Apple°ä²¼´¹Î£°²È«¸üР£¬£¬£¬£¬£¬½¨¸´Á½¸öÒѱ»ÀûÓõķì϶

°ä²¼¹¦·ò 2023-04-10

1¡¢Apple°ä²¼´¹Î£°²È«¸üР£¬£¬£¬£¬£¬½¨¸´Á½¸öÒѱ»ÀûÓõķì϶


¾ÝýÌå4ÔÂ7ÈÕ±¨Â· £¬£¬£¬£¬£¬Apple°ä²¼ÁË´¹Î£°²È«¸üР£¬£¬£¬£¬£¬ÒÔ½¨¸´Á½¸öÒѱ»ÓÃÓÚ¹¥»÷iPhone¡¢MacºÍiPadµÄ·ì϶¡£¡£¡£¡£¡£¡£¡£ ¡£µÚÒ»¸öÊÇIOSurfaceAcceleratorÖеÄÔ½½çдÈë·ì϶£¨CVE-2023-28206£© £¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊý¾Ý°Ü»µ¡¢±ÀÀ£»£»£»£»£»£»£»£»ò´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£ ¡£µÚ¶þ¸öÊÇWebKitÖеĿªÊͺóʹÓ÷ì϶(CVE-2023-28205) £¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÓÕʹָ±ê¼ÓÔØ¶ñÒâÍøÒ³À´´¥·¢¸Ã·ì϶ £¬£¬£¬£¬£¬³É¹¦ÀûÓÿɵ¼ÖÂËÁÒâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£ ¡£µ«¸Ã¹«Ë¾»¹Î´°ä²¼ÓйØÕâЩ¹¥»÷µÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ ¡£×ÔËêÊ×ÒÔÀ´ £¬£¬£¬£¬£¬AppleÒѽ¨¸´ÁË3¸öÁãÈÕ·ì϶¡£¡£¡£¡£¡£¡£¡£ ¡£


https://securityaffairs.com/144551/hacking/apple-zero-day-flaws-3.html


2¡¢¿Æ¼¼¹«Ë¾MSIÔâµ½Money Message¹¥»÷±»ÀÕË÷400ÍòÃÀÔª


¾Ý4ÔÂ7ÈÕ±¨Â· £¬£¬£¬£¬£¬Öйų́ÍåµÄ΢ÐǿƼ¼£¨Micro-Star International £¬£¬£¬£¬£¬¼ò³ÆMSI£©Ôâµ½ÁËMoney MessageµÄ¹¥»÷ £¬£¬£¬£¬£¬²¢±»ÀÕË÷400ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£ ¡£4ÔÂ5ÈÕ £¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÆäÍøÕ¾ÉÏÁгöÁËMSI £¬£¬£¬£¬£¬²¢Ðû³ÆÇÔÈ¡ÁËÆä1.5TBµÄÊý¾Ý £¬£¬£¬£¬£¬Éæ¼°CTMSºÍERPÊý¾Ý¿âÒÔ¼°Ô̺¬Èí¼þÔ´´úÂ롢˽ԿºÍBIOS¹Ì¼þµÄÎļþ¡£¡£¡£¡£¡£¡£¡£ ¡£MSI °µÊ¾ £¬£¬£¬£¬£¬ÔÚ¼ì²âµ½¹¥»÷ºóÆäÒÑÆô¶¯ÐÅÏ¢°²È«·ÀÓù»úÔìºÍ¸´Ô­·¨Ê½¡£¡£¡£¡£¡£¡£¡£ ¡£MSI»¹¶½´ÙÓû§Ö»´ÓÆä¹Ù·½ÍøÕ¾»ñÈ¡¹Ì¼þ/BIOS¸üР£¬£¬£¬£¬£¬²»ÒªÊ¹Óùٷ½ÍøÕ¾ÒÔ±íÆðÔ´µÄÎļþ¡£¡£¡£¡£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/msi-confirms-security-breach-following-ransomware-attack-claims/


