ºÚ¿ÍÇÔÈ¡Òâ´óÀûLeonardo SpAµÄ10GB¾üÊÂÉñÃØ£»£»£»£»£»Ó¢¹úNCSCÐû²¼2020Äê¶È»ØÊ׵įÊÎö±¨¸æ

Ðû²¼Ê±¼ä 2020-12-07

1.ºÚ¿ÍÇÔÈ¡Òâ´óÀûLeonardo SpAµÄ10GB¾üÊÂÉñÃØ


1.jpg


ºÚ¿ÍÇÔÈ¡¹ú·À¹«Ë¾Leonardo SpAµÄ10 GB¾üÊÂÉñÃØ£¬£¬ £¬ £¬£¬£¬ÏÖÒѱ»Òâ´óÀû¾¯·½¾Ð²¶¡£¡£ ¡£LeonardoÊÇÌìÏÂÉÏ×î´óµÄ¹ú·À³Ð°üÉÌÖ®Ò»£¬£¬ £¬ £¬£¬£¬Æä30£¥µÄ¹É·ÝÊôÓÚÒâ´óÀû¾­¼ÃºÍ²ÆÎñ²¿¡£¡£ ¡£´Ë´Îй¶µÄÐÅÏ¢Éæ¼°µ½ÐÐÕþ»á¼ÆÖÎÀí¡¢ÈËÁ¦×ÊÔ´¡¢×ÊÔ´»õÎïµÄ²É¹ººÍ·ÖÅÉ¡¢ÃñÓ÷ɻúÁ㲿¼þºÍ¾üÓ÷ɻúµÄÉè¼Æ¡¢Ô±¹¤Ð¡ÎÒ˽¼ÒÐÅÏ¢¡£¡£ ¡£¾ÝϤ£¬£¬ £¬ £¬£¬£¬ºÚ¿ÍʹÓÃUSBÃÜÔ¿Ïò94¸öÊÂÇéÕ¾·Ö·¢cftmon.exeľÂí£¬£¬ £¬ £¬£¬£¬²¢ÒÔÕý°æWindowsÎļþÃüÃû¸ÃľÂíÒÔÈÆ¹ý¼ì²â¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/police-arrest-two-in-data-theft-cyberattack-on-leonardo-defense-corp/


2.ºÚ¿ÍʹÓÃÍøÂç´¹ÂÚÇÔÈ¡MetaMaskÓû§µÄ¼ÓÃÜÇ®±Ò


2.jpg


ºÚ¿ÍʹÓÃGoogle¹ã¸æÍ¨¹ýÍøÂç´¹ÂÚ¹¥»÷ÇÔÈ¡MetaMaskÓû§µÄ¼ÓÃÜÇ®±ÒÇ®°üÎļþ¡£¡£ ¡£MetaMaskÓµÓÐÁè¼ÝÒ»°ÙÍòÓû§£¬£¬ £¬ £¬£¬£¬Í¨¹ýä¯ÀÀÆ÷À©Õ¹³ÌÐòÔÚä¯ÀÀÆ÷ÖÐÌṩÁËÒ»¸öÒÔÌ«·»¼ÓÃÜÇ®±ÒÇ®°ü£¬£¬ £¬ £¬£¬£¬ÔÚ×°ÖøÃÀ©Õ¹ºó£¬£¬ £¬ £¬£¬£¬¿Éµ¼ÈëÏÖÓеÄÇ®°ü£¬£¬ £¬ £¬£¬£¬Ò²¿É½¨ÉèÐÂÇ®°ü¡£¡£ ¡£ºÚ¿ÍʹÓÃGoogle¹ã¸æ½«Óû§Öض¨Ïòµ½MetaMaskÍøÂç´¹ÂÚÒ³Ãæ£¬£¬ £¬ £¬£¬£¬µ±Óû§µã»÷µ¼ÈëÇ®°üÑ¡Ïîʱ£¬£¬ £¬ £¬£¬£¬»á±»ÒªÇóÊäÈëÏÖÓÐÇ®°üµÄÒªº¦×Ö£¬£¬ £¬ £¬£¬£¬ÕâЩÐÅÏ¢»á±»·¢Ë͸ø¹¥»÷ÕßÓÃÀ´ÇÔÈ¡¼ÓÃÜÇ®±Ò¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/metamask-phishing-steals-cryptocurrency-wallets-via-google-ads/


