ownCloudÖÐÎó²îCVE-2023-49103Òѱ»´ó¹æÄ£Ê¹ÓÃ
Ðû²¼Ê±¼ä 2023-11-301¡¢ownCloudÖÐÎó²îCVE-2023-49103Òѱ»´ó¹æÄ£Ê¹ÓÃ
¾ÝýÌå11ÔÂ28ÈÕ±¨µÀ£¬£¬£¬£¬£¬ownCloudÖеÄÎó²î£¨CVE-2023-49103£©Òѱ»´ó¹æÄ£Ê¹Óᣡ£¡£¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ10£¬£¬£¬£¬£¬¿ÉÓÃÀ´ÇÔÈ¡ÖÎÀíÔ±ÃÜÂë¡¢ÓʼþЧÀÍÆ÷ƾ֤ºÍÔÊÐíÖ¤ÃÜÔ¿µÈ£¬£¬£¬£¬£¬ÒÑÓÚ11ÔÂ21ÈÕ±»ÐÞ¸´¡£¡£¡£¡£¡£Çå¾²¹«Ë¾Greynoise³Æ£¬£¬£¬£¬£¬ËüÊӲ쵽´Ó11ÔÂ25ÈÕ×îÏÈ£¬£¬£¬£¬£¬¸ÃÎó²î¾ÍÔÚÒ°Íâ±»´ó¹æÄ£Ê¹Ó㬣¬£¬£¬£¬ÇÒ³ÊÉÏÉýÇ÷ÊÆ¡£¡£¡£¡£¡£Greynoise×·×Ùµ½12¸öΨһµÄIPµØµãʹÓÃÁËCVE-2023-49103¡£¡£¡£¡£¡£Shadowserver³ÆÆäÏÖÔÚ¼ì²âµ½Áè¼Ý11000¸ö̻¶ʵÀý£¬£¬£¬£¬£¬ÆäÖдó´ó¶¼Î»Óڵ¹ú¡¢ÃÀ¹ú¡¢·¨¹úºÍ¶íÂÞ˹¡£¡£¡£¡£¡£ÓÉÓÚʹÓÃÇéÐÎÔ½À´Ô½¶à£¬£¬£¬£¬£¬½¨ÒéÖÎÀíÔ±Á¬Ã¦ÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£
https://securityaffairs.com/154928/hacking/owncloud-cve-2023-49103-actively-exploited.html
2¡¢Zeroed-In±»¹¥»÷µ¼ÖÂDollar Tree½ü200ÍòÈËÊý¾Ýй¶
¾Ý11ÔÂ29ÈÕ±¨µÀ£¬£¬£¬£¬£¬ÕÛ¿ÛÁãÊÛ¹«Ë¾Dollar TreeÊܵ½µÚÈý·½Ð§ÀÍÌṩÉÌZeroed-In TechnologiesµÄÓ°Ï죬£¬£¬£¬£¬1977486È˵ÄÐÅϢй¶¡£¡£¡£¡£¡£Dollar TreeÔÚÃÀ¹úºÍ¼ÓÄôóµÄ23000¸öËùÔÚı»®Dollar TreeºÍFamily DollarÊÐËÁ¡£¡£¡£¡£¡£Õë¶ÔZeroed-InµÄ¹¥»÷±¬·¢ÓÚ8ÔÂ7ÈÕÖÁ8ÈÕ£¬£¬£¬£¬£¬¹¥»÷ÕßÀÖ³ÉÇÔÈ¡ÁËDollar TreeÔ±¹¤µÄÐÕÃû¡¢³öÉúÈÕÆÚºÍÉç»áÇå¾²ºÅÂë(SSN)¡£¡£¡£¡£¡£Zeroed-In½«ÎªÊÜÓ°ÏìСÎÒ˽¼ÒÌṩ12¸öÔµÄÉí·Ý±£»£»£»£»£»¤ºÍÐÅÓÃ¼à¿ØÐ§ÀÍ¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬Zeroed-InµÄÆäËü¿Í»§Ò²¿ÉÄÜÊܵ½¸ÃÊÂÎñµÄÓ°Ï죬£¬£¬£¬£¬µ«ÕâÒ»µãÉÐδ»ñµÃ֤ʵ¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/dollar-tree-hit-by-third-party-data-breach-impacting-2-million-people/
