TikTokÒòÎ¥·´Ó¢¹úµÄÊý¾Ý±£»£»£»£»£»¤·¨±»·£¿£¿£¿£¿£¿£¿£¿î1270ÍòÓ¢°÷

°ä²¼¹¦·ò 2023-04-06

1¡¢TikTokÒòÎ¥·´Ó¢¹úµÄÊý¾Ý±£»£»£»£»£»¤·¨±»·£¿£¿£¿£¿£¿£¿£¿î1270ÍòÓ¢°÷


¾ÝýÌå4ÔÂ4ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬TikTokÒòÂÅ´ÎÎ¥·´Êý¾Ý±£»£»£»£»£»¤·¨£¬£¬£¬£¬£¬ £¬±»Ó¢¹úÐÅϢרԱ°ì¹«ÊÒ(ICO)·£¿£¿£¿£¿£¿£¿£¿î1270ÍòÓ¢°÷£¨ºÏ1575ÍòÃÀÔª£©µÄ·£¿£¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£ ¡£¡£¡£TikTokδÄܾÍ13ËêÒÔ϶ùͯʹÓÃÆäÆ½Ì¨»ñµÃ¸¸Ä¸µÄÔ޳ɣ¬£¬£¬£¬£¬ £¬Ò²Ã»ÓнøÐгä·ÖµÄ²é³­ÒÔ¼ø±ðºÍÔ¤·Àδ³ÉÄê¶ùͯʹÓÃÉ罻ýÌåÀûÓᣡ£¡£¡£ ¡£¡£¡£¸Ã»ú¹¹°µÊ¾£¬£¬£¬£¬£¬ £¬Ó¦¶Ô´ëÊ©µÄ²»¼°µ¼ÖÂÔ¼100Íò13ËêÒÔ϶ùͯ²»±¾µØ½Ó¼û¸Ãƽ̨£¬£¬£¬£¬£¬ £¬TikTokÍøÂ粢ʹÓÃÁËËûÃǵÄÓ×ÎÒÊý¾Ý¡£¡£¡£¡£ ¡£¡£¡£ÕâÒ»·£¿£¿£¿£¿£¿£¿£¿î±ÈICOÔÚ2022Äê9Ô·¢³öµÄ¶ÔTikTok·£¿£¿£¿£¿£¿£¿£¿î2700ÍòÓ¢°÷µÄԭʼÒâÏò֪ͨÓÐËùÏ÷¼õ¡£¡£¡£¡£ ¡£¡£¡£


https://www.infosecurity-magazine.com/news/tiktok-fined-12m-uk-data-privacy/


2¡¢UnitedLexÔâµ½d0nutÀÕË÷¹¥»÷³¬¹ý200GBÊý¾Ýй¶


¾Ý4ÔÂ4ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬UnitedLex¹«Ë¾Ôâµ½ÁËd0nutµÄÀÕË÷¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£d0nutÐû³Æ£¬£¬£¬£¬£¬ £¬ËûÃÇÒÑ´ÓUnitedLexµÄϵͳÏÂÔØÁ˳¬¹ý200GBµÄÊý¾Ý£¬£¬£¬£¬£¬ £¬Ô̺¬Éæ¼°¸¶¿î¡¢ºÏͬºÍÆäËûÓë¶à¶à×éÖ¯ºÍÓ×ÎÒÓйصĻúÃÜÎļþ¡£¡£¡£¡£ ¡£¡£¡£UnitedLex°µÊ¾½üÆÚÔÚϵͳÉÏ·¢ÏÖÁË¿ÉÒɻ£¬£¬£¬£¬£¬ £¬ÔÚÈ·¶¨»î¶¯µÄÐÔÖʺÍÁìÓò¡£¡£¡£¡£ ¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬ £¬d0nutÔøÒªÇó500ÍòÃÀÔªµÄÊê½ð£¬£¬£¬£¬£¬ £¬ÕâÓë½»ÉæÖÐÌáµ½µÄ60ÍòÃÀÔªµÄÒªÇóÏÔÖø·ÖÆç¡£¡£¡£¡£ ¡£¡£¡£UnitedLexÒѱ»Ôö³¤µ½ÁËBlackCatµÄÍøÕ¾£¬£¬£¬£¬£¬ £¬×êÑÐÈËÔ¹ØýÊÔͼȷ¶¨ÕâЩÊÇ·ñÓëD0nut Leaksй¶µÄÊý¾ÝÒ»Ñù¡£¡£¡£¡£ ¡£¡£¡£


https://www.databreaches.net/unitedlex-hit-by-d0nut-ransomware-team-200-gb-of-corporate-files-leaked/


