TwitterÍøÂçÓû§ÐÅÏ¢¶¨ÏòÍÆË͸æ°×±»·£¿î1.5ÒÚÃÀÔª

°ä²¼¹¦·ò 2022-05-26

1¡¢TwitterÍøÂçÓû§ÐÅÏ¢¶¨ÏòÍÆË͸æ°×±»·£¿î1.5ÒÚÃÀÔª


¾Ý5ÔÂ26ÈÕ±¨Â·£¬ÃÀ¹úÁª¹úÒµÎñίԱ»áFTCÒѶÔTwitter·£¿î1.5ÒÚÃÀÔª£¬Ô­ÒòÊÇËüʹÓÃÍøÂçµÄ2FAÑéÖ¤µÄµç»°ºÅÂëºÍÓʼþµØÖ·À´ÍÆË͸æ°× ¡£Æ¾¾Ý·¨Í¥Îļþ£¬´Ó2013ÄêÆðÍ·£¬TwitterÒªÇ󳬹ý1.4ÒÚÓû§ÌṩÕâЩÐÅÏ¢ÒÔ±£»¤ËûÃǵÄÕË»§£¬µ«Ã»ÓÐ֪ͨËûÃÇÕâЩÊý¾ÝÒ²½«ÓÃÓÚ¸æ°×ÉÌͶ·Å¸æ°× ¡£FTCÖ÷ϯ³Æ£¬TwitterÒÔÓÃÓÚ°²È«Ö÷ÕÅΪ½è¿Ú´ÓÓû§ÄÇÀï»ñÈ¡Êý¾Ý£¬µ«×îÖÕ»¹Ê¹ÓÃÕâЩÊý¾ÝÀ´Õë¶ÔÓû§Í¶·Å¸æ°×£¬ÕâÖÖ×ö·¨Ó°ÏìÁË´óÁ¿Óû§µÄͬʱ»¹ÌáÉýÁËTwitterµÄÊÕÈë ¡£TwitterÒÑÔÞ³ÉÖ§¸¶1.5ÒÚÃÀÔªµÄ·£¿î ¡£


https://www.bleepingcomputer.com/news/technology/ftc-fines-twitter-150m-for-using-2fa-info-for-targeted-advertising/


2¡¢Ç÷Ïò¿Æ¼¼½¨¸´Òѱ»Moshen DragonÀûÓõÄDLL½Ù³Ö·ì϶


¾ÝýÌå5ÔÂ24ÈÕ±¨Â·£¬Ç÷Ïò¿Æ¼¼½¨¸´Æä°²È«²úÆ·ÖеÄDLL½Ù³Ö·ì϶ ¡£ÕýÈçSentinel LabsÔÚ5Ô³õÅû¶µÄÄÇÑù£¬Moshen DragonÔÚÕë¶ÔÖÐÑǵĵçÐÅÐÐÒµµÄ¹¥»÷ÖУ¬ÊÔͼ½Ù³Ö°²È«¹©¸øÉ̵ķ¨Ê½£¬Ô̺¬Symantec¡¢TrendMicro¡¢BitDefender¡¢McAfeeºÍKaspersky ¡£¹¥»÷ÕßÀûÓÃÁ˶à¸ö¶ñÒâÈí¼þ£¬²¢Í¨¹ýDLL½Ù³ÖÀ´²à¼ÓÔØShadowPadºÍPlugX ¡£Trend MicroÒÑÓÚ5ÔÂ19ÈÕͨ¹ýÆäActiveUpdate(AU)°ä²¼ÁËÒ»¸ö½¨¸´·¨Ê½£¬²¢½¨ÒéÓû§µ±¼´½øÐиüР¡£


https://securityaffairs.co/wordpress/131635/hacking/trend-micro-flaw-moshen-dragon.html


3¡¢Ä³ÅäÖÃÃýÎóµÄES·þÎñÆ÷й¶Êý°ÙÍò´û¿îÉêÇëÈ˵ÄÐÅÏ¢


¾Ý5ÔÂ24ÈÕ±¨Â·£¬Ò»¸öÅäÖÃÃýÎóµÄElasticsearch·þÎñÆ÷й¶ÁË147 GBµÄÊý¾Ý£¬¹²8.7Òڱʼͼ ¡£¸Ã·þÎñÆ÷ÓÚ2021Äê12ÔÂ5ÈÕ±»¼ì²âµ½£¬ÖØÒªÔ̺¬ÎÚ¿ËÀ¼¡¢¹þÈø¿Ë˹̹ºÍ¶íÂÞ˹Ó×¶î´û¿îµÄÉêÇëÈ˵ÄÐÅÏ¢£¬ÈçÐÕÃû¡¢×¡Ö·ºÍ»¤ÕÕºÅÂëµÈÓ×ÎÒÐÅÏ¢£¬ÒÔ¼°Ð½Ë®¡¢´û¿îÏêÇéºÍINN£¨Ë°ºÅ£©µÈ²ÆÕþÐÅÏ¢ ¡£¾Ý¹À¼Æ£¬Ô¼ÓÐ1000ÍòÓû§Êܵ½Ó°Ï죬ÆäÖдó²¿ÃÅ·þÎñÆ÷ÈÕÖ¾ºÍ»¤ÕÕºÅÂëÊôÓÚ¶íÂÞ˹£¬´óÎÞÊýINNÊôÓÚÎÚ¿ËÀ¼£¬¶ø¸Ã·þÎñÆ÷λÓÚºÉÀ¼µÄ°¢Ä·Ë¹Ìص¤ ¡£


