΢Èí8Ô·ÝÄþ¾²¸üÐÂÐÞ¸´Á½¸ö±»ÀûÓ鶴ÔÚÄÚµÄ87¸ö©¶´

Ðû²¼Ê±¼ä 2023-08-09

1¡¢Î¢Èí8Ô·ÝÄþ¾²¸üÐÂÐÞ¸´Á½¸ö±»ÀûÓ鶴ÔÚÄÚµÄ87¸ö©¶´


¾ÝýÌå8ÔÂ8ÈÕ±¨µÀ£¬ÊÇ΢ÈíÐû²¼ÁË8Ô·ݵÄÖܶþ²¹¶¡£¬×ܼÆÐÞ¸´ÁË87¸ö©¶´£¬ÆäÖаüÂÞÁ½¸ö±»Ö÷¶¯ÀûÓõÄ©¶´¡£Òѱ»ÀûÓõÄ©¶´·Ö±ðÊÇ.NETºÍVisual Studio¾Ü¾ø·þÎñ©¶´£¨CVE-2023-38180£©£¬Î¢Èíδ¹ûÈ»ÀûÓôË©¶´µÄ¹¥»÷µÄÏêÇé¡£ÁíÒ»¸öÊÇÏÈÇ°ÒÑ»º½â²¢±»»ý¼«ÀûÓõÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2023-36884£©µÄ²¹¶¡ÈƹýÎÊÌ⣬¸Ã©¶´±»RomComÓÃÀ´·Ö·¢ÀÕË÷Èí¼þIndustrial Spy¡£´ËÍ⣬»¹ÐÞ¸´Á˽ÏΪÑÏÖصÄOutlook RCE©¶´£¨CVE-2023-36895£©ºÍTeams RCE©¶´£¨CVE-2023-29328ºÍCVE-2023-29330£©µÈ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2023-patch-tuesday-warns-of-2-zero-days-87-flaws/


2¡¢°²×°Á¿250Íò´ÎµÄ43¸öAndroidÓ¦ÓÃÔÚËøÆÁʱ¼ÓÔعã¸æ


¾Ý8ÔÂ8ÈÕ±¨µÀ£¬McAfee·¢ÏÖGoogle PlayÖеÄ43¸öAndroidÓ¦ÓûáÔÚÊÖ»úËøÆÁʱ¼ÓÔعã¸æ¡£ÕâЩӦÓÃαװ³ÉµçÊÓ/DMB²¥·ÅÆ÷¡¢ÒôÀÖÏÂÔØÆ÷¡¢ÐÂÎźÍÈÕÀúÓ¦Ó÷¨Ê½£¬°²×°Á¿¸ß´ï250Íò´Î£¬Ö÷ÒªÕë¶Ôº«¹úµÄÄ¿±ê¡£´ËÀà¶ñÒâÓ¦ÓûáºÄ¾¡É豸µç³ØÊÙÃü²¢ÏûºÄ´óÁ¿Á÷Á¿¡£Ò»µ©°²×°£¬ÕâЩ¹ã¸æÓ¦ÓûáÆÚ´ý¼¸ÖܲÅÆô¶¯¶ñÒâ»î¶¯£¬ÒÔÆÛÆ­Óû§²¢ÈƹýGoogleÉóºËÈËÔ±µÄ¼ì²â¡£Ä¿Ç°£¬GoogleÒÑ´ÓÆäÓ¦ÓÃÉ̵êÖÐɾ³ýÁËÕâЩӦÓá£


https://securityaffairs.com/149274/malware/google-play-43-rogue-android.html


3¡¢CiscoÅû¶ÀûÓÃYashmaµÄ±äÌåÕë¶ÔÔ½ÄϵȹúµÄ¹¥»÷»î¶¯


Cisco TalosÔÚ8ÔÂ7ÈÕÅû¶ÁËÀûÓÃÀÕË÷Èí¼þYashmaµÄ±äÌåÕë¶Ô±£¼ÓÀûÑǺÍÔ½ÄϵȹúµÄ¹¥»÷»î¶¯¡£¹¥»÷»î¶¯Ê¼ÓÚ6ÔÂ4ÈÕ×óÓÒ£¬¿ÉÄÜÓëÔ½ÄϵĺڿÍÍÅ»ïÓйØ¡£¸Ã»î¶¯Ä£·ÂÁËWannaCryµÄÀÕË÷ÐÅ£¬²¢ÌåÏÖÈç¹ûÄ¿±ê²»ÔÚÈýÌìÄÚ½»Êê½ð£¬Êê½ð½ð¶î½«·­±¶¡£µ«ÀÕË÷ÐÅÖÐûÓÐÁгöÊê½ðÊý¶î£¬¹²ÏíµÄÕË»§ÖÐҲûÓбÈÌرÒ£¬Õâ±íÃ÷¸Ã»î¶¯¿ÉÄÜÈÔ´¦ÓÚ³õÆڽ׶Ρ£´ËÍ⣬¹¥»÷ÕßûÓÐÔÚ¶þ½øÖÆÎļþÖÐǶÈëÀÕË÷ÐŵÄ×Ö·û´®£¬¶øÊÇͨ¹ýÖ´ÐÐǶÈëµÄÅú´¦ÖÃÎļþ£¬´Ó¹¥»÷ÕßµÄGitHub´æ´¢¿âÖÐÏÂÔØ¡£


