Ñо¿ÍŶӷ¢Ã÷³¬µÈÊý¾Ýй¶ºÏ¼¯´ï12TBº¸Ç260ÒÚÌõÊý¾Ý
Ðû²¼Ê±¼ä 2024-01-241ÔÂ22ÈÕ£¬Õâ´Î³¬´ó¹æģй¶°üÀ¨À´×Ô֮ǰ¶à´Î鶵ÄÊý¾Ý£¬ÆäÖаüÀ¨ÁîÈËÕð¾ªµÄ 12 TB ÐÅÏ¢£¬º¸ÇÁîÈËÄÑÒÔÖÃÐÅµÄ 260 ÒÚÌõÊý¾Ý¡£Õâ´Î³¬´ó¹æģй¶°üÀ¨À´×Ô֮ǰ¶à´Î鶵ÄÊý¾Ý£¬ÆäÖаüÀ¨ÁîÈËÕð¾ªµÄ 12 TB ÐÅÏ¢£¬º¸ÇÁîÈËÄÑÒÔÖÃÐÅµÄ 260 ÒÚÌõÊý¾Ý¡£ÏÕЩ¿ÉÒÔÒ»¶¨£¬Õâ´Î×ß©ÊÇÆù½ñΪֹ·¢Ã÷µÄ×î´óµÄÒ»´ÎÊý¾Ýй¶¡£¾Ý³ÆÓÐÊýÒÚÌõÊý¾ÝÀ´×Ô΢²© (504M)¡¢MySpace (360M)¡¢Twitter (281M)¡¢Deezer (258M)¡¢Linkedin (251M)¡¢AdultFriendFinder (220M)¡¢Adobe (153M)¡¢Canva (143M) ¡¢VK (101M)¡¢Daily Motion (86M)¡¢Dropbox (69M)¡¢Telegram (41M) ÒÔ¼°Ðí¶àÆäËû¹«Ë¾ºÍ×éÖ¯¡£´Ë´Î鶻¹°üÀ¨ÃÀ¹ú¡¢°ÍÎ÷¡¢µÂ¹ú¡¢·ÆÂɱö¡¢ÍÁ¶úÆäºÍÆäËû¹ú¼Ò¸÷¸öÕþ¸®×éÖ¯µÄ¼Í¼¡£
2. ÎÚ¿ËÀ¼×î´óµÄÊÖ»úÒøÐÐMonobankÔâÓöب¹ÅδÓеÄDDoS¹¥»÷
1ÔÂ22ÈÕ£¬ÎÚ¿ËÀ¼×î´óµÄÊÖ»úÒøÐÐMonobankÓÚ 1 Ô 21 ÈÕÔâÓöÒ»Á¬´®¾Ü¾ø·þÎñ (DDoS) ¹¥»÷£¬µ¼ÖÂÆäÔËӪ̱»¾²¢Ôì³É´ó¹æÄ£ÖÐÖ¹¡£ÍŽáÊ×´´È˼æÊ×ϯִÐй٠Oleh Horokhovskyi ÔÚTelegram ÉÏ֤ʵÁËMonobank Ôâµ½ÍøÂç¹¥»÷£¬²¢Í¸Â¶ÆäÖÐÒ»´Î¹¥»÷ÖиÃÒøÐÐÊÕµ½Á˾ªÈ赀 5.8 ÒÚ¸ö·þÎñÇëÇó¡£DDoS ¹¥»÷Éæ¼°Óùý¶àµÄÁ÷Á¿Ñ¹¿åÍøÕ¾£¬Ê¹Æä·þÎñÆ÷³¬ÔØ£¬ÒѳÉΪ׷ÇóÆÆËð·þÎñµÄÍøÂç·¸·¨·Ö×Ó×îϲ»¶µÄÕ½ÂÔ¡£¶íÂÞ˹ºÚ¿Í×éÖ¯ Solntsepek Éù³Æ¶ÔKyivstar ÍøÂç¹¥»÷ÈÏÕ棬Òý·¢ÈËÃǶԶíÂÞ˹¿ÉÄܼÓÈë×î½üµÄ Monobank DDoS ¹¥»÷µÄÏÓÒÉ¡£
