###### tags: `資安事件新聞週報` # 資安事件新聞週報 2024/11/04 ~ 2024/11/08 1.重大弱點漏洞/後門/Exploit/Zero Day Cisco 發布 Ultra-Reliable Wireless Backhaul(URWB) 軟體安全更新 https://www.ithome.com.tw/news/165899 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-backhaul-ap-cmdinj-R7E28Ecs Cisco Releases Patch for Critical URWB Vulnerability in Industrial Wireless Systems https://thehackernews.com/2024/11/cisco-releases-patch-for-critical-urwb.html 思科修補工控無線URWB路由器風險達到10分的重大漏洞 https://www.ithome.com.tw/news/165899 Google's AI Tool Big Sleep Finds Zero-Day Vulnerability in SQLite Database Engine https://thehackernews.com/2024/11/googles-ai-tool-big-sleep-finds-zero.html QNAP 修補兩個零日漏洞,用戶應盡速更新 https://www.informationsecurity.com.tw/article/article_detail.aspx?aid=11352 Synology Urges Patch for Critical Zero-Click RCE Flaw Affecting Millions of NAS Devices https://thehackernews.com/2024/11/synology-urges-patch-for-critical-zero.html HPE Aruba Networking修補Wi-Fi基地臺系統軟體漏洞,其中兩個嚴重程度達9分以上 https://www.ithome.com.tw/news/165916 Palo Alto Networks修補的遷移工具漏洞已出現攻擊行動 https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-palo-alto-networks-bug-exploited-in-attacks/ CISA Alerts to Active Exploitation of Critical Palo Alto Networks Vulnerability https://thehackernews.com/2024/11/cisa-alerts-to-active-exploitation-of.html Windows版Veritas網路備份工具存在漏洞,攻擊者可用來提升權限 https://www.ithome.com.tw/news/165926 ServiceNow修補重大層級的沙箱逃逸漏洞CVE-2024-8923 https://securityonline.info/servicenow-patches-critical-sandbox-escape-vulnerability-cve-2024-8923/ Okta修補身分驗證漏洞,使用者名稱超過52個字元就有可能觸發 https://www.darkreading.com/vulnerabilities-threats/okta-fixes-auth-bypass-bug-three-month-lull 存在於X.org長達18年的高風險漏洞,恐導致Linux、Unix電腦遭到挾持 https://securityonline.info/cve-2024-9632-18-year-old-bug-in-x-org-server-leaves-systems-vulnerable-to-attack/ SharePoint漏洞遭到利用,駭客藉此取得初始存取管道 https://securityonline.info/cve-2024-38094-exploited-attackers-gain-domain-access-via-microsoft-sharepoint-server/ Atlassian Confluence漏洞遭到利用,攻擊者透過Titan網路從事挖礦攻擊 https://www.trendmicro.com/en_us/research/24/j/titan-network.html 蘋果對旗下產品發布更新,修補逾70個漏洞 https://www.securityweek.com/apple-patches-over-70-vulnerabilities-across-ios-macos-other-products/ 2.銀行/金融/保險/證券/金融監理 新聞及資安 2024金融科技防詐新態勢,聯合學習機制成最新亮點 https://www.ithome.com.tw/news/165869 安卓金融木馬ToxicPanda攻擊歐洲、香港、秘魯,感染逾1,500臺裝置 https://thehackernews.com/2024/11/new-android-banking-malware-toxicpanda.html 安卓惡意軟體FakeCall出現新手法,用戶聯繫銀行的電話會轉介到詐騙人員以便進行後續攻擊 https://www.ithome.com.tw/news/165836 New FakeCall Malware Variant Hijacks Android Devices for Fraudulent Banking Calls https://thehackernews.com/2024/11/new-fakecall-malware-variant-hijacks.html New Android Banking Malware 'ToxicPanda' Targets Users with Fraudulent Money Transfers https://thehackernews.com/2024/11/new-android-banking-malware-toxicpanda.html 3.信用卡/電子支付/行動支付/pay/支付系統/資安 杜絕信用卡盜刷盜綁 行動支付綁卡變麻煩 https://reurl.cc/Mjrg13 3大電子支付「嗶」進日本 一卡通跨境加碼綠點回饋 https://ec.ltn.com.tw/article/breakingnews/4852046 用現金付款已回不去 日常刷信用卡占近4成 https://reurl.cc/XRogXj 外籍人士赴陸更便利!境外銀聯卡可綁支付寶和微信支付 https://www.chinatimes.com/realtimenews/20241106002547-260409?chdtv 4.加密貨幣/數位貨幣/挖礦/區塊鍊/智能合約/WEB3 資安 比特幣暴漲惹歹徒覬覦?