Adobe½¨¸´AcrobatºÍReader±»ÀûÓ÷ì϶CVE-2023-26369
°ä²¼¹¦·ò 2023-09-141¡¢Adobe½¨¸´AcrobatºÍReader±»ÀûÓ÷ì϶CVE-2023-26369
9ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬AdobeÒѰ䲼±¾ÔµÄÖܶþ²¹¶¡£¬£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËAcrobatºÍReaderÖÐÒѱ»ÀûÓõķì϶£¨CVE-2023-26369£©¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÔ½½çдÈë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬³É¹¦ÀûÓÿÉÔÚÖ¸±êÍÆËã»úÖÐÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ã»ÓÐÅû¶Óйع¥»÷µÄ¸ü¶àÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬µ«½¨ÒéÓû§×îºÃÔÚ72Ó×ʱÄÚ×°ÖøüС£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬Adobe»¹½¨¸´ÁËConnectÖеÄXSS·ì϶£¨CVE-2023-29305ºÍCVE-2023-29306£©ºÍExperience ManagerÖеÄXSS·ì϶£¨CVE-2023-38214ºÍCVE-2023-38215£©¡£¡£¡£¡£¡£
https://thehackernews.com/2023/09/update-adobe-acrobat-and-reader-to.html
2¡¢Microsoft Teams·þÎñÖжÏÖØÒªÓ°Ïì±±ÃÀµØÓòµÄÓû§
¾ÝýÌå9ÔÂ13ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬MicrosoftÔÚµ÷²éµ¼Ö¿ͻ§ÎÞ·¨Ê¹ÓÃMicrosoft TeamsÊÕ·¢ÐÂÎŵÄÖжÏÎÊÌâ¡£¡£¡£¡£¡£´Ó8µã×óÓÒÆðÍ·£¬£¬£¬£¬£¬£¬£¬£¬²¿ÃÅÓû§·´Ó³ÔÚÏνÓTeams·þÎñÆ÷»òWebÀûÓÃʱÓöµ½ÁËÎÊÌâ¡£¡£¡£¡£¡£Î¢ÈíĿǰÒѾȷ¶¨£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎÊÌâ½ö´æÔÚÓÚͨ¹ý±±ÃÀÊÜÓ°Ïì»ù´¡ÉèÊ©Ìṩ·þÎñµÄ²¿ÃÅÓû§£¬£¬£¬£¬£¬£¬£¬£¬ËûÃÇÔÚ½«±»Ó°ÏìµÄ·þÎñÁ÷Á¿Â·Óɵ½ÎÈÖØµÄ»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼õ»ºÓ°Ïì¡£¡£¡£¡£¡£½ØÖÁÃÀ¹ú¶«²¿¹¦·ò9ÔÂ13ÈÕ13:25£¬£¬£¬£¬£¬£¬£¬£¬Î¢Èí°µÊ¾TeamsÐÂÎÅ´«µÝÎÊÌâÏÖÒѽâ¾ö¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-teams-down-ongoing-outage-behind-message-failures-delays/
3¡¢GitHubÖзì϶¿Éµ¼ÖÂ4ǧ¶à´æ´¢¿âÔâµ½Repojacking¹¥»÷
CheckmarxÔÚ9ÔÂ12ÈÕ³ÆÆä·¢ÏÖÁËGitHubÖеÄÒ»¸öзì϶£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂ4000¶à¸ö´æ´¢¿âÔâµ½Repojacking¹¥»÷¡£¡£¡£¡£¡£ÔÚRepoJacking¹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÔںϷ¨´´½¨Õ߸ü¸ÄÓû§ÃûºóʹÓô洢¿âµÄ¾ÉÓû§Ãû£¬£¬£¬£¬£¬£¬£¬£¬¶øºó°ä²¼Í¬ÃûµÄ¶ñÒâ´æ´¢¿âÒÔÓÕÆÓû§ÏÂÔØÆäÄÚÈÝ¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶¿É½Ù³ÖGo¡¢PHPºÍSwiftµÅ×ïÑÔµÄ4000¶à¸ö´úÂë°üÒÔ¼°GitHub»î¶¯¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÓÚ3ÔÂ1ÈÕÅû¶Á˸÷ì϶£¬£¬£¬£¬£¬£¬£¬£¬´úÂëÍÐ¹ÜÆ½Ì¨ÒÑÓÚ9ÔÂ1ÈÕ½¨¸´Á˸ÃÎÊÌâ¡£¡£¡£¡£¡£
https://checkmarx.com/blog/persistent-threat-new-exploit-puts-thousands-of-github-repositories-and-millions-of-users-at-risk/
4¡¢ºÚ¿ÍUSDoDÔÚ°µÍø¹«¿ªAirbusÊýǧ¼Ò¹©¸øÉ̵ÄÊý¾Ý
