Aruba½¨¸´EdgeConnectÖÐRCEºÍÉí·ÝÑéÖ¤ÈÆ¹ýµÈ·ì϶

°ä²¼¹¦·ò 2022-10-14
1¡¢Aruba½¨¸´EdgeConnectÖÐRCEºÍÉí·ÝÑéÖ¤ÈÆ¹ýµÈ·ì϶

      

ýÌå10ÔÂ12ÈÕ±¨Â·£¬Aruba°ä²¼ÁËEdgeConnect Enterprise OrchestratorµÄ°²È«¸üУ¬½¨¸´Á˶à¸öÑϳÁµÄ·ì϶¡£ÆäÖÐÔ̺¬»ùÓÚWebµÄÖÎÀí½çÃæÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2022-37913ºÍCVE-2022-37914£©£¬CVSSÆÀ·ÖΪ9.8£»ÒÔ¼°»ùÓÚWebµÄÖÎÀí½çÃæÖÐδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2022-37915£©£¬CVSSÆÀ·ÖҲΪ9.8¡£ÎªÁË×î´óÏ޶ȵØÏ÷¼õÀûÓÃÉÏÊö·ì϶µÄ¿ÉÄÜÐÔ£¬¹©¸øÉ̽¨ÒéÓû§½«CLIºÍ»ùÓÚWebµÄÖÎÀí½çÃæÏÞ¶ÈÔÚרÓõĵÚ2²ãÍø¶Î/VLAN£¬»ò½«·À»ðǽսÊõÉèÖÃΪµÚ3²ã¼°ÒÔÉÏ¡£


https://securityaffairs.co/wordpress/137000/security/aruba-edgeconnect-flaws.html


2¡¢MinecraftµÄ·þÎñÆ÷Wynncraft½üÆÚÔâµ½DDoS¹¥»÷

      

ýÌå10ÔÂ13Èճƣ¬MinecraftµÄ·þÎñÆ÷Wynncraft×î½üÔâµ½ÁË2.5 TbpsµÄDDoS¹¥»÷¡£Cloudflare°µÊ¾£¬ÕâÊÇһ·³ÖÐøÔ¼Á½·ÖÖӵĶàÏòÁ¿¹¥»÷£¬ÓÉUDPºÍTCPºé·ºÊý¾Ý°ü×é³É£¬ÊÇËûÃǼͼºÍ´¦Öùý×î´ó±ÈÌØÂʵĹ¥»÷¡£´Ë±í£¬¸Ã°²È«¹«Ë¾Ö¸³ö£¬ËûÃÇÔÚ½ñÄêµÄµÚÈý¼¾¶È×èÖ¹Á˱ÈÈ¥Äê¸ü¶àµÄDDoS¹¥»÷£¬ÆäÖлùÓÚHTTPµÄ¹¥»÷Ôö³¤ÁË111%£¬µÚ3²ãºÍµÚ4²ã(L3/4)DDoS¹¥»÷Ò²ÏÕЩͬ±È·­ÁËÒ»·¬£¬Ôö³¤ÁË97%¡£


https://www.bleepingcomputer.com/news/security/cloudflare-mitigated-record-ddos-attack-against-minecraft-server/


3¡¢Mango Marketsƽ̨Ôâµ½ÉÁµç´û¹¥»÷Ëðʧ³¬1ÒÚÃÀÔª

      

¾Ý10ÔÂ12ÈÕ±¨Â·£¬¼ÓÃÜÇ®±ÒÂòÂôƽ̨Mango MarketsÔâµ½ÉÁµç´û¹¥»÷£¬Ëðʧ³¬1ÒÚÃÀÔª¡£¸Ãƽ̨ÖܶþÍíÉÏÔÚTwitterÉÏ֪ͨÓû§£¬ËüÔÚµ÷²éһ·°²È«ÊÂÎñ¡£¼¸¸öÓ×ʱºó£¬¸Ã¹«Ë¾Ö¤Êµ£¬ºÚ¿ÍÀûÓÃÁ½¸öÕË»§Ôڶ̶̼¸·ÖÖÓÄÚ±¨´ð½«MNGO±ÒÔÚ¸÷ÂòÂôËùµÄ¼ÛÖµÌá¸ßÁËÔ­¼ÛµÄ5µ½10±¶£¬Æäʱ¸ÃÕË»§ÌáÈ¡µÄ¾»ÖµÔ¼Îª1ÒÚÃÀÔª¡£Ä¿Ç°Æ½Ì¨ÉϵĿͻ§ÎÞ·¨ÌáÈ¡ÈκÎ×ʲú£¬ÓÉÓںڿͺľ¡ÁËËùÓпÉÓÃ×ʲú£¬Ê¹Æ½Ì¨×ʲ»µÖÕ®¡£¾ÝϤ£¬ºÚ¿ÍÁªÏµÁËMango Markets²¢°µÊ¾Ô¸Òâ½»Éæ¡£

 

https://therecord.media/crypto-trading-platform-mango-markets-drained-of-more-than-100-million-in-flash-loan-attack/


