·¨¹úµçÁ¦¹©Ó¦ÉÌÒòʹÓÃÈõMD5Ëã·¨´æ´¢Óû§ÃÜÂë±»·£¿£¿£¿î

Ðû²¼Ê±¼ä 2022-12-02
1¡¢·¨¹úµçÁ¦¹©Ó¦ÉÌÒòʹÓÃÈõMD5Ëã·¨´æ´¢Óû§ÃÜÂë±»·£¿£¿£¿î

¾ÝýÌå11ÔÂ30ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬µçÁ¦¹©Ó¦ÉÌ·¨¹úµçÁ¦¹«Ë¾(EDF)ÒòÎ¥·´Å·ÃËͨÓÃÊý¾Ý±£»£»£»£»£»£»¤ÌõÀý(GDPR)£¬£¬£¬£¬£¬£¬±»·¨¹úÊý¾Ý±£»£»£»£»£»£»¤î¿Ïµ»ú¹¹·£¿£¿£¿î60ÍòÅ·Ôª¡£¡£¡£ ¡£¡£¡£¹ú¼ÒÐÅÏ¢ºÍ×ÔÓÉίԱ»á(CNIL)ÌåÏÖ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ2022Äê7ÔÂʹÓÃMD5Ëã·¨¶Ô25800¶à¸öÕÊ»§¾ÙÐÐhash´¦Öóͷ£À´´æ´¢ÃÜÂë¡£¡£¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬Óë2414254¸öÕË»§Ïà¹ØµÄÃÜÂë½ö¾­ÓÉhash´¦Öóͷ£¶øÎ´¼ÓÑΣ¬£¬£¬£¬£¬£¬Ê¹ÕË»§³ÖÓÐÈËÃæÁÙDZÔÚµÄÍøÂçÍþв¡£¡£¡£ ¡£¡£¡£¸ÃÊӲ컹ָÔðEDFδÄÜ×ñÊØGDPRÊý¾Ý±£´æÕþ²ß£¬£¬£¬£¬£¬£¬²¢ÌṩÁ˹ØÓÚËùÍøÂçÊý¾ÝȪԴµÄ½û¾øÈ·ÐÅÏ¢¡£¡£¡£ ¡£¡£¡£

https://thehackernews.com/2022/11/french-electricity-provider-fined-for.html

2¡¢ÏÖ´úÆû³µÒƶ¯Ó¦ÓÃÖб£´æ¿ÉÔ¶³Ì½âËøºÍÆô¶¯³µÁ¾µÄÎó²î

¾Ý12ÔÂ1ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬ÏÖ´úºÍGenesisµÄÒÆ¶¯Ó¦ÓÃMyHyundaiºÍMyGenesis¿É±»ÓÃÀ´Ô¶³Ì½âËøºÍÆô¶¯³µÁ¾¡£¡£¡£ ¡£¡£¡£ÔÚ×èµ²ÁËÕâÁ½¸öÓ¦Óñ¬·¢µÄÁ÷Á¿ºó£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±¶ÔÆä¾ÙÐÐÁËÆÊÎö£¬£¬£¬£¬£¬£¬·¢Ã÷ÑéÖ¤ÊÇÆ¾Ö¤Óû§µÄµç×ÓÓʼþµØµãÍê³ÉµÄ£¬£¬£¬£¬£¬£¬¸ÃµØµã°üÀ¨ÔÚPOSTÇëÇóµÄJSONÕýÎÄÖС£¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±ÏòÏÖ´úÖÕ¶Ë·¢ËÍÁËαÔìµÄHTTPÇëÇóÈÆ¹ýÁËÓÐÓÃÐÔ¼ì²é£¬£¬£¬£¬£¬£¬²¢¿ÉÒÔ½âËø³µÁ¾¡£¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷£¬£¬£¬£¬£¬£¬Ê¹ÓÃSiriusXMÖÇÄÜÆû³µÆ½Ì¨µÄ³µÁ¾Ò²±£´æÀàËÆÎÊÌ⣬£¬£¬£¬£¬£¬Éæ¼°±¦Âí¡¢±¾Ìï¡¢Ó¢·ÆÄáµÏ¡¢½Ý±ª¡¢Â·»¢¡¢À׿ËÈøË¹¡¢ÈÕ²ú¡¢Ë¹°Í³ºÍ·áÌïµÈ¡£¡£¡£ ¡£¡£¡£

https://www.bleepingcomputer.com/news/security/hyundai-app-bugs-allowed-hackers-to-remotely-unlock-start-cars/

