OpenSSLÏîÄ¿½¨¸´Æä¿ªÔ´ÃÜÂë¿âÖÐÁ½¸öÑϳÁµÄ·ì϶
°ä²¼¹¦·ò 2022-11-02
¾ÝýÌå11ÔÂ1ÈÕ±¨Â·£¬OpenSSLÏîÄ¿½¨¸´ÁËÆäÓÃÓÚ¼ÓÃÜͨѶͨ·ºÍHTTPSÏνӵĿªÔ´ÃÜÂë¿âÖÐÁ½¸öÑϳÁµÄ·ì϶¡£ÆäÖУ¬CVE-2022-3602ÊÇËÁÒâ4×ֽڲֿ⻺³åÇøÒç¶Âí½Å£¬¿ÉÄÜ´¥·¢±ÀÀ£»òµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ(RCE)¡£CVE-2022-3786¿É±»¹¥»÷Õßͨ¹ý¶ñÒâÓʼþµØÖ·ÀûÓã¬Í¨¹ý»º³åÇøÒç³öÀ´´¥·¢»Ø¾ø·þÎñ״̬¡£¹ÌÈ»×î³õµÄ¾¯±¨¶½´ÙÖÎÀíÔ±µ±¼´²ÉÈ¡Ðж¯À´»º½â·ì϶£¬µ«ÏÖʵӰÏìÒªÓÐÏ޵ö࣬ÓÉÓÚCVE-2022-3602(×î³õ±»ÆÀ¼¶ÎªCritical)Òѱ»½µ¼¶ÎªHigh£¬²¢ÇÒËüÖ»Ó°ÏìOpenSSL 3.0¼°¸ü¸ß°æ±¾¡£
https://www.bleepingcomputer.com/news/security/openssl-fixes-two-high-severity-vulnerabilities-what-you-need-to-know/
2¡¢SnatchÐû³ÆÒÑÈëÇÖ¾ü¹¤ÆóÒµ¹©¸øÉÌHENSOLDT France
ýÌå10ÔÂ31Èճƣ¬ÀÕË÷ÍÅ»ïSnatch¹¥»÷ÁË·¨¹ú¹«Ë¾HENSOLDT France¡£HENSOLDTÊÇÒ»¼ÒרÃÅ´Óʾüʺ͹ú·Àµç×Ó²úÆ·µÄ¹«Ë¾£¬ÖØÒªÎª·¨¹úºÍ¹ú±íµÄº½¿Õ¡¢¹ú·À¡¢ÄÜÔ´ºÍÔËÊ䲿ÃÅÌṩµç×Ó½â¾ö¹æ»®¡¢²úÆ·ºÍ·þÎñ¡£SnatchÒѽ«¸Ã¹«Ë¾Ôö³¤µ½ÆäTorÍøÕ¾ÉÏ£¬²¢°ä²¼ÁËÒ»·Ý±»µÁÊý¾ÝµÄÑù±¾(94 MB)×÷Ϊ¹¥»÷»î¶¯µÄÖ¤¾Ý¡£SnatchÓÚ2019Äêµ×³õ´Î±»·¢ÏÖ£¬Ëü¿É½«±»Ï°È¾µÄÍÆËã»ú³ÁÆôµ½°²È«Ä£Ê½ÒÔÈÆ¹ý°²È«½â¾ö¹æ»®¡£
https://securityaffairs.co/wordpress/137886/cyber-crime/snatch-hensoldt-france-ransomware.html
3¡¢ÐÂÎ÷À¼º½¿Õ¹«Ë¾Ð¹Â©Æä²¿Ãſͻ§Ô⵽ƾ֤Ìî³ä¹¥»÷
¾Ý10ÔÂ30ÈÕ±¨Â·£¬ÐÂÎ÷À¼º½¿Õ¹«Ë¾Ð¹Â©ºÚ¿ÍÊÔͼͨ¹ýƾ֤Ìî³ä¹¥»÷À´½Ó¼ûÆä¿Í»§µÄÕË»§¡£¸Ã¹«Ë¾Ö¸³ö£¬¹¥»÷ÕßûÓÐÈëÇÖ¹«Ë¾µÄÈκÎϵͳ£¬½öÓ×ÎÒµÄÕË»§Êܵ½Ó°Ïì¡£Ö»ÓÐÉÙÊý¿Í»§Ôâµ½Á˹¥»÷£¬ÇÒ¹¥»÷ÕßûÓнӼûÈκÎÚ²ÆÐÔÂòÂôÐÅÏ¢»òÃô¸ÐÐÅÏ¢¡£ÐÂÎ÷À¼º½¿Õ¹«Ë¾Ä¿Ç°ÒÑËø¶¨ÕË»§£¬²¢Í¨Öª¿Í»§±ÉÈË´ÎʹÓÃAirpointsϵͳ֮ǰ¸ü¸ÄËûÃǵĵǼÐÅÏ¢¡£
https://securityaffairs.co/wordpress/137793/cyber-crime/air-new-zealand-breach.html
