ÖÇÄܼҾÓÉÌNexxÂŴκöÂÔ¿ÉÔ¶³Ì´ò¿ª³µ¿âÃŵķì϶

°ä²¼¹¦·ò 2023-04-07

1¡¢ÖÇÄܼҾÓÉÌNexxÂŴκöÂÔ¿ÉÔ¶³Ì´ò¿ª³µ¿âÃŵķì϶


¾ÝýÌå4ÔÂ5ÈÕ±¨Â· £¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÔÚNexxÔì×÷µÄ¼¸¿îÖÇÄÜÉ豸Öз¢ÏÖÁ˶à¸ö·ì϶ £¬£¬£¬£¬£¬£¬£¬¿É±»ÓÃÀ´Ô¶³Ì´ò¿ª³µ¿âÃÅ»òÕß½ÚÔ쾯±¨ºÍÖÇÄܲåÍ·¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶±ðÀëΪʹÓÃÓ²±àÂëÍ´´¦£¨CVE-2023-1748£©¡¢½Ó¼û½ÚÔì²»µ±£¨CVE-2023-1749ºÍCVE-2023-1750£©¡¢ÊäÈëÑéÖ¤²»µ±£¨CVE-2023-1751£©ºÍÉí·ÝÑéÖ¤½ÚÔì²»µ±£¨CVE-2023-1752£©¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±»¹ÑÝʾÁËÈôºÎÀûÓ÷ì϶CVE-2023¨C1748´ò¿ªNexx³µ¿âÃÅ¡£¡£¡£¡£¡£¡£¡£¡£¾ÝϤ £¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±Sam SabetanºÍCISAÔø»ã±¨¹ý¸Ã·ì϶ £¬£¬£¬£¬£¬£¬£¬µ«ÊǶ¼±»NexxºöÂÔÁË¡£¡£¡£¡£¡£¡£¡£¡£


https://www.securityweek.com/nexx-ignores-vulnerabilities-allowing-hackers-to-remotely-open-garage-doors/


2¡¢ÂÉËùGenova Burnsϵͳ±»ºÚÓŲ½Ë¾»úÐÅÏ¢ÔÙ´Îй¶


¾Ý4ÔÂ3ÈÕ±¨Â· £¬£¬£¬£¬£¬£¬£¬ÓŲ½Ë¾»úµÄÐÅÏ¢ÔÙ´Îй¶ £¬£¬£¬£¬£¬£¬£¬Õâ´ÎÔ´ÓÚÂÉʦÊÂÎñËùGenova Burns¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÉæ¼°ÐÕÃû¡¢Éç»á°²È«ºÅÂëºÍ˰ºÅµÈ £¬£¬£¬£¬£¬£¬£¬Ó°ÏìÈËÊý²»Ïê¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓڸù«Ë¾ÎªÓŲ½×ö˾·¨¹¤×÷ £¬£¬£¬£¬£¬£¬£¬ËùÒÔ³ÖÓÐÕâЩÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÂÉËù°µÊ¾ £¬£¬£¬£¬£¬£¬£¬Î´¾­ÊÚȨµÄµÚÈý·½»ñµÃÁËÆäϵͳµÄ½Ó¼ûȨÏÞ £¬£¬£¬£¬£¬£¬£¬²¢ÇÒÔÚ2023Äê1ÔÂ23ÈÕ1ÔÂ31ÈÕ½Ó¼û»òй¶Á˲¿ÃÅÎļþ¡£¡£¡£¡£¡£¡£¡£¡£ËûÃÇÒѾʹËÊÂ֪ͨÁË·¨Âɲ¿ÃÅ £¬£¬£¬£¬£¬£¬£¬²¢¸ü¸ÄÁËËùÓÐϵͳÃÜÂë £¬£¬£¬£¬£¬£¬£¬»¹½«ÎªÊÜÓ°ÏìµÄÓ×ÎÒÌṩ12¸öÔµÄÉí·Ý¼à¿Ø·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£


https://www.theregister.com/2023/04/03/uber_drivers_info_stolen/


3¡¢OCR LabsµÄϵͳÅäÖÃÃýÎóÖØÒªÓ°Ïì½ðÈÚ»ú¹¹µÄ¿Í»§


4ÔÂ4ÈÕ±¨Â·³Æ £¬£¬£¬£¬£¬£¬£¬×êÑÐÍŶÓÔÚ3ÔÂ8ÈÕ·¢ÏÖÁËOCR Labs idkit.comµÄÒ»¸ö»·¾³Îļþ(.env)¿É¹«¿ª½Ó¼û¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÊÇÊý×ÖÉí·ÝÑéÖ¤¹¤¾ßµÄ¹©¸øÉÌ £¬£¬£¬£¬£¬£¬£¬ÆäIDkit¹¤¾ß±»¸÷´óÒøÐÓ×¢µçÐŹ«Ë¾ºÍµ±¾Ö»ú¹¹Ê¹Óᣡ£¡£¡£¡£¡£¡£¡£ÔÚй¶µÄÊý¾ÝÖÐ £¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËGoogleºÍLivenessµÄAPIÃÜÔ¿ÃÜÔ¿¡¢Engine v4ƾ֤ÒÔ¼°À´×ÔExperianµÄAPIÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÓ°ÏìÁËÓ°ÏìÁËQBANK¡¢Defense Bank¡¢Bloom Money¡¢Admiral Money¡¢MA MoneyºÍReed¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓÃй¶µÄÊý¾Ý £¬£¬£¬£¬£¬£¬£¬ÈëÇÖÒøÐеĺó¶Ë»ù´¡ÉèÊ© £¬£¬£¬£¬£¬£¬£¬´Ó¶ø¹¥»÷Æä¿Í»§µÄ»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç° £¬£¬£¬£¬£¬£¬£¬¸ÃÎÊÌâÒѱ»½â¾ö¡£¡£¡£¡£¡£¡£¡£¡£