加密貨幣公司 WonderFi 執行長遇「綁架驚魂」 https://blockcast.it/2024/11/08/wonderfi-ceo-kidnapped-and-released-after-paying-1-million-ransom/ 稅金也可用比特幣、以太幣付?底特律成美國最大加密貨幣繳稅城 https://web3plus.bnext.com.tw/article/3273? 什麼是BTCFi?比特幣生態市值上兆,市場潛力花落誰家 https://web3plus.bnext.com.tw/article/3272 5.資安事件新聞 A.病毒木馬 / 殭屍網路 / 勒索軟體 / Adware /APT /後門程式/IOC 北韓駭客針對加密貨幣業者而來,散布macOS惡意程式 https://www.bleepingcomputer.com/news/security/north-korean-hackers-use-new-macos-malware-against-crypto-firms/ 臺灣企業臉書粉專管理員遭鎖定,駭客企圖散布竊資軟體LummaC2、Rhadamanthys https://www.ithome.com.tw/news/165853 駭客鎖定Windows電腦散播惡意捷徑檔,若不慎點選,會執行內含後門的虛擬機器 https://www.ithome.com.tw/news/165901 惡意軟體SteelFox利用自帶驅動程式手法竊取信用卡資料、挖掘加密貨幣 https://www.bleepingcomputer.com/news/security/new-steelfox-malware-hijacks-windows-pcs-using-vulnerable-driver/ 攻擊行動VEILDrive濫用微軟旗下服務,意圖發動網釣攻擊、散布惡意軟體 https://thehackernews.com/2024/11/veildrive-attack-exploits-microsoft.html 惡意軟體Pygmy Goat鎖定Sophos防火牆而來,意圖入侵政府機關網路環境 https://www.ithome.com.tw/news/165878 巴基斯坦駭客組織Transparent Tribe散布木馬程式ElizaRAT https://www.darkreading.com/cyberattacks-data-breaches/apt36-refines-tools-attacks-indian-targets 惡意廣告透過臉書轉傳,意圖散布竊資軟體SYS01stealer https://www.ithome.com.tw/news/165839 駭客組織APT-Q-37鎖定南亞散布木馬程式MiyaRat https://securityonline.info/new-trojan-miyarat-unleashed-by-bitter-group/ 研究人員發展繞過GPT 4o模型安全護欄手法,使其撰寫出惡意程式碼 https://www.ithome.com.tw/news/165828 竊資軟體Strela Stealer鎖定歐洲而來,利用WebDAV隱匿行蹤 https://www.ithome.com.tw/news/165929 Strela Stealer Targets Europe Stealthily Via WebDav https://cyble.com/blog/strela-stealer-targets-europe-stealthily-via-webdav/ Malicious PyPI Package 'Fabrice' Found Stealing AWS Keys from Thousands of Developers https://thehackernews.com/2024/11/malicious-pypi-package-fabrice-found.html Collection : Malware / Ransomware indicators https://otx.alienvault.com/pulse/59b299cb887f783890b33ad7 Microsoft Warns of Chinese Botnet Exploiting Router Flaws for Credential Theft https://thehackernews.com/2024/11/microsoft-warns-of-chinese-botnet.html Malware Campaign Uses Ethereum Smart Contracts to Control npm Typosquat Packages https://thehackernews.com/2024/11/malware-campaign-uses-ethereum-smart.html 5 Most Common Malware Techniques in 2024 https://thehackernews.com/2024/11/5-most-common-malware-techniques-in-2024.html Malicious NPM Packages Target Roblox Users with Data-Stealing Malware https://thehackernews.com/2024/11/malicious-npm-packages-target-roblox.html New CRON#TRAP Malware Infects Windows by Hiding in Linux VM to Evade Antivirus https://thehackernews.com/2024/11/new-crontrap-malware-infects-windows-by.html North Korean Hackers Target Crypto Firms with Hidden Risk Malware on macOS https://thehackernews.com/2024/11/north-korean-hackers-target-crypto.html B.行動安全 / iPhone / Android /穿戴裝置 /App / 5G / 即時通訊 Google修補安卓兩個零時差漏洞 https://www.ithome.com.tw/news/165888 Google Warns of Actively Exploited CVE-2024-43093 Vulnerability in Android System https://thehackernews.com/2024/11/google-warns-of-actively-exploited-cve.html Canada Orders TikTok to Shut Down Canadian Operations Over Security Concerns https://thehackernews.com/2024/11/canada-orders-tiktok-to-shut-down.html C.