¿ËÂÞµØÑǵçÐÅÔËÓªÉÌA1 Hrvatskaй¶Լ20ÍòÓû§ÐÅÏ¢

Ðû²¼Ê±¼ä 2022-02-15

¿ËÂÞµØÑǵçÐÅÔËÓªÉÌA1 Hrvatskaй¶Լ20ÍòÓû§ÐÅÏ¢


¾ÝýÌå2ÔÂ11ÈÕ±¨µÀ£¬£¬£¬£¬¿ËÂÞµØÑǵçÐÅÔËÓªÉÌA1 Hrvatskaй¶ÁË10%Óû§£¨Ô¼20ÍòÈË£©µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ã»ÓÐÌṩ¹ØÓÚ´Ë´ÎÊÂÎñµÄϸ½Ú£¬£¬£¬£¬Ö»³ÆËûÃǵÄÒ»¸öÓû§Êý¾Ý¿âÔâµ½ÁËδ¾­ÊÚȨ»á¼û£¬£¬£¬£¬µ¼ÖÂÐÕÃû¡¢Ð¡ÎÒ˽¼ÒʶÓÖÃûÂë¡¢ÏÖʵµØµãºÍµç»°ºÅÂëµÈÐÅϢй¶¡£¡£¡£¡£¡£¡£ÎÖ´ï·á¼¸ÈÕǰÔâµ½¹¥»÷µ¼ÖÂÆäÔÚÆÏÌÑÑÀµÄЧÀÍÖÐÖ¹£¬£¬£¬£¬A1 HrvatskaÊÇÆäÕ½ÂÔÏàÖúͬ°é£¬£¬£¬£¬Éв»¿ÉÈ·¶¨ÕâÁ½´ÎÇå¾²ÊÂÎñÖ®¼äÊÇ·ñ±£´æÁªÏµ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/croatian-phone-carrier-data-breach-impacts-200-000-clients/


ÖйúÏã¸Ûº£ÒÝÂùÝÊý¾Ý¿âÔâ¹¥»÷³¬100Íò¿Í»§ÐÅϢй¶


2ÔÂ11Èյı¨µÀ³Æ£¬£¬£¬£¬ÖйúÏã¸ÛµÄº£ÒÝÂùݼ¯ÍÅÔ¤¶©Êý¾Ý¿âÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬Ô¼120Íò¿Í»§µÄÐÅϢй¶¡£¡£¡£¡£¡£¡£Òþ˽רԱAda ChungÉÏÖÜÎåÌåÏÖ£¬£¬£¬£¬ÆäÔÚÉÏÖÜÈýÊÕµ½Í¨ÖªºóÒѾ­¶Ô´ËÊÂÕö¿ªÊӲ졣¡£¡£¡£¡£¡£ÊÐÃñ¿Éͨ¹ýЧÀÍ´¦ÈÈÏß28272827¡¢¼¯Íźô½ÐÖÐÐÄ39080740»ò¹«Ë¾¹ÙÍøÅÌÎÊÊÇ·ñÊܵ½´ËÊÂÎñµÄÓ°Ïì¡£¡£¡£¡£¡£¡£


https://gbcode.rthk.hk/TuniS/news.rthk.hk/rthk/en/component/k2/1633250-20220211.htm


SentinelOneÐû²¼ModifiedElephant¹¥»÷Ó¡¶ÈµÄÆÊÎö±¨¸æ


SentinelOneÔÚ2ÔÂ9ÈÕÐû²¼±¨¸æ£¬£¬£¬£¬Åû¶ÁËModifiedElephant¹¥»÷Ó¡¶ÈµÄϸ½Ú¡£¡£¡£¡£¡£¡£ModifiedElephantÖÁÉÙ´Ó2012Äê×îÏÈÔËÓª£¬£¬£¬£¬Ê¹ÓÃÁËÉÌÒµÔ¶³Ì»á¼ûľÂí(RAT)£¬£¬£¬£¬²¢ÇÒÓëÉÌÒµ¼à¿ØÐÐÒµÓÐÁªÏµ¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÓã²æÊ½´¹ÂڻÀ´·Ö·¢¶ñÒâÈí¼þ£¬£¬£¬£¬ÀýÈçNetWireºÍDarkCometµÈ£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÓ¡¶È¸÷µØµÄÈËȨ»î¶¯Ïà¹ØÖ°Ô±¡¢Ñ§ÕߺÍ״ʦµÈ£¬£¬£¬£¬×îÖÕÖ¼ÔÚÖ²ÈëÓÐ×ïµÄÊý×ÖÖ¤¾Ý¡£¡£¡£¡£¡£¡£


https://www.sentinelone.com/labs/modifiedelephant-apt-and-a-decade-of-fabricating-evidence/


