Microsoft DNSÅäÖÃÃýÎóµ¼ÖÂHotmailÓʼþ·¢ËÍʧ°Ü
°ä²¼¹¦·ò 2023-08-221¡¢Microsoft DNSÅäÖÃÃýÎóµ¼ÖÂHotmailÓʼþ·¢ËÍʧ°Ü
¾ÝýÌå8ÔÂ18ÈÕ±¨Â·£¬£¬£¬£¬£¬È«ÇòÁìÓòÄÚµÄHotmailÓû§ÔÚ·¢Ë͵ç×ÓÓʼþʱÓöµ½ÎÊÌâ¡£¡£¡£¡£¡£¡£ÔÚMicrosoftÃýÎóÅäÖÃÓòµÄDNS SPF¼Í¼ºó£¬£¬£¬£¬£¬Óʼþ±»ÏóÕ÷ΪÀ¬»øÓʼþ»òδͶµÝ¡£¡£¡£¡£¡£¡£¸ÃÎÊÌâʼÓÚ17ÈÕÉîÒ¹£¬£¬£¬£¬£¬ÏÔʾÃýÎóÐÂÎÅ¡°´ËÃýÎóÓë·¢¼þÈËÕ½Êõ¿ò¼Ü(SPF)Óйء£¡£¡£¡£¡£¡£Ö¸±êÓʼþϵͳ¶ÔÓʼþµÄSPF¼Í¼µÄÆÀ¹Àµ¼ÖÂÃýÎ󡣡£¡£¡£¡£¡£ÇëÓëÄúµÄÓò×¢²áÉ̺Ï×÷£¬£¬£¬£¬£¬È·±£ÄúµÄSPF¼Í¼ÅäÖÃÕýÈ·¡±¡£¡£¡£¡£¡£¡£¸ÃÎÊÌâÔ´ÓÚMicrosoftɾ³ýÁËhotmail.com SPF¼Í¼ÖеÄ"include:spf.protection.outlook.com"¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬¸ÃÎÊÌâÒѾµÃµ½½â¾ö¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/microsoft/hotmail-email-delivery-fails-after-microsoft-misconfigures-dns/
2¡¢Ivanti SentryÖеķì϶CVE-2023-38035Òѱ»ÀûÓÃ
¾Ý8ÔÂ21ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬Ivanti Sentry£¨ÒÔǰ³ÆÎªMobileIron Sentry£©ÖеÄÒ»¸öAPIÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶(CVE-2023-38035)Òѱ»ÀûÓᣡ£¡£¡£¡£¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýMobileIronÅäÖ÷þÎñ(MICS)ʹÓõÄ8443¶Ë¿Ú½Ó¼ûÖÎÀíÃÅ»§ÅäÖÃAPI£¬£¬£¬£¬£¬Äܹ»ÀûÓÃÏ޶Ȳ»¼°µÄApache HTTPDÅäÖÃÈÆ¹ýÉí·ÝÑéÖ¤½ÚÔìÀ´ÊµÏÖ¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓú󣬣¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÔÚÔËÐÐIvanti Sentry 9.18¼°¸üµÍ°æ±¾µÄϵͳÉϸü¸ÄÅäÖá¢ÔËÐÐϵͳºÅÁî»òдÈëÎļþ¡£¡£¡£¡£¡£¡£Ä¿Ç°¹©¸øÉÌÒѰ䲼°²È«¸üн¨¸´´Ë·ì϶¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/ivanti-warns-of-new-actively-exploited-mobileiron-zero-day-bug/
