Avast°ä²¼ÓйØGoogle PlayÉ϶ñÒâÈí¼þµÄ·ÖÎö»ã±¨£»£» £»£»£»£»FBI³ÆºÚ¿ÍÀûÓÃSonarQubeÇÔÈ¡µ±¾ÖºÍÆóÒµÔ´´úÂë

°ä²¼¹¦·ò 2020-10-28
1.Avast°ä²¼ÓйØGoogle PlayÉ϶ñÒâÈí¼þµÄ·ÖÎö»ã±¨


1.jpg


ɱ¶¾Èí¼þÔì×÷ÉÌAvast°ä²¼ÓйØGoogle PlayÉ϶ñÒâÈí¼þµÄ·ÖÎö»ã±¨¡£¡£¡£¡£ ¡£¸Ã»ã±¨³ÆGoogle PlayÉ̵êÖÐÓÐ21¸öϰȾÁËHiddenAds¶ñÒâÈí¼þµÄAndroidÀûÓ÷¨Ê½£¬£¬ £¬£¬£¬£¬£¬£¬GoogleÒÑÓÚÖÜĩɾ³ýÁËÆäÖеÄ15¸ö¡£¡£¡£¡£ ¡£Avast¶ñÒâÈí¼þ·ÖÎöʦ°µÊ¾£¬£¬ £¬£¬£¬£¬£¬£¬ÕâЩÀûÓ÷ÂÕÕÁËÊ¢ÐеÄÓÎÏ·£¬£¬ £¬£¬£¬£¬£¬£¬Ò»µ©Óû§×°ÖÃÁËÕâЩÀûÓ㬣¬ £¬£¬£¬£¬£¬£¬HiddenAds¾Í»á°µ²Ø¸ÃÀûÓ÷¨Ê½µÄͼ±êʹÓû§ÄÑÒÔ½øÐÐɾ³ý£¬£¬ £¬£¬£¬£¬£¬£¬¶øºóÆðÍ·Óøæ°×ºäÕ¨Óû§¡£¡£¡£¡£ ¡£Avast°µÊ¾£¬£¬ £¬£¬£¬£¬£¬£¬½ØÖÁÉÏÖÜÕâЩÀûÓ÷¨Ê½ÒÑ´ï700Íò´ÎÏÂÔØÁ¿¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://blog.avast.com/new-malware-apps-on-google-play-avast


2.FBI³ÆºÚ¿ÍÀûÓÃSonarQubeÇÔÈ¡µ±¾ÖºÍÆóÒµÔ´´úÂë


2.jpg


Áª¹úµ÷²é¾Ö£¨FBI£©³Æ£¬£¬ £¬£¬£¬£¬£¬£¬ºÚ¿ÍÀûÓÃSonarQube´ÓÃÀ¹úµ±¾Ö»ú¹¹ºÍÆóÒµÇÔÈ¡Êý¾Ý¡£¡£¡£¡£ ¡£SonarQubeÊÇÒ»¸öÊ¢¿ªÔ´´úÂëÆ½Ì¨£¬£¬ £¬£¬£¬£¬£¬£¬ÓÃÓÚ×Ô¶¯´úÂëÖÊÁ¿ÉóºËºÍ¾²Ì¬·ÖÎö£¬£¬ £¬£¬£¬£¬£¬£¬ÒÔ·¢ÏÖʹÓÃ27ÖÖ±à³Ì˵»°¿ª·¢µÄÏîÄ¿ÖеÄÃýÎóºÍ°²È«·ì϶¡£¡£¡£¡£ ¡£´Ó2020Äê4ÔÂÆðÍ·£¬£¬ £¬£¬£¬£¬£¬£¬FBI¾Í¹Û²ìµ½ÃÀ¹úµ±¾Ö»ú¹¹ºÍ¼¼Êõ¡¢½ðÈÚ¡¢ÁãÊÛ¡¢Ê³Æ·¡¢µç×ÓÉÌÎñºÍÔì×÷Òµ¹«Ë¾ÓÉÓÚSonarQube²»°²È«µ¼ÖµÄÔ´´úÂëй¶ÊÂÎñ£¬£¬ £¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Microsoft¡¢Adobe¡¢Lenovo¡¢AMD¡¢Qualcomm¡¢Motorola¡¢NintendoºÍµÏÊ¿ÄáµÈ¹«Ë¾¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fbi-hackers-stole-government-source-code-via-sonarqube-instances/


