TikTok·ñ¶¨ÆäÔâµ½¹¥»÷ºóÔ´´úÂëºÍÓû§Êý¾Ý±»µÁµÄ˵·¨

°ä²¼¹¦·ò 2022-09-07
1¡¢TikTok·ñ¶¨ÆäÔâµ½¹¥»÷ºóÔ´´úÂëºÍÓû§Êý¾Ý±»µÁµÄ˵·¨

      

¾ÝýÌå9ÔÂ5ÈÕ±¨Â·£¬ÃûΪAgainstTheWestµÄºÚ¿ÍÍÅ»ïÐû³ÆÒÑÈëÇÖTikTokºÍ΢ÐÅ£¬²¢°ä²¼ÁËËùνÊý¾Ý¿âµÄ½ØÍ¼¡£ËûÃÇ˵¸ÃÊý¾Ý¿âÊÇÔÚÒ»¸ö°¢ÀïÔÆÊ·ýÉϽӼûµÄ£¬Ô̺¬20.5Òڱʼͼ£¬Éæ¼°Óû§Êý¾Ý¡¢Æ½Ì¨Í³¼ÆÐÅÏ¢¡¢Èí¼þ´úÂë¡¢cookie¡¢Éí·ÝÑéÖ¤ÁîÅÆºÍ·þÎñÆ÷ÐÅÏ¢µÈ¡£TikTok·ñ¶¨ÁËÆä±»ºÚ¿ÍÈëÇÖµÄ˵·¨£¬²¢°µÊ¾¹¥»÷Õß¹«¿ªµÄµÄÔ´´úÂë²»ÊÇÆäÆ½Ì¨µÄÒ»²¿ÃÅ¡£´Ë±í£¬AgaintTheWest µÄÕ˺ÅÒѱ»Í£Ó㬺ڿÍÂÛ̳BreachÖ¸³öй¶Êý¾Ý²¢·ÇÀ´×ÔTikTok£¬²¢ÇÒ¹¥»÷Õß¿ÉÄÜÔÚ˵»Ñ¡£


https://www.bleepingcomputer.com/news/security/tiktok-denies-security-breach-after-hackers-leak-user-data-source-code/


2¡¢InstagramÒòÎ¥·´GDPRÀÄÓöùͯÊý¾Ý±»°®¶ûÀ¼·£¿î4ÒÚÃÀÔª

      

¾Ý9ÔÂ6ÈÕ±¨Â·£¬InstagramÒòÎ¥·´GDPR±»°®¶ûÀ¼Êý¾Ý±£»¤Î¯Ô±»á(DPC)·£¿î4.02ÒÚÃÀÔª¡£DPC°µÊ¾£¬InstagramÔÊÐí13-17ËêµÄ¶ùͯ³ÉÁ¢Ã³Ò×ÕË»§£¬Õâ¿ÉʹÕâЩ¶ùͯµÄÐÅÏ¢±»¹«¿ª¡£²¢ÇÒÆäÓû§×¢²áϵͳÖжùͯÓû§µÄÕÊ»§Ä¬ÈÏÉèÖÃΪ¹«¿ª£¬´Ó¶ø¹«¿ªÁË´ËÀàÓû§µÄÉ罻ýÌåÄÚÈÝ£¬Óû§±ØÐëÊÖ¶¯½«ÕÊ»§ÉèÖÃΪ¸öÈË¡£InstagramµÄĸ¹«Ë¾Meta¶Ô·£¿îµÄÍÆË㷽ʽÌá³öÒìÒ飬³ÆÆä²»ÇкÏGDPRµÄÎı¾£¬µ¼Ö·£¿îÏÔÖø¸ßÓÚÆäËüÓëGDPRÓйصķ£¿î£¬²¢³ïËã¶Ô¸ÃÖ¸¿ØÌá³öÉÏËß¡£  


https://therecord.media/instagram-appealing-400-million-fine-from-ireland-data-privacy-org-over-gdpr-violations/


3¡¢ResecurityÔÚ°µÍø·¢ÏÖ¿ÉÈÆ¹ýMFAµÄEvilProxy PhaaS 

      

9ÔÂ5ÈÕ£¬ResecurityÅû¶ÁËеÄÍøÂç´¹µö¼´·þÎñ(PaaS)ƽ̨EvilProxy¡£ÔÚijЩÇé¿öÏÂËüµÄ´úÌæÃû³ÆÊÇMoloch£¬Óë֮ǰÕë¶Ô½ðÈÚ»ú¹¹ºÍµçÉÌÐÐÒµµÄ¼¸¸ö³£¼ûµÄ´¹µö¹¤¾ß°üÓÐijÖÖÁªÏµ¡£EvilProxyÓÚ2022Äê5ÔÂÉÏÑ®³õ´Î±»¼ì²âµ½£¬×êÑÐÈËÔ±°µÊ¾ÏñEvilProxyÕâÑùµÄ²úÆ·»¯·þÎñ¿ÉÓÃÀ´×î´ó¹æÄ£µØ¹¥»÷ÆôÓÃÁËMFAµÄÓû§£¬¶øÎÞÐèÆÆ½âÉÏÓηþÎñ¡£¹¥»÷ÕßÀûÓ÷´Ïò´úÀíºÍCookie×¢ÈëµÄ²½ÖèÈÆ¹ý2FAÉí·ÝÑéÖ¤£¬´ËÀಽÖèÔÚAPTºÍ¼äµý¹¥»÷µÅ×ÐÕë¶ÔÐԵĻÖÐʱʱ¼ûµ½¡£ÖµÍ×ÌùÐĵÄÊÇ£¬EvilProxy»¹Ö§³ÖÕë¶ÔPyPiµÄ´¹µö¹¥»÷¡£


https://resecurity.com/blog/article/evilproxy-phishing-as-a-service-with-mfa-bypass-emerged-in-dark-web


