MetaÒò2018ÄêÊý¾Ýй¶ÊÂÎñ±»°®¶ûÀ¼·£¿£¿ £¿î1860ÍòÃÀÔª

Ðû²¼Ê±¼ä 2022-03-18

MetaÒò2018ÄêÊý¾Ýй¶ÊÂÎñ±»°®¶ûÀ¼·£¿£¿ £¿î1860ÍòÃÀÔª


¾ÝýÌå3ÔÂ15ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬°®¶ûÀ¼Êý¾Ý±£»£»£»£»£»£»£»¤Î¯Ô±»á(DPC)ÔÚ±¾Öܶþ¶ÔMeta´¦ÒÔÔ¼1860ÍòÃÀÔªµÄ·£¿£¿ £¿î¡£¡£¡£¡£¡£ ¡£DPC³Æ£¬£¬£¬£¬£¬£¬£¬MetaδÄܽÓÄÉÊʵ±µÄÊÖÒպͲ½·¥£¬£¬£¬£¬£¬£¬£¬ÔÚ2018Äê6ÔÂ7ÈÕ12ÔÂ4ÈÕµÄ6¸öÔÂʱ´ú±¬·¢ÁË12´ÎÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬Î¥·´ÁËGDPR¡£¡£¡£¡£¡£ ¡£MetaÌåÏÖÕâÏî·£¿£¿ £¿îÉæ¼°µ½Æä×Ô2018ÄêÒÔÀ´¸üеļͼÉúÑÄ·½·¨£¬£¬£¬£¬£¬£¬£¬¶ø·ÇδÄܱ£»£»£»£»£»£»£»¤Óû§ÐÅÏ¢¡£¡£¡£¡£¡£ ¡£´Ëǰ£¬£¬£¬£¬£¬£¬£¬°®¶ûÀ¼î¿Ïµ»ú¹¹´ËÇ°ÔøÔÚ2021Äê9ÔÂÒòÎ¥·´Í¸Ã÷¶ÈÒåÎñ¶ÔWhatsApp´¦ÒÔÔ¼2.67ÒÚÃÀÔªµÄ·£¿£¿ £¿î¡£¡£¡£¡£¡£ ¡£


https://www.cyberscoop.com/facebook-meta-gdpr-ireland/


Ñо¿Ö°Ô±·¢Ã÷н©Ê¬ÍøÂçB1txor20ʹÓÃLog4JÎó²îµÄ¹¥»÷


ýÌå3ÔÂ15ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬×î½ü·¢Ã÷µÄÒ»¸öÈÔÔÚÆð¾¢¿ª·¢µÄ½©Ê¬ÍøÂçB1txor20ÕýÃé×¼Linuxϵͳ¡£¡£¡£¡£¡£ ¡£Ñо¿Ö°Ô±ÓÚ2ÔÂ9ÈÕÊ״η¢Ã÷B1txor20£¬£¬£¬£¬£¬£¬£¬ËüÖ÷ÒªÕë¶ÔLinux ARMºÍX64 CPU¼Ü¹¹×°±¸£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃLog4JÎó²îѬȾĿµÄ£¬£¬£¬£¬£¬£¬£¬¾ßÓкóÃÅ¡¢SOCKS5ÊðÀí¡¢¶ñÒâÈí¼þÏÂÔØ¡¢Êý¾ÝÇÔÈ¡¡¢í§ÒâÏÂÁîÖ´ÐкÍrootkit×°Öõȹ¦Ð§¡£¡£¡£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬B1txor20ʹÓÃDNSËíµÀÓëC2ЧÀÍÆ÷¾ÙÐÐͨѶ£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»ÖÖ¹ÅÀϵ«¿É¿¿µÄÊÖÒÕ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃDNSЭÒéͨ¹ýDNSÅÌÎÊת´ï¶ñÒâÈí¼þºÍÊý¾Ý¡£¡£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/new-linux-botnet-exploits-log4j-uses-dns-tunneling-for-comms/


