GoogleÐû²¼Çå¾²¸üÐÂÐÞ¸´ChromeÖеĶà¸öÎó²î

Ðû²¼Ê±¼ä 2023-03-23

1¡¢GoogleÐû²¼Çå¾²¸üÐÂÐÞ¸´ChromeÖеĶà¸öÎó²î


GoogleÔÚ3ÔÂ21ÈÕÐû²¼Çå¾²¸üР£¬ÐÞ¸´ÁËChromeÖеÄ8¸öÎó²î¡£ÆäÖÐ £¬½ÏΪÑÏÖØµÄÊÇPasswordsÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2023-1528£©¡¢WebHIDÖеÄÄÚ´æÔ½½ç»á¼ûÎó²î£¨CVE-2023-1529£©¡¢ÔÚPDFÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2023-1530£©ºÍGPUÊÓÆµÖеÄÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2023-1532£©µÈ¡£GoogleÌåÏÖ £¬ÔÚ´ó´ó¶¼Óû§¸üÐÂÐÞ¸´³ÌÐò֮ǰ £¬Îó²îÏêϸÐÅÏ¢ºÍÁ´½ÓµÄ»á¼û¿ÉÄÜ»áÊܵ½ÏÞÖÆ¡£


https://chromereleases.googleblog.com/2023/03/stable-channel-update-for-desktop_21.html


2¡¢Á÷ýÌåÆ½Ì¨Lionsgate½ü3000ÍòÌõ¼Í¼й¶


¾ÝCybernewsÔÚ3ÔÂ22ÈÕ±¨µÀ £¬ÓµÓÐ3700Íò¶©»§µÄÊÓÆµÁ÷ýÌåÆ½Ì¨Lionsgate PlayµÄElasticSearchÉèÖùýʧ £¬Ð¹Â¶ÁËÓû§Êý¾Ý¡£Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸ö20 GB·þÎñÆ÷ÈÕÖ¾ £¬°üÀ¨½ü3000ÍòÌõÌõÄ¿ £¬×îÔçµÄÈÕÆÚÊÇ2022Äê5Ô¡£ÈÕ־й¶Á˶©ÔÄÕßµÄIPµØµãÒÔ¼°ÓйØ×°±¸¡¢²Ù×÷ϵͳºÍWebä¯ÀÀÆ÷µÄÓû§ÐÅÏ¢¡ £»¹Ð¹Â¶ÁËÆ½Ì¨µÄʹÓÃÊý¾Ý £¬ÈçÓû§Ô¢Ä¿ÄÚÈݵÄÎÊÌâIDºÍËÑË÷ÅÌÎÊµÈ £¬Í¨³£¿ÉÓÃÓÚÆÊÎöºÍÐÔÄܸú×Ù¡£Cybernews¾Í´ËÊÂÁªÏµÁËLionsgate £¬¸Ã¹«Ë¾µÄ»ØÓ¦ÊÇÒѽ«·þÎñÆ÷± £»¤ÆðÀ´ £¬¿ÉÊÇ×èÖ¹ÏÖÔÚÉÐδÌṩ¹Ù·½»ØÓ¦¡£


https://cybernews.com/security/lionsgate-data-leak/


3¡¢REF2924ÍÅ»ïʹÓÃNAPLISTENER¹¥»÷¶«ÄÏÑǵØÇø


¾ÝýÌå3ÔÂ20ÈÕ±¨µÀ £¬REF2924ʹÓÃжñÒâÈí¼þNAPLISTENER¹¥»÷ÄÏÑǺͶ«ÄÏÑǵÄ×éÖ¯¡£Elastic³Æ¸ÃÍÅ»ïʹÓÃÁ˶àÖÖ»úÖÆ £¬½«Öصã´ÓÊý¾ÝÇÔÈ¡×ªÒÆµ½³¤ÆÚ»á¼û¡£2023Äê1ÔÂ20ÈÕ £¬Ò»¸öеĿÉÖ´ÐÐÎļþWmdtc.exe±»½¨Éè²¢×÷ΪWindows·þÎñ×°Öà £¬Í¨¹ýαװ³ÉMicrosoftÂþÑÜʽÊÂÎñ´¦Öóͷ£Ð­µ÷Æ÷·þÎñ(Msdtc.exe)ʹÓõÄÕýµ±¶þ½øÖÆÎļþ¡£Wmdtc.exe±»³ÆÎªNAPLISTENER £¬ÕâÊÇÒ»¸öÓÃC#¿ª·¢µÄHTTPÕìÌýÆ÷ £¬Ö¼ÔÚÈÆ¹ý»ùÓÚÍøÂçµÄÇå¾²¼ì²â¡£


https://www.elastic.co/cn/security-labs/naplistener-more-bad-dreams-from-the-developers-of-siestagraph


