Google°ä²¼°²È«¸üн¨¸´ChromeÖеĶà¸ö·ì϶

°ä²¼¹¦·ò 2023-03-23

1¡¢Google°ä²¼°²È«¸üн¨¸´ChromeÖеĶà¸ö·ì϶


GoogleÔÚ3ÔÂ21ÈÕ°ä²¼°²È«¸üР£¬½¨¸´ÁËChromeÖеÄ8¸ö·ì϶¡£ÆäÖÐ £¬½ÏΪÑϳÁµÄÊÇPasswordsÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2023-1528£©¡¢WebHIDÖеÄÄÚ´æÔ½½ç½Ó¼û·ì϶£¨CVE-2023-1529£©¡¢ÔÚPDFÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2023-1530£©ºÍGPUÊÓÆµÖеÄÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2023-1532£©µÈ¡£Google°µÊ¾ £¬ÔÚ´óÎÞÊýÓû§¸üн¨¸´·¨Ê½Ö®Ç° £¬·ì϶¾ßÌåÐÅÏ¢ºÍÁ´½ÓµÄ½Ó¼û¿ÉÄÜ»áÊܵ½ÏÞ¶È¡£


https://chromereleases.googleblog.com/2023/03/stable-channel-update-for-desktop_21.html


2¡¢Á÷ýÌåÆ½Ì¨Lionsgate½ü3000Íò±Ê¼Í¼й¶


¾ÝCybernewsÔÚ3ÔÂ22ÈÕ±¨Â· £¬Õ¼ÓÐ3700Íò¶©»§µÄÊÓÆµÁ÷ýÌåÆ½Ì¨Lionsgate PlayµÄElasticSearchÅäÖÃÃýÎó £¬Ð¹Â¶ÁËÓû§Êý¾Ý¡£×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸ö20 GB·þÎñÆ÷ÈÕÖ¾ £¬Ô̺¬½ü3000ÍòÌõÌõ¿î £¬×îÔçµÄÈÕÆÚÊÇ2022Äê5Ô¡£ÈÕ־й¶Á˶©ÔÄÕßµÄIPµØÖ·ÒÔ¼°ÓйØÉ豸¡¢²Ù×÷ϵͳºÍWebä¯ÀÀÆ÷µÄÓû§ÐÅÏ¢¡£»¹Ð¹Â¶ÁËÆ½Ì¨µÄʹÓÃÊý¾Ý £¬ÈçÓû§ÅÔ¹ÛÄÚÈݵıêÌâIDºÍËÑË÷²éÎÊµÈ £¬Í¨³£¿ÉÓÃÓÚ·ÖÎöºÍ»úÄܸú×Ù¡£Cybernews¾Í´ËÊÂÁªÏµÁËLionsgate £¬¸Ã¹«Ë¾µÄ»ØÓ¦ÊÇÒѽ«·þÎñÆ÷±£»¤ÆðÀ´ £¬µ«ÊǽØÖÁĿǰÉÐδÌṩ¹Ù·½»ØÓ¦¡£


https://cybernews.com/security/lionsgate-data-leak/


3¡¢REF2924ÍÅ»ïÀûÓÃNAPLISTENER¹¥»÷¶«ÄÏÑǵØÓò


¾ÝýÌå3ÔÂ20ÈÕ±¨Â· £¬REF2924ÀûÓÃжñÒâÈí¼þNAPLISTENER¹¥»÷ÄÏÑǺͶ«ÄÏÑǵÄ×éÖ¯¡£Elastic³Æ¸ÃÍÅ»ïʹÓÃÁ˶àÖÖ»úÔì £¬½«³Áµã´ÓÊý¾ÝÇÔÈ¡×ªÒÆµ½ÓƾýӼû¡£2023Äê1ÔÂ20ÈÕ £¬Ò»¸öеĿÉÖ´ÐÐÎļþWmdtc.exe±»´´½¨²¢×÷ΪWindows·þÎñ×°Öà £¬Í¨¹ý¼Ù×°³ÉMicrosoftÉ¢²¼Ê½ÊÂÎñ´¦ÖÃЭµ÷Æ÷·þÎñ(Msdtc.exe)ʹÓõĺϷ¨¶þ½øÔìÎļþ¡£Wmdtc.exe±»³ÆÎªNAPLISTENER £¬ÕâÊÇÒ»¸öÓÃC#¿ª·¢µÄHTTPÕìÌýÆ÷ £¬Ö¼ÔÚÈÆ¹ý»ùÓÚÍøÂçµÄ°²È«¼ì²â¡£


https://www.elastic.co/cn/security-labs/naplistener-more-bad-dreams-from-the-developers-of-siestagraph


