OpenSSLÏîÄ¿ÐÞ¸´Æä¿ªÔ´ÃÜÂë¿âÖÐÁ½¸öÑÏÖØµÄÎó²î

Ðû²¼Ê±¼ä 2022-11-02
1¡¢OpenSSLÏîÄ¿ÐÞ¸´Æä¿ªÔ´ÃÜÂë¿âÖÐÁ½¸öÑÏÖØµÄÎó²î

      

¾ÝýÌå11ÔÂ1ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬OpenSSLÏîÄ¿ÐÞ¸´ÁËÆäÓÃÓÚ¼ÓÃÜͨѶͨµÀºÍHTTPSÅþÁ¬µÄ¿ªÔ´ÃÜÂë¿âÖÐÁ½¸öÑÏÖØµÄÎó²î¡£ ¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬CVE-2022-3602ÊÇí§Òâ4×Ö½Ú¿ÍÕ»»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬¿ÉÄÜ´¥·¢Í߽⻣»£» £»£»òµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ(RCE)¡£ ¡£¡£¡£¡£¡£CVE-2022-3786¿É±»¹¥»÷Õßͨ¹ý¶ñÒâÓʼþµØµãʹÓ㬣¬£¬£¬£¬£¬Í¨¹ý»º³åÇøÒç³öÀ´´¥·¢¾Ü¾øÐ§ÀÍ״̬¡£ ¡£¡£¡£¡£¡£ËäÈ»×î³õµÄ¾¯±¨±Þ²ßÖÎÀíÔ±Á¬Ã¦½ÓÄÉÐж¯À´»º½âÎó²î£¬£¬£¬£¬£¬£¬µ«ÏÖʵӰÏìÒªÓÐÏ޵ö࣬£¬£¬£¬£¬£¬ÓÉÓÚCVE-2022-3602(×î³õ±»ÆÀ¼¶ÎªCritical)Òѱ»½µ¼¶ÎªHigh£¬£¬£¬£¬£¬£¬²¢ÇÒËüÖ»Ó°ÏìOpenSSL 3.0¼°¸ü¸ß°æ±¾¡£ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/openssl-fixes-two-high-severity-vulnerabilities-what-you-need-to-know/


2¡¢SnatchÉù³ÆÒÑÈëÇÖ¾ü¹¤ÆóÒµ¹©Ó¦ÉÌHENSOLDT France

      

ýÌå10ÔÂ31Èճƣ¬£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïSnatch¹¥»÷ÁË·¨¹ú¹«Ë¾HENSOLDT France¡£ ¡£¡£¡£¡£¡£HENSOLDTÊÇÒ»¼ÒרÃÅ´Óʾüʺ͹ú·Àµç×Ó²úÆ·µÄ¹«Ë¾£¬£¬£¬£¬£¬£¬Ö÷ҪΪ·¨¹úºÍÍâÑóµÄº½¿Õ¡¢¹ú·À¡¢ÄÜÔ´ºÍÔËÊ䲿·ÖÌṩµç×Ó½â¾ö¼Æ»®¡¢²úÆ·ºÍЧÀÍ¡£ ¡£¡£¡£¡£¡£SnatchÒѽ«¸Ã¹«Ë¾Ìí¼Óµ½ÆäTorÍøÕ¾ÉÏ£¬£¬£¬£¬£¬£¬²¢Ðû²¼ÁËÒ»·Ý±»µÁÊý¾ÝµÄÑù±¾(94 MB)×÷Ϊ¹¥»÷»î¶¯µÄÖ¤¾Ý¡£ ¡£¡£¡£¡£¡£SnatchÓÚ2019Äêµ×Ê״α»·¢Ã÷£¬£¬£¬£¬£¬£¬Ëü¿É½«±»Ñ¬È¾µÄÅÌËã»úÖØÆôµ½Ç徲ģʽÒÔÈÆ¹ýÇå¾²½â¾ö¼Æ»®¡£ ¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/137886/cyber-crime/snatch-hensoldt-france-ransomware.html


3¡¢ÐÂÎ÷À¼º½¿Õ¹«Ë¾Í¸Â¶Æä²¿·Ö¿Í»§Ô⵽ƾ֤Ìî³ä¹¥»÷

      

¾Ý10ÔÂ30ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬ÐÂÎ÷À¼º½¿Õ¹«Ë¾Í¸Â¶ºÚ¿ÍÊÔͼͨ¹ýƾ֤Ìî³ä¹¥»÷À´»á¼ûÆä¿Í»§µÄÕË»§¡£ ¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ö¸³ö£¬£¬£¬£¬£¬£¬¹¥»÷ÕßûÓÐÈëÇÖ¹«Ë¾µÄÈκÎϵͳ£¬£¬£¬£¬£¬£¬½öСÎÒ˽¼ÒµÄÕË»§Êܵ½Ó°Ïì¡£ ¡£¡£¡£¡£¡£Ö»ÓÐÉÙÊý¿Í»§Ôâµ½Á˹¥»÷£¬£¬£¬£¬£¬£¬ÇÒ¹¥»÷ÕßûÓлá¼ûÈκÎڲƭÐÔÉúÒâÐÅÏ¢»òÃô¸ÐÐÅÏ¢¡£ ¡£¡£¡£¡£¡£ÐÂÎ÷À¼º½¿Õ¹«Ë¾ÏÖÔÚÒÑËø¶¨ÕË»§£¬£¬£¬£¬£¬£¬²¢Í¨Öª¿Í»§ÔÚÏ´ÎʹÓÃAirpointsϵͳ֮ǰ¸ü¸ÄËûÃǵĵǼÐÅÏ¢¡£ ¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/137793/cyber-crime/air-new-zealand-breach.html


