ownCloudÖзì϶CVE-2023-49103Òѱ»´ó¹æÄ£ÀûÓÃ

°ä²¼¹¦·ò 2023-11-30

1¡¢ownCloudÖзì϶CVE-2023-49103Òѱ»´ó¹æÄ£ÀûÓÃ


¾ÝýÌå11ÔÂ28ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬ownCloudÖеķì϶£¨CVE-2023-49103£©Òѱ»´ó¹æÄ£ÀûÓᣡ£¡£ ¡£¡£¡£¡£¸Ã·ì϶µÄCVSSÆÀ·ÖΪ10£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´ÇÔÈ¡ÖÎÀíÔ±ÃÜÂë¡¢Óʼþ·þÎñÆ÷Í´´¦ºÍÐí¿ÉÖ¤ÃÜÔ¿µÈ£¬£¬£¬£¬£¬£¬ÒÑÓÚ11ÔÂ21ÈÕ±»½¨¸´¡£¡£¡£ ¡£¡£¡£¡£°²È«¹«Ë¾Greynoise³Æ£¬£¬£¬£¬£¬£¬Ëü¹Û²ìµ½´Ó11ÔÂ25ÈÕÆðÍ·£¬£¬£¬£¬£¬£¬¸Ã·ì϶¾ÍÔÚÒ°±í±»´ó¹æÄ£ÀûÓ㬣¬£¬£¬£¬£¬ÇÒ³ÊÉÏÉýÇ÷Ïò¡£¡£¡£ ¡£¡£¡£¡£Greynoise×·×Ùµ½12¸öΨһµÄIPµØÖ·ÀûÓÃÁËCVE-2023-49103¡£¡£¡£ ¡£¡£¡£¡£Shadowserver³ÆÆäĿǰ¼ì²âµ½³¬¹ý11000¸ö¶³öÊ·ý£¬£¬£¬£¬£¬£¬ÆäÖдóÎÞÊýλÓڵ¹ú¡¢ÃÀ¹ú¡¢·¨¹úºÍ¶íÂÞ˹¡£¡£¡£ ¡£¡£¡£¡£ÓÉÓÚÀûÓÃÇé¿öÔ½À´Ô½¶à£¬£¬£¬£¬£¬£¬½¨ÒéÖÎÀíÔ±Á¢¼´½¨¸´¸Ã·ì϶¡£¡£¡£ ¡£¡£¡£¡£


https://securityaffairs.com/154928/hacking/owncloud-cve-2023-49103-actively-exploited.html


2¡¢Zeroed-In±»¹¥»÷µ¼ÖÂDollar Tree½ü200ÍòÈËÊý¾Ýй¶


¾Ý11ÔÂ29ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬ÕÛ¿ÛÁãÊÛ¹«Ë¾Dollar TreeÊܵ½µÚÈý·½·þÎñÌṩÉÌZeroed-In TechnologiesµÄÓ°Ï죬£¬£¬£¬£¬£¬1977486È˵ÄÐÅϢй¶¡£¡£¡£ ¡£¡£¡£¡£Dollar TreeÔÚÃÀ¹úºÍ¼ÓÄôóµÄ23000¸öµØÖ·¾­ÓªDollar TreeºÍFamily DollarÉ̵ê¡£¡£¡£ ¡£¡£¡£¡£Õë¶ÔZeroed-InµÄ¹¥»÷²úÉúÓÚ8ÔÂ7ÈÕÖÁ8ÈÕ£¬£¬£¬£¬£¬£¬¹¥»÷Õ߳ɹ¦ÇÔÈ¡ÁËDollar TreeÔ±¹¤µÄÐÕÃû¡¢µ®ÉúÈÕÆÚºÍÉç»á°²È«ºÅÂë(SSN)¡£¡£¡£ ¡£¡£¡£¡£Zeroed-In½«ÎªÊÜÓ°ÏìÓ×ÎÒÌṩ12¸öÔµÄÉí·Ý±£»£»£»£»£»¤ºÍÐÅÓþ¼à¿Ø·þÎñ¡£¡£¡£ ¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬Zeroed-InµÄÆäËü¿Í»§Ò²¿ÉÄÜÊܵ½¸ÃÊÂÎñµÄÓ°Ï죬£¬£¬£¬£¬£¬µ«ÕâÒ»µãÉÐδµÃµ½Ö¤Êµ¡£¡£¡£ ¡£¡£¡£¡£

https://www.bleepingcomputer.com/news/security/dollar-tree-hit-by-third-party-data-breach-impacting-2-million-people/


