Apple iCloudÖжÏ36Ó×ʱ£¬£¬£¬ £¬ £¬Éв»Ã÷ÏÔ¹ÊÕÏÔ­Òò£»£»£»£»£» £»£»Nintendo 3DS´æÔڿɵ¼ÖÂMiTM¹¥»÷µÄ·ì϶

°ä²¼¹¦·ò 2020-12-28
1.Apple iCloudÖжÏ36Ó×ʱ£¬£¬£¬ £¬ £¬Éв»Ã÷ÏÔ¹ÊÕÏÔ­Òò


1.jpg


Apple iCloud·þÎñ³öÏÖ¹ÊÕÏ£¬£¬£¬ £¬ £¬Ê¹Óû§ÎÞ·¨µÇ¼¸Ã·þÎñ½Ó¼ûÎļþ»òÉèÖÃÐÂÉ豸¡£¡£¡£¡£ ¡£Õâ´ÎÖжϴÓÃÀ¹ú¶«²¿¹¦·ò12ÔÂ25ÈÕÉÏÎç4:45ÆðÍ·£¬£¬£¬ £¬ £¬Ö±µ½12ÔÂ26ÈÕÏÂÎç4:35²Å±»½¨¸´£¬£¬£¬ £¬ £¬Àúʱ36Ó×ʱ¡£¡£¡£¡£ ¡£ÖÐ¶ÏÆÚ¼ä£¬£¬£¬ £¬ £¬AppleµÄϵͳ״̬ҳÉϽöÏÔʾ¡°Óû§¿ÉÄÜÓöµ½´Ë·þÎñµÄÎÊÌ⡱µÄÌáÐÑ£¬£¬£¬ £¬ £¬Ã»Óиü¶àÓÐ¹ØÆäÖжϵÄÐÅÏ¢¡£¡£¡£¡£ ¡£Ä¿Ç°£¬£¬£¬ £¬ £¬Apple¹«Ë¾Ã»ÓÐÌṩÈκÎÒÔÕÏÔ­Òò¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/apple/apple-icloud-outage-prevents-device-activations-access-to-data/


2.ºÚ¿ÍÏúÊÛÓÎÏ·¹«Ë¾Koei TecmoµÄÊý¾ÝºÍ½Ó¼ûȨ


2.png


ºÚ¿ÍÔÚ°µÍøÏúÊÛÓÎÏ·¹«Ë¾Koei TecmoµÄÊý¾ÝºÍ½Ó¼ûȨ¡£¡£¡£¡£ ¡£12ÔÂ20ÈÕ£¬£¬£¬ £¬ £¬ºÚ¿ÍÐû³ÆÆäÓÚ12ÔÂ18ÈÕÀûÓÃÓã²æÊ½´¹µö¹¥»÷ÈëÇÖÁËkoeitecmoeurope.comÍøÕ¾£¬£¬£¬ £¬ £¬ÇÔÈ¡ÁËÂÛ̳Êý¾Ý¿â²¢Ö²ÈëÁËWeb ShellÒÔ±ãºóÐø½Ó¼û¡£¡£¡£¡£ ¡£Ö®ºóºÚ¿ÍÔÚ°µÍøÉÏÒÔ0.05±ÈÌØ±Ò£¨Ô¼ºÏ1300ÃÀÔª£©µÄ¼ÛÖµÏúÊÛÊý¾Ý¿â£¬£¬£¬ £¬ £¬²¢ÒÔ0.25£¨Ô¼ºÏ6500ÃÀÔª£©µÄ¼ÛÖµÏúÊÛWeb shell½Ó¼ûȨÏÞ¡£¡£¡£¡£ ¡£¸Ã±»µÁÊý¾Ý¿âÔ̺¬ÁË65000¸öÓû§µÄÊý¾Ý£¬£¬£¬ £¬ £¬Ô̺¬µç×ÓÓʼþµØÖ·¡¢IPµØÖ·¡¢¹þÏ£ÃÜÂë¡¢Óû§Ãû¡¢µ®ÉúÈÕÆÚºÍ¹ú¶È¡£¡£¡£¡£ ¡£Ä¿Ç°£¬£¬£¬ £¬ £¬Koei TecmoÒѹعØÃÀ¹úºÍÅ·ÖÞµÄÍøÕ¾£¬£¬£¬ £¬ £¬ÒÔÔ¤·À¿ÉÄܲúÉúµÄ¹¥»÷¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/koei-tecmo-discloses-data-breach-after-hacker-leaks-stolen-data/


