°Ä´óÀûÑǵڶþ´óµçÐŹ«Ë¾Optus½üÍòÍòÓû§µÄÐÅϢй¶

Ðû²¼Ê±¼ä 2022-09-26

1¡¢°Ä´óÀûÑǵڶþ´óµçÐŹ«Ë¾Optus½üÍòÍòÓû§µÄÐÅϢй¶

      

¾Ý9ÔÂ23ÈÕ±¨µÀ £¬°Ä´óÀûÑǵڶþ´óµçÐŹ«Ë¾OptusÔâµ½¹¥»÷ £¬¿ÉÄÜÓ°Ïì¶à´ï900Íò¸öÓû§µÄÊý¾Ý¡£Optus³Æ £¬¹¥»÷ÕßÏë·¨½øÈëÁ˿ͻ§Éí·ÝÊý¾Ý¿â £¬²¢Í¨¹ýÓ¦ÓóÌÐò½Ó¿Ú£¨API£©½«Æä¿ª·Å¸øÆäËûϵͳ¡£ÊÂÎñÈÔÔÚÊÓ²ìÖÐ £¬OptusÒÔΪÆäÖÐÒ»¸öÍøÂ类̻¶ÔÚÁËÒ»¸öÓл¥ÁªÍø½ÓÈëµÄ²âÊÔÍøÂçÖС£¸Ã¹«Ë¾ÏÓÒɹ¥»÷ÕßÒѾ­ÇÔÈ¡ÁËÏûºÄÕßµÄÊý¾Ý¿â £¬²¢¿ÉÄܸ´ÖÆÁËÆäÖеÄÈý·ÖÖ®Ò»¡£OptusÌåÏÖËüÔÚ·¢Ã÷¹¥»÷ºóÁ¬Ã¦½ÓÄÉÁ˲½·¥ £¬¿ÉÊÇûÓÐ͸¶¹ØÓÚ¹¥»÷µÄÏêϸÄÚÈÝ¡£


https://www.hackread.com/optus-data-breach-australia-telecom-firm/


2¡¢SophosÐÞ¸´Òѱ»Ê¹ÓõĴúÂë×¢ÈëÎó²îCVE-2022-3236

      

SophosÔÚ9ÔÂ23ÈÕÐÞ¸´ÁËÆä·À»ðǽÖдúÂë×¢ÈëÎó²î£¨CVE-2022-3236£©¡£¸ÃÎó²îCVSSÆÀ·ÖΪ9.8 £¬Éæ¼°Óû§ÃÅ»§ºÍWebÖÎÀí×é¼þ £¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¸Ã¹«Ë¾ÌåÏÖ £¬ËüÒѾ­ÊӲ쵽ʹÓøÃÎó²îµÄ¹¥»÷Ô˶¯ £¬Ö÷ÒªÊÇÔÚÄÏÑǵØÇø £¬²¢Ôö²¹ËµËüÖ±½Ó֪ͨÁËÕâЩ×éÖ¯¡£ÆôÓÃÁËÔÊÐí×Ô¶¯×°ÖÃÐÞ²¹³ÌÐò¹¦Ð§µÄSophos FirewallÓû§ÎÞÐèÖ´ÐÐÈκβÙ×÷ £¬ÇÒÆôÓÃÊÇĬÈÏÉèÖá£SophosÔÚ½ñÄê3Ô»¹ÐÞ¸´ÁËÒ»¸öÀàËÆµÄFirewallÎó²î(CVE-2022-1040) £¬¸ÃÎó²îÒ²ÔÚÕë¶ÔÄÏÑÇ×éÖ¯µÄ¹¥»÷Öб»Ê¹Óá£


https://www.bleepingcomputer.com/news/security/sophos-warns-of-new-firewall-rce-bug-exploited-in-attacks/


3¡¢YouTubeÈ«Çò¹æÄ£ÄÚ·þÎñÖÐÖ¹ÇÒÉв»ÇåÎúÊÂÎñÔµ¹ÊÔ­ÓÉ

      

ýÌå9ÔÂ23ÈÕ³Æ £¬YouTubeÔÚÈ«Çò¹æÄ£ÄÚ·þÎñÖÐÖ¹ £¬³ÉǧÉÏÍòµÄÓû§±¨¸æËûÃÇÎÞ·¨»á¼ûÖ±²¥¡£ÔÚʵÑé»á¼ûYouTubeʱ £¬Óû§»á¿´µ½´øÓмÓÔØ¶¯»­µÄºÚÆÁºÍ¡°ÇëÉÔºóÔÙÊÔ¡±µÄ¹ýʧÐÂÎÅ¡£ÄÇЩÏë·¨¼ÓÔØÖ±²¥µÄÓû§³ÆÊÓÆµÖͺó £¬Ì¸ÌìÐÂÎÅÒ²Öͺó»ò»ù´¡²»ÏÔʾ¡£»¥ÁªÍø¼à¿Ø×éÖ¯NetBlocksҲ֤ʵ £¬YouTubeÕýÂÄÀúÒ»³¡Ó°ÏìÖ±²¥µÄÈ«ÇòÐÔÖÐÖ¹ £¬´ËÊÂÎñÓë¹ú¼Ò¼¶»¥ÁªÍøÖÐÖ¹»ò¹ýÂËÎ޹ء£ÏÖÔÚ £¬Éв»ÇåÎúÕâÊÇÍýÏëÖеÄά»¤Ô˶¯¡¢YouTube·þÎñÆ÷µÄÎÊÌâÕÕ¾ÉÓë¶ñÒâ¹¥»÷ÓйØ¡£


https://www.bleepingcomputer.com/news/technology/youtube-down-live-streams-hit-by-worldwide-outage/


