·áÌïÆû³µ³¤´ïÊ®ÄêµÄÊý¾Ýй¶Ê¼þÓ°ÏìÔ¼215Íò¿Í»§

Ðû²¼Ê±¼ä 2023-05-15

1¡¢·áÌïÆû³µ³¤´ïÊ®ÄêµÄÊý¾Ýй¶Ê¼þÓ°ÏìÔ¼215Íò¿Í»§


¾ÝýÌå5ÔÂ12ÈÕ±¨µÀ£¬·áÌïÆû³µÅû¶ÁËÆäÔÆ»·¾³´Ó2013Äê11ÔÂ6ÈÕµ½2023Äê4ÔÂ17ÈÕµÄÊý¾Ýй¶Ê¼þ£¬Ì»Â¶ÁËÔ¼2150000Ãû¿Í»§µÄÆû³µÎ»ÖÃÐÅÏ¢¡£¸ÃʼþÊÇÓÉÓÚÊý¾Ý¿âÅäÖôíÎóµ¼ÖÂÈκÎÈËÎÞÐèÃÜÂë¼´¿É·ÃÎÊÆäÄÚÈÝ¡£Ð¹Â¶ÁË2012Äê1ÔÂ2ÈÕÖÁ2023Äê4ÔÂ17ÈÕÆÚ¼äʹÓøù«Ë¾T-Connect G-Link¡¢G-Link Lite»òG-BOOK·þÎñµÄ¿Í»§ÐÅÏ¢£¬Éæ¼°³µÁ¾Ê¶±ðºÅ¡¢³µÁ¾Î»ÖüǼºÍÐгµ¼Ç¼ÒÇÊÓƵµÈ¡£


https://www.infosecurity-magazine.com/news/toyota-admits-decade-long-data-leak/


2¡¢DiscordµÚÈý·½Ö§³ÖÊðÀíÔâµ½¹¥»÷µ¼Ö²¿ÃÅÐÅϢй¶


ýÌå5ÔÂ12Èճƣ¬DiscordÕýÔÚ֪ͨÊÜÓ°ÏìÓû§¹ØÓÚµÚÈý·½Ö§³ÖÊðÀíµÄÕÊ»§Ôâµ½ÈëÇÖµ¼ÖµÄÊý¾Ýй¶Ê¼þ¡£Discord͸¶£¬ÓÉÓÚʼþµÄÐÔÖÊ£¬Óû§ÓʼþµØÖ·¡¢¿Í»§·þÎñÏûÏ¢µÄÄÚÈÝÒÔ¼°ÓëDiscordÖ®¼ä·¢Ë͵ÄÈκθ½¼þ¿ÉÄÜÒѾ­Ð¹Â¶¡£ÎªÓ¦¶ÔÕâһʼþ£¬¸Ã¹«Ë¾Á¢¼´½ûÓÃÁ˱»ÈëÇÖµÄÕË»§£¬²¢¶ÔÊÜÓ°ÏìµÄ¼ÆËã»ú½øÐзÖÎö£¬ÒÔÈ·¶¨ËüÊÇ·ñѬȾÁ˶ñÒâÈí¼þ¡£Ä¿Ç°£¬Discord·¢ÑÔÈËûÓлظ´ÖÃÆÀÇëÇó¡£


https://www.bleepingcomputer.com/news/security/discord-discloses-data-breach-after-support-agent-got-hacked/


3¡¢Bl00dyÍÅ»ïÀûÓÃPaperCut RCE©¶´¹¥»÷ÃÀ¹ú½ÌÓýÐÐÒµ


¾Ý5ÔÂ11ÈÕ±¨µÀ£¬ÀÕË÷ÍÅ»ïBl00dy½üÆÚÀûÓÃPaperCut RCE£¨CVE-2023-27350£©¹¥»÷ÃÀ¹úµÄ½ÌÓýÐÐÒµ¡£¹¥»÷ÕßÓÚ4ÔÂÖÐÑ®¾Í¿ªÊ¼ÀûÓø鶴£¬Ä¿Ç°¹¥»÷ÈÔÔÚ½øÐÐÖУ¬Õë¶Ô½ÌÓýÐÐÒµµÄ¹¥»÷ʼÓÚ5Ô³õ¡£½üÆÚÊӲ쵽µÄ»î¶¯ÖУ¬¹¥»÷ÕßÀûÓø鶴ÈƹýÓû§Éí·ÝÑéÖ¤²¢ÒÔ¹ÜÀíÔ±Éí·Ý·ÃÎÊ·þÎñÆ÷¡£Ê¹ÓôËȨÏÞÉú³É¸ßȨÏÞµÄcmd.exeºÍpowershell.exe½ø³Ì£¬»ñµÃÉ豸µÄÔ¶³Ì·ÃÎʲ¢ºáÏòÁ÷´«£¬×îÖջᵼÖÂÊý¾Ýй¶ºÍϵͳ¼ÓÃÜ¡£


