TikTok·ñÈÏÆäÔâµ½¹¥»÷ºóÔ´´úÂëºÍÓû§Êý¾Ý±»µÁµÄ˵·¨
Ðû²¼Ê±¼ä 2022-09-07
¾ÝýÌå9ÔÂ5ÈÕ±¨µÀ£¬ÃûΪAgainstTheWestµÄºÚ¿ÍÍÅ»ïÉù³ÆÒÑÈëÇÖTikTokºÍ΢ÐÅ£¬²¢Ðû²¼ÁËËùνÊý¾Ý¿âµÄ½ØÍ¼¡£ËûÃÇ˵¸ÃÊý¾Ý¿âÊÇÔÚÒ»¸ö°¢ÀïÔÆÊµÀýÉÏ·ÃÎʵ쬰üÂÞ20.5ÒÚÌõ¼Ç¼£¬Éæ¼°Óû§Êý¾Ý¡¢Æ½Ì¨Í³¼ÆÐÅÏ¢¡¢Èí¼þ´úÂë¡¢cookie¡¢Éí·ÝÑéÖ¤ÁîÅÆºÍ·þÎñÆ÷ÐÅÏ¢µÈ¡£TikTok·ñÈÏÁËÆä±»ºÚ¿ÍÈëÇÖµÄ˵·¨£¬²¢ÌåÏÖ¹¥»÷Õß¹ûÈ»µÄµÄÔ´´úÂë²»ÊÇÆäÆ½Ì¨µÄÒ»²¿ÃÅ¡£´ËÍ⣬AgaintTheWest µÄÕ˺ÅÒѱ»Í£Ó㬺ڿÍÂÛ̳BreachÖ¸³öй¶Êý¾Ý²¢·ÇÀ´×ÔTikTok£¬¶øÇÒ¹¥»÷Õß¿ÉÄÜÔÚÈö»Ñ¡£
https://www.bleepingcomputer.com/news/security/tiktok-denies-security-breach-after-hackers-leak-user-data-source-code/
2¡¢InstagramÒòÎ¥·´GDPRÀÄÓöùͯÊý¾Ý±»°®¶ûÀ¼·£¿î4ÒÚÃÀÔª
¾Ý9ÔÂ6ÈÕ±¨µÀ£¬InstagramÒòÎ¥·´GDPR±»°®¶ûÀ¼Êý¾Ý±£»¤Î¯Ô±»á(DPC)·£¿î4.02ÒÚÃÀÔª¡£DPCÌåÏÖ£¬InstagramÔÊÐí13-17ËêµÄ¶ùͯ½¨Á¢ÉÌÒµÕË»§£¬Õâ¿ÉʹÕâЩ¶ùͯµÄÐÅÏ¢±»¹ûÈ»¡£¶øÇÒÆäÓû§×¢²áϵͳÖжùͯÓû§µÄÕÊ»§Ä¬ÈÏÉèÖÃΪ¹ûÈ»£¬´Ó¶ø¹ûÈ»ÁË´ËÀàÓû§µÄÉ罻ýÌåÄÚÈÝ£¬Óû§±ØÐëÊÖ¶¯½«ÕÊ»§ÉèÖÃΪ˽ÈË¡£InstagramµÄĸ¹«Ë¾Meta¶Ô·£¿îµÄ¼ÆË㷽ʽÌá³öÒìÒ飬³ÆÆä²»ÇкÏGDPRµÄÎı¾£¬µ¼Ö·£¿îÃ÷ÏÔ¸ßÓÚÆäËüÓëGDPRÏà¹ØµÄ·£¿î£¬²¢¼Æ»®¶Ô¸ÃÖ¸¿ØÌá³öÉÏËß¡£
https://therecord.media/instagram-appealing-400-million-fine-from-ireland-data-privacy-org-over-gdpr-violations/
3¡¢ResecurityÔÚ°µÍø·¢ÏÖ¿ÉÈÆ¹ýMFAµÄEvilProxy PhaaS
9ÔÂ5ÈÕ£¬ResecurityÅû¶ÁËеÄÍøÂçµöÓã¼´·þÎñ(PaaS)ƽ̨EvilProxy¡£ÔÚijЩÇé¿öÏÂËüµÄÌæ´úÃû³ÆÊÇMoloch£¬Óë֮ǰÕë¶Ô½ðÈÚ»ú¹¹ºÍµçÉÌÐÐÒµµÄ¼¸¸ö³£¼ûµÄµöÓ㹤¾ß°üÓÐijÖÖÁªÏµ¡£EvilProxyÓÚ2022Äê5ÔÂÉÏÑ®Ê״α»¼ì²âµ½£¬Ñо¿ÈËÔ±ÌåÏÖÏñEvilProxyÕâÑùµÄ²úÎﻯ·þÎñ¿ÉÓÃÀ´×î´ó¹æÄ£µØ¹¥»÷ÆôÓÃÁËMFAµÄÓû§£¬¶øÎÞÐèÆÆ½âÉÏÓηþÎñ¡£¹¥»÷ÕßÀûÓ÷´ÏòÊðÀíºÍCookie×¢ÈëµÄÒªÁìÈÆ¹ý2FAÉí·ÝÑéÖ¤£¬´ËÀàÒªÁìÔÚAPTºÍ¼äµý¹¥»÷µÈÓÐÕë¶ÔÐԵĻÖо³£¼ûµ½¡£ÖµµÃ×¢ÒâµÄÊÇ£¬EvilProxy»¹Ö§³ÖÕë¶ÔPyPiµÄµöÓã¹¥»÷¡£
https://resecurity.com/blog/article/evilproxy-phishing-as-a-service-with-mfa-bypass-emerged-in-dark-web
