×êÑÐÈËÔ±Åû¶AWSÖÐÀûÓÃAppSyncµÄ¿ç×â»§·ì϶µÄÏêÇé

°ä²¼¹¦·ò 2022-11-30
1¡¢×êÑÐÈËÔ±Åû¶AWSÖÐÀûÓÃAppSyncµÄ¿ç×â»§·ì϶µÄÏêÇé

¾Ý11ÔÂ28ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±Åû¶ÁËAmazon Web ServicesÖеĿç×â»§·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶»ñµÃ¶Ô×ÊԴδ¾­ÊÚȨµÄ½Ó¼û ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶Óë»ìºÏ´úÀíÎÊÌâÓйØ£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÒ»ÖÖÌáȨ·ì϶ ¡£¡£¡£¡£¡£¡£¡£ÕâÖÖ¹¥»÷ÀûÓÃÁËAppSync·þÎñÀ´³Ðµ£ÆäËûAWSÕË»§ÖеÄIAM½ÇÉ«£¬£¬£¬£¬£¬£¬£¬£¬ÕâʹµÃ¹¥»÷Õß¿ÉÄܽøÈëµ½Ö¸±ê×éÖ¯Öв¢½Ó¼ûÕâЩÕË»§ÖеÄ×ÊÔ´ ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÓÚ2022Äê9ÔÂ1Èջ㱨Á˸ÃÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬AWSÓÚ9ÔÂ6ÈÕ½¨¸´Á˸÷ì϶ ¡£¡£¡£¡£¡£¡£¡£

https://thehackernews.com/2022/11/researchers-detail-appsync-cross-tenant.html

2¡¢Checkmarx·¢ÏÖÀûÓÃTikTokÌôÕ½À´·Ö·¢¶ñÒâÈí¼þµÄ»î¶¯

CheckmarxÔÚ11ÔÂ28ÈÕ³ÆÆä·¢ÏÖÁËÀûÓÃTikTok¡°ÒþÐÎÌôÕ½¡±·Ö·¢¶ñÒâÈí¼þµÄ»î¶¯ ¡£¡£¡£¡£¡£¡£¡£¸ÃÌôÕ½ÒªÇóÓû§Ê¹ÓÃTikTokµÄ¡°Éí¶ÎÒþÐΡ±Â˾µÅÄÉãÂãÌ壬£¬£¬£¬£¬£¬£¬£¬¸ÃÂ˾µ»á´ÓÊÓÆµÖÐÒÆ³ýÉí¶Î²¿ÃŲ¢ÓÃÍÌͲ¼¾°È¡´ú ¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔì×÷ÁËTikTokÊÓÆµ£¬£¬£¬£¬£¬£¬£¬£¬Ðû³ÆÄܹ»ÌṩһÖÖÌØÊâµÄ¹ýÂËÆ÷£¬£¬£¬£¬£¬£¬£¬£¬½â³ýTikTokµÄ¡°Éí¶ÎÒþÐΡ±³ÉЧ ¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÈí¼þ»á×°ÖÃWASP Stealer£¬£¬£¬£¬£¬£¬£¬£¬Ëü¿ÉÄÜÇÔÈ¡´æ´¢ÔÚä¯ÀÀÆ÷¡¢¼ÓÃÜÇ®±ÒÇ®°üÖеÄDiscordÕÊ»§¡¢ÃÜÂëºÍÐÅÓþ¿¨£¬£¬£¬£¬£¬£¬£¬£¬ÉõÖÁÊÇÖ¸±êÍÆËã»úÖеÄÎļþ ¡£¡£¡£¡£¡£¡£¡£

https://checkmarx.com/blog/attacker-uses-a-popular-tiktok-challenge-to-lure-users-into-installing-malicious-package/

3¡¢BianLianÍÅ»ï°ä²¼´Ó¼ÓÄôóHarry RosenÇÔÈ¡µÄ1GBÊý¾Ý

¾ÝýÌå11ÔÂ25ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬¼ÓÄôóÄÐ×°Á¬ËøµêHarry RosenÔâµ½ÁËÍøÂç¹¥»÷ ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÉÐδй©¹¥»÷ÀàÐÍ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÊÇ·ñÓ°ÏìÁ˹«Ë¾µÄÔËÓª ¡£¡£¡£¡£¡£¡£¡£BianLianÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬£¬£¬£¬£¬£¬£¬£¬²¢°ä²¼ÁËÒ»¸ö1 GBµÄÎļþ×÷Ϊ¹¥»÷µÄÖ¤¾Ý£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Harry RosenµÄGold+¿Í»§ÁÐ±í¡¢ÏúÊÛÐÅÏ¢ºÍ¸÷ÀàÆäËüÀàÐ͵ÄÎļþ ¡£¡£¡£¡£¡£¡£¡£BianLianÓÚ8Ô·ݳõ´Î±»·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þÊÇÓÃGo˵»°ÎªWindowsϵͳ¿ª·¢µÄ£¬£¬£¬£¬£¬£¬£¬£¬Æä³õʼ½Ó¼û¿ÉÄÜÊÇͨ¹ýWindows ProxyShell·ì϶»òSonicWall VPN¹Ì¼þ·ì϶»ñµÃµÄ ¡£¡£¡£¡£¡£¡£¡£

https://www.itworldcanada.com/article/canadian-menswear-chain-harry-rosen-confirms-cyber-attack/515325

