Google DriveÓû§³ÆÔÆÐ§ÀÍÖеĴ洢Êý¾Ýɥʧ

Ðû²¼Ê±¼ä 2023-11-28
1¡¢Google DriveÓû§³ÆÔÆÐ§ÀÍÖеĴ洢Êý¾Ýɥʧ


¾ÝýÌå11ÔÂ27ÈÕ±¨µÀ£¬ £¬£¬£¬£¬£¬Google DriveÓû§±¨¸æ³Æ£¬ £¬£¬£¬£¬£¬×î½ü´æ´¢ÔÚÔÆÖеÄÎļþͻȻÏûÊÅÁË£¬ £¬£¬£¬£¬£¬ÔÆÐ§Àͻָ´µ½ÁË2023Äê4Ôµ½5ÔÂ×óÓҵĴ洢¿ìÕÕ¡£¡£¡£ÊÜÓ°ÏìÕÊ»§µÄ»î¶¯ÈÕÖ¾ÏÔʾÓû§×î½üûÓÐÈκÎÐ޸ģ¬ £¬£¬£¬£¬£¬È·Èϲ»ÊÇÓû§ÒâÍâɾ³ýÁËÊý¾Ý¡£¡£¡£×ÜÖ®£¬ £¬£¬£¬£¬£¬Ã»Óм£ÏóÅú×¢ÊÇÓû§ÍÉ»¯£¬ £¬£¬£¬£¬£¬¶øÊÇЧÀÍϵͳ³öÁËÎÊÌ⣬ £¬£¬£¬£¬£¬µ¼ÖÂÍâµØ×°±¸ºÍGoogle CloudÖ®¼äµÄÊý¾ÝÎÞ·¨Í¬²½¡£¡£¡£Ò»Ð©Óû§µÄÀëÏß»º´æÖпÉÄܰüÀ¨É¥Ê§µÄÊý¾Ý£¬ £¬£¬£¬£¬£¬µ«ÏÖÔÚ»¹Ã»ÓÐÒªÁìÀ´»Ö¸´¶ÔÆäÖÐÊý¾ÝµÄ»á¼û¡£¡£¡£GoogleÒѾ­ÔÚÊÓ²ìÕâ¸öÎÊÌ⣬ £¬£¬£¬£¬£¬ÉÐδÌṩÐÞ¸´µÄÔ¤¼ÆÊ±¼ä£¬ £¬£¬£¬£¬£¬½¨ÒéÓû§ÔÚÎÊÌâ»ñµÃ½â¾ö֮ǰ²»Òª¶Ôroot/dataÎļþ¼Ð¾ÙÐиü¸Ä¡£¡£¡£


https://www.bleepingcomputer.com/news/google/google-drive-users-angry-over-losing-months-of-stored-data/


2¡¢TransUnionºÍExperianÒÉËÆÔâµ½¹¥»÷²¢±»ÀÕË÷6ÍòÍòÃÀÔª


11ÔÂ23ÈÕ±¨µÀ³Æ£¬ £¬£¬£¬£¬£¬ÄÏ·Ç×î´óµÄÁ½¼ÒÏûºÄÕßÐÅÓñ¨¸æ»ú¹¹TransUnionºÍExperianÒÉËÆÔâµ½ÍøÂç¹¥»÷£¬ £¬£¬£¬£¬£¬Óû§µÄ²ÆÎñºÍСÎÒ˽¼ÒÊý¾ÝÃæÁÙΣº¦¡£¡£¡£N4ughtySecTUÍÅ»ï´ËÇ°Ôø¹¥»÷¹ýTransUnion£¬ £¬£¬£¬£¬£¬Õâ´ÎÔÙ´ÎÈÆ¹ýÁ˸ù«Ë¾µÄ·À»ðǽºÍÇ徲ϵͳ£¬ £¬£¬£¬£¬£¬ÀÖ³ÉÇÔÈ¡ÁËÊý¾Ý¡£¡£¡£¹¥»÷ÕßÏòTransUnionÀÕË÷3000ÍòÃÀÔª£¬ £¬£¬£¬£¬£¬²¢ÏòExperianÀÕË÷3000ÍòÃÀÔª¡£¡£¡£TransUnionºÍExperian͸¶ÒÑÊÕµ½ÀÕË÷ÒªÇó£¬ £¬£¬£¬£¬£¬µ«ÌåÏÖûÓз¢Ã÷Êý¾Ýй¶¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÉÐδÌṩ¹ØÓÚ¹¥»÷»î¶¯ºÍÊý¾Ýй¶µÄÖ¤¾Ý¡£¡£¡£


