CenturyLink·ÓÉÎÊÌâµ¼ÖÂSteamºÍDiscordµÈЧÀÍÖÐÖ¹ £»£»£»£»£»£»£»Fallguys¿ÉÔÚä¯ÀÀÆ÷ºÍDiscordÖÐÇÔÈ¡Ãô¸ÐÎļþ

Ðû²¼Ê±¼ä 2020-08-31

1.CenturyLink·ÓÉÎÊÌâµ¼ÖÂSteamºÍDiscordµÈЧÀÍÖÐÖ¹


1.jpg


CenturyLink BGP·ÓÉÎÊÌâÒÑÒý·¢ÁËÕû¸ö»¥ÁªÍøµÄÁ¬Ëø·´Ó¦£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂCloudflare¡¢Amazon¡¢Garmin¡¢Steam¡¢DiscordºÍBlizzardµÈÖÚ¶àÍøÂçЧÀÍÖÐÖ¹¡£¡£¡£¡£´Ë´ÎÖÐֹԼĪÔÚÃÀ¹ú¶«²¿±ê׼ʱ¼äÉÏÎç6µã×îÏÈ£¬£¬£¬£¬£¬£¬´ó×ÚÓû§±¨¸æÆäÔÚÃÀ¹úµÄЧÀͱ¬·¢ÖÐÖ¹¡£¡£¡£¡£CenturyLinkÌåÏÖ£¬£¬£¬£¬£¬£¬ÊÇÆäLevel3 CA3Êý¾ÝÖÐÐĵÄÎÊÌâµ¼Ö´˹ÊÕÏ£¬£¬£¬£¬£¬£¬²¢ÕýÔÚÊÓ²ì´ËÎÊÌ⣬£¬£¬£¬£¬£¬ÏÖÔÚЧÀÍÒ²ÕýÔÚ»ºÂý»Ö¸´ÖС£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/centurylink-routing-issue-led-to-outages-on-hulu-steam-discord-more/


2.Fallguys¿ÉÔÚä¯ÀÀÆ÷ºÍDiscordÖÐÇÔÈ¡Ãô¸ÐÎļþ


2.jpg


npmÇå¾²ÍŶӷ¢Ã÷npmÃÅ»§Öб£´æÒ»¸ö¶ñÒâJavaScript¿âFallguys£¬£¬£¬£¬£¬£¬Ö¼ÔÚ´ÓÊÜѬȾÓû§µÄä¯ÀÀÆ÷ºÍDiscordÓ¦ÓÃÖÐÇÔÈ¡Ãô¸ÐÎļþ¡£¡£¡£¡£¸Ã¿âÉù³ÆÊÇFall Guys£ºUltimate Knockout ÓÎÏ·APIµÄ½Ó¿Ú£¬£¬£¬£¬£¬£¬¿ÉÊÇ£¬£¬£¬£¬£¬£¬Æä¶ñÒâ´úÂ뽫»á¼û5¸öÍâµØÎļþ£¬£¬£¬£¬£¬£¬¶ÁÈ¡ÆäÄÚÈݲ¢½«Êý¾ÝÐû²¼µ½DiscordͨµÀÄÚ¡£¡£¡£¡£ÕâÎå¸öÎļþ»®·ÖΪChrome¡¢Opera¡¢Yandex BrowserºÍBraveµÈä¯ÀÀÆ÷µÄLevelDBÊý¾Ý¿â£¬£¬£¬£¬£¬£¬ÒÔ¼°ÓÃÓÚDiscord Windows¿Í»§¶ËLevelDBÊý¾Ý¿â¡£¡£¡£¡£npmÇå¾²ÍŶӽ¨Ò鿪·¢Ö°Ô±´ÓÆäÏîÄ¿ÖÐɾ³ý¸Ã¶ñÒâÈí¼þ°ü¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/malicious-npm-package-caught-trying-to-steal-sensitive-discord-and-browser-files/