3. LoanDepotÔâµ½ÀÕË÷¹¥»÷²¢È·ÈÏÆäÔ¼1660Íò¿Í»§ÐÅÏ¢±»µÁ
4. GoAnywhere MFT ÖеÄÉí·ÝÑéÖ¤ÈƹýÎó²îCVE-2024-0204
1ÔÂ22ÈÕ£¬GoAnywhere MFTÊÇÒ»ÖÖÇå¾²µÄÍйÜÎļþ´«Êä (MFT) ½â¾ö¼Æ»®£¬¿É×ÊÖú×éÖ¯×Ô¶¯»¯¡¢¼¯Öл¯ºÍ±£»¤ÆäÎļþ´«Êä¡£ËüÊÇÒ»¸öÈí¼þƽ̨£¬¿ÉÒÔÏû³ýÔÚ²î±ðϵͳºÍÖ°Ô±Ö®¼äÒƶ¯Êý¾ÝµÄƶÀ§¡£GoAnywhere MFT ÊÇÒ»¿î¹¦Ð§Ç¿Ê¢ÇҶ๦ЧµÄ½â¾ö¼Æ»®£¬ÊʺÏÐèÒªÓÐÓñ£»¤ºÍÖÎÀíÎļþ´«ÊäµÄ×éÖ¯¡£¸ÃÎļþ´«Êä½â¾ö¼Æ»®¾¯±¨µÄ×îпª·¢Ö°Ô±Õ¹ÏÖÁËÒ»¸öÑÏÖØȱÏÝ£¬¸ÃȱÏÝ¿ÉÄÜ»áÈƹýÉí·ÝÑéÖ¤µÄʵÖÊ¡£¸ÃȱÏݵıàºÅΪ CVE-2024-0204£¬CVSS ÆÀ·ÖΪ 9.8£¬±»ÐÎòΪ Fortra 7.4.1 °æ±¾Ö®Ç°µÄ GoAnywhere MFT ÖеÄÉí·ÝÑéÖ¤ÈƹýÎó²î¡£´ËȱÏÝÇÉÃîµØÔÊÐíδ¾ÊÚȨµÄÓû§Í¨¹ýÖÎÀíÃÅ»§Î±×°³ÉÖÎÀíÔ±¡£
5. ÑÅ»¢ÓÉÓÚÀÄÓÃCookie±»·¨¹úî¿Ïµ»ú¹¹·£¿î 1000 ÍòÅ·Ôª
1ÔÂ22ÈÕ£¬·¨¹úÊý¾Ý±£»¤î¿Ïµ»ú¹¹ÖÜËÄÌåÏÖ£¬Ëü¶ÔÑÅ»¢´¦ÒÔ 1000 ÍòÅ·ÔªµÄ·£¿î£¬Ôµ¹ÊÔÓÉÊÇÑÅ»¢²»×ðÖØÓû§¾Ü¾ø»¥ÁªÍø¸ú×Ù¡°cookie¡±µÄÒªÇ󣬻òÕßÌåÏÖÈôÊǾܾø£¬ËûÃǽ«ÎÞ·¨»á¼ûµç×ÓÓʼþÕ˺š£CNIL Õþ¸®ÓÚ 2020 Äê 10 ÔÂºÍ 2021 Äê 6 ÔÂÊÕµ½Í¶Ëß²¢¿ªÕ¹ÊÓ²ìºó£¬ÓÚ 12 Ô´¦ÒÔÏ൱ÓÚ 1090 ÍòÃÀÔªµÄ·£¿î¡£Ñо¿·¢Ã÷£¬»á¼û Yahoo.com Ö÷ÍøÕ¾µÄ»á¼ûÕßËäÈ»µã»÷Á˾ܾø