MetaÒòÎ¥·´Å·ÃËÊý¾ÝÒþÖÔ·¨±»°®¶ûÀ¼· £¿£¿£¿ £¿£¿î4.14ÒÚÃÀÔª

°ä²¼¹¦·ò 2023-01-06
1¡¢MetaÒòÎ¥·´Å·ÃËÊý¾ÝÒþÖÔ·¨±»°®¶ûÀ¼· £¿£¿£¿ £¿£¿î4.14ÒÚÃÀÔª

      

¾ÝýÌå1ÔÂ5ÈÕ±¨Â·£¬£¬£¬£¬ £¬£¬ £¬°®¶ûÀ¼Êý¾Ý±£»£»£»£»£»£»£»£»¤Î¯Ô±»á (DPC) ¶ÔMeta´¦ÒÔ3.9ÒÚÅ·Ôª£¨Ô¼ºÏ4.14ÒÚÃÀÔª£©µÄ· £¿£¿£¿ £¿£¿î¡£ ¡£¡£¡£¡£Ô­ÒòÊÇÆäвÆÈFacebookºÍInstagramÓû§ÔÞ³ÉΪ¶¨Ïò¸æ°×´¦ÖÃÓ×ÎÒÊý¾Ý£¬£¬£¬£¬ £¬£¬ £¬ÕâÎ¥·´ÁËÅ·Ã˵ÄGDPR¡£ ¡£¡£¡£¡£DPC¶ÔFacebookÓйصÄÎ¥¹æÐÐΪ· £¿£¿£¿ £¿£¿î2.1ÒÚÅ·Ôª£¬£¬£¬£¬ £¬£¬ £¬²¢¶ÔInstagram· £¿£¿£¿ £¿£¿î1.8ÒÚÅ·Ôª£¬£¬£¬£¬ £¬£¬ £¬»¹ºÅÁîMetaÔÚÈý¸öÔÂÄÚʹÆäµ±Ç°µÄÊý¾Ý´¦ÖòÙ×÷ÇкÏGDPRµÄ»®¶¨¡£ ¡£¡£¡£¡£Meta°µÊ¾£¬£¬£¬£¬ £¬£¬ £¬Ëü½«¶Ô²Ã¾öµÄÄÚÈÝÄÚÈݺͷ £¿£¿£¿ £¿£¿îÌá³öÉÏËß¡£ ¡£¡£¡£¡£


https://thehackernews.com/2023/01/irish-regulators-fine-facebook-414.html


2¡¢ÆóÒµºÏ×÷ƽ̨Slackй©Æä²¿ÃÅ˽ÓдúÂë´æ´¢¿â±»µÁ

      

¾Ý1ÔÂ5ÈÕ±¨Â·£¬£¬£¬£¬ £¬£¬ £¬ÆóÒµºÏ×÷ƽ̨Slackй©ÆäÔâµ½¹¥»÷£¬£¬£¬£¬ £¬£¬ £¬²¿ÃÅ˽ÓдúÂë´æ´¢¿â±»µÁ¡£ ¡£¡£¡£¡£SlackÓÚ2022Äê12ÔÂ29ÈÕ»ñϤ¿ÉÒɻ²¢¶ÔÊÂÎñ·¢Õ¹µ÷²é£¬£¬£¬£¬ £¬£¬ £¬·¢ÏÖ¹¥»÷Õßͨ¹ý±»µÁµÄSlackÔ±¹¤ÁîÅÆ»ñµÃÁËSlack±í²¿ÍйܵÄGitHub´æ´¢¿âµÄ½Ó¼ûȨÏÞ¡£ ¡£¡£¡£¡£µ÷²é»¹ÏÔʾ£¬£¬£¬£¬ £¬£¬ £¬¹¥»÷ÕßÒÑÓÚ2022Äê12ÔÂ27ÈÕÏÂÔØÁË˽ÓдúÂë´æ´¢¿â£¬£¬£¬£¬ £¬£¬ £¬µ«SlackµÄÖØÒª´úÂë¿âºÍ¿Í»§Êý¾Ý²»ÊÜÓ°Ïì¡£ ¡£¡£¡£¡£Slack»¹³Æ£¬£¬£¬£¬ £¬£¬ £¬Õâ´Îδ¾­ÊÚȨµÄ½Ó¼û²»ÊÇÓÉSlackÖеķì϶µ¼ÖµÄ£¬£¬£¬£¬ £¬£¬ £¬ËûÃÇ»¹½«³ÖÐøµ÷²éºÍ¼à¿Ø½øÒ»²½µÄй¶¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/slacks-private-github-code-repositories-stolen-over-holidays/


