ÔËÓªÉÌRogers´ó¹æÄ£·þÎñÖжϣ¬È«¼ÓÄôó¾ùÊÜÓ°Ï죻Oracle°ä²¼°²È«¸üУ¬½¨¸´¶à¸ö²úÆ·ÖеÄ390¸ö·ì϶
°ä²¼¹¦·ò 2021-04-211.ÔËÓªÉÌRogers´ó¹æÄ£·þÎñÖжϣ¬È«¼ÓÄôó¾ùÊÜÓ°Ïì

µçÐÅÔËÓªÉÌRogers²úÉú´ó¹æÄ£·þÎñÖжϣ¬¼ÓÄôóÈ«¹úÁìÓòÄÚ¾ùÊÜÓ°Ïì¡£ÖжϲúÉúÔÚԼĪÁ賿1µã×óÓÒ£¬Óû§»ã±¨ÆäÎÞ·¨Ê¹ÓÃÓïÒô»òÊý¾Ý·þÎñ¡£RogersÔÚÖÜÒ»£¨4ÔÂ19ÈÕ£©°ä²¼ÉêÃ÷Ö¸³öÆä²¿ÃÅÖ°ÄÜÁÙʱÎÞ·¨Ê¹Ó㬵××ÓÔÒòÊǰ®Á¢ÐÅ×î½üµÄÈí¼þÉý¼¶Ó°ÏìÁËÆäÎÞÏßÍøÂçÖÐÐIJ¿ÃŵÄһ̨É豸£¬µ¼ÖÂÁ˼äЪÐÔÓµ¼·£¬¶ÔÈ«¹ú¸÷µØºÜ¶à¿Í»§µÄ·þÎñÔì³ÉÁËÓ°Ïì¡£RogersÓÚ4ÔÂ20ÈÕ°ä²¼ÍÆÎijƣ¬·þÎñĿǰÒѸ´ÔÕý³£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/mobile/rogers-is-down-canadian-users-report-voice-and-data-outages/
2.Oracle°ä²¼°²È«¸üУ¬½¨¸´¶à¸ö²úÆ·ÖеÄ390¸ö·ì϶

OracleÒÑÓÚ2021Äê4Ô°䲼Á˳ÁÒª²¹¶¡¸üУ¬½¨¸´Á˶à¸ö²úÆ·ÖеÄ390¸ö·ì϶¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶ΪOracleͨѶÀûÓ÷¨Ê½ÖÐCVSSÆÀ·ÖΪ9.8µÄCVE-2020-11612¡¢CVE-2019-0228¡¢CVE-2020-11612ºÍCVE-2020-28052£¬Instantis EnterpriseTrackÖеÄCVE-2019-0219£¬ÆóÒµÖÎÀíÆ÷»ù´¡Æ½Ì¨ÖеÄCVE-2019-17195ÒÔ¼°OracleóÒ×ÖÇÄÜÆóÒµ°æÖеÄCVE-2020-9480µÈ·ì϶¡£OracleÇ¿ÁÒ½¨Òé¿Í»§¾¡¿ìÀûÓð²È«²¹¶¡¡£
ÔÎÄÁ´½Ó£º
https://www.oracle.com/security-alerts/cpuapr2021.html
3.Æû³µ±£ÏÕÉÌGeicoÔâ¹¥»÷£¬Ð¹Â¶½ü3ǧÍò³µÁ¾µÄÐÅÏ¢

Geico¹«Ë¾Ôâµ½¹¥»÷£¬Ð¹Â¶½ü3ǧÍò³µÁ¾µÄÐÅÏ¢¡£GeicoÊÇÃÀ¹úµÚ¶þ´óÆû³µ±£ÏÕ¹«Ë¾£¬Õ¼Óг¬¹ý1700Íò·Ý±£µ¥£¬Éæ¼°³¬¹ý2800ÍòÁ¾Æû³µ¡£¸Ã¹«Ë¾×î½üÈ·¶¨£¬ÔÚ2021Äê1ÔÂ21ÈÕÖÁ3ÔÂ1ÈÕÖ®¼ä£¬ºÚ¿ÍÀûÓÃÔÚÏßÏúÊÛÃÅ»§ÍøÕ¾½Ó¼ûÁËÆäÓû§µÄÊý¾Ý¡£GeicoÒÔΪ¹¥»÷Õß¿ÉÄÜ´òËãʹÓÃÇÔÈ¡µ½µÄ¼ÝÊ»ÅÆÕÕºÅÂ룬ÒÔ±£µ¥³ÖÓÐÈ˵ÄÃûÒåÉêÇëʧҵ¾ÈÖú£¬²¢°µÊ¾½«ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩΪÆÚÒ»ÄêµÄÃâ·ÑÉí·Ý±£»¤·þÎñÀ´×÷ΪÅâ³¥¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/geico-data-breach-exposed-customers-drivers-license-numbers/
4.ºÚ¿ÍÒÔ55ÍòÃÀÔªÏúÊÛ13TB Domino's IndiaµÄÐÅÏ¢

