ºÚ¿ÍÀûÓþɰæMS Excel·ì϶´«²¼¶ñÒâÈí¼þAgent Tesla
°ä²¼¹¦·ò 2023-12-221. ºÚ¿ÍÀûÓþɰæMS Excel·ì϶´«²¼¶ñÒâÈí¼þAgent Tesla
21ÈÕýÌ屨·£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÀûÓÃ¾ÉµÄ Microsoft Office ·ì϶À´´«²¼ÃûΪAgent TeslaµÄ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£ÒÔ·¢Æ±ÎªÖ÷ÌâµÄÐÂÎÅÖи½¼ÓµÄµö¶ü Excel Îĵ·´ÓÕÆÇ±ÔÚÖ¸±ê´ò¿ªËüÃDz¢ÀûÓÃCVE-2017-11882£¨CVSS ÆÀ·Ö£º7.8£©£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇ Office ¹«Ê½±à×ëÆ÷ÖеÄÄÚ´æ°Ü»µ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܻᵼÖ´úÂëÒÔÓû§È¨ÏÞÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£¡£Agent TeslaÊÇÒ»ÖÖ»ùÓÚ .NET µÄ¸ß¼¶¼üÅ̼ͼÆ÷ºÍÔ¶³Ì½Ó¼ûľÂí (RAT)£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜ´ÓÊÜϰȾµÄÖ÷»ú»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£¶øºóÌáÈ¡ÍøÂçµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2023/12/hackers-exploiting-old-ms-excel.html
2. FBI³ÆÀÕË÷ÍÅ»ïPlayÔÚ17¸öÔÂÄÚ·¢ÆðÁ˽ü300´Î¹¥»÷»î¶¯
¾ÝýÌå19ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬½ñÄêÕë¶ÔÃÀ¹úÊÐÕþ·þÎñµÄ¼¸Æð·ÛËéÐÔ¹¥»÷Ö»ÊÇÀÕË÷ÍÅ»ï Play µÄ±ùɽһ½Ç£¬£¬£¬£¬£¬£¬£¬£¬¾Ý FBI ³Æ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïÔÚ 17 ¸öÔÂÄÚÏ®»÷Á˽ü 300 ¸ö×éÖ¯¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯£¨Ò²³ÆÎª Playcrypt£©Ó°ÏìÁ˱±ÃÀ¡¢ÄÏÃÀºÍÅ·ÖÞµÄ¿í·ºÆóÒµºÍ¹Ø¼ü»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¡£¡£Play ÀÕË÷Èí¼þ¹¥»÷Õßѡȡ˫³ÁÀÕË÷Ä£ÐÍ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÇÔÈ¡Êý¾Ýºó¶Ôϵͳ½øÐмÓÃÜ¡£¡£¡£¡£¡£¡£¡£¡£Êê½ðµ¥¾Ý²»Ô̺¬×î³õµÄÊê½ðÒªÇó»ò¸¶¿î×¢Ã÷£¬£¬£¬£¬£¬£¬£¬£¬¶øÊÇÅúʾÊܺ¦Õßͨ¹ýµç×ÓÓʼþÁªÏµÍþвÐÐΪÕß¡£¡£¡£¡£¡£¡£¡£¡£
https://www.scmagazine.com/news/play-ransomware-gang-tied-to-300-attacks-in-17-months
3. °²È«×êÑÐÈËÔ±·¢ÏÖ25%µÄ¸ßΣ·ì϶Ôڰ䲼ȷµ±Ìì¾Í±»ÀûÓÃ
19ÈÕýÌ屨·ÖУ¬£¬£¬£¬£¬£¬£¬£¬ÔÚQualys°ä²¼µÄ×êÑв©¿ÍÖУ¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËһЩÓë´ÓǰһÄê»ã±¨µÄ³£¼û·ì϶ºÍCVE°ä²¼ÓйصÄÇ÷Ïò¡£¡£¡£¡£¡£¡£¡£¡£³ýÁ˺ڿÍÀûÓÃÒÑÖª·ì϶µÄËÙ¶ÈÖ®±í£¬£¬£¬£¬£¬£¬£¬£¬»ã±¨»¹Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬2023 Ä꣨Æù½ñΪֹ£©»ã±¨µÄ¸ß·çÏÕ·ì϶ÖÐÓÐ 97 ¸ö¿ÉÄÜÒѱ»ÀûÓ㬣¬£¬£¬£¬£¬£¬£¬µ«´Óδ³Ê´Ë¿Ì CISA µÄÒÑÖª¿ÉÀûÓ÷ì϶ (KEV) Ŀ¼ÖÓ×£¡£¡£¡£¡£¡£¡£¡£»ã±¨Öл¹Ìá¼°²»µ½ 1% µÄ·ì϶Ôì³É×î¸ß·çÏÕ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒʱʱ±»¿í·ºÀûÓᣡ£¡£¡£¡£¡£¡£¡£
https://www.scmagazine.com/news/1-in-4-high-risk-cves-are-exploited-within-24-hours-of-going-public
4. ŦԼij·¿µØ²ú¹«Ë¾ÔÆ·þÎñÆ÷ÅäÖÃÃýÎóй¶15ÒÚÌõµØ²ú¼Í¼
