·¨¹úµçÁ¦¹©¸øÉÌÒòʹÓÃÈõMD5Ëã·¨´æ´¢Óû§ÃÜÂë±»·£¿î

°ä²¼¹¦·ò 2022-12-02
1¡¢·¨¹úµçÁ¦¹©¸øÉÌÒòʹÓÃÈõMD5Ëã·¨´æ´¢Óû§ÃÜÂë±»·£¿î

¾ÝýÌå11ÔÂ30ÈÕ±¨Â·£¬µçÁ¦¹©¸øÉÌ·¨¹úµçÁ¦¹«Ë¾(EDF)ÒòÎ¥·´Å·ÃËͨÓÃÊý¾Ý±£»¤ÌõÀý(GDPR)£¬±»·¨¹úÊý¾Ý±£»¤¼à¹Ü»ú¹¹·£¿î60ÍòÅ·Ôª¡£¹ú¶ÈÐÅÏ¢ºÍ×ÔÓÉίԱ»á(CNIL)°µÊ¾£¬¸Ã¹«Ë¾ÔÚ2022Äê7ÔÂʹÓÃMD5Ëã·¨¶Ô25800¶à¸öÕÊ»§½øÐÐhash´¦ÖÃÀ´´æ´¢ÃÜÂë¡£´Ë±í£¬Óë2414254¸öÕË»§ÓйصÄÃÜÂë½ö¾­¹ýhash´¦ÖöøÎ´¼ÓÑΣ¬Ê¹ÕË»§³ÖÓÐÈËÃæ¶ÔDZÔÚµÄÍøÂçÍþв¡£¸Ãµ÷²é»¹Ôð¹ÖEDFδÄÜ×ñÊØGDPRÊý¾Ý±£ÁôÕþ²ß£¬²¢ÌṩÁ˹ØÓÚËùÍøÂçÊý¾ÝÆðÔ´µÄ²»ÕýÈ·ÐÅÏ¢¡£

https://thehackernews.com/2022/11/french-electricity-provider-fined-for.html

2¡¢ÏÖ´úÆû³µÒƶ¯ÀûÓÃÖдæÔÚ¿ÉÔ¶³Ì½âËøºÍÆô¶¯³µÁ¾µÄ·ì϶

¾Ý12ÔÂ1ÈÕ±¨Â·£¬ÏÖ´úºÍGenesisµÄÒÆ¶¯ÀûÓÃMyHyundaiºÍMyGenesis¿É±»ÓÃÀ´Ô¶³Ì½âËøºÍÆô¶¯³µÁ¾¡£ÔÚÀ¹½ØÁËÕâÁ½¸öÀûÓòúÉúµÄÁ÷Á¿ºó£¬×êÑÐÈËÔ±¶ÔÆä½øÐÐÁË·ÖÎö£¬·¢ÏÖÑéÖ¤ÊÇÆ¾¾ÝÓû§µÄµç×ÓÓʼþµØÖ·ÊµÏֵģ¬¸ÃµØÖ·Ô̺¬ÔÚPOSTÒªÇóµÄJSONÕýÎÄÖС£×êÑÐÈËÔ±ÏòÏÖ´úÖÕ¶Ë·¢ËÍÁËαÔìµÄHTTPÒªÇóÈÆ¹ýÁËÓÐЧÐԲ鳭£¬²¢Äܹ»½âËø³µÁ¾¡£×êÑÐÈËÔ±»¹·¢ÏÖ£¬Ê¹ÓÃSiriusXMÖÇÄÜÆû³µÆ½Ì¨µÄ³µÁ¾Ò²´æÔÚÀàËÆÎÊÌâ£¬Éæ¼°±¦Âí¡¢±¾Ìï¡¢Ó¢·ÆÄáµÏ¡¢½Ý±ª¡¢Â·»¢¡¢À׿ËÈøË¹¡¢ÈÕ²ú¡¢Ë¹°Í³ºÍ·áÌïµÈ¡£

https://www.bleepingcomputer.com/news/security/hyundai-app-bugs-allowed-hackers-to-remotely-unlock-start-cars/

3¡¢¸çÂ×±ÈÑÇÒ½ÁÆ»ú¹¹KeraltyÔâµ½RansomHouseµÄÀÕË÷¹¥»÷

ýÌå11ÔÂ30Èճƣ¬¸çÂ×±ÈÑǵÄÒ»¼ÒÒ½ÁƱ£½¡ÌṩÉÌKeraltyÔâµ½RansomHouseµÄÀÕË÷¹¥»÷¡£¹¥»÷²úÉúÔÚÉÏÖÜÈÕ£¬Keralty¼°Æä×Ó¹«Ë¾EPS SanitasºÍColsanitasµÄITÔËÓª¡¢Ò½ÁÆÔ¤Ô¼ÆÌÅż°ÍøÕ¾¶¼Êܵ½ÁËÓ°Ïì¡£±¾ÖÜÒ»£¬Keralty°µÊ¾ËûÃÇÓöµ½Á˼¼ÊõÎÊÌ⵫ûÓÐй©ԭÒò¡£¸Ã¹«Ë¾ÓÖÔÚÖܶþ°ä·¢ÉêÃ÷£¬È·ÈÏÖжÏÊÇÓÉÍøÂç¹¥»÷Ôì³ÉµÄ¡£RansomHouse°µÊ¾¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬²¢³ÆÒÑÇÔÈ¡3 TBÊý¾Ý¡£

https://www.bleepingcomputer.com/news/security/keralty-ransomware-attack-impacts-colombias-health-care-system/

