΢ÈíÒòÏòÓû§Ç¿¼Ó¹ã¸æcookie±»·¨¹ú·£¿£¿£¿ £¿î6000ÍòÅ·Ôª

Ðû²¼Ê±¼ä 2022-12-26
1¡¢Î¢ÈíÒòÏòÓû§Ç¿¼Ó¹ã¸æcookie±»·¨¹ú·£¿£¿£¿ £¿î6000ÍòÅ·Ôª

      

¾ÝýÌå12ÔÂ22ÈÕ±¨µÀ£¬£¬£¬£¬£¬·¨¹úÒþ˽î¿Ïµ»ú¹¹ÒѶÔÃÀ¹ú¿Æ¼¼¿Æ¼¼¹«Ë¾Î¢Èí´¦ÒÔ6000ÍòÅ·Ôª£¨6400ÍòÃÀÔª£©µÄ·£¿£¿£¿ £¿î£¬£¬£¬£¬£¬Ôµ¹ÊÔ­ÓÉÊÇÆäÏòÓû§Ç¿¼Ó¹ã¸æcookie¡£¡£¡£¡£¡£¡£¹ú¼ÒÊÖÒÕºÍ×ÔÓÉίԱ»á(CNIL)ÌåÏÖ£¬£¬£¬£¬£¬Î¢ÈíµÄËÑË÷ÒýÇæBingδÉèÖÃÔÊÐíÓû§Ïñ½ÓÊÜcookieÒ»Ñù¼òÆÓµØ¾Ü¾øcookieµÄϵͳ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Òѱ»¸øÓèÈý¸öÔµÄʱ¼äÀ´¾ÀÕýÕâ¸öÎÊÌ⣬£¬£¬£¬£¬ÓâÆÚ»¹¿ÉÄÜÃæÁÙÌìÌì60000Å·ÔªµÄ½øÒ»²½·£¿£¿£¿ £¿î¡£¡£¡£¡£¡£¡£Î¢ÈíÔÚÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬£¬£¬£¬£¬ËüÔÚÕâÏîÊÓ²ì×îÏÈ֮ǰ¾ÍÒѾ­¶Ôcookie×ö·¨¾ÙÐÐÁËÖØ´ó¸ü¸Ä¡£¡£¡£¡£¡£¡£


https://www.securityweek.com/france-fines-microsoft-60-million-euros-over-advertising-cookies


2¡¢°Ä´óÀûÑÇÀ¥Ê¿À¼¿Æ¼¼´óѧÔâµ½Royal TeamµÄÀÕË÷¹¥»÷

      

ýÌå12ÔÂ22Èճƣ¬£¬£¬£¬£¬À¥Ê¿À¼¿Æ¼¼´óѧÔâµ½ÀÕË÷¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂУ԰´òÓ¡»ú´òÓ¡´ó×ÚµÄÊê½ð¼Í¼¡£¡£¡£¡£¡£¡£QUT¸±Ð£³¤Margaret SheilÌåÏÖËýµÄ´òÓ¡»úÒ²Êܵ½Ó°Ï죬£¬£¬£¬£¬Ò»Ö±µØ´òÓ¡Êê½ð¼Í¼ֱµ½´òÓ¡»úÀïµÄÖ½Õźľ¡¡£¡£¡£¡£¡£¡£Êê½ð¼Í¼³ÆÀ´×ÔRoyal ransomware£¬£¬£¬£¬£¬ËüÔÚ֮ǰÖ÷Òª¹¥»÷ÃÀ¹úµÄÒ½ÁÆ»ú¹¹¡£¡£¡£¡£¡£¡£×÷ΪÏìÓ¦²½·¥£¬£¬£¬£¬£¬À¥Ê¿À¼¿Æ¼¼´óѧÒѹرÕËùÓÐITϵͳ£¬£¬£¬£¬£¬²¢¶Ô¸ÃÊÂÎñÕö¿ªÊӲ졣¡£¡£¡£¡£¡£


https://www.abc.net.au/news/2022-12-22/qld-qut-cyber-attack-printers-royal/101802692


3¡¢ºÚ¿Í³öÊ۾ݳƴÓBetMGMÇÔÈ¡µÄÁè¼Ý150Íò¿Í»§µÄÊý¾Ý

      

¾Ý12ÔÂ22ÈÕ±¨µÀ£¬£¬£¬£¬£¬ÌåÓý²©²Ê¹«Ë¾BetMGMÅû¶ÁËÒ»ÆðÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬³Æ²¿·Ö¿Í»§µÄСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ôö²¹Ëµ£¬£¬£¬£¬£¬ÆäÔÚ2022Äê11Ô·¢Ã÷¸ÃÊÂÎñ£¬£¬£¬£¬£¬µ«¹¥»÷Ó¦¸ÃÊDZ¬·¢ÔÚ2022Äê5Ô¡£¡£¡£¡£¡£¡£ÃûΪbetmgmhackedµÄ¹¥»÷ÕßÔÚºÚ¿ÍÂÛ̳Ðû²¼Êý¾Ý³öÊÛµÄͨ¸æ£¬£¬£¬£¬£¬³ÆÆäÈëÇÖÁËBetMGMµÄÊý¾Ý¿â£¬£¬£¬£¬£¬ÆäÖаüÀ¨1569310ÌõÓû§¼Í¼£¬£¬£¬£¬£¬Éæ¼°ÃÜЪ¸ùÖÝ¡¢ÐÂÔóÎ÷ÖݺͰ²¼òªʡµÈ¿Í»§µÄÐÕÃû¡¢ÁªÏµ·½·¨¡¢ºÍÉç»áÇå¾²ºÅÂëµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾½«ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩÁ½ÄêµÄÃâ·ÑÐÅÓÃ¼à¿ØºÍÉí·Ý»Ö¸´Ð§ÀÍ¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/139949/data-breach/betmgm-discloses-security-breach.html


