ºÚ¿ÍÇÔÈ¡Òâ´óÀûLeonardo SpAµÄ10GB¾üÊÂÉñÃØ£»£»£»Ó¢¹úNCSCÐû²¼2020Äê¶È»ØÊ׵įÊÎö±¨¸æ

Ðû²¼Ê±¼ä 2020-12-07

1.ºÚ¿ÍÇÔÈ¡Òâ´óÀûLeonardo SpAµÄ10GB¾üÊÂÉñÃØ


1.jpg


ºÚ¿ÍÇÔÈ¡¹ú·À¹«Ë¾Leonardo SpAµÄ10 GB¾üÊÂÉñÃØ£¬£¬£¬£¬ÏÖÒѱ»Òâ´óÀû¾¯·½¾Ð²¶¡£¡£¡£¡£¡£¡£ ¡£¡£LeonardoÊÇÌìÏÂÉÏ×î´óµÄ¹ú·À³Ð°üÉÌÖ®Ò»£¬£¬£¬£¬Æä30£¥µÄ¹É·ÝÊôÓÚÒâ´óÀû¾­¼ÃºÍ²ÆÎñ²¿¡£¡£¡£¡£¡£¡£ ¡£¡£´Ë´Îй¶µÄÐÅÏ¢Éæ¼°µ½ÐÐÕþ»á¼ÆÖÎÀí¡¢ÈËÁ¦×ÊÔ´¡¢×ÊÔ´»õÎïµÄ²É¹ººÍ·ÖÅÉ¡¢ÃñÓ÷ɻúÁ㲿¼þºÍ¾üÓ÷ɻúµÄÉè¼Æ¡¢Ô±¹¤Ð¡ÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£¡£¾ÝϤ£¬£¬£¬£¬ºÚ¿ÍʹÓÃUSBÃÜÔ¿Ïò94¸öÊÂÇéÕ¾·Ö·¢cftmon.exeľÂí£¬£¬£¬£¬²¢ÒÔÕý°æWindowsÎļþÃüÃû¸ÃľÂíÒÔÈÆ¹ý¼ì²â¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/police-arrest-two-in-data-theft-cyberattack-on-leonardo-defense-corp/


2.ºÚ¿ÍʹÓÃÍøÂç´¹ÂÚÇÔÈ¡MetaMaskÓû§µÄ¼ÓÃÜÇ®±Ò


2.jpg


ºÚ¿ÍʹÓÃGoogle¹ã¸æÍ¨¹ýÍøÂç´¹ÂÚ¹¥»÷ÇÔÈ¡MetaMaskÓû§µÄ¼ÓÃÜÇ®±ÒÇ®°üÎļþ¡£¡£¡£¡£¡£¡£ ¡£¡£MetaMaskÓµÓÐÁè¼ÝÒ»°ÙÍòÓû§£¬£¬£¬£¬Í¨¹ýä¯ÀÀÆ÷À©Õ¹³ÌÐòÔÚä¯ÀÀÆ÷ÖÐÌṩÁËÒ»¸öÒÔÌ«·»¼ÓÃÜÇ®±ÒÇ®°ü£¬£¬£¬£¬ÔÚ×°ÖøÃÀ©Õ¹ºó£¬£¬£¬£¬¿Éµ¼ÈëÏÖÓеÄÇ®°ü£¬£¬£¬£¬Ò²¿É½¨ÉèÐÂÇ®°ü¡£¡£¡£¡£¡£¡£ ¡£¡£ºÚ¿ÍʹÓÃGoogle¹ã¸æ½«Óû§Öض¨Ïòµ½MetaMaskÍøÂç´¹ÂÚÒ³Ãæ£¬£¬£¬£¬µ±Óû§µã»÷µ¼ÈëÇ®°üÑ¡Ïîʱ£¬£¬£¬£¬»á±»ÒªÇóÊäÈëÏÖÓÐÇ®°üµÄÒªº¦×Ö£¬£¬£¬£¬ÕâЩÐÅÏ¢»á±»·¢Ë͸ø¹¥»÷ÕßÓÃÀ´ÇÔÈ¡¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/metamask-phishing-steals-cryptocurrency-wallets-via-google-ads/


