ÐÂ¼ÓÆÂGeniusUÒòй¶126ÍòÓû§µÄÐÅÏ¢±»·£¿î3.5ÍòÃÀÔª

°ä²¼¹¦·ò 2022-04-24

1¡¢Cisco½¨¸´ÆäUmbrella VAµÈ¶à¸ö²úÆ·ÖеÄ3¸ö·ì϶


4ÔÂ21ÈÕ £¬Cisco°ä²¼°²È«¸üР£¬½¨¸´Æä¶à¿î²úÆ·Öеķì϶ ¡£ÆäÖÐÔ̺¬Cisco TelePresenceºÏ×÷Öն˺ÍRoomOSÈí¼þÖеĻؾø·þÎñ·ì϶£¨CVE-2022-20783£© £¬Ô´ÓÚ²»×ãÊäÈëÑéÖ¤£»Cisco UmbrellaÐé¹¹É豸(VA)¾²Ì¬SSHÖ÷»úÃÜÔ¿Öеķì϶£¨CVE-2022-20773£©  £¬¿ÉÓÃÀ´¶ÔSSHÏνÓÖ´ÐÐMitM¹¥»÷²¢½Ù³ÖÖÎÀíԱʹ´¦£»ÒÔ¼°Cisco Virtualized Infrastructure ManagerÖеÄÌáȨ·ì϶£¨CVE-2022-20732£© ¡£


https://www.cisa.gov/uscert/ncas/current-activity/2022/04/21/cisco-releases-security-updates-multiple-products-0


2¡¢T-Mobile³ÆLAPSUS$ÍÅ»ïʹÓñ»µÁÍ´´¦½Ó¼ûÆäÄÚ²¿ÏµÍ³


¾ÝýÌå4ÔÂ22ÈÕ±¨Â· £¬T-Mobile³ÆÀÕË÷ÍÅ»ïLapsus$ÔÚ¼¸ÖÜǰʹÓñ»µÁÍ´´¦ÈëÇÖÁËÆäÍøÂç £¬²¢»ñµÃÁ˶ÔÄÚ²¿ÏµÍ³µÄ½Ó¼ûȨÏÞ ¡£¸Ã¹«Ë¾²¹³ä˵ £¬ÔÚ·¢ÏÖÎÊÌâºóËüÁ¢¿Ì¶Â½ØÁ˹¥»÷Õß¶ÔÆäÍøÂçµÄ½Ó¼û £¬²¢½ûÓÃÁ˹¥»÷ÖÐʹÓõÄÍ´´¦ ¡£Æ¾¾ÝT-MobileµÄ˵·¨ £¬Lapsus$ÔÚ¹¥»÷ÆÚ¼ä²¢Î´ÇÔÈ¡¿Í»§µÄÐÅÏ¢ ¡£×êÑÐÈËԱͨ¹ý¸ÃÍÅ»ïµÄÄÚ²¿Ì¸Ìì¼Í¼·¢ÏÖ £¬ËûÃǽӼûÁËT-MobileµÄÄÚ²¿¿Í»§ÕË»§ÖÎÀí¹¤¾ßAtlas £¬ÈëÇÔìäSlackºÍBitbucketÕË»§ £¬²¢ÀûÓÃÕË»§ÏÂÔØÁË30000¶à¸öÔ´´úÂë´æ´¢¿â ¡£


https://thehackernews.com/2022/04/t-mobile-admits-lapsus-hackers-gained.html


3¡¢LockBitÐû³ÆÒÑÇÔÈ¡ÀïÔ¼ÈÈÄÚ¬²ÆÕþ²¿ÃÅÔ¼420GBµÄÊý¾Ý


ýÌå4ÔÂ22ÈÕ±¨Â· £¬ÀÕË÷ÍÅ»ïLockBitÐû³Æ¹¥»÷ÁËÀïÔ¼ÈÈÄÚ¬µ±¾Ö°ì¹«ÊÒµÄϵͳ £¬²¢ÇÔÈ¡ÁËÔ¼420 GBµÄÊý¾Ý ¡£ÀïÔ¼ÈÈÄÚ¬ÊǰÍÎ÷µÚ¶þ´ó³ÇÊÐ £¬ÄÏÃÀÖ޵ĽðÈÚÖÐÐÄÖ®Ò» £¬ÆäGDPÔÚÈ«ÇòÅÅÃûµÚ30λ ¡£ÀïÔ¼ÈÈÄÚ¬²ÆÕþ²¿ÃŵĹÙÔ±ÔÚÉÏÖÜÎå֤ʵ £¬Ä¿Ç°ÔÚ´¦ÖÃÕë¶ÔÆäϵͳµÄÀÕË÷¹¥»÷ ¡£¸Ã¹ÙÔ±³Æ £¬¹¥»÷ÕßÍþвҪй¶´ÓSefaz-RJϵͳÖÐÇÔÈ¡µÄÊý¾Ý £¬µ«ÕâЩÊý¾Ý½öÏ൱ÓÚÃØÊé´¦Öü´æÊý¾ÝµÄ0.05% ¡£


https://therecord.media/rio-de-janeiro-finance-department-hit-with-lockbit-ransomware/


