×êÑÐÈËÔ±Åû¶WinRARÖеÄRCE·ì϶CVE-2023-40477

°ä²¼¹¦·ò 2023-08-21

1¡¢×êÑÐÈËÔ±Åû¶WinRARÖеÄRCE·ì϶CVE-2023-40477


¾ÝýÌå8ÔÂ18ÈÕ±¨Â· £¬£¬£¬ £¬£¬×êÑÐÈËÔ±goodbyeseleneÅû¶ÁËWinRARÖеķì϶£¨CVE-2023-40477£©¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ã·ì϶´æÔÚÓÚ¸´Ô­¾íµÄ´¦Öùý³ÌÖÐ £¬£¬£¬ £¬£¬ÓÉÓÚ²»×ã¶ÔÓû§ÌṩÊý¾ÝµÄÊʵ±ÑéÖ¤ £¬£¬£¬ £¬£¬¿ÉÄܵ¼ÖÂÄÚ´æ½Ó¼û³¬¹ý¶ÈÅ仺³åÇøµÄ½áβ¡£¡£¡£¡£¡£¡£ ¡£¡£µ±Óû§´ò¿ªÌØÔìµÄRARÎļþºó £¬£¬£¬ £¬£¬Ô¶³Ì¹¥»÷ÕßÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ ¡£¡£×êÑÐÈËÔ±ÓÚ6ÔÂ8ÈÕÏò¹©¸øÉÌRARLAB»ã±¨ÁËÕâÒ»·ì϶ £¬£¬£¬ £¬£¬RARLABÓÚ8ÔÂ2ÈÕ°ä²¼Á˲¹¶¡ £¬£¬£¬ £¬£¬¸Ã²¹¶¡»¹½â¾öÁËÌØÔì´æµµµ¼ÖÂÎļþÆô¶¯ÃýÎóµÄÎÊÌâ¡£¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/winrar-flaw-lets-hackers-run-programs-when-you-open-rar-archives/


2¡¢ÌØË¹À­¹«¿ªÓ°Ï쳬¹ý7ÍòÃûÔ±¹¤ÐÅÏ¢µÄÊý¾Ýй¶ÊÂÎñ


8ÔÂ19ÈÕ±¨Â·³Æ £¬£¬£¬ £¬£¬ÌØË¹À­Åû¶ÁË5Ô·ݲúÉúµÄÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£ ¡£¡£¹«Ë¾µ÷²é·¢ÏÖ £¬£¬£¬ £¬£¬Á½ÃûǰԱ¹¤ÇÔÈ¡ÁË»úÃÜÐÅÏ¢ £¬£¬£¬ £¬£¬Î¥·´ÁËÌØË¹À­µÄIT°²È«ºÍÊý¾Ý±£»£»£»£»£»£»¤Õþ²ß¡£¡£¡£¡£¡£¡£ ¡£¡£Òò¶ø £¬£¬£¬ £¬£¬ÌØË¹À­¶ÔÕâЩǰԱ¹¤Ìá¸æ×´ËÏ £¬£¬£¬ £¬£¬²¢¿ÛѺÁËËûÃÇÔ̺¬±»µÁÐÅÏ¢µÄµç×ÓÉ豸¡£¡£¡£¡£¡£¡£ ¡£¡£´Ë±í £¬£¬£¬ £¬£¬ÌØË¹À­»¹·¢ÏÖÕâÁ½ÃûÔ±¹¤ÓëµÂ¹ú±¨ÉçHandelsblatt·ÖÏíÁ˱»µÁµÄÊý¾Ý¡£¡£¡£¡£¡£¡£ ¡£¡£²»Íâ £¬£¬£¬ £¬£¬Õâ¼Ò±¨ÉçÏòÌØË¹À­±£ÕÏ £¬£¬£¬ £¬£¬ËûÃDz»»á¹«¿ªÕâЩÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£¡£¸ÃÊÂÎñÓ°ÏìÁË75735ÃûÔ±¹¤ £¬£¬£¬ £¬£¬ÌØË¹À­½«ÎªËûÃÇÌṩΪÆÚ12¸öÔµÄÐÅÓþ¼à¿ØºÍÉí·Ý͵ÇÔ·þÎñ¡£¡£¡£¡£¡£¡£ ¡£¡£


