Google DriveÓû§³ÆÔÆÐ§ÀÍÖеĴ洢Êý¾Ýɥʧ
Ðû²¼Ê±¼ä 2023-11-28¾ÝýÌå11ÔÂ27ÈÕ±¨µÀ£¬£¬£¬£¬£¬Google DriveÓû§±¨¸æ³Æ£¬£¬£¬£¬£¬×î½ü´æ´¢ÔÚÔÆÖеÄÎļþͻȻÏûÊÅÁË£¬£¬£¬£¬£¬ÔÆÐ§Àͻָ´µ½ÁË2023Äê4Ôµ½5ÔÂ×óÓҵĴ洢¿ìÕÕ¡£¡£¡£¡£¡£ÊÜÓ°ÏìÕÊ»§µÄ»î¶¯ÈÕÖ¾ÏÔʾÓû§×î½üûÓÐÈκÎÐ޸쬣¬£¬£¬£¬È·Èϲ»ÊÇÓû§ÒâÍâɾ³ýÁËÊý¾Ý¡£¡£¡£¡£¡£×ÜÖ®£¬£¬£¬£¬£¬Ã»Óм£ÏóÅú×¢ÊÇÓû§ÍÉ»¯£¬£¬£¬£¬£¬¶øÊÇЧÀÍϵͳ³öÁËÎÊÌ⣬£¬£¬£¬£¬µ¼ÖÂÍâµØ×°±¸ºÍGoogle CloudÖ®¼äµÄÊý¾ÝÎÞ·¨Í¬²½¡£¡£¡£¡£¡£Ò»Ð©Óû§µÄÀëÏß»º´æÖпÉÄܰüÀ¨É¥Ê§µÄÊý¾Ý£¬£¬£¬£¬£¬µ«ÏÖÔÚ»¹Ã»ÓÐÒªÁìÀ´»Ö¸´¶ÔÆäÖÐÊý¾ÝµÄ»á¼û¡£¡£¡£¡£¡£GoogleÒѾÔÚÊÓ²ìÕâ¸öÎÊÌ⣬£¬£¬£¬£¬ÉÐδÌṩÐÞ¸´µÄÔ¤¼ÆÊ±¼ä£¬£¬£¬£¬£¬½¨ÒéÓû§ÔÚÎÊÌâ»ñµÃ½â¾ö֮ǰ²»Òª¶Ôroot/dataÎļþ¼Ð¾ÙÐиü¸Ä¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/google/google-drive-users-angry-over-losing-months-of-stored-data/
2¡¢TransUnionºÍExperianÒÉËÆÔâµ½¹¥»÷²¢±»ÀÕË÷6ÍòÍòÃÀÔª
11ÔÂ23ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬ÄÏ·Ç×î´óµÄÁ½¼ÒÏûºÄÕßÐÅÓñ¨¸æ»ú¹¹TransUnionºÍExperianÒÉËÆÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬Óû§µÄ²ÆÎñºÍСÎÒ˽¼ÒÊý¾ÝÃæÁÙΣº¦¡£¡£¡£¡£¡£N4ughtySecTUÍÅ»ï´ËÇ°Ôø¹¥»÷¹ýTransUnion£¬£¬£¬£¬£¬Õâ´ÎÔÙ´ÎÈÆ¹ýÁ˸ù«Ë¾µÄ·À»ðǽºÍÇ徲ϵͳ£¬£¬£¬£¬£¬ÀÖ³ÉÇÔÈ¡ÁËÊý¾Ý¡£¡£¡£¡£¡£¹¥»÷ÕßÏòTransUnionÀÕË÷3000ÍòÃÀÔª£¬£¬£¬£¬£¬²¢ÏòExperianÀÕË÷3000ÍòÃÀÔª¡£¡£¡£¡£¡£TransUnionºÍExperian͸¶ÒÑÊÕµ½ÀÕË÷ÒªÇ󣬣¬£¬£¬£¬µ«ÌåÏÖûÓз¢Ã÷Êý¾Ýй¶¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬¹¥»÷ÕßÉÐδÌṩ¹ØÓÚ¹¥»÷»î¶¯ºÍÊý¾Ýй¶µÄÖ¤¾Ý¡£¡£¡£¡£¡£
https://www.businesslive.co.za/bd/national/2023-11-23-hackers-demand-60m-from-transunion-and-experian-claiming-data-theft/
3¡¢DEXƽ̨KyberSwapÔâµ½¹¥»÷Ëðʧ¸ß´ï5470ÍòÃÀÔª
¾Ý11ÔÂ27ÈÕ±¨µÀ£¬£¬£¬£¬£¬DEXƽ̨KyberSwap͸¶ÆäÔâµ½¹¥»÷£¬£¬£¬£¬£¬¼ÛÖµÔ¼5400ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò±»µÁ¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚÉÏÖÜÈýÍí¼ä£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýһϵÁÐÖØ´óµÄÐж¯½«Óû§µÄ×ʽðÌáÈ¡µ½¹¥»÷ÕßµÄÇ®°üÖС£¡£¡£¡£¡£¶Ô´Ë£¬£¬£¬£¬£¬¸Ãƽ̨ÔÝÍ£ÁË´æ¿î£¬£¬£¬£¬£¬Õö¿ªÁËÊӲ죬£¬£¬£¬£¬ÁªÏµÁËÏà¹Ø¸÷·½£¬£¬£¬£¬£¬²¢Óë¹¥»÷ÕßÕö¿ªÌ¸ÅÐÀ´¾¡¿ÉÄÜ×·»ØËðʧ£¬£¬£¬£¬£¬°üÀ¨Ìṩ10%µÄÉͽð×÷Ϊ·µ»¹±»µÁ×ʽðµÄ½±Àø¡£¡£¡£¡£¡£¶à¼ÒÇø¿éÁ´Çå¾²¹«Ë¾ºÍÑо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬´Ë´Î¹¥»÷»î¶¯ºÜÊÇÖØ´ó¡£¡£¡£¡£¡£
