Checkmarx¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©¸øÁ´¹¥»÷

°ä²¼¹¦·ò 2023-07-25

1¡¢Checkmarx¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©¸øÁ´¹¥»÷


CheckmarxÔÚ7ÔÂ21ÈÕ³ÆÆä¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©¸øÁ´£¨OSS£©¹¥»÷¡£¡£¡£¡£¡£µÚÒ»´Î¹¥»÷²úÉúÓÚ4ÔÂÉÏÑ®£¬£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¼ÙÒâÖ¸±êÒøÐÐÔ±¹¤£¬£¬£¬£¬£¬£¬ £¬ÀûÓÃNPMƽ̨ÉÏ´«Á˼¸¸öÈí¼þ°ü£¬£¬£¬£¬£¬£¬ £¬ÆäÖÐÔ̺¬Ô¤×°Öþ籾£¬£¬£¬£¬£¬£¬ £¬¿ÉÔÚ×°ÖÃʱִÐжñÒâ»î¶¯¡£¡£¡£¡£¡£»£»£»£» £»£»£»¹ÀûÓÃAzureµÄCDN×ÓÓòÀ´·Ö·¢µÚ¶þ½×¶ÎµÄpayload Havoc£¬£¬£¬£¬£¬£¬ £¬ÕâÊÇÒ»¸öC2¿ò¼Ü¡£¡£¡£¡£¡£ÔÚ2Ô·ݼì²âµ½µÄÕë¶ÔÒøÐеÄÁíÒ»´Î¹¥»÷ÖУ¬£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÒ²ÉÏ´«ÁËÒ»¸ö¶ñÒânpm°ü£¬£¬£¬£¬£¬£¬ £¬Ö¼ÔÚÀ¹½ØµÇ¼Êý¾Ý²¢½«Æä·¢Ë͸ø¹¥»÷Õß¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬ £¬×êÑÐÈËÔ±ÒѾ­»ã±¨²¢É¾³ýÁËÕâЩ¶ñÒ⿪ԴÈí¼þ°ü¡£¡£¡£¡£¡£


https://checkmarx.com/blog/first-known-targeted-oss-supply-chain-attacks-against-the-banking-sector/


2¡¢Apple¸üн¨¸´Òѱ»ÀûÓõÄÄں˷ì϶CVE-2023-38606 


¾ÝýÌå7ÔÂ24ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬ £¬Apple°ä²¼Á˰²È«¸üУ¬£¬£¬£¬£¬£¬ £¬ÒÔ½¨¸´Õë¶ÔiPhone¡¢MacºÍiPadµÄ¹¥»÷Öб»ÀûÓõķì϶¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÄں˷ì϶£¨CVE-2023-38606£©£¬£¬£¬£¬£¬£¬ £¬¿ÉÄܱ»ÓÃÀ´´Û¸ÄÃô¸ÐµÄÄÚºË״̬£¬£¬£¬£¬£¬£¬ £¬¿ÉÄÜÒÑÔÚiOS 15.7.1֮ǰ°ä²¼µÄiOS°æ±¾Öб»»ý¼«ÀûÓᣡ£¡£¡£¡£Kaspersky°µÊ¾£¬£¬£¬£¬£¬£¬ £¬CVE-2023-38606ÊÇÁãµã»÷·ì϶ÀûÓÃÁ´µÄÒ»²¿ÃÅ£¬£¬£¬£¬£¬£¬ £¬ÓÃÓÚͨ¹ýiMessage·ì϶ÔÚiPhoneÉÏ×°ÖüäµýÈí¼þTriangulation¡£¡£¡£¡£¡£ÕâÊÇAppleÔÚ½ñÄ꽨¸´µÄµÚʮһ¸öÒѱ»ÀûÓõÄÁãÈÕ·ì϶¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/apple/apple-fixes-new-zero-day-used-in-attacks-against-iphones-macs/


