ÍøÂç·¸×ï·Ö×ÓÔÚÕ«ÔºͿªÕ«½ÚÆÚ¼ä·è¿ñÍøÂçÚ¿Æ
°ä²¼¹¦·ò 2024-03-261. ÍøÂç·¸×ï·Ö×ÓÔÚÕ«ÔºͿªÕ«½ÚÆÚ¼ä·è¿ñÍøÂçÚ¿Æ
3ÔÂ24ÈÕ£¬Õ«ÔÂÆÚ¼ä£¬Resecurity¹Û²ìµ½Ú²Æ»î¶¯ºÍÚ¿Æ´ó·ùÔö³¤£¬Í¬Ê±ÁãÊÛºÍÔÚÏßÂòÂô¼¤Ôö¡£Ãæ¶ÔÕâÒ»¼Ó¾ç·çÏÕµÄÖж«ÆóÒµ±»¶½´Ù¼ÓÇ¿Ïû·ÑÕß±£»¤²¢¼ÓÇ¿Æ·ÅÆ°²È«¡£ÖµÍ×ÌùÐĵÄÊÇ£¬É³Ìذ¢À²®Íõ¹ú (KSA) µÄÏû·ÑÕßÖ§³ö³¬¹ý 160 ÒÚÃÀÔª£¬Î»¾ÓµØÓòÅÅÐаñÊ×λ¡£²»ÐÒµÄÊÇ£¬µç×ÓÉÌÎñ»î¶¯µÄ¼¤ÔöÒýÆðÁËÍøÂç·¸×ï·Ö×ÓÈ·°ÑÎÈ£¬ËûÃÇÀûÓÃÕâЩƽִ̨ÐÐÚ¿Æ£¬¸øÏû·ÑÕßºÍÆóÒµ´øÀ´Á˾޴óµÄ²ÆÕþÓ°Ïì¡£ÕâЩ»î¶¯µÄ×ܲÆÕþÓ°Ïì¹À¼ÆÔÚ 70 ÖÁ 1 ÒÚÃÀÔªÖ®¼ä£¬ÆäÖÐÔ̺¬Õë¶Ô±í¼®ÈËÊ¿¡¢¾ÓÃñºÍ±í¹úÓο͵ÄÚ²ÆÐÐΪ¡£ÓÉÓÚ³ÖÐøÖÂÁ¦ÎªÖж«ºÜ¶à¿Í»§Ìá¹©Æ·ÅÆ±£»¤£¬Resecurity ÒÑÓÐЧ×èÖ¹ÁË 320 ¶à¸ö¼ÙÒâÖØÒªÎïÁ÷ÌṩÉ̺͵ç×ÓÕþÎñ·þÎñµÄÚ²Æ×ÊÔ´¡£ÍøÂç·¸×ï·Ö×Ó»ý¼«ÀûÓà Sadad¡¢Musaned¡¢Ajeer¡¢Ejar µÈƽ̨ÒÔ¼°³ÛÃûÎïÁ÷·þÎñÀ´ºýŪ»¥ÁªÍøÓû§£¬²¢½«ËûÃÇÒýÈë·ÖÆçµÄȦÌס£Ç¿ÁÒ½¨Òé²»ÒªÔÚ¿ÉÒÉÍøÕ¾ÉÏ»òÓë¼ÙÒâÒøÐлòµ±¾Ö¹ÍÔ±µÄÓ×ÎÒ·ÖÏíÓ×ÎҺ͸¶¿îÐÅÏ¢¡£
https://securityaffairs.com/161009/cyber-crime/cybercriminals-accelerate-scams-ramadan.html
2. OpenVPN ½¨¸´ Windows ÖеĶà¸öÑϳÁ·ì϶
3ÔÂ24ÈÕ£¬OpenVPN ÒѰ䲼³ÁÒª°²È«¸üУ¨°æ±¾ 2.6.10£©£¬ÒÔ½â¾öÆä Windows Èí¼þÖеÄһϵÁзì϶£¬ÕâЩ·ì϶¿ÉÄܵ¼ÖÂȨÏÞÉý¼¶¡¢Ô¶³Ì¹¥»÷ºÍϵͳ±ÀÀ£¡£ÕâЩ·ì϶͹ÏÔÁ˶¨ÆÚÈí¼þ¸üеıØÒªÐÔ£¬³ö¸ñÊǶÔÓÚ OpenVPN µÈ´¦ÖÃÍøÂçÁ÷Á¿µÄ¹¤¾ß¡£±¾´Î¸üеķì϶Ô̺¬CVE-2024-27459£¨²Ö¿âÒç³ö±£»¤£©¡¢CVE-2024-24974£¨Ô¶³Ì½Ó¼ûÏÞ¶È£©¡¢CVE-2024-27903£¨²å¼þ¼ÓÔØÏÞ¶È£©ºÍCVE-2024-1305£¨TAP Çý¶¯·¨Ê½Òç³ö½¨¸´£©¡£
https://securityonline.info/openvpn-patches-serious-vulnerabilities-in-windows-installations/
3. Vans Ðû³ÆÍøÂçÆ×Ó²¢Î´ÇÔÈ¡¿Í»§µÄ²ÆÕþÐÅÏ¢
