Checkmarx¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©Ó¦Á´¹¥»÷
Ðû²¼Ê±¼ä 2023-07-251¡¢Checkmarx¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©Ó¦Á´¹¥»÷
CheckmarxÔÚ7ÔÂ21ÈÕ³ÆÆä¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©Ó¦Á´£¨OSS£©¹¥»÷¡£µÚÒ»´Î¹¥»÷±¬·¢ÓÚ4ÔÂÉÏÑ®£¬¹¥»÷Õßð³äÄ¿µÄÒøÐÐÔ±¹¤£¬Ê¹ÓÃNPMƽ̨ÉÏ´«Á˼¸¸öÈí¼þ°ü£¬ÆäÖаüÀ¨Ô¤×°Öþ籾£¬¿ÉÔÚ×°ÖÃʱִÐжñÒâÔ˶¯¡£»¹Ê¹ÓÃAzureµÄCDN×ÓÓòÀ´·Ö·¢µÚ¶þ½×¶ÎµÄpayload Havoc£¬ÕâÊÇÒ»¸öC2¿ò¼Ü¡£ÔÚ2Ô·ݼì²âµ½µÄÕë¶ÔÒøÐеÄÁíÒ»´Î¹¥»÷ÖУ¬¹¥»÷ÕßÒ²ÉÏ´«ÁËÒ»¸ö¶ñÒânpm°ü£¬Ö¼ÔÚ×èµ²µÇ¼Êý¾Ý²¢½«Æä·¢Ë͸ø¹¥»÷Õß¡£ÏÖÔÚ£¬Ñо¿Ö°Ô±ÒѾ±¨¸æ²¢É¾³ýÁËÕâЩ¶ñÒ⿪ԴÈí¼þ°ü¡£
https://checkmarx.com/blog/first-known-targeted-oss-supply-chain-attacks-against-the-banking-sector/
2¡¢Apple¸üÐÂÐÞ¸´Òѱ»Ê¹ÓõÄÄÚºËÎó²îCVE-2023-38606
¾ÝýÌå7ÔÂ24ÈÕ±¨µÀ£¬AppleÐû²¼ÁËÇå¾²¸üУ¬ÒÔÐÞ¸´Õë¶ÔiPhone¡¢MacºÍiPadµÄ¹¥»÷Öб»Ê¹ÓõÄÎó²î¡£ÕâÊÇÒ»¸öÄÚºËÎó²î£¨CVE-2023-38606£©£¬Äܹ»±»ÓÃÀ´¸Ä¶¯Ãô¸ÐµÄÄÚºË״̬£¬¿ÉÄÜÒÑÔÚiOS 15.7.1֮ǰÐû²¼µÄiOS°æ±¾Öб»Æð¾¢Ê¹Óá£KasperskyÌåÏÖ£¬CVE-2023-38606ÊÇÁãµã»÷Îó²îʹÓÃÁ´µÄÒ»²¿·Ö£¬ÓÃÓÚͨ¹ýiMessageÎó²îÔÚiPhoneÉÏ×°ÖÃÌع¤Èí¼þTriangulation¡£ÕâÊÇAppleÔÚ½ñÄêÐÞ¸´µÄµÚʮһ¸öÒѱ»Ê¹ÓõÄÁãÈÕÎó²î¡£
https://www.bleepingcomputer.com/news/apple/apple-fixes-new-zero-day-used-in-attacks-against-iphones-macs/
3¡¢ClopʹÓÃMOVEitÎó²îµÄ¹¥»÷Ô¤¹À׬Ǯ7500ÍòÖÁ1ÒÚÃÀÔª
CovewareÔÚ7ÔÂ21ÈÕ͸¶£¬ClopʹÓÃMOVEitÎó²îµÄ´ó¹æÄ£Êý¾ÝÇÔÈ¡Ô˶¯Ô¤¼Æ׬Ǯ¸ß´ï7500ÍòÖÁ1ÒÚÃÀÔª¡£ÔÚ2023ÄêQ2£¬½»Êê½ðµÄ±»¹¥»÷Ä¿µÄµÄÊýÄ¿ÒѽµÖÁ34%£¬´´ÏÂÀúʷеͣ¬µ¼ÖÂÀÕË÷ÍÅ»ï¸Ä±äÕ½ÂÔÒÔ×êÓª¸ü¸ßµÄÀûÈó¡£CovewareÌåÏÖ£¬ClopÒѾ¸Ä±äÁËÕ½ÂÔ£¬ÀÕË÷¸ü¸ßµÄÊê½ð£¬Ï£Íûͨ¹ý¼¸±Ê´ó¶î¸¶¿îÀ´Õ½Ê¤ÕûÌåϽµµÄÇéÐΡ£±ðµÄ£¬ÖØ´óÐÔºÍ×Ô¶¯»¯Ë®Æ½µÍµÄÀÕË÷¹¥»÷µÄÓ°ÏìºÍ±¾Ç®×îС¡£
