¿ËÂÞµØÑǵçÐÅÔËÓªÉÌA1 Hrvatskaй¶Լ20ÍòÓû§ÐÅÏ¢

Ðû²¼Ê±¼ä 2022-02-15

¿ËÂÞµØÑǵçÐÅÔËÓªÉÌA1 Hrvatskaй¶Լ20ÍòÓû§ÐÅÏ¢


¾ÝýÌå2ÔÂ11ÈÕ±¨µÀ £¬¿ËÂÞµØÑǵçÐÅÔËÓªÉÌA1 Hrvatskaй¶ÁË10%Óû§£¨Ô¼20ÍòÈË£©µÄ¸öÈËÐÅÏ¢ ¡£¸Ã¹«Ë¾Ã»ÓÐÌṩ¹ØÓÚ´Ë´ÎʼþµÄϸ½Ú £¬Ö»³ÆËûÃǵÄÒ»¸öÓû§Êý¾Ý¿âÔâµ½ÁËδ¾­ÊÚȨ·ÃÎÊ £¬µ¼ÖÂÐÕÃû¡¢¸öÈËʶ±ðºÅÂ롢ʵ¼ÊµØÖ·ºÍµç»°ºÅÂëµÈÐÅϢй¶ ¡£ÎÖ´ï·á¼¸ÈÕǰÔâµ½¹¥»÷µ¼ÖÂÆäÔÚÆÏÌÑÑÀµÄ·þÎñÖжÏ £¬A1 HrvatskaÊÇÆäÕ½ÂÔºÏ×÷»ï°é £¬Éв»ÄÜÈ·¶¨ÕâÁ½´ÎÄþ¾²Ê¼þÖ®¼äÊÇ·ñ´æÔÚÁªÏµ ¡£


https://www.bleepingcomputer.com/news/security/croatian-phone-carrier-data-breach-impacts-200-000-clients/


ÖйúÏã¸Ûº£ÒݾƵêÊý¾Ý¿âÔâ¹¥»÷³¬100Íò¿Í»§ÐÅϢй¶


2ÔÂ11Èյı¨µÀ³Æ £¬ÖйúÏã¸ÛµÄº£ÒݾƵ꼯ÍÅÔ¤¶©Êý¾Ý¿âÔâµ½ÍøÂç¹¥»÷ £¬Ô¼120Íò¿Í»§µÄÐÅϢй¶ ¡£Òþ˽רԱAda ChungÉÏÖÜÎåÌåÏÖ £¬ÆäÔÚÉÏÖÜÈýÊÕµ½Í¨ÖªºóÒѾ­¶Ô´ËÊÂÕ¹¿ªÊÓ²ì ¡£ÊÐÃñ¿Éͨ¹ý·þÎñ´¦ÈÈÏß28272827¡¢¼¯Íźô½ÐÖÐÐÄ39080740»ò¹«Ë¾¹ÙÍø²éѯÊÇ·ñÊܵ½´ËʼþµÄÓ°Ïì ¡£


https://gbcode.rthk.hk/TuniS/news.rthk.hk/rthk/en/component/k2/1633250-20220211.htm


SentinelOneÐû²¼ModifiedElephant¹¥»÷Ó¡¶ÈµÄ·ÖÎö³ÂËß


SentinelOneÔÚ2ÔÂ9ÈÕÐû²¼³ÂËß £¬Åû¶ÁËModifiedElephant¹¥»÷Ó¡¶ÈµÄϸ½Ú ¡£ModifiedElephantÖÁÉÙ´Ó2012Ä꿪ʼÔËÓª £¬Ê¹ÓÃÁËÉÌÒµÔ¶³Ì·ÃÎÊľÂí(RAT) £¬¶øÇÒÓëÉÌÒµ¼à¿ØÐÐÒµÓÐÁªÏµ ¡£¹¥»÷Õßͨ¹ýÓã²æÊ½µöÓã»î¶¯À´·Ö·¢¶ñÒâÈí¼þ £¬ÀýÈçNetWireºÍDarkCometµÈ £¬Ö÷ÒªÕë¶ÔÓ¡¶È¸÷µØµÄÈËȨ»î¶¯Ïà¹ØÈËÔ±¡¢Ñ§ÕߺÍÂÉʦµÈ £¬×îÖÕÖ¼ÔÚÖ²ÈëÓÐ×ïµÄÊý×ÖÖ¤¾Ý ¡£


https://www.sentinelone.com/labs/modifiedelephant-apt-and-a-decade-of-fabricating-evidence/


