MetaºÍÃÀ¹úÁ½¼ÒÒ½ÁÆ»ú¹¹±»¸æ×´ÍøÂ综ÕßÐÅϢͶ·Å¸æ°×

°ä²¼¹¦·ò 2022-08-01
1¡¢MetaºÍÃÀ¹úÁ½¼ÒÒ½ÁÆ»ú¹¹±»¸æ×´ÍøÂ综ÕßÐÅϢͶ·Å¸æ°×

      

¾ÝýÌå7ÔÂ30ÈÕ±¨Â· £¬¼ÓÖݱ±Çø¶ÔMeta¡¢UCSFÒ½ÁÆÖÐÐĺÍDignity½¡È«Ò½ÁÆ»ù½ð»áÌáÆð¼¯ÌåËßËÏ £¬Ö¸¿ØËûÃÇ·¸·¨ÍøÂçÓйػ¼ÕßµÄÒ½ÁÆÊý¾Ý²¢ÓÃÓÚ¶¨ÏòͶ·Å¸æ°×¡£·¨ÔºÎļþÏÔʾ £¬»¼ÕßÔÚFacebookºÍÓÊÏäÖÐÊÕµ½ÁËÓÐÕë¶ÔÐԵĸæ°× £¬ÕâЩ¸æ°×ÔÚûÓпÆÑ§Ö§³ÖµÄÇé¿öÏÂÐû´«¼²²¡ºÍÒ½ÁÆ·þÎñ¡£Meta PixelÊÇÒ»¶Î´úÂë £¬Äܹ»×¢ÈëÈκÎÍøÕ¾ £¬ÒÔ½øÐзÿͷÖÎö¡¢Êý¾ÝÍøÂçºÍ¶¨ÏòͶ·Å¸æ°×¡£Æ¾¾ÝͶËß £¬±»·¢ÏÖʹÓÃÁËMeta PixelµÄ33¼ÒÒ½Ôº½öÔÚ2020Äê¾Í¹²ÊÕÖÎÁË2600¶àÍòÃû»¼Õß¡£


https://www.bleepingcomputer.com/news/security/meta-us-hospitals-sued-for-using-healthcare-data-to-target-ads/


2¡¢ShinyHuntersÍÅ»ïµÄ³ÁÒª³ÉÔ±ÔÚÀ­°ÍÌØ¹ú¼Ê»ú³¡±»²¶ 

      

ýÌå7ÔÂ31ÈÕ³Æ £¬Èû°Í˹µÙ°²¡¤À­ÎÚ¶û£¨±ðÃûSezyo£©ÓÚ2022Äê6ÔÂ1ÈÕÔÚÀ­°ÍÌØ¹ú¼Ê»ú³¡±»²¶¡£ËûÊÇShinyHuntersÍÅ»ïµÄ³ÁÒª³ÉÔ±Ö®Ò» £¬ÔøÈëÇÖÁËÊý°Ù¸öÃÀ¹ú×éÖ¯¡£³ýÁËÀ­ÎÚ¶û £¬»¹ÓÐÆäËû4Ãû·¨¹ú¾ÓÃñÓ¦Áª¹úµ÷²é¾ÖµÄÒªÇó½ÓÊÜÁËÎÊѶ¡£ÃÀ¹ú´Ë¿ÌÒªÇóÒÔÍøÂçڲƭºÍÍøÂç·¸×ïµÄÖ¸¿Ø½«ÏÓÒÉÈËÒý¶Éµ½ÃÀ¹ú £¬È»¶øÀ­ÎÚ¶ûµÄÂÉʦ»Ø¾øÁËÕâÒ»ÒªÇó £¬³Æ¸Ã°¸¼þÊôÓÚ·¨¹ú¹ÜϽÁìÓò £¬ÓÉÓÚÎ¥·¨ÐÐΪÊÇÓÉ·¨¹ú¹úÃñÔÚ·¨¹ú½øÐеÄ¡£·¨¹úL'Obs±¨Â· £¬ÏÓÒÉÈ˱»²¶ºóÒ»Ïò±»¹ØÑºÔÚTiflet¼àÓü £¬²¢Ãæ¶Ô×Å116ÄêµÄ½ûïÀ¡£


https://www.hackread.com/alleged-shinyhunters-hacker-group-member-arrested/


3¡¢AdrasteaÐû³ÆÒÑÈëÇÖÅ·ÖÞµ¼µ¯Ôì×÷ÉÌMBDA²¢ÇÔÈ¡60GBÊý¾Ý

      

