ownCloudÖЩ¶´CVE-2023-49103Òѱ»´ó¹æÄ£ÀûÓÃ
Ðû²¼Ê±¼ä 2023-11-301¡¢ownCloudÖЩ¶´CVE-2023-49103Òѱ»´ó¹æÄ£ÀûÓÃ
¾ÝýÌå11ÔÂ28ÈÕ±¨µÀ£¬ownCloudÖеÄ©¶´£¨CVE-2023-49103£©Òѱ»´ó¹æÄ£ÀûÓ᣸é¶´µÄCVSSÆÀ·ÖΪ10£¬¿ÉÓÃÀ´ÇÔÈ¡¹ÜÀíÔ±ÃÜÂë¡¢Óʼþ·þÎñÆ÷ƾ¾ÝºÍÐí¿ÉÖ¤ÃÜÔ¿µÈ£¬ÒÑÓÚ11ÔÂ21ÈÕ±»ÐÞ¸´¡£Äþ¾²¹«Ë¾Greynoise³Æ£¬ËüÊӲ쵽´Ó11ÔÂ25ÈÕ¿ªÊ¼£¬¸Ã©¶´¾ÍÔÚÒ°Íâ±»´ó¹æÄ£ÀûÓã¬ÇÒ³ÊÉÏÉýÇ÷ÊÆ¡£Greynoise×·×Ùµ½12¸öΨһµÄIPµØÖ·ÀûÓÃÁËCVE-2023-49103¡£Shadowserver³ÆÆäĿǰ¼ì²âµ½Áè¼Ý11000¸ö̻¶ʵÀý£¬ÆäÖдó¶àÊýλÓڵ¹ú¡¢ÃÀ¹ú¡¢·¨¹úºÍ¶íÂÞ˹¡£ÓÉÓÚÀûÓÃÇé¿öÔ½À´Ô½¶à£¬½¨Òé¹ÜÀíÔ±Á¢¼´ÐÞ¸´¸Ã©¶´¡£
https://securityaffairs.com/154928/hacking/owncloud-cve-2023-49103-actively-exploited.html
2¡¢Zeroed-In±»¹¥»÷µ¼ÖÂDollar Tree½ü200ÍòÈËÊý¾Ýй¶
¾Ý11ÔÂ29ÈÕ±¨µÀ£¬ÕÛ¿ÛÁãÊÛ¹«Ë¾Dollar TreeÊܵ½µÚÈý·½·þÎñÌṩÉÌZeroed-In TechnologiesµÄÓ°Ï죬1977486È˵ÄÐÅϢй¶¡£Dollar TreeÔÚÃÀ¹úºÍ¼ÓÄôóµÄ23000¸öËùÔÚ¾ÓªDollar TreeºÍFamily DollarÉ̵ꡣÕë¶ÔZeroed-InµÄ¹¥»÷·¢ÉúÓÚ8ÔÂ7ÈÕÖÁ8ÈÕ£¬¹¥»÷ÕßÀÖ³ÉÇÔÈ¡ÁËDollar TreeÔ±¹¤µÄÐÕÃû¡¢³öÉúÈÕÆÚºÍÉç»áÄþ¾²ºÅÂë(SSN)¡£Zeroed-In½«ÎªÊÜÓ°Ïì¸öÈËÌṩ12¸öÔµÄÉí·Ý±£»¤ºÍÐÅÓÃ¼à¿Ø·þÎñ¡£¾ÝϤ£¬Zeroed-InµÄÆäËü¿Í»§Ò²¿ÉÄÜÊܵ½¸ÃʼþµÄÓ°Ï죬µ«ÕâÒ»µãÉÐδµÃµ½Ö¤Êµ¡£
https://www.bleepingcomputer.com/news/security/dollar-tree-hit-by-third-party-data-breach-impacting-2-million-people/
3¡¢QilinÍÅ»ïÉù³Æ¶ÔÆû³µÁã¼þ¹©Ó¦ÉÌYanfengµÄ¹¥»÷ÂôÁ¦
11ÔÂ28ÈÕ±¨µÀ£¬ÀÕË÷ÍÅ»ïQilinÉù³Æ¶ÔÈ«Çò×î´óÆû³µÁ㲿¼þ¹©Ó¦ÉÌÖ®Ò»YanfengµÄ¹¥»÷ÂôÁ¦¡£Óб¨µÀ³Æ£¬±¾ÔÂÔçЩʱºò£¬¸Ã¹«Ë¾Ôâµ½¹¥»÷²¨¼°µ½ÁËStellantis£¬ÆÈʹÆä±±ÃÀ¹¤³§Í£²ú¡£11ÔÂ27ÈÕ£¬Qilin£¨ÓÖ³ÆAgenda£©Éù³Æ¹¥»÷ÁËYanfeng£¬²¢Ðû²¼Á˶à¸öÑù±¾£¬Éæ¼°²ÆÕþÎļþ¡¢±£ÃÜÐÒé¡¢±¨¼ÛÎļþ¡¢¼¼ÊõÊý¾Ý±íºÍÄÚ²¿³ÂËߵȡ£QilinÍþвҪÔÚδÀ´¼¸ÌìÄÚÐû²¼ÆäÕÆÎÕµÄËùÓÐÊý¾Ý£¬µ«Ã»ÓÐÉ趨¾ßÌåµÄ½ØÖ¹ÈÕÆÚ¡£
