Checkmarx¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©Ó¦Á´¹¥»÷

Ðû²¼Ê±¼ä 2023-07-25

1¡¢Checkmarx¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©Ó¦Á´¹¥»÷


CheckmarxÔÚ7ÔÂ21ÈÕ³ÆÆä¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©Ó¦Á´£¨OSS£©¹¥»÷¡£¡£¡£µÚÒ»´Î¹¥»÷±¬·¢ÓÚ4ÔÂÉÏÑ®£¬£¬£¬£¬£¬£¬¹¥»÷Õßð³äÄ¿µÄÒøÐÐÔ±¹¤£¬£¬£¬£¬£¬£¬Ê¹ÓÃNPMƽ̨ÉÏ´«Á˼¸¸öÈí¼þ°ü£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Ô¤×°Öþ籾£¬£¬£¬£¬£¬£¬¿ÉÔÚ×°ÖÃʱִÐжñÒâ»î¶¯¡£¡£¡£»£»¹Ê¹ÓÃAzureµÄCDN×ÓÓòÀ´·Ö·¢µÚ¶þ½×¶ÎµÄpayload Havoc£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öC2¿ò¼Ü¡£¡£¡£ÔÚ2Ô·ݼì²âµ½µÄÕë¶ÔÒøÐеÄÁíÒ»´Î¹¥»÷ÖУ¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒ²ÉÏ´«ÁËÒ»¸ö¶ñÒânpm°ü£¬£¬£¬£¬£¬£¬Ö¼ÔÚ×èµ²µÇ¼Êý¾Ý²¢½«Æä·¢Ë͸ø¹¥»÷Õß¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÒѾ­±¨¸æ²¢É¾³ýÁËÕâЩ¶ñÒ⿪ԴÈí¼þ°ü¡£¡£¡£


https://checkmarx.com/blog/first-known-targeted-oss-supply-chain-attacks-against-the-banking-sector/


2¡¢Apple¸üÐÂÐÞ¸´Òѱ»Ê¹ÓõÄÄÚºËÎó²îCVE-2023-38606 


¾ÝýÌå7ÔÂ24ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬AppleÐû²¼ÁËÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´Õë¶ÔiPhone¡¢MacºÍiPadµÄ¹¥»÷Öб»Ê¹ÓõÄÎó²î¡£¡£¡£ÕâÊÇÒ»¸öÄÚºËÎó²î£¨CVE-2023-38606£©£¬£¬£¬£¬£¬£¬Äܹ»±»ÓÃÀ´¸Ä¶¯Ãô¸ÐµÄÄÚºË״̬£¬£¬£¬£¬£¬£¬¿ÉÄÜÒÑÔÚiOS 15.7.1֮ǰÐû²¼µÄiOS°æ±¾Öб»Æð¾¢Ê¹Óᣡ£¡£KasperskyÌåÏÖ£¬£¬£¬£¬£¬£¬CVE-2023-38606ÊÇÁãµã»÷Îó²îʹÓÃÁ´µÄÒ»²¿·Ö£¬£¬£¬£¬£¬£¬ÓÃÓÚͨ¹ýiMessageÎó²îÔÚiPhoneÉÏ×°ÖÃÌØ¹¤Èí¼þTriangulation¡£¡£¡£ÕâÊÇAppleÔÚ½ñÄêÐÞ¸´µÄµÚʮһ¸öÒѱ»Ê¹ÓõÄÁãÈÕÎó²î¡£¡£¡£


https://www.bleepingcomputer.com/news/apple/apple-fixes-new-zero-day-used-in-attacks-against-iphones-macs/


3¡¢ClopʹÓÃMOVEitÎó²îµÄ¹¥»÷Ô¤¹À׬Ǯ7500ÍòÖÁ1ÒÚÃÀÔª


CovewareÔÚ7ÔÂ21ÈÕ͸¶£¬£¬£¬£¬£¬£¬ClopʹÓÃMOVEitÎó²îµÄ´ó¹æÄ£Êý¾ÝÇÔÈ¡»î¶¯Ô¤¼Æ×¬Ç®¸ß´ï7500ÍòÖÁ1ÒÚÃÀÔª¡£¡£¡£ÔÚ2023ÄêQ2£¬£¬£¬£¬£¬£¬½»Êê½ðµÄ±»¹¥»÷Ä¿µÄµÄÊýÄ¿ÒѽµÖÁ34%£¬£¬£¬£¬£¬£¬´´ÏÂÀúʷеÍ£¬£¬£¬£¬£¬£¬µ¼ÖÂÀÕË÷ÍÅ»ï¸Ä±äÕ½ÂÔÒÔ×êÓª¸ü¸ßµÄÀûÈ󡣡£¡£CovewareÌåÏÖ£¬£¬£¬£¬£¬£¬ClopÒѾ­¸Ä±äÁËÕ½ÂÔ£¬£¬£¬£¬£¬£¬ÀÕË÷¸ü¸ßµÄÊê½ð£¬£¬£¬£¬£¬£¬Ï£Íûͨ¹ý¼¸±Ê´ó¶î¸¶¿îÀ´Õ½Ê¤ÕûÌåϽµµÄÇéÐΡ£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ÖØ´óÐÔºÍ×Ô¶¯»¯Ë®Æ½µÍµÄÀÕË÷¹¥»÷µÄÓ°ÏìºÍ±¾Ç®×îС¡£¡£¡£


https://www.coveware.com/blog/2023/7/21/ransom-monetization-rates-fall-to-record-low-despite-jump-in-average-ransom-payments


