ÍøÂç·¸×ï·Ö×ÓÔÚÕ«ÔºͿªÕ«½ÚÆÚ¼ä·è¿ñÍøÂçÕ©Æ­

Ðû²¼Ê±¼ä 2024-03-26

1. ÍøÂç·¸×ï·Ö×ÓÔÚÕ«ÔºͿªÕ«½ÚÆÚ¼ä·è¿ñÍøÂçÕ©Æ­


3ÔÂ24ÈÕ £¬Õ«ÔÂÆÚ¼ä £¬ResecurityÊӲ쵽ÆÛÕ©»î¶¯ºÍÕ©Æ­´ó·ùÔö¼Ó £¬Í¬Ê±ÁãÊÛºÍÔÚÏß½»Ò×¼¤Ôö ¡£ÃæÁÙÕâÒ»¼Ó¾ç·çÏÕµÄÖж«ÆóÒµ±»¶Ø´Ù¼ÓÇ¿Ïû·ÑÕß± £»¤²¢¼ÓÇ¿Æ·ÅÆÄþ¾² ¡£ÖµµÃ×¢ÒâµÄÊÇ £¬É³Ìذ¢À­²®Íõ¹ú (KSA) µÄÏû·ÑÕßÖ§³öÁè¼Ý 160 ÒÚÃÀÔª £¬Î»¾ÓµØÓòÅÅÐаñÊ×λ ¡£²»ÐÒµÄÊÇ £¬µç×ÓÉÌÎñ»î¶¯µÄ¼¤ÔöÒýÆðÁËÍøÂç·¸×ï·Ö×ÓµÄ×¢Òâ £¬ËûÃÇÀûÓÃÕâЩƽ̨ʵʩթƭ £¬¸øÏû·ÑÕßºÍÆóÒµ´øÀ´Á˾޴óµÄ²ÆÕþÓ°Ïì ¡£ÕâЩ»î¶¯µÄ×ܲÆÕþÓ°ÏìÔ¤¼ÆÔÚ 70 ÖÁ 1 ÒÚÃÀÔªÖ®¼ä £¬ÆäÖаüÂÞÕë¶ÔÍâ¼®ÈËÊ¿¡¢¾ÓÃñºÍÍâ¹úÓÎ¿ÍµÄÆÛÕ©ÐÐΪ ¡£ÓÉÓÚÁ¬ÐøÅ¬Á¦ÎªÖж«Ðí¶à¿Í»§Ìá¹©Æ·ÅÆ± £»¤ £¬Resecurity ÒÑÓÐЧ×èÖ¹ÁË 320 ¶à¸öð³äÖ÷ÒªÎïÁ÷ÌṩÉ̺͵ç×ÓÕþÎñ·þÎñµÄÆÛÕ©×ÊÔ´ ¡£ÍøÂç·¸×ï·Ö×Ó»ý¼«ÀûÓà Sadad¡¢Musaned¡¢Ajeer¡¢Ejar µÈƽ̨ÒÔ¼°ÖªÃûÎïÁ÷·þÎñÀ´ÆÛÆ­»¥ÁªÍøÓû§ £¬²¢½«ËûÃÇÒýÈë²îÒìµÄÆ­¾Ö ¡£Ç¿ÁÒ½¨Òé²»ÒªÔÚ¿ÉÒÉÍøÕ¾ÉÏ»òÓëð³äÒøÐлòÕþ¸®¹ÍÔ±µÄ¸öÈË·ÖÏí¸öÈ˺͸¶¿îÐÅÏ¢ ¡£


https://securityaffairs.com/161009/cyber-crime/cybercriminals-accelerate-scams-ramadan.html


