GoogleÐÞ¸´ChromeÖÐÒѱ»Ê¹ÓõÄÎó²îCVE-2022-3723
Ðû²¼Ê±¼ä 2022-10-31
¾Ý10ÔÂ28ÈÕ±¨µÀ£¬GoogleÐû²¼ÁËChromeµÄ½ôÆÈÇå¾²¸üУ¬ÐÞ¸´×Ô2022ÄêÍ·ÒÔÀ´µÄµÚÆß¸öÁãÈÕÎó²î¡£¸ÃÎó²î(CVE-2022-3723)ÊÇChrome V8 JavascriptÒýÇæÖеÄÒ»¸öÀàÐÍ»ìÏýÎó²î£¬ÓÉAvastµÄÑо¿Ö°Ô±ÓÚ½ñÄê10ÔÂ25ÈÕ±¨¸æ¡£³öÓÚÇå¾²Ôµ¹ÊÔÓÉ£¬¸Ã¹«Ë¾Ã»ÓÐÌṩÓйØÎó²îµÄÏêϸÐÅÏ¢£¬Ò²Ã»ÓÐ˵Ã÷Éæ¼°¸ÃÎó²îµÄ¹¥»÷Ô˶¯Ë®Æ½µÄÐÔ×Ó¡£Ñо¿Ö°Ô±Ç¿ÁÒ½¨ÒéChromeÓû§¾¡¿ì¸üÐÂÆää¯ÀÀÆ÷ÒÔ×èÖ¹´ËÀ๥»÷¡£
https://www.bleepingcomputer.com/news/security/google-fixes-seventh-chrome-zero-day-exploited-in-attacks-this-year/
2¡¢Ë¹Âå·¥¿ËºÍ²¨À¼Òé»áµÄITϵͳÔâµ½´ó¹æÄ£ÍøÂç¹¥»÷
ýÌå10ÔÂ29Èճƣ¬Ë¹Âå·¥¿ËºÍ²¨À¼Òé»áÔâµ½´ó¹æÄ£ÍøÂç¹¥»÷¡£²¨À¼Õþ¸®³Æ£¬Õâ´Î¹¥»÷¿ÉÄÜÓë²ÎÒéÔºµÄͶƱÓйأ¬¹¥»÷ÍêÈ«ÖÐÖ¹ÁËÒé»áµÄIT»ù´¡ÉèÊ©¡£²¢Í¸Â¶Õâ´Î¹¥»÷ÊÇ¶àÆ«ÏòµÄ£¬°üÀ¨À´×ÔÂÞ˹Áª°îÄÚ²¿µÄ¹¥»÷¡£Ë¹Âå·¥¿ËÒé»á¸±Ò鳤ÌåÏÖ£¬¹¥»÷µ¼ÖÂ˹Âå·¥¿ËÒé»áµÄITϵͳºÍµç»°Ïß·̱»¾£¬¼¸Ïî·¨°¸µÄͶƱ±»ÖÐÖ¹¡£ËûÃÇÏÖÔÚÉÐδȷ¶¨¸ÃÊÂÎñµÄȪԴ£¬ÆäÊÖÒÕÖ°Ô±ÕýÔÚ½â¾ö¸ÃÎÊÌâ¡£
https://securityaffairs.co/wordpress/137777/hacking/slovak-polish-parliaments-cyberattacks.html
3¡¢Å·ÖÞ×î´óµÄÍÉú²úÉÌAurubisÔÚ±»¹¥»÷ºóϵͳ¹Ø±Õ
10ÔÂ28ÈÕ±¨µÀ£¬Aurubis³ÆÆäÔâµ½¹¥»÷£¬±»ÆÈ¹Ø±ÕITϵͳÒÔ±ÜÃâ¹¥»÷ÉìÕÅ¡£AurubisÊÇÅ·ÖÞ×î´óºÍÌìϵڶþ´óµÄÍÉú²úÉÌ£¬Ã¿ÄêÉú²ú100Íò¶ÖÒõ¼«Í¡£Aurubisͨ¸æÏÔʾ£¬ËûÃǹرÕÁËÆäËùÔڵصÄÖÖÖÖϵͳ£¬µ«²¢Î´Ó°ÏìÉú²ú¡£Ò±Á¶³§µÄÉú²úºÍ»·±£ÉèÊ©Õý³£ÔËÐУ¬ÊÕÖ§»õÎïÒ²ÔÚÈ˹¤Î¬»¤¡£ÏÖÔÚ£¬¸Ã¹«Ë¾ÈÔÕýÔÚÆÀ¹ÀÍøÂç¹¥»÷µÄÓ°Ï죬ÎÞ·¨Ô¤¼ÆÏµÍ³»Ö¸´ÐèÒª¶à³¤Ê±¼ä¡£ÏÖÔÚÈ·µ±ÎñÖ®¼±ÊǼá³Ö²úÁ¿ÔÚÕý³£Ë®Æ½£¬³öÓÚÕâ¸öÔµ¹ÊÔÓÉ£¬Ò»Ð©²Ù×÷ÒÑתÏòÊÖ¶¯Ä£Ê½£¬Ö±µ½ÈÛÁ¶³§»Ö¸´ÅÌËã»ú¸¨ÖúµÄ×Ô¶¯»¯¡£
https://www.bleepingcomputer.com/news/security/largest-eu-copper-producer-aurubis-suffers-cyberattack-it-outage/
4¡¢°Ä´óÀûÑÇÁÙ´²ÊµÑéÊÒ³ÆÀÕË÷¹¥»÷µ¼ÖÂ22ÍòÈËÐÅϢй¶
