TwitterÍøÂçÓû§ÐÅÏ¢¶¨ÏòÍÆË͸æ°×±»·£¿£¿£¿£¿£¿ £¿£¿£¿î1.5ÒÚÃÀÔª

°ä²¼¹¦·ò 2022-05-26

1¡¢TwitterÍøÂçÓû§ÐÅÏ¢¶¨ÏòÍÆË͸æ°×±»·£¿£¿£¿£¿£¿ £¿£¿£¿î1.5ÒÚÃÀÔª


¾Ý5ÔÂ26ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úÁª¹úÒµÎñίԱ»áFTCÒѶÔTwitter·£¿£¿£¿£¿£¿ £¿£¿£¿î1.5ÒÚÃÀÔª£¬£¬£¬£¬£¬£¬£¬Ô­ÒòÊÇËüʹÓÃÍøÂçµÄ2FAÑéÖ¤µÄµç»°ºÅÂëºÍÓʼþµØÖ·À´ÍÆË͸æ°×¡£ ¡£¡£¡£¡£Æ¾¾Ý·¨Í¥Îļþ£¬£¬£¬£¬£¬£¬£¬´Ó2013ÄêÆðÍ·£¬£¬£¬£¬£¬£¬£¬TwitterÒªÇ󳬹ý1.4ÒÚÓû§ÌṩÕâЩÐÅÏ¢ÒÔ±£»£»£»£»£»£»¤ËûÃǵÄÕË»§£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐ֪ͨËûÃÇÕâЩÊý¾ÝÒ²½«ÓÃÓÚ¸æ°×ÉÌͶ·Å¸æ°×¡£ ¡£¡£¡£¡£FTCÖ÷ϯ³Æ£¬£¬£¬£¬£¬£¬£¬TwitterÒÔÓÃÓÚ°²È«Ö÷ÕÅΪ½è¿Ú´ÓÓû§ÄÇÀï»ñÈ¡Êý¾Ý£¬£¬£¬£¬£¬£¬£¬µ«×îÖÕ»¹Ê¹ÓÃÕâЩÊý¾ÝÀ´Õë¶ÔÓû§Í¶·Å¸æ°×£¬£¬£¬£¬£¬£¬£¬ÕâÖÖ×ö·¨Ó°ÏìÁË´óÁ¿Óû§µÄͬʱ»¹ÌáÉýÁËTwitterµÄÊÕÈë¡£ ¡£¡£¡£¡£TwitterÒÑÔÞ³ÉÖ§¸¶1.5ÒÚÃÀÔªµÄ·£¿£¿£¿£¿£¿ £¿£¿£¿î¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/technology/ftc-fines-twitter-150m-for-using-2fa-info-for-targeted-advertising/


2¡¢Ç÷Ïò¿Æ¼¼½¨¸´Òѱ»Moshen DragonÀûÓõÄDLL½Ù³Ö·ì϶


¾ÝýÌå5ÔÂ24ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬Ç÷Ïò¿Æ¼¼½¨¸´Æä°²È«²úÆ·ÖеÄDLL½Ù³Ö·ì϶¡£ ¡£¡£¡£¡£ÕýÈçSentinel LabsÔÚ5Ô³õÅû¶µÄÄÇÑù£¬£¬£¬£¬£¬£¬£¬Moshen DragonÔÚÕë¶ÔÖÐÑǵĵçÐÅÐÐÒµµÄ¹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬ÊÔͼ½Ù³Ö°²È«¹©¸øÉ̵ķ¨Ê½£¬£¬£¬£¬£¬£¬£¬Ô̺¬Symantec¡¢TrendMicro¡¢BitDefender¡¢McAfeeºÍKaspersky¡£ ¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃÁ˶à¸ö¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýDLL½Ù³ÖÀ´²à¼ÓÔØShadowPadºÍPlugX¡£ ¡£¡£¡£¡£Trend MicroÒÑÓÚ5ÔÂ19ÈÕͨ¹ýÆäActiveUpdate(AU)°ä²¼ÁËÒ»¸ö½¨¸´·¨Ê½£¬£¬£¬£¬£¬£¬£¬²¢½¨ÒéÓû§Á¢¼´½øÐиüС£ ¡£¡£¡£¡£


https://securityaffairs.co/wordpress/131635/hacking/trend-micro-flaw-moshen-dragon.html


