GoogleÐû²¼Çå¾²¸üÐÂÐÞ¸´ChromeÖеĶà¸öÎó²î

Ðû²¼Ê±¼ä 2023-03-23

1¡¢GoogleÐû²¼Çå¾²¸üÐÂÐÞ¸´ChromeÖеĶà¸öÎó²î


GoogleÔÚ3ÔÂ21ÈÕÐû²¼Çå¾²¸üР£¬£¬£¬£¬£¬ £¬£¬ÐÞ¸´ÁËChromeÖеÄ8¸öÎó²î¡£¡£¡£ÆäÖÐ £¬£¬£¬£¬£¬ £¬£¬½ÏΪÑÏÖØµÄÊÇPasswordsÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2023-1528£©¡¢WebHIDÖеÄÄÚ´æÔ½½ç»á¼ûÎó²î£¨CVE-2023-1529£©¡¢ÔÚPDFÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2023-1530£©ºÍGPUÊÓÆµÖеÄÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2023-1532£©µÈ¡£¡£¡£GoogleÌåÏÖ £¬£¬£¬£¬£¬ £¬£¬ÔÚ´ó´ó¶¼Óû§¸üÐÂÐÞ¸´³ÌÐò֮ǰ £¬£¬£¬£¬£¬ £¬£¬Îó²îÏêϸÐÅÏ¢ºÍÁ´½ÓµÄ»á¼û¿ÉÄÜ»áÊܵ½ÏÞÖÆ¡£¡£¡£


https://chromereleases.googleblog.com/2023/03/stable-channel-update-for-desktop_21.html


2¡¢Á÷ýÌåÆ½Ì¨Lionsgate½ü3000ÍòÌõ¼Í¼й¶


¾ÝCybernewsÔÚ3ÔÂ22ÈÕ±¨µÀ £¬£¬£¬£¬£¬ £¬£¬ÓµÓÐ3700Íò¶©»§µÄÊÓÆµÁ÷ýÌåÆ½Ì¨Lionsgate PlayµÄElasticSearchÉèÖùýʧ £¬£¬£¬£¬£¬ £¬£¬Ð¹Â¶ÁËÓû§Êý¾Ý¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸ö20 GBЧÀÍÆ÷ÈÕÖ¾ £¬£¬£¬£¬£¬ £¬£¬°üÀ¨½ü3000ÍòÌõÌõÄ¿ £¬£¬£¬£¬£¬ £¬£¬×îÔçµÄÈÕÆÚÊÇ2022Äê5Ô¡£¡£¡£ÈÕ־й¶Á˶©ÔÄÕßµÄIPµØµãÒÔ¼°ÓйØ×°±¸¡¢²Ù×÷ϵͳºÍWebä¯ÀÀÆ÷µÄÓû§ÐÅÏ¢¡£¡£¡£»£»£»£»£»¹Ð¹Â¶ÁËÆ½Ì¨µÄʹÓÃÊý¾Ý £¬£¬£¬£¬£¬ £¬£¬ÈçÓû§Ô¢Ä¿ÄÚÈݵÄÎÊÌâIDºÍËÑË÷ÅÌÎÊµÈ £¬£¬£¬£¬£¬ £¬£¬Í¨³£¿£¿£¿£¿£¿£¿£¿£¿ÉÓÃÓÚÆÊÎöºÍÐÔÄܸú×Ù¡£¡£¡£Cybernews¾Í´ËÊÂÁªÏµÁËLionsgate £¬£¬£¬£¬£¬ £¬£¬¸Ã¹«Ë¾µÄ»ØÓ¦ÊÇÒѽ«Ð§ÀÍÆ÷±£»£»£»£»£»¤ÆðÀ´ £¬£¬£¬£¬£¬ £¬£¬¿ÉÊÇ×èÖ¹ÏÖÔÚÉÐδÌṩ¹Ù·½»ØÓ¦¡£¡£¡£


