΢ÈíÒòXboxÇÖÕ¼¶ùͯÒþ˽±»ÃÀ¹úFTC·£¿î2000ÍòÃÀÔª

Ðû²¼Ê±¼ä 2023-06-08

1¡¢Î¢ÈíÒòXboxÇÖÕ¼¶ùͯÒþ˽±»ÃÀ¹úFTC·£¿î2000ÍòÃÀÔª


¾ÝýÌå6ÔÂ6ÈÕ±¨µÀ £¬Î¢ÈíÒòÎ¥·´Á˶ùͯÔÚÏßÒþ˽±£»¤·¨(COPPA) £¬±»FTC·£¿î2000ÍòÃÀÔª ¡£¸Ã»ú¹¹³Æ £¬Î¢ÈíÉæÏÓÔÚδÕ÷µÃâïÊÑÔÞ³É £¬ÉõÖÁûÓÐ֪ͨËûÃǵÄÇéÐÎÏ £¬ÍøÂç²¢±£´æ×¢²áXbox Live·þÎñµÄ¶ùͯµÄСÎÒ˽¼ÒÐÅÏ¢ ¡£ÔÚ2015ÄêÖÁ2020Äê¼äµÄһЩ°¸ÀýÖÐ £¬Î¢Èí½«¶ùͯÊý¾Ý´æ´¢ÔÚÆä·þÎñÆ÷Öг¤´ïÊýÄêÖ®¾Ã ¡£·¨Í¥ÎļþÏÔʾ £¬´Ó2017Äê1Ôµ½2021Äê12Ô £¬Ô¼ÓÐ218000Ãû²»Âú13ËêµÄÃÀ¹úXboxÓÎÏ·»úÓû§½¨ÉèMicrosoftÕÊ»§ ¡£ÏÖÔÚË«·½ÒÑÔ޳ɸÃÏ¢Õù £¬µ«ÈÔÔÚÆÚ´ý·¨ÔºÅú×¼ ¡£³ýÁË·£¿î £¬¸Ã¹«Ë¾»¹Òª½ÓÄÉÐëÒª²½·¥ÒÔÈ·±£×ñÊØCOPPA ¡£


https://www.theregister.com/2023/06/06/microsoft_fined_20m_for_collecting/


2¡¢Outlook±»Anonymous Sudan DDoS¹¥»÷·þÎñÔÙ´ÎÖÐÖ¹


¾Ý6ÔÂ6ÈÕ±¨µÀ £¬Outlook.comÔÚ6ÔÂ5ÈÕÂÄÀúÁËÁ½´ÎÖØ´óÖÐÖ¹Ö®ºó £¬ÓÖ±¬·¢ÁËһϵÁеķþÎñÖÐÖ¹ ¡£OutlookÓû§ÔÚTwitterÉÏËß¿àµç×ÓÓʼþ·þÎñ²»ÎȹÌ £¬Ó°ÏìÁËËûÃǵÄÊÂÇéЧÂÊ ¡£Î¢Èí˵ÕâЩ¹ÊÕÏÊÇÓÉÊÖÒÕÎÊÌâÒýÆðµÄ £¬ÔÚTwitterÉÏÐû²¼Á˸üÐÂ˵»º½âÁËÎÊÌâ £¬Ö®ºóÓÖ˵ÎÊÌâÔٴα¬·¢ ¡£Anonymous SudanÉù³Æ¶Ô´ËÊÂÈÏÕæ £¬ËµËûÃÇÔÚ¶Ô΢Èí¾ÙÐÐDDoS¹¥»÷ £¬»¹ÀÕË÷1000000ÃÀÔª ¡£ËäÈ»¸Ã˵·¨ÉÐδ»ñµÃ֤ʵ £¬µ«·þÎñÔÚÒÑÍù24СʱÄÚÒ»Ö±ÔËÐлºÂý £¬²¢±»Ò»ÏµÁеÄÖÐÖ¹ËùÀ§ÈÅ ¡£


https://www.bleepingcomputer.com/news/microsoft/outlookcom-hit-by-outages-as-hacktivists-claim-ddos-attacks/


3¡¢Adlumin·¢Ã÷Õë¶ÔÃÀ¹úº½¿Õº½ÌìÒµµÄ¶ñÒâÈí¼þPowerDrop 


AdluminÔÚ6ÔÂ5ÈÕÅû¶ÁËÒ»ÖÖÐÂÐͶñÒâPowerShell¾ç±¾PowerDrop £¬Ö÷ÒªÕë¶ÔÃÀ¹úµÄº½¿Õº½ÌìÒµ ¡£Ñо¿Ö°Ô±ÉϸöÔÂÔÚÃÀ¹úÒ»¼Ò¹ú·À³Ð°üÉ̵ÄϵͳÖз¢Ã÷Á˶ñÒâÈí¼þÑù±¾ ¡£Æä³õÊ¼Ñ¬È¾ÔØÌåδ֪ £¬Ñо¿Ö°Ô±ÍƲâ £¬¹¥»÷Õß¿ÉÄÜʹÓÃÎó²î¡¢´¹ÂÚÓʼþ»òαÔìÈí¼þÏÂÔØÍøÕ¾À´·Ö·¢¾ç±¾ ¡£ËüÊÇÓÉWMI·þÎñÖ´ÐеÄPowerShell¾ç±¾ £¬²¢Ê¹ÓÃBase64¾ÙÐбàÂëÒÔÓÃ×÷ºóÃÅ»òRAT ¡£¸Ã¶ñÒâÈí¼þ»¹Ê¹ÓÃICMP»ØÏÔÇëÇóÐÂÎÅÀ´Æô¶¯ÓëC2·þÎñÆ÷µÄͨѶ ¡£


https://adlumin.com/post/powerdrop-a-new-insidious-powershell-script-for-command-and-control-attacks-targets-u-s-aerospace-defense-industry/


