2019ÄêÊý¾Ýй¶ÊӲ챨¸æ£»£»£»£»£»£»UCä¯ÀÀÆ÷δÐÞ¸´µÄµØµãÀ¸ÓÕÆÎó²î£»£»£»£»£»£»2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼й¶
Ðû²¼Ê±¼ä 2019-05-09
VerizonÐû²¼2019ÄêÊý¾Ýй¶ÊӲ챨¸æ£¨DBIR£©£¬£¬£¬£¬¸Ã±¨¸æÆÊÎöÁË86¸ö¹ú¼Ò±¬·¢µÄ41000¶àÆðÍøÂçÇå¾²ÊÂÎñºÍ2000¶àÆðÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÖ¸³ö£¬£¬£¬£¬´Ó2018Äê×îÏÈÔÆ´æ´¢ÉèÖùýʧ¡¢BECºÍ֪ʶ²úȨ͵ÇÔ¶¼´¦ÓÚÉÏÉýÇ÷ÊÆ¡£¡£¡£¡£¡£¡£ÒÔÉÌÒµÌØ¹¤»î¶¯ÎªÄîÍ·µÄÍøÂç¹¥»÷ÓÐËùÔöÌí£¬£¬£¬£¬ÔÚÒÑÍùµÄ12¸öÔÂÀ£¬£¬£¬ÓÐ1/4µÄÍøÂçÈëÇÖÓëÕì̽ºÍÊý¾ÝÉøÂ©Óйء£¡£¡£¡£¡£¡£×ÜÌå¶øÑÔ´ó´ó¶¼ÍøÂç¹¥»÷¶¼ÊÇÒÔ¾¼ÃÀûÒæ×÷ΪÇý¶¯¡£¡£¡£¡£¡£¡£²»ÐÒµÄÊÇ£¬£¬£¬£¬ÓÐÒ»°ëµÄÆóÒµÐè񻮮·ÑÊýÔÂÉõÖÁ¸ü³¤µÄʱ¼äÀ´·¢Ã÷ÈëÇÖÐÐΪ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://enterprise.verizon.com/resources/reports/2019-data-breach-investigations-report.pdf
2¡¢UCä¯ÀÀÆ÷±»ÆØ±£´æÎ´ÐÞ¸´µÄµØµãÀ¸ÓÕÆÎó²î

Çå¾²Ñо¿Ö°Ô±Arif Khan·¢Ã÷UCä¯ÀÀÆ÷±£´æÒ»¸öÉÐδÐÞ¸´µÄµØµãÀ¸ÓÕÆÎó²î¡£¡£¡£¡£¡£¡£UCä¯ÀÀÆ÷Êǰ¢Àï°Í°ÍÆìϵÄUCWeb¿ª·¢µÄä¯ÀÀÆ÷£¬£¬£¬£¬ÔÚÖйúºÍÓ¡¶ÈÓµÓÐÁè¼Ý5ÒÚÓû§¡£¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚä¯ÀÀÆ÷µÄÓû§½çÃæ´¦Öóͷ£ÌØÊâÄÚÖù¦Ð§£¨¸Ã¹¦Ð§Ö¼ÔÚ¸ÄÉÆÓû§µÄGoogleËÑË÷ÌåÑ飩µÄ·½·¨£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷Õß¿ØÖƵصãÀ¸ÖÐÏÔʾµÄURL×Ö·û´®£¬£¬£¬£¬ÓÕÆÓû§»á¼û¶ñÒâÍøÕ¾¡£¡£¡£¡£¡£¡£¸ÃÎó²îÉÐδ·ÖÅÉCVE±àºÅ£¬£¬£¬£¬UCä¯ÀÀÆ÷µÄ×îа汾12.11.2.1184ºÍUC Miniä¯ÀÀÆ÷µÄ×îа汾12.10.1.1192¾ùÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/05/uc-browser-url-spoofing.html
3¡¢Freedom MobileÒâÍâй¶½ü500ÍòÌõÓû§¼Í¼

¼ÓÄôóµçÐŹ«Ë¾Freedom MobileµÄÒ»¸ö°üÀ¨¿Í»§Êý¾ÝµÄElasticSearchÊý¾Ý¿âÒòÉèÖùýʧÔÚÍøÉÏ̻¶£¬£¬£¬£¬µ¼Ö½ü500ÍòÌõ¿Í»§¼Í¼й¶¡£¡£¡£¡£¡£¡£Æ¾Ö¤Çå¾²Ñо¿Ô±Noam RotemºÍRan LocarµÄ·¢Ã÷£¬£¬£¬£¬¸ÃÊý¾Ý¿âÊôÓÚFreedom MobileµÄµÚÈý·½Ð§ÀÍÌṩÉÌApptium¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾½²»°ÈËÌåÏÖ£¬£¬£¬£¬Ð¹Â¶ÊÂÎñÓ°ÏìÁË3ÔÂ25ÈÕÖÁ4ÔÂ15ÈÕʱ´úÔÚ17¸öFreedom MobileÓªÒµÌü¿ªÉè»ò¸ü¸ÄÕË»§µÄÓû§£¬£¬£¬£¬Ô¼ÓÐ1.5ÍòÓû§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢²»µ«°üÀ¨Óû§µÄÐÕÃû¡¢ÓÊÏäµÈСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬»¹°üÀ¨ÐÅÓÿ¨ºÅµÈÖ§¸¶ÐÅÏ¢¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://cyware.com/news/freedom-mobile-exposed-almost-5-million-customer-records-due-to-a-misconfigured-database-fddd4855
4¡¢ºº±¤Íõ¶ùͯÊÐËÁÒâÍâй¶½ü4ÍòÌõÓû§¼Í¼

