ÖÇÄܼҾÓÉÌNexx¶à´ÎºöÂÔ¿ÉÔ¶³Ì´ò¿ª³µ¿âÃŵÄ©¶´
Ðû²¼Ê±¼ä 2023-04-071¡¢ÖÇÄܼҾÓÉÌNexx¶à´ÎºöÂÔ¿ÉÔ¶³Ì´ò¿ª³µ¿âÃŵÄ©¶´
¾ÝýÌå4ÔÂ5ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±ÔÚNexxÖÆÔìµÄ¼¸¿îÖÇÄÜÉ豸Öз¢ÏÖÁ˶à¸ö©¶´£¬¿É±»ÓÃÀ´Ô¶³Ì´ò¿ª³µ¿âÃÅ»òÕß¿ØÖƾ¯±¨ºÍÖÇÄܲåÍ·¡£ÕâЩ©¶´·Ö±ðΪʹÓÃÓ²±àÂëƾ¾Ý£¨CVE-2023-1748£©¡¢·ÃÎÊ¿ØÖƲ»Í×£¨CVE-2023-1749ºÍCVE-2023-1750£©¡¢ÊäÈëÑéÖ¤²»Í×£¨CVE-2023-1751£©ºÍÉí·ÝÑéÖ¤¿ØÖƲ»Í×£¨CVE-2023-1752£©¡£Ñо¿ÈËÔ±»¹ÑÝʾÁËÈçºÎÀûÓ鶴CVE-2023¨C1748´ò¿ªNexx³µ¿âÃÅ¡£¾ÝϤ£¬Ñо¿ÈËÔ±Sam SabetanºÍCISAÔø³ÂËß¹ý¸Ã©¶´£¬µ«ÊǶ¼±»NexxºöÂÔÁË¡£
https://www.securityweek.com/nexx-ignores-vulnerabilities-allowing-hackers-to-remotely-open-garage-doors/
2¡¢ÂÉËùGenova Burnsϵͳ±»ºÚÓŲ½Ë¾»úÐÅÏ¢ÔÙ´Îй¶
¾Ý4ÔÂ3ÈÕ±¨µÀ£¬ÓŲ½Ë¾»úµÄÐÅÏ¢ÔÙ´Îй¶£¬Õâ´ÎÔ´ÓÚÂÉʦÊÂÎñËùGenova Burns¡£¸ÃʼþÉæ¼°ÐÕÃû¡¢Éç»áÄþ¾²ºÅÂëºÍË°ºÅµÈ£¬Ó°ÏìÈËÊý²»Ïê¡£ÒòΪ¸Ã¹«Ë¾ÎªÓŲ½×öÖ´·¨ÊÂÇ飬ËùÒÔ³ÖÓÐÕâЩÐÅÏ¢¡£ÂÉËùÌåÏÖ£¬Î´¾ÊÚȨµÄµÚÈý·½»ñµÃÁËÆäϵͳµÄ·ÃÎÊȨÏÞ£¬¶øÇÒÔÚ2023Äê1ÔÂ23ÈÕ1ÔÂ31ÈÕ·ÃÎÊ»òй¶Á˲¿ÃÅÎļþ¡£ËûÃÇÒѾʹËÊÂ֪ͨÁËÖ´·¨²¿ÃÅ£¬²¢¸ü¸ÄÁËËùÓÐϵͳÃÜÂ룬»¹½«ÎªÊÜÓ°ÏìµÄ¸öÈËÌṩ12¸öÔµÄÉí·Ý¼à¿Ø·þÎñ¡£
https://www.theregister.com/2023/04/03/uber_drivers_info_stolen/
3¡¢OCR LabsµÄϵͳÅäÖôíÎóÖ÷ÒªÓ°Ïì½ðÈÚ»ú¹¹µÄ¿Í»§
4ÔÂ4ÈÕ±¨µÀ³Æ£¬Ñо¿ÍŶÓÔÚ3ÔÂ8ÈÕ·¢ÏÖÁËOCR Labs idkit.comµÄÒ»¸ö»·¾³Îļþ(.env)¿É¹ûÈ»·ÃÎÊ¡£¸Ã¹«Ë¾ÊÇÊý×ÖÉí·ÝÑéÖ¤¹¤¾ßµÄ¹©Ó¦ÉÌ£¬ÆäIDkit¹¤¾ß±»¸÷´óÒøÐС¢µçÐŹ«Ë¾ºÍÕþ¸®»ú¹¹Ê¹Óá£ÔÚ鶵ÄÊý¾ÝÖУ¬Ñо¿ÈËÔ±·¢ÏÖÁËGoogleºÍLivenessµÄAPIÃÜÔ¿ÃÜÔ¿¡¢Engine v4ƾ֤ÒÔ¼°À´×ÔExperianµÄAPIÃÜÔ¿¡£¸ÃʼþÓ°ÏìÁËÓ°ÏìÁËQBANK¡¢Defense Bank¡¢Bloom Money¡¢Admiral Money¡¢MA MoneyºÍReed¡£¹¥»÷Õß¿ÉÀûÓÃ鶵ÄÊý¾Ý£¬ÈëÇÖÒøÐеĺó¶Ë»ù´¡ÉèÊ©£¬´Ó¶ø¹¥»÷Æä¿Í»§µÄ»ù´¡ÉèÊ©¡£Ä¿Ç°£¬¸ÃÎÊÌâÒѱ»½â¾ö¡£
