Microsoft°ä²¼4Ô·ݰ²È«¸üУ¬£¬£¬£¬£¬£¬ £¬£¬×ܼƽ¨¸´97¸ö·ì϶

°ä²¼¹¦·ò 2023-04-12

1¡¢Microsoft°ä²¼4Ô·ݰ²È«¸üУ¬£¬£¬£¬£¬£¬ £¬£¬×ܼƽ¨¸´97¸ö·ì϶


4ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬ £¬£¬Î¢Èí°ä²¼ÁË2023Äê4Ô·ݵÄÖܶþ²¹¶¡£¬£¬£¬£¬£¬£¬ £¬£¬½¨¸´ÁËÔ̺¬Ò»¸ö±»ÀûÓÃ0 dayÔÚÄÚµÄ97¸ö·ì϶£¨²»Ô̺¬4ÔÂ6ÈÕ½¨¸´µÄ17¸öMicrosoft Edge·ì϶£©¡£¡£ ¡£¡£¡£Õâ´Î½¨¸´µÄÒѱ»ÀûÓ÷ì϶ΪWindowsͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯·¨Ê½ÌáȨ·ì϶£¨CVE-2023-28252£©£¬£¬£¬£¬£¬£¬ £¬£¬Kaspersky·¢Ïָ÷ì϶ÔÚNokoyawaÀÕË÷¹¥»÷Öб»ÀûÓᣡ£ ¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬ £¬£¬»¹½¨¸´Á˽ÏΪÑϳÁµÄMicrosoftÐÂÎŶÓÁÐRCE·ì϶£¨CVE-2023-21554£©¡¢DHCP·þÎñÆ÷·þÎñRCE·ì϶£¨CVE-2023-28231£©ºÍ¶þ²ãËí·ºÍ̸RCE·ì϶£¨CVE-2023-28219ºÍCVE-2023-28220£©µÈ¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2023-patch-tuesday-fixes-1-zero-day-97-flaws/


2¡¢°Ùʤ²ÍÒû¼¯ÍÅÔâµ½ÀÕË÷¹¥»÷Æä²¿ÃÅÔ±¹¤ÐÅϢй¶


¾ÝýÌå4ÔÂ10ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬ £¬£¬°Ùʤ²ÍÒû¼¯ÍÅ£¨Yum! Brands£©Í¨ÖªÔ±¹¤¹ØÓÚÀÕË÷¹¥»÷µ¼ÖµÄÐÅϢй¶ÊÂÎñ¡£¡£ ¡£¡£¡£°ÙʤÊǿϵ»ù¡¢±ØÊ¤¿ÍºÍTaco BellµÄĸ¹«Ë¾£¬£¬£¬£¬£¬£¬ £¬£¬ÊÇÈ«ÇòÃÅÊÐ×î¶àµÄ¿ì²Í¹«Ë¾¡£¡£ ¡£¡£¡£1ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬ £¬£¬ÆäÔâµ½ÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬ £¬£¬±»ÆÈ¹Ø¹ØÁËÓ¢¹úÔ¼300¼Ò²ÍÌü¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾Ð¹Â©£¬£¬£¬£¬£¬£¬ £¬£¬ÔÚȡ֤ºÍµ÷²é¹ý³ÌÖУ¬£¬£¬£¬£¬£¬ £¬£¬·¢ÏÖÁËһЩԱ¹¤µÄÓ×ÎÒÐÅÏ¢ÔÚ1Ô·ݵݲȫÊÂÎñÖÐй¶£¬£¬£¬£¬£¬£¬ £¬£¬Î´Åû¶ÊÜÓ°ÏìÔ±¹¤ÊýÁ¿¡£¡£ ¡£¡£¡£Ð¹Â¶Êý¾ÝÔ̺¬ÐÕÃû¡¢¼ÝÕÕºÅÂëºÍÉí·ÝÖ¤ºÅÂ룬£¬£¬£¬£¬£¬ £¬£¬¿Í»§Êý¾Ý²¢Î´ÊÜÓ°Ïì¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/kfc-pizza-hut-owner-discloses-data-breach-after-ransomware-attack/


