MetaºÍÃÀ¹úÁ½¼ÒÒ½ÁÆ»ú¹¹±»ÆðËßÊÕ¼¯»¼ÕßÐÅϢͶ·Å¹ã¸æ
Ðû²¼Ê±¼ä 2022-08-01
¾ÝýÌå7ÔÂ30ÈÕ±¨µÀ£¬¼ÓÖݱ±Çø¶ÔMeta¡¢UCSFÒ½ÁÆÖÐÐĺÍDignity½¡¿µÒ½ÁÆ»ù½ð»áÌáÆð¼¯ÌåËßËÏ£¬Ö¸¿ØËûÃÇ·Ç·¨ÊÕ¼¯Óйػ¼ÕßµÄÒ½ÁÆÊý¾Ý²¢ÓÃÓÚ¶¨ÏòͶ·Å¹ã¸æ¡£·¨ÔºÎļþÏÔʾ£¬»¼ÕßÔÚFacebookºÍÓÊÏäÖÐÊÕµ½ÁËÓÐÕë¶ÔÐÔµÄ¹ã¸æ£¬ÕâЩ¹ã¸æÔÚûÓпÆÑ§Ö§³ÖµÄÇé¿öÏÂÐû´«¼²²¡ºÍÒ½ÁÆ·þÎñ¡£Meta PixelÊÇÒ»¶Î´úÂ룬¿ÉÒÔ×¢ÈëÈκÎÍøÕ¾£¬ÒÔ½øÐзÿͷÖÎö¡¢Êý¾ÝÊÕ¼¯ºÍ¶¨ÏòͶ·Å¹ã¸æ¡£Æ¾¾ÝͶËߣ¬±»·¢ÏÖʹÓÃÁËMeta PixelµÄ33¼ÒÒ½Ôº½öÔÚ2020Äê¾Í¹²ÊÕÖÎÁË2600¶àÍòÃû»¼Õß¡£
https://www.bleepingcomputer.com/news/security/meta-us-hospitals-sued-for-using-healthcare-data-to-target-ads/
2¡¢ShinyHuntersÍÅ»ïµÄÖØÒª³ÉÔ±ÔÚÀ°ÍÌØ¹ú¼Ê»ú³¡±»²¶
ýÌå7ÔÂ31Èճƣ¬Èû°Í˹µÙ°²¡¤ÀÎÚ¶û£¨ÓÖÃûSezyo£©ÓÚ2022Äê6ÔÂ1ÈÕÔÚÀ°ÍÌØ¹ú¼Ê»ú³¡±»²¶¡£ËûÊÇShinyHuntersÍÅ»ïµÄÖØÒª³ÉÔ±Ö®Ò»£¬ÔøÈëÇÖÁËÊý°Ù¸öÃÀ¹ú×éÖ¯¡£³ýÁËÀÎÚ¶û£¬»¹ÓÐÆäËû4Ãû·¨¹ú¾ÓÃñÓ¦Áª°îÊÓ²ì¾ÖµÄÒªÇó½ÓÊÜÁËÎÊѶ¡£ÃÀ¹úÏÖÔÚÒªÇóÒÔÍøÂçÆÛÕ©ºÍÍøÂç·¸×ïµÄÖ¸¿Ø½«ÏÓÒÉÈËÒý¶Éµ½ÃÀ¹ú£¬È»¶øÀÎÚ¶ûµÄÂÉʦ¾Ü¾øÁËÕâÒ»ÒªÇ󣬳Ƹð¸¼þÊôÓÚ·¨¹ú¹ÜϽ·¶Î§£¬ÒòΪΥ·¨ÐÐΪÊÇÓÉ·¨¹ú¹úÃñÔÚ·¨¹ú½øÐеġ£·¨¹úL'Obs±¨µÀ£¬ÏÓÒÉÈ˱»²¶ºóÒ»Ö±±»¹ØÑºÔÚTiflet¼àÓü£¬²¢ÃæÁÙ×Å116ÄêµÄ¼à½û¡£
https://www.hackread.com/alleged-shinyhunters-hacker-group-member-arrested/
