CiscoÅû¶ÆäSPA112 2-Portµç»°ÊÊÅäÆ÷ÖеÄRCE·ì϶
°ä²¼¹¦·ò 2023-05-061¡¢CiscoÅû¶ÆäSPA112 2-Portµç»°ÊÊÅäÆ÷ÖеÄRCE·ì϶
¾ÝýÌå5ÔÂ4ÈÕ±¨Â·£¬CiscoÅû¶ÁËÆäSPA112 2-Portµç»°ÊÊÅäÆ÷ÖлùÓÚWebµÄÖÎÀí½çÃæÖеķì϶£¬¿É±»Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÓÃÓÚÖ´ÐÐËÁÒâ´úÂë¡£¸Ã·ì϶׷×ÙΪCVE-2023-20126£¨CVSSÆÀ·Ö9.8£©£¬ÊÇÓÉÓڹ̼þÉý¼¶Ö°ÄÜÖжÌȱÉí·ÝÑéÖ¤¹ý³ÌÔì³ÉµÄ£¬¹¥»÷ÕßÄܹ»Í¨¹ý½«Ö¸±êÉ豸Éý¼¶µ½¶ñÒ⿪·¢µÄ¹Ì¼þ°æÕý±¾ÀûÓô˷ì϶¡£ÓÉÓÚCisco SPA112ÓÚ2020Äê6ÔÂ1ÈÕÍ£²ú£¬¹©¸øÉ̲»ÔÙ¶ÔËüÌṩ֧³Ö£¬Ò²²»»á°ä²¼°²È«¸üС£´Ë±í£¬CiscoδÌṩÕë¶Ô¸Ã·ì϶µÄ»º½â´ëÊ©¡£
https://securityaffairs.com/145763/security/cisco-spa112-2-port-phone-adapters-rce.html
2¡¢¼ÓÄôóConstellation SoftwareÔâµ½ALPHVµÄ¹¥»÷
¾Ý5ÔÂ5ÈÕ±¨Â·£¬¼ÓÄôó¶àÔª»¯Èí¼þ¹«Ë¾Constellation Software³ÆÆä²¿ÃÅϵͳÔâµ½¹¥»÷£¬²¿ÃÅÓ×ÎÒÐÅÏ¢ºÍóÒ×Êý¾Ýй¶¡£Constellationй©£¬ËüÒѾ¶ôÔìÁËÕâ´Î¹¥»÷£¬´Ë¿ÌÒ²¸´ÔÁËËùÓÐÊÜÓ°ÏìµÄIT»ù´¡ÉèÊ©¡£¹ÌÈ»¸Ã¹«Ë¾ÉÐδÌṩ¹ØÓÚ¹¥»÷Õß¼°ÆäÈôºÎ½Ó¼ûϵͳµÄ¾ßÌåÐÅÏ¢£¬µ«ALPHVÔÚÆäÍøÕ¾Ôö³¤ÁËÒ»¸öÐÂÌõ¿î£¬³ÆËûÃÇÈëÇÖÁËConstellationµÄϵͳ²¢ÇÔÈ¡Á˳¬¹ý1 TBµÄÎļþ¡£ALPHV»¹¹«¿ªÁ˲¿ÃÅÔ̺¬Ã³Ò×ÐÅÏ¢µÄÎļþ×÷Ϊ¹¥»÷Ö¤¾Ý¡£
https://www.bleepingcomputer.com/news/security/alphv-gang-claims-ransomware-attack-on-constellation-software/
3¡¢Sentinel LabsÏêÊöKimsukyµÄпúËŹ¤¾ßReconShark
5ÔÂ4ÈÕ£¬Sentinel Labs·¢ÏÖÁËÀ´×ÔKimsukyµÄ¹¥»÷»î¶¯¡£¹¥»÷ÕßʹÓÃÁËеĶñÒâÈí¼þ×é¼þReconShark£¬Ëüͨ¹ýÓã²æÊ½´¹µöÓʼþ¡¢OneDriveÁ´½ÓÒÔ¼°¶ñÒâºê½øÐзַ¢¡£ReconShark±»ÒÔΪÊÇBabySharkµÄбäÌ壬¿ÉÀûÓÃWMIÍøÂçÓйØÖ¸±êϵͳµÄÐÅÏ¢£¬»¹²é³»úеÉÏÊÇ·ñÔËÐа²È«Èí¼þ£¬²¢Í¨¹ýHTTP POSTÒªÇó½«Êý¾Ý·¢Ë͵½C2·þÎñÆ÷¡£³ýÁËÇÔÊØÐÅÏ¢±í£¬ReconShark»¹ÒÔ¶à½×¶Î·½Ê½²¿Êð¸ü¶àpayload¡£Õâ´Î»î¶¯Õë¶ÔÃÀ¹ú¡¢Å·ÖÞºÍÑÇÖÞµÄ×éÖ¯ºÍÓ×ÎÒ£¬Ô̺¬Öǿ⡢×êÑÐÐÍ´óѧºÍµ±¾Ö»ú¹¹¡£
https://www.sentinelone.com/labs/kimsuky-evolves-reconnaissance-capabilities-in-new-global-campaign/
4¡¢KasperskyÔÚGoogle Play¼ì²âµ½¶à¸öϰȾFleckpeµÄÀûÓÃ
