Pilot Credentials±»ºÚй¶ÃÀ¹úº½¿ÕºÍÎ÷ÄϺ½¿Õ²¿ÃÅÐÅÏ¢

Ðû²¼Ê±¼ä 2023-06-25

1¡¢Pilot Credentials±»ºÚй¶ÃÀ¹úº½¿ÕºÍÎ÷ÄϺ½¿Õ²¿ÃÅÐÅÏ¢


¾ÝýÌå6ÔÂ24ÈÕ±¨µÀ £¬È«Çò×î´óµÄÁ½¼Òº½¿Õ¹«Ë¾ÃÀ¹úº½¿ÕºÍÎ÷ÄϺ½¿ÕÅû¶ÁËÒòPilot CredentialsÔâµ½ºÚ¿Í¹¥»÷¶øµ¼ÖµÄÊý¾Ýй¶Ê¼þ¡£Pilot CredentialsÊǹÜÀí¶à¼Òº½¿Õ¹«Ë¾·ÉÐÐÔ±ÉêÇëºÍÕÐÆ¸ÍøÕ¾µÄµÚÈý·½¹©Ó¦ÉÌ¡£¹¥»÷ÕßÓÚ4ÔÂ30ÈÕ·ÃÎÊÁË·ÉÐÐÔ±Ö¤Êéϵͳ £¬²¢ÇÔÈ¡Á˲¿ÃÅÉêÇëÈËÔÚ·ÉÐÐÔ±ºÍѧԱÕÐÆ¸¹ý³ÌÖÐÌṩµÄÐÅÏ¢¡£ÃÀ¹úº½¿ÕµÄ5745Ãû·ÉÐÐÔ±Êܵ½Ó°Ïì £¬¶øÎ÷ÄϺ½¿Õ×ܹ²ÓÐ3009Ãû·ÉÐÐÔ±Êܵ½Ó°Ïì¡£Á½¼Ò¹«Ë¾¾ùÓÚ5ÔÂ3ÈÕ»ñϤ´Ëʼþ £¬²¢ÌåÏÖ½öÉæ¼°µÚÈý·½¹©Ó¦É̵Äϵͳ £¬²¢Î´Ó°Ï캽¿Õ¹«Ë¾×Ô¼ºµÄϵͳ¡£


https://www.bleepingcomputer.com/news/security/american-airlines-southwest-airlines-disclose-data-breaches-affecting-pilots/


2¡¢PBIÊý¾ÝÐ¹Â¶Éæ¼°GenworthºÍCalPERSÊý°ÙÍò¿Í»§µÄÐÅÏ¢


¾Ý6ÔÂ23ÈÕ±¨µÀ £¬PBIÑо¿·þÎñ(PBI)Êý¾Ýй¶ £¬Ó°ÏìÁËÆäÈý¸öºÏ×÷¹«Ë¾µÄÔ¼475Íò¿Í»§¡£ÕâЩ¹¥»÷ʼÓÚ5ÔÂ27ÈÕ £¬ÆäʱClopÍŻ↑ʼÀûÓÃMOVEit Transfer©¶´ÇÔÈ¡×éÖ¯µÄÊý¾Ý¡£µÚÒ»¼ÒÊÜÓ°Ïì×éÖ¯ÊÇλÓÚ¸¥¼ªÄáÑÇÖݵÄÈËÊÙ±£ÏÕ·þÎñÌṩÉÌGenworth Financial £¬¾ÝÔ¤¼ÆÓ°ÏìÁË250ÖÁ270ÍòÈË¡£µÚ¶þ¼ÒÊܵ½PBIй¶ӰÏìµÄÊÇλÓÚŦԼµÄ±£ÏÕÌṩÉÌWilton Reassurance £¬Éæ¼°1482490Ãû¿Í»§¡£Êܵ½Ó°ÏìµÄµÚÈý¼Ò¹«Ë¾ÊÇÃÀ¹ú×î´óµÄ¹«¹²ÑøÀÏ»ù½ðCalPERS£¨¼ÓÖݹ«¹²¹ÍÔ±ÍËÐÝϵͳ£© £¬Ó°ÏìÁËÔ¼769000Ãû»áÔ±¡£


https://www.bleepingcomputer.com/news/security/moveit-breach-impacts-genworth-calpers-as-data-for-32-million-exposed/


3¡¢Î¢Èí¼ì²âµ½Ä¾Âí»¯OpenSSHÕë¶ÔLinuxºÍIoTÉ豸µÄ»î¶¯


6ÔÂ22ÈÕ £¬Î¢ÈíÐû²¼³ÂËß³ÆÆä×î½ü·¢ÏÖÁËÒ»ÖÖÀûÓÃ×Ô½ç˵ºÍ¿ªÔ´¹¤¾ßÀ´Õë¶Ô̻¶ÓÚ»¥ÁªÍøµÄLinuxϵͳºÍIoTÉ豸µÄ¹¥»÷¡£¸Ã¹¥»÷ʹÓÃÁËľÂí»¯OpenSSHÀ´¿ØÖƱ»Ñ¬È¾µÄÉ豸 £¬²¢°²×°ÁËÍÚ¿ó¶ñÒâÈí¼þ¡£¹¥»÷ÕßÔÚ»ñµÃ·ÃÎÊȨÏÞºó £¬»á°²×°Ä¾ÂíOpenSSHÈí¼þ°ü £¬Ö¼ÔÚÔÚÄ¿±êÉ豸Öа²×°ºóÃŲ¢ÇÔÈ¡SSHƾ¾ÝÒÔά³Ö³Ö¾ÃÐÔ¡£¸ÃºóÃÅÓÖ°²×°ÁËÖÖÖÖ¹¤¾ßºÍ×é¼þ £¬ÀýÈçRootkitºÍIRC botÀ´½Ù³ÖÉ豸×ÊÔ´ÒÔ½øÐÐÍÚ¿ó»î¶¯¡£


https://www.microsoft.com/en-us/security/blog/2023/06/22/iot-devices-and-linux-based-systems-targeted-by-openssh-trojan-campaign/


