TwitterÍøÂçÓû§ÐÅÏ¢¶¨ÏòÍÆË͸æ°×±»·£¿î1.5ÒÚÃÀÔª

°ä²¼¹¦·ò 2022-05-26

1¡¢TwitterÍøÂçÓû§ÐÅÏ¢¶¨ÏòÍÆË͸æ°×±»·£¿î1.5ÒÚÃÀÔª


¾Ý5ÔÂ26ÈÕ±¨Â· £¬ÃÀ¹úÁª¹úÒµÎñίԱ»áFTCÒѶÔTwitter·£¿î1.5ÒÚÃÀÔª £¬Ô­ÒòÊÇËüʹÓÃÍøÂçµÄ2FAÑéÖ¤µÄµç»°ºÅÂëºÍÓʼþµØÖ·À´ÍÆË͸æ°×¡£Æ¾¾Ý·¨Í¥Îļþ £¬´Ó2013ÄêÆðÍ· £¬TwitterÒªÇ󳬹ý1.4ÒÚÓû§ÌṩÕâЩÐÅÏ¢ÒÔ±£»¤ËûÃǵÄÕË»§ £¬µ«Ã»ÓÐ֪ͨËûÃÇÕâЩÊý¾ÝÒ²½«ÓÃÓÚ¸æ°×ÉÌͶ·Å¸æ°×¡£FTCÖ÷ϯ³Æ £¬TwitterÒÔÓÃÓÚ°²È«Ö÷ÕÅΪ½è¿Ú´ÓÓû§ÄÇÀï»ñÈ¡Êý¾Ý £¬µ«×îÖÕ»¹Ê¹ÓÃÕâЩÊý¾ÝÀ´Õë¶ÔÓû§Í¶·Å¸æ°× £¬ÕâÖÖ×ö·¨Ó°ÏìÁË´óÁ¿Óû§µÄͬʱ»¹ÌáÉýÁËTwitterµÄÊÕÈë¡£TwitterÒÑÔÞ³ÉÖ§¸¶1.5ÒÚÃÀÔªµÄ·£¿î¡£


https://www.bleepingcomputer.com/news/technology/ftc-fines-twitter-150m-for-using-2fa-info-for-targeted-advertising/


2¡¢Ç÷Ïò¿Æ¼¼½¨¸´Òѱ»Moshen DragonÀûÓõÄDLL½Ù³Ö·ì϶


¾ÝýÌå5ÔÂ24ÈÕ±¨Â· £¬Ç÷Ïò¿Æ¼¼½¨¸´Æä°²È«²úÆ·ÖеÄDLL½Ù³Ö·ì϶¡£ÕýÈçSentinel LabsÔÚ5Ô³õÅû¶µÄÄÇÑù £¬Moshen DragonÔÚÕë¶ÔÖÐÑǵĵçÐÅÐÐÒµµÄ¹¥»÷ÖÐ £¬ÊÔͼ½Ù³Ö°²È«¹©¸øÉ̵ķ¨Ê½ £¬Ô̺¬Symantec¡¢TrendMicro¡¢BitDefender¡¢McAfeeºÍKaspersky¡£¹¥»÷ÕßÀûÓÃÁ˶à¸ö¶ñÒâÈí¼þ £¬²¢Í¨¹ýDLL½Ù³ÖÀ´²à¼ÓÔØShadowPadºÍPlugX¡£Trend MicroÒÑÓÚ5ÔÂ19ÈÕͨ¹ýÆäActiveUpdate(AU)°ä²¼ÁËÒ»¸ö½¨¸´·¨Ê½ £¬²¢½¨ÒéÓû§Á¢¼´½øÐиüС£


https://securityaffairs.co/wordpress/131635/hacking/trend-micro-flaw-moshen-dragon.html


3¡¢Ä³ÅäÖÃÃýÎóµÄES·þÎñÆ÷й¶Êý°ÙÍò´û¿îÉêÇëÈ˵ÄÐÅÏ¢


¾Ý5ÔÂ24ÈÕ±¨Â· £¬Ò»¸öÅäÖÃÃýÎóµÄElasticsearch·þÎñÆ÷й¶ÁË147 GBµÄÊý¾Ý £¬¹²8.7Òڱʼͼ¡£¸Ã·þÎñÆ÷ÓÚ2021Äê12ÔÂ5ÈÕ±»¼ì²âµ½ £¬ÖØÒªÔ̺¬ÎÚ¿ËÀ¼¡¢¹þÈø¿Ë˹̹ºÍ¶íÂÞ˹Ó×¶î´û¿îµÄÉêÇëÈ˵ÄÐÅÏ¢ £¬ÈçÐÕÃû¡¢×¡Ö·ºÍ»¤ÕÕºÅÂëµÈÓ×ÎÒÐÅÏ¢ £¬ÒÔ¼°Ð½Ë®¡¢´û¿îÏêÇéºÍINN£¨Ë°ºÅ£©µÈ²ÆÕþÐÅÏ¢¡£¾Ý¹À¼Æ £¬Ô¼ÓÐ1000ÍòÓû§Êܵ½Ó°Ïì £¬ÆäÖдó²¿ÃÅ·þÎñÆ÷ÈÕÖ¾ºÍ»¤ÕÕºÅÂëÊôÓÚ¶íÂÞ˹ £¬´óÎÞÊýINNÊôÓÚÎÚ¿ËÀ¼ £¬¶ø¸Ã·þÎñÆ÷λÓÚºÉÀ¼µÄ°¢Ä·Ë¹Ìص¤¡£


