Checkmarx¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©Ó¦Á´¹¥»÷

Ðû²¼Ê±¼ä 2023-07-25

1¡¢Checkmarx¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©Ó¦Á´¹¥»÷


CheckmarxÔÚ7ÔÂ21ÈÕ³ÆÆä¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©Ó¦Á´£¨OSS£©¹¥»÷¡£¡£¡£¡£¡£¡£µÚÒ»´Î¹¥»÷±¬·¢ÓÚ4ÔÂÉÏÑ®£¬£¬£¬£¬£¬¹¥»÷Õßð³äÄ¿µÄÒøÐÐÔ±¹¤£¬£¬£¬£¬£¬Ê¹ÓÃNPMƽ̨ÉÏ´«Á˼¸¸öÈí¼þ°ü£¬£¬£¬£¬£¬ÆäÖаüÀ¨Ô¤×°Öþ籾£¬£¬£¬£¬£¬¿ÉÔÚ×°ÖÃʱִÐжñÒâ»î¶¯¡£¡£¡£¡£¡£¡£»£»£» £»£»£» £»£»¹Ê¹ÓÃAzureµÄCDN×ÓÓòÀ´·Ö·¢µÚ¶þ½×¶ÎµÄpayload Havoc£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öC2¿ò¼Ü¡£¡£¡£¡£¡£¡£ÔÚ2Ô·ݼì²âµ½µÄÕë¶ÔÒøÐеÄÁíÒ»´Î¹¥»÷ÖУ¬£¬£¬£¬£¬¹¥»÷ÕßÒ²ÉÏ´«ÁËÒ»¸ö¶ñÒânpm°ü£¬£¬£¬£¬£¬Ö¼ÔÚ×èµ²µÇ¼Êý¾Ý²¢½«Æä·¢Ë͸ø¹¥»÷Õß¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÒѾ­±¨¸æ²¢É¾³ýÁËÕâЩ¶ñÒ⿪ԴÈí¼þ°ü¡£¡£¡£¡£¡£¡£


https://checkmarx.com/blog/first-known-targeted-oss-supply-chain-attacks-against-the-banking-sector/


2¡¢Apple¸üÐÂÐÞ¸´Òѱ»Ê¹ÓõÄÄÚºËÎó²îCVE-2023-38606 


¾ÝýÌå7ÔÂ24ÈÕ±¨µÀ£¬£¬£¬£¬£¬AppleÐû²¼ÁËÇå¾²¸üУ¬£¬£¬£¬£¬ÒÔÐÞ¸´Õë¶ÔiPhone¡¢MacºÍiPadµÄ¹¥»÷Öб»Ê¹ÓõÄÎó²î¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÄÚºËÎó²î£¨CVE-2023-38606£©£¬£¬£¬£¬£¬Äܹ»±»ÓÃÀ´¸Ä¶¯Ãô¸ÐµÄÄÚºË״̬£¬£¬£¬£¬£¬¿ÉÄÜÒÑÔÚiOS 15.7.1֮ǰÐû²¼µÄiOS°æ±¾Öб»Æð¾¢Ê¹Óᣡ£¡£¡£¡£¡£KasperskyÌåÏÖ£¬£¬£¬£¬£¬CVE-2023-38606ÊÇÁãµã»÷Îó²îʹÓÃÁ´µÄÒ»²¿·Ö£¬£¬£¬£¬£¬ÓÃÓÚͨ¹ýiMessageÎó²îÔÚiPhoneÉÏ×°ÖÃÌØ¹¤Èí¼þTriangulation¡£¡£¡£¡£¡£¡£ÕâÊÇAppleÔÚ½ñÄêÐÞ¸´µÄµÚʮһ¸öÒѱ»Ê¹ÓõÄÁãÈÕÎó²î¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/apple/apple-fixes-new-zero-day-used-in-attacks-against-iphones-macs/


