McAfeeÅû¶½üÆÚð³äÈÕ±¾µçÁ¦ºÍË®Îñ¹«Ë¾µÄ¹¥»÷Ô˶¯
Ðû²¼Ê±¼ä 2023-07-241¡¢McAfeeÅû¶½üÆÚð³äÈÕ±¾µçÁ¦ºÍË®Îñ¹«Ë¾µÄ¹¥»÷Ô˶¯
McAfeeÔÚ7ÔÂ21ÈÕÅû¶ÁËð³äµçÁ¦ºÍË®Îñ»ù´¡ÉèÊ©¹«Ë¾µÄ¹¥»÷Ô˶¯¡£¸ÃÔ˶¯´Ó6ÔÂ7ÈÕ×îÏÈ£¬Ò»Á¬Á˺̵ܶÄÒ»¶Îʱ¼ä¡£Ö÷ÒªÕë¶ÔÈÕ±¾µÄAndroidÓû§£¬Í¨¹ý¶ÌÐÅÌáÐÑÖ§¸¶ÎÊÌ⣬ÓÕʹĿµÄ»á¼û´¹ÂÚÍøÕ¾£¬È»ºóʹÓÃÌع¤Èí¼þSpyNoteÀ´Ñ¬È¾Ä¿µÄµÄ×°±¸¡£SpyNoteÊÇÒ»¸öÒÑÖªµÄ¶ñÒâÈí¼þϵÁУ¬¿ÉÇÔȡװ±¸ÐÅÏ¢ºÍÃô¸ÐµÄÓû§ÐÅÏ¢£¬ÆäÔ´´úÂëÓÚ2022Äê10ÔÂй¶ºó¼¤Ôö¡£×î½ü£¬Ôø±»ÓÃÓÚ1Ô·ÝÕë¶Ô½ðÈÚ»ú¹¹µÄ¹¥»÷ÒÔ¼°4ÔÂÕë¶ÔÈÕ±¾ÒøÐеĹ¥»÷¡£
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/android-spynote-attacks-electric-and-water-public-utility-users-in-japan/
2¡¢ÑÇÂíÑ·ÔÞ³ÉÒÔ2500ÍòÃÀԪϢÕùAlexaÎ¥·´¶ùͯÒþ˽·¨µÄÖ¸¿Ø
¾Ý7ÔÂ21ÈÕ±¨µÀ£¬ÑÇÂíÑ·ÒÑÔÞ³ÉÖ§¸¶2500ÍòÃÀÔª·£¿î£¬ÒÔÏ¢ÕùÓëÆäAlexaÓïÒôÖúÀí·þÎñÏà¹ØµÄÉæÏÓÎ¥·´¶ùͯÒþ˽·¨µÄÖ¸¿Ø¡£×Ô2018Äê5ÔÂÆð£¬ÑÇÂíÑ·¶Ô13ËêÒÔ϶ùͯÌṩAlexaÉù¿Ø²úÆ·ºÍ·þÎñ¡£2023Äê5Ô£¬ÃÀ¹úFTCºÍDOJ¶ÔÑÇÂíÑ·Ìá³öÖ¸¿Ø£¬³ÆÆäÎ¥·´Á˶ùͯÒþ˽·¨£¬ÆäÖаüÀ¨¡¶Áª°îÉÌҵίԱ»á·¨¡·¡¢¡¶¶ùͯÔÚÏßÒþ˽ÑÚ»¤·¨¡·(COPPA)ºÍCOPPA¹æÔò¡£Ëß×´³Æ£¬ÑÇÂíÑ·ÔÚÏ൱³¤µÄÒ»¶Îʱ¼äÄÚδÄÜÖª×ã¼Ò³¤É¾³ýº¢×Ó¼ÒôµÄÒªÇ󣬱ðµÄ£¬¸Ã¹«Ë¾±¾Ó¦Æ¾Ö¤ÒªÇóɾ³ýÓû§µÄÓïÒôÐÅÏ¢ºÍµØÀíλÖÃÊý¾Ý£¬µ«È´Ñ¡Ôñ±£´æÕâЩÐÅÏ¢ÒÔ¹©¿ÉÄܵÄʹÓá£