3¡¢ÈýÐÇÔ±¹¤Ê¹ÓÃChatGPTµ¼Ö¹«Ë¾»áÒé¼Í¼ºÍÔ´´úÂëй¶   


ýÌå4ÔÂ10Èճƣ¬£¬£¬£¬£¬£¬ £¬£¬ÈýÐÇÔ±¹¤Ê¹ÓÃChatGPT£¬£¬£¬£¬£¬£¬ £¬£¬ÔÚ²»µ½Ò»¸öÔÂÄÚ²úÉúÈýÆðÊý¾Ýй¶ÊÂÎñ¡£¡£ ¡£¡£¡£ÈýÐǹ¤³ÌʦʹÓÃChatGPTÓÅ»¯²âÊÔÐòÁÐÒÔ¼ø±ðоƬÖеĹÊÕÏ£¬£¬£¬£¬£¬£¬ £¬£¬ÊäÈëÁËз¨Ê½µÄÔ´´úÂëÒÔ¼°ÓëÓ²¼þÓйصÄÄÚ²¿»áÒé¼Í¼µÈÊý¾Ý¡£¡£ ¡£¡£¡£ÔÚÁíÒ»¸ö°¸ÀýÖУ¬£¬£¬£¬£¬£¬ £¬£¬Ô±¹¤Ê¹ÓÃChatGPT½«»áÒé¼Í¼ת»»ÎªÑÝʾÎĸ壬£¬£¬£¬£¬£¬ £¬£¬ÆäÖÐÈ´Éæ¼°´óÁ¿ÈýÐDz»½öÔ¸¶Ô±íй©µÄÄÚÈÝ¡£¡£ ¡£¡£¡£µÚÈýÆðÊÂÎñÖУ¬£¬£¬£¬£¬£¬ £¬£¬Ô±¹¤½«³öÏÖÎÊÌâµÄ´úÂ븴Ôìµ½ChatGPTÒÔ½¨¸´ÃýÎ󡣡£ ¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔÈýÐÇÊÇ·ñÒÑÒªÇóɾ³ýÆäÔ±¹¤ÏòOpenAIÌṩµÄÊý¾Ý£¬£¬£¬£¬£¬£¬ £¬£¬µ«Õâ¼ÒIT¹«Ë¾ÒѾö¶¨¿ª·¢×Ô¼ºµÄAI¹©ÄÚ²¿Ê¹Óᣡ£ ¡£¡£¡£


https://securityaffairs.com/144597/security/samsung-data-leak-chatgpt.html


4¡¢Vimeo½«Ö§¸¶225ÍòÃÀÔªÒԺͽâAIÓйØÉúÎï¼ø±ðÒþÖÔËßËÏ


¾Ý4ÔÂ10ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬ £¬£¬VimeoÔÞ³ÉÏòÆäÊÓÆµ´´×÷ºÍ±à×ëÆ½Ì¨MagistoµÄ²¿ÃÅÓû§Ö§¸¶225ÍòÃÀÔª£¬£¬£¬£¬£¬£¬ £¬£¬ÒÔºÍ½â¹ØÓÚÉúÎï¼ø±ðÒþÖÔµÄËßËÏ¡£¡£ ¡£¡£¡£¼¯ÌåËßËÏÖ¸¿ØVimeoÔÚ2014Äê9ÔÂ20ÈÕÖÁ2023Äê1ÔÂ20ÈÕδ¾­Êʵ±Í¨ÖªºÍÔ޳ɾÍÇÔÈ¡ÁËËûÃǵÄÉúÎï¼ø±ðÐÅÏ¢£¬£¬£¬£¬£¬£¬ £¬£¬Î¥·´ÁËÒÁÀûŵÒÁÖݵÄÉúÎïÌØµãÐÅÏ¢ÒþÖÔ·¨(BIPA)¡£¡£ ¡£¡£¡£ËßËϳÆ£¬£¬£¬£¬£¬£¬ £¬£¬¸ÃÀûÓÃÍøÂçºÍ´æ´¢¾ßÌåµÄÃæ²¿Í¼Æ¬£¬£¬£¬£¬£¬£¬ £¬£¬Ê¹ÓÃAIÒýÇæ·ÖÎöÉÏ´«µ½Æ½Ì¨µÄÊÓÆµ£¬£¬£¬£¬£¬£¬ £¬£¬Ô̺¬¼ì²âÈËÁ³£¬£¬£¬£¬£¬£¬ £¬£¬¶øVimeo±»Ö¸¿Ø´´½¨¡¢ÍøÂçºÍ´æ´¢Óû§µÄÃæ²¿Ä£°å¡£¡£ ¡£¡£¡£


https://www.scmagazine.com/news/identity-and-access/vimeo-ai-biometric-privacy-lawsuit


