ÍøÂç·¸×ï·Ö×ÓÔÚÕ«ÔºͿªÕ«½ÚÆÚ¼ä·è¿ñÍøÂçÚ¿Æ­

°ä²¼¹¦·ò 2024-03-26

1. ÍøÂç·¸×ï·Ö×ÓÔÚÕ«ÔºͿªÕ«½ÚÆÚ¼ä·è¿ñÍøÂçÚ¿Æ­


3ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬Õ«ÔÂÆÚ¼ä£¬£¬£¬£¬£¬£¬Resecurity¹Û²ìµ½Ú²Æ­»î¶¯ºÍÚ¿Æ­´ó·ùÔö³¤£¬£¬£¬£¬£¬£¬Í¬Ê±ÁãÊÛºÍÔÚÏßÂòÂô¼¤Ôö¡£¡£¡£¡£¡£¡£¡£Ãæ¶ÔÕâÒ»¼Ó¾ç·çÏÕµÄÖж«ÆóÒµ±»¶½´Ù¼ÓÇ¿Ïû·ÑÕß±£»£»£» £»£»£»£»¤²¢¼ÓÇ¿Æ·ÅÆ°²È«¡£¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬£¬É³Ìذ¢À­²®Íõ¹ú (KSA) µÄÏû·ÑÕßÖ§³ö³¬¹ý 160 ÒÚÃÀÔª£¬£¬£¬£¬£¬£¬Î»¾ÓµØÓòÅÅÐаñÊ×λ¡£¡£¡£¡£¡£¡£¡£²»ÐÒµÄÊÇ£¬£¬£¬£¬£¬£¬µç×ÓÉÌÎñ»î¶¯µÄ¼¤ÔöÒýÆðÁËÍøÂç·¸×ï·Ö×ÓÈ·°ÑÎÈ£¬£¬£¬£¬£¬£¬ËûÃÇÀûÓÃÕâЩƽִ̨ÐÐÚ¿Æ­£¬£¬£¬£¬£¬£¬¸øÏû·ÑÕßºÍÆóÒµ´øÀ´Á˾޴óµÄ²ÆÕþÓ°Ïì¡£¡£¡£¡£¡£¡£¡£ÕâЩ»î¶¯µÄ×ܲÆÕþÓ°Ïì¹À¼ÆÔÚ 70 ÖÁ 1 ÒÚÃÀÔªÖ®¼ä£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Õë¶Ô±í¼®ÈËÊ¿¡¢¾ÓÃñºÍ±í¹úÓο͵ÄڲƭÐÐΪ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ³ÖÐøÖÂÁ¦ÎªÖж«ºÜ¶à¿Í»§Ìá¹©Æ·ÅÆ±£»£»£» £»£»£»£»¤£¬£¬£¬£¬£¬£¬Resecurity ÒÑÓÐЧ×èÖ¹ÁË 320 ¶à¸ö¼ÙÒâÖØÒªÎïÁ÷ÌṩÉ̺͵ç×ÓÕþÎñ·þÎñµÄڲƭ×ÊÔ´¡£¡£¡£¡£¡£¡£¡£ÍøÂç·¸×ï·Ö×Ó»ý¼«ÀûÓà Sadad¡¢Musaned¡¢Ajeer¡¢Ejar µÈƽ̨ÒÔ¼°³ÛÃûÎïÁ÷·þÎñÀ´ºýŪ»¥ÁªÍøÓû§£¬£¬£¬£¬£¬£¬²¢½«ËûÃÇÒýÈë·ÖÆçµÄȦÌס£¡£¡£¡£¡£¡£¡£Ç¿ÁÒ½¨Òé²»ÒªÔÚ¿ÉÒÉÍøÕ¾ÉÏ»òÓë¼ÙÒâÒøÐлòµ±¾Ö¹ÍÔ±µÄÓ×ÎÒ·ÖÏíÓ×ÎҺ͸¶¿îÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/161009/cyber-crime/cybercriminals-accelerate-scams-ramadan.html


