ÖÇÄܼҾÓÉÌNexx¶à´ÎºöÂÔ¿ÉÔ¶³Ì·­¿ª³µ¿âÃŵÄÎó²î

Ðû²¼Ê±¼ä 2023-04-07

1¡¢ÖÇÄܼҾÓÉÌNexx¶à´ÎºöÂÔ¿ÉÔ¶³Ì·­¿ª³µ¿âÃŵÄÎó²î


¾ÝýÌå4ÔÂ5ÈÕ±¨µÀ£¬ £¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÔÚNexxÖÆÔìµÄ¼¸¿îÖÇÄÜ×°±¸Öз¢Ã÷Á˶à¸öÎó²î£¬ £¬£¬£¬£¬£¬£¬¿É±»ÓÃÀ´Ô¶³Ì·­¿ª³µ¿âÃÅ»òÕß¿ØÖƾ¯±¨ºÍÖÇÄܲåÍ·¡£¡£¡£ ¡£¡£¡£ÕâЩÎó²î»®·ÖΪʹÓÃÓ²±àÂëÆ¾Ö¤£¨CVE-2023-1748£©¡¢»á¼û¿ØÖƲ»µ±£¨CVE-2023-1749ºÍCVE-2023-1750£©¡¢ÊäÈëÑéÖ¤²»µ±£¨CVE-2023-1751£©ºÍÉí·ÝÑéÖ¤¿ØÖƲ»µ±£¨CVE-2023-1752£©¡£¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±»¹ÑÝʾÁËÔõÑùʹÓÃÎó²îCVE-2023¨C1748·­¿ªNexx³µ¿âÃÅ¡£¡£¡£ ¡£¡£¡£¾ÝϤ£¬ £¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±Sam SabetanºÍCISAÔø±¨¸æ¹ý¸ÃÎó²î£¬ £¬£¬£¬£¬£¬£¬¿ÉÊǶ¼±»NexxºöÂÔÁË¡£¡£¡£ ¡£¡£¡£


https://www.securityweek.com/nexx-ignores-vulnerabilities-allowing-hackers-to-remotely-open-garage-doors/


2¡¢ÂÉËùGenova Burnsϵͳ±»ºÚÓŲ½Ë¾»úÐÅÏ¢ÔÙ´Îй¶


¾Ý4ÔÂ3ÈÕ±¨µÀ£¬ £¬£¬£¬£¬£¬£¬ÓŲ½Ë¾»úµÄÐÅÏ¢ÔÙ´Îй¶£¬ £¬£¬£¬£¬£¬£¬Õâ´ÎÔ´ÓÚ״ʦÊÂÎñËùGenova Burns¡£¡£¡£ ¡£¡£¡£¸ÃÊÂÎñÉæ¼°ÐÕÃû¡¢Éç»áÇå¾²ºÅÂëºÍ˰ºÅµÈ£¬ £¬£¬£¬£¬£¬£¬Ó°ÏìÈËÊý²»Ïê¡£¡£¡£ ¡£¡£¡£ÓÉÓڸù«Ë¾ÎªÓŲ½×öÖ´·¨ÊÂÇ飬 £¬£¬£¬£¬£¬£¬ÒÔÊdzÖÓÐÕâЩÐÅÏ¢¡£¡£¡£ ¡£¡£¡£ÂÉËùÌåÏÖ£¬ £¬£¬£¬£¬£¬£¬Î´¾­ÊÚȨµÄµÚÈý·½»ñµÃÁËÆäϵͳµÄ»á¼ûȨÏÞ£¬ £¬£¬£¬£¬£¬£¬²¢ÇÒÔÚ2023Äê1ÔÂ23ÈÕ1ÔÂ31ÈÕ»á¼û»òй¶Á˲¿·ÖÎļþ¡£¡£¡£ ¡£¡£¡£ËûÃÇÒѾʹËÊÂ֪ͨÁËÖ´·¨²¿·Ö£¬ £¬£¬£¬£¬£¬£¬²¢¸ü¸ÄÁËËùÓÐϵͳÃÜÂ룬 £¬£¬£¬£¬£¬£¬»¹½«ÎªÊÜÓ°ÏìµÄСÎÒ˽¼ÒÌṩ12¸öÔµÄÉí·Ý¼à¿ØÐ§ÀÍ¡£¡£¡£ ¡£¡£¡£


