CiscoÅû¶ÆäSPA112 2-Portµç»°ÊÊÅäÆ÷ÖеÄRCEÎó²î
Ðû²¼Ê±¼ä 2023-05-061¡¢CiscoÅû¶ÆäSPA112 2-Portµç»°ÊÊÅäÆ÷ÖеÄRCEÎó²î
¾ÝýÌå5ÔÂ4ÈÕ±¨µÀ£¬£¬£¬£¬CiscoÅû¶ÁËÆäSPA112 2-Portµç»°ÊÊÅäÆ÷ÖлùÓÚWebµÄÖÎÀí½çÃæÖеÄÎó²î£¬£¬£¬£¬¿É±»Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÓÃÓÚÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î×·×ÙΪCVE-2023-20126£¨CVSSÆÀ·Ö9.8£©£¬£¬£¬£¬ÊÇÓÉÓڹ̼þÉý¼¶¹¦Ð§ÖÐȱÉÙÉí·ÝÑéÖ¤Àú³ÌÔì³ÉµÄ£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½«Ä¿µÄ×°±¸Éý¼¶µ½¶ñÒ⿪·¢µÄ¹Ì¼þ°æÔÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚCisco SPA112ÓÚ2020Äê6ÔÂ1ÈÕÍ£²ú£¬£¬£¬£¬¹©Ó¦É̲»ÔÙ¶ÔËüÌṩ֧³Ö£¬£¬£¬£¬Ò²²»»áÐû²¼Çå¾²¸üС£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬CiscoδÌṩÕë¶Ô¸ÃÎó²îµÄ»º½â²½·¥¡£¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/145763/security/cisco-spa112-2-port-phone-adapters-rce.html
2¡¢¼ÓÄôóConstellation SoftwareÔâµ½ALPHVµÄ¹¥»÷
¾Ý5ÔÂ5ÈÕ±¨µÀ£¬£¬£¬£¬¼ÓÄôó¶àÔª»¯Èí¼þ¹«Ë¾Constellation Software³ÆÆä²¿·ÖϵͳÔâµ½¹¥»÷£¬£¬£¬£¬²¿·ÖСÎÒ˽¼ÒÐÅÏ¢ºÍÉÌÒµÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¡£Constellation͸¶£¬£¬£¬£¬ËüÒѾ×èÖ¹Á˴˴ι¥»÷£¬£¬£¬£¬ÏÖÔÚÒ²»Ö¸´ÁËËùÓÐÊÜÓ°ÏìµÄIT»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¡£¡£ËäÈ»¸Ã¹«Ë¾ÉÐδÌṩ¹ØÓÚ¹¥»÷Õß¼°ÆäÔõÑù»á¼ûϵͳµÄÏêϸÐÅÏ¢£¬£¬£¬£¬µ«ALPHVÔÚÆäÍøÕ¾Ìí¼ÓÁËÒ»¸öÐÂÌõÄ¿£¬£¬£¬£¬³ÆËûÃÇÈëÇÖÁËConstellationµÄϵͳ²¢ÇÔÈ¡ÁËÁè¼Ý1 TBµÄÎļþ¡£¡£¡£¡£¡£¡£¡£¡£ALPHV»¹¹ûÕæÁ˲¿·Ö°üÀ¨ÉÌÒµÐÅÏ¢µÄÎļþ×÷Ϊ¹¥»÷Ö¤¾Ý¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/alphv-gang-claims-ransomware-attack-on-constellation-software/
3¡¢Sentinel LabsÏêÊöKimsukyµÄÐÂÕì̽¹¤¾ßReconShark
5ÔÂ4ÈÕ£¬£¬£¬£¬Sentinel Labs·¢Ã÷ÁËÀ´×ÔKimsukyµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÁËеĶñÒâÈí¼þ×é¼þReconShark£¬£¬£¬£¬Ëüͨ¹ýÓã²æÊ½´¹ÂÚÓʼþ¡¢OneDriveÁ´½ÓÒÔ¼°¶ñÒâºê¾ÙÐзַ¢¡£¡£¡£¡£¡£¡£¡£¡£ReconShark±»ÒÔΪÊÇBabySharkµÄбäÌ壬£¬£¬£¬¿ÉʹÓÃWMIÍøÂçÓйØÄ¿µÄϵͳµÄÐÅÏ¢£¬£¬£¬£¬»¹¼ì²é»úеÉÏÊÇ·ñÔËÐÐÇå¾²Èí¼þ£¬£¬£¬£¬²¢Í¨¹ýHTTP POSTÇëÇó½«Êý¾Ý·¢Ë͵½C2ЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£¡£³ýÁËÇÔÊØÐÅÏ¢Í⣬£¬£¬£¬ReconShark»¹ÒÔ¶à½×¶Î·½·¨°²ÅŸü¶àpayload¡£¡£¡£¡£¡£¡£¡£¡£´Ë´Î»î¶¯Õë¶ÔÃÀ¹ú¡¢Å·ÖÞºÍÑÇÖÞµÄ×éÖ¯ºÍСÎÒ˽¼Ò£¬£¬£¬£¬°üÀ¨Öǿ⡢Ñо¿ÐÍ´óѧºÍÕþ¸®»ú¹¹¡£¡£¡£¡£¡£¡£¡£¡£
https://www.sentinelone.com/labs/kimsuky-evolves-reconnaissance-capabilities-in-new-global-campaign/
4¡¢KasperskyÔÚGoogle Play¼ì²âµ½¶à¸öѬȾFleckpeµÄÓ¦ÓÃ
