ºÚ¿ÍÇÔÈ¡Òâ´óÀûLeonardo SpAµÄ10GB¾üÊ»úÃÜ£»£»£»£» £»Ó¢¹úNCSC°ä²¼2020Äê¶È»ØÊ׵ķÖÎö»ã±¨

°ä²¼¹¦·ò 2020-12-07

1.ºÚ¿ÍÇÔÈ¡Òâ´óÀûLeonardo SpAµÄ10GB¾üÊ»úÃÜ


1.jpg


ºÚ¿ÍÇÔÈ¡¹ú·À¹«Ë¾Leonardo SpAµÄ10 GB¾üÊ»úÃÜ£¬ £¬£¬£¬£¬£¬£¬£¬ÏÖÒѱ»Òâ´óÀû¾¯·½¿ÛÁô¡£¡£¡£¡£¡£¡£ ¡£¡£LeonardoÊÇÊÀ½çÉÏ×î´óµÄ¹ú·À³Ð°üÉÌÖ®Ò»£¬ £¬£¬£¬£¬£¬£¬£¬Æä30£¥µÄ¹É·ÝÊôÓÚÒâ´óÀû¾­¼ÃºÍ²ÆÕþ²¿¡£¡£¡£¡£¡£¡£ ¡£¡£Õâ´Îй¶µÄÐÅÏ¢Éæ¼°µ½ÐÐÕþ¹ÜÕÊÖÎÀí¡¢ÈËÁ¦×ÊÔ´¡¢±¾Ç®»õÎïµÄ²É¹ººÍ·ÖÅä¡¢ÃñÓ÷ɻúÁ㲿¼þºÍ¾üÓ÷ɻúµÄÉè¼Æ¡¢Ô±¹¤Ó×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£¡£¾ÝϤ£¬ £¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃUSBÃÜÔ¿Ïò94¸ö¹¤×÷Õ¾·Ö·¢cftmon.exeľÂí£¬ £¬£¬£¬£¬£¬£¬£¬²¢ÒÔÕý°æWindowsÎļþ¶¨Ãû¸ÃľÂíÒÔÈÆ¹ý¼ì²â¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/police-arrest-two-in-data-theft-cyberattack-on-leonardo-defense-corp/


2.ºÚ¿ÍÀûÓÃÍøÂç´¹µöÇÔÈ¡MetaMaskÓû§µÄ¼ÓÃÜÇ®±Ò


2.jpg


ºÚ¿ÍÀûÓÃGoogle¸æ°×ͨ¹ýÍøÂç´¹µö¹¥»÷ÇÔÈ¡MetaMaskÓû§µÄ¼ÓÃÜÇ®±ÒÇ®°üÎļþ¡£¡£¡£¡£¡£¡£ ¡£¡£MetaMaskÕ¼Óг¬¹ýÒ»°ÙÍòÓû§£¬ £¬£¬£¬£¬£¬£¬£¬Í¨¹ýä¯ÀÀÆ÷À©´ó·¨Ê½ÔÚä¯ÀÀÆ÷ÖÐÌṩÁËÒ»¸öÒÔÌ«·»¼ÓÃÜÇ®±ÒÇ®°ü£¬ £¬£¬£¬£¬£¬£¬£¬ÔÚ×°ÖøÃÀ©´óºó£¬ £¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÈëÏÖÓеÄÇ®°ü£¬ £¬£¬£¬£¬£¬£¬£¬Ò²¿É´´½¨ÐÂÇ®°ü¡£¡£¡£¡£¡£¡£ ¡£¡£ºÚ¿ÍÀûÓÃGoogle¸æ°×½«Óû§³Á¶¨Ïòµ½MetaMaskÍøÂç´¹µöÒ³Ãæ£¬ £¬£¬£¬£¬£¬£¬£¬µ±Óû§µã»÷µ¼ÈëÇ®°üÑ¡Ïîʱ£¬ £¬£¬£¬£¬£¬£¬£¬»á±»ÒªÇóÊäÈëÏÖÓÐÇ®°üµÄ¹Ø¼ü×Ö£¬ £¬£¬£¬£¬£¬£¬£¬ÕâЩÐÅÏ¢»á±»·¢Ë͸ø¹¥»÷ÕßÓÃÀ´ÇÔÈ¡¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/metamask-phishing-steals-cryptocurrency-wallets-via-google-ads/


