Google°ä²¼ChromeµÄ¸üУ¬£¬£¬ £¬£¬£¬£¬×ܼƽ¨¸´15¸ö°²È«·ì϶

°ä²¼¹¦·ò 2023-05-05

1¡¢Google°ä²¼ChromeµÄ¸üУ¬£¬£¬ £¬£¬£¬£¬×ܼƽ¨¸´15¸ö°²È«·ì϶


5ÔÂ2ÈÕ£¬£¬£¬ £¬£¬£¬£¬Google°ä²¼ÁËChrome 113°²È«¸üУ¬£¬£¬ £¬£¬£¬£¬×ܼƽ¨¸´ÁË15¸ö·ì϶¡£¡£¡£ ¡£¡£ÆäÖнÏΪÑϳÁµÄÊÇÌáÐÑÖеÄÖ´Ðв»µ±·ì϶£¨CVE-2023-2459£©¡¢À©´óÖеĶԲ»ÐÅÀµµÄÊäÈëÑéÖ¤²»¼°£¨CVE-2023-2460£©¡¢²Ù×÷ϵͳÊäÈëÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2023-2461£©ºÍCORSÖеÄÖ´Ðв»µ±£¨CVE-2023-2465£©µÈ¡£¡£¡£ ¡£¡£ÓëÆ½·²Ò»Ñù£¬£¬£¬ £¬£¬£¬£¬ÔÚ´óÎÞÊýÓû§¸üн¨¸´·¨Ê½Ö®Ç°£¬£¬£¬ £¬£¬£¬£¬GoogleûÓÐй©¹ØÓÚÕâЩ·ì϶µÄ¸ü¶àϸ½Ú¡£¡£¡£ ¡£¡£


https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop.html


2¡¢OrqaµÄ¹Ì¼þ±»Ö²Èë¶ñÒâ´úÂë¿Éµ¼ÖÂÉ豸³öÏÖ¹ÊÕÏ


¾ÝýÌå5ÔÂ3ÈÕ±¨Â·£¬£¬£¬ £¬£¬£¬£¬FPVÎÞÈË»ú»¤Ä¿¾µÔì×÷ÉÌOrqa³Æ£¬£¬£¬ £¬£¬£¬£¬Ò»¼Ò³Ð°üÉ̽«´úÂëÖ²ÈëÆä¹Ì¼þÖУ¬£¬£¬ £¬£¬£¬£¬µ¼ÖÂÉ豸³öÏÖ¹ÊÕÏ¡£¡£¡£ ¡£¡£ÉÏÖÜÁù£¬£¬£¬ £¬£¬£¬£¬Orqa¿Í»§»ã±¨£¬£¬£¬ £¬£¬£¬£¬ËûÃǵÄFPV.One V1»¤Ä¿¾µ½øÈëÆô¶¯·¨Ê½Ä£Ê½£¬£¬£¬ £¬£¬£¬£¬±äµÃÎÞ·¨Ê¹Óᣡ£¡£ ¡£¡£¸Ã¹«Ë¾Ð¹Â©£¬£¬£¬ £¬£¬£¬£¬Õâ¸öÎÊÌâÊÇÓÉ"ÈÕÆÚ/¹¦·òÖ°ÄÜÒýÆðµÄ"¹Ì¼þÃýÎóµ¼ÖµÄ¡£¡£¡£ ¡£¡£¸ÃÎÊÌâÔ´ÓÚÒ»¸öÀÕË÷Èí¼þµÄ¶¨Ê¹Ø¨µ¯£¬£¬£¬ £¬£¬£¬£¬Õâ¸öÕ¨µ¯ÊǼ¸ÄêǰÓÉÒ»¸öǰ³Ð°üḚ́ÂÃØÖ²ÈëÆäÊèµ¼·¨Ê½Öе쬣¬£¬ £¬£¬£¬£¬Ö¼ÔÚÏò¹«Ë¾Ë÷È¡¸ß¶îÊê½ð¡£¡£¡£ ¡£¡£¸Ã³Ð°üÉÌ»¹°ä²¼ÁËÒ»¸öδ¾­ÊÚȨµÄ¶þ½øÔìÎļþ£¬£¬£¬ £¬£¬£¬£¬¾Ý³ÆÄܹ»½â¾ö¸ÃÎÊÌâ¡£¡£¡£ ¡£¡£È»¶ø£¬£¬£¬ £¬£¬£¬£¬OrqaÌáÐѿͻ§²»Òª×°Ö÷ǹٷ½¹Ì¼þ¡£¡£¡£ ¡£¡£²¢Ð¹Â©Ö»ÓÐÒ»Óײ¿ÃÅ´úÂëÊܵ½ÕâÖÖ¶ñÒâÈí¼þµÄÓ°Ï죬£¬£¬ £¬£¬£¬£¬Ä¿Ç°ÔÚ½¨¸´ÖС£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/technology/drone-goggles-maker-claims-firmware-sabotaged-to-brick-devices/


