MongoDB¹«Ë¾¼ì²âµ½Æäϵͳ±»ºÚ²¿·Ö¿Í»§µÄÐÅϢй¶

Ðû²¼Ê±¼ä 2023-12-18
1¡¢MongoDB¹«Ë¾¼ì²âµ½Æäϵͳ±»ºÚ²¿·Ö¿Í»§µÄÐÅϢй¶


¾ÝýÌå12ÔÂ17ÈÕ±¨µÀ£¬£¬ £¬£¬£¬ÃÀ¹úÊý¾Ý¿âÈí¼þ¹«Ë¾MongoDBÔâµ½¹¥»÷£¬£¬ £¬£¬£¬²¿·Ö¿Í»§µÄÐÅÏ¢¿ÉÄÜй¶¡£ ¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬ £¬£¬£¬ËûÃÇÔÚ12ÔÂ13ÈÕÍíÉϼì²âµ½Æäϵͳ±»ºÚ¿Í¹¥»÷£¬£¬ £¬£¬£¬²¢×îÏÈÊÓ²ìÕâÆðÊÂÎñ¡£ ¡£¡£¡£ÕâÖÖδ¾­ÊÚȨµÄ»á¼ûÔÚ±»·¢Ã÷֮ǰÒѾ­Ò»Á¬ÁËÒ»¶Îʱ¼ä£¬£¬ £¬£¬£¬¿Í»§ÕÊ»§ÔªÊý¾ÝºÍÁªÏµÐÅÏ¢ÒѾ­Ð¹Â¶£¬£¬ £¬£¬£¬¿ÉÊÇMongoDB AtlasÖд洢µÄ¿Í»§Êý¾ÝûÓб»»á¼û¡£ ¡£¡£¡£16ÈÕÏÂÖç5:25µÄºóÐø¸üÐÂÖУ¬£¬ £¬£¬£¬MongoDB±¨¸æ³ÆµÇ¼ʵÑ鼤Ôö£¬£¬ £¬£¬£¬µ¼Ö»á¼ûMongoDB AtlasºÍSupport PortalµÄ¿Í»§Óöµ½ÎÊÌâ¡£ ¡£¡£¡£²»¹ýËûÖ¸³öÕâÓëÇå¾²ÊÂÎñÎ޹أ¬£¬ £¬£¬£¬²¢½¨ÒéÓû§ÔÚ¼¸·ÖÖÓºóÔÙ´ÎʵÑé¡£ ¡£¡£¡£


https://thehackernews.com/2023/12/mongodb-suffers-security-breach.html


2¡¢¼ÓÖÝDelta DentalÅûÂ¶Éæ¼°½ü700Íò¿Í»§µÄй¶ÊÂÎñ


¾Ý12ÔÂ15ÈÕ±¨µÀ£¬£¬ £¬£¬£¬¼ÓÖÝÑÀ¿Æ°ü¹ÜÌṩÉÌDelta Dental½ü700Íò»¼ÕßµÄÐÅϢй¶¡£ ¡£¡£¡£¸Ã¹«Ë¾Îª15¸öÖݵÄ4500ÍòÈËÌṩ°ü¹Ü£¬£¬ £¬£¬£¬Ð¹Â¶ÊÂÎñÔ´ÓÚMOVEit TransferÈí¼þÖеÄÎó²î¡£ ¡£¡£¡£Delta DentalÓÚ6ÔÂ1ÈÕ»ñϤ¸ÃÎó²î£¬£¬ £¬£¬£¬ÎåÌìºó£¬£¬ £¬£¬£¬¾­ÓÉÄÚ²¿ÊӲ죬£¬ £¬£¬£¬È·ÈÏδ¾­ÊÚȨµÄ¹¥»÷ÕßÔÚ5ÔÂ27ÈÕÖÁ5ÔÂ30ÈÕ»á¼û²¢ÇÔÈ¡ÁËÆäϵͳÖеÄÊý¾Ý¡£ ¡£¡£¡£µÚ¶þ´ÎÊÓ²ìÓÚ11ÔÂ27ÈÕÍê³É£¬£¬ £¬£¬£¬ÒÔÈ·¶¨ÊÂÎñµÄÓ°Ïì¹æÄ£¡£ ¡£¡£¡£¾ÝϤ£¬£¬ £¬£¬£¬×èÖ¹ÏÖÔÚ£¬£¬ £¬£¬£¬¹²6928932Ãû¿Í»§Êܵ½Ó°Ï죬£¬ £¬£¬£¬Éæ¼°ÐÕÃû²ÆÎñÕʺš¢ÐÅÓÿ¨/½è¼Ç¿¨ºÅ¼°Çå¾²´úÂë¡£ ¡£¡£¡£


