Outlook·ºÆð¹ÊÕϵ¼ÖÂÓû§»á¼ûÕË»§Ê±ÊÕµ½503¹ýʧÐÂÎÅ
Ðû²¼Ê±¼ä 2023-06-071¡¢Outlook·ºÆð¹ÊÕϵ¼ÖÂÓû§»á¼ûÕË»§Ê±ÊÕµ½503¹ýʧÐÂÎÅ
¾ÝýÌå6ÔÂ5ÈÕ±¨µÀ£¬Î¢ÈíOutlook·ºÆð¹ÊÕÏÓ°ÏìÁËÈ«ÇòµÄÓû§£¬µ¼ÖÂÎÞ·¨·¢Ë͵ç×ÓÓʼþºÍÖÎÀíÈÕÀú¡£ÔÚ»á¼û¸ÃÍøվʱ£¬Óû§ÏÖÔÚ»áÊÕµ½¡°HTTP¹ýʧ503£º·þÎñ²»¿ÉÓá±µÄÐÂÎÅ£¬ÌåÏÖ·þÎñÔÝʱ²»¿ÉÓûò·þÎñÆ÷¹ýÔØ¡£Òƶ¯OutlookÓ¦ÓóÌÐòÒ²ÎÞ·¨ÅþÁ¬·þÎñ¡£ÏÖÔÚ£¬Î¢ÈíµÄÊÖÒÕÍŶӿÉÄÜÕýÔÚÆð¾¢Ñо¿½â¾ö¼Æ»®¡£¾ÝºóÐø¸üУ¬Î¢ÈíÒѾÐÞ¸´Á˸Ã503¹ýʧ£¬Outlook.comÏÖÔÚÓÖ×îÏȼÓÔØ£¬µ«Óû§ÈÔÈ»ÎÞ·¨·¢ËÍ»ò·¿ªÓʼþ¡£
https://www.bleepingcomputer.com/news/microsoft/microsofts-outlookcom-is-down-again-on-mobile-web/
2¡¢GoogleÐÞ¸´ChromeÖÐÒѱ»Ê¹ÓõÄÎó²îCVE-2023-3079
GoogleÔÚ6ÔÂ5ÈÕÐû²¼µÄÇå¾²¸üÐÂÖУ¬ÐÞ¸´ÁËÒ»¸öÒѱ»ÔÚҰʹÓõÄÎó²î£¨CVE-2023-3079£©¡£ÕâÊDZ£´æÓÚV8 JavaScriptÒýÇæÖеÄÀàÐÍ»ìÏýÎó²î£¬¸Ã¹«Ë¾ÉÐδÐû²¼ÓйظÃÎó²îÒÔ¼°ÔõÑùÔÚ¹¥»÷ÖÐʹÓõÄÏêϸÐÅÏ¢¡£ÕâÊÇGoogleÔÚ½ñÄêÐÞ¸´µÄµÚÈý¸öÁãÈÕÎó²î£¬Ç°Á½¸ö»®·ÖΪV8 JavaScriptÒýÇæÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2023-2033£©ºÍSkiaͼÐοâÖеÄÕûÊýÒç³öÎó²î£¨CVE-2023-2136£©¡£
https://securityaffairs.com/147137/hacking/chrome-zero-day-3.html
3¡¢KeePassÐÞ¸´´ÓÄÚ´æ¼ìË÷Ã÷ÎÄÖ÷ÃÜÂëµÄÎó²îCVE-2023-32784
ýÌå6ÔÂ5Èճƣ¬KeePassÐû²¼ÁË2.54°æ±¾£¬ÐÞ¸´ÁË¿É´ÓÓ¦ÓóÌÐòÄÚ´æÖмìË÷Ã÷ÎÄÖ÷ÃÜÂëµÄÎó²î£¨CVE-2023-32784£©¡£5Ô·ݣ¬Ñо¿Ö°Ô±vdohneyÅû¶Á˸ÃÎó²î²¢Ðû²¼ÁËÒ»¸öPoC¡£¸ÃÎó²îÔ´ÓÚKeePass 2.XÖÐʹÓÃÁËÒ»¸ö×Ô½ç˵¿ª·¢µÄÎı¾¿òSecureTextBoxEx¾ÙÐÐÃÜÂëÊäÈë¡£¸ÃÎı¾¿ò²»µ«ÓÃÓÚÖ÷ÃÜÂëµÄÊäÈ룬²¢ÇÒ»¹ÓÃÓÚKeePassµÄÆäËüµØ·½£¬ÈçÃÜÂë±à¼¿ò£¬¹¥»÷Õß¿ÉʹÓÃËüÀ´»Ö¸´ÆäÄÚÈÝ¡£±ðµÄ£¬KeePass 2.5.4ÐÂÔöÁËÆäËüÇå¾²ÔöÇ¿¹¦Ð§£¬Ñо¿Ö°Ô±Ò²ÎªÎÞ·¨Éý¼¶µÄÓû§ÌṩÁË»º½âÒªÁì¡£
https://securityaffairs.com/147109/security/keepass-fixed-the-bug-that-allows-the-extraction-of-the-cleartext-master-password.html