2. OpenVPN ÐÞ¸´ Windows ÖеĶà¸öÑÏÖØÂ©¶´


3ÔÂ24ÈÕ £¬OpenVPN ÒÑÐû²¼ÖØÒªÄþ¾²¸üУ¨°æ±¾ 2.6.10£© £¬ÒÔ½â¾öÆä Windows Èí¼þÖеÄһϵÁЩ¶´ £¬ÕâЩ©¶´¿ÉÄܵ¼ÖÂȨÏÞÉý¼¶¡¢Ô¶³Ì¹¥»÷ºÍϵͳÍ߽⠡£ÕâЩ©¶´Í¹ÏÔÁ˶¨ÆÚÈí¼þ¸üеÄÐëÒªÐÔ £¬ÌرðÊǶÔÓÚ OpenVPN µÈ´¦ÖÃÍøÂçÁ÷Á¿µÄ¹¤¾ß ¡£±¾´Î¸üеĩ¶´°üÂÞCVE-2024-27459£¨¶ÑÕ»Òç³ö± £»¤£©¡¢CVE-2024-24974£¨Ô¶³Ì·ÃÎÊÏÞÖÆ£©¡¢CVE-2024-27903£¨²å¼þ¼ÓÔØÏÞÖÆ£©ºÍCVE-2024-1305£¨TAP Çý¶¯·¨Ê½Òç³öÐÞ¸´£© ¡£


https://securityonline.info/openvpn-patches-serious-vulnerabilities-in-windows-installations/


3. Vans Éù³ÆÍøÂçÆ­×Ó²¢Î´ÇÔÈ¡¿Í»§µÄ²ÆÕþÐÅÏ¢


3ÔÂ24ÈÕ £¬·þ×°ºÍЬÀà¾ÞÍ· VF Corporation Ïò 3550 Íò¿Í»§Í¨±¨ £¬¼ÌÈ¥ÄêµÄÄþ¾²Â©¶´Ö®ºó £¬ËûÃÇ¿ÉÄÜ»á³ÉΪÉí·Ý͵ÇÔµÄÊܺ¦Õß ¡£Vans ºÍ North Face ĸ¹«Ë¾ÔÚ¸ø¿Í»§µÄÒ»·âµç×ÓÓʼþÖÐÔÊÐí £¬Æ­×Ó²»»á͵ȡËûÃǵÄÐÅÓÿ¨»òÒøÐÐÕË»§ÏêϸÐÅÏ¢ ¡£¶øÇÒ £¬ËüÔö²¹Ëµ £¬¡°Ã»ÓÐÖ¤¾Ý¡±±íÃ÷Èκα»µÁµÄ¸öÈËÐÅÏ¢ £¬°üÂÞÐÕÃû¡¢µç×ÓÓʼþ¡¢µØÖ·ºÍµç»°ºÅÂë £¬Òѱ»ÓÃÓÚа¶ñÄ¿µÄ ¡£ÕâЩ¼Ç¼ÊÇÔÚ VF ÓÚ 12 Ô 13 ÈÕÅû¶µÄÊý×ÖÈëÇÖ¹ý³ÌÖб»·ÃÎÊ»ò»ñÈ¡µÄ ¡£´Ë´ÎÈëÇÖÈÅÂÒÁËÕâ¼Ò·þ×°ÖÆÔìÉ̵ÄÔËÓª¼°ÆäÈÃÈËÃÇ´©×ŸߵÈÍâÌ×µÄÄÜÁ¦ ¡£ËäÈ» VF Æäʱ²¢Î´½«´Ë´ÎÍøÂçÄþ¾²Ê¼þ³ÆÎªÀÕË÷Èí¼þ £¬µ«ÆäÔÚ¼à¹ÜÎļþÖÐÏêϸÃèÊö´Ë´ÎÈëÇÖµÄ˵»°Ê¹ÆäÌýÆðÀ´·Ç³£Ïñ´øÓÐÀÕË÷ÒªÇóµÄÀÕË÷Èí¼þѬȾ ¡£ÔÚÏòÃÀ¹ú֤ȯ½»Ò×ίԱ»á (SEC) Ìá½»µÄ×îР8-K ÎļþÖÐ £¬Õâ¼Ò·þ×°ÏúÊÛÉÌÅû¶ £¬Æä3550 Íò¿Í»§Êܵ½ IT Äþ¾²Â©¶´µÄÓ°Ïì £¬µ«¶ÔÆ­×Ó¿ÉÄÜÇÔÈ¡µÄÊý¾ÝÈ´º¬ºýÆä´ÇÔÚ¹¥»÷ÆÚ¼ä ¡£


