¼ÓÄôóYellow PagesÔâµ½Black BastaµÄÀÕË÷¹¥»÷

°ä²¼¹¦·ò 2023-04-26

1¡¢¼ÓÄôóYellow PagesÔâµ½Black BastaµÄÀÕË÷¹¥»÷


¾ÝýÌå4ÔÂ24ÈÕ±¨Â·£¬£¬ £¬£¬£¬¼ÓÄôóĿ¼³ö°æÉÌYellow Pages Groupй©ÆäÔâµ½ÁËÍøÂç¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£Black BastaÐû³ÆÆäΪÕâ´Î¹¥»÷ÕÆ¹Ü£¬£¬ £¬£¬£¬²¢¹«¿ªÁËÔ̺¬Éí·ÝÖ¤¼þ¡¢Ë°ÎñÎļþºÍÂòÂôºÍ̸µÈÐÅÏ¢µÄÎļþÑù±¾¡£¡£¡£¡£ ¡£¡£¡£Æ¾¾Ýй¶ÎļþµÄÈÕÆÚÄܹ»È·¶¨£¬£¬ £¬£¬£¬¹¥»÷ËÆºõ²úÉúÔÚ3ÔÂ15ÈÕ»òÖ®ºó¡£¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾¶Ô´ËÊ·¢Õ¹µ÷²é£¬£¬ £¬£¬£¬·¢ÏÖÔ±¹¤Êý¾ÝºÍóÒ׿ͻ§µÄÓйØÐÅϢй¶¡£¡£¡£¡£ ¡£¡£¡£ËûÃÇÏÖÒÑ֪ͨÊÜÓ°ÏìµÄÓ×ÎÒ£¬£¬ £¬£¬£¬²¢°µÊ¾Ä¿Ç°¸ù»ùÉÏÒѾ­¸´Ô­ÁËËùÓзþÎñ¡£¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/yellow-pages-canada-confirms-cyber-attack-as-black-basta-leaks-data/


2¡¢VMware½¨¸´ÔÚPwn2OwnºÚ¿Í´óÈüÖб»ÀûÓõÄÁ½¸ö·ì϶


¾Ý4ÔÂ25ÈÕ±¨Â·£¬£¬ £¬£¬£¬VMware°ä²¼°²È«¸üУ¬£¬ £¬£¬£¬½¨¸´ÁËÔÚPwn2Own Vancouver 2023ºÚ¿Í´óÈüÑݳöʾµÄÁ½¸ö·ì϶¡£¡£¡£¡£ ¡£¡£¡£µÚÒ»¸öÊÇÀ¶ÑÀÉ豸¹²ÏíÖ°ÄÜÖлùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å(CVE-2023-20869)£¬£¬ £¬£¬£¬¿É±»±¾µØ¹¥»÷ÕßÓÃÀ´×÷ΪÖ÷»úÉÏÔËÐеÄÐé¹¹»úVMX¹ý³ÌÖ´ÐдúÂë¡£¡£¡£¡£ ¡£¡£¡£µÚ¶þ¸öÊÇÓëVM¹²ÏíÖ÷»úÀ¶ÑÀÉ豸µÄÖ°ÄÜÖеÄÐÅϢй¶·ì϶(CVE-2023-20870)£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶´ÓVM¶ÁÈ¡ÖÎÀí·¨Ê½ÄÚ´æÖÐÔ̺¬µÄÌØÈ¨ÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¡£VMware»¹ÎªÎÞ·¨Á¢¼´×°Öò¹¶¡µÄÓû§ÌṩÁËһʱ½â¾ö²½Ö裬£¬ £¬£¬£¬¼´¹Ø¹ØÐé¹¹»úÉϵÄÀ¶ÑÀÖ§³Ö¡£¡£¡£¡£ ¡£¡£¡£


https://securityaffairs.com/145287/security/vmware-fixes-critical-zero-days-pwn2own.html


