ÐÂ¼ÓÆÂGeniusUÒòй¶126ÍòÓû§µÄÐÅÏ¢±»·£¿î3.5ÍòÃÀÔª
°ä²¼¹¦·ò 2022-04-241¡¢Cisco½¨¸´ÆäUmbrella VAµÈ¶à¸ö²úÆ·ÖеÄ3¸ö·ì϶
4ÔÂ21ÈÕ£¬Cisco°ä²¼°²È«¸üУ¬½¨¸´Æä¶à¿î²úÆ·Öеķì϶¡£ÆäÖÐÔ̺¬Cisco TelePresenceºÏ×÷Öն˺ÍRoomOSÈí¼þÖеĻؾø·þÎñ·ì϶£¨CVE-2022-20783£©£¬Ô´ÓÚ²»×ãÊäÈëÑéÖ¤£»Cisco UmbrellaÐé¹¹É豸(VA)¾²Ì¬SSHÖ÷»úÃÜÔ¿Öеķì϶£¨CVE-2022-20773£© £¬¿ÉÓÃÀ´¶ÔSSHÏνÓÖ´ÐÐMitM¹¥»÷²¢½Ù³ÖÖÎÀíԱʹ´¦£»ÒÔ¼°Cisco Virtualized Infrastructure ManagerÖеÄÌáȨ·ì϶£¨CVE-2022-20732£©¡£
https://www.cisa.gov/uscert/ncas/current-activity/2022/04/21/cisco-releases-security-updates-multiple-products-0
2¡¢T-Mobile³ÆLAPSUS$ÍÅ»ïʹÓñ»µÁÍ´´¦½Ó¼ûÆäÄÚ²¿ÏµÍ³
¾ÝýÌå4ÔÂ22ÈÕ±¨Â·£¬T-Mobile³ÆÀÕË÷ÍÅ»ïLapsus$ÔÚ¼¸ÖÜǰʹÓñ»µÁÍ´´¦ÈëÇÖÁËÆäÍøÂ磬²¢»ñµÃÁ˶ÔÄÚ²¿ÏµÍ³µÄ½Ó¼ûȨÏÞ¡£¸Ã¹«Ë¾²¹³ä˵£¬ÔÚ·¢ÏÖÎÊÌâºóËüÂíÉ϶½ØÁ˹¥»÷Õß¶ÔÆäÍøÂçµÄ½Ó¼û£¬²¢½ûÓÃÁ˹¥»÷ÖÐʹÓõÄÍ´´¦¡£Æ¾¾ÝT-MobileµÄ˵·¨£¬Lapsus$ÔÚ¹¥»÷ÆÚ¼ä²¢Î´ÇÔÈ¡¿Í»§µÄÐÅÏ¢¡£×êÑÐÈËԱͨ¹ý¸ÃÍÅ»ïµÄÄÚ²¿Ì¸Ìì¼Í¼·¢ÏÖ£¬ËûÃǽӼûÁËT-MobileµÄÄÚ²¿¿Í»§ÕË»§ÖÎÀí¹¤¾ßAtlas£¬ÈëÇÔìäSlackºÍBitbucketÕË»§£¬²¢ÀûÓÃÕË»§ÏÂÔØÁË30000¶à¸öÔ´´úÂë´æ´¢¿â¡£
https://thehackernews.com/2022/04/t-mobile-admits-lapsus-hackers-gained.html
3¡¢LockBitÐû³ÆÒÑÇÔÈ¡ÀïÔ¼ÈÈÄÚ¬²ÆÕþ²¿ÃÅÔ¼420GBµÄÊý¾Ý
ýÌå4ÔÂ22ÈÕ±¨Â·£¬ÀÕË÷ÍÅ»ïLockBitÐû³Æ¹¥»÷ÁËÀïÔ¼ÈÈÄÚ¬µ±¾Ö°ì¹«ÊÒµÄϵͳ£¬²¢ÇÔÈ¡ÁËÔ¼420 GBµÄÊý¾Ý¡£ÀïÔ¼ÈÈÄÚ¬ÊǰÍÎ÷µÚ¶þ´ó³ÇÊУ¬ÄÏÃÀÖ޵ĽðÈÚÖÐÐÄÖ®Ò»£¬ÆäGDPÔÚÈ«ÇòÅÅÃûµÚ30λ¡£ÀïÔ¼ÈÈÄÚ¬²ÆÕþ²¿ÃŵĹÙÔ±ÔÚÉÏÖÜÎå֤ʵ£¬Ä¿Ç°ÔÚ´¦ÖÃÕë¶ÔÆäϵͳµÄÀÕË÷¹¥»÷¡£¸Ã¹ÙÔ±³Æ£¬¹¥»÷ÕßÍþвҪй¶´ÓSefaz-RJϵͳÖÐÇÔÈ¡µÄÊý¾Ý£¬µ«ÕâЩÊý¾Ý½öÏ൱ÓÚÃØÊé´¦Öü´æÊý¾ÝµÄ0.05%¡£
https://therecord.media/rio-de-janeiro-finance-department-hit-with-lockbit-ransomware/
4¡¢ÃÀ¹úµ±¾Öй©ÆäÒÑÔÚDHS±í²¿ÏµÍ³Öз¢ÏÖ122¸ö°²È«·ì϶
