¼ÓÄôóYellow PagesÔâµ½Black BastaµÄÀÕË÷¹¥»÷

Ðû²¼Ê±¼ä 2023-04-26

1¡¢¼ÓÄôóYellow PagesÔâµ½Black BastaµÄÀÕË÷¹¥»÷


¾ÝýÌå4ÔÂ24ÈÕ±¨µÀ£¬¼ÓÄôóĿ¼³öÊéÉÌYellow Pages Group͸¶ÆäÔâµ½ÁËÍøÂç¹¥»÷¡£Black BastaÉù³ÆÆäΪ´Ë´Î¹¥»÷ÂôÁ¦£¬²¢¹ûÈ»Á˰üÂÞÉí·ÝÖ¤¼þ¡¢Ë°ÎñÎļþºÍÂòÂôЭÒéµÈÐÅÏ¢µÄÎļþÑù±¾¡£Æ¾¾Ýй¶ÎļþµÄÈÕÆÚ¿ÉÒÔÈ·¶¨£¬¹¥»÷ËÆºõ·¢ÉúÔÚ3ÔÂ15ÈÕ»òÖ®ºó¡£¸Ã¹«Ë¾¶Ô´ËÊÂÕ¹¿ªÊӲ죬·¢ÏÖÔ±¹¤Êý¾ÝºÍÉÌÒµ¿Í»§µÄÏà¹ØÐÅϢй¶¡£ËûÃÇÏÖÒÑ֪ͨÊÜÓ°ÏìµÄ¸öÈË£¬²¢ÌåÏÖĿǰ»ù±¾ÉÏÒѾ­»Ö¸´ÁËËùÓзþÎñ¡£


https://www.bleepingcomputer.com/news/security/yellow-pages-canada-confirms-cyber-attack-as-black-basta-leaks-data/


2¡¢VMwareÐÞ¸´ÔÚPwn2OwnºÚ¿Í´óÈüÖб»ÀûÓõÄÁ½¸ö©¶´


¾Ý4ÔÂ25ÈÕ±¨µÀ£¬VMwareÐû²¼Äþ¾²¸üУ¬ÐÞ¸´ÁËÔÚPwn2Own Vancouver 2023ºÚ¿Í´óÈüÉÏÑÝʾµÄÁ½¸ö©¶´¡£µÚÒ»¸öÊÇÀ¶ÑÀÉ豸¹²Ïí¹¦Ð§ÖлùÓÚ¶ÑÕ»µÄ»º³åÇøÒç³ö©¶´(CVE-2023-20869)£¬¿É±»µ±µØ¹¥»÷ÕßÓÃÀ´×÷ΪÖ÷»úÉÏÔËÐеÄÐéÄâ»úVMX½ø³ÌÖ´ÐдúÂë¡£µÚ¶þ¸öÊÇÓëVM¹²ÏíÖ÷»úÀ¶ÑÀÉ豸µÄ¹¦Ð§ÖеÄÐÅϢй¶©¶´(CVE-2023-20870)£¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´´ÓVM¶ÁÈ¡¹ÜÀí·¨Ê½ÄÚ´æÖаüÂÞµÄÌØÈ¨ÐÅÏ¢¡£VMware»¹ÎªÎÞ·¨Á¢¼´°²×°²¹¶¡µÄÓû§ÌṩÁËÁÙʱ½â¾öÒªÁ죬¼´¹Ø±ÕÐéÄâ»úÉϵÄÀ¶ÑÀÖ§³Ö¡£


https://securityaffairs.com/145287/security/vmware-fixes-critical-zero-days-pwn2own.html


3¡¢KasperskyÅû¶TomirisÕë¶ÔÖÐÑǵØÓòÊÕ¼¯Ç鱨µÄ»î¶¯


4ÔÂ24ÈÕ£¬KasperskyÅû¶ÁËTomirisÔÚÖÐÑǵØÓòµÄ×îл¡£¹¥»÷Ö÷ÒªÕë¶ÔCIS¹ú¼ÒµÄÕþ¸®ºÍÍâ½»»ú¹¹£¬ÆäÌØµãÊÇÇãÏòÓÚʹÓûù±¾µ«ÓÐЧµÄ´ò°üºÍ·Ö·¢¼¼Êõ£¬Å¼¶û»áÀûÓÃÉÌÒµ»ò¿ªÔ´RAT¡£TomirisʹÓÃÁËÖÖÖÖ¸÷ÑùµÄ¶ñÒâÈí¼þÖ²È뷨ʽ£¬ËüÃǵĿª·¢ËٶȺܿ죬²¢Ê¹ÓÃÁËËùÓпÉÒÔÏëÏóµÄ±à³ÌÓïÑÔ¡£TomirisʹÓõŤ¾ß¿É·ÖΪÈýÀࣺÏÂÔØ·¨Ê½¡¢ºóÃźÍÎļþÇÔÈ¡·¨Ê½¡£´ËÍ⣬¸Ã»î¶¯ÖÐʹÓõÄKopiLuwakºÍTunnusSched½«ÆäÓëTurlaÁªÏµÆðÀ´¡£