https://www.businesslive.co.za/bd/national/2023-11-23-hackers-demand-60m-from-transunion-and-experian-claiming-data-theft/


3¡¢DEXƽ̨KyberSwapÔâµ½¹¥»÷Ëðʧ¸ß´ï5470ÍòÃÀÔª


¾Ý11ÔÂ27ÈÕ±¨µÀ£¬ £¬£¬£¬£¬£¬DEXƽ̨KyberSwap͸¶ÆäÔâµ½¹¥»÷£¬ £¬£¬£¬£¬£¬¼ÛÖµÔ¼5400ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò±»µÁ¡£¡£¡£¹¥»÷±¬·¢ÔÚÉÏÖÜÈýÍí¼ä£¬ £¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýһϵÁÐÖØ´óµÄÐж¯½«Óû§µÄ×ʽðÌáÈ¡µ½¹¥»÷ÕßµÄÇ®°üÖС£¡£¡£¶Ô´Ë£¬ £¬£¬£¬£¬£¬¸Ãƽ̨ÔÝÍ£ÁË´æ¿î£¬ £¬£¬£¬£¬£¬Õö¿ªÁËÊӲ죬 £¬£¬£¬£¬£¬ÁªÏµÁËÏà¹Ø¸÷·½£¬ £¬£¬£¬£¬£¬²¢Óë¹¥»÷ÕßÕö¿ªÌ¸ÅÐÀ´¾¡¿ÉÄÜ×·»ØËðʧ£¬ £¬£¬£¬£¬£¬°üÀ¨Ìṩ10%µÄÉͽð×÷Ϊ·µ»¹±»µÁ×ʽðµÄ½±Àø¡£¡£¡£¶à¼ÒÇø¿éÁ´Çå¾²¹«Ë¾ºÍÑо¿Ö°Ô±³Æ£¬ £¬£¬£¬£¬£¬´Ë´Î¹¥»÷»î¶¯ºÜÊÇÖØ´ó¡£¡£¡£


https://therecord.media/kyberswap-crypto-platform-54-million-hack


4¡¢IT¹«Ë¾AppscookÉèÖùýʧй¶Êý°ÙËùѧУµÄѧÉúÐÅÏ¢


ýÌå11ÔÂ24Èճƣ¬ £¬£¬£¬£¬£¬IT¹«Ë¾AppscookÓÉÓÚϵͳÉèÖùýʧ£¬ £¬£¬£¬£¬£¬Ð¹Â¶ÁË´ó×Úδ³ÉÄêÈ˵ÄÊý¾Ý¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬ £¬£¬£¬£¬£¬¿ª·ÅµÄDigitalOcean´æ´¢Í°°üÀ¨½üÒ»°ÙÍò¸öÃô¸ÐÎļþ£¬ £¬£¬£¬£¬£¬É漰ѧÉúºÍ¼Ò³¤ÐÕÃû¡¢ÕÕÆ¬¡¢³öÉú֤ʵºÍ¼ÒͥסַµÈ¡£¡£¡£¸Ã¹«Ë¾¿ª·¢µÄÓ¦ÓóÌÐò±»Ó¡¶ÈºÍ˹ÀïÀ¼¿¨µÄ600¶àËùѧУÓÃÓÚ½ÌÓýÖÎÀí£¬ £¬£¬£¬£¬£¬Æä¹ÙÍø³ÆÁè¼Ý50ÍòѧÉúºÍ100Íò¼Ò³¤Ê¹ÓÃ¸ÃÆ½Ì¨¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÒÑÁªÏµÁËAppscook£¬ £¬£¬£¬£¬£¬µ«ÉÐδÊÕµ½»Ø¸´¡£¡£¡£


https://securityaffairs.com/154743/security/app-used-by-hundreds-of-schools-leaking-childrens-data.html


