Cyble·¢ÏÖºÚ¿ÍÔÚ°µÍøÏúÊÛÁ½ÒÚ¶àÖйú¹«ÃñµÄÐÅÏ¢£»£»£»£»£»×êÑÐÈËÔ±Åû¶Zend FrameworkÖÐÔ¶³Ì´úÂëÖ´Ðзì϶

°ä²¼¹¦·ò 2021-01-05
1.Cyble·¢ÏÖºÚ¿ÍÔÚ°µÍøÏúÊÛÁ½ÒÚ¶àÖйú¹«ÃñµÄÐÅÏ¢


1.jpg


CybleµÄ×êÑÐÍŶӷ¢ÏÖºÚ¿ÍÔÚ°µÍøÏúÊÛÁ½ÒÚ¶àÖйú¹«ÃñµÄÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¡£Õâ´Îй¶µÄÊý¾ÝÀ´×Ô¶à¸öƽ̨ºÍÈí¼þ£¬£¬£¬£¬£¬ £¬ÆäÖÐÔ̺¬730Íòºþ±±Ê¡¾£ÖÝÊй«°²ÏؾÓÃñµÄÉí·ÝÖ¤ºÅ¡¢ÐÔ±ð¡¢ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢ÊÖ»ú¡¢µØÖ·ºÍ´úÂëµÈÐÅÏ¢£¬£¬£¬£¬£¬ £¬4180Íò¸ö΢²©Óû§µÄÕ˺źÍÏàÓ¦µÄÊÖ»úºÅÂ룬£¬£¬£¬£¬ £¬ÒÔ¼°1.92ÒÚQQÓû§µÄÕ˺źÍÏàÓ¦µÄÊÖ»úºÅÂë¡£¡£¡£ ¡£¡£¡£¡£Õâ´Îй¶µÄÓëÖйú¹«ÃñÓйصļͼ×ÜÊý³¬¹ý2ÒÚ¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/112966/deep-web/chinese-citizens-data-darkweb.html


2.д¹µö»î¶¯ÒÔÕÊ»§ÊÜÏÞ¶ÌÐÅΪµö¶üÇÔÈ¡PayPalÍ´´¦


2.jpg


еĴ¹µö»î¶¯ÒÔÕÊ»§ÊÜÏÞ¶ÌÐÅΪµö¶üÇÔÈ¡PayPalµÇ¼ʹ´¦¡£¡£¡£ ¡£¡£¡£¡£Õâ´Î¹¥»÷»î¶¯¼ÙÒâPayPal·¢ËÍÚ¿Æ­¶ÌÐÅ£¬£¬£¬£¬£¬ £¬Ðû³ÆÓû§µÄÕÊ»§Êܵ½ÓÀÔ¶ÏÞ¶È£¬£¬£¬£¬£¬ £¬Ðèµã»÷Á´½ÓÀ´ÑéÖ¤ÕÊ»§¡£¡£¡£ ¡£¡£¡£¡£¸ÃÁ´½Ó½«Óû§³Á¶¨Ïòµ½´¹µöÒ³Ãæ£¬£¬£¬£¬£¬ £¬ÒÔÇÔÈ¡Óû§µÇ¼ƾ֤¡£¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬ÔÚÓû§ÊäÈëµÇ¼ƾ֤ºó¸ÃÍøÕ¾»¹»á½øÒ»²½ÍøÂç¸ü¶à¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬ £¬ÀýÈçÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·ºÍÒøÐоßÌåÐÅÏ¢µÈµÈ£¬£¬£¬£¬£¬ £¬ÒÔÓÃÓÚ½«À´µÄÉí·ÝµÁÓù¥»÷£¬£¬£¬£¬£¬ £¬Õë¶ÔÐÔµÄÓã²æÊ½´¹µö¹¥»÷»ò½Ó¼ûÓû§µÄÆäËûÕÊ»§¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/beware-paypal-phishing-texts-state-your-account-is-limited/


3.Ò½ÁÆ»ú¹¹GenRxÔâµ½ÀÕË÷¹¥»÷£¬£¬£¬£¬£¬ £¬»¼Õß½¡È«Êý¾Ýй¶


3.jpg


ÃÀ¹úµÄÒ½ÁÆ»ú¹¹GenRx PharmacyÔâµ½ÀÕË÷¹¥»÷£¬£¬£¬£¬£¬ £¬»¼Õß½¡È«Êý¾Ýй¶¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷²úÉúÔÚ2020Äê9ÔÂ27ÈÕ£¬£¬£¬£¬£¬ £¬ºÚ¿ÍÌáÒéÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚµÚ¶þÌ죨9ÔÂ28ÈÕ£©·¢ÏÖÁ˸û²¢×èÖ¹ÁËºÚ¿Í¶ÔÆäϵͳµÄ½Ó¼û¡£¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾³ÆÕâ´ÎÍøÂç¹¥»÷²¢Î´³É¹¦£¬£¬£¬£¬£¬ £¬ÆäÒµÎñ²¢Î´Êܵ½Ó°Ï죬£¬£¬£¬£¬ £¬µ«ºÚ¿ÍÒѾ­½Ó¼û²¢É¾³ýÁËijЩ»¼ÕßÊý¾Ý£¬£¬£¬£¬£¬ £¬Ô̺¬»¼ÕßID¡¢ÂòÂôID¡¢ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢ÐԱ𡢹ýÃô¡¢ÓÃÒ©Çåµ¥¡¢½¡È«´òËãÐÅÏ¢ºÍ´¦·½ÐÅÏ¢µÈ¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2021/01/04/genrx-pharmacy-ransomware-attack-resulted-in-data-breach/