4¡¢CiscoÐÞ¸´AnyConnectÖеÄÌáȨÎó²îCVE-2023-20178


ýÌå6ÔÂ7ÈÕ³Æ £¬CiscoÐÞ¸´ÁËCisco Secure Client£¨ÒÔǰ³ÆAnyConnect Secure Mobility Client£©ÖеÄÌáȨÎó²î£¨CVE-2023-20178£© ¡£µÍȨÏÞµÄÍâµØ¹¥»÷Õß¿ÉÒÔÔÚ²»ÓëÓû§½»»¥µÄµÍÖØ´óÐÔ¹¥»÷ÖÐʹÓôËÎó²î £¬½«È¨ÏÞÌáÉýÖÁSYSTEM ¡£¸ÃÎó²îÔ´ÓÚ¶ÔÉý¼¶Àú³ÌÖн¨ÉèµÄÒ»¸öÔÝʱĿ¼·ÖÅÉÁ˲»Êʵ±µÄȨÏÞ £¬¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃWindows×°ÖóÌÐòÀú³ÌµÄÌØ¶¨¹¦Ð§À´Ê¹ÓôËÎó²î ¡£ÏÖÔÚÎó²îÉÐδ±»ÔÚҰʹÓà ¡£


https://www.bleepingcomputer.com/news/security/cisco-fixes-anyconnect-bug-giving-windows-system-privileges/


5¡¢VPN·þÎñÌṩÉÌi2VPNµÄÖÎÀíԱƾ֤±»¹ûÕæÔÚTelegram


SafetyDetectivesÓÚ6ÔÂ5ÈÕ³ÆÆä·¢Ã÷ÁËÒ»ÆðÉæ¼°VPN·þÎñÌṩÉÌi2VPNµÄÊý¾Ýй¶ÊÂÎñ ¡£ºÚ¿ÍÓÚ5ÔÂ29ÈÕÔÚTelegramÉÏÐû²¼Á˾ݳÆÀ´×Ôi2VPNµÄÐÅÏ¢ £¬°üÀ¨ÖÎÀíÔ±µÄÓʼþµØµãºÍÃÜÂë £¬ÒÔ¼°ÏÔʾÊý¾ÝÖÐÐĺÍÓû§¶©ÔÄÏêϸÐÅÏ¢µÄÖÎÀíÃæ°åÆÁÄ»½ØÍ¼ ¡£ËäÈ»ºÚ¿ÍûÓÐÖ±½Ó¹ûÕæÓû§Êý¾Ý £¬µ«±»ÈëÇÖµÄÖÎÀíÃæ°åƾ¿É»á¼û´ó×ÚÓû§Êý¾Ý ¡£i2VPN½öÔÚGoogle PlayÊÐËÁ¾ÍÓÐÁè¼Ý500000µÄÏÂÔØÁ¿ £¬ÔÚApp StoreµÄÏÂÔØÁ¿Î´¹ûÕæ ¡£


https://www.safetydetectives.com/news/i2vpn-exposed-telegram/


6¡¢UptycsÐû²¼¹ØÓÚÐÂÀÕË÷ÍÅ»ïCyclopsµÄÊÖÒÕÆÊÎö±¨¸æ


6ÔÂ5ÈÕ £¬UptycsÐû²¼Á˹ØÓÚÀÕË÷ÍÅ»ïCyclopsµÄÊÖÒÕÆÊÎö±¨¸æ ¡£Cyclops¿ª·¢ÁË¿ÉÒÔѬȾWindows¡¢LinuxºÍmacOSϵͳµÄ¶àƽ̨ÀÕË÷Èí¼þ ¡£»¹ÌṩÁËÒ»ÖÖ»ùÓÚGoµÄµ¥¶ÀµÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ £¬ÕâÊÇΪWindowsºÍLinuxÖеÄÌØ¶¨Îļþ¶ø¿ª·¢µÄ ¡£¸ÃÀÕË÷Èí¼þÖ§³ÖÖØ´óµÄ¼ÓÃÜÀú³Ì £¬ËùÓй¦Ð§¶¼Ê¹Ó÷ǶԳƺͶԳƼÓÃܵÄ×éºÏ¾²Ì¬ÊµÏÖ ¡£Ñо¿Ö°Ô±»¹·¢Ã÷ £¬CyclopsÓëBabukµÄ¼ÓÃÜÂß¼­ÓÐÏàËÆÖ®´¦ £¬Á½Õß¶¼Ê¹ÓÃCurve25519ºÍHC-256¾ÙÐÐWindows¼ÓÃÜ £¬²¢ÍŽáʹÓÃCurve25519ºÍChaCha ¡£


https://www.uptycs.com/blog/cyclops-ransomware-stealer-combo