Ñо¿ÍŶӷ¢ÏÖ³¬¼¶Êý¾Ýй¶ºÏ¼¯´ï12TBº­¸Ç260ÒÚÌõÊý¾Ý

Ðû²¼Ê±¼ä 2024-01-24
1. Ñо¿ÍŶӷ¢ÏÖ³¬¼¶Êý¾Ýй¶ºÏ¼¯´ï12TBº­¸Ç260ÒÚÌõÊý¾Ý


1ÔÂ22ÈÕ  £¬Õâ´Î³¬´ó¹æÄ£Ð¹Â¶°üÂÞÀ´×Ô֮ǰ¶à´Îй¶µÄÊý¾Ý  £¬ÆäÖаüÂÞÁîÈËÕð¾ªµÄ 12 TB ÐÅÏ¢  £¬º­¸ÇÁîÈËÄÑÒÔÖÃÐÅµÄ 260 ÒÚÌõÊý¾Ý¡£Õâ´Î³¬´ó¹æÄ£Ð¹Â¶°üÂÞÀ´×Ô֮ǰ¶à´Îй¶µÄÊý¾Ý  £¬ÆäÖаüÂÞÁîÈËÕð¾ªµÄ 12 TB ÐÅÏ¢  £¬º­¸ÇÁîÈËÄÑÒÔÖÃÐÅµÄ 260 ÒÚÌõÊý¾Ý¡£¼¸ºõ¿ÉÒԿ϶¨  £¬Õâ´Îй©ÊÇÆù½ñΪֹ·¢ÏÖµÄ×î´óµÄÒ»´ÎÊý¾Ýй¶¡£¾Ý³ÆÓÐÊýÒÚÌõÊý¾ÝÀ´×Ô΢²© (504M)¡¢MySpace (360M)¡¢Twitter (281M)¡¢Deezer (258M)¡¢Linkedin (251M)¡¢AdultFriendFinder (220M)¡¢Adobe (153M)¡¢Canva (143M) ¡¢VK (101M)¡¢Daily Motion (86M)¡¢Dropbox (69M)¡¢Telegram (41M) ÒÔ¼°Ðí¶àÆäËû¹«Ë¾ºÍ×éÖ¯¡£´Ë´Îй¶»¹°üÂÞÃÀ¹ú¡¢°ÍÎ÷¡¢µÂ¹ú¡¢·ÆÂɱö¡¢ÍÁ¶úÆäºÍÆäËû¹ú¼Ò¸÷¸öÕþ¸®×éÖ¯µÄ¼Ç¼¡£


2. ÎÚ¿ËÀ¼×î´óµÄÊÖ»úÒøÐÐMonobankÔâÓöǰËùδÓеÄDDoS¹¥»÷


1ÔÂ22ÈÕ  £¬ÎÚ¿ËÀ¼×î´óµÄÊÖ»úÒøÐÐMonobankÓÚ 1 Ô 21 ÈÕÔâÓöÒ»Á¬´®¾Ü¾ø·þÎñ (DDoS) ¹¥»÷  £¬µ¼ÖÂÆäÔËӪ̱»¾²¢Ôì³É´ó·¶Î§ÖжÏ¡£ÁªºÏÊ×´´È˼æÊ×ϯִÐй٠Oleh Horokhovskyi ÔÚTelegram ÉÏ֤ʵÁËMonobank Ôâµ½ÍøÂç¹¥»÷  £¬²¢Í¸Â¶ÆäÖÐÒ»´Î¹¥»÷ÖиÃÒøÐÐÊÕµ½Á˾ªÈ赀 5.8 ÒÚ¸ö·þÎñÇëÇó¡£DDoS ¹¥»÷Éæ¼°Óùý¶àµÄÁ÷Á¿Ñ¹¿åÍøÕ¾  £¬Ê¹Æä·þÎñÆ÷³¬ÔØ  £¬ÒѳÉΪѰÇóÆÆ»µ·þÎñµÄÍøÂç·¸×ï·Ö×Ó×îϲ»¶µÄ¼ÆÄ±¡£¶íÂÞ˹ºÚ¿Í×éÖ¯ Solntsepek Éù³Æ¶ÔKyivstar ÍøÂç¹¥»÷ÂôÁ¦  £¬Òý·¢ÈËÃǶԶíÂÞ˹¿ÉÄܼÓÈë×î½üµÄ Monobank DDoS ¹¥»÷µÄ»³ÒÉ¡£


