GoogleÐû²¼Äþ¾²¸üÐÂÐÞ¸´ChromeÖеĶà¸ö©¶´
Ðû²¼Ê±¼ä 2023-03-231¡¢GoogleÐû²¼Äþ¾²¸üÐÂÐÞ¸´ChromeÖеĶà¸ö©¶´
GoogleÔÚ3ÔÂ21ÈÕÐû²¼Äþ¾²¸üУ¬ÐÞ¸´ÁËChromeÖеÄ8¸ö©¶´¡£ÆäÖУ¬½ÏΪÑÏÖØµÄÊÇPasswordsÖеÄÊͷźóʹÓé¶´£¨CVE-2023-1528£©¡¢WebHIDÖеÄÄÚ´æÔ½½ç·ÃÎÊ©¶´£¨CVE-2023-1529£©¡¢ÔÚPDFÖеÄÊͷźóʹÓé¶´£¨CVE-2023-1530£©ºÍGPUÊÓÆµÖеÄÔ½½ç¶Áȡ©¶´£¨CVE-2023-1532£©µÈ¡£GoogleÌåÏÖ£¬ÔÚ´ó¶àÊýÓû§¸üÐÂÐÞ¸´·¨Ê½Ö®Ç°£¬Â©¶´ÏêϸÐÅÏ¢ºÍÁ´½ÓµÄ·ÃÎÊ¿ÉÄÜ»áÊܵ½ÏÞÖÆ¡£
https://chromereleases.googleblog.com/2023/03/stable-channel-update-for-desktop_21.html
2¡¢Á÷ýÌåÆ½Ì¨Lionsgate½ü3000ÍòÌõ¼Ç¼й¶
¾ÝCybernewsÔÚ3ÔÂ22ÈÕ±¨µÀ£¬ÓµÓÐ3700Íò¶©»§µÄÊÓÆµÁ÷ýÌåÆ½Ì¨Lionsgate PlayµÄElasticSearchÅäÖôíÎó£¬Ð¹Â¶ÁËÓû§Êý¾Ý¡£Ñо¿ÈËÔ±·¢ÏÖÁËÒ»¸ö20 GB·þÎñÆ÷ÈÕÖ¾£¬°üÂÞ½ü3000ÍòÌõÌõÄ¿£¬×îÔçµÄÈÕÆÚÊÇ2022Äê5Ô¡£ÈÕ־й¶Á˶©ÔÄÕßµÄIPµØÖ·ÒÔ¼°ÓйØÉ豸¡¢²Ù×÷ϵͳºÍWebä¯ÀÀÆ÷µÄÓû§ÐÅÏ¢¡£»¹Ð¹Â¶ÁËÆ½Ì¨µÄʹÓÃÊý¾Ý£¬ÈçÓû§Ô¢Ä¿ÄÚÈݵıêÌâIDºÍËÑË÷²éѯµÈ£¬Í¨³£¿ÉÓÃÓÚ·ÖÎöºÍÐÔÄܸú×Ù¡£Cybernews¾Í´ËÊÂÁªÏµÁËLionsgate£¬¸Ã¹«Ë¾µÄ»ØÓ¦ÊÇÒѽ«·þÎñÆ÷±£»¤ÆðÀ´£¬µ«ÊǽØÖÁĿǰÉÐδÌṩ¹Ù·½»ØÓ¦¡£
https://cybernews.com/security/lionsgate-data-leak/
3¡¢REF2924ÍÅ»ïÀûÓÃNAPLISTENER¹¥»÷¶«ÄÏÑǵØÓò
¾ÝýÌå3ÔÂ20ÈÕ±¨µÀ£¬REF2924ÀûÓÃжñÒâÈí¼þNAPLISTENER¹¥»÷ÄÏÑǺͶ«ÄÏÑǵÄ×éÖ¯¡£Elastic³Æ¸ÃÍÅ»ïʹÓÃÁ˶àÖÖ»úÖÆ£¬½«Öصã´ÓÊý¾ÝÇÔÈ¡×ªÒÆµ½³Ö¾Ã·ÃÎÊ¡£2023Äê1ÔÂ20ÈÕ£¬Ò»¸öеĿÉÖ´ÐÐÎļþWmdtc.exe±»´´½¨²¢×÷ΪWindows·þÎñ°²×°£¬Í¨¹ýαװ³ÉMicrosoftÂþÑÜʽÊÂÎñ´¦ÖÃе÷Æ÷·þÎñ(Msdtc.exe)ʹÓõĺϷ¨¶þ½øÖÆÎļþ¡£Wmdtc.exe±»³ÆÎªNAPLISTENER£¬ÕâÊÇÒ»¸öÓÃC#¿ª·¢µÄHTTPÕìÌýÆ÷£¬Ö¼ÔÚÈÆ¹ý»ùÓÚÍøÂçµÄÄþ¾²¼ì²â¡£
https://www.elastic.co/cn/security-labs/naplistener-more-bad-dreams-from-the-developers-of-siestagraph
4¡¢LockBitÒ²³ÆÒÑÇÔÈ¡²¢½«¹ûÈ»°Â¿ËÀ¼ÊÐϵͳÖеÄÎļþ