¾Ý7ÔÂ31ÈÕ±¨Â· £¬AdrasteaÐû³ÆÒÑÈëÇÖMBDA²¢ÇÔÈ¡60 GBÊý¾Ý¡£MBDAÊÇÅ·ÖÞµÄÒ»¼Ò¿ç¹úµ¼µ¯¿ª·¢É̺ÍÔì×÷ÉÌ £¬ÓÉ·¨¹ú¡¢Ó¢¹úºÍÒâ´óÀûÖØÒªµÄµ¼µ¯ÏµÍ³¹«Ë¾£¨A¨¦rospatiale¨CMatra¡¢BAE SystemsºÍFinmeccanica£©¹é²¢¶ø³É¡£Adrastea°µÊ¾ £¬ËûÃÇÔÚ¹«Ë¾µÄ»ù´¡ÉèÊ©Öз¢ÏÖÁËÑϳÁ·ì϶ £¬²¢ÒÑÏÂÔØÉæ¼°¾üÊÂÏîÄ¿¡¢Ã³Ò׻¡¢ºÏͬºÍ̸ÒÔ¼°ÓëÆäËü¹«Ë¾Í¨Ñ¶ÐÅÏ¢µÄ60 GBÊý¾Ý¡£×÷Ϊ¹¥»÷µÄÖ¤¾Ý £¬Adrastea°ä²¼ÁËÒ»¸öÁ´½Ó £¬Ô̺¬ÓëÏîÄ¿ºÍͨѶÓйصÄÄÚ²¿Îļþ¡£Ä¿Ç° £¬Éв»Ã÷ÏÔ¹ØÓÚÕâ´Î¹¥»÷µÄϸ½ÚÐÅÏ¢¡£


https://securityaffairs.co/wordpress/133881/data-breach/mbda-alleged-data-breach.html


4¡¢SharpTongueÀûÓöñÒâä¯ÀÀÆ÷À©´óÇÔȡָ±êµÄÓʼþÊý¾Ý

      

¾ÝVolexityÔÚ7ÔÂ28ÈÕ±¨Â· £¬³¯ÏʺڿÍÍÅ»ïSharpTongueÔÚ»ùÓÚChromiumµÄä¯ÀÀÆ÷Éϲ¿Êð¶ñÒâÀ©´ó·¨Ê½ £¬Ö¼ÔÚ´ÓGmailºÍAOLÇÔÈ¡µç×ÓÓʼþÊý¾Ý¡£¾ÝϤ £¬¸ÃÍÅ»ïÓëÒ»¸ö³ÆÎªKimsukyµÄÍÅ»ïÓÐËù³Áµþ¡£SharpTongueÖØÒªÕë¶ÔΪÃÀ¹ú¡¢Å·Ö޺ͺ«¹úµÄ×éÖ¯¹¤×÷ £¬´ÓÊÂÉæ¼°³¯ÏÊ¡¢ºËÎÊÌâ¡¢±øÆ÷ϵͳµÈ¶Ô³¯ÏÊÓµÓÐÕ½ÊõÒâ˼µÄÎÊÌâµÄÖ¸±ê¡£ÔÚÕâ´Î»î¶¯ÖÐ £¬¹¥»÷ÕßÊ×ÏÈ´Ó±»Ï°È¾µÄÍøÕ¾ÊÖ¶¯ÇÔȡװÖÃÀ©´óËùÐèµÄÎļþ £¬Ò»µ©³É¹¦¹¥»÷Ö¸±êWindowsϵͳ £¬¾Í»á´úÌæä¯ÀÀÆ÷µÄÊ×Ñ¡ÏîºÍ°²È«Ê×Ñ¡Ïî £¬ÔÙͨ¹ýVBS¾ç±¾ÊÖ¶¯×°ÖöñÒâÀ©´óSHARPEXT¡£


https://www.volexity.com/blog/2022/07/28/sharptongue-deploys-clever-mail-stealing-browser-extension-sharpext/


