MicrosoftÐû²¼4Ô·ÝÇå¾²¸üУ¬£¬£¬ £¬£¬£¬ £¬ £¬×ܼÆÐÞ¸´97¸öÎó²î

Ðû²¼Ê±¼ä 2023-04-12

1¡¢MicrosoftÐû²¼4Ô·ÝÇå¾²¸üУ¬£¬£¬ £¬£¬£¬ £¬ £¬×ܼÆÐÞ¸´97¸öÎó²î


4ÔÂ11ÈÕ£¬£¬£¬ £¬£¬£¬ £¬ £¬Î¢ÈíÐû²¼ÁË2023Äê4Ô·ݵÄÖܶþ²¹¶¡£¡£¡£¡£¡£¡£¬£¬£¬ £¬£¬£¬ £¬ £¬ÐÞ¸´Á˰üÀ¨Ò»¸ö±»Ê¹ÓÃ0 dayÔÚÄÚµÄ97¸öÎó²î£¨²»°üÀ¨4ÔÂ6ÈÕÐÞ¸´µÄ17¸öMicrosoft EdgeÎó²î£©¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄÒѱ»Ê¹ÓÃÎó²îΪWindowsͨÓÃÈÕÖ¾ÎļþϵͳÇý¶¯³ÌÐòÌáȨÎó²î£¨CVE-2023-28252£©£¬£¬£¬ £¬£¬£¬ £¬ £¬Kaspersky·¢Ã÷¸ÃÎó²îÔÚNokoyawaÀÕË÷¹¥»÷Öб»Ê¹Óᣡ£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬ £¬ £¬»¹ÐÞ¸´Á˽ÏΪÑÏÖØµÄMicrosoftÐÂÎÅÐÐÁÐRCEÎó²î£¨CVE-2023-21554£©¡¢DHCPЧÀÍÆ÷ЧÀÍRCEÎó²î£¨CVE-2023-28231£©ºÍ¶þ²ãËíµÀЭÒéRCEÎó²î£¨CVE-2023-28219ºÍCVE-2023-28220£©µÈ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2023-patch-tuesday-fixes-1-zero-day-97-flaws/


2¡¢°Ùʤ²ÍÒû¼¯ÍÅÔâµ½ÀÕË÷¹¥»÷Æä²¿·ÖÔ±¹¤ÐÅϢй¶


¾ÝýÌå4ÔÂ10ÈÕ±¨µÀ£¬£¬£¬ £¬£¬£¬ £¬ £¬°Ùʤ²ÍÒû¼¯ÍÅ£¨Yum! Brands£©Í¨ÖªÔ±¹¤¹ØÓÚÀÕË÷¹¥»÷µ¼ÖµÄÐÅϢй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£°ÙʤÊǿϵ»ù¡¢±ØÊ¤¿ÍºÍTaco BellµÄĸ¹«Ë¾£¬£¬£¬ £¬£¬£¬ £¬ £¬ÊÇÈ«ÇòÃÅÊÐ×î¶àµÄ¿ì²Í¹«Ë¾¡£¡£¡£¡£¡£¡£1ÔÂ13ÈÕ£¬£¬£¬ £¬£¬£¬ £¬ £¬ÆäÔâµ½ÀÕË÷¹¥»÷£¬£¬£¬ £¬£¬£¬ £¬ £¬±»ÆÈ¹Ø±ÕÁËÓ¢¹úÔ¼300¼Ò²ÍÌü¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Í¸Â¶£¬£¬£¬ £¬£¬£¬ £¬ £¬ÔÚȡ֤ºÍÊÓ²ìÀú³ÌÖУ¬£¬£¬ £¬£¬£¬ £¬ £¬·¢Ã÷ÁËһЩԱ¹¤µÄСÎÒ˽¼ÒÐÅÏ¢ÔÚ1Ô·ݵÄÇå¾²ÊÂÎñÖÐй¶£¬£¬£¬ £¬£¬£¬ £¬ £¬Î´Åû¶ÊÜÓ°ÏìÔ±¹¤ÊýÄ¿¡£¡£¡£¡£¡£¡£Ð¹Â¶Êý¾Ý°üÀ¨ÐÕÃû¡¢¼ÝÕÕºÅÂëºÍÉí·ÝÖ¤ºÅÂ룬£¬£¬ £¬£¬£¬ £¬ £¬¿Í»§Êý¾Ý²¢Î´ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/kfc-pizza-hut-owner-discloses-data-breach-after-ransomware-attack/