3.SendgridÓû§ÕË»§Ôâµ½ÈëÇÖ²¢±»ÓÃÓÚ·Ö·¢¶ñÒâÈí¼þ


3.png


µç×ÓÓʼþЧÀÍÌṩÉÌSendgrid´ó×Ú¿Í»§µÄÕÊ»§Ôâµ½ÈëÇÖ£¬£¬£¬£¬£¬£¬ÕâЩÕÊ»§µÄÃÜÂë±»ÆÆ½â²¢³öÊÛ¸ø¶ñÒâ¹¥»÷Õߣ¬£¬£¬£¬£¬£¬ÒÔÓÃÓÚ·Ö·¢¶ñÒâÈí¼þ»òÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£¡£¸üÔã¸âµÄÊÇ£¬£¬£¬£¬£¬£¬Í¨¹ýSendgridÕÊ»§·¢Ë͵ĵç×ÓÓʼþÖаüÀ¨µÄ¶ñÒâÁ´½Ó¶¼ÊÇÄ£ºýµÄ£¬£¬£¬£¬£¬£¬Òò´ËÊÕ¼þÈ˲¢²»ÇåÎúµ±ËûÃǵã»÷Á´½ÓʱÊÇË­ÇÔÈ¡ÁËÆäÐÅÏ¢¡£¡£¡£¡£SendgridÌåÏÖ£¬£¬£¬£¬£¬£¬ÆäÕýÔÚÆð¾¢ÔöÇ¿Çå¾²·À»¤£¬£¬£¬£¬£¬£¬³ýÁËÒªÇóÓû§Ê¹ÓÃÓû§ÃûºÍÃÜÂëÍ⣬£¬£¬£¬£¬£¬»¹Ê¹ÓöàÖÖÐÎʽµÄ2FA¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://krebsonsecurity.com/2020/08/sendgrid-under-siege-from-hacked-accounts/


4.EmotetʹÓÃеĶñÒ⸽¼þRed Dawn£¬£¬£¬£¬£¬£¬ÍÑÀëÒÔÍùiOSÖ÷Ìâ


4.png


EmotetʹÓÃеĶñÒ⸽¼þRed Dawn£¬£¬£¬£¬£¬£¬ÍÑÀëÒÔÍùiOSÖ÷Ìâ¡£¡£¡£¡£¾­ÓÉÎå¸öÔµÄÐÝÏ¢ºó£¬£¬£¬£¬£¬£¬EmotetÓÚ2020Äê7ÔÂÉý¼¶»Ø¹é£¬£¬£¬£¬£¬£¬×îÏÈÔÚÈ«Çò¹æÄ£ÄÚÉ¢²¼´ó×Ú¶ñÒâÀ¬»øÓʼþ£¬£¬£¬£¬£¬£¬ÕâЩÓʼþαװ³É·¢Æ±¡¢ÔËÊäÐÅÏ¢¡¢COVID-19ÐÅÏ¢¡¢¼òÀú¡¢²ÆÎñÎļþ»òɨÃèµÄÎļþ£¬£¬£¬£¬£¬£¬ÓÕʹÓû§µã»÷¶ñÒâWord£¨.doc£©¸½¼þ»òÏÂÔØÁ´½Ó¡£¡£¡£¡£ÎªÁËʹÓû§ÆôÓú꣬£¬£¬£¬£¬£¬Emotet³ÆÎĵµÊÇÔÚiOSÉϽ¨ÉèµÄ£¬£¬£¬£¬£¬£¬³ý·Çµ¥»÷ÆôÓÃÄÚÈݲ»È»ÎÞ·¨×¼È·Éó²é¡£¡£¡£¡£µ«´Ë´ÎµÄRed DawnÄ£°åÍÑÀëÁËÒÔÍùµÄiOSÖ÷Ì⣬£¬£¬£¬£¬£¬ÉùÃ÷´ËÎĵµÊܱ £»£»£»£»£»£»£»¤²»¿ÉÔ¤ÀÀ£¬£¬£¬£¬£¬£¬ÐèÒªÆôÓñ༭ºÍÆôÓÃÄÚÈÝÒÔÉó²éÎĵµ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/emotet-malwares-new-red-dawn-attachment-is-just-as-dangerous/