3¡¢KasperskyÅû¶TomirisÕë¶ÔÖÐÑǵØÓòÍøÂçµý±¨µÄ»î¶¯


4ÔÂ24ÈÕ£¬£¬ £¬£¬£¬KasperskyÅû¶ÁËTomirisÔÚÖÐÑǵØÓòµÄ×îл¡£¡£¡£¡£ ¡£¡£¡£¹¥»÷ÖØÒªÕë¶ÔCIS¹ú¶ÈÈ·µ±¾ÖºÍ±í½»»ú¹¹£¬£¬ £¬£¬£¬ÆäÌØµãÊÇÆ«²îÓÚʹÓøù»ùµ«ÓÐЧµÄ´ò°üºÍ·Ö·¢¼¼Êõ£¬£¬ £¬£¬£¬Å¼È»»áÀûÓÃóÒ×»ò¿ªÔ´RAT¡£¡£¡£¡£ ¡£¡£¡£TomirisʹÓÃÁ˸÷Àà¸÷ÑùµÄ¶ñÒâÈí¼þÖ²È뷨ʽ£¬£¬ £¬£¬£¬ËüÃǵĿª·¢ËٶȺܿ죬£¬ £¬£¬£¬²¢Ê¹ÓÃÁËËùÓÐÄܹ»ÉèÏëµÄ±à³Ì˵»°¡£¡£¡£¡£ ¡£¡£¡£TomirisʹÓõŤ¾ß¿É·ÖΪÈýÀࣺÏÂÔØ·¨Ê½¡¢ºóÃźÍÎļþÇÔÈ¡·¨Ê½¡£¡£¡£¡£ ¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬¸Ã»î¶¯ÖÐʹÓõÄKopiLuwakºÍTunnusSched½«ÆäÓëTurlaÁªÏµÆðÀ´¡£¡£¡£¡£ ¡£¡£¡£


https://securelist.com/tomiris-called-they-want-their-turla-malware-back/109552/


4¡¢×êÑÐÈËÔ±ÑÝʾÕë¶ÔIntel CPUµÄÐÂÐͲàÐÅ·¹¥»÷²½Öè


4ÔÂ24ÈÕ±¨Â·³Æ£¬£¬ £¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËÓ°Ïì¶à´úIntel CPUµÄÐÂÐͲàÐÅ·¹¥»÷²½Ö裬£¬ £¬£¬£¬¿Éͨ¹ýEFLAGS¼Ä·ÅÆ÷й¶Êý¾Ý¡£¡£¡£¡£ ¡£¡£¡£ÕâÖÖ¹¥»÷²»ÏñÆäËü²àÐÅ·¹¥»÷ÄÇÑùÒÀÀµ»º´æÏµÍ³£¬£¬ £¬£¬£¬¶øÊÇÀûÓÃ˲ִ̬ÐÐÖеÄÒ»¸ö·ì϶£¬£¬ £¬£¬£¬Í¨¹ýÆÚÐò·ÖÎö´ÓÓû§ÄÚ´æ¿Õ¼äÖÐÇÔÈ¡Êý¾Ý¡£¡£¡£¡£ ¡£¡£¡£¹¥»÷·ÖÁ½¸ö½×¶Î£¬£¬ £¬£¬£¬µÚÒ»½×¶ÎÊÇ´¥·¢Ë²Ê±Ö´ÐУ¬£¬ £¬£¬£¬²¢Í¨¹ýEFLAGS¼Ä·ÅÆ÷±àÂë»úÃÜÊý¾Ý£¬£¬ £¬£¬£¬µÚ¶þ½×¶ÎÊÇÕÉÁ¿KCCÖ¸ÁîµÄÖ´Ðй¦·òÀ´½âÂëÊý¾Ý¡£¡£¡£¡£ ¡£¡£¡£È»¶ø£¬£¬ £¬£¬£¬×êÑÐÈËÔ±Ö¸³ö£¬£¬ £¬£¬£¬ÕâÖÖ°´Ê±¹¥»÷²»È绺´æ×´Ì¬µÄ²àÐÅ·¹¥»÷¿¿µÃס£¬£¬ £¬£¬£¬ÒªÏëÔÚ×î½üµÄоƬÖлñµÃ¸üºÃµÄÁ˾Ö£¬£¬ £¬£¬£¬¾Í±ØÐ뽫¹¥»÷³Á¸´Êýǧ´Î¡£¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/intel-cpus-vulnerable-to-new-transient-execution-side-channel-attack/