3¡¢°Ä´óÀûÑÇauDA·ñ¶¨NoEscapeÇÔÈ¡Æä15 GBÊý¾ÝµÄ˵·¨
ýÌå8ÔÂ21Èճƣ¬£¬£¬£¬£¬ÖÎÀí°Ä´óÀûÑÇÓòÃû.auµÄ»ú¹¹auDA·ñ¶¨Æä²úÉúÁËÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹±»ÊÓΪ°Ä´óÀûÑǹؼü»ù´¡ÉèÊ©£¬£¬£¬£¬£¬ÓÐ400¶àÍò¸öÓòÃû×¢²áÔÚ.auÉÏ¡£¡£¡£¡£¡£¡£8ÔÂ11ÈÕ£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïNoEscapeÐû³Æ¹¥»÷Á˸ûú¹¹²¢ÇÔÈ¡ÁË15 GBÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Ó×ÎÒÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£auDA³ÆËûÃDzé³ÁËNoEscape¹«¿ªµÄÎļþ£¬£¬£¬£¬£¬ÕâЩÎļþ²¢Ã»Óд洢ÔÚËûÃǵÄϵͳÉÏ¡£¡£¡£¡£¡£¡£²¢°µÊ¾Êý¾Ýй¶µÄÆðÔ´ÊÇÒ»¸ö°Ä´óÀûÑǸö±ðÉÌ»§£¬£¬£¬£¬£¬Æä·þÎñÆ÷ÓÚ8ÔÂ10ÈÕÔâµ½¹¥»÷¡£¡£¡£¡£¡£¡£Ëæºó£¬£¬£¬£¬£¬¹¥»÷ÕßÅúÆÀÁËauDAµÄ»ØÓ¦£¬£¬£¬£¬£¬²¢Íþв"½«ÏúÊÛÓà¶î³¬¹ý4000ÃÀÔªµÄÒøÐÐÕË»§µÄ½Ó¼ûȨÏÞ"¡£¡£¡£¡£¡£¡£
https://therecord.media/australia-domain-name-admin-denies-data-breach
4¡¢ESETÅû¶ּÔÚÇÔȡȫÇòZimbraÕË»§µÄ´ó¹æÄ£´¹µö»î¶¯
8ÔÂ17ÈÕ£¬£¬£¬£¬£¬ESETÅû¶ÁËÕë¶ÔZimbra Collaborationµç×ÓÓʼþ·þÎñÆ÷µÄ´ó¹æÄ£´¹µö»î¶¯¡£¡£¡£¡£¡£¡£¸Ã»î¶¯ÖÁÉÙ´Ó4ÔÂÆð¾ÍÒ»ÏòÔÚ½øÐУ¬£¬£¬£¬£¬Ö¼ÔÚÇÔȡȫÇòÁìÓòÄÚZimbraÕË»§µÄÍ´´¦¡£¡£¡£¡£¡£¡£±»¹¥»÷µÄÖ¸±êÖØÒªÎ»ÓÚ²¨À¼£¬£¬£¬£¬£¬Æä´ÎÊǶò¹Ï¶à¶ûºÍÒâ´óÀû¡£¡£¡£¡£¡£¡£´¹µöÓʼþ¼ÙÒâZimbraÖÎÀíÔ±£¬£¬£¬£¬£¬Í¨ÖªÓû§¼´½«½øÐÐÓʼþ·þÎñÆ÷¸üУ¬£¬£¬£¬£¬Õ⽫µ¼ÖÂÕÊ»§ÁÙʱͣÓ㬣¬£¬£¬£¬²¢ÒªÇóÊÕ¼þÈË´ò¿ª¸½¼ÓµÄHTMLÎļþÏàʶ¸ü¶àÐÅÏ¢¡£¡£¡£¡£¡£¡£´ò¿ªºóÊÇÒ»¸öαÔìµÄZimbraµÇÂ¼Ò³Ãæ£¬£¬£¬£¬£¬ÓÕʹָ±êÊäÈëÕË»§µÄƾ֤¡£¡£¡£¡£¡£¡£¶øºó£¬£¬£¬£¬£¬Óû§ÊäÈëµÄÐÅÏ¢½«Í¨¹ýHTTPS POSTÒªÇó·¢Ë͵½¹¥»÷ÕߵķþÎñÆ÷¡£¡£¡£¡£¡£¡£