https://blog.talosintelligence.com/new-threat-actor-using-yashma-ransomware/


4¡¢¼äµýÈí¼þ·þÎñLetMeSpyÔÚ´ó¹æÄ£Êý¾Ýй¶ºóÍ£Ö¹ÔËÓª


ýÌå8ÔÂ7Èճƣ¬Android¼äµýÈí¼þ·þÎñLetMeSpyÔÚ·¢Éú´ó¹æÄ£Êý¾Ýй¶ºó£¬±»ÆÈÍ£Ö¹ÔËÓª¡£Ð¹Â¶Ê¼þ·¢ÉúÓÚ6ÔÂ21ÈÕ£¬°üÂÞÁè¼Ý13000¸öλÖÃÊý¾ÝµãºÍ26000Ãû¿Í»§µÄÊý¾ÝµÈ¡£LetMeSpyͨ¹ýÆäÍøÕ¾Ðû²¼ÁËÒ»Ôòͨ¸æ£¬Í¨ÖªÓû§½«ÔÚ8ÔÂ31ÈÕ֮ǰֹͣËùÓзþÎñ¡£Ê¼þ·¢Éúºó£¬LetMeSpyµÄÍøÕ¾Ò²ÂäÈëÁ˺ڿ͵ĿØÖÆ֮ϡ£Õë¶ÔÕâÒ»Çé¿ö£¬LetMeSpyÒÑָʾϣÍû·ÃÎÊÆäÊý¾ÝµÄÓû§ÔÚ9ÔÂ30ÈÕ֮ǰʹÓÃÍøÕ¾ÉÏÌṩµÄÓʼþµØÖ·ÁªÏµ¹«Ë¾¡£


https://www.hackread.com/letmespy-android-spyware-data-breach-shuts-down/


5¡¢Kasada·¢ÏÖÀûÓÃײ¿â¹¤¾ßOpenBullet·Ö·¢RATµÄ»î¶¯


8ÔÂ7ÈÕ±¨µÀ³Æ£¬Kasada·¢ÏÖÁËÐµĹ¥»÷»î¶¯£¬ÀûÓöñÒâOpenBulletÅäÖÃÎļþÀ´·Ö·¢ÇÔÈ¡ÐÅÏ¢µÄRAT¡£OpenBulletÊÇÒ»¸öºÏ·¨µÄ¿ªÔ´Éø͸²âÊÔ¹¤¾ß£¬ÓÃÓÚ×Ô¶¯×²¿â¹¥»÷¡£ËäÈ»OpenBulletÅäÖÃÎļþµÄ¶à¹¦Ð§ÐÔ¿ÉÒÔʵÏÖÅÓ´óµÄ¹¥»÷£¬µ«È±·¦¾­ÑéµÄÐÂÊֺڿͲ»ÄÜÍêÈ«Àí½âÕýÔÚ´´½¨ÄÄЩÇëÇóÒÔ¼°ÕýÔÚ¼ìË÷ÄÄЩÊý¾Ý¡£ÕâЩ¶ñÒâÅäÖûá·ÃÎÊGitHub´æ´¢¿âÀ´¼ìË÷»ùÓÚRustµÄdropper Ocean£¬Ëü»áÏÂÔØ»ùÓÚPythonµÄ¶ñÒâÈí¼þPatent¡£×îÖÕÆô¶¯Ò»¸öRAT£¬ÒÔTelegram×÷ΪC2£¬ÇÔÈ¡ä¯ÀÀÆ÷ÃÜÂë¡¢cookieºÍ¼ÓÃÜÇ®°üµÈÐÅÏ¢¡£


https://thehackernews.com/2023/08/new-malware-campaign-targets.html


6¡¢FortinetÐû²¼2023ÄêÉÏ°ëÄêÈ«ÇòÍþв̬ÊƵķÖÎö³ÂËß


8ÔÂ7ÈÕ£¬FortinetÐû²¼ÁË2023ÄêÉÏ°ëÄêÈ«ÇòÍþв̬ÊƵķÖÎö³ÂËß¡£½ñÄêÉÏ°ëÄ꣬Ñо¿ÈËÔ±·¢ÏÖAPT»î¶¯Æµ·±¡¢ÀÕË÷Èí¼þƵÂʺÍÅÓ´óÐÔÌá¸ßÒÔ¼°½©Ê¬ÍøÂç»î¶¯Ôö¼ÓµÈÇ÷ÊÆ¡£ËäÈ»¹¥»÷ÊýÁ¿²¢Î´Ïñ¹ýÈ¥ÄÇÑùÁ¬ÐøÅÊÉý£¬µ«ÈëÇÖÆóͼ±äµÃÔ½·¢ÅÓ´óºÍÓÐÕë¶ÔÐÔ¡£¹¥»÷ÕßÀûÓÃÖ÷Ҫ©¶´µÄ¿ÉÄÜÐÔÔö¼ÓÁË327±¶¡£ÔÚMITREʶ´ËÍâ138¸ö¹¥»÷ÍÅ»ïÖУ¬ÓÐ41¸ö(30%)ÔÚ½ñÄêÉÏ°ëÄê»îÔ¾¡£ÔÚ¹ýÈ¥ÎåÄêÖУ¬Î¨Ò»Â©¶´µÄÀûÓôÎÊýÔö¼ÓÁË68%£¬¶ñÒâÈí¼þ¼Ò×åºÍ±äÌå³Ê±¬Õ¨Ê½Ôö³¤£¬·Ö±ðÔö³¤ÁË135%ºÍ175%¡£


https://www.fortinet.com/blog/threat-research/fortiguard-labs-threat-report-key-findings-1h-2023