ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸ÁÐ±í£»ºÚ¿ÍʹÓÃÆ¾Ö¤Ìî³ä¹¥»÷Áè¼Ý30Íò¸öSpotifyÓû§
Ðû²¼Ê±¼ä 2020-11-24
ºÚ¿Í¹ûÕæ5Íò¸ö±£´æÎó²îµÄFortinet VPN×°±¸ÁÐ±í£¬ÆäÖаüÀ¨À´×ÔÌìϸ÷µØµÄ´óÐÍÒøÐкÍÕþ¸®×éÖ¯¡£ÕâЩװ±¸Öоù±£´æÂ·¾¶±éÀúÎó²î£¬±»×·×ÙΪCVE-2018-13379£¬ËüÓ°ÏìÁË´ó×ÚδÐÞ²¹µÄFortinet FortiOS SSL VPN×°±¸¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î£¬´ÓFortinet VPN»á¼ûsslvpn_websessionÎļþÀ´ÇÔÈ¡µÇ¼ƾ֤£¬²¢½«ÆäÓÃÓÚÆÆËðÍøÂç²¢°²ÅÅÀÕË÷Èí¼þ¡£Ö»¹Ü¸ÃÎó²îÔÚÒ»Äêǰ¾Í±»¹ûÕæÅû¶£¬µ«ºÚ¿ÍÈÔ·¢Ã÷²¢¹ûÕæÁËÁË49577¸ö±£´æ´ËÀàÎó²îµÄ´óÐÍ×°±¸µÄÁÐ±í¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hacker-posts-exploits-for-over-49-000-vulnerable-fortinet-vpns/
2.ºÚ¿ÍʹÓÃÆ¾Ö¤Ìî³ä¹¥»÷Áè¼Ý30Íò¸öSpotifyÓû§

VPNMentorÑо¿Ö°Ô±·¢Ã÷£¬ºÚ¿ÍÕýÔÚʹÓðüÀ¨3ÒÚ¸öÓû§ÃûºÍÃÜÂë×éºÏµÄÊý¾Ý¿â£¬¶ÔSpotifyÓû§Ìᳫƾ֤Ìî³ä¹¥»÷¡£¸ÃÊý¾Ý¿âÖеÄÿ¸ö¼Í¼¶¼°üÀ¨Ò»¸öµÇ¼Ãû£¨µç×ÓÓʼþµØµã£©¡¢Ò»¸öÃÜÂëÒÔ¼°¸Ãƾ֤ÊÇ·ñ¿ÉÒÔÀֳɵǼµ½SpotifyÕÊ»§µÄ·´Ïì¡£Ñо¿Ö°Ô±ÒÔΪ£¬Êý¾Ý¿âÖÐÁгöµÄ3ÒÚÌõ¼Í¼¿Éʹ¹¥»÷Õß¹¥ÆÆ300000ÖÁ350000¸öSpotifyÕÊ»§¡£ÏÖÔÚ£¬SpotifyΪËùÓÐÊÜÓ°ÏìµÄÓû§¾ÙÐÐת¶¯ÖØÖÃÃÜÂ룬µ«ÈÔ²»Ö§³ÖÖ§³Ö¶àÒòËØÉí·ÝÑéÖ¤¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/over-300k-spotify-accounts-hacked-in-credential-stuffing-attack/
3.¼ÓÄôóÊ¥Ô¼º²ÊÐÔâÍøÂç¹¥»÷£¬µ¼ÖÂÊÐÕþÍøÂç̱»¾

11ÔÂ15ÈÕ£¬¼ÓÄôóÊ¥Ô¼º²ÊÐÔâÊÜ´ó¹æÄ£ÍøÂç¹¥»÷£¬ÑÏÖØÆÆËðÁËÕû¸ö¶¼»áµÄÊÐÕþ»ù´¡ÉèÊ©¡£´Ë´Î¹¥»÷µ¼ÖÂÕû¸öÊÐÕþÍøÂç¹Ø±Õ£¬°üÀ¨¶¼»áÍøÕ¾¡¢ÔÚÏßÖ§¸¶ÏµÍ³¡¢µç×ÓÓʼþºÍ¿Í»§·þÎñÓ¦ÓóÌÐò£¬µ«²¢Î´ÓÐÈκÎÊÐÃñµÄСÎÒ˽¼ÒÐÅÏ¢±»Ð¹Â¶¡£×¨¼ÒÒÔΪ£¬´ËÊÂÎñΪÓÉÀÕË÷Èí¼þ¹¥»÷µ¼Öµģ¬Ô¤¼Æ¿ÉÄÜÐèÒª¼¸¸öÐÇÆÚ²Å»ªÍêÈ«»Ö¸´Õý³£¡£ÏÖÔÚ£¬¸ÃÊÐÕýÔÚÓëÁª°îºÍÊ¡Õþ¸®ÏàÖú£¬ÒÔ´ÓÍøÂç¹¥»÷Öлָ´¹ýÀ´¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/111259/cyber-crime/saint-john-cyber-attack.html
4.Pickle FinanceÏîÄ¿Ôâ¹¥»÷£¬Ëðʧ½ü2000ÍòÃÀÔª

