TwitterÍøÂçÓû§ÐÅÏ¢¶¨ÏòÍÆË͸æ°×±»·£¿î1.5ÒÚÃÀÔª
°ä²¼¹¦·ò 2022-05-261¡¢TwitterÍøÂçÓû§ÐÅÏ¢¶¨ÏòÍÆË͸æ°×±»·£¿î1.5ÒÚÃÀÔª
¾Ý5ÔÂ26ÈÕ±¨Â·£¬ÃÀ¹úÁª¹úÒµÎñίԱ»áFTCÒѶÔTwitter·£¿î1.5ÒÚÃÀÔª£¬ÔÒòÊÇËüʹÓÃÍøÂçµÄ2FAÑéÖ¤µÄµç»°ºÅÂëºÍÓʼþµØÖ·À´ÍÆË͸æ°×¡£Æ¾¾Ý·¨Í¥Îļþ£¬´Ó2013ÄêÆðÍ·£¬TwitterÒªÇ󳬹ý1.4ÒÚÓû§ÌṩÕâЩÐÅÏ¢ÒÔ±£»¤ËûÃǵÄÕË»§£¬µ«Ã»ÓÐ֪ͨËûÃÇÕâЩÊý¾ÝÒ²½«ÓÃÓÚ¸æ°×ÉÌͶ·Å¸æ°×¡£FTCÖ÷ϯ³Æ£¬TwitterÒÔÓÃÓÚ°²È«Ö÷ÕÅΪ½è¿Ú´ÓÓû§ÄÇÀï»ñÈ¡Êý¾Ý£¬µ«×îÖÕ»¹Ê¹ÓÃÕâЩÊý¾ÝÀ´Õë¶ÔÓû§Í¶·Å¸æ°×£¬ÕâÖÖ×ö·¨Ó°ÏìÁË´óÁ¿Óû§µÄͬʱ»¹ÌáÉýÁËTwitterµÄÊÕÈë¡£TwitterÒÑÔÞ³ÉÖ§¸¶1.5ÒÚÃÀÔªµÄ·£¿î¡£
https://www.bleepingcomputer.com/news/technology/ftc-fines-twitter-150m-for-using-2fa-info-for-targeted-advertising/
2¡¢Ç÷Ïò¿Æ¼¼½¨¸´Òѱ»Moshen DragonÀûÓõÄDLL½Ù³Ö·ì϶
¾ÝýÌå5ÔÂ24ÈÕ±¨Â·£¬Ç÷Ïò¿Æ¼¼½¨¸´Æä°²È«²úÆ·ÖеÄDLL½Ù³Ö·ì϶¡£ÕýÈçSentinel LabsÔÚ5Ô³õÅû¶µÄÄÇÑù£¬Moshen DragonÔÚÕë¶ÔÖÐÑǵĵçÐÅÐÐÒµµÄ¹¥»÷ÖУ¬ÊÔͼ½Ù³Ö°²È«¹©¸øÉ̵ķ¨Ê½£¬Ô̺¬Symantec¡¢TrendMicro¡¢BitDefender¡¢McAfeeºÍKaspersky¡£¹¥»÷ÕßÀûÓÃÁ˶à¸ö¶ñÒâÈí¼þ£¬²¢Í¨¹ýDLL½Ù³ÖÀ´²à¼ÓÔØShadowPadºÍPlugX¡£Trend MicroÒÑÓÚ5ÔÂ19ÈÕͨ¹ýÆäActiveUpdate(AU)°ä²¼ÁËÒ»¸ö½¨¸´·¨Ê½£¬²¢½¨ÒéÓû§µ±¼´½øÐиüС£
https://securityaffairs.co/wordpress/131635/hacking/trend-micro-flaw-moshen-dragon.html
3¡¢Ä³ÅäÖÃÃýÎóµÄES·þÎñÆ÷й¶Êý°ÙÍò´û¿îÉêÇëÈ˵ÄÐÅÏ¢
¾Ý5ÔÂ24ÈÕ±¨Â·£¬Ò»¸öÅäÖÃÃýÎóµÄElasticsearch·þÎñÆ÷й¶ÁË147 GBµÄÊý¾Ý£¬¹²8.7Òڱʼͼ¡£¸Ã·þÎñÆ÷ÓÚ2021Äê12ÔÂ5ÈÕ±»¼ì²âµ½£¬ÖØÒªÔ̺¬ÎÚ¿ËÀ¼¡¢¹þÈø¿Ë˹̹ºÍ¶íÂÞ˹Ó×¶î´û¿îµÄÉêÇëÈ˵ÄÐÅÏ¢£¬ÈçÐÕÃû¡¢×¡Ö·ºÍ»¤ÕÕºÅÂëµÈÓ×ÎÒÐÅÏ¢£¬ÒÔ¼°Ð½Ë®¡¢´û¿îÏêÇéºÍINN£¨Ë°ºÅ£©µÈ²ÆÕþÐÅÏ¢¡£¾Ý¹À¼Æ£¬Ô¼ÓÐ1000ÍòÓû§Êܵ½Ó°Ï죬ÆäÖдó²¿ÃÅ·þÎñÆ÷ÈÕÖ¾ºÍ»¤ÕÕºÅÂëÊôÓÚ¶íÂÞ˹£¬´óÎÞÊýINNÊôÓÚÎÚ¿ËÀ¼£¬¶ø¸Ã·þÎñÆ÷λÓÚºÉÀ¼µÄ°¢Ä·Ë¹Ìص¤¡£
https://www.hackread.com/personal-data-russians-ukrainians-exposed-online/
