Ñо¿Ö°Ô±ÑÝʾÔõÑùʹÓÃChromeÀ©Õ¹³ÌÐòÇÔÈ¡Ã÷ÎÄÃÜÂë

Ðû²¼Ê±¼ä 2023-09-04

1¡¢Ñо¿Ö°Ô±ÑÝʾÔõÑùʹÓÃChromeÀ©Õ¹³ÌÐòÇÔÈ¡Ã÷ÎÄÃÜÂë


¾ÝýÌå9ÔÂ2ÈÕ±¨µÀ£¬Íþ˹¿µÐÇ´óѧÂóµÏÑ··ÖУµÄÒ»×éÑо¿Ö°Ô±·¢Ã÷¿ÉÒÔͨ¹ýChromeÀ©Õ¹´ÓÍøÕ¾Ô´´úÂëÖÐÇÔÈ¡´¿Îı¾ÃÜÂë¡£¸ÃÎÊÌâÉæ¼°ä¯ÀÀÆ÷À©Õ¹¿É²»ÊÜÏÞÖƵػá¼ûÆä¼ÓÔصÄÍøÕ¾µÄDOMÊ÷£¬´Ó¶ø»á¼ûÓû§ÊäÈë×ֶεÈDZÔÚÃô¸ÐÔªËØ¡£¼øÓÚÀ©Õ¹³ÌÐòºÍÍøÕ¾ÔªËØÖ®¼äûÓÐÈκÎÇå¾²½çÏߣ¬Òò´ËÀ©Õ¹¿ÉÒÔ»á¼ûÔ´´úÂëÖпɼûµÄÊý¾Ý£¬²¢ÌáÈ¡Æäí§ÒâÄÚÈÝ¡£±ðµÄ£¬¸ÃÀ©Õ¹³ÌÐò¿ÉÄÜ»áʹÓÃDOM APIÔÚÓû§ÊäÈëʱֱ½ÓÌáÈ¡ÊäÈëÖµ¡£GoogleÌåÏÖËûÃÇÕýÔÚÊÓ²ì´ËÊ¡£


https://www.bleepingcomputer.com/news/security/chrome-extensions-can-steal-plaintext-passwords-from-websites/


2¡¢Ï¤Äá´óѧµÚÈý·½·þÎñÌṩÉÌÔâµ½¹¥»÷²¿·ÖÊý¾Ýй¶


¾Ý9ÔÂ3ÈÕ±¨µÀ£¬Ï¤Äá´óѧ(USYD)͸¶£¬ÆäµÚÈý·½·þÎñÌṩÉÌÔâµ½¹¥»÷£¬µ¼Ö½üÆÚÉêÇëºÍ×¢²áµÄ¹ú¼ÊÉêÇëÈ˵ÄÐÅϢй¶¡£USYD³Æ¸ÃÎÊÌâ½öÏÞÓÚ¼òµ¥Æ½Ì¨£¬¶Ô´óѧµÄÆäËüϵͳûÓÐÓ°Ï죬³õ³ÌÐò²éҲûÓз¢Ã÷ÈκÎÍâµØѧÉú¡¢½ÌÖ°Ô±¹¤»òУÓѵÄÐÅϢй¶¡£¹ûÕæµÄÊÂÎñÐÅÏ¢²¢Î´ËµÃ÷鶱¬·¢µÄʱ¼ä»òÄÄЩµÚÈý·½·þÎñÔâµ½¹¥»÷£¬ÏÖÔÚҲûÓйØÓÚUSYDϵͳÖÐÖ¹µÄͨ¸æ¡£


https://www.bleepingcomputer.com/news/security/university-of-sydney-data-breach-impacts-recent-applicants/


3¡¢EclecticIQÐû²¼ÀÕË÷Èí¼þKey GroupµÄÃ⺬»ìÃܳÌÐò


ýÌå9ÔÂ1Èճƣ¬EclecticIQÐû²¼ÀÕË÷Èí¼þKey Group£¨ÓÖÃûkeygroup777£©µÄÃ⺬»ìÃܳÌÐò£¬ÊÊÓÃÓÚ8Ô³õ¹¹½¨µÄ¶ñÒâÈí¼þ°æ±¾¡£Key GroupÖÁÉÙ×Ô½ñÄê1ÔÂÆð¾ÍÒ»Ö±»îÔ¾£¬¹¥»÷ÕßÉù³ÆËûÃǵĶñÒâÈí¼þʹÓõÄÊÇ"¾üÓü¶±ðAES¼ÓÃÜ"£¬µ«¸ÃlockerÔÚËùÓмÓÃÜÀú³ÌÖж¼Ê¹ÓÃÁ˾²Ì¬salt£¬Òò´Ë¸Ã¼Æ»®¾ßÓÐÒ»¶¨µÄ¿ÉÕ¹ÍûÐÔ£¬¼ÓÃÜÒ²ÓпÉÄܱ»Äæת¡£¸Ã¹¤¾ßÈÔ´¦ÓÚÑéÖ¤½×¶Î£¬¿ÉÄܲ»ÊÊÓÃÓÚÿ¸öKey GroupÑù±¾¡£


