SAPÐû²¼Äþ¾²¸üÐÂÐÞ¸´Ó°ÏìÆä¶à¸ö²úÎïµÄ19¸ö©¶´
Ðû²¼Ê±¼ä 2023-03-161¡¢SAPÐû²¼Äþ¾²¸üУ¬ÐÞ¸´Ó°ÏìÆä¶à¸ö²úÎïµÄ19¸ö©¶´
3ÔÂ14ÈÕ£¬Èí¼þ¹©Ó¦ÉÌSAPÒÑÕë¶Ô19¸ö©¶´Ðû²¼ÁËÄþ¾²¸üС£´Ë´ÎÐÞ¸´µÄ©¶´Ó°ÏìÁËÐí¶à²úÎµ«ÑÏÖصÄ©¶´»áÓ°ÏìSAP Business ObjectsÉÌÒµÖÇÄÜƽ̨(CMC)ºÍSAP NetWeaver¡£´Ë´ÎÐÞ¸´µÄ5¸ö½ÏΪÑÏÖصÄ©¶´·Ö±ðΪ´úÂë×¢È멶´£¨CVE-2023-25616£©¡¢Ä¿Â¼±éÀú©¶´£¨CVE-2023-27269ºÍCVE-2023-27500£©¡¢È±ÉÙÉí·ÝÑéÖ¤¼ì²é©¶´£¨CVE-2023-23857£©ÒÔ¼°ÃüÁîÖ´ÐЩ¶´£¨CVE-2023-25617£©¡£Ñо¿ÈËÔ±½¨ÒéÁ¢¿Ì°²×°²¹¶¡¡£
https://www.bleepingcomputer.com/news/security/sap-releases-security-updates-fixing-five-critical-vulnerabilities/
2¡¢LockBit³Æ´ÓMaximum Industries»ñÈ¡µ½SpaceXµÄÊý¾Ý
¾ÝýÌå3ÔÂ14Èճƣ¬ÀÕË÷ÍÅ»ïLockBitÉù³ÆÈëÇÖÁËÉú²ú¹«Ë¾Maximum IndustriesµÄϵͳ²¢»ñÈ¡µ½SpaceXµÄ»úÃÜÊý¾Ý¡£Maximum IndustriesרÃÅ´ÓÊÂË®µ¶ºÍ¼¤¹âÇиîÒÔ¼°CNC¼Ó¹¤·þÎñ£¬ÊÇSpaceXµÄµÚÈý·½³Ð°üÉÌÖ®Ò»¡£¹¥»÷ÕßÌåÏÖÇÔÈ¡ÁËԼĪ3000ÕÅÓÉspace-x¹¤³ÌʦÈÏÖ¤µÄͼֽ£¬²¢¼Æ»®ÔÚÒ»ÖÜÄÚÌᳫÅÄÂô£¬½«ÕâЩͼֽÂô¸øÆäËûÖÆÔìÉÌ¡£Ä¿Ç°£¬Ñо¿ÈËÔ±ÒѾÁªÏµÁËSpaceXºÍMaximum Industries£¬µ«ËûÃǶ¼Ã»ÓлØÓ¦¡£
https://securityaffairs.com/143495/cyber-crime/lockbit-ransomware-gang-spacex-files.html
3¡¢Ò½ÁƱ£½¡ÌṩÉÌILS͸¶Áè¼Ý420Íò»¼ÕßµÄÐÅϢй¶
ýÌå3ÔÂ15Èճƣ¬Ò½ÁƱ£½¡ÌṩÉÌIndependent Living Systems(ILS)Ðû²¼Í¨ÖªÍ¸Â¶Êý¾Ýй¶Ê¼þÓ°ÏìÁË4226508¸ö»¼Õß¡£¸Ã¹«Ë¾·¢ÏÖÆäϵͳÓÚ2022Äê7ÔÂ5ÈÕÔâµ½¹¥»÷£¬ËæºóÊÓ²ìÏÔʾ¹¥»÷ÕßÔÚ2022Äê6ÔÂ30ÈÕÖÁ7ÔÂ5ÈÕ»ñµÃÁ˲¿ÃÅILSϵͳµÄ·ÃÎÊȨÏÞ¡£Ð¹Â¶ÐÅÏ¢Éæ¼°ÐÕÃû¡¢Éç»áÄþ¾²ºÅÂë¡¢ÄÉË°ÈËʶ±ðºÅºÍÒ½ÁÆÐÅÏ¢µÈ¡£ILSÔÚ·¢ÏÖÎ¥¹æÐÐΪºóµÄÁù¸öÔºó£¬Ò²¾ÍÊÇ2023Äê1ÔÂ17ÈÕÍê³ÉÁËÈ·¶¨ÊÜÓ°Ïì¸öÈË»òʵÌåµÄÄÚ²¿Éó²é¡£×îºó£¬ILSÌåÏÖ½«ÎªÊÜÓ°Ï컼ÕßÌṩΪÆÚÒ»ÄêµÄExperianÉí·Ý±£»¤·þÎñ¡£
