Google PlayÉϵĶà¸ö¶ñÒâÀûÓÃÒѱ»×°Öýü1000Íò´Î

°ä²¼¹¦·ò 2022-07-28

1¡¢Google PlayÉϵĶà¸ö¶ñÒâÀûÓÃÒѱ»×°Öýü1000Íò´Î

      

¾Ý7ÔÂ26ÈÕ±¨Â·£¬£¬ £¬£¬£¬×êÑÐÈËÔ±ÔÚGoogle PlayÉ̵êÖз¢ÏÖÁË28¸ö¶ñÒâAndroidÀûÓ÷¨Ê½£¬£¬ £¬£¬£¬ÀÛ¼ÆÏÂÔØÁ¿½ü1000Íò´Î¡£¡£¡£¡£¡£¡£ÕâЩÀûÓüÙ×°³ÉͼÏñ±à×빤¾ß¡¢Ðé¹¹¼üÅÌ¡¢ÏµÍ³ÓÅ»¯¹¤¾ßºÍ±ÚÖ½¸ü»»¹¤¾ßµÈ¡£¡£¡£¡£¡£¡£ËüÃǵĸù»ùÖ°ÄÜÊÇÍÆËͶñÒâ¸æ°×¡¢ÎªÓû§¶©Ôĸ߼¶·þÎñÒÔ¼°ÇÔȡָ±êµÄÉ罻ýÌåÕÊ»§¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬ £¬£¬£¬¹È¸èÒѾ­É¾³ýÁ˾ø´óÎÞÊý¶ñÒâÀûÓᣡ£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬ £¬£¬£¬ÏÂÔØÀûÓÃʱ²é³­Óû§ÆÀÂÛºÍÆÀ¼¶¡¢½Ó¼û¿ª·¢ÕßÍøÕ¾¡¢ÔĶÁÒþÖÔÕþ²ß²¢ÔÚ×°Öùý³ÌÖаÑÎÈÒªÇóµÄȨÏÞÖÁ¹Ø³ÁÒª¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-android-malware-apps-installed-10-million-times-from-google-play/


2¡¢ÃÀ¹úÍйܷþÎñÉÌNetStandardÔâµ½¹¥»÷ºóÔÆ·þÎñ¹Ø¹Ø

      

ýÌå7ÔÂ27ÈÕ±¨Â·£¬£¬ £¬£¬£¬ÃÀ¹úÍйܷþÎñÌṩÉÌNetStandardÔâµ½¹¥»÷£¬£¬ £¬£¬£¬µ¼Ö¸ù«Ë¾µÄMyAppsAnywhereÔÆ·þÎñ¹Ø¹Ø¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾·¢Ë͸øÓû§µÄÓʼþÖÐд·£¬£¬ £¬£¬£¬ÔÚ7ÔÂ26ÈÕCDTÉÏÎç11:30×óÓÒ£¬£¬ £¬£¬£¬NetStandardÔÚMyAppsAnywhereµÄϵͳÖз¢ÏÖÁ˹¥»÷¼£Ï󣬣¬ £¬£¬£¬MyAppsAnywhere·þÎñ£¨Ô̺¬Hosted GP¡¢Hosted CRM¡¢Hosted ExchangeºÍHosted Sharepoint£©½«ÀëÏߣ¬£¬ £¬£¬£¬Ö±ÖÁÁíÐÐ֪ͨ¡£¡£¡£¡£¡£¡£³ýÁËÔÆ·þÎñ±í£¬£¬ £¬£¬£¬¸Ã¹«Ë¾µÄÖØÒªÍøÕ¾Ò²ÒѾ­¹Ø¹Ø¡£¡£¡£¡£¡£¡£NetStandardûÓÐй©¸ü¶àϸ½Ú£¬£¬ £¬£¬£¬Éв»Ã÷ÏÔ¹¥»÷µÄÀàÐÍ£¬£¬ £¬£¬£¬×êÑÐÈËÔ±ÒÔΪÕâºÜ¿ÉÄÜÊÇÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/kansas-msp-shuts-down-cloud-services-to-fend-off-cyberattack/


3¡¢×êÑÐÍŶӷ¢ÏÖÓÃÀ´½Ù³ÖFacebookÆóÒµÕË»§µÄDucktail

      

WithSecureÔÚ7ÔÂ26ÈÕÅû¶ÁËÕë¶ÔFacebookÆóÒµÕÊ»§µÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þDucktailµÄϸ½Ú¡£¡£¡£¡£¡£¡£¸Ã»î¶¯ÖÁÉÙ×Ô2021Äê7ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬£¬ £¬£¬£¬×îÔç¿É×·Òäµ½2018Ä꣬£¬ £¬£¬£¬ÓëÔ½ÄϵĹ¥»÷ÍÅ»ïÓйء£¡£¡£¡£¡£¡£¹¥»÷Õß»áÁªÏµLinkedInÉÏ¿ÉÄÜÓÐFacebookÆóÒµÕÊ»§½Ó¼ûȨÏÞµÄÔ±¹¤£¬£¬ £¬£¬£¬ÀýÈçÊý×ÖýÌåºÍÊý×ÖÓªÏú¹¤×÷µÄÓû§£¬£¬ £¬£¬£¬ÓÕʹËûÃÇÏÂÔØÍйÜÔÚDropbox»òiCloudµÈºÏ·¨·þÎñÉϵÄÎļþÀ´·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£DucktailÖ¼ÔÚÇÔÈ¡ä¯ÀÀÆ÷cookie£¬£¬ £¬£¬£¬²¢ÀûÓþ­¹ýÉí·ÝÑéÖ¤µÄFacebook»á»°´ÓÖ¸±êÕÊ»§ÖÐÇÔÊØÐÅÏ¢£¬£¬ £¬£¬£¬×îÖÕ½Ù³ÖFacebookÆóÒµÕË»§¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/linkedin-phishing-target-employees-managing-facebook-ad-accounts/