ÃÀ¹úSDCAÔâµ½ÈëÇÖ£¬£¬£¬£¬£¬£¬£¬½ü30Íò¸öÐÄÔಡ»¼ÕßµÄÐÅϢ̻¶


ýÌå3ÔÂ15Èճƣ¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÄϵ¤·ðÐÄÔಡЭ»á(SDCA) Ôâµ½ÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Ô¼287652¸ö»¼ÕßµÄÐÅϢ̻¶¡£¡£¡£¡£¡£ ¡£SDCAÌåÏÖ£¬£¬£¬£¬£¬£¬£¬ËûÃÇÔÚ1ÔÂ4ÈÕÔÚÅÌËã»úϵͳÖз¢Ã÷ÁËÒì³£»£»£»£»£»£»£»î¶¯£¬£¬£¬£¬£¬£¬£¬Ö®ºóÁ¬Ã¦Æô¶¯ÁËÊÂÎñÏìÓ¦Á÷³Ì¡£¡£¡£¡£¡£ ¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨»¼ÕßÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éç»áÇå¾²ºÅÂë¡¢¼Ýʻ֤ºÅÂë¡¢»¼ÕßÕʺš¢¿µ½¡°ü¹ÜÐÅÏ¢ºÍÁÙ´²ÐÅÏ¢µÈ¡£¡£¡£¡£¡£ ¡£SDCAÒѽ«´Ë´Îй¶ÊÂÎñ֪ͨÊÜÓ°ÏìµÄÓû§£¬£¬£¬£¬£¬£¬£¬²¢½«ÎªÆäÌṩÃâ·ÑµÄÐÅÓÃ¼à¿ØºÍÉí·Ý±£»£»£»£»£»£»£»¤Ð§ÀÍ¡£¡£¡£¡£¡£ ¡£


https://www.infosecurity-magazine.com/news/heart-patients-data-exposed/


AppleÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´iOSºÍmacOSÖеĶà¸öÎó²î


AppleÔÚ3ÔÂ14ÈÕÐû²¼ÁËmacOS Monterey 12.3¡¢iOS 15.4ºÍiPadOS 15.4µÄÇå¾²¸üС£¡£¡£¡£¡£ ¡£´Ë´ÎÐÞ¸´µÄ½ÏΪÑÏÖØµÄÎó²îÊÇAccelerate FrameworµÄÄÚ´æËð»µÎó²î£¨CVE-2022-22633£©£¬£¬£¬£¬£¬£¬£¬¿ÉʹÓöñÒâµÄPDFÎļþµ¼ÖÂí§Òâ´úÂëÖ´ÐУ»£»£»£»£»£»£»AppleAVDÖеÄÄÚ´æËð»µÎó²î£¨CVE-2022-22666£©£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÄÚ´æ×ß©»òÕßÄÚ´æ¹ÊÕÏ£»£»£»£»£»£»£»ÒÔ¼°AVEVideoEncoderÖеĻº³åÇøÒç³öÎó²î£¨CVE-2022-22634£©ºÍÔ½½çдÈëÎó²î£¨CVE-2022-22635£©µÈÎó²î¡£¡£¡£¡£¡£ ¡£


https://blog.malwarebytes.com/exploits-and-vulnerabilities/2022/03/update-now-apple-fixes-several-serious-vulnerabilities-in-ios-macos-and-ipados/


Microsoft Defender½«Office¸üÐÂÎó±¨ÎªÀÕË÷Èí¼þ»î¶¯


´Ó3ÔÂ16ÈÕÔçÉÏ×îÏÈ£¬£¬£¬£¬£¬£¬£¬WindowsÖÎÀíÔ±Ôâµ½Ò»²¨Microsoft Defender for EndpointÎ󱨼ì²â¡£¡£¡£¡£¡£ ¡£¾¯±¨½«Office¸üбê¼ÇΪ¶ñÒ⣬£¬£¬£¬£¬£¬£¬³ÆÔÚϵͳÉϼì²âµ½ÓÐÀÕË÷Èí¼þ»î¶¯¡£¡£¡£¡£¡£ ¡£Microsoft³Æ£¬£¬£¬£¬£¬£¬£¬ÊӲ췢Ã÷Î󱨵Ļù´¡Ôµ¹ÊÔ­ÓÉÊÇ×î½üÔÚЧÀÍ×é¼þÖа²ÅÅÁËÓÃÓÚ¼ì²âÀÕË÷Èí¼þ¾¯±¨µÄ¸üУ¬£¬£¬£¬£¬£¬£¬Õâµ¼ÖÂÁËÒ»¸ö´úÂëÎÊÌ⣬£¬£¬£¬£¬£¬£¬Ê¹ÆäÔÚϵͳÉϲ»±£´æÀÕË÷Èí¼þ»î¶¯µÄÇéÐÎÏ´¥·¢¾¯±¨¡£¡£¡£¡£¡£ ¡£¸Ã¹«Ë¾ÏÖÔÚÒÑÐÞ¸´ÎÊÌ⣬£¬£¬£¬£¬£¬£¬²¢È·±£²»»á·¢ËÍеľ¯±¨¡£¡£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/microsoft-defender-tags-office-updates-as-ransomware-activity/


