CNNICÐû²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´¿öͳ¼Æ³ÂËß¡·£ºDeFiƽ̨Cream FinanceÔâµ½¹¥»÷

Ðû²¼Ê±¼ä 2021-09-02

CNNICÐû²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´¿öͳ¼Æ³ÂËß¡·


CNNICÐû²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´¿öͳ¼Æ³ÂËß¡·.jpg


Öйú»¥ÁªÍøÂçÐÅÏ¢ÖÐÐÄ£¨CNNIC£©ÓÚ8ÔÂ27ÈÕÔÚ¾©Ðû²¼µÚ48´Î¡¶Öйú»¥ÁªÍøÂçÉú³¤×´¿öͳ¼Æ³ÂËß¡·¡£³ÂËßÏÔʾ£¬½ØÖÁ½ñÄê6Ô£¬ÖйúÍøÃñ¹æÄ£´ï10.11ÒÚ£¬½Ï2020Äê12ÔÂÔö³¤2175Íò£¬»¥ÁªÍøÆÕ¼°ÂÊ´ï71.6%£»»¥ÁªÍø»ù´¡×ÊÔ´¼ÓËÙ½¨É裬½ØÖÁ6Ô£¬ÖйúIPv6µØÖ·ÊýÁ¿´ï62023¿é/32£»ÖйúÅ©´åÍøÃñ¹æÄ£Îª2.97ÒÚ£¬Å©´åµØÓò»¥ÁªÍøÆÕ¼°ÂÊΪ59.2%£¬½Ï2020Äê12Ô£¬³ÇÏ绥ÁªÍøÆÕ¼°ÂʲîÒìËõС4.8%¡£


Ô­ÎÄÁ´½Ó£º

http://finance.people.com.cn/n1/2021/0828/c1004-32210949.html


Unit42Ðû²¼MiraiÔÚÒ°ÀûÓÃWebSVNÖÐÃüÁî×¢Èë©¶´µÄ³ÂËß


Unit42Ðû²¼MiraiÔÚÒ°ÀûÓÃWebSVNÖÐÃüÁî×¢Èë©¶´µÄ³ÂËß.jpg


Unit42ÔÚ8ÔÂ30ÈÕÐû²¼ÁËÓйØMiraiµÄбäÌåÔÚÒ°ÀûÓÃWebSVNÖÐÃüÁî×¢Èë©¶´µÄ·ÖÎö³ÂËß¡£¸Ã©¶´×·×ÙΪCVE-2021-32305£¬ÓÚ2021Äê5Ô±»·¢ÏÖ²¢ÐÞ¸´¡£ÔÚÆä¿´·¨Ö¤Ã÷Ðû²¼ºóµÄÒ»ÖÜÄÚ£¬¼´2021Äê6ÔÂ26ÈÕ£¬Ñо¿ÈËÔ±·¢ÏÖ¹¥»÷ÕßÀûÓøÃ©¶´°²×°¶ñÒâÈí¼þMiraiµÄ±äÌåµÄ»î¶¯¡£´ËÍ⣬³ÂËß»¹ÁгöÁËÓйظûµÄIoCµÈ¼¼ÊõÏà¹ØÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/cve-2021-32305-websvn/


Ñо¿ÈËÔ±Åû¶ExchangeÖÐЩ¶´ProxyTokenµÄϸ½Ú


Ñо¿ÈËÔ±Åû¶ExchangeÖÐЩ¶´ProxyTokenµÄϸ½Ú.jpg


Zero Day InitiativeÓÚ½ñÄê8ÔÂ30ÈÕ¹ûÈ»ÁËMicrosoft ExchangeÖÐЩ¶´ProxyTokenµÄϸ½Ú¡£¸Ã©¶´ÓÉÔ½ÄÏÓʵ缯ÍÅVNPT-ISCµÄÑо¿ÈËÔ±ÓÚ2021Äê3Ô·¢ÏÖ£¬²¢ÒÑÓÉMicrosoftÔÚ2021Äê7ÔµÄÖܶþ²¹¶¡¸üÐÂÖнâ¾ö¡£¸Ã©¶´×·×ÙΪCVE-2021-33766£¬CVSSÆÀ·ÖΪ7.3¡£Â©¶´´æÔÚÓÚExchangeµÄίÍÐÉí·ÝÑéÖ¤¹¦Ð§ÖУ¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÀûÓøÃ©¶´ÅäÖÃÓû§µÄÓÊÏä¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/08/new-microsoft-exchange-proxytoken-flaw.html