3¡¢×êÑÐÈËԱй©·¨À­ÀûºÍ±¦ÂíµÈÔì×÷ÉÌʹÓÃÒ×±»¹¥»÷µÄAPI

      

ýÌå1ÔÂ4Èճƣ¬£¬£¬£¬ £¬£¬ £¬×êÑÐÈËÔ±·¢ÏÖ·áÌï¡¢·¨À­ÀûºÍ±¦ÂíµÈ½ü20¼ÒÆû³µÔì×÷É̺ͷþÎñÔ̺¬API°²È«·ì϶¡£ ¡£¡£¡£¡£ÕâЩ·ì϶¿ÉÄܱ»ÓÃÓÚ¿í·ºµÄ¶ñÒâ»î¶¯£¬£¬£¬£¬ £¬£¬ £¬ÀýÈç½âËø¡¢Æô¶¯¡¢¸ú×ÙÆû³µÒÔ¼°Ð¹Â¶¿Í»§µÄÓ×ÎÒÐÅÏ¢¡£ ¡£¡£¡£¡£ÀûÓÃijЩ·ì϶£¬£¬£¬£¬ £¬£¬ £¬¹¥»÷ÕßÄܹ»Í¨¹ýÅäÖò»µ±µÄSSO½Ó¼ûÊý°Ù¸ö÷ÈüµÂ˹ÄÚ²¿ÀûÓ÷¨Ê½¡¢ÔÚ¶à¸öϵͳÉÏÔ¶³ÌÖ´ÐдúÂëÒÔ¼°½Ó¼ûijЩϵͳÄÚ´æ¡£ ¡£¡£¡£¡£ÔÚBMWµÄ°¸ÀýÖУ¬£¬£¬£¬ £¬£¬ £¬×êÑÐÈËÔ±·¢ÏÖÁËSSO·ì϶£¬£¬£¬£¬ £¬£¬ £¬¿ÉÓÃÀ´½Ó¼ûÄÚ²¿¾­ÏúÉÌÃÅ»§£¬£¬£¬£¬ £¬£¬ £¬²éÎÊÆû³µµÄVIN²¢¼ìË÷Ô̺¬³µÖ÷¾ßÌåÐÅÏ¢µÄÏúÊÛÎļþ¡£ ¡£¡£¡£¡£


https://securityaffairs.com/140328/hacking/bmw-mercedes-toyota-other-carmakers-flaws.html


4¡¢K7 Labs·¢ÏÖÀûÓÃWindowsÃýÎó»ã±¨¹¤¾ß·Ö·¢¶ñÒâÈí¼þµÄ»î¶¯

      

K7 LabsÓÚ1ÔÂ4ÈÕ³ÆÆä·¢ÏÖÁËÀûÓÃWindowsÃýÎó»ã±¨¹¤¾ßWerFault.exe·Ö·¢¶ñÒâÈí¼þµÄ»î¶¯¡£ ¡£¡£¡£¡£¸Ã»î¶¯Ê¼ÓÚÒ»·â´øÓÐISO¸½¼þµÄµç×ÓÓʼþ£¬£¬£¬£¬ £¬£¬ £¬Ë«»÷ʱISO»á½«×Ô¼º¹ÒÔØÎªÒ»¸öеÄÅÌ·û£¬£¬£¬£¬ £¬£¬ £¬ÆäÖÐÔ̺¬WerFault.exeµÄºÏ·¨¸±±¾¡¢Ò»¸öDLLÎļþÒ»¸öXLSÎļþºÍÒ»¸ö¿ì½Ý·½Ê½Îļþ¡£ ¡£¡£¡£¡£É±¶¾¹¤¾ßͨ³£ÐÅÀµWerFault£¬£¬£¬£¬ £¬£¬ £¬Òò¶øÔÚϵͳÉÏÆô¶¯Ëüͨ³£²»»á´¥·¢¾¯±¨¡£ ¡£¡£¡£¡£Æô¶¯WerFault.exeʱ£¬£¬£¬£¬ £¬£¬ £¬Ëü½«Ê¹ÓÃDLL²à¼ÓÔØ·ì϶À´¼ÓÔØISOÖÐÔ̺¬µÄ¶ñÒâDLL Faultrep.dll£¬£¬£¬£¬ £¬£¬ £¬×îÖÕÖ´ÐÐPupy RAT¡£ ¡£¡£¡£¡£


