Google½ô¼±¸üÐÂÐÞ¸´½ñÄêµÚ¶þ¸öÒѱ»ÀûÓõÄChrome©¶´

Ðû²¼Ê±¼ä 2023-04-20

1¡¢Google½ô¼±¸üÐÂÐÞ¸´½ñÄêµÚ¶þ¸öÒѱ»ÀûÓõÄChrome©¶´


4ÔÂ18ÈÕ£¬GoogleÐû²¼Chrome½ô¼±¸üУ¬ÐÞ¸´ÁË2023ÄêµÚ¶þ¸öÒѱ»ÀûÓé¶´¡£ÕâÊÇ¿ªÔ´2DͼÐοâSkiaÖеÄÕûÊýÒç³ö©¶´£¨CVE-2023-2136£©£¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´£¬Í¨¹ý¶ñÒâµÄHTMLÒ³ÃæÖ´ÐÐɳÏäÌÓÒÝ¡£GoogleÉÐδÐû²¼¹ØÓڸé¶´µÄϸ½Ú¡£´Ë´Î¸üл¹ÐÞ¸´ÁËService Worker APIÖеÄÄÚ´æÔ½½ç·ÃÎÊ©¶´£¨CVE-2023-2133ºÍCVE-2023-2134£©ÒÔ¼°DevToolsÖеÄÊͷźóʹÓé¶´£¨CVE-2023-2135£©µÈ¡£ÉÏÖÜ£¬GoogleÐÞ¸´ÁË2023ÄêµÚÒ»¸ö±»ÀûÓõÄChrome©¶´£¨CVE-2023-2033£©¡£


https://securityaffairs.com/145019/security/google-second-chrome-zero-day-2023.html


2¡¢APT28ÀûÓÃCisco·ÓÉÆ÷ÖеÄ©¶´°²×°Jaguar Tooth


¾ÝýÌå4ÔÂ18ÈÕ±¨µÀ£¬Ó¢ÃÀÕþ¸®Ðû²¼ÁªºÏ×Éѯ£¬Ïêϸ½éÉÜÁËAPT28ÈçºÎÀûÓÃCisco IOS·ÓÉÆ÷ÉϵÄ©¶´°²×°×Ô½ç˵¶ñÒâÈí¼þJaguar Tooth¡£¸Ã¶ñÒâÈí¼þÖ÷ÒªÕë¶ÔÔËÐй̼þC5350-ISM°æ±¾12.3(6)µÄCisco IOS·ÓÉÆ÷¡£Ëü¿ÉÊÕ¼¯É豸ÐÅÏ¢£¬È»ºóͨ¹ýTFTP´«ÊäÕâЩÐÅÏ¢£¬²¢ÆôÓÃδ¾­Éí·ÝÑéÖ¤µÄºóÃÅ·ÃÎÊ¡£¾ÝÊӲ죬ËüÊÇÀûÓÃÒÑÐÞ¸´µÄSNMP©¶´£¨CVE-2017-6742£©½øÐа²×°ºÍÖ´Ðеġ£Ñо¿ÈËÔ±½¨Òé¹ÜÀíÔ±½«Â·ÓÉÆ÷Éý¼¶µ½×îеĹ̼þ°æ±¾ÒÔµÍÓÚ´ËÀ๥»÷¡£


https://www.bleepingcomputer.com/news/security/us-uk-warn-of-govt-hackers-using-custom-malware-on-cisco-routers/


3¡¢Î¢Èí·¢ÏÖMint Sandstorm¹¥»÷ÃÀ¹úµÄÒªº¦»ù´¡ÉèÊ©


4ÔÂ18ÈÕ£¬Î¢Èí³ÆÆä·¢ÏÖÁËMint SandstormµÄÒ»¸ö×Ó×éÕë¶ÔÃÀ¹úµÄ¹¥»÷»î¶¯¡£´Ó2021ÄêÄ©µ½2022ÄêÖУ¬¸ÃÍÅ»ï´ÓÕì²ìתÏòÖ±½Ó¹¥»÷ÃÀ¹úµÄÒªº¦»ù´¡ÉèÊ©£¬°üÂÞº£¸Û¡¢ÄÜÔ´¹«Ë¾¡¢ÔËÊäϵͳ¡¢¹«ÓÃÊÂÒµºÍÌìÈ»Æø×éÖ¯µÈ¡£Ëüͨ³£Ê¹ÓùûÈ»Åû¶µÄPoC£¬Ò²»áʹÓþÉ©¶´£¨ÀýÈçLog4Shell£©À´¹¥»÷δ´ò²¹¶¡µÄÉ豸¡£Ö®ºó£¬Í¨¹ýImpacket¿ò¼ÜºáÏòÁ÷´«£¬²¢Ö´ÐÐÁ½Ìõ¹¥»÷Á´Ö®Ò»¡£µÚÒ»Ìõ»áÇÔÈ¡Windows Active DirectoryÊý¾Ý¿â£¬µÚ¶þÌõ°²×°ÃûΪDrokbkºÍSoldierµÄ×Ô½ç˵ºóÃÅ¡£


https://www.microsoft.com/en-us/security/blog/2023/04/18/nation-state-threat-actor-mint-sandstorm-refines-tradecraft-to-attack-high-value-targets/