https://www.theregister.com/2023/04/03/uber_drivers_info_stolen/


3¡¢OCR LabsµÄϵͳÉèÖùýʧÖ÷ÒªÓ°Ïì½ðÈÚ»ú¹¹µÄ¿Í»§


4ÔÂ4ÈÕ±¨µÀ³Æ£¬ £¬£¬£¬£¬£¬£¬Ñо¿ÍŶÓÔÚ3ÔÂ8ÈÕ·¢Ã÷ÁËOCR Labs idkit.comµÄÒ»¸öÇéÐÎÎļþ(.env)¿É¹ûÕæ»á¼û¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾ÊÇÊý×ÖÉí·ÝÑéÖ¤¹¤¾ßµÄ¹©Ó¦ÉÌ£¬ £¬£¬£¬£¬£¬£¬ÆäIDkit¹¤¾ß±»¸÷´óÒøÐС¢µçÐŹ«Ë¾ºÍÕþ¸®»ú¹¹Ê¹Óᣡ£¡£ ¡£¡£¡£ÔÚй¶µÄÊý¾ÝÖУ¬ £¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËGoogleºÍLivenessµÄAPIÃÜÔ¿ÃÜÔ¿¡¢Engine v4ƾ֤ÒÔ¼°À´×ÔExperianµÄAPIÃÜÔ¿¡£¡£¡£ ¡£¡£¡£¸ÃÊÂÎñÓ°ÏìÁËÓ°ÏìÁËQBANK¡¢Defense Bank¡¢Bloom Money¡¢Admiral Money¡¢MA MoneyºÍReed¡£¡£¡£ ¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃй¶µÄÊý¾Ý£¬ £¬£¬£¬£¬£¬£¬ÈëÇÖÒøÐеĺó¶Ë»ù´¡ÉèÊ©£¬ £¬£¬£¬£¬£¬£¬´Ó¶ø¹¥»÷Æä¿Í»§µÄ»ù´¡ÉèÊ©¡£¡£¡£ ¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬£¬£¬¸ÃÎÊÌâÒѱ»½â¾ö¡£¡£¡£ ¡£¡£¡£


https://cybernews.com/security/ocr-labs-exposes-its-systems/


4¡¢NoteboomÔâµ½BlackCatµÄ¹¥»÷²¢±»ÀÕË÷175ÍòÃÀÔª


ýÌå4ÔÂ5ÈÕ±¨µÀ³Æ£¬ £¬£¬£¬£¬£¬£¬µÂ¿ËÈøË¹ÖݵÄ״ʦÊÂÎñËùNoteboomÔâµ½ÁËBlackCatµÄÀÕË÷¹¥»÷¡£¡£¡£ ¡£¡£¡£BlackCatÏòNoteboom·¢Ë͵ç×ÓÓʼþ£¬ £¬£¬£¬£¬£¬£¬Í¨ÖªÆäÔÚ3ÔÂ24ÈÕ±¬·¢ÁËÊý¾Ýй¶¡£¡£¡£ ¡£¡£¡£Óʼþ»¹³ÆËûÃÇÒÑÈëÇÖϵͳ²¢Í£ÁôÁË7Ì죬 £¬£¬£¬£¬£¬£¬ÏÂÔØÁËÁè¼Ý400GbµÄÊý¾Ý£¬ £¬£¬£¬£¬£¬£¬²¢¼ÓÃÜÁËËùÓÐЧÀÍÆ÷ºÍÊý¾Ý¡£¡£¡£ ¡£¡£¡£Ð¹Â¶Êý¾Ý°üÀ¨±£ÃÜЭÒ顢δ¾ö°¸¼þµÄÎļþ¡¢Éæ¼°ËßËϵÄÒ½ÁƼͼÒÔ¼°Ô±¹¤Êý¾ÝµÈ¡£¡£¡£ ¡£¡£¡£BlackCat͸¶Êê½ðÒªÇóΪ1750000ÃÀÔª£¬ £¬£¬£¬£¬£¬£¬µ«Noteboom»ù´¡Ã»ÓлØÓ¦ËûÃÇ¡£¡£¡£ ¡£¡£¡£