¾Ý3ÔÂ21ÈÕ±¨µÀ£¬ÁíÒ»¸öÀÕË÷ÍÅ»ïLockBitÒ²Éù³Æ´Ó°Â¿ËÀ¼ÊÐϵͳÖÐÇÔÈ¡ÁËÎļþ¡£È»¶ø£¬¸ÃÍÅ»ïÉÐδÐû²¼ÈκÎÖ¤¾ÝÀ´Ö¤Ã÷ËûÃǵĹ¥»÷»î¶¯¡£ÕâÊÇ×ÔPlayÍÅ»ïÔÚ3Ô³õÌåÏֶ԰¿ËÀ¼ÊеÄÍøÂç¹¥»÷ÂôÁ¦ºó£¬µÚ¶þ¸öÀÕË÷ÍÅ»ïÉù³ÆÇÔÈ¡ÁËÊý¾Ý¡£LockBitÔÚÆäÍøÕ¾ÉÏÌí¼ÓÁËÐÂÌõÄ¿£¬²¢Íþв½«ÔÚ4ÔÂ10ÈÕ¹ûÈ»ËùÓÐÊý¾Ý¡£°Â¿ËÀ¼ÊÐÉÐδ¾Í´ËÊ·¢±íÉùÃ÷¡£Ñо¿ÈËÔ±ÌåÏÖ£¬LockBitÔøÔÚ2022Äê6ÔÂÉù³ÆËüÈëÇÖÁËMandiantµÄϵͳ²¢ÇÔÈ¡ÁËÊýÊ®Íò¸öÎļþ£¬ºóÀ´Õâ±»Ö¤Ã÷ÊÇÒ»¸öÐû´«àåÍ·¡£
https://www.bleepingcomputer.com/news/security/lockbit-ransomware-gang-now-also-claims-city-of-oakland-breach/
5¡¢ChatGPT·ºÆðBug¿ÉÒÔ¿´µ½ÆäËûÓû§µÄ¶Ô»°ÀúÊ·±êÌâ
ýÌå3ÔÂ21Èճƣ¬ChatGPT·ºÆðÁËÒ»¸öBug£¬µ¼ÖÂÆäËûÓû§µÄÁÄÌìÀúʷй¶¡£¸ÃÎÊÌâ×î³õÊÇÓÉһλ»³ÒÉÆäÕÊ»§±»ºÚµÄÓû§ÔÚRedditÉϳÂËߵģ¬ËûÔÚ¶Ô»°ÀúÊ·±êÌâÖз¢ÏÖÁ˲»ÊôÓÚ×Ô¼ºµÄ¶Ô»°¡£ÏûÏ¢´«¿ªºó£¬ÍÆÌØÉÏµÄÆäËûÓû§Ò²Éù³ÆÔÚ×Ô¼ºµÄÕ˺ÅÉÏ¿´µ½Á˱ðÈ˵ÄÁÄÌì¼Ç¼¡£Ðí¶àÓû§³Æ¸ÃÎÊÌâÑÏÖØÇÖ·¸ÁËÓû§Òþ˽¡£ChatGPTÓÚ±¾ÖÜÒ»ÔÝʱ½ûÓÃÁËÆäÁÄÌì·þÎñ£¬ÒÔÊÓ²ìºÍÐÞ¸´¸Ã©¶´¡£3ÔÂ23ÈÕ£¬OpenAI CEO Sam AltmanÈÏ¿ÉÆä¿ªÔ´¿âÖеÄÒ»¸ö´íÎóµ¼ÖÂÓû§µÄÁÄÌìÀúʷй¶£¬²¢Ðû²¼ÁËÍÆÎÄÖÂǸ¡£
https://www.hackread.com/chatgpt-bug-conversation-history-titles/
6¡¢Unit 42Ðû²¼2023ÄêÀÕË÷Èí¼þÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß
3ÔÂ21ÈÕ£¬Unit 42Ðû²¼ÁË2023ÄêÀÕË÷Èí¼þÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬¶àÖØÀÕË÷¼ÆÄ±µÄʹÓÃÁ¬ÐøÉÏÉý¡£½ØÖÁ2022Äêµ×£¬ÔÚÔ¼70%µÄ°¸¼þÖз¢ÉúÁËÊý¾Ýй¶£¬2021ÄêÖÐÖ»ÓÐÔ¼40%µÄÊý¾Ý±»µÁ¡£É§ÈÅÊÇÁíÒ»ÖÖÀÕË÷¼ÆÄ±£¬2022Äêµ×Ô¼20%µÄÀÕË÷Èí¼þ°¸¼þ°üÂÞ¸ÃÒòËØ£¬¶ø2021Äê½öÓв»µ½1%¡£ÖÆÔìÒµÊÜ´ËÀ๥»÷×î¶à£¬ÃÀ¹úµÄ×éÖ¯Êܵ½Ó°Ïì×îÑÏÖØ£¨Õ¼42%£©¡£Ñо¿ÈËÔ±Ô¤¼ÆÔÚ2023Ä꣬·ºÆð´óÐÍÔÆÀÕË÷Èí¼þ¹¥»÷¡¢ÄÚ²¿ÍþвÏà¹ØµÄÇÃÕ©ÀÕË÷Ôö¼ÓºÍ³öÓÚÕþÖζ¯»úµÄÀÕË÷Ôö¼ÓµÈ¡£
https://start.paloaltonetworks.com/2023-unit42-ransomware-extortion-report