TikTokÒòÎ¥·´Ó¢¹úµÄÊý¾Ý±£» £»£»£» £»£»£»¤·¨±»·£¿£¿£¿£¿£¿î1270ÍòÓ¢°÷

Ðû²¼Ê±¼ä 2023-04-06

1¡¢TikTokÒòÎ¥·´Ó¢¹úµÄÊý¾Ý±£» £»£»£» £»£»£»¤·¨±»·£¿£¿£¿£¿£¿î1270ÍòÓ¢°÷


¾ÝýÌå4ÔÂ4ÈÕ±¨µÀ£¬ £¬£¬£¬£¬£¬£¬ £¬TikTokÒò¶à´ÎÎ¥·´Êý¾Ý±£» £»£»£» £»£»£»¤·¨£¬ £¬£¬£¬£¬£¬£¬ £¬±»Ó¢¹úÐÅϢרԱ°ì¹«ÊÒ(ICO)·£¿£¿£¿£¿£¿î1270ÍòÓ¢°÷£¨ºÏ1575ÍòÃÀÔª£©µÄ·£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£¡£¡£TikTokδÄܾÍ13ËêÒÔ϶ùͯʹÓÃÆäÆ½Ì¨»ñµÃâïÊѵÄÔ޳ɣ¬ £¬£¬£¬£¬£¬£¬ £¬Ò²Ã»ÓоÙÐгä·ÖµÄ¼ì²éÒÔʶ±ðºÍ±ÜÃâδ³ÉÄê¶ùͯʹÓÃÉ罻ýÌåÓ¦Óᣡ£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹ÌåÏÖ£¬ £¬£¬£¬£¬£¬£¬ £¬Ó¦¶Ô²½·¥µÄȱ·¦µ¼ÖÂÔ¼100Íò13ËêÒÔ϶ùͯ²»ÍâµØ»á¼û¸Ãƽ̨£¬ £¬£¬£¬£¬£¬£¬ £¬TikTokÍøÂ粢ʹÓÃÁËËûÃǵÄСÎÒ˽¼ÒÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£ÕâÒ»·£¿£¿£¿£¿£¿î±ÈICOÔÚ2022Äê9Ô·¢³öµÄ¶ÔTikTok·£¿£¿£¿£¿£¿î2700ÍòÓ¢°÷µÄԭʼÒâÏò֪ͨÓÐËùïÔÌ­¡£¡£¡£¡£¡£¡£¡£¡£


https://www.infosecurity-magazine.com/news/tiktok-fined-12m-uk-data-privacy/


2¡¢UnitedLexÔâµ½d0nutÀÕË÷¹¥»÷Áè¼Ý200GBÊý¾Ýй¶


¾Ý4ÔÂ4ÈÕ±¨µÀ£¬ £¬£¬£¬£¬£¬£¬ £¬UnitedLex¹«Ë¾Ôâµ½ÁËd0nutµÄÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£d0nutÉù³Æ£¬ £¬£¬£¬£¬£¬£¬ £¬ËûÃÇÒÑ´ÓUnitedLexµÄϵͳÏÂÔØÁËÁè¼Ý200GBµÄÊý¾Ý£¬ £¬£¬£¬£¬£¬£¬ £¬°üÀ¨Éæ¼°¸¶¿î¡¢ÌõÔ¼ºÍÆäËûÓëÖÚ¶à×éÖ¯ºÍСÎÒ˽¼ÒÓйصÄÉñÃØÎļþ¡£¡£¡£¡£¡£¡£¡£¡£UnitedLexÌåÏÖ½üÆÚÔÚϵͳÉÏ·¢Ã÷ÁË¿ÉÒɻ£¬ £¬£¬£¬£¬£¬£¬ £¬ÕýÔÚÈ·¶¨»î¶¯µÄÐÔ×Ӻ͹æÄ£¡£¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬ £¬£¬£¬£¬£¬£¬ £¬d0nutÔøÒªÇó500ÍòÃÀÔªµÄÊê½ð£¬ £¬£¬£¬£¬£¬£¬ £¬ÕâÓë̸ÅÐÖÐÌáµ½µÄ60ÍòÃÀÔªµÄÒªÇóÏÔ×Ųî±ð¡£¡£¡£¡£¡£¡£¡£¡£UnitedLexÒѱ»Ìí¼Óµ½ÁËBlackCatµÄÍøÕ¾£¬ £¬£¬£¬£¬£¬£¬ £¬Ñо¿Ö°Ô±ÕýÊÔͼȷ¶¨ÕâЩÊÇ·ñÓëD0nut Leaksй¶µÄÊý¾ÝÏàͬ¡£¡£¡£¡£¡£¡£¡£¡£


https://www.databreaches.net/unitedlex-hit-by-d0nut-ransomware-team-200-gb-of-corporate-files-leaked/


