Google°ä²¼´¹Î£¸üР½¨¸´ChromeÖÐÒѱ»ÀûÓõķì϶

°ä²¼¹¦·ò 2021-12-15

Google°ä²¼´¹Î£¸üУ¬½¨¸´ChromeÖÐÒѱ»ÀûÓõķì϶


Google°ä²¼´¹Î£¸üУ¬½¨¸´ChromeÖÐÒѱ»ÀûÓõķì϶.png


12ÔÂ13ÈÕ£¬Google°ä²¼´¹Î£¸üУ¬½¨¸´ÁËChromeÖеÄ5¸ö·ì϶¡£°²È«²¼¸æ°µÊ¾£¬Õâ´Î½¨¸´µÄV8 JavaScriptÒýÇæÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2021-4102£©Òѱ»ÔÚÒ°ÀûÓ㬿ɵ¼ÖÂËÁÒâ´úÂëÖ´ÐлòɳÏäÌÓÒÝ¡£´Ë±í£¬»¹½¨¸´ÁËMojoÖеÄÊý¾ÝÑéÖ¤²»¼°·ì϶£¨CVE-2021-4098£©ºÍSwiftshaderÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2021-4099£©µÈ¶à¸ö·ì϶¡£ÓÉÓÚ¸Ã0dayÒѱ»ÔÚÒ°ÀûÓã¬×êÑÐÈËԱǿÁÒ½¨Òéµ±¼´×°ÖÃChrome²¹¶¡¡£


Ô­ÎÄÁ´½Ó£º

https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop_13.html


°ÍÎ÷ÎÀÉú²¿ÍøÕ¾Ôâµ½¹¥»÷Êý°ÙÍò¹«ÃñÒßÃç½ÓÖÖÊý¾ÝÃÔʧ


°ÍÎ÷ÎÀÉú²¿ÍøÕ¾Ôâµ½¹¥»÷Êý°ÙÍò¹«ÃñÒßÃç½ÓÖÖÊý¾ÝÃÔʧ.png


12ÔÂ10ÈÕ£¬°ÍÎ÷ÎÀÉú²¿(MoH)ÏÂÊôµÄÍøÕ¾Ôâµ½ÀÕË÷¹¥»÷£¬µ¼ÖÂÊý°ÙÍò¹«ÃñµÄCOVID-19ÒßÃç½ÓÖÖÊý¾ÝÃÔʧ¡£¹¥»÷²úÉúÔÚÁ賿1µã×óÓÒ£¬ÎÀÉú²¿µÄËùÓÐÍøÕ¾£¬Ô̺¬Ò½ÁÆÏµÍ³Öиú×Ù¹«Ãñ¹ì¼£µÄConecteSUS£¬¾ùÎÞ·¨½Ó¼û¡£Ö®ºó£¬ºÚ¿ÍÍÅ»ïLapsus$ GroupÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬²¢ÒѾ­ÇÔÈ¡²¢É¾³ýÁËÔ¼50TBµÄÊý¾Ý¡£¾Ý°ÍÎ÷ÎÀÉú²¿²¿³¤Marcelo Queiroga³Æ£¬ËûÃÇÔÚ¹ú¶ÈÎÀÉú·þÎñÊý¾Ý¿âÖÐÓб»µÁÊý¾Ý±¸·Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/brazilian-ministry-of-health-suffers-cyberattack-and-covid-19-vaccination-data-vanishes/


µÂ¹úÎïÁ÷¹«Ë¾HellmannÔâµ½¹¥»÷µ¼ÖÂÔËÓªÁÙʱÖжÏ


µÂ¹úÎïÁ÷¹«Ë¾HellmannÔâµ½¹¥»÷µ¼ÖÂÔËÓªÁÙʱÖжÏ.png


µÂ¹úÎïÁ÷¹«Ë¾Hellmann Worldwide LogisticsÔÚ12ÔÂ10ÈÕ³ÆÆäÔâµ½ÍøÂç¹¥»÷¡£¸Ã¹«Ë¾Ã¿Äê´¦ÖÃԼĪ1600Íò¼þ»õÎ2020ÄêµÄÊÕÈëΪ28ÒÚÃÀÔª¡£HellmannÔÚÉêÃ÷ÖаµÊ¾£¬Æä¼ì²âµ½¹¥»÷ºóµ±¼´×ö³öÏìÓ¦£¬ÁÙʱ¹Ø¹ØÁËÖÐÑëÊý¾ÝÖÐÐÄ£¬µ«Õâ¶Ô¹«Ë¾µÄÔËÓª²úÉúÁËÑϳÁµÄÓ°Ïì¡£¸Ã¹«Ë¾²¢Î´Ð¹Â©¹¥»÷µÄÐÔÖÊ£¬µ«ÔÚ13ÈÕ°ä²¼²¼¸æ£¬³ÆÒµÎñÔËÓªÒѸù»ù¸´Ô­Õý³££¬Ä¿Ç°ÉÐδȷÈÏÊÇ·ñº±¼û¾Ýй¶µÄÇé¿ö¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/cyberattack-on-hellmann-worldwide/


