CiscoǰԱ¹¤ÈÏ×ïɾ³ýWebEx TeamsµÄ400¶ą̀ÐéÄâ»ú£»£»£»ÐÂÎ÷À¼Ö¤È¯ÉúÒâËùÔâµ½DDoS¹¥»÷£¬£¬£¬£¬£¬£¬ÔÝʱ×èÖ¹ÉúÒâ

Ðû²¼Ê±¼ä 2020-08-28

1.CiscoǰԱ¹¤ÈÏ×ïɾ³ýWebEx TeamsµÄ400¶ą̀ÐéÄâ»ú


1.jpg


˼¿ÆÇ°Ô±¹¤Sudhish Kasaba RameshÈÏ×ïÆäɾ³ýÁËWebEx TeamsµÄ400¶ą̀ÐéÄâ»ú¡£¡£¡£¡£¾ÝÆäÈÏ×ïЭÒéÖгÆ£¬£¬£¬£¬£¬£¬ÆäÈÏ¿ÉÔÚÈ¥Ö°5¸öÔºóµÄ2018Äê9ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬Î´¾­¹«Ë¾µÄÔÊÐíÓÐÒâ»á¼û˼¿ÆµÄÔÆ»ù´¡¼Ü¹¹£¬£¬£¬£¬£¬£¬²¢´ÓÆä×Ô¼ºµÄGoogle Cloud ProjectÕÊ»§Öа²ÅÅÁËÒ»¸ö´úÂ룬£¬£¬£¬£¬£¬É¾³ýÁË˼¿ÆWebEx TeamsÓ¦ÓóÌÐòµÄ456¸öÐéÄâ»ú¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñµ¼ÖÂ16000¸öWebEx TeamsÕÊ»§±»¹Ø±ÕÁ˳¤´ïÁ½¸öÐÇÆÚ£¬£¬£¬£¬£¬£¬CiscoÆÆ·ÑÁËԼĪ140ÍòÃÀÔªÀ´»Ö¸´ÆäÓ¦ÓÃÊܵ½µÄË𺦣¬£¬£¬£¬£¬£¬²¢ÏòÊÜÓ°ÏìµÄ¿Í»§ÍË»¹ÁËÁè¼Ý100ÍòÃÀÔªµÄ¿î×Ó¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/ex-cisco-employee-pleads-guilty-to-deleting-16k-webex-teams-accounts/158748/    


2.Twitterµ·»ÙÐû²¼ÕþÖÎÀ¬»øÓʼþµÄ½©Ê¬ÍøÂçDracula


2.jpg


TwitterÀֳɵ·»ÙÁËÓÃÀ´Ðû²¼ÕþÖÎÀ¬»øÓʼþµÄ½©Ê¬ÍøÂçDracula¡£¡£¡£¡£É罻ýÌåÑо¿×éÖ¯GraphikaÌåÏÖ£¬£¬£¬£¬£¬£¬Æä·¢Ã÷Ò»¸öÓÉԼĪ3000¸ö½©Ê¬³ÌÐò×é³ÉµÄTwitter½©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬Ö÷ÒªÓÃÀ´²¼ÕþÖÎÀ¬»øÓʼþ£¬£¬£¬£¬£¬£¬ÆäÖÐ×îÔçµÄÕË»§Ö»ÄÜ×·Ëݵ½Ò»¸öÔÂǰ£¬£¬£¬£¬£¬£¬¼´2020Äê7Ô¡£¡£¡£¡£GraphikaÊÓ²ìÖ°Ô±Ben NimmoÌåÏÖ£¬£¬£¬£¬£¬£¬TwitterÒѾ­¸ÉÔ¤²¢ÔÝÍ£Á˾ø´ó´ó¶¼Twitter Dracula½©Ê¬ÍøÂçµÄÕÊ»§£¬£¬£¬£¬£¬£¬Í¬Ê±»¹½«Î´±»É¾³ýµÄÆäËûÕÊ»§±ê¼ÇΪÊÜÏÞ£¬£¬£¬£¬£¬£¬ÒÔ×èÖ¹ÆäÐû²¼ÐÂÄÚÈÝ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/twitter-takes-down-dracula-botnet-pushing-pro-chinese-propaganda/


