×êÑÐÈËÔ±Åû¶WinRARÖеÄRCE·ì϶CVE-2023-40477
°ä²¼¹¦·ò 2023-08-211¡¢×êÑÐÈËÔ±Åû¶WinRARÖеÄRCE·ì϶CVE-2023-40477
¾ÝýÌå8ÔÂ18ÈÕ±¨Â·£¬×êÑÐÈËÔ±goodbyeseleneÅû¶ÁËWinRARÖеķì϶£¨CVE-2023-40477£©¡£¸Ã·ì϶´æÔÚÓÚ¸´Ô¾íµÄ´¦Öùý³ÌÖУ¬ÓÉÓÚ²»×ã¶ÔÓû§ÌṩÊý¾ÝµÄÊʵ±ÑéÖ¤£¬¿ÉÄܵ¼ÖÂÄÚ´æ½Ó¼û³¬¹ý¶ÈÅ仺³åÇøµÄ½áβ¡£µ±Óû§´ò¿ªÌØÔìµÄRARÎļþºó£¬Ô¶³Ì¹¥»÷ÕßÄܹ»ÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£×êÑÐÈËÔ±ÓÚ6ÔÂ8ÈÕÏò¹©¸øÉÌRARLAB»ã±¨ÁËÕâÒ»·ì϶£¬RARLABÓÚ8ÔÂ2ÈÕ°ä²¼Á˲¹¶¡£¬¸Ã²¹¶¡»¹½â¾öÁËÌØÔì´æµµµ¼ÖÂÎļþÆô¶¯ÃýÎóµÄÎÊÌâ¡£
https://www.bleepingcomputer.com/news/security/winrar-flaw-lets-hackers-run-programs-when-you-open-rar-archives/
2¡¢ÌØË¹À¹«¿ªÓ°Ï쳬¹ý7ÍòÃûÔ±¹¤ÐÅÏ¢µÄÊý¾Ýй¶ÊÂÎñ
8ÔÂ19ÈÕ±¨Â·³Æ£¬ÌØË¹ÀÅû¶ÁË5Ô·ݲúÉúµÄÊý¾Ýй¶ÊÂÎñ¡£¹«Ë¾µ÷²é·¢ÏÖ£¬Á½ÃûǰԱ¹¤ÇÔÈ¡ÁË»úÃÜÐÅÏ¢£¬Î¥·´ÁËÌØË¹ÀµÄIT°²È«ºÍÊý¾Ý±£»¤Õþ²ß¡£Òò¶ø£¬ÌØË¹À¶ÔÕâЩǰԱ¹¤Ìá¸æ×´ËÏ£¬²¢¿ÛѺÁËËûÃÇÔ̺¬±»µÁÐÅÏ¢µÄµç×ÓÉ豸¡£´Ë±í£¬ÌØË¹À»¹·¢ÏÖÕâÁ½ÃûÔ±¹¤ÓëµÂ¹ú±¨ÉçHandelsblatt·ÖÏíÁ˱»µÁµÄÊý¾Ý¡£²»Í⣬Õâ¼Ò±¨ÉçÏòÌØË¹À±£ÕÏ£¬ËûÃDz»»á¹«¿ªÕâЩÐÅÏ¢¡£¸ÃÊÂÎñÓ°ÏìÁË75735ÃûÔ±¹¤£¬ÌØË¹À½«ÎªËûÃÇÌṩΪÆÚ12¸öÔµÄÐÅÓþ¼à¿ØºÍÉí·Ý͵ÇÔ·þÎñ¡£
https://www.databreaches.net/tesla-notifies-employees-of-data-breach/
3¡¢·¨ÂÉ»ú¹¹Africa Cyber Surge IIÐж¯¿ÛÁô14ÃûÏÓÒÉÈË
ýÌå8ÔÂ18Èճƣ¬¹ú¼ÊÐ̾¯×é֯е÷µÄ·¨ÂÉÐж¯Africa Cyber Surge IIÒÑ¿ÛÁôÁË14ÃûÏÓÒÉÈË¡£¸ÃÐж¯ÓÚ½ñÄê4ÔÂ·ÝÆðÍ·£¬¸²¸ÇÁË·ÇÖÞµÄ25¸ö¹ú¶È£¬µ·»ÙÁË20000¶à¸öÓÃÓÚÀÕË÷¡¢´¹µö¡¢BECºÍڲƹ¥»÷µÄ·¸×ïÍøÂ磬ËüÃÇÒÑÔì³ÉÁ˳¬¹ý40000000ÃÀÔªµÄËðʧ¡£´Ë±í£¬µ±¾Ö»¹²é»ñÁËÊý°Ù¸öÍйܶñÒâÈí¼þÒÔ¼°´«²¼Î£ÏÕµÄÈí¼þµÄ¶ñÒâIPµØÖ·¡£2022Äê11Ô·¢Õ¹µÄµÚÒ»´ÎAfrica Cyber SurgeÐж¯¿ÛÁôÁË11Ó×ÎÒ£¬²¢µ·»ÙÁËÒ»¸öÏúÊۺڿ͹¤¾ßµÄ°µÍøºÍÔ¼20Íò¸ö¶ñÒâ»ù´¡ÉèÊ©¡£
https://therecord.media/africa-cyber-surge-14-arrests-interpol