5¡¢Î¢ÈíÔٴγöÏÖ¹ÊÕÏ£¬£¬ £¬£¬£¬¶à¸ö·þÎñÖеÄËÑË÷Ö°ÄÜÎÞ·¨Ê¹ÓÃ


ýÌå4ÔÂ24Èճƣ¬£¬ £¬£¬£¬Î¢ÈíÔÚµ÷²éÓû§ÎÞ·¨ÔÚ¶à¸öMicrosoft 365·þÎñÖÐʹÓÃËÑË÷Ö°ÄܵÄÎÊÌâ¡£¡£¡£¡£ ¡£¡£¡£¸ÃÎÊÌâÓ°ÏìÁËOutlook¡¢ExchangeºÍSharePointµÈ·þÎñ¡£¡£¡£¡£ ¡£¡£¡£Óë´Ëͬʱ£¬£¬ £¬£¬£¬Î¢Èí»¹ÔÚ½â¾öÁíÒ»¸öÓ°ÏìÁËTeamsµÄÎÊÌ⣬£¬ £¬£¬£¬ÓÐЧ»§»ã±¨ËµÔÚÆô¶¯Èí¼þʱ¿´µ½ÃýÎ󡣡£¡£¡£ ¡£¡£¡£½ØÖÁ4ÔÂ25ÈÕ10:20 EDT£¬£¬ £¬£¬£¬Î¢Èí³Æ´óÎÞÊýÓû§µÄMicrosoft 365ËÑË÷ÎÊÌâÒѵõ½½â¾ö¡£¡£¡£¡£ ¡£¡£¡£ÉÏÖÜ£¬£¬ £¬£¬£¬Î¢ÈíÒ²Ôø³öÏÖ¹ÊÕÏ£¬£¬ £¬£¬£¬µ¼Ö¶à¸öMicrosoft 365·þÎṉ̃»¾£¬£¬ £¬£¬£¬È«ÇòÓû§ÎÞ·¨µÇ¼ÕË»§¡£¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/microsoft-365-search-outage-affects-outlook-teams-and-sharepoint/


6¡¢JFrog°ä²¼¹ØÓÚ¶ñÒâÈí¼þWhiteSnakeµÄ·ÖÎö»ã±¨


4ÔÂ24ÈÕ£¬£¬ £¬£¬£¬JFrog°ä²¼ÁËÕë¶ÔPython¿ª·¢ÈËÔ±µÄ¶ñÒâÈí¼þWhiteSnakeµÄ·ÖÎö»ã±¨¡£¡£¡£¡£ ¡£¡£¡£×êÑÐÈËÔ±×î½üÔÚPyPI´æ´¢¿âÖз¢ÏÖÁËÒ»¸öÓÃC#¿ª·¢µÄжñÒâÈí¼þpayload¡£¡£¡£¡£ ¡£¡£¡£Í¨¹ý¼ì²âÈ·¶¨ÁË22¸öÔ̺¬Ò»ÑùpayloadµÄ¶ñÒâ°ü£¬£¬ £¬£¬£¬Í¬Ê¹Øë¶ÔWindowsºÍLinuxϵͳ¡£¡£¡£¡£ ¡£¡£¡£ÆäÖУ¬£¬ £¬£¬£¬Õë¶ÔWindowsµÄpayload±»È·¶¨ÎªWhiteSnakeµÄ±äÌ壬£¬ £¬£¬£¬ÓµÓз´VM»úÔ죬£¬ £¬£¬£¬Ê¹ÓÃTorºÍ̸ÓëC2·þÎñÆ÷ͨѶ£¬£¬ £¬£¬£¬²¢ÇÒ¿ÉÄÜ´ÓÖ¸±êÇÔÊØÐÅÏ¢²¢Ö´ÐкÅÁî¡£¡£¡£¡£ ¡£¡£¡£¶øLinux°æ±¾µÄpayloadÊÇÒ»¸öµ¥Ò»µÃ¶àµÄPython¾ç±¾£¬£¬ £¬£¬£¬×¨Ò»ÓÚÐÅÏ¢ÇÔÈ¡¡£¡£¡£¡£ ¡£¡£¡£


https://jfrog.com/blog/new-malware-targets-python-developers-uses-tor-for-c2-communication/