ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸Áбí £»ºÚ¿ÍʹÓÃÆ¾Ö¤Ìî³ä¹¥»÷Áè¼Ý30Íò¸öSpotifyÓû§

Ðû²¼Ê±¼ä 2020-11-24
1.ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸Áбí


1.jpg


ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸Áбí £¬ÆäÖаüÀ¨À´×ÔÌìϸ÷µØµÄ´óÐÍÒøÐкÍÕþ¸®×éÖ¯ ¡£ÕâЩװ±¸Öоù±£´æÂ·¾¶±éÀúÎó²î £¬±»×·×ÙΪCVE-2018-13379 £¬ËüÓ°ÏìÁË´ó×ÚδÐÞ²¹µÄFortinet FortiOS SSL VPN×°±¸ ¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î £¬´ÓFortinet VPN»á¼ûsslvpn_websessionÎļþÀ´ÇÔÈ¡µÇ¼ƾ֤ £¬²¢½«ÆäÓÃÓÚÆÆËðÍøÂç²¢°²ÅÅÀÕË÷Èí¼þ ¡£Ö»¹Ü¸ÃÎó²îÔÚÒ»Äêǰ¾Í±»¹ûÕæÅû¶ £¬µ«ºÚ¿ÍÈÔ·¢Ã÷²¢¹ûÕæÁËÁË49577¸ö±£´æ´ËÀàÎó²îµÄ´óÐÍ×°±¸µÄÁбí ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-posts-exploits-for-over-49-000-vulnerable-fortinet-vpns/


2.ºÚ¿ÍʹÓÃÆ¾Ö¤Ìî³ä¹¥»÷Áè¼Ý30Íò¸öSpotifyÓû§


2.jpg


VPNMentorÑо¿Ö°Ô±·¢Ã÷ £¬ºÚ¿ÍÕýÔÚʹÓðüÀ¨3ÒÚ¸öÓû§ÃûºÍÃÜÂë×éºÏµÄÊý¾Ý¿â £¬¶ÔSpotifyÓû§Ìᳫƾ֤Ìî³ä¹¥»÷ ¡£¸ÃÊý¾Ý¿âÖеÄÿ¸ö¼Í¼¶¼°üÀ¨Ò»¸öµÇ¼Ãû£¨µç×ÓÓʼþµØÖ·£©¡¢Ò»¸öÃÜÂëÒÔ¼°¸Ãƾ֤ÊÇ·ñ¿ÉÒÔÀֳɵǼµ½SpotifyÕÊ»§µÄ·´Ïì ¡£Ñо¿Ö°Ô±ÒÔΪ £¬Êý¾Ý¿âÖÐÁгöµÄ3ÒÚÌõ¼Í¼¿Éʹ¹¥»÷Õß¹¥ÆÆ300000ÖÁ350000¸öSpotifyÕÊ»§ ¡£ÏÖÔÚ £¬SpotifyΪËùÓÐÊÜÓ°ÏìµÄÓû§¾ÙÐÐת¶¯ÖØÖÃÃÜÂë £¬µ«ÈÔ²»Ö§³ÖÖ§³Ö¶àÒòËØÉí·ÝÑéÖ¤ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/over-300k-spotify-accounts-hacked-in-credential-stuffing-attack/


3.¼ÓÄôóÊ¥Ô¼º²ÊÐÔâÍøÂç¹¥»÷ £¬µ¼ÖÂÊÐÕþÍøÂç̱»¾


3.jpg


11ÔÂ15ÈÕ £¬¼ÓÄôóÊ¥Ô¼º²ÊÐÔâÊÜ´ó¹æÄ£ÍøÂç¹¥»÷ £¬ÑÏÖØÆÆËðÁËÕû¸ö¶¼»áµÄÊÐÕþ»ù´¡ÉèÊ© ¡£´Ë´Î¹¥»÷µ¼ÖÂÕû¸öÊÐÕþÍøÂç¹Ø±Õ £¬°üÀ¨¶¼»áÍøÕ¾¡¢ÔÚÏßÖ§¸¶ÏµÍ³¡¢µç×ÓÓʼþºÍ¿Í»§·þÎñÓ¦ÓóÌÐò £¬µ«²¢Î´ÓÐÈκÎÊÐÃñµÄСÎÒ˽¼ÒÐÅÏ¢±»Ð¹Â¶ ¡£×¨¼ÒÒÔΪ £¬´ËÊÂÎñΪÓÉÀÕË÷Èí¼þ¹¥»÷µ¼ÖµÄ £¬Ô¤¼Æ¿ÉÄÜÐèÒª¼¸¸öÐÇÆÚ²Å»ªÍêÈ«»Ö¸´Õý³£ ¡£ÏÖÔÚ £¬¸ÃÊÐÕýÔÚÓëÁª°îºÍÊ¡Õþ¸®ºÏ×÷ £¬ÒÔ´ÓÍøÂç¹¥»÷Öлָ´¹ýÀ´ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/111259/cyber-crime/saint-john-cyber-attack.html