4¡¢Ñо¿Ö°Ô±Åû¶OpenMeetings¿ÉÐ®ÖÆÖÎÀíÔ±ÕÊ»§µÄÎó²î


¾Ý7ÔÂ21ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±Åû¶ÁËApache OpenMeetingsÖеÄ3¸öÎó²îµÄϸ½Ú¡£¡£¡£ÕâЩÎó²î»®·ÖΪÈõ¹þÏ£½ÏÁ¿Îó²î£¨CVE-2023-28936£©¡¢Í¨¹ýÔ¼Çë¹þÏ£¾ÙÐÐÎÞÏÞÖÆ»á¼ûµÄÎó²î£¨CVE-2023-29023£©ÒÔ¼°¿Õ×Ö½Ú×¢ÈëÎó²î(CVE-2023-29246£©£¬£¬£¬£¬£¬£¬¿É±»×ÔÐÐ×¢²áÓû§£¨Ä¬ÈÏÆôÓã©ÓÃÀ´Ð®ÖÆÖÎÀíÔ±ÕÊ»§²¢Ô¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬ÕâЩÎó²îÒÑÔÚApache OpenMeetings 7.1.0°æ±¾ÖÐÐÞ¸´¡£¡£¡£


https://www.securityweek.com/openmeetings-flaws-allow-hackers-to-hijack-instances-execute-code-on-servers/


5¡¢AhnLab·¢Ã÷ͨ¹ýMS-SQLЧÀÍÆ÷·Ö·¢PurpleFoxµÄ»î¶¯


7ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬AhnLab³ÆÆä·¢Ã÷ÁËͨ¹ýÖÎÀí²»ÉÆµÄMS-SQLЧÀÍÆ÷·Ö·¢PurpleFoxµÄ»î¶¯¡£¡£¡£¹¥»÷Ê×ÏÈͨ¹ýsqlservr.exeÖ´ÐÐPowerShell£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öÓëMS-SQLЧÀÍÆ÷Ïà¹ØµÄÀú³Ì¡£¡£¡£µ±Ö´ÐÐÉÏÊöPowerShellʱ£¬£¬£¬£¬£¬£¬½«ÏÂÔØ²¢¼ÓÔØÁíÒ»¸ö¾­ÓÉ»ìÏýµÄPowerShell¡£¡£¡£ÆäÖаüÀ¨Ò»¸ö¹¥»÷Õß¿ª·¢µÄº¯ÊýMsiMake£¬£¬£¬£¬£¬£¬¿ÉÏÂÔØÒ»¸öMSIÎļþ¡£¡£¡£MSI°ü¸ü¸Ä×¢²á±íÏîÒÔʵÏÖ³¤ÆÚÐÔºÍȨÏÞÌáÉý¡£¡£¡£×îºó£¬£¬£¬£¬£¬£¬MSI°ü»áʵÑéÖØÆôϵͳ£¬£¬£¬£¬£¬£¬½Ó×ÅSENSЧÀͻᱻִÐУ¬£¬£¬£¬£¬£¬´Ó¶ø¼¤»î¶ñÒâÈí¼þ¡£¡£¡£


https://asec.ahnlab.com/en/55492/


6¡¢IBMÐû²¼¹ØÓÚ2023ÄêÊý¾Ýй¶±¾Ç®µÄÆÊÎö±¨¸æ


7ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬IBMÐû²¼¹ØÓÚ2023ÄêÊý¾Ýй¶±¾Ç®µÄÆÊÎö±¨¸æ¡£¡£¡£¸Ã±¨¸æ¶Ô553¸ö×éÖ¯µÄÊý¾Ýй¶ÇéÐξÙÐÐÁËÆÊÎö£¬£¬£¬£¬£¬£¬Ñо¿µÄÎ¥¹æÊÂÎñ±¬·¢ÔÚ2022Äê3ÔÂÖÁ2023Äê3Ô¡£¡£¡£×îÐÂÑо¿ÏÔʾ£¬£¬£¬£¬£¬£¬Êý¾Ýй¶±¾Ç®Ò»Á¬ÔöÌí£¬£¬£¬£¬£¬£¬È«Çòƽ¾ù±¾Ç®¸ß´ï445ÍòÃÀÔª£¬£¬£¬£¬£¬£¬ÈýÄêÄÚÔöÌíÁË15%¡£¡£¡£Ò½ÁƱ£½¡ÐÐÒµµÄ±¾Ç®Î»¾Ó°ñÊ×£¬£¬£¬£¬£¬£¬Ò»Á¬13Äê³ÉΪ±¾Ç®×î¸ßµÄÐÐÒµ¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬Çå¾²È˹¤ÖÇÄܺÍ×Ô¶¯»¯¡¢DevSecOpsÒªÁìºÍIRÍýÏëÔÚ½ÚÔ¼±¾Ç®·½ÃæÊ©Õ¹ÁËÖ÷µ¼×÷Ó㻣»È˹¤ÖÇÄܺÍASM¼ÓËÙÁËÎ¥¹æÊÂÎñµÄʶ±ðºÍ×èÖ¹£»£»µ±Êý¾Ý´æ´¢ÔÚ¶à¸öÇéÐÎÖÐʱ£¬£¬£¬£¬£¬£¬±¾Ç®ºÜ¸ß£¬£¬£¬£¬£¬£¬²¢ÇÒÐèÒª¸ü³¤Ê±¼ä²Å»ª×èֹΥ¹æÊÂÎñ£»£»ÓµÓз¢Ã÷Î¥¹æÊÂÎñµÄÄÚ²¿ÍŶӵÄ×éÖ¯ÔÚ¿ØÖƱ¾Ç®·½ÃæÌåÏֵøüºÃ¡£¡£¡£


https://securityintelligence.com/posts/whats-new-2023-cost-of-a-data-breach-report/