3¡¢AdrasteaÉù³ÆÒÑÈëÇÖÅ·ÖÞµ¼µ¯ÖÆÔìÉÌMBDA²¢ÇÔÈ¡60GBÊý¾Ý
¾Ý7ÔÂ31ÈÕ±¨µÀ£¬AdrasteaÉù³ÆÒÑÈëÇÖMBDA²¢ÇÔÈ¡60 GBÊý¾Ý¡£MBDAÊÇÅ·ÖÞµÄÒ»¼Ò¿ç¹úµ¼µ¯¿ª·¢É̺ÍÖÆÔìÉÌ£¬ÓÉ·¨¹ú¡¢Ó¢¹úºÍÒâ´óÀûÖ÷ÒªµÄµ¼µ¯ÏµÍ³¹«Ë¾£¨A¨¦rospatiale¨CMatra¡¢BAE SystemsºÍFinmeccanica£©ºÏ²¢¶ø³É¡£AdrasteaÌåÏÖ£¬ËûÃÇÔÚ¹«Ë¾µÄ»ù´¡ÉèÊ©Öз¢ÏÖÁËÑÏÖØÂ©¶´£¬²¢ÒÑÏÂÔØÉæ¼°¾üÊÂÏîÄ¿¡¢ÉÌÒµ»î¶¯¡¢ºÏͬÐÒéÒÔ¼°ÓëÆäËü¹«Ë¾Í¨ÐÅÐÅÏ¢µÄ60 GBÊý¾Ý¡£×÷Ϊ¹¥»÷µÄÖ¤¾Ý£¬AdrasteaÐû²¼ÁËÒ»¸öÁ´½Ó£¬°üÂÞÓëÏîÄ¿ºÍͨÐÅÏà¹ØµÄÄÚ²¿Îļþ¡£Ä¿Ç°£¬Éв»Çå³þ¹ØÓڴ˴ι¥»÷µÄϸ½ÚÐÅÏ¢¡£
https://securityaffairs.co/wordpress/133881/data-breach/mbda-alleged-data-breach.html
4¡¢SharpTongueÀûÓöñÒâä¯ÀÀÆ÷À©Õ¹ÇÔȡĿ±êµÄÓʼþÊý¾Ý
¾ÝVolexityÔÚ7ÔÂ28ÈÕ±¨µÀ£¬³¯ÏʺڿÍÍÅ»ïSharpTongueÔÚ»ùÓÚChromiumµÄä¯ÀÀÆ÷Éϲ¿Êð¶ñÒâÀ©Õ¹·¨Ê½£¬Ö¼ÔÚ´ÓGmailºÍAOLÇÔÈ¡µç×ÓÓʼþÊý¾Ý¡£¾ÝϤ£¬¸ÃÍÅ»ïÓëÒ»¸ö³ÆÎªKimsukyµÄÍÅ»ïÓÐËùÖØµþ¡£SharpTongueÖ÷ÒªÕë¶ÔΪÃÀ¹ú¡¢Å·Ö޺ͺ«¹úµÄ×éÖ¯ÊÂÇ飬´ÓÊÂÉæ¼°³¯ÏÊ¡¢ºËÎÊÌâ¡¢ÎäÆ÷ϵͳµÈ¶Ô³¯ÏʾßÓÐÕ½ÂÔÒâÒåµÄÎÊÌâµÄÄ¿±ê¡£Ôڴ˴λÖУ¬¹¥»÷ÕßÊ×ÏÈ´Ó±»Ñ¬È¾µÄÍøÕ¾ÊÖ¶¯ÇÔÈ¡°²×°À©Õ¹ËùÐèµÄÎļþ£¬Ò»µ©Àֳɹ¥»÷Ä¿±êWindowsϵͳ£¬¾Í»áÌæ»»ä¯ÀÀÆ÷µÄÊ×Ñ¡ÏîºÍÄþ¾²Ê×Ñ¡ÏÔÙͨ¹ýVBS½Å±¾ÊÖ¶¯°²×°¶ñÒâÀ©Õ¹SHARPEXT¡£
