Checkmarx¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©Ó¦Á´¹¥»÷

Ðû²¼Ê±¼ä 2023-07-25

1¡¢Checkmarx¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©Ó¦Á´¹¥»÷


CheckmarxÔÚ7ÔÂ21ÈÕ³ÆÆä¼ì²âµ½¶àÆðÕë¶ÔÒøÐеĿªÔ´Èí¼þ¹©Ó¦Á´£¨OSS£©¹¥»÷¡£¡£¡£¡£¡£µÚÒ»´Î¹¥»÷±¬·¢ÓÚ4ÔÂÉÏÑ®£¬ £¬£¬¹¥»÷Õßð³äÄ¿µÄÒøÐÐÔ±¹¤£¬ £¬£¬Ê¹ÓÃNPMƽ̨ÉÏ´«Á˼¸¸öÈí¼þ°ü£¬ £¬£¬ÆäÖаüÀ¨Ô¤×°Öþ籾£¬ £¬£¬¿ÉÔÚ×°ÖÃʱִÐжñÒâ»î¶¯¡£¡£¡£¡£¡£»£»£»£»£»¹Ê¹ÓÃAzureµÄCDN×ÓÓòÀ´·Ö·¢µÚ¶þ½×¶ÎµÄpayload Havoc£¬ £¬£¬ÕâÊÇÒ»¸öC2¿ò¼Ü¡£¡£¡£¡£¡£ÔÚ2Ô·ݼì²âµ½µÄÕë¶ÔÒøÐеÄÁíÒ»´Î¹¥»÷ÖУ¬ £¬£¬¹¥»÷ÕßÒ²ÉÏ´«ÁËÒ»¸ö¶ñÒânpm°ü£¬ £¬£¬Ö¼ÔÚ×èµ²µÇ¼Êý¾Ý²¢½«Æä·¢Ë͸ø¹¥»÷Õß¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬Ñо¿Ö°Ô±ÒѾ­±¨¸æ²¢É¾³ýÁËÕâЩ¶ñÒ⿪ԴÈí¼þ°ü¡£¡£¡£¡£¡£


https://checkmarx.com/blog/first-known-targeted-oss-supply-chain-attacks-against-the-banking-sector/


2¡¢Apple¸üÐÂÐÞ¸´Òѱ»Ê¹ÓõÄÄÚºËÎó²îCVE-2023-38606 


¾ÝýÌå7ÔÂ24ÈÕ±¨µÀ£¬ £¬£¬AppleÐû²¼ÁËÇå¾²¸üУ¬ £¬£¬ÒÔÐÞ¸´Õë¶ÔiPhone¡¢MacºÍiPadµÄ¹¥»÷Öб»Ê¹ÓõÄÎó²î¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÄÚºËÎó²î£¨CVE-2023-38606£©£¬ £¬£¬Äܹ»±»ÓÃÀ´¸Ä¶¯Ãô¸ÐµÄÄÚºË״̬£¬ £¬£¬¿ÉÄÜÒÑÔÚiOS 15.7.1֮ǰÐû²¼µÄiOS°æ±¾Öб»Æð¾¢Ê¹Óᣡ£¡£¡£¡£KasperskyÌåÏÖ£¬ £¬£¬CVE-2023-38606ÊÇÁãµã»÷Îó²îʹÓÃÁ´µÄÒ»²¿·Ö£¬ £¬£¬ÓÃÓÚͨ¹ýiMessageÎó²îÔÚiPhoneÉÏ×°ÖÃÌØ¹¤Èí¼þTriangulation¡£¡£¡£¡£¡£ÕâÊÇAppleÔÚ½ñÄêÐÞ¸´µÄµÚʮһ¸öÒѱ»Ê¹ÓõÄÁãÈÕÎó²î¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/apple/apple-fixes-new-zero-day-used-in-attacks-against-iphones-macs/


