Dr.Web·¢Ã÷ʹÓÃWin10 ISOºÍEFI·ÖÇø·Ö·¢ClipperµÄÔ˶¯
Ðû²¼Ê±¼ä 2023-06-151¡¢Dr.Web·¢Ã÷ʹÓÃWin10 ISOºÍEFI·ÖÇø·Ö·¢ClipperµÄÔ˶¯
Dr.WebÔÚ6ÔÂ13ÈÕ³ÆÆäÔÚһЩµÁ°æWindows 10 ISOÖз¢Ã÷Á˼ÓÃÜÇ®±ÒЮÖƳÌÐò£¬¹¥»÷Õßͨ¹ýTorrent tracker·Ö·¢ËüÃÇ¡£Õâ¸öľÂí±»³ÆΪTrojan.Clipper.231£¬¿É½«¼ôÌù°åÖеļÓÃÜÇ®±ÒÇ®°üµØµãÌæ»»³É¹¥»÷Õߵĵص㡣×èÖ¹ÏÖÔÚ£¬¹¥»÷ÕßÒÑÀÖ³ÉÇÔÈ¡Á˼ÛÖµÔ¼19000ÃÀÔªµÄ¼ÓÃÜÇ®±Ò¡£¸ÃÔ˶¯»¹Ê¹ÓÃEFI£¨¿ÉÀ©Õ¹¹Ì¼þ½Ó¿Ú£©·ÖÇø×÷ΪClipper×é¼þµÄÇå¾²´æ´¢¿Õ¼ä£¬Ö¼ÔÚÈƹý¶ñÒâÈí¼þ¼ì²â¡£Ñо¿Ö°Ô±½¨Òé²»ÒªÏÂÔصÁ°æ²Ù×÷ϵͳ¡£
https://news.drweb.com/show/?i=14712&lng=en
2¡¢ÄÏ·Ç¿ª·¢ÒøÐÐ͸¶Æä·þÎñÆ÷ºÍÎļþµÈ±»AkiraÍÅ»ï¼ÓÃÜ
¾ÝýÌå6ÔÂ14ÈÕ±¨µÀ£¬ÄÏ·Ç¿ª·¢ÒøÐУ¨DBSA£©Ôâµ½ÁËAkiraÍÅ»ïµÄÀÕË÷¹¥»÷¡£Õâ¼Ò¹úÓÐÒøÐÐ͸¶£¬¹¥»÷ʼÓÚ5ÔÂ21ÈÕ×óÓÒ£¬Æä·þÎñÆ÷¡¢ÈÕÖ¾ÎļþºÍÎļþ±»¼ÓÃÜ¡£²¿·ÖÐÅÏ¢¿ÉÄÜÒѱ»²»·¨»á¼û£¬Éæ¼°¶Êº͹ɶ«µÄСÎÒ˽¼ÒÐÅÏ¢£¬ÓëDBSA±£´æÉÌÒµ»ò¹ÍÓ¶¹ØϵµÄÏêϸÐÅÏ¢£¬ÒÔ¼°ÀûÒæÏà¹ØÕߵIJÆÎñÐÅÏ¢¡£ÏÖÔÚ£¬¸ÃÊÂÎñÈÔÔÚÊÓ²ìÖУ¬DBSAÒѾÄܹ»»Ö¸´ÆäITϵͳ£¬²¢½«ÀÕË÷Èí¼þ×é¼þ´ÓÆäϵͳÖÐɾ³ý¡£
https://therecord.media/development-bank-of-southern-africa-akira-ransomware-attack
3¡¢MandiantÐû²¼UNC3886ʹÓÃVMware ESXiÎó²îµÄÊÖÒÕϸ½Ú
6ÔÂ13ÈÕ£¬MandiantÐû²¼Á˹ØÓÚUNC3886ʹÓÃVMware ESXiÖÐÁãÈÕÎó²îµÄÊÖÒÕϸ½Ú¡£ÕâÊÇVMware ToolsµÄvgauthÄ£¿éÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈƹýÎó²î£¨CVE-2023-20867£©£¬ÒÑÓÚ6ÔÂ13ÈÕ±»ÐÞ¸´¡£´Ë´ÎÔ˶¯ÖУ¬¹¥»÷ÕßʹÓÃÕâÒ»Îó²îÔÚÄ¿µÄESXiÖ÷»úµÄguest VMÉÏ°²ÅÅVirtualPitaºÍVirtualPieºóÃÅ£¬²¢½«È¨ÏÞÉý¼¶µ½root¡£Ñо¿Ö°Ô±»¹·¢Ã÷µÚÈýÖÖ¶ñÒâÈí¼þ±äÖÖ(VirtualGate)×÷Ϊһ¸ömemory-only dropper£¬¶Ô±»Ð®ÖÆÐéÄâ»úÉϵĵڶþ½×¶ÎDLL payload¾ÙÐÐÈ¥»ìÏý´¦Öóͷ£¡£
https://www.mandiant.com/resources/blog/vmware-esxi-zero-day-bypass
4¡¢SpotifyÒòÎ¥·´GDPR±»ÈðµäÕþ¸®·£¿î540ÍòÃÀÔª