3¡¢Ä³ÅäÖÃÃýÎóµÄES·þÎñÆ÷й¶Êý°ÙÍò´û¿îÉêÇëÈ˵ÄÐÅÏ¢


¾Ý5ÔÂ24ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬Ò»¸öÅäÖÃÃýÎóµÄElasticsearch·þÎñÆ÷й¶ÁË147 GBµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬¹²8.7Òڱʼͼ¡£ ¡£¡£¡£¡£¸Ã·þÎñÆ÷ÓÚ2021Äê12ÔÂ5ÈÕ±»¼ì²âµ½£¬£¬£¬£¬£¬£¬£¬ÖØÒªÔ̺¬ÎÚ¿ËÀ¼¡¢¹þÈø¿Ë˹̹ºÍ¶íÂÞ˹Ó×¶î´û¿îµÄÉêÇëÈ˵ÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÈçÐÕÃû¡¢×¡Ö·ºÍ»¤ÕÕºÅÂëµÈÓ×ÎÒÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Ð½Ë®¡¢´û¿îÏêÇéºÍINN£¨Ë°ºÅ£©µÈ²ÆÕþÐÅÏ¢¡£ ¡£¡£¡£¡£¾Ý¹À¼Æ£¬£¬£¬£¬£¬£¬£¬Ô¼ÓÐ1000ÍòÓû§Êܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬ÆäÖдó²¿ÃÅ·þÎñÆ÷ÈÕÖ¾ºÍ»¤ÕÕºÅÂëÊôÓÚ¶íÂÞ˹£¬£¬£¬£¬£¬£¬£¬´óÎÞÊýINNÊôÓÚÎÚ¿ËÀ¼£¬£¬£¬£¬£¬£¬£¬¶ø¸Ã·þÎñÆ÷λÓÚºÉÀ¼µÄ°¢Ä·Ë¹Ìص¤¡£ ¡£¡£¡£¡£


https://www.hackread.com/personal-data-russians-ukrainians-exposed-online/


4¡¢Mozilla°ä²¼¸üн¨¸´Pwn2Own´ó»áÖб»ÀûÓõĶà¸ö·ì϶


5ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬Mozilla°ä²¼ÁËFirefoxºÍThunderbirdµÄ°²È«¸üУ¬£¬£¬£¬£¬£¬£¬ÒÔ½¨¸´ÔÚPwn2Own 2022´ó»áÆÚ¼ä±»ÀûÓõķì϶¡£ ¡£¡£¡£¡£µÚÒ»¸ö·ì϶ÊÇTop-Level AwaitʵÏÖÖеÄÔ­ÐÍÁ´´«È¾£¨prototype pollution£©·ì϶£¬£¬£¬£¬£¬£¬£¬×·×ÙΪCVE-2022-1802£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓÃËüÀ´Ö´ÐÐJavaScript´úÂë¡£ ¡£¡£¡£¡£µÚ¶þ¸ö·ì϶( CVE-2022-1529 ) ÊÇJavaScript¶ÔÏóË÷ÒýÖÐʹÓò»ÊÜÐŵÄÊäÈëµ¼ÖµÄÔ­ÐÍÁ´´«È¾·ì϶£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´ÔÚÌØÈ¨¸¸¹ý³ÌÖÐÖ´ÐÐJavaScript¡£ ¡£¡£¡£¡£CISAÔÚ5ÔÂ23ÈÕ°ä²¼°²È«¹«¸æ£¬£¬£¬£¬£¬£¬£¬½¨ÒéÁ¢¿Ì½¨¸´ÕâЩ·ì϶¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/mozilla-fixes-firefox-thunderbird-zero-days-exploited-at-pwn2own/


