2019ÄêÊý¾Ýй¶ÊӲ챨¸æ£»£»£» £»UCä¯ÀÀÆ÷δÐÞ¸´µÄµØµãÀ¸ÓÕÆ­Îó²î£»£»£» £»2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼й¶

Ðû²¼Ê±¼ä 2019-05-09
1¡¢VerizonÐû²¼2019ÄêÊý¾Ýй¶ÊӲ챨¸æ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾
 
VerizonÐû²¼2019ÄêÊý¾Ýй¶ÊӲ챨¸æ£¨DBIR£©£¬£¬£¬ £¬£¬£¬£¬¸Ã±¨¸æÆÊÎöÁË86¸ö¹ú¼Ò±¬·¢µÄ41000¶àÆðÍøÂçÇå¾²ÊÂÎñºÍ2000¶àÆðÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¸Ã±¨¸æÖ¸³ö£¬£¬£¬ £¬£¬£¬£¬´Ó2018Äê×îÏÈÔÆ´æ´¢ÉèÖùýʧ¡¢BECºÍ֪ʶ²úȨ͵ÇÔ¶¼´¦ÓÚÉÏÉýÇ÷ÊÆ¡£¡£¡£¡£¡£ÒÔÉÌÒµÌØ¹¤»î¶¯ÎªÄîÍ·µÄÍøÂç¹¥»÷ÓÐËùÔöÌí£¬£¬£¬ £¬£¬£¬£¬ÔÚÒÑÍùµÄ12¸öÔÂÀ£¬£¬ £¬£¬£¬£¬ÓÐ1/4µÄÍøÂçÈëÇÖÓëÕì̽ºÍÊý¾ÝÉøÂ©ÓйØ¡£¡£¡£¡£¡£×ÜÌå¶øÑÔ´ó´ó¶¼ÍøÂç¹¥»÷¶¼ÊÇÒÔ¾­¼ÃÀûÒæ×÷ΪÇý¶¯¡£¡£¡£¡£¡£²»ÐÒµÄÊÇ£¬£¬£¬ £¬£¬£¬£¬ÓÐÒ»°ëµÄÆóÒµÐè񻮮·ÑÊýÔÂÉõÖÁ¸ü³¤µÄʱ¼äÀ´·¢Ã÷ÈëÇÖÐÐΪ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://enterprise.verizon.com/resources/reports/2019-data-breach-investigations-report.pdf

2¡¢UCä¯ÀÀÆ÷±»ÆØ±£´æÎ´ÐÞ¸´µÄµØµãÀ¸ÓÕÆ­Îó²î

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾
 
Çå¾²Ñо¿Ö°Ô±Arif Khan·¢Ã÷UCä¯ÀÀÆ÷±£´æÒ»¸öÉÐδÐÞ¸´µÄµØµãÀ¸ÓÕÆ­Îó²î¡£¡£¡£¡£¡£UCä¯ÀÀÆ÷Êǰ¢Àï°Í°ÍÆìϵÄUCWeb¿ª·¢µÄä¯ÀÀÆ÷£¬£¬£¬ £¬£¬£¬£¬ÔÚÖйúºÍÓ¡¶ÈÓµÓÐÁè¼Ý5ÒÚÓû§¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚä¯ÀÀÆ÷µÄÓû§½çÃæ´¦Öóͷ£ÌØÊâÄÚÖù¦Ð§£¨¸Ã¹¦Ð§Ö¼ÔÚ¸ÄÉÆÓû§µÄGoogleËÑË÷ÌåÑ飩µÄ·½·¨£¬£¬£¬ £¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷Õß¿ØÖƵصãÀ¸ÖÐÏÔʾµÄURL×Ö·û´®£¬£¬£¬ £¬£¬£¬£¬ÓÕÆ­Óû§»á¼û¶ñÒâÍøÕ¾¡£¡£¡£¡£¡£¸ÃÎó²îÉÐδ·ÖÅÉCVE±àºÅ£¬£¬£¬ £¬£¬£¬£¬UCä¯ÀÀÆ÷µÄ×îа汾12.11.2.1184ºÍUC Miniä¯ÀÀÆ÷µÄ×îа汾12.10.1.1192¾ùÊÜÓ°Ïì¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/05/uc-browser-url-spoofing.html

3¡¢Freedom MobileÒâÍâй¶½ü500ÍòÌõÓû§¼Í¼

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾
 
¼ÓÄôóµçÐŹ«Ë¾Freedom MobileµÄÒ»¸ö°üÀ¨¿Í»§Êý¾ÝµÄElasticSearchÊý¾Ý¿âÒòÉèÖùýʧÔÚÍøÉÏ̻¶£¬£¬£¬ £¬£¬£¬£¬µ¼Ö½ü500ÍòÌõ¿Í»§¼Í¼й¶¡£¡£¡£¡£¡£Æ¾Ö¤Çå¾²Ñо¿Ô±Noam RotemºÍRan LocarµÄ·¢Ã÷£¬£¬£¬ £¬£¬£¬£¬¸ÃÊý¾Ý¿âÊôÓÚFreedom MobileµÄµÚÈý·½Ð§ÀÍÌṩÉÌApptium¡£¡£¡£¡£¡£¸Ã¹«Ë¾½²»°ÈËÌåÏÖ£¬£¬£¬ £¬£¬£¬£¬Ð¹Â¶ÊÂÎñÓ°ÏìÁË3ÔÂ25ÈÕÖÁ4ÔÂ15ÈÕʱ´úÔÚ17¸öFreedom MobileÓªÒµÌü¿ªÉè»ò¸ü¸ÄÕË»§µÄÓû§£¬£¬£¬ £¬£¬£¬£¬Ô¼ÓÐ1.5ÍòÓû§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢²»µ«°üÀ¨Óû§µÄÐÕÃû¡¢ÓÊÏäµÈСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬ £¬£¬£¬£¬»¹°üÀ¨ÐÅÓÿ¨ºÅµÈÖ§¸¶ÐÅÏ¢¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/freedom-mobile-exposed-almost-5-million-customer-records-due-to-a-misconfigured-database-fddd4855

