ÃÀ¹úCISA¡¢DOEºÍÓ¢¹úµÄNCSC½áºÏ°ä²¼¡¶ICSÍøÂ簲ȫ×î¼Ñʵ¼Ê¡·£»Ó¡¶È2910ÍòÇóÖ°ÕßÐÅϢй¶£¬ÆðԴδ֪
°ä²¼¹¦·ò 2020-05-251.ÃÀ¹úCISA¡¢DOEºÍÓ¢¹úµÄNCSC½áºÏ°ä²¼¡¶ICSÍøÂ簲ȫ×î¼Ñʵ¼Ê¡·
ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©¡¢ÄÜÔ´²¿£¨DOE£©ºÍÓ¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©½áºÏ°ä²¼ÁË¡¶¹¤Òµ½ÚÔìÏµÍ³ÍøÂ簲ȫ×î¼Ñʵ¼Ê¡·£¬ÕâÊÇÒ»¸ö³¤´ïÁ½Ò³µÄÐÅϢͼ£¬ÖØÒª½éÉÜÁ˹¤Òµ½ÚÔìϵͳ£¨ICS£©ÍøÂ簲ȫ×î¼Ñʵ¼Ê²½Öè¡£¸ÃÐÅϢͼ×ܽáÁËICS³£¼ûµÄ·çÏÕ˼¿¼³É·Ö¡¢¶ÌÆÚºÍ³Ö¾ÃµÄÍøÂ簲ȫÊÂÎñÓ°Ïì¡¢±£»¤ICSÁ÷³ÌµÄ×î¼Ñ×ö·¨£¬²¢³Áµã½éÉÜÁËNCSCÔÚ°²È«Éè¼Æ×¼ÔòºÍÔËÓª¼¼Êõ·½ÃæµÄ²úÆ·¡£
ÔÎÄÁ´½Ó£º
https://www.us-cert.gov/ncas/current-activity/2020/05/22/cisa-doe-and-uks-ncsc-issue-guidance-protecting-industrial-control
2.MicrosoftΪEdge°ä²¼°²È«¸üУ¬½¨¸´ÌØÈ¨ÌáÉý·ì϶
MicrosoftÔÚ5ÔÂ22ÈÕ°ä²¼ÁËÒ»¸ö°²È«¸üУ¬ÒÔ½â¾ö»ùÓÚChromiumµÄEdgeÖеÄÌØÈ¨ÌáÉý·ì϶£¨CVE-2020-1195£©¡£¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚËÁÒâµØÎ»Ð´ÈëÎļþ²¢»ñµÃ¸ü¸ßµÄȨÏÞ¡£¸Ã·ì϶×ÔÉí²»ÔÊÐíÖ´ÐÐËÁÒâ´úÂ룬µ«ÊÇ£¬¹¥»÷ÕßÄܹ»½áºÏʹÓô˷ì϶ÓëÒ»¸ö»ò¶à¸öÆäËû·ì϶£¨ÀýÈ磬Զ³Ì´úÂëÖ´Ðзì϶ºÍÁíÒ»ÖÖÌØÈ¨ÌáÉý·ì϶£©£¬ÒÔÀûÓøü¸ßȨÏÞÖ´ÐдúÂë¡£Õâ´Î°²È«¸üÐÂͨ¹ýÅú¸ÄMicrosoft EdgeµÄ·´À¡À©´óÑéÖ¤ÎļþÀ´½¨¸´´Ë·ì϶¡£
ÔÎÄÁ´½Ó£º
https://www.us-cert.gov/ncas/current-activity/2020/05/22/microsoft-releases-security-update-edge
3.Ó¡¶È½ÌÓýÍøÕ¾EduCBAÔâµ½ºÚ¿Í¹¥»÷£¬Ð¹Â¶Óû§Êý¾Ý
5ÔÂ22ÈÕ£¬Ó¡¶ÈÔÚÏß½ÌÓýÍøÕ¾EduCBAͨ¹ýÓʼþ֪ͨÆä¿Í»§£¬ËûÃÇÔâµ½Á˺ڿÍÈëÇÖ£¬²¢ÇÒÓû§Êý¾Ýй¶¡£ÔÚ¸Ã֪ͨÖУ¬²¢Ã»ÓоßÌå×¢Ã÷±»ÇÔÐÅÏ¢£¬Ö»Êǵ¥Ò»µØÖ¸³öµç×ÓÓʼþ¡¢Ãû³Æ¡¢ÃÜÂë¡¢Ëù½Ó¼ûµÄ¿Î³ÌµÈ¿ÉÄÜÒѱ»Ð¹Â¶¡£¸Ã¹«Ë¾°µÊ¾£¬ÓÉÓÚËûÃÇʹÓÃÁ˵ÚÈý·½Æ½Ì¨À´´¦Öø¶¿î£¨ÀýÈçPayPalºÍ2Checkout£©£¬Òò¶øÃ»ÓÐÈκβÆÕþÐÅϢй¶£¬¶øÄ¿Ç°Ò²ÒѳÁÖÃËùÓÐЧ»§µÄÃÜÂë¡£µ«ÊÇÔÚtwitterµÄÆÀÂÛÖУ¬²¿ÃÅÓû§°µÊ¾ÆäÕÊ»§ÃÜÂëδ³ÁÖá£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/online-education-site-educba-discloses-data-breach-after-hack/