3¡¢ClopʹÓÃMOVEitÎó²îµÄ¹¥»÷Ô¤¹À׬Ǯ7500ÍòÖÁ1ÒÚÃÀÔª


CovewareÔÚ7ÔÂ21ÈÕ͸¶£¬£¬£¬£¬£¬ClopʹÓÃMOVEitÎó²îµÄ´ó¹æÄ£Êý¾ÝÇÔÈ¡»î¶¯Ô¤¼Æ×¬Ç®¸ß´ï7500ÍòÖÁ1ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£ÔÚ2023ÄêQ2£¬£¬£¬£¬£¬½»Êê½ðµÄ±»¹¥»÷Ä¿µÄµÄÊýÄ¿ÒѽµÖÁ34%£¬£¬£¬£¬£¬´´ÏÂÀúʷеÍ£¬£¬£¬£¬£¬µ¼ÖÂÀÕË÷ÍÅ»ï¸Ä±äÕ½ÂÔÒÔ×êÓª¸ü¸ßµÄÀûÈ󡣡£¡£¡£¡£¡£CovewareÌåÏÖ£¬£¬£¬£¬£¬ClopÒѾ­¸Ä±äÁËÕ½ÂÔ£¬£¬£¬£¬£¬ÀÕË÷¸ü¸ßµÄÊê½ð£¬£¬£¬£¬£¬Ï£Íûͨ¹ý¼¸±Ê´ó¶î¸¶¿îÀ´Õ½Ê¤ÕûÌåϽµµÄÇéÐΡ£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ÖØ´óÐÔºÍ×Ô¶¯»¯Ë®Æ½µÍµÄÀÕË÷¹¥»÷µÄÓ°ÏìºÍ±¾Ç®×îС¡£¡£¡£¡£¡£¡£


https://www.coveware.com/blog/2023/7/21/ransom-monetization-rates-fall-to-record-low-despite-jump-in-average-ransom-payments


4¡¢Ñо¿Ö°Ô±Åû¶OpenMeetings¿ÉÐ®ÖÆÖÎÀíÔ±ÕÊ»§µÄÎó²î


¾Ý7ÔÂ21ÈÕ±¨µÀ£¬£¬£¬£¬£¬Ñо¿Ö°Ô±Åû¶ÁËApache OpenMeetingsÖеÄ3¸öÎó²îµÄϸ½Ú¡£¡£¡£¡£¡£¡£ÕâЩÎó²î»®·ÖΪÈõ¹þÏ£½ÏÁ¿Îó²î£¨CVE-2023-28936£©¡¢Í¨¹ýÔ¼Çë¹þÏ£¾ÙÐÐÎÞÏÞÖÆ»á¼ûµÄÎó²î£¨CVE-2023-29023£©ÒÔ¼°¿Õ×Ö½Ú×¢ÈëÎó²î(CVE-2023-29246£©£¬£¬£¬£¬£¬¿É±»×ÔÐÐ×¢²áÓû§£¨Ä¬ÈÏÆôÓã©ÓÃÀ´Ð®ÖÆÖÎÀíÔ±ÕÊ»§²¢Ô¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬ÕâЩÎó²îÒÑÔÚApache OpenMeetings 7.1.0°æ±¾ÖÐÐÞ¸´¡£¡£¡£¡£¡£¡£


https://www.securityweek.com/openmeetings-flaws-allow-hackers-to-hijack-instances-execute-code-on-servers/


