÖи½¼þÖÐÔ̺¬ÐÅÏ¢ÇÔÈ¡Æ÷¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬ÔÚ´¹µöÓʼþÖУ¬£¬£¬£¬£¬£¬£¬½ðÈÚÒµÊÇ×î³£±»ºýŪµÄÐÐÒµ£¬£¬£¬£¬£¬£¬£¬µç×ÓÓʼþÊÇ´«²¼¶ñÒâÈí¼þ×îÊ¢Ðеķ½Ê½£¬£¬£¬£¬£¬£¬£¬Õ¼ËùÓÐϰȾý½éµÄÒ»°ëÒÔÉÏ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.f-secure.com/en/press/p/covid-19-spam--phishing-emails--plagued-users-in-first-half-of-2
3.ר¼Ò·¢ÏÖ¿ÉÀûÓÃGoogle App EngineÓò½øÐÐÍøÂç´¹µö»î¶¯

×êÑÐÈËÔ±·¢ÏÖ¿ÉÀûÓÃGoogle App EngineÓò½øÐÐÍøÂç´¹µö»î¶¯£¬£¬£¬£¬£¬£¬£¬²¢²»Ò×±»ÆóÒµ°²È«²úÆ·¼ì²âµ½¡£¡£¡£¡£¡£¡£Google App EngineÊÇÒ»¸ö»ùÓÚÔÆµÄ·þÎñƽ̨£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÔÚGoogleµÄ·þÎñÆ÷ÉÏ¿ª·¢ºÍÍйÜWebÀûÓᣡ£¡£¡£¡£¡£Google App EngineÔÚÌìÉú×ÓÓòʱÈκÎ×Ö¶ÎÃýÎó¶¼²»»áÏÔʾ404δÕÒµ½Ò³Ã棬£¬£¬£¬£¬£¬£¬¶øÊÇÏÔʾÆäĬÈÏÒ³Ãæ¡£¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í¿ÉÀûÓøÃÖ°ÄÜ´´½¨ÎÞÏÞ¸ö¶ñÒâ´¹µöÍøÕ¾£¬£¬£¬£¬£¬£¬£¬ÕâÒ²Ôö³¤ÁËϵͳÖÎÀíÔ±×èÖ¹¸Ã¶ñÒâ»î¶¯µÄÄѶȡ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/google-app-engine-feature-abused-to-create-unlimited-phishing-pages/
4.×êÑÐÈËÔ±Åû¶ʢÐеÄRuby GemÖÐXSS·ì϶£¬£¬£¬£¬£¬£¬£¬ÉÐδ±»ÔÚÒ°ÀûÓÃ

×êÑÐÈËÔ±Åû¶ÁËAction ViewÖеÄXSS·ì϶£¬£¬£¬£¬£¬£¬£¬ÆäÊÇÒ»ÖÖÊ¢ÐеÄRuby Gem£¬£¬£¬£¬£¬£¬£¬Äܹ»ÔÚRails WebÀûÓ÷¨Ê½¿ò¼ÜÖд¦ÖÃWebÒªÇ󣬣¬£¬£¬£¬£¬£¬Ä¿Ç°¸Ã·ì϶ÉÐδ±»ÔÚÒ°ÀûÓᣡ£¡£¡£¡£¡£¸Ã·ì϶λÓÚAction ViewÓÃÀ´·ÒëÓû§ÊäÈëµÄ·Ò븱ÊÖÖУ¬£¬£¬£¬£¬£¬£¬µ±Ò»¸öhtml²»°²È«µÄ×Ö·û´®×÷Ϊȱʡֵ´«µÝ¸øÒ»¸öÃûΪhtml»òÒÔ_html½áβµÄ©Òë¼üʱ£¬£¬£¬£¬£¬£¬£¬Ä¬ÈÏ×Ö·û´®½«±»ÃýÎóµØÏóÕ÷Ϊhtml°²È«ÇÒûÓÐתÒ壬£¬£¬£¬£¬£¬£¬ÕâÒâζ׏¥»÷ÕßÄܹ»ÊäÈë¼Ù×°³ÉºÏ·¨µÄ¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://portswigger.net/daily-swig/action-view-xss-bug-discovered-in-popular-ruby-gem
5.ÃÀ¹úNewhallÑ§ÇøÏ°È¾ÀÕË÷Èí¼þµ¼ÖÂÆä·þÎñÆ÷¹Ø¹Ø

ÃÀ¹ú¼ÓÀû¸£ÄáÑǵÄNewhallÑ§ÇøÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÆä·þÎñÆ÷¹Ø¹Ø£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁË10Ëù·ÖÆç´°Ð£µÄËùÓÐÔ¶³Ì½ÌÓý¡£¡£¡£¡£¡£¡£¸ÃÑ§ÇøµÄÕÆ¹ÜÈ˰µÊ¾£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍµÄ¹¥»÷´ÓÖÜÖçÒ¹¼ä³ÖÐøµ½ÖÜÒ»ÔçÉÏ£¬£¬£¬£¬£¬£¬£¬ËûÔÚÊÔͼ½Ó¼ûOutlookºÍµç×ÓÓʼþʱÊÕµ½ÃýÎóÐÅÏ¢¶ø°ÑÎȵ½¸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£ÓÐȤµÄÊÇ£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í²¢Ã»ÓÐÌá³öÚ²ÆÀÕË÷µÄÐèÒª¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/california-elementary-kids-online-learning-ransomware/159319/
6.ArbiterSportsϰȾÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬£¬54Íò»áÔ±ÐÅÏ¢±»µÁ

ArbiterSports°µÊ¾£¬£¬£¬£¬£¬£¬£¬ËüÒÑÓÚ½ñÄê7ÔÂÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£ArbiterSportsÊÇÒ»¼ÒΪÌåÓýÁªÈüÌṩÈí¼þÀ´ÖÎÀí²ÃÅкͽÇÖð¹ÙÔ±µÄ¹«Ë¾£¬£¬£¬£¬£¬£¬£¬Õâ´ÎÊÂÎñÉæ¼°µ½ÆäÔ¼54ÍòÃû×¢²á»áÔ±£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬²ÃÅÓ×¢ÁªÈü¹ÙÔ±ºÍѧÌôú±í¡£¡£¡£¡£¡£¡£Õâ´Îй¶µÄÊý¾ÝÔ̺¬Óû§µÄÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÀýÈçÕÊ»§Óû§Ãû¡¢ÃÜÂë¡¢ÕæÊµÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢µç×ÓÓʼþµØÖ·ºÍÉç»á°²È«ºÅÂë¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬ ¸Ã¹«Ë¾°µÊ¾ÆäÒѾ֧¸¶ÁËÊê½ð£¬£¬£¬£¬£¬£¬£¬²¢È·ÈϺڿÍ×éÖ¯ÒÑɾ³ý±»µÁÊý¾Ý¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/details-of-540000-sports-referees-taken-in-failed-ransomware-attack/


¾©¹«Íø°²±¸11010802024551ºÅ