https://www.welivesecurity.com/en/eset-research/mass-spreading-campaign-targeting-zimbra-users/
5¡¢Sysdig·¢ÏÖÕë¶ÔGitLabµÄÍÚ¿óºÍ´úÀí½Ù³Ö»î¶¯LABRAT
SysdigÔÚ8ÔÂ17ÈÕ³ÆÆä·¢ÏÖÁ˱»³ÆÎªLABRATµÄ¼ÓÃÜÇ®±ÒÍÚ¾òºÍ´úÀí½Ù³Ö»î¶¯¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃGitLab·ì϶£¨CVE-2021-22205£©»ñµÃ¶ÔÈÝÆ÷µÄ³õʼ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬»¹ÀûÓÃδ±»¼ì²âµ½µÄ»ùÓÚÊðÃûµÄ¹¤¾ß¡¢¸´ÔÓµÄ¿çÆ½Ì¨¶ñÒâÈí¼þ¡¢Èƹý·À»ðǽµÄC2¹¤¾ßÒÔ¼°»ùÓÚÄں˵ÄrootkitÀ´°µ²ØÆä´æÔÚ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬¹¥»÷ÕßÀÄÓúϷ¨·þÎñTryCloudflareÀ´»ìºÏËûÃǵÄC2¡£¡£¡£¡£¡£¡£¸Ã»î¶¯ÖØÒªÍ¨¹ý´úÀí½Ù³ÖºÍ¼ÓÃÜÇ®±ÒÍÚ¿óÀ´×¬È¡ÊÕÈë¡£¡£¡£¡£¡£¡£
https://sysdig.com/blog/labrat-cryptojacking-proxyjacking-campaign/
6¡¢Rapid7°ä²¼¹ØÓÚ2023ÄêÄêÖÐÍþÐ²Ì¬ÊÆµÄ»ØÊ׻㱨
8ÔÂ17ÈÕ£¬£¬£¬£¬£¬Rapid7°ä²¼ÁË2023ÄêÄêÖÐÍþÐ²Ì¬ÊÆµÄ»ØÊ׻㱨¡£¡£¡£¡£¡£¡£2023ÄêÉϰëÄ꣬£¬£¬£¬£¬×êÑÐÍŶӸú×ÙÁË1500¶àÆðÀÕË÷¹¥»÷ÊÂÎñ£¬£¬£¬£¬£¬ÕâЩ¹¥»÷´ó²¿ÃÅÊÇÓÉLockBit(35.3%)¡¢ALPHV/BlackCat(14.2%)ºÍClop(11.9%)Ö´Ðеġ£¡£¡£¡£¡£¡£×î³£¼ûµÄ³õʼ½Ó¼û¼¼ÊõÊÇÔ¶³Ì½Ó¼û£¬£¬£¬£¬£¬Õ¼±È39%£¬£¬£¬£¬£¬Æä´ÎÊÇ·ì϶ÀûÓã¨27%£©¡£¡£¡£¡£¡£¡£40%µÄÊÂÎñÊÇÓÉÓÚMFAȱʧ»òÖ´Ðв»Ò»Öµ¼Öµģ¬£¬£¬£¬£¬ÓÈÆäÊÇÔÚVPN¡¢VDIºÍSaaS²úÆ·ÉÏ¡£¡£¡£¡£¡£¡£79Æð¹¥»÷¹éÒòÓÚÓë¹ú¶ÈÓйصĹ¥»÷Õߣ¬£¬£¬£¬£¬ÆäÖÐÔ¼ËÄ·ÖÖ®Ò»(24%)ÀûÓÃÁËÃæÏò¹«¼ÒµÄÀûÓ÷¨Ê½µÄ·ì϶¡£¡£¡£¡£¡£¡£
https://www.rapid7.com/blog/post/2023/08/17/rapid7s-mid-year-threat-review/


¾©¹«Íø°²±¸11010802024551ºÅ