Ñо¿ÈËÔ±Åû¶WinRARÖеÄRCE©¶´CVE-2023-40477
Ðû²¼Ê±¼ä 2023-08-211¡¢Ñо¿ÈËÔ±Åû¶WinRARÖеÄRCE©¶´CVE-2023-40477
¾ÝýÌå8ÔÂ18ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±goodbyeseleneÅû¶ÁËWinRARÖеÄ©¶´£¨CVE-2023-40477£©¡£¸Ã©¶´´æÔÚÓÚ»Ö¸´¾íµÄ´¦Öùý³ÌÖУ¬ÓÉÓÚȱ·¦¶ÔÓû§ÌṩÊý¾ÝµÄÊʵ±ÑéÖ¤£¬¿ÉÄܵ¼ÖÂÄÚ´æ·ÃÎÊÁè¼Ý·ÖÅ仺³åÇøµÄÄ©¶Ë¡£µ±Óû§´ò¿ªÌØÖƵÄRARÎļþºó£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔÔÚÄ¿±êϵͳÉÏÖ´ÐÐÈÎÒâ´úÂë¡£Ñо¿ÈËÔ±ÓÚ6ÔÂ8ÈÕÏò¹©Ó¦ÉÌRARLAB³ÂËßÁËÕâһ©¶´£¬RARLABÓÚ8ÔÂ2ÈÕÐû²¼Á˲¹¶¡£¬¸Ã²¹¶¡»¹½â¾öÁËÌØÖÆ´æµµµ¼ÖÂÎļþÆô¶¯´íÎóµÄÎÊÌâ¡£
https://www.bleepingcomputer.com/news/security/winrar-flaw-lets-hackers-run-programs-when-you-open-rar-archives/
2¡¢ÌØ˹À¹ûȻӰÏìÁè¼Ý7ÍòÃûÔ±¹¤ÐÅÏ¢µÄÊý¾Ýй¶Ê¼þ
8ÔÂ19ÈÕ±¨µÀ³Æ£¬ÌØ˹ÀÅû¶ÁË5Ô·ݷ¢ÉúµÄÊý¾Ýй¶Ê¼þ¡£¹«Ë¾ÊӲ췢ÏÖ£¬Á½ÃûÇ°Ô±¹¤ÇÔÈ¡ÁË»úÃÜÐÅÏ¢£¬Î¥·´ÁËÌØ˹ÀµÄITÄþ¾²ºÍÊý¾Ý±£»¤Õþ²ß¡£Òò´Ë£¬ÌØ˹À¶ÔÕâЩǰԱ¹¤ÌáÆðËßËÏ£¬²¢¿ÛѺÁËËûÃÇ°üÂÞ±»µÁÐÅÏ¢µÄµç×ÓÉ豸¡£´ËÍ⣬ÌØ˹À»¹·¢ÏÖÕâÁ½ÃûÔ±¹¤ÓëµÂ¹ú±¨ÉçHandelsblatt·ÖÏíÁ˱»µÁµÄÊý¾Ý¡£²»Í⣬Õâ¼Ò±¨ÉçÏòÌØ˹À±£Ö¤£¬ËûÃDz»»á¹ûÈ»ÕâЩÐÅÏ¢¡£¸ÃʼþÓ°ÏìÁË75735ÃûÔ±¹¤£¬ÌØ˹À½«ÎªËûÃÇÌṩΪÆÚ12¸öÔµÄÐÅÓüà¿ØºÍÉí·Ý͵ÇÔ·þÎñ¡£
https://www.databreaches.net/tesla-notifies-employees-of-data-breach/
3¡¢Ö´·¨»ú¹¹Africa Cyber Surge IIÐж¯´þ²¶14ÃûÏÓÒÉÈË
ýÌå8ÔÂ18Èճƣ¬¹ú¼ÊÐ̾¯×é֯е÷µÄÖ´·¨Ðж¯Africa Cyber Surge IIÒÑ´þ²¶ÁË14ÃûÏÓÒÉÈË¡£¸ÃÐж¯ÓÚ½ñÄê4Ô·ݿªÊ¼£¬ÁýÕÖÁË·ÇÖÞµÄ25¸ö¹ú¼Ò£¬µ·»ÙÁË20000¶à¸öÓÃÓÚÀÕË÷¡¢µöÓã¡¢BECºÍÆÛÕ©¹¥»÷µÄ·¸×ïÍøÂ磬ËüÃÇÒÑÔì³ÉÁËÁè¼Ý40000000ÃÀÔªµÄËðʧ¡£´ËÍ⣬Õþ¸®»¹²é»ñÁËÊý°Ù¸öÍйܶñÒâÈí¼þÒÔ¼°Á÷´«Î£ÏÕµÄÈí¼þµÄ¶ñÒâIPµØÖ·¡£2022Äê11Ô¿ªÕ¹µÄµÚÒ»´ÎAfrica Cyber SurgeÐж¯´þ²¶ÁË11¸öÈË£¬²¢µ·»ÙÁËÒ»¸ö³öÊۺڿ͹¤¾ßµÄ°µÍøºÍÔ¼20Íò¸ö¶ñÒâ»ù´¡ÉèÊ©¡£
https://therecord.media/africa-cyber-surge-14-arrests-interpol
