ÍøÂç·¸·¨·Ö×ÓÔÚÕ«ÔºͿªÕ«½Úʱ´ú²þâ±ÍøÂçÕ©Æ­

Ðû²¼Ê±¼ä 2024-03-26

1. ÍøÂç·¸·¨·Ö×ÓÔÚÕ«ÔºͿªÕ«½Úʱ´ú²þâ±ÍøÂçÕ©Æ­


3ÔÂ24ÈÕ £¬£¬£¬£¬Õ«ÔÂʱ´ú £¬£¬£¬£¬ResecurityÊӲ쵽ڲƭ»î¶¯ºÍÕ©Æ­´ó·ùÔöÌí £¬£¬£¬£¬Í¬Ê±ÁãÊÛºÍÔÚÏßÉúÒ⼤Ôö¡£¡£¡£¡£ÃæÁÙÕâÒ»¼Ó¾çΣº¦µÄÖж«ÆóÒµ±»±Þ²ßÔöÇ¿ÏûºÄÕß±£»£»£»£»£»¤²¢ÔöÇ¿Æ·ÅÆÇå¾²¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ £¬£¬£¬£¬É³Ìذ¢À­²®Íõ¹ú (KSA) µÄÏûºÄÕßÖ§³öÁè¼Ý 160 ÒÚÃÀÔª £¬£¬£¬£¬Î»¾ÓµØÇøÅÅÐаñÊ×λ¡£¡£¡£¡£²»ÐÒµÄÊÇ £¬£¬£¬£¬µç×ÓÉÌÎñ»î¶¯µÄ¼¤ÔöÒýÆðÁËÍøÂç·¸·¨·Ö×ÓµÄ×¢ÖØ £¬£¬£¬£¬ËûÃÇʹÓÃÕâЩƽ̨ʵÑéÕ©Æ­ £¬£¬£¬£¬¸øÏûºÄÕßºÍÆóÒµ´øÀ´ÁËÖØ´óµÄ²ÆÎñÓ°Ïì¡£¡£¡£¡£ÕâЩ»î¶¯µÄ×ܲÆÎñÓ°ÏìÔ¤¼ÆÔÚ 70 ÖÁ 1 ÒÚÃÀÔªÖ®¼ä £¬£¬£¬£¬ÆäÖаüÀ¨Õë¶ÔÍâ¼®ÈËÊ¿¡¢×¡ÃñºÍÍâ¹úÓο͵ÄڲƭÐÐΪ¡£¡£¡£¡£ÓÉÓÚÒ»Á¬Æð¾¢ÎªÖж«Ðí¶à¿Í»§Ìá¹©Æ·ÅÆ±£»£»£»£»£»¤ £¬£¬£¬£¬Resecurity ÒÑÓÐÓÃ×èÖ¹ÁË 320 ¶à¸öð³äÖ÷ÒªÎïÁ÷ÌṩÉ̺͵ç×ÓÕþÎñЧÀ͵Äڲƭ×ÊÔ´¡£¡£¡£¡£ÍøÂç·¸·¨·Ö×ÓÆð¾¢Ê¹Óà Sadad¡¢Musaned¡¢Ajeer¡¢Ejar µÈƽ̨ÒÔ¼°×ÅÃûÎïÁ÷ЧÀÍÀ´ÓÕÆ­»¥ÁªÍøÓû§ £¬£¬£¬£¬²¢½«ËûÃÇÒýÈë²î±ðµÄȦÌס£¡£¡£¡£Ç¿ÁÒ½¨Òé²»ÒªÔÚ¿ÉÒÉÍøÕ¾ÉÏ»òÓëð³äÒøÐлòÕþ¸®¹ÍÔ±µÄСÎÒ˽¼Ò·ÖÏíСÎÒ˽¼ÒºÍ¸¶¿îÐÅÏ¢¡£¡£¡£¡£


https://securityaffairs.com/161009/cyber-crime/cybercriminals-accelerate-scams-ramadan.html


