ºÚ¿ÍÇÔÈ¡Òâ´óÀûLeonardo SpAµÄ10GB¾üÊÂÉñÃØ£»£»£»Ó¢¹úNCSCÐû²¼2020Äê¶È»ØÊ׵įÊÎö±¨¸æ
Ðû²¼Ê±¼ä 2020-12-071.ºÚ¿ÍÇÔÈ¡Òâ´óÀûLeonardo SpAµÄ10GB¾üÊÂÉñÃØ

ºÚ¿ÍÇÔÈ¡¹ú·À¹«Ë¾Leonardo SpAµÄ10 GB¾üÊÂÉñÃØ£¬£¬£¬£¬ÏÖÒѱ»Òâ´óÀû¾¯·½¾Ð²¶¡£¡£¡£¡£¡£¡£¡£¡£LeonardoÊÇÌìÏÂÉÏ×î´óµÄ¹ú·À³Ð°üÉÌÖ®Ò»£¬£¬£¬£¬Æä30£¥µÄ¹É·ÝÊôÓÚÒâ´óÀû¾¼ÃºÍ²ÆÎñ²¿¡£¡£¡£¡£¡£¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢Éæ¼°µ½ÐÐÕþ»á¼ÆÖÎÀí¡¢ÈËÁ¦×ÊÔ´¡¢×ÊÔ´»õÎïµÄ²É¹ººÍ·ÖÅÉ¡¢ÃñÓ÷ɻúÁ㲿¼þºÍ¾üÓ÷ɻúµÄÉè¼Æ¡¢Ô±¹¤Ð¡ÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬ºÚ¿ÍʹÓÃUSBÃÜÔ¿Ïò94¸öÊÂÇéÕ¾·Ö·¢cftmon.exeľÂí£¬£¬£¬£¬²¢ÒÔÕý°æWindowsÎļþÃüÃû¸ÃľÂíÒÔÈÆ¹ý¼ì²â¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/police-arrest-two-in-data-theft-cyberattack-on-leonardo-defense-corp/
2.ºÚ¿ÍʹÓÃÍøÂç´¹ÂÚÇÔÈ¡MetaMaskÓû§µÄ¼ÓÃÜÇ®±Ò

ºÚ¿ÍʹÓÃGoogle¹ã¸æÍ¨¹ýÍøÂç´¹ÂÚ¹¥»÷ÇÔÈ¡MetaMaskÓû§µÄ¼ÓÃÜÇ®±ÒÇ®°üÎļþ¡£¡£¡£¡£¡£¡£¡£¡£MetaMaskÓµÓÐÁè¼ÝÒ»°ÙÍòÓû§£¬£¬£¬£¬Í¨¹ýä¯ÀÀÆ÷À©Õ¹³ÌÐòÔÚä¯ÀÀÆ÷ÖÐÌṩÁËÒ»¸öÒÔÌ«·»¼ÓÃÜÇ®±ÒÇ®°ü£¬£¬£¬£¬ÔÚ×°ÖøÃÀ©Õ¹ºó£¬£¬£¬£¬¿Éµ¼ÈëÏÖÓеÄÇ®°ü£¬£¬£¬£¬Ò²¿É½¨ÉèÐÂÇ®°ü¡£¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍʹÓÃGoogle¹ã¸æ½«Óû§Öض¨Ïòµ½MetaMaskÍøÂç´¹ÂÚÒ³Ãæ£¬£¬£¬£¬µ±Óû§µã»÷µ¼ÈëÇ®°üÑ¡Ïîʱ£¬£¬£¬£¬»á±»ÒªÇóÊäÈëÏÖÓÐÇ®°üµÄÒªº¦×Ö£¬£¬£¬£¬ÕâЩÐÅÏ¢»á±»·¢Ë͸ø¹¥»÷ÕßÓÃÀ´ÇÔÈ¡¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/metamask-phishing-steals-cryptocurrency-wallets-via-google-ads/
3.Ç¿Éú³ÆCOVID-19ʱ´úÕë¶ÔÆäµÄ¹¥»÷´ÎÊýÔöÌí30£¥

Ç¿Éú³ÆCOVID-19ʱ´úÕë¶ÔÆäµÄ¹¥»÷´ÎÊýÔöÌíÁË30£¥¡£¡£¡£¡£¡£¡£¡£¡£¾Ý¡¶»ª¶û½ÖÈÕ±¨¡·±¨µÀ£¬£¬£¬£¬³¯ÏʺڿÍÒѾ½«ÃÀ¹ú¡¢Ó¢¹úºÍº«¹ú´ÓÊÂCovid-19ÖÎÁÆÊÂÇéµÄÖÁÉÙÁù¼ÒÖÆÒ©¹«Ë¾ÁÐΪ¹¥»÷Ä¿µÄ£¬£¬£¬£¬Ö¼ÔÚÍøÂç¿ÉÒÔ³öÊÛ»òÎäÆ÷»¯µÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹«Ë¾°üÀ¨Ç¿Éú¹«Ë¾ºÍÂíÀïÀ¼ÖݵÄNovavax¹«Ë¾£¬£¬£¬£¬Æä¶¼ÔÚÑо¿ÊµÑéÐÔÒßÃç¡£¡£¡£¡£¡£¡£¡£¡£Ç¿Éú¹«Ë¾µÄCIO Marene AllisonÌåÏÖ£¬£¬£¬£¬¹ú¼ÒºÚ¿Íʱʱ¿Ì¿Ì¶¼ÔÚ¹¥»÷Ò½ÁÆ×éÖ¯£¬£¬£¬£¬Õë¶ÔÇ¿Éú¹«Ë¾µÄÍøÂç¹¥»÷ÔöÌíÁË30%¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/111960/hacking/covid-19-johnson-johnson-cyber-attacks.html
4.ApacheÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´TomcatÖÐÑÏÖØµÄÎó²î

ApacheÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´ÁËTomcatÖÐÑÏÖØµÄÎó²î£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓôËÎó²îµ¼Ö¾ܾøÐ§ÀÍ״̬¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2020-17527£¬£¬£¬£¬ÓÉÓÚApache Tomcat¿ÉÒÔ½«HTTP/2ÅþÁ¬ÉÏÊÕµ½µÄÏÈǰÁ÷ÖеÄHTTPÇëÇó±êÍ·ÖµÖØÐÂÓÃÓÚÓëºóÐøÁ÷Ïà¹ØÁªµÄÇëÇóËùµ¼Öµġ£¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÕâºÜ¿ÉÄܻᵼÖ¹ýʧ²¢¹Ø±ÕHTTP/2ÅþÁ¬£¬£¬£¬£¬¿ÉÊÇÐÅÏ¢¿ÉÄÜ»áÔÚÇëÇóÖ®¼ä×ß©¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎÊÌâÒÑÓÚTomcat 10.0.0-M10ÖÐÐÞ¸´¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/12/04/apache-releases-security-advisory-apache-tomcat
5.DashlaneÐû²¼2020Äê¶ÈÃÜÂëй¶ÎÊÌâµÄÆÊÎö±¨¸æ

DashlaneÐû²¼2020Äê¶ÈÃÜÂëй¶ÎÊÌâµÄÆÊÎö±¨¸æ£¬£¬£¬£¬ÖصãÏÈÈÝÁ˸ÃÄêÓëÃÜÂëÏà¹ØµÄ×îÑÏÖØÊ¹ʵĹ«Ë¾ºÍ×éÖ¯¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬°ñµ¥ÉÏÅÅÃûµÚÒ»ºÍµÚ¶þµÄÊÇTwitterºÍZoom£¬£¬£¬£¬ËüÃÇÔÊÐíÆäÔ±¹¤ºÍÓû§Ê¹ÓÃÈõÃÜÂ룬£¬£¬£¬Ê¹ÆäÒ×ÊÜÍøÂç¹¥»÷µÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£ÂÃÓΡ¢ÓÎÏ·ºÍ¿ìµÝÁìÓòµÄÆäËû×ÅÃûÆóÒµÒ²³ÉΪºÚ¿ÍµÄÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬DashlaneµÄÊý¾ÝÏÔʾ£¬£¬£¬£¬Æ½¾ùÿ¸ö»¥ÁªÍøÓû§ÓÐÁè¼Ý200¸öÐèҪʹÓÃÃÜÂëµÄÊý×ÖÕË»§£¬£¬£¬£¬ÕâÒ»Êý×ÖÔ¤¼ÆÔÚδÀ´ÎåÄêÄÚ½«·Ò»·¬£¬£¬£¬£¬µÖ´ï400¸ö¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.dashlane.com/twitter-employees-and-zoom-users-top-dashlanes-list-of-2020s-worst-password-offenders/
6.Ó¢¹úNCSCÐû²¼2020Äê¶È»ØÊ׵įÊÎö±¨¸æ

Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ðû²¼ÁË2020Äê¶È»ØÊ×±¨¸æ£¬£¬£¬£¬¸Ã±¨¸æµÄÖØµãÊÇÓ¦¶Ôһֱת±äµÄÌôÕ½ÐÔÍøÂçÍþв£¬£¬£¬£¬»ØÊ×ÁËNCSCµÄ2019Äê9ÔÂ1ÈÕµ½2020Äê8ÔÂ31ÈÕÖ®¼äµÄÊÂÇéÖ÷ҪϣÍûºÍÁÁµã¡£¡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÖ¸³ö£¬£¬£¬£¬ÔÚÕâÖØ´óÌôÕ½µÄÒ»Ä꣬£¬£¬£¬NCSC¼ÌÐø¶ÔѸËÙÑݱäµÄÍøÂçÍþв×÷³ö·´Ó¦¡£¡£¡£¡£¡£¡£¡£¡£²¢Ìá³öÁ˹ØÓÚNCSCÊÂÇéµÄÁ½¸öÖ÷ÒªÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£µÚÒ»£¬£¬£¬£¬Ô¤·À·¸·¨ÊÇ·Ç·¸·¨ÖÐÐĵÄÖ÷ҪʹÃü£¬£¬£¬£¬ÆäÓëÖ´·¨²¿·ÖϸÃÜÏàÖú£¬£¬£¬£¬²¢ÔÚ723×Ú¹¥»÷ÊÂÎñÖÐÖ§Ô®Á˽ü1200ÃûÊܺ¦Õߣ»£»£»µÚ¶þ£¬£¬£¬£¬ÍøÂçÇå¾²ÊÇÒ»ÏîÍŶÓÔ˶¯¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.ncsc.gov.uk/annual-review/2020/docs/ncsc_2020-annual-review_s.pdf


¾©¹«Íø°²±¸11010802024551ºÅ