ºÚ¿ÍÇÔÈ¡Òâ´óÀûLeonardo SpAµÄ10GB¾üÊ»úÃÜ£»£»£»£»£»Ó¢¹úNCSC°ä²¼2020Äê¶È»ØÊ׵ķÖÎö»ã±¨
°ä²¼¹¦·ò 2020-12-071.ºÚ¿ÍÇÔÈ¡Òâ´óÀûLeonardo SpAµÄ10GB¾üÊ»úÃÜ

ºÚ¿ÍÇÔÈ¡¹ú·À¹«Ë¾Leonardo SpAµÄ10 GB¾üÊ»úÃÜ£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÒѱ»Òâ´óÀû¾¯·½¿ÛÁô¡£¡£¡£¡£¡£¡£¡£¡£LeonardoÊÇÊÀ½çÉÏ×î´óµÄ¹ú·À³Ð°üÉÌÖ®Ò»£¬£¬£¬£¬£¬£¬£¬£¬Æä30£¥µÄ¹É·ÝÊôÓÚÒâ´óÀû¾¼ÃºÍ²ÆÕþ²¿¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Îй¶µÄÐÅÏ¢Éæ¼°µ½ÐÐÕþ¹ÜÕÊÖÎÀí¡¢ÈËÁ¦×ÊÔ´¡¢±¾Ç®»õÎïµÄ²É¹ººÍ·ÖÅä¡¢ÃñÓ÷ɻúÁ㲿¼þºÍ¾üÓ÷ɻúµÄÉè¼Æ¡¢Ô±¹¤Ó×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃUSBÃÜÔ¿Ïò94¸ö¹¤×÷Õ¾·Ö·¢cftmon.exeľÂí£¬£¬£¬£¬£¬£¬£¬£¬²¢ÒÔÕý°æWindowsÎļþ¶¨Ãû¸ÃľÂíÒÔÈÆ¹ý¼ì²â¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/police-arrest-two-in-data-theft-cyberattack-on-leonardo-defense-corp/
2.ºÚ¿ÍÀûÓÃÍøÂç´¹µöÇÔÈ¡MetaMaskÓû§µÄ¼ÓÃÜÇ®±Ò

ºÚ¿ÍÀûÓÃGoogle¸æ°×ͨ¹ýÍøÂç´¹µö¹¥»÷ÇÔÈ¡MetaMaskÓû§µÄ¼ÓÃÜÇ®±ÒÇ®°üÎļþ¡£¡£¡£¡£¡£¡£¡£¡£MetaMaskÕ¼Óг¬¹ýÒ»°ÙÍòÓû§£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýä¯ÀÀÆ÷À©´ó·¨Ê½ÔÚä¯ÀÀÆ÷ÖÐÌṩÁËÒ»¸öÒÔÌ«·»¼ÓÃÜÇ®±ÒÇ®°ü£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ×°ÖøÃÀ©´óºó£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÈëÏÖÓеÄÇ®°ü£¬£¬£¬£¬£¬£¬£¬£¬Ò²¿É´´½¨ÐÂÇ®°ü¡£¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍÀûÓÃGoogle¸æ°×½«Óû§³Á¶¨Ïòµ½MetaMaskÍøÂç´¹µöÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬£¬µ±Óû§µã»÷µ¼ÈëÇ®°üÑ¡Ïîʱ£¬£¬£¬£¬£¬£¬£¬£¬»á±»ÒªÇóÊäÈëÏÖÓÐÇ®°üµÄ¹Ø¼ü×Ö£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩÐÅÏ¢»á±»·¢Ë͸ø¹¥»÷ÕßÓÃÀ´ÇÔÈ¡¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/metamask-phishing-steals-cryptocurrency-wallets-via-google-ads/
3.Ç¿Éú³ÆCOVID-19ÆÚ¼äÕë¶ÔÆäµÄ¹¥»÷´ÎÊýÔö³¤30£¥

Ç¿Éú³ÆCOVID-19ÆÚ¼äÕë¶ÔÆäµÄ¹¥»÷´ÎÊýÔö³¤ÁË30£¥¡£¡£¡£¡£¡£¡£¡£¡£¾Ý¡¶»ª¶û½ÖÈÕ±¨¡·±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬³¯ÏʺڿÍÒѾ½«ÃÀ¹ú¡¢Ó¢¹úºÍº«¹ú´ÓÊÂCovid-19Ò½Öι¤×÷µÄÖÁÉÙÁù¼ÒÔìÒ©¹«Ë¾ÁÐΪ¹¥»÷Ö¸±ê£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÍøÂçÄܹ»ÏúÊÛ»ò±øÆ÷»¯µÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹«Ë¾Ô̺¬Ç¿Éú¹«Ë¾ºÍÂíÀïÀ¼ÖݵÄNovavax¹«Ë¾£¬£¬£¬£¬£¬£¬£¬£¬Æä¶¼ÔÚ×êÑг¢ÊÔÐÔÒßÃç¡£¡£¡£¡£¡£¡£¡£¡£Ç¿Éú¹«Ë¾µÄCIO Marene Allison°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬¹ú¶ÈºÚ¿Íÿʱÿ¿Ì¶¼ÔÚ¹¥»÷Ò½ÁÆ×éÖ¯£¬£¬£¬£¬£¬£¬£¬£¬Õë¶ÔÇ¿Éú¹«Ë¾µÄÍøÂç¹¥»÷Ôö³¤ÁË30%¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/111960/hacking/covid-19-johnson-johnson-cyber-attacks.html
4.Apache°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´TomcatÖÐÑϳÁµÄ·ì϶

