ºÚ¿ÍÔÚ°µÍøÏúÊÛº¬½ü5ÒÚÌõWhatsAppÓû§¼Í¼µÄÊý¾Ý¿â

°ä²¼¹¦·ò 2022-11-28
1¡¢ºÚ¿ÍÔÚ°µÍøÏúÊÛº¬½ü5ÒÚÌõWhatsAppÓû§¼Í¼µÄÊý¾Ý¿â

¾ÝCybernewsÔÚ11ÔÂ26ÈÕ±¨Â·£¬ºÚ¿ÍÔÚ°µÍøÏúÊÛÒ»¸öÔ̺¬2022Äê4.87ÒÚWhatsAppÓû§ÊÖ»úºÅÂëµÄÊý¾Ý¿â¡£¸ÃÊý¾Ý¼¯Ô̺¬À´×Ô84¸ö¹ú¶È/µØÓòµÄÓû§Êý¾Ý£¬Éæ¼°ÃÀ¹ú£¨3200Íò£©¡¢°£¼°£¨4500Íò£©¡¢Òâ´óÀû£¨3500Íò£©¡¢É³Ìذ¢À­²®£¨2900Íò£©¡¢·¨¹ú£¨2000Íò£©ºÍÍÁ¶úÆä£¨2000Íò£©¡£¹¥»÷ÕßÒÔ7000ÃÀÔªµÄ¼ÛÖµÏúÊÛÃÀ¹úÊý¾Ý£¬Ó¢¹úµÄ2500ÃÀÔª£¬µÂ¹úµÄ2000ÃÀÔª¡£MetaµÄ½²»°ÈË˵£¬¸Ã»ã±¨ÊÇ´§Ä¦ÐÔÖʵÄ£¬»ùÓÚδ¾­Ö¤ÊµµÄ½ØÍ¼£¬²¢²¹³ä˵¸Ã¹«Ë¾Ã»Óз¢ÏÖWhatsAppϵͳÓÐÈκÎÊý¾Ýй¶ÎÊÌâ¡£

https://cybernews.com/news/whatsapp-data-leak/

2¡¢ÐÁÐÁÄÇÌáÖÝÁ¢´óѧÔâµ½ÀÕË÷ÍÅ»ïVice SocietyµÄ¹¥»÷

¾Ý11ÔÂ25ÈÕ±¨Â·£¬ÐÁÐÁÄÇÌáÖÝÁ¢¼¼ÊõºÍÉçÇøÑ§ÔºÔâµ½ÀÕË÷ÍÅ»ïVice SocietyµÄ¹¥»÷¡£¹¥»÷ÕßÔÚËûÃǵÄÍøÕ¾¹«¿ªÁËÒ»³¤´®±»µÁÎļþ£¬ÕâЩÎļþµÄÈÕÆÚ´Ó¼¸ÄêǰһÏòµ½2022Äê11ÔÂ24ÈÕ£¬ÕâÅúעѧÌò¢Î´Ö§¸¶Êê½ð¡£¸ÃѧÌÃÒÑ֪ͨÆäѧÉúºÍÔ±¹¤Õâ´Î¹¥»÷ÊÂÎñ£¬²¢°µÊ¾ÔÚÏß·þÎñºÍÕý³£ÔËÓªµÄ¸´Ô­±ØÒªÒ»¶Î¹¦·ò¡£Vice Society³Ö¾ÃÒÔÀ´Ò»Ö¹Øë¶ÔK-12ѧÌúʹóѧµÈ½ÌÓý»ú¹¹¡£

https://www.bleepingcomputer.com/news/security/vice-society-ransomware-claims-attack-on-cincinnati-state-college/

3¡¢Sysdigй©³¬¹ý1600¸öDocker Hub¾µÏñ°µ²Ø¶ñÒâ´úÂë

11ÔÂ23ÈÕ£¬Sysdig°ä²¼»ã±¨Ð¹Â©£¬1652¸ö¹«¿ªµÄDocker Hub¾µÏñ°µ²ØÁ˶ñÒâ´úÂë¡£×î³£¼ûµÄÀàÐÍÊǼÓÃܿ󹤣¬ÔÚ608¸öÈÝÆ÷¾µÏñÖз¢ÏÖ£¬ËüÃÇÒÔ·þÎñÆ÷×ÊԴΪָ±ê£¬Îª¹¥»÷ÕßÍÚ¾ò¼ÓÃÜÇ®±Ò¡£Æä´ÎÊǰµ²ØÇ¶Èëʽ»úÃܵľµÏñ£¬¹²281¸ö£¬ÕâЩ¾µÏñÖÐǶÈëÁËSSHÃÜÔ¿¡¢AWSƾ֤¡¢GitHubÁîÅÆºÍNPMÁîÅÆµÈ¡£Sysdig»¹·¢Ïֺܶà¶ñÒâ¾µÏñʹÓÃÓòÃû·Âð¼Ù×°³ÉºÏ·¨¾µÏñ£¬Ö¼ÔÚÈÃÓû§Ï°È¾¼ÓÃܿ󹤣¬ÆäÖÐÁ½¸öÑù±¾Òѱ»ÏÂÔØ½ü17000´Î¡£

https://sysdig.com/blog/analysis-of-supply-chain-attacks-through-public-docker-images/

