MetaºÍÃÀ¹úÁ½¼ÒÒ½ÁÆ»ú¹¹±»¸æ×´ÍøÂ综ÕßÐÅϢͶ·Å¸æ°×

°ä²¼¹¦·ò 2022-08-01
1¡¢MetaºÍÃÀ¹úÁ½¼ÒÒ½ÁÆ»ú¹¹±»¸æ×´ÍøÂ综ÕßÐÅϢͶ·Å¸æ°×

      

¾ÝýÌå7ÔÂ30ÈÕ±¨Â·£¬¼ÓÖݱ±Çø¶ÔMeta¡¢UCSFÒ½ÁÆÖÐÐĺÍDignity½¡È«Ò½ÁÆ»ù½ð»áÌáÆð¼¯ÌåËßËÏ£¬Ö¸¿ØËûÃÇ·¸·¨ÍøÂçÓйػ¼ÕßµÄÒ½ÁÆÊý¾Ý²¢ÓÃÓÚ¶¨ÏòͶ·Å¸æ°×¡£·¨ÔºÎļþÏÔʾ£¬»¼ÕßÔÚFacebookºÍÓÊÏäÖÐÊÕµ½ÁËÓÐÕë¶ÔÐԵĸæ°×£¬ÕâЩ¸æ°×ÔÚûÓпÆÑ§Ö§³ÖµÄÇé¿öÏÂÐû´«¼²²¡ºÍÒ½ÁÆ·þÎñ¡£Meta PixelÊÇÒ»¶Î´úÂ룬Äܹ»×¢ÈëÈκÎÍøÕ¾£¬ÒÔ½øÐзÿͷÖÎö¡¢Êý¾ÝÍøÂçºÍ¶¨ÏòͶ·Å¸æ°×¡£Æ¾¾ÝͶËߣ¬±»·¢ÏÖʹÓÃÁËMeta PixelµÄ33¼ÒÒ½Ôº½öÔÚ2020Äê¾Í¹²ÊÕÖÎÁË2600¶àÍòÃû»¼Õß¡£


https://www.bleepingcomputer.com/news/security/meta-us-hospitals-sued-for-using-healthcare-data-to-target-ads/


2¡¢ShinyHuntersÍÅ»ïµÄ³ÁÒª³ÉÔ±ÔÚÀ­°ÍÌØ¹ú¼Ê»ú³¡±»²¶ 

      

ýÌå7ÔÂ31Èճƣ¬Èû°Í˹µÙ°²¡¤À­ÎÚ¶û£¨±ðÃûSezyo£©ÓÚ2022Äê6ÔÂ1ÈÕÔÚÀ­°ÍÌØ¹ú¼Ê»ú³¡±»²¶¡£ËûÊÇShinyHuntersÍÅ»ïµÄ³ÁÒª³ÉÔ±Ö®Ò»£¬ÔøÈëÇÖÁËÊý°Ù¸öÃÀ¹ú×éÖ¯¡£³ýÁËÀ­ÎÚ¶û£¬»¹ÓÐÆäËû4Ãû·¨¹ú¾ÓÃñÓ¦Áª¹úµ÷²é¾ÖµÄÒªÇó½ÓÊÜÁËÎÊѶ¡£ÃÀ¹ú´Ë¿ÌÒªÇóÒÔÍøÂçڲƭºÍÍøÂç·¸×ïµÄÖ¸¿Ø½«ÏÓÒÉÈËÒý¶Éµ½ÃÀ¹ú£¬È»¶øÀ­ÎÚ¶ûµÄÂÉʦ»Ø¾øÁËÕâÒ»ÒªÇ󣬳Ƹð¸¼þÊôÓÚ·¨¹ú¹ÜϽÁìÓò£¬ÓÉÓÚÎ¥·¨ÐÐΪÊÇÓÉ·¨¹ú¹úÃñÔÚ·¨¹ú½øÐеÄ¡£·¨¹úL'Obs±¨Â·£¬ÏÓÒÉÈ˱»²¶ºóÒ»Ïò±»¹ØÑºÔÚTiflet¼àÓü£¬²¢Ãæ¶Ô×Å116ÄêµÄ½ûïÀ¡£


https://www.hackread.com/alleged-shinyhunters-hacker-group-member-arrested/


3¡¢AdrasteaÐû³ÆÒÑÈëÇÖÅ·ÖÞµ¼µ¯Ôì×÷ÉÌMBDA²¢ÇÔÈ¡60GBÊý¾Ý

      

