Tor µÄРWebTunnel ÇÅÄ£Äâ HTTPS Á÷Á¿À´ÈƹýÉó²é
Ðû²¼Ê±¼ä 2024-03-143ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬Tor ÏîÄ¿ÕýÊ½ÍÆ³öÁË WebTunnel£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»ÖÖеÄÇŽÓÀàÐÍ£¬£¬£¬£¬£¬£¬×¨ÃÅÉè¼ÆÓÃÓÚͨ¹ýÒþ²ØÏÔ×ŵÄÅþÁ¬À´×ÊÖúÈÆ¹ýÕë¶Ô Tor ÍøÂçµÄÉó²éÖÆ¶È¡£¡£¡£¡£¡£¡£¡£¡£Tor ÍøÇÅÊÇδÔÚ¹«¹² Tor Ŀ¼ÖÐÁгöµÄÖм̣¬£¬£¬£¬£¬£¬¿ÉÒÔʹÓû§ÓëÍøÂçµÄÅþÁ¬ÃâÊÜեȡÕþȨµÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£ËäÈ»ÖйúºÍÒÁÀʵÈһЩ¹ú¼ÒÒѾÕÒµ½Á˼ì²âºÍ×èÖ¹´ËÀàÅþÁ¬µÄÒªÁ죬£¬£¬£¬£¬£¬µ« Tor »¹ÌṩÁËobfsproxyÇÅ£¬£¬£¬£¬£¬£¬ÕâÔöÌíÁËÒ»²ãÌØÁíÍâ»ìÏýÒÔ¶Ô¿¹Éó²éÖÆ¶È¡£¡£¡£¡£¡£¡£¡£¡£WebTunnel ÊÇÊÜ HTTPT ¿¹Ì½²âÊðÀíÆô·¢µÄ¿¹Éó²é¿É²å°Î´«Ê䣬£¬£¬£¬£¬£¬Ëü½ÓÄÉÁ˲î±ðµÄÒªÁì¡£¡£¡£¡£¡£¡£¡£¡£Í¨¹ýÈ·±£Á÷Á¿Óë HTTPS ¼ÓÃܵÄÍøÂçÁ÷Á¿»ìÏý£¬£¬£¬£¬£¬£¬×èÖ¹ Tor ÅþÁ¬±äµÃÔ½·¢ÄÑÌâ¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ×èÖ¹ HTTPS Ò²»á×èÖ¹¾ø´ó´ó¶¼Óë Web ЧÀÍÆ÷µÄÅþÁ¬£¬£¬£¬£¬£¬£¬Òò´Ë WebTunnel ÅþÁ¬Ò²½«±»ÔÊÐí£¬£¬£¬£¬£¬£¬´Ó¶øÍ¨¹ýÐÒéÔÊÐíÁбíºÍĬÈϾܾøÕ½ÂÔÓÐÓõعæ±ÜÍøÂçÇéÐÎÖеÄÉó²é¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/tors-new-webtunnel-bridges-mimic-https-traffic-to-evade-censorship/
2. Ð嵀 Vcurms ¶ñÒâÈí¼þÃé׼ʢÐÐä¯ÀÀÆ÷¾ÙÐÐÊý¾Ý͵ÇÔ
3ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬Fortinet µÄ FortiGuard ʵÑéÊÒ×î½ü·¢Ã÷ÁËÒ»ÖÖеÄÍøÂçÇå¾²Íþв£ºÒ»ÖÖÃûΪ¡°Vcurms¡±µÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£Vcurms ¶ñÒâÈí¼þ±³ºóµÄ¹¥»÷Õß½ÓÄÉÁËÖØ´óµÄÕ½ÂÔ£¬£¬£¬£¬£¬£¬Ê¹Óõç×ÓÓʼþ×÷ΪÏÂÁîºÍ¿ØÖÆÖÐÐÄ£¬£¬£¬£¬£¬£¬²¢Ê¹Óà AWS ºÍ GitHub