GoogleÐû²¼½ô¼±¸üРÐÞ¸´ChromeÖÐÒѱ»ÀûÓõÄ©¶´

Ðû²¼Ê±¼ä 2021-12-15

GoogleÐû²¼½ô¼±¸üУ¬ÐÞ¸´ChromeÖÐÒѱ»ÀûÓõÄ©¶´


GoogleÐû²¼½ô¼±¸üУ¬ÐÞ¸´ChromeÖÐÒѱ»ÀûÓõÄ©¶´.png


12ÔÂ13ÈÕ£¬GoogleÐû²¼½ô¼±¸üУ¬ÐÞ¸´ÁËChromeÖеÄ5¸ö©¶´¡£Äþ¾²Í¨¸æÌåÏÖ£¬´Ë´ÎÐÞ¸´µÄV8 JavaScriptÒýÇæÖеÄÊͷźóʹÓé¶´£¨CVE-2021-4102£©Òѱ»ÔÚÒ°ÀûÓ㬿ɵ¼ÖÂÈÎÒâ´úÂëÖ´ÐлòɳÏäÌÓÒÝ¡£´ËÍ⣬»¹ÐÞ¸´ÁËMojoÖеÄÊý¾ÝÑéÖ¤²»×ã©¶´£¨CVE-2021-4098£©ºÍSwiftshaderÖеÄÊͷźóʹÓé¶´£¨CVE-2021-4099£©µÈ¶à¸ö©¶´¡£ÓÉÓÚ¸Ã0dayÒѱ»ÔÚÒ°ÀûÓã¬Ñо¿ÈËԱǿÁÒ½¨ÒéÁ¢¼´°²×°Chrome²¹¶¡¡£


Ô­ÎÄÁ´½Ó£º

https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop_13.html


°ÍÎ÷ÎÀÉú²¿ÍøÕ¾Ôâµ½¹¥»÷Êý°ÙÍò¹«ÃñÒßÃç½ÓÖÖÊý¾Ý¶ªÊ§


°ÍÎ÷ÎÀÉú²¿ÍøÕ¾Ôâµ½¹¥»÷Êý°ÙÍò¹«ÃñÒßÃç½ÓÖÖÊý¾Ý¶ªÊ§.png


12ÔÂ10ÈÕ£¬°ÍÎ÷ÎÀÉú²¿(MoH)ÏÂÊôµÄÍøÕ¾Ôâµ½ÀÕË÷¹¥»÷£¬µ¼ÖÂÊý°ÙÍò¹«ÃñµÄCOVID-19ÒßÃç½ÓÖÖÊý¾Ý¶ªÊ§¡£¹¥»÷·¢ÉúÔÚÁ賿1µã×óÓÒ£¬ÎÀÉú²¿µÄËùÓÐÍøÕ¾£¬°üÂÞÒ½ÁÆÏµÍ³Öиú×Ù¹«Ãñ¹ì¼£µÄConecteSUS£¬¾ùÎÞ·¨·ÃÎÊ¡£Ö®ºó£¬ºÚ¿ÍÍÅ»ïLapsus$ GroupÉù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦£¬²¢ÒѾ­ÇÔÈ¡²¢É¾³ýÁËÔ¼50TBµÄÊý¾Ý¡£¾Ý°ÍÎ÷ÎÀÉú²¿²¿³¤Marcelo Queiroga³Æ£¬ËûÃÇÔÚ¹ú¼ÒÎÀÉú·þÎñÊý¾Ý¿âÖÐÓб»µÁÊý¾Ý±¸·Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/brazilian-ministry-of-health-suffers-cyberattack-and-covid-19-vaccination-data-vanishes/


µÂ¹úÎïÁ÷¹«Ë¾HellmannÔâµ½¹¥»÷µ¼ÖÂÔËÓªÔÝʱÖжÏ


µÂ¹úÎïÁ÷¹«Ë¾HellmannÔâµ½¹¥»÷µ¼ÖÂÔËÓªÔÝʱÖжÏ.png


µÂ¹úÎïÁ÷¹«Ë¾Hellmann Worldwide LogisticsÔÚ12ÔÂ10ÈÕ³ÆÆäÔâµ½ÍøÂç¹¥»÷¡£¸Ã¹«Ë¾Ã¿Äê´¦ÖÃԼĪ1600Íò¼þ»õÎ2020ÄêµÄÊÕÈëΪ28ÒÚÃÀÔª¡£HellmannÔÚÉùÃ÷ÖÐÌåÏÖ£¬Æä¼ì²âµ½¹¥»÷ºóÁ¢¼´×ö³öÏìÓ¦£¬ÔÝʱ¹Ø±ÕÁËÖÐÑëÊý¾ÝÖÐÐÄ£¬µ«Õâ¶Ô¹«Ë¾µÄÔËÓª·¢ÉúÁËÑÏÖØµÄÓ°Ïì¡£¸Ã¹«Ë¾²¢Î´Í¸Â¶¹¥»÷µÄÐÔÖÊ£¬µ«ÔÚ13ÈÕÐû²¼Í¨¸æ£¬³ÆÒµÎñÔËÓªÒÑ»ù±¾»Ö¸´Õý³££¬Ä¿Ç°ÉÐδȷÈÏÊÇ·ñÓÐÊý¾Ýй¶µÄÇé¿ö¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/cyberattack-on-hellmann-worldwide/