cookie µÄ°´Å¥£¬µ«×îÖÕÕÕ¾ÉÊÕµ½ÁËԼĪ 20 ¸öÓÃÓÚ¹ã¸æÄ¿µÄµÄÊý×Ö¸ú×ÙÆ÷¡£×Ô 2018 ÄêÅ·ÃËͨÓÃÊý¾Ý±£»¤ÌõÀý (GDPR) ³ǫ̈ÒÔÀ´£¬»¥ÁªÍø¹«Ë¾ÔÚ»ñµÃÓû§ÔÞ³ÉÔõÑùʹÓÃÆäСÎÒ˽¼ÒÐÅÏ¢·½ÃæÃæÁÙןüÑÏ¿áµÄ¹æÔò¡£·¨¹ú¶Ô¹È¸è¡¢Meta¡¢ÑÇÂíÑ·¡¢Î¢Èí¡¢Æ»¹ûºÍ TikTok µÈ¹«Ë¾µÄÎ¥¹æÐÐΪ¾ÙÐÐÁË´¦·Ö£¬·£¿î×ܶî½ü 4 ÒÚÅ·Ôª¡£
6. Ñо¿ÍŶӷ¢Ã÷Õë¶ÔýÌåºÍר¼ÒµÄÍøÂç¹¥»÷Ô˶¯ScarCruft
1ÔÂ22ÈÕ£¬ÔÚ´í×ÛÖØ´óµÄÈ«ÇòÍøÂçÌع¤ÍøÂçÖУ¬¹ú¼ÒÖ§³ÖµÄ¸ß¼¶Ò»Á¬Íþв (APT)×éÖ¯£¨ ScarCruft£©µÄÔ˶¯ÒòÆä׼ȷÐÔºÍÕ½ÂÔÖصã¶øÍÑÓ±¶ø³ö¡£¿ËÈÕ£¬ÉÚ±øʵÑéÊÒ£¬ÓëNK ÐÂÎÅÏàÖú£¬½Ò¿ªÁË ScarCruft È«ÐIJ߻®µÄÒ»³¡Õë¶ÔýÌå×éÖ¯ºÍ³¯ÏÊÊÂÎñר¼ÒµÄÔ˶¯¡£ÕâÒ»Ðж¯ÒÔ³¤ÆÚÐÔºÍÖØ´óÐÔΪÌص㣬·´Ó¦ÁËÍøÂçÕ½ÖÐÐþÃîµÄȨÁ¦²©ÞÄ¡£Á½¸ö¶àÔÂÒÔÀ´£¬SentinelLabs ÊӲ쵽 ScarCruft Ò»Á¬Õë¶ÔͳһСÎÒ˽¼Ò£¬ÕâÈÃÎÒÃǵÃÒÔÒ»¿ú APT µÄ¹±Ï×¾«ÉñºÍ×ãÖǶàı¡£ÕâһĿµÄÉæ¼°º«¹úѧÊõ½çµÄר¼ÒºÍרÃÅÑо¿³¯ÏÊÊÂÎñµÄÐÂÎÅ»ú¹¹¡£ÕâЩ¹¥»÷¼òÖ±ÇÐÐÔ×ÓÅú×¢Îú ScarCruft µÄÕ½ÂÔÄ¿µÄ£ºÍøÂçÇ鱨²¢Ó°Ïì¿´·¨¡£ScarCruft£¬Ò²³ÆΪ APT37 ºÍ InkySquid£¬ÔÚÆäÎäÆ÷¿âÖÐʹÓÃÁ˶àÖÖ¹¤¾ßºÍÒªÁì¡£¸ÃÔ˶¯µÄÌصãÊÇʹÓÃÁ˶¨ÖƵĺóÃÅ RokRAT£¬ÕâÊÇÒ»ÖÖ¹¦Ð§ÆëÈ«µÄ¼àÊÓ¹¤¾ß£¬Äܹ»¶ÔÄ¿µÄʵÌå¾ÙÐÐÓÐÓõÄÌع¤Ô˶¯¡£¸Ã×éÖ¯µÄѬȾÁ´Éæ¼°¶à½×¶Î»úÖƺͶàÖÖ¿ÉÖ´ÐÐÃûÌ㬲¢½ÓÄɹæ±ÜÊÖÒÕÀ´¼á³Ö²»±»·¢Ã÷¡£