3.Nintendo 3DS´æÔڿɵ¼ÖÂMiTM¹¥»÷µÄ·ì϶


3.png


×êÑÐÈËÔ±·¢ÏÖNintendo 3DS´æÔÚÑϳÁµÄ·ì϶£¬£¬£¬ £¬ £¬¿ÉÄܵ¼ÖÂMiTM¹¥»÷¡£¡£¡£¡£ ¡£¸Ã·ì϶λÓÚNintendo 3DS¶ÔÊý×ÖÖ¤ÊéµÄ´¦ÖÃÖУ¬£¬£¬ £¬ £¬ ³ÉÁ¢SSL/TLSÏνÓʱSSLÏµÍ³Ä £¿£¿£¿£¿£¿£¿£¿£¿éδÕýÈ·ÑéÖ¤x509Ö¤Ê飬£¬£¬ £¬ £¬´Ó¶øÔÊÐí¹¥»÷ÕßαÔìαÔìÖ¤ÊéÀ´Ö´ÐÐMitM¹¥»÷£¬£¬£¬ £¬ £¬»òºýŪÊÜÐÅÀµµÄ·þÎñÆ÷£¬£¬£¬ £¬ £¬ÀýÈçºýŪeShop·þÎñÆ÷²¢ÇÔÈ¡Óû§ÐÅÏ¢£¬£¬£¬ £¬ £¬ºýŪÓëÓÎÏ··þÎñÆ÷µÄÏνӵÈ¡£¡£¡£¡£ ¡£¸Ã·ì϶ӰÏìÁËËùÓй̼þ°æ±¾Îª11.13»ò¸üµÍµÄNintendo 3DS½ÚÔį̀£¬£¬£¬ £¬ £¬Ä¿Ç°Òѱ»½¨¸´¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/12/27/critical-vulnerability-in-nintendo-3ds-console-could-allow-mitm-attacks/


4.ËÕ¸ñÀ¼»·±£¾ÖÊܵ½¹¥»÷£¬£¬£¬ £¬ £¬ÁªÏµÖÐÐĵȲ¿ÃÅÊܵ½Ó°Ïì


4.png


ËÕ¸ñÀ¼»·¾³±£»£»£»£»£» £»£»¤¾Ö£¨Sepa£©Ôâµ½¹¥»÷£¬£¬£¬ £¬ £¬ÁªÏµÖÐÐĵȲ¿ÃÅÊܵ½Ó°Ïì¡£¡£¡£¡£ ¡£¸Ã¹«Ë¾CEO David Pirie³ÆÔÚ°²È»Ò¹µÄÎçÒ¹£¬£¬£¬ £¬ £¬SepaµÄϵͳÔâ·êÁ˳Á´óÇÒ³ÖÐøµÄÍøÂç¹¥»÷¡£¡£¡£¡£ ¡£¹¥»÷Ó°ÏìÁ˸ù«Ë¾µÄÁªÏµÖÐÐÄ¡¢ÄÚ²¿ÏµÍ³¡¢Á÷³ÌºÍÄÚ²¿Í¨Ñ¶¡£¡£¡£¡£ ¡£µ«ÊÇÆäÖ÷Ìâ¼à¿ØÏµÍ³ºÍ¾¯±¨·þÎñûÓÐÊܵ½Ì«´óµÄÓ°Ïì¡£¡£¡£¡£ ¡£Ä¿Ç°£¬£¬£¬ £¬ £¬SepaÕýÓëËÕ¸ñÀ¼µ±¾ÖºÏ×÷£¬£¬£¬ £¬ £¬ÒÔµ÷²é²¢½â¾öÕâ´Î¹¥»÷ÊÂÎñ¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://news.stv.tv/scotland/scottish-environment-protection-agency-targeted-in-cyberattack?top


