Socialarksй¶400GBÊý¾Ý£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÈ«Çò2ÒÚ¶àÓû§£»£»£»£»£»£»£»Î¢ÈíÐû²¼1Ô·ÝÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬×ܼÆÐÞ¸´83¸öÎó²î

Ðû²¼Ê±¼ä 2021-01-13
1.Socialarksй¶400GBÊý¾Ý£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÈ«Çò2ÒÚ¶àÓû§


1.jpg


Çå¾²¹«Ë¾Safety Detectives·¢Ã÷£¬£¬£¬£¬£¬£¬£¬ÖйúÊ×´´¹«Ë¾Socialarks£¨±¿ÄñÉç½»£©Ð¹Â¶ÁË400GBÊý¾Ý¡£¡£¡£¡£¡£´Ë´ÎÊý¾Ýй¶ÊÇÓÉÓÚElasticSearchÊý¾Ý¿âÉèÖùýʧ£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÁË×ܼÆ408GB£¬£¬£¬£¬£¬£¬£¬Áè¼Ý3.18ÒÚÌõÓû§¼Í¼£¬£¬£¬£¬£¬£¬£¬Éæ¼°µ½11651162¸öInstagramÓû§¡¢66117839¸öÁìÓ¢Óû§ºÍ81551567¸öFacebookÓû§¡£¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬£¬SocialarksÔÚ2020Äê8ÔÂÒ²±¬·¢ÁËÀàËÆµÄÊÂÎñ£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÁË1.5ÒÚ¸öÓû§µÄСÎÒ˽¼ÒÊý¾Ý¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.safetydetectives.com/blog/socialarks-leak-report/


2.ÃÀ¹úUbiquitiÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§ÐÞ¸ÄÃÜÂë


2.png


ÃÀ¹úÍøÂç×°±¸ÉÌUbiquitiÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§ÐÞ¸ÄÃÜÂë²¢ÆôÓÃ2FA¡£¡£¡£¡£¡£¸Ã¹«Ë¾·¢Ã÷ÓɵÚÈý·½ÔÆÌṩÉÌÍйܵÄijЩϵͳÔâµ½ÁËδ¾­ÊÚȨµÄ»á¼û£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜй¶ÁËÆäWebÃÅ»§ÍøÕ¾account.ui.comÉϵÄÓû§Ïà¹ØÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÀýÈçÓû§Ãû³Æ¡¢µç×ÓÓʼþµØµã¡¢¼ÓÑÎÃÜÂëºÍ¹þÏ£ÃÜÂ룬£¬£¬£¬£¬£¬£¬ÒÔ¼°²¿·ÖÓû§µÄ¼ÒÍ¥µØµãºÍµç»°ºÅÂëµÈ¡£¡£¡£¡£¡£UbiquitiÌåÏÖÉв»ÇåÎúй¶µÄÏêϸÊý¾ÝÀàÐÍ£¬£¬£¬£¬£¬£¬£¬Ò²Ã»ÓÐÌṩ´Ë´ÎÊÂÎñµÄÏêϸÐÅÏ¢ºÍÊÜÓ°ÏìÓû§µÄÊýÄ¿¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/113296/data-breach/ubiquiti-discloses-data-breach.html


3.΢ÈíÐû²¼1Ô·ÝÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬×ܼÆÐÞ¸´83¸öÎó²î


3.png


΢ÈíÐû²¼2021Äê1Ô·ݵÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬×ܼÆÐÞ¸´83¸öÎó²î¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÎó²îΪMicrosoft DefenderÖеÄÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVEΪ202-1647£©¡¢Microsoft DTV-DVDÊÓÆµ½âÂëÆ÷Ô¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2021-1668£©¡¢Edge£¨»ùÓÚHTML£©µÄÄÚ´æËð»µÎó²î£¨CVE-2021-1705£©¡¢GDI +Ô¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2021-1665£©¡¢HEVCÊÓÆµÀ©Õ¹Ô¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2021-1643£©ºÍÔ¶³ÌÀú³ÌŲÓÃÔËÐÐʱԶ³ÌÖ´ÐдúÂëÎó²î£¨CVE-2021-1666£©µÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-january-2021-patch-tuesday-fixes-83-flaws-1-zero-day/


