Ñо¿Ö°Ô±Åû¶WinRARÖеÄRCEÎó²îCVE-2023-40477
Ðû²¼Ê±¼ä 2023-08-211¡¢Ñо¿Ö°Ô±Åû¶WinRARÖеÄRCEÎó²îCVE-2023-40477
¾ÝýÌå8ÔÂ18ÈÕ±¨µÀ£¬Ñо¿Ö°Ô±goodbyeseleneÅû¶ÁËWinRARÖеÄÎó²î£¨CVE-2023-40477£©¡£¸ÃÎó²î±£´æÓÚ»Ö¸´¾íµÄ´¦Öóͷ£Àú³ÌÖУ¬ÓÉÓÚȱ·¦¶ÔÓû§ÌṩÊý¾ÝµÄÊʵ±ÑéÖ¤£¬¿ÉÄܵ¼ÖÂÄÚ´æ»á¼ûÁè¼Ý·ÖÅÉ»º³åÇøµÄ×îºó¡£µ±Óû§·¿ªÌØÖƵÄRARÎļþºó£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£Ñо¿Ö°Ô±ÓÚ6ÔÂ8ÈÕÏò¹©Ó¦ÉÌRARLAB±¨¸æÁËÕâÒ»Îó²î£¬RARLABÓÚ8ÔÂ2ÈÕÐû²¼Á˲¹¶¡£¬¸Ã²¹¶¡»¹½â¾öÁËÌØÖÆ´æµµµ¼ÖÂÎļþÆô¶¯¹ýʧµÄÎÊÌâ¡£
https://www.bleepingcomputer.com/news/security/winrar-flaw-lets-hackers-run-programs-when-you-open-rar-archives/
2¡¢ÌØ˹À¹ûÕæÓ°ÏìÁè¼Ý7ÍòÃûÔ±¹¤ÐÅÏ¢µÄÊý¾Ýй¶ÊÂÎñ
8ÔÂ19ÈÕ±¨µÀ³Æ£¬ÌØ˹ÀÅû¶ÁË5Ô·ݱ¬·¢µÄÊý¾Ýй¶ÊÂÎñ¡£¹«Ë¾ÊӲ췢Ã÷£¬Á½ÃûÇ°Ô±¹¤ÇÔÈ¡ÁËÉñÃØÐÅÏ¢£¬Î¥·´ÁËÌØ˹ÀµÄITÇå¾²ºÍÊý¾Ý±£»¤Õþ²ß¡£Òò´Ë£¬ÌØ˹À¶ÔÕâЩǰԱ¹¤ÌáÆðËßËÏ£¬²¢¿ÛѺÁËËûÃÇ°üÀ¨±»µÁÐÅÏ¢µÄµç×Ó×°±¸¡£±ðµÄ£¬ÌØ˹À»¹·¢Ã÷ÕâÁ½ÃûÔ±¹¤ÓëµÂ¹ú±¨ÉçHandelsblatt·ÖÏíÁ˱»µÁµÄÊý¾Ý¡£²»¹ý£¬Õâ¼Ò±¨ÉçÏòÌØ˹À°ü¹Ü£¬ËûÃDz»»á¹ûÕæÕâЩÐÅÏ¢¡£¸ÃÊÂÎñÓ°ÏìÁË75735ÃûÔ±¹¤£¬ÌØ˹À½«ÎªËûÃÇÌṩΪÆÚ12¸öÔµÄÐÅÓüà¿ØºÍÉí·Ý͵ÇÔ·þÎñ¡£
https://www.databreaches.net/tesla-notifies-employees-of-data-breach/
3¡¢Ö´·¨»ú¹¹Africa Cyber Surge IIÐж¯¾Ð²¶14ÃûÏÓÒÉÈË
ýÌå8ÔÂ18Èճƣ¬¹ú¼ÊÐ̾¯×é֯е÷µÄÖ´·¨Ðж¯Africa Cyber Surge IIÒѾв¶ÁË14ÃûÏÓÒÉÈË¡£¸ÃÐж¯ÓÚ½ñÄê4Ô·Ý×îÏÈ£¬ÁýÕÖÁË·ÇÖÞµÄ25¸ö¹ú¼Ò£¬µ·»ÙÁË20000¶à¸öÓÃÓÚÀÕË÷¡¢´¹ÂÚ¡¢BECºÍڲƹ¥»÷µÄ·¸·¨ÍøÂ磬ËüÃÇÒÑÔì³ÉÁËÁè¼Ý40000000ÃÀÔªµÄËðʧ¡£±ðµÄ£¬Õþ¸®»¹²é»ñÁËÊý°Ù¸öÍйܶñÒâÈí¼þÒÔ¼°Èö²¥Î£ÏÕµÄÈí¼þµÄ¶ñÒâIPµØµã¡£2022Äê11Ô¿ªÕ¹µÄµÚÒ»´ÎAfrica Cyber SurgeÐж¯¾Ð²¶ÁË11СÎÒ˽¼Ò£¬²¢µ·»ÙÁËÒ»¸ö³öÊۺڿ͹¤¾ßµÄ°µÍøºÍÔ¼20Íò¸ö¶ñÒâ»ù´¡ÉèÊ©¡£
https://therecord.media/africa-cyber-surge-14-arrests-interpol
