CiscoÅû¶ÆäSPA112 2-Portµç»°ÊÊÅäÆ÷ÖеÄRCE·ì϶

°ä²¼¹¦·ò 2023-05-06

1¡¢CiscoÅû¶ÆäSPA112 2-Portµç»°ÊÊÅäÆ÷ÖеÄRCE·ì϶

 

¾ÝýÌå5ÔÂ4ÈÕ±¨Â· £¬CiscoÅû¶ÁËÆäSPA112 2-Portµç»°ÊÊÅäÆ÷ÖлùÓÚWebµÄÖÎÀí½çÃæÖеķì϶ £¬¿É±»Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÓÃÓÚÖ´ÐÐËÁÒâ´úÂë¡£¸Ã·ì϶׷×ÙΪCVE-2023-20126£¨CVSSÆÀ·Ö9.8£© £¬ÊÇÓÉÓڹ̼þÉý¼¶Ö°ÄÜÖжÌȱÉí·ÝÑéÖ¤¹ý³ÌÔì³ÉµÄ £¬¹¥»÷ÕßÄܹ»Í¨¹ý½«Ö¸±êÉ豸Éý¼¶µ½¶ñÒ⿪·¢µÄ¹Ì¼þ°æÕý±¾ÀûÓô˷ì϶¡£ÓÉÓÚCisco SPA112ÓÚ2020Äê6ÔÂ1ÈÕÍ£²ú £¬¹©¸øÉ̲»ÔÙ¶ÔËüÌṩ֧³Ö £¬Ò²²»»á°ä²¼°²È«¸üС£´Ë±í £¬CiscoδÌṩÕë¶Ô¸Ã·ì϶µÄ»º½â´ëÊ©¡£


https://securityaffairs.com/145763/security/cisco-spa112-2-port-phone-adapters-rce.html


2¡¢¼ÓÄôóConstellation SoftwareÔâµ½ALPHVµÄ¹¥»÷


¾Ý5ÔÂ5ÈÕ±¨Â· £¬¼ÓÄôó¶àÔª»¯Èí¼þ¹«Ë¾Constellation Software³ÆÆä²¿ÃÅϵͳÔâµ½¹¥»÷ £¬²¿ÃÅÓ×ÎÒÐÅÏ¢ºÍóÒ×Êý¾Ýй¶¡£Constellationй© £¬ËüÒѾ­¶ôÔìÁËÕâ´Î¹¥»÷ £¬´Ë¿ÌÒ²¸´Ô­ÁËËùÓÐÊÜÓ°ÏìµÄIT»ù´¡ÉèÊ©¡£¹ÌÈ»¸Ã¹«Ë¾ÉÐδÌṩ¹ØÓÚ¹¥»÷Õß¼°ÆäÈôºÎ½Ó¼ûϵͳµÄ¾ßÌåÐÅÏ¢ £¬µ«ALPHVÔÚÆäÍøÕ¾Ôö³¤ÁËÒ»¸öÐÂÌõ¿î £¬³ÆËûÃÇÈëÇÖÁËConstellationµÄϵͳ²¢ÇÔÈ¡Á˳¬¹ý1 TBµÄÎļþ¡£ALPHV»¹¹«¿ªÁ˲¿ÃÅÔ̺¬Ã³Ò×ÐÅÏ¢µÄÎļþ×÷Ϊ¹¥»÷Ö¤¾Ý¡£


https://www.bleepingcomputer.com/news/security/alphv-gang-claims-ransomware-attack-on-constellation-software/


3¡¢Sentinel LabsÏêÊöKimsukyµÄпúËŹ¤¾ßReconShark


5ÔÂ4ÈÕ £¬Sentinel Labs·¢ÏÖÁËÀ´×ÔKimsukyµÄ¹¥»÷»î¶¯¡£¹¥»÷ÕßʹÓÃÁËеĶñÒâÈí¼þ×é¼þReconShark £¬Ëüͨ¹ýÓã²æÊ½´¹µöÓʼþ¡¢OneDriveÁ´½ÓÒÔ¼°¶ñÒâºê½øÐзַ¢¡£ReconShark±»ÒÔΪÊÇBabySharkµÄбäÌå £¬¿ÉÀûÓÃWMIÍøÂçÓйØÖ¸±êϵͳµÄÐÅÏ¢ £¬»¹²é³­»úеÉÏÊÇ·ñÔËÐа²È«Èí¼þ £¬²¢Í¨¹ýHTTP POSTÒªÇó½«Êý¾Ý·¢Ë͵½C2·þÎñÆ÷¡£³ýÁËÇÔÊØÐÅÏ¢±í £¬ReconShark»¹ÒÔ¶à½×¶Î·½Ê½²¿Êð¸ü¶àpayload¡£Õâ´Î»î¶¯Õë¶ÔÃÀ¹ú¡¢Å·ÖÞºÍÑÇÖÞµÄ×éÖ¯ºÍÓ×ÎÒ £¬Ô̺¬Öǿ⡢×êÑÐÐÍ´óѧºÍµ±¾Ö»ú¹¹¡£


https://www.sentinelone.com/labs/kimsuky-evolves-reconnaissance-capabilities-in-new-global-campaign/


