ÐÂ¼ÓÆÂGeniusUÒòй¶126ÍòÓû§µÄÐÅÏ¢±»·£¿£¿£¿£¿£¿£¿£¿£¿î3.5ÍòÃÀÔª

°ä²¼¹¦·ò 2022-04-24

1¡¢Cisco½¨¸´ÆäUmbrella VAµÈ¶à¸ö²úÆ·ÖеÄ3¸ö·ì϶


4ÔÂ21ÈÕ £¬£¬£¬£¬£¬ £¬£¬£¬Cisco°ä²¼°²È«¸üР£¬£¬£¬£¬£¬ £¬£¬£¬½¨¸´Æä¶à¿î²úÆ·Öеķì϶¡£¡£¡£¡£¡£ ¡£¡£ÆäÖÐÔ̺¬Cisco TelePresenceºÏ×÷Öն˺ÍRoomOSÈí¼þÖеĻؾø·þÎñ·ì϶£¨CVE-2022-20783£© £¬£¬£¬£¬£¬ £¬£¬£¬Ô´ÓÚ²»×ãÊäÈëÑéÖ¤£»£»£»£»£»£»£»Cisco UmbrellaÐé¹¹É豸(VA)¾²Ì¬SSHÖ÷»úÃÜÔ¿Öеķì϶£¨CVE-2022-20773£© £¬£¬£¬£¬£¬ £¬£¬£¬¿ÉÓÃÀ´¶ÔSSHÏνÓÖ´ÐÐMitM¹¥»÷²¢½Ù³ÖÖÎÀíԱʹ´¦£»£»£»£»£»£»£»ÒÔ¼°Cisco Virtualized Infrastructure ManagerÖеÄÌáȨ·ì϶£¨CVE-2022-20732£©¡£¡£¡£¡£¡£ ¡£¡£


https://www.cisa.gov/uscert/ncas/current-activity/2022/04/21/cisco-releases-security-updates-multiple-products-0


2¡¢T-Mobile³ÆLAPSUS$ÍÅ»ïʹÓñ»µÁÍ´´¦½Ó¼ûÆäÄÚ²¿ÏµÍ³


¾ÝýÌå4ÔÂ22ÈÕ±¨Â· £¬£¬£¬£¬£¬ £¬£¬£¬T-Mobile³ÆÀÕË÷ÍÅ»ïLapsus$ÔÚ¼¸ÖÜǰʹÓñ»µÁÍ´´¦ÈëÇÖÁËÆäÍøÂç £¬£¬£¬£¬£¬ £¬£¬£¬²¢»ñµÃÁ˶ÔÄÚ²¿ÏµÍ³µÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾²¹³ä˵ £¬£¬£¬£¬£¬ £¬£¬£¬ÔÚ·¢ÏÖÎÊÌâºóËüÁ¢¿Ì¶Â½ØÁ˹¥»÷Õß¶ÔÆäÍøÂçµÄ½Ó¼û £¬£¬£¬£¬£¬ £¬£¬£¬²¢½ûÓÃÁ˹¥»÷ÖÐʹÓõÄÍ´´¦¡£¡£¡£¡£¡£ ¡£¡£Æ¾¾ÝT-MobileµÄ˵·¨ £¬£¬£¬£¬£¬ £¬£¬£¬Lapsus$ÔÚ¹¥»÷ÆÚ¼ä²¢Î´ÇÔÈ¡¿Í»§µÄÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£×êÑÐÈËԱͨ¹ý¸ÃÍÅ»ïµÄÄÚ²¿Ì¸Ìì¼Í¼·¢ÏÖ £¬£¬£¬£¬£¬ £¬£¬£¬ËûÃǽӼûÁËT-MobileµÄÄÚ²¿¿Í»§ÕË»§ÖÎÀí¹¤¾ßAtlas £¬£¬£¬£¬£¬ £¬£¬£¬ÈëÇÔìäSlackºÍBitbucketÕË»§ £¬£¬£¬£¬£¬ £¬£¬£¬²¢ÀûÓÃÕË»§ÏÂÔØÁË30000¶à¸öÔ´´úÂë´æ´¢¿â¡£¡£¡£¡£¡£ ¡£¡£


