·¨ÀÀûÔâµ½ÀÕË÷¹¥»÷µ¼Ö²¿Ãſͻ§µÄ¾ßÌåÐÅϢй¶
°ä²¼¹¦·ò 2023-03-221¡¢·¨ÀÀûÔâµ½ÀÕË÷¹¥»÷µ¼Ö²¿Ãſͻ§µÄ¾ßÌåÐÅϢй¶
¾ÝýÌå3ÔÂ20ÈÕ±¨Â·£¬£¬£¬£¬£¬Òâ´óÀûÅܳµÔì×÷ÉÌ·¨ÀÀûÔâµ½ÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³Æ¹¥»÷Õß»ñµÃÁËÆä²¿ÃÅITϵͳµÄ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬¿Í»§ÐÕÃû¡¢µØÖ·ºÍµç»°ºÅÂëµÈÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£·¨ÀÀû°µÊ¾ÒѲÉÈ¡´ëÊ©±£»£»£»£»£»£»¤ÊÜÓ°Ïìϵͳ£¬£¬£¬£¬£¬ÇÒÕâ´Î¹¥»÷¶Ô¹«Ë¾µÄÔËӪûÓÐÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ã»ÓÐ×¢Ã÷¹¥»÷²úÉúµÄ¹¦·ò£¬£¬£¬£¬£¬µ«Õâ¿ÉÄÜÓë2022Äê10Ô±¨Â·µÄÀÕË÷¹¥»÷Óйأ¬£¬£¬£¬£¬ÆäʱRansomEXXÐû³ÆÇÔÈ¡ÁË·¨ÀÀûµÄ7 GBÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¾ÝÐÂÎÅÈËÊ¿³Æ£¬£¬£¬£¬£¬×î³õµÄÊê½ðÒªÇóÊÇ100ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£·¨ÀÀûÔÚ3ÔÂ20ÈÕµÄÉêÃ÷ÖаµÊ¾£¬£¬£¬£¬£¬²»»á¸¶Êê½ð¡£¡£¡£¡£¡£¡£¡£
https://www.securityweek.com/ferrari-says-ransomware-attack-exposed-customer-data/
2¡¢×êÑÐÈËÔ±·¢ÏÖWin 11½ØÍ¼¹¤¾ßÒ²ÊÜAcropalypse·ì϶ӰÏì
3ÔÂ21ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖWindows 11½ØÍ¼¹¤¾ßÒ²ÊÜAcropalypse°²È«·ì϶µÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£ÉÏÖÜ£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÔÚGoogle PixelÏóÕ÷¹¤¾ßÖз¢Ïָ÷ì϶£¬£¬£¬£¬£¬µ¼ÖÂÔʼͼÏñÊý¾Ý¼´±ã±»±à×ë»ò²Ã¼ôÒ²Äܱ£ÁôÏÂÀ´¡£¡£¡£¡£¡£¡£¡£Windows 11½ØÍ¼¹¤¾ßÓòüôºóµÄ°æ±¾¸²¸ÇÔʼͼÏñʱ£¬£¬£¬£¬£¬·¨Ê½Ã»ÓÐÕýÈ·½Ø¶ÏδʹÓõÄÊý¾Ý£¬£¬£¬£¬£¬¶øÊDZ£ÁôÔÚIENDÊý¾Ý¿éÖ®ºó¡£¡£¡£¡£¡£¡£¡£ÔÚͼÏñ²é¿´Æ÷Öдò¿ªÎļþÖ»»áÏÔʾ²Ã¼ôºóµÄͼÏñ£¬£¬£¬£¬£¬µ«ÊÇδ½Ø¶ÏµÄÊý¾Ý¿ÉÓÃÓÚ³Á½¨ÔʼͼÏñ£¬£¬£¬£¬£¬´Ó¶ø¿ÉÄܵ¼ÖÂÃô¸ÐÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/microsoft/windows-11-snipping-tool-privacy-bug-exposes-cropped-image-content/
3¡¢×êÑÐÍŶÓÏêÊöÀÕË÷Èí¼þCatBÀûÓÃMSDTC·þÎñµÄÈÆ¹ýÕ½Êõ
¾Ý3ÔÂ20ÈÕ±¨Â·£¬£¬£¬£¬£¬×êÑÐÍŶÓÏêÊöÁËÀÕË÷Èí¼þCatBµÄÈÆ¹ýÕ½Êõ¡¢¼ÓÃÜÐÐΪÒÔ¼°ÇÔȡʹ´¦ºÍä¯ÀÀÆ÷Êý¾ÝµÄ³¢ÊÔ¡£¡£¡£¡£¡£¡£¡£CatB£¨Ò²³ÆCatB99ºÍBaxtoy£©ÓÚ2022Äêµ×³õ´Î±»·¢ÏÖ£¬£¬£¬£¬£¬Ëü¿ÉÄÜÊÇÀÕË÷Èí¼þPandoraµÄÑݱä»òÖ±½Ó¸ÄÃû£¬£¬£¬£¬£¬ºóÕßÖØÒªÕë¶ÔÆû³µÐÐÒµ¡£¡£¡£¡£¡£¡£¡£CatBµÄÖØÒªÌØµãÊÇͨ¹ýMicrosoftÉ¢²¼Ê½ÊÂÎñ´¦ÖÃе÷Æ÷(MSDTC)µÄºÏ·¨·þÎñ½Ù³ÖDLL£¬£¬£¬£¬£¬À´ÌáÈ¡ºÍÆô¶¯ÀÕË÷Èí¼þpayload¡£¡£¡£¡£¡£¡£¡£³ýÁËÎļþ¼ÓÃܺͻìºÏÖ®±í£¬£¬£¬£¬£¬CatB»¹»á³¢ÊÔ´ÓÖ¸±êÏµÍ³ÍøÂçÌØ¶¨µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2023/03/researchers-shed-light-on-catb.html