https://securityaffairs.com/150207/malware/key-group-ransomware-decryptor.html


4¡¢Callaway¹«Ë¾¹ûÕæÉæ¼°Áè¼Ý110ÍòÓû§µÄÊý¾Ýй¶ÊÂÎñ


9ÔÂ1ÈÕ±¨µÀ³Æ£¬ÃÀ¹ú¸ß¶û·òÇò×°±¸ÖÆÔìÉ̺ÍÏúÊÛÉÌCallaway¹ûÕæÁ˽üÆÚ±¬·¢µÄÊý¾Ýй¶ÊÂÎñ¡£CallawayÔÚ8ÔÂ29ÈÕÐû²¼Í¨Öª£¬³Æ8ÔÂ1ÈÕ±¬·¢µÄITϵͳÊÂÎñÓ°ÏìÁËÆäµçÉÌ·þÎñµÄ¿ÉÓÃÐÔ£¬²¢½«²¿·Ö¿Í»§ÐÅϢй¶¸øδ¾­ÊÚȨµÄµÚÈý·½¡£¸ÃÊÂÎñÓ°ÏìÁËCallaway¼°Æä×ÓÆ·ÅÆOdyssey¡¢OgioºÍCallaway Gold PreownedÍøÕ¾µÄ¿Í»§£¬Ð¹Â¶ÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢¶©µ¥ÀúÊ·¼Í¼¡¢Çå¾²ÎÊÌâºÍÕË»§ÃÜÂëµÈ£¬Éæ¼°ÁË1114954ÈË¡£ÓÉÓÚÃÜÂëºÍÇå¾²ÎÊÌâµÈÕÊ»§ÐÅϢй¶£¬CallawayÒÑÇ¿ÖÆËùÓпͻ§ÖØÖÃÃÜÂë¡£


https://therecord.media/topgolf-callaway-says-one-million-affected-by-breach


5¡¢SecuronixÅû¶ͨ¹ýMS SQL·Ö·¢FreeWorldµÄ¹¥»÷Ô˶¯


SecuronixÔÚ9ÔÂ1ÈÕÅû¶ÁËͨ¹ýMS SQL·Ö·¢ÀÕË÷Èí¼þFreeWorldµÄ¹¥»÷Ô˶¯DB#JAMMER¡£Æ乤¾ß°üÀ¨Ã¶¾Ù¹¤¾ß¡¢RAT payload¡¢Îó²îʹÓúÍƾ֤ÇÔÈ¡¹¤¾ßÒÔ¼°ÀÕË÷Èí¼þ¡£FreeWorldËƺõÊÇÀÕË÷Èí¼þMimicµÄбäÖÖ¡£³õʼ»á¼ûÊÇͨ¹ý±©Á¦ÆƽâMS SQL·þÎñÆ÷À´ÊµÏֵģ¬ÏÂÒ»½×¶ÎÐèÒª½ÓÄɲ½·¥¹¥»÷ϵͳ·À»ðǽ£¬ÅþÁ¬Ô¶³ÌSMB¹²ÏíÀ´½¨É賤ÆÚÐÔ£¬ÒÔ±ãÔÚϵͳ֮¼ä´«ÊäÎļþ£¬²¢×°ÖÃCobalt StrikeµÈ¹¤¾ß¡£È»ºó×°ÖÃAnyDesk£¬ºáÏòÒƶ¯£¬×îÖÕ×°ÖÃFreeWorld¡£


https://www.securonix.com/blog/securonix-threat-labs-security-advisory-threat-actors-target-mssql-servers-in-dbjammer-to-deliver-freeworld-ransomware/


6¡¢CiscoÐû²¼¹ØÓÚ¿ªÔ´ÇÔÈ¡³ÌÐòSapphireStealerµÄ±¨¸æ


8ÔÂ31ÈÕ£¬CiscoÐû²¼Á˹ØÓÚ¿ªÔ´ÇÔÈ¡³ÌÐòSapphireStealerµÄÆÊÎö±¨¸æ¡£×Ô2022Äê12ÔÂÊ×´ÎÐû²¼ÒÔÀ´£¬SapphireStealerÔÚ¹«¹²¶ñÒâÈí¼þ´æ´¢¿âÖзºÆðµÄƵÂÊÒ»Ö±ÔöÌí¡£Ëü¾ßÓÐÍøÂçÖ÷»úÐÅÏ¢¡¢ä¯ÀÀÆ÷Êý¾Ý¡¢ÎļþºÍÆÁÄ»½ØͼµÄ¹¦Ð§£¬²¢¿Éͨ¹ý¼òÆÓÓʼþ´«ÊäЭÒé(SMTP)ÒÔZIPÎļþµÄÐÎʽ´«ÊäÊý¾Ý¡£±ðµÄ£¬Ñо¿Ö°Ô±»¹·¢Ã÷ÁËSapphireStealerµÄ¶à¸ö±äÌ壬³ÆºÚ¿ÍË¢ÐÂÁËԭʼ´úÂë¿â£¬Ê¹ÆäÖ§³Ö¸ü¶àµÄÊý¾Ý鶻úÖÆ£¬Òò¶ø±¬·¢Á˶à¸ö±äÌå¡£


https://blog.talosintelligence.com/sapphirestealer-goes-open-source/