Checkmarx¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©¸øÁ´¹¥»÷
°ä²¼¹¦·ò 2023-07-251¡¢Checkmarx¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©¸øÁ´¹¥»÷
CheckmarxÔÚ7ÔÂ21ÈÕ³ÆÆä¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©¸øÁ´£¨OSS£©¹¥»÷¡£µÚÒ»´Î¹¥»÷²úÉúÓÚ4ÔÂÉÏÑ®£¬¹¥»÷Õß¼ÙÒâÖ¸±êÒøÐÐÔ±¹¤£¬ÀûÓÃNPMƽ̨ÉÏ´«Á˼¸¸öÈí¼þ°ü£¬ÆäÖÐÔ̺¬Ô¤×°Öþ籾£¬¿ÉÔÚ×°ÖÃʱִÐжñÒâ»î¶¯¡£»¹ÀûÓÃAzureµÄCDN×ÓÓòÀ´·Ö·¢µÚ¶þ½×¶ÎµÄpayload Havoc£¬ÕâÊÇÒ»¸öC2¿ò¼Ü¡£ÔÚ2Ô·ݼì²âµ½µÄÕë¶ÔÒøÐеÄÁíÒ»´Î¹¥»÷ÖУ¬¹¥»÷ÕßÒ²ÉÏ´«ÁËÒ»¸ö¶ñÒânpm°ü£¬Ö¼ÔÚÀ¹½ØµÇ¼Êý¾Ý²¢½«Æä·¢Ë͸ø¹¥»÷Õß¡£Ä¿Ç°£¬×êÑÐÈËÔ±ÒѾ»ã±¨²¢É¾³ýÁËÕâЩ¶ñÒ⿪ԴÈí¼þ°ü¡£
https://checkmarx.com/blog/first-known-targeted-oss-supply-chain-attacks-against-the-banking-sector/
2¡¢Apple¸üн¨¸´Òѱ»ÀûÓõÄÄں˷ì϶CVE-2023-38606
¾ÝýÌå7ÔÂ24ÈÕ±¨Â·£¬Apple°ä²¼Á˰²È«¸üУ¬ÒÔ½¨¸´Õë¶ÔiPhone¡¢MacºÍiPadµÄ¹¥»÷Öб»ÀûÓõķì϶¡£ÕâÊÇÒ»¸öÄں˷ì϶£¨CVE-2023-38606£©£¬¿ÉÄܱ»ÓÃÀ´´Û¸ÄÃô¸ÐµÄÄÚºË״̬£¬¿ÉÄÜÒÑÔÚiOS 15.7.1֮ǰ°ä²¼µÄiOS°æ±¾Öб»»ý¼«ÀûÓá£Kaspersky°µÊ¾£¬CVE-2023-38606ÊÇÁãµã»÷·ì϶ÀûÓÃÁ´µÄÒ»²¿ÃÅ£¬ÓÃÓÚͨ¹ýiMessage·ì϶ÔÚiPhoneÉÏ×°ÖüäµýÈí¼þTriangulation¡£ÕâÊÇAppleÔÚ½ñÄ꽨¸´µÄµÚʮһ¸öÒѱ»ÀûÓõÄÁãÈÕ·ì϶¡£
https://www.bleepingcomputer.com/news/apple/apple-fixes-new-zero-day-used-in-attacks-against-iphones-macs/
3¡¢ClopÀûÓÃMOVEit·ì϶µÄ¹¥»÷Ô¤¹À»ñÀû7500ÍòÖÁ1ÒÚÃÀÔª
CovewareÔÚ7ÔÂ21ÈÕй©£¬ClopÀûÓÃMOVEit·ì϶µÄ´ó¹æÄ£Êý¾ÝÇÔÈ¡»î¶¯Ô¤¼Æ»ñÀû¸ß´ï7500ÍòÖÁ1ÒÚÃÀÔª¡£ÔÚ2023ÄêQ2£¬½»Êê½ðµÄ±»¹¥»÷Ö¸±êµÄÊýÁ¿ÒѽµÖÁ34%£¬´´Ïº¹Çàеͣ¬µ¼ÖÂÀÕË÷ÍÅ»ïŤתսÊõÒÔ×êÓª¸ü¸ßµÄÀûÈó¡£Coveware°µÊ¾£¬ClopÒѾŤתÁËÕ½Êõ£¬ÀÕË÷¸ü¸ßµÄÊê½ð£¬µ«Ô¸Í¨¹ý¼¸±Ê´ó¶î¸¶¿îÀ´¿Ë·þÕûÌå½µÂäµÄÇé¿ö¡£´Ë±í£¬¸´ÔÓÐÔºÍ×Ô¶¯»¯Ë®Æ½µÍµÄÀÕË÷¹¥»÷µÄÓ°ÏìºÍ³É±¾×îÓס£
https://www.coveware.com/blog/2023/7/21/ransom-monetization-rates-fall-to-record-low-despite-jump-in-average-ransom-payments
