΢ÈíÐû²¼6Ô·ݵÄÄþ¾²¸üУ¬×ܼÆÐÞ¸´78¸ö©¶´
Ðû²¼Ê±¼ä 2023-06-141¡¢Î¢ÈíÐû²¼6Ô·ݵÄÄþ¾²¸üУ¬×ܼÆÐÞ¸´78¸ö©¶´
¾Ý6ÔÂ13ÈÕ±¨µÀ£¬Î¢ÈíÐû²¼ÁË2023Äê6ÔµÄÖܶþ²¹¶¡£¬ÐÞ¸´ÁË78¸ö©¶´£¬ÆäÖаüÂÞ38¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£´Ë´ÎÐÞ¸´µÄ½ÏΪÑÏÖØµÄ©¶´ÎªWindows Pragmatic General Multicast(PGM)ÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2023-29363¡¢CVE-2023-32014ºÍCVE-2023-32015£©ÒÔ¼°Microsoft SharePoint ServerÖеÄȨÏÞÌáÉý©¶´£¨CVE-2023-29357£©µÈ¡£´Ë´Î¸üв»°üÂÞÁãÈÕ©¶´»òÒѱ»ÀûÓõÄ©¶´¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2023-patch-tuesday-fixes-78-flaws-38-rce-bugs/
2¡¢ÈðÊ¿Áª°î¹ÜÀí¾ÖÔâµ½DDoS¹¥»÷¶à¸öÍøÕ¾ºÍÓ¦Óò»ÐÐÓÃ
ÈðÊ¿Áª°î¹ÜÀí¾ÖÔÚ6ÔÂ12ÈÕ͸¶£¬ÓÉÓÚϵͳÔâµ½DDoS¹¥»÷£¬Æä¶à¸öÍøÕ¾¼°ÔÚÏß·þÎñ²»ÐзÃÎÊ¡£Óë¶íÂÞ˹Ïà¹ØµÄºÚ¿ÍÍÅ»ïNoNameÉù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦£¬Ëü×Ô2022Äê³õÒÔÀ´Ò»Ö±Õë¶ÔÅ·ÖÞ¡¢ÎÚ¿ËÀ¼ºÍ±±ÃÀµÄ¹ú¼ÒºÍ×éÖ¯£¬ÔÚÉÏÖÜ»¹¹¥»÷ÁËparlament.ch¡£¸Ã»ú¹¹³Æ£¬Ñо¿ÈËÔ±ºÜ¿ì¾Í×¢Òâµ½Á˴˴ι¥»÷£¬²¢ÔÚ½ÓÄÉ´ëÊ©¾¡¿ì»Ö¸´ÍøÕ¾ºÍÓ¦ÓõĿÉÓÃÐÔ¡£6ÔÂ1ÈÕ£¬ÀÕË÷ÍÅ»ïPlayÔø¹ûÈ»ÁË´ÓÈðÊ¿¾üÕþ×éÖ¯µÄ¼¼ÊõÌṩÉÌXplainÇÔÈ¡µÄÐÅÏ¢¡£
https://www.admin.ch/gov/en/start/documentation/media-releases.msg-id-95641.html
3¡¢HIBPÅû¶ӰÏìÔ¼890ÍòÓû§µÄZacksÊý¾Ýй¶Ê¼þ
¾ÝýÌå6ÔÂ12ÈÕ±¨µÀ£¬Êý¾Ýй¶֪ͨ·þÎñHave I Been Pwned(HIBP)Åû¶ÁËÒ»Æð½ÏÔçµÄZacksÊý¾Ýй¶Ê¼þ¡£HIBPÊÕµ½ÁËÒ»¸ö°üÂÞ8929503ÌõÓû§¼Ç¼µÄÊý¾Ý¿â£¬ÆäÖаüÂÞÐÕÃû¡¢ÓʼþµØÖ·¡¢Óû§ÃûºÍSHA256ÃÜÂëµÈÐÅÏ¢£¬Êý¾Ý¿âÖÐ×îмǼµÄÈÕÆÚΪ2020Äê5Ô¡£¸Ã·þÎñ֪ͨÁËZecks£¬ºóÕ߳ƹ¥»÷ÕßÖ»ÄÜ·ÃÎʼÓÃܵÄÃÜÂëÀ´µ»¯´Ë´ÎÄþ¾²Ê¼þ¡£ÔÚHIBPÅû¶¸Ãʼþºó²»¾Ã£¬ZacksÊý¾Ý¿âÓÚ6ÔÂ10ÈÕ±»Ðû²¼ÔÚºÚ¿ÍÂÛ̳ExposedÉÏ¡£
https://www.bleepingcomputer.com/news/security/have-i-been-pwned-warns-of-new-zacks-data-breach-impacting-8-million/
