×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓÃChromeÀ©´ó·¨Ê½ÇÔÈ¡Ã÷ÎÄÃÜÂë

°ä²¼¹¦·ò 2023-09-04

1¡¢×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓÃChromeÀ©´ó·¨Ê½ÇÔÈ¡Ã÷ÎÄÃÜÂë


¾ÝýÌå9ÔÂ2ÈÕ±¨Â· £¬Íþ˹¿µÐÇ´óѧÂóµÏÑ··ÖУµÄÒ»×é×êÑÐÈËÔ±·¢ÏÖÄܹ»Í¨¹ýChromeÀ©´ó´ÓÍøÕ¾Ô´´úÂëÖÐÇÔÈ¡´¿Îı¾ÃÜÂë¡£¸ÃÎÊÌâÉæ¼°ä¯ÀÀÆ÷À©´ó¿É²»ÊÜÏ޶ȵؽӼûÆä¼ÓÔØµÄÍøÕ¾µÄDOMÊ÷ £¬´Ó¶ø½Ó¼ûÓû§ÊäÈë×ֶεÈDZÔÚÃô¸ÐÔªËØ¡£¼øÓÚÀ©´ó·¨Ê½ºÍÍøÕ¾ÔªËØÖ®¼äûÓÐÈκΰ²È«Ììǵ £¬Òò¶øÀ©´óÄܹ»½Ó¼ûÔ´´úÂëÖпɼûµÄÊý¾Ý £¬²¢ÌáÈ¡ÆäËÁÒâÄÚÈÝ¡£´Ë±í £¬¸ÃÀ©´ó·¨Ê½¿ÉÄÜ»áÀûÓÃDOM APIÔÚÓû§ÊäÈëʱֱ½ÓÌáÈ¡ÊäÈëÖµ¡£Google°µÊ¾ËûÃÇÔÚµ÷²é´ËÊ¡£


https://www.bleepingcomputer.com/news/security/chrome-extensions-can-steal-plaintext-passwords-from-websites/


2¡¢Ï¤Äá´óѧµÚÈý·½·þÎñÌṩÉÌÔâµ½¹¥»÷²¿ÃÅÊý¾Ýй¶


¾Ý9ÔÂ3ÈÕ±¨Â· £¬Ï¤Äá´óѧ(USYD)й© £¬ÆäµÚÈý·½·þÎñÌṩÉÌÔâµ½¹¥»÷ £¬µ¼Ö½üÆÚÉêÇëºÍ×¢²áµÄ¹ú¼ÊÉêÇëÈ˵ÄÐÅϢй¶¡£USYD³Æ¸ÃÎÊÌâ½öÏÞÓÚµ¥Ò»Æ½Ì¨ £¬¶Ô´óѧµÄÆäËüϵͳûÓÐÓ°Ïì £¬³õ´ëÊ©²éҲûÓз¢ÏÖÈκα¾µØÑ§Éú¡¢½ÌÈËÔ±¹¤»òУÓѵÄÐÅϢй¶¡£¹«¿ªµÄÊÂÎñÐÅÏ¢²¢Î´×¢Ã÷й¶²úÉúµÄ¹¦·ò»òÄÄЩµÚÈý·½·þÎñÔâµ½¹¥»÷ £¬Ä¿Ç°Ò²Ã»ÓйØÓÚUSYDϵͳÖжϵIJ¼¸æ¡£


https://www.bleepingcomputer.com/news/security/university-of-sydney-data-breach-impacts-recent-applicants/


3¡¢EclecticIQ°ä²¼ÀÕË÷Èí¼þKey GroupµÄÃâ·Ñ½âÃÜ·¨Ê½


ýÌå9ÔÂ1ÈÕ³Æ £¬EclecticIQ°ä²¼ÀÕË÷Èí¼þKey Group£¨±ðÃûkeygroup777£©µÄÃâ·Ñ½âÃÜ·¨Ê½ £¬ºÏÓÃÓÚ8Ô³õ¹¹½¨µÄ¶ñÒâÈí¼þ°æ±¾¡£Key GroupÖÁÉÙ×Ô½ñÄê1ÔÂÆð¾ÍÒ»Ïò»îÔ¾ £¬¹¥»÷ÕßÐû³ÆËûÃǵĶñÒâÈí¼þʹÓõÄÊÇ"¾üÓü¶±ðAES¼ÓÃÜ" £¬µ«¸ÃlockerÔÚËùÓмÓÃܹý³ÌÖж¼Ê¹ÓÃÁ˾²Ì¬salt £¬Òò¶ø¸Ã¹æ»®ÓµÓп϶¨µÄ¿ÉÔ¤²âÐÔ £¬¼ÓÃÜÒ²ÓпÉÄܱ»Äæ×ª¡£¸Ã¹¤¾ßÈÔ´¦ÓÚÑéÖ¤½×¶Î £¬¿ÉÄܲ»ºÏÓÃÓÚÿ¸öKey GroupÑù±¾¡£