3ÔÂ24ÈÕ£¬·þ×°ºÍЬÀà¾ÞÍ· VF Corporation Ïò 3550 Íò¿Í»§´«µÝ£¬¼ÌÈ¥ÄêµÄ°²È«·ì϶֮ºó£¬ËûÃÇ¿ÉÄÜ»á³ÉΪÉí·Ý͵ÇÔµÄÊܺ¦Õß¡£Vans ºÍ North Face ĸ¹«Ë¾ÔÚ¸ø¿Í»§µÄÒ»·âµç×ÓÓʼþÖгÐŵ£¬Æ×Ó²»»áµÁÈ¡ËûÃǵÄÐÅÓþ¿¨»òÒøÐÐÕË»§¾ßÌåÐÅÏ¢¡£²¢ÇÒ£¬Ëü²¹³ä˵£¬¡°Ã»ÓÐÖ¤¾Ý¡±Åú×¢Èκα»µÁµÄÓ×ÎÒÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþ¡¢µØÖ·ºÍµç»°ºÅÂ룬Òѱ»ÓÃÓÚа¶ñÖ÷ÕÅ¡£ÕâЩ¼Í¼ÊÇÔÚ VF ÓÚ 12 Ô 13 ÈÕÅû¶µÄÊý×ÖÈëÇÖ¹ý³ÌÖб»½Ó¼û»ò»ñÈ¡µÄ¡£Õâ´ÎÈëÇÖÇÖÈÅÁËÕâ¼Ò·þ×°Ôì×÷É̵ÄÔËÓª¼°ÆäÈÃÈËÃÇ´©´÷¸ßµµ±íÌ×µÄÄÜÁ¦¡£¹ÌÈ» VF Æäʱ²¢Î´½«Õâ´ÎÍøÂ簲ȫÊÂÎñ³ÆÎªÀÕË÷Èí¼þ£¬µ«ÆäÔÚ¼à¹ÜÎļþÖоßÌåÃèÊöÕâ´ÎÈëÇֵĴë´ÇʹÆäÌýÆðÀ´¼«¶ÈÏñ´øÓÐÀÕË÷ÒªÇóµÄÀÕË÷Èí¼þϰȾ¡£ÔÚÏòÃÀ¹ú֤ȯÂòÂôίԱ»á (SEC) Ìá½»µÄ×îР8-K ÎļþÖУ¬Õâ¼Ò·þ×°ÏúÊÛÉÌÅû¶£¬Æä3550 Íò¿Í»§Êܵ½ IT °²È«·ì϶µÄÓ°Ï죬µ«¶ÔÆ×Ó¿ÉÄÜÇÔÈ¡µÄÊý¾ÝÈ´³éÏóÆä´ÇÔÚ¹¥»÷ÆÚ¼ä¡£
https://www.theregister.com/2024/03/24/vans_breach_disclosure/
4. ÓÐÏßµçÊÓ ISP ÒòÏò FCC »Ñ±¨¿í´øµØÖ·¶ø±»·£¿î
3ÔÂ23ÈÕ£¬Ò»¼Ò»¥ÁªÍø·þÎñÌṩÉÌÈÏ¿ÉÔÚÆäÌṩ¿í´øµÄµØÖ··½ÃæÏò FCC ˵»Ñ£¬½«Ö§¸¶ 10,000 ÃÀÔªµÄ·£¿î£¬²¢Ö´ÐкϹæ´òËãÒÔÔ¤·À½«À´³öÏÖÎ¥¹æÐÐΪ¡£ArsTechnica£º¶íº¥¶íÖݶàÂ×¶àµÄÒ»¼ÒÓ×ÐÍ ISP ½Üì³Ñ·ÏصçÀ (JCC) ÈϿɣ¬ËüÃýÎóµØÐû³ÆÔÚÉÐδÀ©´óµ½µÄµØÓòÌṩ¹âÏË·þÎñ¡£Ò»Î»¹«Ë¾¸ß¹Ü»¹ÈϿɣ¬¸Ã¹«Ë¾Ìá½»ÁËÐéαµÄ¸²¸ÇÊý¾Ý£¬ÒÔ×èÖ¹ÆäËû»¥ÁªÍø·þÎñÌṩÉÌ»ñÇе±¾Ö²¦¿îÀ´Îª¸ÃµØÓòÌṩ·þÎñ¡£Ars ÔÚ 2023 Äê 2 ÔµÄһƪÎÄÕÂÖÐÔ®Êָ淢ÁËÕâÒ»ÊÂÎñ¡£FCC ÓÚ 3 Ô 15 ÈÕ°ä²¼Á˵÷²éÁ˾֣¬³Æ Jefferson County Cable Î¥·´ÁË¿í´øÊý¾ÝÍøÂç´òËãµÄÒªÇóºÍÃÀ¹ú˾·¨¡¶¿í´øÊý¾Ý·¨°¸¡·¡£
https://ordonews.com/cable-isp-fined-10000-for-lying-to-fcc-about-where-it-offers-broadband/
