ÃÀ¹úÃÜÎ÷Î÷±ÈÖݵ±¾Ö»ú¹¹µÄ¶à¸öÍøÕ¾Ôâµ½DDoS¹¥»÷

°ä²¼¹¦·ò 2022-11-10
1¡¢ÃÀ¹úÃÜÎ÷Î÷±ÈÖݵ±¾Ö»ú¹¹µÄ¶à¸öÍøÕ¾Ôâµ½DDoS¹¥»÷

¾ÝýÌå11ÔÂ9ÈÕ±¨Â·£¬ÖÐÆÚÑ¡¾ÙÆÚ¼ä£¬ÃÜÎ÷Î÷±ÈÖݵ±¾Ö»ú¹¹µÄ¶à¸öÍøÕ¾¹Ø¹Ø¡£ÕâÊǵ±Ìì×îÑϳÁµÄÖжÏ£¬²»ÍâijÁª¹ú¹ÙÔ±³Æ£¬Ëæ×Å¼ÆÆ±¹¤×÷µÄ½øÐУ¬¿ÉÄÜ»¹»áÓиü¶àµÄÍøÕ¾±»¹Ø¹Ø¡£ÃÜÎ÷Î÷±ÈÖݹúÎñÇä°ì¹«ÊÒÔÚÖܶþÍíÉϵÄÉêÃ÷°µÊ¾£¬ÓÉÓÚDDoS»î¶¯µ¼ÖÂÁ÷Á¿Òì³£Ôö³¤£¬²¿ÃÅÍøÕ¾ÎÞ·¨½Ó¼û£¬µ«Ã»ÓжÔͶƱ»ò¼ÆÆ±Ôì³ÉÓ°Ï졣Ŀǰ£¬ÉÐÎÞ·¨È·ÈÏÕâ´ÎDDoS¹¥»÷µÄÆðÔ´¡£

https://therecord.media/mississippi-election-websites-knocked-out-by-ddos-attack/

2¡¢åÚÏë°ä²¼¸üУ¬½¨¸´¿ÉÓÃÓÚ½ûÓÃUEFI°²È«Æô¶¯µÄ·ì϶

ýÌå11ÔÂ9Èճƣ¬åÚÏ뽨¸´ÁËÓ°Ïì¸÷ÀàThinkBook¡¢IdeaPadºÍYoga±Ê¼Ç±¾µçÄÔÖеķì϶£¬ËüÃǿɱ»ÓÃÓÚ½ûÓÃUEFI°²È«Æô¶¯¡£Õâ´Î½¨¸´ÁËWMIÉèÖÃÇý¶¯·¨Ê½Öеķì϶£¨CVE-2022-3430£©£¬¿É±»ÓµÓÐÌáÉýȨÏ޵Ĺ¥»÷Õßͨ¹ýÅú¸ÄNVRAM±äÁ¿À´´Û¸Ä°²È«Æô¶¯ÉèÖá£ÒÔ¼°£¬±Ê¼Ç±¾É豸µÄÔì×÷¹ý³ÌÖÐʹÓõÄÇý¶¯·¨Ê½´æÔÚ·ì϶£¨CVE-2022-3431£©£¬ÓµÓиßȨÏ޵Ĺ¥»÷Õß¿Éͨ¹ýÅú¸ÄNVRAM±äÁ¿À´´Û¸Ä°²È«Æô¶¯ÉèÖ᣻¹ÓеÚÈý¸öÀàËÆÐÔÖʵķì϶£¨CVE-2022-3432£©£¬½öÓ°ÏìÁËIdeapad Y700-14ISK¡£ÓÉÓÚÊÜÓ°ÏìµÄ²úÆ·ÒÑ´ïµ½EOL£¬Lenovo²»»á½¨¸´´Ë·ì϶¡£

https://www.bleepingcomputer.com/news/security/lenovo-fixes-flaws-that-can-be-used-to-disable-uefi-secure-boot/

3¡¢VMware½¨¸´ÆäWorkspace ONE AssistÖеĶà¸ö·ì϶

11ÔÂ8ÈÕ£¬VMware°ä²¼°²È«¸üн¨¸´ÁËWorkspace ONE Assist½â¾ö¹æ»®ÖеĶà¸ö·ì϶¡£ÆäÖУ¬½ÏΪÑϳÁµÄÊÇÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2022-31685£©¡¢°Ü»µµÄÉí·ÝÑéÖ¤²½Öè·ì϶£¨CVE-2022-31686£©ºÍ°Ü»µµÄ½Ó¼û½ÚÔì·ì϶£¨CVE-2022-31687£©£¬ËüÃǵÄCVSSÆÀ·Ö¾ùΪ9.8£¬¿É±»Ô¶³Ì¹¥»÷ÕßÓÃÀ´ÈƹýÉí·ÝÑéÖ¤²¢½«È¨ÏÞÌáÉýΪÖÎÀíÔ±¡£´Ë±í£¬¸üл¹½¨¸´ÁËÒ»¸ö·´ÉäÐÍ¿çÕ¾¾ç±¾·ì϶(CVE-2022-31688)ºÍÒ»¸ö»á»°¹Ì¶¨·ì϶(CVE-2022-31689)¡£

https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-auth-bypass-bugs-in-remote-access-tool/