¾ÝýÌå10ÔÂ27Èճƣ¬°Ä´óÀûÑÇÁÙ´²ÊµÑéÊÒ(ACL)͸¶ÆäMedlab PathologyÓªÒµ±¬·¢ÁËÊý¾Ýй¶£¬Ó°ÏìÔ¼223000Ãû»¼ÕߺÍÔ±¹¤¡£ÀÕË÷ÍÅ»ïQuantumÓÚ2022Äê6ÔÂ14ÈÕÔÚÆäTorÍøÕ¾ÉÏ´«ÁËËùÓб»µÁÎļþ£¬¹²86 GBµÄÊý¾Ý£¬°üÀ¨»¼ÕߺÍÔ±¹¤µÄÏêϸÐÅÏ¢¡¢²ÆÎñ±¨¸æ¡¢·¢Æ±¡¢ÌõÔ¼¡¢±í¸ñ¡¢´«Æ±ºÍÆäËû˽ÈËÎļþµÈ¡£Æ¾Ö¤ÍøÕ¾Êý¾Ý£¬MedLabµÄÐ¹Â¶Ò³ÃæÒѱ»»á¼û130000´Î¡£¹¥»÷±¬·¢ÓÚ2022Äê2Ô·ݣ¬µ«¸ÃÇå¾²ÊÂÎñÔÚ±¬·¢9¸öÔºó²Å±»Åû¶£¬ACLµÄͨ¸æÊÔͼΪÕâÖÖÍÏÑÓÌṩÀíÓÉ¡£
https://www.databreaches.net/australian-clinical-labs-says-data-of-223000-people-hacked/
5¡¢iOSºÍmacOSÖеÄSiriSpyÎó²î¿ÉÇÔÌýÓû§ÓëSiriµÄ¶Ô»°
ýÌåÓÚ10ÔÂ27ÈÕ±¨µÀ³Æ£¬Ó°ÏìÁËApple iOSºÍmacOSµÄSiriSpyÎó²î£¨CVE-2022-32946£©£¬¿ÉÒÔ±»Èκοɻá¼ûÀ¶ÑÀµÄÓ¦ÓóÌÐòÓÃÀ´ÇÔÌýÓû§ÓëSiriµÄ¶Ô»°¡£ÔÚ²âÊÔAirBuddyµÄ¹¦Ð§Ê±£¬Ñо¿Ö°Ô±×¢Öص½AirPods°üÀ¨Ò»¸ö´øÓÐUUIDµÄ·þÎñ£¬²¢ÇÒ¾ßÓÐÖ§³Ö֪ͨµÄ¹¦Ð§¡£½øÒ»³ÌÐò²é½«ÉÏÊöUUIDÓëÓÃÓÚSiriºÍÌýд֧³ÖµÄDoAP·þÎñÏà¹ØÁª£¬¹¥»÷Õß¿ÉÒÔ½¨ÉèÒ»¸ö¶ñÒâÓ¦Ó㬸ÃÓ¦ÓÿÉÒÔͨ¹ýÀ¶ÑÀÅþÁ¬µ½AirPods²¢ÔÚºóÌ¨Â¼ÖÆÒôƵ¡£ÏÖÔÚ£¬¸ÃÎó²îÒѱ»ÐÞ¸´¡£
https://securityaffairs.co/wordpress/137710/security/sirispy-apple-flaw-spy-conversations.html
6¡¢SymantecÐû²¼CraneflyÍÅ»ï½üÆÚ¹¥»÷Ô˶¯µÄÆÊÎö±¨¸æ
10ÔÂ28ÈÕ£¬SymantecÐû²¼Á˹ØÓÚCraneflyÍÅ»ï½üÆÚ¹¥»÷Ô˶¯µÄÆÊÎö±¨¸æ¡£±¨¸æÖ¸³ö£¬Cranefly£¨ÓÖÃûUNC3524£©ÕýÔÚʹÓÃÐÂdropper(Trojan.Geppei)À´×°ÖÃÁíÒ»¸öеĶñÒâÈí¼þ(Trojan.Danfuan)ºÍÆäËü¹¤¾ß£¨Hacktool.Regeorg£©¡£Geppei´ÓÕýµ±µÄIISÈÕÖ¾ÖжÁÈ¡ÏÂÁî¡£¶ÁÈ¡µÄÏÂÁî°üÀ¨¶ñÒâ±àÂëµÄ.ashxÎļþ£¬ÕâЩÎļþ±»ÉúÑĵ½ÓÉÏÂÁî²ÎÊýÈ·¶¨µÄí§ÒâÎļþ¼ÐÖУ¬ËüÃÇ×÷ΪºóÃÅÔËÐС£Ö»¹ÜÒÑÔÚÄ¿µÄµÄÍøÂçÉÏDZÔÚÁË18¸öÔ£¬µ«Ñо¿Ö°Ô±ÉÐδÊӲ쵽¹¥»÷Õß´ÓÄ¿µÄÖÐÇÔÈ¡Êý¾ÝµÄÔ˶¯¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/cranefly-new-tools-technique-geppei-danfuan


¾©¹«Íø°²±¸11010802024551ºÅ