Cisco TalosÅû¶WebKitÖжà¸öÑϳÁµÄ·ì϶£»£»£»£»£»Apodis PharmaÊý¾Ý¿âÅäÖÃÃýÎóй¶1.7TB»úÃÜÊý¾Ý

°ä²¼¹¦·ò 2020-12-02
1.Cisco TalosÅû¶WebKitÖжà¸öÑϳÁµÄ·ì϶


1.jpg


Cisco TalosÅû¶WebKitä¯ÀÀÆ÷ÒýÇæ´æÔÚ¶à¸öÑϳÁµÄ·ì϶¡£¡£ ¡£¡£¡£¡£¡£ÕâЩ·ì϶ÓëWebKitµÄWebSocket¡¢AudioSourceProviderGStreamerºÍImageDecoderGStreamerÖ°ÄÜÓйØ¡£¡£ ¡£¡£¡£¡£¡£±ðÀëΪWebSocket´úÂëÖ´Ðзì϶£¨CVE-2020-13543£© £¬£¬£¬£¬ £¬£¬£¬¿Éͨ¹ý´¥·¢¿ªÊͺóʹÓ÷ì϶À´Ô¶³ÌÖ´ÐдúÂ룻£»£»£»£»ImageDecoderGStreamer¿ªÊͺóʹÓ÷ì϶£¨CVE-2020-13584£© £¬£¬£¬£¬ £¬£¬£¬¿Éµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë £¬£¬£¬£¬ £¬£¬£¬ÒÔ¼°±»×·×ÙΪCVE-2020-13543µÄ·ì϶¡£¡£ ¡£¡£¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/webkit-vulnerabilities-allow-remote-code-execution-malicious-websites


2.Ô½ÄÏ×éÖ¯Bismuth¶Ô×¼·¨¹úºÍÔ½ÄÏÈ·µ±¾Ö»ú¹¹ºÍ¹«Ë¾


2.jpg


΢Èí·¢ÏÖÔ½ÄϺڿÍ×éÖ¯Bismuth¶Ô×¼·¨¹úºÍÔ½ÄÏÈ·µ±¾Ö»ú¹¹ºÍ¹«Ë¾¡£¡£ ¡£¡£¡£¡£¡£¸ÃÍÅ»ï×Ô2012ÄêÒÔÀ´Ò»Ïò»îÔ¾ £¬£¬£¬£¬ £¬£¬£¬²¢ÒÔ´úºÅAPT32ºÍOceanLotusµÈΪÈËËùÖª¡£¡£ ¡£¡£¡£¡£¡£ÆäÖØÒª·¢Õ¹Õë¶Ô¹úÄÚ±íµÄ¸´ÔӺڿͻ £¬£¬£¬£¬ £¬£¬£¬Ö÷ÕÅÊÇÍøÂçÐÅÏ¢ÒÔÔ®ÊÔìäµ±¾Ö´¦ÖÃÕþÖΡ¢¾­¼ÃºÍ±í½»Õþ²ß¾ö²ß¡£¡£ ¡£¡£¡£¡£¡£µ«Î¢Èí·¢ÏÖ £¬£¬£¬£¬ £¬£¬£¬ÔÚ2020Äê7ÔÂÖÁ2020Äê8Ô £¬£¬£¬£¬ £¬£¬£¬¸Ã×éÖ¯ÔÚÕë¶Ô·¨¹úºÍÔ½ÄÏÈ·µ±¾Ö»ú¹¹ºÍ¹«Ë¾µÄ¹¥»÷ÖÐÆðͷʹÓÃMoneroÍÚ¿óÈí¼þ £¬£¬£¬£¬ £¬£¬£¬Ä¿Ç°Éв»Ã÷ÏÔÆäΪºÎ½øÐд˸ü¸Ä¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsoft-links-vietnamese-state-hackers-to-crypto-mining-malware-campaign/