3¡¢×êÑÐÈËÔ±Åû¶VM2ɳÏä¿âÖеÄRCE·ì϶CVE-2023-29017


4ÔÂ8ÈÕ±¨Â·³Æ £¬£¬£¬£¬£¬×êÑÐÈËÔ±Åû¶ÁËVM2ɳÏä¿âÖеÄRCE·ì϶CVE-2023-29017¡£¡£¡£¡£¡£¡£¡£ ¡£¸Ã¿âÓÃÓÚÔÚNode.js·þÎñÆ÷µÄ¸ôÀë»·¾³ÖÐÔËÐв»ÊÜÐÅÀµµÄ´úÂë £¬£¬£¬£¬£¬Ã¿Ô±»ÏÂÔØ³¬¹ý1600Íò´Î¡£¡£¡£¡£¡£¡£¡£ ¡£×êÑÐÈËÔ±·¢ÏÖ £¬£¬£¬£¬£¬µ±´¦ÖÃÒì²½ÃýÎóʱ £¬£¬£¬£¬£¬VM2¿âδÕýÈ·´¦ÖÃError.prepareStackTraceµÄËÞÖ÷¶ÔÏó £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓÃÆäÈÆ¹ýɳÏä±£»£»£»£»£»£»£»£»¤²¢ÔÚÖ÷»úÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£ ¡£×êÑÐÈËÔ±»¹Îª¸Ã·ì϶ÌṩÁËÁ½ÖÖPoC £¬£¬£¬£¬£¬ËüÃÇÈÆ¹ýÁËɳÏä±£»£»£»£»£»£»£»£»¤²¢ÔÚÖ÷»úÉÏ´´½¨Ò»¸öÃûΪflagµÄ¿ÕÎļþ¡£¡£¡£¡£¡£¡£¡£ ¡£¸Ã·ì϶ӰÏìËùÓа汾 £¬£¬£¬£¬£¬Ô̺¬3.9.14ºÍ¸üµÍµÄ°æ±¾ £¬£¬£¬£¬£¬ÒÑÔÚ3.9.15°æ±¾Öн¨¸´¡£¡£¡£¡£¡£¡£¡£ ¡£


https://thehackernews.com/2023/04/researchers-discover-critical-remote.html


4¡¢Ó¢¹úACROй©ÓÉÓÚÔâµ½¹¥»÷µ¼ÖÂÍøÕ¾ÒѹعØÊýÖÜ


ýÌå4ÔÂ6ÈÕ±¨Â· £¬£¬£¬£¬£¬Ó¢¹ú·¸×ï¼Í¼°ì¹«ÊÒACROÓÉÓÚÔâµ½¹¥»÷µ¼ÖÂÍøÕ¾ÒѹعØÊýÖÜ¡£¡£¡£¡£¡£¡£¡£ ¡£ËüÓÚ3ÔÂ21ÈÕ³õ´ÎÔÚTwitterÉϰ䷢ÆäÍøÕ¾ÔÚÊØ»¤ £¬£¬£¬£¬£¬²¢ÇÒ´Ó3ÔÂ31ÈÕÆð¾ÍÒ»Ïò´¦ÓڹعØ×´Ì¬ £¬£¬£¬£¬£¬ÍøÕ¾ÏÔʾÓÉÓÚ¼¼ÊõÎÊÌâ¶øÎÞ·¨Ê¹Óᣡ£¡£¡£¡£¡£¡£ ¡£4ÔÂ6ÈÕ £¬£¬£¬£¬£¬¸Ã»ú¹¹°ä²¼ÉêÃ÷Õýʽ½«ÉϸöÔµÄÍøÕ¾ÊØ»¤Óë¹¥»÷ÊÂÎñÁªÏµÆðÀ´¡£¡£¡£¡£¡£¡£¡£ ¡£¹¥»÷²úÉúÓÚ2023Äê1ÔÂ17ÈÕÖÁ3ÔÂ21ÈÕ £¬£¬£¬£¬£¬ËûÃǽ«ÍøÕ¾¹Ø¹ØÒÔ½øÐÐÈ«Ãæµ÷²é¡£¡£¡£¡£¡£¡£¡£ ¡£¸Ã·¨ÂÉ»ú¹¹³ÆÓ×ÎÒÐÅϢûÓÐÊܵ½Ó°Ïì £¬£¬£¬£¬£¬µ«Evening Standard±¨Â· £¬£¬£¬£¬£¬ACRO֪ͨÁËÉêÇëÈËÆäÉí·ÝÐÅÏ¢ºÍÐÌʶ¨×ïÊý¾Ý¿ÉÄÜÊܵ½ÁËÓ°Ïì¡£¡£¡£¡£¡£¡£¡£ ¡£


