ºÚ¿ÍÉù³ÆÒÑ»ñµÃ4ÒÚTwitterÓû§ÐÅÏ¢²¢ÊÔͼ³öÊÛ

Ðû²¼Ê±¼ä 2022-12-27
1¡¢ºÚ¿ÍÉù³ÆÒÑ»ñµÃ4ÒÚTwitterÓû§ÐÅÏ¢²¢ÊÔͼ½«Æä³öÊÛ

      

¾ÝýÌå12ÔÂ25ÈÕ±¨µÀ£¬£¬£¬ £¬£¬£¬£¬ÃûΪRyushiµÄ¹¥»÷ÕßÔÚºÚ¿ÍÂÛ̳BreachedÉϳöÊÛ4ÒÚTwitterÓû§µÄÊý¾Ý¡£¡£¡£¡£¡£ÂôÃÅ·ç³Æ¸ÃÊý¾Ý¿âÊÇ˽È˵Ä£¬£¬£¬ £¬£¬£¬£¬²¢ÌṩÁË1000¸öÕÊ»§µÄÐÅÏ¢×÷ΪÑù±¾£¬£¬£¬ £¬£¬£¬£¬ÆäÖаüÀ¨Donald Trump JRºÍBrian KrebsµÈÈË¡£¡£¡£¡£¡£ºÚ¿Í»¹Ô¼ÇëTwitterºÍElon Musk¹ºÖÃÕâЩÊý¾Ý£¬£¬£¬ £¬£¬£¬£¬ÒÔ×èÖ¹GDPRµÄ·£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£ÏÖÔÚÉÐÎÞ·¨ºËʵÂô¼ÒµÄ˵·¨¡£¡£¡£¡£¡£Êý¾Ý¿âÊÛ¼ÛΪ200000ÃÀÔª£¬£¬£¬ £¬£¬£¬£¬¾ÝϤÊÇʹÓÃTwitterÓÚ2022Äê1ÔÂÐÞ¸´µÄAPIÎó²î¾ÙÐÐÍøÂçµÄ¡£¡£¡£¡£¡£ÁíÒ»ºÚ¿ÍÒ²³ÆÊ¹ÓôËÎó²îץȡÁË1700ÍòÓû§µÄÊý¾Ý£¬£¬£¬ £¬£¬£¬£¬¿ÉÊDz»»á³öÊÛ¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/139993/data-breach/twitter-400-million-users-leak.html


2¡¢MetaÒÔ7.25ÒÚÃÀԪϢÕùCambridge AnalyticaÕûÌåËßËÏ

      

¾Ý12ÔÂ23ÈÕ±¨µÀ£¬£¬£¬ £¬£¬£¬£¬Facebookĸ¹«Ë¾MetaÒÑÔÞ³ÉÖ§¸¶7.25ÒÚÃÀÔª£¬£¬£¬ £¬£¬£¬£¬ÒÔÏ¢Õù¸Ã¹«Ë¾ÔÊÐíµÚÈý·½£¨°üÀ¨Cambridge Analytica£©»á¼ûÓû§Ð¡ÎÒ˽¼ÒÊý¾ÝµÄÕûÌåËßËÏ¡£¡£¡£¡£¡£ÕâÆðËßËÏʼÓÚ2018Ä꣬£¬£¬ £¬£¬£¬£¬ÆäʱFacebookÓû§Ö¸Ôð¸ÃÉç½»ÍøÂçÆ½Ì¨Î¥·´Òþ˽¹æÔò£¬£¬£¬ £¬£¬£¬£¬ÓëµÚÈý·½¹²ÏíÊý¾Ý¡£¡£¡£¡£¡£ËßËϳÆ£¬£¬£¬ £¬£¬£¬£¬Cambridge AnalyticaÔÚδ¾­Óû§Ô޳ɵÄÇéÐÎÏÂÍøÂçºÍʹÓÃÁË8700ÍòFacebookÓû§µÄÊý¾Ý¡£¡£¡£¡£¡£¾Ý³Æ£¬£¬£¬ £¬£¬£¬£¬ÕâЩÐÅÏ¢±»ÓÃÀ´¿ª·¢Èí¼þÖ¸µ¼ÃÀ¹úÑ¡ÃñÖ§³ÖÌØÀÊÆÕ¡£¡£¡£¡£¡£2019Äê7Ô£¬£¬£¬ £¬£¬£¬£¬ÃÀ¹úÕþ¸®ÒÔÎóµ¼Óû§ÎªÓɶÔFacebook´¦ÒÔ50ÒÚÃÀÔªµÄ·£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£Í¬Ô£¬£¬£¬ £¬£¬£¬£¬FacebookÔÞ³ÉÖ§¸¶1ÒÚÃÀÔªÒÔÁËÈ´Ö¸¿Ø¡£¡£¡£¡£¡£


https://therecord.media/meta-to-settle-cambridge-analytica-class-action-for-725-million/


