Dr.Web·¢ÏÖÀûÓÃWin10 ISOºÍEFI·ÖÇø·Ö·¢ClipperµÄ»î¶¯

Ðû²¼Ê±¼ä 2023-06-15

1¡¢Dr.Web·¢ÏÖÀûÓÃWin10 ISOºÍEFI·ÖÇø·Ö·¢ClipperµÄ»î¶¯


Dr.WebÔÚ6ÔÂ13ÈÕ³ÆÆäÔÚһЩµÁ°æWindows 10 ISOÖз¢ÏÖÁ˼ÓÃÜ»õ±Ò½Ù³Ö·¨Ê½£¬¹¥»÷Õßͨ¹ýTorrent tracker·Ö·¢ËüÃÇ¡£Õâ¸öľÂí±»³ÆÎªTrojan.Clipper.231£¬¿É½«¼ôÌù°åÖеļÓÃÜ»õ±ÒÇ®°üµØÖ·Ìæ»»³É¹¥»÷ÕߵĵØÖ·¡£½ØÖÁĿǰ£¬¹¥»÷ÕßÒÑÀÖ³ÉÇÔÈ¡Á˼ÛÖµÔ¼19000ÃÀÔªµÄ¼ÓÃÜ»õ±Ò¡£¸Ã»î¶¯»¹Ê¹ÓÃEFI£¨¿ÉÀ©Õ¹¹Ì¼þ½Ó¿Ú£©·ÖÇø×÷ΪClipper×é¼þµÄÄþ¾²´æ´¢¿Õ¼ä£¬Ö¼ÔÚÈÆ¹ý¶ñÒâÈí¼þ¼ì²â¡£Ñо¿ÈËÔ±½¨Òé²»ÒªÏÂÔØµÁ°æ²Ù×÷ϵͳ¡£


https://news.drweb.com/show/?i=14712&lng=en


2¡¢ÄÏ·Ç¿ª·¢ÒøÐÐ͸¶Æä·þÎñÆ÷ºÍÎļþµÈ±»AkiraÍÅ»ï¼ÓÃÜ


¾ÝýÌå6ÔÂ14ÈÕ±¨µÀ£¬ÄÏ·Ç¿ª·¢ÒøÐУ¨DBSA£©Ôâµ½ÁËAkiraÍÅ»ïµÄÀÕË÷¹¥»÷¡£Õâ¼Ò¹úÓÐÒøÐÐ͸¶£¬¹¥»÷ʼÓÚ5ÔÂ21ÈÕ×óÓÒ£¬Æä·þÎñÆ÷¡¢ÈÕÖ¾ÎļþºÍÎļþ±»¼ÓÃÜ¡£²¿ÃÅÐÅÏ¢¿ÉÄÜÒѱ»·Ç·¨·ÃÎÊ£¬Éæ¼°¶­Êº͹ɶ«µÄ¸öÈËÐÅÏ¢£¬ÓëDBSA´æÔÚÉÌÒµ»ò¹ÍÓ¶¹ØÏµµÄÏêϸÐÅÏ¢£¬ÒÔ¼°ÀûÒæÏà¹ØÕߵIJÆÕþÐÅÏ¢¡£Ä¿Ç°£¬¸ÃʼþÈÔÔÚÊÓ²ìÖУ¬DBSAÒѾ­Äܹ»»Ö¸´ÆäITϵͳ£¬²¢½«ÀÕË÷Èí¼þ×é¼þ´ÓÆäϵͳÖÐɾ³ý¡£


https://therecord.media/development-bank-of-southern-africa-akira-ransomware-attack


3¡¢MandiantÐû²¼UNC3886ÀûÓÃVMware ESXi©¶´µÄ¼¼Êõϸ½Ú


6ÔÂ13ÈÕ£¬MandiantÐû²¼Á˹ØÓÚUNC3886ÀûÓÃVMware ESXiÖÐÁãÈÕ©¶´µÄ¼¼Êõϸ½Ú¡£ÕâÊÇVMware ToolsµÄvgauthÄ£¿éÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¨CVE-2023-20867£©£¬ÒÑÓÚ6ÔÂ13ÈÕ±»ÐÞ¸´¡£´Ë´Î»î¶¯ÖУ¬¹¥»÷ÕßÀûÓÃÕâһ©¶´ÔÚÄ¿±êESXiÖ÷»úµÄguest VMÉϲ¿ÊðVirtualPitaºÍVirtualPieºóÃÅ£¬²¢½«È¨ÏÞÉý¼¶µ½root¡£Ñо¿ÈËÔ±»¹·¢ÏÖµÚÈýÖÖ¶ñÒâÈí¼þ±äÖÖ(VirtualGate)×÷Ϊһ¸ömemory-only dropper£¬¶Ô±»½Ù³ÖÐéÄâ»úÉϵĵڶþ½×¶ÎDLL payload½øÐÐÈ¥»ìÏý´¦Öá£


