Ñо¿ÍŶÓÊÕ¼¯130¶àÍò¸öRDPÕÊ»§ £¬ÆäÖжàÊýÀ´×ÔÒ½ÁÆÐÐÒµ£»SignalÅû¶ºÚ¿Í¹«Ë¾Cellebrite¿ª·¢µÄÈí¼þÖеĶà¸ö©¶´

Ðû²¼Ê±¼ä 2021-04-23

1.Ñо¿ÍŶÓÊÕ¼¯130¶àÍò¸öRDPÕÊ»§ £¬ÆäÖжàÊýÀ´×ÔÒ½ÁÆÐÐÒµ


1.jpg


Äþ¾²ÍŶÓ×Ô2018Äê12ÔÂÒÔÀ´ÃØÃÜ·ÃÎÊÁËĿǰ×î´ó°µÍøUASµÄÊý¾Ý¿â £¬²¢ÊÕ¼¯Á˽üÈýÄêÀ´³öÊÛµÄ1379609¸öRDPƾ֤¡£ÁгöµÄRDP·þÎñÆ÷À´×ÔÊÀ½ç¸÷µØ £¬°üÂÞÀ´×Ô63¸ö¹ú¼ÒºÍµØÓòµÄÕþ¸®»ú¹¹¡£´ËÍâ £¬ÕâЩÕË»§×î³£ÓõĵǼÃûÊÇ'Administrator'¡¢'Admin'¡¢'User'¡¢'test'ºÍ'scanner' £¬×î³£ÓõÄÃÜÂëÊÇ123456¡¢123¡¢P@ssw0rd¡¢1234ºÍPassword1 £¬Ö÷񻃾¼°ÃÀ¹ú¡¢Öйú¡¢°ÍÎ÷¡¢µÂ¹ú¡¢Ó¡¶ÈºÍÓ¢¹úµÈ¹ú¼Ò¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/logins-for-13-million-windows-rdp-servers-collected-from-hacker-market/


2.Ñо¿ÈËÔ±·¢ÏÖÓÉÉϰÙÍòAndroidÉ豸×é³ÉµÄ½©Ê¬ÍøÂçPareto


2.jpg


Human SecurityµÄÑо¿ÈËÔ±·¢ÏÖÁËÓÉÉϰÙÍò¸ö±»Ñ¬È¾µÄAndroidÉ豸×é³ÉµÄÅÓ´óµÄ½©Ê¬ÍøÂçPareto¡£¸Ã½©Ê¬ÍøÂçÓÚ2020ÄêÊ״α»·¢ÏÖ £¬Í¨¹ýÔÚ¶ñÒâµÄAndroidÒÆ¶¯Ó¦Ó÷¨Ê½ÖÐÆÛÆ­ÐźÅÀ´Ä£ÄâÔËÐÐÁËFire OS¡¢tvOS¡¢Roku OSºÍÆäËûÖøÃûCTVƽ̨µÄÏû·ÑµçÊÓÁ÷ýÌå²úÎï¡£ÆäʹÓÃÁËÊýÊ®¸öÒÆ¶¯Ó¦ÓÃÀ´Ä£·ÂÁè¼Ý6000¸öCTVÓ¦Ó÷¨Ê½ £¬Æ½¾ùÿÌì»á·¢³ö6.5ÒÚ´Î¹ã¸æÇëÇó £¬¼Ù×°³ÉÉϰÙÍòµÄÈËÔÚÖÇÄܵçÊÓÉÏԢĿ¹ã¸æ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/massive-android-botnet-hits-smart-tv-ad-ecosystem


3.QNAPÐû²¼Äþ¾²¸üР£¬ÐÞ¸´NSAÖжà¸öÑÏÖØµÄ©¶´


3.jpg


ÍþÁªÍ¨£¨QNAP£©Ðû²¼ÁËÄþ¾²Í¨¸æ £¬Ðû²¼ÒÑÐÞ¸´CVE-2021-28799©¶´¡£¸Ã©¶´ÊÇλÓÚÔÖÄѻָ´ºÍÊý¾Ý±¸·Ý½â¾ö·½°¸HBS 3 Hybrid Backup SyncÖеÄÓ²±àÂëÆ¾¾Ý©¶´ £¬¿É±»ÓÃÀ´À´µÇ¼QNAP NAS£¨ÍøÂçÁ¬½Ó´æ´¢£©É豸¡£Í¬Ò»Ìì £¬QNAP»¹ÐÞ¸´ÁËQTSºÍQuTS heroÖеÄÃüÁî×¢Èë©¶´£¨CVE-2020-2509£©ºÍMedia Streaming Add-OnÖеÄSQL×¢Èë©¶´£¨CVE-2020-36195£©µÈ©¶´¡£´ËÍâ £¬QNAP³ÆÐÂÀÕË÷Èí¼þQlockerÕýÔÚÀûÓÃCVE-2020-36195¶ÔÆäÉè±¹ØÁ¬ÄÊý¾Ý½øÐмÓÃÜ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/qnap-removes-backdoor-account-in-nas-backup-disaster-recovery-app/


