·¨À­ÀûÔâµ½ÀÕË÷¹¥»÷µ¼Ö²¿Ãſͻ§µÄÏêϸÐÅϢй¶

Ðû²¼Ê±¼ä 2023-03-22

1¡¢·¨À­ÀûÔâµ½ÀÕË÷¹¥»÷µ¼Ö²¿Ãſͻ§µÄÏêϸÐÅϢй¶


¾ÝýÌå3ÔÂ20ÈÕ±¨µÀ£¬Òâ´óÀûÅܳµÖÆÔìÉÌ·¨À­ÀûÔâµ½ÀÕË÷¹¥»÷¡£¸Ã¹«Ë¾³Æ¹¥»÷Õß»ñµÃÁËÆä²¿ÃÅITϵͳµÄ·ÃÎÊȨÏÞ£¬¿Í»§ÐÕÃû¡¢µØÖ·ºÍµç»°ºÅÂëµÈÐÅϢй¶¡£·¨À­ÀûÌåÏÖÒѽÓÄÉ´ëÊ©±£»¤ÊÜÓ°Ïìϵͳ£¬ÇҴ˴ι¥»÷¶Ô¹«Ë¾µÄÔËӪûÓÐÓ°Ïì¡£¸Ã¹«Ë¾Ã»ÓÐ˵Ã÷¹¥»÷·¢ÉúµÄʱ¼ä£¬µ«Õâ¿ÉÄÜÓë2022Äê10Ô±¨µÀµÄÀÕË÷¹¥»÷ÓйØ£¬ÆäʱRansomEXXÉù³ÆÇÔÈ¡ÁË·¨À­ÀûµÄ7 GBÊý¾Ý¡£¾ÝÏûÏ¢ÈËÊ¿³Æ£¬×î³õµÄÊê½ðÒªÇóÊÇ100ÍòÃÀÔª¡£·¨À­ÀûÔÚ3ÔÂ20ÈÕµÄÉùÃ÷ÖÐÌåÏÖ£¬²»»á¸¶Êê½ð¡£


https://www.securityweek.com/ferrari-says-ransomware-attack-exposed-customer-data/


2¡¢Ñо¿ÈËÔ±·¢ÏÖWin 11½ØÍ¼¹¤¾ßÒ²ÊÜAcropalypse©¶´Ó°Ïì


3ÔÂ21ÈÕ±¨µÀ³Æ£¬Ñо¿ÈËÔ±·¢ÏÖWindows 11½ØÍ¼¹¤¾ßÒ²ÊÜAcropalypseÄþ¾²Â©¶´µÄÓ°Ïì¡£ÉÏÖÜ£¬Ñо¿ÈËÔ±ÔÚGoogle Pixel±êÖ¾¹¤¾ßÖз¢Ïָé¶´£¬µ¼ÖÂԭʼͼÏñÊý¾Ý¼´Ê¹±»±à¼­»ò²Ã¼ôÒ²Äܱ£ÁôÏÂÀ´¡£Windows 11½ØÍ¼¹¤¾ßÓòüôºóµÄ°æ±¾ÁýÕÖԭʼͼÏñʱ£¬·¨Ê½Ã»ÓÐÕýÈ·½Ø¶ÏδʹÓõÄÊý¾Ý£¬¶øÊDZ£ÁôÔÚIENDÊý¾Ý¿éÖ®ºó¡£ÔÚͼÏñ¼ì²ìÆ÷Öдò¿ªÎļþÖ»»áÏÔʾ²Ã¼ôºóµÄͼÏñ£¬µ«ÊÇδ½Ø¶ÏµÄÊý¾Ý¿ÉÓÃÓÚÖØ½¨Ô­Ê¼Í¼Ïñ£¬´Ó¶ø¿ÉÄܵ¼ÖÂÃô¸ÐÊý¾Ýй¶¡£


https://www.bleepingcomputer.com/news/microsoft/windows-11-snipping-tool-privacy-bug-exposes-cropped-image-content/


3¡¢Ñо¿ÍŶÓÏêÊöÀÕË÷Èí¼þCatBÀûÓÃMSDTC·þÎñµÄÈÆ¹ý¼ÆÄ±


¾Ý3ÔÂ20ÈÕ±¨µÀ£¬Ñо¿ÍŶÓÏêÊöÁËÀÕË÷Èí¼þCatBµÄÈÆ¹ý¼ÆÄ±¡¢¼ÓÃÜÐÐΪÒÔ¼°ÇÔȡƾ¾ÝºÍä¯ÀÀÆ÷Êý¾ÝµÄʵÑé¡£CatB£¨Ò²³ÆCatB99ºÍBaxtoy£©ÓÚ2022Äêµ×Ê״α»·¢ÏÖ£¬Ëü¿ÉÄÜÊÇÀÕË÷Èí¼þPandoraµÄÑݱä»òÖ±½Ó¸üÃû£¬ºóÕßÖ÷ÒªÕë¶ÔÆû³µÐÐÒµ¡£CatBµÄÖ÷ÒªÌØÕ÷ÊÇͨ¹ýMicrosoftÂþÑÜʽÊÂÎñ´¦ÖÃЭµ÷Æ÷(MSDTC)µÄºÏ·¨·þÎñ½Ù³ÖDLL£¬À´ÌáÈ¡ºÍÆô¶¯ÀÕË÷Èí¼þpayload¡£³ýÁËÎļþ¼ÓÃܺͻìÏýÖ®Í⣬CatB»¹»áʵÑé´ÓÄ¿±êϵͳÊÕ¼¯Ìض¨µÄÐÅÏ¢¡£