4¡¢LockBitÒ²³ÆÒÑÇÔÈ¡²¢½«¹ûÕæ°Â¿ËÀ¼ÊÐϵͳÖеÄÎļþ


¾Ý3ÔÂ21ÈÕ±¨µÀ £¬ÁíÒ»¸öÀÕË÷ÍÅ»ïLockBitÒ²Éù³Æ´Ó°Â¿ËÀ¼ÊÐϵͳÖÐÇÔÈ¡ÁËÎļþ¡£È»¶ø £¬¸ÃÍÅ»ïÉÐδÐû²¼ÈκÎÖ¤¾ÝÀ´Ö¤ÊµËûÃǵĹ¥»÷Ô˶¯¡£ÕâÊÇ×ÔPlayÍÅ»ïÔÚ3Ô³õÌåÏֶ԰¿ËÀ¼ÊеÄÍøÂç¹¥»÷ÈÏÕæºó £¬µÚ¶þ¸öÀÕË÷ÍÅ»ïÉù³ÆÇÔÈ¡ÁËÊý¾Ý¡£LockBitÔÚÆäÍøÕ¾ÉÏÌí¼ÓÁËÐÂÌõÄ¿ £¬²¢Íþв½«ÔÚ4ÔÂ10ÈÕ¹ûÕæËùÓÐÊý¾Ý¡£°Â¿ËÀ¼ÊÐÉÐδ¾Í´ËʽÒÏþÉùÃ÷¡£Ñо¿Ö°Ô±ÌåÏÖ £¬LockBitÔøÔÚ2022Äê6ÔÂÉù³ÆËüÈëÇÖÁËMandiantµÄϵͳ²¢ÇÔÈ¡ÁËÊýÊ®Íò¸öÎļþ £¬ØÊºóÕⱻ֤ʵÊÇÒ»¸öÐû´«àåÍ·¡£


https://www.bleepingcomputer.com/news/security/lockbit-ransomware-gang-now-also-claims-city-of-oakland-breach/


5¡¢ChatGPT·ºÆðBug¿ÉÒÔ¿´µ½ÆäËûÓû§µÄ¶Ô»°ÀúÊ·ÎÊÌâ


ýÌå3ÔÂ21ÈÕ³Æ £¬ChatGPT·ºÆðÁËÒ»¸öBug £¬µ¼ÖÂÆäËûÓû§µÄ̸ÌìÀúʷй¶¡£¸ÃÎÊÌâ×î³õÊÇÓÉһλÏÓÒÉÆäÕÊ»§±»ºÚµÄÓû§ÔÚRedditÉϱ¨¸æµÄ £¬ËûÔÚ¶Ô»°ÀúÊ·ÎÊÌâÖз¢Ã÷Á˲»ÊôÓÚ×Ô¼ºµÄ¶Ô»°¡£ÐÂÎÅ´«¿ªºó £¬ÍÆÌØÉÏµÄÆäËûÓû§Ò²Éù³ÆÔÚ×Ô¼ºµÄÕ˺ÅÉÏ¿´µ½Á˱ðÈ˵Ä̸Ìì¼Í¼¡£Ðí¶àÓû§³Æ¸ÃÎÊÌâÑÏÖØÇÖÕ¼ÁËÓû§Òþ˽¡£ChatGPTÓÚ±¾ÖÜÒ»ÔÝʱ½ûÓÃÁËÆä̸Ìì·þÎñ £¬ÒÔÊÓ²ìºÍÐÞ¸´¸ÃÎó²î¡£3ÔÂ23ÈÕ £¬OpenAI CEO Sam AltmanÈÏ¿ÉÆä¿ªÔ´¿âÖеÄÒ»¸ö¹ýʧµ¼ÖÂÓû§µÄ̸ÌìÀúʷй¶ £¬²¢Ðû²¼ÁËÍÆÎÄÖÂǸ¡£


https://www.hackread.com/chatgpt-bug-conversation-history-titles/


6¡¢Unit 42Ðû²¼2023ÄêÀÕË÷Èí¼þÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ


3ÔÂ21ÈÕ £¬Unit 42Ðû²¼ÁË2023ÄêÀÕË÷Èí¼þÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£±¨¸æÖ¸³ö £¬¶àÖØÀÕË÷Õ½ÂÔµÄʹÓÃÒ»Á¬ÉÏÉý¡£×èÖ¹2022Äêµ× £¬ÔÚÔ¼70%µÄ°¸¼þÖб¬·¢ÁËÊý¾Ýй¶ £¬2021ÄêÖÐÖ»ÓÐÔ¼40%µÄÊý¾Ý±»µÁ¡£É§ÈÅÊÇÁíÒ»ÖÖÀÕË÷Õ½ÂÔ £¬2022Äêµ×Ô¼20%µÄÀÕË÷Èí¼þ°¸¼þ°üÀ¨¸ÃÒòËØ £¬¶ø2021Äê½öÓв»µ½1%¡£ÖÆÔìÒµÊÜ´ËÀ๥»÷×î¶à £¬ÃÀ¹úµÄ×éÖ¯Êܵ½Ó°Ïì×îÑÏÖØ£¨Õ¼42%£©¡£Ñо¿Ö°Ô±Ô¤¼ÆÔÚ2023Äê £¬·ºÆð´óÐÍÔÆÀÕË÷Èí¼þ¹¥»÷¡¢ÄÚ²¿ÍþвÏà¹ØµÄڲƭÀÕË÷ÔöÌíºÍ³öÓÚÕþÖÎÄîÍ·µÄÀÕË÷ÔöÌíµÈ¡£


https://start.paloaltonetworks.com/2023-unit42-ransomware-extortion-report