΢Èí8Ô·ݰ²È«¸üн¨¸´Á½¸ö±»ÀûÓ÷ì϶ÔÚÄÚµÄ87¸ö·ì϶
°ä²¼¹¦·ò 2023-08-091¡¢Î¢Èí8Ô·ݰ²È«¸üн¨¸´Á½¸ö±»ÀûÓ÷ì϶ÔÚÄÚµÄ87¸ö·ì϶
¾ÝýÌå8ÔÂ8ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬ÊÇ΢Èí°ä²¼ÁË8Ô·ݵÄÖܶþ²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬×ܼƽ¨¸´ÁË87¸ö·ì϶£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Á½¸ö±»×Ô¶¯ÀûÓõķì϶¡£¡£¡£¡£¡£¡£¡£Òѱ»ÀûÓõķì϶±ðÀëÊÇ.NETºÍVisual Studio»Ø¾ø·þÎñ·ì϶£¨CVE-2023-38180£©£¬£¬£¬£¬£¬£¬Î¢Èíδ¹«¿ªÀûÓô˷ì϶µÄ¹¥»÷µÄÏêÇé¡£¡£¡£¡£¡£¡£¡£ÁíÒ»¸öÊÇÏÈǰÒÑ»º½â²¢±»»ý¼«ÀûÓõÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-36884£©µÄ²¹¶¡ÈƹýÎÊÌ⣬£¬£¬£¬£¬£¬¸Ã·ì϶±»RomComÓÃÀ´·Ö·¢ÀÕË÷Èí¼þIndustrial Spy¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬»¹½¨¸´Á˽ÏΪÑϳÁµÄOutlook RCE·ì϶£¨CVE-2023-36895£©ºÍTeams RCE·ì϶£¨CVE-2023-29328ºÍCVE-2023-29330£©µÈ¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2023-patch-tuesday-warns-of-2-zero-days-87-flaws/
2¡¢×°ÖÃÁ¿250Íò´ÎµÄ43¸öAndroidÀûÓÃÔÚËøÆÁʱ¼ÓÔØ¸æ°×
¾Ý8ÔÂ8ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬McAfee·¢ÏÖGoogle PlayÖеÄ43¸öAndroidÀûÓûáÔÚÊÖ»úËøÆÁʱ¼ÓÔØ¸æ°×¡£¡£¡£¡£¡£¡£¡£ÕâЩÀûÓüÙ×°³ÉµçÊÓ/DMB²¥·ÅÆ÷¡¢ÒôÀÖÏÂÔØÆ÷¡¢ÐÂÎźÍÈÕÀúÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬×°ÖÃÁ¿¸ß´ï250Íò´Î£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶Ôº«¹úµÄÖ¸±ê¡£¡£¡£¡£¡£¡£¡£´ËÀà¶ñÒâÀûÓûáºÄ¾¡É豸µç³ØÊÙÃü²¢¿÷Ëð´óÁ¿Á÷Á¿¡£¡£¡£¡£¡£¡£¡£Ò»µ©×°Ö㬣¬£¬£¬£¬£¬ÕâЩ¸æ°×ÀûÓûáÆÚ´ý¼¸Öܲůô¶¯¶ñÒâ»î¶¯£¬£¬£¬£¬£¬£¬ÒÔºýŪÓû§²¢ÈƹýGoogleÉóºËÈËÔ±µÄ¼ì²â¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬GoogleÒÑ´ÓÆäÀûÓÃÉ̵êÖÐɾ³ýÁËÕâЩÀûÓᣡ£¡£¡£¡£¡£¡£
https://securityaffairs.com/149274/malware/google-play-43-rogue-android.html