事件 / 駭客 / DDOS / APT / 雲端/ 暗網/ 徵才 / 國際資安事件 / 資安人力 2024數位經濟資安趨勢論壇:打造零售、物流、旅遊業資安防護網 https://www.informationsecurity.com.tw/article/article_detail.aspx?aid=11348 三陽工業證實部分資訊系統遭受網路攻擊 https://mops.twse.com.tw/mops/web/ajax_t05sr01_1?firstin=true&stp=1&step=1&SEQ_NO=1&SPOKE_TIME=174209&SPOKE_DATE=20241104&COMPANY_ID=2206 Snowflake資安事故嫌犯傳出在加拿大遭到逮捕 https://www.404media.co/suspected-snowflake-hacker-arrested-in-canada/ 「午夜暴雪」發動大規模網攻,微軟:受害者遍及全球 https://www.informationsecurity.com.tw/article/article_detail.aspx?aid=11353 區塊鏈技術進入軟體供應鏈攻擊,以太坊智慧合約成新媒介 https://www.ithome.com.tw/news/165905 新加坡電信疑似遭到中國駭客Volt Typhoon入侵 https://www.ithome.com.tw/news/165885 中國駭客MirrorFace以世界博覽會為誘餌,攻擊歐洲外交官 https://thehackernews.com/2024/11/china-aligned-mirrorface-hackers-target.html 中國遊戲玩家遭到鎖定,駭客利用惡意框架Winos 4.0從事攻擊行動 https://www.ithome.com.tw/news/165897 德國打算修改刑法內容,針對發現資安弱點的研究人員提供司法保障 https://www.ithome.com.tw/news/165931 北韓駭客Andariel使用鍵盤側錄工具攻擊美國企業組織 https://securityonline.info/new-keylogger-targeting-u-s-organizations-linked-to-north-korean-apt-group-andariel/ 駭客組織Anonymous Sudan近2年發動逾3.5萬次DDoS攻擊 https://securityonline.info/lameduck-a-threat-actor-mixing-politics-and-profit-with-over-35000-ddos-attacks/ 駭客聲稱從Nokia合作廠商竊得原始碼,該公司著手調查此事 https://www.ithome.com.tw/news/165858 Nokia坦承原始碼遭到外洩 https://www.bleepingcomputer.com/news/security/nokia-says-hackers-leaked-third-party-app-source-code/ Cryptocurrency Enthusiasts Targeted in Multi-Vector Supply Chain Attack https://checkmarx.com/blog/cryptocurrency-enthusiasts-targeted-in-multi-vector-supply-chain-attack/ Attacker Abuses Victim Resources to Reap Rewards from Titan Network https://www.trendmicro.com/en_us/research/24/j/titan-network.html Inside Iran's Cyber Playbook: AI, Fake Hosting, and Psychological Warfare https://thehackernews.com/2024/11/inside-irans-cyber-playbook-ai-fake.html German Police Disrupt DDoS-for-Hire Platform dstat[.]cc; Suspects Arrested https://thehackernews.com/2024/11/german-police-disrupt-ddos-for-hire.html Cyber Threats That Could Impact the Retail Industry This Holiday Season (and What to Do About It) https://thehackernews.com/2024/11/cyber-threats-that-could-impact-retail.html Critical Flaws in Ollama AI Framework Could Enable DoS, Model Theft, and Poisoning https://thehackernews.com/2024/11/critical-flaws-in-ollama-ai-framework.html 國際警方破獲逾2.2萬個用於網路犯罪的惡意IP位址,逮捕41名嫌犯 https://www.ithome.com.tw/news/165875 INTERPOL Disrupts Over 22,000 Malicious Servers in Global Crackdown on Cybercrime https://thehackernews.com/2024/11/interpols-operation-synergia-ii.html FBI Seeks Public Help to Identify Chinese Hackers Behind Global Cyber Intrusions https://thehackernews.com/2024/11/fbi-seeks-public-help-to-identify.html SteelFox and Rhadamanthys Malware Use Copyright Scams, Driver Exploits to Target Victims https://thehackernews.com/2024/11/steelfox-and-rhadamanthys-malware-use.html China-Aligned MirrorFace Hackers Target EU Diplomats with World Expo 2025 Bait https://thehackernews.com/2024/11/china-aligned-mirrorface-hackers-target.html IcePeony and Transparent Tribe Target Indian Entities with Cloud-Based Tools https://thehackernews.com/2024/11/icepeony-and-transparent-tribe-target.html D.