5.Rapid7°ä²¼2020Äê¶ÈÍøÂç¹¥»÷µÄÌ¬ÊÆ»ã±¨


5.png


Rapid7°ä²¼ÁË2020Äê¶ÈÍøÂç¹¥»÷µÄÌ¬ÊÆ»ã±¨¡£¡£¡£¡£ ¡£¸Ã»ã±¨ÖØÒª·ÖÎöÁ˶ñÒâµÄMicrosoft SQL Server¹¥»÷¡¢Î¢ÈíÔ¶³Ì×ÀÃæºÍ̸(RDP)¹¥»÷ºÍ΢ÈíSMB¹¥»÷¡£¡£¡£¡£ ¡£»ã±¨·¢ÏÖ£¬£¬£¬ £¬ £¬´ó¹æÄ£µÄ½©Ê¬ÍøÂçÔÚ½ñÄêÏÄÌì֮ǰºöÈ»Òþû£¬£¬£¬ £¬ £¬¶øMS SQL serverÍ´´¦ºÍ²éÎʹ¥»÷´ïµ½ÁËÒÔÍùµÄ¾ùÔÈˮƽ¡£¡£¡£¡£ ¡£´Ë±í£¬£¬£¬ £¬ £¬Õë¶ÔRDPµÄÀÕË÷Èí¼þ¹¥»÷ÊÇÒ»¸ö´óÎÊÌ⣬£¬£¬ £¬ £¬ºÜ¶à¹¥»÷Õß¶Ô×¼ÁË×ÊÔ´²»¼°µÄÒ½ÁÆÐÐÒµ¡¢½ÌÓýºÍµ±¾Ö×éÖ¯¡£¡£¡£¡£ ¡£Õë¶ÔMicrosoft SMB·þÎñÆ÷µÄ×¢ÈëEternalBlueµÄ¹¥»÷Ò²ÓÐËùÔö³¤¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://blog.rapid7.com/2020/12/25/rapid7-labs-2020-naughty-list-summary-report-to-santa/


6.Aspen°ä²¼ÓйØÊý×Ö»ù´¡ÉèÊ©µÄ·ÖÎö»ã±¨


6.png


Aspen°ä²¼ÁËÓйØÊý×Ö»ù´¡ÉèÊ©µÄ·ÖÎö»ã±¨¡£¡£¡£¡£ ¡£2020Ä꣬£¬£¬ £¬ £¬ÍøÂ簲ȫÒѳÉΪÿ¸öÐÐÒµÒÔ¼°ÃÀ¹úµ±¾ÖµÄÄÑÌ⣬£¬£¬ £¬ £¬¸Ã»ã±¨Ö¸³öÁËÐÂÈÎ×Üͳµ±¾ÖÓкܶà»úÓöÄܹ»Ôö³¤ÍøÂ簲ȫ¹¤×÷²¢Ìá¸ßÈËÃǵÄÒâʶ£¬£¬£¬ £¬ £¬ÒÔ´´½¨¸ü¾ßµ¯ÐÔµÄÊý×Ö»ù´¡¼Ü¹¹¡£¡£¡£¡£ ¡£¸Ã»ã±¨Ö¼ÔÚÔ®ÊÖ¾ö²ßÕßÈ·¶¨ÓÅÏȼ¶¡¢¹æ»®ºÍÖ´ÐпɲÙ×÷µÄÍøÂ簲ȫ´òË㣬£¬£¬ £¬ £¬´Ó½ÌÓýºÍÀͶ¯Á¦¡¢±£»£»£»£»£» £»£»¤»ù´¡ÉèÊ©¡¢¹©¸øÁ´°²È«¡¢²âÆÀÍøÂ簲ȫºÍÍÆ½øÒµÎñºÏ×÷¼¸¸ö·½Ãæ½øÐзÖÎö¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.aspeninstitute.org/publications/a-national-cybersecurity-agenda-for-resilient-digital-infrastructure/