GoogleÐÞ¸´Òѱ»ÀûÓõÄChrome©¶´CVE-2023-5217
Ðû²¼Ê±¼ä 2023-09-281¡¢GoogleÐÞ¸´Òѱ»ÀûÓõÄChrome©¶´CVE-2023-5217
¾ÝýÌå9ÔÂ27ÈÕ±¨µÀ£¬GoogleÐû²¼½ô¼±Äþ¾²¸üУ¬ÐÞ¸´Á˽ñÄêµÚ5¸ö±»ÀûÓõÄChrome©¶´£¨CVE-2023-5217£©¡£¸Ã©¶´Ô´ÓÚ¿ªÔ´libvpxÊÓÆµ±à½âÂëÆ÷¿âµÄVP8±àÂëÖеĶѻº³åÇøÒç³ö©¶´£¬¿ÉÄܵ¼ÖÂÓ¦Ó÷¨Ê½Íß½âºÍÈÎÒâ´úÂëÖ´ÐС£Google TAG͸¶£¬¸Ã©¶´±»ÀûÓÃÀ´°²×°¼äµýÈí¼þ¡£ËäÈ»Google³Æ£¬ÐÞ¸´°æ±¾¿ÉÄÜÐèÒª¼¸Ìì»ò¼¸ÖܲůøÁýÕÖÕû¸öÓû§Èº£¬µ«Ñо¿ÈËÔ±¼ì²é¸üÐÂʱ·¢ÏÖÁ¢¼´¿ÉÓ㬶øÇÒä¯ÀÀÆ÷»¹½«×Ô¶¯¼ì²éиüв¢ÔÚÏÂ´ÎÆô¶¯ºó×Ô¶¯°²×°ËüÃÇ¡£
https://www.bleepingcomputer.com/news/security/google-fixes-fifth-actively-exploited-chrome-zero-day-of-2023/
2¡¢¼ÓÄôóFlairº½¿Õ¹«Ë¾µÄÊý¾Ý¿âÒѹûÈ»ÖÁÉÙ7¸öÔÂ
¾Ý9ÔÂ26ÈÕ±¨µÀ£¬Cybernews·¢ÏÖ¼ÓÄôóFlairº½¿Õ¹«Ë¾µÄÊý¾Ý¿âºÍµç×ÓÓʼþµØÖ·µÄƾ¾ÝÒѹûÈ»ÖÁÉÙ7¸öÔ¡£¸Ãʼþй¶ÁËFlyflair.comÍøÕ¾ÉÏÍйܵĻ·¾³Îļþ£¬¸Ã.envÎļþ°üÂÞÊý¾Ý¿âºÍµç×ÓÓʼþÅäÖÃÏêϸÐÅÏ¢¡£Êý¾Ý¿âÅäÖÃÏÔʾ£¬ÆäÖÐÒ»¸öÊý¾Ý¿â̻¶ÔÚ»¥ÁªÍøÉÏ£¬ÈκÎÈ˶¼¿ÉÄÜʹÓÃÕâЩƾ¾ÝÀ´·ÃÎÊ´æ´¢ÔÚ¸ÃÊý¾Ý¿âÖеÄÃô¸ÐÐÅÏ¢¡£Ä¿Ç°ÎÞ·¨È·¶¨Ð¹Â¶Êý¾ÝÊÇ·ñÒѱ»ÀûÓ㬵«¹ûÈ»µÄ.envÎļþÓÚ2022Äê8ÔÂÊ״α»·¢ÏÖ²¢±àÈëË÷Òý£¬ÕâÒâζ×ÅËüÃÇÔÚ½ü7¸öÔµÄʱ¼äÀï¿ÉÒÔ±»·ÃÎÊ¡£
https://securityaffairs.com/151512/data-breach/canadian-flair-airlines-data-leak.html
3¡¢Ó¢¹ú¹«Ë¾KNP LogisticsÒò6ÔÂÔâµ½µÄ¹¥»÷Ðû¸æÆÆ²ú
9ÔÂ27Èճƣ¬KNP LogisticsÔÚ±¾ÖÜÒ»Ðû²¼ÆÆ²ú£¬²¢½«ÔÒò¹é½áÓÚ6Ô·ÝÔâµ½µÄÀÕË÷¹¥»÷¡£ÕâÊÇÓ¢¹ú×î´óµÄ˽ӪÎïÁ÷¹«Ë¾Ö®Ò»¡£¾ÝÆä¹ÜÀíÔ±³Æ£¬ÀÕË÷¹¥»÷Ó°ÏìÁËÒªº¦µÄϵͳ¡¢ÒµÎñÁ÷³ÌºÍ²ÆÕþ£¬Õâ¶Ô¼¯ÍŵIJÆÕþ×´¿öÒÔ¼°×îÖÕ»ñµÃÌØ±ðͶ×ʺÍ×ʽðµÄÄÜÁ¦·¢ÉúÁ˵¹Ã¹Ó°Ïì¡£¸Ã¹«Ë¾ÓÚ6Ô·ݱ»Ìí¼Óµ½AkiraÍÅ»ïµÄÍøÕ¾ÁбíÖУ¬AvastÔÚ7Ô·ÝÐû²¼ÁËAkiraÀÕË÷Èí¼þµÄ½âÃÜÆ÷¡£Ä¿Ç°Éв»Çå³þKLP LogisticsÊÇ·ñʹÓÃÁ˽âÃÜÆ÷¡£
https://therecord.media/knp-logistics-ransomware-insolvency-uk
