ºÚ¿ÍÇÔÈ¡Òâ´óÀûLeonardo SpAµÄ10GB¾üÊ»úÃÜ£»Ó¢¹úNCSC°ä²¼2020Äê¶È»ØÊ׵ķÖÎö»ã±¨

°ä²¼¹¦·ò 2020-12-07

1.ºÚ¿ÍÇÔÈ¡Òâ´óÀûLeonardo SpAµÄ10GB¾üÊ»úÃÜ


1.jpg


ºÚ¿ÍÇÔÈ¡¹ú·À¹«Ë¾Leonardo SpAµÄ10 GB¾üÊ»úÃÜ£¬ÏÖÒѱ»Òâ´óÀû¾¯·½¿ÛÁô¡£LeonardoÊÇÊÀ½çÉÏ×î´óµÄ¹ú·À³Ð°üÉÌÖ®Ò»£¬Æä30£¥µÄ¹É·ÝÊôÓÚÒâ´óÀû¾­¼ÃºÍ²ÆÕþ²¿¡£Õâ´Îй¶µÄÐÅÏ¢Éæ¼°µ½ÐÐÕþ¹ÜÕÊÖÎÀí¡¢ÈËÁ¦×ÊÔ´¡¢±¾Ç®»õÎïµÄ²É¹ººÍ·ÖÅä¡¢ÃñÓ÷ɻúÁ㲿¼þºÍ¾üÓ÷ɻúµÄÉè¼Æ¡¢Ô±¹¤Ó×ÎÒÐÅÏ¢¡£¾ÝϤ£¬ºÚ¿ÍʹÓÃUSBÃÜÔ¿Ïò94¸ö¹¤×÷Õ¾·Ö·¢cftmon.exeľÂí£¬²¢ÒÔÕý°æWindowsÎļþ¶¨Ãû¸ÃľÂíÒÔÈÆ¹ý¼ì²â¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/police-arrest-two-in-data-theft-cyberattack-on-leonardo-defense-corp/


2.ºÚ¿ÍÀûÓÃÍøÂç´¹µöÇÔÈ¡MetaMaskÓû§µÄ¼ÓÃÜÇ®±Ò


2.jpg


ºÚ¿ÍÀûÓÃGoogle¸æ°×ͨ¹ýÍøÂç´¹µö¹¥»÷ÇÔÈ¡MetaMaskÓû§µÄ¼ÓÃÜÇ®±ÒÇ®°üÎļþ¡£MetaMaskÕ¼Óг¬¹ýÒ»°ÙÍòÓû§£¬Í¨¹ýä¯ÀÀÆ÷À©´ó·¨Ê½ÔÚä¯ÀÀÆ÷ÖÐÌṩÁËÒ»¸öÒÔÌ«·»¼ÓÃÜÇ®±ÒÇ®°ü£¬ÔÚ×°ÖøÃÀ©´óºó£¬¿Éµ¼ÈëÏÖÓеÄÇ®°ü£¬Ò²¿É´´½¨ÐÂÇ®°ü¡£ºÚ¿ÍÀûÓÃGoogle¸æ°×½«Óû§³Á¶¨Ïòµ½MetaMaskÍøÂç´¹µöÒ³Ãæ£¬µ±Óû§µã»÷µ¼ÈëÇ®°üÑ¡Ïîʱ£¬»á±»ÒªÇóÊäÈëÏÖÓÐÇ®°üµÄ¹Ø¼ü×Ö£¬ÕâЩÐÅÏ¢»á±»·¢Ë͸ø¹¥»÷ÕßÓÃÀ´ÇÔÈ¡¼ÓÃÜÇ®±Ò¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/metamask-phishing-steals-cryptocurrency-wallets-via-google-ads/


3.Ç¿Éú³ÆCOVID-19ÆÚ¼äÕë¶ÔÆäµÄ¹¥»÷´ÎÊýÔö³¤30£¥


3.jpg


Ç¿Éú³ÆCOVID-19ÆÚ¼äÕë¶ÔÆäµÄ¹¥»÷´ÎÊýÔö³¤ÁË30£¥¡£¾Ý¡¶»ª¶û½ÖÈÕ±¨¡·±¨Â·£¬³¯ÏʺڿÍÒѾ­½«ÃÀ¹ú¡¢Ó¢¹úºÍº«¹ú´ÓÊÂCovid-19Ò½Öι¤×÷µÄÖÁÉÙÁù¼ÒÔìÒ©¹«Ë¾ÁÐΪ¹¥»÷Ö¸±ê£¬Ö¼ÔÚÍøÂçÄܹ»ÏúÊÛ»ò±øÆ÷»¯µÄÃô¸ÐÐÅÏ¢¡£ÕâЩ¹«Ë¾Ô̺¬Ç¿Éú¹«Ë¾ºÍÂíÀïÀ¼ÖݵÄNovavax¹«Ë¾£¬Æä¶¼ÔÚ×êÑг¢ÊÔÐÔÒßÃ硣ǿÉú¹«Ë¾µÄCIO Marene Allison°µÊ¾£¬¹ú¶ÈºÚ¿Íÿʱÿ¿Ì¶¼ÔÚ¹¥»÷Ò½ÁÆ×éÖ¯£¬Õë¶ÔÇ¿Éú¹«Ë¾µÄÍøÂç¹¥»÷Ôö³¤ÁË30%¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/111960/hacking/covid-19-johnson-johnson-cyber-attacks.html