5. µÂ¹úµ±¾Ö°ä·¢È¡µÞÃûΪNemesis MarketµÄ°µÍøÊг¡
3ÔÂ24ÈÕ£¬µÂ¹úµ±¾Ö°ä·¢È¡µÞÒ»¸öÃûΪNemesis MarketµÄ·¸·¨µØÏÂÊг¡£¬¸ÃÊг¡¶µÏú¶¾Æ·¡¢±»µÁÊý¾ÝºÍ¸÷ÀàÍøÂç·¸×ï·þÎñ¡£Áª¹úÐÌʾ¯Ô±¾Ö£¨±ðÃû Bundeskriminalamt »ò BKA£©°µÊ¾£¬Ëü²é»ñÁËλÓڵ¹úºÍÁ¢ÌÕÍðµÄÓë°µÍø·þÎñÓйصÄÊý×Ö»ù´¡ÉèÊ©£¬²¢³ä¹«ÁË 94,000 Å·Ôª£¨102,107 ÃÀÔª£©µÄ¼ÓÃÜÇ®±Ò×ʲú¡£Õâ´ÎÐж¯ÊÇÓëµÂ¹ú¡¢Á¢ÌÕÍðºÍÃÀ¹úµÄ·¨ÂÉ»ú¹¹ºÏ×÷½øÐеģ¬ÓÚ 2022 Äê 10 ÔÂÆðÍ·½øÐÐ¿í·ºµ÷²éºó£¬ÓÚ 2024 Äê 3 Ô 20 ÈÕ½øÐС£Nemesis Market ³ÉÁ¢ÓÚ 2021 Ä꣬¹À¼ÆÔڹعØÖ®Ç°Õ¼ÓÐÀ´×ÔÊÀ½ç¸÷µØµÄ³¬¹ý 150,000 ¸öÓû§ÕÊ»§ºÍ 1,100 ¸öÂô¼ÒÕÊ»§¡£½ü 20 ÃÀÔªµÄÂô¼ÒÕË»§À´×Ե¹ú¡£½ü¼¸¸öÔÂÀ´£¬µÂ¹úµ±¾Ö»¹È¡µÞÁËKingdom MarketºÍCrimemarket£¬ÕâÁ½¸öÍøÕ¾¶¼Óµº±¼ûǧÃûÓû§£¬²¢Ìṩ¿í·ºµÄÏ´Ç®ºÍÍøÂç·¸×ï·þÎñ¡£
https://thehackernews.com/2024/03/german-police-seize-nemesis-market-in.html
6. ¼à¹Ü»ú¹¹¶Ô×¼¿Æ¼¼ÐÐÒµ£¬¹È¸èºÍÆ»¹û·Ö²ðÌáÉÏÈÕ³Ì
3ÔÂ24ÈÕ£¬´óÎ÷ÑóÁ½°¶µÄ·´Â¢¶Ï¼à¹Ü»ú¹¹ÔÚ½ø¹¥¿ÉÄܵ¼ÖÂÆ»¹ûºÍ Alphabet ÆìϹȸ豻·Ö²ðµÄ·´¾ºÕùÐÐΪ£¬´óÐͿƼ¼¹«Ë¾ÕýÃæ¶ÔÊýÊ®ÄêÀ´µÄ×î´óÌôÕ½¡£Òµ½ç³õ´´¡£Õâ·´¹ýÀ´¿ÉÄÜ»áÒý·¢ÊÀ½ç¸÷µØµÄ¼à¹Ü»ú¹¹¼Ó´óÁ¦¶È£¬Å·Ã˺ÍÃÀ¹ú°¸¼þÁ¢°¸ºóÁйú·´Â¢¶Ïµ÷²éÊýÁ¿²»ÐÝÔö³¤¾ÍÖ¤ÁËÈ»ÕâÒ»µã¡£×ÔAT&TÔÚÕûÕû40Äêǰ·Ö²ðÒÔÀ´£¬Æù½ñΪֹ£¬ÔÚÃÀ¹ú»¹Ã»ÓÐÒ»¼Ò¹«Ë¾Ãæ¶Ô¼à¹Ü»ú¹¹Ö÷µ¼·Ö²ðµÄ¿ÉÄÜÐÔ¡£¹È¸è°µÊ¾²»ÔÞ³ÉÅ·Ã˵ÄÖ¸¿Ø£¬¶øÆ»¹ûÔò°µÊ¾ÃÀ¹úµÄËßËÏÔÚÊÂʵºÍ˾·¨É϶¼ÊÇÃýÎóµÄ¡£Ä¿Ç°Éв»È·¶¨¼à¹Ü»ú¹¹ÊÇ·ñ»á°ä²¼·Ö²ðÁÓÉÓÚËûÃÇÔÚ˼¿¼¸÷ÀàÑ¡Ôñ£¬ÈκÎÐж¯¶¼¿ÉÄܵ¼Ö·£¿î¡£
https://www.reuters.com/technology/google-apple-breakups-agenda-global-regulators-target-tech-2024-03-24/


¾©¹«Íø°²±¸11010802024551ºÅ