΢ÈíÒòÏòÓû§Ç¿¼Ó¸æ°×cookie±»·¨¹ú·£¿î6000ÍòÅ·Ôª

°ä²¼¹¦·ò 2022-12-26
1¡¢Î¢ÈíÒòÏòÓû§Ç¿¼Ó¸æ°×cookie±»·¨¹ú·£¿î6000ÍòÅ·Ôª

      

¾ÝýÌå12ÔÂ22ÈÕ±¨Â· £¬·¨¹úÒþÖÔ¼à¹Ü»ú¹¹ÒѶÔÃÀ¹ú¿Æ¼¼¿Æ¼¼¹«Ë¾Î¢Èí´¦ÒÔ6000ÍòÅ·Ôª£¨6400ÍòÃÀÔª£©µÄ·£¿î £¬Ô­ÒòÊÇÆäÏòÓû§Ç¿¼Ó¸æ°×cookie¡£¹ú¶È¼¼ÊõºÍ×ÔÓÉίԱ»á(CNIL)°µÊ¾ £¬Î¢ÈíµÄËÑË÷ÒýÇæBingδÉèÖÃÔÊÐíÓû§Ïñ½ÓÊÜcookieÒ»Ñùµ¥Ò»µØ»Ø¾øcookieµÄϵͳ¡£¸Ã¹«Ë¾Òѱ»´ÍÓëÈý¸öԵŦ·òÀ´¾ÀÕýÕâ¸öÎÊÌâ £¬ÓâÆÚ»¹¿ÉÄÜÃæ¶ÔÿÌì60000Å·ÔªµÄ½øÒ»²½·£¿î¡£Î¢ÈíÔÚÒ»·ÝÉêÃ÷ÖаµÊ¾ £¬ËüÔÚÕâÏîµ÷²éÆðͷ֮ǰ¾ÍÒѾ­¶Ôcookie×ö·¨½øÐÐÁ˳Á´ó¸ü¸Ä¡£


https://www.securityweek.com/france-fines-microsoft-60-million-euros-over-advertising-cookies


2¡¢°Ä´óÀûÑÇÀ¥Ê¿À¼¿Æ¼¼´óѧÔâµ½Royal TeamµÄÀÕË÷¹¥»÷

      

ýÌå12ÔÂ22ÈÕ³Æ £¬À¥Ê¿À¼¿Æ¼¼´óѧÔâµ½ÀÕË÷¹¥»÷ £¬µ¼ÖÂУ԰´òÓ¡»ú´òÓ¡´óÁ¿µÄÊê½ð¼Í¼¡£QUT¸±Ð£³¤Margaret Sheil°µÊ¾ËýµÄ´òÓ¡»úÒ²Êܵ½Ó°Ïì £¬Ò»ÏòµØ´òÓ¡Êê½ð¼Í¼ֱµ½´òÓ¡»úÀïµÄÖ½Õźľ¡¡£Êê½ð¼Í¼³ÆÀ´×ÔRoyal ransomware £¬ËüÔÚÖ®Ç°ÖØÒª¹¥»÷ÃÀ¹úµÄÒ½ÁÆ»ú¹¹¡£×÷ΪÏìÓ¦´ëÊ© £¬À¥Ê¿À¼¿Æ¼¼´óѧÒѹعØËùÓÐITϵͳ £¬²¢¶Ô¸ÃÊÂÎñ·¢Õ¹µ÷²é¡£


https://www.abc.net.au/news/2022-12-22/qld-qut-cyber-attack-printers-royal/101802692


3¡¢ºÚ¿ÍÏúÊ۾ݳƴÓBetMGMÇÔÈ¡µÄ³¬¹ý150Íò¿Í»§µÄÊý¾Ý

      

¾Ý12ÔÂ22ÈÕ±¨Â· £¬ÌåÓý²©²Ê¹«Ë¾BetMGMÅû¶ÁËһ·Êý¾Ýй¶ÊÂÎñ £¬³Æ²¿Ãſͻ§µÄÓ×ÎÒÐÅϢй¶¡£¸Ã¹«Ë¾²¹³ä˵ £¬ÆäÔÚ2022Äê11Ô·¢ÏÖ¸ÃÊÂÎñ £¬µ«¹¥»÷Ó¦¸ÃÊDzúÉúÔÚ2022Äê5Ô¡£ÃûΪbetmgmhackedµÄ¹¥»÷ÕßÔÚºÚ¿ÍÂÛ̳°ä²¼Êý¾ÝÏúÊ۵IJ¼¸æ £¬³ÆÆäÈëÇÖÁËBetMGMµÄÊý¾Ý¿â £¬ÆäÖÐÔ̺¬1569310ÌõÓû§¼Í¼ £¬Éæ¼°ÃÜЪ¸ùÖÝ¡¢ÐÂÔóÎ÷ÖݺͰ²´ÖÂÔÊ¡µÈ¿Í»§µÄÐÕÃû¡¢ÁªÏµ·½Ê½¡¢ºÍÉç»á°²È«ºÅÂëµÈÐÅÏ¢¡£¸Ã¹«Ë¾½«ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩÁ½ÄêµÄÃâ·ÑÐÅÓþ¼à¿ØºÍÉí·Ý¸´Ô­·þÎñ¡£


https://securityaffairs.co/wordpress/139949/data-breach/betmgm-discloses-security-breach.html