3¡¢ClopʹÓÃMOVEitÎó²îµÄ¹¥»÷Ô¤¹À׬Ǯ7500ÍòÖÁ1ÒÚÃÀÔª


CovewareÔÚ7ÔÂ21ÈÕ͸¶£¬ £¬£¬ClopʹÓÃMOVEitÎó²îµÄ´ó¹æÄ£Êý¾ÝÇÔÈ¡»î¶¯Ô¤¼Æ×¬Ç®¸ß´ï7500ÍòÖÁ1ÒÚÃÀÔª¡£¡£¡£¡£¡£ÔÚ2023ÄêQ2£¬ £¬£¬½»Êê½ðµÄ±»¹¥»÷Ä¿µÄµÄÊýÄ¿ÒѽµÖÁ34%£¬ £¬£¬´´ÏÂÀúʷеͣ¬ £¬£¬µ¼ÖÂÀÕË÷ÍÅ»ï¸Ä±äÕ½ÂÔÒÔ×êÓª¸ü¸ßµÄÀûÈ󡣡£¡£¡£¡£CovewareÌåÏÖ£¬ £¬£¬ClopÒѾ­¸Ä±äÁËÕ½ÂÔ£¬ £¬£¬ÀÕË÷¸ü¸ßµÄÊê½ð£¬ £¬£¬Ï£Íûͨ¹ý¼¸±Ê´ó¶î¸¶¿îÀ´Õ½Ê¤ÕûÌåϽµµÄÇéÐΡ£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬ÖØ´óÐÔºÍ×Ô¶¯»¯Ë®Æ½µÍµÄÀÕË÷¹¥»÷µÄÓ°ÏìºÍ±¾Ç®×îС¡£¡£¡£¡£¡£


https://www.coveware.com/blog/2023/7/21/ransom-monetization-rates-fall-to-record-low-despite-jump-in-average-ransom-payments


4¡¢Ñо¿Ö°Ô±Åû¶OpenMeetings¿ÉÐ®ÖÆÖÎÀíÔ±ÕÊ»§µÄÎó²î


¾Ý7ÔÂ21ÈÕ±¨µÀ£¬ £¬£¬Ñо¿Ö°Ô±Åû¶ÁËApache OpenMeetingsÖеÄ3¸öÎó²îµÄϸ½Ú¡£¡£¡£¡£¡£ÕâЩÎó²î»®·ÖΪÈõ¹þÏ£½ÏÁ¿Îó²î£¨CVE-2023-28936£©¡¢Í¨¹ýÔ¼Çë¹þÏ£¾ÙÐÐÎÞÏÞÖÆ»á¼ûµÄÎó²î£¨CVE-2023-29023£©ÒÔ¼°¿Õ×Ö½Ú×¢ÈëÎó²î(CVE-2023-29246£©£¬ £¬£¬¿É±»×ÔÐÐ×¢²áÓû§£¨Ä¬ÈÏÆôÓã©ÓÃÀ´Ð®ÖÆÖÎÀíÔ±ÕÊ»§²¢Ô¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬ÕâЩÎó²îÒÑÔÚApache OpenMeetings 7.1.0°æ±¾ÖÐÐÞ¸´¡£¡£¡£¡£¡£


https://www.securityweek.com/openmeetings-flaws-allow-hackers-to-hijack-instances-execute-code-on-servers/