3¡¢QilinÍÅ»ïÉù³Æ¶ÔÆû³µÁã¼þ¹©Ó¦ÉÌYanfengµÄ¹¥»÷ÈÏÕæ
11ÔÂ28ÈÕ±¨µÀ£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïQilinÉù³Æ¶ÔÈ«Çò×î´óÆû³µÁ㲿¼þ¹©Ó¦ÉÌÖ®Ò»YanfengµÄ¹¥»÷ÈÏÕæ¡£¡£¡£¡£¡£Óб¨µÀ³Æ£¬£¬£¬£¬£¬±¾ÔÂÔçЩʱ¼ä£¬£¬£¬£¬£¬¸Ã¹«Ë¾Ôâµ½¹¥»÷²¨¼°µ½ÁËStellantis£¬£¬£¬£¬£¬ÆÈʹÆä±±ÃÀ¹¤³§Í£²ú¡£¡£¡£¡£¡£11ÔÂ27ÈÕ£¬£¬£¬£¬£¬Qilin£¨ÓÖ³ÆAgenda£©Éù³Æ¹¥»÷ÁËYanfeng£¬£¬£¬£¬£¬²¢Ðû²¼Á˶à¸öÑù±¾£¬£¬£¬£¬£¬Éæ¼°²ÆÎñÎļþ¡¢±£ÃÜÐÒé¡¢±¨¼ÛÎļþ¡¢ÊÖÒÕÊý¾Ý±íºÍÄÚ²¿±¨¸æµÈ¡£¡£¡£¡£¡£QilinÍþвҪÔÚδÀ´¼¸ÌìÄÚÐû²¼ÆäÕÆÎÕµÄËùÓÐÊý¾Ý£¬£¬£¬£¬£¬µ«Ã»ÓÐÉ趨ÏêϸµÄ×èÖ¹ÈÕÆÚ¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/qilin-ransomware-claims-attack-on-automotive-giant-yanfeng/
4¡¢±±µÂ¿ËÈøË¹ÖÝË®Îñ¾ÖNTMWDÔâµ½DaixinµÄÀÕË÷¹¥»÷
ýÌå11ÔÂ28Èճƣ¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïDaixin½«±±µÂ¿ËÈøË¹ÊÐÕþË®Çø(NTMWD)Ìí¼Óµ½ÆäÐ¹Â¶ÍøÕ¾¡£¡£¡£¡£¡£NTMWDÊÇÒ»¸öÕþ¸®»ú¹¹£¬£¬£¬£¬£¬Îª¸ÃÖÝÁè¼Ý13¸ö¶¼»áµÄ200ÍòÈËÌṩЧÀÍ¡£¡£¡£¡£¡£NTMWD³ÆÆäÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬´ó²¿·ÖÓªÒµÒѾ»Ö¸´¡£¡£¡£¡£¡£Ëü»¹³Æ½¹µã¹©Ë®¡¢·ÏË®´¦Öóͷ£ºÍ¹ÌÌå·ÏÎï´¦Öóͷ£Ð§ÀͲ¢Î´Êܵ½Ó°Ï죬£¬£¬£¬£¬µ«µç»°ÏµÍ³Êܵ½Ó°Ïì¡£¡£¡£¡£¡£ÀÕË÷ÍÅ»ïÉù³ÆÇÔÈ¡ÁË33844¸öÎļþ£¬£¬£¬£¬£¬°üÀ¨¶Ê»á¾Û»á¼Í¼¡¢ÄÚ²¿ÏîÄ¿Îĵµ¡¢Ö°Ô±ÏêϸÐÅÏ¢ºÍÉ󼯱¨¸æµÈ¡£¡£¡£¡£¡£
https://therecord.media/north-texas-water-utility-cyberattack
