Nissan ±±ÃÀÊý¾Ýй¶ӰÏìÁè¼Ý 53000 ÃûÔ±¹¤

Ðû²¼Ê±¼ä 2024-05-17
1. Nissan ±±ÃÀÊý¾Ýй¶ӰÏìÁè¼Ý 53000 ÃûÔ±¹¤


5ÔÂ16ÈÕ£¬Nissan North America (Nissan) È¥ÄêÔâÊÜÁËÊý¾Ýй¶£¬ÆäʱÍþвÕßÃé×¼Á˸ù«Ë¾µÄÍⲿ VPN ²¢¹Ø±ÕϵͳÒÔ»ñÈ¡Êê½ð¡£¸ÃÆû³µÖÆÔìÉÌÓÚ 2023 Äê 11 ÔÂÉÏÑ®·¢ÏÖÁËÕâһ©¶´£¬²¢ÓÚ×î½ü·¢ÏÖ¸Ãʼþ̻¶ÁËÁè¼Ý 53,000 ÃûÏÖÈκÍÀëÈÎÔ±¹¤µÄ¸öÈËÊý¾Ý¡£Nissan ͸¶£¬ÍþвÐÐΪÕßÃé×¼ÁËÆäÍⲿ VPN£¬È»ºó¹Ø±ÕÁËijЩ¹«Ë¾ÏµÍ³£¬È»ºóË÷ÒªÊê½ð¡£¸Ã¹«Ë¾Ö¸³ö£¬ÔÚ¹¥»÷ÆÚ¼äÆäϵͳ¾ùδ¼ÓÃÜ¡£¸Ã¹«Ë¾ÓëÍⲿÍøÂçÄþ¾²×¨¼ÒºÏ×÷£¬Äܹ»ÆÀ¹ÀÇé¿ö¡¢Í£Ö¹Ê¼þ²¢ÖÕÖ¹Íþв¡£ËæºóµÄÊÓ²ìÏÔʾ£¬ºÚ¿Í·ÃÎÊÁ˵±µØºÍÍøÂç¹²ÏíÉϵÄһЩÎļþ£¬ÆäÖдó²¿ÃÅ°üÂÞÉÌÒµÐÅÏ¢¡£ÔÚÏòÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒ·¢³öµÄÊý¾Ýй¶֪ͨÖУ¬¸Ã¹«Ë¾ÌåÏÖ£¬Ì»Â¶µÄÏêϸÐÅÏ¢°üÂÞ¸öÈ˱êʶ·û£¨ÀýÈçÐÕÃû£©ºÍÉç»áÄþ¾²ºÅÂ룬¶øÇÒÍþвÐÐΪÕß·ÃÎʵÄÎļþÖв»´æÔÚ²ÆÕþÏêϸÐÅÏ¢¡£ÈÕ²úÖ¸³ö£¬Ëü²»ÖªµÀ̻¶µÄÊý¾ÝÒѱ»ÀÄÓá£


https://www.bleepingcomputer.com/news/security/nissan-north-america-data-breach-impacts-over-53-000-employees/