4¡¢ÃÀ¹úµ±¾Öй©ÆäÒÑÔÚDHS±í²¿ÏµÍ³Öз¢ÏÖ122¸ö°²È«·ì϶


¾Ý4ÔÂ22ÈÕ±¨Â· £¬ÃÀ¹úºÓɽ°²È«Êýй©ÆäHack DHS·ì϶Éͽð´òËãÒÑÔÚDHS±í²¿ÏµÍ³Öз¢ÏÖ122¸ö°²È«·ì϶ ¡£DHSÏò³¬¹ý450Ãû×êÑÐÈËÔ±¼Î½±ÁË125600ÃÀÔª £¬Ã¿¸ö·ì϶µÄ½«½ü¾ùÔÈΪ5000ÃÀÔª ¡£Hack DHS´òËãÓÚ2021Äê12ÔÂÆô¶¯ £¬ËüÒªÇóºÚ¿ÍÅû¶·ì϶µÄ¾ßÌåÐÅÏ¢¡¢ÈôºÎÀûÓÃËüÒÔ¼°ÈôºÎʹÓÃËü½Ó¼ûDHSϵͳ ¡£¶øºó £¬DHS½«ÔÚ48Ó×ʱÄÚÑéÖ¤·ì϶ £¬²¢ÔÚ15Ìì»ò¸ü³¤¹¦·òÄÚ½¨¸´ ¡£


https://www.bleepingcomputer.com/news/security/hack-dhs-bug-hunters-find-122-security-flaws-in-dhs-systems/


5¡¢ÐÂ¼ÓÆÂGeniusUÒòй¶126ÍòÓû§µÄÐÅÏ¢±»·£¿î3.5ÍòÃÀÔª


ýÌå4ÔÂ22ÈÕ³Æ £¬ÐÂ¼ÓÆÂ½ÌÓý¿Æ¼¼¹«Ë¾GeniusUй¶126ÍòÓû§µÄÐÅÏ¢ ¡£ÐÂ¼ÓÆÂÓ×ÎÒÊý¾Ý±£»¤Î¯Ô±»á(PDPC)ÔÚ4ÔÂ21ÈÕ°ä²¼µÄÊéÃæ¾ö¶¨ÖаµÊ¾ £¬GeniusUδÄÜÔì¶©ºÏÀíµÄÕ½Êõ £¬µ¼ÖÂÓû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢Î»ÏàÐÅÏ¢ºÍÉϴεǼIPµØÖ·µÈÐÅÏ¢±»µÁ £¬·£¿î35000ÃÀÔª ¡£GeniusUµÄÄÚ²¿µ÷²é·¢ÏÖ £¬Õâ´ÎÊÂÎñ¿ÉÄÜÊÇÆä¿ª·¢ÈËÔ±µÄÕÊ»§±»µÁµ¼ÖµÄ £¬¹¥»÷ÕßʹÓÃËûµÄGitHubÕÊ»§ÕÒµ½Á˵Ǽʹ´¦ £¬»ñµÃÁËGeniusUÊý¾Ý¿âµÄ½Ó¼ûȨÏÞ²¢ÇÔÈ¡Êý¾Ý ¡£


https://www.straitstimes.com/tech/tech-news/edu-tech-firm-geniusu-fined-35000-for-data-leak-affecting-126m-users


6¡¢Mandiant°ä²¼2021ÄêÒѱ»ÀûÓÃ0-dayµÄ·ÖÎö»ã±¨


4ÔÂ21ÈÕ £¬Mandiant°ä²¼ÁË2021ÄêÒѱ»ÀûÓÃ0-dayµÄ·ÖÎö»ã±¨ ¡£»ã±¨Ö¸³ö £¬MandiantÔÚÈ¥Äê·¢ÏÖÁË80Æð0-dayÔÚÒ°±í±»ÀûÓõÄÊÂÎñ £¬±È2020ÄêºÍ2019ÄêµÄ×ܺͻ¹¶àÁË18Æð ¡£2021Äê0-day¹¥»÷µÄÖØÒª³§ÉÌÊÇ΢Èí¡¢Æ»¹ûºÍ¹È¸è £¬Õ¼ËùÓй¥»÷µÄ75%ÒÔÉÏ ¡£Õë¶ÔÒÆ¶¯²Ù×÷ϵͳAndroidºÍiOSµÄ0-dayÊýÁ¿Ò²³ÊÉÏÉýÇ÷Ïò £¬´Ó2019ÄêºÍ2020ÄêµÄ²»µ½5¸öÔö³¤µ½2021ÄêµÄ17¸ö ¡£´ó²¿ÃŹ¥»÷¹éÒòÓÚ¹ú¶ÈÖ§³ÖµÄ¼äµý»î¶¯ £¬ÀûÓÃ0-dayµÄ¹¥»÷ÕßÖÐÓÐÈý·ÖÖ®Ò»³öÓÚ¾­¼Ã¶¯»ú ¡£


https://www.mandiant.com/resources/zero-days-exploited-2021