Zimbra½¨¸´ZCSÖÐÒѱ»ÀûÓõÄXSS·ì϶CVE-2023-38750

°ä²¼¹¦·ò 2023-08-01

1¡¢Zimbra½¨¸´ZCSÖÐÒѱ»ÀûÓõÄXSS·ì϶CVE-2023-38750 


¾ÝýÌå7ÔÂ27ÈÕ±¨Â· £¬Zimbra°ä²¼°²È«¸üР£¬½¨¸´ÁËÕë¶ÔZimbra Collaboration Suite(ZCS)µç×ÓÓʼþ·þÎñÆ÷µÄ¹¥»÷Öб»ÀûÓõķì϶¡£ÕâÊÇÒ»¸öXSS·ì϶£¨CVE-2023-38750£© £¬¿ÉÄܱ»ÓÃÀ´ÇÔÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐжñÒâ´úÂë¡£¹ÌÈ»ZimbraÔÚ³õ´ÎÅû¶¸Ã·ì϶²¢¶½´ÙÓû§ÊÖ¶¯½¨¸´Ê± £¬²¢Î´Åú×¢¸Ã·ì϶Òѱ»ÀûÓà £¬µ«Google TAGй© £¬¸Ã·ì϶ÊÇÔÚÓÐÕë¶ÔÐԵĹ¥»÷Öб»·¢Ïֵġ£´Ë±í £¬CISAÒ²°ä²¼Á˹«¸æ £¬ÒªÇóÁª¹ú»ú¹¹ÔÚ8ÔÂ17ÈÕ֮ǰ½¨¸´¸Ã·ì϶¡£


https://www.bleepingcomputer.com/news/security/zimbra-patches-zero-day-vulnerability-exploited-in-xss-attacks/


2¡¢Tempur SealyÔâµ½ÍøÂç¹¥»÷µ¼Ö¹«Ë¾ÔËÓªÁÙʱÖжÏ


¾Ý8ÔÂ1ÈÕ±¨Â· £¬´²µæÏúÊÛÉÌTempur SealyÔâµ½ÍøÂç¹¥»÷ £¬ÆÈʹ²¿ÃÅϵÍÂäÙʱ¹Ø¹Ø¡£Tempur Sealy±»ÒÔΪÊÇÈ«Çò×î´óµÄ´²ÉÏÓÃÆ·¹©¸øÉÌ £¬Éϼ¾¶È¾»ÏúÊÛ¶îΪ12ÒÚÃÀÔª¡£¸Ã¹«Ë¾ÔÚ±¾ÖÜһй© £¬ÓÚ7ÔÂ23ÈÕÔâµ½Á˹¥»÷ £¬Æä²ÉÈ¡ÏìÓ¦´ëÊ©×Ô¶¯¹Ø¹ØÁ˲¿ÃÅITϵͳ £¬Õâµ¼Ö¹«Ë¾ÔËÓªÁÙʱÖжÏ¡£Ä¿Ç° £¬¸Ã¹«Ë¾ÒÑÆðÍ·½«²¿ÃÅÖØÒªµÄϵͳ³ÁÐÂÉÏÏß²¢¸´Ô­ÔËÓª¡£µ÷²éÈÔÔÚ½øÐÐÖÐ £¬ÒÔÈ·¶¨¶ÔÒµÎñºÍ²ÆÕþ²úÉúµÄÓ°Ïì £¬Éв»Ã÷ÏÔÊÇ·ñÉæ¼°¿Í»§»òÔ±¹¤ÐÅÏ¢ £¬ÒÔ¼°¹¥»÷ÕßµÄÉí·Ý¡£


https://therecord.media/mattress-giant-tempur-sealy-cyberattack


3¡¢²éËþŬ¼ÓÐÄÔà×êÑÐËù´«µÝÉæ¼°17ÍòÈ˵ÄÊý¾Ýй¶ÊÂÎñ


7ÔÂ29ÈÕ±¨Â·³Æ £¬²éËþŬ¼ÓÐÄÔà×êÑÐËù£¨Chattanooga Heart Institute £¬CHI£©´«µÝÁËÉæ¼°17ÍòÈ˵ÄÊý¾Ýй¶ÊÂÎñ¡£5ÔÂ·Ý £¬KarakurtÍÅ»ï³Æ¹¥»÷Á˸ûú¹¹ £¬²¢ÇÔÈ¡ÁË158GBµÄÊý¾Ý¡£¹¥»÷ÕßûÓÐÌṩ֤¾Ý £¬µ«°µÊ¾Ð¹Â¶Êý¾ÝÔ̺¬Ò½ÁƼͼ¡¢²é³­Á˾֡¢Õï¶Ï¡¢Éç»á°²È«ºÅÂë¡¢»¤ÕÕ¡¢ºÍ²ÆÕþÐÅÏ¢µÈ £¬ÆäʱCHI²¢Î´»ØÓ¦´ËÊÂÎñ¡£7ÔÂ28ÈÕ £¬CHIй©ÓÐ170450ÈËÊܵ½Êý¾Ýй¶ÊÂÎñµÄÓ°Ïì¡£ËûÃÇÓÚ4ÔÂ17ÈÕ¼ì²âµ½¹¥»÷¼£Ïó £¬È·¶¨ÏµÍ³ÔÚ3ÔÂ8ÈÕÖÁ16ÈÕÆÚ¼äÔø±»½Ó¼û¹ý¡£Ö±µ½5ÔÂ31ÈÕ £¬CHI²ÅµÃÖª»¼ÕߵĽ¡È«ÐÅÏ¢ºÍµ£±£ÈËÐÅÏ¢±»Ð¹Â¶¡£


https://www.databreaches.net/the-chattanooga-heart-institute-to-notify-170450-about-march-data-security-incident/


