¿ËÂÞµØÑǵçÐÅÔËÓªÉÌA1 Hrvatskaй¶Լ20ÍòÓû§ÐÅÏ¢
Ðû²¼Ê±¼ä 2022-02-15¿ËÂÞµØÑǵçÐÅÔËÓªÉÌA1 Hrvatskaй¶Լ20ÍòÓû§ÐÅÏ¢
¾ÝýÌå2ÔÂ11ÈÕ±¨µÀ£¬£¬¿ËÂÞµØÑǵçÐÅÔËÓªÉÌA1 Hrvatskaй¶ÁË10%Óû§£¨Ô¼20ÍòÈË£©µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¸Ã¹«Ë¾Ã»ÓÐÌṩ¹ØÓÚ´Ë´ÎÊÂÎñµÄϸ½Ú£¬£¬Ö»³ÆËûÃǵÄÒ»¸öÓû§Êý¾Ý¿âÔâµ½ÁËδ¾ÊÚȨ»á¼û£¬£¬µ¼ÖÂÐÕÃû¡¢Ð¡ÎÒ˽¼ÒʶÓÖÃûÂë¡¢ÏÖʵµØµãºÍµç»°ºÅÂëµÈÐÅϢй¶¡£¡£¡£ÎÖ´ï·á¼¸ÈÕǰÔâµ½¹¥»÷µ¼ÖÂÆäÔÚÆÏÌÑÑÀµÄЧÀÍÖÐÖ¹£¬£¬A1 HrvatskaÊÇÆäÕ½ÂÔÏàÖúͬ°é£¬£¬Éв»¿ÉÈ·¶¨ÕâÁ½´ÎÇå¾²ÊÂÎñÖ®¼äÊÇ·ñ±£´æÁªÏµ¡£¡£¡£
https://www.bleepingcomputer.com/news/security/croatian-phone-carrier-data-breach-impacts-200-000-clients/
ÖйúÏã¸Ûº£ÒÝÂùÝÊý¾Ý¿âÔâ¹¥»÷³¬100Íò¿Í»§ÐÅϢй¶
2ÔÂ11Èյı¨µÀ³Æ£¬£¬ÖйúÏã¸ÛµÄº£ÒÝÂùݼ¯ÍÅÔ¤¶©Êý¾Ý¿âÔâµ½ÍøÂç¹¥»÷£¬£¬Ô¼120Íò¿Í»§µÄÐÅϢй¶¡£¡£¡£Òþ˽רԱAda ChungÉÏÖÜÎåÌåÏÖ£¬£¬ÆäÔÚÉÏÖÜÈýÊÕµ½Í¨ÖªºóÒѾ¶Ô´ËÊÂÕö¿ªÊӲ졣¡£¡£ÊÐÃñ¿Éͨ¹ýЧÀÍ´¦ÈÈÏß28272827¡¢¼¯Íźô½ÐÖÐÐÄ39080740»ò¹«Ë¾¹ÙÍøÅÌÎÊÊÇ·ñÊܵ½´ËÊÂÎñµÄÓ°Ïì¡£¡£¡£
https://gbcode.rthk.hk/TuniS/news.rthk.hk/rthk/en/component/k2/1633250-20220211.htm
SentinelOneÐû²¼ModifiedElephant¹¥»÷Ó¡¶ÈµÄÆÊÎö±¨¸æ
SentinelOneÔÚ2ÔÂ9ÈÕÐû²¼±¨¸æ£¬£¬Åû¶ÁËModifiedElephant¹¥»÷Ó¡¶ÈµÄϸ½Ú¡£¡£¡£ModifiedElephantÖÁÉÙ´Ó2012Äê×îÏÈÔËÓª£¬£¬Ê¹ÓÃÁËÉÌÒµÔ¶³Ì»á¼ûľÂí(RAT)£¬£¬²¢ÇÒÓëÉÌÒµ¼à¿ØÐÐÒµÓÐÁªÏµ¡£¡£¡£¹¥»÷Õßͨ¹ýÓã²æÊ½´¹ÂڻÀ´·Ö·¢¶ñÒâÈí¼þ£¬£¬ÀýÈçNetWireºÍDarkCometµÈ£¬£¬Ö÷ÒªÕë¶ÔÓ¡¶È¸÷µØµÄÈËȨ»î¶¯Ïà¹ØÖ°Ô±¡¢Ñ§ÕߺÍ״ʦµÈ£¬£¬×îÖÕÖ¼ÔÚÖ²ÈëÓÐ×ïµÄÊý×ÖÖ¤¾Ý¡£¡£¡£