FTC³ÆÃÀ¹ú½ñÄêÒòÀñÆ·¿¨Õ©Æ­»î¶¯ÒÑËðʧ1.48ÒÚÃÀÔª


FTC³ÆÃÀ¹ú½ñÄêÒòÀñÆ·¿¨Õ©Æ­»î¶¯ÒÑËðʧ1.48ÒÚÃÀÔª.png


ÃÀ¹úÁª°îóÒ×ίԱ»á(FTC)ÔÚ12ÔÂ8ÈÕÌåÏÖ£¬½ØÖÁ2021Äê9Ôµ×£¬ÃÀ¹ú¹«ÃñÒòÀñÆ·¿¨Õ©Æ­»î¶¯µÄËðʧ¸ß´ï1.48ÒÚÃÀÔª£¬Áè¼Ý2020È«ÄêµÄ×ÜËðʧ¡£FTC³Æ£¬×Ô2018ÄêÒÔÀ´£¬ÊÜÆ­µÄÏû·ÑÕßÊýÁ¿ºÍËðʧ½ð¶î¶¼ÔÚÎȲ½Ôö¼Ó£¬ÆäÖÐÀñÆ·¿¨ÊÇÖ÷ÒªµÄ¸¶¿î·½Ê½¡£ÕâÖÖ¹¥»÷»î¶¯Í¨³ £»áð³äÉç»á±£ÕϾֵȹٷ½×éÖ¯£¬ÍþвҪ¶³½áÄ¿±êÒøÐÐÕË»§£¬²¢ÌåÏÖÈç¹û²»Ïë±»²¶»òÏëÒª±£ÁôÕË»§ÖеĹ¤Òµ¾Í±ØÐ빺ÖÃÀñÆ·¿¨¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ftc-americans-lost-148-million-to-gift-card-scams-this-year/


Proofpoint¼ì²âµ½ÀûÓÃOAuth 2.0µÄURLÖØ¶¨Ïò¹¥»÷


Proofpoint¼ì²âµ½ÀûÓÃOAuth 2.0µÄURLÖØ¶¨Ïò¹¥»÷.png


ProofpointÔÚ12ÔÂ8ÈÕÅû¶ÁËÀûÓÃOAuth 2.0µÄURLÖØ¶¨Ïò¹¥»÷µÄϸ½Ú¡£¹¥»÷Õßͨ¹ýÕâÖÖ·½Ê½Èƹý´ó¶àÊýµöÓã¹¥»÷¼ì²âϵͳºÍµç×ÓÓʼþÄþ¾²¼ÆÄ±£¬¹¥»÷Outlook Web Access¡¢PayPal¡¢Microsoft 365ºÍGoogle WorkspaceµÈÓ¦Óá£OAuth 2.0ÊÇÒ»Öֹ㷺ʹÓõÄÊÚȨЭÒ飬µ±webÓ¦Óúϲ¢ÁËÓû§¿ØÖƵIJÎÊýÀ´Ö¸¶¨Öض¨ÏòÁ´½Óʱ£¬¾Í»á·ºÆð¿ª·ÅÊ½ÖØ¶¨Ïò©¶´£¬¹¥»÷Õß¿ÉÒÔΪwebÓ¦Óô´½¨Ò»¸öURL£¬´Ó¶ø½«Ä¿±êÖØ¶¨Ïòµ½ÈÎÒâµÄÍⲿÓò¡£


Ô­ÎÄÁ´½Ó£º

https://www.proofpoint.com/us/blog/cloud-security/microsoft-and-github-oauth-implementation-vulnerabilities-lead-redirection


MicrosoftÐû²¼¶ñÒâÈí¼þQakbotµÄ¼¼Êõ·ÖÎö³ÂËß


MicrosoftÐû²¼¶ñÒâÈí¼þQakbotµÄ¼¼Êõ·ÖÎö³ÂËß.png

12ÔÂ9ÈÕ£¬MicrosoftÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þQakbotµÄ¼¼Êõ·ÖÎö³ÂËß¡£QakbotÒÑÓнü10ÄêÀúÊ·£¬ÒÑÉú³¤³ÉΪһÖÖ¶àÓÃ;¶ñÒâÈí¼þ£¬¼¸ºõÔÚËùÓдó½µÄ¹ú¼ÒºÍµØÓò¶¼¿ÉÒÔ¼ì²âµ½Qakbot»î¶¯£¬°üÂÞ·ÇÖÞ¡¢ÑÇÖÞ¡¢Å·ÖÞºÍÃÀÖÞ¡£Ñо¿ÈËÔ±ÈÏΪ£¬QakbotµÄÄ£¿é»¯ÌØÐÔʹËüÄܹ»Æ¾¾ÝËùÔÚµÄÍøÂç»·¾³ÎªÃ¿¸ö¹¥»÷Á´£¨attack chain£©ÌôÑ¡ºÏÊʵĹ¹½¨¿é£¨building blocks£©¡£¸Ã³ÂËßÑо¿ÁË×î½üµÄ3¸öQakbot»î¶¯£¬²¢½«Æä¹¥»÷Á´ÆÊÎöΪ¶à¸ö¹¹½¨¿é½øÐзÖÎö¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/security/blog/2021/12/09/a-closer-look-at-qakbots-latest-building-blocks-and-how-to-knock-them-down/