µÈ¹«¹²Ð§ÀÍÀ´´æ´¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ËûÃÇ»¹½ÓÄÉÁËÉÌÒµ±£»£»£»¤³ÌÐòÀ´Ìӱܼì²â£¬£¬£¬£¬£¬£¬ÕâÅú×¢ËûÃÇÕýÔÚÅäºÏÆð¾¢×î´óÏ޶ȵØÀ©´ó¶ñÒâÈí¼þµÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Ö÷ÒªÕë¶Ô×°ÖÃÁË Java µÄƽ̨£¬£¬£¬£¬£¬£¬¶ÔʹÓôËÀàϵͳµÄÈκÎ×éÖ¯×é³ÉΣº¦¡£¡£¡£¡£¡£¡£¡£¡£ÍþвµÄÑÏÖØÐÔ½ûÖ¹µÍ¹À£¬£¬£¬£¬£¬£¬ÓÉÓÚÀֳɵÄÉøÍ¸Ê¹¹¥»÷ÕßÄܹ»ÍêÈ«¿ØÖÆÊÜѬȾµÄϵͳ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßµÄ×÷°¸ÊÖ·¨°üÀ¨ÒýÓÕÓû§ÏÂÔØ¶ñÒâ Java ÏÂÔØ³ÌÐò£¬£¬£¬£¬£¬£¬¸ÃÏÂÔØ³ÌÐò³äµ±Èö²¥ Vcurms ºÍ STRRAT µÄÔØÌ壬£¬£¬£¬£¬£¬STRRAT ÊÇÒ»ÖÖÏÈǰ±»·¢Ã÷ð³ä¼ÙÀÕË÷Èí¼þѬȾÒÔÇÔÈ¡Êý¾ÝµÄľÂí¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ¶ñÒâµç×ÓÓʼþͨ³£Î±×°³ÉÕýµ±ÇëÇ󣬣¬£¬£¬£¬£¬±Þ²ßÊÕ¼þÈËÑéÖ¤¸¶¿îÐÅÏ¢²¢ÏÂÔØ AWS ÉÏÍйܵÄÓк¦Îļþ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.hackread.com/vcurms-malware-browsers-for-data-theft/
3. Meta ÆðËßÈ¥Ö°Ô±¹¤ÉæÏÓÇÔÈ¡¾øÃÜÊý¾ÝÖÐÐÄÀ¶Í¼
3ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬Ò»Î»Ç° Meta ¸±×Üͳ±»ËûµÄǰÀϰåÆðËߣ¬£¬£¬£¬£¬£¬×ïÃûÊÇ¡°¹ûÕæ²»ÖҺͲ»ÖÒʵÑéΪ¡±¡ª¡ªËûÃǵÄÒâ˼ÊÇ£¬£¬£¬£¬£¬£¬ËûÉæÏÓÇÔÈ¡ÉñÃØÎļþ£¬£¬£¬£¬£¬£¬ÒÔ×ÊÖúËûΪһ¼ÒÈ˹¤ÖÇÄÜÔÆÊ×´´¹«Ë¾½¨ÉèºÍÕÐļͬÊ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ Facebook ¾ÞÍ·ÊÂÇéµÄ 12 Äê¼ä£¬£¬£¬£¬£¬£¬Dipinder Singh Khurana£¨ÓÖÃû TS Khurana£©ÌáÉýΪÈÏÕæ»ù´¡ÉèÊ©µÄ¸±×ܲᣡ£¡£¡£¡£¡£¡£¡£ËûÓÚ 2023 Äê 6 ÔÂÍÑÀëÕâ¼Ò´óÐÍÆóÒµ£¬£¬£¬£¬£¬£¬ÔÚÒ»¼ÒÈÔ´¦ÓÚÉñÃØÄ£Ê½µÄÊ×´´¹«Ë¾µ£µ±¹©Ó¦Á´ÔËÓª¸ß¼¶¸±×ܲ㬣¬£¬£¬£¬£¬Õë¶ÔËûµÄËßËÏÖÐûÓÐÌáµ½ËûµÄÃû×Ö¡£¡£¡£¡£¡£¡£¡£¡£Meta ÔÚÌá½»¸ø