MetaÒò2018ÄêÊý¾Ýй¶ÊÂÎñ±»°®¶ûÀ¼·£¿£¿£¿£¿ £¿£¿£¿î1860ÍòÃÀÔª

°ä²¼¹¦·ò 2022-03-18

MetaÒò2018ÄêÊý¾Ýй¶ÊÂÎñ±»°®¶ûÀ¼·£¿£¿£¿£¿ £¿£¿£¿î1860ÍòÃÀÔª


¾ÝýÌå3ÔÂ15ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬°®¶ûÀ¼Êý¾Ý±£»£»£»£»£»£»£»¤Î¯Ô±»á(DPC)ÔÚ±¾Öܶþ¶ÔMeta´¦ÒÔÔ¼1860ÍòÃÀÔªµÄ·£¿£¿£¿£¿ £¿£¿£¿î ¡£¡£¡£¡£¡£¡£DPC³Æ£¬£¬£¬£¬£¬ £¬MetaδÄܲÉÈ¡Êʵ±µÄ¼¼ÊõºÍ´ëÊ©£¬£¬£¬£¬£¬ £¬ÔÚ2018Äê6ÔÂ7ÈÕ12ÔÂ4ÈÕµÄ6¸öÔÂÆÚ¼ä²úÉúÁË12´ÎÊý¾Ýй¶£¬£¬£¬£¬£¬ £¬Î¥·´ÁËGDPR ¡£¡£¡£¡£¡£¡£Meta°µÊ¾ÕâÏî·£¿£¿£¿£¿ £¿£¿£¿îÉæ¼°µ½Æä×Ô2018ÄêÒÔÀ´¸üеļͼ±£Áô·½Ê½£¬£¬£¬£¬£¬ £¬¶ø·ÇδÄܱ£»£»£»£»£»£»£»¤Óû§ÐÅÏ¢ ¡£¡£¡£¡£¡£¡£´Ëǰ£¬£¬£¬£¬£¬ £¬°®¶ûÀ¼¼à¹Ü»ú¹¹´ËÇ°ÔøÔÚ2021Äê9ÔÂÒòÎ¥·´Í¨Ã÷¶ÈʹÃü¶ÔWhatsApp´¦ÒÔÔ¼2.67ÒÚÃÀÔªµÄ·£¿£¿£¿£¿ £¿£¿£¿î ¡£¡£¡£¡£¡£¡£


https://www.cyberscoop.com/facebook-meta-gdpr-ireland/


×êÑÐÈËÔ±·¢ÏÖн©Ê¬ÍøÂçB1txor20ÀûÓÃLog4J·ì϶µÄ¹¥»÷


ýÌå3ÔÂ15ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬×î½ü·¢ÏÖµÄÒ»¸öÈÔÔÚ»ý¼«¿ª·¢µÄ½©Ê¬ÍøÂçB1txor20Õý¶Ô×¼Linuxϵͳ ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÓÚ2ÔÂ9ÈÕ³õ´Î·¢ÏÖB1txor20£¬£¬£¬£¬£¬ £¬ËüÖØÒªÕë¶ÔLinux ARMºÍX64 CPU¼Ü¹¹É豸£¬£¬£¬£¬£¬ £¬ÀûÓÃLog4J·ì϶ϰȾָ±ê£¬£¬£¬£¬£¬ £¬ÓµÓкóÃÅ¡¢SOCKS5´úÀí¡¢¶ñÒâÈí¼þÏÂÔØ¡¢Êý¾ÝÇÔÈ¡¡¢ËÁÒâºÅÁîÖ´ÐкÍrootkit×°ÖõÈÖ°ÄÜ ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬B1txor20ʹÓÃDNSËí·ÓëC2·þÎñÆ÷½øÐÐͨѶ£¬£¬£¬£¬£¬ £¬ÕâÊÇÒ»ÖÖ¹ÅÀϵ«¿¿µÃסµÄ¼¼Êõ£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÀûÓÃDNSºÍ̸ͨ¹ýDNS²éÎÊ´«µÝ¶ñÒâÈí¼þºÍÊý¾Ý ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-linux-botnet-exploits-log4j-uses-dns-tunneling-for-comms/