FritzFrogÔٴλع飬£¬£¬£¬Õë¶ÔÒ½ÁÆ¡¢½ÌÓýºÍÕþ¸®µÄ×éÖ¯


2ÔÂ10ÈÕ£¬£¬£¬£¬Çå¾²¹«Ë¾AkamaiÐû²¼Á˹ØÓÚP2P½©Ê¬ÍøÂçFritzFrogµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£FritzFrogÓÚ2020Äê8ÔÂÊ״α»·¢Ã÷£¬£¬£¬£¬´Ë´Î»Ø¹éÔÚÒ»¸öÔÂÄÚµÄѬȾÂÊÔöÌíÁË10±¶£¬£¬£¬£¬ÒѾ­¹¥»÷ÁË1500̨ҽÁƱ£½¡¡¢½ÌÓýºÍÕþ¸®ÐÐÒµµÄЧÀÍÆ÷£¬£¬£¬£¬ÆäÖд󲿷ÖλÓÚÖйú¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þʹÓÃGolang±àд£¬£¬£¬£¬ÔöÌíÁËй¦Ð§£¬£¬£¬£¬°üÀ¨Ê¹ÓÃÊðÀíÍøÂçºÍ¶¨Î»WordPressЧÀÍÆ÷£¬£¬£¬£¬²¢ÇÒÆä¶ÔµÈ¼Ü¹¹ºÍרÓдúÂë¾ßÓнϸßˮƽµÄÖØ´óÐÔ¡£¡£¡£¡£¡£¡£


https://www.akamai.com/blog/security/fritzfrog-p2p


·¨¹ú³ÆGoogle AnalyticsÎ¥·´GDPR½«ÍøÂçµÄÊý¾Ý´«Êäµ½ÃÀ¹ú


¾ÝýÌå2ÔÂ10Èճƣ¬£¬£¬£¬·¨¹úÊý¾Ý±£»£»£»£»£»¤î¿Ïµ»ú²Ã¶¨Google AnalyticsÎ¥·´ÁËGDPR¡£¡£¡£¡£¡£¡£¹ú¼ÒÐÅϢѧºÍ×ÔÓÉίԱ»á(CNIL)ÌåÏÖ£¬£¬£¬£¬Google Analytics´«Êäµ½ÃÀ¹úµÄÊý¾ÝûÓлñµÃ¡°³ä·Öî¿Ïµ¡±£¬£¬£¬£¬Î¥·´ÁËGDPRµÚ44ÌõÌõ¿î¡£¡£¡£¡£¡£¡£CNIL³Æ£¬£¬£¬£¬Ö»¹ÜGoogleÒѾ­½ÓÄÉÁËÌØÁíÍâ²½·¥À´¹æ·¶Google AnalyticsÖеÄÊý¾Ý´«Ê䣬£¬£¬£¬µ«ÕâЩ»¹È±·¦ÒÔɨ³ýÃÀ¹úÇ鱨ЧÀÍ»á¼ûÕâЩÊý¾ÝµÄ¿ÉÄÜÐÔ¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/02/france-rules-that-using-google.html