https://www.bleepingcomputer.com/news/technology/amazon-agrees-to-25-million-fine-for-alexa-children-privacy-violations/
3¡¢ÓÎϷƽ̨RobloxÊý¾Ýй¶Éæ¼°Êýǧ¸ö¿ª·¢Ö°Ô±µÄÐÅÏ¢
¾Ý7ÔÂ21ÈÕ±¨µÀ£¬¹²ÓÐ3943¸öRoblox¿ª·¢ÕßÕÊ»§±»µÁ¡£ÔçÔÚ2021Ä꣬Roblox¾Í±¬·¢ÁËÊý¾Ýй¶£¬µ«¾ÝϤ¸Ã¹«Ë¾½«¸ÃÊÂÎñÕÚÑÚÁËÖÁÉÙÁ½Äê¡£Have I Been PwnedÓÚ7ÔÂ18ÈÕÊ×´ÎÆعâÁË´Ë´Îй¶ÊÂÎñ£¬³Æй¶×î³õ±¬·¢ÔÚ2020Äê12ÔÂ18ÈÕ£¬Éæ¼°ÐÕÃû¡¢µç»°ºÅÂë¡¢ÓʼþµØµãºÍIPµØµãµÈ¡£RobloxÈÏ¿É£¬Ò»¸öµÚÈý·½Çå¾²ÎÊÌâµ¼Ö¶ÔÆ佨ÉèÕßµÄСÎÒ˽¼ÒÊý¾Ýδ¾ÊÚȨµÄ»á¼û¡£¹ØÓÚÊÜÓ°Ïì½ÏСµÄÓû§£¬ËûÃǽ«»áÊÕµ½Ò»·âÖÂǸÓʼþ¡£¹ØÓÚÊÜÓ°ÏìÑÏÖصÄÓû§£¬ËûÃǽ«»á»ñµÃΪÆÚÒ»ÄêµÄÉí·ÝÑÚ»¤·þÎñ¡£
https://www.hackread.com/roblox-data-breach-developers-pii-data-stolen/
4¡¢Ñо¿Ö°Ô±·¢Ã÷ʹÓÃCitrixÎó²îÕë¶ÔÃÀ¹ú»ù´¡ÉèÊ©µÄ¹¥»÷
7ÔÂ21ÈÕ±¨µÀ³Æ£¬CISAÌáÐÑʹÓÃCitrix NetScaler ADCºÍGatewayÖÐÎó²î¹¥»÷ÃÀ¹úÒªº¦»ù´¡ÉèÊ©µÄÔ˶¯¡£´Ë´Î¹¥»÷±¬·¢ÔÚ6Ô·ݣ¬ºÚ¿ÍʹÓÃÁËRCEÎó²î£¨CVE-2023-3519£©£¬ÔÚÄ¿µÄµÄ·ÇÉú²úNetScalerÓ¦Óý»¸¶¿ØÖÆÆ÷(ADC)×°±¸ÉÏÖ²ÈëWebshell¡£¸ÃºóÃÅ¿ÉÓÃÀ´Ã¶¾ÙAD¹¤¾ß£¬°üÀ¨ÍøÂçÉϵÄÓû§¡¢×é¡¢Ó¦ÓóÌÐòºÍ×°±¸£¬²¢ÇÔÈ¡ADÊý¾Ý¡£È»¶ø£¬ÓÉÓÚÄ¿µÄNetScaler ADC×°±¸Î»ÓÚ¸ôÀëÇéÐÎÖУ¬¹¥»÷ÕßÎÞ·¨ºáÏòÒƶ¯µ½Óò¿ØÖÆÆ÷¡£CISAÐû²¼ÁËÒ»·Ý°üÀ¨TTPÒÔ¼°¼ì²âÒªÁìµÄͨ¸æ£¬²¢½¨ÒéÖÎÀíÔ±Ó¦ÓÃ×îеÄCitrix¸üС£
