Zimbra½¨¸´ZCSÖÐÒѱ»ÀûÓõÄXSS·ì϶CVE-2023-38750

°ä²¼¹¦·ò 2023-08-01

1¡¢Zimbra½¨¸´ZCSÖÐÒѱ»ÀûÓõÄXSS·ì϶CVE-2023-38750 


¾ÝýÌå7ÔÂ27ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬Zimbra°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´ÁËÕë¶ÔZimbra Collaboration Suite(ZCS)µç×ÓÓʼþ·þÎñÆ÷µÄ¹¥»÷Öб»ÀûÓõķì϶¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öXSS·ì϶£¨CVE-2023-38750£©£¬£¬£¬£¬£¬£¬¿ÉÄܱ»ÓÃÀ´ÇÔÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£¹ÌÈ»ZimbraÔÚ³õ´ÎÅû¶¸Ã·ì϶²¢¶½´ÙÓû§ÊÖ¶¯½¨¸´Ê±£¬£¬£¬£¬£¬£¬²¢Î´Åú×¢¸Ã·ì϶Òѱ»ÀûÓà £¬£¬£¬£¬£¬£¬µ«Google TAGй©£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÊÇÔÚÓÐÕë¶ÔÐԵĹ¥»÷Öб»·¢Ïֵġ£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬CISAÒ²°ä²¼Á˹«¸æ£¬£¬£¬£¬£¬£¬ÒªÇóÁª¹ú»ú¹¹ÔÚ8ÔÂ17ÈÕ֮ǰ½¨¸´¸Ã·ì϶¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/zimbra-patches-zero-day-vulnerability-exploited-in-xss-attacks/


2¡¢Tempur SealyÔâµ½ÍøÂç¹¥»÷µ¼Ö¹«Ë¾ÔËÓªÁÙʱÖжÏ


¾Ý8ÔÂ1ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬´²µæÏúÊÛÉÌTempur SealyÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬ÆÈʹ²¿ÃÅϵÍÂäÙʱ¹Ø¹Ø¡£¡£¡£¡£¡£¡£Tempur Sealy±»ÒÔΪÊÇÈ«Çò×î´óµÄ´²ÉÏÓÃÆ·¹©¸øÉÌ£¬£¬£¬£¬£¬£¬Éϼ¾¶È¾»ÏúÊÛ¶îΪ12ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ±¾ÖÜһй©£¬£¬£¬£¬£¬£¬ÓÚ7ÔÂ23ÈÕÔâµ½Á˹¥»÷£¬£¬£¬£¬£¬£¬Æä²ÉÈ¡ÏìÓ¦´ëÊ©×Ô¶¯¹Ø¹ØÁ˲¿ÃÅITϵͳ£¬£¬£¬£¬£¬£¬Õâµ¼Ö¹«Ë¾ÔËÓªÁÙʱÖжϡ£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒÑÆðÍ·½«²¿ÃÅÖØÒªµÄϵͳ³ÁÐÂÉÏÏß²¢¸´Ô­ÔËÓª¡£¡£¡£¡£¡£¡£µ÷²éÈÔÔÚ½øÐÐÖУ¬£¬£¬£¬£¬£¬ÒÔÈ·¶¨¶ÔÒµÎñºÍ²ÆÕþ²úÉúµÄÓ°Ï죬£¬£¬£¬£¬£¬Éв»Ã÷ÏÔÊÇ·ñÉæ¼°¿Í»§»òÔ±¹¤ÐÅÏ¢£¬£¬£¬£¬£¬£¬ÒÔ¼°¹¥»÷ÕßµÄÉí·Ý¡£¡£¡£¡£¡£¡£


https://therecord.media/mattress-giant-tempur-sealy-cyberattack


3¡¢²éËþŬ¼ÓÐÄÔà×êÑÐËù´«µÝÉæ¼°17ÍòÈ˵ÄÊý¾Ýй¶ÊÂÎñ


7ÔÂ29ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬£¬²éËþŬ¼ÓÐÄÔà×êÑÐËù£¨Chattanooga Heart Institute£¬£¬£¬£¬£¬£¬CHI£©´«µÝÁËÉæ¼°17ÍòÈ˵ÄÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£5Ô·Ý£¬£¬£¬£¬£¬£¬KarakurtÍÅ»ï³Æ¹¥»÷Á˸ûú¹¹£¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁË158GBµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¹¥»÷ÕßûÓÐÌṩ֤¾Ý£¬£¬£¬£¬£¬£¬µ«°µÊ¾Ð¹Â¶Êý¾ÝÔ̺¬Ò½ÁƼͼ¡¢²é³­Á˾֡¢Õï¶Ï¡¢Éç»á°²È«ºÅÂë¡¢»¤ÕÕ¡¢ºÍ²ÆÕþÐÅÏ¢µÈ£¬£¬£¬£¬£¬£¬ÆäʱCHI²¢Î´»ØÓ¦´ËÊÂÎñ¡£¡£¡£¡£¡£¡£7ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬CHIй©ÓÐ170450ÈËÊܵ½Êý¾Ýй¶ÊÂÎñµÄÓ°Ïì¡£¡£¡£¡£¡£¡£ËûÃÇÓÚ4ÔÂ17ÈÕ¼ì²âµ½¹¥»÷¼£Ï󣬣¬£¬£¬£¬£¬È·¶¨ÏµÍ³ÔÚ3ÔÂ8ÈÕÖÁ16ÈÕÆÚ¼äÔø±»½Ó¼û¹ý¡£¡£¡£¡£¡£¡£Ö±µ½5ÔÂ31ÈÕ£¬£¬£¬£¬£¬£¬CHI²ÅµÃÖª»¼ÕߵĽ¡È«ÐÅÏ¢ºÍµ£±£ÈËÐÅÏ¢±»Ð¹Â¶¡£¡£¡£¡£¡£¡£


https://www.databreaches.net/the-chattanooga-heart-institute-to-notify-170450-about-march-data-security-incident/


