Zimbra½¨¸´ZCSÖÐÒѱ»ÀûÓõÄXSS·ì϶CVE-2023-38750
°ä²¼¹¦·ò 2023-08-011¡¢Zimbra½¨¸´ZCSÖÐÒѱ»ÀûÓõÄXSS·ì϶CVE-2023-38750
¾ÝýÌå7ÔÂ27ÈÕ±¨Â·£¬Zimbra°ä²¼°²È«¸üУ¬½¨¸´ÁËÕë¶ÔZimbra Collaboration Suite(ZCS)µç×ÓÓʼþ·þÎñÆ÷µÄ¹¥»÷Öб»ÀûÓõķì϶¡£ÕâÊÇÒ»¸öXSS·ì϶£¨CVE-2023-38750£©£¬¿ÉÄܱ»ÓÃÀ´ÇÔÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐжñÒâ´úÂë¡£¹ÌÈ»ZimbraÔÚ³õ´ÎÅû¶¸Ã·ì϶²¢¶½´ÙÓû§ÊÖ¶¯½¨¸´Ê±£¬²¢Î´Åú×¢¸Ã·ì϶Òѱ»ÀûÓà £¬µ«Google TAGй©£¬¸Ã·ì϶ÊÇÔÚÓÐÕë¶ÔÐԵĹ¥»÷Öб»·¢Ïֵġ£´Ë±í£¬CISAÒ²°ä²¼Á˹«¸æ£¬ÒªÇóÁª¹ú»ú¹¹ÔÚ8ÔÂ17ÈÕ֮ǰ½¨¸´¸Ã·ì϶¡£
https://www.bleepingcomputer.com/news/security/zimbra-patches-zero-day-vulnerability-exploited-in-xss-attacks/
2¡¢Tempur SealyÔâµ½ÍøÂç¹¥»÷µ¼Ö¹«Ë¾ÔËÓªÁÙʱÖжÏ
¾Ý8ÔÂ1ÈÕ±¨Â·£¬´²µæÏúÊÛÉÌTempur SealyÔâµ½ÍøÂç¹¥»÷£¬ÆÈʹ²¿ÃÅϵÍÂäÙʱ¹Ø¹Ø¡£Tempur Sealy±»ÒÔΪÊÇÈ«Çò×î´óµÄ´²ÉÏÓÃÆ·¹©¸øÉÌ£¬Éϼ¾¶È¾»ÏúÊÛ¶îΪ12ÒÚÃÀÔª¡£¸Ã¹«Ë¾ÔÚ±¾ÖÜһй©£¬ÓÚ7ÔÂ23ÈÕÔâµ½Á˹¥»÷£¬Æä²ÉÈ¡ÏìÓ¦´ëÊ©×Ô¶¯¹Ø¹ØÁ˲¿ÃÅITϵͳ£¬Õâµ¼Ö¹«Ë¾ÔËÓªÁÙʱÖжϡ£Ä¿Ç°£¬¸Ã¹«Ë¾ÒÑÆðÍ·½«²¿ÃÅÖØÒªµÄϵͳ³ÁÐÂÉÏÏß²¢¸´ÔÔËÓª¡£µ÷²éÈÔÔÚ½øÐÐÖУ¬ÒÔÈ·¶¨¶ÔÒµÎñºÍ²ÆÕþ²úÉúµÄÓ°Ï죬Éв»Ã÷ÏÔÊÇ·ñÉæ¼°¿Í»§»òÔ±¹¤ÐÅÏ¢£¬ÒÔ¼°¹¥»÷ÕßµÄÉí·Ý¡£
https://therecord.media/mattress-giant-tempur-sealy-cyberattack
3¡¢²éËþŬ¼ÓÐÄÔà×êÑÐËù´«µÝÉæ¼°17ÍòÈ˵ÄÊý¾Ýй¶ÊÂÎñ
7ÔÂ29ÈÕ±¨Â·³Æ£¬²éËþŬ¼ÓÐÄÔà×êÑÐËù£¨Chattanooga Heart Institute£¬CHI£©´«µÝÁËÉæ¼°17ÍòÈ˵ÄÊý¾Ýй¶ÊÂÎñ¡£5Ô·ݣ¬KarakurtÍÅ»ï³Æ¹¥»÷Á˸ûú¹¹£¬²¢ÇÔÈ¡ÁË158GBµÄÊý¾Ý¡£¹¥»÷ÕßûÓÐÌṩ֤¾Ý£¬µ«°µÊ¾Ð¹Â¶Êý¾ÝÔ̺¬Ò½ÁƼͼ¡¢²é³Á˾֡¢Õï¶Ï¡¢Éç»á°²È«ºÅÂë¡¢»¤ÕÕ¡¢ºÍ²ÆÕþÐÅÏ¢µÈ£¬ÆäʱCHI²¢Î´»ØÓ¦´ËÊÂÎñ¡£7ÔÂ28ÈÕ£¬CHIй©ÓÐ170450ÈËÊܵ½Êý¾Ýй¶ÊÂÎñµÄÓ°Ïì¡£ËûÃÇÓÚ4ÔÂ17ÈÕ¼ì²âµ½¹¥»÷¼£Ïó£¬È·¶¨ÏµÍ³ÔÚ3ÔÂ8ÈÕÖÁ16ÈÕÆÚ¼äÔø±»½Ó¼û¹ý¡£Ö±µ½5ÔÂ31ÈÕ£¬CHI²ÅµÃÖª»¼ÕߵĽ¡È«ÐÅÏ¢ºÍµ£±£ÈËÐÅÏ¢±»Ð¹Â¶¡£