4¡¢µÂ¹úÁª°î״ʦлá(BRAK)Ôâµ½NoEscapeµÄÀÕË÷¹¥»÷
¾Ý8ÔÂ18ÈÕ±¨µÀ£¬µÂ¹ú¹ú¼Ò״ʦлá(BRAK)͸¶ÕýÔÚÊÓ²ìÆ䲼³Èû¶û·þÎñ´¦Ôâµ½µÄÀÕË÷¹¥»÷¡£BRAKÈÏÕæî¿ÏµµÂ¹ú28¸öµØÇøµÄ״ʦÊÂÎñËù£¬´ú±íº£ÄÚÍâÔ¼166000Ãû״ʦ¡£¸Ã»ú¹¹ÓÚ8ÔÂ2ÈÕ·¢Ã÷Á˹¥»÷ÊÂÎñ£¬ÀÕË÷ÍÅ»ïNoEscapeÔÚ8ÔÂ15ÈÕ³ÆÆä¶Ô´Ë´Î¹¥»÷ÈÏÕæ¡£ºÚ¿ÍÉù³Æ¼ÓÃÜÁËBRAKµÄÓʼþ·þÎñÆ÷²¢»ñÈ¡ÁË160 GBµÄÊý¾Ý¡£BRAKÌåÏÖÒѾ»Ö¸´µç×ÓÓʼþϵͳµÄ»á¼û£¬²¢ÍýÏëÁªÏµÊÜÊý¾Ýй¶ӰÏìµÄСÎÒ˽¼Ò¡£
https://therecord.media/german-national-bar-association-investigating-cyberattack
5¡¢Î¢Èí³ÆBlackCatµÄбäÌåÒÑǶÈëImpacketºÍRemCom
΢ÈíÔÚ8ÔÂ17ÈճƷ¢Ã÷ÁËÀÕË÷Èí¼þBlackCatµÄбäÌ壬ǶÈëÁËÍøÂç¿ò¼ÜImpacketºÍºÚ¿Í¹¤¾ßRemcom¡£Î¢ÈíÌåÏÖ£¬½üÆÚµÄBlackCatÔ˶¯ÕýÔÚʹÓÃImpacket¿ò¼Ü¾ÙÐÐƾ֤¸´ÖƺÍÔ¶³Ì·þÎñÖ´ÐУ¬ÒÔÔÚÕû¸öÍøÂçÉÏ×°ÖüÓÃÜÆ÷³ÌÐò¡£±ðµÄ£¬¼ÓÃܳÌÐò»¹Ç¶ÈëÁËRemcom£¬¿ÉÔÚϵͳÉϵÄÆäËü×°±¸ÉÏÔ¶³ÌÖ´ÐÐÏÂÁ΢Èí»¹Í¸Â¶£¬BlackCatµÄÁ¥Êô»ú¹¹Storm-0875×Ô7ÔÂÒÔÀ´¾ÍʹÓÃÁËÕâÖÖеļÓÃÜ·½·¨¡£Î¢Èí½«Õâ¸öа汾ÃüÃûΪBlackCat 3.0£¬ÀÕË÷ÍÅ»ïÔÚÓëÆäÁ¥Êô»ú¹¹µÄͨѶÖн«Æä³ÆΪSphynx»òBlackCat/ALPHV 2.0¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-blackcats-sphynx-ransomware-embeds-impacket-remcom/
6¡¢Áè¼Ý3000¸ö¶ñÒâÈí¼þʹÓÃδ֪ѹËõÒªÁìÀ´Èƹý¼ì²â
¾Ý8ÔÂ19ÈÕ±¨µÀ³Æ£¬¹¥»÷ÕßÕýÔÚʹÓÃδ֪»ò²»ÊÜÖ§³ÖµÄѹËõÒªÁìµÄAPKÎļþÀ´Èƹý¶ñÒâÈí¼þÆÊÎö¡£ZimperiumÔÚÒ°Íâ·¢Ã÷ÁË3300¸öʹÓôËÀàѹËõËã·¨µÄAndroid¶ñÒâÈí¼þ£¬ÆäÖÐ71¸öÑù±¾¿ÉÒÔ˳ËìµØ¼ÓÔص½ÏµÍ³ÉÏ¡£ÕâÖÖ·½·¨µÄÓŵãÊÇÄܹ»Èƹý·´±àÒ빤¾ß£¬Í¬Ê±»¹ÄÜ×°ÖÃÔÚOS°æ±¾¸ßÓÚAndroid 9 PieµÄ×°±¸ÉÏ¡£±ðµÄ£¬Zimperium»¹·¢Ã÷¶ñÒâÈí¼þ¿ª·¢Õß¾ÓÐÄÆÆËðAPKÎļþÀ´Èƹý¼ì²âµÄÆäËü·½·¨£¬°üÀ¨Ê¹ÓÃÁè¼Ý256×Ö½ÚµÄÎļþÃû¡¢ÃûÌùýʧµÄAndroidManifest.xmlºÍÃûÌùýʧµÄ×Ö·û´®³ØµÈ¡£
https://securityaffairs.com/149678/malware/android-malware-using-unsupported-unknown-compression.html