CarlsbadµÄ¹«Ë¾ÔâǰԱ¹¤Åê»÷£¬£¬£¬ £¬ £¬£¬£¬£¬1200¸öOffice 365ÕÊ»§É¾³ý£»£»£»£»£»CNAѬȾPhoenix£¬£¬£¬ £¬ £¬£¬£¬£¬1.5Íǫ̀װ±¸±»¼ÓÃÜ

Ðû²¼Ê±¼ä 2021-03-26

1.CarlsbadµÄ¹«Ë¾ÔâǰԱ¹¤Åê»÷£¬£¬£¬ £¬ £¬£¬£¬£¬1200¸öOffice 365ÕÊ»§±»É¾³ý


1.jpg


ÃÀ¹úCarlsbadµÄIT×Éѯ¹«Ë¾Ô⵽ǰԱ¹¤Deepanshu KherµÄÅê»÷£¬£¬£¬ £¬ £¬£¬£¬£¬1200¸öOffice 365ÕÊ»§±»É¾³ý¡£¡£¡£¡£¡£¡£¡£KherÓÚ2018Äê5Ô±»Ô­¹«Ë¾¿ª³ý£¬£¬£¬ £¬ £¬£¬£¬£¬Ö®ºó»Øµ½ÁËÓ¡¶È²¢ÓÚͬÄê8ÔÂ8ÈÕÈëÇÖÁ˸ù«Ë¾£¬£¬£¬ £¬ £¬£¬£¬£¬É¾³ýÆä1200¶à¸öMicrosoft Office 365ÕÊ»§£¨×ܹ²1500¸ö£©¡£¡£¡£¡£¡£¡£¡£µ¼Ö¹«Ë¾Ô±¹¤ÎÞ·¨Ê¹Óõç×ÓÓʼþ¡¢ÁªÏµÈËÁÐ±í¡¢¾Û»áÈÕÀú¡¢Îĵµ¡¢ÊÓÆµºÍÒôƵ¾Û»áµÈЧÀÍ£¬£¬£¬ £¬ £¬£¬£¬£¬¹«Ë¾±»ÆÈ¹Ø±ÕÁ½Ì죬£¬£¬ £¬ £¬£¬£¬£¬ºóÓÖÆÆ·ÑÊýÔÂÍêÈ«»Ö¸´ÔËÓª£¬£¬£¬ £¬ £¬£¬£¬£¬ËùÉæÓöȸߴï560000ÃÀÔª¡£¡£¡£¡£¡£¡£¡£KherÓÚ½ñÄê1ÔÂ11ÈÕ±»²¶£¬£¬£¬ £¬ £¬£¬£¬£¬±»Åд¦2ÄêͽÐÌ£¬£¬£¬ £¬ £¬£¬£¬£¬· £¿£¿£¿î567084ÃÀÔª¡£¡£¡£¡£¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/resentful-employee-deletes-1-200-microsoft-office-365-accounts-gets-prison/


2.CNAѬȾPhoenix CryptoLocker£¬£¬£¬ £¬ £¬£¬£¬£¬1.5Íò¶ą̀װ±¸±»¼ÓÃÜ


2.png


°ü¹Ü¹«Ë¾CNA³ÆÆäÔ⵽еÄÀÕË÷Èí¼þPhoenix CryptoLockerµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£CNA FinancialÊÇÃÀ¹ú×î´óµÄÉÌÒµ¹¤ÒµºÍÒâÍâΣÏÕ°ü¹Ü¹«Ë¾Ö®Ò»¡£¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ3ÔÂ21ÈÕ£¬£¬£¬ £¬ £¬£¬£¬£¬ºÚ¿Í¼ÓÃÜÁËÆäÁè¼Ý1.5Íò¶ą̀װ±¸£¬£¬£¬ £¬ £¬£¬£¬£¬°üÀ¨Ê¹Óù«Ë¾µÄVPN¾ÙÐÐÔ¶³Ì°ì¹«µÄÔ±¹¤µÄÅÌËã»ú£¬£¬£¬ £¬ £¬£¬£¬£¬µ¼Ö¹«Ë¾ÔÚÏßЧÀÍÖÐÖ¹£¬£¬£¬ £¬ £¬£¬£¬£¬ÓªÒµÔËÓªÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬ £¬ £¬£¬£¬£¬ÐµÄPhoenix Locker¿ÉÄÜÓëEvil Corp£¬£¬£¬ £¬ £¬£¬£¬£¬¸ÃÍÅ»ïʹÓÃÐÂÀÕË÷Èí¼þ¼Ò×åHadesÒÔÈÆ¹ýÃÀ¹úµÄÖÆ²Ã¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/insurance-giant-cna-hit-by-new-phoenix-cryptolocker-ransomware/