3.ºÚ¿Í´ÓHarvest FinanceÇÔÈ¡¼ÛÖµ2400ÍòÃÀÔª¼ÓÃÜÇ®±Ò


3.jpg


ºÚ¿Í´Ó·Öɢʽ½ðÈÚ·þÎñ£¨DeFi£©·þÎñHarvest FinanceÖÐÇÔÈ¡Á˼ÛÖµÔ¼2400ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò¡£¡£¡£¡£ ¡£Æ¾¾Ý¸Ã¹«Ë¾µ÷²é£¬£¬ £¬£¬£¬£¬£¬£¬ºÚ¿Í×ܹ²ÇÔÈ¡Á˼ÛÖµ1300ÍòÃÀÔªµÄUSD Coin£¨USDC£©ºÍ¼ÛÖµ1100ÍòÃÀÔªµÄTether£¨USDT£©¡£¡£¡£¡£ ¡£ÔÚ¹¥»÷²úÉúÁ½·ÖÖӺ󣬣¬ £¬£¬£¬£¬£¬£¬ºÚ¿Í»¹Ïò¸Ãƽ̨ÍË»¹ÁË250ÍòÃÀÔª£¬£¬ £¬£¬£¬£¬£¬£¬µ«ÆäÔ­ÒòÈÔ²»Ã÷ÏÔ¡£¡£¡£¡£ ¡£Harvest FinanceÈϿɣ¬£¬ £¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷ÊÇÓÉÓÚ×Ô¼ºµÄʧÎóΪ¹¥»÷ÕßÌṩÁË»úÓö£¬£¬ £¬£¬£¬£¬£¬£¬²¢ÐüÉÍ40ÍòÃÀÔªÒԼν±ÕÒµ½±»µÁ×ʽð²¢ËÍ»¹µÄÈË¡£¡£¡£¡£ ¡£    


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-steals-24-million-from-cryptocurrency-service-harvest-finance/


4.³¬¹ý100¸öICC PRO¹à¸Èϵͳ¶³ö£¬£¬ £¬£¬£¬£¬£¬£¬ÖØÒªÉ¢²¼ÔÚÒÔÉ«ÁÐ


4.png


°²È«¹«Ë¾Security Joes·¢ÏÖ³¬¹ý100¸öICC PRO¹à¸Èϵͳ¶³ö£¬£¬ £¬£¬£¬£¬£¬£¬ÆäÖдó°ëÉ¢²¼ÔÚÒÔÉ«ÁС£¡£¡£¡£ ¡£Security Joes°µÊ¾Óû§ÔÚ×°ÖÃICC PROϵͳʱδ¸ü¸ÄĬÈϳö³§ÉèÖ㬣¬ £¬£¬£¬£¬£¬£¬Òò¶ø¿ÉÀûÓÃShodanµÈÎïÁªÍøËÑË÷ÒýÇæÇáËɵØÕÒµ½ËüÃÇ¡£¡£¡£¡£ ¡£¹¥»÷ÕßÔÚÕÒµ½¿É½Ó¼ûµÄICC PROϵͳºó£¬£¬ £¬£¬£¬£¬£¬£¬Í¨¹ýÊäÈëĬÈÏÖÎÀíÔ±Óû§Ãû¼´¿É½Ó¼ûÖÇÄܹà¸È½ÚÔìÃæ°å£¬£¬ £¬£¬£¬£¬£¬£¬¶øºóÔÝÍ£»£» £»£»£»£»òÖÕ³¡½½Ë®¡¢¸ü¸ÄÉèÖᢽÚÔìÊäË͵½±ÃµÄË®Á¿ºÍѹÁ¦¡¢»òͨ¹ýɾ³ýÓû§À´Ëø¶¨¹à¸Èϵͳ¡£¡£¡£¡£ ¡£ÕâЩϵͳ³¬¹ýÒ»°ëλÓÚÒÔÉ«ÁУ¬£¬ £¬£¬£¬£¬£¬£¬ÆäÓàµÄÉ¢²¼ÔÚÈ«Çò¸÷µØ¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/over-100-irrigation-systems-left-exposed-online-without-a-password/


