FBI³Æ×Ô2016ÄêÒÔÀ´BEC¹¥»÷ÒÑÔì³É430ÒÚÃÀÔªµÄËðʧ
°ä²¼¹¦·ò 2022-05-06¾Ý5ÔÂ4ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬FBIµÄÊý¾ÝÏÔʾóÒ×µç×ÓÓʼþй¶(BEC)¹¥»÷Ôì³ÉµÄËðʧ½ð¶îÿÄê¶¼ÔÚÔö³¤¡£¡£¡£¡£¡£ÔÚ2019Äê7ÔÂÖÁ2021Äê12ÔÂÆÚ¼ä£¬£¬£¬£¬£¬£¬£¬£¬ÒÑÈ·¶¨µÄËðʧ½ð¶îÔö³¤ÁË65%¡£¡£¡£¡£¡£´Ó2016Äê6Ôµ½2019Äê7Ô£¬£¬£¬£¬£¬£¬£¬£¬IC3ÊÕµ½ÁË241206Æð¹úÄں͹ú¼ÊÊÂÎñµÄ»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°½ð¶î×ܼÆÎª43312749946ÃÀÔª¡£¡£¡£¡£¡£FBI°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬Æ¾¾Ý2021ÄêµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Î»ÓÚÌ©¹úºÍÏã¸ÛµÄÒøÐÐÊÇÚ²Æ×ʽðµÄÖØÒªÖ÷Õŵء£¡£¡£¡£¡£
https://therecord.media/fbi-business-email-compromise-attacks-led-to-more-than-43-billion-in-losses-since-2016/
2¡¢Windows 11¸üÐÂKB5012643Ó°Ï첿ÃÅÀûÓõÄÕý³£ÔËÐÐ
ýÌå5ÔÂ4Èճƣ¬£¬£¬£¬£¬£¬£¬£¬Î¢Èí½üÆÚ°ä²¼µÄWindows 11ÀۼƸüдæÔÚÎÊÌâ¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬×°ÖÃKB5012643ºó£¬£¬£¬£¬£¬£¬£¬£¬²¿ÃÅ.NET Framework 3.5ÀûÓ÷¨Ê½¿ÉÄÜ»á³öÏÖÎÊÌâ»òÎÞ·¨´ò¿ª¡£¡£¡£¡£¡£¸ÃÎÊÌâ½öÓ°ÏìÔËÐÐÁËWindows 11°æ±¾21H2µÄϵͳÇÒ×°ÖÃÁËKB5012643µÄÓû§¡£¡£¡£¡£¡£Î¢Èí½¨ÒéÊÜÓ°ÏìÓû§ÊÖ¶¯Ð¶ÔØÕâ¸öÓÐÎÊÌâµÄ¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÎÞ·¨Ð¶ÔØ¿ÉÔÚWindowsÖ°ÄÜÖгÁÐÂÆôÓÃ.NET Framework 3.5ºÍWindows Communication Foundation»º½â´ËÎÊÌâ¡£¡£¡£¡£¡£Î¢ÈíÔÚÔì¶©´ËÎÊÌâµÄ½â¾ö¹æ»®£¬£¬£¬£¬£¬£¬£¬£¬Ô¤¼ÆÔÚ¼´½«°ä²¼µÄ°æ±¾ÖÐÌṩ¸üС£¡£¡£¡£¡£
https://news.softpedia.com/news/microsoft-confirms-new-bug-in-windows-11-cumulative-update-kb5012643-535326.shtml
3¡¢Ó¢¹úNHSÉϰÙÃûÔ±¹¤µÄÓÊÏäÒѱ»½Ù³Ö²¢ÓÃÓÚ´¹µö»î¶¯
¾ÝýÌå5ÔÂ4ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ°ëÄêµÄ¹¦·òÀ£¬£¬£¬£¬£¬£¬£¬Ó¢¹ú¹ú¶ÈÎÀÉúϵͳ(NHS)µÄÉϰÙÃûÔ±¹¤µÄÓʼþÕÊ»§±»ÓÃÓÚÂŴδ¹µö»î¶¯¡£¡£¡£¡£¡£¹¥»÷Õß´ÓÈ¥Äê10ÔÂÆðÍ·½Ù³ÖºÏ·¨µÄNHSÓʼþÕË»§£¬£¬£¬£¬£¬£¬£¬£¬Ö±µ½2022Äê4ÔÂÈÔÔÚʹÓÃÕâЩÕË»§½øÐд¹µö¹¥»÷¡£¡£¡£¡£¡£INKY×êÑÐÈËÔ±¸ú×ÙÁËÀ´×ÔNHSÁ½¸öIPµØÖ·µÄ´¹µöÓʼþ£¬£¬£¬£¬£¬£¬£¬£¬·¢ÏÖËüÃÇÉæ¼°µ½NHSµÄ139ÃûÔ±¹¤µÄÕÊ»§£¬£¬£¬£¬£¬£¬£¬£¬×ܹ²ÓÐ1157·â´¹µöÓʼþ¡£¡£¡£¡£¡£ÔÚ´óÎÞÊýÇé¿öÖУ¬£¬£¬£¬£¬£¬£¬£¬´¹µöÓʼþ»á·¢ËÍÐéα¾¯±¨£¬£¬£¬£¬£¬£¬£¬£¬²¢»á½«Óû§³Á¶¨Ïòµ½ÇÔÈ¡MicrosoftÍ´´¦µÄ´¹µöÒ³Ãæ¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/attackers-hijack-uk-nhs-email-accounts-to-steal-microsoft-logins/
4¡¢¶íÂÞ˹ºÍ°×¶íÂÞ˹µÄ¶à¸ö¹Ù·½ÍøÕ¾Ôâµ½DDoS¹¥»÷