3¡¢»ÝÆÕÔ¤¼Æ90ÌìÄÚ½¨¸´LaserJet´òÓ¡»úÖзì϶CVE-2023-1707


ýÌå4ÔÂ4Èճƣ¬£¬£¬£¬£¬ £¬»ÝÆÕÔ¤¼ÆÓÚ90ÌìÄÚ½¨Ó°ÏìijЩóÒ×¼¶´òÓ¡»ú¹Ì¼þµÄ·ì϶¡£¡£¡£¡£ ¡£¡£¡£·ì϶׷×ÙΪCVE-2023-1707£¬£¬£¬£¬£¬ £¬¿ÉÄܻᵼÖÂÐÅϢй¶£¬£¬£¬£¬£¬ £¬Ó°ÏìÁËÔ¼50ÖÖHP Enterprise LaserJetºÍHP LaserJet Managed PrintersÐͺÅ¡£¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾Ö¸³ö£¬£¬£¬£¬£¬ £¬ÓÉÓÚÒ×Êܹ¥»÷µÄÉ豸±ØÒªÔËÐÐFutureSmart¹Ì¼þ°æ±¾5.6²¢ÆôÓÃIPsec£¬£¬£¬£¬£¬ £¬Òò¶øÀûÓû·¾³ÊÇÊÜÏ޵ġ£¡£¡£¡£ ¡£¡£¡£»£»£»£»£»ÝÆÕ°µÊ¾£¬£¬£¬£¬£¬ £¬¹Ì¼þ¸üн«ÔÚ90ÌìÄÚ°ä²¼£¬£¬£¬£¬£¬ £¬Òò¶øÄ¿Ç°Ã»ÓпÉÓõĽ¨¸´·¨Ê½¡£¡£¡£¡£ ¡£¡£¡£¶ÔÓÚÔËÐÐFutureSmart 5.6µÄÓû§£¬£¬£¬£¬£¬ £¬½¨ÒéµÄ»º½â´ëÊ©Êǽ«Æä¹Ì¼þ°æ±¾½µ¼¶µ½FS 5.5.0.3¡£¡£¡£¡£ ¡£¡£¡£»£»£»£»£»ÝÆÕ³Æ¸Ã·ì϶ÉÐδ±»ÀûÓ㬣¬£¬£¬£¬ £¬ÇÒ¶³öÆÚºÜ¶Ì£¨2023Äê2ÔÂÖÐÑ®ÖÁ3Ôµף©¡£¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hp-to-patch-critical-bug-in-laserjet-printers-within-90-days/


4¡¢IRSÊÚȨµÄ±¨Ë°Èí¼þeFile.com±»·¢ÏÖ·Ö·¢JS¶ñÒâÈí¼þ


4ÔÂ4ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬ £¬ÃÀ¹ú¹ú˰¾Ö£¨IRS£©ÊÚȨµÄ±¨Ë°Èí¼þeFile.com±»·¢ÏÖ·Ö·¢JavaScript¶ñÒâÈí¼þ¡£¡£¡£¡£ ¡£¡£¡£ÓÐÎÊÌâµÄ¶ñÒâJavaScriptÎļþÊÇpopper.js£¬£¬£¬£¬£¬ £¬ÖÁÉÙÔÚ4ÔÂ1ÈÕ֮ǰeFile.comµÄÏÕЩÿ¸öÒ³Ãæ¶¼ÔÚ¼ÓÔØ¶ñÒâÎļþ¡£¡£¡£¡£ ¡£¡£¡£3ÔÂ17ÈÕ£¬£¬£¬£¬£¬ £¬RedditÓû§·¢ÌûÒÉ»óeFile.comÍøÕ¾±»½Ù³Ö¡£¡£¡£¡£ ¡£¡£¡£Æäʱ£¬£¬£¬£¬£¬ £¬ÍøÕ¾ÏÔʾÁËÒ»ÌõSSLÃýÎóÐÂÎÅ£¬£¬£¬£¬£¬ £¬ÅúʾËûÃÇÏÂÔØÐéαµÄä¯ÀÀÆ÷¸üÐÂÒÔÕýÈ·½Ó¼û¸Ã·þÎñ¡£¡£¡£¡£ ¡£¡£¡£¸Ã¹¥»÷Éæ¼°Á½¸öÖØÒªµÄ¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬ £¬update.exe×÷ΪÓëC2·þÎñÆ÷ͨѶµÄPHP¾ç±¾µÄÏÂÔØ·¨Ê½£¬£¬£¬£¬£¬ £¬PHP¾ç±¾ÏÂÔØ²¢Ö´Ðжî±íµÄ´úÂë¡£¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/irs-authorized-efilecom-tax-return-software-caught-serving-js-malware/