3¡¢ClopÀûÓÃMOVEit·ì϶µÄ¹¥»÷Ô¤¹À»ñÀû7500ÍòÖÁ1ÒÚÃÀÔª


CovewareÔÚ7ÔÂ21ÈÕй©£¬£¬£¬£¬£¬£¬ £¬ClopÀûÓÃMOVEit·ì϶µÄ´ó¹æÄ£Êý¾ÝÇÔÈ¡»î¶¯Ô¤¼Æ»ñÀû¸ß´ï7500ÍòÖÁ1ÒÚÃÀÔª¡£¡£¡£¡£¡£ÔÚ2023ÄêQ2£¬£¬£¬£¬£¬£¬ £¬½»Êê½ðµÄ±»¹¥»÷Ö¸±êµÄÊýÁ¿ÒѽµÖÁ34%£¬£¬£¬£¬£¬£¬ £¬´´Ïº¹ÇàеÍ£¬£¬£¬£¬£¬£¬ £¬µ¼ÖÂÀÕË÷ÍÅ»ïŤתսÊõÒÔ×êÓª¸ü¸ßµÄÀûÈ󡣡£¡£¡£¡£Coveware°µÊ¾£¬£¬£¬£¬£¬£¬ £¬ClopÒѾ­Å¤×ªÁËÕ½Êõ£¬£¬£¬£¬£¬£¬ £¬ÀÕË÷¸ü¸ßµÄÊê½ð£¬£¬£¬£¬£¬£¬ £¬µ«Ô¸Í¨¹ý¼¸±Ê´ó¶î¸¶¿îÀ´¿Ë·þÕûÌå½µÂäµÄÇé¿ö¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬ £¬¸´ÔÓÐÔºÍ×Ô¶¯»¯Ë®Æ½µÍµÄÀÕË÷¹¥»÷µÄÓ°ÏìºÍ³É±¾×îÓס£¡£¡£¡£¡£


https://www.coveware.com/blog/2023/7/21/ransom-monetization-rates-fall-to-record-low-despite-jump-in-average-ransom-payments


4¡¢×êÑÐÈËÔ±Åû¶OpenMeetings¿É½Ù³ÖÖÎÀíÔ¹ØÊ»§µÄ·ì϶


¾Ý7ÔÂ21ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬ £¬×êÑÐÈËÔ±Åû¶ÁËApache OpenMeetingsÖеÄ3¸ö·ì϶µÄϸ½Ú¡£¡£¡£¡£¡£ÕâЩ·ì϶±ðÀëΪÈõ¹þÏ£±ÈÁ¦·ì϶£¨CVE-2023-28936£©¡¢Í¨¹ýÔ¼Çë¹þÏ£½øÐÐÎÞÏ޶ȽӼûµÄ·ì϶£¨CVE-2023-29023£©ÒÔ¼°¿Õ×Ö½Ú×¢Èë·ì϶(CVE-2023-29246£©£¬£¬£¬£¬£¬£¬ £¬¿É±»×ÔÐÐ×¢²áÓû§£¨Ä¬ÈÏÆôÓã©ÓÃÀ´½Ù³ÖÖÎÀíÔ¹ØÊ»§²¢Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬ £¬ÕâЩ·ì϶ÒÑÔÚApache OpenMeetings 7.1.0°æ±¾Öн¨¸´¡£¡£¡£¡£¡£


https://www.securityweek.com/openmeetings-flaws-allow-hackers-to-hijack-instances-execute-code-on-servers/