3.×êÑÐÍŶӷ¢ÏÖGotkitÓëREvilµÄºÏ×÷ͬ°é¹ØÏµ³ÁÉú


3.jpg


×êÑÐÍŶӷ¢ÏÖ £¬£¬£¬£¬ £¬£¬£¬ÔÚ³¤´ïÒ»ÄêµÄÐÝÏ¢ºó £¬£¬£¬£¬ £¬£¬£¬ÐÅÏ¢ÇÔȡľÂíGootkitÓëREvilһ·ÔÚÕë¶ÔµÂ¹úµÄÐÂÕ½ÕùÖгÁÉú¡£¡£ ¡£¡£¡£¡£¡£ÔÚÕâ´Î¹¥»÷»î¶¯ÖÐ £¬£¬£¬£¬ £¬£¬£¬ºÚ¿Í¹¥»÷WordPressÍøÕ¾ £¬£¬£¬£¬ £¬£¬£¬²¢ÀûÓÃSEO²¡¶¾Ïò½Ó¼ûÕßչʾαÔìµÄÂÛ̳Ìû×Ó £¬£¬£¬£¬ £¬£¬£¬²¢¸½ÓжñÒâ±í¸ñ»òÏÂÔØµÄÁ´½Ó¡£¡£ ¡£¡£¡£¡£¡£µ±Óû§µã»÷Á´½Óʱ £¬£¬£¬£¬ £¬£¬£¬½«ÏÂÔØÒ»¸ö°ü·Ñ½âÏýµÄJSÎļþµÄZIPÎļþ £¬£¬£¬£¬ £¬£¬£¬¸ÃÎļþ½«×°ÖÃGootkit¶ñÒâÈí¼þ»òREvilÀÕË÷Èí¼þ¡£¡£ ¡£¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬ £¬£¬£¬Ê¹ÓÃÁË»ìºÏµÄÓÐÐ§ÔØºÉ¿É½«Æä·Ö»¯³ÉƬ¶Î´æ´¢ÔÚ×¢²á±íÖÐ £¬£¬£¬£¬ £¬£¬£¬Ê¹µÃ°²È«Èí¼þ¸üÄѼì²âµ½¸Ã¶ñÒâ¸ºÔØ¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/gootkit-malware-returns-to-life-alongside-revil-ransomware/


4.×êÑÐÍŶӷ¢ÏÖ¿Éͨ¹ýαÔìPayPal±íµ¥ÇÔÈ¡Óû§ÐÅÏ¢


4.jpg


×êÑÐÍŶӷ¢ÏÖеÄÐÅÓþ¿¨ÇÔÈ¡Æ÷¿Éͨ¹ýαÔìPayPal±íµ¥ÇÔÈ¡Óû§ÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¡£¸ÃÇÔÈ¡Æ÷ÊÇ»ùÓÚJavaScriptµÄ¾ç±¾ £¬£¬£¬£¬ £¬£¬£¬ÓÃÓÚ×¢Èëµ½µçÉÌÆ½Ì¨µÄ½áÕÊÒ³ÃæÖС£¡£ ¡£¡£¡£¡£¡£¸Ã¾ç±¾Í¨¹ýÒþдÊõ±»°µ²ØÔÚ±»Íйܵ½ÊÜϰȾÉ̵êµÄ·þÎñÆ÷ÉϵÄÓ³ÏñÖС£¡£ ¡£¡£¡£¡£¡£¶øºó £¬£¬£¬£¬ £¬£¬£¬Ëü»áʹÓÃÖ®Ç°ÍøÂçµÄ¶©µ¥Êý¾ÝÀ´Ô¤ÌîαÔìµÄPayPalÖ§¸¶±íµ¥ £¬£¬£¬£¬ £¬£¬£¬ÔÙ½«Êܺ¦Õß³Á¶¨Ïòµ½PayPalµÄ¶©µ¥Ò³Ãæ¡£¡£ ¡£¡£¡£¡£¡£Ò»µ©Êܺ¦ÕßÊäÈëÁ˸¶¿îÐÅÏ¢²¢µã»÷ÁËÌá½»°´Å¥ £¬£¬£¬£¬ £¬£¬£¬¸ÃÇÔÈ¡Æ÷»á½«ÆäÈ«ÊýÐÅÏ¢´«»Øµ½¹¥»÷ÕߵķþÎñÆ÷¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/credit-card-skimmer-fills-fake-paypal-forms-with-stolen-order-info/