FritzFrogÔٴλعé £¬Õë¶ÔÒ½ÁÆ¡¢½ÌÓýºÍÕþ¸®µÄ×éÖ¯


2ÔÂ10ÈÕ £¬Äþ¾²¹«Ë¾AkamaiÐû²¼Á˹ØÓÚP2P½©Ê¬ÍøÂçFritzFrogµÄ·ÖÎö³ÂËß ¡£FritzFrogÓÚ2020Äê8ÔÂÊ״α»·¢ÏÖ £¬´Ë´Î»Ø¹éÔÚÒ»¸öÔÂÄÚµÄѬȾÂÊÔö³¤ÁË10±¶ £¬ÒѾ­¹¥»÷ÁË1500̨ҽÁƱ£½¡¡¢½ÌÓýºÍÕþ¸®ÐÐÒµµÄ·þÎñÆ÷ £¬ÆäÖдó²¿ÃÅλÓÚÖйú ¡£¸Ã¶ñÒâÈí¼þʹÓÃGolang±àд £¬Ôö¼ÓÁËй¦Ð§ £¬°üÂÞʹÓÃÊðÀíÍøÂçºÍ¶¨Î»WordPress·þÎñÆ÷ £¬¶øÇÒÆä¶ÔµÈ¼Ü¹¹ºÍרÓдúÂë¾ßÓнϸßˮƽµÄÅÓ´óÐÔ ¡£


https://www.akamai.com/blog/security/fritzfrog-p2p


·¨¹ú³ÆGoogle AnalyticsÎ¥·´GDPR½«ÊÕ¼¯µÄÊý¾Ý´«Êäµ½ÃÀ¹ú


¾ÝýÌå2ÔÂ10ÈÕ³Æ £¬·¨¹úÊý¾Ý±£»¤¼à¹Ü»ú²Ã¶¨Google AnalyticsÎ¥·´ÁËGDPR ¡£¹ú¼ÒÐÅϢѧºÍ×ÔÓÉίԱ»á(CNIL)ÌåÏÖ £¬Google Analytics´«Êäµ½ÃÀ¹úµÄÊý¾ÝûÓеõ½¡°³äʵ¼à¹Ü¡± £¬Î¥·´ÁËGDPRµÚ44ÌõÌõ¿î ¡£CNIL³Æ £¬¾¡¹ÜGoogleÒѾ­½ÓÄÉÁËÌØ±ðµÄ´ëÊ©À´¹æ·¶Google AnalyticsÖеÄÊý¾Ý´«Êä £¬µ«ÕâЩ»¹²»×ãÒÔÅųýÃÀ¹úÇ鱨·þÎñ·ÃÎÊÕâЩÊý¾ÝµÄ¿ÉÄÜÐÔ ¡£


