ºÚ¿ÍÇÔÈ¡Òâ´óÀûLeonardo SpAµÄ10GB¾üÊÂÉñÃØ£»£»£»£»£»Ó¢¹úNCSCÐû²¼2020Äê¶È»ØÊ׵įÊÎö±¨¸æ
Ðû²¼Ê±¼ä 2020-12-071.ºÚ¿ÍÇÔÈ¡Òâ´óÀûLeonardo SpAµÄ10GB¾üÊÂÉñÃØ

ºÚ¿ÍÇÔÈ¡¹ú·À¹«Ë¾Leonardo SpAµÄ10 GB¾üÊÂÉñÃØ£¬£¬£¬£¬£¬£¬ÏÖÒѱ»Òâ´óÀû¾¯·½¾Ð²¶¡£¡£¡£LeonardoÊÇÌìÏÂÉÏ×î´óµÄ¹ú·À³Ð°üÉÌÖ®Ò»£¬£¬£¬£¬£¬£¬Æä30£¥µÄ¹É·ÝÊôÓÚÒâ´óÀû¾¼ÃºÍ²ÆÎñ²¿¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢Éæ¼°µ½ÐÐÕþ»á¼ÆÖÎÀí¡¢ÈËÁ¦×ÊÔ´¡¢×ÊÔ´»õÎïµÄ²É¹ººÍ·ÖÅÉ¡¢ÃñÓ÷ɻúÁ㲿¼þºÍ¾üÓ÷ɻúµÄÉè¼Æ¡¢Ô±¹¤Ð¡ÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃUSBÃÜÔ¿Ïò94¸öÊÂÇéÕ¾·Ö·¢cftmon.exeľÂí£¬£¬£¬£¬£¬£¬²¢ÒÔÕý°æWindowsÎļþÃüÃû¸ÃľÂíÒÔÈÆ¹ý¼ì²â¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/police-arrest-two-in-data-theft-cyberattack-on-leonardo-defense-corp/
2.ºÚ¿ÍʹÓÃÍøÂç´¹ÂÚÇÔÈ¡MetaMaskÓû§µÄ¼ÓÃÜÇ®±Ò

ºÚ¿ÍʹÓÃGoogle¹ã¸æÍ¨¹ýÍøÂç´¹ÂÚ¹¥»÷ÇÔÈ¡MetaMaskÓû§µÄ¼ÓÃÜÇ®±ÒÇ®°üÎļþ¡£¡£¡£MetaMaskÓµÓÐÁè¼ÝÒ»°ÙÍòÓû§£¬£¬£¬£¬£¬£¬Í¨¹ýä¯ÀÀÆ÷À©Õ¹³ÌÐòÔÚä¯ÀÀÆ÷ÖÐÌṩÁËÒ»¸öÒÔÌ«·»¼ÓÃÜÇ®±ÒÇ®°ü£¬£¬£¬£¬£¬£¬ÔÚ×°ÖøÃÀ©Õ¹ºó£¬£¬£¬£¬£¬£¬¿Éµ¼ÈëÏÖÓеÄÇ®°ü£¬£¬£¬£¬£¬£¬Ò²¿É½¨ÉèÐÂÇ®°ü¡£¡£¡£ºÚ¿ÍʹÓÃGoogle¹ã¸æ½«Óû§Öض¨Ïòµ½MetaMaskÍøÂç´¹ÂÚÒ³Ãæ£¬£¬£¬£¬£¬£¬µ±Óû§µã»÷µ¼ÈëÇ®°üÑ¡Ïîʱ£¬£¬£¬£¬£¬£¬»á±»ÒªÇóÊäÈëÏÖÓÐÇ®°üµÄÒªº¦×Ö£¬£¬£¬£¬£¬£¬ÕâЩÐÅÏ¢»á±»·¢Ë͸ø¹¥»÷ÕßÓÃÀ´ÇÔÈ¡¼ÓÃÜÇ®±Ò¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/metamask-phishing-steals-cryptocurrency-wallets-via-google-ads/
3.Ç¿Éú³ÆCOVID-19ʱ´úÕë¶ÔÆäµÄ¹¥»÷´ÎÊýÔöÌí30£¥

Ç¿Éú³ÆCOVID-19ʱ´úÕë¶ÔÆäµÄ¹¥»÷´ÎÊýÔöÌíÁË30£¥¡£¡£¡£¾Ý¡¶»ª¶û½ÖÈÕ±¨¡·±¨µÀ£¬£¬£¬£¬£¬£¬³¯ÏʺڿÍÒѾ½«ÃÀ¹ú¡¢Ó¢¹úºÍº«¹ú´ÓÊÂCovid-19ÖÎÁÆÊÂÇéµÄÖÁÉÙÁù¼ÒÖÆÒ©¹«Ë¾ÁÐΪ¹¥»÷Ä¿µÄ£¬£¬£¬£¬£¬£¬Ö¼ÔÚÍøÂç¿ÉÒÔ³öÊÛ»òÎäÆ÷»¯µÄÃô¸ÐÐÅÏ¢¡£¡£¡£ÕâЩ¹«Ë¾°üÀ¨Ç¿Éú¹«Ë¾ºÍÂíÀïÀ¼ÖݵÄNovavax¹«Ë¾£¬£¬£¬£¬£¬£¬Æä¶¼ÔÚÑо¿ÊµÑéÐÔÒßÃç¡£¡£¡£Ç¿Éú¹«Ë¾µÄCIO Marene AllisonÌåÏÖ£¬£¬£¬£¬£¬£¬¹ú¼ÒºÚ¿Íʱʱ¿Ì¿Ì¶¼ÔÚ¹¥»÷Ò½ÁÆ×éÖ¯£¬£¬£¬£¬£¬£¬Õë¶ÔÇ¿Éú¹«Ë¾µÄÍøÂç¹¥»÷ÔöÌíÁË30%¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/111960/hacking/covid-19-johnson-johnson-cyber-attacks.html
4.ApacheÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´TomcatÖÐÑÏÖØµÄÎó²î

ApacheÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËTomcatÖÐÑÏÖØµÄÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓôËÎó²îµ¼Ö¾ܾøÐ§ÀÍ״̬¡£¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2020-17527£¬£¬£¬£¬£¬£¬ÓÉÓÚApache Tomcat¿ÉÒÔ½«HTTP/2ÅþÁ¬ÉÏÊÕµ½µÄÏÈǰÁ÷ÖеÄHTTPÇëÇó±êÍ·ÖµÖØÐÂÓÃÓÚÓëºóÐøÁ÷Ïà¹ØÁªµÄÇëÇóËùµ¼Öµġ£¡£¡£Ö»¹ÜÕâºÜ¿ÉÄܻᵼÖ¹ýʧ²¢¹Ø±ÕHTTP/2ÅþÁ¬£¬£¬£¬£¬£¬£¬¿ÉÊÇÐÅÏ¢¿ÉÄÜ»áÔÚÇëÇóÖ®¼ä×ß©¡£¡£¡£¸ÃÎÊÌâÒÑÓÚTomcat 10.0.0-M10ÖÐÐÞ¸´¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/12/04/apache-releases-security-advisory-apache-tomcat
5.DashlaneÐû²¼2020Äê¶ÈÃÜÂëй¶ÎÊÌâµÄÆÊÎö±¨¸æ

DashlaneÐû²¼2020Äê¶ÈÃÜÂëй¶ÎÊÌâµÄÆÊÎö±¨¸æ£¬£¬£¬£¬£¬£¬ÖصãÏÈÈÝÁ˸ÃÄêÓëÃÜÂëÏà¹ØµÄ×îÑÏÖØÊ¹ʵĹ«Ë¾ºÍ×éÖ¯¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬°ñµ¥ÉÏÅÅÃûµÚÒ»ºÍµÚ¶þµÄÊÇTwitterºÍZoom£¬£¬£¬£¬£¬£¬ËüÃÇÔÊÐíÆäÔ±¹¤ºÍÓû§Ê¹ÓÃÈõÃÜÂ룬£¬£¬£¬£¬£¬Ê¹ÆäÒ×ÊÜÍøÂç¹¥»÷µÄÓ°Ïì¡£¡£¡£ÂÃÓΡ¢ÓÎÏ·ºÍ¿ìµÝÁìÓòµÄÆäËû×ÅÃûÆóÒµÒ²³ÉΪºÚ¿ÍµÄÊܺ¦Õß¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬DashlaneµÄÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬£¬Æ½¾ùÿ¸ö»¥ÁªÍøÓû§ÓÐÁè¼Ý200¸öÐèҪʹÓÃÃÜÂëµÄÊý×ÖÕË»§£¬£¬£¬£¬£¬£¬ÕâÒ»Êý×ÖÔ¤¼ÆÔÚδÀ´ÎåÄêÄÚ½«·Ò»·¬£¬£¬£¬£¬£¬£¬µÖ´ï400¸ö¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.dashlane.com/twitter-employees-and-zoom-users-top-dashlanes-list-of-2020s-worst-password-offenders/
6.Ó¢¹úNCSCÐû²¼2020Äê¶È»ØÊ׵įÊÎö±¨¸æ

Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ðû²¼ÁË2020Äê¶È»ØÊ×±¨¸æ£¬£¬£¬£¬£¬£¬¸Ã±¨¸æµÄÖØµãÊÇÓ¦¶Ôһֱת±äµÄÌôÕ½ÐÔÍøÂçÍþв£¬£¬£¬£¬£¬£¬»ØÊ×ÁËNCSCµÄ2019Äê9ÔÂ1ÈÕµ½2020Äê8ÔÂ31ÈÕÖ®¼äµÄÊÂÇéÖ÷ҪϣÍûºÍÁÁµã¡£¡£¡£¸Ã±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬ÔÚÕâÖØ´óÌôÕ½µÄÒ»Ä꣬£¬£¬£¬£¬£¬NCSC¼ÌÐø¶ÔѸËÙÑݱäµÄÍøÂçÍþв×÷³ö·´Ó¦¡£¡£¡£²¢Ìá³öÁ˹ØÓÚNCSCÊÂÇéµÄÁ½¸öÖ÷ÒªÐÅÏ¢¡£¡£¡£µÚÒ»£¬£¬£¬£¬£¬£¬Ô¤·À·¸·¨ÊÇ·Ç·¸·¨ÖÐÐĵÄÖ÷ҪʹÃü£¬£¬£¬£¬£¬£¬ÆäÓëÖ´·¨²¿·ÖϸÃÜÏàÖú£¬£¬£¬£¬£¬£¬²¢ÔÚ723×Ú¹¥»÷ÊÂÎñÖÐÖ§Ô®Á˽ü1200ÃûÊܺ¦Õߣ»£»£»£»£»µÚ¶þ£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²ÊÇÒ»ÏîÍŶÓÔ˶¯¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.ncsc.gov.uk/annual-review/2020/docs/ncsc_2020-annual-review_s.pdf


¾©¹«Íø°²±¸11010802024551ºÅ