4¡¢¹ú¼ÊÐ̾¯×éÖ¯µÄ·¨ÂÉÐж¯HAECHI-III½É»ñ1.3ÒÚÃÀÔª

¾ÝýÌå11ÔÂ24Èճƣ¬¹ú¼ÊÐ̾¯×éÖ¯´úºÅΪHAECHI IIIµÄ·¨ÂÉÐж¯£¬ÒѽɻñÓë¸÷ÀàÍøÂç·¸×ï»î¶¯ÓйصÄ1.3ÒÚÃÀÔªµÄ×ʲú¡£¸ÃÐж¯µÄ¹¦·òΪ2022Äê6ÔÂ28ÈÕÖÁ11ÔÂ23ÈÕ£¬×ܹ²¿ÛÁôÁË975ÈË£¬·âÁ˽ü2800¸öÒøÐкÍÐé¹¹×ʲúÕË»§£¬²¢½â¾öÁË1600¶àÆð°¸¼þ¡£Õâ´Î·¨ÂÉÐж¯»¹·¢ÏÖÁË16ÖÖеķ¸×ïÇ÷Ïò£¬Éæ¼°¸÷ÀàÀËÂþȦÌ׺ÍͶ×Êڲƭ»î¶¯£¬ÕâÓÐÖúÓÚÈ«Çò·¨Âɲ¿ÃŲÉÈ¡¸üÓÐÕë¶ÔÐԵķ¨ÂÉÐж¯¡£

https://thehackernews.com/2022/11/interpol-seized-130-million-from.html

5¡¢´÷¶û¡¢»ÝÆÕºÍåÚÏëµÄÉ豸ÈÔʹÓùýÆÚµÄOpenSSL¼ÓÃÜ¿â

¾ÝýÌå11ÔÂ25ÈÕ±¨Â·£¬Binarly·¢ÏÖ£¬´÷¶û¡¢»ÝÆÕºÍåÚÏëµÄÉ豸ÈÔÔÚʹÓùýÆÚ°æ±¾µÄOpenSSL¼ÓÃܿ⡣×êÑз¢ÏÖ£¬ÓëåÚÏëThinkpadÆóÒµÉ豸ÓйصĹ̼þ¾µÏñʹÓÃÁËÈý¸ö·ÖÆç°æ±¾µÄOpenSSL£º0.9.8zb¡¢1.0.0aºÍ1.0.2j£¬×îºóÒ»¸ö°æ±¾ÓÚ2018Äê°ä²¼¡£»ã±¨Ö¸³ö£¬µ±Éæ¼°µ½±àÒë´úÂëʱ£¬»ð¼±±ØÒªÒ»¸ö¶î±íµÄSBOMÑéÖ¤²ã£¬ÒÔ±ãÔÚ¶þ½øÔì²ãÃæÉÏÑéÖ¤Ó빩¸øÉÌÌṩµÄÏÖʵSBOMÏàÆ¥ÅäµÄµÚÈý·½ÒÀÀµÐÅÏ¢Áбí£¬trust-but-verif²½ÖèÊÇ´¦ÖÃSBOM¹ÊÕϺÍÏ÷¼õ¹©¸øÁ´·çÏÕµÄ×î¼Ñ·½Ê½¡£

https://thehackernews.com/2022/11/dell-hp-and-lenovo-devices-found-using.html

6¡¢Dragos³ÆºÚ¿ÍÍÅ»ïÊÔͼ¹¥»÷ºÉÀ¼Òº»¯ÌìÈ»ÆøÕ¾µÄϵͳ

11ÔÂ27ÈÕ±¨Â·£¬ºÚ¿ÍÍÅ»ïXenotimeºÍKamaciteÒ»ÏòÔÚÊÔͼ¹¥»÷ºÉÀ¼Â¹Ìص¤GasunieÒº»¯ÌìÈ»ÆøÕ¾µÄϵͳ¡£FBIй©XenotimeºÍKamaciteÓë¶íÂÞ˹ÓйØÁª¡£ºÉÀ¼¹«Ë¾ElectricIQÒ²»ã±¨Ëµ£¬Õë¶ÔÅ·Ö޺ͺÉÀ¼³ÁÒª»ù´¡ÉèÊ©µÄ»î¶¯ÓÐËùÔö³¤¡£Fox-IT°µÊ¾£¬ÓÉÓÚÈ«ÇòÄÜԴΣ»ú£¬ºÚ¿ÍÍÅ»ïÒ»ÏòÔÚ¹¥»÷ÄÜÔ´ÐÐÒµµÄ×éÖ¯£¬³ö¸ñÊÇÒº»¯ÌìÈ»Æø¹©¸øºÍ·ÖÏúµÄ¹©¸øÁ´¡£

https://www.databreaches.net/russian-hackers-target-dutch-lng-terminal/