https://www.bleepingcomputer.com/news/security/qilin-ransomware-claims-attack-on-automotive-giant-yanfeng/
4¡¢±±µÂ¿ËÈøË¹ÖÝË®Îñ¾ÖNTMWDÔâµ½DaixinµÄÀÕË÷¹¥»÷
ýÌå11ÔÂ28Èճƣ¬ÀÕË÷ÍÅ»ïDaixin½«±±µÂ¿ËÈøË¹ÊÐÕþË®Çø(NTMWD)Ìí¼Óµ½ÆäÐ¹Â¶ÍøÕ¾¡£NTMWDÊÇÒ»¸öÕþ¸®»ú¹¹£¬Îª¸ÃÖÝÁè¼Ý13¸ö¶¼ÊеÄ200ÍòÈËÌṩ·þÎñ¡£NTMWD³ÆÆäÔâµ½ÍøÂç¹¥»÷£¬´ó²¿ÃÅÒµÎñÒѾ»Ö¸´¡£Ëü»¹³ÆºËÐũˮ¡¢·ÏË®´¦Öú͹ÌÌå·ÏÎï´¦Ö÷þÎñ²¢Î´Êܵ½Ó°Ï죬µ«µç»°ÏµÍ³Êܵ½Ó°Ïì¡£ÀÕË÷ÍÅ»ïÉù³ÆÇÔÈ¡ÁË33844¸öÎļþ£¬°üÂÞ¶Ê»á»áÒé¼Ç¼¡¢ÄÚ²¿ÏîÄ¿Îĵµ¡¢ÈËÔ±ÏêϸÐÅÏ¢ºÍÉ󼯳ÂËߵȡ£
https://therecord.media/north-texas-water-utility-cyberattack
5¡¢ÀÕË÷Èí¼þDJVUµÄбäÌåXaroαװ³ÉÆÆ½âÈí¼þÀ´Á÷´«
11ÔÂ29ÈÕýÌ峯£¬Cybereason·¢ÏÖÀÕË÷Èí¼þDJVUµÄбäÌåXaroÕýÔÚαװ³ÉÆÆ½âÈí¼þÀ´Á÷´«¡£DJVU×Ô¼ºÊÇÀÕË÷Èí¼þSTOPµÄ±äÖÖ£¬Ð±äÌåΪÊÜÓ°ÏìÎļþÌí¼ÓÁË.xaroÀ©Õ¹Ãû£¬Òò¶ø±»ÃüÃûΪXaro¡£´ËÍ⣬Xaro»¹ÓëÆäËüÖÖÖÖ¶ñÒâÎļþÒ»Æð·Ö·¢£¬Õâ±íÃ÷¹¥»÷Õß½ÓÄÉÁË"shotgun"·½Ê½¡£ÆäËü¶ñÒâÈí¼þ°üÂÞÖÖÖÖÐÅÏ¢ÇÔÈ¡·¨Ê½¡¢¼ÓÔØ·¨Ê½ºÍÏÂÔØ·¨Ê½£¬Õâ±íÃ÷³ýÁËÖ´ÐÐÀÕË÷¹¥»÷Í⣬¹¥»÷Õß¿ÉÄÜ»¹¶ÔË«ÖØÀÕË÷ºÍ½øÒ»²½ÈëÇÖÄ¿±ê¼ÆËã»ú¸ÐÐËȤ¡£
https://thehackernews.com/2023/11/djvu-ransomwares-latest-variant-xaro.html
6¡¢Ñо¿ÈËÔ±ÑÝʾÈçºÎÀûÓÃÐÂBLUFFS¹¥»÷½Ù³ÖÀ¶ÑÀÁ¬½Ó
ýÌå11ÔÂ28ÈÕ±¨µÀ£¬EurecomÑо¿ÈËÔ±¿ª·¢ÁË6ÖÖÐµĹ¥»÷·½Ê½£¬Í³³ÆÎª¡°BLUFFS¡±¡£ËüÃÇ¿ÉÒÔÆÆ»µÀ¶ÑÀ»á»°µÄ»úÃÜÐÔ£¬´Ó¶øµ¼ÖÂÉ豸ð³äºÍÖмäÈË£¨MitM£©¹¥»÷¡£¹¥»÷ͨ¹ýÀûÓûỰÃÜÔ¿ÍÆµ¼¹ý³ÌÖеÄ4¸ö©¶´£¨ÆäÖÐÁ½¸öÊÇЩ¶´£©À´ÊµÏֵģ¬Â©¶´»áÇ¿ÖÆÍÆµ¼³öÒ»¸ö¼ò¶Ì¡¢Î¢ÈõÇÒ¿ÉÔ¤²âµÄ»á»°ÃÜÔ¿£¨SKC£©¡£½ÓÏÂÀ´£¬¹¥»÷Õß¶ÔÃÜÔ¿½øÐб©Á¦ÆÆ½â£¬´Ó¶ø½âÃܹýÈ¥µÄͨÐÅ£¬²¢½âÃÜ»ò¿ØÖÆÎ´À´µÄͨÐÅ¡£ÕâЩÎÊÌâ±»×·×ÙΪCVE-2023-24023½øÐиú×Ù£¬Ó°ÏìÁËÀ¶ÑÀºËÐĹ淶4.2ÖÁ5.4¡£
https://www.bleepingcomputer.com/news/security/new-bluffs-attack-lets-attackers-hijack-bluetooth-connections/