TeslaºÍSpaceXµÄÁã¼þÔì×÷ÉÌVisserÊý¾Ýй¶£»Î¯ÄÚÈðÀ­´ó¹æÄ£Í£µçµ¼Ö²¿ÃŵØÓò»¥ÁªÍøÖжÏ

°ä²¼¹¦·ò 2020-03-03

1.°Ä´óÀûÑÇÐÅϢרԱ°ì¹«ÊÒ°ä²¼Êý¾Ýй¶֪ͨ£¨NDB£©»ã±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾Ý°Ä´óÀûÑÇÐÅϢרԱ°ì¹«ÊÒ£¨OAIC£©µÄÊý¾Ýй¶֪ͨ£¨NDB£©»ã±¨ £¬ÔÚ2019Äê7ÔÂ1ÈÕÖÁ2019Äê12ÔÂ31ÈÕÆÚ¼ä»ã±¨µÄÊý¾Ýй¶ÊÂÎñÊýÁ¿Îª537Æð £¬±ÈÉϰëÄêµÄ460ÆðÔö³¤ÁË19% ¡£¶ñÒâ¹¥»÷£¨Ô̺¬ÍøÂçÊÂÎñ£©ÒÀÈ»ÊÇÔì³ÉÊý¾Ýй¶µÄÖØÒªÔ­Òò £¬Õ¼ËùÓÐÊÂÎñµÄ64% ¡£Óɱ¨´ðÃýÎóÒýÆðµÄÊý¾Ýй¶ռËùÓÐй¶µÄ32£¥ £¬µÍÓÚÉÏÒ»¸ö»ã±¨ÆÚµÄ34£¥ ¡£Ò½ÁÆÐÐÒµÔٴγÉΪ²úÉúй©×î¶àµÄÐÐÒµ £¬Õ¼ËùÓÐÊÂÎñµÄ22% £¬Æä´ÎÊǽðÈÚ £¬Õ¼14% ¡£ÁªÏµ·½Ê½ÒÀÈ»ÊÇÊý¾Ýй¶ÖÐ×î³£¼ûµÄÓ×ÎÒÐÅÏ¢ÀàÐÍ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.oaic.gov.au/privacy/notifiable-data-breaches/notifiable-data-breaches-statistics/notifiable-data-breaches-report-july-december-2019/


2.TeslaºÍSpaceXµÄÁã¼þÔì×÷ÉÌVisserÈ·ÈÏÔâºÚ¿Í¹¥»÷ÇÒÊý¾Ýй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


TeslaºÍSpaceXµÄÁã¼þÔì×÷ÉÌVisserÈ·ÈÏÔâ·êÊý¾Ýй¶ÊÂÎñ £¬¸Ã¹«Ë¾ÊÇÒ»¼ÒרÃÅΪ̫¿ÕºÍ¹ú·À³Ð°üÉÌÉè¼Æ¾«ÃÜÁã¼þµÄÔì×÷ÉÌ ¡£ÔÚÒ»·Ý¼ò¶ÌµÄÉêÃ÷ÖÐ £¬¸Ã¹«Ë¾È·ÈÏÆä½üÆÚ³ÉΪ¡°ÍøÂ簲ȫ·¸×ïÊÂÎñ£¨Ô̺¬½Ó¼ûºÍ͵ÇÔÊý¾Ý£©µÄÖ¸±ê¡± ¡£¸Ã¹«Ë¾½²»°È˰µÊ¾½«¡°³ÖÐø¶Ô¸Ã¹¥»÷½øÐÐÈ«Ãæµ÷²é £¬²¢ÇÒÒµÎñÔËÐÐÕý³£¡± ¡£TechCrunch×êÑÐÈËÔ±³ÆÕâ´Î¹¥»÷ºÜÓпÉÄÜÊÇÓÉDoppelPaymerÀÕË÷Èí¼þÒýÆðµÄ ¡£


Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2020/03/01/visser-breach/


3.Ó¢¹úWi-FiÌṩÉÌC3UKÔÆÊý¾Ý¿âй¶1ÍòÃûÌú·³Ë¿Í¼Í¼


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


C3UKÔÚÓ¢¹ú¸÷µØµÄ»ð³µÕ¾Îª³Ë¿ÍÌṩÃâ·ÑµÄWi-fi ¡£¸Ã¹«Ë¾ÈÏ¿ÉδÄܶÔÔ̺¬Óû§ÐÅÏ¢µÄÊý¾Ý¿âÌṩ±£»¤ £¬µ¼ÖÂ1ÍòÃûÓ¢¹úÌú·³Ë¿ÍµÄÓ×ÎÒÊý¾Ýй¶ ¡£°²È«×êÑÐÔ±Ò®ÀûÃ×ÑÇ¡¤¸£ÀÕ£¨Jeremiah Fowler£©·¢Ïָù«Ë¾µÄAWSÊý¾Ý¿â²»ÊÜÃÜÂë±£»¤ £¬Òò¶øÈκÎÈ˶¼Äܹ»²é¿´Óû§Êý¾Ý ¡£¸ÃÊý¾Ý¿âÊÇÔÚ2019Äê11ÔÂ28ÈÕÖÁ2020Äê2ÔÂ12ÈÕÖ®¼ä´´½¨µÄ £¬ÆäÖÐÔ̺¬1.46Òڱʼͼ £¬ÀýÈç³Ë¿ÍµÄµ®ÉúÈÕÆÚ¡¢µç×ÓÓʼþµØÖ·ºÍ¹Û¹â´òËã ¡£ÊÜÓ°ÏìµÄ³Ë¿ÍÔ̺¬ÔÚHarlow Mill¡¢Chelmsford¡¢Colchester¡¢Waltham Cross¡¢Burnham¡¢NorwichºÍLondon BridgeʹÓÃÃâ·ÑWi-Fi·þÎñµÄ³Ë¿Í ¡£¸Ã¹«Ë¾³ÆÊý¾Ý¿âûÓÐÔ̺¬Óû§µÄÃÜÂë»ò²ÆÕþÐÅÏ¢µÈ¹Ø¼üÊý¾Ý ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/data-of-10k-rail-passengers/


4.ίÄÚÈðÀ­´ó¹æÄ£Í£µçµ¼Ö²¿ÃŵØÓò»¥ÁªÍøÖжÏ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


3ÔÂ1ÈÕίÄÚÈðÀ­Ôâ·ê´ó¹æÄ£Í£µçÊÂÎñ £¬µ¼Ö¸ùúÔ¼35£¥µÄµçÐÅ»ù´¡Éèʩ̱»¾ ¡£»¥ÁªÍø¹Û²âÕ¾NetBlocks»ã±¨³Æ £¬Í£µçºÍ¹©¸øµßô¤µ¼Ö¸ùúºÜ´óÒ»²¿ÃÅ»¥ÁªÍøÏνÓÖжÏ ¡£Í£µçÓ°ÏìÁËίÄÚÈðÀ­µÄ¶à¸öÖÝ £¬Òƶ¯ÍøÂçÒ²²¿ÃÅÊܵ½ÊÂÎñµÄÓ°Ïì £¬µ«¸Ã×éÖ¯»ã±¨³Æµßô¤ºóËüÃÇÒÑѸ¿ì¸´Ô­ ¡£Õâ²¢²»ÊÇίÄÚÈðÀ­µçÍøµÚÒ»´ÎÊܵ½´ó¹æÄ£Í£µçµÄÓ°Ïì £¬2019Äê3Ô¸ùú¾ÍÔøÔâ·ê´ó¹æÄ£Í£µçÊÂÎñ £¬ÆäʱίÄÚÈðÀ­Í¨Ñ¶ºÍÐÅÏ¢´ó³¼ºÀ¶ûºÕ¡¤ÂÞµÂÀï¸ñ˹£¨Jorge Rodriguez£©Ôð¹ÖÍ£µçÊÇÓÉÃÀ¹ú¶Ô¹ÅÀïË®Á¦·¢µç³§·¢ÆðÍøÂç¹¥»÷µ¼ÖµÄ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/98771/security/venezuela-power-outage.html


