Outlook³öÏÖ¹ÊÕϵ¼ÖÂÓû§½Ó¼ûÕË»§Ê±ÊÕµ½503ÃýÎóÐÂÎÅ
°ä²¼¹¦·ò 2023-06-071¡¢Outlook³öÏÖ¹ÊÕϵ¼ÖÂÓû§½Ó¼ûÕË»§Ê±ÊÕµ½503ÃýÎóÐÂÎÅ
¾ÝýÌå6ÔÂ5ÈÕ±¨Â·£¬Î¢ÈíOutlook³öÏÖ¹ÊÕÏÓ°ÏìÁËÈ«ÇòµÄÓû§£¬µ¼ÖÂÎÞ·¨·¢Ë͵ç×ÓÓʼþºÍÖÎÀíÈÕÀú¡£ÔÚ½Ó¼û¸ÃÍøÕ¾Ê±£¬Óû§´Ë¿Ì»áÊÕµ½¡°HTTPÃýÎó503£º·þÎñ²»³ÉÓá±µÄÐÂÎÅ£¬°µÊ¾·þÎñÁÙʱ²»³ÉÓûò·þÎñÆ÷¹ýÔØ¡£Òƶ¯OutlookÀûÓ÷¨Ê½Ò²ÎÞ·¨ÏνӷþÎñ¡£Ä¿Ç°£¬Î¢ÈíµÄ¼¼ÊõÍŶӿÉÄÜÔÚ»ý¼«×êÑнâ¾ö¹æ»®¡£¾ÝºóÐø¸üУ¬Î¢ÈíÒѾ½¨¸´Á˸Ã503ÃýÎó£¬Outlook.com´Ë¿ÌÓÔìðÍ·¼ÓÔØ£¬µ«Óû§ÒÀÈ»ÎÞ·¨·¢ËÍ»ò´ò¿ªÓʼþ¡£
https://www.bleepingcomputer.com/news/microsoft/microsofts-outlookcom-is-down-again-on-mobile-web/
2¡¢Google½¨¸´ChromeÖÐÒѱ»ÀûÓõķì϶CVE-2023-3079
GoogleÔÚ6ÔÂ5ÈÕ°ä²¼µÄ°²È«¸üÐÂÖУ¬½¨¸´ÁËÒ»¸öÒѱ»ÔÚÒ°ÀûÓõķì϶£¨CVE-2023-3079£©¡£ÕâÊÇ´æÔÚÓÚV8 JavaScriptÒýÇæÖеÄÀàÐÍ»ìºÏ·ì϶£¬¸Ã¹«Ë¾ÉÐδ°ä²¼Óйظ÷ì϶ÒÔ¼°ÈôºÎÔÚ¹¥»÷ÖÐÀûÓõľßÌåÐÅÏ¢¡£ÕâÊÇGoogleÔÚ½ñÄ꽨¸´µÄµÚÈý¸öÁãÈÕ·ì϶£¬Ç°Á½¸ö±ðÀëΪV8 JavaScriptÒýÇæÖеÄÀàÐÍ»ìºÏ·ì϶£¨CVE-2023-2033£©ºÍSkiaͼÐοâÖеÄÕûÊýÒç¶Âí½Å£¨CVE-2023-2136£©¡£
https://securityaffairs.com/147137/hacking/chrome-zero-day-3.html
3¡¢KeePass½¨¸´´ÓÄÚ´æ¼ìË÷Ã÷ÎÄÖ÷ÃÜÂëµÄ·ì϶CVE-2023-32784
ýÌå6ÔÂ5Èճƣ¬KeePass°ä²¼ÁË2.54°æ±¾£¬½¨¸´Á˿ɴÓÀûÓ÷¨Ê½ÄÚ´æÖмìË÷Ã÷ÎÄÖ÷ÃÜÂëµÄ·ì϶£¨CVE-2023-32784£©¡£5Ô·ݣ¬×êÑÐÈËÔ±vdohneyÅû¶Á˸÷ì϶²¢°ä²¼ÁËÒ»¸öPoC¡£¸Ã·ì϶ԴÓÚKeePass 2.XÖÐʹÓÃÁËÒ»¸ö×Ô½ç˵¿ª·¢µÄÎı¾¿òSecureTextBoxEx½øÐÐÃÜÂëÊäÈë¡£¸ÃÎı¾¿ò²»½öÓÃÓÚÖ÷ÃÜÂëµÄÊäÈ룬²¢ÇÒ»¹ÓÃÓÚKeePassµÄÆäËü´¦Ëù£¬ÈçÃÜÂë±à×ë¿ò£¬¹¥»÷Õß¿ÉʹÓÃËüÀ´¸´ÔÆäÄÚÈÝ¡£´Ë±í£¬KeePass 2.5.4ÐÂÔöÁËÆäËü°²È«¼ÓǿְÄÜ£¬×êÑÐÈËԱҲΪÎÞ·¨Éý¼¶µÄÓû§ÌṩÁË»º½â²½Öè¡£
https://securityaffairs.com/147109/security/keepass-fixed-the-bug-that-allows-the-extraction-of-the-cleartext-master-password.html
4¡¢Group-IBÅû¶PostalFuriousÕë¶ÔÖж«µØÓòµÄ´¹µö»î¶¯
