΢ÈíAI²¿ÃÅÑо¿ÈËÔ±ÒâÍâй¶38 TB˽ԿºÍÃÜÂëµÈÊý¾Ý

Ðû²¼Ê±¼ä 2023-09-19

1¡¢Î¢ÈíAI²¿ÃÅÑо¿ÈËÔ±ÒâÍâй¶38 TB˽ԿºÍÃÜÂëµÈÊý¾Ý


¾Ý9ÔÂ18ÈÕ±¨µÀ£¬Äþ¾²¹«Ë¾Wiz·¢ÏÖ£¬Î¢ÈíAIÑо¿²¿ÃÅÔÚÏò¹«¹²GitHub´æ´¢¿âТ¾´¿ªÔ´È˹¤ÖÇÄÜѧϰģÐÍʱÒâÍâй¶ÁË38 TBµÄÃô¸ÐÊý¾Ý ¡£Ð¹Â¶µÄÊý¾Ý°üÂÞ΢Èí·þÎñµÄÃÜÂë¡¢ÃÜÔ¿ÒÔ¼°À´×Ô359Ãû΢ÈíÔ±¹¤µÄ30000¶àÌõÄÚ²¿TeamsÏûÏ¢µÄ´æµµ ¡£Î¢Èí½«Êý¾Ýй¶ÓëʹÓùýÓÚ¿íËɵĹ²Ïí·ÃÎÊÇ©Ãû£¨SAS£©ÁîÅÆÁªÏµÆðÀ´£¬¸ÃÁîÅÆ¿É¶Ô¹²ÏíÎļþ½øÐÐÍêÈ«¿ØÖÆ ¡£Êý¾Ý×Ô2020Äê7Ô¿ªÊ¼Ð¹Â¶£¬ÓÚ½ñÄê6ÔÂ24ÈÕ½â¾ö ¡£

 

https://securityaffairs.com/151004/data-breach/microsoft-ai-data-leak.html


2¡¢Trygg-Hansaй¶65Íò¿Í»§ÐÅÏ¢±»Èðµä·£¿î3500Íò¿ËÀÊ


¾ÝýÌå9ÔÂ17ÈÕ±¨µÀ£¬±£ÏÕ¹«Ë¾Trygg-HansaÒòй¶650000Ãû¿Í»§µÄÐÅÏ¢£¬±»ÈðµäÒþ˽±£»¤¾Ö£¨IMY£©´¦ÒÔ3500ÍòÈðµä¿ËÀʵÄÐÐÕþ´¦·£¿î ¡£IMYµÄÉó²éÏÔʾ£¬2018Äê10ÔÂÖÁ2021Äê2ÔÂÆÚ¼ä¿É·ÃÎÊ65ÍòÃû¿Í»§µÄÊý¾Ý£¬ÆäÖгýÁ˽¡¿µÊý¾ÝÍ⣬»¹ÓвÆÕþÐÅÏ¢¡¢ÁªÏµ·½Ê½¡¢Éç½»ÐÅÏ¢¡¢Äþ¾²ºÅÂëºÍ±£ÏÕ³ÖÓÐÁ¿µÈÆäËüÊý¾Ý ¡£IMYÖ¸³ö£¬Trygg-HansaÔÚʹÓÃÏà¹ØITϵͳ֮ǰ£¬»òÔÚʹÓøÃϵͳµÄºÜ³¤Ò»¶Îʱ¼äÄÚ¶¼Ó¦¸ÃÓлú»á·¢ÏÖ²¢ÐÞ¸´¸ÃÎÊÌâ ¡£IMYÈÏΪTrygg-Hansaδ½ÓÄÉÊʵ±µÄ´ëÊ©À´È·±£Óë·çÏÕÏà³ÆµÄÄþ¾²¼¶±ð£¬Òò´Ë·£¿î3500Íò¿ËÀÊ ¡£


https://www.databreaches.net/swedens-privacy-protection-agency-fines-insurer-trygg-hansa-for-exposing-sensitive-customer-data/


3¡¢USDoDй¶ÃÀ¹úÐÅÓûú¹¹TransUnionÁè¼Ý3 GBµÄÊý¾Ý


9ÔÂ18ÈÕ±¨µÀ³Æ£¬ÍâºÅΪUSDoDµÄºÚ¿Íй¶Á˾ݳÆÊÇ´ÓÃÀ¹úÏû·ÑÕßÐÅÓûú¹¹TransUnionÇÔÈ¡µÄÊý¾Ý ¡£TransUnionÊÇÃÀ¹úÈý´óÕ÷ОÞÍ·Ö®Ò»£¬ÊÕ¼¯²¢»ã×ÜÁË30¶à¸ö¹ú¼ÒºÍµØÓòµÄÁè¼Ý10ÒÚÏû·ÑÕßµÄÐÅÏ¢ ¡£´Ë´Îй¶µÄÊý¾Ý¿âÁè¼Ý3 GB£¬°üÂÞÔ¼58505È˵ÄPIIÐÅÏ¢£¬±é²¼È«Çò£¬°üÂÞÃÀ¹úºÍÅ·ÖÞ ¡£vx-underground³Æ£¬¸Ãµµ°¸°üÂÞ¿É×·Ëݵ½2022Äê3ÔÂ2ÈÕµÄÊý¾Ý ¡£²»¾Ãǰ£¬USDoD»¹Ð¹Â¶ÁËAirbusµÄ3200Ãû¹©Ó¦É̵ÄÐÅÏ¢£¬ÒÔ¼°FBI¹²ÏíϵͳInfraGardµÄÊý¾Ý¿â ¡£