https://cybernews.com/security/lionsgate-data-leak/


3¡¢REF2924ÍÅ»ïʹÓÃNAPLISTENER¹¥»÷¶«ÄÏÑǵØÇø


¾ÝýÌå3ÔÂ20ÈÕ±¨µÀ £¬£¬£¬£¬£¬ £¬£¬REF2924ʹÓÃжñÒâÈí¼þNAPLISTENER¹¥»÷ÄÏÑǺͶ«ÄÏÑǵÄ×éÖ¯¡£¡£¡£Elastic³Æ¸ÃÍÅ»ïʹÓÃÁ˶àÖÖ»úÖÆ £¬£¬£¬£¬£¬ £¬£¬½«Öصã´ÓÊý¾ÝÇÔÈ¡×ªÒÆµ½³¤ÆÚ»á¼û¡£¡£¡£2023Äê1ÔÂ20ÈÕ £¬£¬£¬£¬£¬ £¬£¬Ò»¸öеĿÉÖ´ÐÐÎļþWmdtc.exe±»½¨Éè²¢×÷ΪWindowsЧÀÍ×°Öà £¬£¬£¬£¬£¬ £¬£¬Í¨¹ýαװ³ÉMicrosoftÂþÑÜʽÊÂÎñ´¦Öóͷ£Ð­µ÷Æ÷ЧÀÍ(Msdtc.exe)ʹÓõÄÕýµ±¶þ½øÖÆÎļþ¡£¡£¡£Wmdtc.exe±»³ÆÎªNAPLISTENER £¬£¬£¬£¬£¬ £¬£¬ÕâÊÇÒ»¸öÓÃC#¿ª·¢µÄHTTPÕìÌýÆ÷ £¬£¬£¬£¬£¬ £¬£¬Ö¼ÔÚÈÆ¹ý»ùÓÚÍøÂçµÄÇå¾²¼ì²â¡£¡£¡£


https://www.elastic.co/cn/security-labs/naplistener-more-bad-dreams-from-the-developers-of-siestagraph


4¡¢LockBitÒ²³ÆÒÑÇÔÈ¡²¢½«¹ûÕæ°Â¿ËÀ¼ÊÐϵͳÖеÄÎļþ


¾Ý3ÔÂ21ÈÕ±¨µÀ £¬£¬£¬£¬£¬ £¬£¬ÁíÒ»¸öÀÕË÷ÍÅ»ïLockBitÒ²Éù³Æ´Ó°Â¿ËÀ¼ÊÐϵͳÖÐÇÔÈ¡ÁËÎļþ¡£¡£¡£È»¶ø £¬£¬£¬£¬£¬ £¬£¬¸ÃÍÅ»ïÉÐδÐû²¼ÈκÎÖ¤¾ÝÀ´Ö¤ÊµËûÃǵĹ¥»÷»î¶¯¡£¡£¡£ÕâÊÇ×ÔPlayÍÅ»ïÔÚ3Ô³õÌåÏֶ԰¿ËÀ¼ÊеÄÍøÂç¹¥»÷ÈÏÕæºó £¬£¬£¬£¬£¬ £¬£¬µÚ¶þ¸öÀÕË÷ÍÅ»ïÉù³ÆÇÔÈ¡ÁËÊý¾Ý¡£¡£¡£LockBitÔÚÆäÍøÕ¾ÉÏÌí¼ÓÁËÐÂÌõÄ¿ £¬£¬£¬£¬£¬ £¬£¬²¢Íþв½«ÔÚ4ÔÂ10ÈÕ¹ûÕæËùÓÐÊý¾Ý¡£¡£¡£°Â¿ËÀ¼ÊÐÉÐδ¾Í´ËʽÒÏþÉùÃ÷¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ £¬£¬£¬£¬£¬ £¬£¬LockBitÔøÔÚ2022Äê6ÔÂÉù³ÆËüÈëÇÖÁËMandiantµÄϵͳ²¢ÇÔÈ¡ÁËÊýÊ®Íò¸öÎļþ £¬£¬£¬£¬£¬ £¬£¬ØÊºóÕⱻ֤ʵÊÇÒ»¸öÐû´«àåÍ·¡£¡£¡£


https://www.bleepingcomputer.com/news/security/lockbit-ransomware-gang-now-also-claims-city-of-oakland-breach/