4¡¢ÃÀ¹úSAISÊý¾Ý¿âÅäÖÃÃýÎóй¶572 GBѧÉúºÍÀÏʦµÄÐÅÏ¢


ýÌå7ÔÂ28ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öδÊܱ£»£»£»£»£»¤µÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Óë½ÌÓý»ú¹¹ÓйصÄ682438±Ê¼Í¼¡£¡£¡£¡£¡£¡£µ÷²é·¢ÏÖ£¬£¬£¬£¬£¬£¬Êý¾Ý¿âÊôÓÚÄÏ·½¶ÀÁ¢Ñ§ÌÃЭ»á(SAIS)£¬£¬£¬£¬£¬£¬ÕâÊÇλÓÚÃÀ¹úµÄÒ»¸ö×ÔÔ¸ÐÔµØÓòÈÏ֤Э»á¡£¡£¡£¡£¡£¡£Õâ´Îй¶µÄÊý¾Ý¹²572.8 GB£¬£¬£¬£¬£¬£¬¹¦·ò¿ç¶È´Ó2012Äêµ½2023Ä꣬£¬£¬£¬£¬£¬Ô̺¬Ñ§ÉúºÍÀÏʦ¼Í¼¡¢½¡È«ÐÅÏ¢¡¢Éç»á°²È«ºÅÂ롢ǹ»÷°¸ºÍ¹Ø±Õ֪ͨ¡¢Ñ§ÌõØÍ¼ºÍ²ÆÕþÔ¤ËãµÈ¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÒѱ»±£»£»£»£»£»¤ÆðÀ´¡£¡£¡£¡£¡£¡£


https://www.hackread.com/data-leak-student-faculty-accreditation-org/


5¡¢Google°ä²¼¹ØÓÚ2022Äê¶È0day·ì϶µÄ»ØÊ׻㱨


 7ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬Google°ä²¼ÁËÄê¶È0day·ì϶»ã±¨£¬£¬£¬£¬£¬£¬ÌṩÁË2022ÄêÒÔÀ´µÄÒ°±íÀûÓÃͳ¼ÆÊý¾Ý¡£¡£¡£¡£¡£¡£2022Äê¼ì²â²¢Åû¶ÁË41¸öÔÚÒ°µÄ0day£¬£¬£¬£¬£¬£¬ÆäÖÐÉϰëÄê20¸ö£¬£¬£¬£¬£¬£¬Ï°ëÄê21¸ö£¬£¬£¬£¬£¬£¬½ö´ÎÓÚ2021ÄêµÄ69¸ö·ì϶¡£¡£¡£¡£¡£¡£ÔÚAndroidÖУ¬£¬£¬£¬£¬£¬´æÔÚ¶àÖÖÇé¿ö£¬£¬£¬£¬£¬£¬Óû§Ôںܳ¤Ò»¶Î¹¦·òÄÚÎÞ·¨»ñµÃ²¹¶¡¡£¡£¡£¡£¡£¡£Òò¶ø¶ÔÓÚ¹¥»÷ÕßÀ´Ëµ£¬£¬£¬£¬£¬£¬NdayµÄÖ°ÄÜÀàËÆÓÚ0day¡£¡£¡£¡£¡£¡£ÔÚ2022ÄêµÄ41¸ö0dayÖУ¬£¬£¬£¬£¬£¬ÓÐ17¸öÊÇ֮ǰ»ã±¨µÄ·ì϶µÄ±äÌ壬£¬£¬£¬£¬£¬Õ¼±È³¬¹ý40%¡£¡£¡£¡£¡£¡£


https://security.googleblog.com/2023/07/the-ups-and-downs-of-0-days-year-in.html


6¡¢Kaspersky°ä²¼2023ÄêQ2 APT¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨


7ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬Kaspersky°ä²¼ÁË2023ÄêQ2 APT¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£±¾¼¾¶ÈµÄÖØÒªÁÁµãÖ®Ò»ÊÇ·¢ÏÖÁ˳־ÃÔËÓªµÄOperation Triangulation»î¶¯£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ÐµÄiOS¶ñÒâÈí¼þƽ̨¡£¡£¡£¡£¡£¡£APT»î¶¯ÔÚµØÀíÉ¢²¼ÉÏÒÀÈ»ºÜ·ÖÉ¢£¬£¬£¬£¬£¬£¬±¾¼¾¶È£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÖØÒªÕë¶ÔÅ·ÖÞ¡¢À­¶¡ÃÀÖÞ¡¢Öж«ºÍÑÇÖÞ¸÷µØ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬³ÉÊìµÄ¹¥»÷ÕßÔÚ²»ÐݼÓÇ¿Æä¹¤¾ß£¬£¬£¬£¬£¬£¬ÈçLazarus¿ª·¢ÁËMATA¿ò¼Ü¡¢BlueNoroffʹÓÃÁËеĴ«Ê䷽ʽºÍ±à³Ì˵»°¡¢ScarCruftʹÓÃÁËеÄϰȾ·½Ê½ÒÔ¼°GoldenJackalеĶñÒâÈí¼þÑù±¾¡£¡£¡£¡£¡£¡£»£»£»£»£»¹·¢ÏÖÁËй¥»÷ÕßMysterious ElephantµÄ»î¶¯¡£¡£¡£¡£¡£¡£


https://securelist.com/apt-trends-report-q2-2023/110231/