GoogleÐû²¼ChromeµÄ¸üУ¬£¬£¬£¬ £¬£¬×ܼÆÐÞ¸´15¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2023-05-05

1¡¢GoogleÐû²¼ChromeµÄ¸üУ¬£¬£¬£¬ £¬£¬×ܼÆÐÞ¸´15¸öÇå¾²Îó²î


5ÔÂ2ÈÕ£¬£¬£¬£¬ £¬£¬GoogleÐû²¼ÁËChrome 113Çå¾²¸üУ¬£¬£¬£¬ £¬£¬×ܼÆÐÞ¸´ÁË15¸öÎó²î¡£¡£¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇÌáÐÑÖеÄÖ´Ðв»µ±Îó²î£¨CVE-2023-2459£©¡¢À©Õ¹ÖеĶԲ»ÐÅÈεÄÊäÈëÑé֤ȱ·¦£¨CVE-2023-2460£©¡¢²Ù×÷ϵͳÊäÈëÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2023-2461£©ºÍCORSÖеÄÖ´Ðв»µ±£¨CVE-2023-2465£©µÈ¡£¡£¡£¡£¡£ÓëÍù³£Ò»Ñù£¬£¬£¬£¬ £¬£¬ÔÚ´ó´ó¶¼Óû§¸üÐÂÐÞ¸´³ÌÐò֮ǰ£¬£¬£¬£¬ £¬£¬GoogleûÓÐ͸¶¹ØÓÚÕâЩÎó²îµÄ¸ü¶àϸ½Ú¡£¡£¡£¡£¡£


https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop.html


2¡¢OrqaµÄ¹Ì¼þ±»Ö²Èë¶ñÒâ´úÂë¿Éµ¼ÖÂ×°±¸·ºÆð¹ÊÕÏ


¾ÝýÌå5ÔÂ3ÈÕ±¨µÀ£¬£¬£¬£¬ £¬£¬FPVÎÞÈË»ú»¤Ä¿¾µÖÆÔìÉÌOrqa³Æ£¬£¬£¬£¬ £¬£¬Ò»¼Ò³Ð°üÉ̽«´úÂëÖ²ÈëÆä¹Ì¼þÖУ¬£¬£¬£¬ £¬£¬µ¼ÖÂ×°±¸·ºÆð¹ÊÕÏ¡£¡£¡£¡£¡£ÉÏÖÜÁù£¬£¬£¬£¬ £¬£¬Orqa¿Í»§±¨¸æ£¬£¬£¬£¬ £¬£¬ËûÃǵÄFPV.One V1»¤Ä¿¾µ½øÈëÆô¶¯³ÌÐòģʽ£¬£¬£¬£¬ £¬£¬±äµÃÎÞ·¨Ê¹Óᣡ£¡£¡£¡£¸Ã¹«Ë¾Í¸Â¶£¬£¬£¬£¬ £¬£¬Õâ¸öÎÊÌâÊÇÓÉ"ÈÕÆÚ/ʱ¼ä¹¦Ð§ÒýÆðµÄ"¹Ì¼þ¹ýʧµ¼ÖµÄ¡£¡£¡£¡£¡£¸ÃÎÊÌâÔ´ÓÚÒ»¸öÀÕË÷Èí¼þµÄ׼ʱըµ¯£¬£¬£¬£¬ £¬£¬Õâ¸öÕ¨µ¯ÊǼ¸ÄêǰÓÉÒ»¸öǰ³Ð°üÉÌÉñÃØÖ²ÈëÆäÖ¸µ¼³ÌÐòÖеÄ£¬£¬£¬£¬ £¬£¬Ö¼ÔÚÏò¹«Ë¾Ë÷È¡¸ß¶îÊê½ð¡£¡£¡£¡£¡£¸Ã³Ð°üÉÌ»¹Ðû²¼ÁËÒ»¸öδ¾­ÊÚȨµÄ¶þ½øÖÆÎļþ£¬£¬£¬£¬ £¬£¬¾Ý³Æ¿ÉÒÔ½â¾ö¸ÃÎÊÌâ¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬ £¬£¬OrqaÌáÐѿͻ§²»Òª×°Ö÷ǹٷ½¹Ì¼þ¡£¡£¡£¡£¡£²¢Í¸Â¶Ö»ÓÐһС²¿·Ö´úÂëÊܵ½ÕâÖÖ¶ñÒâÈí¼þµÄÓ°Ï죬£¬£¬£¬ £¬£¬ÏÖÔÚÕýÔÚÐÞ¸´ÖС£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/technology/drone-goggles-maker-claims-firmware-sabotaged-to-brick-devices/


