Apple iCloudÖÐÖ¹36Сʱ£¬£¬£¬£¬£¬£¬£¬Éв»ÇåÎú¹ÊÕÏÔµ¹ÊÔ­ÓÉ£»£»£»£»£»£»Nintendo 3DS±£´æ¿Éµ¼ÖÂMiTM¹¥»÷µÄÎó²î

Ðû²¼Ê±¼ä 2020-12-28
1.Apple iCloudÖÐÖ¹36Сʱ£¬£¬£¬£¬£¬£¬£¬Éв»ÇåÎú¹ÊÕÏÔµ¹ÊÔ­ÓÉ


1.jpg


Apple iCloudЧÀÍ·ºÆð¹ÊÕÏ£¬£¬£¬£¬£¬£¬£¬Ê¹Óû§ÎÞ·¨µÇ¼¸ÃЧÀÍ»á¼ûÎļþ»òÉèÖÃÐÂ×°±¸¡£¡£¡£¡£¡£´Ë´ÎÖÐÖ¹´ÓÃÀ¹ú¶«²¿Ê±¼ä12ÔÂ25ÈÕÉÏÎç4:45×îÏÈ£¬£¬£¬£¬£¬£¬£¬Ö±µ½12ÔÂ26ÈÕÏÂÖç4:35²Å±»ÐÞ¸´£¬£¬£¬£¬£¬£¬£¬Àúʱ36Сʱ¡£¡£¡£¡£¡£ÖÐֹʱ´ú£¬£¬£¬£¬£¬£¬£¬AppleµÄϵͳ״̬ҳÉϽöÏÔʾ¡°Óû§¿ÉÄÜÓöµ½´ËЧÀ͵ÄÎÊÌ⡱µÄÌáÐÑ£¬£¬£¬£¬£¬£¬£¬Ã»Óиü¶àÓÐ¹ØÆäÖÐÖ¹µÄÐÅÏ¢¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬Apple¹«Ë¾Ã»ÓÐÌṩÈκÎÒÔÕÏÔµ¹ÊÔ­ÓÉ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/apple/apple-icloud-outage-prevents-device-activations-access-to-data/


2.ºÚ¿Í³öÊÛÓÎÏ·¹«Ë¾Koei TecmoµÄÊý¾ÝºÍ»á¼ûȨ


2.png


ºÚ¿ÍÕýÔÚ°µÍø³öÊÛÓÎÏ·¹«Ë¾Koei TecmoµÄÊý¾ÝºÍ»á¼ûȨ¡£¡£¡£¡£¡£12ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÉù³ÆÆäÓÚ12ÔÂ18ÈÕʹÓÃÓã²æÊ½´¹ÂÚ¹¥»÷ÈëÇÖÁËkoeitecmoeurope.comÍøÕ¾£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡ÁËÂÛ̳Êý¾Ý¿â²¢Ö²ÈëÁËWeb ShellÒÔ±ãºóÐø»á¼û¡£¡£¡£¡£¡£Ö®ºóºÚ¿ÍÔÚ°µÍøÉÏÒÔ0.05±ÈÌØ±Ò£¨Ô¼ºÏ1300ÃÀÔª£©µÄ¼ÛÇ®³öÊÛÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬²¢ÒÔ0.25£¨Ô¼ºÏ6500ÃÀÔª£©µÄ¼ÛÇ®³öÊÛWeb shell»á¼ûȨÏÞ¡£¡£¡£¡£¡£¸Ã±»µÁÊý¾Ý¿â°üÀ¨ÁË65000¸öÓû§µÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬°üÀ¨µç×ÓÓʼþµØµã¡¢IPµØµã¡¢¹þÏ£ÃÜÂë¡¢Óû§Ãû¡¢³öÉúÈÕÆÚºÍ¹ú¼Ò¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬Koei TecmoÒѹرÕÃÀ¹úºÍÅ·ÖÞµÄÍøÕ¾£¬£¬£¬£¬£¬£¬£¬ÒÔ±ÜÃâ¿ÉÄܱ¬·¢µÄ¹¥»÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/koei-tecmo-discloses-data-breach-after-hacker-leaks-stolen-data/


3.Nintendo 3DS±£´æ¿Éµ¼ÖÂMiTM¹¥»÷µÄÎó²î


3.png


Ñо¿Ö°Ô±·¢Ã÷Nintendo 3DS±£´æÑÏÖØµÄÎó²î£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂMiTM¹¥»÷¡£¡£¡£¡£¡£¸ÃÎó²îλÓÚNintendo 3DS¶ÔÊý×ÖÖ¤ÊéµÄ´¦Öóͷ£ÖУ¬£¬£¬£¬£¬£¬£¬ ½¨ÉèSSL/TLSÅþÁ¬Ê±SSLÏµÍ³Ä £¿£¿£¿£¿£¿£¿éδ׼ȷÑéÖ¤x509Ö¤Ê飬£¬£¬£¬£¬£¬£¬´Ó¶øÔÊÐí¹¥»÷ÕßαÔìαÔìÖ¤ÊéÀ´Ö´ÐÐMitM¹¥»÷£¬£¬£¬£¬£¬£¬£¬»òÓÕÆ­ÊÜÐÅÈεÄЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬ÀýÈçÓÕÆ­eShopЧÀÍÆ÷²¢ÇÔÈ¡Óû§ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÓÕÆ­ÓëÓÎϷЧÀÍÆ÷µÄÅþÁ¬µÈ¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËËùÓй̼þ°æ±¾Îª11.13»ò¸üµÍµÄNintendo 3DS¿ØÖÆÌ¨£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÒѱ»ÐÞ¸´¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/12/27/critical-vulnerability-in-nintendo-3ds-console-could-allow-mitm-attacks/