3¡¢AvosÍÅ»ï½Ù³Ö²¼Â¬·Æ¶ûµÂ´óѧµÄ´¹Î£¾¯±¨ÏµÍ³RamAlert


¾Ý5ÔÂ4ÈÕ±¨Â·£¬£¬£¬ £¬£¬£¬£¬ÀÕË÷ÍÅ»ïAvos½Ù³ÖÁ˲¼Â¬·Æ¶ûµÂ´óѧµÄ´¹Î£¾¯±¨ÏµÍ³¡°RamAlert¡±¡£¡£¡£ ¡£¡£4ÔÂ30ÈÕ£¬£¬£¬ £¬£¬£¬£¬¸ÃУÏòѧÉúºÍ½ÌÖ°¹¤Ð¹Â©£¬£¬£¬ £¬£¬£¬£¬ËûÃǵÄITϵͳÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬ £¬£¬£¬£¬ËùÓп¼ÊÔ±»ÆÈÍÆ³Ù¡£¡£¡£ ¡£¡£Æäʱ£¬£¬£¬ £¬£¬£¬£¬Ñ§ÌÃÐû³ÆÃ»ÓÐÓë´ËÊÂÎñÓйصĽðÈÚڲƭ»òÉí·ÝµÁÓð¸¼þ£¬£¬£¬ £¬£¬£¬£¬ÀÏʦºÍѧÉúÈÔÄܹ»Í¨¹ýÍøÕ¾°²È«µØÊ¹ÓúͽӼûMyBU¡¢CanvasºÍͼÊé¹Ý×ÊÔ´¡£¡£¡£ ¡£¡£µ«ÊÂÎñÔÚ5ÔÂ1ÈÕ²úÉúתÕÛ£¬£¬£¬ £¬£¬£¬£¬AvosÄܹ»½Ó¼ûѧÌõĴ¹Î£¾¯±¨ÏµÍ³RamAlert£¬£¬£¬ £¬£¬£¬£¬²¢Í¨¹ý¸ÃϵͳÏòѧÉúºÍ½ÌÖ°¹¤·¢ËͶÌÐźÍÓʼþ¾¯±¨£¬£¬£¬ £¬£¬£¬£¬³ÆÒÑÇÔÈ¡1.2 TBÎļþ£¬£¬£¬ £¬£¬£¬£¬²¢ÍþвÈôÊDz»¸¶Êê½ð½«°ä²¼Ëùº±¼û¾Ý¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/ransomware-gang-hijacks-university-alert-system-to-issue-threats/


4¡¢SophosÅû¶Dragon BreathÈÆ¹ý¼ì²âµÄм¼ÊõµÄϸ½Ú


5ÔÂ3ÈÕ£¬£¬£¬ £¬£¬£¬£¬SophosÅû¶ÁËDragon Breathͨ¹ýË«DLL²à¼ÓÔØ¼¼ÊõÀ´Èƹý¼ì²âµÄ·½Ê½¡£¡£¡£ ¡£¡£ÕâЩ¹¥»÷ÀûÓÃÁËÒ»¸ö¸É¾»µÄÀûÓ÷¨Ê½£¬£¬£¬ £¬£¬£¬£¬×î³£¼ûµÄÊÇTelegram£¬£¬£¬ £¬£¬£¬£¬Ëü²à¼ÓÔØÒ»¸öµÚ¶þ½×¶Îpayload£¬£¬£¬ £¬£¬£¬£¬ÓÐʱҲÊǸɾ»µÄ£¬£¬£¬ £¬£¬£¬£¬¶øºóÓÖ²à¼ÓÔØÒ»¸ö¶ñÒâÈí¼þ¼ÓÔØ·¨Ê½DLL¡£¡£¡£ ¡£¡£×îÖÕpayload DLL´ÓÒ»¸ötxtÎļþ£¨'templateX.txt'£©ÖнâÃܲ¢ÔÚϵͳÖÐÖ´ÐС£¡£¡£ ¡£¡£ÕâÊÇÒ»¸öºóÃÅ£¬£¬£¬ £¬£¬£¬£¬Ö§³Ö¶à¸öºÅÁ£¬£¬ £¬£¬£¬£¬Èçϵͳ³ÁÆô¡¢×¢²á±íÏîÅú¸ÄºÍÔÚ°µ²ØµÄCMD´°¿ÚÉÏÖ´ÐкÅÁîµÈ£¬£¬£¬ £¬£¬£¬£¬Ëü»¹Õë¶ÔMetaMask¼ÓÃÜÇ®±ÒÇ®°üChromeÀ©´ó¡£¡£¡£ ¡£¡£¸Ã»î¶¯µÄÖØÒªÕë¶ÔÈÕ±¾¡¢Öйų́Íå¡¢ÐÂ¼ÓÆÂ¡¢ÖйúÏã¸ÛºÍ·ÆÂɱöµÈµØ¡£¡£¡£ ¡£¡£