3.Ç¿Éú³ÆCOVID-19ʱ´úÕë¶ÔÆäµÄ¹¥»÷´ÎÊýÔöÌí30£¥


3.jpg


Ç¿Éú³ÆCOVID-19ʱ´úÕë¶ÔÆäµÄ¹¥»÷´ÎÊýÔöÌíÁË30£¥¡£¡£¡£¡£¡£¡£ ¡£¡£¾Ý¡¶»ª¶û½ÖÈÕ±¨¡·±¨µÀ£¬£¬£¬£¬³¯ÏʺڿÍÒѾ­½«ÃÀ¹ú¡¢Ó¢¹úºÍº«¹ú´ÓÊÂCovid-19ÖÎÁÆÊÂÇéµÄÖÁÉÙÁù¼ÒÖÆÒ©¹«Ë¾ÁÐΪ¹¥»÷Ä¿µÄ£¬£¬£¬£¬Ö¼ÔÚÍøÂç¿ÉÒÔ³öÊÛ»òÎäÆ÷»¯µÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£¡£ÕâЩ¹«Ë¾°üÀ¨Ç¿Éú¹«Ë¾ºÍÂíÀïÀ¼ÖݵÄNovavax¹«Ë¾£¬£¬£¬£¬Æä¶¼ÔÚÑо¿ÊµÑéÐÔÒßÃç¡£¡£¡£¡£¡£¡£ ¡£¡£Ç¿Éú¹«Ë¾µÄCIO Marene AllisonÌåÏÖ£¬£¬£¬£¬¹ú¼ÒºÚ¿Íʱʱ¿Ì¿Ì¶¼ÔÚ¹¥»÷Ò½ÁÆ×éÖ¯£¬£¬£¬£¬Õë¶ÔÇ¿Éú¹«Ë¾µÄÍøÂç¹¥»÷ÔöÌíÁË30%¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/111960/hacking/covid-19-johnson-johnson-cyber-attacks.html


4.ApacheÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´TomcatÖÐÑÏÖØµÄÎó²î


4.jpg


ApacheÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´ÁËTomcatÖÐÑÏÖØµÄÎó²î£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓôËÎó²îµ¼Ö¾ܾøÐ§ÀÍ״̬¡£¡£¡£¡£¡£¡£ ¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2020-17527£¬£¬£¬£¬ÓÉÓÚApache Tomcat¿ÉÒÔ½«HTTP/2ÅþÁ¬ÉÏÊÕµ½µÄÏÈǰÁ÷ÖеÄHTTPÇëÇó±êÍ·ÖµÖØÐÂÓÃÓÚÓëºóÐøÁ÷Ïà¹ØÁªµÄÇëÇóËùµ¼ÖµÄ¡£¡£¡£¡£¡£¡£ ¡£¡£Ö»¹ÜÕâºÜ¿ÉÄܻᵼÖ¹ýʧ²¢¹Ø±ÕHTTP/2ÅþÁ¬£¬£¬£¬£¬¿ÉÊÇÐÅÏ¢¿ÉÄÜ»áÔÚÇëÇóÖ®¼ä×ß©¡£¡£¡£¡£¡£¡£ ¡£¡£¸ÃÎÊÌâÒÑÓÚTomcat 10.0.0-M10ÖÐÐÞ¸´¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/12/04/apache-releases-security-advisory-apache-tomcat


