ZimbraÐÞ¸´ZCSÖÐÒѱ»Ê¹ÓõÄXSSÎó²îCVE-2023-38750

Ðû²¼Ê±¼ä 2023-08-01

1¡¢ZimbraÐÞ¸´ZCSÖÐÒѱ»Ê¹ÓõÄXSSÎó²îCVE-2023-38750 


¾ÝýÌå7ÔÂ27ÈÕ±¨µÀ£¬ZimbraÐû²¼Çå¾²¸üУ¬ÐÞ¸´ÁËÕë¶ÔZimbra Collaboration Suite(ZCS)µç×ÓÓʼþ·þÎñÆ÷µÄ¹¥»÷Öб»Ê¹ÓõÄÎó²î ¡£ÕâÊÇÒ»¸öXSSÎó²î£¨CVE-2023-38750£©£¬¿ÉÄܱ»ÓÃÀ´ÇÔÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐжñÒâ´úÂë ¡£ËäÈ»ZimbraÔÚÊ×´ÎÅû¶¸ÃÎó²î²¢±Þ²ßÓû§ÊÖ¶¯ÐÞ¸´Ê±£¬²¢Î´Åú×¢¸ÃÎó²îÒѱ»Ê¹Óà £¬µ«Google TAG͸¶£¬¸ÃÎó²îÊÇÔÚÓÐÕë¶ÔÐԵĹ¥»÷Öб»·¢Ã÷µÄ ¡£±ðµÄ£¬CISAÒ²Ðû²¼ÁËͨ¸æ£¬ÒªÇóÁª°î»ú¹¹ÔÚ8ÔÂ17ÈÕ֮ǰÐÞ¸´¸ÃÎó²î ¡£


https://www.bleepingcomputer.com/news/security/zimbra-patches-zero-day-vulnerability-exploited-in-xss-attacks/


2¡¢Tempur SealyÔâµ½ÍøÂç¹¥»÷µ¼Ö¹«Ë¾ÔËÓªÔÝʱÖÐÖ¹


¾Ý8ÔÂ1ÈÕ±¨µÀ£¬´²µæÏúÊÛÉÌTempur SealyÔâµ½ÍøÂç¹¥»÷£¬ÆÈʹ²¿·ÖϵͳÔÝʱ¹Ø±Õ ¡£Tempur Sealy±»ÒÔΪÊÇÈ«Çò×î´óµÄ´²ÉÏÓÃÆ·¹©Ó¦ÉÌ£¬Éϼ¾¶È¾»ÏúÊÛ¶îΪ12ÒÚÃÀÔª ¡£¸Ã¹«Ë¾ÔÚ±¾ÖÜһ͸¶£¬ÓÚ7ÔÂ23ÈÕÔâµ½Á˹¥»÷£¬Æä½ÓÄÉÏìÓ¦²½·¥×Ô¶¯¹Ø±ÕÁ˲¿·ÖITϵͳ£¬Õâµ¼Ö¹«Ë¾ÔËÓªÔÝʱÖÐÖ¹ ¡£ÏÖÔÚ£¬¸Ã¹«Ë¾ÒÑ×îÏȽ«²¿·ÖÖ÷ÒªµÄϵͳÖØÐÂÉÏÏß²¢»Ö¸´ÔËÓª ¡£ÊÓ²ìÈÔÔÚ¾ÙÐÐÖУ¬ÒÔÈ·¶¨¶ÔÓªÒµºÍ²ÆÎñ±¬·¢µÄÓ°Ï죬Éв»ÇåÎúÊÇ·ñÉæ¼°¿Í»§»òÔ±¹¤ÐÅÏ¢£¬ÒÔ¼°¹¥»÷ÕßµÄÉí·Ý ¡£


https://therecord.media/mattress-giant-tempur-sealy-cyberattack


3¡¢²éËþŬ¼ÓÐÄÔàÑо¿Ëùת´ïÉæ¼°17ÍòÈ˵ÄÊý¾Ýй¶ÊÂÎñ


7ÔÂ29ÈÕ±¨µÀ³Æ£¬²éËþŬ¼ÓÐÄÔàÑо¿Ëù£¨Chattanooga Heart Institute£¬CHI£©×ª´ïÁËÉæ¼°17ÍòÈ˵ÄÊý¾Ýй¶ÊÂÎñ ¡£5Ô·Ý£¬KarakurtÍÅ»ï³Æ¹¥»÷Á˸ûú¹¹£¬²¢ÇÔÈ¡ÁË158GBµÄÊý¾Ý ¡£¹¥»÷ÕßûÓÐÌṩ֤¾Ý£¬µ«ÌåÏÖй¶Êý¾Ý°üÀ¨Ò½ÁƼͼ¡¢¼ì²éЧ¹û¡¢Õï¶Ï¡¢Éç»áÇå¾²ºÅÂë¡¢»¤ÕÕ¡¢ºÍ²ÆÎñÐÅÏ¢µÈ£¬ÆäʱCHI²¢Î´»ØÓ¦´ËÊÂÎñ ¡£7ÔÂ28ÈÕ£¬CHI͸¶ÓÐ170450ÈËÊܵ½Êý¾Ýй¶ÊÂÎñµÄÓ°Ïì ¡£ËûÃÇÓÚ4ÔÂ17ÈÕ¼ì²âµ½¹¥»÷¼£Ïó£¬È·¶¨ÏµÍ³ÔÚ3ÔÂ8ÈÕÖÁ16ÈÕʱ´úÔø±»»á¼û¹ý ¡£Ö±µ½5ÔÂ31ÈÕ£¬CHI²ÅµÃÖª»¼ÕߵĿµ½¡ÐÅÏ¢ºÍµ£±£ÈËÐÅÏ¢±»Ð¹Â¶ ¡£


https://www.databreaches.net/the-chattanooga-heart-institute-to-notify-170450-about-march-data-security-incident/