4¡¢×êÑÐÍŶÓÅû¶ÆôÓÃksmbdµÄSMB·þÎñÆ÷µÄLinuxÄں˷ì϶

      

12ÔÂ25ÈÕ±¨Â·³Æ £¬×êÑÐÍŶÓÅû¶ÁËÒ»¸öÑϳÁµÄLinuxÄں˷ì϶£¨CVSSÆÀ·ÖΪ10£© £¬»áÓ°ÏìÆôÓÃÁËksmbdµÄSMB·þÎñÆ÷¡£¸Ã·ì϶´æÔÚÓÚSMB2_TREE_DISCONNECTºÅÁîµÄ´¦Öùý³ÌÖÐ £¬ÊÇÔÚ¶Ô¶ÔÏóÖ´ÐвÙ×÷֮ǰûÓÐÑéÖ¤¶ÔÏóµÄ´æÔÚ¶øµ¼ÖµÄ £¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚÄÚºËÖÐÖ´ÐÐËÁÒâ´úÂë¡£×êÑÐÈËÔ±²¹³ä·¡£Ê¹ÓÃSambaµÄSMB·þÎñÆ÷²»ÊÜÓ°Ïì £¬Ê¹ÓÃksmbdµÄSMB·þÎñÆ÷ÈÝÒ×Êܵ½¶ÁÈ¡½Ó¼ûµÄÓ°Ïì £¬¿ÉÄÜй¶·þÎñÆ÷µÄÄڴ棨ÀàËÆÓÚHeartbleed·ì϶£©¡£½¨ÒéʹÓÃksmbdµÄÖÎÀíÔ±¸üе½8Ô°䲼µÄLinuxÄں˰汾5.15.61»ò¸ü¸ß°æ±¾¡£


https://securityaffairs.co/wordpress/140013/hacking/critical-linux-kernel-vulnerability.html


5¡¢Securonix·¢ÏÖÕë¶ÔÓ¡¶Èµ±¾ÖµÄ¹¥»÷»î¶¯STEPPY#KAVACH

      

¾Ý12ÔÂ23ÈÕ±¨Â· £¬Securonix·¢ÏÖÁËÕë¶ÔÓ¡¶Èµ±¾ÖµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯ £¬²¢½«Æä¶¨ÃûΪSTEPPY#KAVACH¡£¸Ã»î¶¯Óë°Í»ù˹̹ºÚ¿ÍÍÅ»ïSideCopyµÄTTPÓÐËù³Áµþ £¬ÖØÒªÕë¶ÔÓ¡¶Èµ±¾Ö¹ÙԱʹÓõÄË«³É·ÖÉí·ÝÑéÖ¤½â¾ö¹æ»®Kavach¡£¹¥»÷ʼÓÚ´¹µö»î¶¯ £¬¶øºóͨ¹ý.LNKÎļþÆô¶¯´úÂëÖ´ÐÐ £¬×îÖÕÏÂÔØ²¢ÔËÐжñÒâC# payload £¬³äÈÎÔ¶³Ì½Ó¼ûľÂí¡£Õâ²»ÊǵÚһ·Õë¶ÔKavachµÄ¹¥»÷ £¬×Ô½ñÄêËêÊ×ÒÔÀ´ £¬Transparent Tribe¾Íͨ¹ýKavachÖ÷ÌâµÄµö¶üÀûÓù¥»÷Ó¡¶È¡£ 


https://www.securonix.com/blog/new-steppykavach-attack-campaign/


6¡¢Wordfenceй©WP²å¼þ·ì϶CVE-2022-45359±»ÔÚÒ°ÀûÓÃ

      

WordfenceÔÚ12ÔÂ22ÈÕй© £¬ WordPress²å¼þYITH WooCommerce Gift Cards PremiumÖзì϶Òѱ»ÔÚÒ°ÀûÓ᣸÷ì϶׷×ÙΪCVE-2022-45359(CVSSÆÀ·ÖΪ9.8) £¬¿É±»Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÃÀ´ÔÚÒ×±»¹¥»÷µÄÍøÕ¾ÉÏ´«Îļþ £¬Ô̺¬Ìṩ¶Ô¸ÃÍøÕ¾ÆëÈ«½Ó¼ûȨÏÞµÄWeb shell¡£×êÑÐÈËÔ±³Æ £¬´óÎÞÊý¹¥»÷²úÉúÔÚ2022Äê11Ô £¬ÆäʱÖÎÀíÔ±ÉÐ佨¸´¸Ã·ì϶ £¬µ«ÔÚ12ÔÂ14ÈÕÓÖ³öÏÖÁ˵ڶþ¸ö¶¥·å¡£´Ë±í £¬Ò»¸ö³ÁÒªµÄIPµØÖ·¶Ô10936¸öÍøÕ¾ÌáÒéÁË19604´Î¹¥»÷³¢ÊÔ¡£Ä¿Ç°·ì϶ÀûÓù¥»÷ÈÔÔÚ½øÐÐÖÐ £¬½¨ÒéʹÓøòå¼þµÄÓû§¾¡¿ìÉý¼¶µ½3.21°æ±¾¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-bug-in-wordpress-gift-card-plugin-with-50k-installs/