FTC³ÆÃÀ¹ú½ñÄêÒòÀñÎ│ڿƭ»î¶¯ÒÑËðʧ1.48ÒÚÃÀÔª


FTC³ÆÃÀ¹ú½ñÄêÒòÀñÎ│ڿƭ»î¶¯ÒÑËðʧ1.48ÒÚÃÀÔª.png


ÃÀ¹úÁª¹úÒµÎñίԱ»á(FTC)ÔÚ12ÔÂ8ÈÕ°µÊ¾£¬½ØÖÁ2021Äê9Ôµ×£¬ÃÀ¹ú¹«ÃñÒòÀñÎ│ڿƭ»î¶¯µÄËðʧ¸ß´ï1.48ÒÚÃÀÔª£¬³¬¹ý2020ÕûÄêµÄ×ÜËðʧ¡£FTC³Æ£¬×Ô2018ÄêÒÔÀ´£¬±»Æ­µÄÏû·ÑÕßÊýÁ¿ºÍËðʧ½ð¶î¶¼ÔÚÎȲ½Ôö³¤£¬ÆäÖÐÀñÎ│ÊÇÖØÒªµÄ¸¶¿î·½Ê½¡£ÕâÖÖ¹¥»÷»î¶¯Í¨³£»á¼ÙÒâÉç»á±£Ïվֵȹٷ½×éÖ¯£¬ÍþвҪ¶³½áÖ¸±êÒøÐÐÕË»§£¬²¢°µÊ¾ÈôÊDz»Ïë±»²¶»òÏëÒª±£ÁôÕË»§ÖеIJƸ»¾Í±ØÐë²É°ìÀñÎ│¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ftc-americans-lost-148-million-to-gift-card-scams-this-year/


Proofpoint¼ì²âµ½ÀûÓÃOAuth 2.0µÄURL³Á¶¨Ïò¹¥»÷


Proofpoint¼ì²âµ½ÀûÓÃOAuth 2.0µÄURL³Á¶¨Ïò¹¥»÷.png


ProofpointÔÚ12ÔÂ8ÈÕÅû¶ÁËÀûÓÃOAuth 2.0µÄURL³Á¶¨Ïò¹¥»÷µÄϸ½Ú¡£¹¥»÷Õßͨ¹ýÕâÖÖ·½Ê½Èƹý´óÎÞÊý´¹µö¹¥»÷¼ì²âϵͳºÍµç×ÓÓʼþ°²È«Õ½Êõ£¬¹¥»÷Outlook Web Access¡¢PayPal¡¢Microsoft 365ºÍGoogle WorkspaceµÅצÓá£OAuth 2.0ÊÇÒ»ÖÖ¿í·ºÊ¹ÓõÄÊÚȨºÍ̸£¬µ±webÀûÓù鲢ÁËÓû§½ÚÔìµÄ²ÎÊýÀ´Ö¸¶¨³Á¶¨ÏòÁ´½Óʱ£¬¾Í»á³öÏÖÊ¢¿ªÊ½³Á¶¨Ïò·ì϶£¬¹¥»÷Õß¿ÉÒÔΪwebÀûÓô´½¨Ò»¸öURL£¬´Ó¶ø½«Ö¸±ê³Á¶¨Ïòµ½ËÁÒâµÄ±í²¿Óò¡£


Ô­ÎÄÁ´½Ó£º

https://www.proofpoint.com/us/blog/cloud-security/microsoft-and-github-oauth-implementation-vulnerabilities-lead-redirection


Microsoft°ä²¼¶ñÒâÈí¼þQakbotµÄ¼¼Êõ·ÖÎö»ã±¨


Microsoft°ä²¼¶ñÒâÈí¼þQakbotµÄ¼¼Êõ·ÖÎö»ã±¨.png

12ÔÂ9ÈÕ£¬Microsoft°ä²¼Á˹ØÓÚ¶ñÒâÈí¼þQakbotµÄ¼¼Êõ·ÖÎö»ã±¨¡£QakbotÒÑÓнü10Ä꺹Ç࣬ÒÑ·¢Õ¹³ÉΪһÖÖ¶àÓô¦¶ñÒâÈí¼þ£¬ÏÕЩÔÚËùÓдó½µÄ¹ú¶ÈºÍµØÓò¶¼Äܹ»¼ì²âµ½Qakbot»î¶¯£¬Ô̺¬·ÇÖÞ¡¢ÑÇÖÞ¡¢Å·ÖÞºÍÃÀÖÞ¡£×êÑÐÈËÔ±ÒÔΪ£¬QakbotµÄÄ£¿é»¯¸öÐÔʹËü¿ÉÄÜÆ¾¾ÝµØµãµÄÍøÂç»·¾³ÎªÃ¿¸ö¹¥»÷Á´£¨attack chain£©åàÑ¡ÏàÒ˵Ĺ¹½¨¿é£¨building blocks£©¡£¸Ã»ã±¨×êÑÐÁË×î½üµÄ3¸öQakbot»î¶¯£¬²¢½«Æä¹¥»÷Á´·Ö»¯Îª¶à¸ö¹¹½¨¿é½øÐзÖÎö¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/security/blog/2021/12/09/a-closer-look-at-qakbots-latest-building-blocks-and-how-to-knock-them-down/