΢ÈíÒòXboxÇÖ·¸¶ùͯÒþ˽±»ÃÀ¹úFTC·£¿î2000ÍòÃÀÔª
Ðû²¼Ê±¼ä 2023-06-081¡¢Î¢ÈíÒòXboxÇÖ·¸¶ùͯÒþ˽±»ÃÀ¹úFTC·£¿î2000ÍòÃÀÔª
¾ÝýÌå6ÔÂ6ÈÕ±¨µÀ£¬Î¢ÈíÒòÎ¥·´Á˶ùͯÔÚÏßÒþ˽±£»¤·¨(COPPA)£¬±»FTC·£¿î2000ÍòÃÀÔª¡£¸Ã»ú¹¹³Æ£¬Î¢ÈíÉæÏÓÔÚδÕ÷µÃâïÊÑͬÒ⣬ÉõÖÁûÓÐ֪ͨËûÃǵÄÇé¿öÏ£¬ÊÕ¼¯²¢±£Áô×¢²áXbox Live·þÎñµÄ¶ùͯµÄ¸öÈËÐÅÏ¢¡£ÔÚ2015ÄêÖÁ2020Äê¼äµÄһЩ°¸ÀýÖУ¬Î¢Èí½«¶ùͯÊý¾Ý´æ´¢ÔÚÆä·þÎñÆ÷Öг¤´ïÊýÄêÖ®¾Ã¡£·¨Í¥ÎļþÏÔʾ£¬´Ó2017Äê1Ôµ½2021Äê12Ô£¬Ô¼ÓÐ218000Ãû²»Âú13ËêµÄÃÀ¹úXboxÓÎÏ·»úÓû§´´½¨MicrosoftÕÊ»§¡£Ä¿Ç°Ë«·½ÒÑͬÒâ¸ÃºÍ½â£¬µ«ÈÔÔÚÆÚ´ý·¨ÔºÅú×¼¡£³ýÁË·£¿î£¬¸Ã¹«Ë¾»¹Òª½ÓÄÉÐëÒª´ëÊ©ÒÔÈ·±£×ñÊØCOPPA¡£
https://www.theregister.com/2023/06/06/microsoft_fined_20m_for_collecting/
2¡¢Outlook±»Anonymous Sudan DDoS¹¥»÷·þÎñÔÙ´ÎÖжÏ
¾Ý6ÔÂ6ÈÕ±¨µÀ£¬Outlook.comÔÚ6ÔÂ5ÈÕ¾ÀúÁËÁ½´ÎÖØ´óÖжÏÖ®ºó£¬ÓÖ·¢ÉúÁËһϵÁеķþÎñÖжϡ£OutlookÓû§ÔÚTwitterÉÏËß¿àµç×ÓÓʼþ·þÎñ²»Îȶ¨£¬Ó°ÏìÁËËûÃǵÄÊÂÇéЧÂÊ¡£Î¢Èí˵ÕâЩ¹ÊÕÏÊÇÓɼ¼ÊõÎÊÌâÒýÆðµÄ£¬ÔÚTwitterÉÏÐû²¼Á˸üÐÂ˵»º½âÁËÎÊÌ⣬֮ºóÓÖ˵ÎÊÌâÔٴη¢Éú¡£Anonymous SudanÉù³Æ¶Ô´ËÊÂÂôÁ¦£¬ËµËûÃÇÔÚ¶Ô΢Èí½øÐÐDDoS¹¥»÷£¬»¹ÀÕË÷1000000ÃÀÔª¡£ËäÈ»¸Ã˵·¨ÉÐδµÃµ½Ö¤Êµ£¬µ«·þÎñÔÚ¹ýÈ¥24СʱÄÚÒ»Ö±ÔËÐлºÂý£¬²¢±»Ò»ÏµÁеÄÖжÏËùÀ§ÈÅ¡£
https://www.bleepingcomputer.com/news/microsoft/outlookcom-hit-by-outages-as-hacktivists-claim-ddos-attacks/
3¡¢Adlumin·¢ÏÖÕë¶ÔÃÀ¹úº½¿Õº½ÌìÒµµÄ¶ñÒâÈí¼þPowerDrop
AdluminÔÚ6ÔÂ5ÈÕÅû¶ÁËÒ»ÖÖÐÂÐͶñÒâPowerShell½Å±¾PowerDrop£¬Ö÷ÒªÕë¶ÔÃÀ¹úµÄº½¿Õº½ÌìÒµ¡£Ñо¿ÈËÔ±ÉϸöÔÂÔÚÃÀ¹úÒ»¼Ò¹ú·À³Ð°üÉ̵ÄϵͳÖз¢ÏÖÁ˶ñÒâÈí¼þÑù±¾¡£Æä³õÊ¼Ñ¬È¾ÔØÌåδ֪£¬Ñо¿ÈËÔ±ÍÆ²â£¬¹¥»÷Õß¿ÉÄÜÀûÓé¶´¡¢µöÓãÓʼþ»òαÔìÈí¼þÏÂÔØÍøÕ¾À´·Ö·¢½Å±¾¡£ËüÊÇÓÉWMI·þÎñÖ´ÐеÄPowerShell½Å±¾£¬²¢Ê¹ÓÃBase64½øÐбàÂëÒÔÓÃ×÷ºóÃÅ»òRAT¡£¸Ã¶ñÒâÈí¼þ»¹Ê¹ÓÃICMP»ØÏÔÇëÇóÏûÏ¢À´Æô¶¯ÓëC2·þÎñÆ÷µÄͨÐÅ¡£
