NSAÅû¶ºÚ¿Í³£ÓÃÓÚÖ²ÈëWeb ShellµÄÎó²îÁÐ±í£»£»£»£»Ó¢¹ú3¼Ò˽ļ¹«Ë¾ÔâBECڲƭ¹¥»÷

Ðû²¼Ê±¼ä 2020-04-25

¡¾Çå¾²²¥±¨¡¿


NSAÅû¶ºÚ¿Í³£ÓÃÓÚÖ²ÈëWeb ShellµÄÎó²îÁбí

https://www.zdnet.com/article/nsa-shares-list-of-vulnerabilities-commonly-exploited-to-plant-web-shells/


¡¾ÍþвÇ鱨¡¿


½©Ê¬ÍøÂçVictoryGateÕë¶ÔÀ­¶¡ÃÀÖÞ£¬ £¬£¬ÒÑѬȾ3.5Íǫ̀װ±¸

https://www.welivesecurity.com/2020/04/23/eset-discovery-monero-mining-botnet-disrupted/


Ó¢¹ú3¼Ò˽ļ¹«Ë¾ÔâBECڲƭ¹¥»÷£¬ £¬£¬Ëðʧ130ÍòÃÀÔª

https://thehackernews.com/2020/04/bec-scam-wire-transfer-money.html


¡¾Êý¾Ýй¶¡¿


ŦԼPaayÒòЧÀÍÆ÷ÉèÖò»µ±Ð¹Â¶250Íò±ÊÉúÒâ¼Í¼

https://www.darkreading.com/application-security/paay-misconfiguration-leaves-transaction-data-exposed/d/d-id/1337643


½¡ÉíÓ¦ÓÃKinomap±£´æÎó²î£¬ £¬£¬Ð¹Â¶4200ÍòÓû§Êý¾Ý

https://nakedsecurity.sophos.com/2020/04/23/password-free-database-of-exercise-app-kinomap-leaks-42m-user-records/