https://www.sentinelone.com/labs/modifiedelephant-apt-and-a-decade-of-fabricating-evidence/
FritzFrogÔٴλع飬£¬Õë¶ÔÒ½ÁÆ¡¢½ÌÓýºÍÕþ¸®µÄ×éÖ¯
2ÔÂ10ÈÕ£¬£¬Çå¾²¹«Ë¾AkamaiÐû²¼Á˹ØÓÚP2P½©Ê¬ÍøÂçFritzFrogµÄÆÊÎö±¨¸æ¡£¡£¡£FritzFrogÓÚ2020Äê8ÔÂÊ״α»·¢Ã÷£¬£¬´Ë´Î»Ø¹éÔÚÒ»¸öÔÂÄÚµÄѬȾÂÊÔöÌíÁË10±¶£¬£¬ÒѾ¹¥»÷ÁË1500̨ҽÁƱ£½¡¡¢½ÌÓýºÍÕþ¸®ÐÐÒµµÄЧÀÍÆ÷£¬£¬ÆäÖд󲿷ÖλÓÚÖйú¡£¡£¡£¸Ã¶ñÒâÈí¼þʹÓÃGolang±àд£¬£¬ÔöÌíÁËй¦Ð§£¬£¬°üÀ¨Ê¹ÓÃÊðÀíÍøÂçºÍ¶¨Î»WordPressЧÀÍÆ÷£¬£¬²¢ÇÒÆä¶ÔµÈ¼Ü¹¹ºÍרÓдúÂë¾ßÓнϸßˮƽµÄÖØ´óÐÔ¡£¡£¡£
https://www.akamai.com/blog/security/fritzfrog-p2p
·¨¹ú³ÆGoogle AnalyticsÎ¥·´GDPR½«ÍøÂçµÄÊý¾Ý´«Êäµ½ÃÀ¹ú
¾ÝýÌå2ÔÂ10Èճƣ¬£¬·¨¹úÊý¾Ý±£»£»£»£»£»£»¤î¿Ïµ»ú²Ã¶¨Google AnalyticsÎ¥·´ÁËGDPR¡£¡£¡£¹ú¼ÒÐÅϢѧºÍ×ÔÓÉίԱ»á(CNIL)ÌåÏÖ£¬£¬Google Analytics´«Êäµ½ÃÀ¹úµÄÊý¾ÝûÓлñµÃ¡°³ä·Öî¿Ïµ¡±£¬£¬Î¥·´ÁËGDPRµÚ44ÌõÌõ¿î¡£¡£¡£CNIL³Æ£¬£¬Ö»¹ÜGoogleÒѾ½ÓÄÉÁËÌØÁíÍâ²½·¥À´¹æ·¶Google AnalyticsÖеÄÊý¾Ý´«Ê䣬£¬µ«ÕâЩ»¹È±·¦ÒÔɨ³ýÃÀ¹úÇ鱨ЧÀÍ»á¼ûÕâЩÊý¾ÝµÄ¿ÉÄÜÐÔ¡£¡£¡£
https://thehackernews.com/2022/02/france-rules-that-using-google.html
ÀÕË÷ÍÅ»ïBlackByte³ÆÆäÒÑÈëÇÖNFL¾É½ðɽ49È˶Ó
ýÌå2ÔÂ13ÈÕ±¨µÀ³Æ£¬£¬ÀÕË÷ÍÅ»ïBlackByteÒÑÈëÇ־ɽðɽ49È˶ӡ£¡£¡£¾É½ðɽ49È˶ӣ¨San Francisco 49ers£©ÊÇNFLÖÐ×îÓмÛÖµºÍ×î´«ÆæµÄÇò¶ÓÖ®Ò»£¬£¬¾ÍÔÚNFL×¼±¸Ó½Ó2022Ä곬µÈÍëµÄʱ¼ä£¬£¬BlackByteÉù³Æ¹¥»÷ÁË49ers²¢×îÏÈй¶±»µÁÎļþ£¬£¬¾ÝϤÊÇ292MBµÄ²ÆÎñÐÅÏ¢¡£¡£¡£¸ÃÇò¶ÓÔÚÒ»·ÝÉùÃ÷ÖÐ֤ʵÁËÕâ´Î¹¥»÷£¬£¬²¢ÌåÏÖ¹¥»÷µ¼ÖÂËûÃDz¿·ÖÍøÂçÔÝʱÖÐÖ¹£¬£¬ÏÖÔÚÈÔÔÚ»Ö¸´ÏµÍ³µÄÀú³ÌÖС£¡£¡£
https://www.securityweek.com/ransomware-gang-says-it-has-hacked-49ers-football-team
