ZimbraÐÞ¸´ZCSÖÐÒѱ»Ê¹ÓõÄXSSÎó²îCVE-2023-38750
Ðû²¼Ê±¼ä 2023-08-011¡¢ZimbraÐÞ¸´ZCSÖÐÒѱ»Ê¹ÓõÄXSSÎó²îCVE-2023-38750
¾ÝýÌå7ÔÂ27ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬ZimbraÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÕë¶ÔZimbra Collaboration Suite(ZCS)µç×ÓÓʼþЧÀÍÆ÷µÄ¹¥»÷Öб»Ê¹ÓõÄÎó²î¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öXSSÎó²î£¨CVE-2023-38750£©£¬£¬£¬£¬£¬£¬¿ÉÄܱ»ÓÃÀ´ÇÔÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£ËäÈ»ZimbraÔÚÊ×´ÎÅû¶¸ÃÎó²î²¢±Þ²ßÓû§ÊÖ¶¯ÐÞ¸´Ê±£¬£¬£¬£¬£¬£¬²¢Î´Åú×¢¸ÃÎó²îÒѱ»Ê¹Óà £¬£¬£¬£¬£¬£¬µ«Google TAG͸¶£¬£¬£¬£¬£¬£¬¸ÃÎó²îÊÇÔÚÓÐÕë¶ÔÐԵĹ¥»÷Öб»·¢Ã÷µÄ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬CISAÒ²Ðû²¼ÁËͨ¸æ£¬£¬£¬£¬£¬£¬ÒªÇóÁª°î»ú¹¹ÔÚ8ÔÂ17ÈÕ֮ǰÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/zimbra-patches-zero-day-vulnerability-exploited-in-xss-attacks/
2¡¢Tempur SealyÔâµ½ÍøÂç¹¥»÷µ¼Ö¹«Ë¾ÔËÓªÔÝʱÖÐÖ¹
¾Ý8ÔÂ1ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬´²µæÏúÊÛÉÌTempur SealyÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬ÆÈʹ²¿·ÖϵͳÔÝʱ¹Ø±Õ¡£¡£¡£¡£¡£¡£¡£Tempur Sealy±»ÒÔΪÊÇÈ«Çò×î´óµÄ´²ÉÏÓÃÆ·¹©Ó¦ÉÌ£¬£¬£¬£¬£¬£¬Éϼ¾¶È¾»ÏúÊÛ¶îΪ12ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ±¾ÖÜһ͸¶£¬£¬£¬£¬£¬£¬ÓÚ7ÔÂ23ÈÕÔâµ½Á˹¥»÷£¬£¬£¬£¬£¬£¬Æä½ÓÄÉÏìÓ¦²½·¥×Ô¶¯¹Ø±ÕÁ˲¿·ÖITϵͳ£¬£¬£¬£¬£¬£¬Õâµ¼Ö¹«Ë¾ÔËÓªÔÝʱÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒÑ×îÏȽ«²¿·ÖÖ÷ÒªµÄÏµÍ³ÖØÐÂÉÏÏß²¢»Ö¸´ÔËÓª¡£¡£¡£¡£¡£¡£¡£ÊÓ²ìÈÔÔÚ¾ÙÐÐÖУ¬£¬£¬£¬£¬£¬ÒÔÈ·¶¨¶ÔÓªÒµºÍ²ÆÎñ±¬·¢µÄÓ°Ï죬£¬£¬£¬£¬£¬Éв»ÇåÎúÊÇ·ñÉæ¼°¿Í»§»òÔ±¹¤ÐÅÏ¢£¬£¬£¬£¬£¬£¬ÒÔ¼°¹¥»÷ÕßµÄÉí·Ý¡£¡£¡£¡£¡£¡£¡£
https://therecord.media/mattress-giant-tempur-sealy-cyberattack