4¡¢Ó¢¹úͨÐżà¹Ü»ú¹¹OfcomÔâµ½¹¥»÷²¿ÃÅ»úÃÜÐÅϢй¶
ýÌå6ÔÂ12Èճƣ¬Ó¢¹úͨÐżà¹Ü»ú¹¹OfcomÔâµ½ÁËÁËÀÕË÷ÍÅ»ïClopµÄ¹¥»÷¡£¹¥»÷ÕßÀûÓÃÁËMOVEitÎļþ´«ÊäÖеÄ©¶´(CVE-2023-34362)À´·ÃÎʸûú¹¹µÄ»ù´¡ÉèÊ©¡£·¢ÑÔÈË͸¶£¬¹¥»÷Õ߿ɷÃÎʼà¹Ü»ú¹¹³ÖÓÐµÄÆä¼à¹ÜµÄ¹«Ë¾µÄ»úÃÜÐÅÏ¢£¬ÒÔ¼°²¿ÃÅOfcomÔ±¹¤µÄ¸öÈËÐÅÏ¢¡£ClopÓÚÉÏÖÜÈýÐû²¼ÁËÒ»·ÝÀÕË÷˵Ã÷£¬Éù³ÆÕÆÎÕÁËÊý°Ù¼ÒÆóÒµµÄÐÅÏ¢£¬²¢ÒªÇóÕâЩ×éÖ¯Ö÷¶¯ÁªÏµÆäÀ´ÐÉÌÊê½ð£¬·ñÔòÕâЩ×éÖ¯½«ÓÚ6ÔÂ14ÈÕ±»Áгö¡£
https://therecord.media/ofcom-cyberattack-uk-regulator-moveit-vulnerability
5¡¢KasperskyÐû²¼¶à½×¶Î¼ÓÔØ·¨Ê½DoubleFingerµÄ³ÂËß
6ÔÂ12ÈÕ£¬KasperskyÐû²¼Á˹ØÓÚÀûÓÃÐÂÐͶà½×¶Î¼ÓÔØ·¨Ê½DoubleFinger¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£¹¥»÷ʼÓÚespexe.exeµÄÐ޸İ汾£¬¿É´ÓͼÏñÍйܷþÎñImgur¼ìË÷αװ³ÉPNGµÄ¼ÓÃܵÄpayload¡£¸Ãpayload»á´¥·¢Ò»¸ö°üÂÞËĸö½×¶ÎµÄ¹¥»÷Á´£¬×îÖÕ»áÔÚÄ¿±êÖ÷»úÉÏÖ´ÐÐGreetingGhoul¡£GreetingGhoulÊÇÒ»¸öÇÔÈ¡·¨Ê½£¬Ö¼ÔÚÇÔÈ¡Óë¼ÓÃÜ»õ±ÒÏà¹ØµÄƾ¾Ý¡£´Ë´Î¹¥»÷»î¶¯Ö÷ÒªÕë¶ÔÅ·ÖÞ¡¢ÃÀ¹úºÍÀ¶¡ÃÀÖÞ¡£
https://securelist.com/doublefinger-loader-delivering-greetingghoul-cryptocurrency-stealer/109982/
6¡¢Åµ»ùÑÇÐû²¼¹ØÓÚ2023ÄêÈ«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß
6ÔÂ9ÈÕ±¨µÀ³Æ£¬Åµ»ùÑÇÐû²¼Á˹ØÓÚ2023ÄêÈ«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£¸Ã³ÂËßÉîÈë·ÖÎöÁË4GºÍ5GÄþ¾²¹¥»÷¡¢¶ñÒâÈí¼þ¹¥»÷¡¢DDoS¹¥»÷ÒÔ¼°Õë¶ÔÈ«ÇòÀι̺ÍÒÆ¶¯ÍøÂçµÄÆäËüÐÎʽµçÐÅÍøÂç¹¥»÷µÄÇ÷ÊÆ¡£³ÂËßÖ¸³ö£¬»ùÓÚ½©Ê¬ÍøÂçµÄDDoS¹¥»÷Éý¼¶£¬Ê¹Óõı»Ñ¬È¾ÎïÁªÍøÉ豸ÊýÁ¿´Ó200000¼¤ÔöÖÁÔ¼100Íò£¬Ä¿Ç°Õ¼ËùÓÐDDoSÁ÷Á¿µÄ40%ÒÔÉÏ¡£ÒÔÒÆ¶¯Éè±¹ØÁ¬ÄÒøÐÐÐÅϢΪĿ±êµÄľÂíÊýÁ¿·ÁËÒ»·¬£¬Ä¿Ç°Õ¼ËùÓÐѬȾµÄ9%¡£¼ÒÍ¥ÍøÂçÖеĶñÒâÈí¼þѬȾÓÐËùϽµ£¬´ÓCovid-19ÆÚ¼äµÄ3%Ͻµµ½1.5%¡£
https://www.nokia.com/networks/security-portfolio/threat-intelligence-report/