3.Ç¿Éú³ÆCOVID-19ÆÚ¼äÕë¶ÔÆäµÄ¹¥»÷´ÎÊýÔö³¤30£¥


3.jpg


Ç¿Éú³ÆCOVID-19ÆÚ¼äÕë¶ÔÆäµÄ¹¥»÷´ÎÊýÔö³¤ÁË30£¥¡£¡£¡£¡£¡£¡£ ¡£¡£¾Ý¡¶»ª¶û½ÖÈÕ±¨¡·±¨Â·£¬ £¬£¬£¬£¬£¬£¬£¬³¯ÏʺڿÍÒѾ­½«ÃÀ¹ú¡¢Ó¢¹úºÍº«¹ú´ÓÊÂCovid-19Ò½Öι¤×÷µÄÖÁÉÙÁù¼ÒÔìÒ©¹«Ë¾ÁÐΪ¹¥»÷Ö¸±ê£¬ £¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÍøÂçÄܹ»ÏúÊÛ»ò±øÆ÷»¯µÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£¡£ÕâЩ¹«Ë¾Ô̺¬Ç¿Éú¹«Ë¾ºÍÂíÀïÀ¼ÖݵÄNovavax¹«Ë¾£¬ £¬£¬£¬£¬£¬£¬£¬Æä¶¼ÔÚ×êÑг¢ÊÔÐÔÒßÃç¡£¡£¡£¡£¡£¡£ ¡£¡£Ç¿Éú¹«Ë¾µÄCIO Marene Allison°µÊ¾£¬ £¬£¬£¬£¬£¬£¬£¬¹ú¶ÈºÚ¿Íÿʱÿ¿Ì¶¼ÔÚ¹¥»÷Ò½ÁÆ×éÖ¯£¬ £¬£¬£¬£¬£¬£¬£¬Õë¶ÔÇ¿Éú¹«Ë¾µÄÍøÂç¹¥»÷Ôö³¤ÁË30%¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/111960/hacking/covid-19-johnson-johnson-cyber-attacks.html


4.Apache°ä²¼°²È«¸üУ¬ £¬£¬£¬£¬£¬£¬£¬½¨¸´TomcatÖÐÑϳÁµÄ·ì϶


4.jpg


Apache°ä²¼°²È«¸üУ¬ £¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËTomcatÖÐÑϳÁµÄ·ì϶£¬ £¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶µ¼Ö»ؾø·þÎñÇé¿ö¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ã·ì϶±»×·×ÙΪCVE-2020-17527£¬ £¬£¬£¬£¬£¬£¬£¬ÓÉÓÚApache TomcatÄܹ»½«HTTP/2ÏνÓÉÏÊÕµ½µÄÏÈǰÁ÷ÖеÄHTTPÒªÇó±êÍ·Öµ³ÁÐÂÓÃÓÚÓëºóÐøÁ÷ÓйØÁªµÄÒªÇóËùµ¼ÖµÄ¡£¡£¡£¡£¡£¡£ ¡£¡£Ö»¹ÜÕâºÜ¿ÉÄܻᵼÖÂÃýÎ󲢹عØHTTP/2ÏνÓ£¬ £¬£¬£¬£¬£¬£¬£¬µ«ÊÇÐÅÏ¢¿ÉÄÜ»áÔÚÒªÇóÖ®¼äй©¡£¡£¡£¡£¡£¡£ ¡£¡£¸ÃÎÊÌâÒÑÓÚTomcat 10.0.0-M10Öн¨¸´¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/12/04/apache-releases-security-advisory-apache-tomcat


