Outlook·ºÆð¹ÊÕϵ¼ÖÂÓû§·ÃÎÊÕË»§Ê±ÊÕµ½503´íÎóÏûÏ¢

Ðû²¼Ê±¼ä 2023-06-07

1¡¢Outlook·ºÆð¹ÊÕϵ¼ÖÂÓû§·ÃÎÊÕË»§Ê±ÊÕµ½503´íÎóÏûÏ¢


¾ÝýÌå6ÔÂ5ÈÕ±¨µÀ£¬Î¢ÈíOutlook·ºÆð¹ÊÕÏÓ°ÏìÁËÈ«ÇòµÄÓû§£¬µ¼ÖÂÎÞ·¨·¢Ë͵ç×ÓÓʼþºÍ¹ÜÀíÈÕÀú¡£ÔÚ·ÃÎʸÃÍøվʱ£¬Óû§ÏÖÔÚ»áÊÕµ½¡°HTTP´íÎó503£º·þÎñ²»ÐÐÓá±µÄÏûÏ¢£¬ÌåÏÖ·þÎñÔÝʱ²»ÐÐÓûò·þÎñÆ÷¹ýÔØ¡£Òƶ¯OutlookÓ¦Ó÷¨Ê½Ò²ÎÞ·¨Á¬½Ó·þÎñ¡£Ä¿Ç°£¬Î¢ÈíµÄ¼¼ÊõÍŶӿÉÄÜÕýÔÚ»ý¼«Ñо¿½â¾ö·½°¸¡£¾ÝºóÐø¸üУ¬Î¢ÈíÒѾ­ÐÞ¸´Á˸Ã503´íÎó£¬Outlook.comÏÖÔÚÓÖ¿ªÊ¼¼ÓÔØ£¬µ«Óû§ÈÔÈ»ÎÞ·¨·¢ËÍ»ò´ò¿ªÓʼþ¡£


https://www.bleepingcomputer.com/news/microsoft/microsofts-outlookcom-is-down-again-on-mobile-web/


2¡¢GoogleÐÞ¸´ChromeÖÐÒѱ»ÀûÓõÄ©¶´CVE-2023-3079


GoogleÔÚ6ÔÂ5ÈÕÐû²¼µÄÄþ¾²¸üÐÂÖУ¬ÐÞ¸´ÁËÒ»¸öÒѱ»ÔÚÒ°ÀûÓõÄ©¶´£¨CVE-2023-3079£©¡£ÕâÊÇ´æÔÚÓÚV8 JavaScriptÒýÇæÖеÄÀàÐÍ»ìÏý©¶´£¬¸Ã¹«Ë¾ÉÐδÐû²¼Óйظ鶴ÒÔ¼°ÈçºÎÔÚ¹¥»÷ÖÐÀûÓõÄÏêϸÐÅÏ¢¡£ÕâÊÇGoogleÔÚ½ñÄêÐÞ¸´µÄµÚÈý¸öÁãÈÕ©¶´£¬Ç°Á½¸ö·Ö±ðΪV8 JavaScriptÒýÇæÖеÄÀàÐÍ»ìÏý©¶´£¨CVE-2023-2033£©ºÍSkiaͼÐοâÖеÄÕûÊýÒç³ö©¶´£¨CVE-2023-2136£©¡£


https://securityaffairs.com/147137/hacking/chrome-zero-day-3.html


3¡¢KeePassÐÞ¸´´ÓÄÚ´æ¼ìË÷Ã÷ÎÄÖ÷ÃÜÂëµÄ©¶´CVE-2023-32784 


ýÌå6ÔÂ5Èճƣ¬KeePassÐû²¼ÁË2.54°æ±¾£¬ÐÞ¸´ÁË¿É´ÓÓ¦Ó÷¨Ê½ÄÚ´æÖмìË÷Ã÷ÎÄÖ÷ÃÜÂëµÄ©¶´£¨CVE-2023-32784£©¡£5Ô·ݣ¬Ñо¿ÈËÔ±vdohneyÅû¶Á˸鶴²¢Ðû²¼ÁËÒ»¸öPoC¡£¸Ã©¶´Ô´ÓÚKeePass 2.XÖÐʹÓÃÁËÒ»¸ö×Ô½ç˵¿ª·¢µÄÎı¾¿òSecureTextBoxEx½øÐÐÃÜÂëÊäÈë¡£¸ÃÎı¾¿ò²»½öÓÃÓÚÖ÷ÃÜÂëµÄÊäÈ룬¶øÇÒ»¹ÓÃÓÚKeePassµÄÆäËüµØ·½£¬ÈçÃÜÂë±à¼­¿ò£¬¹¥»÷Õß¿ÉʹÓÃËüÀ´»Ö¸´ÆäÄÚÈÝ¡£´ËÍ⣬KeePass 2.5.4ÐÂÔöÁËÆäËüÄþ¾²ÔöÇ¿¹¦Ð§£¬Ñо¿ÈËԱҲΪÎÞ·¨Éý¼¶µÄÓû§ÌṩÁË»º½âÒªÁì¡£


https://securityaffairs.com/147109/security/keepass-fixed-the-bug-that-allows-the-extraction-of-the-cleartext-master-password.html


