·áÌïÆû³µ³¤´ïÊ®ÄêµÄÊý¾Ýй¶ÊÂÎñÓ°ÏìÔ¼215Íò¿Í»§

°ä²¼¹¦·ò 2023-05-15

1¡¢·áÌïÆû³µ³¤´ïÊ®ÄêµÄÊý¾Ýй¶ÊÂÎñÓ°ÏìÔ¼215Íò¿Í»§


¾ÝýÌå5ÔÂ12ÈÕ±¨Â·£¬·áÌïÆû³µÅû¶ÁËÆäÔÆ»·¾³´Ó2013Äê11ÔÂ6ÈÕµ½2023Äê4ÔÂ17ÈÕµÄÊý¾Ýй¶ÊÂÎñ£¬Â¶³öÁËÔ¼2150000Ãû¿Í»§µÄÆû³µÎ»ÏàÐÅÏ¢¡£¸ÃÊÂÎñÊÇÓÉÓÚÊý¾Ý¿âÅäÖÃÃýÎóµ¼ÖÂÈκÎÈËÎÞÐèÃÜÂë¼´¿É½Ó¼ûÆäÄÚÈÝ¡£Ð¹Â¶ÁË2012Äê1ÔÂ2ÈÕÖÁ2023Äê4ÔÂ17ÈÕÆÚ¼äʹÓøù«Ë¾T-Connect G-Link¡¢G-Link Lite»òG-BOOK·þÎñµÄ¿Í»§ÐÅÏ¢£¬Éæ¼°³µÁ¾¼ø±ðºÅ¡¢³µÁ¾µØÎ»¼Í¼ºÍÐгµ¼Í¼ÒÇÊÓÆµµÈ¡£


https://www.infosecurity-magazine.com/news/toyota-admits-decade-long-data-leak/


2¡¢DiscordµÚÈý·½Ö§³Ö´úÀíÔâµ½¹¥»÷µ¼Ö²¿ÃÅÐÅϢй¶


ýÌå5ÔÂ12Èճƣ¬DiscordÔÚ֪ͨÊÜÓ°ÏìÓû§¹ØÓÚµÚÈý·½Ö§³Ö´úÀíµÄÕÊ»§Ôâµ½ÈëÇÖµ¼ÖµÄÊý¾Ýй¶ÊÂÎñ¡£Discordй©£¬ÓÉÓÚÊÂÎñµÄÐÔÖÊ£¬Óû§ÓʼþµØÖ·¡¢¿Í»§·þÎñÐÂÎŵÄÄÚÈÝÒÔ¼°ÓëDiscordÖ®¼ä·¢Ë͵ÄÈκθ½¼þ¿ÉÄÜÒѾ­Ð¹Â¶¡£ÎªÓ¦¶ÔÕâÒ»ÊÂÎñ£¬¸Ã¹«Ë¾µ±¼´½ûÓÃÁ˱»ÈëÇÖµÄÕË»§£¬²¢¶ÔÊÜÓ°ÏìµÄÍÆËã»ú½øÐзÖÎö£¬ÒÔÈ·¶¨ËüÊÇ·ñϰȾÁ˶ñÒâÈí¼þ¡£Ä¿Ç°£¬Discord½²»°ÈËûÓлظ´ÖÃÆÀÒªÇó¡£


https://www.bleepingcomputer.com/news/security/discord-discloses-data-breach-after-support-agent-got-hacked/


3¡¢Bl00dyÍÅ»ïÀûÓÃPaperCut RCE·ì϶¹¥»÷ÃÀ¹ú½ÌÓýÐÐÒµ


¾Ý5ÔÂ11ÈÕ±¨Â·£¬ÀÕË÷ÍÅ»ïBl00dy½üÆÚÀûÓÃPaperCut RCE£¨CVE-2023-27350£©¹¥»÷ÃÀ¹úµÄ½ÌÓýÐÐÒµ¡£¹¥»÷ÕßÓÚ4ÔÂÖÐÑ®¾ÍÆðÍ·ÀûÓø÷ì϶£¬Ä¿Ç°¹¥»÷ÈÔÔÚ½øÐÐÖУ¬Õë¶Ô½ÌÓýÐÐÒµµÄ¹¥»÷ʼÓÚ5Ô³õ¡£½üÆÚ¹Û²ìµ½µÄ»î¶¯ÖУ¬¹¥»÷ÕßÀûÓø÷ìÏ¶ÈÆ¹ýÓû§Éí·ÝÑéÖ¤²¢ÒÔÖÎÀíÔ±Éí·Ý½Ó¼û·þÎñÆ÷¡£Ê¹ÓôËȨÏÞÌìÉú¸ßȨÏÞµÄcmd.exeºÍpowershell.exe¹ý³Ì£¬»ñµÃÉ豸µÄÔ¶³Ì½Ó¼û²¢ºáÏò´«²¼£¬×îÖջᵼÖÂÊý¾Ýй¶ºÍϵͳ¼ÓÃÜ¡£


