MetaÒòÎ¥·´Å·ÃËÊý¾ÝÒþ˽·¨±»°®¶ûÀ¼· £¿î4.14ÒÚÃÀÔª

Ðû²¼Ê±¼ä 2023-01-06
1¡¢MetaÒòÎ¥·´Å·ÃËÊý¾ÝÒþ˽·¨±»°®¶ûÀ¼· £¿î4.14ÒÚÃÀÔª

      

¾ÝýÌå1ÔÂ5ÈÕ±¨µÀ£¬°®¶ûÀ¼Êý¾Ý± £»¤Î¯Ô±»á (DPC) ¶ÔMeta´¦ÒÔ3.9ÒÚÅ·Ôª£¨Ô¼ºÏ4.14ÒÚÃÀÔª£©µÄ· £¿î¡£Ô­ÒòÊÇÆäÇ¿ÆÈFacebookºÍInstagramÓû§Í¬ÒâΪ¶¨Ïò¹ã¸æ´¦ÖøöÈËÊý¾Ý£¬ÕâÎ¥·´ÁËÅ·Ã˵ÄGDPR¡£DPC¶ÔFacebookÏà¹ØµÄÎ¥¹æÐÐΪ· £¿î2.1ÒÚÅ·Ôª£¬²¢¶ÔInstagram· £¿î1.8ÒÚÅ·Ôª£¬»¹ÃüÁîMetaÔÚÈý¸öÔÂÄÚʹÆ䵱ǰµÄÊý¾Ý´¦ÖòÙ×÷ÇкÏGDPRµÄ¹æ¶¨¡£MetaÌåÏÖ£¬Ëü½«¶Ô²Ã¾öµÄʵÖÊÄÚÈݺͷ £¿îÌá³öÉÏËß¡£


https://thehackernews.com/2023/01/irish-regulators-fine-facebook-414.html


2¡¢ÆóҵЭ×÷ƽ̨Slack͸¶Æ䲿ÃÅ˽ÓдúÂë´æ´¢¿â±»µÁ

      

¾Ý1ÔÂ5ÈÕ±¨µÀ£¬ÆóҵЭ×÷ƽ̨Slack͸¶ÆäÔâµ½¹¥»÷£¬²¿ÃÅ˽ÓдúÂë´æ´¢¿â±»µÁ¡£SlackÓÚ2022Äê12ÔÂ29ÈÕ»ñϤ¿ÉÒɻ²¢¶ÔʼþÕ¹¿ªÊӲ죬·¢ÏÖ¹¥»÷Õßͨ¹ý±»µÁµÄSlackÔ±¹¤ÁîÅÆ»ñµÃÁËSlackÍⲿÍйܵÄGitHub´æ´¢¿âµÄ·ÃÎÊȨÏÞ¡£ÊӲ컹ÏÔʾ£¬¹¥»÷ÕßÒÑÓÚ2022Äê12ÔÂ27ÈÕÏÂÔØÁË˽ÓдúÂë´æ´¢¿â£¬µ«SlackµÄÖ÷Òª´úÂë¿âºÍ¿Í»§Êý¾Ý²»ÊÜÓ°Ïì¡£Slack»¹³Æ£¬´Ë´Îδ¾­ÊÚȨµÄ·ÃÎʲ»ÊÇÓÉSlackÖеÄ©¶´µ¼ÖµÄ£¬ËûÃÇ»¹½«¼ÌÐøÊÓ²ìºÍ¼à¿Ø½øÒ»²½µÄй¶¡£


https://www.bleepingcomputer.com/news/security/slacks-private-github-code-repositories-stolen-over-holidays/


3¡¢Ñо¿ÈËԱ͸¶·¨À­ÀûºÍ±¦ÂíµÈÖÆÔìÉÌʹÓÃÒ×±»¹¥»÷µÄAPI

      

ýÌå1ÔÂ4Èճƣ¬Ñо¿ÈËÔ±·¢ÏÖ·áÌï¡¢·¨À­ÀûºÍ±¦ÂíµÈ½ü20¼ÒÆû³µÖÆÔìÉ̺ͷþÎñ°üÂÞAPIÄþ¾²Â©¶´¡£ÕâЩ©¶´¿ÉÄܱ»ÓÃÓڹ㷺µÄ¶ñÒâ»î¶¯£¬ÀýÈç½âËø¡¢Æô¶¯¡¢¸ú×ÙÆû³µÒÔ¼°Ð¹Â¶¿Í»§µÄ¸öÈËÐÅÏ¢¡£ÀûÓÃijЩ©¶´£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÅäÖò»Í×µÄSSO·ÃÎÊÊý°Ù¸ö÷ÈüµÂ˹ÄÚ²¿Ó¦Ó÷¨Ê½¡¢ÔÚ¶à¸öϵͳÉÏÔ¶³ÌÖ´ÐдúÂëÒÔ¼°·ÃÎÊijЩϵͳÄÚ´æ¡£ÔÚBMWµÄ°¸ÀýÖУ¬Ñо¿ÈËÔ±·¢ÏÖÁËSSO©¶´£¬¿ÉÓÃÀ´·ÃÎÊÄÚ²¿¾­ÏúÉÌÃÅ»§£¬²éѯÆû³µµÄVIN²¢¼ìË÷°üÂÞ³µÖ÷ÏêϸÐÅÏ¢µÄÏúÊÛÎļþ¡£


https://securityaffairs.com/140328/hacking/bmw-mercedes-toyota-other-carmakers-flaws.html