4¡¢¼ÙðµÄSMSÀûÓÃSymoo³äµ¹ØÊ»§´´½¨·þÎñµÄSMSÖмÌ

ýÌå11ÔÂ28Èճƣ¬£¬£¬£¬£¬£¬£¬£¬ÔÚGoogle PlayÉ̵êÖÐ100000´ÎÏÂÔØÁ¿µÄ¼ÙðAndroid SMSÀûÓ㬣¬£¬£¬£¬£¬£¬£¬°ÂÃØµØ³äÈÎMicrosoft¡¢Google¡¢Instagram¡¢TelegramºÍFacebookµÈÍøÕ¾µÄÕÊ»§´´½¨·þÎñµÄSMSÖÐ¼Ì ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬±»Ï°È¾µÄÉè±¸Ëæºó»á×÷Ϊ¡°Ðé¹¹ºÅÂ롱³ö×⣬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÔÚ´´½¨ÐÂÕË»§Ê±×ª·¢ÑéÖ¤Óû§µÄÒ»´ÎÐÔÃÜÂë ¡£¡£¡£¡£¡£¡£¡£¹ÌȻδ¾­Ö¤Êµ£¬£¬£¬£¬£¬£¬£¬£¬µ«¾ÝÐÅSymooÀûÓÃÓÃÓڽӹܺÍת·¢Ê¹ÓÃActivationPW´´½¨ÕÊ»§Ê±ÌìÉúµÄOTPÑéÖ¤Âë ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÀûÓÃÈÔÔÚGoogle PlayÉÏ¿ÉÓà ¡£¡£¡£¡£¡£¡£¡£

https://www.bleepingcomputer.com/news/security/malicious-android-app-found-powering-account-creation-service/

5¡¢Group-IB·¢ÏÖ¶àÆðÕë¶Ô2022ÄêFIFAÊÀ½ç±­µÄ´¹µö»î¶¯

11ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Group-IBй©Æä·¢ÏÖ¶àÆðÕë¶Ô¿¨Ëþ¶û2022ÄêFIFAÊÀ½ç±­ÃÅÆ±¡¢¹Ù·½ÉÌÆ·ºÍ¹¤×÷µÄÚ¿Æ­ºÍ´¹µö¹¥»÷ ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚ¿¨Ëþ¶û2022Äê¹Ù·½ÇòÃÔIDÃÅ»§ÍøÕ¾HayyaÉÏ·¢ÏÖÁË90¶à¸ö¿ÉÄÜÔâµ½ÈëÇÖµÄÕË»§£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇΪÊÀ½ç±­¹Û¶à³ÉÁ¢µÄÇ¿ÔìÐÔϵͳ£¬£¬£¬£¬£¬£¬£¬£¬Äܹ»½øÈ뿨Ëþ¶û²¢»ñµÃÃÅÆ±ºÍ½»Í¨µÈ·þÎñ ¡£¡£¡£¡£¡£¡£¡£¾Ýµ÷²é£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃRedLineºÍErbiumµÈÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ»ñµÃÁËÕâЩÕË»§µÄÃÜÂë ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬Group-IB»¹È·¶¨ÁË4ÖÖ·ÖÆçµÄÚ¿Æ­ºÍ´¹µö¹¥»÷º£³±£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°´óÁ¿¿É´ÓGoogle PlayÉ̵êÏÂÔØµÄÐéαÀûÓà ¡£¡£¡£¡£¡£¡£¡£

https://www.group-ib.com/media-center/press-releases/scammers-on-the-pitch/

6¡¢Kaspersky°ä²¼2023Äê¹ØÓÚÏû·ÑÕßµÄÍþвµÄÔ¤²â»ã±¨

11ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Kaspersky°ä²¼ÁË2023Äê¹ØÓÚÏû·ÑÕßµÄÍþвµÄÔ¤²â»ã±¨ ¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÓÎÏ·ºÍÁ÷ýÌå·þÎñ·½Ã棬£¬£¬£¬£¬£¬£¬£¬Óû§½«Ãæ¶Ô¸ü¶àµÄÓÎÏ·¶©ÔÄڲƭ¡¢ÓÎÏ·»úµÄǷȱ½«±»ÀûÓᢹ¥»÷Õß½«±ØÒªÓÎÏ·ÖеÄÐ鹹Ǯ±Ò¡¢¹¥»÷Õß»áÀûÓõȴýÒѾõÄÓÎÏ·£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Á÷ýÌåÈÔ½«Êǹ¥»÷Õßȡ֮²»¾¡µÄÊÕÈëÆðÔ´£»£»£»£» £»£»ÔÚÉ罻ýÌåºÍÔªÓîÖæ·½Ã棬£¬£¬£¬£¬£¬£¬£¬ÐµÄÉ罻ýÌ彫´øÀ´¸ü¶àµÄÒþÖÔ·çÏÕºÍÔªÓîÖæµÄ¿ª·¢´øÀ´µÄ·çÏÕ£»£»£»£» £»£»À´×ÔÉúÀí½¡È«ÀûÓ÷¨Ê½µÄÊý¾Ý½«ÓÃÓÚ¾«È·¶¨Î»µÄÉç»á¹¤³Ì¹¥»÷£»£»£»£» £»£»ÒÔ¼°£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÏß½ÌÓýƽ̨½«ÎüÒý¸ü¶à·¸×ï»î¶¯µÈ ¡£¡£¡£¡£¡£¡£¡£

https://securelist.com/consumer-threats-2023/108112/