McGraw HillµÄ´æ´¢Í°ÅäÖÃÃýÎóй¶22TBÊý¾Ý

°ä²¼¹¦·ò 2022-12-21
1¡¢McGraw HillµÄAWS S3´æ´¢Í°ÅäÖÃÃýÎóй¶22TBÊý¾Ý

      

¾Ý12ÔÂ19ÈÕ±¨Â·£¬£¬£¬ £¬ £¬ £¬£¬ £¬×êÑÐÈËÔ±·¢ÏÖÁËÁ½¸öÅäÖÃÃýÎóµÄAmazon Web Services S3´æ´¢Í°£¬£¬£¬ £¬ £¬ £¬£¬ £¬ÆäËùÓÐÕß±»È·¶¨ÎªMcGraw Hill¡£¡£¡£¡£¡£¸Ãƽ̨ÊÇÃÀ¹úÈý´ó½ÌÓýÄÚÈݳö°æÉÌÖ®Ò»£¬£¬£¬ £¬ £¬ £¬£¬ £¬Ò²±»¼ÓÄôó¸÷µØµÄ½ÌÓý»ú¹¹ÓÃÓÚÔÚÏ߿γ̡£¡£¡£¡£¡£Õâ´ÎÊÂÎñ×ܹ²Ð¹Â¶ÁË1.17ÒÚ¸öÎļþ£¬£¬£¬ £¬ £¬ £¬£¬ £¬±ðÀëΪһ¸öÔ̺¬10TBÊý¾ÝµÄ·Ç³ö²ú´æ´¢Í°£¬£¬£¬ £¬ £¬ £¬£¬ £¬ÒÔ¼°Ò»¸öÔ̺¬12TBÊý¾ÝµÄ³ö²ú´æ´¢Í°£¬£¬£¬ £¬ £¬ £¬£¬ £¬ÓÚ2022Äê6ÔÂ12ÈÕ³õ´Î±»·¢ÏÖ¡£¡£¡£¡£¡£×êÑÐÈËԱй©£¬£¬£¬ £¬ £¬ £¬£¬ £¬Ô¼10ÍòÃûѧÉú»áÊܵ½¸ÃÊÂÎñµÄÓ°Ï죬£¬£¬ £¬ £¬ £¬£¬ £¬Ä¿Ç°Â¶³öµÄ´æ´¢Í°Òѱ»±£»£»£» £»£»£»£»¤ÆðÀ´¡£¡£¡£¡£¡£


https://www.hackread.com/american-online-ed-platform-22tb-data-leak/


2¡¢DraftKings³¬¹ý6Íò¿Í»§µÄÐÅÏ¢ÒòÔ⵽ײ¿â¹¥»÷й¶

      

ýÌå12ÔÂ19Èճƣ¬£¬£¬ £¬ £¬ £¬£¬ £¬ÌåÓý²©²Ê¹«Ë¾DraftKingsÉÏÖÜй©£¬£¬£¬ £¬ £¬ £¬£¬ £¬67995¸ö¿Í»§µÄÓ×ÎÒÐÅÏ¢ÔÚ11Ô·ݵÄÒ»´Îײ¿â¹¥»÷ÖÐй¶¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾£¬£¬£¬ £¬ £¬ £¬£¬ £¬¹¥»÷Õß´ÓÆäËü´¦Ëù»ñµÃÁ˵Ǽ¿Í»§ÕÊ»§ËùÐèµÄÍ´´¦£¬£¬£¬ £¬ £¬ £¬£¬ £¬¿Í»§µÄÉç»á°²È«ºÅÂë¡¢¼ÝÕÕºÅÂëºÍ½ðÈÚÕ˺Ų¢Î´Ð¹Â¶¡£¡£¡£¡£¡£DraftKingsÔÚ¼ì²âµ½¹¥»÷ºó³ÁÖÃÁËÊÜÓ°ÏìÕÊ»§µÄÃÜÂ룬£¬£¬ £¬ £¬ £¬£¬ £¬²¢Ö´ÐÐÁ˶î±íµÄڲƭ¾¯±¨¡£¡£¡£¡£¡£OktaÔÚ9Ô·ݻ㱨³Æ£¬£¬£¬ £¬ £¬ £¬£¬ £¬½ñÄêµÄÇé¿ö¼±¾ç¶ñ»¯£¬£¬£¬ £¬ £¬ £¬£¬ £¬ËüÔÚ2022ÄêǰÈý¸öÔ¾ͼͼÁ˳¬¹ý100ÒÚ´Îײ¿âÊÂÎñ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/draftkings-warns-data-of-67k-people-was-exposed-in-account-hacks/