資料外洩/個資法/GDPR/網路詐騙/網路釣魚/盜刷/假新聞/網路霸凌/帳號安全 密碼管理解決方案業者LastPass提出警告,有冒牌客服企圖竊取用戶資料 https://www.bleepingcomputer.com/news/security/lastpass-warns-of-fake-support-centers-trying-to-steal-customer-data/ 施耐德電機傳出Jira伺服器資料外洩,駭客聲稱竊得40 GB資料 https://www.ithome.com.tw/news/165854 電子簽名服務DocuSign的API驚傳遭到濫用,駭客寄送大量假發票引誘企業上當 https://www.ithome.com.tw/news/165851 加拿大證實中國駭客在近5年於政府機關搜括機敏資料 https://www.darkreading.com/cyberattacks-data-breaches/canada-prc-backed-threat-actors 網釣工具包「修狗」鎖定歐美、澳洲、日本而來 https://hackread.com/gou-phishing-kit-hits-uk-us-japan-australia-sectors/ 網釣工具包「沉淪」假冒美國郵政署而來 https://www.infosecurity-magazine.com/news/chenluns-phishing-tactics-target/ 跟上國際腳步,臺灣Passkey應用實例出爐 https://www.ithome.com.tw/news/165788 Midnight Blizzard conducts large-scale spear-phishing campaign using RDP files https://www.microsoft.com/en-us/security/blog/2024/10/29/midnight-blizzard-conducts-large-scale-spear-phishing-campaign-using-rdp-files/ Massive Git Config Breach Exposes 15,000 Credentials; 10,000 Private Repos Cloned https://thehackernews.com/2024/11/massive-git-config-breach-exposes-15000.html New Phishing Kit Xiū gǒu Targets Users Across Five Countries With 2,000 Fake Sites https://thehackernews.com/2024/11/new-phishing-kit-xiu-gou-targets-users.html Canadian Suspect Arrested Over Snowflake Customer Breach and Extortion Attacks https://thehackernews.com/2024/11/canadian-suspect-arrested-over.html South Korea Fines Meta $15.67M for Illegally Sharing Sensitive User Data with Advertisers https://thehackernews.com/2024/11/south-korea-fines-meta-1567m-for.html Google Cloud to Enforce Multi-Factor Authentication by 2025 for All Users https://thehackernews.com/2024/11/google-cloud-to-enforce-multi-factor.html A Hacker's Guide to Password Cracking https://thehackernews.com/2024/11/a-hackers-guide-to-password-cracking.html E.研究報告/工具 駭客改造公開工具EDRsandblast發動自帶驅動程式攻擊,企圖繞過EDR代理程式防護機制 https://www.ithome.com.tw/news/165879 5 SaaS Misconfigurations Leading to Major Fu*%@ Ups https://thehackernews.com/2024/11/5-saas-misconfigurations-leading-to.html 2025年SaaS安全風險報告:90% SaaS 應用程式及AI工具仍未受到管理 https://www.informationsecurity.com.tw/article/article_detail.aspx?aid=11347 Leveraging Wazuh for Zero Trust security https://thehackernews.com/2024/11/leveraging-wazuh-for-zero-trust-security.html 9 Steps to Get CTEM on Your 2025 Budgetary Radar https://thehackernews.com/2024/11/9-steps-to-get-ctem-on-your-2025.html F.商業 零時差、無感式攻擊時代來臨! 突破性CDR與沙箱技術提高企業防禦力 https://www.informationsecurity.com.tw/article/article_detail.aspx?aid=11351 思科預測「人工智慧」將成為營收主要來源!基礎建設、網路安全和客戶體驗為關鍵驅動力 https://www.informationsecurity.com.tw/article/article_detail.aspx?aid=11346 Acronis:2024上半年電子郵件攻擊激增293%,資料保護的重要性俱增 https://www.informationsecurity.com.tw/article/article_detail.aspx?aid=11354 Microsoft Delays Windows Copilot+ Recall Release Over Privacy Concerns https://thehackernews.com/2024/11/microsoft-delays-windows-copilot-recall.html 緯創小金雞全景軟體10月底由興櫃轉為上櫃 https://money.udn.com/money/story/11074/8304379 CrowdStrike買下SaaS安全控管業者Adaptive Shield https://www.ithome.com.tw/news/165900 Google Cloud明年將強制執行多因素身分驗證 https://www.ithome.com.tw/news/165866 Google揭露AI抓漏專案Big Sleep https://www.ithome.com.tw/news/165835 The vCISO Academy: Transforming MSPs and MSSPs into Cybersecurity Powerhouses https://thehackernews.com/2024/11/the-vciso-academy-transforming-msps-and.html G.