Microsoft DNSÅäÖÃÃýÎóµ¼ÖÂHotmailÓʼþ·¢ËÍʧ°Ü
°ä²¼¹¦·ò 2023-08-221¡¢Microsoft DNSÅäÖÃÃýÎóµ¼ÖÂHotmailÓʼþ·¢ËÍʧ°Ü
¾ÝýÌå8ÔÂ18ÈÕ±¨Â·£¬È«ÇòÁìÓòÄÚµÄHotmailÓû§ÔÚ·¢Ë͵ç×ÓÓʼþʱÓöµ½ÎÊÌâ¡£ÔÚMicrosoftÃýÎóÅäÖÃÓòµÄDNS SPF¼Í¼ºó£¬Óʼþ±»ÏóÕ÷ΪÀ¬»øÓʼþ»òδͶµÝ¡£¸ÃÎÊÌâʼÓÚ17ÈÕÉîÒ¹£¬ÏÔʾÃýÎóÐÂÎÅ¡°´ËÃýÎóÓë·¢¼þÈËÕ½Êõ¿ò¼Ü(SPF)Óйء£Ö¸±êÓʼþϵͳ¶ÔÓʼþµÄSPF¼Í¼µÄÆÀ¹Àµ¼ÖÂÃýÎó¡£ÇëÓëÄúµÄÓò×¢²áÉ̺Ï×÷£¬È·±£ÄúµÄSPF¼Í¼ÅäÖÃÕýÈ·¡±¡£¸ÃÎÊÌâÔ´ÓÚMicrosoftɾ³ýÁËhotmail.com SPF¼Í¼ÖеÄ"include:spf.protection.outlook.com"¡£Ä¿Ç°£¬¸ÃÎÊÌâÒѾµÃµ½½â¾ö¡£
https://www.bleepingcomputer.com/news/microsoft/hotmail-email-delivery-fails-after-microsoft-misconfigures-dns/
2¡¢Ivanti SentryÖеķì϶CVE-2023-38035Òѱ»ÀûÓÃ
¾Ý8ÔÂ21ÈÕ±¨Â·³Æ£¬Ivanti Sentry£¨ÒÔǰ³ÆÎªMobileIron Sentry£©ÖеÄÒ»¸öAPIÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶(CVE-2023-38035)Òѱ»ÀûÓá£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýMobileIronÅäÖ÷þÎñ(MICS)ʹÓõÄ8443¶Ë¿Ú½Ó¼ûÖÎÀíÃÅ»§ÅäÖÃAPI£¬Äܹ»ÀûÓÃÏ޶Ȳ»¼°µÄApache HTTPDÅäÖÃÈÆ¹ýÉí·ÝÑéÖ¤½ÚÔìÀ´ÊµÏÖ¡£³É¹¦ÀûÓú󣬹¥»÷ÕßÄܹ»ÔÚÔËÐÐIvanti Sentry 9.18¼°¸üµÍ°æ±¾µÄϵͳÉϸü¸ÄÅäÖá¢ÔËÐÐϵͳºÅÁî»òдÈëÎļþ¡£Ä¿Ç°¹©¸øÉÌÒѰ䲼°²È«¸üн¨¸´´Ë·ì϶¡£
https://www.bleepingcomputer.com/news/security/ivanti-warns-of-new-actively-exploited-mobileiron-zero-day-bug/
3¡¢°Ä´óÀûÑÇauDA·ñ¶¨NoEscapeÇÔÈ¡Æä15 GBÊý¾ÝµÄ˵·¨
ýÌå8ÔÂ21Èճƣ¬ÖÎÀí°Ä´óÀûÑÇÓòÃû.auµÄ»ú¹¹auDA·ñ¶¨Æä²úÉúÁËÊý¾Ýй¶¡£¸Ã»ú¹¹±»ÊÓΪ°Ä´óÀûÑǹؼü»ù´¡ÉèÊ©£¬ÓÐ400¶àÍò¸öÓòÃû×¢²áÔÚ.auÉÏ¡£8ÔÂ11ÈÕ£¬ÀÕË÷ÍÅ»ïNoEscapeÐû³Æ¹¥»÷Á˸ûú¹¹²¢ÇÔÈ¡ÁË15 GBÃô¸ÐÊý¾Ý£¬ÆäÖÐÔ̺¬Ó×ÎÒÐÅÏ¢µÈ¡£auDA³ÆËûÃDzé³ÁËNoEscape¹«¿ªµÄÎļþ£¬ÕâЩÎļþ²¢Ã»Óд洢ÔÚËûÃǵÄϵͳÉÏ¡£²¢°µÊ¾Êý¾Ýй¶µÄÆðÔ´ÊÇÒ»¸ö°Ä´óÀûÑǸö±ðÉÌ»§£¬Æä·þÎñÆ÷ÓÚ8ÔÂ10ÈÕÔâµ½¹¥»÷¡£Ëæºó£¬¹¥»÷ÕßÅúÆÀÁËauDAµÄ»ØÓ¦£¬²¢Íþв"½«ÏúÊÛÓà¶î³¬¹ý4000ÃÀÔªµÄÒøÐÐÕË»§µÄ½Ó¼ûȨÏÞ"¡£
