΢ÈíÒòXbox¼Óº¦¶ùͯÒþÖÔ±»ÃÀ¹úFTC·  £¿î2000ÍòÃÀÔª

°ä²¼¹¦·ò 2023-06-08

1¡¢Î¢ÈíÒòXbox¼Óº¦¶ùͯÒþÖÔ±»ÃÀ¹úFTC·  £¿î2000ÍòÃÀÔª


¾ÝýÌå6ÔÂ6ÈÕ±¨Â· £¬Î¢ÈíÒòÎ¥·´Á˶ùͯÔÚÏßÒþÖÔ±£»¤·¨(COPPA) £¬±»FTC·  £¿î2000ÍòÃÀÔª¡£¸Ã»ú¹¹³Æ £¬Î¢ÈíÉæÏÓÔÚδÕ÷µÃ¸¸Ä¸ÔÞ³É £¬ÉõÖÁûÓÐ֪ͨËûÃǵÄÇé¿öÏ £¬ÍøÂç²¢±£Áô×¢²áXbox Live·þÎñµÄ¶ùͯµÄÓ×ÎÒÐÅÏ¢¡£ÔÚ2015ÄêÖÁ2020Äê¼äµÄһЩ°¸ÀýÖÐ £¬Î¢Èí½«¶ùͯÊý¾Ý´æ´¢ÔÚÆä·þÎñÆ÷Öг¤´ïÊýÄêÖ®¾Ã¡£·¨Í¥ÎļþÏÔʾ £¬´Ó2017Äê1Ôµ½2021Äê12Ô £¬Ô¼ÓÐ218000Ãû²»Âú13ËêµÄÃÀ¹úXboxÓÎÏ·»úÓû§´´½¨MicrosoftÕÊ»§¡£Ä¿Ç°Ë«·½ÒÑÔ޳ɸúͽâ £¬µ«ÈÔÔÚÆÚ´ý·¨ÔººË×¼¡£³ýÁË·  £¿î £¬¸Ã¹«Ë¾»¹Òª²ÉÈ¡±ØÒª´ëÊ©ÒÔÈ·±£×ñÊØCOPPA¡£


https://www.theregister.com/2023/06/06/microsoft_fined_20m_for_collecting/


2¡¢Outlook±»Anonymous Sudan DDoS¹¥»÷·þÎñÔÙ´ÎÖжÏ


¾Ý6ÔÂ6ÈÕ±¨Â· £¬Outlook.comÔÚ6ÔÂ5ÈÕ¾­ÀúÁËÁ½´Î³Á´óÖжÏÖ®ºó £¬ÓÖ²úÉúÁËһϵÁеķþÎñÖжÏ¡£OutlookÓû§ÔÚTwitterÉϱ§Ô¹µç×ÓÓʼþ·þÎñ²»²»±ä £¬Ó°ÏìÁËËûÃǵŤ×÷ЧÄÜ¡£Î¢Èí˵ÕâЩ¹ÊÕÏÊÇÓɼ¼ÊõÎÊÌâÒýÆðµÄ £¬ÔÚTwitterÉϰ䲼Á˸üÐÂ˵»º½âÁËÎÊÌâ £¬Ö®ºóÓÖ˵ÎÊÌâÔٴβúÉú¡£Anonymous SudanÐû³Æ¶Ô´ËÊÂÕÆ¹Ü £¬ËµËûÃÇÔÚ¶Ô΢Èí½øÐÐDDoS¹¥»÷ £¬»¹ÀÕË÷1000000ÃÀÔª¡£¹ÌÈ»¸Ã˵·¨ÉÐδµÃµ½Ö¤Êµ £¬µ«·þÎñÔÚ´Óǰ24Ó×ʱÄÚÒ»ÏòÔËÐлºÂý £¬²¢±»Ò»ÏµÁеÄÖжÏËùÀ§ÈÅ¡£


https://www.bleepingcomputer.com/news/microsoft/outlookcom-hit-by-outages-as-hacktivists-claim-ddos-attacks/


3¡¢Adlumin·¢ÏÖÕë¶ÔÃÀ¹úº½¿Õº½ÌìÒµµÄ¶ñÒâÈí¼þPowerDrop 


AdluminÔÚ6ÔÂ5ÈÕÅû¶ÁËÒ»ÖÖÐÂÐͶñÒâPowerShell¾ç±¾PowerDrop £¬ÖØÒªÕë¶ÔÃÀ¹úµÄº½¿Õº½ÌìÒµ¡£×êÑÐÈËÔ±ÉϸöÔÂÔÚÃÀ¹úÒ»¼Ò¹ú·À³Ð°üÉ̵ÄϵͳÖз¢ÏÖÁ˶ñÒâÈí¼þÑù±¾¡£Æä³õÊ¼Ï°È¾ÔØÌåδ֪ £¬×êÑÐÈËÔ±´§Ä¦ £¬¹¥»÷Õß¿ÉÄÜÀûÓ÷ì϶¡¢´¹µöÓʼþ»òαÔìÈí¼þÏÂÔØÍøÕ¾À´·Ö·¢¾ç±¾¡£ËüÊÇÓÉWMI·þÎñÖ´ÐеÄPowerShell¾ç±¾ £¬²¢Ê¹ÓÃBase64½øÐбàÂëÒÔÓÃ×÷ºóÃÅ»òRAT¡£¸Ã¶ñÒâÈí¼þ»¹Ê¹ÓÃICMP»ØÏÔÒªÇóÐÂÎÅÀ´Æô¶¯ÓëC2·þÎñÆ÷µÄͨѶ¡£


https://adlumin.com/post/powerdrop-a-new-insidious-powershell-script-for-command-and-control-attacks-targets-u-s-aerospace-defense-industry/