5¡¢Google°ä²¼2023Äê4ÔµÄAndroid°²È«¸üн¨¸´ÊýÊ®¸ö·ì϶


ýÌå4ÔÂ5ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬Google°ä²¼2023Äê4ÔµÄAndroid°²È«¸üС£¡£¡£¡£ ¡£¡£¡£Õâ´Î¸üзÖΪÁ½²¿ÃÅ£¬£¬£¬£¬£¬ £¬2023-04-01¼¶±ð²¹¶¡½¨¸´ÁË¿ò¼ÜºÍϵͳ×é¼þÖеÄ26¸ö·ì϶£¬£¬£¬£¬£¬ £¬ÆäÖдóÎÞÊýÊǵ¼ÖÂȨÏÞÌáÉý»òÐÅϢй¶µÄ·ì϶£»£»£»£»£»2023-04-05¼¶±ð²¹¶¡½¨¸´ÁËÄںˡ¢Arm¡¢Imagination Technologies¡¢MediaTek¡¢UnisocºÍQualcomm×é¼þÖеÄ40¸ö·ì϶¡£¡£¡£¡£ ¡£¡£¡£ÆäÖнÏΪÑϳÁµÄÊÇSystemÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-21085ºÍCVE-2023-21096£©¡£¡£¡£¡£ ¡£¡£¡£


https://www.securityweek.com/androids-april-2023-updates-patch-critical-remote-code-execution-vulnerabilities/


6¡¢MantisÀûÓÃMicropsiaºÍArid GopherбäÌå¹¥»÷Öж«µØÓò


4ÔÂ4ÈÕ£¬£¬£¬£¬£¬ £¬SymantecÅû¶ÁËMantisÓÃÓÚ¹¥»÷Öж«µØÓòµÄй¤¾ß¡£¡£¡£¡£ ¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖÁ˸ÃÍÅ»ï×î½üÒ»´Î»î¶¯£¬£¬£¬£¬£¬ £¬´Ó2022Äê9ÔÂÆðÍ·£¬£¬£¬£¬£¬ £¬ÖÁÉÙ³ÖÐøµ½2023Äê2Ô¡£¡£¡£¡£ ¡£¡£¡£Õâ´Î¹¥»÷ÖУ¬£¬£¬£¬£¬ £¬¹¥»÷ÕßʹÓÃÆä¶¨ÔìµÄMicropsiaºÍArid GopherºóÃŵÄбäÌåÀ´ÈëÇÖÖ¸±ê£¬£¬£¬£¬£¬ £¬¶øºóÔÙ½øÐÐÍ´´¦ÇÔÈ¡ºÍÊý¾Ýй¶¡£¡£¡£¡£ ¡£¡£¡£´Ë»î¶¯µÄ³õʼϰȾý½éÒÀȻδ֪¡£¡£¡£¡£ ¡£¡£¡£ÔÚÒ»¸öÖ¸±ê×éÖ¯ÖУ¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÔÚÈý×éÍÆËã»úÉÏ×°ÖÃÁËͳһ¹¤¾ßµÄÈý¸ö·ÖÆç±äÌå¡£¡£¡£¡£ ¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬¹¥»÷Õß»¹Ê¹ÓÃÁËÒ»¸ö×Ô½ç˵¹¤¾ßÀ´Ð¹Â¶´ÓÖ¸±ê×éÖ¯ÇÔÈ¡µÄÊý¾Ý£¬£¬£¬£¬£¬ £¬¼´ÃûΪWindowsUpServ.exeµÄ64λPyInstaller¿ÉÖ´ÐÐÎļþ¡£¡£¡£¡£ ¡£¡£¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/mantis-palestinian-attacks