MetaÒòÎ¥·´Å·ÃËÊý¾ÝÒþ˽·¨±»°®¶ûÀ¼·£¿£¿£¿£¿î4.14ÒÚÃÀÔª

Ðû²¼Ê±¼ä 2023-01-06
1¡¢MetaÒòÎ¥·´Å·ÃËÊý¾ÝÒþ˽·¨±»°®¶ûÀ¼·£¿£¿£¿£¿î4.14ÒÚÃÀÔª

      

¾ÝýÌå1ÔÂ5ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬°®¶ûÀ¼Êý¾Ý±£»£» £»£»£»£»¤Î¯Ô±»á (DPC) ¶ÔMeta´¦ÒÔ3.9ÒÚÅ·Ôª£¨Ô¼ºÏ4.14ÒÚÃÀÔª£©µÄ·£¿£¿£¿£¿î¡£ ¡£¡£¡£¡£¡£¡£Ôµ¹ÊÔ­ÓÉÊÇÆäÇ¿ÆÈFacebookºÍInstagramÓû§ÔÞ³ÉΪ¶¨Ïò¹ã¸æ´¦Öóͷ£Ð¡ÎÒ˽¼ÒÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ÕâÎ¥·´ÁËÅ·Ã˵ÄGDPR¡£ ¡£¡£¡£¡£¡£¡£DPC¶ÔFacebookÏà¹ØµÄÎ¥¹æÐÐΪ·£¿£¿£¿£¿î2.1ÒÚÅ·Ôª£¬£¬£¬£¬£¬£¬£¬²¢¶ÔInstagram·£¿£¿£¿£¿î1.8ÒÚÅ·Ôª£¬£¬£¬£¬£¬£¬£¬»¹ÏÂÁîMetaÔÚÈý¸öÔÂÄÚʹÆäÄ¿½ñµÄÊý¾Ý´¦Öóͷ£²Ù×÷ÇкÏGDPRµÄ»®¶¨¡£ ¡£¡£¡£¡£¡£¡£MetaÌåÏÖ£¬£¬£¬£¬£¬£¬£¬Ëü½«¶Ô²Ã¾öµÄʵÖÊÄÚÈݺͷ£¿£¿£¿£¿îÌá³öÉÏËß¡£ ¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2023/01/irish-regulators-fine-facebook-414.html


2¡¢ÆóҵЭ×÷ƽ̨Slack͸¶Æä²¿·Ö˽ÓдúÂë´æ´¢¿â±»µÁ

      

¾Ý1ÔÂ5ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬ÆóҵЭ×÷ƽ̨Slack͸¶ÆäÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬²¿·Ö˽ÓдúÂë´æ´¢¿â±»µÁ¡£ ¡£¡£¡£¡£¡£¡£SlackÓÚ2022Äê12ÔÂ29ÈÕ»ñϤ¿ÉÒɻ²¢¶ÔÊÂÎñÕö¿ªÊӲ죬£¬£¬£¬£¬£¬£¬·¢Ã÷¹¥»÷Õßͨ¹ý±»µÁµÄSlackÔ±¹¤ÁîÅÆ»ñµÃÁËSlackÍⲿÍйܵÄGitHub´æ´¢¿âµÄ»á¼ûȨÏÞ¡£ ¡£¡£¡£¡£¡£¡£ÊӲ컹ÏÔʾ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒÑÓÚ2022Äê12ÔÂ27ÈÕÏÂÔØÁË˽ÓдúÂë´æ´¢¿â£¬£¬£¬£¬£¬£¬£¬µ«SlackµÄÖ÷Òª´úÂë¿âºÍ¿Í»§Êý¾Ý²»ÊÜÓ°Ïì¡£ ¡£¡£¡£¡£¡£¡£Slack»¹³Æ£¬£¬£¬£¬£¬£¬£¬´Ë´Îδ¾­ÊÚȨµÄ»á¼û²»ÊÇÓÉSlackÖеÄÎó²îµ¼ÖµÄ£¬£¬£¬£¬£¬£¬£¬ËûÃÇ»¹½«¼ÌÐøÊÓ²ìºÍ¼à¿Ø½øÒ»²½µÄй¶¡£ ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/slacks-private-github-code-repositories-stolen-over-holidays/


3¡¢Ñо¿Ö°Ô±Í¸Â¶·¨À­ÀûºÍ±¦ÂíµÈÖÆÔìÉÌʹÓÃÒ×±»¹¥»÷µÄAPI

      

ýÌå1ÔÂ4Èճƣ¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷·áÌï¡¢·¨À­ÀûºÍ±¦ÂíµÈ½ü20¼ÒÆû³µÖÆÔìÉ̺ÍЧÀͰüÀ¨APIÇå¾²Îó²î¡£ ¡£¡£¡£¡£¡£¡£ÕâЩÎó²î¿ÉÄܱ»ÓÃÓÚÆÕ±éµÄ¶ñÒâ»î¶¯£¬£¬£¬£¬£¬£¬£¬ÀýÈç½âËø¡¢Æô¶¯¡¢¸ú×ÙÆû³µÒÔ¼°Ð¹Â¶¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢¡£ ¡£¡£¡£¡£¡£¡£Ê¹ÓÃijЩÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÉèÖò»µ±µÄSSO»á¼ûÊý°Ù¸ö÷ÈüµÂ˹ÄÚ²¿Ó¦ÓóÌÐò¡¢ÔÚ¶à¸öϵͳÉÏÔ¶³ÌÖ´ÐдúÂëÒÔ¼°»á¼ûijЩϵͳÄÚ´æ¡£ ¡£¡£¡£¡£¡£¡£ÔÚBMWµÄ°¸ÀýÖУ¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËSSOÎó²î£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´»á¼ûÄÚ²¿¾­ÏúÉÌÃÅ»§£¬£¬£¬£¬£¬£¬£¬ÅÌÎÊÆû³µµÄVIN²¢¼ìË÷°üÀ¨³µÖ÷ÏêϸÐÅÏ¢µÄÏúÊÛÎļþ¡£ ¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/140328/hacking/bmw-mercedes-toyota-other-carmakers-flaws.html