20ÈÕýÌ屨·£¬£¬£¬£¬£¬£¬£¬£¬ÍøÂ簲ȫ×êÑÐÔ± Jeremiah Fowler ·¢ÏÖÁËÒ»¸öÓëŦԼÔÚÏ߯½Ì¨ Real Estate Wealth Network ÓйصÄδÊܱ£»£»£»£»£»£»¤µÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬Êý¾Ý¿â±£ÁôÁË 15 Òڱʼͼ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Êý°ÙÍòÈ˵ķ¿µØ²úËùÓÐȨÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â´óÓ×Ϊ 1.16 TB£¨×ܹ² 1,523,776,691 ±Ê¼Í¼£©£¬£¬£¬£¬£¬£¬£¬£¬ÓµÓÐ×éÖ¯ÓÐÐòµÄÎļþ¼Ð£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ÓйØÒµÖ÷¡¢Âô¼Ò¡¢Í¶×ÊÕߺÍÄÚ²¿Óû§ÈÕÖ¾Êý¾ÝµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ËüÔ̺¬´Ó 2023 Äê 4 Ô 22 ÈÕµ½ 23 Äê 10 Ô 23 ÈÕµÄÖðÈÕÈÕÖ¾¼Í¼£¬£¬£¬£¬£¬£¬£¬£¬½ÒʾÁËÄÚ²¿Óû§ËÑË÷Êý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£
https://www.hackread.com/data-leak-exposes-real-estate-records-elon-musk-trump/
5. ¶ñÒâÈí¼þJaskaGO¿É¿çMacºÍWindowsÇÔÈ¡Óû§Êý¾Ý
20ÈÕýÌ屨·£¬£¬£¬£¬£¬£¬£¬£¬AT&T Alien Labs µÄÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖÁËÒ»ÖÖÃûΪ JaskaGO µÄ¸´ÔÓ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬ËüÊÇÓà Go ( Golang ) ±à³Ì˵»°±àдµÄ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÓµÓÐÔÚÊÜϰȾϵͳÖÐά³ÖÓÆ¾ÃÐÔµÄÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£¡£ËüÄܹ»Ð¹Â¶ÓмÛÖµµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ä¯ÀÀÆ÷Í´´¦ºÍ¼ÓÃÜÇ®±ÒÇ®°ü¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý AT&T Alien Labs µÄ»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬JaskaGO ÊÇÒ»ÖÖºýŪÐÔ¹¤¾ß£¬£¬£¬£¬£¬£¬£¬£¬Ëü»áÏÔʾһÌõÐéαµÄÃýÎóÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬£¬Ðû³ÆÎļþÃÔʧ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÎóµ¼Óû§ÏàÐŶñÒâ´úÂëÎÞ·¨ÔËÐÓ×£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬ËüʹÓÃÀàËÆÓÚ³ÛÃûÀûÓ÷¨Ê½µÄÎļþÃû£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈç¡°Capcut_Installer_Intel_M1.dmg¡±ºÍ¡°Anyconnect.exe¡±£¬£¬£¬£¬£¬£¬£¬£¬ÕâÅú×¢ÔÚµÁ°æÀûÓ÷¨Ê½ÍøÒ³ÖÐÒԺϷ¨Èí¼þΪ»Ï×Ó²¿Êð¶ñÒâÈí¼þµÄ³£¼ûÕ½Êõ¡£¡£¡£¡£¡£¡£¡£¡£
https://www.hackread.com/jaskago-malware-mac-windows-crypto-browser-data/
6. Ivanti°ä²¼¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´13¸öÑϳÁAvalanche RCE·ì϶
20ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Ivanti °ä²¼Á˰²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´Á˸ù«Ë¾ Avalanche ÆóÒµÒÆ¶¯É豸ÖÎÀí (MDM) ½â¾ö¹æ»®ÖÐµÄ 13 ¸ö¹Ø¼ü°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£¡£Avalanche ÔÊÐíÖÎÀíԱͨ¹ý»¥ÁªÍø´ÓÒ»¸öÖÐÑëµØÎ»ÖÎÀí³¬¹ý 100,000 Ì¨ÒÆ¶¯É豸¡¢²¿ÊðÈí¼þ²¢×°ÖøüС£¡£¡£¡£¡£¡£¡£¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Ôڵ͸´ÔÓÐÔ¹¥»÷ÖÐÀûÓÃËüÃÇ£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ¹¥»÷²»±ØÒªÓû§½»»¥¼´¿ÉÔÚ佨²¹µÄϵͳÉÏ»ñµÃÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£¡£CISAÆäʱÖÒ¸æËµ£¬£¬£¬£¬£¬£¬£¬£¬Òƶ¯É豸ÖÎÀí (MDM) ϵͳ¶ÔÓÚÍþвÐÐΪÕßÀ´ËµÊÇÓÐÎüÒýÁ¦µÄÖ¸±ê£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÌṩÁ˶ÔÊýǧ¸öÒÆ¶¯É豸µÄ¸ü¸ß½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ APT ÐÐΪÕßÒѾÀûÓÃÁË֮ǰµÄ MobileIron ·ì϶¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/ivanti-releases-patches-for-13-critical-avalanche-rce-flaws/


¾©¹«Íø°²±¸11010802024551ºÅ