4.ÓÊÂÖ¹«Ë¾AIDAÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬ £¬Í¨ÕÛ·þÎñÁÙʱÖжÏ


4.jpg


µÂ¹úÓÊÂÖ¹«Ë¾AIDAÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬ £¬Í¨ÕÛ·þÎñÁÙʱÖжÏ¡£¡£¡£ ¡£¡£¡£¡£AIDA³ÆÆäµç»°ÏµÍ³ºÍµç×ÓÓʼþϵͳÖжϣ¬£¬£¬£¬£¬ £¬±»ÆÈÈ¡µÞ2020Äê12ÔÂ26ÈÕ´ïµ½µÄÓÊÂÖµÄÐгÌ¡£¡£¡£ ¡£¡£¡£¡£Ö»¹ÜAIDA²¢Î´Ð¹Â©ºÃ¶àϸ½Ú£¬£¬£¬£¬£¬ £¬µ«µÂ¹úýÌ屨·ÆäÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬£¬ £¬Ò»Ð©´¬Éϵij˿ÍÒ²°µÊ¾´¬²°Óë×ܲ¿Ö®¼äµÄͨѶÖжÏ¡£¡£¡£ ¡£¡£¡£¡£Õâ´Î¹¥»÷ÊÂÎñ»¹Ó°ÏìÁËCosta CruiseºÍCarnival Maritime¡£¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬Databreaches.net²Â²âAIDAÔâµ½ÁËDoppelpaymerÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2021/01/03/aida-ships-face-service-disruptions-ransomware-attack-suspected/


5.×êÑÐÈËÔ±Åû¶Zend FrameworkÖÐÔ¶³Ì´úÂëÖ´Ðзì϶


5.jpg


×êÑÐÈËÔ±Ling YizhouÅû¶Zend Framework3.0.0ÖеÄÒ»¸ö²»³ÉÐŵķ´ÐòÁл¯·ì϶£¨CVE-2021-3007£©¡£¡£¡£ ¡£¡£¡£¡£Zend FrameworkµÄ×°ÖÃÁ¿³¬¹ý5.7ÒڴΣ¬£¬£¬£¬£¬ £¬±»ÓÃÀ´¹¹½¨ÃæÏò¶ÔÏóµÄwebÀûÓ÷¨Ê½¡£¡£¡£ ¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚStreamÀàµÄÎö¹¹º¯ÊýÖУ¬£¬£¬£¬£¬ £¬¿É±»ÓÃÀ´¶ÔÒ×Êܹ¥»÷µÄPHPÀûÓýøÐÐÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬ZendÓÚ2020Äê1ÔÂǨáãµ½LaminasÏîÄ¿£¬£¬£¬£¬£¬ £¬ÔÚijЩ°æ±¾µÄLaminasÖÐÒ²´æÔÚÉÏÊöStream.phpÀ࣬£¬£¬£¬£¬ £¬Òò¶ø²¿ÃÅʹÓÃLaminas¹¹½¨µÄÀûÓÃÒ²¿ÉÄÜ»áÊܵ½Ó°Ïì¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/zend-framework-remote-code-execution-vulnerability-revealed/


6.IDG°ä²¼2020Ä갲ȫ³Áµã×êÑеķÖÎö»ã±¨


6.jpg


IDG°ä²¼ÁË2020Ä갲ȫ³Áµã×êÑеķÖÎö»ã±¨£¬£¬£¬£¬£¬ £¬Ö¼ÔÚ¸üºÃµØÏàʶ×éÖ¯´Ë¿ÌºÍÀ´Äê¹Ø×¢µÄ¸÷ÀలȫÏîÄ¿¡£¡£¡£ ¡£¡£¡£¡£¸Ã»ã±¨Ö¸³ö£¬£¬£¬£¬£¬ £¬³¬¹ýÈý·ÖÖ®Ò»£¨37£¥£©µÄÈËÒÔΪ£¬£¬£¬£¬£¬ £¬COVID-19ºÍÀͶ¯Á¦¸Ä¹ÛµÈÒâ±íÕýÆÈʹËûÃǽ«³Áµã´ÓÕ½Êõ°²È«¹¤×÷ÖÐ×ªÒÆ³öÀ´£»£»£»£»£»Èý·ÖÖ®Ò»µÄ¾ö²ßÕß°µÊ¾£¬£¬£¬£¬£¬ £¬ËûÃÇ2021Ä갲ȫԤË㽫¸ßÓÚCOVID-19֮ǰµÄÔ¤Ë㣬£¬£¬£¬£¬ £¬41£¥µÄÈ˰µÊ¾×ÜÌ尲ȫԤË㽫ÔÚ½«À´12¸öÔÂÄÚÔö³¤£»£»£»£»£»´óÎÞÊý£¨87£¥£©ÊÜ·ÃÕßÃ÷È·ÔÚ´ÓǰһÄêÖÐÔì³É°²È«ÊÂÎñµÄÔ­Òò¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.idg.com/tools-for-marketers/2020-security-priorities-study/