2. OpenVPN ÐÞ¸´ Windows ÖеĶà¸öÑÏÖØÎó²î


3ÔÂ24ÈÕ £¬£¬£¬£¬OpenVPN ÒÑÐû²¼Ö÷ÒªÇå¾²¸üУ¨°æ±¾ 2.6.10£© £¬£¬£¬£¬ÒÔ½â¾öÆä Windows Èí¼þÖеÄһϵÁÐÎó²î £¬£¬£¬£¬ÕâЩÎó²î¿ÉÄܵ¼ÖÂȨÏÞÉý¼¶¡¢Ô¶³Ì¹¥»÷ºÍϵͳÍ߽⡣¡£¡£¡£ÕâЩÎó²î͹ÏÔÁ˰´ÆÚÈí¼þ¸üеÄÐëÒªÐÔ £¬£¬£¬£¬ÌØÊâÊǹØÓÚ OpenVPN µÈ´¦Öóͷ£ÍøÂçÁ÷Á¿µÄ¹¤¾ß¡£¡£¡£¡£±¾´Î¸üеÄÎó²î°üÀ¨CVE-2024-27459£¨¿ÍÕ»Òç³ö±£»£»£»£»£»¤£©¡¢CVE-2024-24974£¨Ô¶³Ì»á¼ûÏÞÖÆ£©¡¢CVE-2024-27903£¨²å¼þ¼ÓÔØÏÞÖÆ£©ºÍCVE-2024-1305£¨TAP Çý¶¯³ÌÐòÒç³öÐÞ¸´£©¡£¡£¡£¡£


https://securityonline.info/openvpn-patches-serious-vulnerabilities-in-windows-installations/


3. Vans Éù³ÆÍøÂçÆ­×Ó²¢Î´ÇÔÈ¡¿Í»§µÄ²ÆÎñÐÅÏ¢


3ÔÂ24ÈÕ £¬£¬£¬£¬´ò°çºÍЬÀà¾ÞÍ· VF Corporation Ïò 3550 Íò¿Í»§×ª´ï £¬£¬£¬£¬¼ÌÈ¥ÄêµÄÇå¾²Îó²îÖ®ºó £¬£¬£¬£¬ËûÃÇ¿ÉÄÜ»á³ÉΪÉí·Ý͵ÇÔµÄÊܺ¦Õß¡£¡£¡£¡£Vans ºÍ North Face ĸ¹«Ë¾ÔÚ¸ø¿Í»§µÄÒ»·âµç×ÓÓʼþÖÐÔÊÐí £¬£¬£¬£¬Æ­×Ó²»»á͵ȡËûÃǵÄÐÅÓÿ¨»òÒøÐÐÕË»§ÏêϸÐÅÏ¢¡£¡£¡£¡£²¢ÇÒ £¬£¬£¬£¬ËüÔö²¹Ëµ £¬£¬£¬£¬¡°Ã»ÓÐÖ¤¾Ý¡±Åú×¢Èκα»µÁµÄСÎÒ˽¼ÒÐÅÏ¢ £¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþ¡¢µØµãºÍµç»°ºÅÂë £¬£¬£¬£¬Òѱ»ÓÃÓÚа¶ñÄ¿µÄ¡£¡£¡£¡£ÕâЩ¼Í¼ÊÇÔÚ VF ÓÚ 12 Ô 13 ÈÕÅû¶µÄÊý×ÖÈëÇÖÀú³ÌÖб»»á¼û»ò»ñÈ¡µÄ¡£¡£¡£¡£´Ë´ÎÈëÈÅÂÒÂÒÁËÕâ¼Ò´ò°çÖÆÔìÉ̵ÄÔËÓª¼°ÆäÈÃÈËÃÇÒÂןߵÈÍâÒµÄÄÜÁ¦¡£¡£¡£¡£ËäÈ» VF Æäʱ²¢Î´½«´Ë´ÎÍøÂçÇå¾²ÊÂÎñ³ÆÎªÀÕË÷Èí¼þ £¬£¬£¬£¬µ«ÆäÔÚî¿ÏµÎļþÖÐÏêϸÐÎò´Ë´ÎÈëÇÖµÄÓïÑÔʹÆäÌýÆðÀ´ºÜÊÇÏñ´øÓÐÀÕË÷ÒªÇóµÄÀÕË÷Èí¼þѬȾ¡£¡£¡£¡£ÔÚÏòÃÀ¹ú֤ȯÉúÒâίԱ»á (SEC) Ìá½»µÄ×îР8-K ÎļþÖÐ £¬£¬£¬£¬Õâ¼Ò´ò°çÏúÊÛÉÌÅû¶ £¬£¬£¬£¬Æä3550 Íò¿Í»§Êܵ½ IT Çå¾²Îó²îµÄÓ°Ïì £¬£¬£¬£¬µ«¶ÔÆ­×Ó¿ÉÄÜÇÔÈ¡µÄÊý¾ÝÈ´ÃÔºýÆä´ÇÔÚ¹¥»÷ʱ´ú¡£¡£¡£¡£


