2024年5月安全资讯

2024-05-29 18:38 谦益科技
01

CNNVD 46862024519CNNVD 163246671.45%




02

使访


1.VMware Workstation


CVE-ID: CVE-2024-22267

2024-05-14

windows

:

VMware WorkstationVMwareVMware Workstation

https://www.vmware.com/security/advisories.html


2.Google Golang



CVE-ID: CVE-2024-24787

2024-05-08

windows

:

Google GolangGoogleGoCGoGo·CSPOccamLimboPi1.8PluginGo

Google Golang 1.21.10 1.22.3 使 Apple ld CGO Go

https://pkg.go.dev/vuln/GO-2024-2825


3.Apache OFBiz



CVE-ID:CVE-2024-32113

2024-05-08

Linux

:

Apache OFBizApacheERPJavaWeb

Apache OFBiz 18.12.13

https://lists.apache.org/thread/w6s60okgkxp2th1sr8vx0ndmgk68fqrd


4.PHP



CVE-ID: CVE-2024-1874

2024-04-29

Linux

:

PHPPHP使proc_openWindows shell8.1.*8.1.288.2.*8.2.188.3.*8.3.5

https://www.vmware.com/security/advisories/VMSA-2024-0006.html


5.mysql2



CVE-ID: CVE-2024-21511

2024-04-29

windows

:

MySQL2Andrey Sidorov Node.js MySQL

mysql2 2 3.9.7 MySQL date/time readCodeFor timezone

https://github.com/sidorares/node-mysql2/commit/7d4b098c7e29d5a6cb9eac2633bfcc2f0f1db713


03

1.Android 访


Android 访

Android

SonicWall Capture Labs Android RAT 使 Android

·

·

C&C URL C&C 访 URL

AndroidHTML'asset\website'HTML ID 使 JavaScript showTt

str 01 2CameraManager C&C VirusTotal

SonicWall Capture Labs RTDMI SonicWall Capture ATP


2.Grandoreiro 1,500


Grandoreiro

Windows

2024 3 Windows Grandoreiro 1 IBM X-ForceMaaS1,50060

Grandoreiro 西西广

DGA使Microsoft OutlookGolo MührMelissa Frydrych

PDF Grandoreiro ZIP 100 MB C2

Windows 7 Windows 使 DGA C2

GrandoreiroMicrosoft OutlookOutlookGrandoreiro使OutlookOutlook Outlook 访

使 Outlook Grandoreiro Grandoreiro


04
1.20245


20244920244Windows 11Windows 10Windows Server 2022Windows Server 2008Microsoft Defender for IoT

CNVD广Microsoft

CVE-2024-30044Microsoft SharePoint Server

CVSS8.8 Sharepoint Server API 使 Sharepoint Server SharePoint Server


CVE-2024-30040Windows MSHTML

CVSS8.8使使使使使 Microsoft 365 Microsoft Office OLE COM/OLE


CVE-2024-30006Microsoft WDAC OLE DB Provider for SQL Server

CVSS8.8 OLEDB SQL Server 使 SQL SQL SQL CVSS UIR SQL Server


CVE-2024-30010Windows Hyper-V

CVSS8.8 Hyper-V


CVE-2024-26238Microsoft PLUGScheduler

CVSS7.8 SYSTEM Windows 10 2004 20H2 KB 5001716 Windows 10 Windows Windows Windows10 Windows KB5001716

1MicrosoftWindowsWindows

2

https://msrc.microsoft.com/update-guide/releaseNote/2024-Feb

CVE()

download



05

01

2024 VBScript

2024 VBScriptFOD Windows .NET Framework (.NetFx3) Hyper-VWindows Subsystem for Linux

Naveen Shankar JavaScript PowerShell 广广2024VBScript FOD PowerShell Windows 退

2024 Windows 11 24H2 VBScript

2027 VBScript

VBScript Windows 退

VBScript .dll 使 VBScript

10 30 Windows VBScript Visual Basic Script Microsoft Visual Basic Scripting Edition Internet Explorer Windows 10 2023 2 使 Windows Script Windows 10 Internet Explorer 11 VBScript 2019 7 " "

Windows Office

使VBScript LokibotEmotetQbot DarkGate 2018 AMSI Office 365 Office VBA Excel 4.0 (XLM)VBA OfficeXLMMicrosoft 365XLL


02

Kimsuky APT 使 Linux

APTKimsuky使 Gomir Linux GoBear Kimsuky

Kimsuky SpringtailARCHIPELAGOBlack Banshee ThalliumVelvet Chollima APT43 2013 APT Gomir GoBear

S2W 2024 2 使 Troll Stealer Troll Stealer Go Troll Stealer Kimsuky

Troll Stealer GPKIGPKI TrustPKI NX_PRNMAN SGA Solutions

Troll Stealer Wizvera VeraPortWIZVERA VeraPort 访WIZVERA VeraPort

Wizvera VeraPort Lazarus ID Linux 0GomirGoBear Windows

Kimsuky 3CX X_Trader

Springtail Springtail

使IOCs Troll StealerGomir GoBear dropper


03

4CEOFSD4FSD2024FSD12.5亿20亿520亿60亿60亿FSD

FSDFSDApollo

GhostStripe线使Apollo使CMOS

GhostStripeCMOSCMOS线

线

GhostStripe

·GhostStripe1访LED

·GhostStripe2访线

Leopard Imaging AR023ZWDRApollo使GhostStripe94%97%

GhostStripe

·使

·线

·

·AI使GhostStripe

GhostStripe60亿

GhostStripe

04

广使

202311ICS CERTelit Cinterion87CVE-2023-47610CVE-2023-47616Telit Cinterion广20232511OffensiveCon·(Alexander Kozlov)·(Sergey Anufrienko)Telit CinterionSUPLOver The Air ProvisioningMIDlet使MIDlet20245

CERTTelit Cinterion BGS5Telit Cinterion EHS5/6/8Telit Cinterion PDS5/6/8Telit Cinterion ELS61/81Telit Cinterion PLS62CWE-526访

CVE-2023-47611CVE-2023-47610使CVE-2023-47610(SUPL)

Telit8.8(10)NIST9.8BleepingComputer访

CVE-2023-47610访

访RAM访

One SMS to Root Them All: Exposing Critical Threats in Millions of Connected Devices-midletJava

(CVE-2023-47611)()广Cinterion EHS5-E

BleepingComputer, TelitICS CERT(Evgeny Goncharov):广

Goncharov使APNMIDIets访


05

ChatGPT

ChatGPT使

ChatGPT1OpenAI使使使ChatGPT

AIChatGPTOpenAIChatGPTAI

AIWilliam ChappellGPT-4

AI(CIA)ChatGPTChatGPTSheetal PatelAIAI

18AIChappellDARPA2022

ChappellChatGPT访GPT-4ChappellChappellAI1访

线Chappell

06

IntelBroker广广

Hackread.comBreach Forums20244IntelBrokerSanggieroSQLJARJSON500,000

Hackread.comBreach Forums广20244IntelBrokerSanggieroSQLJARJSON500,000

线

线.

便

IntelBroker


http://www.cnnvd.org.cn/

http://www.cnvd.org.cn/

FreeBuf

https://www.freebuf.com/

https://www.4hou.com/

绿

https://nti.nsfocus.com/news


(020-88524296)