4¡¢×êÑÐÈËÔ±Åû¶OpenMeetings¿É½Ù³ÖÖÎÀíÔ¹ØÊ»§µÄ·ì϶
¾Ý7ÔÂ21ÈÕ±¨Â·£¬×êÑÐÈËÔ±Åû¶ÁËApache OpenMeetingsÖеÄ3¸ö·ì϶µÄϸ½Ú¡£ÕâЩ·ì϶±ðÀëΪÈõ¹þÏ£±ÈÁ¦·ì϶£¨CVE-2023-28936£©¡¢Í¨¹ýÔ¼Çë¹þÏ£½øÐÐÎÞÏ޶ȽӼûµÄ·ì϶£¨CVE-2023-29023£©ÒÔ¼°¿Õ×Ö½Ú×¢Èë·ì϶(CVE-2023-29246£©£¬¿É±»×ÔÐÐ×¢²áÓû§£¨Ä¬ÈÏÆôÓã©ÓÃÀ´½Ù³ÖÖÎÀíÔ¹ØÊ»§²¢Ô¶³ÌÖ´ÐÐËÁÒâ´úÂ롣Ŀǰ£¬ÕâЩ·ì϶ÒÑÔÚApache OpenMeetings 7.1.0°æ±¾Öн¨¸´¡£
https://www.securityweek.com/openmeetings-flaws-allow-hackers-to-hijack-instances-execute-code-on-servers/
5¡¢AhnLab·¢ÏÖͨ¹ýMS-SQL·þÎñÆ÷·Ö·¢PurpleFoxµÄ»î¶¯
7ÔÂ24ÈÕ£¬AhnLab³ÆÆä·¢ÏÖÁËͨ¹ýÖÎÀí²»ÉÆµÄMS-SQL·þÎñÆ÷·Ö·¢PurpleFoxµÄ»î¶¯¡£¹¥»÷Ê×ÏÈͨ¹ýsqlservr.exeÖ´ÐÐPowerShell£¬ÕâÊÇÒ»¸öÓëMS-SQL·þÎñÆ÷ÓйصĹý³Ì¡£µ±Ö´ÐÐÉÏÊöPowerShellʱ£¬½«ÏÂÔØ²¢¼ÓÔØÁíÒ»¸ö¾¹ý»ìºÏµÄPowerShell¡£ÆäÖÐÔ̺¬Ò»¸ö¹¥»÷Õß¿ª·¢µÄº¯ÊýMsiMake£¬¿ÉÏÂÔØÒ»¸öMSIÎļþ¡£MSI°ü¸ü¸Ä×¢²á±íÏîÒÔʵÏÖÓÆ¾ÃÐÔºÍȨÏÞÌáÉý¡£×îºó£¬MSI°ü»á³¢ÊÔ³ÁÆôϵͳ£¬½Ó×ÅSENS·þÎñ»á±»Ö´ÐУ¬´Ó¶ø¼¤»î¶ñÒâÈí¼þ¡£
https://asec.ahnlab.com/en/55492/
6¡¢IBM°ä²¼¹ØÓÚ2023ÄêÊý¾Ýй¶³É±¾µÄ·ÖÎö»ã±¨
7ÔÂ24ÈÕ£¬IBM°ä²¼¹ØÓÚ2023ÄêÊý¾Ýй¶³É±¾µÄ·ÖÎö»ã±¨¡£¸Ã»ã±¨¶Ô553¸ö×éÖ¯µÄÊý¾Ýй¶Çé¿ö½øÐÐÁË·ÖÎö£¬×êÑеÄÎ¥¹æÊÂÎñ²úÉúÔÚ2022Äê3ÔÂÖÁ2023Äê3Ô¡£×îÐÂ×êÑÐÏÔʾ£¬Êý¾Ýй¶³É±¾³ÖÐøÔö³¤£¬È«Çò¾ùÔȳɱ¾¸ß´ï445ÍòÃÀÔª£¬ÈýÄêÄÚÔö³¤ÁË15%¡£Ò½ÁƱ£½¡ÐÐÒµµÄ³É±¾Î»¾Ó°ñÊ×£¬Â½Ðø13Äê³ÉΪ³É±¾×î¸ßµÄÐÐÒµ¡£»ã±¨Ö¸³ö£¬°²È«ÈËΪÖÇÄܺÍ×Ô¶¯»¯¡¢DevSecOps²½ÖèºÍIR´òËãÔÚ½Ú¼ó³É±¾·½Ãæ²ûÑïÁËÖ÷µ¼×÷Óã»ÈËΪÖÇÄܺÍASM¼Ó¿ìÁËÎ¥¹æÊÂÎñµÄ¼ø±ðºÍ¶ôÔ죻µ±Êý¾Ý´æ´¢ÔÚ¶à¸ö»·¾³ÖÐʱ£¬³É±¾ºÜ¸ß£¬²¢ÇÒ±ØÒª¸ü³¤¹¦·òÄÜÁ¦¶ôÔìÎ¥¹æÊÂÎñ£»Õ¼Óз¢ÏÖÎ¥¹æÊÂÎñµÄÄÚ²¿ÍŶӵÄ×éÖ¯ÔÚ½ÚÔì³É±¾·½Ãæ²û·¢µÃ¸üºÃ¡£
https://securityintelligence.com/posts/whats-new-2023-cost-of-a-data-breach-report/


¾©¹«Íø°²±¸11010802024551ºÅ