4¡¢ÃÀ¹úSAISÊý¾Ý¿âÉèÖùýʧй¶572 GBѧÉúºÍÎ÷ϯµÄÐÅÏ¢


ýÌå7ÔÂ28ÈÕ±¨µÀ³Æ£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öδÊܱ£»¤µÄÊý¾Ý¿â£¬ÆäÖаüÀ¨Óë½ÌÓý»ú¹¹Ïà¹ØµÄ682438Ìõ¼Í¼ ¡£ÊӲ췢Ã÷£¬Êý¾Ý¿âÊôÓÚÄÏ·½×ÔÁ¦Ñ§Ð£Ð­»á(SAIS)£¬ÕâÊÇλÓÚÃÀ¹úµÄÒ»¸ö×ÔÔ¸ÐÔµØÇøÈÏ֤Э»á ¡£´Ë´Î鶵ÄÊý¾Ý¹²572.8 GB£¬Ê±¼ä¿ç¶È´Ó2012Äêµ½2023Ä꣬°üÀ¨Ñ§ÉúºÍÎ÷ϯ¼Í¼¡¢¿µ½¡ÐÅÏ¢¡¢Éç»áÇå¾²ºÅÂ롢ǹ»÷°¸ºÍ·â±Õ֪ͨ¡¢Ñ§Ð£µØͼºÍ²ÆÎñÔ¤ËãµÈ ¡£ÏÖÔÚ£¬¸ÃÊý¾Ý¿âÒѱ»±£»¤ÆðÀ´ ¡£


https://www.hackread.com/data-leak-student-faculty-accreditation-org/


5¡¢GoogleÐû²¼¹ØÓÚ2022Äê¶È0dayÎó²îµÄ»ØÊ×±¨¸æ


 7ÔÂ27ÈÕ£¬GoogleÐû²¼ÁËÄê¶È0dayÎó²î±¨¸æ£¬ÌṩÁË2022ÄêÒÔÀ´µÄÒ°ÍâʹÓÃͳ¼ÆÊý¾Ý ¡£2022Äê¼ì²â²¢Åû¶ÁË41¸öÔÚÒ°µÄ0day£¬ÆäÖÐÉÏ°ëÄê20¸ö£¬Ï°ëÄê21¸ö£¬½ö´ÎÓÚ2021ÄêµÄ69¸öÎó²î ¡£ÔÚAndroidÖУ¬±£´æ¶àÖÖÇéÐΣ¬Óû§Ôںܳ¤Ò»¶Îʱ¼äÄÚÎÞ·¨»ñµÃ²¹¶¡ ¡£Òò´Ë¹ØÓÚ¹¥»÷ÕßÀ´Ëµ£¬NdayµÄ¹¦Ð§ÀàËÆÓÚ0day ¡£ÔÚ2022ÄêµÄ41¸ö0dayÖУ¬ÓÐ17¸öÊÇ֮ǰ±¨¸æµÄÎó²îµÄ±äÌ壬ռ±ÈÁè¼Ý40% ¡£


https://security.googleblog.com/2023/07/the-ups-and-downs-of-0-days-year-in.html


6¡¢KasperskyÐû²¼2023ÄêQ2 APT¹¥»÷̬ÊƵÄÆÊÎö±¨¸æ


7ÔÂ27ÈÕ£¬KasperskyÐû²¼ÁË2023ÄêQ2 APT¹¥»÷̬ÊƵÄÆÊÎö±¨¸æ ¡£±¾¼¾¶ÈµÄÖ÷ÒªÁÁµãÖ®Ò»ÊÇ·¢Ã÷Á˺ã¾ÃÔËÓªµÄOperation TriangulationÔ˶¯£¬ÆäÖаüÀ¨ÐµÄiOS¶ñÒâÈí¼þƽ̨ ¡£APTÔ˶¯ÔÚµØÀíÂþÑÜÉÏÈÔÈ»ºÜÊèÉ¢£¬±¾¼¾¶È£¬¹¥»÷ÕßÖ÷ÒªÕë¶ÔÅ·ÖÞ¡¢À­¶¡ÃÀÖÞ¡¢Öж«ºÍÑÇÖÞ¸÷µØ ¡£±ðµÄ£¬³ÉÊìµÄ¹¥»÷ÕßÔÚÒ»Ö±ÔöÇ¿Æ乤¾ß£¬ÈçLazarus¿ª·¢ÁËMATA¿ò¼Ü¡¢BlueNoroffʹÓÃÁËеĴ«Êä·½·¨ºÍ±à³ÌÓïÑÔ¡¢ScarCruftʹÓÃÁËеÄѬȾ·½·¨ÒÔ¼°GoldenJackalеĶñÒâÈí¼þÑù±¾ ¡£»¹·¢Ã÷ÁËй¥»÷ÕßMysterious ElephantµÄÔ˶¯ ¡£


https://securelist.com/apt-trends-report-q2-2023/110231/