΢ÈíAI²¿ÃÅ×êÑÐÈËÔ±Òâ±íй¶38 TB˽ԿºÍÃÜÂëµÈÊý¾Ý

°ä²¼¹¦·ò 2023-09-19

1¡¢Î¢ÈíAI²¿ÃÅ×êÑÐÈËÔ±Òâ±íй¶38 TB˽ԿºÍÃÜÂëµÈÊý¾Ý


¾Ý9ÔÂ18ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬£¬£¬°²È«¹«Ë¾Wiz·¢ÏÖ£¬£¬£¬£¬£¬ £¬£¬£¬Î¢ÈíAI×êÑв¿ÃÅÔÚÏò¹«¹²GitHub´æ´¢¿â¹±Ï׿ªÔ´ÈËΪÖÇÄܽø½¨Ä£ÐÍʱÒâ±íй¶ÁË38 TBµÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬Î¢Èí·þÎñµÄÃÜÂë¡¢ÃÜÔ¿ÒÔ¼°À´×Ô359Ãû΢ÈíÔ±¹¤µÄ30000¶àÌõÄÚ²¿TeamsÐÂÎŵĴ浵¡£¡£¡£¡£¡£¡£Î¢Èí½«Êý¾Ýй¶ÓëʹÓùýÓÚ¿íËɵĹ²Ïí½Ó¼ûÊðÃû£¨SAS£©ÁîÅÆÁªÏµÆðÀ´£¬£¬£¬£¬£¬ £¬£¬£¬¸ÃÁîÅÆ¿É¶Ô¹²ÏíÎļþ½øÐÐÆëÈ«½ÚÔì¡£¡£¡£¡£¡£¡£Êý¾Ý×Ô2020Äê7ÔÂÆðͷй¶£¬£¬£¬£¬£¬ £¬£¬£¬ÓÚ½ñÄê6ÔÂ24ÈÕ½â¾ö¡£¡£¡£¡£¡£¡£

 

https://securityaffairs.com/151004/data-breach/microsoft-ai-data-leak.html


2¡¢Trygg-Hansaй¶65Íò¿Í»§ÐÅÏ¢±»Èðµä· £¿£¿£¿£¿£¿£¿£¿î3500Íò¿ËÀÊ


¾ÝýÌå9ÔÂ17ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬£¬£¬±£ÏÕ¹«Ë¾Trygg-HansaÒòй¶650000Ãû¿Í»§µÄÐÅÏ¢£¬£¬£¬£¬£¬ £¬£¬£¬±»ÈðµäÒþÖÔ±£»£»£»£»£»£»£» £»¤¾Ö£¨IMY£©´¦ÒÔ3500ÍòÈðµä¿ËÀʵÄÐÐÕþ´¦· £¿£¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£IMYµÄÉó²éÏÔʾ£¬£¬£¬£¬£¬ £¬£¬£¬2018Äê10ÔÂÖÁ2021Äê2ÔÂÆÚ¼ä¿É½Ó¼û65ÍòÃû¿Í»§µÄÊý¾Ý£¬£¬£¬£¬£¬ £¬£¬£¬ÆäÖгýÁ˽¡È«Êý¾Ý±í£¬£¬£¬£¬£¬ £¬£¬£¬»¹ÓвÆÕþÐÅÏ¢¡¢ÁªÏµ·½Ê½¡¢Éç½»ÐÅÏ¢¡¢°²È«ºÅÂëºÍ±£ÏÕ³ÖÓÐÁ¿µÈÆäËüÊý¾Ý¡£¡£¡£¡£¡£¡£IMYÖ¸³ö£¬£¬£¬£¬£¬ £¬£¬£¬Trygg-HansaÔÚʹÓÃÓйØITϵͳ֮ǰ£¬£¬£¬£¬£¬ £¬£¬£¬»òÔÚʹÓøÃϵͳµÄºÜ³¤Ò»¶Î¹¦·òÄÚ¶¼Ó¦¸ÃÓлúÓö·¢ÏÖ²¢½¨¸´¸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£IMYÒÔΪTrygg-Hansaδ²ÉÈ¡Êʵ±µÄ´ëÊ©À´È·±£Óë·çÏÕÏà³ÆµÄ°²È«¼¶±ð£¬£¬£¬£¬£¬ £¬£¬£¬Òò¶ø· £¿£¿£¿£¿£¿£¿£¿î3500Íò¿ËÀÊ¡£¡£¡£¡£¡£¡£


https://www.databreaches.net/swedens-privacy-protection-agency-fines-insurer-trygg-hansa-for-exposing-sensitive-customer-data/