3¡¢¸çÂ×±ÈÑÇÒ½ÁÆ»ú¹¹KeraltyÔâµ½RansomHouseµÄÀÕË÷¹¥»÷

ýÌå11ÔÂ30Èճƣ¬£¬£¬£¬£¬£¬¸çÂ×±ÈÑǵÄÒ»¼ÒÒ½ÁƱ£½¡ÌṩÉÌKeraltyÔâµ½RansomHouseµÄÀÕË÷¹¥»÷¡£¡£¡£ ¡£¡£¡£¹¥»÷±¬·¢ÔÚÉÏÖÜÈÕ£¬£¬£¬£¬£¬£¬Keralty¼°Æä×Ó¹«Ë¾EPS SanitasºÍColsanitasµÄITÔËÓª¡¢Ò½ÁÆÔ¤Ô¼°²Åż°ÍøÕ¾¶¼Êܵ½ÁËÓ°Ïì¡£¡£¡£ ¡£¡£¡£±¾ÖÜÒ»£¬£¬£¬£¬£¬£¬KeraltyÌåÏÖËûÃÇÓöµ½ÁËÊÖÒÕÎÊÌ⵫ûÓÐ͸¶Ե¹ÊÔ­ÓÉ¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾ÓÖÔÚÖܶþ½ÒÏþÉùÃ÷£¬£¬£¬£¬£¬£¬È·ÈÏÖÐÖ¹ÊÇÓÉÍøÂç¹¥»÷Ôì³ÉµÄ¡£¡£¡£ ¡£¡£¡£RansomHouseÌåÏֶԴ˴ι¥»÷ÈÏÕæ£¬£¬£¬£¬£¬£¬²¢³ÆÒÑÇÔÈ¡3 TBÊý¾Ý¡£¡£¡£ ¡£¡£¡£

https://www.bleepingcomputer.com/news/security/keralty-ransomware-attack-impacts-colombias-health-care-system/

4¡¢Ë÷ÄáºÍLexarµÄ¼ÓÃÜÌṩÉÌENC SecurityµÄÓªÒµÊý¾Ýй¶

CyberNewsÔÚ11ÔÂ30ÈÕ͸¶£¬£¬£¬£¬£¬£¬ºÉÀ¼Èí¼þ¹«Ë¾ENC Security×Ô2021Äê5ÔÂÒÔÀ´Ò»Ö±ÔÚй¶Ö÷ÒªµÄÓªÒµÊý¾Ý¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾ÔÚÈ«ÇòÓµÓÐ1200ÍòÓû§£¬£¬£¬£¬£¬£¬Í¨¹ýÆäDataVault¼ÓÃÜÈí¼þÌṩ¡°¾üÓü¶Êý¾Ý±£»£»£»£»£»£»¤¡±½â¾ö¼Æ»®¡£¡£¡£ ¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÏúÊÛÇþµÀµÄSMTPƾ֤¡¢¼òµ¥Ö§¸¶Æ½Ì¨µÄAdyenÃÜÔ¿¡¢µç×ÓÓʼþÓªÏú¹«Ë¾µÄMailchimp APIÃÜÔ¿¡¢ÔÊÐíÖ§¸¶APIÃÜÔ¿¡¢HMACÐÂÎÅÉí·ÝÑéÖ¤´úÂ룬£¬£¬£¬£¬£¬ÒÔ¼°ÒÔ.pemÃûÌô洢µÄ¹«¹²ºÍ˽ÈËÃÜÔ¿¡£¡£¡£ ¡£¡£¡£ÕâЩÐÅÏ¢´Ó2021Äê5ÔÂ27ÈÕµ½2022Äê11ÔÂ9ÈÕ¿ÉÒÔ»á¼û¡£¡£¡£ ¡£¡£¡£ENC Security͸¶£¬£¬£¬£¬£¬£¬¸ÃÎó²îÓëµÚÈý·½¹©Ó¦É̵ĹýʧÉèÖÃÓйØ£¬£¬£¬£¬£¬£¬ÎÊÌâÏÖÒѽâ¾ö¡£¡£¡£ ¡£¡£¡£