https://securityaffairs.com/150207/malware/key-group-ransomware-decryptor.html


4¡¢Callaway¹«Ë¾¹«¿ªÉæ¼°³¬¹ý110ÍòÓû§µÄÊý¾Ýй¶ÊÂÎñ


9ÔÂ1ÈÕ±¨Â·³Æ £¬ÃÀ¹ú¸ß¶û·òÇòÉ豸Ôì×÷É̺ÍÏúÊÛÉÌCallaway¹«¿ªÁ˽üÆÚ²úÉúµÄÊý¾Ýй¶ÊÂÎñ¡£CallawayÔÚ8ÔÂ29Èհ䲼֪ͨ £¬³Æ8ÔÂ1ÈÕ²úÉúµÄITϵͳÊÂÎñÓ°ÏìÁËÆäµçÉÌ·þÎñµÄ¿ÉÓÃÐÔ £¬²¢½«²¿Ãſͻ§ÐÅϢй¶¸øÎ´¾­ÊÚȨµÄµÚÈý·½¡£¸ÃÊÂÎñÓ°ÏìÁËCallaway¼°Æä×ÓÆ·ÅÆOdyssey¡¢OgioºÍCallaway Gold PreownedÍøÕ¾µÄ¿Í»§ £¬Ð¹Â¶ÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢¶©µ¥º¹Çà¼Í¼¡¢°²È«ÎÊÌâºÍÕË»§ÃÜÂëµÈ £¬Éæ¼°ÁË1114954ÈË¡£ÓÉÓÚÃÜÂëºÍ°²È«ÎÊÌâµÈÕÊ»§ÐÅϢй¶ £¬CallawayÒÑÇ¿ÔìËùÓпͻ§³ÁÖÃÃÜÂë¡£


https://therecord.media/topgolf-callaway-says-one-million-affected-by-breach


5¡¢SecuronixÅû¶ͨ¹ýMS SQL·Ö·¢FreeWorldµÄ¹¥»÷»î¶¯


SecuronixÔÚ9ÔÂ1ÈÕÅû¶ÁËͨ¹ýMS SQL·Ö·¢ÀÕË÷Èí¼þFreeWorldµÄ¹¥»÷»î¶¯DB#JAMMER¡£Æä¹¤¾ßÔ̺¬Ã¶¾Ù¹¤¾ß¡¢RAT payload¡¢·ì϶ÀûÓÃºÍÆ¾Ö¤ÇÔÈ¡¹¤¾ßÒÔ¼°ÀÕË÷Èí¼þ¡£FreeWorldËÆºõÊÇÀÕË÷Èí¼þMimicµÄбäÖÖ¡£³õʼ½Ó¼ûÊÇͨ¹ý±©Á¦ÆÆ½âMS SQL·þÎñÆ÷À´ÊµÏÖµÄ £¬ÏÂÒ»½×¶Î±ØÒª²ÉÈ¡´ëÊ©¹¥»÷ϵͳ·À»ðǽ £¬ÏνÓÔ¶³ÌSMB¹²ÏíÀ´³ÉÁ¢ÓƾÃÐÔ £¬ÒÔ±ãÔÚϵͳ֮¼ä´«ÊäÎļþ £¬²¢×°ÖÃCobalt StrikeµÈ¹¤¾ß¡£¶øºó×°ÖÃAnyDesk £¬ºáÏòÒÆ¶¯ £¬×îÖÕ×°ÖÃFreeWorld¡£


https://www.securonix.com/blog/securonix-threat-labs-security-advisory-threat-actors-target-mssql-servers-in-dbjammer-to-deliver-freeworld-ransomware/


6¡¢Cisco°ä²¼¹ØÓÚ¿ªÔ´ÇÔÈ¡·¨Ê½SapphireStealerµÄ»ã±¨


8ÔÂ31ÈÕ £¬Cisco°ä²¼Á˹ØÓÚ¿ªÔ´ÇÔÈ¡·¨Ê½SapphireStealerµÄ·ÖÎö»ã±¨¡£×Ô2022Äê12Ô³õ´Î°ä²¼ÒÔÀ´ £¬SapphireStealerÔÚ¹«¹²¶ñÒâÈí¼þ´æ´¢¿âÖгöÏֵįµÂʲ»ÐÝÔö³¤¡£ËüÓµÓÐÍøÂçÖ÷»úÐÅÏ¢¡¢ä¯ÀÀÆ÷Êý¾Ý¡¢ÎļþºÍÆÁÄ»½ØÍ¼µÄÖ°ÄÜ £¬²¢¿Éͨ¹ýµ¥Ò»Óʼþ´«ÊäºÍ̸(SMTP)ÒÔZIPÎļþµÄ´ó¾Ö´«ÊäÊý¾Ý¡£´Ë±í £¬×êÑÐÈËÔ±»¹·¢ÏÖÁËSapphireStealerµÄ¶à¸ö±äÌå £¬³ÆºÚ¿Í¸Ä½øÁËԭʼ´úÂë¿â £¬Ê¹ÆäÖ§³Ö¸ü¶àµÄÊý¾Ýй¶»úÔì £¬Òò¶ø²úÉúÁ˶à¸ö±äÌå¡£


https://blog.talosintelligence.com/sapphirestealer-goes-open-source/