4¡¢K7 Labs·¢ÏÖÀûÓÃWindows´íÎó³ÂËß¹¤¾ß·Ö·¢¶ñÒâÈí¼þµÄ»î¶¯

      

K7 LabsÓÚ1ÔÂ4ÈÕ³ÆÆä·¢ÏÖÁËÀûÓÃWindows´íÎó³ÂËß¹¤¾ßWerFault.exe·Ö·¢¶ñÒâÈí¼þµÄ»î¶¯¡£¸Ã»î¶¯Ê¼ÓÚÒ»·â´øÓÐISO¸½¼þµÄµç×ÓÓʼþ£¬Ë«»÷ʱISO»á½«×Ô¼º¹ÒÔØΪһ¸öеÄÅÌ·û£¬ÆäÖаüÂÞWerFault.exeµÄºÏ·¨¸±±¾¡¢Ò»¸öDLLÎļþÒ»¸öXLSÎļþºÍÒ»¸ö¿ì½Ý·½Ê½Îļþ¡£É±¶¾¹¤¾ßͨ³£ÐÅÈÎWerFault£¬Òò´ËÔÚϵͳÉÏÆô¶¯Ëüͨ³£²»»á´¥·¢¾¯±¨¡£Æô¶¯WerFault.exeʱ£¬Ëü½«Ê¹ÓÃDLL²à¼ÓÔØ©¶´À´¼ÓÔØISOÖаüÂ޵ĶñÒâDLL Faultrep.dll£¬×îÖÕÖ´ÐÐPupy RAT¡£


https://labs.k7computing.com/index.php/pupy-rat-hiding-under-werfaults-cover/


5¡¢É罻ƽ̨Cricketsocial.comÓû§ÐÅÏ¢ºÍ¹ÜÀíԱƾ¾Ýй¶

      

1ÔÂ4ÈÕ±¨µÀ³Æ£¬CyberNews·¢ÏÖ°åÇòÉ罻ƽ̨Cricketsocial.comй¶ÁËÁè¼Ý10ÍòÌõÓû§¸öÈËÐÅÏ¢ºÍƾ¾Ý¡£¸ÃÊý¾Ý¿âÓÉÃÀ¹úAWSÍйÜ£¬°üÂÞµç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢ÐÕÃû¡¢Óû§ÃÜÂë¡¢³öÉúÈÕÆں͵ØÖ·µÈÐÅÏ¢¡£ÆäÖдó²¿ÃżÇ¼Ëƺõ¶¼ÊDzâÊÔÊý¾Ý£¬µ«ÈÔÈ»°üÂ޺Ϸ¨ÍøÕ¾Óû§µÄPIIÐÅÏ¢¡£Ñо¿ÈËÔ±»¹·¢ÏÖ¸ÃÊý¾Ý¿â»¹Ð¹Â¶ÁËÃ÷ÎÄÐÎʽ´æ´¢µÄÍøÕ¾¹ÜÀíԱƾ¾Ý£¬¿É±»¹¥»÷ÕßÓÃÀ´½Ó¹Üƽ̨¡£


https://securityaffairs.com/140329/data-breach/cricketsocial-com-data-leak.html


6¡¢ZohoÐÞ¸´ManageEngineÖÐSQL×¢È멶´CVE-2022-47523

      

ýÌå1ÔÂ4ÈÕ±¨µÀ³Æ£¬Zoho¶Ø´Ù¿Í»§ÐÞ¸´Ó°ÏìÁ˶à¸öManageEngine²úÎïµÄÄþ¾²Â©¶´¡£Â©¶´×·×ÙΪCVE-2022-47523£¬ÊÇPassword Manager Pro¡¢PAM360ºÍAccess Manager PlusÖз¢ÏÖµÄSQL×¢È멶´¡£¹¥»÷ÕßÀûÓø鶴¿É»ñµÃºó¶ËÊý¾Ý¿âµÄ·ÃÎÊȨÏÞ£¬²¢Ö´ÐÐ×Ô½ç˵²éѯÒÔ·ÃÎÊÊý¾Ý¿â±íÌõÄ¿¡£Zoho³ÆÆäÒѾ­Í¨¹ýתÒåÌØÊâ×Ö·ûºÍÌí¼ÓÊʵ±µÄÑéÖ¤½â¾öÁ˸ÃÎÊÌâ¡£¼øÓÚ´Ë©¶´µÄÑÏÖØÐÔ£¬¸Ã¹«Ë¾Ç¿ÁÒ½¨Òé¿Í»§Á¢¼´Éý¼¶µ½×îа汾¡£


https://www.bleepingcomputer.com/news/security/zoho-urges-admins-to-patch-critical-manageengine-bug-immediately/