McAfeeÅû¶½üÆÚ¼ÙÒâÈÕ±¾µçÁ¦ºÍË®Îñ¹«Ë¾µÄ¹¥»÷»î¶¯

°ä²¼¹¦·ò 2023-07-24

1¡¢McAfeeÅû¶½üÆÚ¼ÙÒâÈÕ±¾µçÁ¦ºÍË®Îñ¹«Ë¾µÄ¹¥»÷»î¶¯


McAfeeÔÚ7ÔÂ21ÈÕÅû¶Á˼ÙÒâµçÁ¦ºÍË®Îñ»ù´¡ÉèÊ©¹«Ë¾µÄ¹¥»÷»î¶¯¡£¡£¡£¡£ ¡£¡£¸Ã»î¶¯´Ó6ÔÂ7ÈÕÆðÍ·£¬ £¬£¬£¬£¬³ÖÐøÁ˺̵ܶÄÒ»¶Î¹¦·ò¡£¡£¡£¡£ ¡£¡£ÖØÒªÕë¶ÔÈÕ±¾µÄAndroidÓû§£¬ £¬£¬£¬£¬Í¨¹ý¶ÌÐÅÌáÐÑÖ§¸¶ÎÊÌ⣬ £¬£¬£¬£¬ÓÕʹָ±ê½Ó¼û´¹µöÍøÕ¾£¬ £¬£¬£¬£¬¶øºóÀûÓüäµýÈí¼þSpyNoteÀ´Ï°È¾Ö¸±êµÄÉ豸¡£¡£¡£¡£ ¡£¡£SpyNoteÊÇÒ»¸öÒÑÖªµÄ¶ñÒâÈí¼þϵÁУ¬ £¬£¬£¬£¬¿ÉÇÔÈ¡É豸ÐÅÏ¢ºÍÃô¸ÐµÄÓû§ÐÅÏ¢£¬ £¬£¬£¬£¬ÆäÔ´´úÂëÓÚ2022Äê10ÔÂй¶ºó¼¤Ôö¡£¡£¡£¡£ ¡£¡£×î½ü£¬ £¬£¬£¬£¬Ôø±»ÓÃÓÚ1Ô·ÝÕë¶Ô½ðÈÚ»ú¹¹µÄ¹¥»÷ÒÔ¼°4ÔÂÕë¶ÔÈÕ±¾ÒøÐеĹ¥»÷¡£¡£¡£¡£ ¡£¡£

  

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/android-spynote-attacks-electric-and-water-public-utility-users-in-japan/


2¡¢ÑÇÂíÑ·ÔÞ³ÉÒÔ2500ÍòÃÀÔªºÍ½âAlexaÎ¥·´¶ùͯÒþÖÔ·¨µÄÖ¸¿Ø


¾Ý7ÔÂ21ÈÕ±¨Â·£¬ £¬£¬£¬£¬ÑÇÂíÑ·ÒÑÔÞ³ÉÖ§¸¶2500ÍòÃÀÔª·£¿£¿£¿£¿£¿£¿ £¿£¿î£¬ £¬£¬£¬£¬ÒԺͽâÓëÆäAlexaÓïÒôÖúÀí·þÎñÓйصÄÉæÏÓÎ¥·´¶ùͯÒþÖÔ·¨µÄÖ¸¿Ø¡£¡£¡£¡£ ¡£¡£×Ô2018Äê5ÔÂÆð£¬ £¬£¬£¬£¬ÑÇÂíÑ·¶Ô13ËêÒÔ϶ùͯÌṩAlexaÉù¿Ø²úÆ·ºÍ·þÎñ¡£¡£¡£¡£ ¡£¡£2023Äê5Ô£¬ £¬£¬£¬£¬ÃÀ¹úFTCºÍDOJ¶ÔÑÇÂíÑ·Ìá³öÖ¸¿Ø£¬ £¬£¬£¬£¬³ÆÆäÎ¥·´Á˶ùͯÒþÖÔ·¨£¬ £¬£¬£¬£¬ÆäÖÐÔ̺¬¡¶Áª¹úÒµÎñίԱ»á·¨¡·¡¢¡¶¶ùͯÔÚÏßÒþÖÔ±£»£» £»£»£»£»£»£»¤·¨¡·(COPPA)ºÍCOPPA¹æ¶¨¡£¡£¡£¡£ ¡£¡£Ëß×´³Æ£¬ £¬£¬£¬£¬ÑÇÂíÑ·ÔÚÏ൱³¤µÄÒ»¶Î¹¦·òÄÚδÄÜÂú×ã¼Ò³¤É¾³ýº¢×Ó¹àÒôµÄÒªÇó£¬ £¬£¬£¬£¬´Ë±í£¬ £¬£¬£¬£¬¸Ã¹«Ë¾±¾Ó¦Æ¾¾ÝÒªÇóɾ³ýÓû§µÄÓïÒôÐÅÏ¢ºÍµØÀíµØÎ»Êý¾Ý£¬ £¬£¬£¬£¬µ«È´Ñ¡Ôñ±£ÁôÕâЩÐÅÏ¢ÒÔ¹©¿ÉÄܵÄʹÓᣡ£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/technology/amazon-agrees-to-25-million-fine-for-alexa-children-privacy-violations/