3¡¢Î¢ÈíÔÚMacOSÖз¢ÏÖ¿ÉÈÆ¹ýGatekeeperµÄ·ì϶Achilles

      

12ÔÂ19ÈÕ£¬£¬£¬ £¬ £¬ £¬£¬ £¬Î¢ÈíÅû¶ÁËMacOSÖпÉÈÆ¹ýGatekeeperµÄ·ì϶Achilles£¨CVE-2022-42821£©¡£¡£¡£¡£¡£GatekeeperÊÇmacOSµÄÒ»ÏȫְÄÜ£¬£¬£¬ £¬ £¬ £¬£¬ £¬»á×Ô¶¯²é³­ÏÂÔØµÄÀûÓÃÊÇ·ñ¾­¹ý¹«Ö¤ºÍ¿ª·¢ÈËÔ±ÊðÃû£¨AppleºË×¼£©¡£¡£¡£¡£¡£Achilles·ì϶¿Éͨ¹ýÌØÔìµÄpayloadÀûÓÃÂß¼­ÎÊÌâÀ´ÉèÖÃÏÞ¶ÈÐÔACLȨÏÞ£¬£¬£¬ £¬ £¬ £¬£¬ £¬´Ó¶ø×èÖÓίÀÀÆ÷ºÍ»¥ÁªÍøÏÂÔØÆ÷ΪÏÂÔØµÄZIPÎļþ´æµµµÄpayloadÉèÖÃcom.apple.quarantineÊôÐÔ¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬ £¬ £¬ £¬£¬ £¬Ô̺¬ÔÚ´æµµpayloadÖеĶñÒâÀûÓûáÔÚÖ¸±êϵͳÉÏÆô¶¯£¬£¬£¬ £¬ £¬ £¬£¬ £¬¶ø²»ÊDZ»Gatekeeper×èÖ¹¡£¡£¡£¡£¡£AppleÒÑÔÚ12ÔÂ13ÈÕ°ä²¼µÄ¸üÐÂÖн¨¸´¸Ã·ì϶¡£¡£¡£¡£¡£


https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/


4¡¢¼ÙÒâSentinelOne SDKµÄ¶ñÒâPyPI°üÇÔÈ¡¿ª·¢ÈËÔ±Êý¾Ý

      

ReversingLabsÔÚ12ÔÂ19ÈÕ³ÆÆä·¢ÏÖÒ»¸ö¶ñÒâPython°ü¼ÙÒⰲȫ¹«Ë¾SentinelOneµÄÈí¼þ¿ª·¢¹¤¾ß°ü(SDK)¡£¡£¡£¡£¡£¸ÃÈí¼þ°üÓëSentinelOne¹«Ë¾Ã»ÓÐÈκθÉϵ£¬£¬£¬ £¬ £¬ £¬£¬ £¬ÓÚ2022Äê12ÔÂ11ÈÕ³õ´ÎÉÏ´«µ½ PyPI£¬£¬£¬ £¬ £¬ £¬£¬ £¬¶ûºó¸üÐÂÁË20´Î£¬£¬£¬ £¬ £¬ £¬£¬ £¬×îа汾Ϊ1.2.1£¬£¬£¬ £¬ £¬ £¬£¬ £¬ÓÚ12ÔÂ13ÈÕÉÏ´«¡£¡£¡£¡£¡£¶ñÒâ°üÖÐÔ̺¬´øÓжñÒâ´úÂëµÄapi.pyÎļþ£¬£¬£¬ £¬ £¬ £¬£¬ £¬´Ë¶ñÒâ´úÂë³äÈÎÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ£¬£¬£¬ £¬ £¬ £¬£¬ £¬´ÓÉ豸ÉϵÄËùÓÐÖ÷Ŀ¼µ¼³ö¸÷ÀàÓ뿪·¢ÈËÔ±ÓйصÄÊý¾Ý£¬£¬£¬ £¬ £¬ £¬£¬ £¬Ô̺¬BashºÍZshº¹Çà¼Í¼¡¢SSH ÃÜÔ¿ºÍ.gitconfigµÈÎļþ¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬ £¬ £¬ £¬£¬ £¬Î±ÔìµÄSentinelOne°üÒѱ»É¾³ý¡£¡£¡£¡£¡£


https://blog.reversinglabs.com/blog/sentinelsneak-malicious-pypi-module-poses-as-security-sdk