3¡¢²éËþŬ¼ÓÐÄÔàÑо¿Ëùת´ïÉæ¼°17ÍòÈ˵ÄÊý¾Ýй¶ÊÂÎñ
7ÔÂ29ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬£¬²éËþŬ¼ÓÐÄÔàÑо¿Ëù£¨Chattanooga Heart Institute£¬£¬£¬£¬£¬£¬CHI£©×ª´ïÁËÉæ¼°17ÍòÈ˵ÄÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£5Ô·ݣ¬£¬£¬£¬£¬£¬KarakurtÍÅ»ï³Æ¹¥»÷Á˸ûú¹¹£¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁË158GBµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßûÓÐÌṩ֤¾Ý£¬£¬£¬£¬£¬£¬µ«ÌåÏÖй¶Êý¾Ý°üÀ¨Ò½ÁƼͼ¡¢¼ì²éЧ¹û¡¢Õï¶Ï¡¢Éç»áÇå¾²ºÅÂë¡¢»¤ÕÕ¡¢ºÍ²ÆÎñÐÅÏ¢µÈ£¬£¬£¬£¬£¬£¬ÆäʱCHI²¢Î´»ØÓ¦´ËÊÂÎñ¡£¡£¡£¡£¡£¡£¡£7ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬CHI͸¶ÓÐ170450ÈËÊܵ½Êý¾Ýй¶ÊÂÎñµÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£ËûÃÇÓÚ4ÔÂ17ÈÕ¼ì²âµ½¹¥»÷¼£Ï󣬣¬£¬£¬£¬£¬È·¶¨ÏµÍ³ÔÚ3ÔÂ8ÈÕÖÁ16ÈÕʱ´úÔø±»»á¼û¹ý¡£¡£¡£¡£¡£¡£¡£Ö±µ½5ÔÂ31ÈÕ£¬£¬£¬£¬£¬£¬CHI²ÅµÃÖª»¼ÕߵĿµ½¡ÐÅÏ¢ºÍµ£±£ÈËÐÅÏ¢±»Ð¹Â¶¡£¡£¡£¡£¡£¡£¡£
https://www.databreaches.net/the-chattanooga-heart-institute-to-notify-170450-about-march-data-security-incident/
4¡¢ÃÀ¹úSAISÊý¾Ý¿âÉèÖùýʧй¶572 GBѧÉúºÍÎ÷ϯµÄÐÅÏ¢
ýÌå7ÔÂ28ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öδÊܱ£»£»£»£»£»¤µÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Óë½ÌÓý»ú¹¹Ïà¹ØµÄ682438Ìõ¼Í¼¡£¡£¡£¡£¡£¡£¡£ÊӲ췢Ã÷£¬£¬£¬£¬£¬£¬Êý¾Ý¿âÊôÓÚÄÏ·½×ÔÁ¦Ñ§Ð£Ð»á(SAIS)£¬£¬£¬£¬£¬£¬ÕâÊÇλÓÚÃÀ¹úµÄÒ»¸ö×ÔÔ¸ÐÔµØÇøÈÏ֤лᡣ¡£¡£¡£¡£¡£¡£´Ë´Îй¶µÄÊý¾Ý¹²572.8 GB£¬£¬£¬£¬£¬£¬Ê±¼ä¿ç¶È´Ó2012Äêµ½2023Ä꣬£¬£¬£¬£¬£¬°üÀ¨Ñ§ÉúºÍÎ÷ϯ¼Í¼¡¢¿µ½¡ÐÅÏ¢¡¢Éç»áÇå¾²ºÅÂ롢ǹ»÷°¸ºÍ·â±Õ֪ͨ¡¢Ñ§Ð£µØÍ¼ºÍ²ÆÎñÔ¤ËãµÈ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÒѱ»±£»£»£»£»£»¤ÆðÀ´¡£¡£¡£¡£¡£¡£¡£