3¡¢AvosÍÅ»ïÐ®ÖÆ²¼Â¬·Æ¶ûµÂ´óѧµÄ½ôÆÈ¾¯±¨ÏµÍ³RamAlert


¾Ý5ÔÂ4ÈÕ±¨µÀ£¬£¬£¬£¬ £¬£¬ÀÕË÷ÍÅ»ïAvosÐ®ÖÆÁ˲¼Â¬·Æ¶ûµÂ´óѧµÄ½ôÆÈ¾¯±¨ÏµÍ³¡°RamAlert¡±¡£¡£¡£¡£¡£4ÔÂ30ÈÕ£¬£¬£¬£¬ £¬£¬¸ÃУÏòѧÉúºÍ½ÌÖ°¹¤Í¸Â¶£¬£¬£¬£¬ £¬£¬ËûÃǵÄITϵͳÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬ £¬£¬ËùÓп¼ÊÔ±»ÆÈÍÆ³Ù¡£¡£¡£¡£¡£Æäʱ£¬£¬£¬£¬ £¬£¬Ñ§Ð£Éù³ÆÃ»ÓÐÓë´ËÊÂÎñÏà¹ØµÄ½ðÈÚڲƭ»òÉí·ÝµÁÓð¸¼þ£¬£¬£¬£¬ £¬£¬Î÷ϯºÍѧÉúÈÔ¿ÉÒÔͨ¹ýÍøÕ¾Çå¾²µØÊ¹Óúͻá¼ûMyBU¡¢CanvasºÍͼÊé¹Ý×ÊÔ´¡£¡£¡£¡£¡£µ«ÊÂÎñÔÚ5ÔÂ1ÈÕ±¬·¢×ªÕÛ£¬£¬£¬£¬ £¬£¬Avos¿ÉÒÔ»á¼ûѧУµÄ½ôÆÈ¾¯±¨ÏµÍ³RamAlert£¬£¬£¬£¬ £¬£¬²¢Í¨¹ý¸ÃϵͳÏòѧÉúºÍ½ÌÖ°¹¤·¢ËͶÌÐźÍÓʼþ¾¯±¨£¬£¬£¬£¬ £¬£¬³ÆÒÑÇÔÈ¡1.2 TBÎļþ£¬£¬£¬£¬ £¬£¬²¢ÍþвÈôÊDz»¸¶Êê½ð½«Ðû²¼ËùÓÐÊý¾Ý¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/ransomware-gang-hijacks-university-alert-system-to-issue-threats/


4¡¢SophosÅû¶Dragon BreathÈÆ¹ý¼ì²âµÄÐÂÊÖÒÕµÄϸ½Ú


5ÔÂ3ÈÕ£¬£¬£¬£¬ £¬£¬SophosÅû¶ÁËDragon Breathͨ¹ýË«DLL²à¼ÓÔØÊÖÒÕÀ´Èƹý¼ì²âµÄ·½·¨¡£¡£¡£¡£¡£ÕâЩ¹¥»÷ʹÓÃÁËÒ»¸öÇå½àµÄÓ¦ÓóÌÐò£¬£¬£¬£¬ £¬£¬×î³£¼ûµÄÊÇTelegram£¬£¬£¬£¬ £¬£¬Ëü²à¼ÓÔØÒ»¸öµÚ¶þ½×¶Îpayload£¬£¬£¬£¬ £¬£¬ÓÐʱҲÊÇÇå½àµÄ£¬£¬£¬£¬ £¬£¬È»ºóÓÖ²à¼ÓÔØÒ»¸ö¶ñÒâÈí¼þ¼ÓÔØ³ÌÐòDLL¡£¡£¡£¡£¡£×îÖÕpayload DLL´ÓÒ»¸ötxtÎļþ£¨'templateX.txt'£©ÖнâÃܲ¢ÔÚϵͳÖÐÖ´ÐС£¡£¡£¡£¡£ÕâÊÇÒ»¸öºóÃÅ£¬£¬£¬£¬ £¬£¬Ö§³Ö¶à¸öÏÂÁ£¬£¬£¬ £¬£¬ÈçÏµÍ³ÖØÆô¡¢×¢²á±íÏîÐ޸ĺÍÔÚÒþ²ØµÄCMD´°¿ÚÉÏÖ´ÐÐÏÂÁîµÈ£¬£¬£¬£¬ £¬£¬Ëü»¹Õë¶ÔMetaMask¼ÓÃÜÇ®±ÒÇ®°üChromeÀ©Õ¹¡£¡£¡£¡£¡£¸Ã»î¶¯µÄÖ÷ÒªÕë¶ÔÈÕ±¾¡¢Öйų́Íå¡¢ÐÂ¼ÓÆÂ¡¢ÖйúÏã¸ÛºÍ·ÆÂɱöµÈµØ¡£¡£¡£¡£¡£