4.Apache°ä²¼°²È«¸üУ¬½¨¸´TomcatÖÐÑϳÁµÄ·ì϶


4.jpg


Apache°ä²¼°²È«¸üУ¬½¨¸´ÁËTomcatÖÐÑϳÁµÄ·ì϶£¬¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶µ¼Ö»ؾø·þÎñÇé¿ö¡£¸Ã·ì϶±»×·×ÙΪCVE-2020-17527£¬ÓÉÓÚApache TomcatÄܹ»½«HTTP/2ÏνÓÉÏÊÕµ½µÄÏÈǰÁ÷ÖеÄHTTPÒªÇó±êÍ·Öµ³ÁÐÂÓÃÓÚÓëºóÐøÁ÷ÓйØÁªµÄÒªÇóËùµ¼ÖµÄ¡£Ö»¹ÜÕâºÜ¿ÉÄܻᵼÖÂÃýÎ󲢹عØHTTP/2ÏνÓ£¬µ«ÊÇÐÅÏ¢¿ÉÄÜ»áÔÚÒªÇóÖ®¼äй©¡£¸ÃÎÊÌâÒÑÓÚTomcat 10.0.0-M10Öн¨¸´¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/12/04/apache-releases-security-advisory-apache-tomcat


5.Dashlane°ä²¼2020Äê¶ÈÃÜÂëй¶ÎÊÌâµÄ·ÖÎö»ã±¨


5.jpg


Dashlane°ä²¼2020Äê¶ÈÃÜÂëй¶ÎÊÌâµÄ·ÖÎö»ã±¨£¬³Áµã½éÉÜÁ˸ÃÄêÓëÃÜÂëÓйصÄ×îÑϳÁ±äÂҵĹ«Ë¾ºÍ×éÖ¯¡£ÆäÖУ¬°ñµ¥ÉÏÅÅÃûµÚÒ»ºÍµÚ¶þµÄÊÇTwitterºÍZoom£¬ËüÃÇÔÊÐíÆäÔ±¹¤ºÍÓû§Ê¹ÓÃÈõÃÜÂ룬ʹÆäÒ×ÊÜÍøÂç¹¥»÷µÄÓ°Ïì¡£ÓÎÀÀ¡¢ÓÎÏ·ºÍ¿ìµÝÁìÓòµÄÆäËû³ÛÃûÆóÒµÒ²³ÉΪºÚ¿ÍµÄÊܺ¦Õß¡£´Ë±í£¬DashlaneµÄÊý¾ÝÏÔʾ£¬¾ùÔÈÿ¸ö»¥ÁªÍøÓû§Óг¬¹ý200¸ö±ØÒªÊ¹ÓÃÃÜÂëµÄÊý×ÖÕË»§£¬ÕâÒ»Êý×ÖÔ¤¼ÆÔÚ½«À´ÎåÄêÄÚ½«·­Ò»·¬£¬´ïµ½400¸ö¡£


Ô­ÎÄÁ´½Ó£º

https://blog.dashlane.com/twitter-employees-and-zoom-users-top-dashlanes-list-of-2020s-worst-password-offenders/


6.Ó¢¹úNCSC°ä²¼2020Äê¶È»ØÊ׵ķÖÎö»ã±¨


6.jpg


Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©°ä²¼ÁË2020Äê¶È»ØÊ׻㱨£¬¸Ã»ã±¨µÄ³ÁµãÊÇÓ¦¶Ô²»Ðݱ䶯µÄÌôÕ½ÐÔÍøÂçÍþв£¬»ØÊ×ÁËNCSCµÄ2019Äê9ÔÂ1ÈÕµ½2020Äê8ÔÂ31ÈÕÖ®¼äµÄ¹¤×÷ÖØÒª½øÕ¹ºÍÁÁµã¡£¸Ã»ã±¨Ö¸³ö£¬ÔÚÕ⸴ÔÓÌôÕ½µÄÒ»Ä꣬NCSC³ÖÐø¶ÔѸ¿ìÑݱäµÄÍøÂçÍþв×÷³ö·´Ó³¡£²¢Ìá³öÁ˹ØÓÚNCSC¹¤×÷µÄÁ½¸ö³ÁÒªÐÅÏ¢¡£µÚÒ»£¬Ô¤·À·¸×ﳤ¶Ì·¸×ïÖÐÐĵÄÊ×Òª¹¤×÷£¬ÆäÓë·¨Âɲ¿ÃÅçÇÃܺÏ×÷£¬²¢ÔÚ723×Ú¹¥»÷ÊÂÎñÖÐÔöÔ®Á˽ü1200ÃûÊܺ¦Õߣ»µÚ¶þ£¬ÍøÂç°²ÂúÊÇÒ»ÏîÍŶӻ¡£


Ô­ÎÄÁ´½Ó£º

https://www.ncsc.gov.uk/annual-review/2020/docs/ncsc_2020-annual-review_s.pdf