ExchangeÖжϵ¼ÖÂÓû§ÎÞ·¨·¢ËÍÓʼþ²¢´¥·¢503´íÎó
Ðû²¼Ê±¼ä 2023-07-191¡¢ExchangeÖжϵ¼ÖÂÓû§ÎÞ·¨·¢ËÍÓʼþ²¢´¥·¢503´íÎó
¾Ý7ÔÂ18ÈÕ±¨µÀ£¬MicrosoftÕýÔÚÊÓ²ìÁ¬ÐøµÄExchange OnlineÖжÏʼþ¡£Microsoft³Æ£¬ÓÉÓÚ×î½ü¶Ôfree/busy»ù´¡ÉèÊ©½øÐÐÁ˸ü¸Ä£¬µ¼Ö²¿ÃÅÓû§ÎÞ·¨·¢Ë͵ç×ÓÓʼþ¡£¸ÃʼþÓ°ÏìÁËÃÀ¹ú¡¢Å·ÖÞ¡¢Ó¡¶ÈºÍÓ¢¹úµÄÓû§¡£¾ßÌåÀ´Ëµ£¬ÊÜÓ°ÏìÓû§ÔÚ·¢ËÍÓʼþʱ¿ÉÄÜ»áÓöµ½ÎÊÌ⣬²¢ÏÔʾ¡°503 5.5.1´íÎóµÄÃüÁîÐòÁС±µÄ´íÎóÌáʾ¡£¾ÝÃÀ¹ú¶«²¿Ê±¼ä7ÔÂ18ÈÕ06:39¸üУ¬Î¢ÈíÌåÏÖÖжϵĻù´¡ÔÒòÒѵõ½½â¾ö£¬µ«ÈÔÓÐÓû§·´Ó³ÔÚ·¢ËÍÓʼþʱ´æÔÚÎÊÌâ¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-online-hit-by-new-outage-blocking-emails/
2¡¢Å²Íþ¹«Ë¾TomraÔâµ½´ó¹æÄ£¹¥»÷²¿ÃÅϵͳÔÝʱ¹Ø±Õ
ýÌå7ÔÂ18Èճƣ¬Å²Íþ¹«Ë¾Tomra͸¶ÆäÔâµ½ÁË´ó¹æÄ£ÍøÂç¹¥»÷¡£ÕâÊÇÒ»¼Ò»ØÊպͲɿó¹«Ë¾£¬ÔÚ2022ÄêµÄÓªÒµ¶îµ½´ï12ÒÚÃÀÔª¡£¹¥»÷ʼÓÚÉÏÖÜÄ©7ÔÂ16ÈÕ£¬ÎªÁËÍ£Ö¹¹¥»÷£¬Tomra¹Ø±ÕÁ˲¿ÃÅ·þÎñ¡£ÔÚ¼¯ÍŲãÃ棬ÆäÄÚ²¿IT·þÎñºÍ²¿Ãźǫ́ӦÓÃÈÔÈ»´¦ÓÚÀëÏß״̬£¬Ó°ÏìÁ˹©Ó¦Á´¹ÜÀí£¬Ö÷ÒªµÄ°ì¹«ËùÔÚ´¦ÓÚÀëÏß״̬£¬Ô±¹¤±»ÒªÇóÔ¶³Ì°ì¹«¡£Ä¿Ç°£¬ÉÐÎÞºÚ¿ÍÍÅ»ïÉù³ÆΪ´ËÊÂÂôÁ¦¡£
https://www.theregister.com/2023/07/18/tomra_cyberattack/
3¡¢WordfenceÅû¶ÀûÓÃWPÖ§¸¶²å¼þ©¶´½Ù³ÖÍøÕ¾µÄ¹¥»÷
7ÔÂ17ÈÕ£¬WordfenceÅû¶ÁËÀûÓÃWordPress WooCommerce Payments²å¼þÖЩ¶´µÄ´ó¹æÄ£¹¥»÷»î¶¯¡£¹¥»÷¿ªÊ¼ÓÚ7ÔÂ14ÈÕ£¬²¢ÔÚÖÜÁùµ½´ï·åÖµ£¬Õë¶Ô15.7Íò¸öÍøÕ¾ÌᳫÁË130Íò´Î¹¥»÷¡£´Ë´Î»î¶¯ÀûÓÃÁË3ÔÂ23ÈÕ±»ÐÞ¸´µÄ©¶´CVE-2023-28121£¬¹¥»÷ÕßÀûÓø鶴ÔÚÄ¿±êÉ豸ÉÏ°²×°WP Console²å¼þ»ò´´½¨¹ÜÀíÔ±ÕË»§¡£¶ÔÓÚ°²×°ÁËWP ConsoleµÄϵͳ£¬¹¥»÷ÕßÀûÓòå¼þÖ´ÐÐPHP´úÂ룬ÔÚ·þÎñÆ÷ÉÏ°²×°ÎļþÉÏ´«·¨Ê½£¬¼´Ê¹Â©¶´±»ÐÞ¸´ºó£¬¸Ã·¨Ê½ÈÔ¿ÉÓÃ×÷ºóÃÅ¡£