3.MicrosoftÐû²¼²¹¶¡£¬£¬£¬ £¬ £¬£¬£¬£¬ÐÞ¸´PsExecÓ¦ÓÃÖеÄÌáȨÎó²î


3.jpg


MicrosoftÐû²¼ÁËPsExec v2.33£¬£¬£¬ £¬ £¬£¬£¬£¬ÒÔÐÞ¸´ÆäÖеÄÌáȨÎó²î¡£¡£¡£¡£¡£¡£¡£PsExecÊÇSysinternalsÊÊÓóÌÐò£¬£¬£¬ £¬ £¬£¬£¬£¬ÔÊÐíÖÎÀíÔ±ÔÚÔ¶³ÌÅÌËã»úÉÏÖ´ÐÐÖÖÖֻ£¬£¬£¬ £¬ £¬£¬£¬£¬¹¥»÷Õßͨ³£Ê¹ÓÃÆäÔÚÍøÂçºáÏòÒÆ¶¯²¢×°ÖöñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£David WellsÓÚ2020Äê12Ô·¢Ã÷ÁËλÓÚÃüÃû¹ÜµÀͨѶÖеÄÎó²î£¬£¬£¬ £¬ £¬£¬£¬£¬ÍâµØÓû§¿ÉʹÓÃÆäÌáÉýµ½SYSTEMȨÏÞ¡£¡£¡£¡£¡£¡£¡£WellsÔÚÉϱ¨¸ÃÎó²î²¢ÆÚ´ý90Ììºó£¬£¬£¬ £¬ £¬£¬£¬£¬¹ûÕæÁËÍêÕûµÄPoC¡£¡£¡£¡£¡£¡£¡£Microsoft×îÖÕÓÚ3ÔÂ23ÈÕ£¬£¬£¬ £¬ £¬£¬£¬£¬ÔÚPsExec v2.33ÖÐÐû²¼Á˸ÃÎó²îµÄ²¹¶¡³ÌÐò¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-fixes-windows-psexec-privilege-elevation-vulnerability/


4.Ó¡¶ÈÒ©ÉÌFKOLÒòÏú»ÙÊý¾Ý±»ÃÀ¹úFDA· £¿£¿£¿î5000ÍòÃÀÔª


4.jpg


Ó¡¶Èresenius KabiÁöѧÓÐÏÞ¹«Ë¾£¨FKOL£©µÄÒ»¼ÒÖÆÒ©³§ÒòÏú»ÙÊý¾Ý£¬£¬£¬ £¬ £¬£¬£¬£¬±»ÃÀ¹úʳÎïºÍÒ©ÎïÖÎÀí¾Ö£¨FDA£©· £¿£¿£¿î5000ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¸Ã¹¤³§Ö÷ÒªÉú²úÃÀ¹ú¾øÖ¢»¼ÕßʹÓõļ¸ÖÖ²î±ð°©Ö¢Ò©ÎïµÄ»îÐÔÒ©ÎïÒòËØ(api)¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ô­¶¨ÓÚ2013Äê1Ô½ÓÊÜFDA¼ì²é£¬£¬£¬ £¬ £¬£¬£¬£¬µ«ÃÀ¹ú˾·¨²¿ÌåÏÖ£¬£¬£¬ £¬ £¬£¬£¬£¬¸Ã¹«Ë¾Ô±¹¤´Ó¹¤³§ÖÐ×ªÒÆÁËÅÌËã»ú¡¢Ö½ÖÊÎļþºÍÆäËûÖÊÁÏ£¬£¬£¬ £¬ £¬£¬£¬£¬²¢É¾³ýÁËÓйظó§Î¥¹æÐÐΪ֤¾ÝµÄ¼Í¼¡£¡£¡£¡£¡£¡£¡£3ÔÂ23ÈÕ£¬£¬£¬ £¬ £¬£¬£¬£¬FKOL±»ÃÀ¹úµØÒªÁìÔºÅз £¿£¿£¿î3000ÍòÃÀÔª²¢Ã»ÊÕ2000ÍòÃÀÔªµÄ´¦·Ö¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/drug-maker-to-pay-50m-for/