https://thehackernews.com/2023/03/researchers-shed-light-on-catb.html


4¡¢°Ä´óÀûÑÇ˰Îñ¾ÖʹÓõÄÓïÒôʶ±ðϵͳ¿É±»AIºÏ³ÉÉùÒôÈÆ¹ý


¾ÝÎÀ±¨3ÔÂ16ÈÕ±¨µÀ£¬CentrelinkºÍ°Ä´óÀûÑÇ˰Îñ¾Ö(ATO)ʹÓõÄÓïÒôʶ±ðϵͳ´æÔÚ©¶´¡£¼Ì±¨µÀ³Æ¾­¹ýѵÁ·µÄAIºÏ³ÉÉùÒô¿ÉÓÃÓÚ·ÃÎʺ£Íâµç»°ÒøÐзþÎñºó£¬Ñо¿ÈËÔ±·¢ÏÖÉùÎÆÏµÍ³Ò²¿ÉÒÔ±»AIÉùÒôËùÆÛÆ­¡£Ò»ÃûÎÀ±¨µÄ¼ÇÕß½öÓÃËÄ·ÖÖÓµÄÒôƵ£¬¾ÍÉú³ÉÒ»¸ö×Ô¼ºµÄ¿Ë¡ÉùÒô£¬È»ºó¾ÍÄÜÓÃÕâ¸öÉùÒô½áºÏ×Ô¼ºµÄ¿Í»§²Î¿¼ºÅÂ룬½øÈëÁËCentrelink×ÔÖú·þÎñÕË»§¡£ATOµÄ·¢ÑÔÈËÌåÏÖ£¬¸Ã»ú¹¹ÒѽÓÄÉ´ëÊ©À´±£»¤ÏµÍ³ÃâÊÜAIÓïÒô¿Ë¡֮ÀàµÄÍþв¡£


https://www.theguardian.com/technology/2023/mar/16/voice-system-used-to-verify-identity-by-centrelink-can-be-fooled-by-ai


5¡¢MandiantÐû²¼¹ØÓÚ2022ÄêÁãÈÕ©¶´¹¥»÷µÄ·ÖÎö³ÂËß


3ÔÂ20ÈÕ£¬MandiantÐû²¼Á˹ØÓÚ2022ÄêÁãÈÕ©¶´¹¥»÷µÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬2022ÄêÓÐ55¸öÁãÈÕ©¶´±»ÀûÓã¬Õâ¸öÊý×ÖµÍÓÚ2021ÄêµÄ81¸ö¡£ÓëÍùÄêÒ»Ö£¬´ó²¿ÃÅ©¶´À´×ÔMicrosoft¡¢GoogleºÍApple²úÎ±»ÀûÓÃ×î¶àµÄ²úÎïÀàÐÍÊDzÙ×÷ϵͳ£¨19¸ö£©£¬Æä´ÎÊÇä¯ÀÀÆ÷£¨11¸ö£©ÒÔ¼°Äþ¾²¡¢ITºÍÍøÂç¹ÜÀí²úÎ10£©¡£ÕâЩ©¶´ÖеĴó¶àÊý£¨55ÆäÖеÄ53¸ö£©Äܱ»ÓÃÓÚÔÚÄ¿±êÉ豸ÉÏÌáÉýȨÏÞ»òÔ¶³ÌÖ´ÐдúÂë¡£


https://www.mandiant.com/resources/blog/zero-days-exploited-2022


6¡¢JumpsecÐû²¼2022ÄêÓ¢¹úÀÕË÷¹¥»÷Ì¬ÊÆµÄ·ÖÎö³ÂËß


ýÌå3ÔÂ20Èճƣ¬JumpsecÐû²¼ÁË2022ÄêÓ¢¹úÀÕË÷¹¥»÷Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£Óë2021ÄêÏà±È£¬2022ÄêÓ¢¹ú³ÂËߵĹ¥»÷×ÜÊýÔö¼ÓÁË17%¡£Ð·ºÆðµÄSpring4Shell¡¢FollinaºÍProxyNotShellµÈ©¶´¿ÉÄÜ»áÔö¼ÓÀÕË÷ÍÅ»ï¶Ô×éÖ¯µÄ¹¥»÷¡£Ëæ×ÅContiºÍREvilµÄ½âÌå£¬ÐµĹ¥»÷ÕßÔÚÀÕË÷Èí¼þÁìÓò±äµÃÔ½·¢Í»³ö¡£Lockbit¼Ì³ÐÁËContiµÄÍ·ÏΣ¬³ÉΪȫÇò×î³£¼ûµÄÀÕË÷Èí¼þ£¬Õ¼¹¥»÷µÄ52%¡£Êý¾Ý±íÃ÷£¬½ÌÓý¡¢Ö´·¨ÒÔ¼°ÁãÊÛºÍÅú·¢Ã³Ò×ÐÐÒµÔâµ½µÄ¹¥»÷×î¶à¡£


https://www.jumpsec.com/uk-ransomware-trends-lessons-for-2023/