https://securelist.com/tomiris-called-they-want-their-turla-malware-back/109552/


4¡¢Ñо¿ÈËÔ±ÑÝʾÕë¶ÔIntel CPUµÄÐÂÐͲàÐŵÀ¹¥»÷ÒªÁì


4ÔÂ24ÈÕ±¨µÀ³Æ£¬Ñо¿ÈËÔ±·¢ÏÖÁËÓ°Ïì¶à´úIntel CPUµÄÐÂÐͲàÐŵÀ¹¥»÷ÒªÁ죬¿Éͨ¹ýEFLAGS¼Ä´æÆ÷й¶Êý¾Ý¡£ÕâÖÖ¹¥»÷²»ÏñÆäËü²àÐŵÀ¹¥»÷ÄÇÑùÒÀÀµ»º´æÏµÍ³£¬¶øÊÇÀûÓÃ˲ִ̬ÐÐÖеÄÒ»¸ö©¶´£¬Í¨¹ýʱÐò·ÖÎö´ÓÓû§ÄÚ´æ¿Õ¼äÖÐÇÔÈ¡Êý¾Ý¡£¹¥»÷·ÖÁ½¸ö½×¶Î£¬µÚÒ»½×¶ÎÊÇ´¥·¢Ë²Ê±Ö´ÐУ¬²¢Í¨¹ýEFLAGS¼Ä´æÆ÷±àÂë»úÃÜÊý¾Ý£¬µÚ¶þ½×¶ÎÊÇÕÉÁ¿KCCÖ¸ÁîµÄÖ´ÐÐʱ¼äÀ´½âÂëÊý¾Ý¡£È»¶ø£¬Ñо¿ÈËÔ±Ö¸³ö£¬ÕâÖÖ¶¨Ê±¹¥»÷²»È绺´æ×´Ì¬µÄ²àÐŵÀ¹¥»÷¿É¿¿£¬ÒªÏëÔÚ×î½üµÄоƬÖÐÈ¡µÃ¸üºÃµÄ½á¹û£¬¾Í±ØÐ뽫¹¥»÷ÖØ¸´Êýǧ´Î¡£


https://www.bleepingcomputer.com/news/security/intel-cpus-vulnerable-to-new-transient-execution-side-channel-attack/


5¡¢Î¢ÈíÔٴηºÆð¹ÊÕÏ£¬¶à¸ö·þÎñÖеÄËÑË÷¹¦Ð§ÎÞ·¨Ê¹ÓÃ


ýÌå4ÔÂ24Èճƣ¬Î¢ÈíÕýÔÚÊÓ²ìÓû§ÎÞ·¨ÔÚ¶à¸öMicrosoft 365·þÎñÖÐʹÓÃËÑË÷¹¦Ð§µÄÎÊÌâ¡£¸ÃÎÊÌâÓ°ÏìÁËOutlook¡¢ExchangeºÍSharePointµÈ·þÎñ¡£Óë´Ëͬʱ£¬Î¢Èí»¹ÔÚ½â¾öÁíÒ»¸öÓ°ÏìÁËTeamsµÄÎÊÌ⣬ÓÐÓû§³ÂËß˵ÔÚÆô¶¯Èí¼þʱ¿´µ½´íÎó¡£½ØÖÁ4ÔÂ25ÈÕ10:20 EDT£¬Î¢Èí³Æ´ó¶àÊýÓû§µÄMicrosoft 365ËÑË÷ÎÊÌâÒѵõ½½â¾ö¡£ÉÏÖÜ£¬Î¢ÈíÒ²Ôø·ºÆð¹ÊÕÏ£¬µ¼Ö¶à¸öMicrosoft 365·þÎṉ̃»¾£¬È«ÇòÓû§ÎÞ·¨µÇ¼ÕË»§¡£


https://www.bleepingcomputer.com/news/security/microsoft-365-search-outage-affects-outlook-teams-and-sharepoint/


6¡¢JFrogÐû²¼¹ØÓÚ¶ñÒâÈí¼þWhiteSnakeµÄ·ÖÎö³ÂËß


4ÔÂ24ÈÕ£¬JFrogÐû²¼ÁËÕë¶ÔPython¿ª·¢ÈËÔ±µÄ¶ñÒâÈí¼þWhiteSnakeµÄ·ÖÎö³ÂËß¡£Ñо¿ÈËÔ±×î½üÔÚPyPI´æ´¢¿âÖз¢ÏÖÁËÒ»¸öÓÃC#¿ª·¢µÄжñÒâÈí¼þpayload¡£Í¨¹ý¼ì²âÈ·¶¨ÁË22¸ö°üÂÞÏàͬpayloadµÄ¶ñÒâ°ü£¬Í¬Ê±Õë¶ÔWindowsºÍLinuxϵͳ¡£ÆäÖУ¬Õë¶ÔWindowsµÄpayload±»È·¶¨ÎªWhiteSnakeµÄ±äÌ壬¾ßÓз´VM»úÖÆ£¬Ê¹ÓÃTorЭÒéÓëC2·þÎñÆ÷ͨÐÅ£¬¶øÇÒÄܹ»´ÓÄ¿±êÇÔÈ¡ÐÅÏ¢²¢Ö´ÐÐÃüÁî¡£¶øLinux°æ±¾µÄpayloadÊÇÒ»¸ö¼òµ¥µÃ¶àµÄPython½Å±¾£¬×¨×¢ÓÚÐÅÏ¢ÇÔÈ¡¡£


https://jfrog.com/blog/new-malware-targets-python-developers-uses-tor-for-c2-communication/