5¡¢Ó¢¹úWooton UpperѧÌÃÔâµ½Hive¹¥»÷±»ÀÕË÷50ÍòÓ¢°÷

      

ýÌå7ÔÂ28ÈÕ³Æ £¬Ó¢¹ú±´µÂ¸£µÂ¿¤µÄWooton Upper SchoolÔâµ½¹¥»÷ºó £¬±»ÀÕË÷500000Ó¢°÷¡£¹¥»÷Ô´ÓÚHive £¬¸ÃÍÅ»ïÒÑÏòѧÉúºÍ¼Ò³¤·¢ËÍÐÂÎÅ £¬³ÆËûÃÇÔÚÊýÖÜǰÈëÇÖÁËWoottonµÄϵͳ £¬²¢Éè·¨¼ÓÃÜÁËWoottonËùÓеķþÎñÆ÷ £¬Ô̺¬½ð²®ÀûѧԺ(Kimberley College) £¬ÇÔÈ¡Á˼Òͥסַ¡¢ÒøÐоßÌåÐÅÏ¢¡¢Ò½ÁƼͼºÍѧÉúµÄÉúÀíÆÀ¹ÀµÈÐÅÏ¢¡£¸ÃѧÌÃÕÆ¹ÜÈËÒÑÈ·ÈÏÔâµ½ÁËÍøÂç¹¥»÷ £¬ËûÃÇÔÚÔì¶©´òËãÀ´³Á½¨ÆäITϵͳ¡£Ä¿Ç°ÎÞ·¨È·¶¨¸´Ô­ËùÐ蹦·ò £¬µÚÈý·½½¨ÒéΪ7µ½10¸ö¹¤×÷ÈÕ¡£


https://www.infosecurity-magazine.com/news/ransomware-group-500000-school/


6¡¢ENISA°ä²¼¹ØÓÚ2021Äê³Á´óµçÐŰ²È«ÊÂÎñµÄ»ã×ܻ㱨

      

7ÔÂ28ÈÕ±¨Â· £¬ENISA°ä²¼¹ØÓÚ2021Äê³Á´óµçÐŰ²È«ÊÂÎñµÄ»ã×ܻ㱨¡£»ã±¨Ô̺¬ÁËÀ´×Ô26¸öÅ·Ã˳ÉÔ±¹ú(MS)ºÍ2¸öEFTA¹ú¶ÈÈ·µ±¾ÖÌá½»µÄ168ÆðÊÂÎñ»ã±¨µÄÓйØÊý¾Ý £¬Óû§ËðʧµÄ×ܹ¦·ò£¨Í¨¹ý¶Ôÿ¸öÊÂÎñµÄÓû§Êý³ËÒÔÓ×ʱÊýµÃ³ö£©Îª51.06ÒÚ¸öÓû§Ó×ʱ¡£2021ÄêÉϱ¨µÄÊÂÎñÖÐÓÐ4.16%Éæ¼°OTTͨÕÛ·þÎñ£»±»ÏóÕ÷Ϊ¶ñÒâÊÂÎñÊýÁ¿´Ó2020ÄêµÄ4%ÉÏÉýµ½2021ÄêµÄ8%£»ÏµÍ³¹ÊÕÏÈÔÔÚÓ°Ïì·½ÃæÕ¼¾ÝÖ÷µ¼Ö°Î» £¬ÔÚ2021ÄêÔì³ÉÁË3.63ÒÚÓû§Ó×ʱµÄËðʧ £¬¶ø2020ÄêΪ4.19ÒÚ¡£


https://securityaffairs.co/wordpress/133756/reports/telecom-security-incidents-2021-enisa.html