3.ALEXAǰ1Íò¸ö¶¥¼¶ÓòÃûÖÐÓÐ10£¥Ê¹ÓÃä¯ÀÀÆ÷Ö¸ÎÆ¾ç±¾


3.jpg

°®ºÉ»ªÖÝMozilla´óѧºÍ¼ÓÀû¸£ÄáÑÇ´óѧ´÷ά˹·ÖУµÄÑо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬ALEXAǰ1Íò¸ö¶¥¼¶ÓòÃûÖÐÓÐ10£¥ÔÚʹÓÃä¯ÀÀÆ÷Ö¸ÎÆ¾ç±¾¡£¡£¡£¡£ä¯ÀÀÆ÷Ö¸ÎÆ¾ç±¾ÊÇÒ»¶ÎJavaScript´úÂ룬£¬£¬£¬£¬£¬¹ã¸æ¹«Ë¾Í¨³£ÓÃÆäÀ´¸ú×ÙÓû§¡£¡£¡£¡£ÓÉÓÚÕâÖÖ·½·¨ÇÖÕ¼ÁËÓû§Òþ˽£¬£¬£¬£¬£¬£¬Òò´ËFirefox¡¢Chrome¡¢Opera¡¢BraveºÍTorµÈ¶à¼Òä¯ÀÀÆ÷¹«Ë¾ÒѰ²ÅÅÁ˼ì²âºÍ×èÖ¹ÕâЩ¶ñÒâ´úÂëµÄ¹¦Ð§¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ´Ë´ÎÑо¿Öл¹·¢Ã÷ÁËÐí¶àÐÂÖ¸ÎÆÊÖÒÕ£¬£¬£¬£¬£¬£¬°üÀ¨È¨ÏÞÖ¸ÎÆÊ¶±ð¡¢ÍâÎ§Ö¸ÎÆÊ¶±ð¡¢APIÖ¸ÎÆÊ¶±ð¡¢×¼Ê±Ö¸ÎÆÊ¶±ð¡¢¶¯»­Ö¸ÎÆÊ¶±ðºÍ´«¸ÐÆ÷Ö¸ÎÆÊ¶±ð¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/a-quarter-of-the-alexa-top-10k-websites-are-using-browser-fingerprinting-scripts/


4.ÐÂÎ÷À¼Ö¤È¯ÉúÒâËù£¨NZX£©Ôâµ½DDoS¹¥»÷£¬£¬£¬£¬£¬£¬ÔÝʱ×èÖ¹ÉúÒâ


4.jpg


ÐÂÎ÷À¼Ö¤È¯ÉúÒâËù£¨NZX£©Ôâµ½ÂþÑÜʽ¾Ü¾øÐ§ÀÍ£¨DDoS£©¹¥»÷£¬£¬£¬£¬£¬£¬ÔÝʱ×èÖ¹ÉúÒâ¡£¡£¡£¡£¾ÝϤÕâÆðÏ®»÷ÊÂÎñÀ´×ÔÍâÑ󣬣¬£¬£¬£¬£¬NZXÓÚÍâµØÊ±¼äÖܶþÏÂÖç4µã×îÏÈ×èÖ¹ÁË¹ÉÆ±ÉúÒâ¡£¡£¡£¡£Ëæºó£¬£¬£¬£¬£¬£¬ÔÚÖÜÈýºÍÖÜËĵĴ󲿷Öʱ¼äÀ£¬£¬£¬£¬£¬Õ®ÎñºÍ¹ÉȨÉúÒâ×èÖ¹£¬£¬£¬£¬£¬£¬ÖÜËÄÏÂÖç4µã×îÏÈ£¬£¬£¬£¬£¬£¬ÑÜÉúÆ·ÉúÒâ×èÖ¹¡£¡£¡£¡£Ö»¹ÜNZXµÄ¾¯±¨Öв¢Î´ËµÃ÷¹¥»÷ÕßÉí·ÝÒÔ¼°¹¥»÷ÒªÁ죬£¬£¬£¬£¬£¬µ«Ñо¿Ö°Ô±ÍƲâËüÃǺÜÓпÉÄÜʹÓÃÁËÌṩDDoS×âÓÃЧÀÍÕ¾µãµÄЧÀÍ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-zealand-stock-exchange-halted-trading-after-ddos-attacks/