Çå¾²Ñо¿Ô±Bob Diachenko·¢Ã÷ºº±¤ÍõµÄÒ»¸öרΪ¶ùͯЧÀ͵퍹úÍøÉÏÊÐËÁÒâÍâй¶ÁË37900Ìõ¿Í»§¼Í¼¡£¡£¡£¡£¡£¡£ÕâЩ¼Í¼°üÀ¨ÔÚÒ»¸öδÊܱ£»£»£»£»£»£»¤µÄElasticsearch¼¯ÈºÖУ¬£¬£¬£¬¸ÃÊý¾Ý¿âÖÁÉÙ´Ó4ÔÂ24ÈÕ×îÏÈÔÚÍøÉÏ̻¶¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢²»µ«°üÀ¨Óû§µÄÐÕÃû¡¢µç»°µÈPIIÐÅÏ¢£¬£¬£¬£¬»¹°üÀ¨²¿·ÖÔ±¹¤µÄÓÊÏ䵨µã¡¢CRMºó¶ËÈÕÖ¾µÈÐÅÏ¢¡£¡£¡£¡£¡£¡£Î´Êܱ£»£»£»£»£»£»¤µÄElasticSearchÊý¾Ý¿âÕýÔÚ³ÉΪ³£Ì¬¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/burger-kings-online-store-for-kids-exposes-customers-info/
5¡¢AWSÉÏδÊܱ£»£»£»£»£»£»¤µÄMongoDBй¶Áè¼Ý2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼

Çå¾²Ñо¿Ô±Bob DiachenkoʹÓÃShodan·¢Ã÷ÔÚAmazon AWSÉÏÍйܵÄÒ»¸ö¿É¹ûÕæ»á¼ûµÄMongoDBÊý¾Ý¿â£¬£¬£¬£¬¸ÃÊý¾Ý¿âй¶ÁËÁè¼Ý2.75ÒÚÌõÓ¡¶È¹«Ãñ¼Í¼¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢ÓÊÏä¡¢ÊÖ»úºÅÂë¡¢Ö°ÒµºÍнˮµÈPII£¬£¬£¬£¬µ«DiachenkoûÓз¢Ã÷¸ÃÊý¾Ý¿âµÄ¹éÊô×éÖ¯¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÓÚ4ÔÂ23ÈÕ×îÏÈÔÚÍøÉÏ̻¶¡£¡£¡£¡£¡£¡£Diachenko֪ͨÁËÓ¡¶ÈCERT£¬£¬£¬£¬µ«¸ÃÊý¾Ý¿â²¢Î´Êܵ½±£»£»£»£»£»£»¤£¬£¬£¬£¬Ö±µ½5ÔÂ8ÈÕ·¸·¨ÍÅ»ïUnistellarɾ³ýÁ˸ÃÊý¾Ý¿â²¢ÁôÏÂÁËÁªÏµ·½·¨¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/over-275-million-records-exposed-by-unsecured-mongodb-database/
6¡¢°Í¶ûµÄĦÊÐÕþÌüºÍ²¨ÌØÏؾùÔâÀÕË÷Èí¼þ¹¥»÷

µÂ¿ËÈøË¹Öݲ¨ÌØÏؼ°ÂíÀïÀ¼ÖݰͶûµÄĦÊÐÕþÌü¾ùÔâÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£Æ¾Ö¤°Í¶ûµÄĦÊг¤Jack YoungµÄ¹Ù·½ÉùÃ÷£¬£¬£¬£¬¸ÃÊеĽ¹µãЧÀÍ£¨¾¯Ô±¡¢Ïû·À¡¢EMSºÍ311£©ÈÔÔÚÔË×÷£¬£¬£¬£¬µ«ÒÑÈ·½¨¶¼»áÍøÂçѬȾÁËÀÕË÷²¡¶¾£¬£¬£¬£¬³öÓÚÔ¤·À¸ÃÊÐÒѾ¹Ø±ÕÁ˴󲿷ÖЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¶øÆ¾Ö¤NewsChannel 10µÄ˵·¨£¬£¬£¬£¬²¨ÌØÏØÔÚ4ÔÂ22ÈÕÔâµ½¶ñÒâÈí¼þ¹¥»÷ºó£¬£¬£¬£¬ÒѾÏë·¨½«²¿·ÖÅÌËã»úÏµÍ³ÖØÐÂÉÏÏß¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/local-authorities-in-texas-and-maryland-hit-by-ransomware/