CiscoÐû²¼Äþ¾²¸üÐÂÐÞ¸´IP PhoneϵÁвúÎïÖЩ¶´
Ðû²¼Ê±¼ä 2023-03-031¡¢CiscoÐû²¼Äþ¾²¸üÐÂÐÞ¸´IP PhoneϵÁвúÎïÖЩ¶´
CiscoÔÚ3ÔÂ1ÈÕÐû²¼Äþ¾²¸üУ¬ÐÞ¸´Ó°ÏìÆäIP Phone 6800¡¢7800¡¢7900ºÍ8800ϵÁвúÎïµÄ©¶´¡£ÕâÊÇ»ùÓÚWebµÄ¹ÜÀí½çÃæÖеÄÃüÁî×¢Èë©¶´£¨CVE-2023-20078£©£¬CVSSÆÀ·ÖΪ9.8£¬ÊÇÓÉÓÚ¶ÔÓû§ÌṩµÄÊäÈëµÄÑéÖ¤²»³äʵµ¼Öµģ¬ÀֳɵÄÀûÓôË©¶´¿ÉÔÚÊÜÓ°ÏìÉ豸µÄµ×²ã²Ù×÷ϵͳÉÏÖ´ÐÐÈÎÒâÃüÁî¡£´ËÍ⣬¸Ã¹«Ë¾»¹Åû¶ÁËDoS©¶´£¨CVE-2023-20079£©£¬Ò²ÊǶÔÓû§ÌṩµÄÊäÈëµÄÑéÖ¤²»³äʵµ¼Öµģ¬¿É±»ÓÃÀ´´¥·¢DoSÌõ¼þ¡£
https://thehackernews.com/2023/03/critical-flaw-in-cisco-ip-phone-series.html
2¡¢Exchange Online·ºÆðBugµ¼ÖÂÈ«ÇòÓû§ÎÞ·¨·ÃÎÊ
¾ÝýÌå3ÔÂ1ÈÕ±¨µÀ£¬MicrosoftÕýÔÚÊÓ²ìÈ«ÇòExchange OnlineÓû§ÎÞ·¨·ÃÎÊÆäÓÊÏäµÄÎÊÌâ¡£´Ó3ÔÂ1ÈÕ1:11 PM UTC¿ªÊ¼£¬ÊÜÓ°ÏìÓû§ÔÚ·¢ËÍ»ò½ÓÊÕÓʼþʱ»á¿´µ½"550 5.4.1 Recipient address rejected: Access denied"µÄ´íÎóÌáʾ¡£MicrosoftÔÚ5:22 PM UTC³ÆÒѾ·¢ÏÖÁËÒ»¸öDZÔڵĻùÓÚĿ¼µÄ±ßÔµ·âËø£¨DBEB£©ÎÊÌâ¡£16:01 EST£¬MicrosoftÌåÏÖ£¬Í¨¹ýExchange Online Protection(EOP)Á÷Á¿ÔÚÊÜÓ°ÏìµÄ»ù´¡ÉèÊ©ÖÐÖØÐÂÅäÖ÷ÓÉ£¬½â¾öÁ˸ÃÎÊÌâ¡£
https://www.bleepingcomputer.com/news/security/microsoft-exchange-online-outage-blocks-access-to-mailboxes-worldwide/
3¡¢eSentireÅû¶Õë¶Ô¶à¸öÂÉʦÊÂÎñËùµÄ¹¥»÷»î¶¯µÄÏêÇé
eSentireÓÚ2ÔÂ28ÈÕÅû¶ÁËÔÚ2023Äê1ÔºÍ2ÔÂÕë¶Ô6¼Ò²îÒìµÄÂÉʦÊÂÎñËùµÄ¹¥»÷¡£ÕâЩ¹¥»÷Ô´×ÔÁ½¸ö²îÒìµÄ¹¥»÷»î¶¯£¬ÆäÖÐÖ®Ò»ÊÔͼÓöñÒâÈí¼þGootLoaderѬȾÂÉʦÊÂÎñËùµÄÔ±¹¤£¬ÁíÒ»³¡»î¶¯Ê¹ÓöñÒâÈí¼þSocGholish¹¥»÷ÂÉʦÊÂÎñËùÔ±¹¤ºÍÆäËüÄ¿±ê¡£GootLoader»î¶¯Ê¹ÓÃËÑË÷ÒýÇæÓÅ»¯(SEO)Öж¾£¬ÆäÈëÇÖÁ˺Ϸ¨µÄWordPressÍøÕ¾£¬²¢ÀûÓá°ÐÒ顱µÈÒªº¦×ÖÓÕʹĿ±êÏÂÔØ¶ñÒâÈí¼þ¡£SocGholish»î¶¯ÀûÓÃÁËÂÉʦÊÂÎñËù¾³£¹â¹ËµÄÍøÕ¾½øÐÐË®¿Ó¹¥»÷£¬ÒÔÐé¼ÙµÄä¯ÀÀÆ÷¸üÐÂΪÓÕ¶üÁ÷´«¶ñÒâÈí¼þ¡£
https://www.esentire.com/blog/hackers-attack-employees-from-six-law-firms-with-the-gootloader-and-socgholish-malware-using-fake-legal-agreements-and-malicious-watering-hole-s-reports-esentire