4.Pickle FinanceÏîÄ¿Ôâ¹¥»÷ £¬Ëðʧ½ü2000ÍòÃÀÔª


4.jpg


Á÷¶¯ÐÔÍÚ¿óÏîÄ¿Pickle FinanceÔâµ½¹¥»÷ £¬Ëðʧ½ü2000ÍòÃÀÔª ¡£´Ë´Î¹¥»÷ÖÐ £¬ºÚ¿Í²¢Ã»ÓÐʹÓÃ×î½üÔÚ´ó´ó¶¼ÀàËÆÊÂÎñÖзºÆðµÄFlash Loan £¬¶øÊǰ²ÅÅÁËÒ»¸ö¶ñÒâjarÀ´Î±ÔìµÄ½»Á÷ £¬ÒÔʹÓÃPickle FinanceÖÇÄܺÏÔ¼DAI PickleJarÖеÄÎó²î ¡£¸ÃÏîÄ¿µÄÍŶÓÌåÏÖ £¬Æä19759355¸öDAIÒѱ»ºÄ¾¡ £¬¶ø¸ÃÏîÄ¿µÄÁîÅÆ£¨PICKLE£©Ò²ÔÚÔâÊܺڿ͹¥»÷ºóËðʧÁËÆä¼ÛÖµµÄ50£¥ÒÔÉÏ £¬µÖ´ïÁË8.84ÃÀÔªµÄµÍµã ¡£


Ô­ÎÄÁ´½Ó£º

https://www.fxstreet.com/cryptocurrencies/news/nearly-20-million-stolen-from-the-defi-protocol-pickle-finance-202011221250


5.ÁãÊÛ¹«Ë¾E-LandѬȾÀÕË÷Èí¼þµ¼Ö½ü°ëÊýÊÐËÁ¹Ø±Õ


5.jpg


º«¹úʱװºÍÁãÊÛ¼¯ÍÅE-Land GroupÖÜÈÕÌåÏÖ £¬ÓÉÓÚѬȾÀÕË÷Èí¼þ £¬Æä°ëÊýÊÐËÁ¹Ø±Õ ¡£¸Ã×éÖ¯³ÆÆä¹«Ë¾ÍøÂçϵͳÔÚÇåÔçÔâµ½ÀÕË÷Èí¼þµÄ¹¥»÷ £¬ÆÈʹÆäNC°Ù»õÊÐËÁºÍNewCore OutletµÄ50¸ö·ÖÖ§»ú¹¹ÖеÄ23¸ö×èÖ¹ÁËÔËÓª ¡£E-LandÌåÏÖ £¬ÏÖÔÚÒÑ¹Ø±ÕÆä²¿·Ö¹«Ë¾ÍøÂçϵͳ £¬ÒÔ×îºéÁ÷ƽµØïÔÌ­Ë𺦠£¬²¢ÒÑÒªÇ󾯷½ÊÓ²ìÍøÂç¹¥»÷ ¡£    


Ô­ÎÄÁ´½Ó£º

https://www.koreatimes.co.kr/www/tech/2020/11/694_299692.html


6.WiproÐû²¼ÓйØÊ¹ÓÃAIºÍMLÓ¦¶ÔÍøÂç¹¥»÷µÄÆÊÎö±¨¸æ


6.jpg


WiproÐû²¼ÁËÓйØÊ¹ÓÃAIºÍMLÓ¦¶ÔÍøÂç¹¥»÷µÄÆÊÎö±¨¸æ ¡£±¨¸æ·¢Ã÷ £¬ÔÚÒÑÍùµÄËÄÄêÀï £¬È«ÇòÓÐ49%µÄÓëÍøÂçÇå¾²Ïà¹ØµÄרÀû¶¼ÓëÈ˹¤ÖÇÄܺͻúеѧϰµÄÓ¦ÓÃÓÐ¹Ø ¡£¶ø½üÒ»°ë£¨49£¥£©µÄ×éÖ¯ÕýÔÚÀ©Õ¹ÈÏÖª¼ì²âÄÜÁ¦ £¬ÒÔÓ¦¶ÔÆäÇå¾²ÔËÓªÖÐÐÄ(SOC)ÖеÄδ֪¹¥»÷ ¡£65£¥µÄ×éÖ¯ÕýÔÚ¶Ô²Ù×÷ÊÖÒÕ£¨OT£©ºÍIoT×°±¸¾ÙÐÐÈÕÖ¾¼à¿Ø £¬ÒÔ¼õÇáOTΣº¦µÄÔöÌí ¡£57£¥µÄ×éÖ¯Ö»Ô¸Òâ¹²ÏíIoC £¬64£¥µÄ×éÖ¯ÒÔΪÉùÓþΣº¦ÊÇÐÅÏ¢¹²ÏíµÄ×è°­ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/11/23/ai-ml-tackle-unknown-attacks/