΢ÈíÒòÏòÓû§Ç¿¼Ó¹ã¸æcookie±»·¨¹ú·£¿î6000ÍòÅ·Ôª

Ðû²¼Ê±¼ä 2022-12-26
1¡¢Î¢ÈíÒòÏòÓû§Ç¿¼Ó¹ã¸æcookie±»·¨¹ú·£¿î6000ÍòÅ·Ôª

      

¾ÝýÌå12ÔÂ22ÈÕ±¨µÀ£¬·¨¹úÒþ˽¼à¹Ü»ú¹¹ÒѶÔÃÀ¹ú¿Æ¼¼¿Æ¼¼¹«Ë¾Î¢Èí´¦ÒÔ6000ÍòÅ·Ôª£¨6400ÍòÃÀÔª£©µÄ·£¿î£¬Ô­ÒòÊÇÆäÏòÓû§Ç¿¼Ó¹ã¸æcookie ¡£¹ú¼Ò¼¼ÊõºÍ×ÔÓÉίԱ»á(CNIL)ÌåÏÖ£¬Î¢ÈíµÄËÑË÷ÒýÇæBingδÉèÖÃÔÊÐíÓû§Ïñ½ÓÊÜcookieÒ»Ñù¼òµ¥µØ¾Ü¾øcookieµÄϵͳ ¡£¸Ã¹«Ë¾Òѱ»¸øÓèÈý¸öÔµÄʱ¼äÀ´¾ÀÕýÕâ¸öÎÊÌ⣬ÓâÆÚ»¹¿ÉÄÜÃæÁÙÿÌì60000Å·ÔªµÄ½øÒ»²½·£¿î ¡£Î¢ÈíÔÚÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬ËüÔÚÕâÏîÊӲ쿪ʼ֮ǰ¾ÍÒѾ­¶Ôcookie×ö·¨½øÐÐÁËÖØ´ó¸ü¸Ä ¡£


https://www.securityweek.com/france-fines-microsoft-60-million-euros-over-advertising-cookies


2¡¢°Ä´óÀûÑÇÀ¥Ê¿À¼¿Æ¼¼´óѧÔâµ½Royal TeamµÄÀÕË÷¹¥»÷

      

ýÌå12ÔÂ22Èճƣ¬À¥Ê¿À¼¿Æ¼¼´óѧÔâµ½ÀÕË÷¹¥»÷£¬µ¼ÖÂУ԰´òÓ¡»ú´òÓ¡´óÁ¿µÄÊê½ð¼Ç¼ ¡£QUT¸±Ð£³¤Margaret SheilÌåÏÖËýµÄ´òÓ¡»úÒ²Êܵ½Ó°Ï죬²»Í£µØ´òÓ¡Êê½ð¼Ç¼ֱµ½´òÓ¡»úÀïµÄÖ½Õźľ¡ ¡£Êê½ð¼Ç¼³ÆÀ´×ÔRoyal ransomware£¬ËüÔÚ֮ǰÖ÷Òª¹¥»÷ÃÀ¹úµÄÒ½ÁÆ»ú¹¹ ¡£×÷ΪÏìÓ¦´ëÊ©£¬À¥Ê¿À¼¿Æ¼¼´óѧÒѹرÕËùÓÐITϵͳ£¬²¢¶Ô¸ÃʼþÕ¹¿ªÊÓ²ì ¡£


https://www.abc.net.au/news/2022-12-22/qld-qut-cyber-attack-printers-royal/101802692


3¡¢ºÚ¿Í³öÊ۾ݳƴÓBetMGMÇÔÈ¡µÄÁè¼Ý150Íò¿Í»§µÄÊý¾Ý

      

¾Ý12ÔÂ22ÈÕ±¨µÀ£¬ÌåÓý²©²Ê¹«Ë¾BetMGMÅû¶ÁËÒ»ÆðÊý¾Ýй¶Ê¼þ£¬³Æ²¿Ãſͻ§µÄ¸öÈËÐÅϢй¶ ¡£¸Ã¹«Ë¾Ôö²¹Ëµ£¬ÆäÔÚ2022Äê11Ô·¢ÏÖ¸Ãʼþ£¬µ«¹¥»÷Ó¦¸ÃÊÇ·¢ÉúÔÚ2022Äê5Ô ¡£ÃûΪbetmgmhackedµÄ¹¥»÷ÕßÔÚºÚ¿ÍÂÛ̳Ðû²¼Êý¾Ý³öÊÛµÄͨ¸æ£¬³ÆÆäÈëÇÖÁËBetMGMµÄÊý¾Ý¿â£¬ÆäÖаüÂÞ1569310ÌõÓû§¼Ç¼£¬Éæ¼°ÃÜЪ¸ùÖÝ¡¢ÐÂÔóÎ÷ÖݺͰ²´óÂÔÊ¡µÈ¿Í»§µÄÐÕÃû¡¢ÁªÏµ·½Ê½¡¢ºÍÉç»áÄþ¾²ºÅÂëµÈÐÅÏ¢ ¡£¸Ã¹«Ë¾½«ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩÁ½ÄêµÄÃâ·ÑÐÅÓÃ¼à¿ØºÍÉí·Ý»Ö¸´·þÎñ ¡£


https://securityaffairs.co/wordpress/139949/data-breach/betmgm-discloses-security-breach.html


