΢Èí°ä²¼6Ô·ݵݲȫ¸üУ¬£¬£¬£¬£¬ £¬£¬×ܼƽ¨¸´78¸ö·ì϶

°ä²¼¹¦·ò 2023-06-14

1¡¢Î¢Èí°ä²¼6Ô·ݵݲȫ¸üУ¬£¬£¬£¬£¬ £¬£¬×ܼƽ¨¸´78¸ö·ì϶


¾Ý6ÔÂ13ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬£¬Î¢Èí°ä²¼ÁË2023Äê6ÔµÄÖܶþ²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬ £¬£¬½¨¸´ÁË78¸ö·ì϶£¬£¬£¬£¬£¬ £¬£¬ÆäÖÐÔ̺¬38¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶ΪWindows Pragmatic General Multicast(PGM)ÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-29363¡¢CVE-2023-32014ºÍCVE-2023-32015£©ÒÔ¼°Microsoft SharePoint ServerÖеÄȨÏÞÌáÉý·ì϶£¨CVE-2023-29357£©µÈ¡£¡£¡£¡£¡£¡£¡£Õâ´Î¸üв»Ô̺¬ÁãÈÕ·ì϶»òÒѱ»ÀûÓõķì϶¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2023-patch-tuesday-fixes-78-flaws-38-rce-bugs/


2¡¢ÈðÊ¿Áª¹úÖÎÀí¾ÖÔâµ½DDoS¹¥»÷¶à¸öÍøÕ¾ºÍÀûÓò»³ÉÓÃ


ÈðÊ¿Áª¹úÖÎÀí¾ÖÔÚ6ÔÂ12ÈÕй©£¬£¬£¬£¬£¬ £¬£¬ÓÉÓÚϵͳÔâµ½DDoS¹¥»÷£¬£¬£¬£¬£¬ £¬£¬Æä¶à¸öÍøÕ¾¼°ÔÚÏß·þÎñ²»³É½Ó¼û¡£¡£¡£¡£¡£¡£¡£Óë¶íÂÞ˹ÓйصĺڿÍÍÅ»ïNoNameÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬£¬£¬£¬£¬ £¬£¬Ëü×Ô2022ËêÊ×ÒÔÀ´Ò»Ö¹Øë¶ÔÅ·ÖÞ¡¢ÎÚ¿ËÀ¼ºÍ±±ÃÀµÄ¹ú¶ÈºÍ×éÖ¯£¬£¬£¬£¬£¬ £¬£¬ÔÚÉÏÖÜ»¹¹¥»÷ÁËparlament.ch¡£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹³Æ£¬£¬£¬£¬£¬ £¬£¬×êÑÐÈËÔ±ºÜ¿ì¾Í°ÑÎȵ½ÁËÕâ´Î¹¥»÷£¬£¬£¬£¬£¬ £¬£¬²¢ÔÚ²ÉÈ¡´ëÊ©¾¡¿ì¸´Ô­ÍøÕ¾ºÍÀûÓõĿÉÓÃÐÔ¡£¡£¡£¡£¡£¡£¡£6ÔÂ1ÈÕ£¬£¬£¬£¬£¬ £¬£¬ÀÕË÷ÍÅ»ïPlayÔø¹«¿ªÁË´ÓÈðÊ¿¾üÕþ×éÖ¯µÄ¼¼ÊõÌṩÉÌXplainÇÔÈ¡µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


https://www.admin.ch/gov/en/start/documentation/media-releases.msg-id-95641.html


3¡¢HIBPÅû¶ӰÏìÔ¼890ÍòÓû§µÄZacksÊý¾Ýй¶ÊÂÎñ


¾ÝýÌå6ÔÂ12ÈÕ±¨Â·£¬£¬£¬£¬£¬ £¬£¬Êý¾Ýй¶֪ͨ·þÎñHave I Been Pwned(HIBP)Åû¶ÁËһ·½ÏÔçµÄZacksÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£HIBPÊÕµ½ÁËÒ»¸öÔ̺¬8929503ÌõÓû§¼Í¼µÄÊý¾Ý¿â£¬£¬£¬£¬£¬ £¬£¬ÆäÖÐÔ̺¬ÐÕÃû¡¢ÓʼþµØÖ·¡¢Óû§ÃûºÍSHA256ÃÜÂëµÈÐÅÏ¢£¬£¬£¬£¬£¬ £¬£¬Êý¾Ý¿âÖÐ×îмͼµÄÈÕÆÚΪ2020Äê5Ô¡£¡£¡£¡£¡£¡£¡£¸Ã·þÎñ֪ͨÁËZecks£¬£¬£¬£¬£¬ £¬£¬ºóÕ߳ƹ¥»÷ÕßÖ»ÄܽӼû¼ÓÃܵÄÃÜÂëÀ´µ­»¯Õâ´Î°²È«ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£ÔÚHIBPÅû¶¸ÃÊÂÎñºó²»¾Ã£¬£¬£¬£¬£¬ £¬£¬ZacksÊý¾Ý¿âÓÚ6ÔÂ10ÈÕ±»°ä²¼ÔÚºÚ¿ÍÂÛ̳ExposedÉÏ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/have-i-been-pwned-warns-of-new-zacks-data-breach-impacting-8-million/