4¡¢KasperskyÔÚGoogle Play¼ì²âµ½¶à¸öϰȾFleckpeµÄÀûÓÃ


KasperskyÓÚ5ÔÂ4ÈÕ³ÆÆä·¢ÏÖÁËÐÂAndroid¶ñÒâÈí¼þFleckpe £¬ÖØÒªÕë¶ÔÌ©¹ú¡¢ÂíÀ´Î÷ÑÇ¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢ÐÂ¼ÓÆÂºÍ²¨À¼¡£×êÑÐÈËÔ±ÔÚGoogle Play¼ì²âµ½11¸öϰȾFleckpeµÄÀûÓà £¬ÕâЩÀûÓüÙÒâͼÏñ±à×ëÆ÷¡¢ÕÕÆ¬¿â¡¢¸ß¼¶±ÚÖ½µÈ £¬Òѱ»×°Öó¬¹ý620000´Î¡£¸ÃľÂí×Ô2022ÄêÒÔÀ´Ò»Ïò»îÔ¾ £¬Ëüͨ¹ýΪÓû§¶©Ôĸ߼¶·þÎñ¶ø²úÉúδ¾­ÊÚȨµÄÓöÈ £¬²¢´ÓÖлñÀû¡£Îª·À±¸´ËÀàÍþв £¬×êÑÐÈËÔ±½¨ÒéAndroidÓû§½ö´Ó¿ÉÐÅÆðÔ´ºÍ¿ª·¢ÉÌÏÂÔØÀûÓà £¬²¢ÔÚ×°Öùý³ÌÖаÑÎÈÒªÇóµÄȨÏÞ¡£


http://securelist.com/fleckpe-a-new-family-of-trojan-subscribers-on-google-play/109643/


5¡¢Ermetic½üÆÚÔÚAzure APIÖÎÀí·þÎñÖз¢ÏÖ3¸ö·ì϶


ýÌå5ÔÂ4ÈÕ³Æ £¬Ermetic½üÆÚÔÚAzure APIÖÎÀí·þÎñÖз¢ÏÖ3¸ö·ì϶¡£ÆäÖÐÔ̺¬Á½¸öSSRF·ì϶ºÍÒ»¸öÎļþÉÏ´«õè¾¶±éÀú·ì϶¡£ÕâЩ·ì϶ÊÇͨ¹ýurlÌåÊ½ÈÆ¹ýºÍAPIÖÎÀí¿ª·¢ÈËÔ±ÃÅ»§ÖеÄÎÞÏÞ¶ÈÎļþÉÏ´«Ö°ÄÜʵÏֵġ£ÀûÓÃSSRF·ì϶ £¬¹¥»÷Õ߿ɴӷþÎñµÄCORS´úÀíºÍÍйܴúÀí×ÔÉí·¢ËÍÒªÇó £¬½Ó¼ûÄÚ²¿Azure×ʲú £¬»Ø¾ø·þÎñ²¢ÈƹýWebÀûÓ÷À»ðǽ¡£ÀûÓÃÎļþÉÏ´«õè¾¶±éÀú·ì϶ £¬¹¥»÷Õ߿ɽ«¶ñÒâÎļþÉÏ´«µ½AzureÍйܵÄÄÚ²¿workload¡£Ä¿Ç° £¬MSRCÒѾ­½¨¸´ÁËÕâ3¸ö·ì϶¡£


https://ermetic.com/blog/azure/when-good-apis-go-bad-uncovering-3-azure-api-management-vulnerabilities/


6¡¢Avast°ä²¼¹ØÓÚ2023ÄêµÚÒ»¼¾¶ÈÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨


5ÔÂ4ÈÕ £¬Avast°ä²¼Á˹ØÓÚ2023ÄêµÚÒ»¼¾¶ÈÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö £¬¹¥»÷Õß²»ÐÝѰÕÒеIJ½ÖèÀ´·Ö·¢¶ñÒâÈí¼þ £¬Ô̺¬ÀûÓÃMicrosoft OneNoteºÍAdobe Acrobat Sign¡£±¾¼¾¶È £¬Õë¶Ô¶«ÑǵØÓòµÄ¶ñÒâ¸æ°×Èí¼þ»î¶¯ÏÔÖøÔö³¤¡£ÐÅÏ¢ÇÔÈ¡·¨Ê½ÈÔÊÇ×î´óµÄÍþв֮һ £¬ÆäÖÐ×î³£¼ûµÄÊÇAgentTesla¡¢FormBook¡¢RaccoonºÍRedLineµÈ¡£¶ÔÓÚÀÕË÷Èí¼þ £¬WannaCryÈÔ´¦ÓÚµ±ÏÈְλ£¨Õ¼±È18%£© £¬Æä´ÎÊÇSTOP ransomware(15%)ºÍThanatos(3%)¡£×î³£¼ûµÄRATÔ̺¬HWorm¡¢Remcos¡¢njRATºÍAsyncRatµÈ¡£ 


https://decoded.avast.io/threatresearch/avast-q1-2023-threat-report/