https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-131a


4¡¢·¨¹úÂÃÓι«Ë¾La Malle Postaleй¶9ÍòÓû§¸öÈËÐÅÏ¢


5ÔÂ13ÈÕ±¨µÀ³Æ£¬Ñо¿ÍŶӷ¢ÏÖ·¨¹úÂÃÓι«Ë¾La Malle Postaleй¶ÁËÆä¿Í»§µÄ¸öÈËÊý¾Ý¡£1ÔÂ11ÈÕ£¬Cybernews·¢ÏÖÁËÒ»¸ö¿É¹ûÈ»·ÃÎʵÄÊý¾Ý´æ´¢£¬´æ´¢ÁËÁè¼Ý4GBµÄÊý¾Ý£¬°üÂÞ½ü90000¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþºÍµç»°ºÅÂ룬13000¶àÌõ¹«Ë¾Óë¿Í»§Ö®¼äSMSÏûÏ¢£¬70000¸ö¿Í»§Æ¾Ö¤ÒÔ¼°¹«Ë¾µÄÇý¶¯·¨Ê½ºÍ¹ÜÀíԱƾ¾ÝµÈ¡£Ä¿Ç°£¬¸ÃÊý¾ÝÊý¾Ý¿âÓÚ4Ôµױ»±£»¤ÆðÀ´¡£


https://securityaffairs.com/146191/data-breach/personal-info-of-90k-hikers-leaked-by-french-tourism-company-la-malle-postale.html


5¡¢Deep InstinctÅû¶LinuxºóÃÅBPFDoorбäÌåµÄϸ½Ú


5ÔÂ11ÈÕ£¬Deep InstinctÅû¶ÁËLinuxºóÃÅBPFDoorбäÌåµÄϸ½Ú¡£BPFDoorÊÇÒ»ÖÖÒþ±ÎµÄºóÃÅ£¬´Ó2017Ä꿪ʼ»îÔ¾£¬µ«Ö±µ½Ò»ÄêÇ°²ÅÊ״α»·¢ÏÖ¡£¸ÃбäÌå¾ßÓÐÐí¶àÌص㣬°üÂÞʹÓþ²Ì¬¿â¼ÓÃÜ£¬Ê¹Ó÷´ÏòshellͨÐÅ£¬ÒÔ¼°ËùÓÐÃüÁî¾ùÓÉC2·þÎñÆ÷·¢ËÍ¡£Ê×´ÎÖ´ÐÐʱ£¬BPFDoorÔÚ/var/run/initd.lockÖд´½¨²¢Ëø¶¨Ò»¸öÔËÐÐʱÎļþ£¬È»ºó½«×Ô¼ºforkΪһ¸ö×Ó½ø³ÌÔËÐС£BPFDoorÈÔδ±»Äþ¾²Èí¼þ¼ì²âµ½£¬Òò´Ë¹ÜÀíÔ±Ö»ÄÜÒÀ¿¿Ç¿´óµÄÍøÂçÁ÷Á¿ºÍÈÕÖ¾¼à¿Ø¡£


https://www.deepinstinct.com/blog/bpfdoor-malware-evolves-stealthy-sniffing-backdoor-ups-its-game


6¡¢WordPress²å¼þÖЩ¶´CVE-2023-32243Ó°ÏìÉÏ°ÙÍòÍøÕ¾


ýÌå5ÔÂ11ÈÕ±¨µÀ³Æ£¬WordPress²å¼þEssential Addons for ElementorÖЩ¶´¿É±»Ô¶³Ì¹¥»÷ÓÃÀ´»ñµÃÍøÕ¾µÄ¹ÜÀíԱȨÏÞ¡£ÕâÊÇÒ»¸ö°üÂÞ90¸öÀ©Õ¹µÄ¿â£¬±»Áè¼Ý100Íò¸öWordPressÍøվʹÓ᣸鶴¸ú×ÙΪCVE-2023-32243£¬ÊDzå¼þÃÜÂëÖØÖù¦Ð§µÄδ¾­Éí·ÝÑéÖ¤µÄȨÏÞÌáÉý©¶´£¬Ó°Ïì°æ±¾5.4.0ÖÁ5.7.1¡£Ñо¿ÈËÔ±³Æ£¬Í¨¹ýÀûÓø鶴£¬Ö»ÐèÖªµÀÓû§Ãû£¬¾Í¿ÉÒÔÖØÖÃÈκÎÓû§µÄÃÜÂ룬´Ó¶øÖØÖùÜÀíÔ±ÃÜÂë²¢µÇ¼ÕÊ»§¡£Ä¿Ç°£¬ÐÞ¸´·¨Ê½ÒѾ­Ðû²¼£¬½¨ÒéËùÓÐÓû§¾¡¿ìÉý¼¶¡£


https://securityaffairs.com/146119/hacking/essential-addons-for-elementor-flaw.html