5.Avast·¢Ã÷DVB-T2»ú¶¥ºÐÒ×Êܽ©Ê¬ÍøÂçºÍÀÕË÷Èí¼þ¹¥»÷


5.png


Avast Security·¢Ã÷DVB-T2»ú¶¥ºÐ±£´æÎó²î£¬£¬£¬£¬£¬£¬Ò×Êܽ©Ê¬ÍøÂçºÍÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£ÊÜÓ°ÏìµÄ»ú¶¥ºÐÐͺÅΪTHOMSON THT741FTAºÍPhilips DTR3502BFTA£¬£¬£¬£¬£¬£¬ËüÃÇÔÊÐíÏûºÄÕßÔÚδÄÚÖõÄÇéÐÎÏÂʹÆäµçÊÓÖ§³ÖDVB-T2¡£¡£¡£¡£¸ÃÎó²îµÄ½¹µãÔÚÓÚ£¬£¬£¬£¬£¬£¬ÕâÁ½ÖÖ×°±¸¶¼Ã»ÓÐʹÓüÓÃÜÊÖÒÕÔÚЧÀÍÆ÷»òÆäËûÅþÁ¬×°±¸Ö®¼äÍù·µ´«ÊäÊý¾Ý¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬»ú¶¥ºÐʹÓùŰåAPIÓëAccuWeatherºó¶Ë¾ÙÐÐͨѶ£¬£¬£¬£¬£¬£¬¿Éµ¼Ö¹¥»÷Õ߸͝Êý¾Ý£¬£¬£¬£¬£¬£¬²¢ÏÔʾËûÃÇ×Ô¼ºÑ¡ÔñµÄÊý¾Ý¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/flaws-dvb-t2-set-top-boxes-botnet-ransomware-attacks/


6.Ñо¿Ö°Ô±·¢Ã÷й¥»÷·½·¨¿ÉÈÆ¹ýEMV¿¨µÄPINÑéÖ¤»·½Ú


6.png


ËÕÀèÊÀÁª°îÀí¹¤Ñ§ÔºµÄÑо¿Ö°Ô±·¢Ã÷ÐµĹ¥»÷·½·¨¿ÉʹÓÃEMVÖеÄÎó²î£¬£¬£¬£¬£¬£¬ÈƹýPINÑéÖ¤»·½Ú¡£¡£¡£¡£¸ÃÎó²îÖ÷ÒªÓÉÓÚÂß¼­È±ÏÝ£¬£¬£¬£¬£¬£¬¿É±»Ê¹ÓÃÌᳫÖÐÐÄÈ˹¥»÷£¬£¬£¬£¬£¬£¬¸æËßÖÕ¶ËÒѾ­ÔÚÏûºÄÕßµÄ×°±¸ÉÏÖ´ÐÐÁËPINÑéÖ¤£¬£¬£¬£¬£¬£¬²»ÔÙÐèÒªPINÑéÖ¤¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚ²»ÖªµÀÐÅÓÿ¨ÃÜÂëµÄÇéÐÎÏÂʹÓÃ͵À´µÄVisa¿¨¾ÙÐзǽӴ¥Ê½ÉúÒâ¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬ Ñо¿Ö°Ô±¾­Ê¹ÓÃVisaÐÅÓÿ¨¡¢Visa ElectronºÍVPay¿¨µÈVisaÆ·ÅÆµÄ¿¨ÀֳɵزâÊÔÁ˴˴ι¥»÷£¬£¬£¬£¬£¬£¬²¢Òѽ«ÊÓ²ìЧ¹û±¨¸æ¸øVisa¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/new-attacks-allow-bypassing-emv-card-pin-verification