https://therecord.media/acro-cybersecurity-incident-uk-criminal-records


5¡¢Kaspersky·¢ÏÖ´¹µö¹¥»÷Õ߸üÒÀÀµTelegramµÄÇ÷Ïò


KasperskyÔÚ4ÔÂ5ÈÕ³ÆÆä·¢ÏÖÁË´¹µö¹¥»÷ÕßÔÚ×î½ü¼¸¸öÔÂÆðÍ·¸ü¶àµØÒÀÀµÊ¢Ðеļ´Ê±Í¨Ñ¶Æ½Ì¨¡£¡£¡£¡£¡£¡£¡£ ¡£¹¥»÷ÕßÒÑÄÜ´¿ÊìµØÊ¹ÓÃTelegramÀ´×Ô¶¯»¯Æä»î¶¯ £¬£¬£¬£¬£¬²¢ÎªÔ¸Ò⸶·ÑµÄºÚ¿ÍÌṩ¸÷Àà·þÎñ¡£¡£¡£¡£¡£¡£¡£ ¡£×êÑÐÈËÔ±³Æ £¬£¬£¬£¬£¬Ä¿Ç°Í¨¹ýTelegramÌṩÃâ·ÑµÄ´¹µö¹¤¾ß°ü¡¢×Ô¶¯£¨»ùÓÚ»úеÈË£©´¹µöÒ³Ãæ´´½¨ºÍÓû§Êý¾ÝÍøÂç¡¢¸ß¼¶ÍøÂç´¹µöÒ³Ãæ¡¢±»µÁÍ´´¦ºÍPhaaS¶©ÔĵÈ¡£¡£¡£¡£¡£¡£¡£ ¡£×êÑÐÈËÔ±³Æ £¬£¬£¬£¬£¬¹¥»÷Õß×ªÒÆµ½Telegramºó £¬£¬£¬£¬£¬´¹µö¹¥»÷Ãż÷½µµÍÁË £¬£¬£¬£¬£¬ÈκÎÈ˶¼¿Éͨ¹ýTelegram»úеÈËÀ´ÌìÉú´¹µöÒ³Ãæ²¢ÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£¡£ ¡£


https://securelist.com/telegram-phishing-services/109383/


6¡¢2022ÄêµÚÈýºÍµÚËÄʱ¶ÈÆÏÌÑÑÀÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨


ýÌå4ÔÂ6ÈÕ±¨Â·ÁË2022ÄêQ3ºÍQ4ÆÏÌÑÑÀÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£ ¡£»ã±¨ÏÔʾ £¬£¬£¬£¬£¬´¹µö»î¶¯(98.7%)±È¶ñÒâÈí¼þ(1.3%)¸üÆÕ±é¡£¡£¡£¡£¡£¡£¡£ ¡£ÔÚ2022ÄêQ1 £¬£¬£¬£¬£¬¹¥»÷Õ߸üÐÂÁËÕë¶ÔÆÏÌÑÑÀÒøÐлú¹¹µÄÍøÂç´¹µöÄ£°å¡£¡£¡£¡£¡£¡£¡£ ¡£Satori/Mirai½©Ê¬ÍøÂç¡¢URSAľÂíºÍQakbotľÂíÊÇ2022ÄêQ3ºÍQ4×îÆÕ±éµÄÍþв¡£¡£¡£¡£¡£¡£¡£ ¡£»£»£»£»£»£»£»£»¹¹Û²ìµ½Ó°ÏìÆÏÌÑÑÀ·ÖÆçÒøÐÐµÄÆäËüľÂí±äÖÖ £¬£¬£¬£¬£¬Ô̺¬Maxtrilha¡¢JavaliºÍLampion¡£¡£¡£¡£¡£¡£¡£ ¡£´Ë±í £¬£¬£¬£¬£¬EmotetÔÚ´ËÁбíÖÐÕ¼ÓÐÏÔ×ŵØÎ»¡£¡£¡£¡£¡£¡£¡£ ¡£¹ØÓÚÐÐÒµ £¬£¬£¬£¬£¬ÒøÐÐÊÜÓ°Ïì×î´ó £¬£¬£¬£¬£¬Æä´ÎÊÇÁãÊۺͽ¡È«ÐÐÒµ¡£¡£¡£¡£¡£¡£¡£ ¡£


https://securityaffairs.com/144508/malware/threat-report-portugal-q3-q4-2022.html