https://www.databreaches.net/tesla-notifies-employees-of-data-breach/


3¡¢·¨ÂÉ»ú¹¹Africa Cyber Surge IIÐж¯¿ÛÁô14ÃûÏÓÒÉÈË


ýÌå8ÔÂ18ÈÕ³Æ £¬£¬£¬ £¬£¬¹ú¼ÊÐ̾¯×é֯Эµ÷µÄ·¨ÂÉÐж¯Africa Cyber Surge IIÒÑ¿ÛÁôÁË14ÃûÏÓÒÉÈË¡£¡£¡£¡£¡£¡£ ¡£¡£¸ÃÐж¯ÓÚ½ñÄê4ÔÂ·ÝÆðÍ· £¬£¬£¬ £¬£¬¸²¸ÇÁË·ÇÖÞµÄ25¸ö¹ú¶È £¬£¬£¬ £¬£¬µ·»ÙÁË20000¶à¸öÓÃÓÚÀÕË÷¡¢´¹µö¡¢BECºÍڲƭ¹¥»÷µÄ·¸×ïÍøÂç £¬£¬£¬ £¬£¬ËüÃÇÒÑÔì³ÉÁ˳¬¹ý40000000ÃÀÔªµÄËðʧ¡£¡£¡£¡£¡£¡£ ¡£¡£´Ë±í £¬£¬£¬ £¬£¬µ±¾Ö»¹²é»ñÁËÊý°Ù¸öÍйܶñÒâÈí¼þÒÔ¼°´«²¼Î£ÏÕµÄÈí¼þµÄ¶ñÒâIPµØÖ·¡£¡£¡£¡£¡£¡£ ¡£¡£2022Äê11Ô·¢Õ¹µÄµÚÒ»´ÎAfrica Cyber SurgeÐж¯¿ÛÁôÁË11Ó×ÎÒ £¬£¬£¬ £¬£¬²¢µ·»ÙÁËÒ»¸öÏúÊۺڿ͹¤¾ßµÄ°µÍøºÍÔ¼20Íò¸ö¶ñÒâ»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£ ¡£¡£


https://therecord.media/africa-cyber-surge-14-arrests-interpol


4¡¢µÂ¹úÁª¹úÂÉʦЭ»á(BRAK)Ôâµ½NoEscapeµÄÀÕË÷¹¥»÷


¾Ý8ÔÂ18ÈÕ±¨Â· £¬£¬£¬ £¬£¬µÂ¹ú¹ú¶ÈÂÉʦЭ»á(BRAK)й©ÔÚµ÷²éÆä²¼Â³Èû¶û´¦Ê´¦Ôâµ½µÄÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£ ¡£¡£BRAKÕÆ¹Ü¼à¹ÜµÂ¹ú28¸öµØÓòµÄÂÉʦÊÂÎñËù £¬£¬£¬ £¬£¬´ú±í¹úÄÚ±íÔ¼166000ÃûÂÉʦ¡£¡£¡£¡£¡£¡£ ¡£¡£¸Ã»ú¹¹ÓÚ8ÔÂ2ÈÕ·¢ÏÖÁ˹¥»÷ÊÂÎñ £¬£¬£¬ £¬£¬ÀÕË÷ÍÅ»ïNoEscapeÔÚ8ÔÂ15ÈÕ³ÆÆä¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£¡£¡£¡£¡£¡£ ¡£¡£ºÚ¿ÍÐû³Æ¼ÓÃÜÁËBRAKµÄÓʼþ·þÎñÆ÷²¢»ñÈ¡ÁË160 GBµÄÊý¾Ý¡£¡£¡£¡£¡£¡£ ¡£¡£BRAK°µÊ¾ÒѾ­¸´Ô­µç×ÓÓʼþϵͳµÄ½Ó¼û £¬£¬£¬ £¬£¬²¢´òËãÁªÏµÊÜÊý¾Ýй¶ӰÏìµÄÓ×ÎÒ¡£¡£¡£¡£¡£¡£ ¡£¡£


https://therecord.media/german-national-bar-association-investigating-cyberattack