¾Ý9ÔÂ13ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬º½¿Õ¹«Ë¾AirbusÔÚµ÷²éÉæ¼°3200¼Ò¹©¸øÉ̵ÄÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£ÃûΪUSDoDµÄºÚ¿ÍÓÚ±¾ÖÜÒ»ÔÚBreachForumsÉÏ·¢Ìû³Æ£¬£¬£¬£¬£¬£¬£¬£¬ËûÃÇÈëÇÖÁËÒ»ÃûÍÁ¶úÆäº½¿Õ¹«Ë¾Ô±¹¤µÄÕË»§²¢»ñµÃÁËAirbusÃÅ»§ÍøÕ¾µÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£»£»£»£»£»£»¹Ð¹Â©Óµº±¼ûǧ¼ÒAirbus¹©¸øÉ̵ľßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµÈ¡£¡£¡£¡£¡£USDoD×Ô³ÆÊÇRansomedµÄÕýʽ³ÉÔ±£¬£¬£¬£¬£¬£¬£¬£¬²¢°µÊ¾Lockheed MartinºÍRaytheon¿ÉÄÜ»áÊÇÏÂÒ»¸öûָ±ê¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïÔÚÈ¥Äê12Ô·ݻ¹ÔøÏúÊÛÁËFBI¹²ÏíϵͳInfraGardµÄÊý¾Ý¿â¡£¡£¡£¡£¡£
https://therecord.media/airbus-data-leak-suppliers-breachedforums
5¡¢Symantec·¢ÏÖRedflyÕë¶ÔÑÇÖÞij¹ú¶ÈµçÍøµÄ¹¥»÷»î¶¯
9ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬SymantecÅû¶ÁËRedflyÕë¶ÔÑÇÖÞij¹ú¶ÈµçÍøµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¹¥»÷»î¶¯×îÔçµÄ¼£ÏóÓÚ2ÔÂ23ÈÕ±»¼Í¼£¬£¬£¬£¬£¬£¬£¬£¬ÆäʱShadowPadÔÚÒ»Ì¨ÍÆËã»úÉÏÖ´ÐУ¬£¬£¬£¬£¬£¬£¬£¬ºóÓÚ5ÔÂ17ÈÕÔٴα»Ö´ÐУ¬£¬£¬£¬£¬£¬£¬£¬×îºóµÄ»î¶¯¼£Ïó³öÏÖÓÚ8ÔÂ3ÈÕ¡£¡£¡£¡£¡£¹¥»÷»î¶¯Ê¹ÓõŤ¾ßÔ̺¬£ºÄ£¿£¿£¿£¿£¿é»¯RAT ShadowPad£¬£¬£¬£¬£¬£¬£¬£¬Ëü¼Ù×°³ÉVMwareÎļþ£¬£¬£¬£¬£¬£¬£¬£¬Ö§³ÖÊý¾Ýй¶¡¢»÷¼ü¼Í¼¡¢ÎļþËÑË÷ÒÔ¼°Ô¶³ÌºÅÁîÖ´Ðеȣ»£»£»£»£»£»Packerloader£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÔÚ¿ÉÄÜÈÆ¹ýAV¼ì²âµÄAES¼ÓÃÜÎļþÖмÓÔØºÍÖ´ÐÐshellcode£»£»£»£»£»£»ÒÔ¼°¼üÅ̼ͼ·¨Ê½£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÖ¸±êϵͳÉϵÄÈÕÖ¾ÎļþÖв¶»ñ»÷¼ü¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷ÓëAPT41£¨±ðÃûWinnti£©µÄ»î¶¯ÓгÁµþ¡£¡£¡£¡£¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/critical-infrastructure-attacks
6¡¢KasperskyÅû¶Free Download Manager¹©¸øÁ´¹¥»÷
9ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Kaspersky»ã±¨³ÆFree Download Manager¹©¸øÁ´¹¥»÷½«LinuxÓû§³Á¶¨Ïòµ½×°ÖÃÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þµÄ¶ñÒâDebianÈí¼þ°ü´æ´¢¿â¡£¡£¡£¡£¡£KasperskyÔÚµ÷²é¿ÉÒÉÓòʱ·¢ÏÖÁ˸û£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ÒѾ½øÐÐÁËÈýÄê¶à¡£¡£¡£¡£¡£¸Ã¶ñÒâDebianÈí¼þ°üÓÃÓÚ×°ÖûùÓÚDebianµÄLinux¿¯Ðа棬£¬£¬£¬£¬£¬£¬£¬Ëü»á·Ö·¢Ò»¸öBashÐÅÏ¢ÇÔÈ¡¾ç±¾ºÍÒ»¸ö´ÓC2³ÉÁ¢·´ÏòshellµÄcrondºóÃÅ¡£¡£¡£¡£¡£crond×é¼þÔÚϵͳÉÏ´´½¨Ò»¸öеÄcron¹¤×÷£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÔÚϵͳÆô¶¯Ê±ÔËÐÐÇÔÈ¡¾ç±¾¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÒÑÏòÈí¼þ¹©¸øÉÌ´«µÝÁË´ËÊ£¬£¬£¬£¬£¬£¬£¬£¬µ«ÉÐδÊÕµ½»Ø¸´£¬£¬£¬£¬£¬£¬£¬£¬Òò¶øÈ·ÇеÄÈëÇÖ·½Ê½ÈÔ²»Ã÷ÏÔ¡£¡£¡£¡£¡£
https://securelist.com/backdoored-free-download-manager-linux-malware/110465/


¾©¹«Íø°²±¸11010802024551ºÅ