3. LoanDepotÔâµ½ÀÕË÷¹¥»÷²¢È·ÈÏÆäÔ¼1660Íò¿Í»§ÐÅÏ¢±»µÁ


ÔÚ 1 Ô 22 ÈÕÏòÃÀ¹ú֤ȯ½»Ò×ίԱ»á (SEC) Ìá½»µÄÒ»·ÝÐÂÎļþÖÐ  £¬LoanDepot ÌṩÁËÓÐ¹Ø 1 Ô 8 ÈÕÓ°Ïì¸Ã¹«Ë¾¼ÆËã»úϵͳµÄÍøÂçʼþµÄ¸ü¶àϸ½Ú¡£µÖѺ´û¿îÌṩÉÌ´Ëǰ½«¸ÃʼþÃèÊöΪÀÕË÷Èí¼þ¹¥»÷¡£ËäÈ»¸Ã¹«Ë¾ÈÔÔÚ¡°Íⲿȡ֤ºÍÄþ¾²×¨¼Ò¡±µÄ×ÊÖúÏÂÊÓ²ì´Ë´Îй¶Ê¼þ  £¬µ«¿ª¶Ë½á¹ûÏÔʾ  £¬¡°Î´¾­ÊÚȨµÄµÚÈý·½»ñÈ¡ÁËÆäϵͳÖÐÔ¼ 1660 ÍòÈ˵ÄÃô¸Ð¸öÈËÐÅÏ¢¡£¡±LoanDepot ÔÊÐí֪ͨÊÜÓ°ÏìµÄ¿Í»§  £¬²¢ÌṩÃâ·ÑµÄÐÅÓÃ¼à¿ØºÍÉí·Ý± £»¤·þÎñ¡£


4. GoAnywhere MFT ÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý©¶´CVE-2024-0204


1ÔÂ22ÈÕ  £¬GoAnywhere MFTÊÇÒ»ÖÖÄþ¾²µÄÍйÜÎļþ´«Êä (MFT) ½â¾ö·½°¸  £¬¿É×ÊÖú×éÖ¯×Ô¶¯»¯¡¢¼¯Öл¯ºÍ± £»¤ÆäÎļþ´«Êä¡£ËüÊÇÒ»¸öÈí¼þƽ̨  £¬¿ÉÒÔÏû³ýÔÚ²îÒìϵͳºÍÈËÔ±Ö®¼äÒÆ¶¯Êý¾ÝµÄÂé·³¡£GoAnywhere MFT ÊÇÒ»¿î¹¦Ð§Ç¿´óÇҶ๦ЧµÄ½â¾ö·½°¸  £¬ÊʺÏÐèÒªÓÐЧ± £»¤ºÍ¹ÜÀíÎļþ´«ÊäµÄ×éÖ¯¡£¸ÃÎļþ´«Êä½â¾ö·½°¸¾¯±¨µÄ×îпª·¢ÈËÔ±½ÒʾÁËÒ»¸öÑÏÖØÈ±ÏÝ  £¬¸ÃȱÏÝ¿ÉÄÜ»áÈÆ¹ýÉí·ÝÑéÖ¤µÄ±¾ÖÊ¡£¸ÃȱÏݵıàºÅΪ CVE-2024-0204  £¬CVSS ÆÀ·ÖΪ 9.8  £¬±»ÃèÊöΪ Fortra 7.4.1 °æ±¾Ö®Ç°µÄ GoAnywhere MFT ÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý©¶´¡£´ËȱÏÝÇÉÃîµØÔÊÐíδ¾­ÊÚȨµÄÓû§Í¨¹ý¹ÜÀíÃÅ»§Î±×°³É¹ÜÀíÔ±¡£


