Ñо¿ÍŶÓÍøÂç130¶àÍò¸öRDPÕÊ»§£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖдó¶¼À´×ÔÒ½ÁÆÐÐÒµ£»£»£»£»SignalÅû¶ºÚ¿Í¹«Ë¾Cellebrite¿ª·¢µÄÈí¼þÖеĶà¸öÎó²î
Ðû²¼Ê±¼ä 2021-04-231.Ñо¿ÍŶÓÍøÂç130¶àÍò¸öRDPÕÊ»§£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖдó¶¼À´×ÔÒ½ÁÆÐÐÒµ

Çå¾²ÍŶÓ×Ô2018Äê12ÔÂÒÔÀ´ÉñÃØ»á¼ûÁËÏÖÔÚ×î´ó°µÍøUASµÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬²¢ÍøÂçÁ˽üÈýÄêÀ´³öÊÛµÄ1379609¸öRDPƾ֤¡£¡£¡£ÁгöµÄRDPЧÀÍÆ÷À´×ÔÌìϸ÷µØ£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨À´×Ô63¸ö¹ú¼ÒºÍµØÇøµÄÕþ¸®»ú¹¹¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩÕË»§×î³£ÓõĵǼÃûÊÇ'Administrator'¡¢'Admin'¡¢'User'¡¢'test'ºÍ'scanner'£¬£¬£¬£¬£¬£¬£¬£¬×î³£ÓõÄÃÜÂëÊÇ123456¡¢123¡¢P@ssw0rd¡¢1234ºÍPassword1£¬£¬£¬£¬£¬£¬£¬£¬Ö÷񻃾¼°ÃÀ¹ú¡¢Öйú¡¢°ÍÎ÷¡¢µÂ¹ú¡¢Ó¡¶ÈºÍÓ¢¹úµÈ¹ú¼Ò¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/logins-for-13-million-windows-rdp-servers-collected-from-hacker-market/
2.Ñо¿Ö°Ô±·¢Ã÷ÓÉÉϰÙÍòAndroid×°±¸×é³ÉµÄ½©Ê¬ÍøÂçPareto

Human SecurityµÄÑо¿Ö°Ô±·¢Ã÷ÁËÓÉÉϰÙÍò¸ö±»Ñ¬È¾µÄAndroid×°±¸×é³ÉµÄÖØ´óµÄ½©Ê¬ÍøÂçPareto¡£¡£¡£¸Ã½©Ê¬ÍøÂçÓÚ2020ÄêÊ״α»·¢Ã÷£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÔÚ¶ñÒâµÄAndroidÒÆ¶¯Ó¦ÓóÌÐòÖÐÓÕÆÐźÅÀ´Ä£ÄâÔËÐÐÁËFire OS¡¢tvOS¡¢Roku OSºÍÆäËûÖøÃûCTVƽ̨µÄÏûºÄµçÊÓÁ÷ýÌå²úÆ·¡£¡£¡£ÆäʹÓÃÁËÊýÊ®¸öÒÆ¶¯Ó¦ÓÃÀ´Ä£ÄâÁè¼Ý6000¸öCTVÓ¦ÓóÌÐò£¬£¬£¬£¬£¬£¬£¬£¬Æ½¾ùÌìÌì»á·¢³ö6.5ÒÚ´Î¹ã¸æÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬Ã°³ä³ÉÉϰÙÍòµÄÈËÔÚÖÇÄܵçÊÓÉÏԢĿ¹ã¸æ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/massive-android-botnet-hits-smart-tv-ad-ecosystem
3.QNAPÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´NSAÖжà¸öÑÏÖØµÄÎó²î

ÍþÁªÍ¨£¨QNAP£©Ðû²¼ÁËÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬£¬Ðû²¼ÒÑÐÞ¸´CVE-2021-28799Îó²î¡£¡£¡£¸ÃÎó²îÊÇλÓÚÔÖÄѻָ´ºÍÊý¾Ý±¸·Ý½â¾ö¼Æ»®HBS 3 Hybrid Backup SyncÖеÄÓ²±àÂëÆ¾Ö¤Îó²î£¬£¬£¬£¬£¬£¬£¬£¬¿É±»ÓÃÀ´À´µÇ¼QNAP NAS£¨ÍøÂçÅþÁ¬´æ´¢£©×°±¸¡£¡£¡£Í³Ò»Ì죬£¬£¬£¬£¬£¬£¬£¬QNAP»¹ÐÞ¸´ÁËQTSºÍQuTS heroÖеÄÏÂÁî×¢ÈëÎó²î£¨CVE-2020-2509£©ºÍMedia Streaming Add-OnÖеÄSQL×¢ÈëÎó²î£¨CVE-2020-36195£©µÈÎó²î¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬QNAP³ÆÐÂÀÕË÷Èí¼þQlockerÕýÔÚʹÓÃCVE-2020-36195¶ÔÆäÉè±¹ØÁ¬ÄÊý¾Ý¾ÙÐмÓÃÜ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/qnap-removes-backdoor-account-in-nas-backup-disaster-recovery-app/
4.EversourceÖÒÑÔÆä¿Í»§ÒòÔÆ´æ´¢ÉèÖùýʧÊý¾Ýй¶

3ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÐÂÓ¢¸ñÀ¼×î´óµÄÄÜÔ´ÌṩÉÌEversource Energy·¢Ã÷ÆäÔÆ´æ´¢ÉèÖùýʧ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÖÒÑÔ¿Í»§ËûÃǵÄÊý¾Ý¿ÉÄÜÒѾй¶¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¡¢Éç»á°ü¹ÜºÅ¡¢Õ˵¥µØµãÒÔ¼°EversourceÕʺźÍЧÀ͵ص㣬£¬£¬£¬£¬£¬£¬£¬Éæ¼°ÆÜÉíÔÚÂíÈøÖîÈûÖݵÄԼĪ11000¸ö¿Í»§¡£¡£¡£¸ÃÎļþ½¨ÉèÓÚ2019Äê8Ô£¬£¬£¬£¬£¬£¬£¬£¬ÒѾÒÔÃ÷ÎĵÄÃûÌÃÒ»Á¬Ì»Â¶ÁËÒ»ÄêÁãÆß¸öÔ¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬Eversource¶ÔÄÇЩÊܵ½Ó°ÏìµÄ¿Í»§Ãâ·ÑÌṩÁË1ÄêµÄÉí·Ý¼à¿ØÐ§ÀÍÀ´×÷ΪÅâ³¥¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/eversource-data-breach/
5.SignalÅû¶ºÚ¿Í¹«Ë¾Cellebrite¿ª·¢µÄÈí¼þÖеĶà¸öÎó²î

SignalÅû¶ºÚ¿Í¹«Ë¾Cellebrite¿ª·¢µÄÈí¼þÖб£´æ¶à¸öÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔÚ×°±¸ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£CellebriteµÄ²úƷͨ³£±»¾¯Ô±ºÍÕþ¸®ÓÃÀ´½âËøiOSºÍAndroidÊÖ»ú²¢ÌáÈ¡ÆäÖеÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬È¥Äê12Ô£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Ðû²¼ÆäPhysical AnalyzerÒ²¿ÉÒÔ»á¼ûSignalµÄÊý¾Ý¡£¡£¡£SignalµÄCEO Moxie Marlinspike³Æ£¬£¬£¬£¬£¬£¬£¬£¬cellebriteµÄÈí¼þ¶¼ÊÇ̫ͨ¹ýÎöÀ´×Ô²»¿ÉÐÅȪԴµÄÊý¾Ý¾ÙÐÐÊÂÇéµÄ£¬£¬£¬£¬£¬£¬£¬£¬Òò´ËËü¿ÉÒÔ½ÓÊÜÃûÌò»×¼È·µÄÊäÈ룬£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄܻᴥ·¢ÄÚ´æËð»µÎó²î²¢µ¼Ö´úÂëÖ´ÐС£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/signal-ceo-gives-mobile-hacking-firm-a-taste-of-being-hacked/
6.ICT¹©Ó¦ÉÌManagedITÔâ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ºÉÀ¼µÄ96¼Ò¹«Ö¤´¦ÎÞ·¨ÊÂÇé

ºÉÀ¼»Ê¼ÒÃñ·¨ÆÀÅÐÈËлᣨKNB£©Ðû²¼Í¨¸æ³Æ£¬£¬£¬£¬£¬£¬£¬£¬ICT¹©Ó¦ÉÌManaged ITÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ºÉÀ¼µÄ96¼Ò¹«Ö¤´¦ÎÞ·¨ÊÂÇé¡£¡£¡£¸Ã¹«Ë¾ÓÚ4ÔÂ16ÈÕ£¨ÐÇÆÚÎ壩ÉÏÎç·¢Ã÷Á˴˴ι¥»÷£¬£¬£¬£¬£¬£¬£¬£¬²¢Á¬Ã¦¶Ï¿ªÁËÓë¶à¸ö¹«Ö¤Èí¼þ¹©Ó¦É̵ÄЧÀÍÆ÷ºÍÊý¾Ý¿âµÄÅþÁ¬£¬£¬£¬£¬£¬£¬£¬£¬Õâµ¼ÖÂÁË96¸ö¹«Ö¤´¦ÎÞ·¨¾ÙÐÐÊý×Ö»¯ÊÂÇé¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚȱÉÙÓйع¥»÷µÄÏêϸÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Òò´ËÉв»¿ÉÈ·¶¨´Ë´Î¹¥»÷µÄÀàÐÍÒÔ¼°Ìᳫ¹¥»÷µÄ×éÖ¯¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/nl-nearly-a-hundred-notary-offices-victim-of-hacker/


¾©¹«Íø°²±¸11010802024551ºÅ