TwitterÊÕ¼¯Óû§ÐÅÏ¢¶¨ÏòÍÆË͹ã¸æ±»·£¿î1.5ÒÚÃÀÔª

Ðû²¼Ê±¼ä 2022-05-26

1¡¢TwitterÊÕ¼¯Óû§ÐÅÏ¢¶¨ÏòÍÆË͹ã¸æ±»·£¿î1.5ÒÚÃÀÔª


¾Ý5ÔÂ26ÈÕ±¨µÀ£¬ÃÀ¹úÁª°îóÒ×ίԱ»áFTCÒѶÔTwitter·£¿î1.5ÒÚÃÀÔª£¬Ô­ÒòÊÇËüʹÓÃÊÕ¼¯µÄ2FAÑéÖ¤µÄµç»°ºÅÂëºÍÓʼþµØÖ·À´ÍÆË͹ã¸æ¡£Æ¾¾Ý·¨Í¥Îļþ£¬´Ó2013Ä꿪ʼ£¬TwitterÒªÇóÁè¼Ý1.4ÒÚÓû§ÌṩÕâЩÐÅÏ¢ÒÔ±£»¤ËûÃǵÄÕË»§£¬µ«Ã»ÓÐ֪ͨËûÃÇÕâЩÊý¾ÝÒ²½«ÓÃÓÚ¹ã¸æÉÌͶ·Å¹ã¸æ¡£FTCÖ÷ϯ³Æ£¬TwitterÒÔÓÃÓÚÄþ¾²Ä¿µÄΪ½è¿Ú´ÓÓû§ÄÇÀï»ñÈ¡Êý¾Ý£¬µ«×îÖÕ»¹Ê¹ÓÃÕâЩÊý¾ÝÀ´Õë¶ÔÓû§Í¶·Å¹ã¸æ£¬ÕâÖÖ×ö·¨Ó°ÏìÁË´óÁ¿Óû§µÄͬʱ»¹ÌáÉýÁËTwitterµÄÊÕÈë¡£TwitterÒÑͬÒâÖ§¸¶1.5ÒÚÃÀÔªµÄ·£¿î¡£


https://www.bleepingcomputer.com/news/technology/ftc-fines-twitter-150m-for-using-2fa-info-for-targeted-advertising/


2¡¢Ç÷ÊƿƼ¼ÐÞ¸´Òѱ»Moshen DragonÀûÓõÄDLL½Ù³Ö©¶´


¾ÝýÌå5ÔÂ24ÈÕ±¨µÀ£¬Ç÷ÊƿƼ¼ÐÞ¸´ÆäÄþ¾²²úÎïÖеÄDLL½Ù³Ö©¶´¡£ÕýÈçSentinel LabsÔÚ5Ô³õÅû¶µÄÄÇÑù£¬Moshen DragonÔÚÕë¶ÔÖÐÑǵĵçÐÅÐÐÒµµÄ¹¥»÷ÖУ¬ÊÔͼ½Ù³ÖÄþ¾²¹©Ó¦É̵ķ¨Ê½£¬°üÂÞSymantec¡¢TrendMicro¡¢BitDefender¡¢McAfeeºÍKaspersky¡£¹¥»÷ÕßÀûÓÃÁ˶à¸ö¶ñÒâÈí¼þ£¬²¢Í¨¹ýDLL½Ù³ÖÀ´²à¼ÓÔØShadowPadºÍPlugX¡£Trend MicroÒÑÓÚ5ÔÂ19ÈÕͨ¹ýÆäActiveUpdate(AU)Ðû²¼ÁËÒ»¸öÐÞ¸´·¨Ê½£¬²¢½¨ÒéÓû§Á¢¼´½øÐиüС£


https://securityaffairs.co/wordpress/131635/hacking/trend-micro-flaw-moshen-dragon.html


3¡¢Ä³ÅäÖôíÎóµÄES·þÎñÆ÷й¶Êý°ÙÍò´û¿îÉêÇëÈ˵ÄÐÅÏ¢


¾Ý5ÔÂ24ÈÕ±¨µÀ£¬Ò»¸öÅäÖôíÎóµÄElasticsearch·þÎñÆ÷й¶ÁË147 GBµÄÊý¾Ý£¬¹²8.7ÒÚÌõ¼Ç¼¡£¸Ã·þÎñÆ÷ÓÚ2021Äê12ÔÂ5ÈÕ±»¼ì²âµ½£¬Ö÷Òª°üÂÞÎÚ¿ËÀ¼¡¢¹þÈø¿Ë˹̹ºÍ¶íÂÞ˹С¶î´û¿îµÄÉêÇëÈ˵ÄÐÅÏ¢£¬ÈçÐÕÃû¡¢×¡Ö·ºÍ»¤ÕÕºÅÂëµÈ¸öÈËÐÅÏ¢£¬ÒÔ¼°Ð½Ë®¡¢´û¿îÏêÇéºÍINN£¨Ë°ºÅ£©µÈ²ÆÕþÐÅÏ¢¡£¾ÝÔ¤¼Æ£¬Ô¼ÓÐ1000ÍòÓû§Êܵ½Ó°Ï죬ÆäÖдó²¿ÃÅ·þÎñÆ÷ÈÕÖ¾ºÍ»¤ÕÕºÅÂëÊôÓÚ¶íÂÞ˹£¬´ó¶àÊýINNÊôÓÚÎÚ¿ËÀ¼£¬¶ø¸Ã·þÎñÆ÷λÓÚºÉÀ¼µÄ°¢Ä·Ë¹Ìص¤¡£


