·¨¹úµçÁ¦¹©Ó¦ÉÌÒòʹÓÃÈõMD5Ëã·¨´æ´¢Óû§ÃÜÂë±»·£¿î

Ðû²¼Ê±¼ä 2022-12-02
1¡¢·¨¹úµçÁ¦¹©Ó¦ÉÌÒòʹÓÃÈõMD5Ëã·¨´æ´¢Óû§ÃÜÂë±»·£¿î

¾ÝýÌå11ÔÂ30ÈÕ±¨µÀ£¬µçÁ¦¹©Ó¦ÉÌ·¨¹úµçÁ¦¹«Ë¾(EDF)ÒòÎ¥·´Å·ÃËͨÓÃÊý¾Ý±£»¤ÌõÀý(GDPR)£¬±»·¨¹úÊý¾Ý±£»¤¼à¹Ü»ú¹¹·£¿î60ÍòÅ·Ôª ¡£¹ú¼ÒÐÅÏ¢ºÍ×ÔÓÉίԱ»á(CNIL)ÌåÏÖ£¬¸Ã¹«Ë¾ÔÚ2022Äê7ÔÂʹÓÃMD5Ëã·¨¶Ô25800¶à¸öÕÊ»§½øÐÐhash´¦ÖÃÀ´´æ´¢ÃÜÂë ¡£´ËÍ⣬Óë2414254¸öÕË»§Ïà¹ØµÄÃÜÂë½ö¾­¹ýhash´¦ÖöøÎ´¼ÓÑΣ¬Ê¹ÕË»§³ÖÓÐÈËÃæÁÙDZÔÚµÄÍøÂçÍþв ¡£¸ÃÊӲ컹ָÔðEDFδÄÜ×ñÊØGDPRÊý¾Ý±£ÁôÕþ²ß£¬²¢ÌṩÁ˹ØÓÚËùÊÕ¼¯Êý¾ÝÀ´Ô´µÄ½û¾øÈ·ÐÅÏ¢ ¡£

https://thehackernews.com/2022/11/french-electricity-provider-fined-for.html

2¡¢ÏÖ´úÆû³µÒƶ¯Ó¦ÓÃÖдæÔÚ¿ÉÔ¶³Ì½âËøºÍÆô¶¯³µÁ¾µÄ©¶´

¾Ý12ÔÂ1ÈÕ±¨µÀ£¬ÏÖ´úºÍGenesisµÄÒÆ¶¯Ó¦ÓÃMyHyundaiºÍMyGenesis¿É±»ÓÃÀ´Ô¶³Ì½âËøºÍÆô¶¯³µÁ¾ ¡£ÔÚÀ¹½ØÁËÕâÁ½¸öÓ¦Ó÷¢ÉúµÄÁ÷Á¿ºó£¬Ñо¿ÈËÔ±¶ÔÆä½øÐÐÁË·ÖÎö£¬·¢ÏÖÑéÖ¤ÊÇÆ¾¾ÝÓû§µÄµç×ÓÓʼþµØÖ·Íê³ÉµÄ£¬¸ÃµØÖ·°üÂÞÔÚPOSTÇëÇóµÄJSONÕýÎÄÖÐ ¡£Ñо¿ÈËÔ±ÏòÏÖ´úÖÕ¶Ë·¢ËÍÁËαÔìµÄHTTPÇëÇóÈÆ¹ýÁËÓÐЧÐÔ¼ì²é£¬²¢¿ÉÒÔ½âËø³µÁ¾ ¡£Ñо¿ÈËÔ±»¹·¢ÏÖ£¬Ê¹ÓÃSiriusXMÖÇÄÜÆû³µÆ½Ì¨µÄ³µÁ¾Ò²´æÔÚÀàËÆÎÊÌâ£¬Éæ¼°±¦Âí¡¢±¾Ìï¡¢Ó¢·ÆÄáµÏ¡¢½Ý±ª¡¢Â·»¢¡¢À׿ËÈøË¹¡¢ÈÕ²ú¡¢Ë¹°Í³ºÍ·áÌïµÈ ¡£

https://www.bleepingcomputer.com/news/security/hyundai-app-bugs-allowed-hackers-to-remotely-unlock-start-cars/

3¡¢¸çÂ×±ÈÑÇÒ½ÁÆ»ú¹¹KeraltyÔâµ½RansomHouseµÄÀÕË÷¹¥»÷

ýÌå11ÔÂ30Èճƣ¬¸çÂ×±ÈÑǵÄÒ»¼ÒÒ½ÁƱ£½¡ÌṩÉÌKeraltyÔâµ½RansomHouseµÄÀÕË÷¹¥»÷ ¡£¹¥»÷·¢ÉúÔÚÉÏÖÜÈÕ£¬Keralty¼°Æä×Ó¹«Ë¾EPS SanitasºÍColsanitasµÄITÔËÓª¡¢Ò½ÁÆÔ¤Ô¼²¿Êð¼°ÍøÕ¾¶¼Êܵ½ÁËÓ°Ïì ¡£±¾ÖÜÒ»£¬KeraltyÌåÏÖËûÃÇÓöµ½Á˼¼ÊõÎÊÌ⵫ûÓÐ͸¶ԭÒò ¡£¸Ã¹«Ë¾ÓÖÔÚÖܶþ·¢±íÉùÃ÷£¬È·ÈÏÖжÏÊÇÓÉÍøÂç¹¥»÷Ôì³ÉµÄ ¡£RansomHouseÌåÏֶԴ˴ι¥»÷ÂôÁ¦£¬²¢³ÆÒÑÇÔÈ¡3 TBÊý¾Ý ¡£

https://www.bleepingcomputer.com/news/security/keralty-ransomware-attack-impacts-colombias-health-care-system/