2. OpenVPN ½¨¸´ Windows ÖеĶà¸öÑϳÁ·ì϶


3ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬OpenVPN ÒѰ䲼³ÁÒª°²È«¸üУ¨°æ±¾ 2.6.10£©£¬£¬£¬£¬£¬£¬ÒÔ½â¾öÆä Windows Èí¼þÖеÄһϵÁзì϶£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶¿ÉÄܵ¼ÖÂȨÏÞÉý¼¶¡¢Ô¶³Ì¹¥»÷ºÍϵͳ±ÀÀ£¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶͹ÏÔÁ˶¨ÆÚÈí¼þ¸üеıØÒªÐÔ£¬£¬£¬£¬£¬£¬³ö¸ñÊǶÔÓÚ OpenVPN µÈ´¦ÖÃÍøÂçÁ÷Á¿µÄ¹¤¾ß¡£¡£¡£¡£¡£¡£¡£±¾´Î¸üеķì϶Ô̺¬CVE-2024-27459£¨²Ö¿âÒç³ö±£»£»£» £»£»£»£»¤£©¡¢CVE-2024-24974£¨Ô¶³Ì½Ó¼ûÏÞ¶È£©¡¢CVE-2024-27903£¨²å¼þ¼ÓÔØÏÞ¶È£©ºÍCVE-2024-1305£¨TAP Çý¶¯·¨Ê½Òç³ö½¨¸´£©¡£¡£¡£¡£¡£¡£¡£


https://securityonline.info/openvpn-patches-serious-vulnerabilities-in-windows-installations/


3. Vans Ðû³ÆÍøÂçÆ­×Ó²¢Î´ÇÔÈ¡¿Í»§µÄ²ÆÕþÐÅÏ¢


3ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬·þ×°ºÍЬÀà¾ÞÍ· VF Corporation Ïò 3550 Íò¿Í»§´«µÝ£¬£¬£¬£¬£¬£¬¼ÌÈ¥ÄêµÄ°²È«·ì϶֮ºó£¬£¬£¬£¬£¬£¬ËûÃÇ¿ÉÄÜ»á³ÉΪÉí·Ý͵ÇÔµÄÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£Vans ºÍ North Face ĸ¹«Ë¾ÔÚ¸ø¿Í»§µÄÒ»·âµç×ÓÓʼþÖгÐŵ£¬£¬£¬£¬£¬£¬Æ­×Ó²»»áµÁÈ¡ËûÃǵÄÐÅÓþ¿¨»òÒøÐÐÕË»§¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£²¢ÇÒ£¬£¬£¬£¬£¬£¬Ëü²¹³ä˵£¬£¬£¬£¬£¬£¬¡°Ã»ÓÐÖ¤¾Ý¡±Åú×¢Èκα»µÁµÄÓ×ÎÒÐÅÏ¢£¬£¬£¬£¬£¬£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþ¡¢µØÖ·ºÍµç»°ºÅÂ룬£¬£¬£¬£¬£¬Òѱ»ÓÃÓÚа¶ñÖ÷ÕÅ¡£¡£¡£¡£¡£¡£¡£ÕâЩ¼Í¼ÊÇÔÚ VF ÓÚ 12 Ô 13 ÈÕÅû¶µÄÊý×ÖÈëÇÖ¹ý³ÌÖб»½Ó¼û»ò»ñÈ¡µÄ¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÈëÇÖÇÖÈÅÁËÕâ¼Ò·þ×°Ôì×÷É̵ÄÔËÓª¼°ÆäÈÃÈËÃÇ´©´÷¸ßµµ±íÌ×µÄÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£¹ÌÈ» VF Æäʱ²¢Î´½«Õâ´ÎÍøÂ簲ȫÊÂÎñ³ÆÎªÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬µ«ÆäÔÚ¼à¹ÜÎļþÖоßÌåÃèÊöÕâ´ÎÈëÇֵĴë´ÇʹÆäÌýÆðÀ´¼«¶ÈÏñ´øÓÐÀÕË÷ÒªÇóµÄÀÕË÷Èí¼þϰȾ¡£¡£¡£¡£¡£¡£¡£ÔÚÏòÃÀ¹ú֤ȯÂòÂôίԱ»á (SEC) Ìá½»µÄ×îР8-K ÎļþÖУ¬£¬£¬£¬£¬£¬Õâ¼Ò·þ×°ÏúÊÛÉÌÅû¶£¬£¬£¬£¬£¬£¬Æä3550 Íò¿Í»§Êܵ½ IT °²È«·ì϶µÄÓ°Ï죬£¬£¬£¬£¬£¬µ«¶ÔÆ­×Ó¿ÉÄÜÇÔÈ¡µÄÊý¾ÝÈ´³éÏóÆä´ÇÔÚ¹¥»÷ÆÚ¼ä¡£¡£¡£¡£¡£¡£¡£


