Google½¨¸´ChromeÖÐÒѱ»ÀûÓõķì϶CVE-2022-3723
°ä²¼¹¦·ò 2022-10-31
¾Ý10ÔÂ28ÈÕ±¨Â·£¬Google°ä²¼ÁËChromeµÄ´¹Î£°²È«¸üУ¬½¨¸´×Ô2022ËêÊ×ÒÔÀ´µÄµÚÆß¸öÁãÈÕ·ì϶¡£¸Ã·ì϶(CVE-2022-3723)ÊÇChrome V8 JavascriptÒýÇæÖеÄÒ»¸öÀàÐÍ»ìºÏ·ì϶£¬ÓÉAvastµÄ×êÑÐÈËÔ±ÓÚ½ñÄê10ÔÂ25Èջ㱨¡£³öÓÚ°²È«ÔÒò£¬¸Ã¹«Ë¾Ã»ÓÐÌṩÓйطì϶µÄ¾ßÌåÐÅÏ¢£¬Ò²Ã»ÓÐ×¢Ã÷Éæ¼°¸Ã·ì϶µÄ¹¥»÷»î¶¯Ë®Æ½µÄÐÔÖÊ¡£×êÑÐÈËԱǿÁÒ½¨ÒéChromeÓû§¾¡¿ì¸üÐÂÆää¯ÀÀÆ÷ÒÔ×èÖ¹´ËÀ๥»÷¡£
https://www.bleepingcomputer.com/news/security/google-fixes-seventh-chrome-zero-day-exploited-in-attacks-this-year/
2¡¢Ë¹Âå·¥¿ËºÍ²¨À¼Òé»áµÄITϵͳÔâµ½´ó¹æÄ£ÍøÂç¹¥»÷
ýÌå10ÔÂ29Èճƣ¬Ë¹Âå·¥¿ËºÍ²¨À¼Òé»áÔâµ½´ó¹æÄ£ÍøÂç¹¥»÷¡£²¨À¼µ±¾Ö³Æ£¬Õâ´Î¹¥»÷¿ÉÄÜÓë²ÎÒéÔºµÄͶƱÓйأ¬¹¥»÷ÆëÈ«ÖжÏÁËÒé»áµÄIT»ù´¡ÉèÊ©¡£²¢Ð¹Â©Õâ´Î¹¥»÷ÊǶ෽ÏòµÄ£¬Ô̺¬À´×ÔÂÞ˹Áª¹úÄÚ²¿µÄ¹¥»÷¡£Ë¹Âå·¥¿ËÒé»á¸±Ò鳤°µÊ¾£¬¹¥»÷µ¼ÖÂ˹Âå·¥¿ËÒé»áµÄITϵͳºÍµç»°Ïß·̱»¾£¬¼¸Ïî·¨°¸µÄͶƱ±»Öжϡ£ËûÃÇĿǰÉÐδȷ¶¨¸ÃÊÂÎñµÄÆðÔ´£¬Æä¼¼ÊõÈËÔ¹ØýÔÚ½â¾ö¸ÃÎÊÌâ¡£
https://securityaffairs.co/wordpress/137777/hacking/slovak-polish-parliaments-cyberattacks.html
3¡¢Å·ÖÞ×î´óµÄͳö²úÉÌAurubisÔÚ±»¹¥»÷ºóϵͳ¹Ø¹Ø
10ÔÂ28ÈÕ±¨Â·£¬Aurubis³ÆÆäÔâµ½¹¥»÷£¬±»ÆÈ¹Ø¹ØITϵͳÒÔÔ¤·À¹¥»÷ÊæÕ¹¡£AurubisÊÇÅ·ÖÞ×î´óºÍÊÀ½çµÚ¶þ´óµÄͳö²úÉÌ£¬Ã¿Äê³ö²ú100Íò¶ÖÒõ¼«Í¡£Aurubis²¼¸æÏÔʾ£¬ËûÃǹعØÁËÆäµØµãµØµÄ¸÷Ààϵͳ£¬µ«²¢Î´Ó°Ïì³ö²ú¡£Ò±Á¶³§µÄ³ö²úºÍ»·±£ÉèÊ©Õý³£ÔËÐУ¬½ø³ö»õÎïÒ²ÔÚÈËÎªÊØ»¤¡£Ä¿Ç°£¬¸Ã¹«Ë¾ÈÔÔÚÆÀ¹ÀÍøÂç¹¥»÷µÄÓ°Ï죬ÎÞ·¨¹À¼ÆÏµÍ³¸´Ô±ØÒª¶à³¤¹¦·ò¡£´Ë¿ÌÈ·µ±ÎñÖ®¼±ÊÇά³Ö²úÁ¿ÔÚÕý³£Ë®Æ½£¬³öÓÚÕâ¸öÔÒò£¬Ò»Ð©²Ù×÷ÒÑתÏòÊÖ¶¯Ä£Ê½£¬Ö±µ½ÈÛÁ¶³§¸´ÔÍÆËã»ú¸¨ÖúµÄ×Ô¶¯»¯¡£
https://www.bleepingcomputer.com/news/security/largest-eu-copper-producer-aurubis-suffers-cyberattack-it-outage/
4¡¢°Ä´óÀûÑÇÁÙ´²³¢ÊÔÊÒ³ÆÀÕË÷¹¥»÷µ¼ÖÂ22ÍòÈËÐÅϢй¶
