Google°ä²¼°²È«¸üн¨¸´ChromeÖеĶà¸ö·ì϶
°ä²¼¹¦·ò 2023-03-231¡¢Google°ä²¼°²È«¸üн¨¸´ChromeÖеĶà¸ö·ì϶
GoogleÔÚ3ÔÂ21ÈÕ°ä²¼°²È«¸üУ¬½¨¸´ÁËChromeÖеÄ8¸ö·ì϶¡£ÆäÖУ¬½ÏΪÑϳÁµÄÊÇPasswordsÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2023-1528£©¡¢WebHIDÖеÄÄÚ´æÔ½½ç½Ó¼û·ì϶£¨CVE-2023-1529£©¡¢ÔÚPDFÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2023-1530£©ºÍGPUÊÓÆµÖеÄÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2023-1532£©µÈ¡£Google°µÊ¾£¬ÔÚ´óÎÞÊýÓû§¸üн¨¸´·¨Ê½Ö®Ç°£¬·ì϶¾ßÌåÐÅÏ¢ºÍÁ´½ÓµÄ½Ó¼û¿ÉÄÜ»áÊܵ½ÏÞ¶È¡£
https://chromereleases.googleblog.com/2023/03/stable-channel-update-for-desktop_21.html
2¡¢Á÷ýÌåÆ½Ì¨Lionsgate½ü3000Íò±Ê¼Í¼й¶
¾ÝCybernewsÔÚ3ÔÂ22ÈÕ±¨Â·£¬Õ¼ÓÐ3700Íò¶©»§µÄÊÓÆµÁ÷ýÌåÆ½Ì¨Lionsgate PlayµÄElasticSearchÅäÖÃÃýÎó£¬Ð¹Â¶ÁËÓû§Êý¾Ý¡£×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸ö20 GB·þÎñÆ÷ÈÕÖ¾£¬Ô̺¬½ü3000ÍòÌõÌõ¿î£¬×îÔçµÄÈÕÆÚÊÇ2022Äê5Ô¡£ÈÕ־й¶Á˶©ÔÄÕßµÄIPµØÖ·ÒÔ¼°ÓйØÉ豸¡¢²Ù×÷ϵͳºÍWebä¯ÀÀÆ÷µÄÓû§ÐÅÏ¢¡£»¹Ð¹Â¶ÁËÆ½Ì¨µÄʹÓÃÊý¾Ý£¬ÈçÓû§ÅÔ¹ÛÄÚÈݵıêÌâIDºÍËÑË÷²éÎʵȣ¬Í¨³£¿ÉÓÃÓÚ·ÖÎöºÍ»úÄܸú×Ù¡£Cybernews¾Í´ËÊÂÁªÏµÁËLionsgate£¬¸Ã¹«Ë¾µÄ»ØÓ¦ÊÇÒѽ«·þÎñÆ÷±£»¤ÆðÀ´£¬µ«ÊǽØÖÁĿǰÉÐδÌṩ¹Ù·½»ØÓ¦¡£
https://cybernews.com/security/lionsgate-data-leak/
3¡¢REF2924ÍÅ»ïÀûÓÃNAPLISTENER¹¥»÷¶«ÄÏÑǵØÓò
¾ÝýÌå3ÔÂ20ÈÕ±¨Â·£¬REF2924ÀûÓÃжñÒâÈí¼þNAPLISTENER¹¥»÷ÄÏÑǺͶ«ÄÏÑǵÄ×éÖ¯¡£Elastic³Æ¸ÃÍÅ»ïʹÓÃÁ˶àÖÖ»úÔ죬½«³Áµã´ÓÊý¾ÝÇÔÈ¡×ªÒÆµ½ÓƾýӼû¡£2023Äê1ÔÂ20ÈÕ£¬Ò»¸öеĿÉÖ´ÐÐÎļþWmdtc.exe±»´´½¨²¢×÷ΪWindows·þÎñ×°Öã¬Í¨¹ý¼Ù×°³ÉMicrosoftÉ¢²¼Ê½ÊÂÎñ´¦ÖÃе÷Æ÷·þÎñ(Msdtc.exe)ʹÓõĺϷ¨¶þ½øÔìÎļþ¡£Wmdtc.exe±»³ÆÎªNAPLISTENER£¬ÕâÊÇÒ»¸öÓÃC#¿ª·¢µÄHTTPÕìÌýÆ÷£¬Ö¼ÔÚÈÆ¹ý»ùÓÚÍøÂçµÄ°²È«¼ì²â¡£
https://www.elastic.co/cn/security-labs/naplistener-more-bad-dreams-from-the-developers-of-siestagraph