https://www.theregister.com/2024/03/24/vans_breach_disclosure/


4. ÓÐÏßµçÊÓ ISP ÒòÏò FCC »Ñ±¨¿í´øµØÖ·¶ø±»·£¿£¿ £¿£¿£¿£¿î


3ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬Ò»¼Ò»¥ÁªÍø·þÎñÌṩÉÌÈÏ¿ÉÔÚÆäÌṩ¿í´øµÄµØÖ··½ÃæÏò FCC ˵»Ñ£¬£¬£¬£¬£¬£¬½«Ö§¸¶ 10,000 ÃÀÔªµÄ·£¿£¿ £¿£¿£¿£¿î£¬£¬£¬£¬£¬£¬²¢Ö´ÐкϹæ´òËãÒÔÔ¤·À½«À´³öÏÖÎ¥¹æÐÐΪ¡£¡£¡£¡£¡£¡£¡£ArsTechnica£º¶íº¥¶íÖݶàÂ×¶àµÄÒ»¼ÒÓ×ÐÍ ISP ½Üì³Ñ·ÏصçÀ (JCC) ÈϿɣ¬£¬£¬£¬£¬£¬ËüÃýÎóµØÐû³ÆÔÚÉÐδÀ©´óµ½µÄµØÓòÌṩ¹âÏË·þÎñ¡£¡£¡£¡£¡£¡£¡£Ò»Î»¹«Ë¾¸ß¹Ü»¹ÈϿɣ¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Ìá½»ÁËÐéαµÄ¸²¸ÇÊý¾Ý£¬£¬£¬£¬£¬£¬ÒÔ×èÖ¹ÆäËû»¥ÁªÍø·þÎñÌṩÉÌ»ñÇе±¾Ö²¦¿îÀ´Îª¸ÃµØÓòÌṩ·þÎñ¡£¡£¡£¡£¡£¡£¡£Ars ÔÚ 2023 Äê 2 ÔµÄһƪÎÄÕÂÖÐÔ®Êָ淢ÁËÕâÒ»ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£FCC ÓÚ 3 Ô 15 ÈÕ°ä²¼Á˵÷²éÁ˾Ö£¬£¬£¬£¬£¬£¬³Æ Jefferson County Cable Î¥·´ÁË¿í´øÊý¾ÝÍøÂç´òËãµÄÒªÇóºÍÃÀ¹ú˾·¨¡¶¿í´øÊý¾Ý·¨°¸¡·¡£¡£¡£¡£¡£¡£¡£


https://ordonews.com/cable-isp-fined-10000-for-lying-to-fcc-about-where-it-offers-broadband/


5. µÂ¹úµ±¾Ö°ä·¢È¡µÞÃûΪNemesis MarketµÄ°µÍøÊг¡


3ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬µÂ¹úµ±¾Ö°ä·¢È¡µÞÒ»¸öÃûΪNemesis MarketµÄ·¸·¨µØÏÂÊг¡£¬£¬£¬£¬£¬£¬¸ÃÊг¡¶µÏú¶¾Æ·¡¢±»µÁÊý¾ÝºÍ¸÷ÀàÍøÂç·¸×ï·þÎñ¡£¡£¡£¡£¡£¡£¡£Áª¹úÐÌʾ¯Ô±¾Ö£¨±ðÃû Bundeskriminalamt »ò BKA£©°µÊ¾£¬£¬£¬£¬£¬£¬Ëü²é»ñÁËλÓڵ¹úºÍÁ¢ÌÕÍðµÄÓë°µÍø·þÎñÓйصÄÊý×Ö»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬²¢³ä¹«ÁË 94,000 Å·Ôª£¨102,107 ÃÀÔª£©µÄ¼ÓÃÜÇ®±Ò×ʲú¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÐж¯ÊÇÓëµÂ¹ú¡¢Á¢ÌÕÍðºÍÃÀ¹úµÄ·¨ÂÉ»ú¹¹ºÏ×÷½øÐеÄ£¬£¬£¬£¬£¬£¬ÓÚ 2022 Äê 10 ÔÂÆðÍ·½øÐÐ¿í·ºµ÷²éºó£¬£¬£¬£¬£¬£¬ÓÚ 2024 Äê 3 Ô 20 ÈÕ½øÐÓ×£¡£¡£¡£¡£¡£¡£Nemesis Market ³ÉÁ¢ÓÚ 2021 Ä꣬£¬£¬£¬£¬£¬¹À¼ÆÔڹعØÖ®Ç°Õ¼ÓÐÀ´×ÔÊÀ½ç¸÷µØµÄ³¬¹ý 150,000 ¸öÓû§ÕÊ»§ºÍ 1,100 ¸öÂô¼ÒÕÊ»§¡£¡£¡£¡£¡£¡£¡£½ü 20 ÃÀÔªµÄÂô¼ÒÕË»§À´×Ե¹ú¡£¡£¡£¡£¡£¡£¡£½ü¼¸¸öÔÂÀ´£¬£¬£¬£¬£¬£¬µÂ¹úµ±¾Ö»¹È¡µÞÁËKingdom MarketºÍCrimemarket£¬£¬£¬£¬£¬£¬ÕâÁ½¸öÍøÕ¾¶¼Óµº±¼ûǧÃûÓû§£¬£¬£¬£¬£¬£¬²¢Ìṩ¿í·ºµÄÏ´Ç®ºÍÍøÂç·¸×ï·þÎñ¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2024/03/german-police-seize-nemesis-market-in.html