ÃÀ¹úSDCAÔâµ½ÈëÇÖ£¬£¬£¬£¬£¬ £¬½ü30Íò¸öÐÄÔಡ»¼ÕßµÄÐÅϢ¶³ö


ýÌå3ÔÂ15Èճƣ¬£¬£¬£¬£¬ £¬ÃÀ¹úÄϵ¤·ðÐÄÔಡЭ»á(SDCA) Ôâµ½ÈëÇÖ£¬£¬£¬£¬£¬ £¬Ô¼287652¸ö»¼ÕßµÄÐÅϢ¶³ö ¡£¡£¡£¡£¡£¡£SDCA°µÊ¾£¬£¬£¬£¬£¬ £¬ËûÃÇÔÚ1ÔÂ4ÈÕÔÚÍÆËã»úϵͳÖз¢ÏÖÁËÒì³£»£»£»£»£»£»£»î¶¯£¬£¬£¬£¬£¬ £¬Ö®ºóÁ¢¼´Æô¶¯ÁËÊÂÎñÏìÓ¦Á÷³Ì ¡£¡£¡£¡£¡£¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬»¼ÕßÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢¼Ýʻ֤ºÅÂë¡¢»¼ÕßÕʺš¢½¡È«±£ÏÕÐÅÏ¢ºÍÁÙ´²ÐÅÏ¢µÈ ¡£¡£¡£¡£¡£¡£SDCAÒѽ«Õâ´Îй¶ÊÂÎñ֪ͨÊÜÓ°ÏìµÄÓû§£¬£¬£¬£¬£¬ £¬²¢½«ÎªÆäÌṩÃâ·ÑµÄÐÅÓþ¼à¿ØºÍÉí·Ý±£»£»£»£»£»£»£»¤·þÎñ ¡£¡£¡£¡£¡£¡£


https://www.infosecurity-magazine.com/news/heart-patients-data-exposed/


Apple°ä²¼°²È«¸üУ¬£¬£¬£¬£¬ £¬½¨¸´iOSºÍmacOSÖеĶà¸ö·ì϶


AppleÔÚ3ÔÂ14ÈÕ°ä²¼ÁËmacOS Monterey 12.3¡¢iOS 15.4ºÍiPadOS 15.4µÄ°²È«¸üР¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶ÊÇAccelerate FrameworµÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2022-22633£©£¬£¬£¬£¬£¬ £¬¿ÉÀûÓöñÒâµÄPDFÎļþµ¼ÖÂËÁÒâ´úÂëÖ´ÐУ»£»£»£»£»£»£»AppleAVDÖеÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2022-22666£©£¬£¬£¬£¬£¬ £¬¿ÉÄܵ¼ÖÂÄÚ´æÐ¹Â©»òÕßÄÚ´æ¹ÊÕÏ£»£»£»£»£»£»£»ÒÔ¼°AVEVideoEncoderÖеĻº³åÇøÒç¶Âí½Å£¨CVE-2022-22634£©ºÍÔ½½çдÈë·ì϶£¨CVE-2022-22635£©µÈ·ì϶ ¡£¡£¡£¡£¡£¡£


https://blog.malwarebytes.com/exploits-and-vulnerabilities/2022/03/update-now-apple-fixes-several-serious-vulnerabilities-in-ios-macos-and-ipados/


Microsoft Defender½«Office¸üÐÂÎó±¨ÎªÀÕË÷Èí¼þ»î¶¯


´Ó3ÔÂ16ÈÕÔçÉÏÆðÍ·£¬£¬£¬£¬£¬ £¬WindowsÖÎÀíÔ±Ôâµ½Ò»²¨Microsoft Defender for EndpointÎ󱨼ì²â ¡£¡£¡£¡£¡£¡£¾¯±¨½«Office¸üÐÂÏóÕ÷Ϊ¶ñÒ⣬£¬£¬£¬£¬ £¬³ÆÔÚϵͳÉϼì²âµ½ÓÐÀÕË÷Èí¼þ»î¶¯ ¡£¡£¡£¡£¡£¡£Microsoft³Æ£¬£¬£¬£¬£¬ £¬µ÷²é·¢ÏÖÎ󱨵ĵ××ÓÔ­ÒòÊÇ×î½üÔÚ·þÎñ×é¼þÖв¿ÊðÁËÓÃÓÚ¼ì²âÀÕË÷Èí¼þ¾¯±¨µÄ¸üУ¬£¬£¬£¬£¬ £¬Õâµ¼ÖÂÁËÒ»¸ö´úÂëÎÊÌ⣬£¬£¬£¬£¬ £¬Ê¹ÆäÔÚϵͳÉϲ»´æÔÚÀÕË÷Èí¼þ»î¶¯µÄÇé¿öÏ´¥·¢¾¯±¨ ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ä¿Ç°Òѽ¨¸´ÎÊÌ⣬£¬£¬£¬£¬ £¬²¢È·±£²»»á·¢ËÍеľ¯±¨ ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/microsoft-defender-tags-office-updates-as-ransomware-activity/