4¡¢Anonymous³ÆÒÑÈëÇÖ¶íÂÞ˹¹ú·À²¿ÍøÕ¾²¢¹ûÕæ30ÍòÈËÊý¾Ý

      

AnonymousÓÚ9ÔÂ23ÈÕÔÚÆäTwitterÕË»§ÉÏÐû²¼ÐÂÎÅ £¬³ÆÒѾ­ÈëÇÖÁ˶íÂÞ˹¹ú·À²¿µÄÍøÕ¾¡£¸ÃÍŻﻹй¶ÁË305925È˵ÄÊý¾Ý £¬ÕâЩÈË¿ÉÄÜÊÇÆÕ¾©×ÜͳÐû²¼µÄÈý²¨¾üÊÂÔ˶¯·¢¶¯ÖеĵÚÒ»²¨×¼±¸ÒÛÎäÊ¿¡£¹¥»÷Õßͨ¹ýProtonDrive¹ûÕæÁËÒ»¸ö90MB¾ÞϸµÄTXTÎļþ £¬ÆäÖаüÀ¨Áè¼Ý30ÍòÈ˵ÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µØÇøºÍµØÇø¡£ÏÖÔÚÎÞ·¨ÑéÖ¤ÕâЩµµ°¸¼òÖ±ÇÐȪԴ¡£


https://www.infosecurity-magazine.com/news/russian-reservists-leaked-anonymous/


5¡¢GitHub·¢Ã÷ð³äCircleCIƽ̨ÈëÇÖÆäÓû§ÕË»§µÄ¹¥»÷Ô˶¯

      

¾ÝýÌå9ÔÂ25ÈÕ±¨µÀ £¬GitHubÌáÐÑÕë¶ÔÆäÓû§µÄ´¹ÂÚ¹¥»÷Ô˶¯ £¬Í¨¹ýð³äCircleCI DevOpsƽ̨À´ÇÔȡƾ֤ºÍË«ÖØÉí·ÝÑéÖ¤(2FA)´úÂë¡£¸Ã¹«Ë¾ÓÚ9ÔÂ16ÈÕ»ñϤ´Ë´Î¹¥»÷ £¬²¢Ö¸³ö³ýGitHubÍâ £¬´¹ÂÚÔ˶¯ÒÑÓ°Ïìµ½Ðí¶à×éÖ¯¡£´¹ÂÚÐÅÏ¢Éù³ÆÓû§µÄCircleCI»á»°ÒÑÓâÆÚ £¬²¢ÊÔͼÓÕʹÊÕ¼þÈËʹÓÃGitHubƾ֤µÇ¼¡£ÊÕ¼þÈ˱»Öض¨Ïòµ½Î±ÔìµÄGitHubµÇÂ¼Ò³Ãæºó £¬»á±»ÇÔÈ¡ÊäÈëµÄƾ֤ºÍ2FA´úÂë¡£¸Ã¹«Ë¾ÌåÏÖ £¬ÊÜÓ²¼þÇå¾²ÃÜÔ¿±£»¤µÄÕË»§²»Ò×Ôâµ½µ½ÕâÖÖ¹¥»÷¡£


https://securityaffairs.co/wordpress/136211/hacking/phishing-circleci-github-accounts.html


6¡¢AhnLabÐû²¼FARGO¹¥»÷MS-SQL·þÎñÆ÷µÄÆÊÎö±¨¸æ

      

9ÔÂ23ÈÕ £¬AhnLabÐû²¼±¨¸æ³ÆÒ×Êܹ¥»÷µÄMicrosoft SQL·þÎñÆ÷Ôâµ½ÁËFARGOµÄÐÂÒ»ÂÖ¹¥»÷¡£FARGOÓëGlobeImposterÒ»Ñù £¬ÊÇÖ÷ÒªÕë¶ÔMS-SQL·þÎñÆ÷µÄÀÕË÷Èí¼þÖ®Ò» £¬ÔÚÒÑÍùÒ²±»³ÆÎªMallox¡£Ñ¬È¾Ê¼ÓÚÄ¿µÄÉè±¹ØÁ¬ÄMS-SQLÀú³ÌʹÓÃcmd.exeºÍpowershell.exeÏÂÔØ.NETÎļþ¡£Payload»á»ñÈ¡ÆäËû¶ñÒâÈí¼þ £¬ÌìÉú²¢ÔËÐÐÖÕÖ¹ÌØ¶¨Àú³ÌºÍ·þÎñµÄBATÎļþ¡£È»ºó £¬½«ÀÕË÷Èí¼þpayload×¢Èëµ½Õýµ±µÄWindowsÀú³ÌAppLaunch.exeÖС£


https://asec.ahnlab.com/en/39152/