政府 副總統蕭美琴臺灣駭客年會企業場致詞強調,AI應該成為資安的助力 https://www.ithome.com.tw/news/165837 台灣睽違近10年主辦國際資安年會 蕭美琴:資安為政府施政首要任務 https://news.cnyes.com/news/id/5768233 蕭美琴強調資安即國安 臺灣視為國家安全的優先要務 https://reurl.cc/E6keOK 全球資安專家齊聚台灣2大盛會 蕭美琴揭政府最優先工作 https://www.chinatimes.com/realtimenews/20241107004231-260407?ctrack=pc_main_rtime_p03&chdtv 政府111簡訊平台被詐騙集團破解?數發部:未查獲駭客入侵 https://www.technice.com.tw/techmanage/infosecurity/149442/ 台灣數位發展部的三大任務 https://reurl.cc/0dLRYb 數位產業署「5G專頻專網創新應用體驗展」開幕 見證通訊傳播科技引領數位轉型 https://www.thehubnews.net/archives/451623 數位產業署推動六都智慧治理聯盟|公私民合作實現數位共榮 https://www.tcpttw.com/2024/11/137475/ H.工控系統/ICS/SCADA/IOT/物聯網/車聯網/電動車/人工智慧/AI/ML/人臉辨識/醫療 相關資安 ABB智慧建築能源管理系統存在重大漏洞,恐讓攻擊者接管、遠端執行程式碼 https://www.ithome.com.tw/news/165928 海康威視網路攝影機存在漏洞,若不處理可被用於明文傳輸帳密 https://securityonline.info/hikvision-patches-security-flaw-in-network-cameras-preventing-cleartext-credential-transmission/ I.教育訓練 資安事件發生必要知道的復原程序,降低傷害 https://www.ithome.com.tw/pr/163614 iPAS資訊安全工程師中級筆記 https://hackmd.io/@Not/iPASInformationSecuritySpecialist iPas資安工程師證照考前研習 https://reurl.cc/GEbA3p iPAS◆資訊安全規劃實務◆中級測驗題庫彙編(123題) https://reurl.cc/orlD1g GCP Associate Cloud Engineer (ACE) 學習心得、教材資源與筆記分享 — 學習天然高可用與零信任設計 https://medium.com/blacksecurity/gcp-associate-cloud-engineer-78f736aee7ad Coursera 盤點 7 項雲端資安認證,高薪跳板都在這了! https://buzzorange.com/techorange/2022/07/12/cloud-security-certificates/ 一般人也能拿到國際資安認證!CSCU安全電腦使用者認證課程 https://www.ithome.com.tw/pr/160954 全球網絡安全勞動力失衡 (ISC)2免費課程及考試填補人才缺口 https://reurl.cc/m39MDj CISSP資安認證的8大領域 https://2formosa.blogspot.com/2022/12/CISSP-topic-domains.html CISSP考試心得 https://reurl.cc/KbY83j CISSP考試心得 – Benson https://reurl.cc/GbWvxd 目標導向-20天光速考過CISSP https://reurl.cc/2Zq6zn CISSP證照考試實戰心得 第一章:初期準備工作 https://netmag.tw/2022/06/17/the-cissp-has-learned-the-first-chapter-in-actual-combat CISSP證照考試實戰心得 第二章:規律且有紀律的讀書策略 https://netmag.tw/2022/07/01/the-cissp-is-in-the-field-of-combat-chapter-two-regular-and-disciplined-reading-strategies CISSP證照考試實戰心得 第三章:終極一戰 https://netmag.tw/2022/07/12/the-cissp-has-learned-a-third-chapter-in-actual-combat-experience-the-ultimate-battle Quick CISSP Infographic for IPSec https://www.studynotesandtheory.com/single-post/quick-cissp-infographic-for-ipsec CSSLP Certification - Security models in F# https://github.com/vbocan/csslp Certified Secure Software Lifecycle Professional in bullet points https://github.com/joeyhage/csslp-notes CPSA(CREST Practitioner Security Analyst) 資安分析師考試心得 https://tech-blog.cymetrics.io/posts/huli/crest-cpsa-prepare/ EC-Council CEH v11 考試心得、改版資訊以及準備方向 2021、2022 https://reurl.cc/1oyEM8 CEH v11 考試心得與準備方式 https://blog.sean.taipei/2022/01/ceh CEH https://github.com/a3cipher/CEH CodeRed by EC-Council https://github.com/codered-by-ec-council EC-Council CEH Practical / Master 準備心得 — 讓理論與實作相輔相成的學習 https://medium.com/blacksecurity/ceh-practical-master-3e80cac180a2 EC-Council CEHP考試準備心得 