https://www.databreaches.net/the-chattanooga-heart-institute-to-notify-170450-about-march-data-security-incident/
4¡¢ÃÀ¹úSAISÊý¾Ý¿âÅäÖÃÃýÎóй¶572 GBѧÉúºÍÀÏʦµÄÐÅÏ¢
ýÌå7ÔÂ28ÈÕ±¨Â·³Æ£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öδÊܱ£»¤µÄÊý¾Ý¿â£¬ÆäÖÐÔ̺¬Óë½ÌÓý»ú¹¹ÓйصÄ682438±Ê¼Í¼¡£µ÷²é·¢ÏÖ£¬Êý¾Ý¿âÊôÓÚÄÏ·½¶ÀÁ¢Ñ§ÌÃлá(SAIS)£¬ÕâÊÇλÓÚÃÀ¹úµÄÒ»¸ö×ÔÔ¸ÐÔµØÓòÈÏ֤лᡣÕâ´Îй¶µÄÊý¾Ý¹²572.8 GB£¬¹¦·ò¿ç¶È´Ó2012Äêµ½2023Ä꣬Ô̺¬Ñ§ÉúºÍÀÏʦ¼Í¼¡¢½¡È«ÐÅÏ¢¡¢Éç»á°²È«ºÅÂ롢ǹ»÷°¸ºÍ¹Ø±Õ֪ͨ¡¢Ñ§ÌõØÍ¼ºÍ²ÆÕþÔ¤ËãµÈ¡£Ä¿Ç°£¬¸ÃÊý¾Ý¿âÒѱ»±£»¤ÆðÀ´¡£
https://www.hackread.com/data-leak-student-faculty-accreditation-org/
5¡¢Google°ä²¼¹ØÓÚ2022Äê¶È0day·ì϶µÄ»ØÊ׻㱨
7ÔÂ27ÈÕ£¬Google°ä²¼ÁËÄê¶È0day·ì϶»ã±¨£¬ÌṩÁË2022ÄêÒÔÀ´µÄÒ°±íÀûÓÃͳ¼ÆÊý¾Ý¡£2022Äê¼ì²â²¢Åû¶ÁË41¸öÔÚÒ°µÄ0day£¬ÆäÖÐÉϰëÄê20¸ö£¬Ï°ëÄê21¸ö£¬½ö´ÎÓÚ2021ÄêµÄ69¸ö·ì϶¡£ÔÚAndroidÖУ¬´æÔÚ¶àÖÖÇé¿ö£¬Óû§Ôںܳ¤Ò»¶Î¹¦·òÄÚÎÞ·¨»ñµÃ²¹¶¡¡£Òò¶ø¶ÔÓÚ¹¥»÷ÕßÀ´Ëµ£¬NdayµÄÖ°ÄÜÀàËÆÓÚ0day¡£ÔÚ2022ÄêµÄ41¸ö0dayÖУ¬ÓÐ17¸öÊÇ֮ǰ»ã±¨µÄ·ì϶µÄ±äÌ壬ռ±È³¬¹ý40%¡£
https://security.googleblog.com/2023/07/the-ups-and-downs-of-0-days-year-in.html
6¡¢Kaspersky°ä²¼2023ÄêQ2 APT¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨
7ÔÂ27ÈÕ£¬Kaspersky°ä²¼ÁË2023ÄêQ2 APT¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£±¾¼¾¶ÈµÄÖØÒªÁÁµãÖ®Ò»ÊÇ·¢ÏÖÁ˳־ÃÔËÓªµÄOperation Triangulation»î¶¯£¬ÆäÖÐÔ̺¬ÐµÄiOS¶ñÒâÈí¼þƽ̨¡£APT»î¶¯ÔÚµØÀíÉ¢²¼ÉÏÒÀÈ»ºÜ·ÖÉ¢£¬±¾¼¾¶È£¬¹¥»÷ÕßÖØÒªÕë¶ÔÅ·ÖÞ¡¢À¶¡ÃÀÖÞ¡¢Öж«ºÍÑÇÖÞ¸÷µØ¡£´Ë±í£¬³ÉÊìµÄ¹¥»÷ÕßÔÚ²»ÐݼÓÇ¿Æä¹¤¾ß£¬ÈçLazarus¿ª·¢ÁËMATA¿ò¼Ü¡¢BlueNoroffʹÓÃÁËеĴ«Ê䷽ʽºÍ±à³Ì˵»°¡¢ScarCruftʹÓÃÁËеÄϰȾ·½Ê½ÒÔ¼°GoldenJackalеĶñÒâÈí¼þÑù±¾¡£»¹·¢ÏÖÁËй¥»÷ÕßMysterious ElephantµÄ»î¶¯¡£
https://securelist.com/apt-trends-report-q2-2023/110231/


¾©¹«Íø°²±¸11010802024551ºÅ