Docker HubÉÏÍйܵĴóÁ¿¾µÏñй¶˽ԿºÍAPIÃÜÔ¿µÈÐÅÏ¢

°ä²¼¹¦·ò 2023-07-18

1¡¢Docker HubÉÏÍйܵĴóÁ¿¾µÏñй¶˽ԿºÍAPIÃÜÔ¿µÈÐÅÏ¢


¾ÝýÌå7ÔÂ16ÈÕ±¨Â·£¬µÂ¹úÑÇ衹¤Òµ´óѧ×êÑÐÈËÔ±·¢ÏÖ£¬Docker HubÉÏÍйܵĴóÁ¿¾µÏñй¼ûô¸ÐµÄÐÅÏ¢¡£×êÑÐÈËÔ±·ÖÎöÁËÀ´×ÔDocker HubºÍÊýǧ¸ö˽ÓÐ×¢²á±íµÄ337171¸ö¾µÏñ£¬·¢ÏÖÔ¼8.5%Ô̺¬Ë½Ô¿ºÍAPIÃÜÔ¿µÈÊý¾Ý¡£Ê¹ÓÃÕýÔò±í°×ʽËÑË÷ÌØ¶¨Êý¾ÝµÄ·ÖÎöÏÔʾ£¬28621¸öDocker¾µÏñй¶ÁË52107¸öÓÐЧ˽ԿºÍ3158¸ö·ÖÆçµÄAPIÃÜÔ¿¡£´óÎÞÊýй¶µÄÐÅÏ¢£¨95%Ϊ˽Կ£¬90%ΪAPIÃÜÔ¿£©¶¼´æÔÚÓÚµ¥Óû§¾µÏñÖУ¬ÕâÅú×¢ËüÃÇ¿ÉÄÜÊÇÎÞÒâ¼äй¶µÄ¡£


https://www.bleepingcomputer.com/news/security/thousands-of-images-on-docker-hub-leak-auth-secrets-private-keys/


2¡¢Rapid7й©¶à¸öAdobe ColdFusion·ì϶Òѱ»×Ô¶¯ÀûÓÃ


Rapid7ÔÚ7ÔÂ17ÈÕй©£¬Æä¹Û²ìµ½Adobe ColdFusion·ì϶ÔÚ¶à¸ö¿Í»§ÏµÍ³Öб»ÀûÓõÄÇé¿ö¡£Æ¾¾ÝÏÖÓÐÖ¤¾Ý£¬¹¥»÷ÕßÈçͬÔÚÀûÓýӼû½ÚÔìÈÆ¹ý·ì϶(CVE-2023-29298)ºÍÁíÒ»¸ö·ì϶¡£×êÑÐÈËÔ±³Æ£¬¹Û²ìµ½µÄ¹¥»÷ËÆºõÓëCVE-2023-38203ÓйØ¡£´Ë±í£¬AdobeÔÚ7ÔÂ11ÈÕΪCVE-2023-29298ÌṩµÄ½¨¸´·¨Ê½²¢²»ÆëÈ«£¬¾­¹ýµ¥Ò»Åú¸ÄµÄ·ì϶ÀûÓÃÒÀÈ»ºÏÓÃÓÚ×îа汾µÄColdFusion¡£µ«ÓÉÓڸ÷ì϶±ØÒªÓëÁíÒ»¸ö·ì϶½áºÏʹÓã¬ÀýÈçCVE-2023-38203¡£Òò¶ø£¬×°ÖÃ×îа汾µÄColdFusionÈÔÄܹ»×èÖ¹·ì϶µÄÀûÓá£


https://www.rapid7.com/blog/post/2023/07/17/etr-active-exploitation-of-multiple-adobe-coldfusion-vulnerabilities/


3¡¢¿ÆÂÞÀ­¶àÖÝÁ¢´óѧÔâµ½ÀÕË÷¹¥»÷ѧÉúºÍÔ±¹¤µÄÐÅϢй¶


¾Ý7ÔÂ14ÈÕ±¨Â·£¬¿ÆÂÞÀ­¶àÖÝÁ¢´óѧ(CSU)Ôâµ½ÁËClopÀÕË÷¹¥»÷£¬ÏÖÈκÍǰÈÎѧÉúºÍÔ±¹¤µÄÓ×ÎÒÐÅϢй¶¡£¸Ã´óѧÓÚ7ÔÂ12ÈÕÏòÊÜÓ°ÏìµÄÓ×ÎҰ䲼֪ͨ¡£Õâ´Îй¶²¢²»ÊÇCSUµÄϵͳÔâµ½¹¥»÷µ¼ÖµÄ£¬¶øÊÇ·þÎñÌṩÉÌ¡¢TIAA¡¢¹ú¶ÈѧÉúÐÅÏ¢»¥»»ËùºÍCorebridge FinancialµÈʹÓÃÁËMOVEit Transfer°²È«Îļþ´«ÊäÆ½Ì¨Ôâµ½ÈëÇÖµ¼ÖµÄ¡£Ä¿Ç°£¬¸ÃѧÌò»»áÏòCSU»áÔ±ÌṩÉí·Ý͵ÇÔ±£»¤·þÎñ£¬½¨Òé»áÔ±×ñÑ­FTC°ä²¼µÄ½¨Òé¡£ 


https://www.bleepingcomputer.com/news/security/colorado-state-university-says-data-breach-impacts-students-staff/