https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-131a


4¡¢·¨¹úÓÎÀÀ¹«Ë¾La Malle Postaleй¶9ÍòÓû§Ó×ÎÒÐÅÏ¢


5ÔÂ13ÈÕ±¨Â·³Æ£¬×êÑÐÍŶӷ¢ÏÖ·¨¹úÓÎÀÀ¹«Ë¾La Malle Postaleй¶ÁËÆä¿Í»§µÄÓ×ÎÒÊý¾Ý¡£1ÔÂ11ÈÕ£¬Cybernews·¢ÏÖÁËÒ»¸ö¿É¹«¿ª½Ó¼ûµÄÊý¾Ý´æ´¢£¬´æ´¢Á˳¬¹ý4GBµÄÊý¾Ý£¬Ô̺¬½ü90000¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþºÍµç»°ºÅÂ룬13000¶àÌõ¹«Ë¾Óë¿Í»§Ö®¼äSMSÐÂÎÅ£¬70000¸ö¿Í»§Æ¾Ö¤ÒÔ¼°¹«Ë¾µÄÇý¶¯·¨Ê½ºÍÖÎÀíԱʹ´¦µÈ¡£Ä¿Ç°£¬¸ÃÊý¾ÝÊý¾Ý¿âÓÚ4Ôµױ»±£»¤ÆðÀ´¡£


https://securityaffairs.com/146191/data-breach/personal-info-of-90k-hikers-leaked-by-french-tourism-company-la-malle-postale.html


5¡¢Deep InstinctÅû¶LinuxºóÃÅBPFDoorбäÌåµÄϸ½Ú


5ÔÂ11ÈÕ£¬Deep InstinctÅû¶ÁËLinuxºóÃÅBPFDoorбäÌåµÄϸ½Ú¡£BPFDoorÊÇÒ»ÖÖÒñ±ÎµÄºóÃÅ£¬´Ó2017ÄêÆðÍ·»îÔ¾£¬µ«Ö±µ½Ò»Äêǰ²Å³õ´Î±»·¢ÏÖ¡£¸ÃбäÌåÓµÓкܶàÌØµã£¬Ô̺¬Ê¹Óþ²Ì¬¿â¼ÓÃÜ£¬Ê¹Ó÷´ÏòshellͨѶ£¬ÒÔ¼°ËùÓкÅÁî¾ùÓÉC2·þÎñÆ÷·¢ËÍ¡£³õ´ÎÖ´ÐÐʱ£¬BPFDoorÔÚ/var/run/initd.lockÖд´½¨²¢Ëø¶¨Ò»¸öÔËÐÐʱÎļþ£¬¶øºó½«×Ô¼ºforkΪһ¸ö×Ó¹ý³ÌÔËÐС£BPFDoorÈÔδ±»°²È«Èí¼þ¼ì²âµ½£¬Òò¶øÖÎÀíÔ±Ö»ÄÜÒÀ¸½×³´óµÄÍøÂçÁ÷Á¿ºÍÈÕÖ¾¼à¿Ø¡£


https://www.deepinstinct.com/blog/bpfdoor-malware-evolves-stealthy-sniffing-backdoor-ups-its-game


6¡¢WordPress²å¼þÖзì϶CVE-2023-32243Ó°ÏìÉϰÙÍòÍøÕ¾


ýÌå5ÔÂ11ÈÕ±¨Â·³Æ£¬WordPress²å¼þEssential Addons for ElementorÖзì϶¿É±»Ô¶³Ì¹¥»÷ÓÃÀ´»ñµÃÍøÕ¾µÄÖÎÀíԱȨÏÞ¡£ÕâÊÇÒ»¸öÔ̺¬90¸öÀ©´óµÄ¿â£¬±»³¬¹ý100Íò¸öWordPressÍøÕ¾Ê¹Ó᣸÷ì϶¸ú×ÙΪCVE-2023-32243£¬ÊDzå¼þÃÜÂë³ÁÖÃÖ°ÄܵÄδ¾­Éí·ÝÑéÖ¤µÄȨÏÞÌáÉý·ì϶£¬Ó°Ïì°æ±¾5.4.0ÖÁ5.7.1¡£×êÑÐÈËÔ±³Æ£¬Í¨¹ýÀûÓø÷ì϶£¬Ö»Ðè֪·Óû§Ãû£¬¾ÍÄܹ»³ÁÖÃÈκÎÓû§µÄÃÜÂ룬´Ó¶ø³ÁÖÃÖÎÀíÔ±ÃÜÂë²¢µÇ¼ÕÊ»§¡£Ä¿Ç°£¬½¨¸´·¨Ê½ÒѾ­°ä²¼£¬½¨ÒéËùÓÐЧ»§¾¡¿ìÉý¼¶¡£


https://securityaffairs.com/146119/hacking/essential-addons-for-elementor-flaw.html