https://thehackernews.com/2022/02/france-rules-that-using-google.html


ÀÕË÷ÍÅ»ïBlackByte³ÆÆäÒÑÈëÇÖNFL¾É½ðɽ49È˶Ó


ýÌå2ÔÂ13ÈÕ±¨µÀ³Æ £¬ÀÕË÷ÍÅ»ïBlackByteÒÑÈëÇ־ɽðɽ49È˶Ó ¡£¾É½ðɽ49È˶ӣ¨San Francisco 49ers£©ÊÇNFLÖÐ×îÓмÛÖµºÍ×î´«ÆæµÄÇò¶ÓÖ®Ò» £¬¾ÍÔÚNFL×¼±¸Ó­½Ó2022Ä곬¼¶ÍëµÄʱºò £¬BlackByteÉù³Æ¹¥»÷ÁË49ers²¢¿ªÊ¼Ð¹Â¶±»µÁÎļþ £¬¾ÝϤÊÇ292MBµÄ²ÆÕþÐÅÏ¢ ¡£¸ÃÇò¶ÓÔÚÒ»·ÝÉùÃ÷ÖÐ֤ʵÁËÕâ´Î¹¥»÷ £¬²¢ÌåÏÖ¹¥»÷µ¼ÖÂËûÃDz¿ÃÅÍøÂçÔÝʱÖжÏ £¬Ä¿Ç°ÈÔÔÚ»Ö¸´ÏµÍ³µÄ¹ý³ÌÖÐ ¡£


https://www.securityweek.com/ransomware-gang-says-it-has-hacked-49ers-football-team


Äþ¾²¹¤¾ß


VulnLab


Yavuzlar ¿ª·¢µÄ Web ©¶´ÊµÑéÊÒÏîÄ¿ ¡£


https://github.com/Yavuzlar/VulnLab


Http2Smugl


¸Ã¹¤¾ßÓÐÖúÓÚ¼ì²âºÍÀûÓà HTTP ÇëÇó×ß˽ £¬ÒÔ·ÀËüͨ¹ýǰ¶Ë·þÎñÆ÷ͨ¹ý HTTP/2 -> HTTP/1.1 ת»»À´ÊµÏÖ ¡£


https://github.com/neex/http2smugl


FACT


ÓÃÓÚÊÕ¼¯¡¢´¦ÖúͿÉÊÓ»¯À´×ÔÔÚÔÆÖлòµ±µØÔËÐеĻúÆ÷¼¯ÈºµÄȡ֤Êý¾Ý ¡£


https://github.com/unicornunicode/FACT


iris-web


ËüÊÇʼþÏìÓ¦·ÖÎöʦµÄЭ×÷ƽ̨ £¬ÔÊÐíÔÚ¼¼Êõ²ãÃæ¹²ÏíÊÓ²ì ¡£


https://dfir-iris.github.io/


hobbits


ÓÃÓÚ·ÖÎö¡¢´¦ÖúͿÉÊÓ»¯±ÈÌØµÄÈí¼þƽ̨ ¡£


https://mahlet-inc.github.io/


Äþ¾²·ÖÎö


ÃÀ¹ú¹ú·À²¿Ñ¡Ôñ DataRobot ΪÕþ¸®µÄÈ˹¤ÖÇÄܼƻ®Ìṩ¶¯Á¦


https://www.helpnetsecurity.com/2022/02/13/datarobot-department-of-defense/



¹È¸èÌåÏÖ £¬×éÖ¯ÕýÔÚ¸ü¿ìµØ½â¾öÁãÈÕ©¶´


https://securityaffairs.co/wordpress/127932/security/zero-day-flaws-metrics.html



¹È¸èÔÚ 2021 ÄêÏò Bug Hunters Ö§¸¶ÁË 870 ÍòÃÀÔª


https://www.darkreading.com/vulnerabilities-threats/google-paid-record-8-7-million-to-bug-hunters-in-2021



CISA ÃüÁîÁª°î»ú¹¹ÔÚ 2 Ô 25 ÈÕ֮ǰ¸üРiPhone¡¢Mac


https://www.bleepingcomputer.com/news/security/cisa-orders-federal-agencies-to-update-iphones-macs-until-feb-25th/



΢Èí£º¶Ô Windows 10 20H2 µÄÖ§³Ö½«ÓÚ 2022 Äê 5 Ô½áÊø


https://www.bleepingcomputer.com/news/microsoft/microsoft-support-for-windows-10-20h2-ending-in-may-2022/



Щ¶´¿ÉÈúڿÍÔ¶³ÌÆÆ»µÎ÷ÃÅ×Ó PLC


https://www.securityweek.com/new-vulnerabilities-can-allow-hackers-remotely-crash-siemens-plcs