4¡¢Cisco½¨¸´AnyConnectÖеÄÌáȨ·ì϶CVE-2023-20178


ýÌå6ÔÂ7ÈÕ³Æ £¬Cisco½¨¸´ÁËCisco Secure Client£¨ÒÔǰ³ÆAnyConnect Secure Mobility Client£©ÖеÄÌáȨ·ì϶£¨CVE-2023-20178£©¡£µÍȨÏ޵ı¾µØ¹¥»÷ÕßÄܹ»ÔÚ²»ÓëÓû§½»»¥µÄµÍ¸´ÔÓÐÔ¹¥»÷ÖÐÀûÓô˷ì϶ £¬½«È¨ÏÞÌáÉýÖÁSYSTEM¡£¸Ã·ì϶ԴÓÚ¶ÔÉý¼¶¹ý³ÌÖд´½¨µÄÒ»¸öһʱĿ¼·ÖÅäÁ˲»Êʵ±µÄȨÏÞ £¬¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓÃWindows×°Ö÷¨Ê½¹ý³ÌµÄÌØ¶¨Ö°ÄÜÀ´ÀûÓô˷ì϶¡£Ä¿Ç°·ì϶ÉÐδ±»ÔÚÒ°ÀûÓá£


https://www.bleepingcomputer.com/news/security/cisco-fixes-anyconnect-bug-giving-windows-system-privileges/


5¡¢VPN·þÎñÌṩÉÌi2VPNµÄÖÎÀíԱƾ֤±»¹«¿ªÔÚTelegram


SafetyDetectivesÓÚ6ÔÂ5ÈÕ³ÆÆä·¢ÏÖÁËÒ»Â·Éæ¼°VPN·þÎñÌṩÉÌi2VPNµÄÊý¾Ýй¶ÊÂÎñ¡£ºÚ¿ÍÓÚ5ÔÂ29ÈÕÔÚTelegramÉϰ䲼Á˾ݳÆÀ´×Ôi2VPNµÄÐÅÏ¢ £¬Ô̺¬ÖÎÀíÔ±µÄÓʼþµØÖ·ºÍÃÜÂë £¬ÒÔ¼°ÏÔʾÊý¾ÝÖÐÐĺÍÓû§¶©ÔľßÌåÐÅÏ¢µÄÖÎÀíÃæ°åÆÁÄ»½ØÍ¼¡£¹ÌÈ»ºÚ¿ÍûÓÐÖ±½Ó¹«¿ªÓû§Êý¾Ý £¬µ«±»ÈëÇÖµÄÖÎÀíÃæ°åƾ¿É½Ó¼û´óÁ¿Óû§Êý¾Ý¡£i2VPN½öÔÚGoogle PlayÉ̵ê¾ÍÓг¬¹ý500000µÄÏÂÔØÁ¿ £¬ÔÚApp StoreµÄÏÂÔØÁ¿Î´¹«¿ª¡£


https://www.safetydetectives.com/news/i2vpn-exposed-telegram/


6¡¢Uptycs°ä²¼¹ØÓÚÐÂÀÕË÷ÍÅ»ïCyclopsµÄ¼¼Êõ·ÖÎö»ã±¨


6ÔÂ5ÈÕ £¬Uptycs°ä²¼Á˹ØÓÚÀÕË÷ÍÅ»ïCyclopsµÄ¼¼Êõ·ÖÎö»ã±¨¡£Cyclops¿ª·¢ÁËÄܹ»Ï°È¾Windows¡¢LinuxºÍmacOSϵͳµÄ¶àƽ̨ÀÕË÷Èí¼þ¡£»¹ÌṩÁËÒ»ÖÖ»ùÓÚGoµÄµ¥¶ÀµÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ £¬ÕâÊÇΪWindowsºÍLinuxÖеÄÌØ¶¨Îļþ¶ø¿ª·¢µÄ¡£¸ÃÀÕË÷Èí¼þÖ§³Ö¸´ÔӵļÓÃܹý³Ì £¬ËùÓÐÖ°Äܶ¼Ê¹Ó÷ǶԳƺͶԳƼÓÃܵÄ×éºÏ¾²Ì¬ÊµÏÖ¡£×êÑÐÈËÔ±»¹·¢ÏÖ £¬CyclopsÓëBabukµÄ¼ÓÃÜÂß¼­ÓÐÀàËÆÖ®´¦ £¬Á½Õß¶¼Ê¹ÓÃCurve25519ºÍHC-256½øÐÐWindows¼ÓÃÜ £¬²¢½áºÏʹÓÃCurve25519ºÍChaCha¡£


https://www.uptycs.com/blog/cyclops-ransomware-stealer-combo