https://hackmd.io/@9dCJrgb6QHGd8dRfgHO0zg/r14xNn1po My ceh practical notes https://github.com/dhabaleshwar/CEHPractical/blob/main/Everything%20You%20Need.md CEHP課程筆記 https://hackmd.io/@nfu-johnny/B1Ju_BMPR ECSA v10 考試心得與讀書資料分享/ ECSA v10 Review and Study Materials https://medium.com/blacksecurity/ecsa-v10-1ec76c0eb7d4 EC-Council ECSA資安分析專家 v10 考試心得分享 https://javaxtalk.blogspot.com/2019/05/ec-council-ecsa-v10.html 20180817 EC-Council ECSA v10 PASS https://www.ptt.cc/bbs/License/M.1534571704.A.5BA.html 關於EC-Council CPENT和LPT Master滲透測試證照準備方式及心得分享 https://medium.com/@ChadSecurity/%E9%97%9C%E6%96%BCec-council-cpent%E5%92%8Clpt-master%E6%BB%B2%E9%80%8F%E6%B8%AC%E8%A9%A6%E8%AD%89%E7%85%A7%E6%BA%96%E5%82%99%E6%96%B9%E5%BC%8F%E5%8F%8A%E5%BF%83%E5%BE%97%E5%88%86%E4%BA%AB-efb63de00a8d 深度解析 CPENT 考試心得、以及與 OSCP 的比較 https://reurl.cc/41eL8v EC-Council CPENT v1 滲透測試認證 – 內容及心得分享 https://hackercat.org/pentesting/ec-council-cpent-v1-experience-review CPENT 從暴力到破解 https://hackmd.io/@3WAsoRFgSlyy7pm10p60kg/ByO0zs295 Ec-Council CPENT心得 - 資安菜鳥從CEH到LPT Master https://4hsienyang.medium.com/cpent-lpt-master-ccaebf2dbc7f CPENT考試心得分享:一次拿到 LPT 滲透測試大師認證 https://ucom.uuu.com.tw/web/Testimony/Article/4404 kaizensecurity/CPENT https://github.com/kaizensecurity/CPENT/tree/master CPENT : Pentesting like NO OTHERS ! https://www.linkedin.com/pulse/cpent-pentesting-like-others-belly-rachdianto/ Journey of My CPENT Exam https://medium.com/techiepedia/journey-of-my-cpent-exam-3a5d7ee6d917 [備考心得]CompTIA Security+ (SY0–601) 上篇 https://reurl.cc/M053DK [備考心得]CompTIA Security+ (SY0–601) 下篇 https://reurl.cc/M053Gv comptia-security-plus https://github.com/ajfuto/comptia-security-plus security-plus https://github.com/fjavierm/security-plus CompTIA Security+ Certification Practice Test Questions https://www.examcompass.com/comptia/security-plus-certification/free-security-plus-practice-tests#google_vignette 不只是工程師才要懂的 App 資訊安全:取得資安檢測合格證書血淚史(iT邦幫忙鐵人賽系列書) https://news.pchome.com.tw/living/books/20220202/index-64375841669874292009.html App防駭學,資安防護實戰課程全面提升安全觀念 https://www.ithome.com.tw/pr/161505 OSEP (Evasion Techniques and Breaching Defenses (PEN-300) 心得分享 https://hackmd.io/@henry-ko/HyQ56e8eF OSEP (Evasion Techniques and Breaching Defenses (PEN-300) http://github.com/In3x0rabl3/OSEP OSCP(Offensive Security Certified Professional) https://github.com/0x584A/oscp-notes/tree/master ISACA Certified Information Systems Auditor® (CISA) 國際電腦稽核師認證準備歷程心得、申請流程分享- 2023年 https://reurl.cc/aVLoX9 Learn NIST Inside Out With 21 Hours of Training @ 86% OFF https://thehackernews.com/2022/06/learn-nist-inside-out-with-21-hours-of.html 駭客與國家: 網路攻擊與地緣政治新常態 The hacker and the state: cyber attacks and the new normal of geopolitic https://reurl.cc/D3nKKj Practical Network Penetration Tester (PNPT) Certification Review https://tmc222.medium.com/practical-network-penetration-tester-pnpt-certification-review-4280e4e164df WUSON常用的基本詞彙 https://choson.lifenet.com.tw/?p=1958 證照仍是學習資安基本功的主要管道,有專家打造「資安證照地圖」 https://www.ithome.com.tw/news/156754 用證照證明自己實力之餘,更應將證照視為督促學習的最大動力 https://www.ithome.com.tw/news/156756 打破證照誤解與迷思,資安專家帶你釐清資安證照的意義 https://www.ithome.com.tw/news/156755 Accelerate Your Career with the Global Leader in Cyber Security Training https://www.sans.org/mlp/promo-partnership-hacker-news/ 【成大資安社社課】資安禁術 - 逆向工程地獄試煉 https://www.youtube.com/watch?v=4Yc3-9CjG6U 透過實務演練,教你建立實作標準的安全SOP流程 https://www.ithome.com.tw/pr/163514 6.