2. ÂéÊ¡Àí¹¤Ñ§ÔºµÄѧÉúÀûÓÃETH©¶´¿ÉÇÔÈ¡2500ÍòÃÀÔª


5ÔÂ16ÈÕ£¬Æ¾¾ÝÃÀ¹ú˾·¨²¿Ðû²¼µÄÆðËßÊ飬ÔÚԼĪ 12 ÃëÄÚ£¬Á½ÃûÊܹý¸ßµÈ½ÌÓýµÄÐÖµÜÉæÏÓͨ¹ý¸Ä¶¯ÒÔÌ«·»Çø¿éÁ´£¬ÒÔÒ»ÖÖÇ°Ëùδ¼ûµÄ¼ÓÃÜ»õ±Ò¼Æ»®ÇÔÈ¡ÁË 2500 ÍòÃÀÔª¡£ÔÚ˾·¨²¿µÄÒ»·ÝÐÂΟåÖУ¬ÃÀ¹ú¼ì²ì¹Ù´ïÃ×°²¡¤ÍþÁ®Ä·Ë¹ (Damian Williams) ÌåÏÖ£¬¸Ã¼Æ»®·Ç³£ÅÓ´ó£¬ÒÔÖÁÓÚ¡°Ê¹Çø¿éÁ´µÄÍêÕûÐÔÊܵ½ÖÊÒÉ¡±¡£ÍþÁ®Ä·Ë¹Ëµ£º¡°Õâ¶ÔÐÖµÜÔÚÊÀ½çÉÏ×ʢÃûµÄ´óѧ֮һѧϰ¼ÆËã»ú¿ÆѧºÍÊýѧ£¬¾Ý³ÆÀûÓÃËûÃǵÄרҵ¼¼ÄܺͽÌÓýÀ´¸Ä¶¯ºÍÀûÓÃÈ«ÇòÊý°ÙÍòÒÔÌ«·»Óû§ËùÒÀÀµµÄЭÒé¡£¡± ¡°Ò»µ©ËûÃǽ«¼Æ»®¸¶Öîʵʩ£¬ËûÃǵÄÇÀ½ÙÖ»»¨ÁË 12 Ãë¾ÍÍê³ÉÁË¡£¡± 24 ËêµÄ°²¶«ºÍ 28 ËêµÄղķ˹¡¤ÅåÀ׶û-²¼°£Åµ±»²¶£¬±»Ö¸¿Ø´®Ä±ÊµÊ©µç»ãÆÛÕ©¡¢µç»ãÆÛÕ©ºÍ´®Ä±Ï´Ç®¡£ÃÀ¹ú˾·¨²¿ÌåÏÖ£¬ÐÖµÜÁ©¡°Ã¿Ïî×ïÃû×î¸ß¿ÉÅд¦ 20 Äê¼à½û¡±¡£


https://news.hitb.org/content/mit-students-stole-25m-seconds-exploiting-eth-blockchain-bug


3. LinuxϵͳÄں˵Ļù´¡ÉèÊ©Òѱ»ÅÓ´óµÄ¶ñÒâÈí¼þѬȾÁ½Äê


5ÔÂ16ÈÕ£¬´Ó 2009 Ä꿪ʼ£¬ÓÃÓÚά»¤ºÍ·Ö·¢ Linux ²Ù×÷ϵͳÄں˵Ļù´¡ÉèÊ©Òѱ»ÅÓ´óµÄ¶ñÒâÈí¼þѬȾÁËÁ½Ä꣬ÕâЩ¶ñÒâÈí¼þÉè·¨¿ØÖÆÁË¿ª·¢ÈËÔ±±£»¤×îÑÏÃܵÄ×ÊÔ´Ö®Ò»£º´æ´¢¼ÓÃÜµÄ /etc/shadow Îļþ¡£ÓÐÁè¼Ý 550 ÃûϵͳÓû§µÄÃÜÂëÊý¾Ý¡£Äþ¾²¹«Ë¾ ESET µÄÑо¿ÈËÔ±ÌåÏÖ£¬´Ë´Î¹¥»÷±³ºóµÄδ֪¹¥»÷ÕßѬȾÁË kernel.org ÄÚµÄÖÁÉÙËĄ̈·þÎñÆ÷£¬¸Ã»¥ÁªÍøÓòÖ§³Å×ÅÅÓ´óµÄ Linux ¿ª·¢ºÍ·Ö·¢ÍøÂç¡£ÔÚ»ñµÃÍøÂçÉÏ 551 ¸öÓû§ÕÊ»§µÄ¼ÓÃܹþÏ£Öµºó£¬¹¥»÷Õß¿ÉÄÜͨ¹ýÃÜÂëÆƽ⼼ÊõºÍʹÓöñÒâÈí¼þÄÚÖõĸ߼¶Æ¾¾ÝÇÔÈ¡¹¦Ð§£¬½«Ò»°ëÃÜÂëת»»ÎªÃ÷ÎÄÃÜÂë¡£´ÓÄÇÀ¹¥»÷ÕßÀûÓ÷þÎñÆ÷·¢ËÍÀ¬»øÓʼþ²¢½øÐÐÆäËûа¶ñ»î¶¯¡£ÕâËĄ̈·þÎñÆ÷¿ÉÄÜÔÚ²îÒìʱ¼ä±»Ñ¬È¾ºÍÏû¶¾£¬×îºóÁ½Ì¨·þÎñÆ÷ÔÚ 2011 ÄêµÄij¸öʱ¼äµÃµ½ÐÞ¸´¡£kernel.org µÄѬȾʼþÓÚ 2011 ÄêÆع⣬ÆäʱÄÚºËά»¤ÈËԱ͸¶£¬¹¥»÷ÕßÒÔijÖÖ·½Ê½Éè·¨»ñµÃ¶ÔÁ¬½Óµ½¸ÃÓòµÄ·þÎñÆ÷µÄ²»ÊÜÏÞÖƵÄϵͳ·ÃÎÊȨÏÞ£¨¼´¡°root¡±£©£¬µ¼Ö 448 ¸öÕÊ»§Ô⵽й¶¡£