5¡¢AhnLab·¢Ã÷ͨ¹ýMS-SQLЧÀÍÆ÷·Ö·¢PurpleFoxµÄ»î¶¯


7ÔÂ24ÈÕ£¬ £¬£¬AhnLab³ÆÆä·¢Ã÷ÁËͨ¹ýÖÎÀí²»ÉÆµÄMS-SQLЧÀÍÆ÷·Ö·¢PurpleFoxµÄ»î¶¯¡£¡£¡£¡£¡£¹¥»÷Ê×ÏÈͨ¹ýsqlservr.exeÖ´ÐÐPowerShell£¬ £¬£¬ÕâÊÇÒ»¸öÓëMS-SQLЧÀÍÆ÷Ïà¹ØµÄÀú³Ì¡£¡£¡£¡£¡£µ±Ö´ÐÐÉÏÊöPowerShellʱ£¬ £¬£¬½«ÏÂÔØ²¢¼ÓÔØÁíÒ»¸ö¾­ÓÉ»ìÏýµÄPowerShell¡£¡£¡£¡£¡£ÆäÖаüÀ¨Ò»¸ö¹¥»÷Õß¿ª·¢µÄº¯ÊýMsiMake£¬ £¬£¬¿ÉÏÂÔØÒ»¸öMSIÎļþ¡£¡£¡£¡£¡£MSI°ü¸ü¸Ä×¢²á±íÏîÒÔʵÏÖ³¤ÆÚÐÔºÍȨÏÞÌáÉý¡£¡£¡£¡£¡£×îºó£¬ £¬£¬MSI°ü»áʵÑéÖØÆôϵͳ£¬ £¬£¬½Ó×ÅSENSЧÀͻᱻִÐУ¬ £¬£¬´Ó¶ø¼¤»î¶ñÒâÈí¼þ¡£¡£¡£¡£¡£


https://asec.ahnlab.com/en/55492/


6¡¢IBMÐû²¼¹ØÓÚ2023ÄêÊý¾Ýй¶±¾Ç®µÄÆÊÎö±¨¸æ


7ÔÂ24ÈÕ£¬ £¬£¬IBMÐû²¼¹ØÓÚ2023ÄêÊý¾Ýй¶±¾Ç®µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¸Ã±¨¸æ¶Ô553¸ö×éÖ¯µÄÊý¾Ýй¶ÇéÐξÙÐÐÁËÆÊÎö£¬ £¬£¬Ñо¿µÄÎ¥¹æÊÂÎñ±¬·¢ÔÚ2022Äê3ÔÂÖÁ2023Äê3Ô¡£¡£¡£¡£¡£×îÐÂÑо¿ÏÔʾ£¬ £¬£¬Êý¾Ýй¶±¾Ç®Ò»Á¬ÔöÌí£¬ £¬£¬È«Çòƽ¾ù±¾Ç®¸ß´ï445ÍòÃÀÔª£¬ £¬£¬ÈýÄêÄÚÔöÌíÁË15%¡£¡£¡£¡£¡£Ò½ÁƱ£½¡ÐÐÒµµÄ±¾Ç®Î»¾Ó°ñÊ×£¬ £¬£¬Ò»Á¬13Äê³ÉΪ±¾Ç®×î¸ßµÄÐÐÒµ¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬ £¬£¬Çå¾²È˹¤ÖÇÄܺÍ×Ô¶¯»¯¡¢DevSecOpsÒªÁìºÍIRÍýÏëÔÚ½ÚÔ¼±¾Ç®·½ÃæÊ©Õ¹ÁËÖ÷µ¼×÷Ó㻣»£»£»£»È˹¤ÖÇÄܺÍASM¼ÓËÙÁËÎ¥¹æÊÂÎñµÄʶ±ðºÍ×èÖ¹£»£»£»£»£»µ±Êý¾Ý´æ´¢ÔÚ¶à¸öÇéÐÎÖÐʱ£¬ £¬£¬±¾Ç®ºÜ¸ß£¬ £¬£¬²¢ÇÒÐèÒª¸ü³¤Ê±¼ä²Å»ª×èֹΥ¹æÊÂÎñ£»£»£»£»£»ÓµÓз¢Ã÷Î¥¹æÊÂÎñµÄÄÚ²¿ÍŶӵÄ×éÖ¯ÔÚ¿ØÖƱ¾Ç®·½ÃæÌåÏֵøüºÃ¡£¡£¡£¡£¡£


https://securityintelligence.com/posts/whats-new-2023-cost-of-a-data-breach-report/