5.Nando's¿Í»§Ô⵽ƾ֤Ìî³ä¹¥»÷µ¼Ö´óÁ¿×ʽ𱻵Á


5.png


Nando's¿Í»§Ô⵽ƾ֤Ìî³ä¹¥»÷µ¼Ö´óÁ¿×ʽ𱻵Á¡£¡£¡£¡£ ¡£Nando'sÊÇÖØÒªÎ»ÓÚÓ¢¹úºÍÅ·ÖÞ³ÇÊеļ¦ÈâÁ¬Ëø²ÍÌü£¬£¬ £¬£¬£¬£¬£¬£¬ÓÚÉÏÖÜÎåÔâµ½ÁËÆ¾Ö¤Ìî³ä¹¥»÷¡£¡£¡£¡£ ¡£¸Ã²ÍÌü³ÆÆäϵͳ²¢Î´Ôâµ½ºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬£¬£¬£¬ºÚ¿Í´ÓÆäËû´¦ËùÇÔÈ¡ÁËÆä¿Í»§µÄµç×ÓÓʼþµØÖ·ºÍÃÜÂ룬£¬ £¬£¬£¬£¬£¬£¬²¢½Ó¼ûËûÃǵÄNando'sÕÊ»§£¬£¬ £¬£¬£¬£¬£¬£¬ÆäÖÐÒ»ÃûÊܺ¦Õß±»µÁÁËԼĪ870ÃÀÔª¡£¡£¡£¡£ ¡£Akamai³Æ£¬£¬ £¬£¬£¬£¬£¬£¬ÔÚ2018Äê7ÔÂÖÁ½ñÄê6ÔÂÖ®¼ä£¬£¬ £¬£¬£¬£¬£¬£¬×ܹ²²úÉúÁ˳¬¹ý1000ÒÚÆðƾ֤Ìî³ä¹¥»÷£¬£¬ £¬£¬£¬£¬£¬£¬ÆäÖÐ640ÒÚÆðÕë¶ÔÁãÊÛ¡¢ÓÎÀÀºÍ¾ÆµêÐÐÒµ¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/nandos-hackers-customer-accounts/160527/


6.ÃÀ¹úÂÉËùFragomenÔâµ½¹¥»÷µ¼Ö¹ȸèÔ±¹¤ÐÅϢй¶


6.png


ÃÀ¹úÒÆÃñÂÉʦÊÂÎñËùFragomenÔâµ½¹¥»÷µ¼Ö¹ȸèÔ±¹¤ÐÅϢй¶¡£¡£¡£¡£ ¡£¸Ã¹«Ë¾°ä²¼Í¨Öª³Æ£¬£¬ £¬£¬£¬£¬£¬£¬ÆäÔâµ½ÁËÍøÂç¹¥»÷£¬£¬ £¬£¬£¬£¬£¬£¬ºÚ¿Í½Ó¼ûÁËÔ̺¬I-9¾ÍÒµÑéÖ¤·þÎñÓ×ÎÒÐÅÏ¢µÄÎļþ£¬£¬ £¬£¬£¬£¬£¬£¬Éæ¼°µ½Á˹ȸèÔ±¹¤ºÍǰԱ¹¤¡£¡£¡£¡£ ¡£Õâ´ÎÊÂÎñй¶ÁËÔ±¹¤µÄÈ«Ãû¡¢ÓʼĵØÖ·¡¢µ®ÉúÈÕÆÚ¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢Éç»á±£Ïպ𢻤ÕÕºÅÂëºÍÆäËûÒÆÃñ±êʶ·û¡£¡£¡£¡£ ¡£FragomenΪËùÓÐÊÜÓ°ÏìµÄGoogleÔ±¹¤ÌṩÁËÒ»ÄêµÄÃâ·ÑÐÅÓþ¼à¿Ø¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-employees-personal-info-exposed-in-law-firm-data-breach/