Ñо¿ÈËÔ±ÑÝʾÈçºÎÀûÓÃChromeÀ©Õ¹·¨Ê½ÇÔÈ¡Ã÷ÎÄÃÜÂë
Ðû²¼Ê±¼ä 2023-09-041¡¢Ñо¿ÈËÔ±ÑÝʾÈçºÎÀûÓÃChromeÀ©Õ¹·¨Ê½ÇÔÈ¡Ã÷ÎÄÃÜÂë
¾ÝýÌå9ÔÂ2ÈÕ±¨µÀ£¬Íþ˹¿µÐÇ´óѧÂóµÏÑ··ÖУµÄÒ»×éÑо¿ÈËÔ±·¢ÏÖ¿ÉÒÔͨ¹ýChromeÀ©Õ¹´ÓÍøÕ¾Ô´´úÂëÖÐÇÔÈ¡´¿Îı¾ÃÜÂë¡£¸ÃÎÊÌâÉæ¼°ä¯ÀÀÆ÷À©Õ¹¿É²»ÊÜÏÞÖÆµØ·ÃÎÊÆä¼ÓÔØµÄÍøÕ¾µÄDOMÊ÷£¬´Ó¶ø·ÃÎÊÓû§ÊäÈë×ֶεÈDZÔÚÃô¸ÐÔªËØ¡£¼øÓÚÀ©Õ¹·¨Ê½ºÍÍøÕ¾ÔªËØÖ®¼äûÓÐÈκÎÄþ¾²½çÏÞ£¬Òò´ËÀ©Õ¹¿ÉÒÔ·ÃÎÊÔ´´úÂëÖпɼûµÄÊý¾Ý£¬²¢ÌáÈ¡ÆäÈÎÒâÄÚÈÝ¡£´ËÍ⣬¸ÃÀ©Õ¹·¨Ê½¿ÉÄÜ»áÀûÓÃDOM APIÔÚÓû§ÊäÈëʱֱ½ÓÌáÈ¡ÊäÈëÖµ¡£GoogleÌåÏÖËûÃÇÕýÔÚÊÓ²ì´ËÊ¡£
https://www.bleepingcomputer.com/news/security/chrome-extensions-can-steal-plaintext-passwords-from-websites/
2¡¢Ï¤Äá´óѧµÚÈý·½·þÎñÌṩÉÌÔâµ½¹¥»÷²¿ÃÅÊý¾Ýй¶
¾Ý9ÔÂ3ÈÕ±¨µÀ£¬Ï¤Äá´óѧ(USYD)͸¶£¬ÆäµÚÈý·½·þÎñÌṩÉÌÔâµ½¹¥»÷£¬µ¼Ö½üÆÚÉêÇëºÍ×¢²áµÄ¹ú¼ÊÉêÇëÈ˵ÄÐÅϢй¶¡£USYD³Æ¸ÃÎÊÌâ½öÏÞÓÚµ¥Ò»Æ½Ì¨£¬¶Ô´óѧµÄÆäËüϵͳûÓÐÓ°Ï죬³õ·¨Ê½²éҲûÓз¢ÏÖÈκε±µØÑ§Éú¡¢½ÌÖ°Ô±¹¤»òУÓѵÄÐÅϢй¶¡£¹ûÈ»µÄʼþÐÅÏ¢²¢Î´ËµÃ÷й¶·¢ÉúµÄʱ¼ä»òÄÄЩµÚÈý·½·þÎñÔâµ½¹¥»÷£¬Ä¿Ç°Ò²Ã»ÓйØÓÚUSYDϵͳÖжϵÄͨ¸æ¡£
https://www.bleepingcomputer.com/news/security/university-of-sydney-data-breach-impacts-recent-applicants/
3¡¢EclecticIQÐû²¼ÀÕË÷Èí¼þKey GroupµÄÃâ·Ñ½âÃÜ·¨Ê½
ýÌå9ÔÂ1Èճƣ¬EclecticIQÐû²¼ÀÕË÷Èí¼þKey Group£¨ÓÖÃûkeygroup777£©µÄÃâ·Ñ½âÃÜ·¨Ê½£¬ÊÊÓÃÓÚ8Ô³õ¹¹½¨µÄ¶ñÒâÈí¼þ°æ±¾¡£Key GroupÖÁÉÙ×Ô½ñÄê1ÔÂÆð¾ÍÒ»Ö±»îÔ¾£¬¹¥»÷ÕßÉù³ÆËûÃǵĶñÒâÈí¼þʹÓõÄÊÇ"¾üÓü¶±ðAES¼ÓÃÜ"£¬µ«¸ÃlockerÔÚËùÓмÓÃܹý³ÌÖж¼Ê¹ÓÃÁ˾²Ì¬salt£¬Òò´Ë¸Ã·½°¸¾ßÓÐÒ»¶¨µÄ¿ÉÔ¤²âÐÔ£¬¼ÓÃÜÒ²ÓпÉÄܱ»Äæ×ª¡£¸Ã¹¤¾ßÈÔ´¦ÓÚÑéÖ¤½×¶Î£¬¿ÉÄܲ»ÊÊÓÃÓÚÿ¸öKey GroupÑù±¾¡£
https://securityaffairs.com/150207/malware/key-group-ransomware-decryptor.html
4¡¢Callaway¹«Ë¾¹ûÈ»Éæ¼°Áè¼Ý110ÍòÓû§µÄÊý¾Ýй¶Ê¼þ
