Cisco°ä²¼°²È«¸üн¨¸´IP PhoneϵÁвúÆ·Öзì϶

°ä²¼¹¦·ò 2023-03-03

1¡¢Cisco°ä²¼°²È«¸üн¨¸´IP PhoneϵÁвúÆ·Öзì϶


CiscoÔÚ3ÔÂ1ÈÕ°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´Ó°ÏìÆäIP Phone 6800¡¢7800¡¢7900ºÍ8800ϵÁвúÆ·µÄ·ì϶¡£¡£¡£¡£¡£¡£ ¡£ÕâÊÇ»ùÓÚWebµÄÖÎÀí½çÃæÖеĺÅÁî×¢Èë·ì϶£¨CVE-2023-20078£©£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚ¶ÔÓû§ÌṩµÄÊäÈëµÄÑéÖ¤²»³ä·Öµ¼ÖµÄ£¬£¬£¬£¬£¬£¬£¬£¬³É¹¦µÄÀûÓô˷ì϶¿ÉÔÚÊÜÓ°ÏìÉ豸µÄµ×²ã²Ù×÷ϵͳÉÏÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£ ¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾»¹Åû¶ÁËDoS·ì϶£¨CVE-2023-20079£©£¬£¬£¬£¬£¬£¬£¬£¬Ò²ÊǶÔÓû§ÌṩµÄÊäÈëµÄÑéÖ¤²»³ä·Öµ¼ÖµÄ£¬£¬£¬£¬£¬£¬£¬£¬¿É±»ÓÃÀ´´¥·¢DoSǰÌá¡£¡£¡£¡£¡£¡£ ¡£


https://thehackernews.com/2023/03/critical-flaw-in-cisco-ip-phone-series.html


2¡¢Exchange Online³öÏÖBugµ¼ÖÂÈ«ÇòÓû§ÎÞ·¨½Ó¼û


¾ÝýÌå3ÔÂ1ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬MicrosoftÔÚµ÷²éÈ«ÇòExchange OnlineÓû§ÎÞ·¨½Ó¼ûÆäÓÊÏäµÄÎÊÌâ¡£¡£¡£¡£¡£¡£ ¡£´Ó3ÔÂ1ÈÕ1:11 PM UTCÆðÍ·£¬£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§ÔÚ·¢ËÍ»ò½Ó¹ÜÓʼþʱ»á¿´µ½"550 5.4.1 Recipient address rejected: Access denied"µÄÃýÎóÌáÐÑ¡£¡£¡£¡£¡£¡£ ¡£MicrosoftÔÚ5:22 PM UTC³ÆÒѾ­·¢ÏÖÁËÒ»¸öDZÔڵĻùÓÚĿ¼µÄ±ßÔµ¹Ø±Õ£¨DBEB£©ÎÊÌâ¡£¡£¡£¡£¡£¡£ ¡£16:01 EST£¬£¬£¬£¬£¬£¬£¬£¬Microsoft°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýExchange Online Protection(EOP)Á÷Á¿ÔÚÊÜÓ°ÏìµÄ»ù´¡ÉèÊ©ÖгÁÐÂÅäÖ÷ÓÉ£¬£¬£¬£¬£¬£¬£¬£¬½â¾öÁ˸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/microsoft-exchange-online-outage-blocks-access-to-mailboxes-worldwide/


3¡¢eSentireÅû¶Õë¶Ô¶à¸öÂÉʦÊÂÎñËùµÄ¹¥»÷»î¶¯µÄÏêÇé


eSentireÓÚ2ÔÂ28ÈÕÅû¶ÁËÔÚ2023Äê1ÔºÍ2ÔÂÕë¶Ô6¼Ò·ÖÆçµÄÂÉʦÊÂÎñËùµÄ¹¥»÷¡£¡£¡£¡£¡£¡£ ¡£ÕâЩ¹¥»÷Ô´×ÔÁ½¸ö·ÖÆçµÄ¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÖ®Ò»ÊÔͼÓöñÒâÈí¼þGootLoaderϰȾÂÉʦÊÂÎñËùµÄÔ±¹¤£¬£¬£¬£¬£¬£¬£¬£¬ÁíÒ»³¡»î¶¯Ê¹ÓöñÒâÈí¼þSocGholish¹¥»÷ÂÉʦÊÂÎñËùÔ±¹¤ºÍÆäËüÖ¸±ê¡£¡£¡£¡£¡£¡£ ¡£GootLoader»î¶¯Ê¹ÓÃËÑË÷ÒýÇæÓÅ»¯(SEO)Öж¾£¬£¬£¬£¬£¬£¬£¬£¬ÆäÈëÇÖÁ˺Ϸ¨µÄWordPressÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬²¢ÀûÓá°ºÍ̸¡±µÈ¹Ø¼ü×ÖÓÕʹָ±êÏÂÔØ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£ ¡£SocGholish»î¶¯ÀûÓÃÁËÂÉʦÊÂÎñËùʱʱ¹â¹ËµÄÍøÕ¾½øÐÐË®¿Ó¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÐéαµÄä¯ÀÀÆ÷¸üÐÂΪµö¶ü´«²¼¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£ ¡£


https://www.esentire.com/blog/hackers-attack-employees-from-six-law-firms-with-the-gootloader-and-socgholish-malware-using-fake-legal-agreements-and-malicious-watering-hole-s-reports-esentire