3¡¢Ñо¿Ö°Ô±Åû¶¿ªÔ´²©¿Íƽ̨GhostÖеÄÁ½¸öÇå¾²Îó²î

      

ýÌå12ÔÂ22Èճƣ¬£¬£¬ £¬£¬£¬£¬Cisco Talos·¢Ã÷¿ªÔ´²©¿Íƽ̨GhostÖб£´æÁ½¸öÇå¾²Îó²î¡£¡£¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇÉí·ÝÈÆ¹ýÎó²î£¨CVE-2022-41654£¬£¬£¬ £¬£¬£¬£¬CVSSÆÀ·ÖΪ9.6£©£¬£¬£¬ £¬£¬£¬£¬ÔÊÐí·ÇÌØÈ¨Óû§£¨¼´»áÔ±£©¶ÔÊ±ÊÆÍ¨Ñ¶ÉèÖþÙÐÐδ¾­ÊÚȨµÄÐ޸ġ£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬£¬ÍøÕ¾ÖÎÀíԱĬÈÏÇéÐÎÏÂÔÚÊ±ÊÆÍ¨Ñ¶ÖÐ×¢ÈëJavaScriptµÄÄÜÁ¦¿É±»Ê¹Ó㬣¬£¬ £¬£¬£¬£¬Ôڱ༭ͨѶʱ´¥·¢À´½¨Éèí§ÒâµÄÖÎÀíÔ±ÕË»§¡£¡£¡£¡£¡£ÁíÒ»¸öÊǵǼ¹¦Ð§ÖеÄö¾ÙÎó²î£¨CVE-2022-41697£©£¬£¬£¬ £¬£¬£¬£¬¿Éµ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬ £¬£¬£¬£¬GhostÒÑÔÚ×îа汾µÄCMSÉϽâ¾öÁËÕâÁ½¸öÎó²î¡£¡£¡£¡£¡£


https://thehackernews.com/2022/12/two-new-security-flaws-reported-in.html


4¡¢±ÈÀûʱÉÌÒµÒøÐÐDegroof Petercam±¬·¢Êý¾Ýй¶

      

¾ÝLe Soir 12ÔÂ22ÈÕ±¨µÀ£¬£¬£¬ £¬£¬£¬£¬±ÈÀûʱÉÌÒµÒøÐÐDegroof Petercam±¬·¢Êý¾Ýй¶£¬£¬£¬ £¬£¬£¬£¬Ó°ÏìÁËÊý°Ù¼Ò±ÈÀûʱµÄ¹«Ë¾¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬ £¬£¬£¬£¬¸ÃÒøÐеÄÒ»ÃûÔ±¹¤ÀÄÓÃÆä¶Ô¿Í»§ÐÅÏ¢µÄ»á¼ûȨ²»·¨ÏÂÔØÁ˿ͻ§Îļþ¡£¡£¡£¡£¡£Le SoirµÄ½ãÃÃÆµµÀRTLÓÚ12ÔÂ9ÈÕÊÕµ½ÒøÐеÄ֪ͨ£¬£¬£¬ £¬£¬£¬£¬³ÆÆäÊý¾ÝÒÑй¶¡£¡£¡£¡£¡£Degroof PetercamÒ²ÒѾ­È·ÈÏ´Ë´Îй¶ÊÂÎñ¡£¡£¡£¡£¡£¾Ý¸ÃÒøÐн²»°È˳Æ£¬£¬£¬ £¬£¬£¬£¬Ö»ÓÐרҵµÄ¹ÉƱÆÚȨÍýÏë(SOP) ÕË»§»áÊܵ½¸ÃÊÂÎñµÄÓ°Ï죬£¬£¬ £¬£¬£¬£¬µ«¾Ý³ÆÊý°Ù¼ÒÖÖÖÖ¹æÄ£µÄ±ÈÀûʱ¹«Ë¾¶¼Êܵ½ÁËÓ°Ïì¡£¡£¡£¡£¡£


https://www.databreaches.net/data-leak-at-degroof-petercam-affects-hundreds-of-belgian-companies/


