Google DriveÓû§³ÆÔÆ·þÎñÖеĴ洢Êý¾Ý¶ªÊ§
Ðû²¼Ê±¼ä 2023-11-28¾ÝýÌå11ÔÂ27ÈÕ±¨µÀ£¬Google DriveÓû§³ÂË߳ƣ¬×î½ü´æ´¢ÔÚÔÆÖеÄÎļþͻȻÏûʧÁË£¬ÔÆ·þÎñ»Ö¸´µ½ÁË2023Äê4Ôµ½5ÔÂ×óÓҵĴ洢¿ìÕÕ¡£ÊÜÓ°ÏìÕÊ»§µÄ»î¶¯ÈÕÖ¾ÏÔʾÓû§×î½üûÓÐÈκÎÐ޸ģ¬È·Èϲ»ÊÇÓû§ÒâÍâɾ³ýÁËÊý¾Ý¡£×ÜÖ®£¬Ã»Óм£Ïó±íÃ÷ÊÇÓû§¶éÂ䣬¶øÊÇ·þÎñϵͳ³öÁËÎÊÌ⣬µ¼Öµ±µØÉ豸ºÍGoogle CloudÖ®¼äµÄÊý¾ÝÎÞ·¨Í¬²½¡£Ò»Ð©Óû§µÄÀëÏß»º´æÖпÉÄܰüÂÞ¶ªÊ§µÄÊý¾Ý£¬µ«Ä¿Ç°»¹Ã»ÓÐÒªÁìÀ´»Ö¸´¶ÔÆäÖÐÊý¾ÝµÄ·ÃÎÊ¡£GoogleÒѾÔÚÊÓ²ìÕâ¸öÎÊÌ⣬ÉÐδÌṩÐÞ¸´µÄÔ¤¼ÆÊ±¼ä£¬½¨ÒéÓû§ÔÚÎÊÌâµÃµ½½â¾ö֮ǰ²»Òª¶Ôroot/dataÎļþ¼Ð½øÐиü¸Ä¡£
https://www.bleepingcomputer.com/news/google/google-drive-users-angry-over-losing-months-of-stored-data/
2¡¢TransUnionºÍExperianÒÉËÆÔâµ½¹¥»÷²¢±»ÀÕË÷6ǧÍòÃÀÔª
11ÔÂ23ÈÕ±¨µÀ³Æ£¬ÄÏ·Ç×î´óµÄÁ½¼ÒÏû·ÑÕßÐÅÓóÂËß»ú¹¹TransUnionºÍExperianÒÉËÆÔâµ½ÍøÂç¹¥»÷£¬Óû§µÄ²ÆÕþºÍ¸öÈËÊý¾ÝÃæÁÙ·çÏÕ¡£N4ughtySecTUÍÅ»ï´ËÇ°Ôø¹¥»÷¹ýTransUnion£¬Õâ´ÎÔÙ´ÎÈÆ¹ýÁ˸ù«Ë¾µÄ·À»ðǽºÍÄþ¾²ÏµÍ³£¬ÀÖ³ÉÇÔÈ¡ÁËÊý¾Ý¡£¹¥»÷ÕßÏòTransUnionÀÕË÷3000ÍòÃÀÔª£¬²¢ÏòExperianÀÕË÷3000ÍòÃÀÔª¡£TransUnionºÍExperian͸¶ÒÑÊÕµ½ÀÕË÷ÒªÇ󣬵«ÌåÏÖûÓз¢ÏÖÊý¾Ýй¶¡£Ä¿Ç°£¬¹¥»÷ÕßÉÐδÌṩ¹ØÓÚ¹¥»÷»î¶¯ºÍÊý¾Ýй¶µÄÖ¤¾Ý¡£
https://www.businesslive.co.za/bd/national/2023-11-23-hackers-demand-60m-from-transunion-and-experian-claiming-data-theft/
3¡¢DEXƽ̨KyberSwapÔâµ½¹¥»÷Ëðʧ¸ß´ï5470ÍòÃÀÔª
¾Ý11ÔÂ27ÈÕ±¨µÀ£¬DEXƽ̨KyberSwap͸¶ÆäÔâµ½¹¥»÷£¬¼ÛÖµÔ¼5400ÍòÃÀÔªµÄ¼ÓÃÜ»õ±Ò±»µÁ¡£¹¥»÷·¢ÉúÔÚÉÏÖÜÈýÍí¼ä£¬¹¥»÷Õßͨ¹ýһϵÁÐÅÓ´óµÄÐж¯½«Óû§µÄ×ʽðÌáÈ¡µ½¹¥»÷ÕßµÄÇ®°üÖС£¶Ô´Ë£¬¸Ãƽ̨ÔÝÍ£ÁË´æ¿î£¬Õ¹¿ªÁËÊӲ죬ÁªÏµÁËÏà¹Ø¸÷·½£¬²¢Óë¹¥»÷ÕßÕ¹¿ªÌ¸ÅÐÀ´¾¡¿ÉÄÜ×·»ØËðʧ£¬°üÂÞÌṩ10%µÄÉͽð×÷Ϊ·µ»¹±»µÁ×ʽðµÄ½±Àø¡£¶à¼ÒÇø¿éÁ´Äþ¾²¹«Ë¾ºÍÑо¿ÈËÔ±³Æ£¬´Ë´Î¹¥»÷»î¶¯·Ç³£ÅÓ´ó¡£