https://www.theregister.com/2024/03/24/vans_breach_disclosure/


4. ÓÐÏßµçÊÓ ISP ÒòÏò FCC »Ñ±¨¿í´øËùÔÚ¶ø±»· £¿ £¿£¿î


3ÔÂ23ÈÕ £¬£¬£¬£¬Ò»¼Ò»¥ÁªÍøÐ§ÀÍÌṩÉÌÈÏ¿ÉÔÚÆäÌṩ¿í´øµÄËùÔÚ·½ÃæÏò FCC ˵»Ñ £¬£¬£¬£¬½«Ö§¸¶ 10,000 ÃÀÔªµÄ· £¿ £¿£¿î £¬£¬£¬£¬²¢ÊµÑéºÏ¹æÍýÏëÒÔ±ÜÃâδÀ´·ºÆðÎ¥¹æÐÐΪ¡£¡£¡£¡£ArsTechnica£º¶íº¥¶íÖݶàÂ×¶àµÄÒ»¼ÒСÐÍ ISP ½Üì³Ñ·ÏصçÀ (JCC) ÈÏ¿É £¬£¬£¬£¬Ëü¹ýʧµØÉù³ÆÔÚÉÐδÀ©Õ¹µ½µÄµØÇøÌṩ¹âÏËЧÀÍ¡£¡£¡£¡£Ò»Î»¹«Ë¾¸ß¹Ü»¹ÈÏ¿É £¬£¬£¬£¬¸Ã¹«Ë¾Ìá½»ÁËÐéαµÄÁýÕÖÊý¾Ý £¬£¬£¬£¬ÒÔ×èÖ¹ÆäËû»¥ÁªÍøÐ§ÀÍÌṩÉÌ»ñµÃÕþ¸®²¦¿îÀ´Îª¸ÃµØÇøÌṩЧÀÍ¡£¡£¡£¡£Ars ÔÚ 2023 Äê 2 ÔµÄһƪÎÄÕÂÖÐ×ÊÖú½ÒÆÆÁËÕâÒ»ÊÂÎñ¡£¡£¡£¡£FCC ÓÚ 3 Ô 15 ÈÕÐû²¼ÁËÊÓ²ìЧ¹û £¬£¬£¬£¬³Æ Jefferson County Cable Î¥·´ÁË¿í´øÊý¾ÝÍøÂçÍýÏëµÄÒªÇóºÍÃÀ¹úÖ´·¨¡¶¿í´øÊý¾Ý·¨°¸¡·¡£¡£¡£¡£


https://ordonews.com/cable-isp-fined-10000-for-lying-to-fcc-about-where-it-offers-broadband/


5. µÂ¹úÕþ¸®Ðû²¼È¡µÞÃûΪNemesis MarketµÄ°µÍøÊг¡


3ÔÂ24ÈÕ £¬£¬£¬£¬µÂ¹úÕþ¸®Ðû²¼È¡µÞÒ»¸öÃûΪNemesis MarketµÄ²»·¨µØÏÂÊг¡ £¬£¬£¬£¬¸ÃÊг¡¶µÊÛ¶¾Æ·¡¢±»µÁÊý¾ÝºÍÖÖÖÖÍøÂç·¸·¨Ð§ÀÍ¡£¡£¡£¡£Áª°îÐÌʾ¯Ô±¾Ö£¨ÓÖÃû Bundeskriminalamt »ò BKA£©ÌåÏÖ £¬£¬£¬£¬Ëü²é»ñÁËλÓڵ¹úºÍÁ¢ÌÕÍðµÄÓë°µÍøÐ§ÀÍÏà¹ØµÄÊý×Ö»ù´¡ÉèÊ© £¬£¬£¬£¬²¢Ã»ÊÕÁË 94,000 Å·Ôª£¨102,107 ÃÀÔª£©µÄ¼ÓÃÜÇ®±Ò×ʲú¡£¡£¡£¡£´Ë´ÎÐж¯ÊÇÓëµÂ¹ú¡¢Á¢ÌÕÍðºÍÃÀ¹úµÄÖ´·¨»ú¹¹ÏàÖú¾ÙÐÐµÄ £¬£¬£¬£¬ÓÚ 2022 Äê 10 ÔÂ×îÏȾÙÐÐÆÕ±éÊÓ²ìºó £¬£¬£¬£¬ÓÚ 2024 Äê 3 Ô 20 ÈÕ¾ÙÐС£¡£¡£¡£Nemesis Market ½¨ÉèÓÚ 2021 Äê £¬£¬£¬£¬Ô¤¼ÆÔڹرÕ֮ǰӵÓÐÀ´×ÔÌìϸ÷µØµÄÁè¼Ý 150,000 ¸öÓû§ÕÊ»§ºÍ 1,100 ¸öÂô¼ÒÕÊ»§¡£¡£¡£¡£½ü 20 ÃÀÔªµÄÂô¼ÒÕË»§À´×Ե¹ú¡£¡£¡£¡£½ü¼¸¸öÔÂÀ´ £¬£¬£¬£¬µÂ¹úÕþ¸®»¹È¡µÞÁËKingdom MarketºÍCrimemarket £¬£¬£¬£¬ÕâÁ½¸öÍøÕ¾¶¼ÓµÓÐÊýǧÃûÓû§ £¬£¬£¬£¬²¢ÌṩÆÕ±éµÄÏ´Ç®ºÍÍøÂç·¸·¨Ð§ÀÍ¡£¡£¡£¡£


https://thehackernews.com/2024/03/german-police-seize-nemesis-market-in.html


6. î¿Ïµ»ú¹¹Ãé×¼¿Æ¼¼ÐÐÒµ £¬£¬£¬£¬¹È¸èºÍÆ»¹û·Ö²ðÌáÉÏÈÕ³Ì


3ÔÂ24ÈÕ £¬£¬£¬£¬´óÎ÷ÑóÁ½°¶µÄ·´Â¢¶Ïî¿Ïµ»ú¹¹ÕýÔÚ¹¥»÷¿ÉÄܵ¼ÖÂÆ»¹ûºÍ Alphabet ÆìϹȸ豻·Ö²ðµÄ·´¾ºÕùÐÐΪ £¬£¬£¬£¬´óÐͿƼ¼¹«Ë¾ÕýÃæÁÙÊýÊ®ÄêÀ´µÄ×î´óÌôÕ½¡£¡£¡£¡£Òµ½çÊ×´´¡£¡£¡£¡£Õâ·´¹ýÀ´¿ÉÄÜ»áÒý·¢Ììϸ÷µØµÄî¿Ïµ»ú¹¹¼Ó¶¦Á¦´ó¾Ù¶È £¬£¬£¬£¬Å·Ã˺ÍÃÀ¹ú°¸¼þÁ¢°¸ºó¸÷¹ú·´Â¢¶ÏÊÓ²ìÊýĿһֱÔöÌí¾Í֤ʵÎúÕâÒ»µã¡£¡£¡£¡£×ÔAT&TÔÚÕûÕû40Äêǰ·Ö²ðÒÔÀ´ £¬£¬£¬£¬Æù½ñΪֹ £¬£¬£¬£¬ÔÚÃÀ¹ú»¹Ã»ÓÐÒ»¼Ò¹«Ë¾ÃæÁÙî¿Ïµ»ú¹¹Ö÷µ¼·Ö²ðµÄ¿ÉÄÜÐÔ¡£¡£¡£¡£¹È¸èÌåÏÖ²î±ðÒâÅ·Ã˵ÄÖ¸¿Ø £¬£¬£¬£¬¶øÆ»¹ûÔòÌåÏÖÃÀ¹úµÄËßËÏÔÚÊÂʵºÍÖ´·¨É϶¼ÊǹýʧµÄ¡£¡£¡£¡£ÏÖÔÚÉв»È·¶¨î¿Ïµ»ú¹¹ÊÇ·ñ»áÐû²¼·Ö²ðÁî £¬£¬£¬£¬ÓÉÓÚËûÃÇÕýÔÚ˼Á¿ÖÖÖÖÑ¡Ôñ £¬£¬£¬£¬ÈκÎÐж¯¶¼¿ÉÄܵ¼Ö· £¿ £¿£¿î¡£¡£¡£¡£


https://www.reuters.com/technology/google-apple-breakups-agenda-global-regulators-target-tech-2024-03-24/