GoogleÐû²¼Çå¾²¸üУ¬ÐÞ¸´ChromeÖеĶà¸öÎó²î
Ðû²¼Ê±¼ä 2022-12-0111ÔÂ29ÈÕ£¬GoogleÐû²¼ChromeÇå¾²¸üУ¬×ܼÆÐÞ¸´ÁË28¸öÎó²î¡£ÆäÖнÏΪÑÏÖØµÄÊÇV8ÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2022-4174£©¡¢Camera CaptureÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2022-4175£©¡¢Lacros GraphicsÖеÄÔ½½çдÈëÎó²î£¨CVE-2022-4176£©¡¢À©Õ¹ÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2022-4177£©ÒÔ¼°MojoÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2022-4178£©µÈ¡£GoogleÌåÏÖ£¬ÏÖÔÚûÓйØÓÚÕâЩÎó²îÔÚÒ°ÍⱻʹÓõı¨¸æ¡£
https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_29.html
2¡¢Lastpass͸¶ÆäÔÆ´æ´¢·þÎñÖеĿͻ§Êý¾ÝÒѾй¶
LastPassÔÚ11ÔÂ30ÈÕÐû²¼ÉùÃ÷³Æ£¬¹¥»÷ÕßʹÓÃÔÚ2022Äê8ÔµĹ¥»÷ÊÂÎñÖÐÇÔÈ¡µÄÐÅÏ¢ÈëÇÖÁËÆäÔÆ´æ´¢·þÎñ¡£¸Ã¹«Ë¾ÔÚÆäµÚÈý·½ÔÆ´æ´¢·þÎñÖмì²âµ½Òì³£Ô˶¯£¬Ò»µ©ÀֳɽøÈë¹¥»÷Õß»¹Ïë·¨»á¼û´æ´¢ÔÚ´æ´¢·þÎñÖеĿͻ§Êý¾Ý¡£LastpassÔö²¹ÌåÏÖ£¬ËûÃÇÕýÔÚÆð¾¢Ïàʶ¸ÃÊÂÎñµÄÓ°Ïì¹æÄ££¬²¢È·¶¨ºÚ¿Í»á¼ûÁËÄÄЩÐÅÏ¢¡£ÕâÊÇLastpassÔÚ½ñÄêÅû¶µÄµÚ¶þÆðÇå¾²ÊÂÎñ£¬´Ëǰ£¬¸Ã¹«Ë¾ÔÚ8ÔÂÈ·ÈÏÆä¿ª·¢ÕßÇéÐÎÒò¿ª·¢ÕßÕË»§±»µÁ¶øÔâµ½ÈëÇÖ¡£
https://www.bleepingcomputer.com/news/security/lastpass-says-hackers-accessed-customer-data-in-new-breach/
3¡¢Mandiant·¢Ã÷ʹÓÃUSB×°±¸¹¥»÷·ÆÂɱö×éÖ¯µÄÔ˶¯
¾ÝMandiant 11ÔÂ28ÈÕ±¨µÀ£¬½üÆÚ·¢Ã÷ÁËʹÓÃUSB×°±¸×÷Ϊ³õʼѬȾǰÑÔµÄÌØ¹¤Ô˶¯£¬²¢¼¯ÖÐÔÚ·ÆÂɱö¡£Mandiant½«´ËÔ˶¯¸ú×ÙΪUNC4191£¬×îÔç¿É×·Ëݵ½2021Äê9Ô£¬¸ÃÔ˶¯Ö÷ÒªÓ°ÏìÁ˶«ÄÏÑǵÄ×éÖ¯£¬²¢ÑÓÉìµ½ÁËÃÀ¹ú¡¢Å·ÖÞºÍÑÇÌ«µØÇø¡£×ÝȻĿµÄ×é֯λÓÚÆäËûλÖã¬UNC4191ËùÕë¶ÔµÄϵͳÏÖʵλÓÚ·ÆÂɱö¡£ÔÚͨ¹ýUSB×°±¸¾ÙÐгõʼѬȾºó£¬¹¥»÷Õß»áʹÓÃÕýµ±Ç©ÊðµÄ¶þ½øÖÆÎļþÀ´²à¼ÓÔØ3¸öеĶñÒâÈí¼þϵÁУ¬MISTCLOAK¡¢DARKDEWºÍBLUEHAZE¡£ÀÖ³ÉÈëÇÖºó»á×°ÖÃÖØÃüÃûµÄNCAT¶þ½øÖÆÎļþ²¢ÔÚÄ¿µÄϵͳÉÏÖ´Ðз´Ïòshell£¬´Ó¶øÎª¹¥»÷ÕßÌṩºóÃÅ»á¼û¡£