×êÑÐÈËÔ±Rajshekhar Rajaharia·¢ÏÖºÚ¿ÍÔÚ°µÍøÏúÊÛ13TB Domino's IndiaµÄÊý¾Ý£¬Éæ¼°1.8ÒÚ¸ö¶©µ¥µÄ¾ßÌåÐÅÏ¢£¬Ô̺¬¿Í»§µÄÐÕÃû¡¢µç»°ºÅÂë¡¢¸¶¿î¾ßÌåÐÅÏ¢ÒÔ¼°²¿ÃÅÕÅÐÅÓþ¿¨¾ßÌåÐÅÏ¢¡£´Ë±í£¬Rajahariaй©ºÚ¿ÍÏëÓøÃÊý¾Ý¿â»»È¡55ÍòÃÀÔªµÄÊê½ð¡£¾Ýͳ¼Æ£¬ÔÚ´Óǰ6¸öÔÂÀӡ¶ÈµÄÒ»¸ö×éÖ¯¾ùÔÈÿÖÜÊܵ½1681´Î¹¥»÷£¬Õâ±ÈÈ«ÇòµÄ¾ùÔÈÖµ£¨667Æð£©ÓâÔ½2.5±¶ÒÔÉÏ¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/dominos-india-database-hacked-13-tb-data/
5.ºÚ¿ÍÔÚ°µÍøÏúÊÛ³¬¹ý7000ÍòTwitterÓû§µÄÊý¾Ý

°²È«¹«Ë¾Swascan·¢ÏÖºÚ¿ÍÔÚ°µÍø800ÃÀÔªµÄ¼ÛÖµÏúÊÛ³¬¹ý7000ÍòTwitterÓû§µÄÊý¾Ý¡£Õâ´ÎÏúÊÛµÄÐÅÏ¢Ô̺¬Óû§µÄÐÕÃû¡¢TwitterÕÊ»§¡¢µç×ÓÓʼþµØÖ·ºÍµç»°ºÅÂëµÈÐÅÏ¢£¬µ«²»Ô̺¬ÃÜÂë¡£Ö®ºó£¬×êÑÐÈËÔ±·¢ÏÖÁíÒ»¸öÓû§ÔÚ°µÍø¹«¿ªÁË1800ÍòTwitterÓû§µÄÊý¾Ý£¬Ô̺¬ÓʼþµØÖ·µÄÃÜÂ롣Ŀǰ£¬Éв»Ã÷ÏÔºÚ¿ÍÊÇÒÔºÎÖÖ²½ÖèÍøÂçµ½µÄÕâЩÊý¾Ý£¬Swascan½¨ÒéÓû§Ñ¡È¡2FAÉí·ÝÑéÖ¤²¢°´Ê±¸üÐÂÃÜÂëÀ´±£»¤ÕÊ»§¡£
ÔÎÄÁ´½Ó£º
https://latesthackingnews.com/2021/04/19/70-million-twitter-users-data-dumped-for-sale-after-facebook-linkedin/
6.Lazarus APTÔÚ½üÆÚµÄ¹¥»÷ÖÐʹÓÃв½ÖèÈÆ¹ý¼ì²â

Malwarebytes·¢ÏÖ³¯ÏÊAPT×éÖ¯ÔÚ½üÆÚµÄ¹¥»÷ÖÐʹÓÃв½ÖèÈÆ¹ý¼ì²â¡£Õâ´ÎµÄÍøÂç´¹µö»î¶¯Ê¼ÓÚ4ÔÂ13ÈÕ£¬¹¥»÷Õß½«Æä¶ñÒâHTAÎļþ×÷ΪѹËõµÄzlibÎļþǶÈëµ½PNGÎļþÖУ¬¶øºóÔÚÔËÐÐʱ½«Æäת»»ÎªBMPÌåʽ½øÐнâѹËõ¡£µö¶üÎļþÊǺ«ÎÄдµÄ£¬´´½¨ÓÚ2021Äê3ÔÂ31ÈÕ£¬¼Ù×°³ÉÁ˺«¹úij³ÇÊÐÂòÂô»áµÄ²ÎÓëÉêÇë±í£¬ÔÚÓû§³õ´Î´ò¿ªÊ±»áÆôÓú꣬×îÖÕ½«×°ÖÃÒ»¸öÃûΪAppStore.exeµÄ¿ÉÖ´ÐÐÎļþ¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/04/lazarus-apt-hackers-are-now-using-bmp.html


¾©¹«Íø°²±¸11010802024551ºÅ