΢Èí°ä²¼6Ô·ݵݲȫ¸üУ¬×ܼƽ¨¸´78¸ö·ì϶
°ä²¼¹¦·ò 2023-06-141¡¢Î¢Èí°ä²¼6Ô·ݵݲȫ¸üУ¬×ܼƽ¨¸´78¸ö·ì϶
¾Ý6ÔÂ13ÈÕ±¨Â·£¬Î¢Èí°ä²¼ÁË2023Äê6ÔµÄÖܶþ²¹¶¡£¬½¨¸´ÁË78¸ö·ì϶£¬ÆäÖÐÔ̺¬38¸öÔ¶³Ì´úÂëÖ´Ðзì϶¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶ΪWindows Pragmatic General Multicast(PGM)ÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-29363¡¢CVE-2023-32014ºÍCVE-2023-32015£©ÒÔ¼°Microsoft SharePoint ServerÖеÄȨÏÞÌáÉý·ì϶£¨CVE-2023-29357£©µÈ¡£Õâ´Î¸üв»Ô̺¬ÁãÈÕ·ì϶»òÒѱ»ÀûÓõķì϶¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2023-patch-tuesday-fixes-78-flaws-38-rce-bugs/
2¡¢ÈðÊ¿Áª¹úÖÎÀí¾ÖÔâµ½DDoS¹¥»÷¶à¸öÍøÕ¾ºÍÀûÓò»³ÉÓÃ
ÈðÊ¿Áª¹úÖÎÀí¾ÖÔÚ6ÔÂ12ÈÕй©£¬ÓÉÓÚϵͳÔâµ½DDoS¹¥»÷£¬Æä¶à¸öÍøÕ¾¼°ÔÚÏß·þÎñ²»³É½Ó¼û¡£Óë¶íÂÞ˹ÓйصĺڿÍÍÅ»ïNoNameÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬Ëü×Ô2022ËêÊ×ÒÔÀ´Ò»Ö¹Øë¶ÔÅ·ÖÞ¡¢ÎÚ¿ËÀ¼ºÍ±±ÃÀµÄ¹ú¶ÈºÍ×éÖ¯£¬ÔÚÉÏÖÜ»¹¹¥»÷ÁËparlament.ch¡£¸Ã»ú¹¹³Æ£¬×êÑÐÈËÔ±ºÜ¿ì¾Í°ÑÎȵ½ÁËÕâ´Î¹¥»÷£¬²¢ÔÚ²ÉÈ¡´ëÊ©¾¡¿ì¸´ÔÍøÕ¾ºÍÀûÓõĿÉÓÃÐÔ¡£6ÔÂ1ÈÕ£¬ÀÕË÷ÍÅ»ïPlayÔø¹«¿ªÁË´ÓÈðÊ¿¾üÕþ×éÖ¯µÄ¼¼ÊõÌṩÉÌXplainÇÔÈ¡µÄÐÅÏ¢¡£
https://www.admin.ch/gov/en/start/documentation/media-releases.msg-id-95641.html
3¡¢HIBPÅû¶ӰÏìÔ¼890ÍòÓû§µÄZacksÊý¾Ýй¶ÊÂÎñ
¾ÝýÌå6ÔÂ12ÈÕ±¨Â·£¬Êý¾Ýй¶֪ͨ·þÎñHave I Been Pwned(HIBP)Åû¶ÁËһ·½ÏÔçµÄZacksÊý¾Ýй¶ÊÂÎñ¡£HIBPÊÕµ½ÁËÒ»¸öÔ̺¬8929503ÌõÓû§¼Í¼µÄÊý¾Ý¿â£¬ÆäÖÐÔ̺¬ÐÕÃû¡¢ÓʼþµØÖ·¡¢Óû§ÃûºÍSHA256ÃÜÂëµÈÐÅÏ¢£¬Êý¾Ý¿âÖÐ×îмͼµÄÈÕÆÚΪ2020Äê5Ô¡£¸Ã·þÎñ֪ͨÁËZecks£¬ºóÕ߳ƹ¥»÷ÕßÖ»ÄܽӼû¼ÓÃܵÄÃÜÂëÀ´µ»¯Õâ´Î°²È«ÊÂÎñ¡£ÔÚHIBPÅû¶¸ÃÊÂÎñºó²»¾Ã£¬ZacksÊý¾Ý¿âÓÚ6ÔÂ10ÈÕ±»°ä²¼ÔÚºÚ¿ÍÂÛ̳ExposedÉÏ¡£
https://www.bleepingcomputer.com/news/security/have-i-been-pwned-warns-of-new-zacks-data-breach-impacting-8-million/