4¡¢K7 Labs·¢Ã÷ʹÓÃWindows¹ýʧ±¨¸æ¹¤¾ß·Ö·¢¶ñÒâÈí¼þµÄ»î¶¯

      

K7 LabsÓÚ1ÔÂ4ÈÕ³ÆÆä·¢Ã÷ÁËʹÓÃWindows¹ýʧ±¨¸æ¹¤¾ßWerFault.exe·Ö·¢¶ñÒâÈí¼þµÄ»î¶¯¡£ ¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Ê¼ÓÚÒ»·â´øÓÐISO¸½¼þµÄµç×ÓÓʼþ£¬£¬£¬£¬£¬£¬£¬Ë«»÷ʱISO»á½«×Ô¼º¹ÒÔØÎªÒ»¸öеÄÅÌ·û£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨WerFault.exeµÄÕýµ±¸±±¾¡¢Ò»¸öDLLÎļþÒ»¸öXLSÎļþºÍÒ»¸ö¿ì½Ý·½·¨Îļþ¡£ ¡£¡£¡£¡£¡£¡£É±¶¾¹¤¾ßͨ³£ÐÅÈÎWerFault£¬£¬£¬£¬£¬£¬£¬Òò´ËÔÚϵͳÉÏÆô¶¯Ëüͨ³£²»»á´¥·¢¾¯±¨¡£ ¡£¡£¡£¡£¡£¡£Æô¶¯WerFault.exeʱ£¬£¬£¬£¬£¬£¬£¬Ëü½«Ê¹ÓÃDLL²à¼ÓÔØÎó²îÀ´¼ÓÔØISOÖаüÀ¨µÄ¶ñÒâDLL Faultrep.dll£¬£¬£¬£¬£¬£¬£¬×îÖÕÖ´ÐÐPupy RAT¡£ ¡£¡£¡£¡£¡£¡£


https://labs.k7computing.com/index.php/pupy-rat-hiding-under-werfaults-cover/


5¡¢É罻ƽ̨Cricketsocial.comÓû§ÐÅÏ¢ºÍÖÎÀíԱƾ֤й¶

      

1ÔÂ4ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬£¬£¬CyberNews·¢Ã÷°åÇòÉ罻ƽ̨Cricketsocial.comй¶ÁËÁè¼Ý10ÍòÌõÓû§Ð¡ÎÒ˽¼ÒÐÅÏ¢ºÍƾ֤¡£ ¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÓÉÃÀ¹úAWSÍйÜ£¬£¬£¬£¬£¬£¬£¬°üÀ¨µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢ÐÕÃû¡¢Óû§ÃÜÂë¡¢³öÉúÈÕÆÚºÍµØµãµÈÐÅÏ¢¡£ ¡£¡£¡£¡£¡£¡£ÆäÖд󲿷ּÍÂ¼ËÆºõ¶¼ÊDzâÊÔÊý¾Ý£¬£¬£¬£¬£¬£¬£¬µ«ÈÔÈ»°üÀ¨Õýµ±ÍøÕ¾Óû§µÄPIIÐÅÏ¢¡£ ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷¸ÃÊý¾Ý¿â»¹Ð¹Â¶ÁËÃ÷ÎÄÐÎʽ´æ´¢µÄÍøÕ¾ÖÎÀíԱƾ֤£¬£¬£¬£¬£¬£¬£¬¿É±»¹¥»÷ÕßÓÃÀ´½ÓÊÜÆ½Ì¨¡£ ¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/140329/data-breach/cricketsocial-com-data-leak.html


6¡¢ZohoÐÞ¸´ManageEngineÖÐSQL×¢ÈëÎó²îCVE-2022-47523

      

ýÌå1ÔÂ4ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬£¬£¬Zoho±Þ²ß¿Í»§ÐÞ¸´Ó°ÏìÁ˶à¸öManageEngine²úÆ·µÄÇå¾²Îó²î¡£ ¡£¡£¡£¡£¡£¡£Îó²î×·×ÙΪCVE-2022-47523£¬£¬£¬£¬£¬£¬£¬ÊÇPassword Manager Pro¡¢PAM360ºÍAccess Manager PlusÖз¢Ã÷µÄSQL×¢ÈëÎó²î¡£ ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓøÃÎó²î¿É»ñµÃºó¶ËÊý¾Ý¿âµÄ»á¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬²¢Ö´ÐÐ×Ô½ç˵ÅÌÎÊÒÔ»á¼ûÊý¾Ý¿â±íÌõÄ¿¡£ ¡£¡£¡£¡£¡£¡£Zoho³ÆÆäÒѾ­Í¨¹ýתÒåÌØÊâ×Ö·ûºÍÌí¼ÓÊʵ±µÄÑéÖ¤½â¾öÁ˸ÃÎÊÌâ¡£ ¡£¡£¡£¡£¡£¡£¼øÓÚ´ËÎó²îµÄÑÏÖØÐÔ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Ç¿ÁÒ½¨Òé¿Í»§Á¬Ã¦Éý¼¶µ½×îа汾¡£ ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/zoho-urges-admins-to-patch-critical-manageengine-bug-immediately/