ºÚ¿ÍÇÔÈ¡Òâ´óÀûLeonardo SpAµÄ10GB¾üÊÂÉñÃØ£» £»£»Ó¢¹úNCSCÐû²¼2020Äê¶È»ØÊ׵įÊÎö±¨¸æ

Ðû²¼Ê±¼ä 2020-12-07

1.ºÚ¿ÍÇÔÈ¡Òâ´óÀûLeonardo SpAµÄ10GB¾üÊÂÉñÃØ


1.jpg


ºÚ¿ÍÇÔÈ¡¹ú·À¹«Ë¾Leonardo SpAµÄ10 GB¾üÊÂÉñÃØ£¬£¬£¬£¬£¬£¬ÏÖÒѱ»Òâ´óÀû¾¯·½¾Ð²¶¡£¡£¡£¡£¡£¡£LeonardoÊÇÌìÏÂÉÏ×î´óµÄ¹ú·À³Ð°üÉÌÖ®Ò»£¬£¬£¬£¬£¬£¬Æä30£¥µÄ¹É·ÝÊôÓÚÒâ´óÀû¾­¼ÃºÍ²ÆÎñ²¿¡£¡£¡£¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢Éæ¼°µ½ÐÐÕþ»á¼ÆÖÎÀí¡¢ÈËÁ¦×ÊÔ´¡¢×ÊÔ´»õÎïµÄ²É¹ººÍ·ÖÅÉ¡¢ÃñÓ÷ɻúÁ㲿¼þºÍ¾üÓ÷ɻúµÄÉè¼Æ¡¢Ô±¹¤Ð¡ÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃUSBÃÜÔ¿Ïò94¸öÊÂÇéÕ¾·Ö·¢cftmon.exeľÂí£¬£¬£¬£¬£¬£¬²¢ÒÔÕý°æWindowsÎļþÃüÃû¸ÃľÂíÒÔÈÆ¹ý¼ì²â¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/police-arrest-two-in-data-theft-cyberattack-on-leonardo-defense-corp/


2.ºÚ¿ÍʹÓÃÍøÂç´¹ÂÚÇÔÈ¡MetaMaskÓû§µÄ¼ÓÃÜÇ®±Ò


2.jpg


ºÚ¿ÍʹÓÃGoogle¹ã¸æÍ¨¹ýÍøÂç´¹ÂÚ¹¥»÷ÇÔÈ¡MetaMaskÓû§µÄ¼ÓÃÜÇ®±ÒÇ®°üÎļþ¡£¡£¡£¡£¡£¡£MetaMaskÓµÓÐÁè¼ÝÒ»°ÙÍòÓû§£¬£¬£¬£¬£¬£¬Í¨¹ýä¯ÀÀÆ÷À©Õ¹³ÌÐòÔÚä¯ÀÀÆ÷ÖÐÌṩÁËÒ»¸öÒÔÌ«·»¼ÓÃÜÇ®±ÒÇ®°ü£¬£¬£¬£¬£¬£¬ÔÚ×°ÖøÃÀ©Õ¹ºó£¬£¬£¬£¬£¬£¬¿Éµ¼ÈëÏÖÓеÄÇ®°ü£¬£¬£¬£¬£¬£¬Ò²¿É½¨ÉèÐÂÇ®°ü¡£¡£¡£¡£¡£¡£ºÚ¿ÍʹÓÃGoogle¹ã¸æ½«Óû§Öض¨Ïòµ½MetaMaskÍøÂç´¹ÂÚÒ³Ãæ£¬£¬£¬£¬£¬£¬µ±Óû§µã»÷µ¼ÈëÇ®°üÑ¡Ïîʱ£¬£¬£¬£¬£¬£¬»á±»ÒªÇóÊäÈëÏÖÓÐÇ®°üµÄÒªº¦×Ö£¬£¬£¬£¬£¬£¬ÕâЩÐÅÏ¢»á±»·¢Ë͸ø¹¥»÷ÕßÓÃÀ´ÇÔÈ¡¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/metamask-phishing-steals-cryptocurrency-wallets-via-google-ads/


3.Ç¿Éú³ÆCOVID-19ʱ´úÕë¶ÔÆäµÄ¹¥»÷´ÎÊýÔöÌí30£¥


3.jpg


Ç¿Éú³ÆCOVID-19ʱ´úÕë¶ÔÆäµÄ¹¥»÷´ÎÊýÔöÌíÁË30£¥¡£¡£¡£¡£¡£¡£¾Ý¡¶»ª¶û½ÖÈÕ±¨¡·±¨µÀ£¬£¬£¬£¬£¬£¬³¯ÏʺڿÍÒѾ­½«ÃÀ¹ú¡¢Ó¢¹úºÍº«¹ú´ÓÊÂCovid-19ÖÎÁÆÊÂÇéµÄÖÁÉÙÁù¼ÒÖÆÒ©¹«Ë¾ÁÐΪ¹¥»÷Ä¿µÄ£¬£¬£¬£¬£¬£¬Ö¼ÔÚÍøÂç¿ÉÒÔ³öÊÛ»òÎäÆ÷»¯µÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£ÕâЩ¹«Ë¾°üÀ¨Ç¿Éú¹«Ë¾ºÍÂíÀïÀ¼ÖݵÄNovavax¹«Ë¾£¬£¬£¬£¬£¬£¬Æä¶¼ÔÚÑо¿ÊµÑéÐÔÒßÃç¡£¡£¡£¡£¡£¡£Ç¿Éú¹«Ë¾µÄCIO Marene AllisonÌåÏÖ£¬£¬£¬£¬£¬£¬¹ú¼ÒºÚ¿Íʱʱ¿Ì¿Ì¶¼ÔÚ¹¥»÷Ò½ÁÆ×éÖ¯£¬£¬£¬£¬£¬£¬Õë¶ÔÇ¿Éú¹«Ë¾µÄÍøÂç¹¥»÷ÔöÌíÁË30%¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/111960/hacking/covid-19-johnson-johnson-cyber-attacks.html


