CiscoÅû¶ÆäSPA112 2-Portµç»°ÊÊÅäÆ÷ÖеÄRCE©¶´

Ðû²¼Ê±¼ä 2023-05-06

1¡¢CiscoÅû¶ÆäSPA112 2-Portµç»°ÊÊÅäÆ÷ÖеÄRCE©¶´

 

¾ÝýÌå5ÔÂ4ÈÕ±¨µÀ £¬CiscoÅû¶ÁËÆäSPA112 2-Portµç»°ÊÊÅäÆ÷ÖлùÓÚWebµÄ¹ÜÀí½çÃæÖеÄ©¶´ £¬¿É±»Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÓÃÓÚÖ´ÐÐÈÎÒâ´úÂë ¡£¸Ã©¶´×·×ÙΪCVE-2023-20126£¨CVSSÆÀ·Ö9.8£© £¬ÊÇÓÉÓڹ̼þÉý¼¶¹¦Ð§ÖÐȱÉÙÉí·ÝÑéÖ¤¹ý³ÌÔì³ÉµÄ £¬¹¥»÷Õß¿ÉÒÔͨ¹ý½«Ä¿±êÉ豸Éý¼¶µ½¶ñÒ⿪·¢µÄ¹Ì¼þ°æÔ­À´ÀûÓôË©¶´ ¡£ÓÉÓÚCisco SPA112ÓÚ2020Äê6ÔÂ1ÈÕÍ£²ú £¬¹©Ó¦É̲»ÔÙ¶ÔËüÌṩ֧³Ö £¬Ò²²»»áÐû²¼Äþ¾²¸üР¡£´ËÍâ £¬CiscoδÌṩÕë¶Ô¸Ã©¶´µÄ»º½â´ëÊ© ¡£


https://securityaffairs.com/145763/security/cisco-spa112-2-port-phone-adapters-rce.html


2¡¢¼ÓÄôóConstellation SoftwareÔâµ½ALPHVµÄ¹¥»÷


¾Ý5ÔÂ5ÈÕ±¨µÀ £¬¼ÓÄôó¶àÔª»¯Èí¼þ¹«Ë¾Constellation Software³ÆÆ䲿ÃÅϵͳÔâµ½¹¥»÷ £¬²¿ÃŸöÈËÐÅÏ¢ºÍÉÌÒµÊý¾Ýй¶ ¡£Constellation͸¶ £¬ËüÒѾ­Í£Ö¹Á˴˴ι¥»÷ £¬ÏÖÔÚÒ²»Ö¸´ÁËËùÓÐÊÜÓ°ÏìµÄIT»ù´¡ÉèÊ© ¡£ËäÈ»¸Ã¹«Ë¾ÉÐδÌṩ¹ØÓÚ¹¥»÷Õß¼°ÆäÈçºÎ·ÃÎÊϵͳµÄÏêϸÐÅÏ¢ £¬µ«ALPHVÔÚÆäÍøÕ¾Ìí¼ÓÁËÒ»¸öÐÂÌõÄ¿ £¬³ÆËûÃÇÈëÇÖÁËConstellationµÄϵͳ²¢ÇÔÈ¡ÁËÁè¼Ý1 TBµÄÎļþ ¡£ALPHV»¹¹ûÈ»Á˲¿ÃÅ°üÂÞÉÌÒµÐÅÏ¢µÄÎļþ×÷Ϊ¹¥»÷Ö¤¾Ý ¡£


https://www.bleepingcomputer.com/news/security/alphv-gang-claims-ransomware-attack-on-constellation-software/


3¡¢Sentinel LabsÏêÊöKimsukyµÄÐÂÕì²ì¹¤¾ßReconShark


5ÔÂ4ÈÕ £¬Sentinel Labs·¢ÏÖÁËÀ´×ÔKimsukyµÄ¹¥»÷»î¶¯ ¡£¹¥»÷ÕßʹÓÃÁËеĶñÒâÈí¼þ×é¼þReconShark £¬Ëüͨ¹ýÓã²æʽµöÓãÓʼþ¡¢OneDriveÁ´½ÓÒÔ¼°¶ñÒâºê½øÐзַ¢ ¡£ReconShark±»ÈÏΪÊÇBabySharkµÄбäÌå £¬¿ÉÀûÓÃWMIÊÕ¼¯ÓйØÄ¿±êϵͳµÄÐÅÏ¢ £¬»¹¼ì²é»úÆ÷ÉÏÊÇ·ñÔËÐÐÄþ¾²Èí¼þ £¬²¢Í¨¹ýHTTP POSTÇëÇó½«Êý¾Ý·¢Ë͵½C2·þÎñÆ÷ ¡£³ýÁËÇÔÈ¡ÐÅÏ¢Íâ £¬ReconShark»¹ÒÔ¶à½×¶Î·½Ê½²¿Êð¸ü¶àpayload ¡£´Ë´Î»î¶¯Õë¶ÔÃÀ¹ú¡¢Å·ÖÞºÍÑÇÖÞµÄ×éÖ¯ºÍ¸öÈË £¬°üÂÞÖÇ¿â¡¢Ñо¿ÐÍ´óѧºÍÕþ¸®»ú¹¹ ¡£


https://www.sentinelone.com/labs/kimsuky-evolves-reconnaissance-capabilities-in-new-global-campaign/