5¡¢Prodaft·¢Ã÷FIN7ʹÓÃ×Ô¶¯¹¥»÷ƽ̨CheckmarksµÄ»î¶¯

      

ProdaftÔÚ12ÔÂ22ÈÕ³ÆÆä·¢Ã÷FIN7ʹÓÃÒ»¸ö×Ô¶¯¹¥»÷ƽ̨Checkmarks£¬£¬£¬ £¬£¬£¬£¬À´ÈëÇÖ¹«Ë¾ÍøÂç¡¢ÇÔÈ¡Êý¾Ý²¢Æ¾Ö¤²ÆÎñ¹æÄ£Ñ¡ÔñÀÕË÷¹¥»÷µÄÄ¿µÄ¡£¡£¡£¡£¡£CheckmarksʹÓÃÁËMicrosoft ExchangeºÍSQL ×¢ÈëÎó²î£¬£¬£¬ £¬£¬£¬£¬´Ó2021Äê6ÔÂ×îÏȾͱ»ÓÃÓÚ×Ô¶¯Õì̽¹«Ë¾ÍøÂçÖÐÒ×±»¹¥»÷µÄ¶Ëµã£¬£¬£¬ £¬£¬£¬£¬È»ºóͨ¹ýPowerShell·Ö·¢web shellÀ´»ñÈ¡»á¼ûȨÏÞ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷FIN7ÓëDarkside¡¢REvilºÍLockBitµÈ¶à¸öÀÕË÷ÍÅ»ïÓйØ£¬£¬£¬ £¬£¬£¬£¬²¢Ê¹ÓÃÁËÐÂSSHºóÃÅ£¬£¬£¬ £¬£¬£¬£¬Í¨¹ýOnionÓòʹÓ÷´ÏòSSHÅþÁ¬(SFTP)´ÓÄ¿µÄ×°±¸ÖÐÇÔÈ¡Îļþ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/fin7-hackers-create-auto-attack-platform-to-breach-exchange-servers/


6¡¢SentinelOneÐû²¼¹ØÓÚVice SocietyÍÅ»ïµÄÆÊÎö±¨¸æ

      

12ÔÂ22ÈÕ£¬£¬£¬ £¬£¬£¬£¬SentinelOneÐû²¼±¨¸æ³Æ£¬£¬£¬ £¬£¬£¬£¬Vice Society×îÏÈʹÓÃеÄ×Ô½ç˵¼ÓÃܳÌÐò¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ¸ÃÍÅ»ï×î½üµÄÒ»´Î¹¥»÷Öз¢Ã÷ÁËÐÂÀÕË÷Èí¼þPolyVice£¬£¬£¬ £¬£¬£¬£¬Ëü½ÓÄÉ»ìÏý¼ÓÃܼƻ®£¬£¬£¬ £¬£¬£¬£¬½«·Ç¶Ô³Æ¼ÓÃÜÓëNTRUEncryptËã·¨ÏàÁ¬Ïµ£¬£¬£¬ £¬£¬£¬£¬¶Ô³Æ¼ÓÃÜÓëChaCha20-Poly1305Ëã·¨ÏàÁ¬Ïµ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÍƲ⣬£¬£¬ £¬£¬£¬£¬Õâ¿ÉÄÜÊÇVice Society´ÓÒ»¼ÒΪÆäËûÀÕË÷ÍÅ»ïÌṩÀàËÆ¹¤¾ßµÄ×éÖ¯´¦²É¹ºµÄ¡£¡£¡£¡£¡£¸Ã±äÌåÓÚ2022Äê7ÔÂ13ÈÕÊ×´ÎÔÚÒ°Íâ·ºÆð£¬£¬£¬ £¬£¬£¬£¬µ«Ö±µ½Á¼¾ÃÒÔºó²Å±»¸Ã×éÖ¯ÍêÈ«½ÓÄÉ¡£¡£¡£¡£¡£ÆÊÎöÅú×¢£¬£¬£¬ £¬£¬£¬£¬PolyViceÓëChillyºÍSunnyDayµÄ´úÂë¾ßÓÐÏàËÆÐÔ£¬£¬£¬ £¬£¬£¬£¬¹¦Ð§100%Æ¥Å䣬£¬£¬ £¬£¬£¬£¬Ö»ÓÐһЩϸ½Ú²î±ð¡£¡£¡£¡£¡£


https://www.sentinelone.com/labs/custom-branded-ransomware-the-vice-society-group-and-the-threat-of-outsourced-development/