4.CrowdStrikeÅû¶SolarWinds¹¥»÷ÖеĵÚÈýÖÖ¶ñÒâÈí¼þ


4.png


Çå¾²¹«Ë¾CrowdStrikeÅû¶ÁËSolarWinds¹©Ó¦Á´¹¥»÷Öб£´æµÚÈýÖÖ¶ñÒâÈí¼þSunspot¡£¡£¡£¡£¡£CrowdStrikeÌåÏÖÖ»¹ÜSunspotÊÇ×îб»·¢Ã÷µÄ£¬£¬£¬£¬£¬£¬£¬µ«ÏÖʵÉÏÊǺڿÍʹÓõĵÚÒ»¸ö¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬ÓÚ2019Äê9Ô±»°²ÅÅ¡£¡£¡£¡£¡£SunspotΨһµÄÄ¿µÄÊǼàÊÓ¹¹½¨Ð§ÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬»ñÈ¡±àÒëOrionµÄ¹¹½¨ÏÂÁî¡£¡£¡£¡£¡£Ò»µ©¼ì²âµ½¹¹½¨ÏÂÁ£¬£¬£¬£¬£¬£¬Æä¾Í»áʹÓüÓÔØÁËSunburst¶ñÒâÈí¼þµÄÎļþÀ´Ìæ»»OrionÓ¦ÓÃÄÚµÄÔ´´úÂëÎļþ£¬£¬£¬£¬£¬£¬£¬À´×°ÖÃSunburst¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/third-malware-strain-discovered-in-solarwinds-supply-chain-attack/


5.BitdefenderÐû²¼Ãâ·ÑµÄDarkSideÀÕË÷Èí¼þ½âÃÜÆ÷


5.png


ÂÞÂíÄáÑǵÄÍøÂçÇå¾²¹«Ë¾BitdefenderÐû²¼ÁËÃâ·ÑµÄDarkSideÀÕË÷Èí¼þ½âÃÜÆ÷¡£¡£¡£¡£¡£DarkSideÀÕË÷Èí¼þ×Ô2020Äê8ÔÂ×îÏÈ»îÔ¾£¬£¬£¬£¬£¬£¬£¬Êê½ð¹æÄ£´Ó20ÍòÃÀÔªµ½200ÍòÃÀÔª²»µÈ£¬£¬£¬£¬£¬£¬£¬ÒѾ­»ñµÃÁËÊý°ÙÍòÃÀÔªµÄÀûÈ󡣡£¡£¡£¡£¸Ã½âÃÜÆ÷½«×Ô¶¯½âÃÜËüÔÚÅÌËã»úÉÏɨÃèµ½µÄËùÓмÓÃÜÎĵµ£¬£¬£¬£¬£¬£¬£¬Íê³Éºó»¹»áÌáÐÑÓû§±¸·ÝÊý¾Ý¡£¡£¡£¡£¡£BitdefenderÌåÏÖÔÚ»Ö¸´Îļþºó£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýËÑË÷À©Õ¹ÃûµÄ·½·¨À´ÅúÁ¿É¾³ýÒѱ»¼ÓÃܵÄÎļþ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/darkside-ransomware-decryptor-recovers-victims-files-for-free/


6.NSAÐû²¼2020ÄêÍøÂçÇå¾²µÄÄê¶È»ØÊ×±¨¸æ


6.png


ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©Ðû²¼ÁË2020ÄêÍøÂçÇå¾²µÄÄê¶È»ØÊ×±¨¸æ¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬NSA 2020Äê×ÊÖú¹ú·À²¿ÏòÔ¶³ÌÊÂÇé¹ý¶É£¬£¬£¬£¬£¬£¬£¬ÎªÔ¼Äª100000ÃûÓû§ÌṩÁËÔ¶³ÌÇå¾²ÊÂÇéµÄ½â¾ö¼Æ»®£¬£¬£¬£¬£¬£¬£¬»¹¼ÓÈëÁËÖ¼ÔÚ¼ÓËÙ¿ª·¢COVID-19ÒßÃçµÄOWSÐж¯¡£¡£¡£¡£¡£2020ÄêÐû²¼µÄÖ÷ÒªÇ鱨°üÀ¨ÓйØWindows 10µÄÎó²îºÍDrovorub¶ñÒâÈí¼þµÄÏêϸÐÅÏ¢¡¢Óë¶íÂÞ˹ÓйصÄɳ³æÍÅ»ïÕë¶ÔEximÓʼþЧÀÍÆ÷µÄIOCºÍÀÄÓÃÔÚwebЧÀÍÆ÷ÉÏ×°ÖÃweb shellµÄ¶ñÒâÈí¼þµÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/nsa-publishes-cybersecurity-year-review-report