https://news.hitb.org/content/linux-maintainers-were-infected-2-years-ssh-dwelling-backdoor-huge-reach


4. FBIµ·»ÙBreachForumsÀÕË÷ÍøÕ¾ºÍÆäTelegramƵµÀ


5ÔÂ15ÈÕ£¬FBI ÓëÊÀ½ç¸÷µØµÄ¾¯·½ÁªºÏ¿ØÖÆÁËÀÕË÷Èí¼þ¾­¼ÍÍøÕ¾ BreachForums µÄÍøÕ¾ºÍ Telegram ƵµÀ¡£¾¡¹Ü¸ÃÍøÕ¾µÄÔËÓª¶à´Î±»¹Ø±Õ£¬µ«¸ÃÍøÕ¾ÈÔÈ»²»Í£·ºÆð£¬ÏÖÔÚ¾¯²ìÔÝʱ¿ØÖÆÁ˸ÃÍøÕ¾¡£¸ÃÍøÕ¾ÏÖÔÚдµÀ£º¡°ÔÚ¹ú¼ÊºÏ×÷»ï°éµÄЭÖúÏ£¬Áª°îÊÓ²ì¾ÖºÍ˾·¨²¿ÒѹرոÃÍøÕ¾¡£¡± ¡°ÎÒÃÇÕýÔÚÉó²é¸ÃÍøÕ¾µÄºó¶ËÊý¾Ý¡£Èç¹ûÄúÓÐÐÅÏ¢ÐèÒª¾Ù±¨ BreachForums ÉϵÄÍøÂç·¸×ï»î¶¯£¬ÇëÁªÏµ¶«É­Æ½Ì¨¡£¡±Õâ´ÎÐж¯ÊÇÓÉÎåÑÛ¹ú¼ÒÒÔ¼°ÈðÊ¿¡¢±ùµººÍÎÚ¿ËÀ¼µÄ¾¯²ìÖ´ÐеÄ¡£BreachForums ½Ó¹ÜÁË֮ǰ±»¹Ø±ÕµÄ RaidForums ÍøÕ¾£¬¸ÃÍøÕ¾ÔÚ¾¯·½µÄÁíÒ»´ÎÁªºÏÐж¯ºóÓÚ 2022 Äê¹Ø±Õ¡£ÕâÁ½¸öÍøÕ¾¶¼½»Ò×±»µÁÐÅÏ¢£¬¶øÇÒÊÇËùνµÄË«ÖØÀÕË÷¹¥»÷µÄÒªº¦£¬ÔÚÕâÖÖ¹¥»÷ÖУ¬Êý¾Ý²»½ö±»¼ÓÃÜÒÔ»ñÈ¡Êê½ð£¬¶øÇÒ»¹±»ÇÔÈ¡£¬²¢ÓÃÀ´ÍþвÊܺ¦Õߣ¬Èç¹ûËûÃDz»¸¶¿î£¬¾Í»á̻¶Êý¾Ý¡£


