Tor µÄРWebTunnel ÇÅ·ÂÕÕ HTTPS Á÷Á¿À´ÈƹýÉó²é
°ä²¼¹¦·ò 2024-03-143ÔÂ12ÈÕ£¬£¬£¬£¬£¬Tor ÏîÄ¿ÕýÊ½ÍÆ³öÁË WebTunnel£¬£¬£¬£¬£¬ÕâÊÇÒ»ÖÖеÄÇŽÓÀàÐÍ£¬£¬£¬£¬£¬×¨ÃÅÉè¼ÆÓÃÓÚͨ¹ý°µ²ØÏÔÖøµÄÏνÓÀ´Ô®ÊÖÈÆ¹ýÕë¶Ô Tor ÍøÂçµÄÉó²éÔì¶È¡£¡£¡£¡£¡£Tor ÍøÇÅÊÇδÔÚ¹«¹² Tor Ŀ¼ÖÐÁгöµÄÖм̣¬£¬£¬£¬£¬Äܹ»Ê¹Óû§ÓëÍøÂçµÄÏνÓÃâÊÜѹÆÈÕþȨµÄÓ°Ïì¡£¡£¡£¡£¡£¹ÌÈ»ÖйúºÍÒÁÀʵÈһЩ¹ú¶ÈÒѾÕÒµ½Á˼ì²âºÍ×èÖ¹´ËÀàÏνӵIJ½Ö裬£¬£¬£¬£¬µ« Tor »¹ÌṩÁËobfsproxyÇÅ£¬£¬£¬£¬£¬ÕâÔö³¤ÁËÒ»²ã¶î±íµÄ»ìºÏÒÔÆ¥µÐÉó²éÔì¶È¡£¡£¡£¡£¡£WebTunnel ÊÇÊÜ HTTPT ¿¹Ì½²â´úÀíÆô·¢µÄ¿¹Éó²é¿É²å°Î´«Ê䣬£¬£¬£¬£¬ËüѡȡÁË·ÖÆçµÄ²½Öè¡£¡£¡£¡£¡£Í¨¹ýÈ·±£Á÷Á¿Óë HTTPS ¼ÓÃܵÄÍøÂçÁ÷Á¿»ìºÏ£¬£¬£¬£¬£¬×èÖ¹ Tor ÏνӱäµÃÔ½·¢ÄÑÌâ¡£¡£¡£¡£¡£ÓÉÓÚ×èÖ¹ HTTPS Ò²»á×èÖ¹¾ø´óÎÞÊýÓë Web ·þÎñÆ÷µÄÏνӣ¬£¬£¬£¬£¬Òò¶ø WebTunnel ÏνÓÒ²½«±»ÔÊÐí£¬£¬£¬£¬£¬´Ó¶øÍ¨¹ýºÍ̸ÔÊÐíÁбíºÍĬÈϻؾøÕ½ÊõÓÐЧµØ¶ã±ÜÍøÂç»·¾³ÖеÄÉó²é¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/tors-new-webtunnel-bridges-mimic-https-traffic-to-evade-censorship/
2. Ð嵀 Vcurms ¶ñÒâÈí¼þ¶Ô׼ʢÐÐä¯ÀÀÆ÷½øÐÐÊý¾Ý͵ÇÔ
3ÔÂ12ÈÕ£¬£¬£¬£¬£¬Fortinet µÄ FortiGuard ³¢ÊÔÊÒ×î½ü·¢ÏÖÁËÒ»ÖÖеÄÍøÂ簲ȫÍþв£ºÒ»ÖÖÃûΪ¡°Vcurms¡±µÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£Vcurms ¶ñÒâÈí¼þ±³ºóµÄ¹¥»÷ÕßѡȡÁ˸´ÔÓµÄÕ½Êõ£¬£¬£¬£¬£¬Ê¹Óõç×ÓÓʼþ×÷ΪºÅÁîºÍ½ÚÔìÖÐÐÄ£¬£¬£¬£¬£¬²¢ÀûÓà AWS ºÍ GitHub