¾Ý6ÔÂ14ÈÕ±¨µÀ£¬ÒôÀÖÁ÷ýÌ幫˾SpotifyÒòδ׼ȷ¼û¸æÓû§ÆäÍøÂçµÄÊý¾ÝÊÇÔõÑù±»Ê¹Óõģ¬±»ÈðµäÒþ˽±£»¤¾Ö(IMY)·£¿î5800ÍòÈðµä¿ËÀÊ£¨Ô¼ºÏ540ÍòÃÀÔª£©¡£¸Ãî¿Ïµ»ú¹¹Ö¸³ö£¬Æ¾Ö¤GDPRµÄ»®¶¨£¬Óû§ÓÐȨÏàʶ¹«Ë¾ÓµÓйØÓÚСÎÒ˽¼ÒµÄÄÄЩÊý¾ÝÒÔ¼°ÕâЩÊý¾ÝµÄʹÓ÷½·¨¡£µ«ÓÉÓÚSpotifyÌṩµÄÐÅÏ¢Ò»Ö±²»Ã÷È·£¬Ð¡ÎÒ˽¼ÒºÜÄÑÏàʶËûÃǵÄÊý¾ÝÊÇÔõÑù±»´¦Öóͷ£µÄ£¬Ò²ºÜÄѼì²é´¦Öóͷ£ÊÇ·ñÕýµ±¡£IMY»¹³Æ£¬×ܵÄÀ´Ëµ£¬¸ÃÎÊÌâ±»ÒÔΪÊǽϵÍÑÏÖØÐԵġ£SpotifyÌåÏÖÍýÏë¶Ô¸Ã¾öÒéÌá³öÉÏËß¡£
https://www.securityweek.com/spotify-fined-5-million-for-breaching-eu-data-rules/
5¡¢Ñо¿Ö°Ô±¹ûÕæWPÖ§¸¶²å¼þÖеÄÎó²îCVE-2023-34000
ýÌå6ÔÂ13Èճƣ¬Ñо¿Ö°Ô±Åû¶ÁËWordPressµÄWooCommerce Stripe Gateway²å¼þÖеÄÎó²î£¨CVE-2023-34000£©¡£ÕâÊǵçÉÌÍøÕ¾µÄÖ§¸¶Íø¹Ø²å¼þ£¬ÏÖÔÚÓÐÁè¼Ý900000µÄ×°ÖÃÁ¿¡£¸ÃÎó²îÊÇδ¾Éí·ÝÑéÖ¤µÄ²»Çå¾²Ö±½Ó¹¤¾ßÒýÓÃ(IDOR)Îó²î£¬»áÓ°Ïì7.4.0¼°ÒÔÏ°汾£¬ÒÑÓÚ5ÔÂ30ÈÕ±»ÐÞ¸´¡£Îó²îÔ´ÓÚ¶©µ¥¹¤¾ßµÄ²»Çå¾²´¦Öóͷ£ÒÔ¼°²å¼þµÄjavascript_paramsºÍpayment_fieldsº¯ÊýÖÐȱ·¦Êʵ±µÄ»á¼û¿ØÖƲ½·¥£¬¿É±»¹¥»÷ÕßÓÃÀ´ÈƹýÊÚȨ²¢»á¼ûÃô¸ÐÐÅÏ¢¡£
https://patchstack.com/articles/unauthenticated-idor-to-pii-disclosure-vulnerability-in-woocommerce-stripe-gateway-plugin/
6¡¢BolsterÅû¶Õë¶ÔÉÏ°Ù¸ö´ò°çÆ·ÅƵĴó¹æÄ£´¹ÂÚÔ˶¯
6ÔÂ13ÈÕ£¬BolsterÅû¶Õë¶ÔÉÏ°Ù¸ö´ò°çÆ·ÅƵĴó¹æÄ£´¹ÂÚÔ˶¯£¬Ö¼ÔÚÇÔÈ¡Ä¿µÄµÄÕË»§Æ¾Ö¤ºÍ²ÆÎñÐÅÏ¢¡£¸ÃÔ˶¯×Ô2022Äê6ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬ÔÚ2022Äê11ÔÂÖÁ2023Äê2Ôµִï·åÖµ¡£´¹ÂÚÍøվð³äµÄÆ·ÅÆ°üÀ¨ÄÍ¿Ë¡¢±ëÂí¡¢Íò˹¡¢°¢µÏ´ï˹¡¢¸çÂ×±ÈÑÇ¡¢ºÍ¿¨Î÷Å·µÈ£¬Bolster³ÆÒÑʶ±ð³ö3000¶à¸ö»îÔ¾µÄÓòÃû¡£Óë´ËÔ˶¯Ïà¹ØµÄÓòÃû±»×·Ëݵ½×ÔÖ÷ϵͳ±àºÅAS48950£¬ÓÉÁ½¸öÌض¨µÄ»¥ÁªÍø·þÎñÌṩÉÌPacket Exchange LimitedºÍGlobal Colocation LimitedÍйܡ£
https://bolster.ai/blog/brand-impersonation-scam