https://cybernews.com/security/ocr-labs-exposes-its-systems/
4¡¢NoteboomÔâµ½BlackCatµÄ¹¥»÷²¢±»ÀÕË÷175ÍòÃÀÔª
ýÌå4ÔÂ5ÈÕ±¨µÀ³Æ£¬µÂ¿ËÈø˹ÖݵÄÂÉʦÊÂÎñËùNoteboomÔâµ½ÁËBlackCatµÄÀÕË÷¹¥»÷¡£BlackCatÏòNoteboom·¢Ë͵ç×ÓÓʼþ£¬Í¨ÖªÆäÔÚ3ÔÂ24ÈÕ·¢ÉúÁËÊý¾Ýй¶¡£Óʼþ»¹³ÆËûÃÇÒÑÈëÇÖϵͳ²¢Í£ÁôÁË7Ì죬ÏÂÔØÁËÁè¼Ý400GbµÄÊý¾Ý£¬²¢¼ÓÃÜÁËËùÓзþÎñÆ÷ºÍÊý¾Ý¡£Ð¹Â¶Êý¾Ý°üÂÞ±£ÃÜÐÒ顢δ¾ö°¸¼þµÄÎļþ¡¢Éæ¼°ËßËϵÄÒ½ÁƼǼÒÔ¼°Ô±¹¤Êý¾ÝµÈ¡£BlackCat͸¶Êê½ðÒªÇóΪ1750000ÃÀÔª£¬µ«Noteboom»ù´¡Ã»ÓлØÓ¦ËûÃÇ¡£
https://www.databreaches.net/noteboom-the-law-firm-hit-by-blackcat/
5¡¢Ó¢¹úÍâ°ü¹«Ë¾CapitaÔâµ½¹¥»÷µ¼Ö²¿ÃÅ·þÎñÔÝʱÖжÏ
ýÌå4ÔÂ3Èճƣ¬Ó¢¹úÍâ°ü¹«Ë¾Capita͸¶ÉÏÖÜÎåµÄ·þÎñÖжÏÊÇÍøÂç¹¥»÷µ¼Öµġ£CapitaÊÇÕþ¸®×î´óµÄ¹©Ó¦ÉÌÖ®Ò»£¬ÓµÓÐ65ÒÚÓ¢°÷µÄ¹«¹²²¿ÃźÏͬ¡£¸Ã¹«Ë¾ÔÚÉùÃ÷Öгƣ¬´Ë´ÎʼþÖ÷ÒªÓ°ÏìÁËÆäMicrosoft 365Ó¦Ó÷¨Ê½µÄÄÚ²¿·ÃÎÊ£¬´Ó¶øµ¼Ö²¿ÃÅ¿Í»§·þÎñÖжϡ£Ä¿Ç°£¬Ê¼þÒÑ»ù±¾µÃµ½¿ØÖÆ£¬·þÎñÕýÔÚ»Ö¸´ÖС£¸Ã¹«Ë¾Ã»ÓÐ͸¶ÓйظÃʼþµÄϸ½Ú£¬µ«ÆäÓ°Ïì±íÃ÷Õâ¿ÉÄÜÊÇÀÕË÷¹¥»÷¡£
https://securityaffairs.com/144398/hacking/capita-suffered-cyber-incident.html
6¡¢Unit 42Ðû²¼¹ØÓÚ¶ñÒâÈí¼þCryptoClippyµÄ·ÖÎö³ÂËß
4ÔÂ5ÈÕ£¬Unit 42Åû¶Á˶ñÒâÈí¼þCryptoClippyÕë¶ÔÆÏÌÑÑÀµÄ¹¥»÷»î¶¯¡£¸Ã»î¶¯Ê¼ÓÚSEOÖж¾£¬Ä¿±êËÑË÷WhatsApp Webʱ£¬½á¹û»á½«ËûÃÇÒýµ¼ÖÁ¹¥»÷ÕßµÄÓò£¬È»ºóÏÂÔضñÒâÈí¼þ¡£CryptoClippyÊÇ»ùÓÚCµÄ¿ÉÖ´ÐÐÎļþ£¬Ëü»á¼àÊÓÄ¿±êµÄ¼ôÌù°å£¬Ñ°ÕÒ¸´ÖƼÓÃÜ»õ±ÒÇ®°üµØÖ·µÄÐÐΪ£¬²¢Óù¥»÷ÕߵĵØÖ·Ìæ»»Óû§µÄʵ¼ÊµØÖ·¡£Ñо¿ÈËÔ±·¢ÏÖ±»¹¥»÷Õ߱鲼ÖÆÔìÒµ¡¢IT·þÎñºÍ·¿µØ²úÐÐÒµ¡£ÕâÖÖÍþв²¢²»Õë¶ÔÌض¨ÐÐÒµ£¬ÊÜÓ°ÏìÉ豸¶¼ÊÇÔâµ½ÁË»ú»áÖ÷ÒåµÄ¹¥»÷¡£
https://unit42.paloaltonetworks.com/crypto-clipper-targets-portuguese-speakers/