4¡¢°Ä´óÀûÑÇ˰Îñ¾ÖʹÓõÄÓïÒô¼ø±ðϵͳ¿É±»AIºÏ³ÉÉùÒôÈÆ¹ý
¾ÝÎÀ±¨3ÔÂ16ÈÕ±¨Â·£¬£¬£¬£¬£¬CentrelinkºÍ°Ä´óÀûÑÇ˰Îñ¾Ö(ATO)ʹÓõÄÓïÒô¼ø±ðϵͳ´æÔÚ·ì϶¡£¡£¡£¡£¡£¡£¡£¼Ì±¨Â·³Æ¾¹ýѵÁ·µÄAIºÏ³ÉÉùÒô¿ÉÓÃÓÚ½Ó¼ûº£±íµç»°ÒøÐзþÎñºó£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÉùÎÆÏµÍ³Ò²Äܹ»±»AIÉùÒôËùºýŪ¡£¡£¡£¡£¡£¡£¡£Ò»ÃûÎÀ±¨µÄ¼ÇÕß½öÓÃËÄ·ÖÖÓµÄÒôƵ£¬£¬£¬£¬£¬¾ÍÌìÉúÒ»¸ö×Ô¼ºµÄ¿Ë¡ÉùÒô£¬£¬£¬£¬£¬¶øºó¾ÍÄÜÓÃÕâ¸öÉùÒô½áºÏ×Ô¼ºµÄ¿Í»§²Î¿¼ºÅÂ룬£¬£¬£¬£¬½øÈëÁËCentrelink×ÔÖ÷·þÎñÕË»§¡£¡£¡£¡£¡£¡£¡£ATOµÄ½²»°È˰µÊ¾£¬£¬£¬£¬£¬¸Ã»ú¹¹ÒѲÉÈ¡´ëÊ©À´±£»£»£»£»£»£»¤ÏµÍ³ÃâÊÜAIÓïÒô¿Ë¡֮ÀàµÄÍþв¡£¡£¡£¡£¡£¡£¡£
https://www.theguardian.com/technology/2023/mar/16/voice-system-used-to-verify-identity-by-centrelink-can-be-fooled-by-ai
5¡¢Mandiant°ä²¼¹ØÓÚ2022ÄêÁãÈÕ·ì϶¹¥»÷µÄ·ÖÎö»ã±¨
3ÔÂ20ÈÕ£¬£¬£¬£¬£¬Mandiant°ä²¼Á˹ØÓÚ2022ÄêÁãÈÕ·ì϶¹¥»÷µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬2022ÄêÓÐ55¸öÁãÈÕ·ì϶±»ÀûÓ㬣¬£¬£¬£¬Õâ¸öÊý×ÖµÍÓÚ2021ÄêµÄ81¸ö¡£¡£¡£¡£¡£¡£¡£ÓëÍùÄêÒ»Ö£¬£¬£¬£¬£¬´ó²¿ÃÅ·ì϶À´×ÔMicrosoft¡¢GoogleºÍApple²úÆ·£¬£¬£¬£¬£¬±»ÀûÓÃ×î¶àµÄ²úÆ·ÀàÐÍÊDzÙ×÷ϵͳ£¨19¸ö£©£¬£¬£¬£¬£¬Æä´ÎÊÇä¯ÀÀÆ÷£¨11¸ö£©ÒÔ¼°°²È«¡¢ITºÍÍøÂçÖÎÀí²úÆ·£¨10£©¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶ÖеĴóÎÞÊý£¨55¸öÖеÄ53¸ö£©Äܱ»ÓÃÓÚÔÚÖ¸±êÉ豸ÉÏÌáÉýȨÏÞ»òÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£
https://www.mandiant.com/resources/blog/zero-days-exploited-2022
6¡¢Jumpsec°ä²¼2022ÄêÓ¢¹úÀÕË÷¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨
ýÌå3ÔÂ20Èճƣ¬£¬£¬£¬£¬Jumpsec°ä²¼ÁË2022ÄêÓ¢¹úÀÕË÷¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£Óë2021ÄêÏà±È£¬£¬£¬£¬£¬2022ÄêÓ¢¹ú»ã±¨µÄ¹¥»÷×ÜÊýÔö³¤ÁË17%¡£¡£¡£¡£¡£¡£¡£Ð³öÏÖµÄSpring4Shell¡¢FollinaºÍProxyNotShellµÈ·ì϶¿ÉÄÜ»áÔö³¤ÀÕË÷ÍÅ»ï¶Ô×éÖ¯µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£Ëæ×ÅContiºÍREvilµÄ±ÀÀ££¬£¬£¬£¬£¬ÐµĹ¥»÷ÕßÔÚÀÕË÷Èí¼þÁìÓò±äµÃÔ½·¢Í¹Æð¡£¡£¡£¡£¡£¡£¡£Lockbit¼Ì³ÐÁËContiµÄÍ·ÏΣ¬£¬£¬£¬£¬³ÉΪȫÇò×î³£¼ûµÄÀÕË÷Èí¼þ£¬£¬£¬£¬£¬Õ¼¹¥»÷µÄ52%¡£¡£¡£¡£¡£¡£¡£Êý¾ÝÅú×¢£¬£¬£¬£¬£¬½ÌÓý¡¢Ë¾·¨ÒÔ¼°ÁãÊÛºÍÅú·¢ÒµÎñÐÐÒµÔâµ½µÄ¹¥»÷×î¶à¡£¡£¡£¡£¡£¡£¡£
https://www.jumpsec.com/uk-ransomware-trends-lessons-for-2023/


¾©¹«Íø°²±¸11010802024551ºÅ