https://labs.k7computing.com/index.php/pupy-rat-hiding-under-werfaults-cover/


5¡¢É罻ƽ̨Cricketsocial.comÓû§ÐÅÏ¢ºÍÖÎÀíԱʹ´¦Ð¹Â¶

      

1ÔÂ4ÈÕ±¨Â·³Æ£¬£¬£¬£¬ £¬£¬ £¬CyberNews·¢ÏÖ°åÇòÉ罻ƽ̨Cricketsocial.comй¶Á˳¬¹ý10ÍòÌõÓû§Ó×ÎÒÐÅÏ¢ºÍÍ´´¦¡£ ¡£¡£¡£¡£¸ÃÊý¾Ý¿âÓÉÃÀ¹úAWSÍйÜ£¬£¬£¬£¬ £¬£¬ £¬Ô̺¬µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢ÐÕÃû¡¢Óû§ÃÜÂë¡¢µ®ÉúÈÕÆÚºÍµØÖ·µÈÐÅÏ¢¡£ ¡£¡£¡£¡£ÆäÖдó²¿ÃżÍÂ¼ËÆºõ¶¼ÊDzâÊÔÊý¾Ý£¬£¬£¬£¬ £¬£¬ £¬µ«ÒÀÈ»Ô̺¬ºÏ·¨ÍøÕ¾Óû§µÄPIIÐÅÏ¢¡£ ¡£¡£¡£¡£×êÑÐÈËÔ±»¹·¢ÏÖ¸ÃÊý¾Ý¿â»¹Ð¹Â¶ÁËÃ÷ÎÄ´ó¾Ö´æ´¢µÄÍøÕ¾ÖÎÀíԱʹ´¦£¬£¬£¬£¬ £¬£¬ £¬¿É±»¹¥»÷ÕßÓÃÀ´ÊÕÊÜÆ½Ì¨¡£ ¡£¡£¡£¡£


https://securityaffairs.com/140329/data-breach/cricketsocial-com-data-leak.html


6¡¢Zoho½¨¸´ManageEngineÖÐSQL×¢Èë·ì϶CVE-2022-47523

      

ýÌå1ÔÂ4ÈÕ±¨Â·³Æ£¬£¬£¬£¬ £¬£¬ £¬Zoho¶½´Ù¿Í»§½¨¸´Ó°ÏìÁ˶à¸öManageEngine²úÆ·µÄ°²È«·ì϶¡£ ¡£¡£¡£¡£·ì϶׷×ÙΪCVE-2022-47523£¬£¬£¬£¬ £¬£¬ £¬ÊÇPassword Manager Pro¡¢PAM360ºÍAccess Manager PlusÖз¢ÏÖµÄSQL×¢Èë·ì϶¡£ ¡£¡£¡£¡£¹¥»÷ÕßÀûÓø÷ì϶¿É»ñµÃºó¶ËÊý¾Ý¿âµÄ½Ó¼ûȨÏÞ£¬£¬£¬£¬ £¬£¬ £¬²¢Ö´ÐÐ×Ô½ç˵²éÎÊÒÔ½Ó¼ûÊý¾Ý¿â±íÌõ¿î¡£ ¡£¡£¡£¡£Zoho³ÆÆäÒѾ­Í¨¹ýתÒåÌØÊâ×Ö·ûºÍÔö³¤Êʵ±µÄÑéÖ¤½â¾öÁ˸ÃÎÊÌâ¡£ ¡£¡£¡£¡£¼øÓÚ´Ë·ì϶µÄÑϳÁÐÔ£¬£¬£¬£¬ £¬£¬ £¬¸Ã¹«Ë¾Ç¿ÁÒ½¨Òé¿Í»§Á¢¼´Éý¼¶µ½×îа汾¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/zoho-urges-admins-to-patch-critical-manageengine-bug-immediately/