5. ÑÅ»¢ÒòΪÀÄÓÃCookie±»·¨¹ú¼à¹Ü»ú¹¹·£¿î 1000 ÍòÅ·Ôª


1ÔÂ22ÈÕ  £¬·¨¹úÊý¾Ý± £»¤¼à¹Ü»ú¹¹ÖÜËÄÌåÏÖ  £¬Ëü¶ÔÑÅ»¢´¦ÒÔ 1000 ÍòÅ·ÔªµÄ·£¿î  £¬Ô­ÒòÊÇÑÅ»¢²»×ðÖØÓû§¾Ü¾ø»¥ÁªÍø¸ú×Ù¡°cookie¡±µÄÒªÇó  £¬»òÕßÌåÏÖÈç¹û¾Ü¾ø  £¬ËûÃǽ«ÎÞ·¨·ÃÎʵç×ÓÓʼþÕ˺Å¡£CNIL Õþ¸®ÓÚ 2020 Äê 10 ÔÂºÍ 2021 Äê 6 ÔÂÊÕµ½Í¶Ëß²¢¿ªÕ¹ÊÓ²ìºó  £¬ÓÚ 12 Ô´¦ÒÔÏ൱ÓÚ 1090 ÍòÃÀÔªµÄ·£¿î¡£Ñо¿·¢ÏÖ  £¬·ÃÎÊ Yahoo.com Ö÷ÍøÕ¾µÄ·ÃÎÊÕßËäÈ»µã»÷Á˾ܾø cookie µÄ°´Å¥  £¬µ«×îÖÕ»¹ÊÇÊÕµ½ÁËԼĪ 20 ¸öÓÃÓÚ¹ã¸æÄ¿µÄµÄÊý×Ö¸ú×ÙÆ÷¡£×Ô 2018 ÄêÅ·ÃËͨÓÃÊý¾Ý± £»¤ÌõÀý (GDPR) ³ǫ̈ÒÔÀ´  £¬»¥ÁªÍø¹«Ë¾ÔÚ»ñµÃÓû§Í¬ÒâÈçºÎʹÓÃÆä¸öÈËÐÅÏ¢·½ÃæÃæÁÙןüÑϸñµÄ¹æÔò¡£·¨¹ú¶Ô¹È¸è¡¢Meta¡¢ÑÇÂíÑ·¡¢Î¢Èí¡¢Æ»¹ûºÍ TikTok µÈ¹«Ë¾µÄÎ¥¹æÐÐΪ½øÐÐÁË´¦·£  £¬·£¿î×ܶî½ü 4 ÒÚÅ·Ôª¡£


6. Ñо¿ÍŶӷ¢ÏÖÕë¶ÔýÌåºÍר¼ÒµÄÍøÂç¹¥»÷»î¶¯ScarCruft


1ÔÂ22ÈÕ  £¬ÔÚ´í×ÛÅÓ´óµÄÈ«ÇòÍøÂç¼äµýÍøÂçÖÐ  £¬¹ú¼ÒÖ§³ÖµÄ¸ß¼¶Á¬ÐøÍþв (APT)×éÖ¯£¨ ScarCruft£©µÄ»î¶¯ÒòÆä¾«È·ÐÔºÍÕ½ÂÔÖØµã¶øÍÑÓ±¶ø³ö¡£½üÈÕ  £¬ÉÚ±øÊµÑéÊÒ  £¬ÓëNK ÐÂÎźÏ×÷  £¬½Ò¿ªÁË ScarCruft ¾«ÐijïıµÄÒ»³¡Õë¶ÔýÌå×éÖ¯ºÍ³¯ÏÊÊÂÎñר¼ÒµÄ»î¶¯¡£ÕâÒ»Ðж¯ÒÔ³Ö¾ÃÐÔºÍÅÓ´óÐÔÎªÌØµã  £¬·´Ó³ÁËÍøÂçÕ½ÖÐ΢ÃîµÄȨÁ¦²©ÞÄ¡£Á½¸ö¶àÔÂÒÔÀ´  £¬SentinelLabs ÊӲ쵽 ScarCruft Á¬ÐøÕë¶Ôͬһ¸öÈË  £¬ÕâÈÃÎÒÃǵÃÒÔÒ»¿ú APT µÄ·îÏ×¾«ÉñºÍ×ãÖǶàı¡£ÕâһĿ±êÉæ¼°º«¹úѧÊõ½çµÄר¼ÒºÍרÃÅÑо¿³¯ÏÊÊÂÎñµÄÐÂÎÅ»ú¹¹¡£ÕâЩ¹¥»÷¼òÖ±ÇÐÐÔÖʱíÃ÷ÁË ScarCruft µÄÕ½ÂÔÄ¿±ê£ºÊÕ¼¯Ç鱨²¢Ó°Ïì¿´·¨¡£ScarCruft  £¬Ò²³ÆÎª APT37 ºÍ InkySquid  £¬ÔÚÆäÎäÆ÷¿âÖÐʹÓÃÁ˶àÖÖ¹¤¾ßºÍÒªÁì¡£¸Ã»î¶¯µÄÌØµãÊÇʹÓÃÁ˶¨ÖƵĺóÃÅ RokRAT  £¬ÕâÊÇÒ»ÖÖ¹¦Ð§ÆëÈ«µÄ¼àÊÓ¹¤¾ß  £¬Äܹ»¶ÔÄ¿±êʵÌå½øÐÐÓÐЧµÄ¼äµý»î¶¯¡£¸Ã×éÖ¯µÄѬȾÁ´Éæ¼°¶à½×¶Î»úÖÆºÍ¶àÖÖ¿ÉÖ´Ðиñʽ  £¬²¢½ÓÄɹæ±Ü¼¼ÊõÀ´±£³Ö²»±»·¢ÏÖ¡£