https://www.hackread.com/personal-data-russians-ukrainians-exposed-online/


4¡¢Mozilla°ä²¼¸üн¨¸´Pwn2Own´ó»áÖб»ÀûÓõĶà¸ö·ì϶


5ÔÂ20ÈÕ £¬Mozilla°ä²¼ÁËFirefoxºÍThunderbirdµÄ°²È«¸üР£¬ÒÔ½¨¸´ÔÚPwn2Own 2022´ó»áÆÚ¼ä±»ÀûÓõķì϶¡£µÚÒ»¸ö·ì϶ÊÇTop-Level AwaitʵÏÖÖеÄÔ­ÐÍÁ´´«È¾£¨prototype pollution£©·ì϶ £¬×·×ÙΪCVE-2022-1802 £¬¹¥»÷Õß¿ÉÀûÓÃËüÀ´Ö´ÐÐJavaScript´úÂë¡£µÚ¶þ¸ö·ì϶( CVE-2022-1529 ) ÊÇJavaScript¶ÔÏóË÷ÒýÖÐʹÓò»ÊÜÐŵÄÊäÈëµ¼ÖµÄÔ­ÐÍÁ´´«È¾·ì϶ £¬¿ÉÓÃÀ´ÔÚÌØÈ¨¸¸¹ý³ÌÖÐÖ´ÐÐJavaScript¡£CISAÔÚ5ÔÂ23ÈÕ°ä²¼°²È«¹«¸æ £¬½¨ÒéÁ¢¿Ì½¨¸´ÕâЩ·ì϶¡£


https://www.bleepingcomputer.com/news/security/mozilla-fixes-firefox-thunderbird-zero-days-exploited-at-pwn2own/


5¡¢ChromeÀ©´óScreencastify½¨¸´¿É½Ù³ÖÉãÏñÍ·µÄXSS·ì϶


ýÌå5ÔÂ24ÈÕ³Æ £¬Ê¢ÐеÄChromeÀ©´óScreencastify½¨¸´ÁËÒ»¸öXSS·ì϶¡£ÕâÊÇÒ»¸öÓÃÓÚ¼ÆÁ¡¢ÊÓÆµ±à×ëºÍýÌå¹²ÏíµÄä¯ÀÀÆ÷À©´ó £¬ÔÚChromeÖеÄ×°ÖÃÁ¿³¬¹ý10000000´Î¡£¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶ÆôÓÃScreencastify¼ÔìÊÓÆµ £¬²¢½«ÆäÉÏ´«µ½Google Drive¡£»¹Äܹ»ÀûÓÃͬÑùµÄ·ì϶À´ÇÔÈ¡¹È¸èÇý¶¯Æ÷µÄOAuthÁîÅÆ £¬²¢ÓÃËüÀ´ÏÂÔØÉÏ´«µÄÊÓÆµ £¬ÒÔ¼°´æ´¢ÔڹȸèÇý¶¯Æ÷ÉÏµÄÆäËüÆ÷²Ä¡£


https://www.bleepingcomputer.com/news/security/screencastify-chrome-extension-flaws-allow-webcam-hijacks/


6¡¢BlackBerry°ä²¼¹ØÓÚChaosбäÌåYashmaµÄ·ÖÎö»ã±¨


5ÔÂ24ÈÕ £¬BlackBerry°ä²¼Á˹ØÓÚÀÕË÷Èí¼þYashma¼°Æä¼Ò×åµÄ·ÖÎö»ã±¨¡£ChaosÊÇÒ»Öֿɶ¨ÔìµÄÀÕË÷Èí¼þ¹¹½¨Æ÷ £¬ÓÚ2021Äê6ÔÂ9ÈÕ³õ´Î³öÏÖ £¬Ôø¾­ÀúÁË5´Îµü´ú £¬YashmaÐû³ÆÊÇËüµÄµÚÁù°æ(v6.0) £¬ÓÚ2022ÄêµÄÄêÖÐÔÚÒ°±í±»·¢ÏÖ¡£ChaosµÄǰÈý¸ö°æ±¾Ó봫ͳµÄÀÕË÷Èí¼þ±ÈÆðÀ´¸üÏñÊÇÓµÓзÛËéÐԵľÂí £¬µ«Chaos 4.0½øÒ»²½¸Ä½ø £¬½«¿É¼ÓÃÜÎļþµÄÉÏÏÞÌá¸ßµ½2.1MB¡£Chaos 5.0ʹÓÃÁËAES-256¼ÓÃÜÖ¸±êÎļþ £¬¶øYashmaÓëÉÏÒ»¸ö°æ±¾ÏÕЩһÑù £¬½öÔö³¤ÁËÁ½ÏîÅú¸Ä¡£ 


https://blogs.blackberry.com/en/2022/05/yashma-ransomware-tracing-the-chaos-family-tree