4¡¢Ë÷ÄáºÍLexarµÄ¼ÓÃÜÌṩÉÌENC SecurityµÄÒµÎñÊý¾Ýй¶

CyberNewsÔÚ11ÔÂ30ÈÕй©£¬ºÉÀ¼Èí¼þ¹«Ë¾ENC Security×Ô2021Äê5ÔÂÒÔÀ´Ò»ÏòÔÚй¶³ÁÒªµÄÒµÎñÊý¾Ý¡£¸Ã¹«Ë¾ÔÚÈ«ÇòÕ¼ÓÐ1200ÍòÓû§£¬Í¨¹ýÆäDataVault¼ÓÃÜÈí¼þÌṩ¡°¾üÓü¶Êý¾Ý±£»¤¡±½â¾ö¹æ»®¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÏúÊÛÇþ·µÄSMTPÍ´´¦¡¢µ¥Ò»Ö§¸¶Æ½Ì¨µÄAdyenÃÜÔ¿¡¢µç×ÓÓʼþÓªÏú¹«Ë¾µÄMailchimp APIÃÜÔ¿¡¢Ðí¿ÉÖ§¸¶APIÃÜÔ¿¡¢HMACÐÂÎÅÉí·ÝÑéÖ¤´úÂ룬ÒÔ¼°ÒÔ.pemÌåʽ´æ´¢µÄ¹«¹²ºÍ¸öÈËÃÜÔ¿¡£ÕâЩÐÅÏ¢´Ó2021Äê5ÔÂ27ÈÕµ½2022Äê11ÔÂ9ÈÕÄܹ»½Ó¼û¡£ENC Securityй©£¬¸Ã·ì϶ÓëµÚÈý·½¹©¸øÉ̵ÄÃýÎóÅäÖÃÓйØ£¬ÎÊÌâÏÖÒѽâ¾ö¡£

https://cybernews.com/security/encsecurity-leaked-sensitive-data/

5¡¢Ò½ÁÆÈí¼þ¹«Ë¾Connexin Software 220Íò»¼ÕßÐÅϢй¶

11ÔÂ30ÈÕ±¨Â·£¬Connexin Software½üÆÚ֪ͨHHSÆäÊý¾Ýй¶ÊÂÎñÓ°ÏìÁË2216365¸ö»¼Õß¡£¸Ã¹«Ë¾ÊÇÒ»¼ÒΪ¶ù¿ÆÒ½ÁÆÍŶÓÌṩµç×Ó²¡ÀúºÍÖ´ÒµÖÎÀíÈí¼þ¡¢¼Æ·Ñ·þÎñºÍÒµÎñ·ÖÎö¹¤¾ßµÄ¹©¸øÉÌ¡£8ÔÂ26ÈÕ£¬ConnexinÔÚÄÚÍø¼ì²âµ½Êý¾ÝÒì³££¬Ö®ºóµ±¼´·¢Õ¹µ÷²é¡£9ÔÂ13ÈÕ£¬È·ÈÏδ¾­ÊÚȨµÄµÚÈý·½¿ÉÄܽӼûÓÃÓÚÊý¾Ýת»»ºÍ¹ÊÕÏÅųýµÄÒ»×éÀëÏß²¡ÈËÊý¾Ý¡£Ä¿Ç°£¬Connexin³ÁÖÃÁËËùÓй«Ë¾ÕÊ»§µÄÃÜÂ룬½«»¼ÕßÊý¾ÝÒÆÖÁ¸ü°²È«µÄ»·¾³ÖУ¬²¢Í¨¹ýKrollΪÊÜÓ°Ï컼ÕßÌṩһÄêµÄÉí·Ý¼à¿Ø·þÎñ¡£

https://www.databreaches.net/connexin-software-notifies-parents-of-2-2-million-pediatric-patients-of-hack/

6¡¢ESET°ä²¼¹ØÓÚScarCruftкóÃÅDolphinµÄ·ÖÎö»ã±¨

11ÔÂ30ÈÕ£¬ESET°ä²¼Á˹ØÓÚAPTÍÅ»ïScarCruftµÄкóÃÅDolphinµÄ·ÖÎö»ã±¨¡£×Ô2021Äê4Ô³õ´Î·¢ÏÖDolphinÒÔÀ´£¬×êÑÐÈËÔ±ÒѾ­¹Û²ìµ½¶à¸ö°æ±¾µÄºóÃÅ¡£DolphinÊÇÒ»¸öC++¿ÉÖ´ÐÐÎļþ£¬Ê¹ÓÃGoogle Drive×÷ΪÃüC2·þÎñÆ÷²¢´æ´¢±»µÁÎļþ¡£ËüµÄËÑË÷Ö°ÄÜͨ¹ýʹÓÃWindows±ãЯÉ豸APIÀ©´óµ½ÈκÎÏνӵ½±»¹¥»÷Ö÷»úµÄÊÖ»ú£¬Ëü»¹Äܹ»Í¨¹ý¸ü¸ÄÓйØÉèÖÃÀ´½µµÍÖ¸±êGoogleÕÊ»§µÄ°²È«ÐÔ¡£

https://www.welivesecurity.com/2022/11/30/whos-swimming-south-korean-waters-meet-scarcrufts-dolphin/