4¡¢Ó¢¹úͨѶ¼à¹Ü»ú¹¹OfcomÔâµ½¹¥»÷²¿ÃÅ»úÃÜÐÅϢй¶


ýÌå6ÔÂ12Èճƣ¬£¬£¬£¬£¬ £¬£¬Ó¢¹úͨѶ¼à¹Ü»ú¹¹OfcomÔâµ½ÁËÁËÀÕË÷ÍÅ»ïClopµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃÁËMOVEitÎļþ´«ÊäÖеķì϶(CVE-2023-34362)À´½Ó¼û¸Ã»ú¹¹µÄ»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¡£½²»°ÈËй©£¬£¬£¬£¬£¬ £¬£¬¹¥»÷Õ߿ɽӼû¼à¹Ü»ú¹¹³ÖÓÐµÄÆä¼à¹ÜµÄ¹«Ë¾µÄ»úÃÜÐÅÏ¢£¬£¬£¬£¬£¬ £¬£¬ÒÔ¼°²¿ÃÅOfcomÔ±¹¤µÄÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ClopÓÚÉÏÖÜÈý°ä²¼ÁËÒ»·ÝÀÕË÷×¢Ã÷£¬£¬£¬£¬£¬ £¬£¬Ðû³Æ°ÑÎÕÁËÊý°Ù¼ÒÆóÒµµÄÐÅÏ¢£¬£¬£¬£¬£¬ £¬£¬²¢ÒªÇóÕâЩ×éÖ¯×Ô¶¯ÁªÏµÆäÀ´Ð­ÉÌÊê½ð£¬£¬£¬£¬£¬ £¬£¬²»È»ÕâЩ×éÖ¯½«ÓÚ6ÔÂ14ÈÕ±»Áгö¡£¡£¡£¡£¡£¡£¡£


https://therecord.media/ofcom-cyberattack-uk-regulator-moveit-vulnerability


5¡¢Kaspersky°ä²¼¶à½×¶Î¼ÓÔØ·¨Ê½DoubleFingerµÄ»ã±¨


6ÔÂ12ÈÕ£¬£¬£¬£¬£¬ £¬£¬Kaspersky°ä²¼Á˹ØÓÚÀûÓÃÐÂÐͶà½×¶Î¼ÓÔØ·¨Ê½DoubleFinger¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¹¥»÷ʼÓÚespexe.exeµÄÅú¸Ä°æ±¾£¬£¬£¬£¬£¬ £¬£¬¿É´ÓͼÏñÍйܷþÎñImgur¼ìË÷¼Ù×°³ÉPNGµÄ¼ÓÃܵÄpayload¡£¡£¡£¡£¡£¡£¡£¸Ãpayload»á´¥·¢Ò»¸öÔ̺¬Ëĸö½×¶ÎµÄ¹¥»÷Á´£¬£¬£¬£¬£¬ £¬£¬×îÖÕ»áÔÚÖ¸±êÖ÷»úÉÏÖ´ÐÐGreetingGhoul¡£¡£¡£¡£¡£¡£¡£GreetingGhoulÊÇÒ»¸öÇÔÈ¡·¨Ê½£¬£¬£¬£¬£¬ £¬£¬Ö¼ÔÚÇÔÈ¡Óë¼ÓÃÜÇ®±ÒÓйصÄÍ´´¦¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷»î¶¯ÖØÒªÕë¶ÔÅ·ÖÞ¡¢ÃÀ¹úºÍÀ­¶¡ÃÀÖÞ¡£¡£¡£¡£¡£¡£¡£


https://securelist.com/doublefinger-loader-delivering-greetingghoul-cryptocurrency-stealer/109982/


6¡¢Åµ»ùÑǰ䲼¹ØÓÚ2023ÄêÈ«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨


6ÔÂ9ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬ £¬£¬Åµ»ùÑǰ䲼Á˹ØÓÚ2023ÄêÈ«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¸Ã»ã±¨Éî¿Ì·ÖÎöÁË4GºÍ5G°²È«¹¥»÷¡¢¶ñÒâÈí¼þ¹¥»÷¡¢DDoS¹¥»÷ÒÔ¼°Õë¶ÔÈ«Çò¹Ì¶¨ºÍÒÆ¶¯ÍøÂçµÄÆäËü´ó¾ÖµçÐÅÍøÂç¹¥»÷µÄÇ÷Ïò¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬ £¬£¬»ùÓÚ½©Ê¬ÍøÂçµÄDDoS¹¥»÷Éý¼¶£¬£¬£¬£¬£¬ £¬£¬Ê¹Óõı»Ï°È¾ÎïÁªÍøÉ豸ÊýÁ¿´Ó200000¼¤ÔöÖÁÔ¼100Íò£¬£¬£¬£¬£¬ £¬£¬Ä¿Ç°Õ¼ËùÓÐDDoSÁ÷Á¿µÄ40%ÒÔÉÏ¡£¡£¡£¡£¡£¡£¡£ÒÔÒÆ¶¯É豸ÉϵÄÒøÐÐÐÅϢΪָ±êµÄľÂíÊýÁ¿·­ÁËÒ»·¬£¬£¬£¬£¬£¬ £¬£¬Ä¿Ç°Õ¼ËùÓÐϰȾµÄ9%¡£¡£¡£¡£¡£¡£¡£¼ÒÍ¥ÍøÂçÖеĶñÒâÈí¼þϰȾÓÐËù½µÂ䣬£¬£¬£¬£¬ £¬£¬´ÓCovid-19ÆÚ¼äµÄ3%½µÂäµ½1.5%¡£¡£¡£¡£¡£¡£¡£


https://www.nokia.com/networks/security-portfolio/threat-intelligence-report/