3.Ç¿Éú³ÆCOVID-19ʱ´úÕë¶ÔÆäµÄ¹¥»÷´ÎÊýÔöÌí30£¥


3.jpg


Ç¿Éú³ÆCOVID-19ʱ´úÕë¶ÔÆäµÄ¹¥»÷´ÎÊýÔöÌíÁË30£¥¡£¡£ ¡£¾Ý¡¶»ª¶û½ÖÈÕ±¨¡·±¨µÀ£¬£¬ £¬ £¬£¬£¬³¯ÏʺڿÍÒѾ­½«ÃÀ¹ú¡¢Ó¢¹úºÍº«¹ú´ÓÊÂCovid-19ÖÎÁÆÊÂÇéµÄÖÁÉÙÁù¼ÒÖÆÒ©¹«Ë¾ÁÐΪ¹¥»÷Ä¿µÄ£¬£¬ £¬ £¬£¬£¬Ö¼ÔÚÍøÂç¿ÉÒÔ³öÊÛ»òÎäÆ÷»¯µÄÃô¸ÐÐÅÏ¢¡£¡£ ¡£ÕâЩ¹«Ë¾°üÀ¨Ç¿Éú¹«Ë¾ºÍÂíÀïÀ¼ÖݵÄNovavax¹«Ë¾£¬£¬ £¬ £¬£¬£¬Æä¶¼ÔÚÑо¿ÊµÑéÐÔÒßÃç¡£¡£ ¡£Ç¿Éú¹«Ë¾µÄCIO Marene AllisonÌåÏÖ£¬£¬ £¬ £¬£¬£¬¹ú¼ÒºÚ¿Íʱʱ¿Ì¿Ì¶¼ÔÚ¹¥»÷Ò½ÁÆ×éÖ¯£¬£¬ £¬ £¬£¬£¬Õë¶ÔÇ¿Éú¹«Ë¾µÄÍøÂç¹¥»÷ÔöÌíÁË30%¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/111960/hacking/covid-19-johnson-johnson-cyber-attacks.html


4.ApacheÐû²¼Çå¾²¸üУ¬£¬ £¬ £¬£¬£¬ÐÞ¸´TomcatÖÐÑÏÖØµÄÎó²î


4.jpg


ApacheÐû²¼Çå¾²¸üУ¬£¬ £¬ £¬£¬£¬ÐÞ¸´ÁËTomcatÖÐÑÏÖØµÄÎó²î£¬£¬ £¬ £¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓôËÎó²îµ¼Ö¾ܾøÐ§ÀÍ״̬¡£¡£ ¡£¸ÃÎó²î±»×·×ÙΪCVE-2020-17527£¬£¬ £¬ £¬£¬£¬ÓÉÓÚApache Tomcat¿ÉÒÔ½«HTTP/2ÅþÁ¬ÉÏÊÕµ½µÄÏÈǰÁ÷ÖеÄHTTPÇëÇó±êÍ·ÖµÖØÐÂÓÃÓÚÓëºóÐøÁ÷Ïà¹ØÁªµÄÇëÇóËùµ¼ÖµÄ¡£¡£ ¡£Ö»¹ÜÕâºÜ¿ÉÄܻᵼÖ¹ýʧ²¢¹Ø±ÕHTTP/2ÅþÁ¬£¬£¬ £¬ £¬£¬£¬¿ÉÊÇÐÅÏ¢¿ÉÄÜ»áÔÚÇëÇóÖ®¼ä×ß©¡£¡£ ¡£¸ÃÎÊÌâÒÑÓÚTomcat 10.0.0-M10ÖÐÐÞ¸´¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/12/04/apache-releases-security-advisory-apache-tomcat