KasperskyÓÚ5ÔÂ4ÈÕ³ÆÆä·¢Ã÷ÁËÐÂAndroid¶ñÒâÈí¼þFleckpe£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÌ©¹ú¡¢ÂíÀ´Î÷ÑÇ¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢ÐÂ¼ÓÆÂºÍ²¨À¼¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚGoogle Play¼ì²âµ½11¸öѬȾFleckpeµÄÓ¦Ó㬣¬£¬£¬ÕâЩӦÓÃð³äͼÏñ±à¼Æ÷¡¢ÕÕÆ¬¿â¡¢¸ß¼¶±ÚÖ½µÈ£¬£¬£¬£¬Òѱ»×°ÖÃÁè¼Ý620000´Î¡£¡£¡£¡£¡£¡£¡£¡£¸ÃľÂí×Ô2022ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬Ëüͨ¹ýΪÓû§¶©Ôĸ߼¶Ð§ÀͶø±¬·¢Î´¾ÊÚȨµÄÓöȣ¬£¬£¬£¬²¢´ÓÖÐ׬Ǯ¡£¡£¡£¡£¡£¡£¡£¡£ÎªÌá·À´ËÀàÍþв£¬£¬£¬£¬Ñо¿Ö°Ô±½¨ÒéAndroidÓû§½ö´Ó¿ÉÐÅȪԴºÍ¿ª·¢ÉÌÏÂÔØÓ¦Ó㬣¬£¬£¬²¢ÔÚ×°ÖÃÀú³ÌÖÐ×¢ÖØÇëÇóµÄȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£
http://securelist.com/fleckpe-a-new-family-of-trojan-subscribers-on-google-play/109643/
5¡¢Ermetic½üÆÚÔÚAzure APIÖÎÀíЧÀÍÖз¢Ã÷3¸öÎó²î
ýÌå5ÔÂ4Èճƣ¬£¬£¬£¬Ermetic½üÆÚÔÚAzure APIÖÎÀíЧÀÍÖз¢Ã÷3¸öÎó²î¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖаüÀ¨Á½¸öSSRFÎó²îºÍÒ»¸öÎļþÉÏ´«Â·¾¶±éÀúÎó²î¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²îÊÇͨ¹ýurlÃûÌÃÈÆ¹ýºÍAPIÖÎÀí¿ª·¢Ö°Ô±ÃÅ»§ÖеÄÎÞÏÞÖÆÎļþÉÏ´«¹¦Ð§ÊµÏֵġ£¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃSSRFÎó²î£¬£¬£¬£¬¹¥»÷Õ߿ɴÓЧÀ͵ÄCORSÊðÀíºÍÍйÜÊðÀí×Ô¼º·¢ËÍÇëÇ󣬣¬£¬£¬»á¼ûÄÚ²¿Azure×ʲú£¬£¬£¬£¬¾Ü¾øÐ§ÀͲ¢ÈƹýWebÓ¦Ó÷À»ðǽ¡£¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃÎļþÉÏ´«Â·¾¶±éÀúÎó²î£¬£¬£¬£¬¹¥»÷Õ߿ɽ«¶ñÒâÎļþÉÏ´«µ½AzureÍйܵÄÄÚ²¿workload¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬MSRCÒѾÐÞ¸´ÁËÕâ3¸öÎó²î¡£¡£¡£¡£¡£¡£¡£¡£
https://ermetic.com/blog/azure/when-good-apis-go-bad-uncovering-3-azure-api-management-vulnerabilities/
6¡¢AvastÐû²¼¹ØÓÚ2023ÄêµÚÒ»¼¾¶ÈÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ
5ÔÂ4ÈÕ£¬£¬£¬£¬AvastÐû²¼Á˹ØÓÚ2023ÄêµÚÒ»¼¾¶ÈÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬¹¥»÷ÕßһֱѰÕÒеÄÒªÁìÀ´·Ö·¢¶ñÒâÈí¼þ£¬£¬£¬£¬°üÀ¨Ê¹ÓÃMicrosoft OneNoteºÍAdobe Acrobat Sign¡£¡£¡£¡£¡£¡£¡£¡£±¾¼¾¶È£¬£¬£¬£¬Õë¶Ô¶«ÑǵØÇøµÄ¶ñÒâ¹ã¸æÈí¼þ»î¶¯ÏÔÖøÔöÌí¡£¡£¡£¡£¡£¡£¡£¡£ÐÅÏ¢ÇÔÈ¡³ÌÐòÈÔÊÇ×î´óµÄÍþв֮һ£¬£¬£¬£¬ÆäÖÐ×î³£¼ûµÄÊÇAgentTesla¡¢FormBook¡¢RaccoonºÍRedLineµÈ¡£¡£¡£¡£¡£¡£¡£¡£¹ØÓÚÀÕË÷Èí¼þ£¬£¬£¬£¬WannaCryÈÔ´¦ÓÚÁìÏÈְλ£¨Õ¼±È18%£©£¬£¬£¬£¬Æä´ÎÊÇSTOP ransomware(15%)ºÍThanatos(3%)¡£¡£¡£¡£¡£¡£¡£¡£×î³£¼ûµÄRAT°üÀ¨HWorm¡¢Remcos¡¢njRATºÍAsyncRatµÈ¡£¡£¡£¡£¡£¡£¡£¡£
https://decoded.avast.io/threatresearch/avast-q1-2023-threat-report/


¾©¹«Íø°²±¸11010802024551ºÅ