ZimbraÐÞ¸´ZCSÖÐÒѱ»ÀûÓõÄXSS©¶´CVE-2023-38750

Ðû²¼Ê±¼ä 2023-08-01

1¡¢ZimbraÐÞ¸´ZCSÖÐÒѱ»ÀûÓõÄXSS©¶´CVE-2023-38750 


¾ÝýÌå7ÔÂ27ÈÕ±¨µÀ £¬ZimbraÐû²¼Äþ¾²¸üР£¬ÐÞ¸´ÁËÕë¶ÔZimbra Collaboration Suite(ZCS)µç×ÓÓʼþ·þÎñÆ÷µÄ¹¥»÷Öб»ÀûÓõÄ©¶´¡£ÕâÊÇÒ»¸öXSS©¶´£¨CVE-2023-38750£© £¬¿ÉÄܱ»ÓÃÀ´ÇÔÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐжñÒâ´úÂë¡£ËäÈ»ZimbraÔÚÊ×´ÎÅû¶¸Ã©¶´²¢¶Ø´ÙÓû§ÊÖ¶¯ÐÞ¸´Ê± £¬²¢Î´±íÃ÷¸Ã©¶´Òѱ»ÀûÓà £¬µ«Google TAG͸¶ £¬¸Ã©¶´ÊÇÔÚÓÐÕë¶ÔÐԵĹ¥»÷Öб»·¢Ïֵġ£´ËÍâ £¬CISAÒ²Ðû²¼ÁËͨ¸æ £¬ÒªÇóÁª°î»ú¹¹ÔÚ8ÔÂ17ÈÕ֮ǰÐÞ¸´¸Ã©¶´¡£


https://www.bleepingcomputer.com/news/security/zimbra-patches-zero-day-vulnerability-exploited-in-xss-attacks/


2¡¢Tempur SealyÔâµ½ÍøÂç¹¥»÷µ¼Ö¹«Ë¾ÔËÓªÔÝʱÖжÏ


¾Ý8ÔÂ1ÈÕ±¨µÀ £¬´²µæÏúÊÛÉÌTempur SealyÔâµ½ÍøÂç¹¥»÷ £¬ÆÈʹ²¿ÃÅϵͳÔÝʱ¹Ø±Õ¡£Tempur Sealy±»ÈÏΪÊÇÈ«Çò×î´óµÄ´²ÉÏÓÃÆ·¹©Ó¦ÉÌ £¬Éϼ¾¶È¾»ÏúÊÛ¶îΪ12ÒÚÃÀÔª¡£¸Ã¹«Ë¾ÔÚ±¾ÖÜһ͸¶ £¬ÓÚ7ÔÂ23ÈÕÔâµ½Á˹¥»÷ £¬Æä½ÓÄÉÏìÓ¦´ëÊ©Ö÷¶¯¹Ø±ÕÁ˲¿ÃÅITϵͳ £¬Õâµ¼Ö¹«Ë¾ÔËÓªÔÝʱÖжÏ¡£Ä¿Ç° £¬¸Ã¹«Ë¾ÒÑ¿ªÊ¼½«²¿ÃÅÖ÷ÒªµÄÏµÍ³ÖØÐÂÉÏÏß²¢»Ö¸´ÔËÓª¡£ÊÓ²ìÈÔÔÚ½øÐÐÖÐ £¬ÒÔÈ·¶¨¶ÔÒµÎñºÍ²ÆÕþ·¢ÉúµÄÓ°Ïì £¬Éв»Çå³þÊÇ·ñÉæ¼°¿Í»§»òÔ±¹¤ÐÅÏ¢ £¬ÒÔ¼°¹¥»÷ÕßµÄÉí·Ý¡£


https://therecord.media/mattress-giant-tempur-sealy-cyberattack


3¡¢²éËþŬ¼ÓÐÄÔàÑо¿Ëùͨ±¨Éæ¼°17ÍòÈ˵ÄÊý¾Ýй¶Ê¼þ


7ÔÂ29ÈÕ±¨µÀ³Æ £¬²éËþŬ¼ÓÐÄÔàÑо¿Ëù£¨Chattanooga Heart Institute £¬CHI£©Í¨±¨ÁËÉæ¼°17ÍòÈ˵ÄÊý¾Ýй¶Ê¼þ¡£5ÔÂ·Ý £¬KarakurtÍÅ»ï³Æ¹¥»÷Á˸ûú¹¹ £¬²¢ÇÔÈ¡ÁË158GBµÄÊý¾Ý¡£¹¥»÷ÕßûÓÐÌṩ֤¾Ý £¬µ«ÌåÏÖй¶Êý¾Ý°üÂÞÒ½ÁƼǼ¡¢¼ì²é½á¹û¡¢Õï¶Ï¡¢Éç»áÄþ¾²ºÅÂë¡¢»¤ÕÕ¡¢ºÍ²ÆÕþÐÅÏ¢µÈ £¬ÆäʱCHI²¢Î´»ØÓ¦´Ëʼþ¡£7ÔÂ28ÈÕ £¬CHI͸¶ÓÐ170450ÈËÊܵ½Êý¾Ýй¶Ê¼þµÄÓ°Ïì¡£ËûÃÇÓÚ4ÔÂ17ÈÕ¼ì²âµ½¹¥»÷¼£Ïó £¬È·¶¨ÏµÍ³ÔÚ3ÔÂ8ÈÕÖÁ16ÈÕÆÚ¼äÔø±»·ÃÎʹý¡£Ö±µ½5ÔÂ31ÈÕ £¬CHI²ÅµÃÖª»¼ÕߵĽ¡¿µÐÅÏ¢ºÍµ£±£ÈËÐÅÏ¢±»Ð¹Â¶¡£


https://www.databreaches.net/the-chattanooga-heart-institute-to-notify-170450-about-march-data-security-incident/