5.×êÑÐÈËÔ±ÑÝʾͨ¹ý³¬Éù²¨ÈëÇÔ컹ûºÍ¹È¸èÓïÒô¸±ÊÖ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖÒ»ÖÖÐµĹ¥»÷²½Öè £¬Äܹ»Í¨¹ýÔÚ¹ÌÌå×ʲÂÖд«²¼³¬Éù²¨À´¶Ô×¼ÓïÒô¸±ÊÖÉ豸 £¬´Ó¶øÔÚÊܺ¦Õß²»ÖªÇéµÄÇé¿öÏÂÓëÓïÒôÉ豸½øÐн»»¥ºÍÖ´ÐÐÈëÇÖ ¡£ÕâÖÖ¹¥»÷±»³ÆÎª¡°SurferingAttack¡± £¬ËüÀûÓÃÁ˹ÌÌå×ÊÁÏ£¨ÀýÈç×À×Ó£©ÖÐÉùÒô´«ÊäµÄ¹ÖÒì¸öÐÔ £¬ÒÔ¡°Ê¹¹¥»÷ÕßÄܹ»ÓëÓïÒôÉ豸֮¼ä½øÐиü³¤¾àÀëµÄÂŴν»»¥ £¬¶øÎÞÐè³Ê´Ë¿ÌÊÓÏßÄÚ ¡£¡±×êÑÐÈËÔ±ÔÚÂÛÎÄÖиÅÊöÁ˹¥»÷Õß¿ÉÄÜÀûÓÃÕâÖÖ¹¥»÷½Ù³ÖSMS¶ÌÐÅË«³É·ÖÉí·ÝÑéÖ¤Âë £¬ÉõÖÁ²¦´òڲƭÐԵ绰µÄÐÐΪ ¡£×êÑÐÈËÔ±²âÊÔÁË17ÖÖÉ豸 £¬ÆäÖÐ13̨É豸ÔËÐеÄÊÇ´øÓÐGoogle AssistantµÄAndroidϵͳ £¬ËĄ̈ÊÇ´øÓÐApple SiriµÄiPhone £¬×êÑÐÈËÔ±¿ÉÄܽÚÔì15̨É豸 £¬µ«¸Ã¼¼Êõ¶ÔÈýÐǵÄGalaxy Note 10+ºÍ»ªÎªµÄMate 9ÎÞЧ ¡£


Ô­ÎÄÁ´½Ó£º

https://nakedsecurity.sophos.com/2020/03/02/siri-and-google-assistant-hacked-in-new-ultrasonic-attack/


6.Õë¶Ôº«¹úµÄ¡°Blue Esteeate Part5¡± APT¹¥»÷·ÖÎö»ã±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝEast SecurityµÄÒ»·Ý»ã±¨ £¬2ÔÂ28ÈÕ³öÏÖÁËÀûÓüÙ×°³ÉHangulÎĵµ£¨ºó׺ÃûΪhwp £¬º«¹úÈËʹÓõÄÒ»ÖÖÎĵµÌåʽ£©¼òÀúµÄscrÎļþ½øÐеÄAPT¹¥»÷ ¡£¸ÃAPT¹¥»÷ÖÐʹÓõĶñÒâÎļþ±»¼ì²âΪTrojan.Agent.115608C/Trojan.Agent.Detplock ¡£EastÈ·Èϸù¥»÷Ϊ·¸×ïÍÅ»ïKim Soo-kiÌáÒéµÄAPT¹¥»÷-¼´Blue House Green Support/Sangchunjae Estimate APT¹¥»÷-µÄµÚ5¸ö±äÌå ¡£¸Ã±äÌåÓÚ2ÔÂ27ÈÕ±àÒë £¬ÊÇÆÁÄ»±£»¤·¨Ê½ÀàÐ͵ĿÉÖ´ÐÐÎļþ £¬¿É·ÂÕÕhwpÎĵµ £¬ÀýÈç¾­Ñé±íform.hwp.scr ¡£ÈôÊÇÓû§³¢ÊÔ½«Îļþ×÷ΪhwpÎĵµ²é¿´ £¬Ôò¸Ã¶ñÒâÈí¼þ½«ÔËÐÐ £¬¿ªÊÍÏÖʵÓÐÐ§ÔØºÉ²¢×ÔÐÐɾ³ý£¨¸´Ô­form.hwp.scr£© £¬ÒÔÔ¤·ÀÒýÆðÓû§µÄÒÉ»ó ¡£¸Ã¶ñÒâÈí¼þ½«ÍøÂçºÍÉÏ´«Êܺ¦ÕßµÄÐÅÏ¢ £¬²¢ÆÚ´ý¹¥»÷ÕߵįäËûºÅÁî ¡£


Ô­ÎÄÁ´½Ó£º

https://blog.alyac.co.kr/2784