4¡¢µÂ¹úÁª°îÂÉʦлá(BRAK)Ôâµ½NoEscapeµÄÀÕË÷¹¥»÷
¾Ý8ÔÂ18ÈÕ±¨µÀ£¬µÂ¹ú¹ú¼ÒÂÉʦлá(BRAK)͸¶ÕýÔÚÊÓ²ìÆ䲼³Èû¶û·þÎñ´¦Ôâµ½µÄÀÕË÷¹¥»÷¡£BRAKÂôÁ¦¼à¹ÜµÂ¹ú28¸öµØÓòµÄÂÉʦÊÂÎñËù£¬´ú±í¹úÄÚÍâÔ¼166000ÃûÂÉʦ¡£¸Ã»ú¹¹ÓÚ8ÔÂ2ÈÕ·¢ÏÖÁ˹¥»÷ʼþ£¬ÀÕË÷ÍÅ»ïNoEscapeÔÚ8ÔÂ15ÈÕ³ÆÆä¶Ô´Ë´Î¹¥»÷ÂôÁ¦¡£ºÚ¿ÍÉù³Æ¼ÓÃÜÁËBRAKµÄÓʼþ·þÎñÆ÷²¢»ñÈ¡ÁË160 GBµÄÊý¾Ý¡£BRAKÌåÏÖÒѾ»Ö¸´µç×ÓÓʼþϵͳµÄ·ÃÎÊ£¬²¢¼Æ»®ÁªÏµÊÜÊý¾Ýй¶ӰÏìµÄ¸öÈË¡£
https://therecord.media/german-national-bar-association-investigating-cyberattack
5¡¢Î¢Èí³ÆBlackCatµÄбäÌåÒÑǶÈëImpacketºÍRemCom
΢ÈíÔÚ8ÔÂ17ÈճƷ¢ÏÖÁËÀÕË÷Èí¼þBlackCatµÄбäÌ壬ǶÈëÁËÍøÂç¿ò¼ÜImpacketºÍºÚ¿Í¹¤¾ßRemcom¡£Î¢ÈíÌåÏÖ£¬½üÆÚµÄBlackCat»î¶¯ÕýÔÚʹÓÃImpacket¿ò¼Ü½øÐÐƾ֤¸´ÖƺÍÔ¶³Ì·þÎñÖ´ÐУ¬ÒÔÔÚÕû¸öÍøÂçÉÏ°²×°¼ÓÃÜÆ÷·¨Ê½¡£´ËÍ⣬¼ÓÃÜ·¨Ê½»¹Ç¶ÈëÁËRemcom£¬¿ÉÔÚϵͳÉϵÄÆäËüÉ豸ÉÏÔ¶³ÌÖ´ÐÐÃüÁ΢Èí»¹Í¸Â¶£¬BlackCatµÄÁ¥Êô»ú¹¹Storm-0875×Ô7ÔÂÒÔÀ´¾ÍʹÓÃÁËÕâÖÖеļÓÃÜ·½Ê½¡£Î¢Èí½«Õâ¸öа汾ÃüÃûΪBlackCat 3.0£¬ÀÕË÷ÍÅ»ïÔÚÓëÆäÁ¥Êô»ú¹¹µÄͨÐÅÖн«Æä³ÆΪSphynx»òBlackCat/ALPHV 2.0¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-blackcats-sphynx-ransomware-embeds-impacket-remcom/
6¡¢Áè¼Ý3000¸ö¶ñÒâÈí¼þʹÓÃδ֪ѹËõÒªÁìÀ´Èƹý¼ì²â
¾Ý8ÔÂ19ÈÕ±¨µÀ³Æ£¬¹¥»÷ÕßÕýÔÚʹÓÃδ֪»ò²»ÊÜÖ§³ÖµÄѹËõÒªÁìµÄAPKÎļþÀ´Èƹý¶ñÒâÈí¼þ·ÖÎö¡£ZimperiumÔÚÒ°Íâ·¢ÏÖÁË3300¸öÀûÓôËÀàѹËõËã·¨µÄAndroid¶ñÒâÈí¼þ£¬ÆäÖÐ71¸öÑù±¾¿ÉÒÔ˳ÀûµØ¼ÓÔص½ÏµÍ³ÉÏ¡£ÕâÖÖ·½Ê½µÄÓŵãÊÇÄܹ»Èƹý·´±àÒ빤¾ß£¬Í¬Ê±»¹ÄÜ°²×°ÔÚOS°æ±¾¸ßÓÚAndroid 9 PieµÄÉ豸ÉÏ¡£´ËÍ⣬Zimperium»¹·¢ÏÖ¶ñÒâÈí¼þ¿ª·¢Õß¹ÊÒâÆÆ»µAPKÎļþÀ´Èƹý¼ì²âµÄÆäËü·½Ê½£¬°üÂÞʹÓÃÁè¼Ý256×Ö½ÚµÄÎļþÃû¡¢¸ñʽ´íÎóµÄAndroidManifest.xmlºÍ¸ñʽ´íÎóµÄ×Ö·û´®³ØµÈ¡£
https://securityaffairs.com/149678/malware/android-malware-using-unsupported-unknown-compression.html