4.Ó¡¶È2910ÍòÇóÖ°ÕßÐÅϢй¶£¬Ä¿Ç°ÉÐÔÚµ÷²éÐÂäį´Ô´
×êÑÐÈËÔ±ÔÚ°µÍøÉÏ·¢ÏÖÁËһ·Ãô¸ÐÊý¾Ýй¶ÊÂÎñ£¬ºÚ¿Íй¶ÁËÔ¼2910ÍòÓ¡¶È¼®ÇóÖ°ÕßµÄÓ×ÎÒ¾ßÌåÐÅÏ¢¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬µç×ÓÓʼþ¡¢µç»°¡¢¼Òͥסַ¡¢×ʸñ¡¢¹¤×÷¾ÀúµÈ¡£CybleÔÚµ÷²éÕâ¸öÎÊÌâʱ£¬»¹·¢ÏÖÓкڿÍÔÚÒ»¸ö°µÍøÉϰ䲼ÁË2000¶àÕÅÓ¡¶ÈÉí·ÝÖ¤£¨Aadhaar¿¨£©£¬ÕâÆðй¶ÊÂÎñËÆºõ²úÉúÔÚ2019Äê¡£ºÚ¿ÍÄܹ»ÀûÓÃÕâÁ½´Îй©µÄÊý¾Ý½øÐи÷Àà¶ñÒâ»î¶¯£¬Ô̺¬Éí·Ý͵ÇÔ¡¢Ú¿ÆºÍÆóÒµ¼äµý»î¶¯¡£Ä¿Ç°£¬×¨¼ÒÃÇÈÔÔÚµ÷²éй©µÄÆðÔ´£¬²¢²Â²â¿ÉÄÜÔ´×Ô¼òÀú»ã×Ü·þÎñ¹«Ë¾¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/103694/data-breach/indian-jobseekers-data-leak.html
5.ºÚ¿ÍÔÚ°µÍøÏúÊÛ350ÍòÃûZoomcar¿Í»§Êý¾Ý
×êÑÐÈËÔ±·¢ÏÖ£¬×ÔÉÏÖÜËÄ£¬ºÚ¿ÍÔÚ°µÍøÉÏÏúÊÛÔ¼350ÍòZoomcarÓû§µÄÓ×ÎÒÊý¾Ý£¬Ô̺¬Ãû³Æ¡¢µç×ÓÓʼþID¡¢ÃÜÂë¡¢ÊÖ»úºÅÂëºÍIPµØÖ·¡£ºÚ¿Í»¹°µÊ¾£¬½«ÒÔ300ÃÀÔªµÄ¼ÛÖµÏúÊÛ¸ü¶àµÄ900ÍòÃûZoomcarÓû§µÄÊý¾Ý¡£¾ÝºÚ¿Í³Æ£¬Õâ´ÎÊÂÎñ²úÉúÔÚ2018Äê7Ô£¬ÕýÓÉÓÚºÚ¿ÍÊÇÔÚÒ»ÄêºóÏúÊÛÊý¾Ý¶ø²»ÊÇÇÔÈ¡ºóµ±¼´ÏúÊÛ£¬Ê¹µÃ·¨ÂÉÈËÔ±¸üÄѸú×ÙÆäIPµØÖ·ºÍ·ì϶ÆðÔ´¡£Zoomcar CEO Greg Moran°µÊ¾£¬¹«Ë¾Ê¹ÓÃ׳´óµÄ¼ÓÃÜËã·¨¼ÓÃÜËùº±¼û¾Ý£¬ZoomcarÓû§ÃÜÂëÊý¾Ýй¶µÄ¶ÏÑÔÏÔÈ»ÊDz»ÕýÈ·µÄ¡£
ÔÎÄÁ´½Ó£º
https://tech.economictimes.indiatimes.com/news/internet/data-of-3-5-million-zoomcar-customers-up-for-sale/75896086
6.ºÚ¿Í¼ÙÒâÓ¢¹ú×î¸ß·¨Ôº´¹µö¹¥»÷£¬ÇÔÈ¡Office 365Í´´¦
½üÈÕ£¬µç×ÓÓʼþ±£»¤¹«Ë¾Armorblox°ä²¼ÁËÒ»·Ý»ã±¨£¬³ÆÓкڿͼÙÒâÓ¢¹ú×î¸ß·¨Ôº·¢ËÍ´¹µöµç×ÓÓʼþ¡£Õâ´Î¹¥»÷ÖУ¬¹¥»÷Õß½ö½«Óʼþ·¢Ë͸øÌض¨Óû§¶ø²»ÊÇÅúÁ¿·¢ËÍ£¬ÒԴ˶ã±ÜExchange Online Protection£¨EOP£©É¸Ñ¡Æ÷µÄ¹ýÂË¡£²¢ÇÒ£¬¸ÃÓʼþÖл¹Ô̺¬0dayµÄÁ´½Ó£¬Í¨¹ýһϵÁеijÁ¶¨Ïò£¬×îºóÁ´½Óµ½Î±ÔìµÄMicrosoft Office 365Ò³Ãæ£¬ÒÔÇÔÈ¡Óû§Í´´¦¡£¸Ã´¹µö»î¶¯´æÔÚ²¿ÃÅÒì³££¬ÀýÈ磬ºÚ¿ÍʹÓõÄÓòÃûΪ·ÇºÏ·¨Óò¡®docketsender[.]com¡¯£¬µ«Óû§ÈôÊDz»×Ðϸ¹Û²ìºÜÄÑ·¢ÏÖ¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/fake-supreme-court-subpoena-phishing-scam-office-365-credentials/


¾©¹«Íø°²±¸11010802024551ºÅ