QNAP³ÆÆäNAS²úÎïÊÜOpenSSLÖеÄRCEºÍDoS©¶´Ó°Ïì


QNAP³ÆÆäNAS²úÎïÊÜOpenSSLÖеÄRCEºÍDoS©¶´Ó°Ïì.jpg


NASÖÆÔìÉÌÓÚ±¾ÖÜÒ»Ðû²¼ÁËÁ½·Ý¹ØÓÚOpenSSLÔ¶³Ì´úÂëÖ´Ðк;ܾø·þÎñ©¶´µÄÄþ¾²Í¨¸æ¡£ÕâÁ½¸ö©¶´×·×ÙΪCVE-2021-3711ºÍCVE-2021-3712£¬ÒÑÔÚÉÏÖÜÓÉOpenSSLÐÞ¸´£¬ËüÃÇÓ°ÏìÁËÔËÐÐQTS¡¢QuTS hero¡¢QuTScloudºÍHBS 3 Hybrid Backup SyncµÄQNAP NASÉ豸¡£QNAPÌåÏÖÆäĿǰÕýÔÚ³¹µ×ÊÓ²ì´Ë°¸£¬²¢¼Æ»®¾¡¿ìÐû²¼Äþ¾²¸üС£ÉÏÖÜ£¬Öйų́ÍåµÄNASÖÆÔìÉÌSynologyÒ²ÌåÏÖÆä²¿ÃÅNAS²úÎïÊܵ½ÕâЩ©¶´µÄÓ°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/qnap-works-on-patches-for-openssl-bugs-impacting-its-nas-devices/


ÒòGoogleÓ¦ÓÃbug£¬²¿ÃŰ²×¿Óû§ÎÞ·¨²¦´òºÍ½ÓÌýµç»°


ÒòGoogleÓ¦ÓÃbug£¬²¿ÃŰ²×¿Óû§ÎÞ·¨²¦´òºÍ½ÓÌýµç»°.jpg


GoogleÌåÏÖ£¬²¿ÃÅAndroidÊÖ»úÐͺŵÄÓû§Êܵ½GoogleÓ¦ÓÃÖÐbugµÄÓ°Ï죬ÎÞ·¨²¦´òºÍ½ÓÌýµç»°¡£Ä¿Ç°GoogleûÓйûÈ»ÊÜÓ°ÏìÊÖ»úµÄÐͺÅ£¬µ«±¾ÖÜÄ©ÊÜÓ°ÏìÓû§Ìáµ½ÁËLGµÄÉ豸£¬ÈçLG G7¡¢LG G7 ThinQ¡¢LG V40 ThinQºÍLG Q70µÈ¡£Google³ÆÆäÕýÔÚÊÓ²ì´ËÊ£¬²¢ÒÑÐû²¼ÁË×îиüÐÂÀ´ÐÞ¸´¸Ãbug£¬½¨ÒéÓû§ÊÖ¶¯°²×°×îиüС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/google/google-app-bug-blocks-android-users-from-receiving-making-calls/


DeFiƽ̨Cream FinanceÔâµ½¹¥»÷ËðʧÁè¼Ý2900ÍòÃÀÔª


DeFiƽ̨Cream FinanceÔâµ½¹¥»÷ËðʧÁè¼Ý2900ÍòÃÀÔª.jpg


È¥ÖÐÐÄ»¯½ðÈÚ(DeFi)ƽ̨Cream FinanceÓÚ8ÔÂ30ÈÕ³ÆÆäÔâµ½¹¥»÷£¬Ô¤¼ÆËðʧÁè¼Ý2900ÍòÃÀÔª¡£¸Ã¹«Ë¾³Æ£¬¹¥»÷ÕßÀûÓá°reentrancy attack¡±¹¥»÷ÁËÆä¡°flash loan¡±¹¦Ð§£¬ÇÔÈ¡ÁË418311571¸öAMP±Ò£¨Ô¼Îª2510ÍòÃÀÔª£©ºÍ1308.09¸öETH±Ò£¨Ô¼Îª415ÍòÃÀÔª£©¡£Æ¾¾ÝCipherTraceµÄÊý¾Ý£¬2021ÄêÓëDeFiÏà¹ØµÄ¹¥»÷»î¶¯Õ¼ËùÓÐÖ÷Òª¹¥»÷»î¶¯µÄ76%£¬¶ÔDeFiƽ̨µÄ¹¥»÷Ôì³ÉµÄËðʧÁè¼Ý4.74ÒÚÃÀÔª¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/hackers-steal-29-million-from-crypto-platform-cream-finance/