4¡¢¹ú¼ÊÐ̾¯×éÖ¯·¢ÏÖ²¢³É¹¦µ·»Ùij¿ç¹úÊý×ÖÀÕË÷ÍÅ»ï

      

ýÌå9ÔÂ5Èճƣ¬¹ú¼ÊÐ̾¯×éÖ¯µÄÍøÂç·¸×ﲿÃÅÓëÐÂ¼ÓÆÂºÍÖйúÏã¸Û¾¯·½½áºÏµ÷²éºó£¬·¢ÏÖ²¢³É¹¦µ·»Ùij¿ç¹úÊý×ÖÀÕË÷ÍŻµ÷²éÈËÔ±·¢ÏÖ¹¥»÷Õßͨ¹ýÔÚÏßÉ«ÇéÆ½Ì¨ºÍÔ¼»áƽ̨ҪÇóÖ¸±êÏÂÔØ¶ñÒâÒÆ¶¯ÀûÓò¢½øÐÐÂãÁÄ£¬¶øºó¸Ã¶ñÒâÀûÓûáÇÔÈ¡ËûÃÇÊÖ»úÁªÏµÈËÁбíÖеÄÄÚÈÝ£¬¹¥»÷Õß»áÀûÓÃÕâЩÐÅÏ¢À´Ú²Æ­Ö¸±ê£¬ÍþвҪÓëËûÃÇͨѶ¼ÖеÄÇ×ÓÑ·ÖÏíÕâЩÊÓÆµ¡£Ä¿Ç°£¬12ÃûÉæÏÓÊǸÃÍÅ»ïÖ÷Ìâ³ÉÔ±µÄÏÓÒÉÈËÒÑÓÚ7ÔºÍ8Ô±»²¶¡£¹ú¼ÊÐ̾¯×éÖ¯°µÊ¾£¬½üÄêÀ´Êý×ÖÀÕË÷µÄ»ã±¨¼±¾çÔö³¤£¬¶øCOVID-19¼Ó¾çÁËÕâÖÖÔö³¤¡£


https://www.bleepingcomputer.com/news/security/interpol-dismantles-sextortion-ring-warns-of-increased-attacks/


5¡¢NCCй©ÐÂSharkBot±äÖÖÔÙ´ÎÈÆ¹ýGoogle PlayµÄ¼ì²â

      

¾ÝýÌå9ÔÂ5Èճƣ¬NCC Group×êÑÐÈËÔ±ÔÚGoogle Play StoreÖз¢ÏÖÁËеÄSharkBot±äÖÖ¡£ÐµÄSharkBot dropper²»ÒÀ¸½AccessibilityȨÏÞÀ´×Ô¶¯Ö´ÐÐ×°Öã¬Ïà·´£¬Õâ¸öбäÌåÒªÇóÖ¸±ê½«¸Ã¶ñÒâÈí¼þ×÷Ϊһ¸öÐéα¸üÐÂÀ´×°Öá£ÓÐÎÊÌâµÄÁ½¸öÀûÓ÷¨Ê½ÎªMister Phone CleanerºÍKylhavy Mobile Security£¬×°ÖÃÁ¿±ðÀëΪ10000ºÍ50000£¬ÖØÒªÕë¶ÔÎ÷°àÑÀ¡¢°Ä´óÀûÑÇ¡¢²¨À¼¡¢µÂ¹ú¡¢ÃÀ¹úºÍ°ÂµØÀûµÄÓû§¡£Ä¿Ç°£¬ÊÜÓ°ÏìÀûÓÃÒÑ´ÓGoogle PlayÖÐɾ³ý£¬µ«ÒÑ×°ÖõÄÓû§ÈÔÃæ¶Ô·çÏÕ£¬Ó¦ÊÖ¶¯É¾³ýËüÃÇ¡£


https://securityaffairs.co/wordpress/135303/malware/sharkbot-variant-google-play.html


6¡¢Kaspersky°ä²¼2021ÄêÍøÂ簲ȫÊÂÎñÏìÓ¦µÄ·ÖÎö»ã±¨

      

9ÔÂ5ÈÕ£¬Kaspersky°ä²¼ÁË2021ÄêÍøÂ簲ȫÊÂÎñÏìÓ¦µÄ·ÖÎö»ã±¨¡£ÔÚ¸ÃÄê¶ÈÊÂÎñÏìÓ¦»ã±¨ÖУ¬×êÑÐÈËԱƾ¾Ý¶Ô°²È«ÊÂÎñµÄµ÷²é¹«¿ªÁË×îз¢ÏÖºÍͳ¼ÆÊý¾Ý¡£ÔÚ2021Ä꣬´óÎÞÊýÊÂÎñÏìÓ¦·þÎñÒªÇóÀ´×ÔÓÉÅ·ÖÞ (30.1%)¡¢CIS(24.7%)ºÍÖж«(23.7%)£»¹¤Òµ(30.1%)¡¢µ±¾Ö(19.4%)ºÍ½ðÈÚ(12.9%)ÐÐÒµµÄ×éÖ¯ÒÀÈ»ÊÇ×î¾ßÕë¶ÔÐÔµÄ×éÖ¯£»ÔÚ53.6%µÄ°¸ÀýÖУ¬ÀûÓÃÃæÏò¹«¼ÒµÄÀûÓ÷¨Ê½Öеķì϶ÊÇ×î³õµÄϰȾý½é£»ÔÚ40%µÄÊÂÎñÖУ¬¹¥»÷ÕßʹÓÃÁ˺Ϸ¨¹¤¾ß¡£


https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2022/09/02120838/Kaspersky-The-nature-of-cyber-incidents_v11-1.pdf