µÈ¹«¹²·þÎñÀ´´æ´¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ËûÃÇ»¹Ñ¡È¡ÁËóÒ×±£»£»£»£»£»¤·¨Ê½À´Ìӱܼì²â£¬£¬£¬£¬£¬ÕâÅú×¢ËûÃÇÔÚ¹²Í¬ÖÂÁ¦×î´óÏ޶ȵØÀ©´ó¶ñÒâÈí¼þµÄÓ°Ïì¡£¡£¡£¡£¡£¸Ã»î¶¯ÖØÒªÕë¶Ô×°ÖÃÁË Java µÄƽ̨£¬£¬£¬£¬£¬¶ÔʹÓôËÀàϵͳµÄÈκÎ×éÖ¯×é³É·çÏÕ¡£¡£¡£¡£¡£ÍþвµÄÑϳÁÐÔ²»Èݵ͹À£¬£¬£¬£¬£¬ÓÉÓڳɹ¦µÄÉøÈëʹ¹¥»÷Õß¿ÉÄÜÆëÈ«½ÚÔìÊÜϰȾµÄϵͳ¡£¡£¡£¡£¡£¹¥»÷ÕßµÄ×÷°¸ÊÖ·¨Ô̺¬ÒýÓÕÓû§ÏÂÔØ¶ñÒâ Java ÏÂÔØ·¨Ê½£¬£¬£¬£¬£¬¸ÃÏÂÔØ·¨Ê½³äÈδ«²¼ Vcurms ºÍ STRRAT µÄÔØÌ壬£¬£¬£¬£¬STRRAT ÊÇÒ»ÖÖÏÈǰ±»·¢ÏÖ¼ÙÒâ¼ÙÀÕË÷Èí¼þϰȾÒÔÇÔÈ¡Êý¾ÝµÄľÂí¡£¡£¡£¡£¡£ÕâЩ¶ñÒâµç×ÓÓʼþͨ³£¼Ù×°³ÉºÏ·¨ÒªÇ󣬣¬£¬£¬£¬¶½´ÙÊÕ¼þÈËÑéÖ¤¸¶¿îÐÅÏ¢²¢ÏÂÔØ AWS ÉÏÍйܵÄÓк¦Îļþ¡£¡£¡£¡£¡£
https://www.hackread.com/vcurms-malware-browsers-for-data-theft/
3. Meta ¸æ×´È¥ÈËÔ±¹¤ÉæÏÓÇÔÈ¡¾øÃÜÊý¾ÝÖÐÐÄÀ¶Í¼
3ÔÂ12ÈÕ£¬£¬£¬£¬£¬Ò»Î»Ç° Meta ¸±×Üͳ±»ËûµÄǰÀÏ°å¸æ×´£¬£¬£¬£¬£¬×ïÃûÊÇ¡°¹«¿ª²»ÖҺͲ»¿ÒÇÐÐÐΪ¡±¡ª¡ªËûÃǵÄÒâ˼ÊÇ£¬£¬£¬£¬£¬ËûÉæÏÓÇÔÈ¡»úÃÜÎļþ£¬£¬£¬£¬£¬ÒÔÔ®ÊÖËûΪһ¼ÒÈËΪÖÇÄÜÔÆ²Ý´´¹«Ë¾³ÉÁ¢ºÍÕÐļͬÊ¡£¡£¡£¡£¡£ÔÚ Facebook ¾ÞÍ·¹¤×÷µÄ 12 Äê¼ä£¬£¬£¬£¬£¬Dipinder Singh Khurana£¨±ðÃû TS Khurana£©ÌáÉýÎªÕÆ¹Ü»ù´¡ÉèÊ©µÄ¸±×ܲᣡ£¡£¡£¡£ËûÓÚ 2023 Äê 6 ÔÂÍÑÀëÕâ¼Ò´óÐÍÆóÒµ£¬£¬£¬£¬£¬ÔÚÒ»¼ÒÈÔ´¦ÓÚ°ÂÃØÄ£Ê½µÄ²Ý´´¹«Ë¾µ£Èι©¸øÁ´ÔËÓª¸ß¼¶¸±×ܲ㬣¬£¬£¬£¬Õë¶ÔËûµÄËßËÏÖÐûÓÐÌáµ½ËûµÄÃû×Ö¡£¡£¡£¡£¡£Meta ÔÚÌá½»¸ø Meta µÄÒ»·Ý¸æ×´ÊéÖгƣ¬£¬£¬£¬£¬ÔÚ֪ͨ Meta ÀϰåËû´òËãÍÑÀëºó£¬£¬£¬£¬£¬¿âÀÄɾݳÆÀûÓÃ×Ô¼ºÔÚ¹«Ë¾µÄÔü×Ò¹¦·òÇÔÈ¡ÁË¡°´óÁ¿ÓÐ¹Ø Meta ÒµÎñºÍÔ±¹¤µÄרÓÓ×¢¸ß¶ÈÃô¸Ó×¢»úÃܺͷǹ«¿ªÎļþ¡± ¡£¡£¡£¡£¡£Meta ¶Ô¿âÀÄÉÌá³öÁËÎåÏîÖ¸¿Ø£ºÎ¥·´ºÏͬ¡¢Î¥·´ÖÒ³ÏʹÃü¡¢Î¥·´ÐÅÈÎʹÃü¡¢²»µ±µÃÀûÒÔ¼°Î¥·´¼ÓÖÝÍÆËã»ú·¸×ï·¨¡£¡£¡£¡£¡£Facebook ¾ÞÍ·ÒªÇó¿âÀÄɱ»ÆÈÖ§¸¶Åâ³¥½ð£¬£¬£¬£¬£¬²¢½»³öËûÒòÉæÏÓÇÔÈ¡¹«Ë¾»úÃܶø»ñµÃµÄÈκνðÇ®»òÀûÒæ¡£¡£¡£¡£¡£
https://www.theregister.com/2024/03/12/meta_vp_infrastructure_allegations/
4. Windows KB5035849 ¸üÐÂÎÞ·¨×°Ö㬣¬£¬£¬£¬²¢³öÏÖ 0xd000034 ÃýÎó
3ÔÂ12ÈÕ£¬£¬£¬£¬£¬Î¢Èí°ä²¼µÄ KB5035849 ÀÛ»ý¸üÐÂÎÞ·¨ÔÚ Windows 10 ºÍ Windows Server ϵͳÉÏ×°Ö㬣¬£¬£¬£¬²¢³öÏÖ 0xd0000034 ÃýÎ󡣡£¡£¡£¡£Æ¾¾ÝÖÎÀíÔ±ºÍÓû§µÄÒ»²¨ »ã±¨ £¬£¬£¬£¬£¬µ±Í¨¹ý Windows ºÍ Microsoft ¸üзþÎñÆ÷ÔÚÏ߲鳸üÐÂʱ£¬£¬£¬£¬£¬KB5035849 ½«ÎÞ·¨×°Öᣡ£¡£¡£¡£ÊÜÓ°ÏìµÄϵͳÔ̺¬ÔËÐÐ Windows Server 2019 »ò Windows 10 Enterprise LTSC 2019 µÄϵͳ£¬£¬£¬£¬£¬ÕâЩϵͳÒÑÓÚ 1 Ô 9 ÈÕ´ïµ½Ö÷Á÷Ö§³ÖÖÕÖ¹ÈÕÆÚ£¬£¬£¬£¬£¬²¢µ¢¸éÖ§³ÖÎåÄêÖ±ÖÁ 2029 Äê 1 Ô¡£¡£¡£¡£¡£¹ÌÈ»ºÜ¶à¿Í»§ÒѾ»ã±¨ KB5035849 ûÓÐ×°ÖÃÔÚËûÃǵÄÉ豸ÉÏ£¬£¬£¬£¬£¬µ«Î¢Èí°µÊ¾¡°Ä¿Ç°²»ÖªÂ·´Ë¸üÐÂÓÐÈκÎÎÊÌ⡱¡£¡£¡£¡£¡£ÔÚ½ñÌìµÄÖ§³ÖÎĵµÖУ¬£¬£¬£¬£¬¸Ã¹«Ë¾»¹½«ÆäÏóÕ÷Ϊ¿Éͨ¹ý Windows Update ºÍ Microsoft Update ×°Öᣡ£¡£¡£¡£Óöµ½ÕâЩÎÊÌâµÄÓû§ÒÀÈ»Äܹ»Í¨¹ý´ÓMicrosoft µÄ¸üÐÂĿ¼ÏÂÔØ²¢×°Öà KB5035849 À´ÊÖ¶¯²¿ÊðËü¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/microsoft/windows-kb5035849-update-failing-to-install-with-0xd000034-errors/