https://www.databreaches.net/independent-living-systems-updates-its-breach-disclosure-notifying-more-than-4-2-million-patients/
4¡¢CiscoÅû¶YoroTrooperÕë¶ÔCIS¹ú¼ÒÕþ¸®ºÍÄÜÔ´×éÖ¯µÄ¹¥»÷
CiscoÔÚ3ÔÂ14ÈÕÅû¶ÁËÒ»¸öÐµĹ¥»÷ÍÅ»ïYoroTrooper£¬Ö÷ÒªÕë¶Ô¶ÀÁ¢¹ú¼ÒÁªºÏÌå(CIS)¹ú¼ÒµÄÕþ¸®ºÍÄÜÔ´×éÖ¯¡£¸ÃÍÅ»ïÖÁÉÙ´Ó2022Äê6Ô¿ªÊ¼»îÔ¾£¬ÒѾÈëÇÖÁËÒ»¸ö´ÓÊÂÒ½ÁƱ£½¡µÄÖØҪŷÃË»ú¹¹¡¢ÊÀ½ç֪ʶ²úȨ×éÖ¯(WIPO)ºÍ¶à¸öÅ·ÖÞ´óʹ¹Ý¡£YoroTrooperµÄ¹¤¾ß°üÂÞÉÌÆ·ºÍ×Ô½ç˵ÐÅÏ¢ÇÔÈ¡·¨Ê½¡¢Ô¶³Ì·ÃÎÊľÂíºÍ»ùÓÚPythonµÄ¶ñÒâÈí¼þ£¬Ñ¬È¾Á´ÓɶñÒâ¿ì½Ý·½Ê½Îļþ(LNK)ºÍ¿ÉÑ¡µÄÓÕ¶üÎļþ×é³É¡£
https://blog.talosintelligence.com/yorotrooper-espionage-campaign-cis-turkey-europe/
5¡¢ESET·¢ÏÖTickÕë¶Ô¶«ÑÇijDLPÈí¼þ¿ª·¢É̵Ĺ¥»÷»î¶¯
3ÔÂ14ÈÕ£¬ESET³ÆÆä·¢ÏÖÁËAPT×éÖ¯TickÕë¶Ô¶«ÑÇÒ»¼Ò¿ª·¢Êý¾Ý¶ªÊ§·À»¤(DLP)Èí¼þµÄ¹«Ë¾µÄ»î¶¯¡£¹¥»÷ÕßÈëÇÖÁ˸ù«Ë¾µÄÄÚ²¿¸üзþÎñÆ÷£¬ÔÚÈí¼þ¿ª·¢É̵ÄϵͳÄÚÁ÷´«¶ñÒâÈí¼þ£¬²¢Ä¾Âí»¯¸Ã¹«Ë¾Ê¹ÓõĺϷ¨¹¤¾ßµÄ°²×°·¨Ê½£¬×îÖÕµ¼ÖÂÔÚ¹«Ë¾¿Í»§µÄ¼ÆËã»úÉÏÖ´ÐжñÒâÈí¼þ¡£ÔÚÈëÇÖ¹ý³ÌÖУ¬¹¥»÷Õß°²×°ÁËÒ»¸öеÄÏÂÔØ·¨Ê½ShadowPy£¬»¹ÀûÓÃÁ˺óÃÅNetboy£¨ÓÖÃûInvader£©ºÍÏÂÔØ·¨Ê½Ghostdown¡£
https://www.welivesecurity.com/2023/03/14/slow-ticking-time-bomb-tick-apt-group-dlp-software-developer-east-asia/
6¡¢Check PointÐû²¼¹ØÓÚAndroidľÂíFakeCallsµÄ·ÖÎö³ÂËß
Check PointÔÚ3ÔÂ14ÈÕÐû²¼Á˹ØÓÚAndroidľÂíFakeCallsµÄ·ÖÎö³ÂËß¡£ÕâÖÖ¶ñÒâÈí¼þ¿ÉÒÔαװ³É20¶àÖÖ½ðÈÚÓ¦Ó㬲¢Ä£·ÂÓëÒøÐлò½ðÈÚ·þÎñÔ±¹¤µÄµç»°½»Ì¸½øÐÐÓïÒôµöÓã¹¥»÷¡£FakeCallsÖ÷ÒªÕë¶Ôº«¹ú£¬¾ßÓÐÈðÊ¿¾üµ¶µÄ¹¦Ð§£¬²»½öÄܹ»Ö´ÐÐÆäÖ÷ÒªÈÎÎñ£¬¶øÇÒÄܹ»´ÓÄ¿±êÉ豸ÖÐÇÔÈ¡¸öÈËÊý¾Ý¡£Ñо¿ÈËÔ±³ÆÆä·¢ÏÖÁË2500¶à¸öFakeCallsÑù±¾£¬ËüÃÇʹÓÃÁËÖÖÖÖÄ£Äâ½ðÈÚ×éÖ¯µÄ×éºÏ²¢ÊµÊ©ÁË ·´·ÖÎö¼¼Êõ¡£
https://research.checkpoint.com/2023/south-korean-android-banking-menace-fakecalls/