5.ºÚ¿ÍʹÓÃAutodeskÖÐÎó²î¶Ô¹ú¼ÊÐÞ½¨¹«Ë¾Ìᳫ¹¥»÷


5.jpg

ºÚ¿ÍʹÓÃ3DÅÌËã»úͼÐÎÈí¼þAutodeskÖеÄÎó²î£¬£¬£¬£¬£¬£¬¶Ô¹ú¼ÊÐÞ½¨¹«Ë¾ÌᳫÁËÍøÂçÌØ¹¤¹¥»÷¡£¡£¡£¡£ºÚ¿Í´Ë´ÎʹÓõĶñÒâÈí¼þÊÇAutodesk 3ds MaxÖеĶñÒâ²å¼þPhysXPluginMfx¡£¡£¡£¡£Ëü¿ÉÒÔÆÆËð3ds MaxÈí¼þµÄÉèÖÃÀ´ÔËÐжñÒâ´úÂ룬£¬£¬£¬£¬£¬²¢×îÖÕÈö²¥µ½WindowsϵͳÉÏµÄÆäËûÎļþ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ºÚ¿Í»¹Ê¹ÓÃÁË´ó×ÚÌØ¹¤¹¤¾ß£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨ÓÃÀ´Áгö¡¢Ñ¹Ëõ²¢½«Ìض¨ÎļþÉÏ´«µ½C2µÄHdCrawler£¬£¬£¬£¬£¬£¬ºÍ¿ÉÒÔ½ØÆÁ²¢ÍøÂçÓû§Ãû¡¢ÍøÂçÊÊÅäÆ÷µÄIPµØµãµÄInfoStealer¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/hackers-exploit-autodesk-flaw-in-recent-cyberespionage-attack/158669/


6.CiscoÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ÆäÍøÂç×°±¸Öжà¸öÑÏÖØµÄÎó²î


6.jpg

CiscoÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´Æä½»Á÷»úºÍ¹âÏË´æ´¢½â¾ö¼Æ»®ÖеÄ9¸öÎó²î£¬£¬£¬£¬£¬£¬ÆäÖÐ8¸ö±»ÆÀΪ¸ßÑÏÖØÐÔ¡£¡£¡£¡£´Ë´Î¸üÐÂÖУ¬£¬£¬£¬£¬£¬Ë¼¿ÆµÄNX-OSÊܵ½µÄÓ°Ïì×îΪÑÏÖØ£¬£¬£¬£¬£¬£¬×ܹ²ÐÞ¸´ÁË6¸öÎó²î£¬£¬£¬£¬£¬£¬°üÀ¨Á½¸öCisco NX-OSÈí¼þ½çÏßÍø¹ØÐ­Òé¶à²¥VPNÖеľܾøÐ§ÀÍÎó²î£¨CVE-2020-3397ºÍCVE-2020-3398£©£¬£¬£¬£¬£¬£¬»ùÓÚIPv6ЭÒé×ÔÁ¦×é²¥(PIM)ÖеľܾøÐ§ÀÍÎó²î(CVE-2020-3338)£¬£¬£¬£¬£¬£¬ÒÔ¼°Îó²îCVE-2020-3415£¬£¬£¬£¬£¬£¬CVE-2020-3517ºÍCVE-2020-3454¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/cisco-high-severity-bugs-impact-switches-fibre-storage/158691/