4.ApacheÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´TomcatÖÐÑÏÖØµÄÎó²î


4.jpg


ApacheÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËTomcatÖÐÑÏÖØµÄÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓôËÎó²îµ¼Ö¾ܾøÐ§ÀÍ״̬¡£¡£¡£¡£¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2020-17527£¬£¬£¬£¬£¬£¬ÓÉÓÚApache Tomcat¿ÉÒÔ½«HTTP/2ÅþÁ¬ÉÏÊÕµ½µÄÏÈǰÁ÷ÖеÄHTTPÇëÇó±êÍ·ÖµÖØÐÂÓÃÓÚÓëºóÐøÁ÷Ïà¹ØÁªµÄÇëÇóËùµ¼ÖµÄ¡£¡£¡£¡£¡£¡£Ö»¹ÜÕâºÜ¿ÉÄܻᵼÖ¹ýʧ²¢¹Ø±ÕHTTP/2ÅþÁ¬£¬£¬£¬£¬£¬£¬¿ÉÊÇÐÅÏ¢¿ÉÄÜ»áÔÚÇëÇóÖ®¼ä×ß©¡£¡£¡£¡£¡£¡£¸ÃÎÊÌâÒÑÓÚTomcat 10.0.0-M10ÖÐÐÞ¸´¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/12/04/apache-releases-security-advisory-apache-tomcat


5.DashlaneÐû²¼2020Äê¶ÈÃÜÂëй¶ÎÊÌâµÄÆÊÎö±¨¸æ


5.jpg


DashlaneÐû²¼2020Äê¶ÈÃÜÂëй¶ÎÊÌâµÄÆÊÎö±¨¸æ£¬£¬£¬£¬£¬£¬ÖصãÏÈÈÝÁ˸ÃÄêÓëÃÜÂëÏà¹ØµÄ×îÑÏÖØÊ¹ʵĹ«Ë¾ºÍ×éÖ¯¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬°ñµ¥ÉÏÅÅÃûµÚÒ»ºÍµÚ¶þµÄÊÇTwitterºÍZoom£¬£¬£¬£¬£¬£¬ËüÃÇÔÊÐíÆäÔ±¹¤ºÍÓû§Ê¹ÓÃÈõÃÜÂ룬£¬£¬£¬£¬£¬Ê¹ÆäÒ×ÊÜÍøÂç¹¥»÷µÄÓ°Ïì¡£¡£¡£¡£¡£¡£ÂÃÓΡ¢ÓÎÏ·ºÍ¿ìµÝÁìÓòµÄÆäËû×ÅÃûÆóÒµÒ²³ÉΪºÚ¿ÍµÄÊܺ¦Õß¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬DashlaneµÄÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬£¬Æ½¾ùÿ¸ö»¥ÁªÍøÓû§ÓÐÁè¼Ý200¸öÐèҪʹÓÃÃÜÂëµÄÊý×ÖÕË»§£¬£¬£¬£¬£¬£¬ÕâÒ»Êý×ÖÔ¤¼ÆÔÚδÀ´ÎåÄêÄÚ½«·­Ò»·¬£¬£¬£¬£¬£¬£¬µÖ´ï400¸ö¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.dashlane.com/twitter-employees-and-zoom-users-top-dashlanes-list-of-2020s-worst-password-offenders/


6.Ó¢¹úNCSCÐû²¼2020Äê¶È»ØÊ׵įÊÎö±¨¸æ


6.jpg


Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ðû²¼ÁË2020Äê¶È»ØÊ×±¨¸æ£¬£¬£¬£¬£¬£¬¸Ã±¨¸æµÄÖØµãÊÇÓ¦¶Ôһֱת±äµÄÌôÕ½ÐÔÍøÂçÍþв£¬£¬£¬£¬£¬£¬»ØÊ×ÁËNCSCµÄ2019Äê9ÔÂ1ÈÕµ½2020Äê8ÔÂ31ÈÕÖ®¼äµÄÊÂÇéÖ÷ҪϣÍûºÍÁÁµã¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬ÔÚÕâÖØ´óÌôÕ½µÄÒ»Ä꣬£¬£¬£¬£¬£¬NCSC¼ÌÐø¶ÔѸËÙÑݱäµÄÍøÂçÍþв×÷³ö·´Ó¦¡£¡£¡£¡£¡£¡£²¢Ìá³öÁ˹ØÓÚNCSCÊÂÇéµÄÁ½¸öÖ÷ÒªÐÅÏ¢¡£¡£¡£¡£¡£¡£µÚÒ»£¬£¬£¬£¬£¬£¬Ô¤·À·¸·¨ÊÇ·Ç·¸·¨ÖÐÐĵÄÖ÷ҪʹÃü£¬£¬£¬£¬£¬£¬ÆäÓëÖ´·¨²¿·ÖϸÃÜÏàÖú£¬£¬£¬£¬£¬£¬²¢ÔÚ723×Ú¹¥»÷ÊÂÎñÖÐÖ§Ô®Á˽ü1200ÃûÊܺ¦Õߣ» £»£»µÚ¶þ£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²ÊÇÒ»ÏîÍŶÓÔ˶¯¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ncsc.gov.uk/annual-review/2020/docs/ncsc_2020-annual-review_s.pdf