https://securityaffairs.com/150968/data-breach/transunion-data-leak.html


4¡¢GoogleͬÒâÒÔ9300ÍòÃÀÔªºÍ½âAndroidÓû§×·×ÙµÄËßËÏ


ýÌå9ÔÂ15Èճƣ¬GoogleͬÒâÖ§¸¶9300ÍòÃÀÔª£¬ÒԺͽâÒ»ÏîÖ¸¿ØÆäÎ¥·´ÃÀ¹úÏû·ÑÕß±£»¤·¨µÄËßËÏ ¡£¼ÓÖÝ˾·¨²¿µÄÒ»ÏîÊӲ췢ÏÖ£¬GoogleÔÚÊÕ¼¯¡¢±£ÁôºÍÀûÓÃAndroidÓû§µÄλÖÃÊý¾ÝÓÃÓÚÏû·ÑÕß·ÖÎöºÍ¹ã¸æµÈÄ¿µÄ·½Ãæ´æÔÚÆÛÆ­ÐÐΪ£¬ËùÓÐÕâЩ¶¼Ã»ÓлñµÃÓû§µÄÖªÇéºÍͬÒâ ¡£ÖصãÊÇλÖøú×Ù£¬µ±Óû§ÍêÈ«½ûÓÃλÖøú×Ùʱ£¬»áĬÈÏÆôÓá°ÍøÂçºÍÓ¦Ó÷¨Ê½»î¶¯¡±ÉèÖ㬿ÉÊÕ¼¯¡¢±£ÁôºÍÀûÓÃÓû§µÄλÖÃÊý¾Ý ¡£ÔںͽâÖ®ºó£¬GoogleͬÒâʵʩԽ·¢Óû§ÓѺõÄÕÊ»§¿ØÖÆ£¬Í¬Ê±ÏÞÖÆÌØ¶¨Î»ÖÃÊý¾ÝÀà´ËÍâʹÓúͱ£Áô ¡£


https://www.bleepingcomputer.com/news/google/google-pays-93m-to-settle-android-tracking-lawsuit-in-california/


5¡¢Î¢ÈíÅû¶ncurses¿âÖеÄÄÚ´æËð»µÂ©¶´CVE-2023-29491


΢ÈíÔÚ9ÔÂ14ÈÕÅû¶ÁËncurses¿âÖеÄÒ»×éÄÚ´æËð»µÂ©¶´µÄϸ½ÚÐÅÏ¢ ¡£ÕâЩ©¶´Í³³ÆÎªCVE-2023-29491£¨CVSSÆÀ·Ö7.8£©£¬¿É±»ÓÃÀ´ÔÚLinuxºÍmacOSϵͳÉÏÖ´ÐжñÒâ´úÂë ¡£ncurses¿âÓÚ1993ÄêÐû²¼£¬Ìṩ֧³Ö»ùÓÚÎı¾µÄÓû§½çÃæ(TUI)µÄAPI£¬Í¨³£±»¿ÉÒÆÖ²²Ù×÷ϵͳ½Ó¿Ú(POSIX)ϵͳÉϵÄÖÖÖÖ·¨Ê½Ê¹Óà ¡£ÀûÓû·¾³±äÁ¿Öж¾£¬¹¥»÷Õß¿ÉÒÔ½áºÏʹÓÃÕâЩ©¶´À´ÌáÉýȨÏÞ£¬²¢ÔÚÄ¿±ê·¨Ê½µÄϵͳÖÐÔËÐдúÂë»òÖ´ÐÐÆäËü¹¥»÷ ¡£Î¢ÈíÓÚ4Ô·ÝÐÞ¸´Á˸é¶´ ¡£


https://www.microsoft.com/en-us/security/blog/2023/09/14/uncursing-the-ncurses-memory-corruption-vulnerabilities-found-in-library/


6¡¢MandiantÐû²¼¹ØÓÚUNC3944¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß


9ÔÂ14ÈÕ£¬MandiantÐû²¼Á˹ØÓÚUNC3944¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß ¡£×Ô2022ÄêÖÁ2023Äê³õ£¬UNC3944רעÓÚ·ÃÎÊÓÃÓÚ½øÐÐSIM½»»»¹¥»÷µÄƾ֤»òϵͳ£¬È»¶øÔÚ2023ÄêÖÐÆÚ£¬UNC3944¿ªÊ¼×ªÏòÔÚÄ¿±êϵͳÖв¿ÊðÀÕË÷Èí¼þ ¡£Ñо¿ÈËÔ±ÔÚUNC3944Ðж¯ÆÚ¼äÊӲ쵽µÄTTP£¬°üÂ޷dz£ÒÀÀµÓÚÉ繤¹¥»÷½øÐгõʼ·ÃÎÊ£¬Ê¹ÓÃÉÌҵסլÊðÀí·þÎñ´Óͬһ¾ÖÓò·ÃÎÊÄ¿±êÒÔÈÆ¹ý¼à¿Ø¹¤¾ß£¬Ê¼ÖÕʹÓúϷ¨Èí¼þ£¬Ðж¯½Ú×༫¿ì²¢ÔÚ¼¸ÌìÄÚ¾ÍÄÜ·ÃÎÊÒªº¦ÏµÍ³À´ÇÔÈ¡´óÁ¿Êý¾ÝµÈ ¡£


https://www.mandiant.com/resources/blog/unc3944-sms-phishing-sim-swapping-ransomware