5¡¢ChromeÀ©´óScreencastify½¨¸´¿É½Ù³ÖÉãÏñÍ·µÄXSS·ì϶


ýÌå5ÔÂ24Èճƣ¬£¬£¬£¬£¬£¬£¬Ê¢ÐеÄChromeÀ©´óScreencastify½¨¸´ÁËÒ»¸öXSS·ì϶¡£ ¡£¡£¡£¡£ÕâÊÇÒ»¸öÓÃÓÚ¼ÆÁ¡¢ÊÓÆµ±à×ëºÍýÌå¹²ÏíµÄä¯ÀÀÆ÷À©´ó£¬£¬£¬£¬£¬£¬£¬ÔÚChromeÖеÄ×°ÖÃÁ¿³¬¹ý10000000´Î¡£ ¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶ÆôÓÃScreencastify¼ÔìÊÓÆµ£¬£¬£¬£¬£¬£¬£¬²¢½«ÆäÉÏ´«µ½Google Drive¡£ ¡£¡£¡£¡£»£»£»£»£»£»¹Äܹ»ÀûÓÃͬÑùµÄ·ì϶À´ÇÔÈ¡¹È¸èÇý¶¯Æ÷µÄOAuthÁîÅÆ£¬£¬£¬£¬£¬£¬£¬²¢ÓÃËüÀ´ÏÂÔØÉÏ´«µÄÊÓÆµ£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°´æ´¢ÔڹȸèÇý¶¯Æ÷ÉÏµÄÆäËüÆ÷²Ä¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/screencastify-chrome-extension-flaws-allow-webcam-hijacks/


6¡¢BlackBerry°ä²¼¹ØÓÚChaosбäÌåYashmaµÄ·ÖÎö»ã±¨


5ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬£¬BlackBerry°ä²¼Á˹ØÓÚÀÕË÷Èí¼þYashma¼°Æä¼Ò×åµÄ·ÖÎö»ã±¨¡£ ¡£¡£¡£¡£ChaosÊÇÒ»Öֿɶ¨ÔìµÄÀÕË÷Èí¼þ¹¹½¨Æ÷£¬£¬£¬£¬£¬£¬£¬ÓÚ2021Äê6ÔÂ9ÈÕ³õ´Î³öÏÖ£¬£¬£¬£¬£¬£¬£¬Ôø¾­ÀúÁË5´Îµü´ú£¬£¬£¬£¬£¬£¬£¬YashmaÐû³ÆÊÇËüµÄµÚÁù°æ(v6.0)£¬£¬£¬£¬£¬£¬£¬ÓÚ2022ÄêµÄÄêÖÐÔÚÒ°±í±»·¢ÏÖ¡£ ¡£¡£¡£¡£ChaosµÄǰÈý¸ö°æ±¾Ó봫ͳµÄÀÕË÷Èí¼þ±ÈÆðÀ´¸üÏñÊÇÓµÓзÛËéÐԵľÂí£¬£¬£¬£¬£¬£¬£¬µ«Chaos 4.0½øÒ»²½¸Ä½ø£¬£¬£¬£¬£¬£¬£¬½«¿É¼ÓÃÜÎļþµÄÉÏÏÞÌá¸ßµ½2.1MB¡£ ¡£¡£¡£¡£Chaos 5.0ʹÓÃÁËAES-256¼ÓÃÜÖ¸±êÎļþ£¬£¬£¬£¬£¬£¬£¬¶øYashmaÓëÉÏÒ»¸ö°æ±¾ÏÕЩһÑù£¬£¬£¬£¬£¬£¬£¬½öÔö³¤ÁËÁ½ÏîÅú¸Ä¡£ ¡£¡£¡£¡£ 


https://blogs.blackberry.com/en/2022/05/yashma-ransomware-tracing-the-chaos-family-tree