GoogleÒò¼Óº¦ÒþÖÔÔÞ³ÉÏòÒÁÀûŵÒÁÖݵĹ«ÃñÖ§¸¶1ÒÚÃÀÔª

°ä²¼¹¦·ò 2022-06-09
1¡¢GoogleÒò¼Óº¦ÒþÖÔÔÞ³ÉÏòÒÁÀûŵÒÁÖݵĹ«ÃñÖ§¸¶1ÒÚÃÀÔª


¾ÝýÌå6ÔÂ6Èճƣ¬ £¬£¬ £¬£¬£¬GoogleÃæ¶Ô×ÅÃÀ¹úÒÁÀûŵÒÁÖݵĹ«ÃñµÄ¼¯ÌåËßËÏ£¬ £¬£¬ £¬£¬£¬Æä±»Ö¸¿ØÎ´¾­ÔÞ³ÉÍøÂçºÍ´æ´¢Ó×ÎÒÉúÎïÌØµã¡£¡£¡£¡£¡£¡£¡£ÕâÎ¥·´ÁËÒÁÀûŵÒÁÖݵÄÉúÎï¼ø±ðÐÅÏ¢ÒþÖÔ·¨(BIPA)£¬ £¬£¬ £¬£¬£¬×îÖչȸèÔÞ³ÉÖ§¸¶1ÒÚÃÀÔª½øÐÐÅâ³¥¡£¡£¡£¡£¡£¡£¡£ËùÓÐÒÁÀûŵÒÁÖݾÓÃñ£¬ £¬£¬ £¬£¬£¬Ö»ÓÐÔÚ2015Äê5ÔÂ1ÈÕÖÁ2022Äê4ÔÂ25ÈÕÄڳʴ˿ÌGoogleÕÕÆ¬ÖУ¬ £¬£¬ £¬£¬£¬¶¼ÓÐ×ʸñÉêÇëÅ⸶£¬ £¬£¬ £¬£¬£¬Ô¤¼ÆÃ¿È˽«µÃµ½200-400ÃÀÔª¡£¡£¡£¡£¡£¡£¡£FacebookÒ²Ãæ¶Ô¹ýÀàËÆµÄ¼¯ÌåËßËÏ£¬ £¬£¬ £¬£¬£¬²¢ÔÞ³ÉÏòÒÁÀûŵÒÁÖݵĹ«ÃñÖ§¸¶6.5ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£


https://www.engadget.com/google-photos-bipa-lawsuit-settlement-161237789.html


2¡¢ÃÀ¹ú·¨Âɲ¿ÃÅÒѲé·âÏúÊÛ¹«ÃñÉí·ÝÐÅÏ¢µÄ°µÍøÊг¡SSNDOB


6ÔÂ7ÈÕ±¨Â·£¬ £¬£¬ £¬£¬£¬ÃÀ¹ú˾·¨²¿¡¢¹ú˰¾ÖºÍÁª¹úµ÷²é¾Ö½áºÏÐж¯£¬ £¬£¬ £¬£¬£¬¹Ø¹ØÁËÒ»¸öÊ¢ÐеİµÍøÊг¡SSNDOB¡£¡£¡£¡£¡£¡£¡£¸ÃÍøÕ¾ÒÑÏúÊÛÁËÔ¼2400ÍòÈ˵ÄÐÅÏ¢£¬ £¬£¬ £¬£¬£¬²¢»ñÀû³¬¹ý1900ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£SSNDOBÊг¡Óɶà¸öÍøÕ¾×é³É£¬ £¬£¬ £¬£¬£¬ÕâÐ©ÍøÕ¾³äÈα˴˵ľµÏñ£¬ £¬£¬ £¬£¬£¬ÒÔÕмÜDDoS¹¥»÷»ò·¨ÂÉÐж¯¡£¡£¡£¡£¡£¡£¡£ÃÀ¹úµ±¾ÖÔÚÈûÆÖ·˹ºÍÀ­ÍÑάÑǵÄЭÖúÏ£¬ £¬£¬ £¬£¬£¬²é·âÁËSSNDOBµÄ4¸öÓòÃû¡°ssndob.ws¡±¡¢¡°ssndob.vip¡±¡¢¡°ssndob.club¡±ºÍ¡°blackjob.biz¡±¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬ £¬£¬ £¬£¬£¬Chainalysis·¢ÏÖSSNDOBÓëJoker's StashÖ®¼ä´æÔÚÁªÏµ£¬ £¬£¬ £¬£¬£¬ºóÕßÓÚ2021Äê1Ô¹عØ¡£¡£¡£¡£¡£¡£¡£


https://therecord.media/doj-fbi-shut-down-marketplace-for-stolen-social-security-numbers/


