GoogleÒò¼Óº¦ÒþÖÔÔÞ³ÉÏòÒÁÀûŵÒÁÖݵĹ«ÃñÖ§¸¶1ÒÚÃÀÔª
°ä²¼¹¦·ò 2022-06-09¾ÝýÌå6ÔÂ6Èճƣ¬GoogleÃæ¶Ô×ÅÃÀ¹úÒÁÀûŵÒÁÖݵĹ«ÃñµÄ¼¯ÌåËßËÏ£¬Æä±»Ö¸¿ØÎ´¾ÔÞ³ÉÍøÂçºÍ´æ´¢Ó×ÎÒÉúÎïÌØµã¡£ÕâÎ¥·´ÁËÒÁÀûŵÒÁÖݵÄÉúÎï¼ø±ðÐÅÏ¢ÒþÖÔ·¨(BIPA)£¬×îÖչȸèÔÞ³ÉÖ§¸¶1ÒÚÃÀÔª½øÐÐÅâ³¥¡£ËùÓÐÒÁÀûŵÒÁÖݾÓÃñ£¬Ö»ÓÐÔÚ2015Äê5ÔÂ1ÈÕÖÁ2022Äê4ÔÂ25ÈÕÄڳʴ˿ÌGoogleÕÕÆ¬ÖУ¬¶¼ÓÐ×ʸñÉêÇëÅ⸶£¬Ô¤¼ÆÃ¿È˽«µÃµ½200-400ÃÀÔª¡£FacebookÒ²Ãæ¶Ô¹ýÀàËÆµÄ¼¯ÌåËßËÏ£¬²¢ÔÞ³ÉÏòÒÁÀûŵÒÁÖݵĹ«ÃñÖ§¸¶6.5ÒÚÃÀÔª¡£
https://www.engadget.com/google-photos-bipa-lawsuit-settlement-161237789.html
2¡¢ÃÀ¹ú·¨Âɲ¿ÃÅÒѲé·âÏúÊÛ¹«ÃñÉí·ÝÐÅÏ¢µÄ°µÍøÊг¡SSNDOB
6ÔÂ7ÈÕ±¨Â·£¬ÃÀ¹ú˾·¨²¿¡¢¹ú˰¾ÖºÍÁª¹úµ÷²é¾Ö½áºÏÐж¯£¬¹Ø¹ØÁËÒ»¸öÊ¢ÐеİµÍøÊг¡SSNDOB¡£¸ÃÍøÕ¾ÒÑÏúÊÛÁËÔ¼2400ÍòÈ˵ÄÐÅÏ¢£¬²¢»ñÀû³¬¹ý1900ÍòÃÀÔª¡£SSNDOBÊг¡Óɶà¸öÍøÕ¾×é³É£¬ÕâÐ©ÍøÕ¾³äÈα˴˵ľµÏñ£¬ÒÔÕмÜDDoS¹¥»÷»ò·¨ÂÉÐж¯¡£ÃÀ¹úµ±¾ÖÔÚÈûÆÖ·˹ºÍÀÍÑάÑǵÄÐÖúÏ£¬²é·âÁËSSNDOBµÄ4¸öÓòÃû¡°ssndob.ws¡±¡¢¡°ssndob.vip¡±¡¢¡°ssndob.club¡±ºÍ¡°blackjob.biz¡±¡£´Ë±í£¬Chainalysis·¢ÏÖSSNDOBÓëJoker's StashÖ®¼ä´æÔÚÁªÏµ£¬ºóÕßÓÚ2021Äê1Ô¹عء£
https://therecord.media/doj-fbi-shut-down-marketplace-for-stolen-social-security-numbers/
3¡¢ÐÂSVCReadyͨ¹ý°µ²ØÔÚÎĵµÊôÐÔÖеÄshellcode·Ö·¢
6ÔÂ6ÈÕ£¬»ÝÆÕÔÚһƪ¼¼ÊõÎÄÕÂÖй«¿ªÁËеĶñÒâÈí¼þSVCReady¡£¸Ã¶ñÒâÈí¼þÈÔ´¦ÓÚÔçÆÚ¿ª·¢½×¶Î£¬¿ª·¢ÕßÔÚÉϸöÔ½øÐÐÁËÂŴεü´úÀ´¸üжñÒâÈí¼þ£¬Æä×î³õµÄ»î¶¯¼£ÏóÄܹ»×·Òäµ½2022Äê4ÔÂ22ÈÕ¡£¸Ã»î¶¯ÀûÓÃÁËÔ̺¬VBAºêµÄWordÎĵµ×°ÖöñÒâpayload¡£µ«ËüµÄ·ÖÆçÖ®´¦ÔÚÓÚ£¬¸ÃºêûÓÐʹÓÃPowerShell»òMSHTA´ÓÔ¶³Ì·þÎñÆ÷¼ìË÷ÏÂÒ»½×¶ÎµÄ¿ÉÖ´ÐÐÎļþ£¬¶øÊÇÔËÐд洢ÔÚÎĵµÊôÐÔÖеÄshellcode£¬¶øºó×°ÖöñÒâÈí¼þSVCReady¡£¾Ý·ÖÎö£¬SVCReady¿ÉÄÜÓëTA551ÓйØÁª¡£
https://thehackernews.com/2022/06/researchers-warn-of-spam-campaign.html
4¡¢Google°ä²¼6Ô·ÝAndroid°²È«¸üУ¬½¨¸´41¸ö·ì϶