5¡¢AhnLabÅû¶AndarielʹÓÃÎó²îCVE-2023-46604µÄÏêÇé


11ÔÂ27ÈÕ£¬ £¬£¬£¬£¬£¬AhnLabÔÚ¼à¿ØAndarielÍÅ»ï½üÆÚµÄ¹¥»÷ʱ£¬ £¬£¬£¬£¬£¬·¢Ã÷ÆäʹÓÃApache ActiveMQÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-46604£©×°ÖöñÒâÈí¼þ¡£¡£¡£AhnLab·¢Ã÷ij¸öϵͳÖб»×°ÖÃÁËAndarielÒÑÍùһֱʹÓõĺóÃÅNukeSped¡£¡£¡£ÊÓ²ìÏÔʾ£¬ £¬£¬£¬£¬£¬¸ÃϵͳÖÐ×°ÖÃÁËApache ActiveMQЧÀÍÆ÷£¬ £¬£¬£¬£¬£¬²¢È·ÈÏÆäÖб£´æ×Ô¸ÃÎó²îÐÅÏ¢Ðû²¼ÒÔÀ´µÄÖÖÖÖ¹¥»÷µÄÈÕÖ¾£¬ £¬£¬£¬£¬£¬°üÀ¨Éæ¼°HelloKittyÀÕË÷Èí¼þµÄ¹¥»÷ÈÕÖ¾¡£¡£¡£ÏÖÔÚ»¹Ã»ÓÐÖ±½ÓÈÕÖ¾£¬ £¬£¬£¬£¬£¬µ«Ñо¿Ö°Ô±ÍƲâAndarielÕýÔÚʹÓøÃÎó²îÀ´×°ÖÃNukeSpedºÍTigerRatºóÃÅ¡£¡£¡£


https://asec.ahnlab.com/en/59318/


6¡¢IBMÐû²¼¹ØÓÚWailingCrab¼°ÆäC2ͨѶµÄÆÊÎö±¨¸æ


11ÔÂ23ÈÕ±¨µÀ£¬ £¬£¬£¬£¬£¬IBMÐû²¼±¨¸æ¸ÅÊöÁËWailingCrab¼°ÆäC2ͨѶ£¬ £¬£¬£¬£¬£¬ÖصãÏÈÈÝÁËÆä¶ÔMQTTЭÒéµÄʹÓᣡ£¡£¹¥»÷Á´Ê¼ÓÚ°üÀ¨PDF¸½¼þµÄÓʼþ£¬ £¬£¬£¬£¬£¬Ê¹ÓÃÁËÓâÆÚ½»»õºÍÔËÊ䷢ƱµÈÖ÷Ìâ¡£¡£¡£ÆäÖаüÀ¨¶ñÒâURL£¬ £¬£¬£¬£¬£¬µã»÷¾Í»áÏÂÔØÒ»¸öJavaScriptÎļþ£¬ £¬£¬£¬£¬£¬¸ÃÎļþ¼ìË÷²¢Æô¶¯DiscordÉÏÍйܵÄWailingCrab¼ÓÔØ³ÌÐò¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬×Ô2023ÄêÖÐÆÚÒÔÀ´£¬ £¬£¬£¬£¬£¬WailingCrabºóÃÅ×é¼þºÍC2Ö®¼äµÄͨѶÊÇʹÓÃMQTTЭÒéÖ´ÐеÄ£¬ £¬£¬£¬£¬£¬¸ÃЭÒéÊÇÒ»ÖÖÇáÁ¿¼¶IoTÐÂÎÅת´ïЭÒé¡£¡£¡£


https://thehackernews.com/2023/11/alert-new-wailingcrab-malware-loader.html