Checkmarx¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©Ó¦Á´¹¥»÷

Ðû²¼Ê±¼ä 2023-07-25

1¡¢Checkmarx¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©Ó¦Á´¹¥»÷


CheckmarxÔÚ7ÔÂ21ÈÕ³ÆÆä¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©Ó¦Á´£¨OSS£©¹¥»÷¡£¡£¡£¡£µÚÒ»´Î¹¥»÷±¬·¢ÓÚ4ÔÂÉÏÑ®£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßð³äÄ¿µÄÒøÐÐÔ±¹¤£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃNPMƽ̨ÉÏ´«Á˼¸¸öÈí¼þ°ü£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Ô¤×°Öþ籾£¬£¬£¬£¬£¬£¬£¬¿ÉÔÚ×°ÖÃʱִÐжñÒâ»î¶¯¡£¡£¡£¡£»£» £»£»¹Ê¹ÓÃAzureµÄCDN×ÓÓòÀ´·Ö·¢µÚ¶þ½×¶ÎµÄpayload Havoc£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öC2¿ò¼Ü¡£¡£¡£¡£ÔÚ2Ô·ݼì²âµ½µÄÕë¶ÔÒøÐеÄÁíÒ»´Î¹¥»÷ÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒ²ÉÏ´«ÁËÒ»¸ö¶ñÒânpm°ü£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ×èµ²µÇ¼Êý¾Ý²¢½«Æä·¢Ë͸ø¹¥»÷Õß¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÒѾ­±¨¸æ²¢É¾³ýÁËÕâЩ¶ñÒ⿪ԴÈí¼þ°ü¡£¡£¡£¡£


https://checkmarx.com/blog/first-known-targeted-oss-supply-chain-attacks-against-the-banking-sector/


2¡¢Apple¸üÐÂÐÞ¸´Òѱ»Ê¹ÓõÄÄÚºËÎó²îCVE-2023-38606 


¾ÝýÌå7ÔÂ24ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬AppleÐû²¼ÁËÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´Õë¶ÔiPhone¡¢MacºÍiPadµÄ¹¥»÷Öб»Ê¹ÓõÄÎó²î¡£¡£¡£¡£ÕâÊÇÒ»¸öÄÚºËÎó²î£¨CVE-2023-38606£©£¬£¬£¬£¬£¬£¬£¬Äܹ»±»ÓÃÀ´¸Ä¶¯Ãô¸ÐµÄÄÚºË״̬£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜÒÑÔÚiOS 15.7.1֮ǰÐû²¼µÄiOS°æ±¾Öб»Æð¾¢Ê¹Óᣡ£¡£¡£KasperskyÌåÏÖ£¬£¬£¬£¬£¬£¬£¬CVE-2023-38606ÊÇÁãµã»÷Îó²îʹÓÃÁ´µÄÒ»²¿·Ö£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚͨ¹ýiMessageÎó²îÔÚiPhoneÉÏ×°ÖÃÌØ¹¤Èí¼þTriangulation¡£¡£¡£¡£ÕâÊÇAppleÔÚ½ñÄêÐÞ¸´µÄµÚʮһ¸öÒѱ»Ê¹ÓõÄÁãÈÕÎó²î¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/apple/apple-fixes-new-zero-day-used-in-attacks-against-iphones-macs/


3¡¢ClopʹÓÃMOVEitÎó²îµÄ¹¥»÷Ô¤¹À׬Ǯ7500ÍòÖÁ1ÒÚÃÀÔª


CovewareÔÚ7ÔÂ21ÈÕ͸¶£¬£¬£¬£¬£¬£¬£¬ClopʹÓÃMOVEitÎó²îµÄ´ó¹æÄ£Êý¾ÝÇÔÈ¡»î¶¯Ô¤¼Æ×¬Ç®¸ß´ï7500ÍòÖÁ1ÒÚÃÀÔª¡£¡£¡£¡£ÔÚ2023ÄêQ2£¬£¬£¬£¬£¬£¬£¬½»Êê½ðµÄ±»¹¥»÷Ä¿µÄµÄÊýÄ¿ÒѽµÖÁ34%£¬£¬£¬£¬£¬£¬£¬´´ÏÂÀúʷеÍ£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÀÕË÷ÍÅ»ï¸Ä±äÕ½ÂÔÒÔ×êÓª¸ü¸ßµÄÀûÈ󡣡£¡£¡£CovewareÌåÏÖ£¬£¬£¬£¬£¬£¬£¬ClopÒѾ­¸Ä±äÁËÕ½ÂÔ£¬£¬£¬£¬£¬£¬£¬ÀÕË÷¸ü¸ßµÄÊê½ð£¬£¬£¬£¬£¬£¬£¬Ï£Íûͨ¹ý¼¸±Ê´ó¶î¸¶¿îÀ´Õ½Ê¤ÕûÌåϽµµÄÇéÐΡ£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÖØ´óÐÔºÍ×Ô¶¯»¯Ë®Æ½µÍµÄÀÕË÷¹¥»÷µÄÓ°ÏìºÍ±¾Ç®×îС¡£¡£¡£¡£


https://www.coveware.com/blog/2023/7/21/ransom-monetization-rates-fall-to-record-low-despite-jump-in-average-ransom-payments