https://therecord.media/kyberswap-crypto-platform-54-million-hack
4¡¢IT¹«Ë¾AppscookÅäÖôíÎóй¶Êý°ÙËùѧУµÄѧÉúÐÅÏ¢
ýÌå11ÔÂ24Èճƣ¬IT¹«Ë¾AppscookÓÉÓÚϵͳÅäÖôíÎó£¬Ð¹Â¶ÁË´óÁ¿Î´³ÉÄêÈ˵ÄÊý¾Ý¡£Ñо¿ÈËÔ±³Æ£¬¿ª·ÅµÄDigitalOcean´æ´¢Í°°üÂÞ½üÒ»°ÙÍò¸öÃô¸ÐÎļþ£¬É漰ѧÉúºÍ¼Ò³¤ÐÕÃû¡¢ÕÕÆ¬¡¢³öÉúÖ¤Ã÷ºÍ¼ÒͥסַµÈ¡£¸Ã¹«Ë¾¿ª·¢µÄÓ¦Ó÷¨Ê½±»Ó¡¶ÈºÍ˹ÀïÀ¼¿¨µÄ600¶àËùѧУÓÃÓÚ½ÌÓý¹ÜÀí£¬Æä¹ÙÍø³ÆÁè¼Ý50ÍòѧÉúºÍ100Íò¼Ò³¤Ê¹ÓÃ¸ÃÆ½Ì¨¡£Ä¿Ç°£¬Ñо¿ÈËÔ±ÒÑÁªÏµÁËAppscook£¬µ«ÉÐδÊÕµ½»Ø¸´¡£
https://securityaffairs.com/154743/security/app-used-by-hundreds-of-schools-leaking-childrens-data.html
5¡¢AhnLabÅû¶AndarielÀûÓé¶´CVE-2023-46604µÄÏêÇé
11ÔÂ27ÈÕ£¬AhnLabÔÚ¼à¿ØAndarielÍÅ»ï½üÆÚµÄ¹¥»÷ʱ£¬·¢ÏÖÆäÀûÓÃApache ActiveMQÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2023-46604£©°²×°¶ñÒâÈí¼þ¡£AhnLab·¢ÏÖij¸öϵͳÖб»°²×°ÁËAndariel¹ýȥһֱʹÓõĺóÃÅNukeSped¡£ÊÓ²ìÏÔʾ£¬¸ÃϵͳÖа²×°ÁËApache ActiveMQ·þÎñÆ÷£¬²¢È·ÈÏÆäÖдæÔÚ×Ըé¶´ÐÅÏ¢Ðû²¼ÒÔÀ´µÄÖÖÖÖ¹¥»÷µÄÈÕÖ¾£¬°üÂÞÉæ¼°HelloKittyÀÕË÷Èí¼þµÄ¹¥»÷ÈÕÖ¾¡£Ä¿Ç°»¹Ã»ÓÐÖ±½ÓÈÕÖ¾£¬µ«Ñо¿ÈËÔ±ÍÆ²âAndarielÕýÔÚÀûÓøÃ©¶´À´°²×°NukeSpedºÍTigerRatºóÃÅ¡£
https://asec.ahnlab.com/en/59318/
6¡¢IBMÐû²¼¹ØÓÚWailingCrab¼°ÆäC2ͨÐŵķÖÎö³ÂËß
11ÔÂ23ÈÕ±¨µÀ£¬IBMÐû²¼³ÂË߸ÅÊöÁËWailingCrab¼°ÆäC2ͨÐÅ£¬Öصã½éÉÜÁËÆä¶ÔMQTTÐÒéµÄʹÓ᣹¥»÷Á´Ê¼ÓÚ°üÂÞPDF¸½¼þµÄÓʼþ£¬Ê¹ÓÃÁËÓâÆÚ½»»õºÍÔËÊ䷢ƱµÈÖ÷Ìâ¡£ÆäÖаüÂÞ¶ñÒâURL£¬µã»÷¾Í»áÏÂÔØÒ»¸öJavaScriptÎļþ£¬¸ÃÎļþ¼ìË÷²¢Æô¶¯DiscordÉÏÍйܵÄWailingCrab¼ÓÔØ·¨Ê½¡£´ËÍ⣬×Ô2023ÄêÖÐÆÚÒÔÀ´£¬WailingCrabºóÃÅ×é¼þºÍC2Ö®¼äµÄͨÐÅÊÇʹÓÃMQTTÐÒéÖ´Ðе쬏ÃÐÒéÊÇÒ»ÖÖÇáÁ¿¼¶IoTÏûϢͨ±¨ÐÒé¡£
https://thehackernews.com/2023/11/alert-new-wailingcrab-malware-loader.html