3¡¢USDoDй¼ûÀ¹úÐÅÓþ»ú¹¹TransUnion³¬¹ý3 GBµÄÊý¾Ý


9ÔÂ18ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬ £¬£¬£¬ÍâºÅΪUSDoDµÄºÚ¿Íй¶Á˾ݳÆÊÇ´ÓÃÀ¹úÏû·ÑÕßÐÅÓþ»ú¹¹TransUnionÇÔÈ¡µÄÊý¾Ý¡£¡£¡£¡£¡£¡£TransUnionÊÇÃÀ¹úÈý´óÕ÷ОÞÍ·Ö®Ò»£¬£¬£¬£¬£¬ £¬£¬£¬ÍøÂç²¢»ã×ÜÁË30¶à¸ö¹ú¶ÈºÍµØÓòµÄ³¬¹ý10ÒÚÏû·ÑÕßµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£Õâ´Îй¶µÄÊý¾Ý¿â³¬¹ý3 GB£¬£¬£¬£¬£¬ £¬£¬£¬Ô̺¬Ô¼58505È˵ÄPIIÐÅÏ¢£¬£¬£¬£¬£¬ £¬£¬£¬±é²¼È«Çò£¬£¬£¬£¬£¬ £¬£¬£¬Ô̺¬ÃÀ¹úºÍÅ·ÖÞ¡£¡£¡£¡£¡£¡£vx-underground³Æ£¬£¬£¬£¬£¬ £¬£¬£¬¸Ãµµ°¸Ô̺¬¿É×·Òäµ½2022Äê3ÔÂ2ÈÕµÄÊý¾Ý¡£¡£¡£¡£¡£¡£²»¾Ãǰ£¬£¬£¬£¬£¬ £¬£¬£¬USDoD»¹Ð¹Â¶ÁËAirbusµÄ3200Ãû¹©¸øÉ̵ÄÐÅÏ¢£¬£¬£¬£¬£¬ £¬£¬£¬ÒÔ¼°FBI¹²ÏíϵͳInfraGardµÄÊý¾Ý¿â¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/150968/data-breach/transunion-data-leak.html


4¡¢GoogleÔÞ³ÉÒÔ9300ÍòÃÀÔªºÍ½âAndroidÓû§×·×ÙµÄËßËÏ


ýÌå9ÔÂ15Èճƣ¬£¬£¬£¬£¬ £¬£¬£¬GoogleÔÞ³ÉÖ§¸¶9300ÍòÃÀÔª£¬£¬£¬£¬£¬ £¬£¬£¬ÒԺͽâÒ»ÏîÖ¸¿ØÆäÎ¥·´ÃÀ¹úÏû·ÑÕß±£»£»£»£»£»£»£» £»¤·¨µÄËßËÏ¡£¡£¡£¡£¡£¡£¼ÓÖÝ˾·¨²¿µÄÒ»Ïîµ÷²é·¢ÏÖ£¬£¬£¬£¬£¬ £¬£¬£¬GoogleÔÚÍøÂç¡¢±£ÁôºÍÀûÓÃAndroidÓû§µÄµØÎ»Êý¾ÝÓÃÓÚÏû·ÑÕß·ÖÎöºÍ¸æ°×µÈÖ÷ÕÅ·½Ãæ´æÔÚºýŪÐÐΪ£¬£¬£¬£¬£¬ £¬£¬£¬ËùÓÐÕâЩ¶¼Ã»ÓлñµÃÓû§µÄÖªÇéºÍÔ޳ɡ£¡£¡£¡£¡£¡£³ÁµãÊǵØÎ»¸ú×Ù£¬£¬£¬£¬£¬ £¬£¬£¬µ±Óû§ÆëÈ«½ûÓõØÎ»¸ú×Ùʱ£¬£¬£¬£¬£¬ £¬£¬£¬»áĬÈÏÆôÓá°ÍøÂçºÍÀûÓ÷¨Ê½»î¶¯¡±ÉèÖ㬣¬£¬£¬£¬ £¬£¬£¬¿ÉÍøÂç¡¢±£ÁôºÍÀûÓÃÓû§µÄµØÎ»Êý¾Ý¡£¡£¡£¡£¡£¡£ÔںͽâÖ®ºó£¬£¬£¬£¬£¬ £¬£¬£¬GoogleÔÞ³ÉÖ´ÐÐÔ½·¢Óû§¶ØÄÀµÄÕÊ»§½ÚÔ죬£¬£¬£¬£¬ £¬£¬£¬Í¬Ê±ÏÞ¶ÈÌØ¶¨µØÎ»Êý¾ÝÀà´ËÍâʹÓúͱ£Áô¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/google/google-pays-93m-to-settle-android-tracking-lawsuit-in-california/