https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/


5¡¢Meta¼ì²âµ½NodeStealerºÍ¶à¸ö¼ÙÒâChatGPTµÄ¶ñÒâÈí¼þ


5ÔÂ3ÈÕ£¬£¬£¬ £¬£¬£¬£¬Meta³ÆÆä·¢ÏÖDucktail¡¢NodeStealerºÍ¼ÙÒâChatGPTµÈ¹¤¾ßµÄ¶ñÒâÈí¼þµÄ¹¥»÷»î¶¯¡£¡£¡£ ¡£¡£×Ô3ÔÂÒÔÀ´£¬£¬£¬ £¬£¬£¬£¬Meta¾Í·¢ÏÖÁËÔ¼10¸ö¶ñÒâÈí¼þ¼Ò×åʹÓÃChatGPTµÈÀàËÆÖ÷ÌâÈëÇÖÍøÂçÉϵÄÕÊ»§¡£¡£¡£ ¡£¡£1ÔÂÏÂÑ®£¬£¬£¬ £¬£¬£¬£¬×êÑÐÈËÔ±³õ´Î·¢ÏÖÁËNodeStealer¶ñÒâÈí¼þ£¬£¬£¬ £¬£¬£¬£¬²¢½«Æä¹éÒòÓÚÔ½ÄϵĹ¥»÷Õߣ¬£¬£¬ £¬£¬£¬£¬VirusTotalÉÏÏÕЩËùÓÐAVÒýÇæ¶¼Î´Äܽ«ÆäÏóÕ÷Ϊ¶ñÒâÈí¼þ¡£¡£¡£ ¡£¡£¸Ã¶ñÒâÈí¼þÖØÒªÇÔÈ¡´æ´¢ÔÚChromiumä¯ÀÀÆ÷£¨ÈçChromeºÍEdge£©ÖеÄFacebook¡¢GmailºÍOutlookµÄcookieºÍÕÊ»§Í´´¦¡£¡£¡£ ¡£¡£FacebookÒÑÏòÓò×¢²áÉ̻㱨Á˹¥»÷ÕߵķþÎñÆ÷£¬£¬£¬ £¬£¬£¬£¬²¢ÓÚ1ÔÂ25ÈÕ½«Æä¹Ø¹Ø¡£¡£¡£ ¡£¡£


https://engineering.fb.com/2023/05/03/security/malware-nodestealer-ducktail/


6¡¢Trend Micro°ä²¼Earth Longzhi¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨


Trend MicroÔÚ5ÔÂ2ÈÕ°ä²¼Á˹ØÓÚEarth Longzhi¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£ ¡£¡£¸Ã»î¶¯ÖØÒªÕë¶ÔÖйų́Í塢̩¹ú¡¢·ÆÂɱöºÍì³¼ÃÈ·µ±¾Ö¡¢Ò½ÁƱ£½¡¡¢¼¼ÊõºÍÔì×÷ÓйØ×éÖ¯¡£¡£¡£ ¡£¡£¹¥»÷ÕßÀûÓÃWindows Defender¿ÉÖ´ÐÐÎļþÀ´Ö´ÐÐDLL²à¼ÓÔØ£¬£¬£¬ £¬£¬£¬£¬Í¬Ê±»¹ÀûÓÃÁËÒ»¸öÒ×Êܹ¥»÷µÄÇý¶¯·¨Ê½zamguard64.sys£¬£¬£¬ £¬£¬£¬£¬Í¨¹ý×Ô´øÒ×Êܹ¥»÷µÄÇý¶¯·¨Ê½£¨BYOVD£©À´½ûÓÃÖ÷»úÉϵݲȫ²úÆ·¡£¡£¡£ ¡£¡£´Ë±í£¬£¬£¬ £¬£¬£¬£¬Earth Longzhi»¹Ê¹ÓÃÁËÒ»ÖÖеķ½Ê½À´½ûÓð²È«²úÆ·£¬£¬£¬ £¬£¬£¬£¬Í¨¹ýͼÏñÎļþÖ´ÐÐÑ¡ÏIFEO£©µÄ "stack rumbling"£¬£¬£¬ £¬£¬£¬£¬ÕâÊÇÒ»ÖÖеÄDoS¼¼Êõ¡£¡£¡£ ¡£¡£ 


https://www.trendmicro.com/en_us/research/23/e/attack-on-security-titans-earth-longzhi-returns-with-new-tricks.html