5.DashlaneÐû²¼2020Äê¶ÈÃÜÂëй¶ÎÊÌâµÄÆÊÎö±¨¸æ


5.jpg


DashlaneÐû²¼2020Äê¶ÈÃÜÂëй¶ÎÊÌâµÄÆÊÎö±¨¸æ£¬£¬ £¬ £¬£¬£¬ÖصãÏÈÈÝÁ˸ÃÄêÓëÃÜÂëÏà¹ØµÄ×îÑÏÖØÊ¹ʵĹ«Ë¾ºÍ×éÖ¯¡£¡£ ¡£ÆäÖУ¬£¬ £¬ £¬£¬£¬°ñµ¥ÉÏÅÅÃûµÚÒ»ºÍµÚ¶þµÄÊÇTwitterºÍZoom£¬£¬ £¬ £¬£¬£¬ËüÃÇÔÊÐíÆäÔ±¹¤ºÍÓû§Ê¹ÓÃÈõÃÜÂ룬£¬ £¬ £¬£¬£¬Ê¹ÆäÒ×ÊÜÍøÂç¹¥»÷µÄÓ°Ïì¡£¡£ ¡£ÂÃÓΡ¢ÓÎÏ·ºÍ¿ìµÝÁìÓòµÄÆäËû×ÅÃûÆóÒµÒ²³ÉΪºÚ¿ÍµÄÊܺ¦Õß¡£¡£ ¡£±ðµÄ£¬£¬ £¬ £¬£¬£¬DashlaneµÄÊý¾ÝÏÔʾ£¬£¬ £¬ £¬£¬£¬Æ½¾ùÿ¸ö»¥ÁªÍøÓû§ÓÐÁè¼Ý200¸öÐèҪʹÓÃÃÜÂëµÄÊý×ÖÕË»§£¬£¬ £¬ £¬£¬£¬ÕâÒ»Êý×ÖÔ¤¼ÆÔÚδÀ´ÎåÄêÄÚ½«·­Ò»·¬£¬£¬ £¬ £¬£¬£¬µÖ´ï400¸ö¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://blog.dashlane.com/twitter-employees-and-zoom-users-top-dashlanes-list-of-2020s-worst-password-offenders/


6.Ó¢¹úNCSCÐû²¼2020Äê¶È»ØÊ׵įÊÎö±¨¸æ


6.jpg


Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ðû²¼ÁË2020Äê¶È»ØÊ×±¨¸æ£¬£¬ £¬ £¬£¬£¬¸Ã±¨¸æµÄÖØµãÊÇÓ¦¶Ôһֱת±äµÄÌôÕ½ÐÔÍøÂçÍþв£¬£¬ £¬ £¬£¬£¬»ØÊ×ÁËNCSCµÄ2019Äê9ÔÂ1ÈÕµ½2020Äê8ÔÂ31ÈÕÖ®¼äµÄÊÂÇéÖ÷ҪϣÍûºÍÁÁµã¡£¡£ ¡£¸Ã±¨¸æÖ¸³ö£¬£¬ £¬ £¬£¬£¬ÔÚÕâÖØ´óÌôÕ½µÄÒ»Ä꣬£¬ £¬ £¬£¬£¬NCSC¼ÌÐø¶ÔѸËÙÑݱäµÄÍøÂçÍþв×÷³ö·´Ó¦¡£¡£ ¡£²¢Ìá³öÁ˹ØÓÚNCSCÊÂÇéµÄÁ½¸öÖ÷ÒªÐÅÏ¢¡£¡£ ¡£µÚÒ»£¬£¬ £¬ £¬£¬£¬Ô¤·À·¸·¨ÊÇ·Ç·¸·¨ÖÐÐĵÄÖ÷ҪʹÃü£¬£¬ £¬ £¬£¬£¬ÆäÓëÖ´·¨²¿·ÖϸÃÜÏàÖú£¬£¬ £¬ £¬£¬£¬²¢ÔÚ723×Ú¹¥»÷ÊÂÎñÖÐÖ§Ô®Á˽ü1200ÃûÊܺ¦Õߣ»£»£»£»£»µÚ¶þ£¬£¬ £¬ £¬£¬£¬ÍøÂçÇå¾²ÊÇÒ»ÏîÍŶÓÔ˶¯¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.ncsc.gov.uk/annual-review/2020/docs/ncsc_2020-annual-review_s.pdf