4¡¢Mozilla°ä²¼¸üн¨¸´Pwn2Own´ó»áÖб»ÀûÓõĶà¸ö·ì϶
5ÔÂ20ÈÕ£¬Mozilla°ä²¼ÁËFirefoxºÍThunderbirdµÄ°²È«¸üУ¬ÒÔ½¨¸´ÔÚPwn2Own 2022´ó»áÆÚ¼ä±»ÀûÓõķì϶¡£µÚÒ»¸ö·ì϶ÊÇTop-Level AwaitʵÏÖÖеÄÔÐÍÁ´´«È¾£¨prototype pollution£©·ì϶£¬×·×ÙΪCVE-2022-1802£¬¹¥»÷Õß¿ÉÀûÓÃËüÀ´Ö´ÐÐJavaScript´úÂë¡£µÚ¶þ¸ö·ì϶( CVE-2022-1529 ) ÊÇJavaScript¶ÔÏóË÷ÒýÖÐʹÓò»ÊÜÐŵÄÊäÈëµ¼ÖµÄÔÐÍÁ´´«È¾·ì϶£¬¿ÉÓÃÀ´ÔÚÌØÈ¨¸¸¹ý³ÌÖÐÖ´ÐÐJavaScript¡£CISAÔÚ5ÔÂ23ÈÕ°ä²¼°²È«¹«¸æ£¬½¨ÒéÂíÉϽ¨¸´ÕâЩ·ì϶¡£
https://www.bleepingcomputer.com/news/security/mozilla-fixes-firefox-thunderbird-zero-days-exploited-at-pwn2own/
5¡¢ChromeÀ©´óScreencastify½¨¸´¿É½Ù³ÖÉãÏñÍ·µÄXSS·ì϶
ýÌå5ÔÂ24Èճƣ¬Ê¢ÐеÄChromeÀ©´óScreencastify½¨¸´ÁËÒ»¸öXSS·ì϶¡£ÕâÊÇÒ»¸öÓÃÓÚ¼ÆÁ¡¢ÊÓÆµ±à×ëºÍýÌå¹²ÏíµÄä¯ÀÀÆ÷À©´ó£¬ÔÚChromeÖеÄ×°ÖÃÁ¿³¬¹ý10000000´Î¡£¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶ÆôÓÃScreencastify¼ÔìÊÓÆµ£¬²¢½«ÆäÉÏ´«µ½Google Drive¡£»¹Äܹ»ÀûÓÃͬÑùµÄ·ì϶À´ÇÔÈ¡¹È¸èÇý¶¯Æ÷µÄOAuthÁîÅÆ£¬²¢ÓÃËüÀ´ÏÂÔØÉÏ´«µÄÊÓÆµ£¬ÒÔ¼°´æ´¢ÔڹȸèÇý¶¯Æ÷ÉÏµÄÆäËüÆ÷²Ä¡£
https://www.bleepingcomputer.com/news/security/screencastify-chrome-extension-flaws-allow-webcam-hijacks/
6¡¢BlackBerry°ä²¼¹ØÓÚChaosбäÌåYashmaµÄ·ÖÎö»ã±¨
5ÔÂ24ÈÕ£¬BlackBerry°ä²¼Á˹ØÓÚÀÕË÷Èí¼þYashma¼°Æä¼Ò×åµÄ·ÖÎö»ã±¨¡£ChaosÊÇÒ»Öֿɶ¨ÔìµÄÀÕË÷Èí¼þ¹¹½¨Æ÷£¬ÓÚ2021Äê6ÔÂ9ÈÕ³õ´Î³öÏÖ£¬Ôø¾ÀúÁË5´Îµü´ú£¬YashmaÐû³ÆÊÇËüµÄµÚÁù°æ(v6.0)£¬ÓÚ2022ÄêµÄÄêÖÐÔÚÒ°±í±»·¢ÏÖ¡£ChaosµÄǰÈý¸ö°æ±¾Ó봫ͳµÄÀÕË÷Èí¼þ±ÈÆðÀ´¸üÏñÊÇÓµÓзÛËéÐԵľÂí£¬µ«Chaos 4.0½øÒ»²½¸Ä½ø£¬½«¿É¼ÓÃÜÎļþµÄÉÏÏÞÌá¸ßµ½2.1MB¡£Chaos 5.0ʹÓÃÁËAES-256¼ÓÃÜÖ¸±êÎļþ£¬¶øYashmaÓëÉÏÒ»¸ö°æ±¾ÏÕЩһÑù£¬½öÔö³¤ÁËÁ½ÏîÅú¸Ä¡£
https://blogs.blackberry.com/en/2022/05/yashma-ransomware-tracing-the-chaos-family-tree


¾©¹«Íø°²±¸11010802024551ºÅ