×êÑÐÍŶÓÍøÂç130¶àÍò¸öRDPÕÊ»§£¬£¬£¬£¬ £¬ £¬£¬£¬ÆäÖÐÎÞÊýÀ´×ÔÒ½ÁÆÐÐÒµ £»£»£»£»£»£»£»SignalÅû¶ºÚ¿Í¹«Ë¾Cellebrite¿ª·¢µÄÈí¼þÖеĶà¸ö·ì϶

°ä²¼¹¦·ò 2021-04-23

1.×êÑÐÍŶÓÍøÂç130¶àÍò¸öRDPÕÊ»§£¬£¬£¬£¬ £¬ £¬£¬£¬ÆäÖÐÎÞÊýÀ´×ÔÒ½ÁÆÐÐÒµ


1.jpg


°²È«ÍŶÓ×Ô2018Äê12ÔÂÒÔÀ´°ÂÃØ½Ó¼ûÁËĿǰ×î´ó°µÍøUASµÄÊý¾Ý¿â£¬£¬£¬£¬ £¬ £¬£¬£¬²¢ÍøÂçÁ˽üÈýÄêÀ´ÏúÊÛµÄ1379609¸öRDPƾ֤¡£¡£¡£¡£¡£ÁгöµÄRDP·þÎñÆ÷À´×ÔÊÀ½ç¸÷µØ£¬£¬£¬£¬ £¬ £¬£¬£¬Ô̺¬À´×Ô63¸ö¹ú¶ÈºÍµØÓòÈ·µ±¾Ö»ú¹¹¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬ £¬£¬£¬ÕâЩÕË»§×î³£ÓõĵǼÃûÊÇ'Administrator'¡¢'Admin'¡¢'User'¡¢'test'ºÍ'scanner'£¬£¬£¬£¬ £¬ £¬£¬£¬×î³£ÓõÄÃÜÂëÊÇ123456¡¢123¡¢P@ssw0rd¡¢1234ºÍPassword1£¬£¬£¬£¬ £¬ £¬£¬£¬ÖØÒªÉæ¼°ÃÀ¹ú¡¢Öйú¡¢°ÍÎ÷¡¢µÂ¹ú¡¢Ó¡¶ÈºÍÓ¢¹úµÈ¹ú¶È¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/logins-for-13-million-windows-rdp-servers-collected-from-hacker-market/


2.×êÑÐÈËÔ±·¢ÏÖÓÉÉϰÙÍòAndroidÉ豸×é³ÉµÄ½©Ê¬ÍøÂçPareto


2.jpg


Human SecurityµÄ×êÑÐÈËÔ±·¢ÏÖÁËÓÉÉϰÙÍò¸ö±»Ï°È¾µÄAndroidÉ豸×é³ÉµÄÖØ´óµÄ½©Ê¬ÍøÂçPareto¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂçÓÚ2020Äê³õ´Î±»·¢ÏÖ£¬£¬£¬£¬ £¬ £¬£¬£¬Í¨¹ýÔÚ¶ñÒâµÄAndroidÒÆ¶¯ÀûÓ÷¨Ê½ÖкýŪÐźÅÀ´Ä£ÄâÔËÐÐÁËFire OS¡¢tvOS¡¢Roku OSºÍÆäËû³ÛÃûCTVƽ̨µÄÏû·ÑµçÊÓÁ÷ýÌå²úÆ·¡£¡£¡£¡£¡£ÆäʹÓÃÁËÊýÊ®¸öÒÆ¶¯ÀûÓÃÀ´·ÂÕÕ³¬¹ý6000¸öCTVÀûÓ÷¨Ê½£¬£¬£¬£¬ £¬ £¬£¬£¬¾ùÔÈÿÌì»á·¢³ö6.5Òڴθæ°×ÒªÇ󣬣¬£¬£¬ £¬ £¬£¬£¬¼Ù×°³ÉÉϰÙÍòµÄÈËÔÚÖÇÄܵçÊÓÉÏÅÔ¹Û¸æ°×¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/massive-android-botnet-hits-smart-tv-ad-ecosystem


3.QNAP°ä²¼°²È«¸üУ¬£¬£¬£¬ £¬ £¬£¬£¬½¨¸´NSAÖжà¸öÑϳÁµÄ·ì϶


3.jpg


ÍþÁªÍ¨£¨QNAP£©°ä²¼Á˰²È«²¼¸æ£¬£¬£¬£¬ £¬ £¬£¬£¬°ä·¢Òѽ¨¸´CVE-2021-28799·ì϶¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇλÓÚ¿àÄѸ´Ô­ºÍÊý¾Ý±¸·Ý½â¾ö¹æ»®HBS 3 Hybrid Backup SyncÖеÄÓ²±àÂëÍ´´¦·ì϶£¬£¬£¬£¬ £¬ £¬£¬£¬¿É±»ÓÃÀ´À´µÇ¼QNAP NAS£¨ÍøÂçÏνӴ洢£©É豸¡£¡£¡£¡£¡£Í³Ò»Ì죬£¬£¬£¬ £¬ £¬£¬£¬QNAP»¹½¨¸´ÁËQTSºÍQuTS heroÖеĺÅÁî×¢Èë·ì϶£¨CVE-2020-2509£©ºÍMedia Streaming Add-OnÖеÄSQL×¢Èë·ì϶£¨CVE-2020-36195£©µÈ·ì϶¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬ £¬£¬£¬QNAP³ÆÐÂÀÕË÷Èí¼þQlockerÔÚÀûÓÃCVE-2020-36195¶ÔÆäÉ豸ÉϵÄÊý¾Ý½øÐмÓÃÜ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/qnap-removes-backdoor-account-in-nas-backup-disaster-recovery-app/