3¡¢»ÝÆÕÔ¤¼Æ90ÌìÄÚÐÞ¸´LaserJet´òÓ¡»úÖÐÎó²îCVE-2023-1707


ýÌå4ÔÂ4Èճƣ¬ £¬£¬£¬£¬£¬£¬ £¬»ÝÆÕÔ¤¼ÆÓÚ90ÌìÄÚÐÞÓ°ÏìijЩÉÌÒµ¼¶´òÓ¡»ú¹Ì¼þµÄÎó²î¡£¡£¡£¡£¡£¡£¡£¡£Îó²î×·×ÙΪCVE-2023-1707£¬ £¬£¬£¬£¬£¬£¬ £¬¿ÉÄܻᵼÖÂÐÅϢй¶£¬ £¬£¬£¬£¬£¬£¬ £¬Ó°ÏìÁËÔ¼50ÖÖHP Enterprise LaserJetºÍHP LaserJet Managed PrintersÐͺ𣡣¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ö¸³ö£¬ £¬£¬£¬£¬£¬£¬ £¬ÓÉÓÚÒ×Êܹ¥»÷µÄ×°±¸ÐèÒªÔËÐÐFutureSmart¹Ì¼þ°æ±¾5.6²¢ÆôÓÃIPsec£¬ £¬£¬£¬£¬£¬£¬ £¬Òò´ËʹÓÃÇéÐÎÊÇÊÜÏ޵ġ£¡£¡£¡£¡£¡£¡£¡£» £»£»£» £»£»£»ÝÆÕÌåÏÖ£¬ £¬£¬£¬£¬£¬£¬ £¬¹Ì¼þ¸üн«ÔÚ90ÌìÄÚÐû²¼£¬ £¬£¬£¬£¬£¬£¬ £¬Òò´ËÏÖÔÚûÓпÉÓõÄÐÞ¸´³ÌÐò¡£¡£¡£¡£¡£¡£¡£¡£¹ØÓÚÔËÐÐFutureSmart 5.6µÄÓû§£¬ £¬£¬£¬£¬£¬£¬ £¬½¨ÒéµÄ»º½â²½·¥Êǽ«Æä¹Ì¼þ°æ±¾½µ¼¶µ½FS 5.5.0.3¡£¡£¡£¡£¡£¡£¡£¡£» £»£»£» £»£»£»ÝÆÕ³Æ¸ÃÎó²îÉÐδ±»Ê¹Ó㬠£¬£¬£¬£¬£¬£¬ £¬ÇÒ̻¶ÆÚºÜ¶Ì£¨2023Äê2ÔÂÖÐÑ®ÖÁ3ÔÂ⣩¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hp-to-patch-critical-bug-in-laserjet-printers-within-90-days/


4¡¢IRSÊÚȨµÄ±¨Ë°Èí¼þeFile.com±»·¢Ã÷·Ö·¢JS¶ñÒâÈí¼þ


4ÔÂ4ÈÕ±¨µÀ³Æ£¬ £¬£¬£¬£¬£¬£¬ £¬ÃÀ¹ú¹ú˰¾Ö£¨IRS£©ÊÚȨµÄ±¨Ë°Èí¼þeFile.com±»·¢Ã÷·Ö·¢JavaScript¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£ÓÐÎÊÌâµÄ¶ñÒâJavaScriptÎļþÊÇpopper.js£¬ £¬£¬£¬£¬£¬£¬ £¬ÖÁÉÙÔÚ4ÔÂ1ÈÕ֮ǰeFile.comµÄÏÕЩÿ¸öÒ³Ãæ¶¼ÔÚ¼ÓÔØ¶ñÒâÎļþ¡£¡£¡£¡£¡£¡£¡£¡£3ÔÂ17ÈÕ£¬ £¬£¬£¬£¬£¬£¬ £¬RedditÓû§·¢ÌûÏÓÒÉeFile.comÍøÕ¾±»Ð®ÖÆ¡£¡£¡£¡£¡£¡£¡£¡£Æäʱ£¬ £¬£¬£¬£¬£¬£¬ £¬ÍøÕ¾ÏÔʾÁËÒ»ÌõSSL¹ýʧÐÂÎÅ£¬ £¬£¬£¬£¬£¬£¬ £¬Ö¸Ê¾ËûÃÇÏÂÔØÐéαµÄä¯ÀÀÆ÷¸üÐÂÒÔ׼ȷ»á¼û¸ÃЧÀÍ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷Éæ¼°Á½¸öÖ÷ÒªµÄ¿ÉÖ´ÐÐÎļþ£¬ £¬£¬£¬£¬£¬£¬ £¬update.exe×÷ΪÓëC2ЧÀÍÆ÷ͨѶµÄPHP¾ç±¾µÄÏÂÔØ³ÌÐò£¬ £¬£¬£¬£¬£¬£¬ £¬PHP¾ç±¾ÏÂÔØ²¢Ö´ÐÐÌØÁíÍâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/irs-authorized-efilecom-tax-return-software-caught-serving-js-malware/