https://thehackernews.com/2022/04/t-mobile-admits-lapsus-hackers-gained.html


3¡¢LockBitÐû³ÆÒÑÇÔÈ¡ÀïÔ¼ÈÈÄÚ¬²ÆÕþ²¿ÃÅÔ¼420GBµÄÊý¾Ý


ýÌå4ÔÂ22ÈÕ±¨Â· £¬£¬£¬£¬£¬ £¬£¬£¬ÀÕË÷ÍÅ»ïLockBitÐû³Æ¹¥»÷ÁËÀïÔ¼ÈÈÄÚ¬µ±¾Ö°ì¹«ÊÒµÄϵͳ £¬£¬£¬£¬£¬ £¬£¬£¬²¢ÇÔÈ¡ÁËÔ¼420 GBµÄÊý¾Ý¡£¡£¡£¡£¡£ ¡£¡£ÀïÔ¼ÈÈÄÚ¬ÊǰÍÎ÷µÚ¶þ´ó³ÇÊÐ £¬£¬£¬£¬£¬ £¬£¬£¬ÄÏÃÀÖ޵ĽðÈÚÖÐÐÄÖ®Ò» £¬£¬£¬£¬£¬ £¬£¬£¬ÆäGDPÔÚÈ«ÇòÅÅÃûµÚ30λ¡£¡£¡£¡£¡£ ¡£¡£ÀïÔ¼ÈÈÄÚ¬²ÆÕþ²¿ÃŵĹÙÔ±ÔÚÉÏÖÜÎå֤ʵ £¬£¬£¬£¬£¬ £¬£¬£¬Ä¿Ç°ÔÚ´¦ÖÃÕë¶ÔÆäϵͳµÄÀÕË÷¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£¸Ã¹ÙÔ±³Æ £¬£¬£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßÍþвҪй¶´ÓSefaz-RJϵͳÖÐÇÔÈ¡µÄÊý¾Ý £¬£¬£¬£¬£¬ £¬£¬£¬µ«ÕâЩÊý¾Ý½öÏ൱ÓÚÃØÊé´¦Öü´æÊý¾ÝµÄ0.05%¡£¡£¡£¡£¡£ ¡£¡£


https://therecord.media/rio-de-janeiro-finance-department-hit-with-lockbit-ransomware/


4¡¢ÃÀ¹úµ±¾Öй©ÆäÒÑÔÚDHS±í²¿ÏµÍ³Öз¢ÏÖ122¸ö°²È«·ì϶


¾Ý4ÔÂ22ÈÕ±¨Â· £¬£¬£¬£¬£¬ £¬£¬£¬ÃÀ¹úºÓɽ°²È«Êýй©ÆäHack DHS·ì϶Éͽð´òËãÒÑÔÚDHS±í²¿ÏµÍ³Öз¢ÏÖ122¸ö°²È«·ì϶¡£¡£¡£¡£¡£ ¡£¡£DHSÏò³¬¹ý450Ãû×êÑÐÈËÔ±¼Î½±ÁË125600ÃÀÔª £¬£¬£¬£¬£¬ £¬£¬£¬Ã¿¸ö·ì϶µÄ½«½ü¾ùÔÈΪ5000ÃÀÔª¡£¡£¡£¡£¡£ ¡£¡£Hack DHS´òËãÓÚ2021Äê12ÔÂÆô¶¯ £¬£¬£¬£¬£¬ £¬£¬£¬ËüÒªÇóºÚ¿ÍÅû¶·ì϶µÄ¾ßÌåÐÅÏ¢¡¢ÈôºÎÀûÓÃËüÒÔ¼°ÈôºÎʹÓÃËü½Ó¼ûDHSϵͳ¡£¡£¡£¡£¡£ ¡£¡£¶øºó £¬£¬£¬£¬£¬ £¬£¬£¬DHS½«ÔÚ48Ó×ʱÄÚÑéÖ¤·ì϶ £¬£¬£¬£¬£¬ £¬£¬£¬²¢ÔÚ15Ìì»ò¸ü³¤¹¦·òÄÚ½¨¸´¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/hack-dhs-bug-hunters-find-122-security-flaws-in-dhs-systems/