Intel 471Ðû²¼2021ÄêQ4ÀÕË÷Èí¼þ±äÖֵįÊÎö±¨¸æ


ýÌå3ÔÂ15ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬Intel 471ÔÚ½üÆÚÐû²¼ÁË2021ÄêQ4ÀÕË÷Èí¼þ±äÖֵįÊÎö±¨¸æ¡£¡£¡£¡£¡£ ¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬ÔÚµÚËÄÐò¶È¼ì²âµ½Á˶à´ï722ÆðÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÁË34ÖÖ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬ÆäÖÐLockBit 2.0£¨Õ¼±È29.7%£©¡¢Conti£¨19%£©¡¢PYSA£¨10.5%£©ºÍHive£¨10.1%£©×î³£¼û¡£¡£¡£¡£¡£ ¡£Êܵ½¹¥»÷µÄ×î¶àµØÇøÊDZ±ÃÀ£¬£¬£¬£¬£¬£¬£¬Õ¼±ÈÁè¼Ý50%£¬£¬£¬£¬£¬£¬£¬½ôËæØÊºóµÄÊÇÅ·ÖÞ£¬£¬£¬£¬£¬£¬£¬Ô¼Îª30%¡£¡£¡£¡£¡£ ¡£ÊÜÓ°Ïì×î´óµÄÐÐÒµÊÇÏûºÄÆ·ºÍ¹¤Òµ²úÆ·£¬£¬£¬£¬£¬£¬£¬Æä´ÎÎªÖÆÔìÒµ¡¢×¨ÒµÐ§Àͺͷ¿µØ²ú¡£¡£¡£¡£¡£ ¡£


https://thehackernews.com/2022/03/nearly-34-ransomware-variants-observed.html



Çå¾²¹¤¾ß


Patching


IDA Pro µÄ½»»¥Ê½¶þ½øÖƲ¹¶¡²å¼þ¡£¡£¡£¡£¡£ ¡£


https://github.com/gaasedelen/patching


Codecat


ÊÇÒ»¸ö¿ªÔ´¹¤¾ß£¬£¬£¬£¬£¬£¬£¬¿É×ÊÖúʹÓþ²Ì¬´úÂëÆÊÎöÀ´²éÕÒ/¸ú×ÙÓû§ÊäÈëÎüÊÕÆ÷ºÍÇå¾²Îó²î¡£¡£¡£¡£¡£ ¡£


https://github.com/CoolerVoid/codecat


poro


ɨÃè AWS ÇéÐÎÖпɹûÕæ»á¼ûµÄ×ʲú¡£¡£¡£¡£¡£ ¡£


https://github.com/9rnt/poro


GOAD (Game Of Active Directory)


GOAD ÊÇÒ»¸öÉøÍ¸²âÊÔµÄActive DirectoryʵÑéÊÒÏîÄ¿¡£¡£¡£¡£¡£ ¡£


https://github.com/Orange-Cyberdefense/GOAD



Çå¾²ÆÊÎö


¶íÂÞË¹ÃæÁÙ IT Σ»£»£»£»£»£»£»ú£¬£¬£¬£¬£¬£¬£¬Êý¾Ý´æ´¢¿Õ¼ä½ö¹»Á½¸öÔÂ


https://www.bleepingcomputer.com/news/technology/russia-faces-it-crisis-with-just-two-months-of-data-storage-left/


Anonymous¹¥»÷¶íÂÞ˹Áª°îÇå¾²¾Ö (FSB)


https://www.hackread.com/ddos-attacks-anonymous-cripple-russia-fsb-websites/


ÑÏÖØÎó²îÓ°Ïì Veeam Data Backup Èí¼þ


https://securityaffairs.co/wordpress/129094/hacking/veeam-rce.html


µÂ¹úÕþ¸®½¨Ò鲻ҪʹÓÿ¨°Í˹»ùɱ¶¾Èí¼þ


https://www.bleepingcomputer.com/news/security/german-government-advises-against-using-kaspersky-antivirus/


Android ľÂí×Ô 1 ÔÂÆðÔÚ Google Play ÊÐËÁÖÐÒ»Á¬±£´æ


https://www.bleepingcomputer.com/news/security/android-trojan-persists-on-the-google-play-store-since-january/


FBI ÖÒÑÔ¹ú¼ÒºÚ¿ÍʹÓà MFA Îó²î¾ÙÐкáÏòÒÆ¶¯


https://www.bleepingcomputer.com/news/security/fbi-warns-of-mfa-flaw-used-by-state-hackers-for-lateral-movement/