4¡¢°µÍøBidenCashÖÜÄê»î¶¯¹ûÈ»200¶àÍòÕÅÐÅÓÿ¨µÄÐÅÏ¢
¾Ý3ÔÂ2ÈÕ±¨µÀ£¬Ò»¸ö°µÍøÐÅÓÿ¨Êг¡BidenCash¹ûÈ»ÁËÁè¼Ý200ÍòÕÅÓÐЧÐÅÓÿ¨µÄÐÅÏ¢£¬×÷ΪÆäÖÜÄê´ÙÏú»î¶¯µÄÒ»²¿ÃÅ¡£ÕâЩÐÅÓÿ¨À´×ÔÊÀ½ç¸÷µØ£¬ÆäÖдó²¿ÃÅÊÇÔÚÃÀ¹ú¡¢Ä«Î÷¸ç¡¢Ó¡¶È¡¢¼ÓÄôóºÍÓ¢¹ú¿¯Ðеġ£Ð¹Â¶µÄÐÅÏ¢°üÂÞ³Ö¿¨È˵ÄÐÕÃû¡¢¿¨ºÅ¡¢ÒøÐÐÏêϸÐÅÏ¢¡¢ÓÐЧÆÚ¡¢¿¨ÑéÖ¤Öµ(CVV)¡¢¼ÒͥסַºÍÁè¼Ý500000¸öÓʼþµØÖ·¡£Ä¿Ç°£¬BidenCashÇÔÈ¡ÐÅÏ¢µÄ·½Ê½Éв»Ã÷È·£¬Õþ¸®ÕýÔÚÊÓ²ìÕâÆðʼþ£¬²¢½¨ÒéÊÜÓ°ÏìµÄ³Ö¿¨ÈË¼à¿ØËûÃǵÄÕË»§¡£
https://www.hackread.com/bidencash-leaks-2-million-credit-cards/
5¡¢Ó¢¹úÁãÊÛÉ̵êWH Smith³ÆÆäÔ±¹¤Êý¾ÝÔâµ½·Ç·¨·ÃÎÊ
ýÌå3ÔÂ2Èճƣ¬Ó¢¹úÁãÊÛÉ̵êWH SmithÔâµ½¹¥»÷£¬ÏÖÔ±¹¤ºÍǰԱ¹¤µÄÐÅϢй¶¡£¸Ã¹«Ë¾ÔÚÓ¢¹ú¾Óª×Å1700¸öÉ̵꣬ӵÓÐÁè¼Ý12500ÃûÔ±¹¤£¬2022ÄêµÄÊÕÈëΪ16.7ÒÚÃÀÔª¡£¸Ã¹«Ë¾ÌåÏÖ£¬´Ë´Îʼþµ¼Ö¹«Ë¾µÄ²¿ÃÅÊý¾Ý±»·Ç·¨·ÃÎÊ£¬µ«²¢Î´Ó°ÏìÆäóÒ×ÒµÎñ¡£¿Í»§ÐÅϢûÓÐÊܵ½Ó°Ï죬ÒòΪÕâЩÐÅÏ¢´æ´¢ÔÚµ¥¶ÀµÄϵͳÉÏ¡£¸Ã¹«Ë¾Ã»ÓÐ͸¶Ê¼þµÄÐÔÖÊ£¬µ«¿ÉÄÜÊÇÀÕË÷Èí¼þ¹¥»÷¡£ËäȻûÓйØÓÚ¹¥»÷ÈÕÆÚµÄÏêϸÐÅÏ¢£¬µ«¹¥»÷Ó¦¸ÃÊÇ·¢ÉúÔÚ1ÔÂ18ÈÕÖ®ºó¡£
https://www.bleepingcomputer.com/news/security/british-retail-chain-wh-smith-says-data-stolen-in-cyberattack/
6¡¢TrendMicroÐû²¼APT27¶ñÒâÈí¼þSysUpdateµÄ·ÖÎö³ÂËß
3ÔÂ1ÈÕ£¬Trend MicroÐû²¼ÁËAPT27£¨Iron Tiger£©Linux°æ±¾×Ô½ç˵¶ñÒâÈí¼þSysUpdateµÄ·ÖÎö³ÂËß¡£ºÚ¿ÍÓÚ2022Äê7ÔÂÊ״βâÊÔÁËLinux°æ±¾£¬È»¶øÖ±µ½2022Äê10Ô£¬¶à¸öpayload²Å¿ªÊ¼ÔÚÒ°ÍâÁ÷´«¡£¸ÃLinux±äÌåÊÇÒ»¸öELF¿ÉÖ´ÐÐÎļþ£¬Ê¹ÓÃAsio¿âÓÃC++¿ª·¢£¬Æä¹¦Ð§ÓëWindows°æSysUpdate·Ç³£ÏàËÆ£¬ÐÂÔöÁËDNSËíµÀ¹¦Ð§¡£Trend MicroÌåÏÖ£¬Ñ¡ÔñAsio¿âÀ´¿ª·¢Linux°æ±¾µÄSysUpdate¿ÉÄÜÊÇÒòΪËüµÄ¶àƽ̨¿ÉÒÆÖ²ÐÔ£¬²¢Ô¤²âmacOS°æ±¾¿ÉÄܺܿì¾Í»á·ºÆð¡£
https://www.trendmicro.com/en_us/research/23/c/iron-tiger-sysupdate-adds-linux-targeting.html