5¡¢ÀÕË÷Èí¼þDJVUµÄбäÌåXaroαװ³ÉÆÆ½âÈí¼þÀ´Èö²¥
11ÔÂ29ÈÕýÌ峯£¬£¬£¬£¬£¬Cybereason·¢Ã÷ÀÕË÷Èí¼þDJVUµÄбäÌåXaroÕýÔÚαװ³ÉÆÆ½âÈí¼þÀ´Èö²¥¡£¡£¡£¡£¡£DJVU×Ô¼ºÊÇÀÕË÷Èí¼þSTOPµÄ±äÖÖ£¬£¬£¬£¬£¬Ð±äÌåΪÊÜÓ°ÏìÎļþÌí¼ÓÁË.xaroÀ©Õ¹Ãû£¬£¬£¬£¬£¬Òò¶ø±»ÃüÃûΪXaro¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Xaro»¹ÓëÆäËüÖÖÖÖ¶ñÒâÎļþÒ»Æð·Ö·¢£¬£¬£¬£¬£¬ÕâÅú×¢¹¥»÷Õß½ÓÄÉÁË"shotgun"·½·¨¡£¡£¡£¡£¡£ÆäËü¶ñÒâÈí¼þ°üÀ¨ÖÖÖÖÐÅÏ¢ÇÔÈ¡³ÌÐò¡¢¼ÓÔØ³ÌÐòºÍÏÂÔØ³ÌÐò£¬£¬£¬£¬£¬ÕâÅú×¢³ýÁËÖ´ÐÐÀÕË÷¹¥»÷Í⣬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ»¹¶ÔË«ÖØÀÕË÷ºÍ½øÒ»²½ÈëÇÖÄ¿µÄÅÌËã»ú¸ÐÐËȤ¡£¡£¡£¡£¡£
https://thehackernews.com/2023/11/djvu-ransomwares-latest-variant-xaro.html
6¡¢Ñо¿Ö°Ô±ÑÝʾÔõÑùʹÓÃÐÂBLUFFS¹¥»÷Ð®ÖÆÀ¶ÑÀÅþÁ¬
ýÌå11ÔÂ28ÈÕ±¨µÀ£¬£¬£¬£¬£¬EurecomÑо¿Ö°Ô±¿ª·¢ÁË6ÖÖÐµĹ¥»÷·½·¨£¬£¬£¬£¬£¬Í³³ÆÎª¡°BLUFFS¡±¡£¡£¡£¡£¡£ËüÃÇ¿ÉÒÔÆÆËðÀ¶ÑÀ»á»°µÄÉñÃØÐÔ£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂ×°±¸Ã°³äºÍÖÐÐÄÈË£¨MitM£©¹¥»÷¡£¡£¡£¡£¡£¹¥»÷ͨ¹ýʹÓûỰÃÜÔ¿ÍÆµ¼Àú³ÌÖеÄ4¸öÎó²î£¨ÆäÖÐÁ½¸öÊÇÐÂÎó²î£©À´ÊµÏֵ쬣¬£¬£¬£¬Îó²î»áÇ¿ÖÆÍÆµ¼³öÒ»¸ö¼ò¶Ì¡¢Î¢ÈõÇÒ¿ÉÕ¹ÍûµÄ»á»°ÃÜÔ¿£¨SKC£©¡£¡£¡£¡£¡£½ÓÏÂÀ´£¬£¬£¬£¬£¬¹¥»÷Õß¶ÔÃÜÔ¿¾ÙÐб©Á¦ÆÆ½â£¬£¬£¬£¬£¬´Ó¶ø½âÃÜÒÑÍùµÄͨѶ£¬£¬£¬£¬£¬²¢½âÃÜ»ò¿ØÖÆÎ´À´µÄͨѶ¡£¡£¡£¡£¡£ÕâЩÎÊÌâ±»×·×ÙΪCVE-2023-24023¾ÙÐиú×Ù£¬£¬£¬£¬£¬Ó°ÏìÁËÀ¶ÑÀ½¹µã¹æ·¶4.2ÖÁ5.4¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-bluffs-attack-lets-attackers-hijack-bluetooth-connections/


¾©¹«Íø°²±¸11010802024551ºÅ