TikTokÒòÎ¥·´Ó¢¹úµÄÊý¾Ý±£»¤·¨±»·£¿î1270ÍòÓ¢°÷

Ðû²¼Ê±¼ä 2023-04-06

1¡¢TikTokÒòÎ¥·´Ó¢¹úµÄÊý¾Ý±£»¤·¨±»·£¿î1270ÍòÓ¢°÷


¾ÝýÌå4ÔÂ4ÈÕ±¨µÀ £¬TikTokÒò¶à´ÎÎ¥·´Êý¾Ý±£»¤·¨ £¬±»Ó¢¹úÐÅϢרԱ°ì¹«ÊÒ(ICO)·£¿î1270ÍòÓ¢°÷£¨ºÏ1575ÍòÃÀÔª£©µÄ·£¿î ¡£TikTokδÄܾÍ13ËêÒÔ϶ùͯʹÓÃÆäÆ½Ì¨»ñµÃâïÊѵÄͬÒâ £¬Ò²Ã»ÓнøÐгäʵµÄ¼ì²éÒÔʶ±ðºÍ·Àֹδ³ÉÄê¶ùͯʹÓÃÉ罻ýÌåÓ¦Óà ¡£¸Ã»ú¹¹ÌåÏÖ £¬Ó¦¶Ô´ëÊ©µÄ²»×ãµ¼ÖÂÔ¼100Íò13ËêÒÔ϶ùͯ²»Í׵طÃÎÊ¸ÃÆ½Ì¨ £¬TikTokÊÕ¼¯²¢Ê¹ÓÃÁËËûÃǵĸöÈËÊý¾Ý ¡£ÕâÒ»·£¿î±ÈICOÔÚ2022Äê9Ô·¢³öµÄ¶ÔTikTok·£¿î2700ÍòÓ¢°÷µÄԭʼÒâÏò֪ͨÓÐËù¼õÉÙ ¡£


https://www.infosecurity-magazine.com/news/tiktok-fined-12m-uk-data-privacy/


2¡¢UnitedLexÔâµ½d0nutÀÕË÷¹¥»÷Áè¼Ý200GBÊý¾Ýй¶


¾Ý4ÔÂ4ÈÕ±¨µÀ £¬UnitedLex¹«Ë¾Ôâµ½ÁËd0nutµÄÀÕË÷¹¥»÷ ¡£d0nutÉù³Æ £¬ËûÃÇÒÑ´ÓUnitedLexµÄϵͳÏÂÔØÁËÁè¼Ý200GBµÄÊý¾Ý £¬°üÂÞÉæ¼°¸¶¿î¡¢ºÏͬºÍÆäËûÓëÖÚ¶à×éÖ¯ºÍ¸öÈËÓйصĻúÃÜÎļþ ¡£UnitedLexÌåÏÖ½üÆÚÔÚϵͳÉÏ·¢ÏÖÁË¿ÉÒɻ £¬ÕýÔÚÈ·¶¨»î¶¯µÄÐÔÖʺͷ¶Î§ ¡£¾ÝϤ £¬d0nutÔøÒªÇó500ÍòÃÀÔªµÄÊê½ð £¬ÕâÓë̸ÅÐÖÐÌáµ½µÄ60ÍòÃÀÔªµÄÒªÇóÃ÷ÏÔ²îÒì ¡£UnitedLexÒѱ»Ìí¼Óµ½ÁËBlackCatµÄÍøÕ¾ £¬Ñо¿ÈËÔ±ÕýÊÔͼȷ¶¨ÕâЩÊÇ·ñÓëD0nut Leaksй¶µÄÊý¾ÝÏàͬ ¡£


https://www.databreaches.net/unitedlex-hit-by-d0nut-ransomware-team-200-gb-of-corporate-files-leaked/


3¡¢»ÝÆÕÔ¤¼Æ90ÌìÄÚÐÞ¸´LaserJet´òÓ¡»úÖЩ¶´CVE-2023-1707


ýÌå4ÔÂ4ÈÕ³Æ £¬»ÝÆÕÔ¤¼ÆÓÚ90ÌìÄÚÐÞÓ°ÏìijЩÉÌÒµ¼¶´òÓ¡»ú¹Ì¼þµÄ©¶´ ¡£Â©¶´×·×ÙΪCVE-2023-1707 £¬¿ÉÄܻᵼÖÂÐÅϢй¶ £¬Ó°ÏìÁËÔ¼50ÖÖHP Enterprise LaserJetºÍHP LaserJet Managed PrintersÐͺÅ ¡£¸Ã¹«Ë¾Ö¸³ö £¬ÓÉÓÚÒ×Êܹ¥»÷µÄÉ豸ÐèÒªÔËÐÐFutureSmart¹Ì¼þ°æ±¾5.6²¢ÆôÓÃIPsec £¬Òò´ËÀûÓû·¾³ÊÇÊÜÏÞµÄ ¡£»ÝÆÕÌåÏÖ £¬¹Ì¼þ¸üн«ÔÚ90ÌìÄÚÐû²¼ £¬Òò´ËĿǰûÓпÉÓõÄÐÞ¸´·¨Ê½ ¡£¶ÔÓÚÔËÐÐFutureSmart 5.6µÄÓû§ £¬½¨ÒéµÄ»º½â´ëÊ©Êǽ«Æä¹Ì¼þ°æ±¾½µ¼¶µ½FS 5.5.0.3 ¡£»ÝÆÕ³Æ¸Ã©¶´ÉÐδ±»ÀûÓà £¬ÇÒ̻¶ÆÚºÜ¶Ì£¨2023Äê2ÔÂÖÐÑ®ÖÁ3Ôµף© ¡£


https://www.bleepingcomputer.com/news/security/hp-to-patch-critical-bug-in-laserjet-printers-within-90-days/


