΢ÈíÐû²¼3Ô¸üÐÂÐÞ¸´Á½¸öÒѱ»ÀûÓé¶´ÔÚÄÚµÄ83¸ö©¶´
Ðû²¼Ê±¼ä 2023-03-151¡¢Î¢ÈíÐû²¼3Ô¸üÐÂÐÞ¸´Á½¸öÒѱ»ÀûÓé¶´ÔÚÄÚµÄ83¸ö©¶´
3ÔÂ14ÈÕ£¬Î¢ÈíÐû²¼2023Äê3ÔµÄÖܶþ²¹¶¡£¬ÐÞ¸´Á˰üÂÞÁ½¸öÒѱ»ÀûÓõÄ0 dayÔÚÄÚµÄ83¸ö©¶´£¬´Ë¼ÆÊý²»°üÂÞ21¸öMicrosoft Edge©¶´¡£Òѱ»ÀûÓõÄ©¶´·Ö±ðΪMicrosoft OutlookȨÏÞÌáÉý©¶´£¨CVE-2023-23397£©ºÍWindows SmartScreenÄþ¾²¹¦Ð§Èƹý©¶´£¨CVE-2023-24880£©¡£´ËÍ⣬½ÏΪÑÏÖØµÄ©¶´°üÂÞ»¥ÁªÍø¿ØÖÆÏûÏ¢ÐÒé(ICMP)Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2023-23415£©ºÍWindows Hyper-V¾Ü¾ø·þÎñ©¶´£¨CVE-2023-23411£©µÈ¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2023-patch-tuesday-fixes-2-zero-days-83-flaws/
2¡¢Euler FinanceÔâµ½ÉÁµç´û¹¥»÷Ëðʧ¸ß´ï1.96ÒÚÃÀÔª
¾ÝýÌå3ÔÂ13ÈÕ±¨µÀ£¬Euler FinanceÔâµ½ÉÁµç´û¹¥»÷£¬ËðʧÁ˼ÛÖµ1.97ÒÚÃÀÔªµÄ¶àÖÖÊý×Ö×ʲú¡£Ñо¿ÈËÔ±³Æ£¬¹¥»÷Õß¿ÉÄÜʹÓÃÉÁ´æ´û¿î´ÓDe-FiÐÒéAaveºÍBalancer½èÇ®£¬²¢½«Ç®´æÈëEuler¡£È»ºó£¬¹¥»÷Õß½èÁËÊ®±¶ÓÚÆä´æÈëEulerµÄ½ð¶î¡£¹¥»÷ÕßÈëÇÖÖÇÄܺÏÔ¼²¢±£Áô½è¿î¼òÖ±ÇÐÊֶλò©¶´²¢²»Çå³þ£¬Ò²²»Çå³þ¹¥»÷ÊÇ·ñÒѾ½áÊø¡£Elliptic³ÂË߳ƣ¬¹¥»÷ÕßÒѾÔÚͨ¹ýTornado CashÏ´Ç®¡£Õâ´Î¹¥»÷µ¼ÖÂEuler(EUL)´ú±Ò¼ÛÖµÒ»Ò¹Ö®¼äϵøÁË44.2%£¬´Ó6.56ÃÀÔªµøÖÁ3.37ÃÀÔª¡£
https://www.securityweek.com/euler-loses-nearly-200-million-to-flash-loan-attack/
3¡¢Î¢Èí¹ûÈ»¹ØÓÚDEV-1101¼°ÆäÏà¹ØAiTM»î¶¯µÄÏêϸÐÅÏ¢
΢ÈíÔÚ3ÔÂ13ÈÕ¹ûÈ»Á˹ØÓÚDEV-1101¼°ÆäÏà¹ØAiTM»î¶¯µÄÏêϸÐÅÏ¢¡£DEV-1101ÊÇ΢Èí¸ú×ٵĹ¥»÷Õߣ¬ÂôÁ¦¿ª·¢¡¢Ö§³ÖºÍÐû´«¶à¸öAiTMÍøÂçµöÓ㹤¾ß°ü¡£¸ÃÍÅ»ïÓÚ2022Ä꿪ʼÌṩËûÃǵÄAiTMµöÓ㹤¾ß°ü£¬½ñºó¶ÔÆä¹¤¾ß°ü½øÐÐÁ˶àÏî¸ïУ¬ÀýÈç´ÓÒÆ¶¯É豸¹ÜÀí»î¶¯µÄÄÜÁ¦£¬ÒÔ¼°CAPTCHAÒ³ÃæµÈÈÆ¹ý¹¦Ð§¡£Ñо¿ÈËÔ±³Æ£¬ËäÈ»AiTMµöÓãÊÔÍ¼ÈÆ¹ýMFA£¬µ«MFAÈÔÈ»ÊÇÉí·ÝÄþ¾²µÄÖØÒªÖ§Öù£¬¶øÇÒÔÚ×èÖ¹ÖÖÖÖÍþв·½Ãæ·Ç³£ÓÐЧ¡£
https://www.microsoft.com/en-us/security/blog/2023/03/13/dev-1101-enables-high-volume-aitm-campaigns-with-open-source-phishing-kit/