4¡¢APT 10ʹÓÃɱ¶¾Èí¼þÏòÈÕ±¾µÄ×éÖ¯·Ö·¢LODEINFO 

      

KasperskyÓÚ10ÔÂ31ÈÕÅû¶ÁËAPT 10ʹÓÃÇå¾²Èí¼þ·Ö·¢×Ô½ç˵ºóÃÅLODEINFOµÄ¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÈÕ±¾µÄýÌ弯ÍÅ¡¢Íâ½»»ú¹¹¡¢Õþ¸®ºÍ¹«¹²²¿·Ö×éÖ¯ÒÔ¼°Öǿ⡣ ¡£¡£¡£¡£¡£´Ó½ñÄê3Ô·Ý×îÏÈ£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±×¢Öص½Õë¶ÔAPT10¹¥»÷ʹÓÃÁËеÄѬȾǰÑÔ£¬£¬£¬£¬£¬£¬°üÀ¨Óã²æÊ½´¹ÂÚÓʼþ¡¢×Ô½âѹ(SFX)RARÎļþÒÔ¼°ÀÄÓÃÇå¾²Èí¼þÖеÄDLL²à¼ÓÔØÎó²î¡£ ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ¿ª·¢ÕßÔÚ2022ÄêÐû²¼ÁË6¸ö°æ±¾µÄLODEINFO£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹ÆÊÎöÁ˸úóÃÅÔÚÕâÒ»ÄêÖеÄÑݱä¡£ ¡£¡£¡£¡£¡£


https://securelist.com/apt10-tracking-down-lodeinfo-2022-part-i/107742/


5¡¢½ÌÓýÊÖÒÕ¹«Ë¾CheggÒò3ÄêÄÚµÄ4´ÎÊý¾Ýй¶±»FTCÆðËß

      

ýÌå10ÔÂ31ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬½ÌÓýÊÖÒÕ¹«Ë¾Chegg±»FTCÆðËߣ¬£¬£¬£¬£¬£¬ÒòÆäÔÚ2017ÄêÒÔÀ´µÄ4´ÎÊý¾Ýй¶ÊÂÎñÖÐй¶ÁËÊýÍòÍò¿Í»§ºÍÔ±¹¤µÄÐÅÏ¢¡£ ¡£¡£¡£¡£¡£CheggÔÚ2017Äê9ÔÂÊ×´ÎÔâµ½ÈëÇÖ£¬£¬£¬£¬£¬£¬Ô´ÓÚÕë¶Ô¶àÃûÔ±¹¤µÄ´¹ÂÚ¹¥»÷£»£»£» £»£»2018Äê4Ô£¬£¬£¬£¬£¬£¬Ä³Ç°³Ð°üÉÌʹÓõǼÐÅÏ¢»á¼ûÁ˰üÀ¨Êý°ÙÍòÓû§Êý¾ÝµÄ´æ´¢Í°£»£»£» £»£»Ò»Äêºó£¬£¬£¬£¬£¬£¬Cheggij¸ß¹ÜµÄƾ֤ÔÚÒ»´Î´¹ÂÚ¹¥»÷Öб»µÁµ¼ÖÂÊý¾Ýй¶£»£»£» £»£»ÓÖ¹ýÁË12¸öÔ£¬£¬£¬£¬£¬£¬ÁíÒ»ÃûCheggÔ±¹¤Ôâµ½´¹ÂÚ¹¥»÷¡£ ¡£¡£¡£¡£¡£FTCͶË߳ƣ¬£¬£¬£¬£¬£¬ÕâЩй¶ÊÂÎñ¶¼ÊÇÈô¸É²»Á¼µÄÊý¾ÝÇ徲ʵ¼ùµÄЧ¹û¡£ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/chegg-sued-by-ftc-after-suffering-four-data-breaches-within-3-years/


6¡¢Unit42Ðû²¼¹ØÓÚ¶à¸öÒøÐÐľÂíʹÓõÄÊÖÒյįÊÎö±¨¸æ

      

Unit42ÔÚ10ÔÂ31ÈÕÐû²¼Á˹ØÓÚÒøÐÐľÂíÊÖÒյįÊÎö±¨¸æ¡£ ¡£¡£¡£¡£¡£ÓÉÓÚ¹¥»÷ÕßһֱʹÓÃеÄÊÖÒÕÀ´Èƹý¼ì²âºÍÖ´Ðй¥»÷£¬£¬£¬£¬£¬£¬Ñо¿³öÓÚ¾­¼ÃÄ¿µÄµÄ¶ñÒâÈí¼þ¿ÉÒÔ×ÊÖú·ÀÓùÕ߸üÓÐÓõر£»£»£» £»£»¤×éÖ¯¡£ ¡£¡£¡£¡£¡£¸Ã±¨¸æÆÊÎöÁËÖøÃûµÄÒøÐÐľÂíÓÃÀ´Èƹý¼ì²â¡¢ÇÔÈ¡Ãô¸ÐÊý¾ÝºÍÐÞ¸ÄÊý¾ÝµÄÊÖÒÕ£¬£¬£¬£¬£¬£¬»¹½«ÐÎòÔõÑù·ÀÓùÕâЩÊÖÒÕ£¬£¬£¬£¬£¬£¬Éæ¼°Zeus¡¢Kronos¡¢Trickbot¡¢IcedID¡¢EmotetºÍDridex¡£ ¡£¡£¡£¡£¡£ÒøÐÐľÂíʹÓõÄÊÖÒÕ°üÀ¨Webinject¡¢Named Pipe¡¢Heaven's Gate¡¢AtomBombing¡¢HookingºÍPE InjectionµÈ¡£ ¡£¡£¡£¡£¡£     


https://unit42.paloaltonetworks.com/banking-trojan-techniques/