CrowdStrikeÔÚ5ÔÂ4Èճƣ¬£¬£¬£¬£¬£¬£¬£¬Docker¾µÏñÒѱ»ÓÃÓÚDDoS¹¥»÷¶íÂÞ˹ºÍ°×¶íÂÞ˹ȷµ±¾Ö¡¢¾ü·½ºÍýÌå»ú¹¹µÄÊ®¼¸¸öÍøÕ¾¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷»¹Éæ¼°µ½Á¢ÌÕÍðµÄ3¸öýÌåÍøÕ¾¡£¡£¡£¡£¡£×êÑÐÈËԱȷ¶¨ÁË2¸öDocker¾µÏñ¡°erikmnkl/ stoppropaganda¡±ºÍ¡°abagayev/ stop-russia¡±£¬£¬£¬£¬£¬£¬£¬£¬ËüÃÇÓÚ2022Äê2ÔÂÖÁ3Ô²¿Ê𣬣¬£¬£¬£¬£¬£¬£¬Òѱ»ÏÂÔØ³¬¹ý150000´Î¡£¡£¡£¡£¡£¾ÝÐÅ£¬£¬£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷»î¶¯ÓëÎÚ¿ËÀ¼Óйأ¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÕâЩ¾µÏñµÄÖ¸±êÁбíÓëÎÚ¿ËÀ¼UIA¹²ÏíµÄÓòÓгÁµþ¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/130901/cyber-warfare-2/docker-images-ddos-attack-russia.html
5¡¢HerokuÇ¿Ôì³ÁÖÃËùÓÐЧ»§µÄÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬²¢Î´Ú¹ÊÍÆäÖÐÔÒò
¾ÝýÌå5ÔÂ4Èճƣ¬£¬£¬£¬£¬£¬£¬£¬SalesforceµÄ×Ó¹«Ë¾HerokuÇ¿Ôì³ÁÖÃÁËËùÓÐЧ»§µÄÃÜÂë¡£¡£¡£¡£¡£¸Ã¹«Ë¾·¢Ë͸øÓû§µÄ°²È«¹«¸æÖгƣ¬£¬£¬£¬£¬£¬£¬£¬5ÔÂ4ÈÕ½«Ç¿Ôì³ÁÖÃÃÜÂëÒÔÓ¦¶ÔÉϸöԵݲȫÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬µ«ÊDz¢Î´Ú¹Ê;ßÌåÔÒò¡£¡£¡£¡£¡£²¿ÃÅÓû§·´Ó³Heroku¶Ô¹¥»÷µÄͨÃ÷¶È²»¹»£¬£¬£¬£¬£¬£¬£¬£¬¸øÆäÔì³ÉÁ˲ÂÒÉ¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ5ÔÂ5ÈÕ°ä²¼ÁË×îÐÂÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬£¬°µÊ¾Æä±»µÁµÄGitHub OAuthÁîÅÆÒѱ»ÓÃÓÚÈëÇÖÊý¾Ý¿â²¢Ð¹Â¶Óû§µÄÕË»§ºÍÃÜÂë¡£¡£¡£¡£¡£GitHubÓÚ4ÔÂ12ÈÕ·¢ÏÖÁ˸ù¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÁËÔ̺¬NPMÔÚÄÚµÄÊýÊ®¸ö×éÖ¯µÄÊý¾Ý¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/heroku-forces-user-password-resets-but-fails-to-explain-why/
6¡¢Google°ä²¼5Ô·ÝAndroid¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´¶à¸ö°²È«·ì϶
5ÔÂ5ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Google°ä²¼ÁË5Ô·ÝAndroid¸üеĵڶþ²¿ÃÅ£¬£¬£¬£¬£¬£¬£¬£¬½¨¸´Á˶à¸ö·ì϶¡£¡£¡£¡£¡£ÆäÖнÏΪÑϳÁµÄÊÇLinuxÄÚºËÖеÄÌáȨ·ì϶£¨CVE-2021-22600£©£¬£¬£¬£¬£¬£¬£¬£¬CISAÔÚ4Ô°䲼µÄ°²È«¹«¸æÖгƸ÷ì϶Õý±»»ý¼«ÀûÓᣡ£¡£¡£¡£Õâ´Î¸üл¹½¨¸´ÁËÄÚºË×é¼þÖеÄÌáȨ·ì϶£¨CVE-2022-0847¡¢CVE-2022-20009ºÍCVE-2021-22600£©ºÍ¸ßͨ×é¼þÖеģ¨CVE-2022-22057ºÍCVE-2022-22064£©µÈ¶à¸ö·ì϶¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬Google»¹°ä²¼ÁËÕë¶ÔPixelÉ豸ÖÐ11¸ö·ì϶µÄ²¹¶¡¡£¡£¡£¡£¡£
https://www.securityweek.com/androids-may-2022-security-updates-patch-36-vulnerabilities


¾©¹«Íø°²±¸11010802024551ºÅ