5¡¢Î÷°àÑÀÒøÐÐAbancaÒòÑÓ³¤»ã±¨ÍøÂç¹¥»÷±»·£¿£¿£¿£¿£¿£¿£¿£¿î310ÍòÅ·Ôª

      

¾ÝýÌå12ÔÂ16ÈÕ±¨Â·£¬£¬£¬ £¬ £¬ £¬£¬ £¬Å·ÖÞÖÐÑëÒøÐаµÊ¾£¬£¬£¬ £¬ £¬ £¬£¬ £¬ÒѶÔÎ÷°àÑÀÒøÐÐAbanca´¦ÒÔ310ÍòÅ·Ôª£¨329ÍòÃÀÔª£©µÄ·£¿£¿£¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£Ô­ÒòÊǸÃÒøÐÐÑÓ³¤»ã±¨ÍøÂç¹¥»÷ÊÂÎñ£¬£¬£¬ £¬ £¬ £¬£¬ £¬ÆÈʹÆäÔÚ2019ÄêÔÝÍ£ÆäÖØÒªµÄÖ§¸¶·½Ê½¡£¡£¡£¡£¡£Å·ÖÞÑëÐгƣ¬£¬£¬ £¬ £¬ £¬£¬ £¬¸ÃÒøÐеĺöÂÔ¹ÊÕÏÁËÅ·ÖÞÑëÐÐÕýÈ·ÆÀ¹ÀAbancaµÄÉóÉ÷Çé¿ö£¬£¬£¬ £¬ £¬ £¬£¬ £¬ÒÔ¼°ÊµÊ±Ó¦¶ÔÆäËûÒøÐÐÃæ¶ÔµÄDZÔÚÍþвµÄÄÜÁ¦¡£¡£¡£¡£¡£


https://www.usnews.com/news/technology/articles/2022-12-16/ecb-fines-spains-abanca-for-delay-in-reporting-cyber-hack    


6¡¢ÎÚ¿ËÀ¼Ð¹Â©UAC-0142ÍŻﴹµö¹¥»÷ÆäDelta¾üʵý±¨ÏµÍ³

      

ÎÚ¿ËÀ¼CERT-UAÔÚ12ÔÂ18ÈÕ°ä²¼¹«¸æ£¬£¬£¬ £¬ £¬ £¬£¬ £¬ÌáÐÑAPTÍÅ»ïUAC-0142Õë¶ÔÆäDelta¾üʵý±¨ÏµÍ³µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£´¹µöÐÅÏ¢ÊÇ´Ó¹ú·À²¿Ò»Ãû¹ÍÔ±µÄ±»ÈëÇÖÓÊÏäºÍmessenger·¢Ë͵쬣¬£¬ £¬ £¬ £¬£¬ £¬¸ÃÐÂÎŶ½´ÙÊÕ¼þÈ˸üÐÂDELTAϵͳÖеÄÖ¤Ê飬£¬£¬ £¬ £¬ £¬£¬ £¬Ëü»¹Ô̺¬Ò»¸ö¸½¼ÓµÄPDFÎļþ£¬£¬£¬ £¬ £¬ £¬£¬ £¬·ÂÕÕÁËZaporizhzhia¾¯Ô±¾ÖISTAR²¿ÃŵĺϷ¨ÌáÒª¡£¡£¡£¡£¡£ÔÚÖ´Ðд浵ÖеÄcertificates_rootCA.exeºó£¬£¬£¬ £¬ £¬ £¬£¬ £¬½«×°ÖÃÁ½¸ö¶ñÒâÈí¼þ£¬£¬£¬ £¬ £¬ £¬£¬ £¬±ðÀëΪÇÔÈ¡µç×ÓÓʼþ¡¢Êý¾Ý¿â¡¢¾ç±¾ºÍÎļþµÈÊý¾ÝµÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þFateGrab£¬£¬£¬ £¬ £¬ £¬£¬ £¬¼°ÇÔÈ¡ä¯ÀÀÆ÷Êý¾ÝµÄ¶ñÒâÈí¼þStealDeal¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/139859/intelligence/ukraine-delta-military-intelligence-attack.html