5¡¢AhnLab·¢Ã÷ͨ¹ýMS-SQLЧÀÍÆ÷·Ö·¢PurpleFoxµÄ»î¶¯


7ÔÂ24ÈÕ£¬£¬£¬£¬£¬AhnLab³ÆÆä·¢Ã÷ÁËͨ¹ýÖÎÀí²»ÉÆµÄMS-SQLЧÀÍÆ÷·Ö·¢PurpleFoxµÄ»î¶¯¡£¡£¡£¡£¡£¡£¹¥»÷Ê×ÏÈͨ¹ýsqlservr.exeÖ´ÐÐPowerShell£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öÓëMS-SQLЧÀÍÆ÷Ïà¹ØµÄÀú³Ì¡£¡£¡£¡£¡£¡£µ±Ö´ÐÐÉÏÊöPowerShellʱ£¬£¬£¬£¬£¬½«ÏÂÔØ²¢¼ÓÔØÁíÒ»¸ö¾­ÓÉ»ìÏýµÄPowerShell¡£¡£¡£¡£¡£¡£ÆäÖаüÀ¨Ò»¸ö¹¥»÷Õß¿ª·¢µÄº¯ÊýMsiMake£¬£¬£¬£¬£¬¿ÉÏÂÔØÒ»¸öMSIÎļþ¡£¡£¡£¡£¡£¡£MSI°ü¸ü¸Ä×¢²á±íÏîÒÔʵÏÖ³¤ÆÚÐÔºÍȨÏÞÌáÉý¡£¡£¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬MSI°ü»áʵÑéÖØÆôϵͳ£¬£¬£¬£¬£¬½Ó×ÅSENSЧÀͻᱻִÐУ¬£¬£¬£¬£¬´Ó¶ø¼¤»î¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£


https://asec.ahnlab.com/en/55492/


6¡¢IBMÐû²¼¹ØÓÚ2023ÄêÊý¾Ýй¶±¾Ç®µÄÆÊÎö±¨¸æ


7ÔÂ24ÈÕ£¬£¬£¬£¬£¬IBMÐû²¼¹ØÓÚ2023ÄêÊý¾Ýй¶±¾Ç®µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¸Ã±¨¸æ¶Ô553¸ö×éÖ¯µÄÊý¾Ýй¶ÇéÐξÙÐÐÁËÆÊÎö£¬£¬£¬£¬£¬Ñо¿µÄÎ¥¹æÊÂÎñ±¬·¢ÔÚ2022Äê3ÔÂÖÁ2023Äê3Ô¡£¡£¡£¡£¡£¡£×îÐÂÑо¿ÏÔʾ£¬£¬£¬£¬£¬Êý¾Ýй¶±¾Ç®Ò»Á¬ÔöÌí£¬£¬£¬£¬£¬È«Çòƽ¾ù±¾Ç®¸ß´ï445ÍòÃÀÔª£¬£¬£¬£¬£¬ÈýÄêÄÚÔöÌíÁË15%¡£¡£¡£¡£¡£¡£Ò½ÁƱ£½¡ÐÐÒµµÄ±¾Ç®Î»¾Ó°ñÊ×£¬£¬£¬£¬£¬Ò»Á¬13Äê³ÉΪ±¾Ç®×î¸ßµÄÐÐÒµ¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬Çå¾²È˹¤ÖÇÄܺÍ×Ô¶¯»¯¡¢DevSecOpsÒªÁìºÍIRÍýÏëÔÚ½ÚÔ¼±¾Ç®·½ÃæÊ©Õ¹ÁËÖ÷µ¼×÷Ó㻣»£» £»£»£» £»£»È˹¤ÖÇÄܺÍASM¼ÓËÙÁËÎ¥¹æÊÂÎñµÄʶ±ðºÍ×èÖ¹£»£»£» £»£»£» £»£»µ±Êý¾Ý´æ´¢ÔÚ¶à¸öÇéÐÎÖÐʱ£¬£¬£¬£¬£¬±¾Ç®ºÜ¸ß£¬£¬£¬£¬£¬²¢ÇÒÐèÒª¸ü³¤Ê±¼ä²Å»ª×èֹΥ¹æÊÂÎñ£»£»£» £»£»£» £»£»ÓµÓз¢Ã÷Î¥¹æÊÂÎñµÄÄÚ²¿ÍŶӵÄ×éÖ¯ÔÚ¿ØÖƱ¾Ç®·½ÃæÌåÏֵøüºÃ¡£¡£¡£¡£¡£¡£


https://securityintelligence.com/posts/whats-new-2023-cost-of-a-data-breach-report/