5.Dashlane°ä²¼2020Äê¶ÈÃÜÂëй¶ÎÊÌâµÄ·ÖÎö»ã±¨


5.jpg


Dashlane°ä²¼2020Äê¶ÈÃÜÂëй¶ÎÊÌâµÄ·ÖÎö»ã±¨£¬ £¬£¬£¬£¬£¬£¬£¬³Áµã½éÉÜÁ˸ÃÄêÓëÃÜÂëÓйصÄ×îÑϳÁ±äÂҵĹ«Ë¾ºÍ×éÖ¯¡£¡£¡£¡£¡£¡£ ¡£¡£ÆäÖУ¬ £¬£¬£¬£¬£¬£¬£¬°ñµ¥ÉÏÅÅÃûµÚÒ»ºÍµÚ¶þµÄÊÇTwitterºÍZoom£¬ £¬£¬£¬£¬£¬£¬£¬ËüÃÇÔÊÐíÆäÔ±¹¤ºÍÓû§Ê¹ÓÃÈõÃÜÂ룬 £¬£¬£¬£¬£¬£¬£¬Ê¹ÆäÒ×ÊÜÍøÂç¹¥»÷µÄÓ°Ïì¡£¡£¡£¡£¡£¡£ ¡£¡£ÓÎÀÀ¡¢ÓÎÏ·ºÍ¿ìµÝÁìÓòµÄÆäËû³ÛÃûÆóÒµÒ²³ÉΪºÚ¿ÍµÄÊܺ¦Õß¡£¡£¡£¡£¡£¡£ ¡£¡£´Ë±í£¬ £¬£¬£¬£¬£¬£¬£¬DashlaneµÄÊý¾ÝÏÔʾ£¬ £¬£¬£¬£¬£¬£¬£¬¾ùÔÈÿ¸ö»¥ÁªÍøÓû§Óг¬¹ý200¸ö±ØÒªÊ¹ÓÃÃÜÂëµÄÊý×ÖÕË»§£¬ £¬£¬£¬£¬£¬£¬£¬ÕâÒ»Êý×ÖÔ¤¼ÆÔÚ½«À´ÎåÄêÄÚ½«·­Ò»·¬£¬ £¬£¬£¬£¬£¬£¬£¬´ïµ½400¸ö¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.dashlane.com/twitter-employees-and-zoom-users-top-dashlanes-list-of-2020s-worst-password-offenders/


6.Ó¢¹úNCSC°ä²¼2020Äê¶È»ØÊ׵ķÖÎö»ã±¨


6.jpg


Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©°ä²¼ÁË2020Äê¶È»ØÊ׻㱨£¬ £¬£¬£¬£¬£¬£¬£¬¸Ã»ã±¨µÄ³ÁµãÊÇÓ¦¶Ô²»Ðݱ䶯µÄÌôÕ½ÐÔÍøÂçÍþв£¬ £¬£¬£¬£¬£¬£¬£¬»ØÊ×ÁËNCSCµÄ2019Äê9ÔÂ1ÈÕµ½2020Äê8ÔÂ31ÈÕÖ®¼äµÄ¹¤×÷ÖØÒª½øÕ¹ºÍÁÁµã¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ã»ã±¨Ö¸³ö£¬ £¬£¬£¬£¬£¬£¬£¬ÔÚÕ⸴ÔÓÌôÕ½µÄÒ»Ä꣬ £¬£¬£¬£¬£¬£¬£¬NCSC³ÖÐø¶ÔѸËÙÑݱäµÄÍøÂçÍþв×÷³ö·´Ó³¡£¡£¡£¡£¡£¡£ ¡£¡£²¢Ìá³öÁ˹ØÓÚNCSC¹¤×÷µÄÁ½¸ö³ÁÒªÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£¡£µÚÒ»£¬ £¬£¬£¬£¬£¬£¬£¬Ô¤·À·¸×ﳤ¶Ì·¸×ïÖÐÐĵÄÊ×Òª¹¤×÷£¬ £¬£¬£¬£¬£¬£¬£¬ÆäÓë·¨Âɲ¿ÃÅçÇÃܺÏ×÷£¬ £¬£¬£¬£¬£¬£¬£¬²¢ÔÚ723×Ú¹¥»÷ÊÂÎñÖÐÔöÔ®Á˽ü1200ÃûÊܺ¦Õߣ»£»£»£» £»µÚ¶þ£¬ £¬£¬£¬£¬£¬£¬£¬ÍøÂç°²ÂúÊÇÒ»ÏîÍŶӻ¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ncsc.gov.uk/annual-review/2020/docs/ncsc_2020-annual-review_s.pdf