4¡¢LockBitÒ²³ÆÒÑÇÔÈ¡²¢½«¹«¿ª°Â¿ËÀ¼ÊÐϵͳÖеÄÎļþ


¾Ý3ÔÂ21ÈÕ±¨Â· £¬ÁíÒ»¸öÀÕË÷ÍÅ»ïLockBitÒ²Ðû³Æ´Ó°Â¿ËÀ¼ÊÐϵͳÖÐÇÔÈ¡ÁËÎļþ¡£È»¶ø £¬¸ÃÍÅ»ïÉÐδ°ä²¼ÈκÎÖ¤¾ÝÀ´Ö¤Ã÷ËûÃǵĹ¥»÷»î¶¯¡£ÕâÊÇ×ÔPlayÍÅ»ïÔÚ3Ô³õ°µÊ¾¶Ô°Â¿ËÀ¼ÊеÄÍøÂç¹¥»÷ÕÆ¹Üºó £¬µÚ¶þ¸öÀÕË÷ÍÅ»ïÐû³ÆÇÔÈ¡ÁËÊý¾Ý¡£LockBitÔÚÆäÍøÕ¾ÉÏÔö³¤ÁËÐÂÌõ¿î £¬²¢Íþв½«ÔÚ4ÔÂ10ÈÕ¹«¿ªËùº±¼û¾Ý¡£°Â¿ËÀ¼ÊÐÉÐδ¾Í´Ëʰ䷢ÉêÃ÷¡£×êÑÐÈËÔ±°µÊ¾ £¬LockBitÔøÔÚ2022Äê6ÔÂÐû³ÆËüÈëÇÖÁËMandiantµÄϵͳ²¢ÇÔÈ¡ÁËÊýÊ®Íò¸öÎļþ £¬ºóÀ´Õâ±»Ö¤Ã÷ÊÇÒ»¸öÐû´«àåÍ·¡£


https://www.bleepingcomputer.com/news/security/lockbit-ransomware-gang-now-also-claims-city-of-oakland-breach/


5¡¢ChatGPT³öÏÖBugÄܹ»¿´µ½ÆäËûÓû§µÄ¶Ô»°º¹Çà±êÌâ


ýÌå3ÔÂ21ÈÕ³Æ £¬ChatGPT³öÏÖÁËÒ»¸öBug £¬µ¼ÖÂÆäËûÓû§µÄ̸Ì캹Çàй¶¡£¸ÃÎÊÌâ×î³õÊÇÓÉһλÒÉ»óÆäÕÊ»§±»ºÚµÄÓû§ÔÚRedditÉϻ㱨µÄ £¬ËûÔÚ¶Ô»°º¹Çà±êÌâÖз¢ÏÖÁ˲»ÊôÓÚ×Ô¼ºµÄ¶Ô»°¡£ÐÂÎÅ´«¿ªºó £¬ÍÆÌØÉÏµÄÆäËûÓû§Ò²Ðû³ÆÔÚ×Ô¼ºµÄÕ˺ÅÉÏ¿´µ½Á˱ðÈ˵Ä̸Ìì¼Í¼¡£ºÜ¶àÓû§³Æ¸ÃÎÊÌâÑϳÁ¼Óº¦ÁËÓû§ÒþÖÔ¡£ChatGPTÓÚ±¾ÖÜÒ»ÁÙʱ½ûÓÃÁËÆä̸Ìì·þÎñ £¬ÒÔµ÷²éºÍ½¨¸´¸Ã·ì϶¡£3ÔÂ23ÈÕ £¬OpenAI CEO Sam AltmanÈÏ¿ÉÆä¿ªÔ´¿âÖеÄÒ»¸öÃýÎóµ¼ÖÂÓû§µÄ̸Ì캹Çàй¶ £¬²¢°ä²¼ÁËÍÆÎÄÖÂǸ¡£


https://www.hackread.com/chatgpt-bug-conversation-history-titles/


6¡¢Unit 42°ä²¼2023ÄêÀÕË÷Èí¼þÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨


3ÔÂ21ÈÕ £¬Unit 42°ä²¼ÁË2023ÄêÀÕË÷Èí¼þÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö £¬¶à³ÁÀÕË÷Õ½ÊõµÄʹÓóÖÐøÉÏÉý¡£½ØÖÁ2022Äêµ× £¬ÔÚÔ¼70%µÄ°¸¼þÖвúÉúÁËÊý¾Ýй¶ £¬2021ÄêÖÐÖ»ÓÐÔ¼40%µÄÊý¾Ý±»µÁ¡£É§ÈÅÊÇÁíÒ»ÖÖÀÕË÷Õ½Êõ £¬2022Äêµ×Ô¼20%µÄÀÕË÷Èí¼þ°¸¼þÔ̺¬¸Ã³É·Ö £¬¶ø2021Äê½öÓв»µ½1%¡£Ôì×÷ÒµÊÜ´ËÀ๥»÷×î¶à £¬ÃÀ¹úµÄ×éÖ¯Êܵ½Ó°Ïì×îÑϳÁ£¨Õ¼42%£©¡£×êÑÐÈËÔ±Ô¤¼ÆÔÚ2023Äê £¬³öÏÖ´óÐÍÔÆÀÕË÷Èí¼þ¹¥»÷¡¢ÄÚ²¿ÍþвÓйصÄڲƭÀÕË÷Ôö³¤ºÍ³öÓÚÕþÖζ¯»úµÄÀÕË÷Ôö³¤µÈ¡£


https://start.paloaltonetworks.com/2023-unit42-ransomware-extortion-report