3¡¢ÓÎϷƽ̨RobloxÊý¾ÝÐ¹Â¶Éæ¼°Êýǧ¸ö¿ª·¢ÈËÔ±µÄÐÅÏ¢


¾Ý7ÔÂ21ÈÕ±¨Â·£¬ £¬£¬£¬£¬¹²ÓÐ3943¸öRoblox¿ª·¢ÕßÕÊ»§±»µÁ¡£¡£¡£¡£ ¡£¡£ÔçÔÚ2021Ä꣬ £¬£¬£¬£¬Roblox¾Í²úÉúÁËÊý¾Ýй¶£¬ £¬£¬£¬£¬µ«¾ÝϤ¸Ã¹«Ë¾½«¸ÃÊÂÎñÒþÂ÷ÁËÖÁÉÙÁ½Äê¡£¡£¡£¡£ ¡£¡£Have I Been PwnedÓÚ7ÔÂ18ÈÕ³õ´ÎÆØ¹âÁËÕâ´Îй¶ÊÂÎñ£¬ £¬£¬£¬£¬³ÆÐ¹Â¶×î³õ²úÉúÔÚ2020Äê12ÔÂ18ÈÕ£¬ £¬£¬£¬£¬Éæ¼°ÐÕÃû¡¢µç»°ºÅÂë¡¢ÓʼþµØÖ·ºÍIPµØÖ·µÈ¡£¡£¡£¡£ ¡£¡£RobloxÈϿɣ¬ £¬£¬£¬£¬Ò»¸öµÚÈý·½°²È«ÎÊÌâµ¼ÖÂ¶ÔÆä´´½¨ÕßµÄÓ×ÎÒÊý¾Ýδ¾­ÊÚȨµÄ½Ó¼û¡£¡£¡£¡£ ¡£¡£¶ÔÓÚÊÜÓ°Ïì½ÏÓ×µÄÓû§£¬ £¬£¬£¬£¬ËûÃǽ«»áÊÕµ½Ò»·âÖÂǸÓʼþ¡£¡£¡£¡£ ¡£¡£¶ÔÓÚÊÜÓ°ÏìÑϳÁµÄÓû§£¬ £¬£¬£¬£¬ËûÃǽ«»á»ñµÃΪÆÚÒ»ÄêµÄÉí·Ý±£»£» £»£»£»£»£»£»¤·þÎñ¡£¡£¡£¡£ ¡£¡£


https://www.hackread.com/roblox-data-breach-developers-pii-data-stolen/


4¡¢×êÑÐÈËÔ±·¢ÏÖÀûÓÃCitrix·ì϶Õë¶ÔÃÀ¹ú»ù´¡ÉèÊ©µÄ¹¥»÷


7ÔÂ21ÈÕ±¨Â·³Æ£¬ £¬£¬£¬£¬CISAÌáÐÑÀûÓÃCitrix NetScaler ADCºÍGatewayÖзì϶¹¥»÷ÃÀ¹ú¹Ø¼ü»ù´¡ÉèÊ©µÄ»î¶¯¡£¡£¡£¡£ ¡£¡£Õâ´Î¹¥»÷²úÉúÔÚ6Ô·ݣ¬ £¬£¬£¬£¬ºÚ¿ÍÀûÓÃÁËRCE·ì϶£¨CVE-2023-3519£©£¬ £¬£¬£¬£¬ÔÚÖ¸±êµÄ·Ç³ö²úNetScalerÀûÓý»¸¶½ÚÔìÆ÷(ADC)É豸ÉÏÖ²ÈëWebshell¡£¡£¡£¡£ ¡£¡£¸ÃºóÃÅ¿ÉÓÃÀ´Ã¶¾ÙAD¶ÔÏó£¬ £¬£¬£¬£¬Ô̺¬ÍøÂçÉϵÄÓû§¡¢×é¡¢ÀûÓ÷¨Ê½ºÍÉ豸£¬ £¬£¬£¬£¬²¢ÇÔÈ¡ADÊý¾Ý¡£¡£¡£¡£ ¡£¡£È»¶ø£¬ £¬£¬£¬£¬ÓÉÓÚÖ¸±êNetScaler ADCÉ豸λÓÚ¸ôÀë»·¾³ÖУ¬ £¬£¬£¬£¬¹¥»÷ÕßÎÞ·¨ºáÏòÒÆ¶¯µ½Óò½ÚÔìÆ÷¡£¡£¡£¡£ ¡£¡£CISA°ä²¼ÁËÒ»·ÝÔ̺¬TTPÒÔ¼°¼ì²â²½ÖèµÄ¹«¸æ£¬ £¬£¬£¬£¬²¢½¨ÒéÖÎÀíÔ±ÀûÓÃ×îеÄCitrix¸üС£¡£¡£¡£ ¡£¡£