6. ¼à¹Ü»ú¹¹¶Ô×¼¿Æ¼¼ÐÐÒµ£¬£¬£¬£¬£¬£¬¹È¸èºÍÆ»¹û·Ö²ðÌáÉÏÈÕ³Ì


3ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬´óÎ÷ÑóÁ½°¶µÄ·´Â¢¶Ï¼à¹Ü»ú¹¹ÔÚ½ø¹¥¿ÉÄܵ¼ÖÂÆ»¹ûºÍ Alphabet ÆìϹȸ豻·Ö²ðµÄ·´¾ºÕùÐÐΪ£¬£¬£¬£¬£¬£¬´óÐͿƼ¼¹«Ë¾ÕýÃæ¶ÔÊýÊ®ÄêÀ´µÄ×î´óÌôÕ½¡£¡£¡£¡£¡£¡£¡£Òµ½ç³õ´´¡£¡£¡£¡£¡£¡£¡£Õâ·´¹ýÀ´¿ÉÄÜ»áÒý·¢ÊÀ½ç¸÷µØµÄ¼à¹Ü»ú¹¹¼Ó´óÁ¦¶È£¬£¬£¬£¬£¬£¬Å·Ã˺ÍÃÀ¹ú°¸¼þÁ¢°¸ºóÁйú·´Â¢¶Ïµ÷²éÊýÁ¿²»ÐÝÔö³¤¾ÍÖ¤ÁËÈ»ÕâÒ»µã¡£¡£¡£¡£¡£¡£¡£×ÔAT&TÔÚÕûÕû40Äêǰ·Ö²ðÒÔÀ´£¬£¬£¬£¬£¬£¬Æù½ñΪֹ£¬£¬£¬£¬£¬£¬ÔÚÃÀ¹ú»¹Ã»ÓÐÒ»¼Ò¹«Ë¾Ãæ¶Ô¼à¹Ü»ú¹¹Ö÷µ¼·Ö²ðµÄ¿ÉÄÜÐÔ¡£¡£¡£¡£¡£¡£¡£¹È¸è°µÊ¾²»ÔÞ³ÉÅ·Ã˵ÄÖ¸¿Ø£¬£¬£¬£¬£¬£¬¶øÆ»¹ûÔò°µÊ¾ÃÀ¹úµÄËßËÏÔÚÊÂʵºÍ˾·¨É϶¼ÊÇÃýÎóµÄ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°Éв»È·¶¨¼à¹Ü»ú¹¹ÊÇ·ñ»á°ä²¼·Ö²ðÁ£¬£¬£¬£¬£¬ÓÉÓÚËûÃÇÔÚ˼¿¼¸÷ÀàÑ¡Ôñ£¬£¬£¬£¬£¬£¬ÈκÎÐж¯¶¼¿ÉÄܵ¼Ö·£¿£¿ £¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£¡£


https://www.reuters.com/technology/google-apple-breakups-agenda-global-regulators-target-tech-2024-03-24/