5.ResearchAndMarkets°ä²¼½«À´5ÄêSD-WANÊг¡Ô¤²â»ã±¨


5.jpg


ResearchAndMarkets°ä²¼Á˽«À´5ÄêSD-WANÊг¡Ô¤²â»ã±¨¡£¡£ ¡£¡£¡£¡£¡£»ã±¨Ô¤¼Æ £¬£¬£¬£¬ £¬£¬£¬È«ÇòSD-WANÊг¡¹æÄ£½«´Ó2020ÄêµÄ19ÒÚÃÀÔªÔö³¤µ½2025ÄêµÄ84ÒÚÃÀÔª £¬£¬£¬£¬ £¬£¬£¬ÔÚ´ËÆÚ¼äµÄ¸´ºÏÄêÔö³¤ÂÊ£¨CAGR£©Îª34.5£¥¡£¡£ ¡£¡£¡£¡£¡£°´×éÖ¯¹æÄ£»£»£»£»£»®·Ö £¬£¬£¬£¬ £¬£¬£¬ÖÐÓ×ÐÍÆóÒµ½«Õ¼¾Ý¸ü¸ßµÄÊг¡·Ý¶î¡£¡£ ¡£¡£¡£¡£¡£ÓÉÓÚ¸ü¶àµÄSD-WAN½â¾ö¹æ»®»ùÓÚÔÆ £¬£¬£¬£¬ £¬£¬£¬Ìá¸ßÁËÆä¿É½ÓÊÜÐÔ £¬£¬£¬£¬ £¬£¬£¬Ê¹ÖÐÓׯóÒµ¶ÔSD-WAN½â¾ö¹æ»®µÄÐèÒªÔö³¤¡£¡£ ¡£¡£¡£¡£¡£´Ë±í £¬£¬£¬£¬ £¬£¬£¬ÆóÒµÕýתÏò»ùÓÚÔÆµÄÀûÓ÷¨Ê½ £¬£¬£¬£¬ £¬£¬£¬Òò¶øÔ¤¼ÆÔƲ¿Êð½«ÔÚ½«À´Ö÷µ¼Êг¡¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.researchandmarkets.com/reports/5137053/software-defined-wide-area-network-sd-wan


6.Apodis PharmaÊý¾Ý¿âÅäÖÃÃýÎóй¶1.7TB»úÃÜÊý¾Ý


6.jpg


CyberNews·¢ÏÖApodis PharmaµÄElasticSearchÊý¾Ý¿âÅäÖÃÃýÎó £¬£¬£¬£¬ £¬£¬£¬Ð¹Â¶³¬¹ý1.7TBµÄ»úÃÜÊý¾Ý¡£¡£ ¡£¡£¡£¡£¡£Apodis PharmaÊÇÒ»¼ÒΪҩ·¿¡¢Ò½ÁÆ»ú¹¹µÈ¹«Ë¾ÌṩÊý×Ö¹©¸øÁ´ÖÎÀíÆ½Ì¨ºÍÈí¼þ½â¾ö¹æ»®µÄ¹«Ë¾¡£¡£ ¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÔ̺¬´óÁ¿ÓëÒµÎñÓйصĻúÃÜÊý¾Ý £¬£¬£¬£¬ £¬£¬£¬Ô̺¬Ò©Æ·×°ÔËÊý¾ÝºÍ´æ´¢×´Ì¬¡¢Æä25000¶à¸öºÏ×÷ͬ°éºÍ¿Í»§µÄµµ°¸¡¢²úÆ·ÊýÁ¿ºÍIDµÈ²úÆ·Êý¾Ý¡¢ÏúÊÛÈÕÆÚºÍ¼ÛÖµµÈÏúÊÛÐÅÏ¢¡¢¿Í»§¼°Ô±¹¤ÐÕÃûµÅ×û§Êý¾Ý¡¢Ïû·ÑÕߺͿͻ§Êý¾ÝµÄ¿ÉÊÓ»¯ºÍ·ÖÎöÊý¾Ý¡£¡£ ¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÒÑÓÚ11ÔÂ17ÈÕ±»±£»£»£»£»£»¤ÆðÀ´¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/111756/data-breach/apodis-pharma-data-leak.html