4¡¢Cyble·¢ÏÖ¼ÙÒâTeamViewer×°Ö÷¨Ê½·Ö·¢njRATµÄ»î¶¯


7ÔÂ13ÈÕ£¬CybleÅû¶Á˼ÙÒâTeamViewer×°Ö÷¨Ê½·Ö·¢Ä¾ÂínjRAT£¨±ðÃûBladabindi£©µÄ»î¶¯¡£njRAT×î³õÓÚ2012Äê±»·¢ÏÖ£¬ÖØÒªÓÃÓÚÕë¶ÔÖж«¹ú¶ÈµÄ×éÖ¯¡£×êÑÐÈËÔ±·¢ÏֵĶñÒâÈí¼þÑù±¾ÊÇÒ»¸ö32λÖÇÄÜ×°Ö÷¨Ê½£¬Ëü»á×°ÖÃÒ»¸öÕý°æTeamViewerÀûÓúͶñÒâÈí¼þnjRAT¡£Ö´Ðк󣬻áÆô¶¯TeamViewerÀûÓò¢´¥·¢njRAT¡£ÎªÁËÈ·Î¬ÓÆ¾ÃÐÔ£¬njRAT»¹Åú¸ÄϵͳÉèÖ㬴ӶøÈƹý°²È«ÖÒ¸æÌáÐÑ¡£²¢ÔÚϵͳע²á±íÖд´½¨×Ô¶¯ÔËÐÐÌõ¿î£¬ÒÔ±£ÕÏÿ´ÎϵͳÆô¶¯Ê±×Ô¶¯ÔËÐС£


https://blog.cyble.com/2023/07/13/trojanized-application-preying-on-teamviewer-users/


5¡¢ZimbraÌáÐÑÓû§ÊÖ¶¯½¨¸´ÆäZCSÖÐÒѱ»ÀûÓõÄXSS·ì϶


7ÔÂ13ÈÕ±¨Â·³Æ£¬ZimbraÌáÐÑÓû§ÊÖ¶¯½¨¸´Zimbra Collaboration Suite(ZCS)µç×ÓÓʼþ·þÎñÆ÷ÖÐÒѱ»ÀûÓõÄXSS·ì϶¡£¹ÌÈ»ZimbraûÓÐй©¸Ã·ì϶±»ÓÃÓÚ¹¥»÷£¬µ«Google TAG°µÊ¾£¬¸ÃXSS·ì϶ÊÇÔÚÒ»´ÎÓÐÕë¶ÔÐԵĹ¥»÷Öб»·¢Ïֵġ£ZimbraÉÐδÌṩ°²È«²¹¶¡À´½¨¸´Õâ¸öÁãÈÕ·ì϶£¬µ«ËüµÄÈ·ÌṩÁËÒ»¸ö½¨¸´·¨Ê½£¬²¢½¨ÒéÖÎÀíÔ±ÊÖ¶¯ÀûÓøý¨¸´·¨Ê½À´½¨¸´´Ë·ì϶¡£´Ë±í£¬Zimbra³Æ¸Ã½¨¸´·¨Ê½´òËãÔÚ7Ô·ݵIJ¹¶¡ÖÐÌṩ¡£


https://securityaffairs.com/148429/hacking/zimbra-collaboration-suite-zeroday.html


6¡¢Check Point°ä²¼2023ÄêQ2ÍøÂç¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨


7ÔÂ13ÈÕ£¬Check Point°ä²¼2023ÄêµÚ¶þ¼¾¶ÈÍøÂç¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£2023ÄêQ2£¬È«Çò¾ùÔÈÿÖܹ¥»÷´ÎÊý½ÏÉÏÄêÔö³¤8%£¬Ã¿¸ö×é֯ÿÖܵľùÔȹ¥»÷´ÎÊý´ïµ½1258´Î¡£½ÌÓýºÍ×êÑÐÐÐÒµÔâµ½µÄ¹¥»÷´ÎÊý×î¶à£¬Ã¿¸ö×éÖ¯¾ùÔÈÿÖܱ»¹¥»÷2179´Î£¬Óë2022ÄêQ2Ïà±È½µÂäÁË6% ¡£µ±¾ÖºÍ¾üʲ¿ÃÅ´ÎÖ®£¬¾ùÔÈÿÖÜ1772´Î¹¥»÷£¬±ÈÈ¥ÄêͬÆÚÔö³¤9%¡£·ÇÖÞµÄ×éÖ¯Ôâµ½µÄ¹¥»÷×î¶à£¬±ÈÈ¥Äêͬ±ÈÔö³¤23%¡£Æä´ÎÊÇÑÇÌ«µØÓò£¬Ôö³¤ÁË22%¡£È«Çòÿ44¸ö×éÖ¯ÖоÍÓÐ1¸öÔâµ½ÁËÀÕË÷¹¥»÷£¬ÆäÖе±¾ÖºÍ¾üÊÂÐÐÒµÔâµ½´ËÀ๥»÷µÄ´ÎÊý×î¶à¡£


https://blog.checkpoint.com/security/average-weekly-global-cyberattacks-peak-with-the-highest-number-in-2-years-marking-an-8-growth-year-over-year-according-to-check-point-research/