https://www.mandiant.com/resources/blog/vmware-esxi-zero-day-bypass


4¡¢SpotifyÒòÎ¥·´GDPR±»ÈðµäÕþ¸®·£¿î540ÍòÃÀÔª


¾Ý6ÔÂ14ÈÕ±¨µÀ£¬ÒôÀÖÁ÷ýÌ幫˾SpotifyÒòδÕýÈ·¼û¸æÓû§ÆäÊÕ¼¯µÄÊý¾ÝÊÇÈçºÎ±»Ê¹ÓõÄ£¬±»ÈðµäÒþ˽±£»¤¾Ö(IMY)·£¿î5800ÍòÈðµä¿ËÀÊ£¨Ô¼ºÏ540ÍòÃÀÔª£©¡£¸Ã¼à¹Ü»ú¹¹Ö¸³ö£¬Æ¾¾ÝGDPRµÄ¹æ¶¨£¬Óû§ÓÐȨÁ˽⹫˾ӵÓйØÓÚ¸öÈ˵ÄÄÄЩÊý¾ÝÒÔ¼°ÕâЩÊý¾ÝµÄʹÓ÷½Ê½¡£µ«ÓÉÓÚSpotifyÌṩµÄÐÅÏ¢Ò»Ö±²»Ã÷È·£¬¸öÈ˺ÜÄÑÁ˽âËûÃǵÄÊý¾ÝÊÇÈçºÎ±»´¦ÖõÄ£¬Ò²ºÜÄѼì²é´¦ÖÃÊÇ·ñºÏ·¨¡£IMY»¹³Æ£¬×ܵÄÀ´Ëµ£¬¸ÃÎÊÌâ±»ÈÏΪÊǽϵÍÑÏÖØÐԵġ£SpotifyÌåÏּƻ®¶Ô¸Ã¾ö¶¨Ìá³öÉÏËß¡£


https://www.securityweek.com/spotify-fined-5-million-for-breaching-eu-data-rules/


5¡¢Ñо¿ÈËÔ±¹ûÈ»WPÖ§¸¶²å¼þÖеÄ©¶´CVE-2023-34000


ýÌå6ÔÂ13Èճƣ¬Ñо¿ÈËÔ±Åû¶ÁËWordPressµÄWooCommerce Stripe Gateway²å¼þÖеÄ©¶´£¨CVE-2023-34000£©¡£ÕâÊǵçÉÌÍøÕ¾µÄÖ§¸¶Íø¹Ø²å¼þ£¬Ä¿Ç°ÓÐÁè¼Ý900000µÄ°²×°Á¿¡£¸Ã©¶´ÊÇδ¾­Éí·ÝÑéÖ¤µÄ²»Äþ¾²Ö±½Ó¹¤¾ßÒýÓÃ(IDOR)©¶´£¬»áÓ°Ïì7.4.0¼°ÒÔϰ汾£¬ÒÑÓÚ5ÔÂ30ÈÕ±»ÐÞ¸´¡£Â©¶´Ô´ÓÚ¶©µ¥¹¤¾ßµÄ²»Äþ¾²´¦ÖÃÒÔ¼°²å¼þµÄjavascript_paramsºÍpayment_fieldsº¯ÊýÖÐȱ·¦Êʵ±µÄ·ÃÎÊ¿ØÖÆ´ëÊ©£¬¿É±»¹¥»÷ÕßÓÃÀ´ÈƹýÊÚȨ²¢·ÃÎÊÃô¸ÐÐÅÏ¢¡£ 


https://patchstack.com/articles/unauthenticated-idor-to-pii-disclosure-vulnerability-in-woocommerce-stripe-gateway-plugin/


6¡¢BolsterÅû¶Õë¶ÔÉϰٸö·þ×°Æ·ÅÆµÄ´ó¹æÄ£µöÓã»î¶¯


6ÔÂ13ÈÕ£¬BolsterÅû¶Õë¶ÔÉϰٸö·þ×°Æ·ÅÆµÄ´ó¹æÄ£µöÓã»î¶¯£¬Ö¼ÔÚÇÔȡĿ±êµÄÕË»§Æ¾Ö¤ºÍ²ÆÕþÐÅÏ¢¡£¸Ã»î¶¯×Ô2022Äê6ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬ÔÚ2022Äê11ÔÂÖÁ2023Äê2Ôµ½´ï·åÖµ¡£µöÓãÍøÕ¾Ã°³äµÄÆ·ÅÆ°üÂÞÄͿˡ¢±ëÂí¡¢Íò˹¡¢°¢µÏ´ï˹¡¢¸çÂ×±ÈÑÇ¡¢ºÍ¿¨Î÷Å·µÈ£¬Bolster³ÆÒÑʶ±ð³ö3000¶à¸ö»îÔ¾µÄÓòÃû¡£Óë´Ë»î¶¯Ïà¹ØµÄÓòÃû±»×·Ëݵ½×ÔÖ÷ϵͳ±àºÅAS48950£¬ÓÉÁ½¸öÌØ¶¨µÄ»¥ÁªÍø·þÎñÌṩÉÌPacket Exchange LimitedºÍGlobal Colocation LimitedÍйܡ£


https://bolster.ai/blog/brand-impersonation-scam