4¡¢×êÑÐÍŶӷ¢ÏÖÒ»ÖÖеÄnpm°´Ê±¹¥»÷¿Éµ¼Ö¹©¸øÁ´¹¥»÷ 

      

¾ÝýÌå10ÔÂ12ÈÕ±¨Â·£¬Aqua SecurityÍŶӷ¢ÏÖÒ»ÖÖеÄnpm°´Ê±¹¥»÷¡£ËüÄܹ»Ð¹Â©Ë½ÓÐÈí¼þ°üµÄÃû³Æ£¬Òò¶ø¹¥»÷ÕßÄܹ»¹«¿ª°ä²¼¶ñÒâ¿Ë¡£¬²¢ÓÕʹ¿ª·¢ÈËԱʹÓÃËüÃÇ¡£ÕâÖÖ¹¥»÷ÒÀÀµÓÚÔÚËÑË÷Ò»¸ö˽Óаüʱ£¬Óë¿âÖв»´æÔڵİüÏà±È£¬·µ»Ø404 Not FoundÃýÎóµÄ΢Ó×¹¦·ò²î¡£¹ÌÈ»ÏìÓ¦¹¦·ò²îÖ»Óм¸°ÙºÁÃ룬µ«Ëü×ãÒÔÈ·¶¨Õâ¸ö˽ÓаüÊÇ·ñ´æÔÚ£¬´Ó¶ø½øÐмÙð¹¥»÷¡£×êÑÐÈËÔ±³Æ£¬ÕâÖÖеļ¼Êõ¿ÉÄܵ¼Ö¹©¸øÁ´¹¥»÷£¬¶øGitHub°µÊ¾²»»á½â¾öÕâ¸öÎÊÌâ¡£


https://www.bleepingcomputer.com/news/security/new-npm-timing-attack-could-lead-to-supply-chain-attacks/


5¡¢INKY³ÆÒÔCOVID-19ΪÖ÷ÌâµÄ´¹µö¹¥»÷»î¶¯ÔÚÃÀ¹ú¼¤Ôö

      

10ÔÂ12ÈÕ±¨Â·£¬Óʼþ°²È«¹«Ë¾INKYÖ¸³ö£¬ÒÔCOVID-19ΪÖ÷ÌâµÄ´¹µö»î¶¯ÔÚÃÀ¹ú¼¤Ôö¡£ÔÚ×î½üµÄ¹¥»÷ÖУ¬´¹µöÓʼþ¼ÙÒâÃÀ¹úÓׯóÒµÖÎÀí¾Ö(SBA)²¢ÀÄÓÃGoogle±íµ¥À´ÍйÜÓÃÓÚÇÔÈ¡ÆóÒµÖ÷Ó×ÎÒÐÅÏ¢µÄ´¹µöÒ³Ãæ¡£¸Ã»î¶¯Ê¹Óõĵö¶üÊÇÕë¶ÔCOVID-19µÄ½ðÈÚÖ§³Ö´òË㣬ּÔÚÇÔȡָ±êµÄGoogleÕÊ»§Í´´¦¡¢SSN¡¢EIN¡¢State ID¡¢¼ÝÊ»ÅÆÕÕÐÅÏ¢ÒÔ¼°ÒøÐÐÕʺÅ¡£INKY»¹Ð¹Â©£¬ÓëǰÈý¸öÔÂÏà±È£¬9Ô·ݵÄÀ¬»øÓʼþÊýÁ¿·­ÁËÒ»·¬£¬Ô¤¼Æ»¹»á½øÒ»²½ÉÏÉý¡£


https://www.bleepingcomputer.com/news/security/new-npm-timing-attack-could-lead-to-supply-chain-attacks/


6¡¢Kaspersky°ä²¼¹ØÓÚ¶ñÒâWhatsApp modµÄ·ÖÎö»ã±¨

      

10ÔÂ12ÈÕ£¬Kaspersky°ä²¼ÁËͨ¹ýºÏ·¨ÀûÓ÷ַ¢µÄ¶ñÒâWhatsApp modµÄ·ÖÎö»ã±¨¡£×êÑÐÈËÔ±ÔÚYoWhatsApp°æ±¾2.22.11.75Öз¢ÏÖÁËÒ»¸ö¶ñÒâÄ £¿é£¬¸ÃÄ £¿é½âÃܲ¢Æô¶¯ÁËTrojan.AndroidOS.Triada.efµÄÖØÒªpayload¡£´Ë±í£¬¸Ã¶ñÒâÄ £¿é»¹ÇÔÈ¡Á˺Ϸ¨WhatsApp¹¤×÷ËùÐèµÄ¸÷ÀàÃÜÔ¿¡£¸ÃÀûÓÃͨ³£Í¨¹ýSnaptubeºÍVidmateÉϵÄڲƭ¸æ°×´«²¼£¬×°Öúó»áÒªÇóÓëWhatsAppÒ»ÑùµÄȨÏÞ¡£


https://securelist.com/malicious-whatsapp-mod-distributed-through-legitimate-apps/107690/