https://news.sophos.com/en-us/2023/05/03/doubled-dll-sideloading-dragon-breath/


5¡¢Meta¼ì²âµ½NodeStealerºÍ¶à¸öð³äChatGPTµÄ¶ñÒâÈí¼þ


5ÔÂ3ÈÕ£¬£¬£¬£¬ £¬£¬Meta³ÆÆä·¢Ã÷Ducktail¡¢NodeStealerºÍð³äChatGPTµÈ¹¤¾ßµÄ¶ñÒâÈí¼þµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£×Ô3ÔÂÒÔÀ´£¬£¬£¬£¬ £¬£¬Meta¾Í·¢Ã÷ÁËÔ¼10¸ö¶ñÒâÈí¼þ¼Ò×åʹÓÃChatGPTµÈÀàËÆÖ÷ÌâÈëÇÖÍøÂçÉϵÄÕÊ»§¡£¡£¡£¡£¡£1ÔÂÏÂÑ®£¬£¬£¬£¬ £¬£¬Ñо¿Ö°Ô±Ê״η¢Ã÷ÁËNodeStealer¶ñÒâÈí¼þ£¬£¬£¬£¬ £¬£¬²¢½«Æä¹éÒòÓÚÔ½ÄϵĹ¥»÷Õߣ¬£¬£¬£¬ £¬£¬VirusTotalÉÏÏÕЩËùÓÐAVÒýÇæ¶¼Î´Äܽ«Æä±ê¼ÇΪ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÖ÷ÒªÇÔÈ¡´æ´¢ÔÚChromiumä¯ÀÀÆ÷£¨ÈçChromeºÍEdge£©ÖеÄFacebook¡¢GmailºÍOutlookµÄcookieºÍÕÊ»§Æ¾Ö¤¡£¡£¡£¡£¡£FacebookÒÑÏòÓò×¢²áÉ̱¨¸æÁ˹¥»÷ÕßµÄЧÀÍÆ÷£¬£¬£¬£¬ £¬£¬²¢ÓÚ1ÔÂ25ÈÕ½«Æä¹Ø±Õ¡£¡£¡£¡£¡£


https://engineering.fb.com/2023/05/03/security/malware-nodestealer-ducktail/


6¡¢Trend MicroÐû²¼Earth Longzhi¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ


Trend MicroÔÚ5ÔÂ2ÈÕÐû²¼Á˹ØÓÚEarth Longzhi¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¸Ã»î¶¯Ö÷ÒªÕë¶ÔÖйų́Í塢̩¹ú¡¢·ÆÂɱöºÍ쳼õÄÕþ¸®¡¢Ò½ÁƱ£½¡¡¢ÊÖÒÕºÍÖÆÔìÏà¹Ø×éÖ¯¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃWindows Defender¿ÉÖ´ÐÐÎļþÀ´Ö´ÐÐDLL²à¼ÓÔØ£¬£¬£¬£¬ £¬£¬Í¬Ê±»¹Ê¹ÓÃÁËÒ»¸öÒ×Êܹ¥»÷µÄÇý¶¯³ÌÐòzamguard64.sys£¬£¬£¬£¬ £¬£¬Í¨¹ý×Ô´øÒ×Êܹ¥»÷µÄÇý¶¯³ÌÐò£¨BYOVD£©À´½ûÓÃÖ÷»úÉϵÄÇå¾²²úÆ·¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬Earth Longzhi»¹Ê¹ÓÃÁËÒ»ÖÖÐµķ½·¨À´½ûÓÃÇå¾²²úÆ·£¬£¬£¬£¬ £¬£¬Í¨¹ýͼÏñÎļþÖ´ÐÐÑ¡ÏIFEO£©µÄ "stack rumbling"£¬£¬£¬£¬ £¬£¬ÕâÊÇÒ»ÖÖеÄDoSÊÖÒÕ¡£¡£¡£¡£¡£ 


https://www.trendmicro.com/en_us/research/23/e/attack-on-security-titans-earth-longzhi-returns-with-new-tricks.html