5. ºê³žÖ¤Êµ·ÆÂɱöÔ±¹¤Êý¾ÝÔÚºÚ¿ÍÂÛ̳ÉÏй¶
3ÔÂ12ÈÕ£¬£¬£¬£¬£¬ºê³ž·ÆÂɱö¹«Ë¾Ö¤Êµ£¬£¬£¬£¬£¬ÔÚºÚ¿ÍÂÛ̳ÉÏй¶Êý¾Ýºó£¬£¬£¬£¬£¬ÖÎÀí¸Ã¹«Ë¾Ô±¹¤³öÇÚÊý¾ÝµÄµÚÈý·½¹©¸øÉÌÔâµ½¹¥»÷£¬£¬£¬£¬£¬Ô±¹¤Êý¾Ý±»µÁ¡£¡£¡£¡£¡£ºê³žÊÇÒ»¼Ǫ̀ÍåÍÆËã»úÓ²¼þºÍµç×Ó²úÆ·Ôì×÷ÉÌ£¬£¬£¬£¬£¬ÒÔÆäÔÚ»úÄÜ¡¢ÖÊÁ¿ºÍÓоºÕùÁ¦µÄ¼ÛÖµÖ®¼ä»ñµÃÓÅÁ¼Æ½ºâµÄ±Ê¼Ç±¾µçÄÔ¶øÎÅÃû¡£¡£¡£¡£¡£ÔçЩʱ³½£¬£¬£¬£¬£¬Ò»¸öÃûΪ¡°ph1ns¡±µÄÍþвÐÐΪÕßÔÚºÚ¿ÍÂÛ̳Éϰ䲼ÁËÒ»¸öÁ´½Ó£¬£¬£¬£¬£¬Äܹ»Ãâ·ÑÏÂÔØÔ̺¬ Acer Ô±¹¤Êý¾ÝµÄ±»µÁÊý¾Ý¿â¡£¡£¡£¡£¡£¹¥»÷Õß֪ͨ BleepingComputer£¬£¬£¬£¬£¬Ã»ÓÐÉæ¼°ÀÕË÷Èí¼þ»ò¼ÓÃÜ£¬£¬£¬£¬£¬ÕâÖ»ÊÇÒ»´Î´¿ÕýµÄÊý¾Ý͵ÇÔ¹¥»÷¡£¡£¡£¡£¡£ËûÃǽøÒ»²½Ïò BleepingComputer ֤ʵ£¬£¬£¬£¬£¬ËûÃDz¢Ã»ÓÐÊÔͼÀÕË÷¸Ã¹«Ë¾¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬ËûÃǵÄÈ·ÌṩÁËÖ¤¾Ý£¬£¬£¬£¬£¬Åú×¢ËûÃÇÔÚʧȥ½Ó¼ûȨÏÞ֮ǰ²Á³ýÁ˱»ÈëÇÖ·þÎñÆ÷ÉϵÄÊý¾Ý¡£¡£¡£¡£¡£ºê³ž½üÄêÀ´²úÉú¶àÆð°²È«ÊÂÎñ¡£¡£¡£¡£¡£2023 Äê 2 Ô£¬£¬£¬£¬£¬ºÚ¿ÍÈëÇÖÁ˹«Ë¾·þÎñÆ÷£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬¼¼ÊõÊֲᡢÈí¼þ¹¤¾ß¡¢BIOS Ó³ÏñºÍ´úÌæÊý×Ö²úÆ·ÃÜÔ¿ (RDPK) µÈ¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/acer-confirms-philippines-employee-data-leaked-on-hacking-forum/
