ºÚ¿ÍʹÓþɰæMS ExcelÎó²îÈö²¥¶ñÒâÈí¼þAgent Tesla
Ðû²¼Ê±¼ä 2023-12-221. ºÚ¿ÍʹÓþɰæMS ExcelÎó²îÈö²¥¶ñÒâÈí¼þAgent Tesla
21ÈÕýÌ屨µÀ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÕýÔÚʹÓÃ¾ÉµÄ Microsoft Office Îó²îÀ´Èö²¥ÃûΪAgent TeslaµÄ¶ñÒâÈí¼þ¡£¡£¡£ÒÔ·¢Æ±ÎªÖ÷ÌâµÄÐÂÎÅÖи½¼ÓµÄÓÕ¶ü Excel ÎĵµÀ´ÓÕÆÇ±ÔÚÄ¿µÄ·¿ªËüÃDz¢Ê¹ÓÃCVE-2017-11882£¨CVSS ÆÀ·Ö£º7.8£©£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇ Office ¹«Ê½±à¼Æ÷ÖеÄÄÚ´æËð»µÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܻᵼÖ´úÂëÒÔÓû§È¨ÏÞÖ´ÐС£¡£¡£Agent TeslaÊÇÒ»ÖÖ»ùÓÚ .NET µÄ¸ß¼¶¼üÅ̼ͼÆ÷ºÍÔ¶³Ì»á¼ûľÂí (RAT)£¬£¬£¬£¬£¬£¬£¬£¬Äܹ»´ÓÊÜѬȾµÄÖ÷»ú»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£È»ºóÌáÈ¡ÍøÂçµÄÊý¾Ý¡£¡£¡£
https://thehackernews.com/2023/12/hackers-exploiting-old-ms-excel.html
2. FBI³ÆÀÕË÷ÍÅ»ïPlayÔÚ17¸öÔÂÄÚ·¢¶¯Á˽ü300´Î¹¥»÷»î¶¯
¾ÝýÌå19ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬½ñÄêÕë¶ÔÃÀ¹úÊÐÕþЧÀ͵ðÆÆËðÐÔ¹¥»÷Ö»ÊÇÀÕË÷ÍÅ»ï Play µÄ±ùɽһ½Ç£¬£¬£¬£¬£¬£¬£¬£¬¾Ý FBI ³Æ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïÔÚ 17 ¸öÔÂÄÚÏ®»÷Á˽ü 300 ¸ö×éÖ¯¡£¡£¡£¸Ã×éÖ¯£¨Ò²³ÆÎª Playcrypt£©Ó°ÏìÁ˱±ÃÀ¡¢ÄÏÃÀºÍÅ·ÖÞµÄÆÕ±éÆóÒµºÍÒªº¦»ù´¡ÉèÊ©¡£¡£¡£Play ÀÕË÷Èí¼þ¹¥»÷Õß½ÓÄÉË«ÖØÀÕË÷Ä£×Ó£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÇÔÈ¡Êý¾Ýºó¶Ôϵͳ¾ÙÐмÓÃÜ¡£¡£¡£Êê½ðƱ¾Ý²»°üÀ¨×î³õµÄÊê½ðÒªÇó»ò¸¶¿î˵Ã÷£¬£¬£¬£¬£¬£¬£¬£¬¶øÊÇָʾÊܺ¦Õßͨ¹ýµç×ÓÓʼþÁªÏµÍþвÐÐΪÕß¡£¡£¡£
https://www.scmagazine.com/news/play-ransomware-gang-tied-to-300-attacks-in-17-months
3. Çå¾²Ñо¿Ö°Ô±·¢Ã÷25%µÄ¸ßΣÎó²îÔÚÐû²¼È·µ±Ìì¾Í±»Ê¹ÓÃ
19ÈÕýÌ屨µÀÖУ¬£¬£¬£¬£¬£¬£¬£¬ÔÚQualysÐû²¼µÄÑо¿²©¿ÍÖУ¬£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËһЩÓëÒÑÍùÒ»Ä걨¸æµÄ³£¼ûÎó²îºÍCVEÐû²¼Ïà¹ØµÄÇ÷ÊÆ¡£¡£¡£³ýÁ˺ڿÍʹÓÃÒÑÖªÎó²îµÄËÙÂÊÖ®Í⣬£¬£¬£¬£¬£¬£¬£¬±¨¸æ»¹Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬2023 Ä꣨Æù½ñΪֹ£©±¨¸æµÄ¸ßΣº¦Îó²îÖÐÓÐ 97 ¸ö¿ÉÄÜÒѱ»Ê¹Ó㬣¬£¬£¬£¬£¬£¬£¬µ«´Óδ·ºÆðÔÚ CISA µÄÒÑÖª¿ÉʹÓÃÎó²î (KEV) Ŀ¼ÖС£¡£¡£±¨¸æÖл¹Ìá¼°²»µ½ 1% µÄÎó²îÔì³É×î¸ßΣº¦£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¾³£±»ÆÕ±éʹÓᣡ£¡£
https://www.scmagazine.com/news/1-in-4-high-risk-cves-are-exploited-within-24-hours-of-going-public
4. ŦԼij·¿µØ²ú¹«Ë¾ÔÆÐ§ÀÍÆ÷ÉèÖùýʧй¶15ÒÚÌõµØ²ú¼Í¼