4¡¢IRSÊÚȨµÄ±¨Ë°Èí¼þeFile.com±»·¢ÏÖ·Ö·¢JS¶ñÒâÈí¼þ


4ÔÂ4ÈÕ±¨µÀ³Æ £¬ÃÀ¹ú¹ú˰¾Ö£¨IRS£©ÊÚȨµÄ±¨Ë°Èí¼þeFile.com±»·¢ÏÖ·Ö·¢JavaScript¶ñÒâÈí¼þ ¡£ÓÐÎÊÌâµÄ¶ñÒâJavaScriptÎļþÊÇpopper.js £¬ÖÁÉÙÔÚ4ÔÂ1ÈÕ֮ǰeFile.comµÄ¼¸ºõÿ¸öÒ³Ãæ¶¼ÔÚ¼ÓÔØ¶ñÒâÎļþ ¡£3ÔÂ17ÈÕ £¬RedditÓû§·¢Ìû»³ÒÉeFile.comÍøÕ¾±»½Ù³Ö ¡£Æäʱ £¬ÍøÕ¾ÏÔʾÁËÒ»ÌõSSL´íÎóÏûÏ¢ £¬Ö¸Ê¾ËûÃÇÏÂÔØÐé¼ÙµÄä¯ÀÀÆ÷¸üÐÂÒÔÕýÈ··ÃÎʸ÷þÎñ ¡£¸Ã¹¥»÷Éæ¼°Á½¸öÖ÷ÒªµÄ¿ÉÖ´ÐÐÎļþ £¬update.exe×÷ΪÓëC2·þÎñÆ÷ͨÐŵÄPHP½Å±¾µÄÏÂÔØ·¨Ê½ £¬PHP½Å±¾ÏÂÔØ²¢Ö´ÐÐÌØ±ðµÄ´úÂë ¡£


https://www.bleepingcomputer.com/news/security/irs-authorized-efilecom-tax-return-software-caught-serving-js-malware/


5¡¢GoogleÐû²¼2023Äê4ÔµÄAndroidÄþ¾²¸üÐÂÐÞ¸´ÊýÊ®¸ö©¶´


ýÌå4ÔÂ5ÈÕ±¨µÀ £¬GoogleÐû²¼2023Äê4ÔµÄAndroidÄþ¾²¸üР¡£´Ë´Î¸üзÖΪÁ½²¿ÃÅ £¬2023-04-01¼¶±ð²¹¶¡ÐÞ¸´ÁË¿ò¼ÜºÍϵͳ×é¼þÖеÄ26¸ö©¶´ £¬ÆäÖдó¶àÊýÊǵ¼ÖÂȨÏÞÌáÉý»òÐÅϢй¶µÄ©¶´£»2023-04-05¼¶±ð²¹¶¡ÐÞ¸´ÁËÄںˡ¢Arm¡¢Imagination Technologies¡¢MediaTek¡¢UnisocºÍQualcomm×é¼þÖеÄ40¸ö©¶´ ¡£ÆäÖнÏΪÑÏÖØµÄÊÇSystemÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2023-21085ºÍCVE-2023-21096£© ¡£


https://www.securityweek.com/androids-april-2023-updates-patch-critical-remote-code-execution-vulnerabilities/


6¡¢MantisÀûÓÃMicropsiaºÍArid GopherбäÌå¹¥»÷Öж«µØÓò


4ÔÂ4ÈÕ £¬SymantecÅû¶ÁËMantisÓÃÓÚ¹¥»÷Öж«µØÓòµÄй¤¾ß ¡£Ñо¿ÈËÔ±·¢ÏÖÁ˸ÃÍÅ»ï×î½üÒ»´Î»î¶¯ £¬´Ó2022Äê9Ô¿ªÊ¼ £¬ÖÁÉÙÁ¬Ðøµ½2023Äê2Ô ¡£´Ë´Î¹¥»÷ÖÐ £¬¹¥»÷ÕßʹÓÃÆä¶¨ÖÆµÄMicropsiaºÍArid GopherºóÃŵÄбäÌåÀ´ÈëÇÖÄ¿±ê £¬È»ºóÔÙ½øÐÐÆ¾¾ÝÇÔÈ¡ºÍÊý¾Ýй¶ ¡£´Ë»î¶¯µÄ³õʼѬȾý½éÈÔȻδ֪ ¡£ÔÚÒ»¸öÄ¿±ê×éÖ¯ÖÐ £¬¹¥»÷ÕßÔÚÈý×鼯Ëã»úÉϰ²×°ÁËͬһ¹¤¾ßµÄÈý¸ö²îÒì±äÌå ¡£´ËÍâ £¬¹¥»÷Õß»¹Ê¹ÓÃÁËÒ»¸ö×Ô½ç˵¹¤¾ßÀ´Ð¹Â¶´ÓÄ¿±ê×éÖ¯ÇÔÈ¡µÄÊý¾Ý £¬¼´ÃûΪWindowsUpServ.exeµÄ64λPyInstaller¿ÉÖ´ÐÐÎļþ ¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/mantis-palestinian-attacks