5¡¢ChatGPT·ºÆðBug¿ÉÒÔ¿´µ½ÆäËûÓû§µÄ¶Ô»°ÀúÊ·ÎÊÌâ


ýÌå3ÔÂ21ÈÕ³Æ £¬£¬£¬£¬£¬ £¬£¬ChatGPT·ºÆðÁËÒ»¸öBug £¬£¬£¬£¬£¬ £¬£¬µ¼ÖÂÆäËûÓû§µÄ̸ÌìÀúʷй¶¡£¡£¡£¸ÃÎÊÌâ×î³õÊÇÓÉһλÏÓÒÉÆäÕÊ»§±»ºÚµÄÓû§ÔÚRedditÉϱ¨¸æµÄ £¬£¬£¬£¬£¬ £¬£¬ËûÔÚ¶Ô»°ÀúÊ·ÎÊÌâÖз¢Ã÷Á˲»ÊôÓÚ×Ô¼ºµÄ¶Ô»°¡£¡£¡£ÐÂÎÅ´«¿ªºó £¬£¬£¬£¬£¬ £¬£¬ÍÆÌØÉÏµÄÆäËûÓû§Ò²Éù³ÆÔÚ×Ô¼ºµÄÕ˺ÅÉÏ¿´µ½Á˱ðÈ˵Ä̸Ìì¼Í¼¡£¡£¡£Ðí¶àÓû§³Æ¸ÃÎÊÌâÑÏÖØÇÖÕ¼ÁËÓû§Òþ˽¡£¡£¡£ChatGPTÓÚ±¾ÖÜÒ»ÔÝʱ½ûÓÃÁËÆä̸ÌìЧÀÍ £¬£¬£¬£¬£¬ £¬£¬ÒÔÊÓ²ìºÍÐÞ¸´¸ÃÎó²î¡£¡£¡£3ÔÂ23ÈÕ £¬£¬£¬£¬£¬ £¬£¬OpenAI CEO Sam AltmanÈÏ¿ÉÆä¿ªÔ´¿âÖеÄÒ»¸ö¹ýʧµ¼ÖÂÓû§µÄ̸ÌìÀúʷй¶ £¬£¬£¬£¬£¬ £¬£¬²¢Ðû²¼ÁËÍÆÎÄÖÂǸ¡£¡£¡£


https://www.hackread.com/chatgpt-bug-conversation-history-titles/


6¡¢Unit 42Ðû²¼2023ÄêÀÕË÷Èí¼þÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ


3ÔÂ21ÈÕ £¬£¬£¬£¬£¬ £¬£¬Unit 42Ðû²¼ÁË2023ÄêÀÕË÷Èí¼þÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£±¨¸æÖ¸³ö £¬£¬£¬£¬£¬ £¬£¬¶àÖØÀÕË÷Õ½ÂÔµÄʹÓÃÒ»Á¬ÉÏÉý¡£¡£¡£×èÖ¹2022Äêµ× £¬£¬£¬£¬£¬ £¬£¬ÔÚÔ¼70%µÄ°¸¼þÖб¬·¢ÁËÊý¾Ýй¶ £¬£¬£¬£¬£¬ £¬£¬2021ÄêÖÐÖ»ÓÐÔ¼40%µÄÊý¾Ý±»µÁ¡£¡£¡£É§ÈÅÊÇÁíÒ»ÖÖÀÕË÷Õ½ÂÔ £¬£¬£¬£¬£¬ £¬£¬2022Äêµ×Ô¼20%µÄÀÕË÷Èí¼þ°¸¼þ°üÀ¨¸ÃÒòËØ £¬£¬£¬£¬£¬ £¬£¬¶ø2021Äê½öÓв»µ½1%¡£¡£¡£ÖÆÔìÒµÊÜ´ËÀ๥»÷×î¶à £¬£¬£¬£¬£¬ £¬£¬ÃÀ¹úµÄ×éÖ¯Êܵ½Ó°Ïì×îÑÏÖØ£¨Õ¼42%£©¡£¡£¡£Ñо¿Ö°Ô±Ô¤¼ÆÔÚ2023Äê £¬£¬£¬£¬£¬ £¬£¬·ºÆð´óÐÍÔÆÀÕË÷Èí¼þ¹¥»÷¡¢ÄÚ²¿ÍþвÏà¹ØµÄڲƭÀÕË÷ÔöÌíºÍ³öÓÚÕþÖÎÄîÍ·µÄÀÕË÷ÔöÌíµÈ¡£¡£¡£


https://start.paloaltonetworks.com/2023-unit42-ransomware-extortion-report