4¡¢Ñо¿ÍŶÓÅû¶ÆôÓÃksmbdµÄSMB·þÎñÆ÷µÄLinuxÄں˩¶´

      

12ÔÂ25ÈÕ±¨µÀ³Æ£¬Ñо¿ÍŶÓÅû¶ÁËÒ»¸öÑÏÖØµÄLinuxÄں˩¶´£¨CVSSÆÀ·ÖΪ10£©£¬»áÓ°ÏìÆôÓÃÁËksmbdµÄSMB·þÎñÆ÷ ¡£¸Ã©¶´´æÔÚÓÚSMB2_TREE_DISCONNECTÃüÁîµÄ´¦Öùý³ÌÖУ¬ÊÇÔÚ¶Ô¹¤¾ßÖ´ÐвÙ×÷֮ǰûÓÐÑéÖ¤¹¤¾ßµÄ´æÔÚ¶øµ¼ÖµÄ£¬¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´ÔÚÄÚºËÖÐÖ´ÐÐÈÎÒâ´úÂë ¡£Ñо¿ÈËÔ±Ôö²¹µÀ ¡£Ê¹ÓÃSambaµÄSMB·þÎñÆ÷²»ÊÜÓ°Ï죬ʹÓÃksmbdµÄSMB·þÎñÆ÷ÈÝÒ×Êܵ½¶ÁÈ¡·ÃÎʵÄÓ°Ï죬¿ÉÄÜй¶·þÎñÆ÷µÄÄڴ棨ÀàËÆÓÚHeartbleed©¶´£© ¡£½¨ÒéʹÓÃksmbdµÄ¹ÜÀíÔ±¸üе½8ÔÂÐû²¼µÄLinuxÄں˰汾5.15.61»ò¸ü¸ß°æ±¾ ¡£


https://securityaffairs.co/wordpress/140013/hacking/critical-linux-kernel-vulnerability.html


5¡¢Securonix·¢ÏÖÕë¶ÔÓ¡¶ÈÕþ¸®µÄ¹¥»÷»î¶¯STEPPY#KAVACH

      

¾Ý12ÔÂ23ÈÕ±¨µÀ£¬Securonix·¢ÏÖÁËÕë¶ÔÓ¡¶ÈÕþ¸®µÄÐÂÒ»ÂÖ¹¥»÷»î¶¯£¬²¢½«ÆäÃüÃûΪSTEPPY#KAVACH ¡£¸Ã»î¶¯Óë°Í»ù˹̹ºÚ¿ÍÍÅ»ïSideCopyµÄTTPÓÐËùÖØµþ£¬Ö÷ÒªÕë¶ÔÓ¡¶ÈÕþ¸®¹ÙԱʹÓõÄË«ÒòËØÉí·ÝÑéÖ¤½â¾ö·½°¸Kavach ¡£¹¥»÷ʼÓÚµöÓã»î¶¯£¬È»ºóͨ¹ý.LNKÎļþÆô¶¯´úÂëÖ´ÐУ¬×îÖÕÏÂÔØ²¢ÔËÐжñÒâC# payload£¬³äµ±Ô¶³Ì·ÃÎÊľÂí ¡£Õâ²»ÊǵÚÒ»ÆðÕë¶ÔKavachµÄ¹¥»÷£¬×Ô½ñÄêÄê³õÒÔÀ´£¬Transparent Tribe¾Íͨ¹ýKavachÖ÷ÌâµÄÓÕ¶üÓ¦Óù¥»÷Ó¡¶È ¡£ 


https://www.securonix.com/blog/new-steppykavach-attack-campaign/


6¡¢Wordfence͸¶WP²å¼þ©¶´CVE-2022-45359±»ÔÚÒ°ÀûÓÃ

      

WordfenceÔÚ12ÔÂ22ÈÕ͸¶£¬ WordPress²å¼þYITH WooCommerce Gift Cards PremiumÖЩ¶´Òѱ»ÔÚÒ°ÀûÓà ¡£¸Ã©¶´×·×ÙΪCVE-2022-45359(CVSSÆÀ·ÖΪ9.8)£¬¿É±»Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÃÀ´ÔÚÒ×±»¹¥»÷µÄÍøÕ¾ÉÏ´«Îļþ£¬°üÂÞÌṩ¶Ô¸ÃÍøÕ¾ÍêÈ«·ÃÎÊȨÏÞµÄWeb shell ¡£Ñо¿ÈËÔ±³Æ£¬´ó¶àÊý¹¥»÷·¢ÉúÔÚ2022Äê11Ô£¬Æäʱ¹ÜÀíÔ±ÉÐδÐÞ¸´¸Ã©¶´£¬µ«ÔÚ12ÔÂ14ÈÕÓÖ·ºÆðÁ˵ڶþ¸öá¯Áë ¡£´ËÍ⣬һ¸öÖØÒªµÄIPµØÖ·¶Ô10936¸öÍøÕ¾ÌᳫÁË19604´Î¹¥»÷ʵÑé ¡£Ä¿Ç°Â©¶´ÀûÓù¥»÷ÈÔÔÚ½øÐÐÖУ¬½¨ÒéʹÓøòå¼þµÄÓû§¾¡¿ìÉý¼¶µ½3.21°æ±¾ ¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-bug-in-wordpress-gift-card-plugin-with-50k-installs/