Meta µÄÒ»·ÝÆðËßÊéÖгƣ¬£¬£¬£¬£¬£¬ÔÚ¸æËß Meta ÀϰåËûÍýÏëÍÑÀëºó£¬£¬£¬£¬£¬£¬¿âÀÄɾݳÆÊ¹ÓÃ×Ô¼ºÔÚ¹«Ë¾µÄÊ£Óàʱ¼äÇÔÈ¡ÁË¡°´ó×ÚÓÐ¹Ø Meta ÓªÒµºÍÔ±¹¤µÄרÓС¢¸ß¶ÈÃô¸Ð¡¢ÉñÃØºÍ·Ç¹ûÕæÎļþ¡± ¡£¡£¡£¡£¡£¡£¡£¡£Meta ¶Ô¿âÀÄÉÌá³öÁËÎåÏîÖ¸¿Ø£ºÎ¥·´ÌõÔ¼¡¢Î¥·´ÖÒ³ÏÒåÎñ¡¢Î¥·´ÐÅÍÐÒåÎñ¡¢²»µ±µÃÀûÒÔ¼°Î¥·´¼ÓÖÝÅÌËã»ú·¸·¨·¨¡£¡£¡£¡£¡£¡£¡£¡£Facebook ¾ÞÍ·ÒªÇó¿âÀÄɱ»ÆÈÖ§¸¶Åâ³¥½ð£¬£¬£¬£¬£¬£¬²¢½»³öËûÒòÉæÏÓÇÔÈ¡¹«Ë¾ÉñÃØ¶ø»ñµÃµÄÈκοî×Ó»òÀûÒæ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.theregister.com/2024/03/12/meta_vp_infrastructure_allegations/
4. Windows KB5035849 ¸üÐÂÎÞ·¨×°Ö㬣¬£¬£¬£¬£¬²¢·ºÆð 0xd000034 ¹ýʧ
3ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬Î¢ÈíÐû²¼µÄ KB5035849 ÀÛ»ý¸üÐÂÎÞ·¨ÔÚ Windows 10 ºÍ Windows Server ϵͳÉÏ×°Ö㬣¬£¬£¬£¬£¬²¢·ºÆð 0xd0000034 ¹ýʧ¡£¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤ÖÎÀíÔ±ºÍÓû§µÄÒ»²¨ ±¨¸æ £¬£¬£¬£¬£¬£¬µ±Í¨¹ý Windows ºÍ Microsoft ¸üÐÂЧÀÍÆ÷ÔÚÏß¼ì²é¸üÐÂʱ£¬£¬£¬£¬£¬£¬KB5035849 ½«ÎÞ·¨×°Öᣡ£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄϵͳ°üÀ¨ÔËÐÐ Windows Server 2019 »ò Windows 10 Enterprise LTSC 2019 µÄϵͳ£¬£¬£¬£¬£¬£¬ÕâЩϵͳÒÑÓÚ 1 Ô 9 ÈÕµÖ´ïÖ÷Á÷Ö§³ÖÖÕÖ¹ÈÕÆÚ£¬£¬£¬£¬£¬£¬²¢ÑÓÉìÖ§³ÖÎåÄêÖ±ÖÁ 2029 Äê 1 Ô¡£¡£¡£¡£¡£¡£¡£¡£ËäÈ»Ðí¶à¿Í»§ÒѾ±¨¸æ KB5035849 ûÓÐ×°ÖÃÔÚËûÃǵÄ×°±¸ÉÏ£¬£¬£¬£¬£¬£¬µ«Î¢ÈíÌåÏÖ¡°ÏÖÔÚ²»ÖªµÀ´Ë¸üÐÂÓÐÈκÎÎÊÌ⡱¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ½ñÌìµÄÖ§³ÖÎĵµÖУ¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾»¹½«Æä±ê¼ÇΪ¿Éͨ¹ý Windows Update ºÍ Microsoft Update ×°Öᣡ£¡£¡£¡£¡£¡£¡£Óöµ½ÕâЩÎÊÌâµÄÓû§ÈÔÈ»¿ÉÒÔͨ¹ý´ÓMicrosoft µÄ¸üÐÂĿ¼ÏÂÔØ²¢×°Öà KB5035849 À´ÊÖ¶¯°²ÅÅËü¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/microsoft/windows-kb5035849-update-failing-to-install-with-0xd000034-errors/
5. ºê³žÖ¤Êµ·ÆÂɱöÔ±¹¤Êý¾ÝÔÚºÚ¿ÍÂÛ̳ÉÏй¶
3ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬ºê³ž·ÆÂɱö¹«Ë¾Ö¤Êµ£¬£¬£¬£¬£¬£¬ÔÚºÚ¿ÍÂÛ̳ÉÏй¶Êý¾Ýºó£¬£¬£¬£¬£¬£¬ÖÎÀí¸Ã¹«Ë¾Ô±¹¤³öÇÚÊý¾ÝµÄµÚÈý·½¹©Ó¦ÉÌÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬Ô±¹¤Êý¾Ý±»µÁ¡£¡£¡£¡£¡£¡£¡£¡£ºê³žÊÇÒ»¼Ǫ̀ÍåÅÌËã»úÓ²¼þºÍµç×Ó²úÆ·ÖÆÔìÉÌ£¬£¬£¬£¬£¬£¬ÒÔÆäÔÚÐÔÄÜ¡¢ÖÊÁ¿ºÍÓоºÕùÁ¦µÄ¼ÛǮ֮¼äÈ¡µÃÓÅÒìÆ½ºâµÄÌõ¼Ç±¾µçÄÔ¶øÖøÃû¡£¡£¡£¡£¡£¡£¡£¡£ÔçЩʱ¼ä£¬£¬£¬£¬£¬£¬Ò»¸öÃûΪ¡°ph1ns¡±µÄÍþвÐÐΪÕßÔÚºÚ¿ÍÂÛ̳ÉÏÐû²¼ÁËÒ»¸öÁ´½Ó£¬£¬£¬£¬£¬£¬¿ÉÒÔÃâ·ÑÏÂÔØ°üÀ¨ Acer Ô±¹¤Êý¾ÝµÄ±»µÁÊý¾Ý¿â¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õ߸æËß BleepingComputer£¬£¬£¬£¬£¬£¬Ã»ÓÐÉæ¼°ÀÕË÷Èí¼þ»ò¼ÓÃÜ£¬£¬£¬£¬£¬£¬ÕâÖ»ÊÇÒ»´Î´¿´âµÄÊý¾Ý͵ÇÔ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ËûÃǽøÒ»²½Ïò BleepingComputer ֤ʵ£¬£¬£¬£¬£¬£¬ËûÃDz¢Ã»ÓÐÊÔͼÀÕË÷¸Ã¹«Ë¾¡£¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬ËûÃÇȷʵÌṩÁËÖ¤¾Ý£¬£¬£¬£¬£¬£¬Åú×¢ËûÃÇÔÚʧȥ»á¼ûȨÏÞ֮ǰ²Á³ýÁ˱»ÈëÇÖЧÀÍÆ÷ÉϵÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£ºê³ž½üÄêÀ´±¬·¢¶àÆðÇå¾²ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¡£2023 Äê 2 Ô£¬£¬£¬£¬£¬£¬ºÚ¿ÍÈëÇÖÁ˹«Ë¾Ð§ÀÍÆ÷£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨ÊÖÒÕÊֲᡢÈí¼þ¹¤¾ß¡¢BIOS Ó³ÏñºÍÌæ»»Êý×Ö²úÆ·ÃÜÔ¿ (RDPK) µÈ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/acer-confirms-philippines-employee-data-leaked-on-hacking-forum/
