×êÑÐÈËÔ±Åû¶WinRARÖеÄRCE·ì϶CVE-2023-40477

°ä²¼¹¦·ò 2023-08-21

1¡¢×êÑÐÈËÔ±Åû¶WinRARÖеÄRCE·ì϶CVE-2023-40477


¾ÝýÌå8ÔÂ18ÈÕ±¨Â· £¬×êÑÐÈËÔ±goodbyeseleneÅû¶ÁËWinRARÖеķì϶£¨CVE-2023-40477£© ¡£¸Ã·ì϶´æÔÚÓÚ¸´Ô­¾íµÄ´¦Öùý³ÌÖÐ £¬ÓÉÓÚ²»×ã¶ÔÓû§ÌṩÊý¾ÝµÄÊʵ±ÑéÖ¤ £¬¿ÉÄܵ¼ÖÂÄÚ´æ½Ó¼û³¬¹ý¶ÈÅ仺³åÇøµÄ½áβ ¡£µ±Óû§´ò¿ªÌØÔìµÄRARÎļþºó £¬Ô¶³Ì¹¥»÷ÕßÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë ¡£×êÑÐÈËÔ±ÓÚ6ÔÂ8ÈÕÏò¹©¸øÉÌRARLAB»ã±¨ÁËÕâÒ»·ì϶ £¬RARLABÓÚ8ÔÂ2ÈÕ°ä²¼Á˲¹¶¡ £¬¸Ã²¹¶¡»¹½â¾öÁËÌØÔì´æµµµ¼ÖÂÎļþÆô¶¯ÃýÎóµÄÎÊÌâ ¡£


https://www.bleepingcomputer.com/news/security/winrar-flaw-lets-hackers-run-programs-when-you-open-rar-archives/


2¡¢ÌØË¹À­¹«¿ªÓ°Ï쳬¹ý7ÍòÃûÔ±¹¤ÐÅÏ¢µÄÊý¾Ýй¶ÊÂÎñ


8ÔÂ19ÈÕ±¨Â·³Æ £¬ÌØË¹À­Åû¶ÁË5Ô·ݲúÉúµÄÊý¾Ýй¶ÊÂÎñ ¡£¹«Ë¾µ÷²é·¢ÏÖ £¬Á½ÃûǰԱ¹¤ÇÔÈ¡ÁË»úÃÜÐÅÏ¢ £¬Î¥·´ÁËÌØË¹À­µÄIT°²È«ºÍÊý¾Ý±£»¤Õþ²ß ¡£Òò¶ø £¬ÌØË¹À­¶ÔÕâЩǰԱ¹¤Ìá¸æ×´ËÏ £¬²¢¿ÛѺÁËËûÃÇÔ̺¬±»µÁÐÅÏ¢µÄµç×ÓÉ豸 ¡£´Ë±í £¬ÌØË¹À­»¹·¢ÏÖÕâÁ½ÃûÔ±¹¤ÓëµÂ¹ú±¨ÉçHandelsblatt·ÖÏíÁ˱»µÁµÄÊý¾Ý ¡£²»Íâ £¬Õâ¼Ò±¨ÉçÏòÌØË¹À­±£ÕÏ £¬ËûÃDz»»á¹«¿ªÕâЩÐÅÏ¢ ¡£¸ÃÊÂÎñÓ°ÏìÁË75735ÃûÔ±¹¤ £¬ÌØË¹À­½«ÎªËûÃÇÌṩΪÆÚ12¸öÔµÄÐÅÓþ¼à¿ØºÍÉí·Ý͵ÇÔ·þÎñ ¡£


https://www.databreaches.net/tesla-notifies-employees-of-data-breach/


3¡¢·¨ÂÉ»ú¹¹Africa Cyber Surge IIÐж¯¿ÛÁô14ÃûÏÓÒÉÈË


ýÌå8ÔÂ18ÈÕ³Æ £¬¹ú¼ÊÐ̾¯×é֯Эµ÷µÄ·¨ÂÉÐж¯Africa Cyber Surge IIÒÑ¿ÛÁôÁË14ÃûÏÓÒÉÈË ¡£¸ÃÐж¯ÓÚ½ñÄê4ÔÂ·ÝÆðÍ· £¬¸²¸ÇÁË·ÇÖÞµÄ25¸ö¹ú¶È £¬µ·»ÙÁË20000¶à¸öÓÃÓÚÀÕË÷¡¢´¹µö¡¢BECºÍڲƭ¹¥»÷µÄ·¸×ïÍøÂç £¬ËüÃÇÒÑÔì³ÉÁ˳¬¹ý40000000ÃÀÔªµÄËðʧ ¡£´Ë±í £¬µ±¾Ö»¹²é»ñÁËÊý°Ù¸öÍйܶñÒâÈí¼þÒÔ¼°´«²¼Î£ÏÕµÄÈí¼þµÄ¶ñÒâIPµØÖ· ¡£2022Äê11Ô·¢Õ¹µÄµÚÒ»´ÎAfrica Cyber SurgeÐж¯¿ÛÁôÁË11Ó×ÎÒ £¬²¢µ·»ÙÁËÒ»¸öÏúÊۺڿ͹¤¾ßµÄ°µÍøºÍÔ¼20Íò¸ö¶ñÒâ»ù´¡ÉèÊ© ¡£