¾Ý6ÔÂ7ÈÕ±¨Â·£¬Google°ä²¼ÁË6Ô·ݵÄAndroid°²È«¸üУ¬×ܼƽ¨¸´41¸ö·ì϶¡£¸Ã¸üзÖΪÁ½¸ö²¿ÃÅ£¬±ðÀëÓÚ6ÔÂ1ÈÕºÍ5ÈÕ°ä²¼£¬µÚÒ»¸öÔ̺¬AndroidϵͳºÍ¿ò¼Ü×é¼þµÄ²¹¶¡£¬µÚ¶þ¸öÔ̺¬Äں˺͵ÚÈý·½¹©¸øÉ̹ØÔ´×é¼þµÄ¸üС£Õâ´Î½¨¸´µÄ×îÑϳÁµÄÊÇϵͳ×é¼þÖеÄÒ»¸öRCE·ì϶£¨CVE-2022-20210£©£¬ÎÞÐè¶î±íÖ´ÐÐȨÏÞ¼´¿ÉÔ¶³ÌÖ´ÐдúÂë¡£´Ë±í£¬»¹½¨¸´ÁË2¸öÌáȨ·ì϶£¨CVE-2022-20140ºÍCVE-2022-20145£©£¬ÒÔ¼°UnisocоƬÖеķì϶£¨CVE-2022-20210£©µÈ¡£
https://www.infosecurity-magazine.com/news/google-android-security-patches/
5¡¢EmotetµÄÐÂÄ£¿é¿ÉÇÔÈ¡´æ´¢ÔÚChromeÖеÄÐÅÓþ¿¨ÐÅÏ¢
ýÌå6ÔÂ8ÈÕ±¨Â·£¬×êÑÐÈËÔ±·¢ÏÖ½©Ê¬ÍøÂçEmotetÔÚʹÓÃÒ»¸öеÄÄ£¿é£¬À´ÇÔÈ¡´æ´¢ÔÚChromeÓû§ÅäÖÃÎļþÖеÄÐÅÓþ¿¨ÐÅÏ¢¡£Ëü»áÍøÂçÐÕÃû¡¢ÐÅÓþ¿¨µ½ÆÚÄêÔºͿ¨ºÅµÈÐÅÏ¢£¬¶øºó»á½«ÕâЩÐÅÏ¢·¢Ë͵½C2·þÎñÆ÷£¬¶ø²»ÊǸÃÐÅÏ¢ÇÔȡģ¿éËùʹÓõķþÎñÆ÷¡£EmotetÓÚ2014ÄêÆðÍ·»îÔ¾£¬ÔÚ2021ËêÊ×µÄÒ»´Î¹ú¼Ê·¨ÂÉÐж¯Öб»²ð³ý¡£ESETÔÚ±¾Öܶþй©£¬×Ô½ñÄêËêÊ×ÒÔÀ´£¬EmotetµÄ»î¶¯´ó·ùÔö³¤£¬±ÈT3 2021Ôö³¤ÁË100±¶ÒÔÉÏ¡£
https://www.bleepingcomputer.com/news/security/emotet-malware-now-steals-credit-cards-from-google-chrome-users/
6¡¢KELA°ä²¼2022ÄêµÚÒ»¼¾¶ÈÀÕË÷Èí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨
6ÔÂ2ÈÕ£¬ÒÔÉ«Áа²È«¹«Ë¾KELA°ä²¼ÁË2022ÄêµÚÒ»¼¾¶ÈÀÕË÷Èí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬2022ÄêQ1£¬ÀÕË÷Èí¼þ±»¹¥»÷Ö¸±êµÄ×ÜÊý½µÂäÁË40%£¬´Ó2021ÄêQ4µÄ982¸ö½µÖÁ698¸ö¡£LockBitÈ¡´úConti³ÉΪ2022ËêÊ×ÒÔÀ´×î»îÔ¾µÄÍŻ¹¥»÷ÁË226¸öÖ¸±ê£¬Õ¼±ÈΪ32%£¬Æä´ÎÊÇConti£¨18%£©¡¢Alphv£¨8%£©¡¢Hive£¨6%£©ºÍKarakurt£¨5%£©¡£ÃÀ¹úÊÇÔâµ½¹¥»÷×î¶àµÄ¹ú¶È£¨40%£©£¬Ö®ºóÊÇÓ¢¹ú¡¢Òâ´óÀû¡¢µÂ¹úºÍ¼ÓÄôó¡£
https://ke-la.com/wp-content/uploads/2022/06/KELA-RESEARCH-RANSOMWARE-VICTIMS-AND-NETWORK-ACCESS-SALES-IN-Q1-2022.pdf


¾©¹«Íø°²±¸11010802024551ºÅ