3¡¢ÈýÐÇÔ±¹¤Ê¹ÓÃChatGPTµ¼Ö¹«Ë¾¾Û»á¼Í¼ºÍÔ´´úÂëй¶   


ýÌå4ÔÂ10Èճƣ¬£¬£¬ £¬£¬£¬ £¬ £¬ÈýÐÇÔ±¹¤Ê¹ÓÃChatGPT£¬£¬£¬ £¬£¬£¬ £¬ £¬ÔÚ²»µ½Ò»¸öÔÂÄÚ±¬·¢ÈýÆðÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£ÈýÐǹ¤³ÌʦʹÓÃChatGPTÓÅ»¯²âÊÔÐòÁÐÒÔʶ±ðоƬÖеĹÊÕÏ£¬£¬£¬ £¬£¬£¬ £¬ £¬ÊäÈëÁËгÌÐòµÄÔ´´úÂëÒÔ¼°ÓëÓ²¼þÏà¹ØµÄÄÚ²¿¾Û»á¼Í¼µÈÊý¾Ý¡£¡£¡£¡£¡£¡£ÔÚÁíÒ»¸ö°¸ÀýÖУ¬£¬£¬ £¬£¬£¬ £¬ £¬Ô±¹¤Ê¹ÓÃChatGPT½«¾Û»á¼Í¼ת»»ÎªÑÝʾÎĸ壬£¬£¬ £¬£¬£¬ £¬ £¬ÆäÖÐÈ´Éæ¼°´ó×ÚÈýÐDz»Ï£Íû¶ÔÍâ͸¶µÄÄÚÈÝ¡£¡£¡£¡£¡£¡£µÚÈýÆðÊÂÎñÖУ¬£¬£¬ £¬£¬£¬ £¬ £¬Ô±¹¤½«·ºÆðÎÊÌâµÄ´úÂë¸´ÖÆµ½ChatGPTÒÔÐÞ¸´¹ýʧ¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎúÈýÐÇÊÇ·ñÒÑÒªÇóɾ³ýÆäÔ±¹¤ÏòOpenAIÌṩµÄÊý¾Ý£¬£¬£¬ £¬£¬£¬ £¬ £¬µ«Õâ¼ÒIT¹«Ë¾ÒѾöÒ鿪·¢×Ô¼ºµÄAI¹©ÄÚ²¿Ê¹Óᣡ£¡£¡£¡£¡£


https://securityaffairs.com/144597/security/samsung-data-leak-chatgpt.html


4¡¢Vimeo½«Ö§¸¶225ÍòÃÀÔªÒÔÏ¢ÕùAIÏà¹ØÉúÎïʶ±ðÒþ˽ËßËÏ


¾Ý4ÔÂ10ÈÕ±¨µÀ£¬£¬£¬ £¬£¬£¬ £¬ £¬VimeoÔÞ³ÉÏòÆäÊÓÆµ´´×÷ºÍ±à¼­Æ½Ì¨MagistoµÄ²¿·ÖÓû§Ö§¸¶225ÍòÃÀÔª£¬£¬£¬ £¬£¬£¬ £¬ £¬ÒÔÏ¢Õù¹ØÓÚÉúÎïʶ±ðÒþ˽µÄËßËÏ¡£¡£¡£¡£¡£¡£ÕûÌåËßËÏÖ¸¿ØVimeoÔÚ2014Äê9ÔÂ20ÈÕÖÁ2023Äê1ÔÂ20ÈÕδ¾­Êʵ±Í¨ÖªºÍÔ޳ɼ¨ÇÔÈ¡ÁËËûÃǵÄÉúÎïʶ±ðÐÅÏ¢£¬£¬£¬ £¬£¬£¬ £¬ £¬Î¥·´ÁËÒÁÀûŵÒÁÖݵÄÉúÎïÌØÕ÷ÐÅÏ¢Òþ˽·¨(BIPA)¡£¡£¡£¡£¡£¡£ËßËϳƣ¬£¬£¬ £¬£¬£¬ £¬ £¬¸ÃÓ¦ÓÃÍøÂçºÍ´æ´¢ÏêϸµÄÃæ²¿Í¼Æ¬£¬£¬£¬ £¬£¬£¬ £¬ £¬Ê¹ÓÃAIÒýÇæÆÊÎöÉÏ´«µ½Æ½Ì¨µÄÊÓÆµ£¬£¬£¬ £¬£¬£¬ £¬ £¬°üÀ¨¼ì²âÈËÁ³£¬£¬£¬ £¬£¬£¬ £¬ £¬¶øVimeo±»Ö¸¿Ø½¨Éè¡¢ÍøÂçºÍ´æ´¢Óû§µÄÃæ²¿Ä£°å¡£¡£¡£¡£¡£¡£


https://www.scmagazine.com/news/identity-and-access/vimeo-ai-biometric-privacy-lawsuit


