McAfeeÅû¶½üÆÚð³äÈÕ±¾µçÁ¦ºÍË®Îñ¹«Ë¾µÄ¹¥»÷»î¶¯

Ðû²¼Ê±¼ä 2023-07-24

1¡¢McAfeeÅû¶½üÆÚð³äÈÕ±¾µçÁ¦ºÍË®Îñ¹«Ë¾µÄ¹¥»÷»î¶¯


McAfeeÔÚ7ÔÂ21ÈÕÅû¶ÁËð³äµçÁ¦ºÍË®Îñ»ù´¡ÉèÊ©¹«Ë¾µÄ¹¥»÷»î¶¯¡£¸Ã»î¶¯´Ó6ÔÂ7ÈÕ¿ªÊ¼£¬Á¬ÐøÁ˺̵ܶÄÒ»¶Îʱ¼ä¡£Ö÷ÒªÕë¶ÔÈÕ±¾µÄAndroidÓû§£¬Í¨¹ý¶ÌÐÅÌáʾ֧¸¶ÎÊÌ⣬ÓÕʹĿ±ê·ÃÎʵöÓãÍøÕ¾£¬È»ºóÀûÓüäµýÈí¼þSpyNoteÀ´Ñ¬È¾Ä¿±êµÄÉ豸¡£SpyNoteÊÇÒ»¸öÒÑÖªµÄ¶ñÒâÈí¼þϵÁУ¬¿ÉÇÔÈ¡É豸ÐÅÏ¢ºÍÃô¸ÐµÄÓû§ÐÅÏ¢£¬ÆäÔ´´úÂëÓÚ2022Äê10ÔÂй¶ºó¼¤Ôö¡£×î½ü£¬Ôø±»ÓÃÓÚ1Ô·ÝÕë¶Ô½ðÈÚ»ú¹¹µÄ¹¥»÷ÒÔ¼°4ÔÂÕë¶ÔÈÕ±¾ÒøÐеĹ¥»÷¡£

  

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/android-spynote-attacks-electric-and-water-public-utility-users-in-japan/


2¡¢ÑÇÂíѷͬÒâÒÔ2500ÍòÃÀÔªºÍ½âAlexaÎ¥·´¶ùͯÒþ˽·¨µÄÖ¸¿Ø


¾Ý7ÔÂ21ÈÕ±¨µÀ£¬ÑÇÂíÑ·ÒÑͬÒâÖ§¸¶2500ÍòÃÀÔª·£¿î£¬ÒԺͽâÓëÆäAlexaÓïÒôÖúÀí·þÎñÏà¹ØµÄÉæÏÓÎ¥·´¶ùͯÒþ˽·¨µÄÖ¸¿Ø¡£×Ô2018Äê5ÔÂÆð£¬ÑÇÂíÑ·¶Ô13ËêÒÔ϶ùͯÌṩAlexaÉù¿Ø²úÎïºÍ·þÎñ¡£2023Äê5Ô£¬ÃÀ¹úFTCºÍDOJ¶ÔÑÇÂíÑ·Ìá³öÖ¸¿Ø£¬³ÆÆäÎ¥·´Á˶ùͯÒþ˽·¨£¬ÆäÖаüÂÞ¡¶Áª°îóÒ×ίԱ»á·¨¡·¡¢¡¶¶ùͯÔÚÏßÒþ˽± £»¤·¨¡·(COPPA)ºÍCOPPA¹æÔò¡£Ëß×´³Æ£¬ÑÇÂíÑ·ÔÚÏ൱³¤µÄÒ»¶Îʱ¼äÄÚδÄÜÂú×ã¼Ò³¤É¾³ýº¢×Ó¼ÒôµÄÒªÇ󣬴ËÍ⣬¸Ã¹«Ë¾±¾Ó¦Æ¾¾ÝÒªÇóɾ³ýÓû§µÄÓïÒôÐÅÏ¢ºÍµØÀíλÖÃÊý¾Ý£¬µ«È´Ñ¡Ôñ±£ÁôÕâЩÐÅÏ¢ÒÔ¹©¿ÉÄܵÄʹÓá£


https://www.bleepingcomputer.com/news/technology/amazon-agrees-to-25-million-fine-for-alexa-children-privacy-violations/


3¡¢ÓÎϷƽ̨RobloxÊý¾ÝÐ¹Â¶Éæ¼°Êýǧ¸ö¿ª·¢ÈËÔ±µÄÐÅÏ¢


¾Ý7ÔÂ21ÈÕ±¨µÀ£¬¹²ÓÐ3943¸öRoblox¿ª·¢ÕßÕÊ»§±»µÁ¡£ÔçÔÚ2021Ä꣬Roblox¾Í·¢ÉúÁËÊý¾Ýй¶£¬µ«¾ÝϤ¸Ã¹«Ë¾½«¸ÃʼþÒþÂ÷ÁËÖÁÉÙÁ½Äê¡£Have I Been PwnedÓÚ7ÔÂ18ÈÕÊ×´ÎÆØ¹âÁË´Ë´Îй¶Ê¼þ£¬³ÆÐ¹Â¶×î³õ·¢ÉúÔÚ2020Äê12ÔÂ18ÈÕ£¬Éæ¼°ÐÕÃû¡¢µç»°ºÅÂë¡¢ÓʼþµØÖ·ºÍIPµØÖ·µÈ¡£RobloxÈϿɣ¬Ò»¸öµÚÈý·½Äþ¾²ÎÊÌâµ¼ÖÂ¶ÔÆä´´½¨ÕߵĸöÈËÊý¾Ýδ¾­ÊÚȨµÄ·ÃÎÊ¡£¶ÔÓÚÊÜÓ°Ïì½ÏСµÄÓû§£¬ËûÃǽ«»áÊÕµ½Ò»·âÖÂǸÓʼþ¡£¶ÔÓÚÊÜÓ°ÏìÑÏÖØµÄÓû§£¬ËûÃǽ«»á»ñµÃΪÆÚÒ»ÄêµÄÉí·Ý± £»¤·þÎñ¡£