4¡¢Group-IBÅû¶PostalFuriousÕë¶ÔÖж«µØÇøµÄ´¹ÂÚÔ˶¯
Group-IBÓÚ6ÔÂ1ÈÕÅû¶Á˽üÆÚPostalFuriousÕë¶ÔÖж«µØÇøµÄ´¹ÂÚÔ˶¯¡£Group-IBÓÚ4ÔÂÊ״η¢Ã÷µ½¸ÃÍÅ»ïͨ¹ýð³äÓÊÕþÆ·ÅƺÍÊÕ·ÑÔËÓªÉÌÀ´¹¥»÷ÑÇÌ«µØÇøµÄÓû§¡£ÏÖÔÚ£¬¸ÃÍÅ»ïÒѽ«ÓªÒµ¹æÄ£À©Õ¹ÖÁÖж«¡£4ÔÂ15ÈÕ×îÏȵÄÔ˶¯ÖУ¬¹¥»÷ÕßÏòÓû§·¢ËÍ°üÀ¨Ëõ¶ÌURL´¹ÂÚÁ´½ÓµÄÐéα¶ÌÐÅ¡£ÕâЩ¶ÌÐÅÊÇ´ÓÔÚÂíÀ´Î÷ÑǺÍÌ©¹ú×¢²áµÄµç»°ºÅÂëÒÔ¼°Í¨¹ýiMessage·þÎñµÄÓʼþµØµã·¢Ë͵ġ£Á´½ÓÓеØÀíΧÀ¸£¬Ö»ÄÜ´Ó°¢ÁªÇõµÄIPµØµã»á¼û¡£¹¥»÷ÕßÌìÌ춼ÔÚ×¢²áеĴ¹ÂÚÓòÃû£¬ÒÔÀ©´óÓ°Ïì¹æÄ£¡£4ÔÂ29ÈÕ·¢Ã÷Á˵ڶþ´Î½üºõÏàͬµÄÔ˶¯£¬Ã°³äÁË°¢ÁªÇõÓÊÕþÔËÓªÉÌ¡£
https://www.group-ib.com/media-center/press-releases/postalfurious/
5¡¢Scrubs & Beyondй¶400GBµÄÓû§ºÍÒøÐп¨ÏêϸÐÅÏ¢
¾Ý6ÔÂ5ÈÕ±¨µÀ£¬Scrubs & BeyondÒÔ´¿Îı¾ÐÎʽй¶ÁË400 GBµÄÓû§PIIºÍÒøÐп¨ÐÅÏ¢¡£¸ÃÊý¾Ý¿âÓÚ5ÔÂ16ÈÕ̻¶£¬Ñо¿Ö°Ô±ÔÚ5ÔÂ25ÈÕ·¢Ã÷£¬ÒÔºóÕâЩÐÅÏ¢Ò»Ö±´¦ÓڿɹûÕæ»á¼ûµÄ״̬¡£ÏÖÔÚ£¬·þÎñÆ÷ÓµÓÐÁè¼Ý100000Ìõ¿Í»§¼Í¼£¬×ܼÆ400 GB£¬ÇÒÊý¾Ý¿â¾ÞϸºÍÓû§ÊýÄ¿Ëæ×ÅÌìÌìÐÂÔöµÄÐÅÏ¢¶øÒ»Ö±ÔöÌí¡£Ð¹Â¶ÐÅÏ¢Éæ¼°ÐÕÃû¡¢µç»°¡¢µØµãºÍÄÚ²¿Æ¾Ö¤µÈСÎÒ˽¼ÒÐÅÏ¢£¬ÒÔ¼°ÒøÐп¨ºÅ¡¢CVV´úÂëºÍPayPalÖ§¸¶ÈÕÖ¾µÈ²ÆÎñÐÅÏ¢¡£ÏÖÔÚ£¬¸Ã¹«Ë¾²¢Î´¶Ô´ËÊÂ×÷³ö»ØÓ¦£¬Ò²Î´½«¸ÃÊý¾Ý¿â±£»¤ÆðÀ´¡£
https://www.hackread.com/scrubs-beyond-leaks-400gb-of-user-data/
6¡¢KasperskyÏêÊöÓëSatacomÏà¹ØµÄ¶ñÒâÈí¼þ·Ö·¢Ô˶¯
6ÔÂ5ÈÕ£¬Kaspersky³ÆÆä·¢Ã÷Ò»ÆðеĶñÒâÈí¼þÔ˶¯£¬Ê¹ÓÃSatacom downloader£¨Ò²³ÆLegionLoader£©À´·Ö·¢ÇÔÈ¡¼ÓÃÜÇ®±ÒµÄä¯ÀÀÆ÷À©Õ¹¡£Ñ¬È¾Ê¼ÓÚÒ»¸öZIPÎļþ£¬ÆäÖаüÀ¨¼¸¸öÕýµ±µÄDLLºÍÒ»¸ö¶ñÒâµÄSetup.exe£¬Óû§ÐèÒªÊÖ¶¯Ö´ÐÐÕâЩÎļþ²Å»ªÆô¶¯Ñ¬È¾Á´¡£Ö®ºó£¬Ä¿µÄ±»Öض¨Ïòµ½Î±×°³ÉÎļþ¹²Ïí·þÎñµÄÍøÕ¾À´·Ö·¢¶ñÒâÈí¼þ¡£Ò»µ©¶ñÒâÈí¼þ±»Ö´ÐУ¬Ëü¾Í»áʹÓÃÀú³Ì×¢ÈëÊÖÒÕÀ´Èƹýɱ¶¾Èí¼þµÄ¼ì²â¡£±ðµÄ£¬QUADS¹ã¸æ²å¼þÒѱ»ÓÃÀ´Èö²¥Satacom¡£
https://securelist.com/satacom-delivers-cryptocurrency-stealing-browser-extension/109807/