https://adlumin.com/post/powerdrop-a-new-insidious-powershell-script-for-command-and-control-attacks-targets-u-s-aerospace-defense-industry/
4¡¢CiscoÐÞ¸´AnyConnectÖеÄÌáȨ©¶´CVE-2023-20178
ýÌå6ÔÂ7Èճƣ¬CiscoÐÞ¸´ÁËCisco Secure Client£¨ÒÔǰ³ÆAnyConnect Secure Mobility Client£©ÖеÄÌáȨ©¶´£¨CVE-2023-20178£©¡£µÍȨÏ޵ĵ±µØ¹¥»÷Õß¿ÉÒÔÔÚ²»ÓëÓû§½»»¥µÄµÍÅÓ´óÐÔ¹¥»÷ÖÐÀûÓôË©¶´£¬½«È¨ÏÞÌáÉýÖÁSYSTEM¡£¸Ã©¶´Ô´ÓÚ¶ÔÉý¼¶¹ý³ÌÖд´½¨µÄÒ»¸öÁÙʱĿ¼·ÖÅäÁ˲»Êʵ±µÄȨÏÞ£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÀûÓÃWindows°²×°·¨Ê½½ø³ÌµÄÌØ¶¨¹¦Ð§À´ÀûÓôË©¶´¡£Ä¿Ç°Â©¶´ÉÐδ±»ÔÚÒ°ÀûÓá£
https://www.bleepingcomputer.com/news/security/cisco-fixes-anyconnect-bug-giving-windows-system-privileges/
5¡¢VPN·þÎñÌṩÉÌi2VPNµÄ¹ÜÀíԱƾ֤±»¹ûÈ»ÔÚTelegram
SafetyDetectivesÓÚ6ÔÂ5ÈÕ³ÆÆä·¢ÏÖÁËÒ»ÆðÉæ¼°VPN·þÎñÌṩÉÌi2VPNµÄÊý¾Ýй¶Ê¼þ¡£ºÚ¿ÍÓÚ5ÔÂ29ÈÕÔÚTelegramÉÏÐû²¼Á˾ݳÆÀ´×Ôi2VPNµÄÐÅÏ¢£¬°üÂÞ¹ÜÀíÔ±µÄÓʼþµØÖ·ºÍÃÜÂ룬ÒÔ¼°ÏÔʾÊý¾ÝÖÐÐĺÍÓû§¶©ÔÄÏêϸÐÅÏ¢µÄ¹ÜÀíÃæ°åÆÁÄ»½ØÍ¼¡£ËäÈ»ºÚ¿ÍûÓÐÖ±½Ó¹ûÈ»Óû§Êý¾Ý£¬µ«±»ÈëÇֵĹÜÀíÃæ°åƾ¿É·ÃÎÊ´óÁ¿Óû§Êý¾Ý¡£i2VPN½öÔÚGoogle PlayÉ̵ê¾ÍÓÐÁè¼Ý500000µÄÏÂÔØÁ¿£¬ÔÚApp StoreµÄÏÂÔØÁ¿Î´¹ûÈ»¡£
https://www.safetydetectives.com/news/i2vpn-exposed-telegram/
6¡¢UptycsÐû²¼¹ØÓÚÐÂÀÕË÷ÍÅ»ïCyclopsµÄ¼¼Êõ·ÖÎö³ÂËß
6ÔÂ5ÈÕ£¬UptycsÐû²¼Á˹ØÓÚÀÕË÷ÍÅ»ïCyclopsµÄ¼¼Êõ·ÖÎö³ÂËß¡£Cyclops¿ª·¢ÁË¿ÉÒÔѬȾWindows¡¢LinuxºÍmacOSϵͳµÄ¶àƽ̨ÀÕË÷Èí¼þ¡£»¹ÌṩÁËÒ»ÖÖ»ùÓÚGoµÄµ¥¶ÀµÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ£¬ÕâÊÇΪWindowsºÍLinuxÖеÄÌØ¶¨Îļþ¶ø¿ª·¢µÄ¡£¸ÃÀÕË÷Èí¼þÖ§³ÖÅÓ´óµÄ¼ÓÃܹý³Ì£¬ËùÓй¦Ð§¶¼Ê¹Ó÷ǶԳƺͶԳƼÓÃܵÄ×éºÏ¾²Ì¬ÊµÏÖ¡£Ñо¿ÈËÔ±»¹·¢ÏÖ£¬CyclopsÓëBabukµÄ¼ÓÃÜÂß¼ÓÐÏàËÆÖ®´¦£¬Á½Õß¶¼Ê¹ÓÃCurve25519ºÍHC-256½øÐÐWindows¼ÓÃÜ£¬²¢½áºÏʹÓÃCurve25519ºÍChaCha¡£
https://www.uptycs.com/blog/cyclops-ransomware-stealer-combo