https://www.hackread.com/roblox-data-breach-developers-pii-data-stolen/


4¡¢Ñо¿ÈËÔ±·¢ÏÖÀûÓÃCitrix©¶´Õë¶ÔÃÀ¹ú»ù´¡ÉèÊ©µÄ¹¥»÷


7ÔÂ21ÈÕ±¨µÀ³Æ£¬CISAÌáÐÑÀûÓÃCitrix NetScaler ADCºÍGatewayÖЩ¶´¹¥»÷ÃÀ¹úÒªº¦»ù´¡ÉèÊ©µÄ»î¶¯¡£´Ë´Î¹¥»÷·¢ÉúÔÚ6Ô·ݣ¬ºÚ¿ÍÀûÓÃÁËRCE©¶´£¨CVE-2023-3519£©£¬ÔÚÄ¿±êµÄ·ÇÉú²úNetScalerÓ¦Óý»¸¶¿ØÖÆÆ÷(ADC)É豸ÉÏÖ²ÈëWebshell¡£¸ÃºóÃÅ¿ÉÓÃÀ´Ã¶¾ÙAD¹¤¾ß£¬°üÂÞÍøÂçÉϵÄÓû§¡¢×é¡¢Ó¦Ó÷¨Ê½ºÍÉ豸£¬²¢ÇÔÈ¡ADÊý¾Ý¡£È»¶ø£¬ÓÉÓÚÄ¿±êNetScaler ADCÉ豸λÓÚ¸ôÀë»·¾³ÖУ¬¹¥»÷ÕßÎÞ·¨ºáÏòÒÆ¶¯µ½Óò¿ØÖÆÆ÷¡£CISAÐû²¼ÁËÒ»·Ý°üÂÞTTPÒÔ¼°¼ì²âÒªÁìµÄͨ¸æ£¬²¢½¨Òé¹ÜÀíÔ±Ó¦ÓÃ×îеÄCitrix¸üС£


https://securityaffairs.com/148690/security/cisa-citrix-netscaler-adc.html


5¡¢ÁåľµÄÁ½¼Ò¾­ÏúÉÌÍøÕ¾ÒòÅäÖôíÎóй¶¿Í»§µÄÐÅÏ¢


ýÌå7ÔÂ21Èճƣ¬ÁåľÊÚȨµÄÁ½¸ö¾­ÏúÉ̵ÄÍøÕ¾Ð¹Â¶Á˿ͻ§µÄÃô¸ÐÐÅÏ¢¡£µÚÒ»¼Ò¾­ÏúµêÔÚ°ÍÎ÷ÔËÓª£¬Ñо¿ÈËÔ±·¢ÏÖÁËÄÚÈÝ·Ö·¢ÍøÂç(CDN)GoChacheµÄ¶ËµãºÍÃÜÔ¿¡¢MySQLÊý¾Ý¿â¡¢SMTPƾ֤ÒÔ¼°Ó¦Ó÷¨Ê½ºÍÍⲿµÚÈý·½·þÎñµÄÖÖÖÖÃÜÔ¿¡£µÚ¶þ¼ÒÊǰÍÁÖΨһµÄÁåľÆû³µ¾­ÏúÉÌ£¬¸Ã¹«Ë¾µÄLaravelÓ¦ÓÃÃÜÔ¿¡¢Êý¾Ý¿âºÍSMTPƾ¾Ý²»Êܱ £»¤¡£Ñо¿ÈËÔ±³Æ£¬SMTPƾ¾Ý¿ÉÓÃÓÚÏòÓû§·¢ËͶñÒâÓʼþ£¬Êý¾Ý¿âƾ¾Ý¿ÉÓÃÀ´·ÃÎÊÊý¾Ý¿âÄÚÈÝ£¬ÆäÖпÉÄܰüÂÞÓû§ÐÅÏ¢¡£


https://securityaffairs.com/148675/data-breach/nice-suzuki-sport-shame-dealer-left-your-data-up-for-grabs.html


6¡¢Unit 42Ðû²¼¹ØÓÚÀÕË÷Èí¼þMalox¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß


7ÔÂ20ÈÕ£¬Unit 42Ðû²¼Á˹ØÓÚÀÕË÷Èí¼þMalox¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£Mallox£¨ÓÖÃûTargetCompany£©ÊÇÒ»ÖÖÕë¶ÔMicrosoft WindowsϵͳµÄÀÕË÷Èí¼þ£¬×Ô2021Äê6ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬Ö÷ÒªÀûÓò»Äþ¾²µÄMS-SQL·þÎñÆ÷×÷ÎªÔØÌ壬ÈëÇÖÄ¿±êµÄÍøÂç¡£½üÆÚ£¬Unit 42ÊӲ쵽Mallox¹¥»÷»î¶¯ÓÐËùÔö¼Ó£¬ÓëǰһÄêÏà±ÈÔö¼ÓÁ˽ü174%¡£MalloxʹÓÃÁ˱©Á¦ÆÆ½â¡¢Êý¾Ýй¶ºÍÍøÂçɨÃ蹤¾ßµÈ¡£´ËÍ⣬Ñо¿ÈËÔ±·¢ÏÖÓм£Ïó±íÃ÷¸Ã×éÖ¯ÕýÔÚŬÁ¦À©´óÆäÒµÎñ£¬²¢ÔÚºÚ¿ÍÂÛ̳ÉÏÕÐļÁ¥Êô»ú¹¹¡£


https://unit42.paloaltonetworks.com/mallox-ransomware/