https://www.databreaches.net/noteboom-the-law-firm-hit-by-blackcat/


5¡¢Ó¢ÍâÑó°ü¹«Ë¾CapitaÔâµ½¹¥»÷µ¼Ö²¿·ÖЧÀÍÔÝʱÖÐÖ¹


ýÌå4ÔÂ3Èճƣ¬ £¬£¬£¬£¬£¬£¬Ó¢ÍâÑó°ü¹«Ë¾Capita͸¶ÉÏÖÜÎåµÄЧÀÍÖÐÖ¹ÊÇÍøÂç¹¥»÷µ¼ÖµÄ¡£¡£¡£ ¡£¡£¡£CapitaÊÇÕþ¸®×î´óµÄ¹©Ó¦ÉÌÖ®Ò»£¬ £¬£¬£¬£¬£¬£¬ÓµÓÐ65ÒÚÓ¢°÷µÄ¹«¹²²¿·ÖÌõÔ¼¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾ÔÚÉùÃ÷ÖгÆ£¬ £¬£¬£¬£¬£¬£¬´Ë´ÎÊÂÎñÖ÷ÒªÓ°ÏìÁËÆäMicrosoft 365Ó¦ÓóÌÐòµÄÄÚ²¿»á¼û£¬ £¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö²¿·Ö¿Í»§Ð§ÀÍÖÐÖ¹¡£¡£¡£ ¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬£¬£¬ÊÂÎñÒÑ»ù±¾»ñµÃ¿ØÖÆ£¬ £¬£¬£¬£¬£¬£¬Ð§ÀÍÕýÔÚ»Ö¸´ÖС£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾Ã»ÓÐ͸¶ÓйظÃÊÂÎñµÄϸ½Ú£¬ £¬£¬£¬£¬£¬£¬µ«ÆäÓ°ÏìÅú×¢Õâ¿ÉÄÜÊÇÀÕË÷¹¥»÷¡£¡£¡£ ¡£¡£¡£


https://securityaffairs.com/144398/hacking/capita-suffered-cyber-incident.html


6¡¢Unit 42Ðû²¼¹ØÓÚ¶ñÒâÈí¼þCryptoClippyµÄÆÊÎö±¨¸æ


4ÔÂ5ÈÕ£¬ £¬£¬£¬£¬£¬£¬Unit 42Åû¶Á˶ñÒâÈí¼þCryptoClippyÕë¶ÔÆÏÌÑÑÀµÄ¹¥»÷»î¶¯¡£¡£¡£ ¡£¡£¡£¸Ã»î¶¯Ê¼ÓÚSEOÖж¾£¬ £¬£¬£¬£¬£¬£¬Ä¿µÄËÑË÷WhatsApp Webʱ£¬ £¬£¬£¬£¬£¬£¬Ð§¹û»á½«ËûÃÇÖ¸µ¼ÖÁ¹¥»÷ÕßµÄÓò£¬ £¬£¬£¬£¬£¬£¬È»ºóÏÂÔØ¶ñÒâÈí¼þ¡£¡£¡£ ¡£¡£¡£CryptoClippyÊÇ»ùÓÚCµÄ¿ÉÖ´ÐÐÎļþ£¬ £¬£¬£¬£¬£¬£¬Ëü»á¼àÊÓÄ¿µÄµÄ¼ôÌù°å£¬ £¬£¬£¬£¬£¬£¬Ñ°ÕÒ¸´ÖƼÓÃÜÇ®±ÒÇ®°üµØµãµÄÐÐΪ£¬ £¬£¬£¬£¬£¬£¬²¢Óù¥»÷ÕߵĵصãÌæ»»Óû§µÄÏÖʵµØµã¡£¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷±»¹¥»÷Õ߱鲼֯ÔìÒµ¡¢ITЧÀͺͷ¿µØ²úÐÐÒµ¡£¡£¡£ ¡£¡£¡£ÕâÖÖÍþв²¢²»Õë¶ÔÌØ¶¨ÐÐÒµ£¬ £¬£¬£¬£¬£¬£¬ÊÜÓ°Ïì×°±¸¶¼ÊÇÔâµ½ÁËʱ»úÖ÷ÒåµÄ¹¥»÷¡£¡£¡£ ¡£¡£¡£


https://unit42.paloaltonetworks.com/crypto-clipper-targets-portuguese-speakers/