Group-IBÓÚ6ÔÂ1ÈÕÅû¶Á˽üÆÚPostalFuriousÕë¶ÔÖж«µØÓòµÄ´¹µö»î¶¯¡£Group-IBÓÚ4Ô³õ´Î·¢ÏÖµ½¸ÃÍÅ»ïͨ¹ý¼ÙÒâÓÊÕþÆ·ÅÆºÍÊÕ·ÑÔËÓªÉÌÀ´¹¥»÷ÑÇÌ«µØÓòµÄÓû§¡£´Ë¿Ì£¬¸ÃÍÅ»ïÒѽ«ÒµÎñÁìÓòÀ©´óÖÁÖж«¡£4ÔÂ15ÈÕÆðÍ·µÄ»î¶¯ÖУ¬¹¥»÷ÕßÏòÓû§·¢ËÍÔ̺¬Ëõ¶ÌURL´¹µöÁ´½ÓµÄÐéα¶ÌÐÅ¡£ÕâЩ¶ÌÐÅÊÇ´ÓÔÚÂíÀ´Î÷ÑǺÍÌ©¹ú×¢²áµÄµç»°ºÅÂëÒÔ¼°Í¨¹ýiMessage·þÎñµÄÓʼþµØÖ··¢Ë͵ġ£Á´½ÓÓеØÀíΧÀ¸£¬Ö»ÄÜ´Ó°¢ÁªÇõµÄIPµØÖ·½Ó¼û¡£¹¥»÷ÕßÿÌì¶¼ÔÚ×¢²áеĴ¹µöÓòÃû£¬ÒÔÀ©´óÓ°ÏìÁìÓò¡£4ÔÂ29ÈÕ·¢ÏÖÁ˵ڶþ´Î½üºõÒ»ÑùµÄ»î¶¯£¬¼ÙÒâÁ˰¢ÁªÇõÓÊÕþÔËÓªÉÌ¡£
https://www.group-ib.com/media-center/press-releases/postalfurious/
5¡¢Scrubs & Beyondй¶400GBµÄÓû§ºÍÒøÐп¨¾ßÌåÐÅÏ¢
¾Ý6ÔÂ5ÈÕ±¨Â·£¬Scrubs & BeyondÒÔ´¿Îı¾´ó¾Öй¶ÁË400 GBµÄÓû§PIIºÍÒøÐп¨ÐÅÏ¢¡£¸ÃÊý¾Ý¿âÓÚ5ÔÂ16ÈÕ¶³ö£¬×êÑÐÈËÔ±ÔÚ5ÔÂ25ÈÕ·¢ÏÖ£¬¶ûºóÕâЩÐÅÏ¢Ò»Ïò´¦Óڿɹ«¿ª½Ó¼ûµÄ״̬¡£Ä¿Ç°£¬·þÎñÆ÷Õ¼Óг¬¹ý100000Ìõ¿Í»§¼Í¼£¬×ܼÆ400 GB£¬ÇÒÊý¾Ý¿â´óÓ׺ÍÓû§ÊýÁ¿Ëæ×ÅÿÌìÐÂÔöµÄÐÅÏ¢¶ø²»ÐÝÔö³¤¡£Ð¹Â¶ÐÅÏ¢Éæ¼°ÐÕÃû¡¢µç»°¡¢µØÖ·ºÍÄÚ²¿Í´´¦µÈÓ×ÎÒÐÅÏ¢£¬ÒÔ¼°ÒøÐп¨ºÅ¡¢CVV´úÂëºÍPayPalÖ§¸¶ÈÕÖ¾µÈ²ÆÕþÐÅÏ¢¡£Ä¿Ç°£¬¸Ã¹«Ë¾²¢Î´¶Ô´ËÊÂ×÷³ö»ØÓ¦£¬Ò²Î´½«¸ÃÊý¾Ý¿â±£»¤ÆðÀ´¡£
https://www.hackread.com/scrubs-beyond-leaks-400gb-of-user-data/
6¡¢KasperskyÏêÊöÓëSatacomÓйصĶñÒâÈí¼þ·Ö·¢»î¶¯
6ÔÂ5ÈÕ£¬Kaspersky³ÆÆä·¢ÏÖһ·ÐµĶñÒâÈí¼þ»î¶¯£¬ÀûÓÃSatacom downloader£¨Ò²³ÆLegionLoader£©À´·Ö·¢ÇÔÈ¡¼ÓÃÜÇ®±ÒµÄä¯ÀÀÆ÷À©´ó¡£Ï°È¾Ê¼ÓÚÒ»¸öZIPÎļþ£¬ÆäÖÐÔ̺¬¼¸¸öºÏ·¨µÄDLLºÍÒ»¸ö¶ñÒâµÄSetup.exe£¬Óû§±ØÒªÊÖ¶¯Ö´ÐÐÕâЩÎļþÄÜÁ¦Æô¶¯Ï°È¾Á´¡£Ö®ºó£¬Ö¸±ê±»³Á¶¨Ïòµ½¼Ù×°³ÉÎļþ¹²Ïí·þÎñµÄÍøÕ¾À´·Ö·¢¶ñÒâÈí¼þ¡£Ò»µ©¶ñÒâÈí¼þ±»Ö´ÐУ¬Ëü¾Í»áʹÓùý³Ì×¢Èë¼¼ÊõÀ´Èƹýɱ¶¾Èí¼þµÄ¼ì²â¡£´Ë±í£¬QUADS¸æ°×²å¼þÒѱ»ÓÃÀ´´«²¼Satacom¡£
https://securelist.com/satacom-delivers-cryptocurrency-stealing-browser-extension/109807/


¾©¹«Íø°²±¸11010802024551ºÅ