4¡¢ÃÀ¹úSAISÊý¾Ý¿âÅäÖÃÃýÎóй¶572 GBѧÉúºÍÀÏʦµÄÐÅÏ¢


ýÌå7ÔÂ28ÈÕ±¨Â·³Æ £¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öδÊܱ £»¤µÄÊý¾Ý¿â £¬ÆäÖÐÔ̺¬Óë½ÌÓý»ú¹¹ÓйصÄ682438±Ê¼Í¼¡£µ÷²é·¢ÏÖ £¬Êý¾Ý¿âÊôÓÚÄÏ·½¶ÀÁ¢Ñ§ÌÃЭ»á(SAIS) £¬ÕâÊÇλÓÚÃÀ¹úµÄÒ»¸ö×ÔÔ¸ÐÔµØÓòÈÏ֤Э»á¡£Õâ´Îй¶µÄÊý¾Ý¹²572.8 GB £¬¹¦·ò¿ç¶È´Ó2012Äêµ½2023Äê £¬Ô̺¬Ñ§ÉúºÍÀÏʦ¼Í¼¡¢½¡È«ÐÅÏ¢¡¢Éç»á°²È«ºÅÂ롢ǹ»÷°¸ºÍ¹Ø±Õ֪ͨ¡¢Ñ§ÌõØÍ¼ºÍ²ÆÕþÔ¤ËãµÈ¡£Ä¿Ç° £¬¸ÃÊý¾Ý¿âÒѱ»± £»¤ÆðÀ´¡£


https://www.hackread.com/data-leak-student-faculty-accreditation-org/


5¡¢Google°ä²¼¹ØÓÚ2022Äê¶È0day·ì϶µÄ»ØÊ׻㱨


 7ÔÂ27ÈÕ £¬Google°ä²¼ÁËÄê¶È0day·ì϶»ã±¨ £¬ÌṩÁË2022ÄêÒÔÀ´µÄÒ°±íÀûÓÃͳ¼ÆÊý¾Ý¡£2022Äê¼ì²â²¢Åû¶ÁË41¸öÔÚÒ°µÄ0day £¬ÆäÖÐÉϰëÄê20¸ö £¬Ï°ëÄê21¸ö £¬½ö´ÎÓÚ2021ÄêµÄ69¸ö·ì϶¡£ÔÚAndroidÖÐ £¬´æÔÚ¶àÖÖÇé¿ö £¬Óû§Ôںܳ¤Ò»¶Î¹¦·òÄÚÎÞ·¨»ñµÃ²¹¶¡¡£Òò¶ø¶ÔÓÚ¹¥»÷ÕßÀ´Ëµ £¬NdayµÄÖ°ÄÜÀàËÆÓÚ0day¡£ÔÚ2022ÄêµÄ41¸ö0dayÖÐ £¬ÓÐ17¸öÊÇ֮ǰ»ã±¨µÄ·ì϶µÄ±äÌå £¬Õ¼±È³¬¹ý40%¡£


https://security.googleblog.com/2023/07/the-ups-and-downs-of-0-days-year-in.html


6¡¢Kaspersky°ä²¼2023ÄêQ2 APT¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨


7ÔÂ27ÈÕ £¬Kaspersky°ä²¼ÁË2023ÄêQ2 APT¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£±¾¼¾¶ÈµÄÖØÒªÁÁµãÖ®Ò»ÊÇ·¢ÏÖÁ˳־ÃÔËÓªµÄOperation Triangulation»î¶¯ £¬ÆäÖÐÔ̺¬ÐµÄiOS¶ñÒâÈí¼þƽ̨¡£APT»î¶¯ÔÚµØÀíÉ¢²¼ÉÏÒÀÈ»ºÜ·ÖÉ¢ £¬±¾¼¾¶È £¬¹¥»÷ÕßÖØÒªÕë¶ÔÅ·ÖÞ¡¢À­¶¡ÃÀÖÞ¡¢Öж«ºÍÑÇÖÞ¸÷µØ¡£´Ë±í £¬³ÉÊìµÄ¹¥»÷ÕßÔÚ²»ÐݼÓÇ¿Æä¹¤¾ß £¬ÈçLazarus¿ª·¢ÁËMATA¿ò¼Ü¡¢BlueNoroffʹÓÃÁËеĴ«Ê䷽ʽºÍ±à³Ì˵»°¡¢ScarCruftʹÓÃÁËеÄϰȾ·½Ê½ÒÔ¼°GoldenJackalеĶñÒâÈí¼þÑù±¾¡ £»¹·¢ÏÖÁËй¥»÷ÕßMysterious ElephantµÄ»î¶¯¡£


https://securelist.com/apt-trends-report-q2-2023/110231/