3¡¢QilinÍÅ»ïÐû³Æ¶ÔÆû³µÁã¼þ¹©¸øÉÌYanfengµÄ¹¥»÷ÕÆ¹Ü


11ÔÂ28ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïQilinÐû³Æ¶ÔÈ«Çò×î´óÆû³µÁ㲿¼þ¹©¸øÉÌÖ®Ò»YanfengµÄ¹¥»÷ÕÆ¹Ü¡£¡£¡£ ¡£¡£¡£¡£Óб¨Â·³Æ£¬£¬£¬£¬£¬£¬±¾ÔÂÔçЩʱ³½£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Ôâµ½¹¥»÷²¨¼°µ½ÁËStellantis£¬£¬£¬£¬£¬£¬ÆÈʹÆä±±ÃÀ¹¤³§Í£²ú¡£¡£¡£ ¡£¡£¡£¡£11ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬Qilin£¨ÓÖ³ÆAgenda£©Ðû³Æ¹¥»÷ÁËYanfeng£¬£¬£¬£¬£¬£¬²¢°ä²¼Á˶à¸öÑù±¾£¬£¬£¬£¬£¬£¬Éæ¼°²ÆÕþÎļþ¡¢±£ÃܺÍ̸¡¢±¨¼ÛÎļþ¡¢¼¼·¨Êõ¾Ý±íºÍÄÚ²¿»ã±¨µÈ¡£¡£¡£ ¡£¡£¡£¡£QilinÍþвҪÔÚ½«À´¼¸ÌìÄÚ°ä²¼Æä°ÑÎÕµÄËùº±¼û¾Ý£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐÉ趨¾ßÌåµÄ½ØÖ¹ÈÕÆÚ¡£¡£¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/qilin-ransomware-claims-attack-on-automotive-giant-yanfeng/


4¡¢±±µÂ¿ËÈøË¹ÖÝË®Îñ¾ÖNTMWDÔâµ½DaixinµÄÀÕË÷¹¥»÷


ýÌå11ÔÂ28Èճƣ¬£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïDaixin½«±±µÂ¿ËÈøË¹ÊÐÕþË®Çø(NTMWD)Ôö³¤µ½ÆäÐ¹Â¶ÍøÕ¾¡£¡£¡£ ¡£¡£¡£¡£NTMWDÊÇÒ»¸öµ±¾Ö»ú¹¹£¬£¬£¬£¬£¬£¬Îª¸ÃÖݳ¬¹ý13¸ö³ÇÊеÄ200ÍòÈËÌṩ·þÎñ¡£¡£¡£ ¡£¡£¡£¡£NTMWD³ÆÆäÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬´ó²¿ÃÅÒµÎñÒѾ­¸´Ô­¡£¡£¡£ ¡£¡£¡£¡£Ëü»¹³ÆÖ÷Ì⹩ˮ¡¢·ÏË®´¦Öú͹ÌÌå·ÏÁÏ´¦Ö÷þÎñ²¢Î´Êܵ½Ó°Ï죬£¬£¬£¬£¬£¬µ«µç»°ÏµÍ³Êܵ½Ó°Ïì¡£¡£¡£ ¡£¡£¡£¡£ÀÕË÷ÍÅ»ïÐû³ÆÇÔÈ¡ÁË33844¸öÎļþ£¬£¬£¬£¬£¬£¬Ô̺¬¶­Ê»á»áÒé¼Í¼¡¢ÄÚ²¿ÏîÄ¿Îĵµ¡¢ÈËÔ±¾ßÌåÐÅÏ¢ºÍÉó¼Æ»ã±¨µÈ¡£¡£¡£ ¡£¡£¡£¡£


