OpenSSLÏîÄ¿ÐÞ¸´Æä¿ªÔ´ÃÜÂë¿âÖÐÁ½¸öÑÏÖØµÄÎó²î

Ðû²¼Ê±¼ä 2022-11-02
1¡¢OpenSSLÏîÄ¿ÐÞ¸´Æä¿ªÔ´ÃÜÂë¿âÖÐÁ½¸öÑÏÖØµÄÎó²î

      

¾ÝýÌå11ÔÂ1ÈÕ±¨µÀ£¬£¬£¬£¬ £¬OpenSSLÏîÄ¿ÐÞ¸´ÁËÆäÓÃÓÚ¼ÓÃÜͨѶͨµÀºÍHTTPSÅþÁ¬µÄ¿ªÔ´ÃÜÂë¿âÖÐÁ½¸öÑÏÖØµÄÎó²î¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬ £¬CVE-2022-3602ÊÇí§Òâ4×Ö½Ú¿ÍÕ»»º³åÇøÒç³öÎó²î£¬£¬£¬£¬ £¬¿ÉÄÜ´¥·¢±ÀÀ£»£»£»£»£»òµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ(RCE)¡£¡£¡£¡£¡£¡£CVE-2022-3786¿É±»¹¥»÷Õßͨ¹ý¶ñÒâÓʼþµØµãʹÓ㬣¬£¬£¬ £¬Í¨¹ý»º³åÇøÒç³öÀ´´¥·¢¾Ü¾øÐ§ÀÍ״̬¡£¡£¡£¡£¡£¡£ËäÈ»×î³õµÄ¾¯±¨±Þ²ßÖÎÀíÔ±Á¬Ã¦½ÓÄÉÐж¯À´»º½âÎó²î£¬£¬£¬£¬ £¬µ«ÏÖʵӰÏìÒªÓÐÏ޵ö࣬£¬£¬£¬ £¬ÓÉÓÚCVE-2022-3602(×î³õ±»ÆÀ¼¶ÎªCritical)Òѱ»½µ¼¶ÎªHigh£¬£¬£¬£¬ £¬²¢ÇÒËüÖ»Ó°ÏìOpenSSL 3.0¼°¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/openssl-fixes-two-high-severity-vulnerabilities-what-you-need-to-know/


2¡¢SnatchÉù³ÆÒÑÈëÇÖ¾ü¹¤ÆóÒµ¹©Ó¦ÉÌHENSOLDT France

      

ýÌå10ÔÂ31Èճƣ¬£¬£¬£¬ £¬ÀÕË÷ÍÅ»ïSnatch¹¥»÷ÁË·¨¹ú¹«Ë¾HENSOLDT France¡£¡£¡£¡£¡£¡£HENSOLDTÊÇÒ»¼ÒרÃÅ´Óʾüʺ͹ú·Àµç×Ó²úÆ·µÄ¹«Ë¾£¬£¬£¬£¬ £¬Ö÷ҪΪ·¨¹úºÍÍâÑóµÄº½¿Õ¡¢¹ú·À¡¢ÄÜÔ´ºÍÔËÊ䲿·ÖÌṩµç×Ó½â¾ö¼Æ»®¡¢²úÆ·ºÍЧÀÍ¡£¡£¡£¡£¡£¡£SnatchÒѽ«¸Ã¹«Ë¾Ìí¼Óµ½ÆäTorÍøÕ¾ÉÏ£¬£¬£¬£¬ £¬²¢Ðû²¼ÁËÒ»·Ý±»µÁÊý¾ÝµÄÑù±¾(94 MB)×÷Ϊ¹¥»÷»î¶¯µÄÖ¤¾Ý¡£¡£¡£¡£¡£¡£SnatchÓÚ2019Äêµ×Ê״α»·¢Ã÷£¬£¬£¬£¬ £¬Ëü¿É½«±»Ñ¬È¾µÄÅÌËã»úÖØÆôµ½Ç徲ģʽÒÔÈÆ¹ýÇå¾²½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/137886/cyber-crime/snatch-hensoldt-france-ransomware.html


3¡¢ÐÂÎ÷À¼º½¿Õ¹«Ë¾Í¸Â¶Æä²¿·Ö¿Í»§Ô⵽ƾ֤Ìî³ä¹¥»÷

      

¾Ý10ÔÂ30ÈÕ±¨µÀ£¬£¬£¬£¬ £¬ÐÂÎ÷À¼º½¿Õ¹«Ë¾Í¸Â¶ºÚ¿ÍÊÔͼͨ¹ýƾ֤Ìî³ä¹¥»÷À´»á¼ûÆä¿Í»§µÄÕË»§¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ö¸³ö£¬£¬£¬£¬ £¬¹¥»÷ÕßûÓÐÈëÇÖ¹«Ë¾µÄÈκÎϵͳ£¬£¬£¬£¬ £¬½öСÎÒ˽¼ÒµÄÕË»§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£Ö»ÓÐÉÙÊý¿Í»§Ôâµ½Á˹¥»÷£¬£¬£¬£¬ £¬ÇÒ¹¥»÷ÕßûÓлá¼ûÈκÎڲƭÐÔÉúÒâÐÅÏ¢»òÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£ÐÂÎ÷À¼º½¿Õ¹«Ë¾ÏÖÔÚÒÑËø¶¨ÕË»§£¬£¬£¬£¬ £¬²¢Í¨Öª¿Í»§ÔÚÏ´ÎʹÓÃAirpointsϵͳ֮ǰ¸ü¸ÄËûÃǵĵǼÐÅÏ¢¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/137793/cyber-crime/air-new-zealand-breach.html