5¡¢Î¢Èí³ÆBlackCatµÄбäÌåÒÑǶÈëImpacketºÍRemCom


΢ÈíÔÚ8ÔÂ17ÈճƷ¢ÏÖÁËÀÕË÷Èí¼þBlackCatµÄбäÌå £¬£¬£¬ £¬£¬Ç¶ÈëÁËÍøÂç¿ò¼ÜImpacketºÍºÚ¿Í¹¤¾ßRemcom¡£¡£¡£¡£¡£¡£ ¡£¡£Î¢Èí°µÊ¾ £¬£¬£¬ £¬£¬½üÆÚµÄBlackCat»î¶¯ÔÚʹÓÃImpacket¿ò¼Ü½øÐÐÆ¾Ö¤¸´ÔìºÍÔ¶³Ì·þÎñÖ´ÐÐ £¬£¬£¬ £¬£¬ÒÔÔÚÕû¸öÍøÂçÉÏ×°ÖüÓÃÜÆ÷·¨Ê½¡£¡£¡£¡£¡£¡£ ¡£¡£´Ë±í £¬£¬£¬ £¬£¬¼ÓÃÜ·¨Ê½»¹Ç¶ÈëÁËRemcom £¬£¬£¬ £¬£¬¿ÉÔÚϵͳÉÏµÄÆäËüÉ豸ÉÏÔ¶³ÌÖ´ÐкÅÁî¡£¡£¡£¡£¡£¡£ ¡£¡£Î¢Èí»¹Ð¹Â© £¬£¬£¬ £¬£¬BlackCatµÄ´ÓÊô»ú¹¹Storm-0875×Ô7ÔÂÒÔÀ´¾ÍʹÓÃÁËÕâÖÖеļÓÃÜ·½Ê½¡£¡£¡£¡£¡£¡£ ¡£¡£Î¢Èí½«Õâ¸öа汾¶¨ÃûΪBlackCat 3.0 £¬£¬£¬ £¬£¬ÀÕË÷ÍÅ»ïÔÚÓëÆä´ÓÊô»ú¹¹µÄͨѶÖн«Æä³ÆÎªSphynx»òBlackCat/ALPHV 2.0¡£¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-blackcats-sphynx-ransomware-embeds-impacket-remcom/


6¡¢³¬¹ý3000¸ö¶ñÒâÈí¼þʹÓÃδ֪ѹËõ²½ÖèÀ´Èƹý¼ì²â


¾Ý8ÔÂ19ÈÕ±¨Â·³Æ £¬£¬£¬ £¬£¬¹¥»÷ÕßÔÚʹÓÃδ֪»ò²»ÊÜÖ§³ÖµÄѹËõ²½ÖèµÄAPKÎļþÀ´Èƹý¶ñÒâÈí¼þ·ÖÎö¡£¡£¡£¡£¡£¡£ ¡£¡£ZimperiumÔÚÒ°±í·¢ÏÖÁË3300¸öÀûÓôËÀàѹËõËã·¨µÄAndroid¶ñÒâÈí¼þ £¬£¬£¬ £¬£¬ÆäÖÐ71¸öÑù±¾Äܹ»Ë³ÀûµØ¼ÓÔØµ½ÏµÍ³ÉÏ¡£¡£¡£¡£¡£¡£ ¡£¡£ÕâÖÖ·½Ê½µÄÀûÒæÊÇ¿ÉÄÜÈÆ¹ý·´±àÒ빤¾ß £¬£¬£¬ £¬£¬Í¬Ê±»¹ÄÜ×°ÖÃÔÚOS°æ±¾¸ßÓÚAndroid 9 PieµÄÉ豸ÉÏ¡£¡£¡£¡£¡£¡£ ¡£¡£´Ë±í £¬£¬£¬ £¬£¬Zimperium»¹·¢ÏÖ¶ñÒâÈí¼þ¿ª·¢ÕßÓÐÒâ·ÛËéAPKÎļþÀ´Èƹý¼ì²âµÄÆäËü·½Ê½ £¬£¬£¬ £¬£¬Ô̺¬Ê¹Óó¬¹ý256×Ö½ÚµÄÎļþÃû¡¢ÌåʽÃýÎóµÄAndroidManifest.xmlºÍÌåʽÃýÎóµÄ×Ö·û´®³ØµÈ¡£¡£¡£¡£¡£¡£ ¡£¡£


https://securityaffairs.com/149678/malware/android-malware-using-unsupported-unknown-compression.html