5¡¢AhnLab·¢ÏÖͨ¹ýMS-SQL·þÎñÆ÷·Ö·¢PurpleFoxµÄ»î¶¯


7ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬ £¬AhnLab³ÆÆä·¢ÏÖÁËͨ¹ýÖÎÀí²»ÉÆµÄMS-SQL·þÎñÆ÷·Ö·¢PurpleFoxµÄ»î¶¯¡£¡£¡£¡£¡£¹¥»÷Ê×ÏÈͨ¹ýsqlservr.exeÖ´ÐÐPowerShell£¬£¬£¬£¬£¬£¬ £¬ÕâÊÇÒ»¸öÓëMS-SQL·þÎñÆ÷ÓйصĹý³Ì¡£¡£¡£¡£¡£µ±Ö´ÐÐÉÏÊöPowerShellʱ£¬£¬£¬£¬£¬£¬ £¬½«ÏÂÔØ²¢¼ÓÔØÁíÒ»¸ö¾­¹ý»ìºÏµÄPowerShell¡£¡£¡£¡£¡£ÆäÖÐÔ̺¬Ò»¸ö¹¥»÷Õß¿ª·¢µÄº¯ÊýMsiMake£¬£¬£¬£¬£¬£¬ £¬¿ÉÏÂÔØÒ»¸öMSIÎļþ¡£¡£¡£¡£¡£MSI°ü¸ü¸Ä×¢²á±íÏîÒÔʵÏÖÓÆ¾ÃÐÔºÍȨÏÞÌáÉý¡£¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬£¬ £¬MSI°ü»á³¢ÊÔ³ÁÆôϵͳ£¬£¬£¬£¬£¬£¬ £¬½Ó×ÅSENS·þÎñ»á±»Ö´ÐУ¬£¬£¬£¬£¬£¬ £¬´Ó¶ø¼¤»î¶ñÒâÈí¼þ¡£¡£¡£¡£¡£


https://asec.ahnlab.com/en/55492/


6¡¢IBM°ä²¼¹ØÓÚ2023ÄêÊý¾Ýй¶³É±¾µÄ·ÖÎö»ã±¨


7ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬ £¬IBM°ä²¼¹ØÓÚ2023ÄêÊý¾Ýй¶³É±¾µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¸Ã»ã±¨¶Ô553¸ö×éÖ¯µÄÊý¾Ýй¶Çé¿ö½øÐÐÁË·ÖÎö£¬£¬£¬£¬£¬£¬ £¬×êÑеÄÎ¥¹æÊÂÎñ²úÉúÔÚ2022Äê3ÔÂÖÁ2023Äê3Ô¡£¡£¡£¡£¡£×îÐÂ×êÑÐÏÔʾ£¬£¬£¬£¬£¬£¬ £¬Êý¾Ýй¶³É±¾³ÖÐøÔö³¤£¬£¬£¬£¬£¬£¬ £¬È«Çò¾ùÔȳɱ¾¸ß´ï445ÍòÃÀÔª£¬£¬£¬£¬£¬£¬ £¬ÈýÄêÄÚÔö³¤ÁË15%¡£¡£¡£¡£¡£Ò½ÁƱ£½¡ÐÐÒµµÄ³É±¾Î»¾Ó°ñÊ×£¬£¬£¬£¬£¬£¬ £¬Â½Ðø13Äê³ÉΪ³É±¾×î¸ßµÄÐÐÒµ¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬ £¬°²È«ÈËΪÖÇÄܺÍ×Ô¶¯»¯¡¢DevSecOps²½ÖèºÍIR´òËãÔÚ½Ú¼ó³É±¾·½Ãæ²ûÑïÁËÖ÷µ¼×÷Ó㻣»£»£» £»£»£»ÈËΪÖÇÄܺÍASM¼Ó¿ìÁËÎ¥¹æÊÂÎñµÄ¼ø±ðºÍ¶ôÔ죻£»£»£» £»£»£»µ±Êý¾Ý´æ´¢ÔÚ¶à¸ö»·¾³ÖÐʱ£¬£¬£¬£¬£¬£¬ £¬³É±¾ºÜ¸ß£¬£¬£¬£¬£¬£¬ £¬²¢ÇÒ±ØÒª¸ü³¤¹¦·òÄÜÁ¦¶ôÔìÎ¥¹æÊÂÎñ£»£»£»£» £»£»£»Õ¼Óз¢ÏÖÎ¥¹æÊÂÎñµÄÄÚ²¿ÍŶӵÄ×éÖ¯ÔÚ½ÚÔì³É±¾·½Ãæ²û·¢µÃ¸üºÃ¡£¡£¡£¡£¡£


https://securityintelligence.com/posts/whats-new-2023-cost-of-a-data-breach-report/