4¡¢Ñо¿ÍŶÓÅû¶ÆôÓÃksmbdµÄSMBЧÀÍÆ÷µÄLinuxÄÚºËÎó²î

      

12ÔÂ25ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬Ñо¿ÍŶÓÅû¶ÁËÒ»¸öÑÏÖØµÄLinuxÄÚºËÎó²î£¨CVSSÆÀ·ÖΪ10£©£¬£¬£¬£¬£¬»áÓ°ÏìÆôÓÃÁËksmbdµÄSMBЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚSMB2_TREE_DISCONNECTÏÂÁîµÄ´¦Öóͷ£Àú³ÌÖУ¬£¬£¬£¬£¬ÊÇÔÚ¶Ô¹¤¾ßÖ´ÐвÙ×÷֮ǰûÓÐÑéÖ¤¹¤¾ßµÄ±£´æ¶øµ¼Öµģ¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚÄÚºËÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ôö²¹µÀ¡£¡£¡£¡£¡£¡£Ê¹ÓÃSambaµÄSMBЧÀÍÆ÷²»ÊÜÓ°Ï죬£¬£¬£¬£¬Ê¹ÓÃksmbdµÄSMBЧÀÍÆ÷ÈÝÒ×Êܵ½¶ÁÈ¡»á¼ûµÄÓ°Ï죬£¬£¬£¬£¬¿ÉÄÜй¶ЧÀÍÆ÷µÄÄڴ棨ÀàËÆÓÚHeartbleedÎó²î£©¡£¡£¡£¡£¡£¡£½¨ÒéʹÓÃksmbdµÄÖÎÀíÔ±¸üе½8ÔÂÐû²¼µÄLinuxÄں˰汾5.15.61»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/140013/hacking/critical-linux-kernel-vulnerability.html


5¡¢Securonix·¢Ã÷Õë¶ÔÓ¡¶ÈÕþ¸®µÄ¹¥»÷»î¶¯STEPPY#KAVACH

      

¾Ý12ÔÂ23ÈÕ±¨µÀ£¬£¬£¬£¬£¬Securonix·¢Ã÷ÁËÕë¶ÔÓ¡¶ÈÕþ¸®µÄÐÂÒ»ÂÖ¹¥»÷»î¶¯£¬£¬£¬£¬£¬²¢½«ÆäÃüÃûΪSTEPPY#KAVACH¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Óë°Í»ù˹̹ºÚ¿ÍÍÅ»ïSideCopyµÄTTPÓÐËùÖØµþ£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÓ¡¶ÈÕþ¸®¹ÙԱʹÓõÄË«ÒòËØÉí·ÝÑéÖ¤½â¾ö¼Æ»®Kavach¡£¡£¡£¡£¡£¡£¹¥»÷ʼÓÚ´¹Âڻ£¬£¬£¬£¬£¬È»ºóͨ¹ý.LNKÎļþÆô¶¯´úÂëÖ´ÐУ¬£¬£¬£¬£¬×îÖÕÏÂÔØ²¢ÔËÐжñÒâC# payload£¬£¬£¬£¬£¬³äµ±Ô¶³Ì»á¼ûľÂí¡£¡£¡£¡£¡£¡£Õâ²»ÊǵÚÒ»ÆðÕë¶ÔKavachµÄ¹¥»÷£¬£¬£¬£¬£¬×Ô½ñÄêÄêÍ·ÒÔÀ´£¬£¬£¬£¬£¬Transparent Tribe¾Íͨ¹ýKavachÖ÷ÌâµÄÓÕ¶üÓ¦Óù¥»÷Ó¡¶È¡£¡£¡£¡£¡£¡£ 


https://www.securonix.com/blog/new-steppykavach-attack-campaign/


6¡¢Wordfence͸¶WP²å¼þÎó²îCVE-2022-45359±»ÔÚҰʹÓÃ

      

WordfenceÔÚ12ÔÂ22ÈÕ͸¶£¬£¬£¬£¬£¬ WordPress²å¼þYITH WooCommerce Gift Cards PremiumÖÐÎó²îÒѱ»ÔÚҰʹÓᣡ£¡£¡£¡£¡£¸ÃÎó²î×·×ÙΪCVE-2022-45359(CVSSÆÀ·ÖΪ9.8)£¬£¬£¬£¬£¬¿É±»Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÃÀ´ÔÚÒ×±»¹¥»÷µÄÍøÕ¾ÉÏ´«Îļþ£¬£¬£¬£¬£¬°üÀ¨Ìṩ¶Ô¸ÃÍøÕ¾ÍêÈ«»á¼ûȨÏÞµÄWeb shell¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬´ó´ó¶¼¹¥»÷±¬·¢ÔÚ2022Äê11Ô£¬£¬£¬£¬£¬ÆäʱÖÎÀíÔ±ÉÐδÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬µ«ÔÚ12ÔÂ14ÈÕÓÖ·ºÆðÁ˵ڶþ¸öá¯Áë¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Ò»¸öÖ÷ÒªµÄIPµØµã¶Ô10936¸öÍøÕ¾ÌᳫÁË19604´Î¹¥»÷ʵÑé¡£¡£¡£¡£¡£¡£ÏÖÔÚÎó²îʹÓù¥»÷ÈÔÔÚ¾ÙÐÐÖУ¬£¬£¬£¬£¬½¨ÒéʹÓøòå¼þµÄÓû§¾¡¿ìÉý¼¶µ½3.21°æ±¾¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-bug-in-wordpress-gift-card-plugin-with-50k-installs/