4¡¢Group-IBÅû¶MuddyWaterÀûÓÃSimpleHelpµÄ»î¶¯ 


Group-IBÔÚ4ÔÂ18ÈÕÅû¶ÁËMuddyWaterʹÓúϷ¨µÄÔ¶³ÌÉ豸¿ØÖƺ͹ÜÀí¹¤¾ßSimpleHelp±£³Ö³Ö¾ÃÐÔ¡£SimpleHelp²¢Ã»Óб»¹¥»÷£¬Ïà·´£¬¹¥»÷ÕßÕÒµ½ÁË´Ó¹ÙÍøÏÂÔØ¸Ã¹¤¾ß²¢ÔÚ¹¥»÷ÖÐʹÓÃËüµÄÒªÁì¡£¸ÃÍÅ»ïÓÚ2022Äê6ÔÂ30ÈÕÊ×´ÎʹÓÃSimpleHelp£¬½ØÖÁĿǰ£¬¸Ã×éÖ¯ÖÁÉÙÓаĘ̈·þÎñÆ÷°²×°ÁËSimpleHelp¡£°²×°ÔÚÄ¿±êÉè±¹ØÁ¬ÄSimpleHelp¿Í»§¶Ë¿ÉÒÔ×÷Ϊϵͳ·þÎñÁ¬ÐøÔËÐУ¬Òò´Ë¹¥»÷ÕßÄܹ»ËæÊ±·ÃÎÊÓû§µÄÉ豸£¬°üÂÞÔÚÖØÆôºó¡£³õÊ¼Ñ¬È¾ÔØÌåĿǰδ֪£¬Ñо¿ÈËÔ±»³ÒÉÊǵöÓã¹¥»÷¡£


https://www.group-ib.com/blog/muddywater-infrastructure/


5¡¢·¿²úÖнéOrangeTee&TieÒòй¶25ÍòÈËÊý¾Ý±»·£¿î


¾Ý4ÔÂ18ÈÕ±¨µÀ£¬ÐÂ¼ÓÆÂ·¿µØ²ú¹«Ë¾OrangeTee & TieÒòй¶Áè¼Ý25Íò¿Í»§ºÍÔ±¹¤µÄÐÅÏ¢£¬±»Òþ˽¼à¹Ü»ú¹¹·£¿î37000ÐÂÔª¡£2021Äê8ÔÂ3ÈÕ£¬¸Ã¹«Ë¾ÊÕµ½ÁËALTDOSµÄÀÕË÷Óʼþ£¬ÒªÇó10¸ö±ÈÌØ±Ò×÷ΪÊê½ð¡£ÀÕË÷ÍÅ»ïûÓÐÊÕµ½Êê½ð£¬Òò¶øÖ´ÐÐDDoS¹¥»÷µ¼ÖÂOrangeTee & TieµÄÍøÂç̱»¾¡£¸Ã·¿²ú¹«Ë¾È¡Ö¤·¢ÏÖALTDOS·ÃÎÊÁË11¸öÊý¾Ý¿â£¬Éæ¼°256583¸ö¿Í»§ºÍÔ±¹¤µÄÐÅÏ¢¡£ÔÚ4ÔÂ17ÈÕÐû²¼µÄÊéÃæÅоöÖУ¬PDPC³ÆÒòOrangeTee & TieµÄ¼¸¸öʧÎóµ¼ÖÂÁËÊý¾Ýй¶¡£


https://www.channelnewsasia.com/singapore/orangetee-real-estate-personal-data-breach-pdpa-customers-employees-3425291


6¡¢CheckPointÐû²¼¹ØÓÚRaspberry RobinµÄ·ÖÎö³ÂËß


4ÔÂ18ÈÕ£¬Check PointÐû²¼Á˹ØÓÚRaspberry RobinµÄ·ÖÎö³ÂËß¡£Raspberry RobinʹÓÃÁ˺ܶàÈÆ¹ý¼ì²âµÄÒªÁ죬°üÂÞ¼ì²éPEB£¨½ø³Ì»·¾³¿é£©¡¢Óû§ÃûºÍ¼ÆËã»úÃû¡¢MacµØÖ·¡¢CPUID¡¢»î¶¯CPUÊýÁ¿¡¢ÄÚ´æÒ³¡¢MulDivºÍ¹Ì¼þ±íµÈ¡£´ËÍ⣬ËüÀûÓúܶàÒªÁìÀ´ÖÆÖ¹±»Äþ¾²½â¾ö·½°¸¼ì²âµ½£¬ÀýÈçÈ¥³ýIFEOºÍWindows DefenderÅųýÁбíµÈ¡£Raspberry Robin»¹ÀûÓÃÁËÁ½¸öEoP©¶´£¨CVE-2020-1054ºÍCVE-2021-1732£©½øÐÐÌáȨ¡£


https://research.checkpoint.com/2023/raspberry-robin-anti-evasion-how-to-exploit-analysis/