¾Ý7ÔÂ31ÈÕ±¨Â·£¬AdrasteaÐû³ÆÒÑÈëÇÖMBDA²¢ÇÔÈ¡60 GBÊý¾Ý¡£MBDAÊÇÅ·ÖÞµÄÒ»¼Ò¿ç¹úµ¼µ¯¿ª·¢É̺ÍÔì×÷ÉÌ£¬ÓÉ·¨¹ú¡¢Ó¢¹úºÍÒâ´óÀûÖØÒªµÄµ¼µ¯ÏµÍ³¹«Ë¾£¨A¨¦rospatiale¨CMatra¡¢BAE SystemsºÍFinmeccanica£©¹é²¢¶ø³É¡£Adrastea°µÊ¾£¬ËûÃÇÔÚ¹«Ë¾µÄ»ù´¡ÉèÊ©Öз¢ÏÖÁËÑϳÁ·ì϶£¬²¢ÒÑÏÂÔØÉæ¼°¾üÊÂÏîÄ¿¡¢Ã³Ò׻¡¢ºÏͬºÍ̸ÒÔ¼°ÓëÆäËü¹«Ë¾Í¨Ñ¶ÐÅÏ¢µÄ60 GBÊý¾Ý¡£×÷Ϊ¹¥»÷µÄÖ¤¾Ý£¬Adrastea°ä²¼ÁËÒ»¸öÁ´½Ó£¬Ô̺¬ÓëÏîÄ¿ºÍͨѶÓйصÄÄÚ²¿Îļþ¡£Ä¿Ç°£¬Éв»Ã÷ÏÔ¹ØÓÚÕâ´Î¹¥»÷µÄϸ½ÚÐÅÏ¢¡£


https://securityaffairs.co/wordpress/133881/data-breach/mbda-alleged-data-breach.html


4¡¢SharpTongueÀûÓöñÒâä¯ÀÀÆ÷À©´óÇÔȡָ±êµÄÓʼþÊý¾Ý

      

¾ÝVolexityÔÚ7ÔÂ28ÈÕ±¨Â·£¬³¯ÏʺڿÍÍÅ»ïSharpTongueÔÚ»ùÓÚChromiumµÄä¯ÀÀÆ÷Éϲ¿Êð¶ñÒâÀ©´ó·¨Ê½£¬Ö¼ÔÚ´ÓGmailºÍAOLÇÔÈ¡µç×ÓÓʼþÊý¾Ý¡£¾ÝϤ£¬¸ÃÍÅ»ïÓëÒ»¸ö³ÆÎªKimsukyµÄÍÅ»ïÓÐËù³Áµþ¡£SharpTongueÖØÒªÕë¶ÔΪÃÀ¹ú¡¢Å·Ö޺ͺ«¹úµÄ×éÖ¯¹¤×÷£¬´ÓÊÂÉæ¼°³¯ÏÊ¡¢ºËÎÊÌâ¡¢±øÆ÷ϵͳµÈ¶Ô³¯ÏÊÓµÓÐÕ½ÊõÒâ˼µÄÎÊÌâµÄÖ¸±ê¡£ÔÚÕâ´Î»î¶¯ÖУ¬¹¥»÷ÕßÊ×ÏÈ´Ó±»Ï°È¾µÄÍøÕ¾ÊÖ¶¯ÇÔȡװÖÃÀ©´óËùÐèµÄÎļþ£¬Ò»µ©³É¹¦¹¥»÷Ö¸±êWindowsϵͳ£¬¾Í»á´úÌæä¯ÀÀÆ÷µÄÊ×Ñ¡ÏîºÍ°²È«Ê×Ñ¡ÏÔÙͨ¹ýVBS¾ç±¾ÊÖ¶¯×°ÖöñÒâÀ©´óSHARPEXT¡£


https://www.volexity.com/blog/2022/07/28/sharptongue-deploys-clever-mail-stealing-browser-extension-sharpext/