https://securityaffairs.com/148690/security/cisa-citrix-netscaler-adc.html


5¡¢ÁåľµÄÁ½¼Ò¾­ÏúÉÌÍøÕ¾ÒòÅäÖÃÃýÎóй¶¿Í»§µÄÐÅÏ¢


ýÌå7ÔÂ21Èճƣ¬ £¬£¬£¬£¬ÁåľÊÚȨµÄÁ½¸ö¾­ÏúÉ̵ÄÍøÕ¾Ð¹Â¶Á˿ͻ§µÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£ ¡£¡£µÚÒ»¼Ò¾­ÏúµêÔÚ°ÍÎ÷ÔËÓª£¬ £¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËÄÚÈÝ·Ö·¢ÍøÂç(CDN)GoChacheµÄ¶ËµãºÍÃÜÔ¿¡¢MySQLÊý¾Ý¿â¡¢SMTPƾ֤ÒÔ¼°ÀûÓ÷¨Ê½ºÍ±í²¿µÚÈý·½·þÎñµÄ¸÷ÀàÃÜÔ¿¡£¡£¡£¡£ ¡£¡£µÚ¶þ¼ÒÊǰÍÁÖΨһµÄÁåľÆû³µ¾­ÏúÉÌ£¬ £¬£¬£¬£¬¸Ã¹«Ë¾µÄLaravelÀûÓÃÃÜÔ¿¡¢Êý¾Ý¿âºÍSMTPÍ´´¦²»Êܱ£»£» £»£»£»£»£»£»¤¡£¡£¡£¡£ ¡£¡£×êÑÐÈËÔ±³Æ£¬ £¬£¬£¬£¬SMTPÍ´´¦¿ÉÓÃÓÚÏòÓû§·¢ËͶñÒâÓʼþ£¬ £¬£¬£¬£¬Êý¾Ý¿âÍ´´¦¿ÉÓÃÀ´½Ó¼ûÊý¾Ý¿âÄÚÈÝ£¬ £¬£¬£¬£¬ÆäÖпÉÄÜÔ̺¬Óû§ÐÅÏ¢¡£¡£¡£¡£ ¡£¡£


https://securityaffairs.com/148675/data-breach/nice-suzuki-sport-shame-dealer-left-your-data-up-for-grabs.html


6¡¢Unit 42°ä²¼¹ØÓÚÀÕË÷Èí¼þMalox¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨


7ÔÂ20ÈÕ£¬ £¬£¬£¬£¬Unit 42°ä²¼Á˹ØÓÚÀÕË÷Èí¼þMalox¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£ ¡£¡£Mallox£¨±ðÃûTargetCompany£©ÊÇÒ»ÖÖÕë¶ÔMicrosoft WindowsϵͳµÄÀÕË÷Èí¼þ£¬ £¬£¬£¬£¬×Ô2021Äê6ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬ £¬£¬£¬£¬ÖØÒªÀûÓò»°²È«µÄMS-SQL·þÎñÆ÷×÷ÎªÔØÌ壬 £¬£¬£¬£¬ÈëÇÖÖ¸±êµÄÍøÂç¡£¡£¡£¡£ ¡£¡£½üÆÚ£¬ £¬£¬£¬£¬Unit 42¹Û²ìµ½Mallox¹¥»÷»î¶¯ÓÐËùÔö³¤£¬ £¬£¬£¬£¬ÓëǰһÄêÏà±ÈÔö³¤Á˽ü174%¡£¡£¡£¡£ ¡£¡£MalloxʹÓÃÁ˱©Á¦ÆÆ½â¡¢Êý¾Ýй¶ºÍÍøÂçɨÃ蹤¾ßµÈ¡£¡£¡£¡£ ¡£¡£´Ë±í£¬ £¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÓм£ÏóÅú×¢¸Ã×éÖ¯ÔÚÖÂÁ¦À©´óÆäÒµÎñ£¬ £¬£¬£¬£¬²¢ÔÚºÚ¿ÍÂÛ̳ÉÏÕÐļ´ÓÊô»ú¹¹¡£¡£¡£¡£ ¡£¡£


https://unit42.paloaltonetworks.com/mallox-ransomware/