3¡¢CiscoÅû¶ÀûÓÃYashmaµÄ±äÌåÕë¶ÔÔ½ÄϵȹúµÄ¹¥»÷»î¶¯
Cisco TalosÔÚ8ÔÂ7ÈÕÅû¶ÁËÀûÓÃÀÕË÷Èí¼þYashmaµÄ±äÌåÕë¶Ô±£¼ÓÀûÑǺÍÔ½ÄϵȹúµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¹¥»÷»î¶¯Ê¼ÓÚ6ÔÂ4ÈÕ×óÓÒ£¬£¬£¬£¬£¬£¬¿ÉÄÜÓëÔ½ÄϵĺڿÍÍÅ»ïÓйء£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯·ÂÕÕÁËWannaCryµÄÀÕË÷ÐÅ£¬£¬£¬£¬£¬£¬²¢°µÊ¾ÈôÊÇÖ¸±ê²»ÔÚÈýÌìÄÚ½»Êê½ð£¬£¬£¬£¬£¬£¬Êê½ð½ð¶î½«·±¶¡£¡£¡£¡£¡£¡£¡£µ«ÀÕË÷ÐÅÖÐûÓÐÁгöÊê½ðÊý¶î£¬£¬£¬£¬£¬£¬¹²ÏíµÄÕË»§ÖÐҲûÓбÈÌØ±Ò£¬£¬£¬£¬£¬£¬ÕâÅú×¢¸Ã»î¶¯¿ÉÄÜÈÔ´¦ÓÚ³õÆÚ½×¶Î¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬¹¥»÷ÕßûÓÐÔÚ¶þ½øÔìÎļþÖÐǶÈëÀÕË÷ÐŵÄ×Ö·û´®£¬£¬£¬£¬£¬£¬¶øÊÇͨ¹ýÖ´ÐÐǶÈëµÄÅú´¦ÖÃÎļþ£¬£¬£¬£¬£¬£¬´Ó¹¥»÷ÕßµÄGitHub´æ´¢¿âÖÐÏÂÔØ¡£¡£¡£¡£¡£¡£¡£
https://blog.talosintelligence.com/new-threat-actor-using-yashma-ransomware/
4¡¢¼äµýÈí¼þ·þÎñLetMeSpyÔÚ´ó¹æÄ£Êý¾Ýй¶ºóÖÕ³¡ÔËÓª
ýÌå8ÔÂ7Èճƣ¬£¬£¬£¬£¬£¬Android¼äµýÈí¼þ·þÎñLetMeSpyÔÚ²úÉú´ó¹æÄ£Êý¾Ýй¶ºó£¬£¬£¬£¬£¬£¬±»ÆÈÖÕ³¡ÔËÓª¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶ÊÂÎñ²úÉúÓÚ6ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬Ô̺¬³¬¹ý13000¸öµØÎ»Êý¾ÝµãºÍ26000Ãû¿Í»§µÄÊý¾ÝµÈ¡£¡£¡£¡£¡£¡£¡£LetMeSpyͨ¹ýÆäÍøÕ¾°ä²¼ÁËÒ»Ôò²¼¸æ£¬£¬£¬£¬£¬£¬Í¨ÖªÓû§½«ÔÚ8ÔÂ31ÈÕ֮ǰÖÕ³¡ËùÓзþÎñ¡£¡£¡£¡£¡£¡£¡£ÊÂÎñ²úÉúºó£¬£¬£¬£¬£¬£¬LetMeSpyµÄÍøÕ¾Ò²ÂäÈëÁ˺ڿ͵ĽÚÔì֮ϡ£¡£¡£¡£¡£¡£¡£Õë¶ÔÕâÒ»Çé¿ö£¬£¬£¬£¬£¬£¬LetMeSpyÒÑÅúʾµ«Ô¸½Ó¼ûÆäÊý¾ÝµÄÓû§ÔÚ9ÔÂ30ÈÕ֮ǰʹÓÃÍøÕ¾ÉÏÌṩµÄÓʼþµØÖ·ÁªÏµ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£
https://www.hackread.com/letmespy-android-spyware-data-breach-shuts-down/
5¡¢Kasada·¢ÏÖÀûÓÃײ¿â¹¤¾ßOpenBullet·Ö·¢RATµÄ»î¶¯