4¡¢VMwareÐÞ¸´ÆävCenter ServerÖеĶà¸öÄþ¾²Â©¶´


ýÌå6ÔÂ23ÈÕ³Æ £¬VMwareÐû²¼¸üР£¬ÐÞ¸´ÁËvCenter ServerÖеÄ5¸öÄþ¾²Â©¶´¡£ÕâЩ©¶´´æÔÚÓÚDCE/RPCЭÒéµÄʵÏÖÖС£´Ë´ÎÐÞ¸´µÄ©¶´°üÂÞ¶ÑÒç³ö©¶´(CVE-2023-20892)¡¢ÊͷźóʹÓé¶´(CVE-2023-20893)¡¢Ô½½çдÈë©¶´£¨CVE-2023-20894£©ÒÔ¼°Ô½½ç¶Áȡ©¶´(CVE-2023-20895ºÍCVE-2023-20896)¡£ÆäÖÐ £¬Ç°Á½¸ö©¶´£¨CVE-2023-20892ºÍCVE-2023-20893£©¿É±»Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÀûÓà £¬À´»ñÈ¡´úÂëÖ´ÐÐȨÏÞ¡£


https://securityaffairs.com/147774/hacking/vmware-vcenter-server-memory-corruption-bugs.html


5¡¢Camaro DragonÀûÓÃUSBÇý¶¯Æ÷¹¥»÷Å·ÖÞµÄÒ½ÁÆ»ú¹¹


Check PointÔÚ6ÔÂ22ÈÕÅû¶ÁËCamaro DragonÀûÓÃUSBÇý¶¯Æ÷·Ö·¢¶ñÒâÈí¼þµÄ»î¶¯¡£¸Ã»î¶¯ÊÇÔÚ¶ÔÅ·ÖÞÒ»¼ÒÒ½ÁÆ»ú¹¹Ôâµ½µÄ¹¥»÷½øÐÐÊÓ²ìµÄ¹ý³ÌÖз¢Ïֵġ£¾ÝϤ £¬Ä³Ô±¹¤ÔÚÑÇÖÞµÄÒ»´Î»áÒéÖн«×Ô¼ºµÄUSB²åÈëͬʵļÆËã»úʱ±»Ñ¬È¾¡£¸ÃÔ±¹¤·µ»ØÅ·ÖÞµÄÒ½ÁÆ»ú¹¹ºó £¬ÎÞÒâÖÐͨ¹ý´ËUSBѬȾÁËÒ½ÔºµÄϵͳ¡£Ñ¬È¾Á´°üÂÞÒ»¸öÃûΪHopperTickµÄDelphi launcher £¬Í¨¹ýUSBÁ÷´« £¬ÆäÖ÷ÒªpayloadÃûΪWispRider £¬ÂôÁ¦ÔÚÁ¬½Óµ½»úÆ÷ʱѬȾÉ豸¡£WispRiderµÄ²¿ÃűäÌ廹¿ÉÒԳ䵱ºóÃŲ¢Èƹýɱ¶¾Èí¼þ £¬ÓëÆäÒ»ÆðÌṩµÄ»¹ÓÐÒ»¸öÇÔÈ¡Ä £¿éHPCustPartUI.dll¡£


https://research.checkpoint.com/2023/beyond-the-horizon-traveling-the-world-on-camaro-dragons-usb-flash-drives/


6¡¢AppleÐÞ¸´ÔÚTriangulation»î¶¯Öб»ÀûÓõĶà¸ö©¶´


6ÔÂ22ÈÕ±¨µÀ³Æ £¬AppleÐÞ¸´ÁËiOS¡¢iPadOS¡¢macOS¡¢watchOSºÍSafariÖеĶà¸ö©¶´¡£ÆäÖаüÂÞ×Ô2019ÄêÒÔÀ´Ò»Ö±»îÔ¾µÄTriangulation»î¶¯Öб»ÀûÓõÄÁ½¸ö©¶´ £¬ÄÚºËÖеÄÕûÊýÒç³ö©¶´£¨CVE-2023-32434 £©ºÍWebKitÖеÄÄÚ´æËð»µÂ©¶´£¨WebKit ÖеÄÄÚ´æËð»µÂ©¶´£©¡£AppleÌåÏÖÕâÁ½¸ö©¶´¿ÉÄÜÒѱ»ÓÃÓÚ¹¥»÷iOS 15.7֮ǰµÄiOS°æ±¾¡£´Ë´Î»¹ÐÞ¸´Á˵ÚÈý¸öÁãÈÕ©¶´£¨CVE-2023-32439£© £¬¸Ã©¶´ÔÚ´¦ÖöñÒâWebÄÚÈÝʱ¿ÉÄܵ¼ÖÂÈÎÒâ´úÂëÖ´ÐС£


https://thehackernews.com/2023/06/zero-day-alert-apple-releases-patches.html