Google´¹Î£¸üн¨¸´½ñÄêµÚ¶þ¸öÒѱ»ÀûÓõÄChrome·ì϶

°ä²¼¹¦·ò 2023-04-20

1¡¢Google´¹Î£¸üн¨¸´½ñÄêµÚ¶þ¸öÒѱ»ÀûÓõÄChrome·ì϶


4ÔÂ18ÈÕ£¬£¬£¬£¬£¬Google°ä²¼Chrome´¹Î£¸üУ¬£¬£¬£¬£¬½¨¸´ÁË2023ÄêµÚ¶þ¸öÒѱ»ÀûÓ÷ì϶¡£¡£¡£¡£¡£ÕâÊÇ¿ªÔ´2DͼÐοâSkiaÖеÄÕûÊýÒç¶Âí½Å£¨CVE-2023-2136£©£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶£¬£¬£¬£¬£¬Í¨¹ý¶ñÒâµÄHTMLÒ³ÃæÖ´ÐÐɳÏäÌÓÒÝ¡£¡£¡£¡£¡£GoogleÉÐδ°ä²¼¹ØÓڸ÷ì϶µÄϸ½Ú¡£¡£¡£¡£¡£Õâ´Î¸üл¹½¨¸´ÁËService Worker APIÖеÄÄÚ´æÔ½½ç½Ó¼û·ì϶£¨CVE-2023-2133ºÍCVE-2023-2134£©ÒÔ¼°DevToolsÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2023-2135£©µÈ¡£¡£¡£¡£¡£ÉÏÖÜ£¬£¬£¬£¬£¬Google½¨¸´ÁË2023ÄêµÚÒ»¸ö±»ÀûÓõÄChrome·ì϶£¨CVE-2023-2033£©¡£¡£¡£¡£¡£


https://securityaffairs.com/145019/security/google-second-chrome-zero-day-2023.html


2¡¢APT28ÀûÓÃCisco·ÓÉÆ÷Öеķì϶װÖÃJaguar Tooth


¾ÝýÌå4ÔÂ18ÈÕ±¨Â·£¬£¬£¬£¬£¬Ó¢ÃÀµ±¾Ö°ä²¼½áºÏÕ÷ѯ£¬£¬£¬£¬£¬¾ßÌå½éÉÜÁËAPT28ÈôºÎÀûÓÃCisco IOS·ÓÉÆ÷Éϵķì϶װÖÃ×Ô½ç˵¶ñÒâÈí¼þJaguar Tooth¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÖØÒªÕë¶ÔÔËÐй̼þC5350-ISM°æ±¾12.3(6)µÄCisco IOS·ÓÉÆ÷¡£¡£¡£¡£¡£Ëü¿ÉÍøÂçÉ豸ÐÅÏ¢£¬£¬£¬£¬£¬¶øºóͨ¹ýTFTP´«ÊäÕâЩÐÅÏ¢£¬£¬£¬£¬£¬²¢ÆôÓÃδ¾­Éí·ÝÑéÖ¤µÄºóÃŽӼû¡£¡£¡£¡£¡£¾Ý¹Û²ì£¬£¬£¬£¬£¬ËüÊÇÀûÓÃÒѽ¨¸´µÄSNMP·ì϶£¨CVE-2017-6742£©½øÐÐ×°ÖúÍÖ´Ðеġ£¡£¡£¡£¡£×êÑÐÈËÔ±½¨ÒéÖÎÀíÔ±½«Â·ÓÉÆ÷Éý¼¶µ½×îеĹ̼þ°æ±¾ÒÔµÍÓÚ´ËÀ๥»÷¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/us-uk-warn-of-govt-hackers-using-custom-malware-on-cisco-routers/


3¡¢Î¢Èí·¢ÏÖMint Sandstorm¹¥»÷ÃÀ¹úµÄ¹Ø¼ü»ù´¡ÉèÊ©


4ÔÂ18ÈÕ£¬£¬£¬£¬£¬Î¢Èí³ÆÆä·¢ÏÖÁËMint SandstormµÄÒ»¸ö×Ó×éÕë¶ÔÃÀ¹úµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£´Ó2021Ëêĺµ½2022ÄêÖУ¬£¬£¬£¬£¬¸ÃÍÅ»ï´Ó¿úËÅתÏòÖ±½Ó¹¥»÷ÃÀ¹úµÄ¹Ø¼ü»ù´¡ÉèÊ©£¬£¬£¬£¬£¬Ô̺¬º£¸Û¡¢ÄÜÔ´¹«Ë¾¡¢ÔËÊäϵͳ¡¢¹«ÓÃÊÂÒµºÍÌìÈ»Æø×éÖ¯µÈ¡£¡£¡£¡£¡£Ëüͨ³£Ê¹Óù«¿ªÅû¶µÄPoC£¬£¬£¬£¬£¬Ò²»áʹÓþɷì϶£¨ÀýÈçLog4Shell£©À´¹¥»÷δ´ò²¹¶¡µÄÉ豸¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬Í¨¹ýImpacket¿ò¼ÜºáÏò´«²¼£¬£¬£¬£¬£¬²¢Ö´ÐÐÁ½Ìõ¹¥»÷Á´Ö®Ò»¡£¡£¡£¡£¡£µÚÒ»Ìõ»áÇÔÈ¡Windows Active DirectoryÊý¾Ý¿â£¬£¬£¬£¬£¬µÚ¶þÌõ×°ÖÃÃûΪDrokbkºÍSoldierµÄ×Ô½ç˵ºóÃÅ¡£¡£¡£¡£¡£


https://www.microsoft.com/en-us/security/blog/2023/04/18/nation-state-threat-actor-mint-sandstorm-refines-tradecraft-to-attack-high-value-targets/