5¡¢Kaspersky°ä²¼°µÍøÉϵÄGoogle PlayÍþвµÄ¸ÅÊö


4ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬ £¬£¬Kaspersky¸ÅÊöÁ˰µÍøÉÏÏúÊ۵Ľ«Android¶ñÒâÈí¼þÔö³¤µ½Google PlayµÄ·þÎñ¡£¡£ ¡£¡£¡£°µÍøÉÏÌṩµÄ¶ñÒâ·þÎñÀàÐÍÔ̺¬Google Play¼ÓÔØ·¨Ê½¡¢°ó¸¿·þÎñ¡¢¶ñÒâÈí¼þ»ìºÏ·þÎñºÍ×°Ö÷þÎñµÈ¡£¡£ ¡£¡£¡£ÏòGoogle PlayÌṩ¶ñÒâÀûÓõļÓÔØ·¨Ê½µÄ¼ÛÖµÔÚ2000ÖÁ20000ÃÀÔªÖ®¼ä¡£¡£ ¡£¡£¡£¶ñÒâÈí¼þͨ³£°µ²ØÔÚɱ¶¾Èí¼þ¡¢¼ÓÃÜÇ®±Ò×ʲúÖÎÀíÆ÷¡¢¶þάÂëɨÃèÆ÷¡¢Ó×ÓÎÏ·ºÍÔ¼»áÀûÓÃÖС£¡£ ¡£¡£¡£×êÑÐÈËÔ±½¨Ò飬£¬£¬£¬£¬£¬ £¬£¬AndroidÓû§Ó¦ÔÚ×°ÖÃÀûÓÃʱ×Ðϸ²é³­ÒªÇóµÄȨÏÞ£¬£¬£¬£¬£¬£¬ £¬£¬ÇÐÎð´ÓµÚÈý·½ÍøÕ¾×°ÖÃAndroid APK¡£¡£ ¡£¡£¡£


https://securelist.com/google-play-threats-on-the-dark-web/109452/


6¡¢Jfrog°ä²¼¹ØÓÚ¶ñÒâÈí¼þImpala StealerµÄ·ÖÎö»ã±¨


JfrogÔÚ4ÔÂ10ÈÕ°ä²¼Á˹ØÓÚImpala StealerµÄ·ÖÎö»ã±¨¡£¡£ ¡£¡£¡£ÕâÊÇÒ»ÖÖ×Ô½ç˵¼ÓÃÜÇÔÈ¡·¨Ê½£¬£¬£¬£¬£¬£¬ £¬£¬×÷ΪNuGet¶ñÒâ°ü»î¶¯µÄpayload¡£¡£ ¡£¡£¡£Õâ¸ö¸´ÔӵĹ¥»÷»î¶¯Ê¹ÓÃÓòÃû·Âð¼¼Êõ´«²¼ÁË13¸ö¶ñÒâ°ü£¬£¬£¬£¬£¬£¬ £¬£¬ÖØÒªÕë¶Ô.NET¿ª·¢ÈËÔ±¡£¡£ ¡£¡£¡£Impala StealerµÄÖØÒªpayloadÊÇÒ»¸ö¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬£¬ £¬£¬ËƺõÊÇʹÓÃ.NET Ahead of Time£¨AoT£©±àÒëµÄ±¾µØ.NETÀûÓ÷¨Ê½¡£¡£ ¡£¡£¡£ËüÓµÓÐ×°ÖúÍ×Ô¶¯¸üлúÔì¡¢¿Éͨ¹ý´úÂë×¢ÈëʵÏÖÓÆ¾Ã»¯²¢¿ÉÄÜ´ÓExodusÇ®°üÖÐÇÔÈ¡×ʽ𡣡£ ¡£¡£¡£


https://jfrog.com/blog/impala-stealer-malicious-nuget-package-payload/