https://www.wordfence.com/blog/2023/07/massive-targeted-exploit-campaign-against-woocommerce-payments-underway/
4¡¢vpnMentor·¢ÏÖ¶à¸öÔ¼»áÓ¦ÓõÄÔ¼230ÍòÌõ¼Ç¼й¶
vpnMentorÔÚ7ÔÂ17ÈÕ³ÆÆäÒ»¸ö°üÂÞԼĪ230ÍòÌõ¼Ç¼µÄÎÞÃÜÂë±£»¤µÄÊý¾Ý¿â¡£½øÒ»·¨Ê½²éÏÔʾ£¬ÕâЩÊý¾ÝÉæ¼°¶à¸öÔ¼»áÓ¦Ó㬿ÉÄÜÒòΪÕâЩӦÓÃÊôÓÚͬһ¸ö¹«Ë¾£¬»òÓÉͬһ¹«Ë¾¿ª·¢¡£Ð¹Â¶¼Ç¼¹²2357896Ìõ£¬×ܾÞϸ340.6 GB£¬°üÂÞÐÕÃû¡¢Õʺš¢µç×ÓÓʼþºÍÃÜÂëµÈÐÅÏ¢£¬ÉõÖÁ»¹ÓÐ969571ÕÅÓû§Í¼Ïñ¡£´ËÍ⣬¸ÃÊý¾Ý¿â»¹°üÂÞ¹ûÈ»µÄSDKÎļþ£¬Õâ¿ÉÄܻᱻ¹¥»÷ÕßÓÃÓÚ´´½¨´øÓÐÒþ²Ø¶ñÒ⹦Ч»ò©¶´µÄÓ¦Ó÷¨Ê½¡£
https://www.vpnmentor.com/news/report-419dating-breach/
5¡¢JumpCloud¹ûÈ»Æä½üÆÚÔâµ½µÄÄþ¾²Ê¼þµÄϸ½ÚÐÅÏ¢
ýÌå7ÔÂ18Èճƣ¬ÃÀ¹úÆóÒµÈí¼þ¹«Ë¾JumpCloud¹ûÈ»ÁËÆä½üÆÚÔâµ½µÄÄþ¾²Ê¼þµÄÏêÇ顣ԼĪһ¸öÔÂÇ°£¬Ò»¸öÓɹú¼ÒÖ§³ÖµÄºÚ¿ÍÍÅ»ïÈëÇÖÁËÆäϵͳ¡£¸Ã¹«Ë¾ÓÚ6ÔÂ27ÈÕ·¢ÏÖÁËÕâһʼþ£¬¼´¹¥»÷Õßͨ¹ýÓã²æʽµöÓã¹¥»÷ÈëÇÖÆäϵͳһÖܺó¡£Ö®ºó¶Ô¸ÃʼþÕ¹¿ªÊӲ죬·¢Ïִ˴ι¥»÷µÄÕë¶ÔÐÔ¼«Ç¿£¬Ö»Õë¶ÔÌض¨¿Í»§£¬¹¥»÷Õß½«Êý¾Ý×¢ÈëÁËJumpCloudµÄÃüÁî¿ò¼Ü¡£ÎªÁËÓ¦¶Ô´Ë´Î¹¥»÷£¬¸Ã¹«Ë¾¾ö¶¨¸ü»»APIÃÜÔ¿²¢Öؽ¨±»ÈëÇֵĻù´¡ÉèÊ©¡£
https://securityaffairs.com/148547/apt/jumpcloud-nation-state-actor-attack.html
6¡¢FACCTÐû²¼¹ØÓÚRedCurl×î½ü¹¥»÷ºÍ¹¤¾ßµÄ·ÖÎö³ÂËß
7ÔÂ17ÈÕ£¬FACCTÐû²¼³ÂË߳ƣ¬RedCurl½üÆÚ¹¥»÷ÁËÒ»¼Ò¶íÂÞ˹µÄ´óÐÍÒøÐкÍÒ»¼Ò°Ä´óÀûÑǵĹ«Ë¾¡£FAACTÌåÏÖ£¬RedCurlÔøÁ½´ÎʵÑé¹¥»÷Õâ¼Ò¶íÂÞ˹ÒøÐУ¬ÔÚ2022Äê11ÔµĵÚÒ»´ÎʵÑéÖУ¬ËûÃÇʹÓÃÁ˵öÓãÓʼþ£¬µ«Ê§°ÜÁË¡£ÔÚ½ñÄê5Ô£¬¸ÃÍÅ»ïÀÖ³ÉÈëÇÖÁ˸ÃÒøÐеÄÒ»Ãû³Ð°üÉÌ£¬ÒÔÈëÇÖÄ¿±êµÄ»ù´¡ÉèÊ©¡£6Ô£¬RedCurlÔÚ¶Ô°Ä´óÀûÑǹ«Ë¾µÄ¹¥»÷ÖÐʹÓÃÁËÏàͬµÄ¼ÆıºÍ¹¤¾ß¡£Ñо¿ÈËÔ±»¹·¢ÏÖÁËÕâЩ»î¶¯Ê¹ÓõÄй¤¾ßRedCurl.SimpleDownloader£¬Ä¿Ç°ÈÔÔÚ¿ª·¢ÖС£
https://www.facct.ru/blog/redcurl-2023/