4¡¢LockBit 3.0ͨ¹ý¶ñÒâÈí¼þAmadey Bot½øÐзַ¢

AhnLabÔÚ11ÔÂ8ÈÕй©£¬¹¥»÷ÕßÔÚʹÓöñÒâÈí¼þAmadey BotÀ´·Ö·¢LockBit¡£×êÑÐÈËÔ±°ÑÎȵ½Á½¸ö·ÖÆçµÄϰȾÁ´£¬Ò»¸öÒÀÀµÓÚWordÎĵµÖеÄVBAºê£¬ÁíÒ»¸ö½«¶ñÒâ¿ÉÖ´ÐÐÎļþ¼Ù×°³ÉWordÎļþ¡£ÔÚǰһÖÖÇé¿öÏ£¬Óû§±ØÐëµã»÷ÆôÓÃÄÚÈÝÀ´Ö´Ðк꣬¸Ãºê»á´´½¨Ò»¸öLNKÎļþ²¢½«Æä´æ´¢µ½C:\Users\Public\skem.lnk£¬´ËÎļþÊÇAmadeyµÄdownloader¡£ÁíÒ»Ìõ¹¥»÷Á´ÖУ¬Amadey¼Ù×°³É´øÓÐWordͼ±êµÄÎļþ£¬µ«ËüÏÖʵÉÏÊÇÒ»¸öͨ¹ý´¹µöÓʼþ´«²¼µÄ¿ÉÖ´ÐÐÎļþ£¨¡°Resume.exe¡±£©¡£

https://thehackernews.com/2022/11/amadey-bot-spotted-deploying-lockbit-30.html

5¡¢Ä«Î÷¸ç»ù´¡ÉèÊ©¡¢Í¨Ñ¶ºÍ½»Í¨²¿SICTй©ÆäITϵͳ±»ºÚ

¾Ý11ÔÂ8ÈÕ±¨Â·£¬Ä«Î÷¸ç»ù´¡ÉèÊ©¡¢Í¨Ñ¶ºÍ½»Í¨²¿£¨SICT£©³ÆÆäITϵͳ±»ºÚ¡£ÓÉÓÚÕâ´Î¹¥»÷£¬Ä«Î÷¸ç½»Í¨²¿ÒÑÖÕ³¡ÎªÉÌÓÿ¨³µÔËÓªÉÌ·¢·ÅеÄÐí¿ÉÖ¤¡¢³µÅƺͼÝÊ»ÅÆÕÕ£¬Ö±ÖÁ12ÔÂ31ÈÕ£¬Õâ¿ÉÄܸøÔËÊäÔËÓªÉÌÔì³ÉÓ°Ïì¡£SICTÔÚ10ÔÂ24ÈÕ°ä²¼ÍÆÎÄÅû¶ÁËÕâ´ÎÊÂÎñ£¬²¢°µÊ¾ÍøÂçÊÂÎñÖÎÀíºÍÓ¦¼±´òËãÒÑÆô¶¯£¬µ÷²éÔÚ½øÐÐÖС£¸Ã»ú¹¹ÉÐδעÃ÷Õë¶ÔµÄÊÇÄÄЩÐÅÏ¢£¬µ«°µÊ¾¹¥»÷»î¶¯²¢Î´·ÛËé¸Ã»ú¹¹µÄϵͳ»òÓ°Ï칫ÃñµÄÊý¾Ý¡£

https://www.databreaches.net/cyberattack-disrupts-mexicos-transportation-system/

6¡¢Zimperium°ä²¼¹ØÓÚChrome¶ñÒâÀ©´óCloud9µÄ·ÖÎö»ã±¨

11ÔÂ8ÈÕ£¬Zimperium³ÆÆä·¢ÏÖÁËÒ»¸öÃûΪCloud9µÄÐÂChromeä¯ÀÀÆ÷½©Ê¬ÍøÂ磬ËüʹÓöñÒâÀ©´óÀ´ÇÔÈ¡ÔÚÏßÕÊ»§¡¢¼Í¼¼üÅÌÊäÈë¡¢×¢Èë¸æ°×ºÍ¶ñÒâJS´úÂ룬²¢ÈÃÖ¸±êµÄä¯ÀÀÆ÷²Î¼ÓDDoS¹¥»÷¡£Cloud9ÏÖʵÉÏÊÇChromiumä¯ÀÀÆ÷£¨Ô̺¬ChromeºÍEdge£©µÄÔ¶³Ì½Ó¼ûľÂí£¬¿ÉÔ¶³ÌÖ´ÐкÅÁî¡£¸Ã¶ñÒâChromeÀ©´ó·¨Ê½ÔÚ¹Ù·½ÍøÉÏÉ̵êÖв»³ÉÓ㬶øÊÇͨ¹ýÆäËüÇþ·´«²¼£¬ÀýÈçÍÆËͼÙðµÄAdobe Flash Player¸üеÄÍøÕ¾¡£ÕâÖÖ²½ÖèËÆºõºÜ³É¹¦£¬ÓÉÓÚZimperium»ã±¨³Æ£¬ËûÃÇÒѾ­ÔÚÈ«ÇòµÄϵͳÉ϶¼¿´µ½ÁËϰȾCloud9µÄÇé¿ö¡£

https://www.zimperium.com/blog/the-case-of-cloud9-chrome-botnet/