5.DashlaneÐû²¼2020Äê¶ÈÃÜÂëй¶ÎÊÌâµÄÆÊÎö±¨¸æ


5.jpg


DashlaneÐû²¼2020Äê¶ÈÃÜÂëй¶ÎÊÌâµÄÆÊÎö±¨¸æ£¬£¬£¬£¬ÖصãÏÈÈÝÁ˸ÃÄêÓëÃÜÂëÏà¹ØµÄ×îÑÏÖØÊ¹ʵĹ«Ë¾ºÍ×éÖ¯¡£¡£¡£¡£¡£¡£ ¡£¡£ÆäÖУ¬£¬£¬£¬°ñµ¥ÉÏÅÅÃûµÚÒ»ºÍµÚ¶þµÄÊÇTwitterºÍZoom£¬£¬£¬£¬ËüÃÇÔÊÐíÆäÔ±¹¤ºÍÓû§Ê¹ÓÃÈõÃÜÂ룬£¬£¬£¬Ê¹ÆäÒ×ÊÜÍøÂç¹¥»÷µÄÓ°Ïì¡£¡£¡£¡£¡£¡£ ¡£¡£ÂÃÓΡ¢ÓÎÏ·ºÍ¿ìµÝÁìÓòµÄÆäËû×ÅÃûÆóÒµÒ²³ÉΪºÚ¿ÍµÄÊܺ¦Õß¡£¡£¡£¡£¡£¡£ ¡£¡£±ðµÄ£¬£¬£¬£¬DashlaneµÄÊý¾ÝÏÔʾ£¬£¬£¬£¬Æ½¾ùÿ¸ö»¥ÁªÍøÓû§ÓÐÁè¼Ý200¸öÐèҪʹÓÃÃÜÂëµÄÊý×ÖÕË»§£¬£¬£¬£¬ÕâÒ»Êý×ÖÔ¤¼ÆÔÚδÀ´ÎåÄêÄÚ½«·­Ò»·¬£¬£¬£¬£¬µÖ´ï400¸ö¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.dashlane.com/twitter-employees-and-zoom-users-top-dashlanes-list-of-2020s-worst-password-offenders/


6.Ó¢¹úNCSCÐû²¼2020Äê¶È»ØÊ׵įÊÎö±¨¸æ


6.jpg


Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ðû²¼ÁË2020Äê¶È»ØÊ×±¨¸æ£¬£¬£¬£¬¸Ã±¨¸æµÄÖØµãÊÇÓ¦¶Ôһֱת±äµÄÌôÕ½ÐÔÍøÂçÍþв£¬£¬£¬£¬»ØÊ×ÁËNCSCµÄ2019Äê9ÔÂ1ÈÕµ½2020Äê8ÔÂ31ÈÕÖ®¼äµÄÊÂÇéÖ÷ҪϣÍûºÍÁÁµã¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ã±¨¸æÖ¸³ö£¬£¬£¬£¬ÔÚÕâÖØ´óÌôÕ½µÄÒ»Ä꣬£¬£¬£¬NCSC¼ÌÐø¶ÔѸËÙÑݱäµÄÍøÂçÍþв×÷³ö·´Ó¦¡£¡£¡£¡£¡£¡£ ¡£¡£²¢Ìá³öÁ˹ØÓÚNCSCÊÂÇéµÄÁ½¸öÖ÷ÒªÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£¡£µÚÒ»£¬£¬£¬£¬Ô¤·À·¸·¨ÊÇ·Ç·¸·¨ÖÐÐĵÄÖ÷ҪʹÃü£¬£¬£¬£¬ÆäÓëÖ´·¨²¿·ÖϸÃÜÏàÖú£¬£¬£¬£¬²¢ÔÚ723×Ú¹¥»÷ÊÂÎñÖÐÖ§Ô®Á˽ü1200ÃûÊܺ¦Õߣ»£»£»µÚ¶þ£¬£¬£¬£¬ÍøÂçÇå¾²ÊÇÒ»ÏîÍŶÓÔ˶¯¡£¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ncsc.gov.uk/annual-review/2020/docs/ncsc_2020-annual-review_s.pdf