4¡¢Nuki½¨¸´ÆäÖÇÄÜËø²úÆ·ÖдæÔÚµÄ11¸ö°²È«·ì϶

     

¾ÝýÌå7ÔÂ26ÈÕ±¨Â·£¬£¬ £¬£¬£¬NCC·¢ÏÖÁËNukiÖÇÄÜËøÖжà´ï11¸öÑϳÁµÄ·ì϶¡£¡£¡£¡£¡£¡£Õâ´ÎÅû¶µÄ·ì϶Ô̺¬¿Éµ¼ÖÂÖÐÑëÈ˹¥»÷µÄSSL/TLSÖ¤ÊéÑéÖ¤²»×ã·ì϶£¨CVE-2022-32509£©¡¢¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐеIJֿ⻺³åÇøÒç¶Âí½Å£¨CVE-2022-32504£©¡¢²»³ä·ÖµÄ½Ó¼û½ÚÔ죨CVE-2022-32507£©¡¢SWDÓ²¼þ½Ó¿Ú¶³ö£¨CVE-2022-32506£©ºÍDoS·ì϶£¨CVE-2022-32508£©¡£¡£¡£¡£¡£¡£NCCÓÚ2022Äê4ÔÂ20ÈÕ´«µÝÁËÕâЩ·ì϶£¬£¬ £¬£¬£¬NukiÔÚ6ÔÂ9ÈÕÕë¶ÔËùÓзì϶°ä²¼Á˲¹¶¡¡£¡£¡£¡£¡£¡£


https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/


5¡¢Check Point°ä²¼2022ÄêQ2ÍøÂç¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨

      

7ÔÂ26ÈÕ£¬£¬ £¬£¬£¬Check Point°ä²¼ÁË2022ÄêQ2ÍøÂç¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£Óë2021ÄêQ2Ïà±È£¬£¬ £¬£¬£¬2022ÄêQ2È«ÇòÍøÂç¹¥»÷ÊýÁ¿Ôö³¤ÁË32%£¬£¬ £¬£¬£¬È«Çòÿ¸ö×éÖ¯¾ùÔÈÿÖܹ¥»÷´ÎÊý´ïµ½ÁË1.2K´ÎµÄ·åÖµ¡£¡£¡£¡£¡£¡£½ÌÓýºÍ×êÑÐÐÐÒµÒÀÈ»ÊÇÔâµ½¹¥»÷×î¶àµÄÐÐÒµ£¬£¬ £¬£¬£¬¾ùÔÈÿ¸ö×éÖ¯Ôâµ½1.7K´Î¹¥»÷£¬£¬ £¬£¬£¬ÓëÉÏÒ»ÄêÏà±ÈÔö³¤ÁË59%¡£¡£¡£¡£¡£¡£·ÇÖÞÊÇÕâÒ»¼¾¶ÈÔâµ½¹¥»÷×î¶àµÄµØÓò£¬£¬ £¬£¬£¬Ã¿¸ö×éÖ¯¾ùÔÈÿÖܹ¥»÷Ôâµ½1.76k´Î£¬£¬ £¬£¬£¬Í¬±ÈÔö³¤ÁË3%¡£¡£¡£¡£¡£¡£


https://blog.checkpoint.com/2022/07/26/check-point-research-weekly-cyber-attacks-increased-by-32-year-over-year-1-out-of-40-organizations-impacted-by-ransomware-2/


6¡¢Unit 42°ä²¼¹ØÓÚ2022Äê¹¥»÷ÊÂÎñÏìÓ¦µÄ·ÖÎö»ã±¨


Unit 42ÓÚ7ÔÂ26ÈÕ°ä²¼Á˹ØÓÚ2022Äê¹¥»÷ÊÂÎñÏìÓ¦µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£½ØÖÁ6Ô£¬£¬ £¬£¬£¬Unit 42ÔÚ2022Äê´¦ÖõÄÊÂÎñÏìÓ¦°¸¼þÖÐÖ§¸¶µÄ¾ùÔÈÀÕË÷Èí¼þÓöÈΪ925162ÃÀÔª£¬£¬ £¬£¬£¬±È2021ÄêÔö³¤ÁË71%¡£¡£¡£¡£¡£¡£ÀÕË÷¹¥»÷ºÍBECÊÇ´ÓǰһÄêÖÐÏìÓ¦µÄÖØÒª¹¥»÷£¬£¬ £¬£¬£¬Ô¼Õ¼È«ÊýÊÂÎñÏìÓ¦°¸ÀýµÄ70%£¬£¬ £¬£¬£¬65%µÄÔÆ°²È«ÊÂÎñÊÇÓÉÓÚÅäÖÃÃýÎóµ¼Öµġ£¡£¡£¡£¡£¡£ÖØÒªµÄ³õʼ½Ó¼ûý½éÊÇ´¹µö¹¥»÷¡¢·ì϶ÀûÓúͱ©Á¦¹¥»÷£¨ÖØÒªÕë¶ÔÔ¶³Ì×ÀÃæºÍ̸£©¡£¡£¡£¡£¡£¡£87%µÄ±»ÀûÓ÷ì϶½öÀ´×Ô6¸öCVEÀà±ð£ºProxyShell£¨55%£©Log4Shell£¨14% £©¡¢SonicWall CVE£¨7%£©¡¢ProxyLogon£¨5%£©¡¢Zoho ManageEngine ADSelfService Plus£¨4%£©ºÍFortiNet CVE£¨3%£©¡£¡£¡£¡£¡£¡£


https://www.paloaltonetworks.com/unit42/2022-incident-response-report