3¡¢ÐÂSVCReadyͨ¹ý°µ²ØÔÚÎĵµÊôÐÔÖеÄshellcode·Ö·¢  


6ÔÂ6ÈÕ£¬ £¬£¬ £¬£¬£¬»ÝÆÕÔÚһƪ¼¼ÊõÎÄÕÂÖй«¿ªÁËеĶñÒâÈí¼þSVCReady¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÈÔ´¦ÓÚÔçÆÚ¿ª·¢½×¶Î£¬ £¬£¬ £¬£¬£¬¿ª·¢ÕßÔÚÉϸöÔ½øÐÐÁËÂŴεü´úÀ´¸üжñÒâÈí¼þ£¬ £¬£¬ £¬£¬£¬Æä×î³õµÄ»î¶¯¼£ÏóÄܹ»×·Òäµ½2022Äê4ÔÂ22ÈÕ¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯ÀûÓÃÁËÔ̺¬VBAºêµÄWordÎĵµ×°ÖöñÒâpayload¡£¡£¡£¡£¡£¡£¡£µ«ËüµÄ·ÖÆçÖ®´¦ÔÚÓÚ£¬ £¬£¬ £¬£¬£¬¸ÃºêûÓÐʹÓÃPowerShell»òMSHTA´ÓÔ¶³Ì·þÎñÆ÷¼ìË÷ÏÂÒ»½×¶ÎµÄ¿ÉÖ´ÐÐÎļþ£¬ £¬£¬ £¬£¬£¬¶øÊÇÔËÐд洢ÔÚÎĵµÊôÐÔÖеÄshellcode£¬ £¬£¬ £¬£¬£¬¶øºó×°ÖöñÒâÈí¼þSVCReady¡£¡£¡£¡£¡£¡£¡£¾Ý·ÖÎö£¬ £¬£¬ £¬£¬£¬SVCReady¿ÉÄÜÓëTA551ÓйØÁª¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/06/researchers-warn-of-spam-campaign.html


4¡¢Google°ä²¼6Ô·ÝAndroid°²È«¸üУ¬ £¬£¬ £¬£¬£¬½¨¸´41¸ö·ì϶


¾Ý6ÔÂ7ÈÕ±¨Â·£¬ £¬£¬ £¬£¬£¬Google°ä²¼ÁË6Ô·ݵÄAndroid°²È«¸üУ¬ £¬£¬ £¬£¬£¬×ܼƽ¨¸´41¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£¸Ã¸üзÖΪÁ½¸ö²¿ÃÅ£¬ £¬£¬ £¬£¬£¬±ðÀëÓÚ6ÔÂ1ÈÕºÍ5ÈÕ°ä²¼£¬ £¬£¬ £¬£¬£¬µÚÒ»¸öÔ̺¬AndroidϵͳºÍ¿ò¼Ü×é¼þµÄ²¹¶¡£¬ £¬£¬ £¬£¬£¬µÚ¶þ¸öÔ̺¬Äں˺͵ÚÈý·½¹©¸øÉ̹ØÔ´×é¼þµÄ¸üС£¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ×îÑϳÁµÄÊÇϵͳ×é¼þÖеÄÒ»¸öRCE·ì϶£¨CVE-2022-20210£©£¬ £¬£¬ £¬£¬£¬ÎÞÐè¶î±íÖ´ÐÐȨÏÞ¼´¿ÉÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬ £¬£¬ £¬£¬£¬»¹½¨¸´ÁË2¸öÌáȨ·ì϶£¨CVE-2022-20140ºÍCVE-2022-20145£©£¬ £¬£¬ £¬£¬£¬ÒÔ¼°UnisocоƬÖеķì϶£¨CVE-2022-20210£©µÈ¡£¡£¡£¡£¡£¡£¡£