ÀÕË÷ÍÅ»ïBlackByte³ÆÆäÒÑÈëÇÖNFL¾É½ðɽ49È˶Ó


ýÌå2ÔÂ13ÈÕ±¨µÀ³Æ£¬£¬£¬£¬ÀÕË÷ÍÅ»ïBlackByteÒÑÈëÇ־ɽðɽ49È˶Ó¡£¡£¡£¡£¡£¡£¾É½ðɽ49È˶ӣ¨San Francisco 49ers£©ÊÇNFLÖÐ×îÓмÛÖµºÍ×î´«ÆæµÄÇò¶ÓÖ®Ò»£¬£¬£¬£¬¾ÍÔÚNFL×¼±¸Ó­½Ó2022Ä곬µÈÍëµÄʱ¼ä£¬£¬£¬£¬BlackByteÉù³Æ¹¥»÷ÁË49ers²¢×îÏÈй¶±»µÁÎļþ£¬£¬£¬£¬¾ÝϤÊÇ292MBµÄ²ÆÎñÐÅÏ¢¡£¡£¡£¡£¡£¡£¸ÃÇò¶ÓÔÚÒ»·ÝÉùÃ÷ÖÐ֤ʵÁËÕâ´Î¹¥»÷£¬£¬£¬£¬²¢ÌåÏÖ¹¥»÷µ¼ÖÂËûÃDz¿·ÖÍøÂçÔÝʱÖÐÖ¹£¬£¬£¬£¬ÏÖÔÚÈÔÔÚ»Ö¸´ÏµÍ³µÄÀú³ÌÖС£¡£¡£¡£¡£¡£


https://www.securityweek.com/ransomware-gang-says-it-has-hacked-49ers-football-team


Çå¾²¹¤¾ß


VulnLab


Yavuzlar ¿ª·¢µÄ Web Îó²îʵÑéÊÒÏîÄ¿¡£¡£¡£¡£¡£¡£


https://github.com/Yavuzlar/VulnLab


Http2Smugl


¸Ã¹¤¾ßÓÐÖúÓÚ¼ì²âºÍʹÓà HTTP ÇëÇó×ß˽£¬£¬£¬£¬ÒÔ·ÀËüͨ¹ýǰ¶ËЧÀÍÆ÷ͨ¹ý HTTP/2 -> HTTP/1.1 ת»»À´ÊµÏÖ¡£¡£¡£¡£¡£¡£


https://github.com/neex/http2smugl


FACT


ÓÃÓÚÍøÂç¡¢´¦Öóͷ£ºÍ¿ÉÊÓ»¯À´×ÔÔÚÔÆÖлòÍâµØÔËÐеĻúе¼¯ÈºµÄȡ֤Êý¾Ý¡£¡£¡£¡£¡£¡£


https://github.com/unicornunicode/FACT


iris-web


ËüÊÇÊÂÎñÏìÓ¦ÆÊÎöʦµÄЭ×÷ƽ̨£¬£¬£¬£¬ÔÊÐíÔÚÊÖÒÕ²ãÃæ¹²ÏíÊӲ졣¡£¡£¡£¡£¡£


https://dfir-iris.github.io/


hobbits


ÓÃÓÚÆÊÎö¡¢´¦Öóͷ£ºÍ¿ÉÊÓ»¯±ÈÌØµÄÈí¼þƽ̨¡£¡£¡£¡£¡£¡£


https://mahlet-inc.github.io/


Çå¾²ÆÊÎö


ÃÀ¹ú¹ú·À²¿Ñ¡Ôñ DataRobot ΪÕþ¸®µÄÈ˹¤ÖÇÄÜÍýÏëÌṩ¶¯Á¦


https://www.helpnetsecurity.com/2022/02/13/datarobot-department-of-defense/



¹È¸èÌåÏÖ£¬£¬£¬£¬×éÖ¯ÕýÔÚ¸ü¿ìµØ½â¾öÁãÈÕÎó²î


https://securityaffairs.co/wordpress/127932/security/zero-day-flaws-metrics.html



¹È¸èÔÚ 2021 ÄêÏò Bug Hunters Ö§¸¶ÁË 870 ÍòÃÀÔª


https://www.darkreading.com/vulnerabilities-threats/google-paid-record-8-7-million-to-bug-hunters-in-2021



CISA ÏÂÁîÁª°î»ú¹¹ÔÚ 2 Ô 25 ÈÕ֮ǰ¸üРiPhone¡¢Mac


https://www.bleepingcomputer.com/news/security/cisa-orders-federal-agencies-to-update-iphones-macs-until-feb-25th/



΢Èí£º¶Ô Windows 10 20H2 µÄÖ§³Ö½«ÓÚ 2022 Äê 5 Ô¿¢ÊÂ


https://www.bleepingcomputer.com/news/microsoft/microsoft-support-for-windows-10-20h2-ending-in-may-2022/



ÐÂÎó²î¿ÉÈúڿÍÔ¶³ÌÆÆËðÎ÷ÃÅ×Ó PLC


https://www.securityweek.com/new-vulnerabilities-can-allow-hackers-remotely-crash-siemens-plcs