¾Ý4ÔÂ22ÈÕ±¨Â·£¬ÃÀ¹úºÓɽ°²È«Êýй©ÆäHack DHS·ì϶Éͽð´òËãÒÑÔÚDHS±í²¿ÏµÍ³Öз¢ÏÖ122¸ö°²È«·ì϶¡£DHSÏò³¬¹ý450Ãû×êÑÐÈËÔ±¼Î½±ÁË125600ÃÀÔª£¬Ã¿¸ö·ì϶µÄ½«½ü¾ùÔÈΪ5000ÃÀÔª¡£Hack DHS´òËãÓÚ2021Äê12ÔÂÆô¶¯£¬ËüÒªÇóºÚ¿ÍÅû¶·ì϶µÄ¾ßÌåÐÅÏ¢¡¢ÈôºÎÀûÓÃËüÒÔ¼°ÈôºÎʹÓÃËü½Ó¼ûDHSϵͳ¡£¶øºó£¬DHS½«ÔÚ48Ó×ʱÄÚÑéÖ¤·ì϶£¬²¢ÔÚ15Ìì»ò¸ü³¤¹¦·òÄÚ½¨¸´¡£
https://www.bleepingcomputer.com/news/security/hack-dhs-bug-hunters-find-122-security-flaws-in-dhs-systems/
5¡¢ÐÂ¼ÓÆÂGeniusUÒòй¶126ÍòÓû§µÄÐÅÏ¢±»·£¿î3.5ÍòÃÀÔª
ýÌå4ÔÂ22Èճƣ¬ÐÂ¼ÓÆÂ½ÌÓý¿Æ¼¼¹«Ë¾GeniusUй¶126ÍòÓû§µÄÐÅÏ¢¡£ÐÂ¼ÓÆÂÓ×ÎÒÊý¾Ý±£»¤Î¯Ô±»á(PDPC)ÔÚ4ÔÂ21ÈÕ°ä²¼µÄÊéÃæ¾ö¶¨ÖаµÊ¾£¬GeniusUδÄÜÔì¶©ºÏÀíµÄÕ½Êõ£¬µ¼ÖÂÓû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢Î»ÏàÐÅÏ¢ºÍÉϴεǼIPµØÖ·µÈÐÅÏ¢±»µÁ£¬·£¿î35000ÃÀÔª¡£GeniusUµÄÄÚ²¿µ÷²é·¢ÏÖ£¬Õâ´ÎÊÂÎñ¿ÉÄÜÊÇÆä¿ª·¢ÈËÔ±µÄÕÊ»§±»µÁµ¼Öµģ¬¹¥»÷ÕßʹÓÃËûµÄGitHubÕÊ»§ÕÒµ½Á˵Ǽʹ´¦£¬»ñµÃÁËGeniusUÊý¾Ý¿âµÄ½Ó¼ûȨÏÞ²¢ÇÔÈ¡Êý¾Ý¡£
https://www.straitstimes.com/tech/tech-news/edu-tech-firm-geniusu-fined-35000-for-data-leak-affecting-126m-users
6¡¢Mandiant°ä²¼2021ÄêÒѱ»ÀûÓÃ0-dayµÄ·ÖÎö»ã±¨
4ÔÂ21ÈÕ£¬Mandiant°ä²¼ÁË2021ÄêÒѱ»ÀûÓÃ0-dayµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬MandiantÔÚÈ¥Äê·¢ÏÖÁË80Æð0-dayÔÚÒ°±í±»ÀûÓõÄÊÂÎñ£¬±È2020ÄêºÍ2019ÄêµÄ×ܺͻ¹¶àÁË18Æð¡£2021Äê0-day¹¥»÷µÄÖØÒª³§ÉÌÊÇ΢Èí¡¢Æ»¹ûºÍ¹È¸è£¬Õ¼ËùÓй¥»÷µÄ75%ÒÔÉÏ¡£Õë¶ÔÒÆ¶¯²Ù×÷ϵͳAndroidºÍiOSµÄ0-dayÊýÁ¿Ò²³ÊÉÏÉýÇ÷Ïò£¬´Ó2019ÄêºÍ2020ÄêµÄ²»µ½5¸öÔö³¤µ½2021ÄêµÄ17¸ö¡£´ó²¿ÃŹ¥»÷¹éÒòÓÚ¹ú¶ÈÖ§³ÖµÄ¼äµý»î¶¯£¬ÀûÓÃ0-dayµÄ¹¥»÷ÕßÖÐÓÐÈý·ÖÖ®Ò»³öÓÚ¾¼Ã¶¯»ú¡£
https://www.mandiant.com/resources/zero-days-exploited-2021


¾©¹«Íø°²±¸11010802024551ºÅ