https://www.mandiant.com/resources/blog/china-nexus-espionage-southeast-asia
4¡¢Ò˼ÒÕýÔÚÊÓ²ìÕë¶ÔÆä¿ÆÍþÌØºÍĦÂå¸çÃŵêµÄÍøÂç¹¥»÷
¾Ý11ÔÂ29ÈÕ±¨µÀ£¬Ò˼ÒÕýÔÚÊÓ²ìÕë¶ÔÆä¿ÆÍþÌØºÍĦÂå¸çÃŵêµÄ¹¥»÷ÊÂÎñ¡£ÖÜÒ»£¬¿ÆÍþÌØºÍĦÂå¸çµÄÍøµã±»Ìí¼Óµ½Vice SocietyÀÕË÷Èí¼þµÄÍøÕ¾£¬ÍøÕ¾ÉϹûÕæµÄÎļþÃûÅú×¢¹¥»÷ÕßÒÑÇÔȡӪҵºÍÔ±¹¤µÄÊý¾Ý£¬²¢¿ÉÄÜ»¹´ÓÔ¼µ©µÄÒ˼ÒÃŵêÇÔÈ¡ÁËÆäËüÐÅÏ¢¡£¹«Ë¾½²»°ÈËÌåÏÖËûÃÇÕýÔÚÓëÏà¹ØÕþ¸®ºÍÍøÂçÇå¾²ÏàÖúͬ°éÒ»ÆðÊÓ²ì´ËÊÂÎñ¡£²îδ¼¸Ò»Äêǰ£¬Ò˼ÒÔøÃæÁÙÕë¶ÔÔ±¹¤ÄÚ²¿ÓÊÏäµÄ´¹ÂÚ¹¥»÷Ô˶¯¡£
https://therecord.media/ikea-investigating-cyberattacks-on-outlets-in-kuwait-morocco/
5¡¢ÐÂÀÕË÷Èí¼þPunisherαװ³ÉCOVID-19¸ú×ÙÓ¦Ó÷ַ¢
¾ÝýÌå11ÔÂ29ÈÕ±¨µÀ£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖÐÂÀÕË÷Èí¼þPunisher±äÌ壬ͨ¹ýÍйÜÔÚcovid19[.]digitalhealthconsulting[.]clÉϵĻùÓÚCOVID-19Ö÷ÌâµÄ´¹ÂÚÍøÕ¾¾ÙÐÐÈö²¥¡£Õâ¸öÍøÕ¾ÌṩαÔìµÄCOVID-19¸ú×ÙÓ¦Óã¬Ö÷ÒªÕë¶ÔÖÇÀû¡£Ñо¿Ö°Ô±ÒÔΪ£¬´Ë´ÎÔ˶¯Õë¶ÔµÄÊÇСÎÒ˽¼Ò¶ø·ÇÆóÒµ£¬ËüÀÕË÷¼ÛÖµ1000ÃÀÔªµÄ±ÈÌØ±ÒÀ´½âÃÜÎļþ¡£±»ÕâÖÖÀÕË÷Èí¼þ¼ÓÃܵÄÎļþÒ²ºÜÈÝÒ×±»½âÃÜ£¬ÓÉÓÚËüʹÓÃAES-128¶Ô³ÆËã·¨¾ÙÐмÓÃÜ¡£
https://www.hackread.com/covid-19-app-punisher-ransomware/
6¡¢È«Ó¡¶Èҽѧ¿ÆÑ§Ñо¿ËùAIIMS±»¹¥»÷ϵͳ崻ú6Ìì
ýÌå11ÔÂ29Èճƣ¬Î»ÓÚµÂÀïµÄȫӡ¶Èҽѧ¿ÆÑ§Ñо¿Ëù(AIIMS) Ôâµ½¹¥»÷ºó£¬ÆäϵͳÒÑÒ»Á¬å´»ú6Ìì¡£¾Ý³Æ£¬ºÚ¿ÍÀÕË÷ԼĪ20ÒÚ¬±ÈµÄ¼ÓÃÜÇ®±Ò£¬µ«µÂÀᆵ·½·ñ¶¨AIIMS±¨¸æÊÕµ½¹ýÈκδËÀàÒªÇó¡£ÏÖÔÚ£¬¿ÉÄÜÒѾй¶ÁË3-4ÍòÍò»¼ÕßµÄÊý¾Ý¡£ÓÉÓÚ·þÎñÆ÷´¦ÓÚÍ£»ú״̬£¬¼±Õï¡¢ÃÅÕסԺºÍ»¯ÑéÊҵϼÕßÕչ˻¤Ê¿·þÎñ¾ùÓÉÈ˹¤ÖÎÀí¡£µÂÀᆵ·½¡¢ÄÚÕþ²¿ºÍÓ¡¶ÈÅÌËã»úÓ¦¼±ÏìӦС×é(CERT-IN)ÕýÔÚÊÓ²ì´ËÀÕË÷¹¥»÷ÊÂÎñ¡£
https://www.businesstoday.in/latest/in-focus/story/cyber-attack-at-aiims-delhi-hackers-demand-rs-200-cr-in-crypto-says-report-354475-2022-11-28


¾©¹«Íø°²±¸11010802024551ºÅ