5¡¢ÐÂ¼ÓÆÂGeniusUÒòй¶126ÍòÓû§µÄÐÅÏ¢±»·£¿£¿£¿£¿£¿£¿£¿£¿î3.5ÍòÃÀÔª


ýÌå4ÔÂ22ÈÕ³Æ £¬£¬£¬£¬£¬ £¬£¬£¬ÐÂ¼ÓÆÂ½ÌÓý¿Æ¼¼¹«Ë¾GeniusUй¶126ÍòÓû§µÄÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£ÐÂ¼ÓÆÂÓ×ÎÒÊý¾Ý±£»£»£»£»£»£»£»¤Î¯Ô±»á(PDPC)ÔÚ4ÔÂ21ÈÕ°ä²¼µÄÊéÃæ¾ö¶¨ÖаµÊ¾ £¬£¬£¬£¬£¬ £¬£¬£¬GeniusUδÄÜÔì¶©ºÏÀíµÄÕ½Êõ £¬£¬£¬£¬£¬ £¬£¬£¬µ¼ÖÂÓû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢Î»ÏàÐÅÏ¢ºÍÉϴεǼIPµØÖ·µÈÐÅÏ¢±»µÁ £¬£¬£¬£¬£¬ £¬£¬£¬·£¿£¿£¿£¿£¿£¿£¿£¿î35000ÃÀÔª¡£¡£¡£¡£¡£ ¡£¡£GeniusUµÄÄÚ²¿µ÷²é·¢ÏÖ £¬£¬£¬£¬£¬ £¬£¬£¬Õâ´ÎÊÂÎñ¿ÉÄÜÊÇÆä¿ª·¢ÈËÔ±µÄÕÊ»§±»µÁµ¼Ö嵀 £¬£¬£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßʹÓÃËûµÄGitHubÕÊ»§ÕÒµ½Á˵Ǽʹ´¦ £¬£¬£¬£¬£¬ £¬£¬£¬»ñµÃÁËGeniusUÊý¾Ý¿âµÄ½Ó¼ûȨÏÞ²¢ÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£ ¡£¡£


https://www.straitstimes.com/tech/tech-news/edu-tech-firm-geniusu-fined-35000-for-data-leak-affecting-126m-users


6¡¢Mandiant°ä²¼2021ÄêÒѱ»ÀûÓÃ0-dayµÄ·ÖÎö»ã±¨


4ÔÂ21ÈÕ £¬£¬£¬£¬£¬ £¬£¬£¬Mandiant°ä²¼ÁË2021ÄêÒѱ»ÀûÓÃ0-dayµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£ ¡£¡£»ã±¨Ö¸³ö £¬£¬£¬£¬£¬ £¬£¬£¬MandiantÔÚÈ¥Äê·¢ÏÖÁË80Æð0-dayÔÚÒ°±í±»ÀûÓõÄÊÂÎñ £¬£¬£¬£¬£¬ £¬£¬£¬±È2020ÄêºÍ2019ÄêµÄ×ܺͻ¹¶àÁË18Æð¡£¡£¡£¡£¡£ ¡£¡£2021Äê0-day¹¥»÷µÄÖØÒª³§ÉÌÊÇ΢Èí¡¢Æ»¹ûºÍ¹È¸è £¬£¬£¬£¬£¬ £¬£¬£¬Õ¼ËùÓй¥»÷µÄ75%ÒÔÉÏ¡£¡£¡£¡£¡£ ¡£¡£Õë¶ÔÒÆ¶¯²Ù×÷ϵͳAndroidºÍiOSµÄ0-dayÊýÁ¿Ò²³ÊÉÏÉýÇ÷Ïò £¬£¬£¬£¬£¬ £¬£¬£¬´Ó2019ÄêºÍ2020ÄêµÄ²»µ½5¸öÔö³¤µ½2021ÄêµÄ17¸ö¡£¡£¡£¡£¡£ ¡£¡£´ó²¿ÃŹ¥»÷¹éÒòÓÚ¹ú¶ÈÖ§³ÖµÄ¼äµý»î¶¯ £¬£¬£¬£¬£¬ £¬£¬£¬ÀûÓÃ0-dayµÄ¹¥»÷ÕßÖÐÓÐÈý·ÖÖ®Ò»³öÓÚ¾­¼Ã¶¯»ú¡£¡£¡£¡£¡£ ¡£¡£


https://www.mandiant.com/resources/zero-days-exploited-2021