https://www.theregister.com/2024/05/15/fbi_breachforums_ransomware/


5. Wi-Fi ³ß¶ÈÖеÄȱÏÝ¿ÉÄܵ¼Ö SSID »ìÏý¹¥»÷


5ÔÂ16ÈÕ£¬±ÈÀûʱ³ãë´óѧµÄÑо¿ÈËÔ±·¢ÏÖÁË IEEE 802.11 Wi-Fi ³ß¶ÈÖеÄÒ»¸ö»ù±¾Éè¼ÆȱÏÝ£¬¸ÃȱÏÝΪ¹¥»÷ÕßÌṩÁËÒ»ÖÖÒªÁìÀ´ÓÕÆ­Êܺ¦ÕßÁ¬½Óµ½±ÈËûÃÇÏëÒªÁ¬½ÓµÄÍøÂçÄþ¾²ÐԽϵ͵ÄÎÞÏßÍøÂ硣ƾ¾Ý VPN ÆÀÂÛÍøÕ¾ Top10VPN µÄ˵·¨£¬´ËÀ๥»÷¿ÉÄÜ»áʹÊܺ¦ÕßÃæÁÙ¸ü¸ßµÄÁ÷Á¿À¹½ØºÍÀûÓ÷çÏÕ¡£¸ÃÍøÕ¾Óë KU Leuven µÄһλÑо¿ÈËÔ±ºÏ×÷£¬½«ÔÚº«¹úÊ׶û¼´½«¾ÙÐеĻáÒéÉϽøÐÐÑÝʾ֮ǰÐû²¼ÁË©¶´ÏêϸÐÅÏ¢¡£¸Ã©¶´±àºÅΪ CVE-2023-52424£¬Ó°ÏìËùÓвÙ×÷ϵͳÉϵÄËùÓÐ Wi-Fi ¿Í»§¶Ë¡£ÊÜÓ°ÏìµÄ Wi-Fi ÍøÂç°üÂÞ»ùÓڹ㷺²¿ÊðµÄ WPA3 ЭÒé¡¢WEP ºÍ 802.11X/EAP µÄÍøÂç¡£Ñо¿ÈËÔ±Ìá³öÁË Wi-Fi ³ß¶ÈµÄ¸üÐÂÒÔ¼°¸öÈ˺Í×éÖ¯¿ÉÒÔÓÃÀ´½µµÍ·çÏÕµÄÒªÁì¡£


https://news.hitb.org/content/flaw-wi-fi-standard-can-enable-ssid-confusion-attacks


6. ºÚ¿Í¹¥»÷ Foxit PDF Reader Óû§ÇÔÈ¡Ãô¸ÐÊý¾Ý


5ÔÂ15ÈÕ£¬Ñо¿ÈËÔ±·¢ÏÖÁËÒ»¸öÕë¶Ô Foxit Reader Óû§µÄ PDF ©¶´£¬¸Ã©¶´ÀûÓÃÁËÒ»¸öÉè¼ÆȱÏÝ£¬¸ÃȱÏÝ»áͨ¹ýĬÈϵġ°È·¶¨¡±Ñ¡ÏîÏÔʾÄþ¾²¾¯¸æ£¬´Ó¶ø¿ÉÄÜÓÕÆ­Óû§Ö´ÐжñÒâ´úÂë¡£ÓÉÓڸ鶴Ö÷ÒªÕë¶Ô Foxit Reader£¬ÓëÐÐÒµ³ß¶È Adobe Acrobat Reader Ïà±È£¬¸Ã©¶´ÊÇÒ»ÖÖÏÊΪÈËÖªµÄ PDF ¼ì²ìÆ÷£¬Òò´Ë¸Ã©¶´±»¹ã·ºÊ¹Óò¢ÈƹýÁ˵äÐ͵ļì²âÒªÁì¡£ÓÉÓÚ¾¯¸æÏûÏ¢µÄÉè¼ÆȱÏÝ£¬¸£ê¿ÔĶÁÆ÷´æÔÚÑÏÖصÄÄþ¾²Â©¶´£¬Èç¹ûÓû§ÔÚûÓÐ×Ðϸ¿¼ÂǵÄÇé¿öϵ¥»÷Á½´Î£¬¾Í»áÔÚ²»Öª²»¾õÖÐΣº¦ÆäÄþ¾²¡£¸Ã©¶´Ê¹¹¥»÷ÕßÄܹ»´ÓÔ¶³Ì·þÎñÆ÷ÏÂÔز¢Ö´ÐжñÒâ´úÂ룬´Ó¶ø¿ÉÄÜʹËûÃÇÄܹ»Î´¾­ÊÚȨ·ÃÎÊÓû§µÄϵͳºÍÊý¾Ý¡£¸Ã©¶´ÒÑÔÚÏÖʵÊÀ½çµÄ¹¥»÷Öб»»ý¼«ÀûÓã¬ÓÃÓÚÖÖÖÖ¶ñÒâÄ¿µÄ£¬°üÂÞ¼äµý»î¶¯ºÍµç×Ó·¸×ï¡£


https://gbhackers.com/hackers-attack-foxit-pdf-reader-users/