4¡¢APT 10ʹÓÃɱ¶¾Èí¼þÏòÈÕ±¾µÄ×éÖ¯·Ö·¢LODEINFO 

      

KasperskyÓÚ10ÔÂ31ÈÕÅû¶ÁËAPT 10ʹÓÃÇå¾²Èí¼þ·Ö·¢×Ô½ç˵ºóÃÅLODEINFOµÄ¹¥»÷»î¶¯£¬£¬£¬£¬ £¬Ö÷ÒªÕë¶ÔÈÕ±¾µÄýÌ弯ÍÅ¡¢Íâ½»»ú¹¹¡¢Õþ¸®ºÍ¹«¹²²¿·Ö×éÖ¯ÒÔ¼°Öǿ⡣¡£¡£¡£¡£¡£´Ó½ñÄê3Ô·Ý×îÏÈ£¬£¬£¬£¬ £¬Ñо¿Ö°Ô±×¢Öص½Õë¶ÔAPT10¹¥»÷ʹÓÃÁËеÄѬȾǰÑÔ£¬£¬£¬£¬ £¬°üÀ¨Óã²æÊ½´¹ÂÚÓʼþ¡¢×Ô½âѹ(SFX)RARÎļþÒÔ¼°ÀÄÓÃÇå¾²Èí¼þÖеÄDLL²à¼ÓÔØÎó²î¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬¶ñÒâÈí¼þ¿ª·¢ÕßÔÚ2022ÄêÐû²¼ÁË6¸ö°æ±¾µÄLODEINFO£¬£¬£¬£¬ £¬Ñо¿Ö°Ô±»¹ÆÊÎöÁ˸úóÃÅÔÚÕâÒ»ÄêÖеÄÑݱä¡£¡£¡£¡£¡£¡£


https://securelist.com/apt10-tracking-down-lodeinfo-2022-part-i/107742/


5¡¢½ÌÓýÊÖÒÕ¹«Ë¾CheggÒò3ÄêÄÚµÄ4´ÎÊý¾Ýй¶±»FTCÆðËß

      

ýÌå10ÔÂ31ÈÕ±¨µÀ£¬£¬£¬£¬ £¬½ÌÓýÊÖÒÕ¹«Ë¾Chegg±»FTCÆðËߣ¬£¬£¬£¬ £¬ÒòÆäÔÚ2017ÄêÒÔÀ´µÄ4´ÎÊý¾Ýй¶ÊÂÎñÖÐй¶ÁËÊýÍòÍò¿Í»§ºÍÔ±¹¤µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£CheggÔÚ2017Äê9ÔÂÊ×´ÎÔâµ½ÈëÇÖ£¬£¬£¬£¬ £¬Ô´ÓÚÕë¶Ô¶àÃûÔ±¹¤µÄ´¹ÂÚ¹¥»÷£»£»£»£»£»2018Äê4Ô£¬£¬£¬£¬ £¬Ä³Ç°³Ð°üÉÌʹÓõǼÐÅÏ¢»á¼ûÁ˰üÀ¨Êý°ÙÍòÓû§Êý¾ÝµÄ´æ´¢Í°£»£»£»£»£»Ò»Äêºó£¬£¬£¬£¬ £¬Cheggij¸ß¹ÜµÄƾ֤ÔÚÒ»´Î´¹ÂÚ¹¥»÷Öб»µÁµ¼ÖÂÊý¾Ýй¶£»£»£»£»£»ÓÖ¹ýÁË12¸öÔ£¬£¬£¬£¬ £¬ÁíÒ»ÃûCheggÔ±¹¤Ôâµ½´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£FTCͶË߳ƣ¬£¬£¬£¬ £¬ÕâЩй¶ÊÂÎñ¶¼ÊÇÈô¸É²»Á¼µÄÊý¾ÝÇ徲ʵ¼ùµÄЧ¹û¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/chegg-sued-by-ftc-after-suffering-four-data-breaches-within-3-years/


6¡¢Unit42Ðû²¼¹ØÓÚ¶à¸öÒøÐÐľÂíʹÓõÄÊÖÒյįÊÎö±¨¸æ

      

Unit42ÔÚ10ÔÂ31ÈÕÐû²¼Á˹ØÓÚÒøÐÐľÂíÊÖÒյįÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£ÓÉÓÚ¹¥»÷ÕßһֱʹÓÃеÄÊÖÒÕÀ´Èƹý¼ì²âºÍÖ´Ðй¥»÷£¬£¬£¬£¬ £¬Ñо¿³öÓÚ¾­¼ÃÄ¿µÄµÄ¶ñÒâÈí¼þ¿ÉÒÔ×ÊÖú·ÀÓùÕ߸üÓÐÓõر£»£»£»£»£»¤×éÖ¯¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÆÊÎöÁËÖøÃûµÄÒøÐÐľÂíÓÃÀ´Èƹý¼ì²â¡¢ÇÔÈ¡Ãô¸ÐÊý¾ÝºÍÐÞ¸ÄÊý¾ÝµÄÊÖÒÕ£¬£¬£¬£¬ £¬»¹½«ÐÎòÔõÑù·ÀÓùÕâЩÊÖÒÕ£¬£¬£¬£¬ £¬Éæ¼°Zeus¡¢Kronos¡¢Trickbot¡¢IcedID¡¢EmotetºÍDridex¡£¡£¡£¡£¡£¡£ÒøÐÐľÂíʹÓõÄÊÖÒÕ°üÀ¨Webinject¡¢Named Pipe¡¢Heaven's Gate¡¢AtomBombing¡¢HookingºÍPE InjectionµÈ¡£¡£¡£¡£¡£¡£     


https://unit42.paloaltonetworks.com/banking-trojan-techniques/