5.ºÚ¿ÍÔÚÒÔÉ«ÁдóѡǰһÌì¹ûÕæÁè¼Ý600Íò¸öÑ¡ÃñµÄÐÅÏ¢


5.jpg


ÔÚÒÔÉ«Áдóѡǰ²»µ½24Сʱ£¬£¬£¬ £¬ £¬£¬£¬£¬ºÚ¿Í¹ûÕæÁËÁè¼Ý650Íò¸öÑ¡ÃñµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨6528565ÃûÑ¡ÃñµÄÐÕÃûºÍѡƱºÅÂ룬£¬£¬ £¬ £¬£¬£¬£¬ÒÔ¼°Áè¼Ý300ÍòÒÔÉ«Áй«ÃñµÄÐÕÃû¡¢µç»°ºÅÂë¡¢Éí·ÝÖ¤ºÅÂë¡¢¼ÒÍ¥µØµã¡¢ÐÔ±ð¡¢ÄêËêºÍÕþÖÎÆ«ºÃµÈСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬ £¬ £¬£¬£¬£¬´Ë´ÎÊÂÎñÊÇÓÉÓÚÈí¼þ¹«Ë¾Elector SoftwareΪÒÔÉ«ÁÐÕþµ³Likud¿ª·¢µÄÓ¦ÓóÌÐòElectorÖб£´æÎó²î£¬£¬£¬ £¬ £¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎúй¶µÄÊý¾ÝÊÇ·ñÒѱ»»á¼û¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115918/hacking/israeli-voters-leak.html


6.Íâ»ãÉúÒâÉÌFBSй¶½ü20TBÁè¼Ý160ÒÚÌõ¿Í»§µÄÉúÒâ¼Í¼


6.jpg


WizCaseÑо¿Ö°Ô±·¢Ã÷Íâ»ãÉúÒâÉÌFBSÒòElasticsearchЧÀÍÆ÷ÉèÖùýʧ£¬£¬£¬ £¬ £¬£¬£¬£¬Ð¹Â¶Á˽ü20TBÁè¼Ý160ÒÚÌõ¿Í»§µÄÉúÒâ¼Í¼¡£¡£¡£¡£¡£¡£¡£FBSÊÇÌìÏÂÉÏ×îæµµÄÍâ»ã£¨forex£©ÉúÒâÔÚÏ߯½Ì¨Ö®Ò»£¬£¬£¬ £¬ £¬£¬£¬£¬ÔÚÈ«ÇòÓµÓжà´ï1600ÍòÓû§¡£¡£¡£¡£¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨Óû§ÐÕÃû¡¢µç×ÓÓʼþºÍÕ˵¥µØµã¡¢µç»°ºÅÂë¡¢IPµØµã¡¢»¤ÕÕºÅÂë¡¢É罻ýÌåID¡¢Éí·ÝÖ¤¡¢¼ÝʻִÕÕ¡¢ÒøÐÐÕË»§¶ÔÕʵ¥¡¢Ë®µç·ÑÕ˵¥ºÍÐÅÓÿ¨µÈ£¬£¬£¬ £¬ £¬£¬£¬£¬ÒÔ¼°Óû§ID¡¢Î´¼ÓÃܵÄÃÜÂë¡¢µÇ¼ÀúÊ·¼Í¼¡¢»áÔ±Êý¾ÝºÍÃÜÂëÖØÖÃÁ´½ÓµÈÊý¾Ý¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/forex-leaks-millions-customer/