https://cybernews.com/security/encsecurity-leaked-sensitive-data/

5¡¢Ò½ÁÆÈí¼þ¹«Ë¾Connexin Software 220Íò»¼ÕßÐÅϢй¶

11ÔÂ30ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬Connexin Software½üÆÚ֪ͨHHSÆäÊý¾Ýй¶ÊÂÎñÓ°ÏìÁË2216365¸ö»¼Õß¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾ÊÇÒ»¼ÒΪ¶ù¿ÆÒ½ÁÆÍŶÓÌṩµç×Ó²¡ÀúºÍÖ´ÒµÖÎÀíÈí¼þ¡¢¼Æ·ÑЧÀͺÍÓªÒµÆÊÎö¹¤¾ßµÄ¹©Ó¦ÉÌ¡£¡£¡£ ¡£¡£¡£8ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬ConnexinÔÚÄÚÍø¼ì²âµ½Êý¾ÝÒì³££¬£¬£¬£¬£¬£¬Ö®ºóÁ¬Ã¦Õö¿ªÊӲ졣¡£¡£ ¡£¡£¡£9ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬È·ÈÏδ¾­ÊÚȨµÄµÚÈý·½Äܹ»»á¼ûÓÃÓÚÊý¾Ýת»»ºÍ¹ÊÕÏɨ³ýµÄÒ»×éÀëÏß²¡ÈËÊý¾Ý¡£¡£¡£ ¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬ConnexinÖØÖÃÁËËùÓй«Ë¾ÕÊ»§µÄÃÜÂ룬£¬£¬£¬£¬£¬½«»¼ÕßÊý¾ÝÒÆÖÁ¸üÇå¾²µÄÇéÐÎÖУ¬£¬£¬£¬£¬£¬²¢Í¨¹ýKrollΪÊÜÓ°Ï컼ÕßÌṩһÄêµÄÉí·Ý¼à¿ØÐ§ÀÍ¡£¡£¡£ ¡£¡£¡£

https://www.databreaches.net/connexin-software-notifies-parents-of-2-2-million-pediatric-patients-of-hack/

6¡¢ESETÐû²¼¹ØÓÚScarCruftкóÃÅDolphinµÄÆÊÎö±¨¸æ

11ÔÂ30ÈÕ£¬£¬£¬£¬£¬£¬ESETÐû²¼Á˹ØÓÚAPTÍÅ»ïScarCruftµÄкóÃÅDolphinµÄÆÊÎö±¨¸æ¡£¡£¡£ ¡£¡£¡£×Ô2021Äê4ÔÂÊ״η¢Ã÷DolphinÒÔÀ´£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÒѾ­ÊӲ쵽¶à¸ö°æ±¾µÄºóÃÅ¡£¡£¡£ ¡£¡£¡£DolphinÊÇÒ»¸öC++¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬£¬Ê¹ÓÃGoogle Drive×÷ΪÃüC2ЧÀÍÆ÷²¢´æ´¢±»µÁÎļþ¡£¡£¡£ ¡£¡£¡£ËüµÄËÑË÷¹¦Ð§Í¨¹ýʹÓÃWindows±ãЯװ±¸APIÀ©Õ¹µ½ÈκÎÅþÁ¬µ½±»¹¥»÷Ö÷»úµÄÊÖ»ú£¬£¬£¬£¬£¬£¬Ëü»¹¿ÉÒÔͨ¹ý¸ü¸ÄÏà¹ØÉèÖÃÀ´½µµÍÄ¿µÄGoogleÕÊ»§µÄÇå¾²ÐÔ¡£¡£¡£ ¡£¡£¡£

https://www.welivesecurity.com/2022/11/30/whos-swimming-south-korean-waters-meet-scarcrufts-dolphin/