https://therecord.media/africa-cyber-surge-14-arrests-interpol


4¡¢µÂ¹úÁª¹úÂÉʦЭ»á(BRAK)Ôâµ½NoEscapeµÄÀÕË÷¹¥»÷


¾Ý8ÔÂ18ÈÕ±¨Â· £¬µÂ¹ú¹ú¶ÈÂÉʦЭ»á(BRAK)й©ÔÚµ÷²éÆä²¼Â³Èû¶û´¦Ê´¦Ôâµ½µÄÀÕË÷¹¥»÷ ¡£BRAKÕÆ¹Ü¼à¹ÜµÂ¹ú28¸öµØÓòµÄÂÉʦÊÂÎñËù £¬´ú±í¹úÄÚ±íÔ¼166000ÃûÂÉʦ ¡£¸Ã»ú¹¹ÓÚ8ÔÂ2ÈÕ·¢ÏÖÁ˹¥»÷ÊÂÎñ £¬ÀÕË÷ÍÅ»ïNoEscapeÔÚ8ÔÂ15ÈÕ³ÆÆä¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü ¡£ºÚ¿ÍÐû³Æ¼ÓÃÜÁËBRAKµÄÓʼþ·þÎñÆ÷²¢»ñÈ¡ÁË160 GBµÄÊý¾Ý ¡£BRAK°µÊ¾ÒѾ­¸´Ô­µç×ÓÓʼþϵͳµÄ½Ó¼û £¬²¢´òËãÁªÏµÊÜÊý¾Ýй¶ӰÏìµÄÓ×ÎÒ ¡£


https://therecord.media/german-national-bar-association-investigating-cyberattack


5¡¢Î¢Èí³ÆBlackCatµÄбäÌåÒÑǶÈëImpacketºÍRemCom


΢ÈíÔÚ8ÔÂ17ÈճƷ¢ÏÖÁËÀÕË÷Èí¼þBlackCatµÄбäÌå £¬Ç¶ÈëÁËÍøÂç¿ò¼ÜImpacketºÍºÚ¿Í¹¤¾ßRemcom ¡£Î¢Èí°µÊ¾ £¬½üÆÚµÄBlackCat»î¶¯ÔÚʹÓÃImpacket¿ò¼Ü½øÐÐÆ¾Ö¤¸´ÔìºÍÔ¶³Ì·þÎñÖ´ÐÐ £¬ÒÔÔÚÕû¸öÍøÂçÉÏ×°ÖüÓÃÜÆ÷·¨Ê½ ¡£´Ë±í £¬¼ÓÃÜ·¨Ê½»¹Ç¶ÈëÁËRemcom £¬¿ÉÔÚϵͳÉÏµÄÆäËüÉ豸ÉÏÔ¶³ÌÖ´ÐкÅÁî ¡£Î¢Èí»¹Ð¹Â© £¬BlackCatµÄ´ÓÊô»ú¹¹Storm-0875×Ô7ÔÂÒÔÀ´¾ÍʹÓÃÁËÕâÖÖеļÓÃÜ·½Ê½ ¡£Î¢Èí½«Õâ¸öа汾¶¨ÃûΪBlackCat 3.0 £¬ÀÕË÷ÍÅ»ïÔÚÓëÆä´ÓÊô»ú¹¹µÄͨѶÖн«Æä³ÆÎªSphynx»òBlackCat/ALPHV 2.0 ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-blackcats-sphynx-ransomware-embeds-impacket-remcom/


6¡¢³¬¹ý3000¸ö¶ñÒâÈí¼þʹÓÃδ֪ѹËõ²½ÖèÀ´Èƹý¼ì²â


¾Ý8ÔÂ19ÈÕ±¨Â·³Æ £¬¹¥»÷ÕßÔÚʹÓÃδ֪»ò²»ÊÜÖ§³ÖµÄѹËõ²½ÖèµÄAPKÎļþÀ´Èƹý¶ñÒâÈí¼þ·ÖÎö ¡£ZimperiumÔÚÒ°±í·¢ÏÖÁË3300¸öÀûÓôËÀàѹËõËã·¨µÄAndroid¶ñÒâÈí¼þ £¬ÆäÖÐ71¸öÑù±¾Äܹ»Ë³ÀûµØ¼ÓÔØµ½ÏµÍ³ÉÏ ¡£ÕâÖÖ·½Ê½µÄÀûÒæÊÇ¿ÉÄÜÈÆ¹ý·´±àÒ빤¾ß £¬Í¬Ê±»¹ÄÜ×°ÖÃÔÚOS°æ±¾¸ßÓÚAndroid 9 PieµÄÉ豸ÉÏ ¡£´Ë±í £¬Zimperium»¹·¢ÏÖ¶ñÒâÈí¼þ¿ª·¢ÕßÓÐÒâ·ÛËéAPKÎļþÀ´Èƹý¼ì²âµÄÆäËü·½Ê½ £¬Ô̺¬Ê¹Óó¬¹ý256×Ö½ÚµÄÎļþÃû¡¢ÌåʽÃýÎóµÄAndroidManifest.xmlºÍÌåʽÃýÎóµÄ×Ö·û´®³ØµÈ ¡£


https://securityaffairs.com/149678/malware/android-malware-using-unsupported-unknown-compression.html