5¡¢Ó¢¹úWooton UpperѧÌÃÔâµ½Hive¹¥»÷±»ÀÕË÷50ÍòÓ¢°÷

      

ýÌå7ÔÂ28Èճƣ¬Ó¢¹ú±´µÂ¸£µÂ¿¤µÄWooton Upper SchoolÔâµ½¹¥»÷ºó£¬±»ÀÕË÷500000Ó¢°÷¡£¹¥»÷Ô´ÓÚHive£¬¸ÃÍÅ»ïÒÑÏòѧÉúºÍ¼Ò³¤·¢ËÍÐÂÎÅ£¬³ÆËûÃÇÔÚÊýÖÜǰÈëÇÖÁËWoottonµÄϵͳ£¬²¢Éè·¨¼ÓÃÜÁËWoottonËùÓеķþÎñÆ÷£¬Ô̺¬½ð²®ÀûѧԺ(Kimberley College)£¬ÇÔÈ¡Á˼Òͥסַ¡¢ÒøÐоßÌåÐÅÏ¢¡¢Ò½ÁƼͼºÍѧÉúµÄÉúÀíÆÀ¹ÀµÈÐÅÏ¢¡£¸ÃѧÌÃÕÆ¹ÜÈËÒÑÈ·ÈÏÔâµ½ÁËÍøÂç¹¥»÷£¬ËûÃÇÔÚÔì¶©´òËãÀ´³Á½¨ÆäITϵͳ¡£Ä¿Ç°ÎÞ·¨È·¶¨¸´Ô­ËùÐ蹦·ò£¬µÚÈý·½½¨ÒéΪ7µ½10¸ö¹¤×÷ÈÕ¡£


https://www.infosecurity-magazine.com/news/ransomware-group-500000-school/


6¡¢ENISA°ä²¼¹ØÓÚ2021Äê³Á´óµçÐŰ²È«ÊÂÎñµÄ»ã×ܻ㱨

      

7ÔÂ28ÈÕ±¨Â·£¬ENISA°ä²¼¹ØÓÚ2021Äê³Á´óµçÐŰ²È«ÊÂÎñµÄ»ã×ܻ㱨¡£»ã±¨Ô̺¬ÁËÀ´×Ô26¸öÅ·Ã˳ÉÔ±¹ú(MS)ºÍ2¸öEFTA¹ú¶ÈÈ·µ±¾ÖÌá½»µÄ168ÆðÊÂÎñ»ã±¨µÄÓйØÊý¾Ý£¬Óû§ËðʧµÄ×ܹ¦·ò£¨Í¨¹ý¶Ôÿ¸öÊÂÎñµÄÓû§Êý³ËÒÔÓ×ʱÊýµÃ³ö£©Îª51.06ÒÚ¸öÓû§Ó×ʱ¡£2021ÄêÉϱ¨µÄÊÂÎñÖÐÓÐ4.16%Éæ¼°OTTͨÕÛ·þÎñ£»±»ÏóÕ÷Ϊ¶ñÒâÊÂÎñÊýÁ¿´Ó2020ÄêµÄ4%ÉÏÉýµ½2021ÄêµÄ8%£»ÏµÍ³¹ÊÕÏÈÔÔÚÓ°Ïì·½ÃæÕ¼¾ÝÖ÷µ¼Ö°Î»£¬ÔÚ2021ÄêÔì³ÉÁË3.63ÒÚÓû§Ó×ʱµÄËðʧ£¬¶ø2020ÄêΪ4.19ÒÚ¡£


https://securityaffairs.co/wordpress/133756/reports/telecom-security-incidents-2021-enisa.html