https://www.hackread.com/personal-data-russians-ukrainians-exposed-online/


4¡¢MozillaÐû²¼¸üÐÂÐÞ¸´Pwn2Own´ó»áÖб»ÀûÓõĶà¸ö©¶´


5ÔÂ20ÈÕ£¬MozillaÐû²¼ÁËFirefoxºÍThunderbirdµÄÄþ¾²¸üУ¬ÒÔÐÞ¸´ÔÚPwn2Own 2022´ó»áÆڼ䱻ÀûÓõÄ©¶´¡£µÚÒ»¸ö©¶´ÊÇTop-Level AwaitʵÏÖÖеÄÔ­ÐÍÁ´ÎÛȾ£¨prototype pollution£©Â©¶´£¬×·×ÙΪCVE-2022-1802£¬¹¥»÷Õß¿ÉÀûÓÃËüÀ´Ö´ÐÐJavaScript´úÂë¡£µÚ¶þ¸ö©¶´( CVE-2022-1529 ) ÊÇJavaScript¹¤¾ßË÷ÒýÖÐʹÓò»ÊÜÐŵÄÊäÈëµ¼ÖµÄÔ­ÐÍÁ´ÎÛȾ©¶´£¬¿ÉÓÃÀ´ÔÚÌØȨ¸¸½ø³ÌÖÐÖ´ÐÐJavaScript¡£CISAÔÚ5ÔÂ23ÈÕÐû²¼Äþ¾²Í¨¸æ£¬½¨ÒéÁ¢¿ÌÐÞ¸´ÕâЩ©¶´¡£


https://www.bleepingcomputer.com/news/security/mozilla-fixes-firefox-thunderbird-zero-days-exploited-at-pwn2own/


5¡¢ChromeÀ©Õ¹ScreencastifyÐÞ¸´¿É½Ù³ÖÉãÏñÍ·µÄXSS©¶´


ýÌå5ÔÂ24Èճƣ¬Á÷ÐеÄChromeÀ©Õ¹ScreencastifyÐÞ¸´ÁËÒ»¸öXSS©¶´¡£ÕâÊÇÒ»¸öÓÃÓÚ¼ÆÁ¡¢ÊÓƵ±à¼­ºÍýÌå¹²ÏíµÄä¯ÀÀÆ÷À©Õ¹£¬ÔÚChromeÖеݲװÁ¿Áè¼Ý10000000´Î¡£¹¥»÷Õß¿ÉÒÔÀûÓ鶴ÆôÓÃScreencastify¼ÖÆÊÓƵ£¬²¢½«ÆäÉÏ´«µ½Google Drive¡£»¹¿ÉÒÔÀûÓÃͬÑùµÄ©¶´À´ÇÔÈ¡¹È¸èÇý¶¯Æ÷µÄOAuthÁîÅÆ£¬²¢ÓÃËüÀ´ÏÂÔØÉÏ´«µÄÊÓƵ£¬ÒÔ¼°´æ´¢ÔڹȸèÇý¶¯Æ÷ÉϵÄÆäËü¹¤¾ß¡£


https://www.bleepingcomputer.com/news/security/screencastify-chrome-extension-flaws-allow-webcam-hijacks/


6¡¢BlackBerryÐû²¼¹ØÓÚChaosбäÌåYashmaµÄ·ÖÎö³ÂËß


5ÔÂ24ÈÕ£¬BlackBerryÐû²¼Á˹ØÓÚÀÕË÷Èí¼þYashma¼°Æä¼Ò×åµÄ·ÖÎö³ÂËß¡£ChaosÊÇÒ»Öֿɶ¨ÖƵÄÀÕË÷Èí¼þ¹¹½¨Æ÷£¬ÓÚ2021Äê6ÔÂ9ÈÕÊ״ηºÆð£¬ÒѾ­ÀúÁË5´Îµü´ú£¬YashmaÉù³ÆÊÇËüµÄµÚÁù°æ(v6.0)£¬ÓÚ2022ÄêµÄÄêÖÐÔÚÒ°Íâ±»·¢ÏÖ¡£ChaosµÄÇ°Èý¸ö°æ±¾Ó봫ͳµÄÀÕË÷Èí¼þ±ÈÆðÀ´¸üÏñÊǾßÓÐÆÆ»µÐԵľÂí£¬µ«Chaos 4.0½øÒ»²½¸ïУ¬½«¿É¼ÓÃÜÎļþµÄÉÏÏÞÌá¸ßµ½2.1MB¡£Chaos 5.0ʹÓÃÁËAES-256¼ÓÃÜÄ¿±êÎļþ£¬¶øYashmaÓëÉÏÒ»¸ö°æ±¾¼¸ºõÏàͬ£¬½öÌí¼ÓÁËÁ½ÏîÐ޸ġ£ 


https://blogs.blackberry.com/en/2022/05/yashma-ransomware-tracing-the-chaos-family-tree