5¡¢Î¢ÈíÅû¶ncurses¿âÖеÄÄÚ´æ°Ü»µ·ì϶CVE-2023-29491


΢ÈíÔÚ9ÔÂ14ÈÕÅû¶ÁËncurses¿âÖеÄÒ»×éÄÚ´æ°Ü»µ·ì϶µÄϸ½ÚÐÅÏ¢¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶ͳ³ÆÎªCVE-2023-29491£¨CVSSÆÀ·Ö7.8£©£¬£¬£¬£¬£¬ £¬£¬£¬¿É±»ÓÃÀ´ÔÚLinuxºÍmacOSϵͳÉÏÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£ncurses¿âÓÚ1993Äê°ä²¼£¬£¬£¬£¬£¬ £¬£¬£¬Ìṩ֧³Ö»ùÓÚÎı¾µÄÓû§½çÃæ(TUI)µÄAPI£¬£¬£¬£¬£¬ £¬£¬£¬Í¨³£±»¿ÉÒÆÖ²²Ù×÷ϵͳ½Ó¿Ú(POSIX)ϵͳÉϵĸ÷À෨ʽʹÓᣡ£¡£¡£¡£¡£ÀûÓû·¾³±äÁ¿Öж¾£¬£¬£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßÄܹ»½áºÏʹÓÃÕâЩ·ì϶À´ÌáÉýȨÏÞ£¬£¬£¬£¬£¬ £¬£¬£¬²¢ÔÚÖ¸±ê·¨Ê½µÄϵͳÖÐÔËÐдúÂë»òÖ´ÐÐÆäËü¹¥»÷¡£¡£¡£¡£¡£¡£Î¢ÈíÓÚ4Ô·ݽ¨¸´Á˸÷ì϶¡£¡£¡£¡£¡£¡£


https://www.microsoft.com/en-us/security/blog/2023/09/14/uncursing-the-ncurses-memory-corruption-vulnerabilities-found-in-library/


6¡¢Mandiant°ä²¼¹ØÓÚUNC3944¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨


9ÔÂ14ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬Mandiant°ä²¼Á˹ØÓÚUNC3944¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£×Ô2022ÄêÖÁ2023ËêÊ×£¬£¬£¬£¬£¬ £¬£¬£¬UNC3944רһÓÚ½Ó¼ûÓÃÓÚ½øÐÐSIM»¥»»¹¥»÷µÄƾ֤»òϵͳ£¬£¬£¬£¬£¬ £¬£¬£¬È»¶øÔÚ2023ÄêÖÐÆÚ£¬£¬£¬£¬£¬ £¬£¬£¬UNC3944ÆðͷתÏòÔÚÖ¸±êϵͳÖв¿ÊðÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚUNC3944Ðж¯ÆÚ¼ä¹Û²ìµ½µÄTTP£¬£¬£¬£¬£¬ £¬£¬£¬Ô̺¬¼«¶ÈÒÀÀµÓÚÉ繤¹¥»÷½øÐгõʼ½Ó¼û£¬£¬£¬£¬£¬ £¬£¬£¬Ê¹ÓÃóÒ×סլ´úÀí·þÎñ´Óͳһ¾ÖÓò½Ó¼ûÖ¸±êÒÔÈÆ¹ý¼à¿Ø¹¤¾ß£¬£¬£¬£¬£¬ £¬£¬£¬Ê¼ÖÕʹÓúϷ¨Èí¼þ£¬£¬£¬£¬£¬ £¬£¬£¬Ðж¯½ÚÅļ«¿ì²¢ÔÚ¼¸ÌìÄÚ¾ÍÄܽӼû¹Ø¼üϵͳÀ´ÇÔÈ¡´óÁ¿Êý¾ÝµÈ¡£¡£¡£¡£¡£¡£


https://www.mandiant.com/resources/blog/unc3944-sms-phishing-sim-swapping-ransomware