https://www.coveware.com/blog/2023/7/21/ransom-monetization-rates-fall-to-record-low-despite-jump-in-average-ransom-payments
4¡¢Ñо¿Ö°Ô±Åû¶OpenMeetings¿ÉЮÖÆÖÎÀíÔ±ÕÊ»§µÄÎó²î
¾Ý7ÔÂ21ÈÕ±¨µÀ£¬Ñо¿Ö°Ô±Åû¶ÁËApache OpenMeetingsÖеÄ3¸öÎó²îµÄϸ½Ú¡£ÕâЩÎó²î»®·ÖΪÈõ¹þÏ£½ÏÁ¿Îó²î£¨CVE-2023-28936£©¡¢Í¨¹ýÔ¼Çë¹þÏ£¾ÙÐÐÎÞÏÞÖÆ»á¼ûµÄÎó²î£¨CVE-2023-29023£©ÒÔ¼°¿Õ×Ö½Ú×¢ÈëÎó²î(CVE-2023-29246£©£¬¿É±»×ÔÐÐ×¢²áÓû§£¨Ä¬ÈÏÆôÓã©ÓÃÀ´Ð®ÖÆÖÎÀíÔ±ÕÊ»§²¢Ô¶³ÌÖ´ÐÐí§Òâ´úÂë¡£ÏÖÔÚ£¬ÕâЩÎó²îÒÑÔÚApache OpenMeetings 7.1.0°æ±¾ÖÐÐÞ¸´¡£
https://www.securityweek.com/openmeetings-flaws-allow-hackers-to-hijack-instances-execute-code-on-servers/
5¡¢AhnLab·¢Ã÷ͨ¹ýMS-SQL·þÎñÆ÷·Ö·¢PurpleFoxµÄÔ˶¯
7ÔÂ24ÈÕ£¬AhnLab³ÆÆä·¢Ã÷ÁËͨ¹ýÖÎÀí²»ÉƵÄMS-SQL·þÎñÆ÷·Ö·¢PurpleFoxµÄÔ˶¯¡£¹¥»÷Ê×ÏÈͨ¹ýsqlservr.exeÖ´ÐÐPowerShell£¬ÕâÊÇÒ»¸öÓëMS-SQL·þÎñÆ÷Ïà¹ØµÄÀú³Ì¡£µ±Ö´ÐÐÉÏÊöPowerShellʱ£¬½«ÏÂÔز¢¼ÓÔØÁíÒ»¸ö¾ÓÉ»ìÏýµÄPowerShell¡£ÆäÖаüÀ¨Ò»¸ö¹¥»÷Õß¿ª·¢µÄº¯ÊýMsiMake£¬¿ÉÏÂÔØÒ»¸öMSIÎļþ¡£MSI°ü¸ü¸Ä×¢²á±íÏîÒÔʵÏÖ³¤ÆÚÐÔºÍȨÏÞÌáÉý¡£×îºó£¬MSI°ü»áʵÑéÖØÆôϵͳ£¬½Ó×ÅSENS·þÎñ»á±»Ö´ÐУ¬´Ó¶ø¼¤»î¶ñÒâÈí¼þ¡£
https://asec.ahnlab.com/en/55492/
6¡¢IBMÐû²¼¹ØÓÚ2023ÄêÊý¾Ý鶱¾Ç®µÄÆÊÎö±¨¸æ
7ÔÂ24ÈÕ£¬IBMÐû²¼¹ØÓÚ2023ÄêÊý¾Ý鶱¾Ç®µÄÆÊÎö±¨¸æ¡£¸Ã±¨¸æ¶Ô553¸ö×éÖ¯µÄÊý¾Ýй¶ÇéÐξÙÐÐÁËÆÊÎö£¬Ñо¿µÄÎ¥¹æÊÂÎñ±¬·¢ÔÚ2022Äê3ÔÂÖÁ2023Äê3Ô¡£×îÐÂÑо¿ÏÔʾ£¬Êý¾Ý鶱¾Ç®Ò»Á¬ÔöÌí£¬È«Çòƽ¾ù±¾Ç®¸ß´ï445ÍòÃÀÔª£¬ÈýÄêÄÚÔöÌíÁË15%¡£Ò½ÁƱ£½¡ÐÐÒµµÄ±¾Ç®Î»¾Ó°ñÊ×£¬Ò»Á¬13Äê³ÉΪ±¾Ç®×î¸ßµÄÐÐÒµ¡£±¨¸æÖ¸³ö£¬Çå¾²È˹¤ÖÇÄܺÍ×Ô¶¯»¯¡¢DevSecOpsÒªÁìºÍIRÍýÏëÔÚ½ÚÔ¼±¾Ç®·½ÃæÊ©Õ¹ÁËÖ÷µ¼×÷Óã»È˹¤ÖÇÄܺÍASM¼ÓËÙÁËÎ¥¹æÊÂÎñµÄʶ±ðºÍ×èÖ¹£»µ±Êý¾Ý´æ´¢ÔÚ¶à¸öÇéÐÎÖÐʱ£¬±¾Ç®ºÜ¸ß£¬²¢ÇÒÐèÒª¸ü³¤Ê±¼ä²Å»ª×èֹΥ¹æÊÂÎñ£»ÓµÓз¢Ã÷Î¥¹æÊÂÎñµÄÄÚ²¿ÍŶӵÄ×éÖ¯ÔÚ¿ØÖƱ¾Ç®·½ÃæÌåÏֵøüºÃ¡£
https://securityintelligence.com/posts/whats-new-2023-cost-of-a-data-breach-report/