4¡¢Ñо¿Ö°Ô±Åû¶OpenMeetings¿ÉÐ®ÖÆÖÎÀíÔ±ÕÊ»§µÄÎó²î


¾Ý7ÔÂ21ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±Åû¶ÁËApache OpenMeetingsÖеÄ3¸öÎó²îµÄϸ½Ú¡£¡£¡£¡£ÕâЩÎó²î»®·ÖΪÈõ¹þÏ£½ÏÁ¿Îó²î£¨CVE-2023-28936£©¡¢Í¨¹ýÔ¼Çë¹þÏ£¾ÙÐÐÎÞÏÞÖÆ»á¼ûµÄÎó²î£¨CVE-2023-29023£©ÒÔ¼°¿Õ×Ö½Ú×¢ÈëÎó²î(CVE-2023-29246£©£¬£¬£¬£¬£¬£¬£¬¿É±»×ÔÐÐ×¢²áÓû§£¨Ä¬ÈÏÆôÓã©ÓÃÀ´Ð®ÖÆÖÎÀíÔ±ÕÊ»§²¢Ô¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬ÕâЩÎó²îÒÑÔÚApache OpenMeetings 7.1.0°æ±¾ÖÐÐÞ¸´¡£¡£¡£¡£


https://www.securityweek.com/openmeetings-flaws-allow-hackers-to-hijack-instances-execute-code-on-servers/


5¡¢AhnLab·¢Ã÷ͨ¹ýMS-SQLЧÀÍÆ÷·Ö·¢PurpleFoxµÄ»î¶¯


7ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬£¬AhnLab³ÆÆä·¢Ã÷ÁËͨ¹ýÖÎÀí²»ÉÆµÄMS-SQLЧÀÍÆ÷·Ö·¢PurpleFoxµÄ»î¶¯¡£¡£¡£¡£¹¥»÷Ê×ÏÈͨ¹ýsqlservr.exeÖ´ÐÐPowerShell£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öÓëMS-SQLЧÀÍÆ÷Ïà¹ØµÄÀú³Ì¡£¡£¡£¡£µ±Ö´ÐÐÉÏÊöPowerShellʱ£¬£¬£¬£¬£¬£¬£¬½«ÏÂÔØ²¢¼ÓÔØÁíÒ»¸ö¾­ÓÉ»ìÏýµÄPowerShell¡£¡£¡£¡£ÆäÖаüÀ¨Ò»¸ö¹¥»÷Õß¿ª·¢µÄº¯ÊýMsiMake£¬£¬£¬£¬£¬£¬£¬¿ÉÏÂÔØÒ»¸öMSIÎļþ¡£¡£¡£¡£MSI°ü¸ü¸Ä×¢²á±íÏîÒÔʵÏÖ³¤ÆÚÐÔºÍȨÏÞÌáÉý¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬£¬£¬MSI°ü»áʵÑéÖØÆôϵͳ£¬£¬£¬£¬£¬£¬£¬½Ó×ÅSENSЧÀͻᱻִÐУ¬£¬£¬£¬£¬£¬£¬´Ó¶ø¼¤»î¶ñÒâÈí¼þ¡£¡£¡£¡£


https://asec.ahnlab.com/en/55492/


6¡¢IBMÐû²¼¹ØÓÚ2023ÄêÊý¾Ýй¶±¾Ç®µÄÆÊÎö±¨¸æ


7ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬£¬IBMÐû²¼¹ØÓÚ2023ÄêÊý¾Ýй¶±¾Ç®µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¸Ã±¨¸æ¶Ô553¸ö×éÖ¯µÄÊý¾Ýй¶ÇéÐξÙÐÐÁËÆÊÎö£¬£¬£¬£¬£¬£¬£¬Ñо¿µÄÎ¥¹æÊÂÎñ±¬·¢ÔÚ2022Äê3ÔÂÖÁ2023Äê3Ô¡£¡£¡£¡£×îÐÂÑо¿ÏÔʾ£¬£¬£¬£¬£¬£¬£¬Êý¾Ýй¶±¾Ç®Ò»Á¬ÔöÌí£¬£¬£¬£¬£¬£¬£¬È«Çòƽ¾ù±¾Ç®¸ß´ï445ÍòÃÀÔª£¬£¬£¬£¬£¬£¬£¬ÈýÄêÄÚÔöÌíÁË15%¡£¡£¡£¡£Ò½ÁƱ£½¡ÐÐÒµµÄ±¾Ç®Î»¾Ó°ñÊ×£¬£¬£¬£¬£¬£¬£¬Ò»Á¬13Äê³ÉΪ±¾Ç®×î¸ßµÄÐÐÒµ¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬Çå¾²È˹¤ÖÇÄܺÍ×Ô¶¯»¯¡¢DevSecOpsÒªÁìºÍIRÍýÏëÔÚ½ÚÔ¼±¾Ç®·½ÃæÊ©Õ¹ÁËÖ÷µ¼×÷Ó㻣» £»£»È˹¤ÖÇÄܺÍASM¼ÓËÙÁËÎ¥¹æÊÂÎñµÄʶ±ðºÍ×èÖ¹£»£» £»£»µ±Êý¾Ý´æ´¢ÔÚ¶à¸öÇéÐÎÖÐʱ£¬£¬£¬£¬£¬£¬£¬±¾Ç®ºÜ¸ß£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÐèÒª¸ü³¤Ê±¼ä²Å»ª×èֹΥ¹æÊÂÎñ£»£» £»£»ÓµÓз¢Ã÷Î¥¹æÊÂÎñµÄÄÚ²¿ÍŶӵÄ×éÖ¯ÔÚ¿ØÖƱ¾Ç®·½ÃæÌåÏֵøüºÃ¡£¡£¡£¡£


https://securityintelligence.com/posts/whats-new-2023-cost-of-a-data-breach-report/