6. 2023 ÄêGitHub й¶Áè¼Ý 1200 Íò¸öÉí·ÝÑéÖ¤ºÍÃÜÔ¿
3ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬GitHub Óû§ÒâÍâ̻¶ÁËÁè¼Ý 300 Íò¸ö¹«¹²´æ´¢¿âÖÐµÄ 1280 Íò¸öÉí·ÝÑéÖ¤ºÍÃô¸ÐÉñÃØ£¬£¬£¬£¬£¬£¬ÆäÖоø´ó´ó¶¼ÔÚÎåÌìºóÈÔÈ»ÓÐÓᣡ£¡£¡£¡£¡£¡£¡£ÕâÊÇGitGuardianÍøÂçÇ徲ר¼ÒµÄ˵·¨ £¬£¬£¬£¬£¬£¬ËûÃÇÏòÄÇЩй¶ÉñÃØµÄÈË·¢³öÁË 180 Íò·âÃâ·Ñµç×ÓÓʼþ¾¯±¨£¬£¬£¬£¬£¬£¬·¢Ã÷Ö»Óм«Ð¡µÄ 1.8% µÄÈ˽ÓÄÉÁË¿ìËÙÐж¯À´¾ÀÕý¹ýʧ¡£¡£¡£¡£¡£¡£¡£¡£Ì»Â¶µÄÉñÃØ°üÀ¨ÕÊ»§ÃÜÂë¡¢API ÃÜÔ¿¡¢TLS/SSL Ö¤Êé¡¢¼ÓÃÜÃÜÔ¿¡¢ÔÆÐ§ÀÍÆ¾Ö¤¡¢OAuth ÁîÅÆºÍÆäËûÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬ÕâЩÊý¾Ý¿ÉÄÜʹÍⲿ¼ÓÈëÕßÎÞÏÞÖÆµØ»á¼ûÖÖÖÖ˽ÓÐ×ÊÔ´ºÍЧÀÍ£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÊý¾Ýй¶ºÍ²ÆÎñËðʧ¡£¡£¡£¡£¡£¡£¡£¡£2023 Äê Sophos ±¨¸æÇ¿µ÷£¬£¬£¬£¬£¬£¬Æ¾Ö¤Ð¹Â¶ Õ¼ ÉϰëÄêËê¼µÄËùÓй¥»÷»ù´¡Ôµ¹ÊÔÓÉµÄ 50%£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÎó²îʹÓ㬣¬£¬£¬£¬£¬ÕâÊÇ 23% °¸ÀýÖеĹ¥»÷ÒªÁì¡£¡£¡£¡£¡£¡£¡£¡£GitGuardian ÌåÏÖ£¬£¬£¬£¬£¬£¬È«Çò×îÊܽӴýµÄ´úÂëÍйܺÍÐ×÷ƽ̨ GitHub ÉϵÄÉñÃØÆØ¹â×Ô 2020 ÄêÒÔÀ´Ò»Ö±³Ê¸ºÃæÇ÷ÊÆ¡£¡£¡£¡£¡£¡£¡£¡£¾Íй¶ÉñÃØ×î¶àµÄÐÐÒµ¶øÑÔ£¬£¬£¬£¬£¬£¬IT ÒÔ 65.9% µÄ·Ý¶îλ¾Ó°ñÊ×£¬£¬£¬£¬£¬£¬Æä´ÎÊǽÌÓý£¬£¬£¬£¬£¬£¬Õ¼ 20.1%£¬£¬£¬£¬£¬£¬ÒÔ¼°ËùÓÐÆäËûÐÐÒµµÄ×ܺͣ¨¿ÆÑ§¡¢ÁãÊÛ¡¢ÖÆÔì¡¢½ðÈÚ¡¢¹«¹²ÖÎÀí¡¢Ò½ÁƱ£½¡¡¢ÓéÀÖ£© ¡¢½»Í¨£©Õ¼14%¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/over-12-million-auth-secrets-and-keys-leaked-on-github-in-2023/


¾©¹«Íø°²±¸11010802024551ºÅ