https://www.hackread.com/delta-dental-data-breach-moveit-linked-attack/


3¡¢ÔÆ´æ´¢ÌṩÉÌBox±¬·¢ÖÐÖ¹Óû§ÎÞ·¨»á¼û´æ´¢µÄÎļþ 


ýÌå12ÔÂ15Èճƣ¬£¬ £¬£¬£¬ÔÆ´æ´¢ÌṩÉÌBox±¬·¢ÖÐÖ¹£¬£¬ £¬£¬£¬¿Í»§ÔÝʱÎÞ·¨»á¼û´æ´¢µÄÎļþ¡£ ¡£¡£¡£ÖÐÖ¹×îÏÈÓÚ15ÈÕÉÏÎç9µã×óÓÒ£¬£¬ £¬£¬£¬Ó°ÏìÁ˵Ǽ¡¢ÉÏ´«¡¢ÏÂÔØºÍAPIŲÓᣠ¡£¡£¡£ÊµÑéʹÓÃBoxµÄÓû§¿ÉÄܻῴµ½¹ýʧºÍ³¬Ê±£¬£¬ £¬£¬£¬µ«´ó´ó¶¼ÇéÐÎÏÂЧÀͽ«ÍêÈ«ÎÞ·¨»á¼û¡£ ¡£¡£¡£µ±Óû§ÊµÑéµÇ¼»ò»á¼û¸ÃЧÀÍʱ£¬£¬ £¬£¬£¬»áÓöµ½HTTP¹ýʧ503£¬£¬ £¬£¬£¬Ö¸³ö¡°´ËÒ³ÃæÎÞ·¨Õý³£ÊÂÇé¡£ ¡£¡£¡£account.box.comÏÖÔÚÎÞ·¨´¦Öóͷ£´ËÇëÇó¡£ ¡£¡£¡£¡±×èÖ¹12ÔÂ15ÈÕÏÂÖç1:21£¬£¬ £¬£¬£¬BoxÌåÏÖÒÑÐÞ¸´¸ÃÎÊÌ⣬£¬ £¬£¬£¬¿Í»§¿ÉÒÔÔٴλá¼ûÔÆÐ§ÀÍ¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/technology/box-cloud-storage-down-amid-critical-outage/


4¡¢Ã°³äWPÍйÜÉÌKinstaµÄ´¹ÂڻּÔÚÇÔÈ¡MyKinstaƾ֤


12ÔÂ17ÈÕ±¨µÀ³Æ£¬£¬ £¬£¬£¬WordPressÍйÜÌṩÉÌKinsta·¢Ã÷ÁËʹÓÃGoogle AdµÄ´¹Âڻ£¬£¬ £¬£¬£¬Ö¼ÔÚÇÔÈ¡ÆäÍÐ¹ÜÆ¾Ö¤¡£ ¡£¡£¡£KinstaÌåÏÖ£¬£¬ £¬£¬£¬¹¥»÷ÕßʹÓÃGoogle Ads£¬£¬ £¬£¬£¬Õë¶ÔÒÔǰ»á¼û¹ýKinsta¹Ù·½ÍøÕ¾µÄСÎÒ˽¼Ò¡£ ¡£¡£¡£ÕâЩ¹¥»÷Õß½¨ÉèÁËÓëKinstaºÜÊÇÏàËÆµÄÍøÕ¾£¬£¬ £¬£¬£¬À´ÓÕÆ­Óû§µã»÷ËüÃÇ£¬£¬ £¬£¬£¬×îÖÕ»áÍøÂçMyKinstaµÇ¼ƾ֤¡£ ¡£¡£¡£ÎªÁËÓ¦¶ÔÕâЩÍþв£¬£¬ £¬£¬£¬KinstaÕýÔÚÆð¾¢Ê¶±ð²¢¹Ø±Õ´¹ÂÚÍøÕ¾£¬£¬ £¬£¬£¬µ«½¨ÒéÓû§½ÓÄÉ×Ô¶¯²½·¥À´±£»£»£» £»£»£»¤×Ô¼ºµÄÕÊ»§¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/wordpress-hosting-service-kinsta-targeted-by-google-phishing-ads/


