Google´¹Î£¸üн¨¸´½ñÄêµÚ¶þ¸öÒѱ»ÀûÓõÄChrome·ì϶
°ä²¼¹¦·ò 2023-04-201¡¢Google´¹Î£¸üн¨¸´½ñÄêµÚ¶þ¸öÒѱ»ÀûÓõÄChrome·ì϶
4ÔÂ18ÈÕ£¬Google°ä²¼Chrome´¹Î£¸üУ¬½¨¸´ÁË2023ÄêµÚ¶þ¸öÒѱ»ÀûÓ÷ì϶¡£ÕâÊÇ¿ªÔ´2DͼÐοâSkiaÖеÄÕûÊýÒç¶Âí½Å£¨CVE-2023-2136£©£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶£¬Í¨¹ý¶ñÒâµÄHTMLÒ³ÃæÖ´ÐÐɳÏäÌÓÒÝ¡£GoogleÉÐδ°ä²¼¹ØÓڸ÷ì϶µÄϸ½Ú¡£Õâ´Î¸üл¹½¨¸´ÁËService Worker APIÖеÄÄÚ´æÔ½½ç½Ó¼û·ì϶£¨CVE-2023-2133ºÍCVE-2023-2134£©ÒÔ¼°DevToolsÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2023-2135£©µÈ¡£ÉÏÖÜ£¬Google½¨¸´ÁË2023ÄêµÚÒ»¸ö±»ÀûÓõÄChrome·ì϶£¨CVE-2023-2033£©¡£
https://securityaffairs.com/145019/security/google-second-chrome-zero-day-2023.html
2¡¢APT28ÀûÓÃCisco·ÓÉÆ÷Öеķì϶װÖÃJaguar Tooth
¾ÝýÌå4ÔÂ18ÈÕ±¨Â·£¬Ó¢ÃÀµ±¾Ö°ä²¼½áºÏÕ÷ѯ£¬¾ßÌå½éÉÜÁËAPT28ÈôºÎÀûÓÃCisco IOS·ÓÉÆ÷Éϵķì϶װÖÃ×Ô½ç˵¶ñÒâÈí¼þJaguar Tooth¡£¸Ã¶ñÒâÈí¼þÖØÒªÕë¶ÔÔËÐй̼þC5350-ISM°æ±¾12.3(6)µÄCisco IOS·ÓÉÆ÷¡£Ëü¿ÉÍøÂçÉ豸ÐÅÏ¢£¬¶øºóͨ¹ýTFTP´«ÊäÕâЩÐÅÏ¢£¬²¢ÆôÓÃδ¾Éí·ÝÑéÖ¤µÄºóÃŽӼû¡£¾Ý¹Û²ì£¬ËüÊÇÀûÓÃÒѽ¨¸´µÄSNMP·ì϶£¨CVE-2017-6742£©½øÐÐ×°ÖúÍÖ´Ðеġ£×êÑÐÈËÔ±½¨ÒéÖÎÀíÔ±½«Â·ÓÉÆ÷Éý¼¶µ½×îеĹ̼þ°æ±¾ÒÔµÍÓÚ´ËÀ๥»÷¡£
https://www.bleepingcomputer.com/news/security/us-uk-warn-of-govt-hackers-using-custom-malware-on-cisco-routers/
3¡¢Î¢Èí·¢ÏÖMint Sandstorm¹¥»÷ÃÀ¹úµÄ¹Ø¼ü»ù´¡ÉèÊ©
4ÔÂ18ÈÕ£¬Î¢Èí³ÆÆä·¢ÏÖÁËMint SandstormµÄÒ»¸ö×Ó×éÕë¶ÔÃÀ¹úµÄ¹¥»÷»î¶¯¡£´Ó2021Ëêĺµ½2022ÄêÖУ¬¸ÃÍÅ»ï´Ó¿úËÅתÏòÖ±½Ó¹¥»÷ÃÀ¹úµÄ¹Ø¼ü»ù´¡ÉèÊ©£¬Ô̺¬º£¸Û¡¢ÄÜÔ´¹«Ë¾¡¢ÔËÊäϵͳ¡¢¹«ÓÃÊÂÒµºÍÌìÈ»Æø×éÖ¯µÈ¡£Ëüͨ³£Ê¹Óù«¿ªÅû¶µÄPoC£¬Ò²»áʹÓþɷì϶£¨ÀýÈçLog4Shell£©À´¹¥»÷δ´ò²¹¶¡µÄÉ豸¡£Ö®ºó£¬Í¨¹ýImpacket¿ò¼ÜºáÏò´«²¼£¬²¢Ö´ÐÐÁ½Ìõ¹¥»÷Á´Ö®Ò»¡£µÚÒ»Ìõ»áÇÔÈ¡Windows Active DirectoryÊý¾Ý¿â£¬µÚ¶þÌõ×°ÖÃÃûΪDrokbkºÍSoldierµÄ×Ô½ç˵ºóÃÅ¡£