Çå¾²¹¤¾ß
VulnLab
Yavuzlar ¿ª·¢µÄ Web Îó²îʵÑéÊÒÏîÄ¿¡£¡£¡£
https://github.com/Yavuzlar/VulnLab
Http2Smugl
¸Ã¹¤¾ßÓÐÖúÓÚ¼ì²âºÍʹÓà HTTP ÇëÇó×ß˽£¬£¬ÒÔ·ÀËüͨ¹ýǰ¶ËЧÀÍÆ÷ͨ¹ý HTTP/2 -> HTTP/1.1 ת»»À´ÊµÏÖ¡£¡£¡£
https://github.com/neex/http2smugl
FACT
ÓÃÓÚÍøÂç¡¢´¦Öóͷ£ºÍ¿ÉÊÓ»¯À´×ÔÔÚÔÆÖлòÍâµØÔËÐеĻúе¼¯ÈºµÄȡ֤Êý¾Ý¡£¡£¡£
https://github.com/unicornunicode/FACT
iris-web
ËüÊÇÊÂÎñÏìÓ¦ÆÊÎöʦµÄÐ×÷ƽ̨£¬£¬ÔÊÐíÔÚÊÖÒÕ²ãÃæ¹²ÏíÊӲ졣¡£¡£
https://dfir-iris.github.io/
hobbits
ÓÃÓÚÆÊÎö¡¢´¦Öóͷ£ºÍ¿ÉÊÓ»¯±ÈÌØµÄÈí¼þƽ̨¡£¡£¡£
Çå¾²ÆÊÎö
ÃÀ¹ú¹ú·À²¿Ñ¡Ôñ DataRobot ΪÕþ¸®µÄÈ˹¤ÖÇÄÜÍýÏëÌṩ¶¯Á¦
https://www.helpnetsecurity.com/2022/02/13/datarobot-department-of-defense/
¹È¸èÌåÏÖ£¬£¬×éÖ¯ÕýÔÚ¸ü¿ìµØ½â¾öÁãÈÕÎó²î
https://securityaffairs.co/wordpress/127932/security/zero-day-flaws-metrics.html
¹È¸èÔÚ 2021 ÄêÏò Bug Hunters Ö§¸¶ÁË 870 ÍòÃÀÔª
https://www.darkreading.com/vulnerabilities-threats/google-paid-record-8-7-million-to-bug-hunters-in-2021
CISA ÏÂÁîÁª°î»ú¹¹ÔÚ 2 Ô 25 ÈÕ֮ǰ¸üРiPhone¡¢Mac
https://www.bleepingcomputer.com/news/security/cisa-orders-federal-agencies-to-update-iphones-macs-until-feb-25th/
΢Èí£º¶Ô Windows 10 20H2 µÄÖ§³Ö½«ÓÚ 2022 Äê 5 Ô¿¢ÊÂ
https://www.bleepingcomputer.com/news/microsoft/microsoft-support-for-windows-10-20h2-ending-in-may-2022/
ÐÂÎó²î¿ÉÈúڿÍÔ¶³ÌÆÆËðÎ÷ÃÅ×Ó PLC
https://www.securityweek.com/new-vulnerabilities-can-allow-hackers-remotely-crash-siemens-plcs