4¡¢Group-IBÅû¶PostalFuriousÕë¶ÔÖж«µØÓòµÄµöÓã»î¶¯


Group-IBÓÚ6ÔÂ1ÈÕÅû¶Á˽üÆÚPostalFuriousÕë¶ÔÖж«µØÓòµÄµöÓã»î¶¯¡£Group-IBÓÚ4ÔÂÊ״η¢ÏÖµ½¸ÃÍÅ»ïͨ¹ýð³äÓÊÕþÆ·ÅƺÍÊÕ·ÑÔËÓªÉÌÀ´¹¥»÷ÑÇÌ«µØÓòµÄÓû§¡£ÏÖÔÚ£¬¸ÃÍÅ»ïÒѽ«ÒµÎñ·¶Î§À©Õ¹ÖÁÖж«¡£4ÔÂ15ÈÕ¿ªÊ¼µÄ»î¶¯ÖУ¬¹¥»÷ÕßÏòÓû§·¢ËÍ°üÂÞËõ¶ÌURLµöÓãÁ´½ÓµÄÐé¼Ù¶ÌÐÅ¡£ÕâЩ¶ÌÐÅÊÇ´ÓÔÚÂíÀ´Î÷ÑǺÍÌ©¹ú×¢²áµÄµç»°ºÅÂëÒÔ¼°Í¨¹ýiMessage·þÎñµÄÓʼþµØÖ··¢Ë͵Ä¡£Á´½ÓÓеØÀíΧÀ¸£¬Ö»ÄÜ´Ó°¢ÁªÇõµÄIPµØÖ··ÃÎÊ¡£¹¥»÷ÕßÿÌ춼ÔÚ×¢²áеĵöÓãÓòÃû£¬ÒÔÀ©´óÓ°Ï췶Χ¡£4ÔÂ29ÈÕ·¢ÏÖÁ˵ڶþ´Î½üºõÏàͬµÄ»î¶¯£¬Ã°³äÁË°¢ÁªÇõÓÊÕþÔËÓªÉÌ¡£


https://www.group-ib.com/media-center/press-releases/postalfurious/


5¡¢Scrubs & Beyondй¶400GBµÄÓû§ºÍÒøÐп¨ÏêϸÐÅÏ¢


¾Ý6ÔÂ5ÈÕ±¨µÀ£¬Scrubs & BeyondÒÔ´¿Îı¾ÐÎʽй¶ÁË400 GBµÄÓû§PIIºÍÒøÐп¨ÐÅÏ¢¡£¸ÃÊý¾Ý¿âÓÚ5ÔÂ16ÈÕ̻¶£¬Ñо¿ÈËÔ±ÔÚ5ÔÂ25ÈÕ·¢ÏÖ£¬½ñºóÕâЩÐÅÏ¢Ò»Ö±´¦ÓڿɹûÈ»·ÃÎʵÄ״̬¡£Ä¿Ç°£¬·þÎñÆ÷ÓµÓÐÁè¼Ý100000Ìõ¿Í»§¼Ç¼£¬×ܼÆ400 GB£¬ÇÒÊý¾Ý¿â¾ÞϸºÍÓû§ÊýÁ¿Ëæ×ÅÿÌìÐÂÔöµÄÐÅÏ¢¶ø²»Í£Ôö³¤¡£Ð¹Â¶ÐÅÏ¢Éæ¼°ÐÕÃû¡¢µç»°¡¢µØÖ·ºÍÄÚ²¿Æ¾¾ÝµÈ¸öÈËÐÅÏ¢£¬ÒÔ¼°ÒøÐп¨ºÅ¡¢CVV´úÂëºÍPayPalÖ§¸¶ÈÕÖ¾µÈ²ÆÕþÐÅÏ¢¡£Ä¿Ç°£¬¸Ã¹«Ë¾²¢Î´¶Ô´ËÊÂ×÷³ö»ØÓ¦£¬Ò²Î´½«¸ÃÊý¾Ý¿â±£»¤ÆðÀ´¡£


https://www.hackread.com/scrubs-beyond-leaks-400gb-of-user-data/


6¡¢KasperskyÏêÊöÓëSatacomÏà¹ØµÄ¶ñÒâÈí¼þ·Ö·¢»î¶¯


6ÔÂ5ÈÕ£¬Kaspersky³ÆÆä·¢ÏÖÒ»ÆðеĶñÒâÈí¼þ»î¶¯£¬ÀûÓÃSatacom downloader£¨Ò²³ÆLegionLoader£©À´·Ö·¢ÇÔÈ¡¼ÓÃÜ»õ±ÒµÄä¯ÀÀÆ÷À©Õ¹¡£Ñ¬È¾Ê¼ÓÚÒ»¸öZIPÎļþ£¬ÆäÖаüÂÞ¼¸¸öºÏ·¨µÄDLLºÍÒ»¸ö¶ñÒâµÄSetup.exe£¬Óû§ÐèÒªÊÖ¶¯Ö´ÐÐÕâЩÎļþ²ÅÆøÆô¶¯Ñ¬È¾Á´¡£Ö®ºó£¬Ä¿±ê±»Öض¨Ïòµ½Î±×°³ÉÎļþ¹²Ïí·þÎñµÄÍøÕ¾À´·Ö·¢¶ñÒâÈí¼þ¡£Ò»µ©¶ñÒâÈí¼þ±»Ö´ÐУ¬Ëü¾Í»áʹÓýø³Ì×¢Èë¼¼ÊõÀ´Èƹýɱ¶¾Èí¼þµÄ¼ì²â¡£´ËÍ⣬QUADS¹ã¸æ²å¼þÒѱ»ÓÃÀ´Á÷´«Satacom¡£


https://securelist.com/satacom-delivers-cryptocurrency-stealing-browser-extension/109807/