https://www.microsoft.com/en-us/security/blog/2023/04/18/nation-state-threat-actor-mint-sandstorm-refines-tradecraft-to-attack-high-value-targets/
4¡¢Group-IBÅû¶MuddyWaterÀûÓÃSimpleHelpµÄ»î¶¯
Group-IBÔÚ4ÔÂ18ÈÕÅû¶ÁËMuddyWaterʹÓúϷ¨µÄÔ¶³ÌÉ豸½ÚÔìºÍÖÎÀí¹¤¾ßSimpleHelpά³ÖÓÆ¾ÃÐÔ¡£SimpleHelp²¢Ã»Óб»¹¥»÷£¬Ïà·´£¬¹¥»÷ÕßÕÒµ½ÁË´Ó¹ÙÍøÏÂÔØ¸Ã¹¤¾ß²¢ÔÚ¹¥»÷ÖÐʹÓÃËüµÄ²½Öè¡£¸ÃÍÅ»ïÓÚ2022Äê6ÔÂ30ÈÕ³õ´ÎʹÓÃSimpleHelp£¬½ØÖÁĿǰ£¬¸Ã×éÖ¯ÖÁÉÙÓаĘ̈·þÎñÆ÷×°ÖÃÁËSimpleHelp¡£×°ÖÃÔÚÖ¸±êÉ豸ÉϵÄSimpleHelp¿Í»§¶ËÄܹ»×÷Ϊϵͳ·þÎñ³ÖÐøÔËÐУ¬Òò¶ø¹¥»÷Õß¿ÉÄÜËæÊ±½Ó¼ûÓû§µÄÉ豸£¬Ô̺¬ÔÚ³ÁÆôºó¡£³õÊ¼Ï°È¾ÔØÌåĿǰδ֪£¬×êÑÐÈËÔ±ÒÉ»óÊÇ´¹µö¹¥»÷¡£
https://www.group-ib.com/blog/muddywater-infrastructure/
5¡¢·¿²úÖнéOrangeTee&TieÒòй¶25ÍòÈËÊý¾Ý±»·£¿î
¾Ý4ÔÂ18ÈÕ±¨Â·£¬ÐÂ¼ÓÆÂ·¿µØ²ú¹«Ë¾OrangeTee & TieÒòй¶³¬¹ý25Íò¿Í»§ºÍÔ±¹¤µÄÐÅÏ¢£¬±»ÒþÖÔ¼à¹Ü»ú¹¹·£¿î37000ÐÂÔª¡£2021Äê8ÔÂ3ÈÕ£¬¸Ã¹«Ë¾ÊÕµ½ÁËALTDOSµÄÀÕË÷Óʼþ£¬ÒªÇó10¸ö±ÈÌØ±Ò×÷ΪÊê½ð¡£ÀÕË÷ÍÅ»ïûÓÐÊÕµ½Êê½ð£¬Òò¶øÖ´ÐÐDDoS¹¥»÷µ¼ÖÂOrangeTee & TieµÄÍøÂç̱»¾¡£¸Ã·¿²ú¹«Ë¾È¡Ö¤·¢ÏÖALTDOS½Ó¼ûÁË11¸öÊý¾Ý¿â£¬Éæ¼°256583¸ö¿Í»§ºÍÔ±¹¤µÄÐÅÏ¢¡£ÔÚ4ÔÂ17ÈÕ°ä²¼µÄÊéÃæÅоöÖУ¬PDPC³ÆÒòOrangeTee & TieµÄ¼¸¸öʧÎóµ¼ÖÂÁËÊý¾Ýй¶¡£
https://www.channelnewsasia.com/singapore/orangetee-real-estate-personal-data-breach-pdpa-customers-employees-3425291
6¡¢CheckPoint°ä²¼¹ØÓÚRaspberry RobinµÄ·ÖÎö»ã±¨
4ÔÂ18ÈÕ£¬Check Point°ä²¼Á˹ØÓÚRaspberry RobinµÄ·ÖÎö»ã±¨¡£Raspberry RobinʹÓÃÁ˺öàÈÆ¹ý¼ì²âµÄ²½Ö裬Ô̺¬²é³PEB£¨¹ý³Ì»·¾³¿é£©¡¢Óû§ÃûºÍÍÆËã»úÃû¡¢MacµØÖ·¡¢CPUID¡¢»î¶¯CPUÊýÁ¿¡¢ÄÚ´æÒ³¡¢MulDivºÍ¹Ì¼þ±íµÈ¡£´Ë±í£¬ËüÀûÓúöಽÖèÀ´Ô¤·À±»°²È«½â¾ö¹æ»®¼ì²âµ½£¬ÀýÈçÈ¥³ýIFEOºÍWindows DefenderÅųýÁбíµÈ¡£Raspberry Robin»¹ÀûÓÃÁËÁ½¸öEoP·ì϶£¨CVE-2020-1054ºÍCVE-2021-1732£©½øÐÐÌáȨ¡£
https://research.checkpoint.com/2023/raspberry-robin-anti-evasion-how-to-exploit-analysis/


¾©¹«Íø°²±¸11010802024551ºÅ