4¡¢ºº±¤Íõ¶ùͯÊÐËÁÒâÍâй¶½ü4ÍòÌõÓû§¼Í¼

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾
 
Çå¾²Ñо¿Ô±Bob Diachenko·¢Ã÷ºº±¤ÍõµÄÒ»¸öרΪ¶ùͯЧÀ͵퍹úÍøÉÏÊÐËÁÒâÍâй¶ÁË37900Ìõ¿Í»§¼Í¼¡£¡£¡£¡£¡£ÕâЩ¼Í¼°üÀ¨ÔÚÒ»¸öδÊܱ£»£»£» £»¤µÄElasticsearch¼¯ÈºÖУ¬£¬£¬ £¬£¬£¬£¬¸ÃÊý¾Ý¿âÖÁÉÙ´Ó4ÔÂ24ÈÕ×îÏÈÔÚÍøÉÏ̻¶¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢²»µ«°üÀ¨Óû§µÄÐÕÃû¡¢µç»°µÈPIIÐÅÏ¢£¬£¬£¬ £¬£¬£¬£¬»¹°üÀ¨²¿·ÖÔ±¹¤µÄÓÊÏ䵨µã¡¢CRMºó¶ËÈÕÖ¾µÈÐÅÏ¢¡£¡£¡£¡£¡£Î´Êܱ£»£»£» £»¤µÄElasticSearchÊý¾Ý¿âÕýÔÚ³ÉΪ³£Ì¬¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/burger-kings-online-store-for-kids-exposes-customers-info/

5¡¢AWSÉÏδÊܱ£»£»£» £»¤µÄMongoDBй¶Áè¼Ý2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾
 
Çå¾²Ñо¿Ô±Bob DiachenkoʹÓÃShodan·¢Ã÷ÔÚAmazon AWSÉÏÍйܵÄÒ»¸ö¿É¹ûÕæ»á¼ûµÄMongoDBÊý¾Ý¿â£¬£¬£¬ £¬£¬£¬£¬¸ÃÊý¾Ý¿âй¶ÁËÁè¼Ý2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢ÓÊÏä¡¢ÊÖ»úºÅÂë¡¢Ö°ÒµºÍнˮµÈPII£¬£¬£¬ £¬£¬£¬£¬µ«DiachenkoûÓз¢Ã÷¸ÃÊý¾Ý¿âµÄ¹éÊô×éÖ¯¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÓÚ4ÔÂ23ÈÕ×îÏÈÔÚÍøÉÏ̻¶¡£¡£¡£¡£¡£Diachenko֪ͨÁËÓ¡¶ÈCERT£¬£¬£¬ £¬£¬£¬£¬µ«¸ÃÊý¾Ý¿â²¢Î´Êܵ½±£»£»£» £»¤£¬£¬£¬ £¬£¬£¬£¬Ö±µ½5ÔÂ8ÈÕ·¸·¨ÍÅ»ïUnistellarɾ³ýÁ˸ÃÊý¾Ý¿â²¢ÁôÏÂÁËÁªÏµ·½·¨¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/over-275-million-records-exposed-by-unsecured-mongodb-database/

6¡¢°Í¶ûµÄĦÊÐÕþÌüºÍ²¨ÌØÏؾùÔâÀÕË÷Èí¼þ¹¥»÷

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾
 
µÂ¿ËÈøË¹Öݲ¨ÌØÏؼ°ÂíÀïÀ¼ÖݰͶûµÄĦÊÐÕþÌü¾ùÔâÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£Æ¾Ö¤°Í¶ûµÄĦÊг¤Jack YoungµÄ¹Ù·½ÉùÃ÷£¬£¬£¬ £¬£¬£¬£¬¸ÃÊеĽ¹µãЧÀÍ£¨¾¯Ô±¡¢Ïû·À¡¢EMSºÍ311£©ÈÔÔÚÔË×÷£¬£¬£¬ £¬£¬£¬£¬µ«ÒÑÈ·½¨¶¼»áÍøÂçѬȾÁËÀÕË÷²¡¶¾£¬£¬£¬ £¬£¬£¬£¬³öÓÚÔ¤·À¸ÃÊÐÒѾ­¹Ø±ÕÁ˴󲿷ÖЧÀÍÆ÷¡£¡£¡£¡£¡£¶øÆ¾Ö¤NewsChannel 10µÄ˵·¨£¬£¬£¬ £¬£¬£¬£¬²¨ÌØÏØÔÚ4ÔÂ22ÈÕÔâµ½¶ñÒâÈí¼þ¹¥»÷ºó£¬£¬£¬ £¬£¬£¬£¬ÒѾ­Ïë·¨½«²¿·ÖÅÌËã»úÏµÍ³ÖØÐÂÉÏÏß¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/local-authorities-in-texas-and-maryland-hit-by-ransomware/