Apache°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËTomcatÖÐÑϳÁµÄ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶µ¼Ö»ؾø·þÎñÇé¿ö¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶±»×·×ÙΪCVE-2020-17527£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚApache TomcatÄܹ»½«HTTP/2ÏνÓÉÏÊÕµ½µÄÏÈǰÁ÷ÖеÄHTTPÒªÇó±êÍ·Öµ³ÁÐÂÓÃÓÚÓëºóÐøÁ÷ÓйØÁªµÄÒªÇóËùµ¼Öµġ£¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÕâºÜ¿ÉÄܻᵼÖÂÃýÎ󲢹عØHTTP/2Ïνӣ¬£¬£¬£¬£¬£¬£¬£¬µ«ÊÇÐÅÏ¢¿ÉÄÜ»áÔÚÒªÇóÖ®¼äй©¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎÊÌâÒÑÓÚTomcat 10.0.0-M10Öн¨¸´¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/12/04/apache-releases-security-advisory-apache-tomcat
5.Dashlane°ä²¼2020Äê¶ÈÃÜÂëй¶ÎÊÌâµÄ·ÖÎö»ã±¨

Dashlane°ä²¼2020Äê¶ÈÃÜÂëй¶ÎÊÌâµÄ·ÖÎö»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬³Áµã½éÉÜÁ˸ÃÄêÓëÃÜÂëÓйصÄ×îÑϳÁ±äÂҵĹ«Ë¾ºÍ×éÖ¯¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬£¬°ñµ¥ÉÏÅÅÃûµÚÒ»ºÍµÚ¶þµÄÊÇTwitterºÍZoom£¬£¬£¬£¬£¬£¬£¬£¬ËüÃÇÔÊÐíÆäÔ±¹¤ºÍÓû§Ê¹ÓÃÈõÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬Ê¹ÆäÒ×ÊÜÍøÂç¹¥»÷µÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£ÓÎÀÀ¡¢ÓÎÏ·ºÍ¿ìµÝÁìÓòµÄÆäËû³ÛÃûÆóÒµÒ²³ÉΪºÚ¿ÍµÄÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬DashlaneµÄÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬¾ùÔÈÿ¸ö»¥ÁªÍøÓû§Óг¬¹ý200¸ö±ØÒªÊ¹ÓÃÃÜÂëµÄÊý×ÖÕË»§£¬£¬£¬£¬£¬£¬£¬£¬ÕâÒ»Êý×ÖÔ¤¼ÆÔÚ½«À´ÎåÄêÄÚ½«·Ò»·¬£¬£¬£¬£¬£¬£¬£¬£¬´ïµ½400¸ö¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.dashlane.com/twitter-employees-and-zoom-users-top-dashlanes-list-of-2020s-worst-password-offenders/
6.Ó¢¹úNCSC°ä²¼2020Äê¶È»ØÊ׵ķÖÎö»ã±¨

Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©°ä²¼ÁË2020Äê¶È»ØÊ׻㱨£¬£¬£¬£¬£¬£¬£¬£¬¸Ã»ã±¨µÄ³ÁµãÊÇÓ¦¶Ô²»Ðݱ䶯µÄÌôÕ½ÐÔÍøÂçÍþв£¬£¬£¬£¬£¬£¬£¬£¬»ØÊ×ÁËNCSCµÄ2019Äê9ÔÂ1ÈÕµ½2020Äê8ÔÂ31ÈÕÖ®¼äµÄ¹¤×÷ÖØÒª½øÕ¹ºÍÁÁµã¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÕ⸴ÔÓÌôÕ½µÄÒ»Ä꣬£¬£¬£¬£¬£¬£¬£¬NCSC³ÖÐø¶ÔѸËÙÑݱäµÄÍøÂçÍþв×÷³ö·´Ó³¡£¡£¡£¡£¡£¡£¡£¡£²¢Ìá³öÁ˹ØÓÚNCSC¹¤×÷µÄÁ½¸ö³ÁÒªÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£µÚÒ»£¬£¬£¬£¬£¬£¬£¬£¬Ô¤·À·¸×ﳤ¶Ì·¸×ïÖÐÐĵÄÊ×Òª¹¤×÷£¬£¬£¬£¬£¬£¬£¬£¬ÆäÓë·¨Âɲ¿ÃÅçÇÃܺÏ×÷£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ723×Ú¹¥»÷ÊÂÎñÖÐÔöÔ®Á˽ü1200ÃûÊܺ¦Õߣ»£»£»£»£»µÚ¶þ£¬£¬£¬£¬£¬£¬£¬£¬ÍøÂç°²ÂúÊÇÒ»ÏîÍŶӻ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.ncsc.gov.uk/annual-review/2020/docs/ncsc_2020-annual-review_s.pdf


¾©¹«Íø°²±¸11010802024551ºÅ