https://www.hackread.com/personal-data-russians-ukrainians-exposed-online/


4¡¢Mozilla°ä²¼¸üн¨¸´Pwn2Own´ó»áÖб»ÀûÓõĶà¸ö·ì϶


5ÔÂ20ÈÕ£¬Mozilla°ä²¼ÁËFirefoxºÍThunderbirdµÄ°²È«¸üУ¬ÒÔ½¨¸´ÔÚPwn2Own 2022´ó»áÆÚ¼ä±»ÀûÓõķì϶ ¡£µÚÒ»¸ö·ì϶ÊÇTop-Level AwaitʵÏÖÖеÄÔ­ÐÍÁ´´«È¾£¨prototype pollution£©·ì϶£¬×·×ÙΪCVE-2022-1802£¬¹¥»÷Õß¿ÉÀûÓÃËüÀ´Ö´ÐÐJavaScript´úÂë ¡£µÚ¶þ¸ö·ì϶( CVE-2022-1529 ) ÊÇJavaScript¶ÔÏóË÷ÒýÖÐʹÓò»ÊÜÐŵÄÊäÈëµ¼ÖµÄÔ­ÐÍÁ´´«È¾·ì϶£¬¿ÉÓÃÀ´ÔÚÌØÈ¨¸¸¹ý³ÌÖÐÖ´ÐÐJavaScript ¡£CISAÔÚ5ÔÂ23ÈÕ°ä²¼°²È«¹«¸æ£¬½¨ÒéÂíÉϽ¨¸´ÕâЩ·ì϶ ¡£


https://www.bleepingcomputer.com/news/security/mozilla-fixes-firefox-thunderbird-zero-days-exploited-at-pwn2own/


5¡¢ChromeÀ©´óScreencastify½¨¸´¿É½Ù³ÖÉãÏñÍ·µÄXSS·ì϶


ýÌå5ÔÂ24Èճƣ¬Ê¢ÐеÄChromeÀ©´óScreencastify½¨¸´ÁËÒ»¸öXSS·ì϶ ¡£ÕâÊÇÒ»¸öÓÃÓÚ¼ÆÁ¡¢ÊÓÆµ±à×ëºÍýÌå¹²ÏíµÄä¯ÀÀÆ÷À©´ó£¬ÔÚChromeÖеÄ×°ÖÃÁ¿³¬¹ý10000000´Î ¡£¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶ÆôÓÃScreencastify¼ÔìÊÓÆµ£¬²¢½«ÆäÉÏ´«µ½Google Drive ¡£»¹Äܹ»ÀûÓÃͬÑùµÄ·ì϶À´ÇÔÈ¡¹È¸èÇý¶¯Æ÷µÄOAuthÁîÅÆ£¬²¢ÓÃËüÀ´ÏÂÔØÉÏ´«µÄÊÓÆµ£¬ÒÔ¼°´æ´¢ÔڹȸèÇý¶¯Æ÷ÉÏµÄÆäËüÆ÷²Ä ¡£


https://www.bleepingcomputer.com/news/security/screencastify-chrome-extension-flaws-allow-webcam-hijacks/


6¡¢BlackBerry°ä²¼¹ØÓÚChaosбäÌåYashmaµÄ·ÖÎö»ã±¨


5ÔÂ24ÈÕ£¬BlackBerry°ä²¼Á˹ØÓÚÀÕË÷Èí¼þYashma¼°Æä¼Ò×åµÄ·ÖÎö»ã±¨ ¡£ChaosÊÇÒ»Öֿɶ¨ÔìµÄÀÕË÷Èí¼þ¹¹½¨Æ÷£¬ÓÚ2021Äê6ÔÂ9ÈÕ³õ´Î³öÏÖ£¬Ôø¾­ÀúÁË5´Îµü´ú£¬YashmaÐû³ÆÊÇËüµÄµÚÁù°æ(v6.0)£¬ÓÚ2022ÄêµÄÄêÖÐÔÚÒ°±í±»·¢ÏÖ ¡£ChaosµÄǰÈý¸ö°æ±¾Ó봫ͳµÄÀÕË÷Èí¼þ±ÈÆðÀ´¸üÏñÊÇÓµÓзÛËéÐԵľÂí£¬µ«Chaos 4.0½øÒ»²½¸Ä½ø£¬½«¿É¼ÓÃÜÎļþµÄÉÏÏÞÌá¸ßµ½2.1MB ¡£Chaos 5.0ʹÓÃÁËAES-256¼ÓÃÜÖ¸±êÎļþ£¬¶øYashmaÓëÉÏÒ»¸ö°æ±¾ÏÕЩһÑù£¬½öÔö³¤ÁËÁ½ÏîÅú¸Ä ¡£ 


https://blogs.blackberry.com/en/2022/05/yashma-ransomware-tracing-the-chaos-family-tree