https://therecord.media/north-texas-water-utility-cyberattack


5¡¢ÀÕË÷Èí¼þDJVUµÄбäÌåXaro¼Ù×°³ÉÆÆ½âÈí¼þÀ´´«²¼


11ÔÂ29ÈÕýÌ峯£¬£¬£¬£¬£¬£¬Cybereason·¢ÏÖÀÕË÷Èí¼þDJVUµÄбäÌåXaroÔÚ¼Ù×°³ÉÆÆ½âÈí¼þÀ´´«²¼¡£¡£¡£ ¡£¡£¡£¡£DJVU×ÔÉíÊÇÀÕË÷Èí¼þSTOPµÄ±äÖÖ£¬£¬£¬£¬£¬£¬Ð±äÌåΪÊÜÓ°ÏìÎļþÔö³¤ÁË.xaroÀ©´óÃû£¬£¬£¬£¬£¬£¬Òò¶ø±»¶¨ÃûΪXaro¡£¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬Xaro»¹ÓëÆäËü¸÷Àà¶ñÒâÎļþһ··Ö·¢£¬£¬£¬£¬£¬£¬ÕâÅú×¢¹¥»÷ÕßѡȡÁË"shotgun"·½Ê½¡£¡£¡£ ¡£¡£¡£¡£ÆäËü¶ñÒâÈí¼þÔ̺¬¸÷ÀàÐÅÏ¢ÇÔÈ¡·¨Ê½¡¢¼ÓÔØ·¨Ê½ºÍÏÂÔØ·¨Ê½£¬£¬£¬£¬£¬£¬ÕâÅú×¢³ýÁËÖ´ÐÐÀÕË÷¹¥»÷±í£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ»¹¶ÔË«³ÁÀÕË÷ºÍ½øÒ»²½ÈëÇÖÖ¸±êÍÆËã»ú¸ÐÐËÖ¡£¡£¡£ ¡£¡£¡£¡£


https://thehackernews.com/2023/11/djvu-ransomwares-latest-variant-xaro.html


6¡¢×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓÃÐÂBLUFFS¹¥»÷½Ù³ÖÀ¶ÑÀÏνÓ


ýÌå11ÔÂ28ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬Eurecom×êÑÐÈËÔ±¿ª·¢ÁË6ÖÖÐµĹ¥»÷·½Ê½£¬£¬£¬£¬£¬£¬Í³³ÆÎª¡°BLUFFS¡±¡£¡£¡£ ¡£¡£¡£¡£ËüÃÇÄܹ»ÆÆ»Â·¶ÑÀ»á»°µÄ»úÃÜÐÔ£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÉ豸¼ÙÒâºÍÖÐÑëÈË£¨MitM£©¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷ͨ¹ýÀûÓûỰÃÜÔ¿ÍÆµ¼¹ý³ÌÖеÄ4¸ö·ì϶£¨ÆäÖÐÁ½¸öÊÇзì϶£©À´ÊµÏֵ쬣¬£¬£¬£¬£¬·ì϶»áÇ¿ÔìÍÆµ¼³öÒ»¸ö¼ò¶Ì¡¢ÓÄ΢ÇÒ¿ÉÔ¤²âµÄ»á»°ÃÜÔ¿£¨SKC£©¡£¡£¡£ ¡£¡£¡£¡£½ÓÏÂÀ´£¬£¬£¬£¬£¬£¬¹¥»÷Õß¶ÔÃÜÔ¿½øÐб©Á¦ÆÆ½â£¬£¬£¬£¬£¬£¬´Ó¶ø½âÃÜ´ÓǰµÄͨѶ£¬£¬£¬£¬£¬£¬²¢½âÃÜ»ò½ÚÔ콫À´µÄͨѶ¡£¡£¡£ ¡£¡£¡£¡£ÕâЩÎÊÌâ±»×·×ÙΪCVE-2023-24023½øÐиú×Ù£¬£¬£¬£¬£¬£¬Ó°ÏìÁËÀ¶ÑÀÖ÷Ìâ¹æ·¶4.2ÖÁ5.4¡£¡£¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-bluffs-attack-lets-attackers-hijack-bluetooth-connections/