4¡¢Ó¢¹úͨѶ¼à¹Ü»ú¹¹OfcomÔâµ½¹¥»÷²¿ÃÅ»úÃÜÐÅϢй¶
ýÌå6ÔÂ12Èճƣ¬Ó¢¹úͨѶ¼à¹Ü»ú¹¹OfcomÔâµ½ÁËÁËÀÕË÷ÍÅ»ïClopµÄ¹¥»÷¡£¹¥»÷ÕßÀûÓÃÁËMOVEitÎļþ´«ÊäÖеķì϶(CVE-2023-34362)À´½Ó¼û¸Ã»ú¹¹µÄ»ù´¡ÉèÊ©¡£½²»°ÈËй©£¬¹¥»÷Õ߿ɽӼû¼à¹Ü»ú¹¹³ÖÓÐµÄÆä¼à¹ÜµÄ¹«Ë¾µÄ»úÃÜÐÅÏ¢£¬ÒÔ¼°²¿ÃÅOfcomÔ±¹¤µÄÓ×ÎÒÐÅÏ¢¡£ClopÓÚÉÏÖÜÈý°ä²¼ÁËÒ»·ÝÀÕË÷×¢Ã÷£¬Ðû³Æ°ÑÎÕÁËÊý°Ù¼ÒÆóÒµµÄÐÅÏ¢£¬²¢ÒªÇóÕâЩ×éÖ¯×Ô¶¯ÁªÏµÆäÀ´ÐÉÌÊê½ð£¬²»È»ÕâЩ×éÖ¯½«ÓÚ6ÔÂ14ÈÕ±»Áгö¡£
https://therecord.media/ofcom-cyberattack-uk-regulator-moveit-vulnerability
5¡¢Kaspersky°ä²¼¶à½×¶Î¼ÓÔØ·¨Ê½DoubleFingerµÄ»ã±¨
6ÔÂ12ÈÕ£¬Kaspersky°ä²¼Á˹ØÓÚÀûÓÃÐÂÐͶà½×¶Î¼ÓÔØ·¨Ê½DoubleFinger¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¹¥»÷ʼÓÚespexe.exeµÄÅú¸Ä°æ±¾£¬¿É´ÓͼÏñÍйܷþÎñImgur¼ìË÷¼Ù×°³ÉPNGµÄ¼ÓÃܵÄpayload¡£¸Ãpayload»á´¥·¢Ò»¸öÔ̺¬Ëĸö½×¶ÎµÄ¹¥»÷Á´£¬×îÖÕ»áÔÚÖ¸±êÖ÷»úÉÏÖ´ÐÐGreetingGhoul¡£GreetingGhoulÊÇÒ»¸öÇÔÈ¡·¨Ê½£¬Ö¼ÔÚÇÔÈ¡Óë¼ÓÃÜÇ®±ÒÓйصÄÍ´´¦¡£Õâ´Î¹¥»÷»î¶¯ÖØÒªÕë¶ÔÅ·ÖÞ¡¢ÃÀ¹úºÍÀ¶¡ÃÀÖÞ¡£
https://securelist.com/doublefinger-loader-delivering-greetingghoul-cryptocurrency-stealer/109982/
6¡¢Åµ»ùÑǰ䲼¹ØÓÚ2023ÄêÈ«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨
6ÔÂ9ÈÕ±¨Â·³Æ£¬Åµ»ùÑǰ䲼Á˹ØÓÚ2023ÄêÈ«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¸Ã»ã±¨Éî¿Ì·ÖÎöÁË4GºÍ5G°²È«¹¥»÷¡¢¶ñÒâÈí¼þ¹¥»÷¡¢DDoS¹¥»÷ÒÔ¼°Õë¶ÔÈ«Çò¹Ì¶¨ºÍÒÆ¶¯ÍøÂçµÄÆäËü´ó¾ÖµçÐÅÍøÂç¹¥»÷µÄÇ÷Ïò¡£»ã±¨Ö¸³ö£¬»ùÓÚ½©Ê¬ÍøÂçµÄDDoS¹¥»÷Éý¼¶£¬Ê¹Óõı»Ï°È¾ÎïÁªÍøÉ豸ÊýÁ¿´Ó200000¼¤ÔöÖÁÔ¼100Íò£¬Ä¿Ç°Õ¼ËùÓÐDDoSÁ÷Á¿µÄ40%ÒÔÉÏ¡£ÒÔÒÆ¶¯É豸ÉϵÄÒøÐÐÐÅϢΪָ±êµÄľÂíÊýÁ¿·ÁËÒ»·¬£¬Ä¿Ç°Õ¼ËùÓÐϰȾµÄ9%¡£¼ÒÍ¥ÍøÂçÖеĶñÒâÈí¼þϰȾÓÐËù½µÂ䣬´ÓCovid-19ÆÚ¼äµÄ3%½µÂäµ½1.5%¡£
https://www.nokia.com/networks/security-portfolio/threat-intelligence-report/


¾©¹«Íø°²±¸11010802024551ºÅ