近期資安活動及研討會 Lets talk about Entertainment 2024/11/9 https://www.meetup.com/i-t-social-cafe/events/304176693/ ISC2 Taipei Chapter 2024年度會員大會暨「共益資安 共榮台灣」資訊安全研討會 2024/11/9 https://isc2taipei.kktix.cc/events/allforsecuritysecurityforall Use Predictive and Generative AI to Solve Problems 预测式和生成式人工智能 2024/11/9 https://www.meetup.com/hands-on-ai/events/304040666/ 八王子 WordPress Meetup 2024年11月度「一からノーコードでWordPressサイト制作・3」2024/11/9 https://www.meetup.com/tokyo-wordpress-meetup/events/304177700/ HITCON 菁英人才交流活動 2024/11/9 - 2024/11/10 https://hitcon.kktix.cc/events/hitcon-ctf 【2024/11】WordPress 彩虹小聚:重塑網站靈魂|如何運用文字打造網站獨特個性2024/11/11 https://www.meetup.com/taipei-wordpress/events/304093283/ DQS Taiwan: TISAX® 國際車載資安驗證標準研討會 2024/11/11 https://www.accupass.com/event/2410030757211689575196 Algorithms Study Group! 2024/11/12 https://www.meetup.com/codeseoul/events/rslrltygcpbqb/ Trustrade Business Networking powered by ZOOM 2024/11/12 https://www.meetup.com/sophisticated-blockchain-cryptocurrency-professionals/events/ffdghsygcpbqb/ Trustrade weekly TUESDAY ZOOM meeting! 2024/11/12 https://www.meetup.com/hong-kong-blockchain-business/events/rzkwqsygcpbqb/ Silicon Valley Business Networking (Online) 2024/11/12 https://www.meetup.com/hong-kong-startup-idea-to-ipo/events/304262951/ Self-Taught Coding Tuesdays - Study, Code, Design, Build, Network 2024/11/12 https://www.meetup.com/taiwan-code-camp/events/304159943/ 後量子密碼安全產品開發工作坊-加密資安共識會議 2024/11/12 https://www.accupass.com/event/2410300724121165776300 Free OPEN Passes to CloudX 2024 2024/11/12 https://www.meetup.com/aws-user-group-philippines/events/304057059/ [ONLINE OPEN CAMPUS] Discover our Web Development & Data Science bootcamps!2024/11/13 https://www.meetup.com/le-wagon-seoul/events/304140213/ [HYBRID OPEN CAMPUS] Discover our Web Development & Data Science bootcamps! 2024/11/13 https://www.meetup.com/le-wagon-tokyo-coding-station/events/303914082/ HackingThursday 固定聚會 台北場 Taipei 2024/11/14 https://www.meetup.com/hackingthursday/events/fcmtntygcpbsb/ 國際自動化協會臺灣分會:融合與創新:數位轉型下的工控場域資安挑戰 2024/11/14 https://isatw.kktix.cc/events/isa-2024q4-isataiwan-meeting 網路自由小聚 [11月] :全球數位人權大會 RightsCon 25 Taipei 前導介紹會 2024/11/14 https://ocftw.kktix.cc/events/internetfreedom-nov2024 Slot 1 (APAC/EMEA) 2024/11/14 https://www.meetup.com/coop-casual-conference/events/lxqrltygcpbsb/ Pitch Your Ideas to Investors, Online 2024/11/14 https://www.meetup.com/hanoi-startup-founder-101/events/303786941/ 打造 Microsoft 365 資料安全堡壘 2024/11/15 https://www.accupass.com/event/2410240717102969754260 2024 第九屆區塊鏈愛好者年會 2024/11/18 https://www.accupass.com/event/2409130849071943030502 Trustrade weekly TUESDAY ZOOM meeting! 2024/11/19 https://www.meetup.com/hong-kong-blockchain-business/events/rzkwqsygcpbzb/ Algorithms Study Group! 