https://securityaffairs.com/148690/security/cisa-citrix-netscaler-adc.html
5¡¢ÁåľµÄÁ½¼Ò¾ÏúÉÌÍøÕ¾ÒòÉèÖùýʧй¶¿Í»§µÄÐÅÏ¢
ýÌå7ÔÂ21Èճƣ¬ÁåľÊÚȨµÄÁ½¸ö¾ÏúÉ̵ÄÍøվй¶ÁË¿Í»§µÄÃô¸ÐÐÅÏ¢¡£µÚÒ»¼Ò¾ÏúµêÔÚ°ÍÎ÷ÔËÓª£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÄÚÈÝ·Ö·¢ÍøÂç(CDN)GoChacheµÄ¶ËµãºÍÃÜÔ¿¡¢MySQLÊý¾Ý¿â¡¢SMTPƾ֤ÒÔ¼°Ó¦ÓóÌÐòºÍÍⲿµÚÈý·½·þÎñµÄÖÖÖÖÃÜÔ¿¡£µÚ¶þ¼ÒÊÇ°ÍÁÖΨһµÄÁåľÆû³µ¾ÏúÉÌ£¬¸Ã¹«Ë¾µÄLaravelÓ¦ÓÃÃÜÔ¿¡¢Êý¾Ý¿âºÍSMTPƾ֤²»ÊÜÑÚ»¤¡£Ñо¿Ö°Ô±³Æ£¬SMTPƾ֤¿ÉÓÃÓÚÏòÓû§·¢ËͶñÒâÓʼþ£¬Êý¾Ý¿âƾ֤¿ÉÓÃÀ´»á¼ûÊý¾Ý¿âÄÚÈÝ£¬ÆäÖпÉÄÜ°üÀ¨Óû§ÐÅÏ¢¡£
https://securityaffairs.com/148675/data-breach/nice-suzuki-sport-shame-dealer-left-your-data-up-for-grabs.html
6¡¢Unit 42Ðû²¼¹ØÓÚÀÕË÷Èí¼þMalox¹¥»÷Ô˶¯µÄÆÊÎö±¨¸æ
7ÔÂ20ÈÕ£¬Unit 42Ðû²¼Á˹ØÓÚÀÕË÷Èí¼þMalox¹¥»÷Ô˶¯µÄÆÊÎö±¨¸æ¡£Mallox£¨ÓÖÃûTargetCompany£©ÊÇÒ»ÖÖÕë¶ÔMicrosoft WindowsϵͳµÄÀÕË÷Èí¼þ£¬×Ô2021Äê6ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬Ö÷ҪʹÓò»Çå¾²µÄMS-SQL·þÎñÆ÷×÷ΪÔØÌ壬ÈëÇÖÄ¿µÄµÄÍøÂç¡£½üÆÚ£¬Unit 42ÊӲ쵽Mallox¹¥»÷Ô˶¯ÓÐËùÔöÌí£¬ÓëÇ°Ò»ÄêÏà±ÈÔöÌíÁ˽ü174%¡£MalloxʹÓÃÁ˱©Á¦Æƽ⡢Êý¾Ýй¶ºÍÍøÂçɨÃ蹤¾ßµÈ¡£±ðµÄ£¬Ñо¿Ö°Ô±·¢Ã÷Óм£ÏóÅú×¢¸Ã×éÖ¯ÕýÔÚÆð¾¢À©´óÆäÓªÒµ£¬²¢ÔÚºÚ¿ÍÂÛ̳ÉÏÕÐļÁ¥Êô»ú¹¹¡£
https://unit42.paloaltonetworks.com/mallox-ransomware/