4¡¢µÂ¹úÁª¹úÂÉʦлá(BRAK)Ôâµ½NoEscapeµÄÀÕË÷¹¥»÷
¾Ý8ÔÂ18ÈÕ±¨Â·£¬µÂ¹ú¹ú¶ÈÂÉʦлá(BRAK)й©ÔÚµ÷²éÆä²¼Â³Èû¶û´¦Ê´¦Ôâµ½µÄÀÕË÷¹¥»÷¡£BRAKÕÆ¹Ü¼à¹ÜµÂ¹ú28¸öµØÓòµÄÂÉʦÊÂÎñËù£¬´ú±í¹úÄÚ±íÔ¼166000ÃûÂÉʦ¡£¸Ã»ú¹¹ÓÚ8ÔÂ2ÈÕ·¢ÏÖÁ˹¥»÷ÊÂÎñ£¬ÀÕË÷ÍÅ»ïNoEscapeÔÚ8ÔÂ15ÈÕ³ÆÆä¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£ºÚ¿ÍÐû³Æ¼ÓÃÜÁËBRAKµÄÓʼþ·þÎñÆ÷²¢»ñÈ¡ÁË160 GBµÄÊý¾Ý¡£BRAK°µÊ¾ÒѾ¸´Ôµç×ÓÓʼþϵͳµÄ½Ó¼û£¬²¢´òËãÁªÏµÊÜÊý¾Ýй¶ӰÏìµÄÓ×ÎÒ¡£
https://therecord.media/german-national-bar-association-investigating-cyberattack
5¡¢Î¢Èí³ÆBlackCatµÄбäÌåÒÑǶÈëImpacketºÍRemCom
΢ÈíÔÚ8ÔÂ17ÈճƷ¢ÏÖÁËÀÕË÷Èí¼þBlackCatµÄбäÌ壬ǶÈëÁËÍøÂç¿ò¼ÜImpacketºÍºÚ¿Í¹¤¾ßRemcom¡£Î¢Èí°µÊ¾£¬½üÆÚµÄBlackCat»î¶¯ÔÚʹÓÃImpacket¿ò¼Ü½øÐÐÆ¾Ö¤¸´ÔìºÍÔ¶³Ì·þÎñÖ´ÐУ¬ÒÔÔÚÕû¸öÍøÂçÉÏ×°ÖüÓÃÜÆ÷·¨Ê½¡£´Ë±í£¬¼ÓÃÜ·¨Ê½»¹Ç¶ÈëÁËRemcom£¬¿ÉÔÚϵͳÉÏµÄÆäËüÉ豸ÉÏÔ¶³ÌÖ´ÐкÅÁ΢Èí»¹Ð¹Â©£¬BlackCatµÄ´ÓÊô»ú¹¹Storm-0875×Ô7ÔÂÒÔÀ´¾ÍʹÓÃÁËÕâÖÖеļÓÃÜ·½Ê½¡£Î¢Èí½«Õâ¸öа汾¶¨ÃûΪBlackCat 3.0£¬ÀÕË÷ÍÅ»ïÔÚÓëÆä´ÓÊô»ú¹¹µÄͨѶÖн«Æä³ÆÎªSphynx»òBlackCat/ALPHV 2.0¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-blackcats-sphynx-ransomware-embeds-impacket-remcom/
6¡¢³¬¹ý3000¸ö¶ñÒâÈí¼þʹÓÃδ֪ѹËõ²½ÖèÀ´Èƹý¼ì²â
¾Ý8ÔÂ19ÈÕ±¨Â·³Æ£¬¹¥»÷ÕßÔÚʹÓÃδ֪»ò²»ÊÜÖ§³ÖµÄѹËõ²½ÖèµÄAPKÎļþÀ´Èƹý¶ñÒâÈí¼þ·ÖÎö¡£ZimperiumÔÚÒ°±í·¢ÏÖÁË3300¸öÀûÓôËÀàѹËõËã·¨µÄAndroid¶ñÒâÈí¼þ£¬ÆäÖÐ71¸öÑù±¾Äܹ»Ë³ÀûµØ¼ÓÔØµ½ÏµÍ³ÉÏ¡£ÕâÖÖ·½Ê½µÄÀûÒæÊÇ¿ÉÄÜÈÆ¹ý·´±àÒ빤¾ß£¬Í¬Ê±»¹ÄÜ×°ÖÃÔÚOS°æ±¾¸ßÓÚAndroid 9 PieµÄÉ豸ÉÏ¡£´Ë±í£¬Zimperium»¹·¢ÏÖ¶ñÒâÈí¼þ¿ª·¢ÕßÓÐÒâ·ÛËéAPKÎļþÀ´Èƹý¼ì²âµÄÆäËü·½Ê½£¬Ô̺¬Ê¹Óó¬¹ý256×Ö½ÚµÄÎļþÃû¡¢ÌåʽÃýÎóµÄAndroidManifest.xmlºÍÌåʽÃýÎóµÄ×Ö·û´®³ØµÈ¡£
https://securityaffairs.com/149678/malware/android-malware-using-unsupported-unknown-compression.html


¾©¹«Íø°²±¸11010802024551ºÅ