4¡¢Group-IBÅû¶MuddyWaterÀûÓÃSimpleHelpµÄ»î¶¯ 


Group-IBÔÚ4ÔÂ18ÈÕÅû¶ÁËMuddyWaterʹÓúϷ¨µÄÔ¶³ÌÉ豸½ÚÔìºÍÖÎÀí¹¤¾ßSimpleHelpά³ÖÓÆ¾ÃÐÔ¡£¡£¡£¡£¡£SimpleHelp²¢Ã»Óб»¹¥»÷£¬£¬£¬£¬£¬Ïà·´£¬£¬£¬£¬£¬¹¥»÷ÕßÕÒµ½ÁË´Ó¹ÙÍøÏÂÔØ¸Ã¹¤¾ß²¢ÔÚ¹¥»÷ÖÐʹÓÃËüµÄ²½Öè¡£¡£¡£¡£¡£¸ÃÍÅ»ïÓÚ2022Äê6ÔÂ30ÈÕ³õ´ÎʹÓÃSimpleHelp£¬£¬£¬£¬£¬½ØÖÁĿǰ£¬£¬£¬£¬£¬¸Ã×éÖ¯ÖÁÉÙÓаĘ̈·þÎñÆ÷×°ÖÃÁËSimpleHelp¡£¡£¡£¡£¡£×°ÖÃÔÚÖ¸±êÉ豸ÉϵÄSimpleHelp¿Í»§¶ËÄܹ»×÷Ϊϵͳ·þÎñ³ÖÐøÔËÐУ¬£¬£¬£¬£¬Òò¶ø¹¥»÷Õß¿ÉÄÜËæÊ±½Ó¼ûÓû§µÄÉ豸£¬£¬£¬£¬£¬Ô̺¬ÔÚ³ÁÆôºó¡£¡£¡£¡£¡£³õÊ¼Ï°È¾ÔØÌåĿǰδ֪£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÒÉ»óÊÇ´¹µö¹¥»÷¡£¡£¡£¡£¡£


https://www.group-ib.com/blog/muddywater-infrastructure/


5¡¢·¿²úÖнéOrangeTee&TieÒòй¶25ÍòÈËÊý¾Ý±»·£¿£¿£¿£¿£¿î


¾Ý4ÔÂ18ÈÕ±¨Â·£¬£¬£¬£¬£¬ÐÂ¼ÓÆÂ·¿µØ²ú¹«Ë¾OrangeTee & TieÒòй¶³¬¹ý25Íò¿Í»§ºÍÔ±¹¤µÄÐÅÏ¢£¬£¬£¬£¬£¬±»ÒþÖÔ¼à¹Ü»ú¹¹·£¿£¿£¿£¿£¿î37000ÐÂÔª¡£¡£¡£¡£¡£2021Äê8ÔÂ3ÈÕ£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÊÕµ½ÁËALTDOSµÄÀÕË÷Óʼþ£¬£¬£¬£¬£¬ÒªÇó10¸ö±ÈÌØ±Ò×÷ΪÊê½ð¡£¡£¡£¡£¡£ÀÕË÷ÍÅ»ïûÓÐÊÕµ½Êê½ð£¬£¬£¬£¬£¬Òò¶øÖ´ÐÐDDoS¹¥»÷µ¼ÖÂOrangeTee & TieµÄÍøÂç̱»¾¡£¡£¡£¡£¡£¸Ã·¿²ú¹«Ë¾È¡Ö¤·¢ÏÖALTDOS½Ó¼ûÁË11¸öÊý¾Ý¿â£¬£¬£¬£¬£¬Éæ¼°256583¸ö¿Í»§ºÍÔ±¹¤µÄÐÅÏ¢¡£¡£¡£¡£¡£ÔÚ4ÔÂ17ÈÕ°ä²¼µÄÊéÃæÅоöÖУ¬£¬£¬£¬£¬PDPC³ÆÒòOrangeTee & TieµÄ¼¸¸öʧÎóµ¼ÖÂÁËÊý¾Ýй¶¡£¡£¡£¡£¡£


https://www.channelnewsasia.com/singapore/orangetee-real-estate-personal-data-breach-pdpa-customers-employees-3425291


6¡¢CheckPoint°ä²¼¹ØÓÚRaspberry RobinµÄ·ÖÎö»ã±¨


4ÔÂ18ÈÕ£¬£¬£¬£¬£¬Check Point°ä²¼Á˹ØÓÚRaspberry RobinµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£Raspberry RobinʹÓÃÁ˺öàÈÆ¹ý¼ì²âµÄ²½Ö裬£¬£¬£¬£¬Ô̺¬²é³­PEB£¨¹ý³Ì»·¾³¿é£©¡¢Óû§ÃûºÍÍÆËã»úÃû¡¢MacµØÖ·¡¢CPUID¡¢»î¶¯CPUÊýÁ¿¡¢ÄÚ´æÒ³¡¢MulDivºÍ¹Ì¼þ±íµÈ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ËüÀûÓúöಽÖèÀ´Ô¤·À±»°²È«½â¾ö¹æ»®¼ì²âµ½£¬£¬£¬£¬£¬ÀýÈçÈ¥³ýIFEOºÍWindows DefenderÅųýÁбíµÈ¡£¡£¡£¡£¡£Raspberry Robin»¹ÀûÓÃÁËÁ½¸öEoP·ì϶£¨CVE-2020-1054ºÍCVE-2021-1732£©½øÐÐÌáȨ¡£¡£¡£¡£¡£


https://research.checkpoint.com/2023/raspberry-robin-anti-evasion-how-to-exploit-analysis/