9ÔÂ1ÈÕ±¨µÀ³Æ£¬ÃÀ¹ú¸ß¶û·òÇò×°±¸ÖÆÔìÉ̺ÍÏúÊÛÉÌCallaway¹ûÈ»Á˽üÆÚ·¢ÉúµÄÊý¾Ýй¶Ê¼þ¡£CallawayÔÚ8ÔÂ29ÈÕÐû²¼Í¨Öª£¬³Æ8ÔÂ1ÈÕ·¢ÉúµÄITϵͳʼþÓ°ÏìÁËÆäµçÉÌ·þÎñµÄ¿ÉÓÃÐÔ£¬²¢½«²¿Ãſͻ§ÐÅϢй¶¸øÎ´¾ÊÚȨµÄµÚÈý·½¡£¸ÃʼþÓ°ÏìÁËCallaway¼°Æä×ÓÆ·ÅÆOdyssey¡¢OgioºÍCallaway Gold PreownedÍøÕ¾µÄ¿Í»§£¬Ð¹Â¶ÐÅÏ¢°üÂÞÐÕÃû¡¢µØÖ·¡¢¶©µ¥ÀúÊ·¼Ç¼¡¢Äþ¾²ÎÊÌâºÍÕË»§ÃÜÂëµÈ£¬Éæ¼°ÁË1114954ÈË¡£ÓÉÓÚÃÜÂëºÍÄþ¾²ÎÊÌâµÈÕÊ»§ÐÅϢй¶£¬CallawayÒÑÇ¿ÖÆËùÓпͻ§ÖØÖÃÃÜÂë¡£
https://therecord.media/topgolf-callaway-says-one-million-affected-by-breach
5¡¢SecuronixÅû¶ͨ¹ýMS SQL·Ö·¢FreeWorldµÄ¹¥»÷»î¶¯
SecuronixÔÚ9ÔÂ1ÈÕÅû¶ÁËͨ¹ýMS SQL·Ö·¢ÀÕË÷Èí¼þFreeWorldµÄ¹¥»÷»î¶¯DB#JAMMER¡£Æä¹¤¾ß°üÂÞö¾Ù¹¤¾ß¡¢RAT payload¡¢Â©¶´ÀûÓÃºÍÆ¾Ö¤ÇÔÈ¡¹¤¾ßÒÔ¼°ÀÕË÷Èí¼þ¡£FreeWorldËÆºõÊÇÀÕË÷Èí¼þMimicµÄбäÖÖ¡£³õʼ·ÃÎÊÊÇͨ¹ý±©Á¦ÆÆ½âMS SQL·þÎñÆ÷À´ÊµÏֵģ¬ÏÂÒ»½×¶ÎÐèÒª½ÓÄÉ´ëÊ©¹¥»÷ϵͳ·À»ðǽ£¬Á¬½ÓÔ¶³ÌSMB¹²ÏíÀ´½¨Á¢³Ö¾ÃÐÔ£¬ÒÔ±ãÔÚϵͳ֮¼ä´«ÊäÎļþ£¬²¢°²×°Cobalt StrikeµÈ¹¤¾ß¡£È»ºó°²×°AnyDesk£¬ºáÏòÒÆ¶¯£¬×îÖÕ°²×°FreeWorld¡£
https://www.securonix.com/blog/securonix-threat-labs-security-advisory-threat-actors-target-mssql-servers-in-dbjammer-to-deliver-freeworld-ransomware/
6¡¢CiscoÐû²¼¹ØÓÚ¿ªÔ´ÇÔÈ¡·¨Ê½SapphireStealerµÄ³ÂËß
8ÔÂ31ÈÕ£¬CiscoÐû²¼Á˹ØÓÚ¿ªÔ´ÇÔÈ¡·¨Ê½SapphireStealerµÄ·ÖÎö³ÂËß¡£×Ô2022Äê12ÔÂÊ×´ÎÐû²¼ÒÔÀ´£¬SapphireStealerÔÚ¹«¹²¶ñÒâÈí¼þ´æ´¢¿âÖзºÆðµÄƵÂʲ»Í£Ôö¼Ó¡£Ëü¾ßÓÐÊÕ¼¯Ö÷»úÐÅÏ¢¡¢ä¯ÀÀÆ÷Êý¾Ý¡¢ÎļþºÍÆÁÄ»½ØÍ¼µÄ¹¦Ð§£¬²¢¿Éͨ¹ý¼òµ¥Óʼþ´«ÊäÐÒé(SMTP)ÒÔZIPÎļþµÄÐÎʽ´«ÊäÊý¾Ý¡£´ËÍ⣬Ñо¿ÈËÔ±»¹·¢ÏÖÁËSapphireStealerµÄ¶à¸ö±äÌ壬³ÆºÚ¿Í¸ïÐÂÁËÔʼ´úÂë¿â£¬Ê¹ÆäÖ§³Ö¸ü¶àµÄÊý¾Ýй¶»úÖÆ£¬Òò¶ø·¢ÉúÁ˶à¸ö±äÌå¡£
https://blog.talosintelligence.com/sapphirestealer-goes-open-source/