4¡¢ÂåÉ¼í¶ºâÓî¹ÜÀí¾ÖÅû¶LockBit¹¥»÷µ¼ÖµÄÊý¾Ýй¶Ê¼þ
¾Ý3ÔÂ13ÈÕ±¨µÀ£¬ÂåÉ¼í¶ºâÓî¹ÜÀí¾Ö£¨HACLA£©Åû¶ÁËLockBitÀÕË÷¹¥»÷µ¼ÖµÄÊý¾Ýй¶Ê¼þ¡£Æ¾¾Ý֪ͨ£¬2022Äê12ÔÂ31ÈÕ£¬HACLA·¢ÏÖÆäϵͳÒѱ»¼ÓÃÜ£¬ÆÈʹ¸Ã»ú¹¹µÄITÍŶӹرÕËùÓзþÎñÆ÷²¢Õ¹¿ªÊӲ졣ÊÓ²ìÓÚ2023Äê2ÔÂ13ÈÕÍê³É£¬ÏÔʾºÚ¿ÍÔÚ2022Äê1ÔÂ15ÈÕÖÁ12ÔÂ31ÈÕδ¾ÊÚȨ·ÃÎÊÁËϵͳ¡£LockBit 3.0ÍÅ»ïÉù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦£¬²¢ÍþвҪÔÚ2023Äê1ÔÂ27ÈÕÐû²¼ËùÓÐÎļþ¡£Õâ±íÃ÷̸ÅÐʧ°Ü£¬¸Ã»ú¹¹¾Ü¾øÁ˺ڿ͵ÄÒªÇó¡£Ä¿Ç°£¬LockBitÍøÕ¾ÉϵÄÏÂÔØÁ´½ÓÒÑʧЧ£¬ÕâÔÚÒ»¶¨Ë®Æ½ÉϼõÇáÁËÓ°Ïì¡£
https://www.bleepingcomputer.com/news/security/la-housing-authority-discloses-data-breach-after-ransomware-attack/
5¡¢Dark PinkÕë¶Ô¶«ÄÏÑǵÄ×éÖ¯·Ö·¢¶ñÒâÈí¼þKamiKakaBot
3ÔÂ10ÈÕ£¬EclecticIQ³ÆÆä·¢ÏÖÁ˶à¸ö¶ñÒâÈí¼þKamiKakaBotÑù±¾£¬±»Dark Pink£¨ÓÖÃûSaaiwc£©ÓÃÀ´¹¥»÷¶«ÄÏÑǹú¼ÒµÄÕþ¸®»ú¹¹¡£×î½üµÄ¹¥»÷·¢ÉúÔÚ2023Äê2Ô£¬Group-IBÓÚ1Ô·ÝÊ×´ÎÏêϸ½éÉÜÁ˸ÃÍÅ»ïµÄ»î¶¯£¬Á½´Î»î¶¯µÄÇø±ðÊǹ¥»÷Õ߸ïÐÂÁ˶ñÒâÈí¼þµÄ»ìÏý·¨Ê½ÒÔÖÆÖ¹±»·¢ÏÖ¡£KamiKakaBotͨ¹ý°üÂÞ¶ñÒâISOÎļþµÄµöÓãÓʼþ½øÐÐÁ÷´«£¬Ëü¿ÉÒÔÇÔÈ¡´æ´¢ÔÚä¯ÀÀÆ÷ÖеÄÊý¾Ý£¬»¹Ö§³Ö¸üлúÖÆ£¬¿ÉÒÔÔÚÄ¿±êÉ豸ÉÏÔ¶³ÌÖ´ÐдúÂë¡£
https://blog.eclecticiq.com/dark-pink-apt-group-strikes-government-entities-in-south-asian-countries
6¡¢Ñо¿ÈËÔ±·¢ÏÖAkuvox E11ÖÇÄܶԽ²»úÖеÄÊ®¶à¸ö©¶´
ýÌå3ÔÂ13ÈÕ±¨µÀ³Æ£¬ ClarotyÑо¿ÈËÔ±·¢ÏÖAkuvox E11ÖÇÄܶԽ²»úÖеÄÊ®¶à¸ö©¶´¡£ÕâЩ©¶´Éæ¼°Èõ¼ÓÃÜ¡¢Ê¹ÓÃÓ²±àÂëÃÜÔ¿¡¢Ãô¸ÐÐÅϢ̻¶¡¢²»Äþ¾²µÄÃÜÂë»Ö¸´»úÖÆºÍÃüÁî×¢Èë©¶´µÈ¡£Ñо¿ÈËÔ±³Æ£¬¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ©¶´Ô¶³ÌÖ´ÐдúÂ룬Զ³Ì¼¤»îÉ豸µÄÂó¿Ë·çºÍÉãÏñÍ·²¢½«Êý¾Ý´«Êäµ½Ô¶³Ì·þÎñÆ÷£¬²¢»ñÈ¡´æ´¢µÄͼÏñºÍÉ豸²¶×½µÄÊý¾Ý¡£AkuvoxÌåÏּƻ®Ðû²¼¹Ì¼þ¸üУ¬ÒÔÔÚ2023Äê3ÔÂ20ÈÕ֮ǰÐÞ¸´ÕâЩ©¶´¡£
https://thehackernews.com/2023/03/researchers-uncover-over-dozen-security.html