6. 2023 ÄêGitHub й¶³¬¹ý 1200 Íò¸öÉí·ÝÑéÖ¤ºÍÃÜÔ¿
3ÔÂ12ÈÕ£¬£¬£¬£¬£¬GitHub Óû§ÒⱩ¶³öÁ˳¬¹ý 300 Íò¸ö¹«¹²´æ´¢¿âÖÐµÄ 1280 Íò¸öÉí·ÝÑéÖ¤ºÍÃô¸Ð»úÃÜ£¬£¬£¬£¬£¬ÆäÖоø´óÎÞÊýÔÚÎåÌìºóÒÀÈ»ÓÐЧ¡£¡£¡£¡£¡£ÕâÊÇGitGuardianÍøÂ簲ȫר¼ÒµÄ˵·¨ £¬£¬£¬£¬£¬ËûÃÇÏòÄÇЩй¶°ÂÃØµÄÈË·¢³öÁË 180 Íò·âÃâ·Ñµç×ÓÓʼþ¾¯±¨£¬£¬£¬£¬£¬·¢ÏÖÖ»Óм«Ó×µÄ 1.8% µÄÈ˲ÉÈ¡Á˼±¾çÐж¯À´¾ÀÕýÃýÎ󡣡£¡£¡£¡£Â¶³öµÄ°ÂÃØÔ̺¬ÕÊ»§ÃÜÂë¡¢API ÃÜÔ¿¡¢TLS/SSL Ö¤Êé¡¢¼ÓÃÜÃÜÔ¿¡¢ÔÆ·þÎñƾ֤¡¢OAuth ÁîÅÆºÍÆäËûÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬ÕâЩÊý¾Ý¿ÉÄÜʹ±í²¿²Î¼ÓÕßÎÞÏ޶ȵؽӼû¸÷Àà˽ÓÐ×ÊÔ´ºÍ·þÎñ£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÊý¾Ýй¶ºÍ²ÆÕþËðʧ¡£¡£¡£¡£¡£2023 Äê Sophos »ã±¨Ç¿µ÷£¬£¬£¬£¬£¬Æ¾Ö¤Ð¹Â¶ Õ¼ ÉϰëÄê¼Í¼µÄËùÓй¥»÷µ××ÓÔÒòµÄ 50%£¬£¬£¬£¬£¬Æä´ÎÊÇ·ì϶ÀûÓ㬣¬£¬£¬£¬ÕâÊÇ 23% °¸ÀýÖеĹ¥»÷²½Öè¡£¡£¡£¡£¡£GitGuardian °µÊ¾£¬£¬£¬£¬£¬È«Çò×îÊÜ»¶ÓµÄ´úÂëÍйܺͺÏ×÷ƽ̨ GitHub ÉϵİÂÃØÆØ¹â×Ô 2020 ÄêÒÔÀ´Ò»Ïò³Ê¸ºÃæÇ÷Ïò¡£¡£¡£¡£¡£¾Íй¶»úÃÜ×î¶àµÄÐÐÒµ¶øÑÔ£¬£¬£¬£¬£¬IT ÒÔ 65.9% µÄ·Ý¶îλ¾Ó°ñÊ×£¬£¬£¬£¬£¬Æä´ÎÊǽÌÓý£¬£¬£¬£¬£¬Õ¼ 20.1%£¬£¬£¬£¬£¬ÒÔ¼°ËùÓÐÆäËûÐÐÒµµÄ×ܺͣ¨¿ÆÑ§¡¢ÁãÊÛ¡¢Ôì×÷¡¢½ðÈÚ¡¢¹«¹²ÖÎÀí¡¢Ò½ÁƱ£½¡¡¢ÓéÀÖ£© ¡¢½»Í¨£©Õ¼14%¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/over-12-million-auth-secrets-and-keys-leaked-on-github-in-2023/


¾©¹«Íø°²±¸11010802024551ºÅ