20ÈÕýÌ屨µÀ£¬£¬£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ô± Jeremiah Fowler ·¢Ã÷ÁËÒ»¸öÓëŦԼÔÚÏ߯½Ì¨ Real Estate Wealth Network Ïà¹ØµÄδÊܱ£»£»£»£»£»£»¤µÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬Êý¾Ý¿âÉúÑÄÁË 15 ÒÚÌõ¼Í¼£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Êý°ÙÍòÈ˵ķ¿µØ²úËùÓÐȨÊý¾Ý¡£¡£¡£¸ÃÊý¾Ý¿â¾ÞϸΪ 1.16 TB£¨×ܹ² 1,523,776,691 Ìõ¼Í¼£©£¬£¬£¬£¬£¬£¬£¬£¬¾ßÓÐ×éÖ¯ÓÐÐòµÄÎļþ¼Ð£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨ÓйØÒµÖ÷¡¢Âô¼Ò¡¢Í¶×ÊÕߺÍÄÚ²¿Óû§ÈÕÖ¾Êý¾ÝµÄÐÅÏ¢¡£¡£¡£Ëü°üÀ¨´Ó 2023 Äê 4 Ô 22 ÈÕµ½ 23 Äê 10 Ô 23 ÈÕµÄÖðÈÕÈÕÖ¾¼Í¼£¬£¬£¬£¬£¬£¬£¬£¬Õ¹ÏÖÁËÄÚ²¿Óû§ËÑË÷Êý¾Ý¡£¡£¡£
https://www.hackread.com/data-leak-exposes-real-estate-records-elon-musk-trump/
5. ¶ñÒâÈí¼þJaskaGO¿É¿çMacºÍWindowsÇÔÈ¡Óû§Êý¾Ý
20ÈÕýÌ屨µÀ£¬£¬£¬£¬£¬£¬£¬£¬AT&T Alien Labs µÄÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖÃûΪ JaskaGO µÄÖØ´ó¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬ËüÊÇÓà Go ( Golang ) ±à³ÌÓïÑÔ±àдµÄ£¬£¬£¬£¬£¬£¬£¬£¬²¢¾ßÓÐÔÚÊÜѬȾϵͳÖмá³Ö³¤ÆÚÐÔµÄÄÜÁ¦¡£¡£¡£Ëü¿ÉÒÔй¶ÓмÛÖµµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨ä¯ÀÀÆ÷ƾ֤ºÍ¼ÓÃÜÇ®±ÒÇ®°üÏêϸÐÅÏ¢¡£¡£¡£Æ¾Ö¤ AT&T Alien Labs µÄ±¨¸æ£¬£¬£¬£¬£¬£¬£¬£¬JaskaGO ÊÇÒ»ÖÖÓÕÆÐÔ¹¤¾ß£¬£¬£¬£¬£¬£¬£¬£¬Ëü»áÏÔʾһÌõÐéαµÄ¹ýʧÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬£¬Éù³ÆÎļþɥʧ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÎóµ¼Óû§ÏàÐŶñÒâ´úÂëÎÞ·¨ÔËÐС£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬ËüʹÓÃÀàËÆÓÚ×ÅÃûÓ¦ÓóÌÐòµÄÎļþÃû£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈç¡°Capcut_Installer_Intel_M1.dmg¡±ºÍ¡°Anyconnect.exe¡±£¬£¬£¬£¬£¬£¬£¬£¬ÕâÅú×¢ÔÚµÁ°æÓ¦ÓóÌÐòÍøÒ³ÖÐÒÔÕýµ±Èí¼þΪ»Ï×Ó°²ÅŶñÒâÈí¼þµÄ³£¼ûÕ½ÂÔ¡£¡£¡£
https://www.hackread.com/jaskago-malware-mac-windows-crypto-browser-data/
6. IvantiÐû²¼¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´13¸öÑÏÖØAvalanche RCEÎó²î
20ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Ivanti Ðû²¼ÁËÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Á˸ù«Ë¾ Avalanche ÆóÒµÒÆ¶¯×°±¸ÖÎÀí (MDM) ½â¾ö¼Æ»®ÖÐµÄ 13 ¸öÒªº¦Çå¾²Îó²î¡£¡£¡£Avalanche ÔÊÐíÖÎÀíԱͨ¹ý»¥ÁªÍø´ÓÒ»ÆäÖÐÑëλÖÃÖÎÀíÁè¼Ý 100,000 Ì¨ÒÆ¶¯×°±¸¡¢°²ÅÅÈí¼þ²¢×°ÖøüС£¡£¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÔÚµÍÖØ´óÐÔ¹¥»÷ÖÐʹÓÃËüÃÇ£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ¹¥»÷²»ÐèÒªÓû§½»»¥¼´¿ÉÔÚδÐÞ²¹µÄϵͳÉÏ»ñµÃÔ¶³Ì´úÂëÖ´ÐС£¡£¡£CISAÆäʱÖÒÑÔ˵£¬£¬£¬£¬£¬£¬£¬£¬Òƶ¯×°±¸ÖÎÀí (MDM) ϵͳ¹ØÓÚÍþвÐÐΪÕßÀ´ËµÊÇÓÐÎüÒýÁ¦µÄÄ¿µÄ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÌṩÁ˶ÔÊýǧ¸öÒÆ¶¯×°±¸µÄ¸ü¸ß»á¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ APT ÐÐΪÕßÒѾʹÓÃÁË֮ǰµÄ MobileIron Îó²î¡£¡£¡£
https://www.bleepingcomputer.com/news/security/ivanti-releases-patches-for-13-critical-avalanche-rce-flaws/


¾©¹«Íø°²±¸11010802024551ºÅ