8ÔÂ7ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬£¬Kasada·¢ÏÖÁËÐµĹ¥»÷»î¶¯£¬£¬£¬£¬£¬£¬ÀûÓöñÒâOpenBulletÅäÖÃÎļþÀ´·Ö·¢ÇÔÊØÐÅÏ¢µÄRAT¡£¡£¡£¡£¡£¡£¡£OpenBulletÊÇÒ»¸öºÏ·¨µÄ¿ªÔ´ÉøÈë²âÊÔ¹¤¾ß£¬£¬£¬£¬£¬£¬ÓÃÓÚ×Ô¶¯×²¿â¹¥»÷¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»OpenBulletÅäÖÃÎļþµÄ¶àÖ°ÄÜÖ°Äܹ»ÊµÏÖ¸´ÔӵĹ¥»÷£¬£¬£¬£¬£¬£¬µ«²»×ã¾ÑéµÄÐÂÊֺڿͲ»ÄÜÆëÈ«Àí½âÔÚ´´½¨ÄÄЩҪÇóÒÔ¼°ÔÚ¼ìË÷ÄÄЩÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÕâЩ¶ñÒâÅäÖûá½Ó¼ûGitHub´æ´¢¿âÀ´¼ìË÷»ùÓÚRustµÄdropper Ocean£¬£¬£¬£¬£¬£¬Ëü»áÏÂÔØ»ùÓÚPythonµÄ¶ñÒâÈí¼þPatent¡£¡£¡£¡£¡£¡£¡£×îÖÕÆô¶¯Ò»¸öRAT£¬£¬£¬£¬£¬£¬ÒÔTelegram×÷ΪC2£¬£¬£¬£¬£¬£¬ÇÔÈ¡ä¯ÀÀÆ÷ÃÜÂë¡¢cookieºÍ¼ÓÃÜÇ®°üµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2023/08/new-malware-campaign-targets.html
6¡¢Fortinet°ä²¼2023ÄêÉϰëÄêÈ«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨
8ÔÂ7ÈÕ£¬£¬£¬£¬£¬£¬Fortinet°ä²¼ÁË2023ÄêÉϰëÄêÈ«ÇòÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£½ñÄêÉϰëÄ꣬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖAPT»î¶¯ÆµÈÔ¡¢ÀÕË÷Èí¼þƵÂʺ͸´ÔÓÐÔÌá¸ßÒÔ¼°½©Ê¬ÍøÂç»î¶¯Ôö³¤µÈÇ÷Ïò¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»¹¥»÷ÊýÁ¿²¢Î´Ïñ´ÓǰÄÇÑù³ÖÐøÅÊÉý£¬£¬£¬£¬£¬£¬µ«ÈëÇÔìóͼ±äµÃÔ½·¢¸´ÔÓºÍÓÐÕë¶ÔÐÔ¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃÖØÒª·ì϶µÄ¿ÉÄÜÐÔÔö³¤ÁË327±¶¡£¡£¡£¡£¡£¡£¡£ÔÚMITREʶ´ËÍâ138¸ö¹¥»÷ÍÅ»ïÖУ¬£¬£¬£¬£¬£¬ÓÐ41¸ö(30%)ÔÚ½ñÄêÉϰëÄê»îÔ¾¡£¡£¡£¡£¡£¡£¡£ÔÚ´ÓǰÎåÄêÖУ¬£¬£¬£¬£¬£¬Î¨Ò»·ì϶µÄÀûÓôÎÊýÔö³¤ÁË68%£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ¼Ò×åºÍ±äÌå³Ê±¬Õ¨Ê½Ôö³¤£¬£¬£¬£¬£¬£¬±ðÀëÔö³¤ÁË135%ºÍ175%¡£¡£¡£¡£¡£¡£¡£
https://www.fortinet.com/blog/threat-research/fortiguard-labs-threat-report-key-findings-1h-2023


¾©¹«Íø°²±¸11010802024551ºÅ