Intel 471°ä²¼2021ÄêQ4ÀÕË÷Èí¼þ±äÖֵķÖÎö»ã±¨


ýÌå3ÔÂ15ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬Intel 471ÔÚ½üÆÚ°ä²¼ÁË2021ÄêQ4ÀÕË÷Èí¼þ±äÖֵķÖÎö»ã±¨ ¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬ £¬ÔÚµÚËÄʱ¶È¼ì²âµ½Á˶à´ï722ÆðÀÕË÷¹¥»÷£¬£¬£¬£¬£¬ £¬Ê¹ÓÃÁË34ÖÖ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ £¬ÆäÖÐLockBit 2.0£¨Õ¼±È29.7%£©¡¢Conti£¨19%£©¡¢PYSA£¨10.5%£©ºÍHive£¨10.1%£©×î³£¼û ¡£¡£¡£¡£¡£¡£Êܵ½¹¥»÷µÄ×î¶àµØÓòÊDZ±ÃÀ£¬£¬£¬£¬£¬ £¬Õ¼±È³¬¹ý50%£¬£¬£¬£¬£¬ £¬½ôËæÆäºóµÄÊÇÅ·ÖÞ£¬£¬£¬£¬£¬ £¬Ô¼Îª30% ¡£¡£¡£¡£¡£¡£ÊÜÓ°Ïì×î´óµÄÐÐÒµÊÇÏû·ÑÆ·ºÍ¹¤Òµ²úÆ·£¬£¬£¬£¬£¬ £¬Æä´ÎΪÔì×÷Òµ¡¢×¨Òµ·þÎñºÍ·¿µØ²ú ¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/03/nearly-34-ransomware-variants-observed.html



°²È«¹¤¾ß


Patching


IDA Pro µÄ½»»¥Ê½¶þ½øÔì²¹¶¡²å¼þ ¡£¡£¡£¡£¡£¡£


https://github.com/gaasedelen/patching


Codecat


ÊÇÒ»¸ö¿ªÔ´¹¤¾ß£¬£¬£¬£¬£¬ £¬¿ÉÔ®ÊÖʹÓþ²Ì¬´úÂë·ÖÎöÀ´²éÕÒ/¸ú×ÙÓû§ÊäÈë½Ó¹ÜÆ÷ºÍ°²È«·ì϶ ¡£¡£¡£¡£¡£¡£


https://github.com/CoolerVoid/codecat


poro


ɨÃè AWS »·¾³Öпɹ«¿ª½Ó¼ûµÄ×ʲú ¡£¡£¡£¡£¡£¡£


https://github.com/9rnt/poro


GOAD (Game Of Active Directory)


GOAD ÊÇÒ»¸öÉøÈë²âÊÔµÄActive Directory³¢ÊÔÊÒÏîÄ¿ ¡£¡£¡£¡£¡£¡£


https://github.com/Orange-Cyberdefense/GOAD



°²È«·ÖÎö


¶íÂÞË¹Ãæ¶Ô IT Σ»£»£»£»£»£»£»ú£¬£¬£¬£¬£¬ £¬Êý¾Ý´æ´¢¿Õ¼ä½ö¹»Á½¸öÔÂ


https://www.bleepingcomputer.com/news/technology/russia-faces-it-crisis-with-just-two-months-of-data-storage-left/


Anonymous¹¥»÷¶íÂÞ˹Áª¹ú°²È«¾Ö (FSB)


https://www.hackread.com/ddos-attacks-anonymous-cripple-russia-fsb-websites/


ÑϳÁ·ì϶ӰÏì Veeam Data Backup Èí¼þ


https://securityaffairs.co/wordpress/129094/hacking/veeam-rce.html


µÂ¹úµ±¾Ö½¨Ò鲻ҪʹÓÿ¨°Í˹»ùɱ¶¾Èí¼þ


https://www.bleepingcomputer.com/news/security/german-government-advises-against-using-kaspersky-antivirus/


Android ľÂí×Ô 1 ÔÂÆðÔÚ Google Play É̵êÖгÖÐø´æÔÚ


https://www.bleepingcomputer.com/news/security/android-trojan-persists-on-the-google-play-store-since-january/


FBI ÖÒ¸æ¹ú¶ÈºÚ¿ÍʹÓà MFA ·ì϶½øÐкáÏòÒÆ¶¯


https://www.bleepingcomputer.com/news/security/fbi-warns-of-mfa-flaw-used-by-state-hackers-for-lateral-movement/