https://www.theregister.com/2024/03/24/vans_breach_disclosure/


4. ÓÐÏßµçÊÓ ISP ÒòÏò FCC »Ñ±¨¿í´øËùÔÚ¶ø±»·£¿î


3ÔÂ23ÈÕ £¬Ò»¼Ò»¥ÁªÍø·þÎñÌṩÉÌÈÏ¿ÉÔÚÆäÌṩ¿í´øµÄËùÔÚ·½ÃæÏò FCC Èö»Ñ £¬½«Ö§¸¶ 10,000 ÃÀÔªµÄ·£¿î £¬²¢ÊµÊ©ºÏ¹æ¼Æ»®ÒÔ·ÀֹδÀ´·ºÆðÎ¥¹æÐÐΪ ¡£ArsTechnica£º¶íº¥¶íÖݶàÂ×¶àµÄÒ»¼ÒСÐÍ ISP ½Üì³Ñ·ÏصçÀ (JCC) ÈÏ¿É £¬Ëü´íÎóµØÉù³ÆÔÚÉÐδÀ©Õ¹µ½µÄµØÓòÌṩ¹âÏË·þÎñ ¡£Ò»Î»¹«Ë¾¸ß¹Ü»¹ÈÏ¿É £¬¸Ã¹«Ë¾Ìá½»ÁËÐé¼ÙµÄÁýÕÖÊý¾Ý £¬ÒÔ×èÖ¹ÆäËû»¥ÁªÍø·þÎñÌṩÉÌ»ñµÃÕþ¸®²¦¿îÀ´Îª¸ÃµØÓòÌṩ·þÎñ ¡£Ars ÔÚ 2023 Äê 2 ÔµÄһƪÎÄÕÂÖÐ×ÊÖú½Ò¶ÁËÕâһʼþ ¡£FCC ÓÚ 3 Ô 15 ÈÕÐû²¼ÁËÊÓ²ì½á¹û £¬³Æ Jefferson County Cable Î¥·´ÁË¿í´øÊý¾ÝÊÕ¼¯¼Æ»®µÄÒªÇóºÍÃÀ¹úÖ´·¨¡¶¿í´øÊý¾Ý·¨°¸¡· ¡£


https://ordonews.com/cable-isp-fined-10000-for-lying-to-fcc-about-where-it-offers-broadband/