https://www.hackread.com/data-leak-student-faculty-accreditation-org/
5¡¢GoogleÐû²¼¹ØÓÚ2022Äê¶È0dayÎó²îµÄ»ØÊ×±¨¸æ
7ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬GoogleÐû²¼ÁËÄê¶È0dayÎó²î±¨¸æ£¬£¬£¬£¬£¬£¬ÌṩÁË2022ÄêÒÔÀ´µÄÒ°ÍâʹÓÃͳ¼ÆÊý¾Ý¡£¡£¡£¡£¡£¡£¡£2022Äê¼ì²â²¢Åû¶ÁË41¸öÔÚÒ°µÄ0day£¬£¬£¬£¬£¬£¬ÆäÖÐÉϰëÄê20¸ö£¬£¬£¬£¬£¬£¬Ï°ëÄê21¸ö£¬£¬£¬£¬£¬£¬½ö´ÎÓÚ2021ÄêµÄ69¸öÎó²î¡£¡£¡£¡£¡£¡£¡£ÔÚAndroidÖУ¬£¬£¬£¬£¬£¬±£´æ¶àÖÖÇéÐΣ¬£¬£¬£¬£¬£¬Óû§Ôںܳ¤Ò»¶Îʱ¼äÄÚÎÞ·¨»ñµÃ²¹¶¡¡£¡£¡£¡£¡£¡£¡£Òò´Ë¹ØÓÚ¹¥»÷ÕßÀ´Ëµ£¬£¬£¬£¬£¬£¬NdayµÄ¹¦Ð§ÀàËÆÓÚ0day¡£¡£¡£¡£¡£¡£¡£ÔÚ2022ÄêµÄ41¸ö0dayÖУ¬£¬£¬£¬£¬£¬ÓÐ17¸öÊÇ֮ǰ±¨¸æµÄÎó²îµÄ±äÌ壬£¬£¬£¬£¬£¬Õ¼±ÈÁè¼Ý40%¡£¡£¡£¡£¡£¡£¡£
https://security.googleblog.com/2023/07/the-ups-and-downs-of-0-days-year-in.html
6¡¢KasperskyÐû²¼2023ÄêQ2 APT¹¥»÷Ì¬ÊÆµÄÆÊÎö±¨¸æ
7ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬KasperskyÐû²¼ÁË2023ÄêQ2 APT¹¥»÷Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£±¾¼¾¶ÈµÄÖ÷ÒªÁÁµãÖ®Ò»ÊÇ·¢Ã÷Á˺ã¾ÃÔËÓªµÄOperation Triangulation»î¶¯£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨ÐµÄiOS¶ñÒâÈí¼þƽ̨¡£¡£¡£¡£¡£¡£¡£APT»î¶¯ÔÚµØÀíÂþÑÜÉÏÈÔÈ»ºÜÊèÉ¢£¬£¬£¬£¬£¬£¬±¾¼¾¶È£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÖ÷ÒªÕë¶ÔÅ·ÖÞ¡¢À¶¡ÃÀÖÞ¡¢Öж«ºÍÑÇÖÞ¸÷µØ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬³ÉÊìµÄ¹¥»÷ÕßÔÚÒ»Ö±ÔöÇ¿Æä¹¤¾ß£¬£¬£¬£¬£¬£¬ÈçLazarus¿ª·¢ÁËMATA¿ò¼Ü¡¢BlueNoroffʹÓÃÁËеĴ«Êä·½·¨ºÍ±à³ÌÓïÑÔ¡¢ScarCruftʹÓÃÁËеÄѬȾ·½·¨ÒÔ¼°GoldenJackalеĶñÒâÈí¼þÑù±¾¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»¹·¢Ã÷ÁËй¥»÷ÕßMysterious ElephantµÄ»î¶¯¡£¡£¡£¡£¡£¡£¡£
https://securelist.com/apt-trends-report-q2-2023/110231/


¾©¹«Íø°²±¸11010802024551ºÅ