5¡¢Kaspersky·¢Ã÷ʹÓÃNKNЭÒéµÄ¶àƽ̨¶ñÒâÈí¼þNKAbuse


KasperskyÔÚ12ÔÂ14ÈÕ³ÆÆä·¢Ã÷ÁËÒ»ÖÖÃûΪNKAbuseµÄÐÂÐÍ¶àÆ½Ì¨¶ñÒâÈí¼þ¡£ ¡£¡£¡£Ëü½ÓÄÉGoÓïÑÔ¿ª·¢£¬£¬ £¬£¬£¬ÊǵÚÒ»¸öÒÀÀµNKNÊÖÒÕÔÚ½ÚµãÖ®¼ä¾ÙÐÐÊý¾Ý½»Á÷µÄ¶ñÒâÈí¼þ¡£ ¡£¡£¡£¶ñÒâÈí¼þ³äµ±Ö²Èë³ÌÐò£¬£¬ £¬£¬£¬²¢Å䱸ºéË®¹¥»÷ºÍºóÃŹ¦Ð§£¬£¬ £¬£¬£¬¿ÉÒÔÌìÉúÓëÖÖÖּܹ¹¼æÈݵĶþ½øÖÆÎļþ¡£ ¡£¡£¡£ÆÊÎöÅú×¢NKAbuseÖ÷ÒªÕë¶ÔLinux×ÀÃæ£¬£¬ £¬£¬£¬µ«¼øÓÚÆäѬȾMISPºÍARMϵͳµÄÄÜÁ¦£¬£¬ £¬£¬£¬Ò²¶ÔÎïÁªÍø×°±¸×é³ÉÁËÍþв¡£ ¡£¡£¡£Ò£²âÊý¾ÝÏÔʾ£¬£¬ £¬£¬£¬¸çÂ×±ÈÑÇ¡¢Ä«Î÷¸çºÍÔ½ÄÏÒÑ·ºÆð±»¹¥»÷Ä¿µÄ¡£ ¡£¡£¡£


https://securelist.com/unveiling-nkabuse/111512/


6¡¢ZimperiumÐû²¼2023ÄêÊÖ»úÒøÐжñÒâÈí¼þµÄÆÊÎö±¨¸æ


12ÔÂ14ÈÕ£¬£¬ £¬£¬£¬ZimperiumÐû²¼ÁË2023ÄêÊÖ»úÒøÐжñÒâÈí¼þµÄÆÊÎö±¨¸æ¡£ ¡£¡£¡£±¨¸æÖ¸³ö£¬£¬ £¬£¬£¬½ñÄê·ºÆðÁË10¸öеÄAndroidÒøÐжñÒâÈí¼þ¼Ò×壬£¬ £¬£¬£¬Õë¶Ô61¸ö¹ú¼Ò/µØÇø½ðÈÚ»ú¹¹µÄ985¸öÒøÐкͽðÈڿƼ¼/ÉúÒâÓ¦Óᣠ¡£¡£¡£³ýÁËÕâ10¸öÐÂľÂíÖ®Í⣬£¬ £¬£¬£¬2022ÄêµÄ19¸öľÂí¼Ò×åÒ²¾ÙÐÐÁËÐ޸ġ£ ¡£¡£¡£½ñÄêÔÚÒøÐжñÒâÈí¼þÖÐÊӲ쵽µÄй¦Ð§°üÀ¨£º×Ô¶¯×ªÕËϵͳ(ATS)¡¢»ùÓڵ绰µÄ¹¥»÷½»¸¶(TOAD)¡¢ÆÁÄ»¹²ÏíÒÔ¼°¶ñÒâÈí¼þ¼´Ð§ÀÍ (MaaS)¡£ ¡£¡£¡£ÎªÁËÌá·À´ËÀ๥»÷£¬£¬ £¬£¬£¬½¨ÒéÓû§²»Òª´Ó¹Ù·½ÇþµÀÖ®ÍâÏÂÔØAPK¡£ ¡£¡£¡£


https://www.zimperium.com/resources/zimperiums-2023-mobile-banking-heists-report-finds-29-malware-families-targeted-1800-banking-apps-across-61-countries-in-the-last-year/