https://www.volexity.com/blog/2022/07/28/sharptongue-deploys-clever-mail-stealing-browser-extension-sharpext/
5¡¢Ó¢¹úWooton UpperѧУÔâµ½Hive¹¥»÷±»ÀÕË÷50ÍòÓ¢°÷
ýÌå7ÔÂ28Èճƣ¬Ó¢¹ú±´µÂ¸£µÂ¿¤µÄWooton Upper SchoolÔâµ½¹¥»÷ºó£¬±»ÀÕË÷500000Ó¢°÷¡£¹¥»÷Ô´ÓÚHive£¬¸ÃÍÅ»ïÒÑÏòѧÉúºÍ¼Ò³¤·¢ËÍÏûÏ¢£¬³ÆËûÃÇÔÚÊýÖÜǰÈëÇÖÁËWoottonµÄϵͳ£¬²¢Éè·¨¼ÓÃÜÁËWoottonËùÓеķþÎñÆ÷£¬°üÂÞ½ð²®ÀûѧԺ(Kimberley College)£¬ÇÔÈ¡Á˼Òͥסַ¡¢ÒøÐÐÏêϸÐÅÏ¢¡¢Ò½ÁƼǼºÍѧÉúµÄÐÄÀíÆÀ¹ÀµÈÐÅÏ¢¡£¸ÃѧУÂôÁ¦ÈËÒÑÈ·ÈÏÔâµ½ÁËÍøÂç¹¥»÷£¬ËûÃÇÕýÔÚÖÆ¶¨¼Æ»®À´Öؽ¨ÆäITϵͳ¡£Ä¿Ç°ÎÞ·¨È·¶¨»Ö¸´ËùÐèʱ¼ä£¬µÚÈý·½½¨ÒéΪ7µ½10¸öÊÂÇéÈÕ¡£
https://www.infosecurity-magazine.com/news/ransomware-group-500000-school/
6¡¢ENISAÐû²¼¹ØÓÚ2021ÄêÖØ´óµçÐÅÄþ¾²Ê¼þµÄ»ã×ܳÂËß
7ÔÂ28ÈÕ±¨µÀ£¬ENISAÐû²¼¹ØÓÚ2021ÄêÖØ´óµçÐÅÄþ¾²Ê¼þµÄ»ã×ܳÂËß¡£³ÂËß°üÂÞÁËÀ´×Ô26¸öÅ·Ã˳ÉÔ±¹ú(MS)ºÍ2¸öEFTA¹ú¼ÒµÄÕþ¸®Ìá½»µÄ168Æðʼþ³ÂËßµÄÏà¹ØÊý¾Ý£¬Óû§ËðʧµÄ×Üʱ¼ä£¨Í¨¹ý¶Ôÿ¸öʼþµÄÓû§Êý³ËÒÔСʱÊýµÃ³ö£©Îª51.06ÒÚ¸öÓû§Ð¡Ê±¡£2021ÄêÉϱ¨µÄʼþÖÐÓÐ4.16%Éæ¼°OTTͨÐÅ·þÎñ£»±»±ê־Ϊ¶ñÒâʼþÊýÁ¿´Ó2020ÄêµÄ4%ÉÏÉýµ½2021ÄêµÄ8%£»ÏµÍ³¹ÊÕÏÈÔÔÚÓ°Ïì·½ÃæÕ¼¾ÝÖ÷µ¼Ö°Î»£¬ÔÚ2021ÄêÔì³ÉÁË3.63ÒÚÓû§Ð¡Ê±µÄËðʧ£¬¶ø2020ÄêΪ4.19ÒÚ¡£
https://securityaffairs.co/wordpress/133756/reports/telecom-security-incidents-2021-enisa.html