2024/11/19 https://www.meetup.com/codeseoul/events/rslrltygcpbzb/ Self-Taught Coding Tuesdays - Study, Code, Design, Build, Network 2024/11/19 https://www.meetup.com/taiwan-code-camp/events/304284758/ Trustrade Business Networking powered by ZOOM 2024/11/19 https://www.meetup.com/sophisticated-blockchain-cryptocurrency-professionals/events/ffdghsygcpbzb/ Silicon Valley Business Networking (Online) 2024/11/19 https://www.meetup.com/hong-kong-startup-idea-to-ipo/events/xppjhtygcpbzb/ 資安五四三 2024/11/20 https://csa.kktix.cc/events/202411-543 Machine Learning Tech Talks 2024/11/20 https://www.meetup.com/machine-learning-tech-talks/events/304154748/ Slot 1 (APAC/EMEA) 2024/11/21 https://www.meetup.com/coop-casual-conference/events/lxqrltygcpbcc/ Session #9: Google AI Seminar (Virtual) 2024/11/21 https://www.meetup.com/meetup-group-epigxybb/events/304205745/ HackingThursday 固定聚會 台北場 Taipei 2024/11/21 https://www.meetup.com/hackingthursday/events/fcmtntygcpbcc/ [Online] Philippine Bitcoin meetup 2024/11/21 https://www.meetup.com/philippine-bitcoiners/events/300961127/ 【安碁學苑】資安職能培訓|安全程式開發管理師 2024/11/23 ~ 2024/12/21 https://acsiacad.kktix.cc/events/308914 Taoyuan WordPress Café 桃園咖啡小聚 #42 2024/11/23 https://www.meetup.com/taoyuan-wordpress-meetup/events/304123625/ #130 swirl: The Package for Learning and Teaching Data Science in R 2024/11/23 https://www.meetup.com/r-user-group-philippines/events/296013262/ Exploring Azure AI Services and Certification Pathways 2024/11/25 https://www.meetup.com/rladies-taipei/events/303989737/ Algorithms Study Group! 2024/11/26 https://www.meetup.com/codeseoul/events/rslrltygcpbjc/ Self-Taught Coding Tuesdays - Study, Code, Design, Build, Network 2024/11/26 https://www.meetup.com/taiwan-code-camp/events/xfxtjtygcpbjc/ Trustrade Business Networking powered by ZOOM 2024/11/26 https://www.meetup.com/sophisticated-blockchain-cryptocurrency-professionals/events/ffdghsygcpbjc/ Trustrade weekly TUESDAY ZOOM meeting! 2024/11/26 https://www.meetup.com/hong-kong-blockchain-business/events/rzkwqsygcpbjc/ Silicon Valley Business Networking (Online) 2024/11/26 https://www.meetup.com/hong-kong-startup-idea-to-ipo/events/xppjhtygcpbjc/ Free Startup Fundraising Office Hours Expert AMA with Angel Investor Scott Fox! 2024/11/27 https://www.meetup.com/taipei-startups-investors-masterminds-network/events/bmzxltygcpbkc/ 【2024 RMN ASIA】AI 驅動零售變革 · RMN重新定義行銷生態 2024/11/28 https://www.accupass.com/event/2409050256092193763570 Slot 1 (APAC/EMEA) 2024/11/28 https://www.meetup.com/coop-casual-conference/events/lxqrltygcpblc/ HackingThursday 固定聚會 台北場 Taipei 2024/11/28 https://www.meetup.com/hackingthursday/events/fcmtntygcpblc/ 【TIRI線上董事、公司治理主管進修課程】漫談資安治理的盲點與對策 2024/11/29 https://www.accupass.com/event/2408290602361963077719 金融反詐 X AI深偽:資安實務專題講座(北部場) 2024/11/29 https://isipevent.kktix.cc/events/n165isip Threat Analyst Summit 2024 威脅分析師高峰會 2024/12/11 ~ 2024/12/12 https://teamt5tw.kktix.cc/events/tas2024 金融反詐 X AI深偽:資安實務專題講座(中部場)2024/12/16 https://isipevent.kktix.cc/events/m165isip Free Startup Fundraising Office Hours Expert AMA with Angel Investor Scott Fox! 2024/12/25 https://www.meetup.com/taipei-startups-investors-masterminds-network/events/bmzxltygcqbhc/