KasperskyÓÚ5ÔÂ4ÈÕ³ÆÆä·¢ÏÖÁËÐÂAndroid¶ñÒâÈí¼þFleckpe£¬ÖØÒªÕë¶ÔÌ©¹ú¡¢ÂíÀ´Î÷ÑÇ¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢ÐÂ¼ÓÆÂºÍ²¨À¼¡£×êÑÐÈËÔ±ÔÚGoogle Play¼ì²âµ½11¸öϰȾFleckpeµÄÀûÓã¬ÕâЩÀûÓüÙÒâͼÏñ±à×ëÆ÷¡¢ÕÕÆ¬¿â¡¢¸ß¼¶±ÚÖ½µÈ£¬Òѱ»×°Öó¬¹ý620000´Î¡£¸ÃľÂí×Ô2022ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬Ëüͨ¹ýΪÓû§¶©Ôĸ߼¶·þÎñ¶ø²úÉúδ¾ÊÚȨµÄÓöȣ¬²¢´ÓÖлñÀû¡£Îª·À±¸´ËÀàÍþв£¬×êÑÐÈËÔ±½¨ÒéAndroidÓû§½ö´Ó¿ÉÐÅÆðÔ´ºÍ¿ª·¢ÉÌÏÂÔØÀûÓ㬲¢ÔÚ×°Öùý³ÌÖаÑÎÈÒªÇóµÄȨÏÞ¡£
http://securelist.com/fleckpe-a-new-family-of-trojan-subscribers-on-google-play/109643/
5¡¢Ermetic½üÆÚÔÚAzure APIÖÎÀí·þÎñÖз¢ÏÖ3¸ö·ì϶
ýÌå5ÔÂ4Èճƣ¬Ermetic½üÆÚÔÚAzure APIÖÎÀí·þÎñÖз¢ÏÖ3¸ö·ì϶¡£ÆäÖÐÔ̺¬Á½¸öSSRF·ì϶ºÍÒ»¸öÎļþÉÏ´«õè¾¶±éÀú·ì϶¡£ÕâЩ·ì϶ÊÇͨ¹ýurlÌåÊ½ÈÆ¹ýºÍAPIÖÎÀí¿ª·¢ÈËÔ±ÃÅ»§ÖеÄÎÞÏÞ¶ÈÎļþÉÏ´«Ö°ÄÜʵÏֵġ£ÀûÓÃSSRF·ì϶£¬¹¥»÷Õ߿ɴӷþÎñµÄCORS´úÀíºÍÍйܴúÀí×ÔÉí·¢ËÍÒªÇ󣬽ӼûÄÚ²¿Azure×ʲú£¬»Ø¾ø·þÎñ²¢ÈƹýWebÀûÓ÷À»ðǽ¡£ÀûÓÃÎļþÉÏ´«õè¾¶±éÀú·ì϶£¬¹¥»÷Õ߿ɽ«¶ñÒâÎļþÉÏ´«µ½AzureÍйܵÄÄÚ²¿workload¡£Ä¿Ç°£¬MSRCÒѾ½¨¸´ÁËÕâ3¸ö·ì϶¡£
https://ermetic.com/blog/azure/when-good-apis-go-bad-uncovering-3-azure-api-management-vulnerabilities/
6¡¢Avast°ä²¼¹ØÓÚ2023ÄêµÚÒ»¼¾¶ÈÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨
5ÔÂ4ÈÕ£¬Avast°ä²¼Á˹ØÓÚ2023ÄêµÚÒ»¼¾¶ÈÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬¹¥»÷Õß²»ÐÝѰÕÒеIJ½ÖèÀ´·Ö·¢¶ñÒâÈí¼þ£¬Ô̺¬ÀûÓÃMicrosoft OneNoteºÍAdobe Acrobat Sign¡£±¾¼¾¶È£¬Õë¶Ô¶«ÑǵØÓòµÄ¶ñÒâ¸æ°×Èí¼þ»î¶¯ÏÔÖøÔö³¤¡£ÐÅÏ¢ÇÔÈ¡·¨Ê½ÈÔÊÇ×î´óµÄÍþв֮һ£¬ÆäÖÐ×î³£¼ûµÄÊÇAgentTesla¡¢FormBook¡¢RaccoonºÍRedLineµÈ¡£¶ÔÓÚÀÕË÷Èí¼þ£¬WannaCryÈÔ´¦ÓÚµ±ÏÈְλ£¨Õ¼±È18%£©£¬Æä´ÎÊÇSTOP ransomware(15%)ºÍThanatos(3%)¡£×î³£¼ûµÄRATÔ̺¬HWorm¡¢Remcos¡¢njRATºÍAsyncRatµÈ¡£
https://decoded.avast.io/threatresearch/avast-q1-2023-threat-report/


¾©¹«Íø°²±¸11010802024551ºÅ