4¡¢Ë÷ÄáºÍLexarµÄ¼ÓÃÜÌṩÉÌENC SecurityµÄÒµÎñÊý¾Ýй¶

CyberNewsÔÚ11ÔÂ30ÈÕ͸¶£¬ºÉÀ¼Èí¼þ¹«Ë¾ENC Security×Ô2021Äê5ÔÂÒÔÀ´Ò»Ö±ÔÚÐ¹Â¶ÖØÒªµÄÒµÎñÊý¾Ý ¡£¸Ã¹«Ë¾ÔÚÈ«ÇòÓµÓÐ1200ÍòÓû§£¬Í¨¹ýÆäDataVault¼ÓÃÜÈí¼þÌṩ¡°¾üÓü¶Êý¾Ý±£»¤¡±½â¾ö·½°¸ ¡£Ð¹Â¶µÄÐÅÏ¢°üÂÞÏúÊÛÇþµÀµÄSMTPƾ¾Ý¡¢µ¥Ò»Ö§¸¶Æ½Ì¨µÄAdyenÃÜÔ¿¡¢µç×ÓÓʼþÓªÏú¹«Ë¾µÄMailchimp APIÃÜÔ¿¡¢Ðí¿ÉÖ§¸¶APIÃÜÔ¿¡¢HMACÏûÏ¢Éí·ÝÑéÖ¤´úÂ룬ÒÔ¼°ÒÔ.pem¸ñʽ´æ´¢µÄ¹«¹²ºÍ˽ÈËÃÜÔ¿ ¡£ÕâЩÐÅÏ¢´Ó2021Äê5ÔÂ27ÈÕµ½2022Äê11ÔÂ9ÈÕ¿ÉÒÔ·ÃÎÊ ¡£ENC Security͸¶£¬¸Ã©¶´ÓëµÚÈý·½¹©Ó¦É̵ĴíÎóÅäÖÃÓйØ£¬ÎÊÌâÏÖÒѽâ¾ö ¡£

https://cybernews.com/security/encsecurity-leaked-sensitive-data/

5¡¢Ò½ÁÆÈí¼þ¹«Ë¾Connexin Software 220Íò»¼ÕßÐÅϢй¶

11ÔÂ30ÈÕ±¨µÀ£¬Connexin Software½üÆÚ֪ͨHHSÆäÊý¾Ýй¶Ê¼þÓ°ÏìÁË2216365¸ö»¼Õß ¡£¸Ã¹«Ë¾ÊÇÒ»¼ÒΪ¶ù¿ÆÒ½ÁÆÍŶÓÌṩµç×Ó²¡ÀúºÍÖ´Òµ¹ÜÀíÈí¼þ¡¢¼Æ·Ñ·þÎñºÍÒµÎñ·ÖÎö¹¤¾ßµÄ¹©Ó¦ÉÌ ¡£8ÔÂ26ÈÕ£¬ConnexinÔÚÄÚÍø¼ì²âµ½Êý¾ÝÒì³££¬Ö®ºóÁ¢¼´Õ¹¿ªÊÓ²ì ¡£9ÔÂ13ÈÕ£¬È·ÈÏδ¾­ÊÚȨµÄµÚÈý·½Äܹ»·ÃÎÊÓÃÓÚÊý¾Ýת»»ºÍ¹ÊÕÏÅųýµÄÒ»×éÀëÏß²¡ÈËÊý¾Ý ¡£Ä¿Ç°£¬ConnexinÖØÖÃÁËËùÓй«Ë¾ÕÊ»§µÄÃÜÂ룬½«»¼ÕßÊý¾ÝÒÆÖÁ¸üÄþ¾²µÄ»·¾³ÖУ¬²¢Í¨¹ýKrollΪÊÜÓ°Ï컼ÕßÌṩһÄêµÄÉí·Ý¼à¿Ø·þÎñ ¡£

https://www.databreaches.net/connexin-software-notifies-parents-of-2-2-million-pediatric-patients-of-hack/

6¡¢ESETÐû²¼¹ØÓÚScarCruftкóÃÅDolphinµÄ·ÖÎö³ÂËß

11ÔÂ30ÈÕ£¬ESETÐû²¼Á˹ØÓÚAPTÍÅ»ïScarCruftµÄкóÃÅDolphinµÄ·ÖÎö³ÂËß ¡£×Ô2021Äê4ÔÂÊ״η¢ÏÖDolphinÒÔÀ´£¬Ñо¿ÈËÔ±ÒѾ­ÊӲ쵽¶à¸ö°æ±¾µÄºóÃÅ ¡£DolphinÊÇÒ»¸öC++¿ÉÖ´ÐÐÎļþ£¬Ê¹ÓÃGoogle Drive×÷ΪÃüC2·þÎñÆ÷²¢´æ´¢±»µÁÎļþ ¡£ËüµÄËÑË÷¹¦Ð§Í¨¹ýʹÓÃWindows±ãЯÉ豸APIÀ©Õ¹µ½ÈκÎÁ¬½Óµ½±»¹¥»÷Ö÷»úµÄÊÖ»ú£¬Ëü»¹¿ÉÒÔͨ¹ý¸ü¸ÄÏà¹ØÉèÖÃÀ´½µµÍÄ¿±êGoogleÕÊ»§µÄÄþ¾²ÐÔ ¡£

https://www.welivesecurity.com/2022/11/30/whos-swimming-south-korean-waters-meet-scarcrufts-dolphin/