https://therecord.media/kyberswap-crypto-platform-54-million-hack
4¡¢IT¹«Ë¾AppscookÉèÖùýʧй¶Êý°ÙËùѧУµÄѧÉúÐÅÏ¢
ýÌå11ÔÂ24Èճƣ¬£¬£¬£¬£¬IT¹«Ë¾AppscookÓÉÓÚϵͳÉèÖùýʧ£¬£¬£¬£¬£¬Ð¹Â¶ÁË´ó×Úδ³ÉÄêÈ˵ÄÊý¾Ý¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬¿ª·ÅµÄDigitalOcean´æ´¢Í°°üÀ¨½üÒ»°ÙÍò¸öÃô¸ÐÎļþ£¬£¬£¬£¬£¬É漰ѧÉúºÍ¼Ò³¤ÐÕÃû¡¢ÕÕÆ¬¡¢³öÉú֤ʵºÍ¼ÒͥסַµÈ¡£¡£¡£¡£¡£¸Ã¹«Ë¾¿ª·¢µÄÓ¦ÓóÌÐò±»Ó¡¶ÈºÍ˹ÀïÀ¼¿¨µÄ600¶àËùѧУÓÃÓÚ½ÌÓýÖÎÀí£¬£¬£¬£¬£¬Æä¹ÙÍø³ÆÁè¼Ý50ÍòѧÉúºÍ100Íò¼Ò³¤Ê¹ÓÃ¸ÃÆ½Ì¨¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÒÑÁªÏµÁËAppscook£¬£¬£¬£¬£¬µ«ÉÐδÊÕµ½»Ø¸´¡£¡£¡£¡£¡£
https://securityaffairs.com/154743/security/app-used-by-hundreds-of-schools-leaking-childrens-data.html
5¡¢AhnLabÅû¶AndarielʹÓÃÎó²îCVE-2023-46604µÄÏêÇé
11ÔÂ27ÈÕ£¬£¬£¬£¬£¬AhnLabÔÚ¼à¿ØAndarielÍÅ»ï½üÆÚµÄ¹¥»÷ʱ£¬£¬£¬£¬£¬·¢Ã÷ÆäʹÓÃApache ActiveMQÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2023-46604£©×°ÖöñÒâÈí¼þ¡£¡£¡£¡£¡£AhnLab·¢Ã÷ij¸öϵͳÖб»×°ÖÃÁËAndarielÒÑÍùһֱʹÓõĺóÃÅNukeSped¡£¡£¡£¡£¡£ÊÓ²ìÏÔʾ£¬£¬£¬£¬£¬¸ÃϵͳÖÐ×°ÖÃÁËApache ActiveMQЧÀÍÆ÷£¬£¬£¬£¬£¬²¢È·ÈÏÆäÖб£´æ×Ô¸ÃÎó²îÐÅÏ¢Ðû²¼ÒÔÀ´µÄÖÖÖÖ¹¥»÷µÄÈÕÖ¾£¬£¬£¬£¬£¬°üÀ¨Éæ¼°HelloKittyÀÕË÷Èí¼þµÄ¹¥»÷ÈÕÖ¾¡£¡£¡£¡£¡£ÏÖÔÚ»¹Ã»ÓÐÖ±½ÓÈÕÖ¾£¬£¬£¬£¬£¬µ«Ñо¿Ö°Ô±ÍƲâAndarielÕýÔÚʹÓøÃÎó²îÀ´×°ÖÃNukeSpedºÍTigerRatºóÃÅ¡£¡£¡£¡£¡£
https://asec.ahnlab.com/en/59318/
6¡¢IBMÐû²¼¹ØÓÚWailingCrab¼°ÆäC2ͨѶµÄÆÊÎö±¨¸æ
11ÔÂ23ÈÕ±¨µÀ£¬£¬£¬£¬£¬IBMÐû²¼±¨¸æ¸ÅÊöÁËWailingCrab¼°ÆäC2ͨѶ£¬£¬£¬£¬£¬ÖصãÏÈÈÝÁËÆä¶ÔMQTTÐÒéµÄʹÓᣡ£¡£¡£¡£¹¥»÷Á´Ê¼ÓÚ°üÀ¨PDF¸½¼þµÄÓʼþ£¬£¬£¬£¬£¬Ê¹ÓÃÁËÓâÆÚ½»»õºÍÔËÊ䷢ƱµÈÖ÷Ìâ¡£¡£¡£¡£¡£ÆäÖаüÀ¨¶ñÒâURL£¬£¬£¬£¬£¬µã»÷¾Í»áÏÂÔØÒ»¸öJavaScriptÎļþ£¬£¬£¬£¬£¬¸ÃÎļþ¼ìË÷²¢Æô¶¯DiscordÉÏÍйܵÄWailingCrab¼ÓÔØ³ÌÐò¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬×Ô2023ÄêÖÐÆÚÒÔÀ´£¬£¬£¬£¬£¬WailingCrabºóÃÅ×é¼þºÍC2Ö®¼äµÄͨѶÊÇʹÓÃMQTTÐÒéÖ´Ðе쬣¬£¬£¬£¬¸ÃÐÒéÊÇÒ»ÖÖÇáÁ¿¼¶IoTÐÂÎÅת´ïÐÒé¡£¡£¡£¡£¡£
https://thehackernews.com/2023/11/alert-new-wailingcrab-malware-loader.html


¾©¹«Íø°²±¸11010802024551ºÅ