https://www.infosecurity-magazine.com/news/google-android-security-patches/


5¡¢EmotetµÄÐÂÄ£¿£¿£¿£¿£¿é¿ÉÇÔÈ¡´æ´¢ÔÚChromeÖеÄÐÅÓþ¿¨ÐÅÏ¢


ýÌå6ÔÂ8ÈÕ±¨Â·£¬ £¬£¬ £¬£¬£¬×êÑÐÈËÔ±·¢ÏÖ½©Ê¬ÍøÂçEmotetÔÚʹÓÃÒ»¸öеÄÄ£¿£¿£¿£¿£¿é£¬ £¬£¬ £¬£¬£¬À´ÇÔÈ¡´æ´¢ÔÚChromeÓû§ÅäÖÃÎļþÖеÄÐÅÓþ¿¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Ëü»áÍøÂçÐÕÃû¡¢ÐÅÓþ¿¨µ½ÆÚÄêÔºͿ¨ºÅµÈÐÅÏ¢£¬ £¬£¬ £¬£¬£¬¶øºó»á½«ÕâЩÐÅÏ¢·¢Ë͵½C2·þÎñÆ÷£¬ £¬£¬ £¬£¬£¬¶ø²»ÊǸÃÐÅÏ¢ÇÔȡģ¿£¿£¿£¿£¿éËùʹÓõķþÎñÆ÷¡£¡£¡£¡£¡£¡£¡£EmotetÓÚ2014ÄêÆðÍ·»îÔ¾£¬ £¬£¬ £¬£¬£¬ÔÚ2021ËêÊ×µÄÒ»´Î¹ú¼Ê·¨ÂÉÐж¯Öб»²ð³ý¡£¡£¡£¡£¡£¡£¡£ESETÔÚ±¾Öܶþй©£¬ £¬£¬ £¬£¬£¬×Ô½ñÄêËêÊ×ÒÔÀ´£¬ £¬£¬ £¬£¬£¬EmotetµÄ»î¶¯´ó·ùÔö³¤£¬ £¬£¬ £¬£¬£¬±ÈT3 2021Ôö³¤ÁË100±¶ÒÔÉÏ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/emotet-malware-now-steals-credit-cards-from-google-chrome-users/


6¡¢KELA°ä²¼2022ÄêµÚÒ»¼¾¶ÈÀÕË÷Èí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨


6ÔÂ2ÈÕ£¬ £¬£¬ £¬£¬£¬ÒÔÉ«Áа²È«¹«Ë¾KELA°ä²¼ÁË2022ÄêµÚÒ»¼¾¶ÈÀÕË÷Èí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬ £¬£¬ £¬£¬£¬2022ÄêQ1£¬ £¬£¬ £¬£¬£¬ÀÕË÷Èí¼þ±»¹¥»÷Ö¸±êµÄ×ÜÊý½µÂäÁË40%£¬ £¬£¬ £¬£¬£¬´Ó2021ÄêQ4µÄ982¸ö½µÖÁ698¸ö¡£¡£¡£¡£¡£¡£¡£LockBitÈ¡´úConti³ÉΪ2022ËêÊ×ÒÔÀ´×î»îÔ¾µÄÍŻ £¬£¬ £¬£¬£¬¹¥»÷ÁË226¸öÖ¸±ê£¬ £¬£¬ £¬£¬£¬Õ¼±ÈΪ32%£¬ £¬£¬ £¬£¬£¬Æä´ÎÊÇConti£¨18%£©¡¢Alphv£¨8%£©¡¢Hive£¨6%£©ºÍKarakurt£¨5%£©¡£¡£¡£¡£¡£¡£¡£ÃÀ¹úÊÇÔâµ½¹¥»÷×î¶àµÄ¹ú¶È£¨40%£©£¬ £¬£¬ £¬£¬£¬Ö®ºóÊÇÓ¢¹ú¡¢Òâ´óÀû¡¢µÂ¹úºÍ¼ÓÄô󡣡£¡£¡£¡£¡£¡£


https://ke-la.com/wp-content/uploads/2022/06/KELA-RESEARCH-RANSOMWARE-VICTIMS-AND-NETWORK-ACCESS-SALES-IN-Q1-2022.pdf