4¡¢LockBitÒ²³ÆÒÑÇÔÈ¡²¢½«¹«¿ª°Â¿ËÀ¼ÊÐϵͳÖеÄÎļþ
¾Ý3ÔÂ21ÈÕ±¨Â·£¬ÁíÒ»¸öÀÕË÷ÍÅ»ïLockBitÒ²Ðû³Æ´Ó°Â¿ËÀ¼ÊÐϵͳÖÐÇÔÈ¡ÁËÎļþ¡£È»¶ø£¬¸ÃÍÅ»ïÉÐδ°ä²¼ÈκÎÖ¤¾ÝÀ´Ö¤Ã÷ËûÃǵĹ¥»÷»î¶¯¡£ÕâÊÇ×ÔPlayÍÅ»ïÔÚ3Ô³õ°µÊ¾¶Ô°Â¿ËÀ¼ÊеÄÍøÂç¹¥»÷ÕÆ¹Üºó£¬µÚ¶þ¸öÀÕË÷ÍÅ»ïÐû³ÆÇÔÈ¡ÁËÊý¾Ý¡£LockBitÔÚÆäÍøÕ¾ÉÏÔö³¤ÁËÐÂÌõ¿î£¬²¢Íþв½«ÔÚ4ÔÂ10ÈÕ¹«¿ªËùº±¼û¾Ý¡£°Â¿ËÀ¼ÊÐÉÐδ¾Í´Ëʰ䷢ÉêÃ÷¡£×êÑÐÈËÔ±°µÊ¾£¬LockBitÔøÔÚ2022Äê6ÔÂÐû³ÆËüÈëÇÖÁËMandiantµÄϵͳ²¢ÇÔÈ¡ÁËÊýÊ®Íò¸öÎļþ£¬ºóÀ´Õâ±»Ö¤Ã÷ÊÇÒ»¸öÐû´«àåÍ·¡£
https://www.bleepingcomputer.com/news/security/lockbit-ransomware-gang-now-also-claims-city-of-oakland-breach/
5¡¢ChatGPT³öÏÖBugÄܹ»¿´µ½ÆäËûÓû§µÄ¶Ô»°º¹Çà±êÌâ
ýÌå3ÔÂ21Èճƣ¬ChatGPT³öÏÖÁËÒ»¸öBug£¬µ¼ÖÂÆäËûÓû§µÄ̸Ì캹Çàй¶¡£¸ÃÎÊÌâ×î³õÊÇÓÉһλÒÉ»óÆäÕÊ»§±»ºÚµÄÓû§ÔÚRedditÉϻ㱨µÄ£¬ËûÔÚ¶Ô»°º¹Çà±êÌâÖз¢ÏÖÁ˲»ÊôÓÚ×Ô¼ºµÄ¶Ô»°¡£ÐÂÎÅ´«¿ªºó£¬ÍÆÌØÉÏµÄÆäËûÓû§Ò²Ðû³ÆÔÚ×Ô¼ºµÄÕ˺ÅÉÏ¿´µ½Á˱ðÈ˵Ä̸Ìì¼Í¼¡£ºÜ¶àÓû§³Æ¸ÃÎÊÌâÑϳÁ¼Óº¦ÁËÓû§ÒþÖÔ¡£ChatGPTÓÚ±¾ÖÜÒ»ÁÙʱ½ûÓÃÁËÆä̸Ìì·þÎñ£¬ÒÔµ÷²éºÍ½¨¸´¸Ã·ì϶¡£3ÔÂ23ÈÕ£¬OpenAI CEO Sam AltmanÈÏ¿ÉÆä¿ªÔ´¿âÖеÄÒ»¸öÃýÎóµ¼ÖÂÓû§µÄ̸Ì캹Çàй¶£¬²¢°ä²¼ÁËÍÆÎÄÖÂǸ¡£
https://www.hackread.com/chatgpt-bug-conversation-history-titles/
6¡¢Unit 42°ä²¼2023ÄêÀÕË÷Èí¼þÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨
3ÔÂ21ÈÕ£¬Unit 42°ä²¼ÁË2023ÄêÀÕË÷Èí¼þÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬¶à³ÁÀÕË÷Õ½ÊõµÄʹÓóÖÐøÉÏÉý¡£½ØÖÁ2022Äêµ×£¬ÔÚÔ¼70%µÄ°¸¼þÖвúÉúÁËÊý¾Ýй¶£¬2021ÄêÖÐÖ»ÓÐÔ¼40%µÄÊý¾Ý±»µÁ¡£É§ÈÅÊÇÁíÒ»ÖÖÀÕË÷Õ½Êõ£¬2022Äêµ×Ô¼20%µÄÀÕË÷Èí¼þ°¸¼þÔ̺¬¸Ã³É·Ö£¬¶ø2021Äê½öÓв»µ½1%¡£Ôì×÷ÒµÊÜ´ËÀ๥»÷×î¶à£¬ÃÀ¹úµÄ×éÖ¯Êܵ½Ó°Ïì×îÑϳÁ£¨Õ¼42%£©¡£×êÑÐÈËÔ±Ô¤¼ÆÔÚ2023Ä꣬³öÏÖ´óÐÍÔÆÀÕË÷Èí¼þ¹¥»÷¡¢ÄÚ²¿ÍþвÓйصÄÚ²ÆÀÕË÷Ôö³¤ºÍ³öÓÚÕþÖζ¯»úµÄÀÕË÷Ôö³¤µÈ¡£
https://start.paloaltonetworks.com/2023-unit42-ransomware-extortion-report


¾©¹«Íø°²±¸11010802024551ºÅ