4¡¢KasperskyÔÚGoogle Play¼ì²âµ½¶à¸öѬȾFleckpeµÄÓ¦ÓÃ


KasperskyÓÚ5ÔÂ4ÈÕ³ÆÆä·¢ÏÖÁËÐÂAndroid¶ñÒâÈí¼þFleckpe £¬Ö÷ÒªÕë¶ÔÌ©¹ú¡¢ÂíÀ´Î÷ÑÇ¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢Ð¼ÓƺͲ¨À¼ ¡£Ñо¿ÈËÔ±ÔÚGoogle Play¼ì²âµ½11¸öѬȾFleckpeµÄÓ¦Óà £¬ÕâЩӦÓÃð³äͼÏñ±à¼­Æ÷¡¢ÕÕƬ¿â¡¢¸ß¼¶±ÚÖ½µÈ £¬Òѱ»°²×°Áè¼Ý620000´Î ¡£¸ÃľÂí×Ô2022ÄêÒÔÀ´Ò»Ö±»îÔ¾ £¬Ëüͨ¹ýΪÓû§¶©Ôĸ߼¶·þÎñ¶ø·¢Éúδ¾­ÊÚȨµÄÓöÈ £¬²¢´ÓÖлñÀû ¡£Îª·À·¶´ËÀàÍþв £¬Ñо¿ÈËÔ±½¨ÒéAndroidÓû§½ö´Ó¿ÉÐÅÀ´Ô´ºÍ¿ª·¢ÉÌÏÂÔØÓ¦Óà £¬²¢ÔÚ°²×°¹ý³ÌÖÐ×¢ÒâÇëÇóµÄȨÏÞ ¡£


http://securelist.com/fleckpe-a-new-family-of-trojan-subscribers-on-google-play/109643/


5¡¢Ermetic½üÆÚÔÚAzure API¹ÜÀí·þÎñÖз¢ÏÖ3¸ö©¶´


ýÌå5ÔÂ4ÈÕ³Æ £¬Ermetic½üÆÚÔÚAzure API¹ÜÀí·þÎñÖз¢ÏÖ3¸ö©¶´ ¡£ÆäÖаüÂÞÁ½¸öSSRF©¶´ºÍÒ»¸öÎļþÉÏ´«Â·¾¶±éÀú©¶´ ¡£ÕâЩ©¶´ÊÇͨ¹ýurl¸ñʽÈƹýºÍAPI¹ÜÀí¿ª·¢ÈËÔ±ÃÅ»§ÖеÄÎÞÏÞÖÆÎļþÉÏ´«¹¦Ð§ÊµÏÖµÄ ¡£ÀûÓÃSSRF©¶´ £¬¹¥»÷Õß¿É´Ó·þÎñµÄCORSÊðÀíºÍÍйÜÊðÀí×Ô¼º·¢ËÍÇëÇó £¬·ÃÎÊÄÚ²¿Azure×ʲú £¬¾Ü¾ø·þÎñ²¢ÈƹýWebÓ¦Ó÷À»ðǽ ¡£ÀûÓÃÎļþÉÏ´«Â·¾¶±éÀú©¶´ £¬¹¥»÷Õ߿ɽ«¶ñÒâÎļþÉÏ´«µ½AzureÍйܵÄÄÚ²¿workload ¡£Ä¿Ç° £¬MSRCÒѾ­ÐÞ¸´ÁËÕâ3¸ö©¶´ ¡£


https://ermetic.com/blog/azure/when-good-apis-go-bad-uncovering-3-azure-api-management-vulnerabilities/


6¡¢AvastÐû²¼¹ØÓÚ2023ÄêµÚÒ»¼¾¶ÈÍþв̬ÊƵķÖÎö³ÂËß


5ÔÂ4ÈÕ £¬AvastÐû²¼Á˹ØÓÚ2023ÄêµÚÒ»¼¾¶ÈÍþв̬ÊƵķÖÎö³ÂËß ¡£³ÂËßÖ¸³ö £¬¹¥»÷Õß²»Í£Ñ°ÕÒеÄÒªÁìÀ´·Ö·¢¶ñÒâÈí¼þ £¬°üÂÞÀûÓÃMicrosoft OneNoteºÍAdobe Acrobat Sign ¡£±¾¼¾¶È £¬Õë¶Ô¶«ÑǵØÓòµÄ¶ñÒâ¹ã¸æÈí¼þ»î¶¯ÏÔÖøÔö¼Ó ¡£ÐÅÏ¢ÇÔÈ¡·¨Ê½ÈÔÊÇ×î´óµÄÍþв֮һ £¬ÆäÖÐ×î³£¼ûµÄÊÇAgentTesla¡¢FormBook¡¢RaccoonºÍRedLineµÈ ¡£¶ÔÓÚÀÕË÷Èí¼þ £¬WannaCryÈÔ´¦ÓÚÁìÏÈְλ£¨Õ¼±È18%£© £¬Æä´ÎÊÇSTOP ransomware(15%)ºÍThanatos(3%) ¡£×î³£¼ûµÄRAT°üÂÞHWorm¡¢Remcos¡¢njRATºÍAsyncRatµÈ ¡£ 


https://decoded.avast.io/threatresearch/avast-q1-2023-threat-report/