4.Eversource¾¯¸æÆä¿Í»§ÒòÔÆ´æ´¢ÅäÖôíÎóÊý¾Ýй¶


4.jpg


3ÔÂ16ÈÕ £¬ÐÂÓ¢¸ñÀ¼×î´óµÄÄÜÔ´ÌṩÉÌEversource Energy·¢ÏÖÆäÔÆ´æ´¢ÅäÖôíÎó £¬²¢¾¯¸æ¿Í»§ËûÃǵÄÊý¾Ý¿ÉÄÜÒѾ­Ð¹Â¶¡£Ð¹Â¶µÄÐÅÏ¢°üÂÞÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢Éç»á±£Ïպš¢Õ˵¥µØÖ·ÒÔ¼°EversourceÕʺźͷþÎñµØÖ· £¬Éæ¼°¾ÓסÔÚÂíÈøÖîÈûÖݵÄԼĪ11000¸ö¿Í»§¡£¸ÃÎļþ´´½¨ÓÚ2019Äê8Ô £¬ÒѾ­ÒÔÃ÷ÎĵĸñʽÁ¬ÐøÌ»Â¶ÁËÒ»ÄêÁãÆß¸öÔ¡£´ËÍâ £¬Eversource¶ÔÄÇЩÊܵ½Ó°ÏìµÄ¿Í»§Ãâ·ÑÌṩÁË1ÄêµÄÉí·Ý¼à¿Ø·þÎñÀ´×÷ΪÅâ³¥¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/eversource-data-breach/


5.SignalÅû¶ºÚ¿Í¹«Ë¾Cellebrite¿ª·¢µÄÈí¼þÖеĶà¸ö©¶´


5.jpg


SignalÅû¶ºÚ¿Í¹«Ë¾Cellebrite¿ª·¢µÄÈí¼þÖдæÔÚ¶à¸ö©¶´ £¬ÔÊÐíÔÚÉ豸ÉÏÖ´ÐÐÈÎÒâ´úÂë¡£CellebriteµÄ²úÎïͨ³£±»¾¯²ìºÍÕþ¸®ÓÃÀ´½âËøiOSºÍAndroidÊÖ»ú²¢ÌáÈ¡ÆäÖеÄÊý¾Ý £¬È¥Äê12Ô £¬¸Ã¹«Ë¾Ðû²¼ÆäPhysical AnalyzerÒ²¿ÉÒÔ·ÃÎÊSignalµÄÊý¾Ý¡£SignalµÄCEO Moxie Marlinspike³Æ £¬cellebriteµÄÈí¼þ¶¼ÊÇͨ¹ý·ÖÎöÀ´×Ô²»ÐÐÐÅÀ´Ô´µÄÊý¾Ý½øÐÐÊÂÇéµÄ £¬Òò´ËËü¿ÉÒÔ½ÓÊܸñʽ²»ÕýÈ·µÄÊäÈë £¬Õâ¿ÉÄܻᴥ·¢ÄÚ´æËð»µÂ©¶´²¢µ¼Ö´úÂëÖ´ÐС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/signal-ceo-gives-mobile-hacking-firm-a-taste-of-being-hacked/


6.ICT¹©Ó¦ÉÌManagedITÔâ¹¥»÷ £¬ºÉÀ¼µÄ96¼Ò¹«Ö¤´¦ÎÞ·¨ÊÂÇé


6.jpg


ºÉÀ¼»Ê¼ÒÃñ·¨¹«Ö¤ÈËЭ»á£¨KNB£©Ðû²¼Í¨¸æ³Æ £¬ICT¹©Ó¦ÉÌManaged ITÔâµ½¹¥»÷ £¬ºÉÀ¼µÄ96¼Ò¹«Ö¤´¦ÎÞ·¨ÊÂÇé¡£¸Ã¹«Ë¾ÓÚ4ÔÂ16ÈÕ£¨ÐÇÆÚÎ壩ÉÏÎç·¢ÏÖÁ˴˴ι¥»÷ £¬²¢Á¢¼´¶Ï¿ªÁËÓë¶à¸ö¹«Ö¤Èí¼þ¹©Ó¦É̵ķþÎñÆ÷ºÍÊý¾Ý¿âµÄÁ¬½Ó £¬Õâµ¼ÖÂÁË96¸ö¹«Ö¤´¦ÎÞ·¨½øÐÐÊý×Ö»¯ÊÂÇ顣Ŀǰ £¬ÒòΪȱÉÙÓйع¥»÷µÄÏêϸÐÅÏ¢ £¬Òò´ËÉв»ÄÜÈ·¶¨´Ë´Î¹¥»÷µÄÀàÐÍÒÔ¼°Ìᳫ¹¥»÷µÄ×éÖ¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/nl-nearly-a-hundred-notary-offices-victim-of-hacker/