4.EversourceÖÒ¸æÆä¿Í»§ÒòÔÆ´æ´¢ÅäÖÃÃýÎóÊý¾Ýй¶


4.jpg


3ÔÂ16ÈÕ£¬£¬£¬£¬ £¬ £¬£¬£¬ÐÂÓ¢¸ñÀ¼×î´óµÄÄÜÔ´ÌṩÉÌEversource Energy·¢ÏÔìäÔÆ´æ´¢ÅäÖÃÃýÎ󣬣¬£¬£¬ £¬ £¬£¬£¬²¢ÖÒ¸æ¿Í»§ËûÃǵÄÊý¾Ý¿ÉÄÜÒѾ­Ð¹Â¶¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢Éç»á±£Ïպš¢Õ˵¥µØÖ·ÒÔ¼°EversourceÕʺźͷþÎñµØÖ·£¬£¬£¬£¬ £¬ £¬£¬£¬Éæ¼°¾ÓסÔÚÂíÈøÖîÈûÖݵÄԼĪ11000¸ö¿Í»§¡£¡£¡£¡£¡£¸ÃÎļþ´´½¨ÓÚ2019Äê8Ô£¬£¬£¬£¬ £¬ £¬£¬£¬ÒѾ­ÒÔÃ÷ÎĵÄÌåʽ³ÖÐøÂ¶³öÁËÒ»ÄêÁãÆß¸öÔ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬ £¬£¬£¬Eversource¶ÔÄÇЩÊܵ½Ó°ÏìµÄ¿Í»§Ãâ·ÑÌṩÁË1ÄêµÄÉí·Ý¼à¿Ø·þÎñÀ´×÷ΪÅâ³¥¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/eversource-data-breach/


5.SignalÅû¶ºÚ¿Í¹«Ë¾Cellebrite¿ª·¢µÄÈí¼þÖеĶà¸ö·ì϶


5.jpg


SignalÅû¶ºÚ¿Í¹«Ë¾Cellebrite¿ª·¢µÄÈí¼þÖдæÔÚ¶à¸ö·ì϶£¬£¬£¬£¬ £¬ £¬£¬£¬ÔÊÐíÔÚÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£CellebriteµÄ²úƷͨ³£±»¾¯Ô±ºÍµ±¾ÖÓÃÀ´½âËøiOSºÍAndroidÊÖ»ú²¢ÌáÈ¡ÆäÖеÄÊý¾Ý£¬£¬£¬£¬ £¬ £¬£¬£¬È¥Äê12Ô£¬£¬£¬£¬ £¬ £¬£¬£¬¸Ã¹«Ë¾°ä·¢ÆäPhysical AnalyzerÒ²Äܹ»½Ó¼ûSignalµÄÊý¾Ý¡£¡£¡£¡£¡£SignalµÄCEO Moxie Marlinspike³Æ£¬£¬£¬£¬ £¬ £¬£¬£¬cellebriteµÄÈí¼þ¶¼ÊÇͨ¹ý¶ÈÎöÀ´×Ô²»³ÉÐÅÆðÔ´µÄÊý¾Ý½øÐй¤×÷µÄ£¬£¬£¬£¬ £¬ £¬£¬£¬Òò¶øËüÄܹ»½ÓÊÜÌåʽ²»ÕýÈ·µÄÊäÈ룬£¬£¬£¬ £¬ £¬£¬£¬Õâ¿ÉÄܻᴥ·¢ÄÚ´æ°Ü»µ·ì϶²¢µ¼Ö´úÂëÖ´ÐС£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/signal-ceo-gives-mobile-hacking-firm-a-taste-of-being-hacked/


6.ICT¹©¸øÉÌManagedITÔâ¹¥»÷£¬£¬£¬£¬ £¬ £¬£¬£¬ºÉÀ¼µÄ96¼Ò¹«Ö¤´¦ÎÞ·¨¹¤×÷


6.jpg


ºÉÀ¼»Ê¼ÒÃñ·¨¹«Ö¤ÈËЭ»á£¨KNB£©°ä²¼²¼¸æ³Æ£¬£¬£¬£¬ £¬ £¬£¬£¬ICT¹©¸øÉÌManaged ITÔâµ½¹¥»÷£¬£¬£¬£¬ £¬ £¬£¬£¬ºÉÀ¼µÄ96¼Ò¹«Ö¤´¦ÎÞ·¨¹¤×÷¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ4ÔÂ16ÈÕ£¨ÐÇÆÚÎ壩ÉÏÎç·¢ÏÖÁËÕâ´Î¹¥»÷£¬£¬£¬£¬ £¬ £¬£¬£¬²¢Á¢¼´¶Ï¿ªÁËÓë¶à¸ö¹«Ö¤Èí¼þ¹©¸øÉ̵ķþÎñÆ÷ºÍÊý¾Ý¿âµÄÏνӣ¬£¬£¬£¬ £¬ £¬£¬£¬Õâµ¼ÖÂÁË96¸ö¹«Ö¤´¦ÎÞ·¨½øÐÐÊý×Ö»¯¹¤×÷¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬ £¬ £¬£¬£¬ÓÉÓÚ¶ÌȱÓйع¥»÷µÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬ £¬ £¬£¬£¬Òò¶øÉв»ÄÜÈ·¶¨Õâ´Î¹¥»÷µÄÀàÐÍÒÔ¼°ÌáÒé¹¥»÷µÄ×éÖ¯¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/nl-nearly-a-hundred-notary-offices-victim-of-hacker/