https://cybernews.com/security/ocr-labs-exposes-its-systems/


4¡¢NoteboomÔâµ½BlackCatµÄ¹¥»÷²¢±»ÀÕË÷175ÍòÃÀÔª


ýÌå4ÔÂ5ÈÕ±¨Â·³Æ £¬£¬£¬£¬£¬£¬£¬µÂ¿ËÈøË¹ÖݵÄÂÉʦÊÂÎñËùNoteboomÔâµ½ÁËBlackCatµÄÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£BlackCatÏòNoteboom·¢Ë͵ç×ÓÓʼþ £¬£¬£¬£¬£¬£¬£¬Í¨ÖªÆäÔÚ3ÔÂ24ÈÕ²úÉúÁËÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¡£Óʼþ»¹³ÆËûÃÇÒÑÈëÇÖϵͳ²¢Í£¶ÙÁË7Ìì £¬£¬£¬£¬£¬£¬£¬ÏÂÔØÁ˳¬¹ý400GbµÄÊý¾Ý £¬£¬£¬£¬£¬£¬£¬²¢¼ÓÃÜÁËËùÓзþÎñÆ÷ºÍÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶Êý¾ÝÔ̺¬±£ÃܺÍ̸¡¢Î´¾ö°¸¼þµÄÎļþ¡¢Éæ¼°ËßËϵÄÒ½ÁƼͼÒÔ¼°Ô±¹¤Êý¾ÝµÈ¡£¡£¡£¡£¡£¡£¡£¡£BlackCatй©Êê½ðÒªÇóΪ1750000ÃÀÔª £¬£¬£¬£¬£¬£¬£¬µ«Noteboomµ××ÓûÓлØÓ¦ËûÃÇ¡£¡£¡£¡£¡£¡£¡£¡£


https://www.databreaches.net/noteboom-the-law-firm-hit-by-blackcat/


5¡¢Ó¢¹ú±í°ü¹«Ë¾CapitaÔâµ½¹¥»÷µ¼Ö²¿ÃÅ·þÎñÁÙʱÖжÏ


ýÌå4ÔÂ3ÈÕ³Æ £¬£¬£¬£¬£¬£¬£¬Ó¢¹ú±í°ü¹«Ë¾Capitaй©ÉÏÖÜÎåµÄ·þÎñÖжÏÊÇÍøÂç¹¥»÷µ¼ÖµÄ¡£¡£¡£¡£¡£¡£¡£¡£CapitaÊǵ±¾Ö×î´óµÄ¹©¸øÉÌÖ®Ò» £¬£¬£¬£¬£¬£¬£¬Õ¼ÓÐ65ÒÚÓ¢°÷µÄ¹«¹²²¿ÃźÏͬ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÉêÃ÷ÖÐ³Æ £¬£¬£¬£¬£¬£¬£¬Õâ´ÎÊÂÎñÖØÒªÓ°ÏìÁËÆäMicrosoft 365ÀûÓ÷¨Ê½µÄÄÚ²¿½Ó¼û £¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö²¿Ãſͻ§·þÎñÖжÏ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç° £¬£¬£¬£¬£¬£¬£¬ÊÂÎñÒѸù»ùµÃµ½½ÚÔì £¬£¬£¬£¬£¬£¬£¬·þÎñÔÚ¸´Ô­ÖС£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ã»ÓÐй©ÓйظÃÊÂÎñµÄϸ½Ú £¬£¬£¬£¬£¬£¬£¬µ«ÆäÓ°ÏìÅú×¢Õâ¿ÉÄÜÊÇÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/144398/hacking/capita-suffered-cyber-incident.html


6¡¢Unit 42°ä²¼¹ØÓÚ¶ñÒâÈí¼þCryptoClippyµÄ·ÖÎö»ã±¨


4ÔÂ5ÈÕ £¬£¬£¬£¬£¬£¬£¬Unit 42Åû¶Á˶ñÒâÈí¼þCryptoClippyÕë¶ÔÆÏÌÑÑÀµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Ê¼ÓÚSEOÖж¾ £¬£¬£¬£¬£¬£¬£¬Ö¸±êËÑË÷WhatsApp Webʱ £¬£¬£¬£¬£¬£¬£¬Á˾ֻὫËûÃÇÊèµ¼ÖÁ¹¥»÷ÕßµÄÓò £¬£¬£¬£¬£¬£¬£¬¶øºóÏÂÔØ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£CryptoClippyÊÇ»ùÓÚCµÄ¿ÉÖ´ÐÐÎļþ £¬£¬£¬£¬£¬£¬£¬Ëü»á¼à¶½Ö¸±êµÄ¼ôÌù°å £¬£¬£¬£¬£¬£¬£¬Ñ°ÕÒ¸´Ôì¼ÓÃÜÇ®±ÒÇ®°üµØÖ·µÄÐÐΪ £¬£¬£¬£¬£¬£¬£¬²¢Óù¥»÷ÕߵĵØÖ·´úÌæÓû§µÄÏÖʵµØÖ·¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖ±»¹¥»÷Õ߱鲼Ôì×÷Òµ¡¢IT·þÎñºÍ·¿µØ²úÐÐÒµ¡£¡£¡£¡£¡£¡£¡£¡£ÕâÖÖÍþв²¢²»Õë¶ÔÌØ¶¨ÐÐÒµ £¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÉ豸¶¼ÊÇÔâµ½ÁË»úÓöÖ÷ÒåµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£


https://unit42.paloaltonetworks.com/crypto-clipper-targets-portuguese-speakers/