4¡¢APT 10ÀûÓÃɱ¶¾Èí¼þÏòÈÕ±¾µÄ×éÖ¯·Ö·¢LODEINFO
KasperskyÓÚ10ÔÂ31ÈÕÅû¶ÁËAPT 10ÀûÓð²È«Èí¼þ·Ö·¢×Ô½ç˵ºóÃÅLODEINFOµÄ¹¥»÷»î¶¯£¬ÖØÒªÕë¶ÔÈÕ±¾µÄýÌ弯ÍÅ¡¢±í½»»ú¹¹¡¢µ±¾ÖºÍ¹«¹²²¿ÃÅ×éÖ¯ÒÔ¼°Öǿ⡣´Ó½ñÄê3ÔÂ·ÝÆðÍ·£¬×êÑÐÈËÔ±°ÑÎȵ½Õë¶ÔAPT10¹¥»÷ʹÓÃÁËеÄϰȾý½é£¬Ô̺¬Óã²æÊ½´¹µöÓʼþ¡¢×Ô½âѹ(SFX)RARÎļþÒÔ¼°ÀÄÓð²È«Èí¼þÖеÄDLL²à¼ÓÔØ·ì϶¡£´Ë±í£¬¶ñÒâÈí¼þ¿ª·¢ÕßÔÚ2022Äê°ä²¼ÁË6¸ö°æ±¾µÄLODEINFO£¬×êÑÐÈËÔ±»¹·ÖÎöÁ˸úóÃÅÔÚÕâÒ»ÄêÖеÄÑݱ䡣
https://securelist.com/apt10-tracking-down-lodeinfo-2022-part-i/107742/
5¡¢½ÌÓý¼¼Êõ¹«Ë¾CheggÒò3ÄêÄÚµÄ4´ÎÊý¾Ýй¶±»FTC¸æ×´
ýÌå10ÔÂ31ÈÕ±¨Â·£¬½ÌÓý¼¼Êõ¹«Ë¾Chegg±»FTC¸æ×´£¬ÒòÆäÔÚ2017ÄêÒÔÀ´µÄ4´ÎÊý¾Ýй¶ÊÂÎñÖÐй¶ÁËÊýǧÍò¿Í»§ºÍÔ±¹¤µÄÐÅÏ¢¡£CheggÔÚ2017Äê9Ô³õ´ÎÔâµ½ÈëÇÖ£¬Ô´ÓÚÕë¶Ô¶àÃûÔ±¹¤µÄ´¹µö¹¥»÷£»2018Äê4Ô£¬Ä³Ç°³Ð°üÉÌʹÓõǼÐÅÏ¢½Ó¼ûÁËÔ̺¬Êý°ÙÍòÓû§Êý¾ÝµÄ´æ´¢Í°£»Ò»Äêºó£¬Cheggij¸ß¹ÜµÄÍ´´¦ÔÚÒ»´Î´¹µö¹¥»÷Öб»µÁµ¼ÖÂÊý¾Ýй¶£»ÓÖ¹ýÁË12¸öÔ£¬ÁíÒ»ÃûCheggÔ±¹¤Ôâµ½´¹µö¹¥»÷¡£FTCͶË߳ƣ¬ÕâЩй¶ÊÂÎñ¶¼ÊÇÈô¸É²»Á¼µÄÊý¾Ý°²È«Êµ¼ÊµÄÁ˾֡£
https://www.bleepingcomputer.com/news/security/chegg-sued-by-ftc-after-suffering-four-data-breaches-within-3-years/
6¡¢Unit42°ä²¼¹ØÓÚ¶à¸öÒøÐÐľÂíʹÓõļ¼ÊõµÄ·ÖÎö»ã±¨
Unit42ÔÚ10ÔÂ31ÈÕ°ä²¼Á˹ØÓÚÒøÐÐľÂí¼¼ÊõµÄ·ÖÎö»ã±¨¡£ÓÉÓÚ¹¥»÷Õß²»ÐÝʹÓÃеļ¼ÊõÀ´Èƹý¼ì²âºÍÖ´Ðй¥»÷£¬×êÑгöÓÚ¾¼ÃÖ÷ÕŵĶñÒâÈí¼þÄܹ»Ô®ÊÖ·ÀÓùÕ߸üÓÐЧµØ±£»¤×éÖ¯¡£¸Ã»ã±¨·ÖÎöÁ˳ÛÃûµÄÒøÐÐľÂíÓÃÀ´Èƹý¼ì²â¡¢ÇÔÈ¡Ãô¸ÐÊý¾ÝºÍÅú¸ÄÊý¾ÝµÄ¼¼Êõ£¬»¹½«ÃèÊöÈôºÎ·ÀÓùÕâЩ¼¼Êõ£¬Éæ¼°Zeus¡¢Kronos¡¢Trickbot¡¢IcedID¡¢EmotetºÍDridex¡£ÒøÐÐľÂíʹÓõļ¼ÊõÔ̺¬Webinject¡¢Named Pipe¡¢Heaven's Gate¡¢AtomBombing¡¢HookingºÍPE InjectionµÈ¡£
https://unit42.paloaltonetworks.com/banking-trojan-techniques/


¾©¹«Íø°²±¸11010802024551ºÅ