5¡¢GoogleÐû²¼2023Äê4ÔµÄAndroidÇå¾²¸üÐÂÐÞ¸´ÊýÊ®¸öÎó²î


ýÌå4ÔÂ5ÈÕ±¨µÀ£¬ £¬£¬£¬£¬£¬£¬ £¬GoogleÐû²¼2023Äê4ÔµÄAndroidÇå¾²¸üС£¡£¡£¡£¡£¡£¡£¡£´Ë´Î¸üзÖΪÁ½²¿·Ö£¬ £¬£¬£¬£¬£¬£¬ £¬2023-04-01¼¶±ð²¹¶¡ÐÞ¸´ÁË¿ò¼ÜºÍϵͳ×é¼þÖеÄ26¸öÎó²î£¬ £¬£¬£¬£¬£¬£¬ £¬ÆäÖдó´ó¶¼Êǵ¼ÖÂȨÏÞÌáÉý»òÐÅϢй¶µÄÎó²î£» £»£»£» £»£»£»2023-04-05¼¶±ð²¹¶¡ÐÞ¸´ÁËÄںˡ¢Arm¡¢Imagination Technologies¡¢MediaTek¡¢UnisocºÍQualcomm×é¼þÖеÄ40¸öÎó²î¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇSystemÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-21085ºÍCVE-2023-21096£©¡£¡£¡£¡£¡£¡£¡£¡£


https://www.securityweek.com/androids-april-2023-updates-patch-critical-remote-code-execution-vulnerabilities/


6¡¢MantisʹÓÃMicropsiaºÍArid GopherбäÌå¹¥»÷Öж«µØÇø


4ÔÂ4ÈÕ£¬ £¬£¬£¬£¬£¬£¬ £¬SymantecÅû¶ÁËMantisÓÃÓÚ¹¥»÷Öж«µØÇøµÄй¤¾ß¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷Á˸ÃÍÅ»ï×î½üÒ»´Î»î¶¯£¬ £¬£¬£¬£¬£¬£¬ £¬´Ó2022Äê9ÔÂ×îÏÈ£¬ £¬£¬£¬£¬£¬£¬ £¬ÖÁÉÙÒ»Á¬µ½2023Äê2Ô¡£¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ÖУ¬ £¬£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßʹÓÃÆä¶¨ÖÆµÄMicropsiaºÍArid GopherºóÃŵÄбäÌåÀ´ÈëÇÖÄ¿µÄ£¬ £¬£¬£¬£¬£¬£¬ £¬È»ºóÔÙ¾ÙÐÐÆ¾Ö¤ÇÔÈ¡ºÍÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¡£´Ë»î¶¯µÄ³õʼѬȾǰÑÔÈÔȻδ֪¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÒ»¸öÄ¿µÄ×éÖ¯ÖУ¬ £¬£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÔÚÈý×éÅÌËã»úÉÏ×°ÖÃÁËͳһ¹¤¾ßµÄÈý¸ö²î±ð±äÌå¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬£¬ £¬¹¥»÷Õß»¹Ê¹ÓÃÁËÒ»¸ö×Ô½ç˵¹¤¾ßÀ´Ð¹Â¶´ÓÄ¿µÄ×éÖ¯ÇÔÈ¡µÄÊý¾Ý£¬ £¬£¬£¬£¬£¬£¬ £¬¼´ÃûΪWindowsUpServ.exeµÄ64λPyInstaller¿ÉÖ´ÐÐÎļþ¡£¡£¡£¡£¡£¡£¡£¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/mantis-palestinian-attacks