4¡¢¹ú¼ÊÐ̾¯×éÖ¯·¢ÏÖ²¢Àֳɵ·»Ùij¿ç¹úÊý×ÖÀÕË÷ÍÅ»ï
ýÌå9ÔÂ5Èճƣ¬¹ú¼ÊÐ̾¯×éÖ¯µÄÍøÂç·¸×ﲿÃÅÓëÐÂ¼ÓÆÂºÍÖйúÏã¸Û¾¯·½ÁªºÏÊÓ²ìºó£¬·¢ÏÖ²¢Àֳɵ·»Ùij¿ç¹úÊý×ÖÀÕË÷ÍŻÊÓ²ìÈËÔ±·¢ÏÖ¹¥»÷Õßͨ¹ýÔÚÏßÉ«ÇéÆ½Ì¨ºÍÔ¼»áƽ̨ҪÇóÄ¿±êÏÂÔØ¶ñÒâÒÆ¶¯Ó¦Óò¢½øÐÐÂãÁÄ£¬È»ºó¸Ã¶ñÒâÓ¦ÓûáÇÔÈ¡ËûÃÇÊÖ»úÁªÏµÈËÁбíÖеÄÄÚÈÝ£¬¹¥»÷Õß»áÀûÓÃÕâЩÐÅÏ¢À´ÇÃÕ©Ä¿±ê£¬ÍþвҪÓëËûÃÇͨѶ¼ÖеÄÇ×ÓÑ·ÖÏíÕâЩÊÓÆµ¡£Ä¿Ç°£¬12ÃûÉæÏÓÊǸÃÍÅ»ïºËÐijÉÔ±µÄÏÓÒÉÈËÒÑÓÚ7ÔºÍ8Ô±»²¶¡£¹ú¼ÊÐ̾¯×éÖ¯ÌåÏÖ£¬½üÄêÀ´Êý×ÖÀÕË÷µÄ³ÂËß¼±¾çÔö¼Ó£¬¶øCOVID-19¼Ó¾çÁËÕâÖÖÔö³¤¡£
https://www.bleepingcomputer.com/news/security/interpol-dismantles-sextortion-ring-warns-of-increased-attacks/
5¡¢NCC͸¶ÐÂSharkBot±äÖÖÔÙ´ÎÈÆ¹ýGoogle PlayµÄ¼ì²â
¾ÝýÌå9ÔÂ5Èճƣ¬NCC GroupÑо¿ÈËÔ±ÔÚGoogle Play StoreÖз¢ÏÖÁËеÄSharkBot±äÖÖ¡£ÐµÄSharkBot dropper²»ÒÀ¿¿AccessibilityȨÏÞÀ´×Ô¶¯Ö´Ðа²×°£¬Ïà·´£¬Õâ¸öбäÌåÒªÇóÄ¿±ê½«¸Ã¶ñÒâÈí¼þ×÷Ϊһ¸öÐé¼Ù¸üÐÂÀ´°²×°¡£ÓÐÎÊÌâµÄÁ½¸öÓ¦Ó÷¨Ê½ÎªMister Phone CleanerºÍKylhavy Mobile Security£¬°²×°Á¿·Ö±ðΪ10000ºÍ50000£¬Ö÷ÒªÕë¶ÔÎ÷°àÑÀ¡¢°Ä´óÀûÑÇ¡¢²¨À¼¡¢µÂ¹ú¡¢ÃÀ¹úºÍ°ÂµØÀûµÄÓû§¡£Ä¿Ç°£¬ÊÜÓ°ÏìÓ¦ÓÃÒÑ´ÓGoogle PlayÖÐɾ³ý£¬µ«ÒѰ²×°µÄÓû§ÈÔÃæÁÙ·çÏÕ£¬Ó¦ÊÖ¶¯É¾³ýËüÃÇ¡£
https://securityaffairs.co/wordpress/135303/malware/sharkbot-variant-google-play.html
6¡¢KasperskyÐû²¼2021ÄêÍøÂçÄþ¾²Ê¼þÏìÓ¦µÄ·ÖÎö³ÂËß
9ÔÂ5ÈÕ£¬KasperskyÐû²¼ÁË2021ÄêÍøÂçÄþ¾²Ê¼þÏìÓ¦µÄ·ÖÎö³ÂËß¡£ÔÚ¸ÃÄê¶ÈʼþÏìÓ¦³ÂËßÖУ¬Ñо¿ÈËԱƾ¾Ý¶ÔÄþ¾²Ê¼þµÄÊÓ²ì¹ûÈ»ÁË×îз¢ÏÖºÍͳ¼ÆÊý¾Ý¡£ÔÚ2021Ä꣬´ó¶àÊýʼþÏìÓ¦·þÎñÇëÇóÀ´×ÔÔÚÅ·ÖÞ (30.1%)¡¢CIS(24.7%)ºÍÖж«(23.7%)£»¹¤Òµ(30.1%)¡¢Õþ¸®(19.4%)ºÍ½ðÈÚ(12.9%)ÐÐÒµµÄ×éÖ¯ÈÔÈ»ÊÇ×î¾ßÕë¶ÔÐÔµÄ×éÖ¯£»ÔÚ53.6%µÄ°¸ÀýÖУ¬ÀûÓÃÃæÏò¹«ÖÚµÄÓ¦Ó÷¨Ê½ÖеÄ©¶´ÊÇ×î³õµÄѬȾý½é£»ÔÚ40%µÄʼþÖУ¬¹¥»÷ÕßʹÓÃÁ˺Ϸ¨¹¤¾ß¡£
https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2022/09/02120838/Kaspersky-The-nature-of-cyber-incidents_v11-1.pdf