5¡¢KasperskyÐû²¼°µÍøÉϵÄGoogle PlayÍþвµÄ¸ÅÊö


4ÔÂ10ÈÕ£¬£¬£¬ £¬£¬£¬ £¬ £¬Kaspersky¸ÅÊöÁ˰µÍøÉϳöÊ۵Ľ«Android¶ñÒâÈí¼þÌí¼Óµ½Google PlayµÄЧÀÍ¡£¡£¡£¡£¡£¡£°µÍøÉÏÌṩµÄ¶ñÒâЧÀÍÀàÐͰüÀ¨Google Play¼ÓÔØ³ÌÐò¡¢À¦°óЧÀÍ¡¢¶ñÒâÈí¼þ»ìÏýЧÀͺÍ×°ÖÃЧÀ͵È¡£¡£¡£¡£¡£¡£ÏòGoogle PlayÌṩ¶ñÒâÓ¦ÓõļÓÔØ³ÌÐòµÄ¼ÛÇ®ÔÚ2000ÖÁ20000ÃÀÔªÖ®¼ä¡£¡£¡£¡£¡£¡£¶ñÒâÈí¼þͨ³£Òþ²ØÔÚɱ¶¾Èí¼þ¡¢¼ÓÃÜÇ®±Ò×ʲúÖÎÀíÆ÷¡¢¶þάÂëɨÃèÆ÷¡¢Ð¡ÓÎÏ·ºÍÔ¼»áÓ¦ÓÃÖС£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±½¨Ò飬£¬£¬ £¬£¬£¬ £¬ £¬AndroidÓû§Ó¦ÔÚ×°ÖÃÓ¦ÓÃʱ×Ðϸ¼ì²éÇëÇóµÄȨÏÞ£¬£¬£¬ £¬£¬£¬ £¬ £¬ÇÐÎð´ÓµÚÈý·½ÍøÕ¾×°ÖÃAndroid APK¡£¡£¡£¡£¡£¡£


https://securelist.com/google-play-threats-on-the-dark-web/109452/


6¡¢JfrogÐû²¼¹ØÓÚ¶ñÒâÈí¼þImpala StealerµÄÆÊÎö±¨¸æ


JfrogÔÚ4ÔÂ10ÈÕÐû²¼Á˹ØÓÚImpala StealerµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»ÖÖ×Ô½ç˵¼ÓÃÜÇÔÈ¡³ÌÐò£¬£¬£¬ £¬£¬£¬ £¬ £¬×÷ΪNuGet¶ñÒâ°ü»î¶¯µÄpayload¡£¡£¡£¡£¡£¡£Õâ¸öÖØ´óµÄ¹¥»÷»î¶¯Ê¹ÓÃÓòÃû·ÂðÊÖÒÕÈö²¥ÁË13¸ö¶ñÒâ°ü£¬£¬£¬ £¬£¬£¬ £¬ £¬Ö÷ÒªÕë¶Ô.NET¿ª·¢Ö°Ô±¡£¡£¡£¡£¡£¡£Impala StealerµÄÖ÷ÒªpayloadÊÇÒ»¸ö¿ÉÖ´ÐÐÎļþ£¬£¬£¬ £¬£¬£¬ £¬ £¬ËƺõÊÇʹÓÃ.NET Ahead of Time£¨AoT£©±àÒëµÄÍâµØ.NETÓ¦ÓóÌÐò¡£¡£¡£¡£¡£¡£Ëü¾ßÓÐ×°ÖúÍ×Ô¶¯¸üлúÖÆ¡¢¿Éͨ¹ý´úÂë×¢ÈëʵÏÖ³¤ÆÚ»¯²¢Äܹ»´ÓExodusÇ®°üÖÐÇÔÈ¡×ʽ𡣡£¡£¡£¡£¡£


https://jfrog.com/blog/impala-stealer-malicious-nuget-package-payload/