Á÷¶¯ÐÔÍÚ¿óÏîÄ¿Pickle FinanceÔâµ½¹¥»÷£¬Ëðʧ½ü2000ÍòÃÀÔª¡£´Ë´Î¹¥»÷ÖУ¬ºÚ¿Í²¢Ã»ÓÐʹÓÃ×î½üÔÚ´ó´ó¶¼ÀàËÆÊÂÎñÖзºÆðµÄFlash Loan£¬¶øÊǰ²ÅÅÁËÒ»¸ö¶ñÒâjarÀ´Î±ÔìµÄ½»Á÷£¬ÒÔʹÓÃPickle FinanceÖÇÄܺÏÔ¼DAI PickleJarÖеÄÎó²î¡£¸ÃÏîÄ¿µÄÍŶÓÌåÏÖ£¬Æä19759355¸öDAIÒѱ»ºÄ¾¡£¬¶ø¸ÃÏîÄ¿µÄÁîÅÆ£¨PICKLE£©Ò²ÔÚÔâÊܺڿ͹¥»÷ºóËðʧÁËÆä¼ÛÖµµÄ50£¥ÒÔÉÏ£¬µÖ´ïÁË8.84ÃÀÔªµÄµÍµã¡£
ÔÎÄÁ´½Ó£º
https://www.fxstreet.com/cryptocurrencies/news/nearly-20-million-stolen-from-the-defi-protocol-pickle-finance-202011221250
5.ÁãÊÛ¹«Ë¾E-LandѬȾÀÕË÷Èí¼þµ¼Ö½ü°ëÊýÊÐËÁ¹Ø±Õ

º«¹úʱװºÍÁãÊÛ¼¯ÍÅE-Land GroupÖÜÈÕÌåÏÖ£¬ÓÉÓÚѬȾÀÕË÷Èí¼þ£¬Æä°ëÊýÊÐËÁ¹Ø±Õ¡£¸Ã×éÖ¯³ÆÆä¹«Ë¾ÍøÂçϵͳÔÚÇåÔçÔâµ½ÀÕË÷Èí¼þµÄ¹¥»÷£¬ÆÈʹÆäNC°Ù»õÊÐËÁºÍNewCore OutletµÄ50¸ö·ÖÖ§»ú¹¹ÖеÄ23¸ö×èÖ¹ÁËÔËÓª¡£E-LandÌåÏÖ£¬ÏÖÔÚÒÑ¹Ø±ÕÆä²¿·Ö¹«Ë¾ÍøÂçϵͳ£¬ÒÔ×îºéÁ÷ƽµØïÔÌË𺦣¬²¢ÒÑÒªÇ󾯷½ÊÓ²ìÍøÂç¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.koreatimes.co.kr/www/tech/2020/11/694_299692.html
6.WiproÐû²¼ÓйØÊ¹ÓÃAIºÍMLÓ¦¶ÔÍøÂç¹¥»÷µÄÆÊÎö±¨¸æ

WiproÐû²¼ÁËÓйØÊ¹ÓÃAIºÍMLÓ¦¶ÔÍøÂç¹¥»÷µÄÆÊÎö±¨¸æ¡£±¨¸æ·¢Ã÷£¬ÔÚÒÑÍùµÄËÄÄêÀȫÇòÓÐ49%µÄÓëÍøÂçÇå¾²Ïà¹ØµÄרÀû¶¼ÓëÈ˹¤ÖÇÄܺͻúеѧϰµÄÓ¦ÓÃÓйء£¶ø½üÒ»°ë£¨49£¥£©µÄ×éÖ¯ÕýÔÚÀ©Õ¹ÈÏÖª¼ì²âÄÜÁ¦£¬ÒÔÓ¦¶ÔÆäÇå¾²ÔËÓªÖÐÐÄ(SOC)ÖеÄδ֪¹¥»÷¡£65£¥µÄ×éÖ¯ÕýÔÚ¶Ô²Ù×÷ÊÖÒÕ£¨OT£©ºÍIoT×°±¸¾ÙÐÐÈÕÖ¾¼à¿Ø£¬ÒÔ¼õÇáOTΣº¦µÄÔöÌí¡£57£¥µÄ×éÖ¯Ö»Ô¸Òâ¹²ÏíIoC£¬64£¥µÄ×éÖ¯ÒÔΪÉùÓþΣº¦ÊÇÐÅÏ¢¹²ÏíµÄ×è°¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/11/23/ai-ml-tackle-unknown-attacks/


¾©¹«Íø°²±¸11010802024551ºÅ