https://therecord.media/australia-domain-name-admin-denies-data-breach
4¡¢ESETÅû¶ּÔÚÇÔȡȫÇòZimbraÕË»§µÄ´ó¹æÄ£´¹µö»î¶¯
8ÔÂ17ÈÕ£¬ESETÅû¶ÁËÕë¶ÔZimbra Collaborationµç×ÓÓʼþ·þÎñÆ÷µÄ´ó¹æÄ£´¹µö»î¶¯¡£¸Ã»î¶¯ÖÁÉÙ´Ó4ÔÂÆð¾ÍÒ»ÏòÔÚ½øÐУ¬Ö¼ÔÚÇÔȡȫÇòÁìÓòÄÚZimbraÕË»§µÄÍ´´¦¡£±»¹¥»÷µÄÖ¸±êÖØÒªÎ»ÓÚ²¨À¼£¬Æä´ÎÊǶò¹Ï¶à¶ûºÍÒâ´óÀû¡£´¹µöÓʼþ¼ÙÒâZimbraÖÎÀíÔ±£¬Í¨ÖªÓû§¼´½«½øÐÐÓʼþ·þÎñÆ÷¸üУ¬Õ⽫µ¼ÖÂÕÊ»§ÁÙʱͣÓ㬲¢ÒªÇóÊÕ¼þÈË´ò¿ª¸½¼ÓµÄHTMLÎļþÏàʶ¸ü¶àÐÅÏ¢¡£´ò¿ªºóÊÇÒ»¸öαÔìµÄZimbraµÇÂ¼Ò³Ãæ£¬ÓÕʹָ±êÊäÈëÕË»§µÄƾ֤¡£¶øºó£¬Óû§ÊäÈëµÄÐÅÏ¢½«Í¨¹ýHTTPS POSTÒªÇó·¢Ë͵½¹¥»÷ÕߵķþÎñÆ÷¡£
https://www.welivesecurity.com/en/eset-research/mass-spreading-campaign-targeting-zimbra-users/
5¡¢Sysdig·¢ÏÖÕë¶ÔGitLabµÄÍÚ¿óºÍ´úÀí½Ù³Ö»î¶¯LABRAT
SysdigÔÚ8ÔÂ17ÈÕ³ÆÆä·¢ÏÖÁ˱»³ÆÎªLABRATµÄ¼ÓÃÜÇ®±ÒÍÚ¾òºÍ´úÀí½Ù³Ö»î¶¯¡£¹¥»÷ÕßÀûÓÃGitLab·ì϶£¨CVE-2021-22205£©»ñµÃ¶ÔÈÝÆ÷µÄ³õʼ½Ó¼ûȨÏÞ£¬»¹ÀûÓÃδ±»¼ì²âµ½µÄ»ùÓÚÊðÃûµÄ¹¤¾ß¡¢¸´ÔÓµÄ¿çÆ½Ì¨¶ñÒâÈí¼þ¡¢Èƹý·À»ðǽµÄC2¹¤¾ßÒÔ¼°»ùÓÚÄں˵ÄrootkitÀ´°µ²ØÆä´æÔÚ¡£´Ë±í£¬¹¥»÷ÕßÀÄÓúϷ¨·þÎñTryCloudflareÀ´»ìºÏËûÃǵÄC2¡£¸Ã»î¶¯ÖØÒªÍ¨¹ý´úÀí½Ù³ÖºÍ¼ÓÃÜÇ®±ÒÍÚ¿óÀ´×¬È¡ÊÕÈë¡£
https://sysdig.com/blog/labrat-cryptojacking-proxyjacking-campaign/
6¡¢Rapid7°ä²¼¹ØÓÚ2023ÄêÄêÖÐÍþÐ²Ì¬ÊÆµÄ»ØÊ׻㱨
8ÔÂ17ÈÕ£¬Rapid7°ä²¼ÁË2023ÄêÄêÖÐÍþÐ²Ì¬ÊÆµÄ»ØÊ׻㱨¡£2023ÄêÉϰëÄ꣬×êÑÐÍŶӸú×ÙÁË1500¶àÆðÀÕË÷¹¥»÷ÊÂÎñ£¬ÕâЩ¹¥»÷´ó²¿ÃÅÊÇÓÉLockBit(35.3%)¡¢ALPHV/BlackCat(14.2%)ºÍClop(11.9%)Ö´Ðеġ£×î³£¼ûµÄ³õʼ½Ó¼û¼¼ÊõÊÇÔ¶³Ì½Ó¼û£¬Õ¼±È39%£¬Æä´ÎÊÇ·ì϶ÀûÓã¨27%£©¡£40%µÄÊÂÎñÊÇÓÉÓÚMFAȱʧ»òÖ´Ðв»Ò»Öµ¼Öµģ¬ÓÈÆäÊÇÔÚVPN¡¢VDIºÍSaaS²úÆ·ÉÏ¡£79Æð¹¥»÷¹éÒòÓÚÓë¹ú¶ÈÓйصĹ¥»÷Õߣ¬ÆäÖÐÔ¼ËÄ·ÖÖ®Ò»(24%)ÀûÓÃÁËÃæÏò¹«¼ÒµÄÀûÓ÷¨Ê½µÄ·ì϶¡£
https://www.rapid7.com/blog/post/2023/08/17/rapid7s-mid-year-threat-review/


¾©¹«Íø°²±¸11010802024551ºÅ