4¡¢ÃÀ¹úSAISÊý¾Ý¿âÅäÖôíÎóй¶572 GBѧÉúºÍ½ÌʦµÄÐÅÏ¢


ýÌå7ÔÂ28ÈÕ±¨µÀ³Æ £¬Ñо¿ÈËÔ±·¢ÏÖÁËÒ»¸öδÊܱ£»¤µÄÊý¾Ý¿â £¬ÆäÖаüÂÞÓë½ÌÓý»ú¹¹Ïà¹ØµÄ682438Ìõ¼Ç¼¡£ÊӲ췢ÏÖ £¬Êý¾Ý¿âÊôÓÚÄÏ·½¶ÀÁ¢Ñ§Ð£Ð­»á(SAIS) £¬ÕâÊÇλÓÚÃÀ¹úµÄÒ»¸ö×ÔÔ¸ÐÔµØÓòÈÏ֤Э»á¡£´Ë´Îй¶µÄÊý¾Ý¹²572.8 GB £¬Ê±¼ä¿ç¶È´Ó2012Äêµ½2023Äê £¬°üÂÞѧÉúºÍ½Ìʦ¼Ç¼¡¢½¡¿µÐÅÏ¢¡¢Éç»áÄþ¾²ºÅÂ롢ǹ»÷°¸ºÍ·âËøÍ¨Öª¡¢Ñ§Ð£µØÍ¼ºÍ²ÆÕþÔ¤ËãµÈ¡£Ä¿Ç° £¬¸ÃÊý¾Ý¿âÒѱ»±£»¤ÆðÀ´¡£


https://www.hackread.com/data-leak-student-faculty-accreditation-org/


5¡¢GoogleÐû²¼¹ØÓÚ2022Äê¶È0day©¶´µÄ»Ø¹Ë³ÂËß


 7ÔÂ27ÈÕ £¬GoogleÐû²¼ÁËÄê¶È0day©¶´³ÂËß £¬ÌṩÁË2022ÄêÒÔÀ´µÄÒ°ÍâÀûÓÃͳ¼ÆÊý¾Ý¡£2022Äê¼ì²â²¢Åû¶ÁË41¸öÔÚÒ°µÄ0day £¬ÆäÖÐÉϰëÄê20¸ö £¬Ï°ëÄê21¸ö £¬½ö´ÎÓÚ2021ÄêµÄ69¸ö©¶´¡£ÔÚAndroidÖÐ £¬´æÔÚ¶àÖÖÇé¿ö £¬Óû§Ôںܳ¤Ò»¶Îʱ¼äÄÚÎÞ·¨»ñµÃ²¹¶¡¡£Òò´Ë¶ÔÓÚ¹¥»÷ÕßÀ´Ëµ £¬NdayµÄ¹¦Ð§ÀàËÆÓÚ0day¡£ÔÚ2022ÄêµÄ41¸ö0dayÖÐ £¬ÓÐ17¸öÊÇ֮ǰ³ÂËߵĩ¶´µÄ±äÌå £¬Õ¼±ÈÁè¼Ý40%¡£


https://security.googleblog.com/2023/07/the-ups-and-downs-of-0-days-year-in.html


6¡¢KasperskyÐû²¼2023ÄêQ2 APT¹¥»÷Ì¬ÊÆµÄ·ÖÎö³ÂËß


7ÔÂ27ÈÕ £¬KasperskyÐû²¼ÁË2023ÄêQ2 APT¹¥»÷Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£±¾¼¾¶ÈµÄÖ÷ÒªÁÁµãÖ®Ò»ÊÇ·¢ÏÖÁ˺ã¾ÃÔËÓªµÄOperation Triangulation»î¶¯ £¬ÆäÖаüÂÞеÄiOS¶ñÒâÈí¼þƽ̨¡£APT»î¶¯ÔÚµØÀíÂþÑÜÉÏÈÔÈ»ºÜÊèÉ¢ £¬±¾¼¾¶È £¬¹¥»÷ÕßÖ÷ÒªÕë¶ÔÅ·ÖÞ¡¢À­¶¡ÃÀÖÞ¡¢Öж«ºÍÑÇÖÞ¸÷µØ¡£´ËÍâ £¬³ÉÊìµÄ¹¥»÷ÕßÔÚ²»Í£ÔöÇ¿Æä¹¤¾ß £¬ÈçLazarus¿ª·¢ÁËMATA¿ò¼Ü¡¢BlueNoroffʹÓÃÁËеĴ«Ê䷽ʽºÍ±à³ÌÓïÑÔ¡¢ScarCruftʹÓÃÁËеÄѬȾ·½Ê½ÒÔ¼°GoldenJackalеĶñÒâÈí¼þÑù±¾¡£»¹·¢ÏÖÁËй¥»÷ÕßMysterious ElephantµÄ»î¶¯¡£


https://securelist.com/apt-trends-report-q2-2023/110231/