Docker HubÉÏÍйܵĴóÁ¿¾µÏñй¶˽ԿºÍAPIÃÜÔ¿µÈÐÅÏ¢
°ä²¼¹¦·ò 2023-07-181¡¢Docker HubÉÏÍйܵĴóÁ¿¾µÏñй¶˽ԿºÍAPIÃÜÔ¿µÈÐÅÏ¢
¾ÝýÌå7ÔÂ16ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬µÂ¹úÑÇ衹¤Òµ´óѧ×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬Docker HubÉÏÍйܵĴóÁ¿¾µÏñй¼ûô¸ÐµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·ÖÎöÁËÀ´×ÔDocker HubºÍÊýǧ¸ö˽ÓÐ×¢²á±íµÄ337171¸ö¾µÏñ£¬£¬£¬£¬£¬£¬£¬£¬·¢ÏÖÔ¼8.5%Ô̺¬Ë½Ô¿ºÍAPIÃÜÔ¿µÈÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÃÕýÔò±í°×ʽËÑË÷ÌØ¶¨Êý¾ÝµÄ·ÖÎöÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬28621¸öDocker¾µÏñй¶ÁË52107¸öÓÐЧ˽ԿºÍ3158¸ö·ÖÆçµÄAPIÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£¡£´óÎÞÊýй¶µÄÐÅÏ¢£¨95%Ϊ˽Կ£¬£¬£¬£¬£¬£¬£¬£¬90%ΪAPIÃÜÔ¿£©¶¼´æÔÚÓÚµ¥Óû§¾µÏñÖУ¬£¬£¬£¬£¬£¬£¬£¬ÕâÅú×¢ËüÃÇ¿ÉÄÜÊÇÎÞÒâ¼äй¶µÄ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/thousands-of-images-on-docker-hub-leak-auth-secrets-private-keys/
2¡¢Rapid7й©¶à¸öAdobe ColdFusion·ì϶Òѱ»×Ô¶¯ÀûÓÃ
Rapid7ÔÚ7ÔÂ17ÈÕй©£¬£¬£¬£¬£¬£¬£¬£¬Æä¹Û²ìµ½Adobe ColdFusion·ì϶ÔÚ¶à¸ö¿Í»§ÏµÍ³Öб»ÀûÓõÄÇé¿ö¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝÏÖÓÐÖ¤¾Ý£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÈçͬÔÚÀûÓýӼû½ÚÔìÈÆ¹ý·ì϶(CVE-2023-29298)ºÍÁíÒ»¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬£¬£¬¹Û²ìµ½µÄ¹¥»÷ËÆºõÓëCVE-2023-38203Óйء£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬AdobeÔÚ7ÔÂ11ÈÕΪCVE-2023-29298ÌṩµÄ½¨¸´·¨Ê½²¢²»ÆëÈ«£¬£¬£¬£¬£¬£¬£¬£¬¾¹ýµ¥Ò»Åú¸ÄµÄ·ì϶ÀûÓÃÒÀÈ»ºÏÓÃÓÚ×îа汾µÄColdFusion¡£¡£¡£¡£¡£¡£¡£¡£µ«ÓÉÓڸ÷ì϶±ØÒªÓëÁíÒ»¸ö·ì϶½áºÏʹÓ㬣¬£¬£¬£¬£¬£¬£¬ÀýÈçCVE-2023-38203¡£¡£¡£¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬£¬£¬£¬×°ÖÃ×îа汾µÄColdFusionÈÔÄܹ»×èÖ¹·ì϶µÄÀûÓᣡ£¡£¡£¡£¡£¡£¡£
https://www.rapid7.com/blog/post/2023/07/17/etr-active-exploitation-of-multiple-adobe-coldfusion-vulnerabilities/
3¡¢¿ÆÂÞÀ¶àÖÝÁ¢´óѧÔâµ½ÀÕË÷¹¥»÷ѧÉúºÍÔ±¹¤µÄÐÅϢй¶
¾Ý7ÔÂ14ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬¿ÆÂÞÀ¶àÖÝÁ¢´óѧ(CSU)Ôâµ½ÁËClopÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÈκÍǰÈÎѧÉúºÍÔ±¹¤µÄÓ×ÎÒÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£¡£¸Ã´óѧÓÚ7ÔÂ12ÈÕÏòÊÜÓ°ÏìµÄÓ×ÎҰ䲼֪ͨ¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Îй¶²¢²»ÊÇCSUµÄϵͳÔâµ½¹¥»÷µ¼Öµģ¬£¬£¬£¬£¬£¬£¬£¬¶øÊÇ·þÎñÌṩÉÌ¡¢TIAA¡¢¹ú¶ÈѧÉúÐÅÏ¢»¥»»ËùºÍCorebridge FinancialµÈʹÓÃÁËMOVEit Transfer°²È«Îļþ´«ÊäÆ½Ì¨Ôâµ½ÈëÇÖµ¼Öµġ£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬¸ÃѧÌò»»áÏòCSU»áÔ±ÌṩÉí·Ý͵ÇÔ±£»£»£»£»£»£»£»¤·þÎñ£¬£¬£¬£¬£¬£¬£¬£¬½¨Òé»áÔ±×ñÑFTC°ä²¼µÄ½¨Òé¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/colorado-state-university-says-data-breach-impacts-students-staff/
4¡¢Cyble·¢ÏÖ¼ÙÒâTeamViewer×°Ö÷¨Ê½·Ö·¢njRATµÄ»î¶¯
7ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬CybleÅû¶Á˼ÙÒâTeamViewer×°Ö÷¨Ê½·Ö·¢Ä¾ÂínjRAT£¨±ðÃûBladabindi£©µÄ»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£njRAT×î³õÓÚ2012Äê±»·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÓÃÓÚÕë¶ÔÖж«¹ú¶ÈµÄ×éÖ¯¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏֵĶñÒâÈí¼þÑù±¾ÊÇÒ»¸ö32λÖÇÄÜ×°Ö÷¨Ê½£¬£¬£¬£¬£¬£¬£¬£¬Ëü»á×°ÖÃÒ»¸öÕý°æTeamViewerÀûÓúͶñÒâÈí¼þnjRAT¡£¡£¡£¡£¡£¡£¡£¡£Ö´Ðк󣬣¬£¬£¬£¬£¬£¬£¬»áÆô¶¯TeamViewerÀûÓò¢´¥·¢njRAT¡£¡£¡£¡£¡£¡£¡£¡£ÎªÁËÈ·Î¬ÓÆ¾ÃÐÔ£¬£¬£¬£¬£¬£¬£¬£¬njRAT»¹Åú¸ÄϵͳÉèÖ㬣¬£¬£¬£¬£¬£¬£¬´Ó¶øÈƹý°²È«ÖÒ¸æÌáÐÑ¡£¡£¡£¡£¡£¡£¡£¡£²¢ÔÚϵͳע²á±íÖд´½¨×Ô¶¯ÔËÐÐÌõ¿î£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ±£ÕÏÿ´ÎϵͳÆô¶¯Ê±×Ô¶¯ÔËÐС£¡£¡£¡£¡£¡£¡£¡£
https://blog.cyble.com/2023/07/13/trojanized-application-preying-on-teamviewer-users/
5¡¢ZimbraÌáÐÑÓû§ÊÖ¶¯½¨¸´ÆäZCSÖÐÒѱ»ÀûÓõÄXSS·ì϶
7ÔÂ13ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬£¬£¬£¬ZimbraÌáÐÑÓû§ÊÖ¶¯½¨¸´Zimbra Collaboration Suite(ZCS)µç×ÓÓʼþ·þÎñÆ÷ÖÐÒѱ»ÀûÓõÄXSS·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»ZimbraûÓÐй©¸Ã·ì϶±»ÓÃÓÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬µ«Google TAG°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬¸ÃXSS·ì϶ÊÇÔÚÒ»´ÎÓÐÕë¶ÔÐԵĹ¥»÷Öб»·¢Ïֵġ£¡£¡£¡£¡£¡£¡£¡£ZimbraÉÐδÌṩ°²È«²¹¶¡À´½¨¸´Õâ¸öÁãÈÕ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬µ«ËüµÄÈ·ÌṩÁËÒ»¸ö½¨¸´·¨Ê½£¬£¬£¬£¬£¬£¬£¬£¬²¢½¨ÒéÖÎÀíÔ±ÊÖ¶¯ÀûÓøý¨¸´·¨Ê½À´½¨¸´´Ë·ì϶¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬Zimbra³Æ¸Ã½¨¸´·¨Ê½´òËãÔÚ7Ô·ݵIJ¹¶¡ÖÐÌṩ¡£¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/148429/hacking/zimbra-collaboration-suite-zeroday.html
6¡¢Check Point°ä²¼2023ÄêQ2ÍøÂç¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨
7ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Check Point°ä²¼2023ÄêµÚ¶þ¼¾¶ÈÍøÂç¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£2023ÄêQ2£¬£¬£¬£¬£¬£¬£¬£¬È«Çò¾ùÔÈÿÖܹ¥»÷´ÎÊý½ÏÉÏÄêÔö³¤8%£¬£¬£¬£¬£¬£¬£¬£¬Ã¿¸ö×é֯ÿÖܵľùÔȹ¥»÷´ÎÊý´ïµ½1258´Î¡£¡£¡£¡£¡£¡£¡£¡£½ÌÓýºÍ×êÑÐÐÐÒµÔâµ½µÄ¹¥»÷´ÎÊý×î¶à£¬£¬£¬£¬£¬£¬£¬£¬Ã¿¸ö×éÖ¯¾ùÔÈÿÖܱ»¹¥»÷2179´Î£¬£¬£¬£¬£¬£¬£¬£¬Óë2022ÄêQ2Ïà±È½µÂäÁË6% ¡£¡£¡£¡£¡£¡£¡£¡£µ±¾ÖºÍ¾üʲ¿ÃÅ´ÎÖ®£¬£¬£¬£¬£¬£¬£¬£¬¾ùÔÈÿÖÜ1772´Î¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬±ÈÈ¥ÄêͬÆÚÔö³¤9%¡£¡£¡£¡£¡£¡£¡£¡£·ÇÖÞµÄ×éÖ¯Ôâµ½µÄ¹¥»÷×î¶à£¬£¬£¬£¬£¬£¬£¬£¬±ÈÈ¥Äêͬ±ÈÔö³¤23%¡£¡£¡£¡£¡£¡£¡£¡£Æä´ÎÊÇÑÇÌ«µØÓò£¬£¬£¬£¬£¬£¬£¬£¬Ôö³¤ÁË22%¡£¡£¡£¡£¡£¡£¡£¡£È«Çòÿ44¸ö×éÖ¯ÖоÍÓÐ1¸öÔâµ½ÁËÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖе±¾ÖºÍ¾üÊÂÐÐÒµÔâµ½´ËÀ๥»÷µÄ´ÎÊý×î¶à¡£¡£¡£¡£¡£¡£¡£¡£
https://blog.checkpoint.com/security/average-weekly-global-cyberattacks-peak-with-the-highest-number-in-2-years-marking-an-8-growth-year-over-year-according-to-check-point-research/


¾©¹«Íø°²±¸11010802024551ºÅ