¾ÝýÌå10ÔÂ27Èճƣ¬°Ä´óÀûÑÇÁÙ´²³¢ÊÔÊÒ(ACL)й©ÆäMedlab PathologyÒµÎñ²úÉúÁËÊý¾Ýй¶£¬Ó°ÏìÔ¼223000Ãû»¼ÕߺÍÔ±¹¤¡£ÀÕË÷ÍÅ»ïQuantumÓÚ2022Äê6ÔÂ14ÈÕÔÚÆäTorÍøÕ¾ÉÏ´«ÁËËùÓб»µÁÎļþ£¬¹²86 GBµÄÊý¾Ý£¬Ô̺¬»¼ÕߺÍÔ±¹¤µÄ¾ßÌåÐÅÏ¢¡¢²ÆÕþ»ã±¨¡¢·¢Æ±¡¢ºÏͬ¡¢±í¸ñ¡¢´«Æ±ºÍÆäËû¸öÈËÎļþµÈ¡£Æ¾¾ÝÍøÕ¾Êý¾Ý£¬MedLabµÄÐ¹Â¶Ò³ÃæÒѱ»½Ó¼û130000´Î¡£¹¥»÷²úÉúÓÚ2022Äê2Ô·ݣ¬µ«¸Ã°²È«ÊÂÎñÔÚ²úÉú9¸öÔºó²Å±»Åû¶£¬ACLµÄ²¼¸æÊÔͼΪÕâÖÖ³ÙÑÓÌṩÀíÓÉ¡£
https://www.databreaches.net/australian-clinical-labs-says-data-of-223000-people-hacked/
5¡¢iOSºÍmacOSÖеÄSiriSpy·ì϶¿ÉÇÔÌýÓû§ÓëSiriµÄ¶Ô»°
ýÌåÓÚ10ÔÂ27ÈÕ±¨Â·³Æ£¬Ó°ÏìÁËApple iOSºÍmacOSµÄSiriSpy·ì϶£¨CVE-2022-32946£©£¬Äܹ»±»ÈκοɽӼûÀ¶ÑÀµÄÀûÓ÷¨Ê½ÓÃÀ´ÇÔÌýÓû§ÓëSiriµÄ¶Ô»°¡£ÔÚ²âÊÔAirBuddyµÄÖ°ÄÜʱ£¬×êÑÐÈËÔ±°ÑÎȵ½AirPodsÔ̺¬Ò»¸ö´øÓÐUUIDµÄ·þÎñ£¬²¢ÇÒÓµÓÐÖ§³Ö֪ͨµÄÖ°ÄÜ¡£½øÒ»´ëÊ©²é½«ÉÏÊöUUIDÓëÓÃÓÚSiriºÍÌýд֧³ÖµÄDoAP·þÎñÓйØÁª£¬¹¥»÷ÕßÄܹ»´´½¨Ò»¸ö¶ñÒâÀûÓ㬸ÃÀûÓÃÄܹ»Í¨¹ýÀ¶ÑÀÏνӵ½AirPods²¢ÔÚºó¶Ü¼ÔìÒôƵ¡£Ä¿Ç°£¬¸Ã·ì϶Òѱ»½¨¸´¡£
https://securityaffairs.co/wordpress/137710/security/sirispy-apple-flaw-spy-conversations.html
6¡¢Symantec°ä²¼CraneflyÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨
10ÔÂ28ÈÕ£¬Symantec°ä²¼Á˹ØÓÚCraneflyÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬Cranefly£¨±ðÃûUNC3524£©ÔÚʹÓÃÐÂdropper(Trojan.Geppei)À´×°ÖÃÁíÒ»¸öеĶñÒâÈí¼þ(Trojan.Danfuan)ºÍÆäËü¹¤¾ß£¨Hacktool.Regeorg£©¡£Geppei´ÓºÏ·¨µÄIISÈÕÖ¾ÖжÁÈ¡ºÅÁî¡£¶ÁÈ¡µÄºÅÁîÔ̺¬¶ñÒâ±àÂëµÄ.ashxÎļþ£¬ÕâЩÎļþ±»±£Áôµ½ÓɺÅÁî²ÎÊýÈ·¶¨µÄËÁÒâÎļþ¼ÐÖУ¬ËüÃÇ×÷ΪºóÃÅÔËÐС£Ö»¹ÜÒÑÔÚÖ¸±êµÄÍøÂçÉÏÂñ·üÁË18¸öÔ£¬µ«×êÑÐÈËÔ±ÉÐδ¹Û²ìµ½¹¥»÷Õß´ÓÖ¸±êÖÐÇÔÈ¡Êý¾ÝµÄ»î¶¯¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/cranefly-new-tools-technique-geppei-danfuan


¾©¹«Íø°²±¸11010802024551ºÅ