4¡¢°µÍøBidenCashÖÜÄê»î¶¯¹«¿ª200¶àÍòÕÅÐÅÓþ¿¨µÄÐÅÏ¢


¾Ý3ÔÂ2ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬Ò»¸ö°µÍøÐÅÓþ¿¨Êг¡BidenCash¹«¿ªÁ˳¬¹ý200ÍòÕÅÓÐЧÐÅÓþ¿¨µÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬×÷ΪÆäÖÜÄê´ÙÏú»î¶¯µÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£ ¡£ÕâЩÐÅÓþ¿¨À´×ÔÊÀ½ç¸÷µØ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖдó²¿ÃÅÊÇÔÚÃÀ¹ú¡¢Ä«Î÷¸ç¡¢Ó¡¶È¡¢¼ÓÄôóºÍÓ¢¹ú¿¯Ðеġ£¡£¡£¡£¡£¡£ ¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬³Ö¿¨È˵ÄÐÕÃû¡¢¿¨ºÅ¡¢ÒøÐоßÌåÐÅÏ¢¡¢ÓÐЧÆÚ¡¢¿¨ÑéÖ¤Öµ(CVV)¡¢¼ÒͥסַºÍ³¬¹ý500000¸öÓʼþµØÖ·¡£¡£¡£¡£¡£¡£ ¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬BidenCashÇÔÊØÐÅÏ¢µÄ·½Ê½Éв»Ã÷È·£¬£¬£¬£¬£¬£¬£¬£¬µ±¾ÖÔÚµ÷²éÕâÆðÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬²¢½¨ÒéÊÜÓ°ÏìµÄ³Ö¿¨ÈË¼à¿ØËûÃǵÄÕË»§¡£¡£¡£¡£¡£¡£ ¡£


https://www.hackread.com/bidencash-leaks-2-million-credit-cards/


5¡¢Ó¢¹úÁãÊÛÉ̵êWH Smith³ÆÆäÔ±¹¤Êý¾ÝÔâµ½·¸·¨½Ó¼û


ýÌå3ÔÂ2Èճƣ¬£¬£¬£¬£¬£¬£¬£¬Ó¢¹úÁãÊÛÉ̵êWH SmithÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔ±¹¤ºÍǰԱ¹¤µÄÐÅϢй¶¡£¡£¡£¡£¡£¡£ ¡£¸Ã¹«Ë¾ÔÚÓ¢¹ú¾­Óª×Å1700¸öÉ̵꣬£¬£¬£¬£¬£¬£¬£¬Õ¼Óг¬¹ý12500ÃûÔ±¹¤£¬£¬£¬£¬£¬£¬£¬£¬2022ÄêµÄÊÕÈëΪ16.7ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£ ¡£¸Ã¹«Ë¾°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬Õâ´ÎÊÂÎñµ¼Ö¹«Ë¾µÄ²¿ÃÅÊý¾Ý±»·¸·¨½Ó¼û£¬£¬£¬£¬£¬£¬£¬£¬µ«²¢Î´Ó°ÏìÆäÒµÎñÒµÎñ¡£¡£¡£¡£¡£¡£ ¡£¿£¿£¿£¿ £¿£¿£¿ £¿Í»§ÐÅϢûÓÐÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÕâЩÐÅÏ¢´æ´¢ÔÚµ¥¶ÀµÄϵͳÉÏ¡£¡£¡£¡£¡£¡£ ¡£¸Ã¹«Ë¾Ã»ÓÐй©ÊÂÎñµÄÐÔÖÊ£¬£¬£¬£¬£¬£¬£¬£¬µ«¿ÉÄÜÊÇÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£ ¡£¹ÌȻûÓйØÓÚ¹¥»÷ÈÕÆÚµÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬µ«¹¥»÷Ó¦¸ÃÊDzúÉúÔÚ1ÔÂ18ÈÕÖ®ºó¡£¡£¡£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/british-retail-chain-wh-smith-says-data-stolen-in-cyberattack/


6¡¢TrendMicro°ä²¼APT27¶ñÒâÈí¼þSysUpdateµÄ·ÖÎö»ã±¨


3ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Trend Micro°ä²¼ÁËAPT27£¨Iron Tiger£©Linux°æ±¾×Ô½ç˵¶ñÒâÈí¼þSysUpdateµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£ ¡£ºÚ¿ÍÓÚ2022Äê7Ô³õ´Î²âÊÔÁËLinux°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬È»¶øÖ±µ½2022Äê10Ô£¬£¬£¬£¬£¬£¬£¬£¬¶à¸öpayload²ÅÆðÍ·ÔÚÒ°±í´«²¼¡£¡£¡£¡£¡£¡£ ¡£¸ÃLinux±äÌåÊÇÒ»¸öELF¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃAsio¿âÓÃC++¿ª·¢£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖ°ÄÜÓëWindows°æSysUpdate¼«¶ÈÀàËÆ£¬£¬£¬£¬£¬£¬£¬£¬ÐÂÔöÁËDNSËí·ְÄÜ¡£¡£¡£¡£¡£¡£ ¡£Trend Micro°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬Ñ¡ÔñAsio¿âÀ´¿ª·¢Linux°æ±¾µÄSysUpdate¿ÉÄÜÊÇÓÉÓÚËüµÄ¶àƽ̨¿ÉÒÆÖ²ÐÔ£¬£¬£¬£¬£¬£¬£¬£¬²¢Ô¤²âmacOS°æ±¾¿ÉÄܺܿì¾Í»á³öÏÖ¡£¡£¡£¡£¡£¡£ ¡£


https://www.trendmicro.com/en_us/research/23/c/iron-tiger-sysupdate-adds-linux-targeting.html