5. µÂ¹úÕþ¸®Ðû²¼È¡µÞÃûΪNemesis MarketµÄ°µÍøÊг¡


3ÔÂ24ÈÕ £¬µÂ¹úÕþ¸®Ðû²¼È¡µÞÒ»¸öÃûΪNemesis MarketµÄ·Ç·¨µØÏÂÊг¡ £¬¸ÃÊг¡¶µÏú¶¾Æ·¡¢±»µÁÊý¾ÝºÍÖÖÖÖÍøÂç·¸×ï·þÎñ ¡£Áª°îÐÌʾ¯²ì¾Ö£¨ÓÖÃû Bundeskriminalamt »ò BKA£©ÌåÏÖ £¬Ëü²é»ñÁËλÓڵ¹úºÍÁ¢ÌÕÍðµÄÓë°µÍø·þÎñÏà¹ØµÄÊý×Ö»ù´¡ÉèÊ© £¬²¢Ã»ÊÕÁË 94,000 Å·Ôª£¨102,107 ÃÀÔª£©µÄ¼ÓÃÜ»õ±Ò×ʲú ¡£´Ë´ÎÐж¯ÊÇÓëµÂ¹ú¡¢Á¢ÌÕÍðºÍÃÀ¹úµÄÖ´·¨»ú¹¹ºÏ×÷½øÐÐµÄ £¬ÓÚ 2022 Äê 10 Ô¿ªÊ¼½øÐй㷺ÊÓ²ìºó £¬ÓÚ 2024 Äê 3 Ô 20 ÈÕ½øÐÐ ¡£Nemesis Market ½¨Á¢ÓÚ 2021 Äê £¬Ô¤¼ÆÔڹرÕ֮ǰӵÓÐÀ´×ÔÊÀ½ç¸÷µØµÄÁè¼Ý 150,000 ¸öÓû§ÕÊ»§ºÍ 1,100 ¸öÂô¼ÒÕÊ»§ ¡£½ü 20 ÃÀÔªµÄÂô¼ÒÕË»§À´×Ե¹ú ¡£½ü¼¸¸öÔÂÀ´ £¬µÂ¹úÕþ¸®»¹È¡µÞÁËKingdom MarketºÍCrimemarket £¬ÕâÁ½¸öÍøÕ¾¶¼ÓµÓÐÊýǧÃûÓû§ £¬²¢Ìṩ¹ã·ºµÄÏ´Ç®ºÍÍøÂç·¸×ï·þÎñ ¡£


https://thehackernews.com/2024/03/german-police-seize-nemesis-market-in.html


6. ¼à¹Ü»ú¹¹Ãé×¼¿Æ¼¼ÐÐÒµ £¬¹È¸èºÍÆ»¹û·Ö²ðÌáÉÏÈÕ³Ì


3ÔÂ24ÈÕ £¬´óÎ÷ÑóÁ½°¶µÄ·´Â¢¶Ï¼à¹Ü»ú¹¹ÕýÔÚ¹¥»÷¿ÉÄܵ¼ÖÂÆ»¹ûºÍ Alphabet ÆìϹȸ豻·Ö²ðµÄ·´¾ºÕùÐÐΪ £¬´óÐͿƼ¼¹«Ë¾ÕýÃæÁÙÊýÊ®ÄêÀ´µÄ×î´óÌôÕ½ ¡£Òµ½çÊ×´´ ¡£Õâ·´¹ýÀ´¿ÉÄܻἤ·¢ÊÀ½ç¸÷µØµÄ¼à¹Ü»ú¹¹¼Ó¶¦Á¦¶È £¬Å·Ã˺ÍÃÀ¹ú°¸¼þÁ¢°¸ºó¸÷¹ú·´Â¢¶ÏÊÓ²ìÊýÁ¿²»Í£Ôö¼Ó¾ÍÖ¤Ã÷ÁËÕâÒ»µã ¡£×ÔAT&TÔÚÕûÕû40Äêǰ·Ö²ðÒÔÀ´ £¬Æù½ñΪֹ £¬ÔÚÃÀ¹ú»¹Ã»ÓÐÒ»¼Ò¹«Ë¾ÃæÁÙ¼à¹Ü»ú¹¹Ö÷µ¼·Ö²ðµÄ¿ÉÄÜÐÔ ¡£¹È¸èÌåÏÖ²îÒìÒâÅ·Ã˵ÄÖ¸¿Ø £¬¶øÆ»¹ûÔòÌåÏÖÃÀ¹úµÄËßËÏÔÚÊÂʵºÍÖ´·¨É϶¼ÊÇ´íÎóµÄ ¡£Ä¿Ç°Éв»È·¶¨¼à¹Ü»ú¹¹ÊÇ·ñ»áÐû²¼·Ö²ðÁî £¬ÒòΪËûÃÇÕýÔÚ¿¼ÂÇÖÖÖÖÑ¡Ôñ £¬ÈκÎÐж¯¶¼¿ÉÄܵ¼Ö·£¿î ¡£


https://www.reuters.com/technology/google-apple-breakups-agenda-global-regulators-target-tech-2024-03-24/