4¡¢AtlasCrossÒÔºìÊ®×Ö»áΪÓÕ¶ü·Ö·¢ºóÃŶñÒâÈí¼þ
ýÌå9ÔÂ26Èճƣ¬ºÚ¿ÍÍÅ»ïAtlasCrossÒÔÃÀ¹úºìÊ®×Ö»áΪÓÕ¶ü¹¥»÷Ä¿±ê£¬ÒÔ·Ö·¢ºóÃŶñÒâÈí¼þ¡£AtlassCrossð³äÀ´×ÔÃÀ¹úºìÊ®×ֻᷢË͵öÓãÓʼþ£¬ÑûÇëÊÕ¼þÈ˼ÓÈë2023Äê9ÔµÄÏ×Ѫ»î¶¯¡£ÕâЩÓʼþ°üÂÞÆôÓúêµÄWordÎĵµ(.docm)¸½¼þ£¬ÆôÓúóÊ×ÏÈ»áÔÚWindowsÉ豸ÉÏÏÂÔØZIP´æµµ£¬À´·Ö·¢KB4495667.pkg£¬ÕâÊÇDangerAdsϵͳ·ÖÎöÆ÷ºÍ¶ñÒâÈí¼þ¼ÓÔØ·¨Ê½¡£×îÖÕ£¬DangerAds»á¼ÓÔØx64.dll£¬ÕâÊÇ×îÖÕAtlasAgentľÂí£¬Ò²ÊǴ˴ι¥»÷ÖеÄ×îÖÕpayload¡£
https://www.bleepingcomputer.com/news/security/new-atlascross-hackers-use-american-red-cross-as-phishing-lure/
5¡¢Ð¶ñÒâÈí¼þZenRATͨ¹ý¼ÙµÄBitwarden°²×°°üÁ÷´«
ProofpointÔÚ9ÔÂ26ÈÕÅû¶ÁËжñÒâÈí¼þZenRATͨ¹ýÐé¼ÙÃÜÂë¹ÜÀíÆ÷Bitwarden°²×°°ü½øÐзַ¢µÄ»î¶¯¡£¸ÃRATÖ÷ÒªÕë¶ÔWindowsϵͳ£¬Ö¼ÔÚÇÔÈ¡ÐÅÏ¢¡£¶ñÒâ°²×°·¨Ê½ÓÚ7ÔÂ28ÈÕÊ×´ÎÔÚVirusTotalÉϳÂËߣ¬ÒѾÒÔÁ½¸ö²îÒìµÄÃû³ÆÔÚ½Ó½üµÄλÖ÷ºÆð¹ýÁ½´Î¡£°²×°·¨Ê½×Ô³ÆÊÇPiriform's Speccy£¬²¢¼Ù×°´øÓÐTim KosseµÄÇ©Ãû¡£Ä¿Ç°£¬Éв»Çå³þ¶ñÒâÈí¼þÊÇÈçºÎÁ÷´«µÄ¡£´ËÍ⣬½öµ±Ä¿±êͨ¹ýWindowsÖ÷»ú·ÃÎʸöñÒâÍøÕ¾Ê±£¬²Å»áÏÔʾÐé¼ÙµÄBitwarden°²×°°ü¡£
https://www.proofpoint.com/us/blog/threat-insight/zenrat-malware-brings-more-chaos-calm
6¡¢Group-IBÐû²¼¹ØÓÚShadowSyndicateµÄ·ÖÎö³ÂËß
9ÔÂ26ÈÕ£¬Group-IBÐû²¼Á˹ØÓÚShadowSyndicateµÄ·ÖÎö³ÂËß¡£ShadowSyndicateÔÚÐí¶à·þÎñÆ÷ÉÏʹÓÃÁËÏàͬµÄSecure Shell(SSH)Ö¸ÎÆ£¨½ØÖÁĿǰÓÐ85¸ö£©£¬ÖÁÉÙ52̨¾ßÓдËSSHµÄ·þÎñÆ÷±»ÓÃ×÷Cobalt Strike C2¿ò¼Ü¡£Ëü×Ô2022Äê7ÔÂ16ÈÕ¿ªÊ¼Ò»Ö±»îÔ¾£¬ÓëQuantum¡¢Nokoyawa¡¢BlackCat¡¢Royal¡¢Cl0p¡¢CactusºÍPlayÏà¹ØµÄÀÕË÷»î¶¯Óйأ¬Í¬Ê±»¹Ê¹ÓÃÁË¡°Ïֳɵġ±¹¤¾ß°ü£¬ÀýÈçCobalt Strike¡¢Sliver¡¢IcedIDºÍMatanbuchusµÈ¡£Ñо¿ÈËÔ±»¹·¢ÏÖÁËShadowSyndicateµÄ»ù´¡ÉèÊ©ºÍCl0p/TruebotÖ®¼äµÄÁªÏµ¡£
https://www.group-ib.com/blog/shadowsyndicate-raas/