4.ËÕ¸ñÀ¼»·±£¾ÖÊܵ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÁªÂçÖÐÐĵȲ¿·ÖÊܵ½Ó°Ïì


4.png


ËÕ¸ñÀ¼ÇéÐα£»£»£»£»£»£»¤¾Ö£¨Sepa£©Ôâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÁªÂçÖÐÐĵȲ¿·ÖÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¸Ã¹«Ë¾CEO David Pirie³ÆÔÚÆ½°²Ò¹µÄÎçÒ¹£¬£¬£¬£¬£¬£¬£¬SepaµÄϵͳÔâÊÜÁËÖØ´óÇÒÒ»Á¬µÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£¹¥»÷Ó°ÏìÁ˸ù«Ë¾µÄÁªÂçÖÐÐÄ¡¢ÄÚ²¿ÏµÍ³¡¢Á÷³ÌºÍÄÚ²¿Í¨Ñ¶¡£¡£¡£¡£¡£¿ÉÊÇÆä½¹µã¼à¿ØÏµÍ³ºÍ¾¯±¨Ð§ÀÍûÓÐÊܵ½Ì«´óµÄÓ°Ïì¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬SepaÕýÓëËÕ¸ñÀ¼Õþ¸®ÏàÖú£¬£¬£¬£¬£¬£¬£¬ÒÔÊӲ첢½â¾ö´Ë´Î¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://news.stv.tv/scotland/scottish-environment-protection-agency-targeted-in-cyberattack?top


5.Rapid7Ðû²¼2020Äê¶ÈÍøÂç¹¥»÷µÄÌ¬ÊÆ±¨¸æ


5.png


Rapid7Ðû²¼ÁË2020Äê¶ÈÍøÂç¹¥»÷µÄÌ¬ÊÆ±¨¸æ¡£¡£¡£¡£¡£¸Ã±¨¸æÖ÷ÒªÆÊÎöÁ˶ñÒâµÄMicrosoft SQL Server¹¥»÷¡¢Î¢ÈíÔ¶³Ì×ÀÃæÐ­Òé(RDP)¹¥»÷ºÍ΢ÈíSMB¹¥»÷¡£¡£¡£¡£¡£±¨¸æ·¢Ã÷£¬£¬£¬£¬£¬£¬£¬´ó¹æÄ£µÄ½©Ê¬ÍøÂçÔÚ½ñÄêÑ×Ìì֮ǰͻȻÏûÊÅ£¬£¬£¬£¬£¬£¬£¬¶øMS SQL serverƾ֤ºÍÅÌÎʹ¥»÷µÖ´ïÁËÒÔÍùµÄƽ¾ùˮƽ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Õë¶ÔRDPµÄÀÕË÷Èí¼þ¹¥»÷ÊÇÒ»¸ö´óÎÊÌ⣬£¬£¬£¬£¬£¬£¬Ðí¶à¹¥»÷ÕßÃé×¼ÁË×ÊԴȱ·¦µÄÒ½ÁÆÐÐÒµ¡¢½ÌÓýºÍÕþ¸®×éÖ¯¡£¡£¡£¡£¡£Õë¶ÔMicrosoft SMBЧÀÍÆ÷µÄ×¢ÈëEternalBlueµÄ¹¥»÷Ò²ÓÐËùÔöÌí¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.rapid7.com/2020/12/25/rapid7-labs-2020-naughty-list-summary-report-to-santa/


6.AspenÐû²¼ÓйØÊý×Ö»ù´¡ÉèÊ©µÄÆÊÎö±¨¸æ


6.png


AspenÐû²¼ÁËÓйØÊý×Ö»ù´¡ÉèÊ©µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£2020Ä꣬£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²ÒѳÉΪÿ¸öÐÐÒµÒÔ¼°ÃÀ¹úÕþ¸®µÄÄÑÌ⣬£¬£¬£¬£¬£¬£¬¸Ã±¨¸æÖ¸³öÁËÐÂÈÎ×ÜͳÕþ¸®ÓÐÐí¶àʱ»ú¿ÉÒÔÔöÌíÍøÂçÇå¾²ÊÂÇé²¢Ìá¸ßÈËÃǵÄÒâʶ£¬£¬£¬£¬£¬£¬£¬ÒÔ½¨Éè¸ü¾ßµ¯ÐÔµÄÊý×Ö»ù´¡¼Ü¹¹¡£¡£¡£¡£¡£¸Ã±¨¸æÖ¼ÔÚ×ÊÖú¾öÒéÕßÈ·¶¨ÓÅÏȼ¶¡¢ÍýÏëºÍÖ´ÐпɲÙ×÷µÄÍøÂçÇå¾²ÍýÏ룬£¬£¬£¬£¬£¬£¬´Ó½ÌÓýºÍÀͶ¯Á¦¡¢±£»£»£»£»£»£»¤»ù´¡ÉèÊ©¡¢¹©Ó¦Á´Çå¾²¡¢²âÆÀÍøÂçÇå¾²ºÍÔö½øÓªÒµÏàÖú¼¸¸ö·½Ãæ¾ÙÐÐÆÊÎö¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.aspeninstitute.org/publications/a-national-cybersecurity-agenda-for-resilient-digital-infrastructure/