AppleÐÞ¸´iPhoneºÍMacÖпÉÄÜÒѱ»Æð¾¢Ê¹ÓõÄÎó²î
Ðû²¼Ê±¼ä 2022-09-13
ýÌå9ÔÂ12Èճƣ¬£¬£¬£¬£¬£¬£¬£¬AppleÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÓÃÓÚ¹¥»÷iPhoneºÍMacµÄÎó²î¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î×·×ÙΪCVE-2022-32917£¬£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ý¶ñÒâÖÆ×÷µÄÓ¦ÓóÌÐòÒÔÄÚºËȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£ÕâÊǸù«Ë¾×ÔÄêÍ·ÒÔÀ´ÐÞ¸´µÄµÚ8¸öÁãÈÕÎó²î£¬£¬£¬£¬£¬£¬£¬£¬AppleÔÚÇ徲ͨ¸æÖÐ͸¶¸ÃÎó²î¿ÉÄÜÒѱ»Æð¾¢Ê¹Ó㬣¬£¬£¬£¬£¬£¬£¬µ«ÉÐδÐû²¼ÓйØÕâЩ¹¥»÷µÄÈκÎÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ç¿ÁÒ½¨ÒéÓû§¾¡¿ì¾ÙÐÐÇå¾²¸üÐÂÒÔ×èÖ¹´ËÀ๥»÷¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/apple-fixes-eighth-zero-day-used-to-hack-iphones-and-macs-this-year/
2¡¢BRONZE PRESIDENTÍÅ»ïʹÓÃPlugX¹¥»÷È«ÇòµÄÕþ¸®»ú¹¹
SecureworksÔÚ9ÔÂ8ÈÕÅû¶ÁËAPT×éÖ¯BRONZE PRESIDENTÕë¶ÔÅ·ÖÞ¡¢Öж«ºÍÄÏÃÀµÈµØÕþ¸®»ú¹¹µÄPlugX¶ñÒâÈí¼þ»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ2022Äê6ÔºÍ7Ô·¢Ã÷¸Ã»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬Ñ¬È¾Á´Ê¼ÓÚÒ»¸ö°üÀ¨¶ñÒâÈí¼þµÄRAR´æµµ£¬£¬£¬£¬£¬£¬£¬£¬·¿ª´æµµºó»áÏÔʾһ¸öαװ³ÉÎĵµµÄLNKÎļþ£¬£¬£¬£¬£¬£¬£¬£¬µã»÷¸ÃÎļþºó½«Ö´ÐжñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹·Ö·¢Á˶ñÒâDLLºÍ¼ÓÃܵÄpayload£¬£¬£¬£¬£¬£¬£¬£¬Õýµ±µÄ¶þ½øÖÆÎļþÈÝÒ×Ôâµ½DLLËÑË÷˳ÐòÐ®ÖÆ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
https://www.secureworks.com/blog/bronze-president-targets-government-officials
3¡¢Cofense·¢Ã÷ͨ¹ýWeTransferЧÀÍ·Ö·¢LampionµÄ»î¶¯
¾Ý9ÔÂ9ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬Cofense¼ì²âµ½ÐÂÒ»Âֻ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀÄÓÃWeTransferЧÀÍ´ó¹æÄ£·Ö·¢¶ñÒâÈí¼þLampion¡£¡£¡£¡£¡£¡£¡£¡£WeTransferÊÇÒ»ÖÖÕýµ±Îļþ¹²ÏíЧÀÍ£¬£¬£¬£¬£¬£¬£¬£¬±»ÓÃÀ´ÈƹýÇå¾²Èí¼þ¶Ôµç×ÓÓʼþÖÐʹÓõÄURLµÄ¾¯±¨¡£¡£¡£¡£¡£¡£¡£¡£LampionÔËÓªÍÅ»ï´Ó±»Ñ¬È¾µÄ¹«Ë¾ÕÊ»§·¢ËÍ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬£¬£¬ÒªÇóÓû§´ÓWeTransferÏÂÔØ¡°¸¶¿î֤ʵ¡±Îļþ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿µÄ»áÊÕµ½Ò»¸öZIP´æµµ£¬£¬£¬£¬£¬£¬£¬£¬²¢×îÖÕÖ´ÐÐLampion¡£¡£¡£¡£¡£¡£¡£¡£Lampionͨ¹ý´ÓC2ÖлñȡעÈëµÄÊý¾Ý²¢ÔÚµÇÂ¼Ò³ÃæÉÏÁýÕÖαÔìµÄ±íµ¥À´Ëø¶¨ÒøÐÐÕË»§¡£¡£¡£¡£¡£¡£¡£¡£µ±Óû§ÊäÈëÆ¾Ö¤Ê±£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩÊý¾Ý½«±»ÇÔÈ¡²¢·¢Ë͸ø¹¥»÷Õß¡£¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/lampion-malware-returns-in-phishing-attacks-abusing-wetransfer/
4¡¢WordfenceÅû¶WP²å¼þBackupBuddyÖÐÒѱ»Ê¹ÓÃÎó²îµÄϸ½Ú
WordfenceÓÚ9ÔÂ7ÈÕ͸¶£¬£¬£¬£¬£¬£¬£¬£¬WordPress²å¼þBackupBuddyÖеÄÎó²îÕýÔÚ±»Æð¾¢Ê¹Óᣡ£¡£¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2022-31474£©Ô¼ÓÐ140000´Î×°Ö㬣¬£¬£¬£¬£¬£¬£¬¿É±»Î´¾Éí·ÝÑéÖ¤µÄÓû§ÓÃÀ´´ÓÄ¿µÄÍøÕ¾ÏÂÔØí§ÒâÎļþ£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨/etc/passwdµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Îó²îÓ°Ïì°æ±¾8.5.8.0ÖÁ8.7.4.1£¬£¬£¬£¬£¬£¬£¬£¬ÒÑÔÚ9ÔÂ2ÈÕÐû²¼µÄ°æ±¾8.7.5ÖÐÐÞ¸´¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ²éÔÄÀúÊ·Êý¾Ýºó£¬£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±È·¶¨¹¥»÷×îÏÈ×Ô2022Äê8ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬×ÔÄÇʱÆð¸Ã¹«Ë¾ÒÑ×èÖ¹Á˽ü500Íò´ÎÕë¶Ô¸ÃÎó²îµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
https://www.wordfence.com/blog/2022/09/psa-nearly-5-million-attacks-blocked-targeting-0-day-in-backupbuddy-plugin/
5¡¢Ó¢¹úPVCÖÆÔìÉÌEurocellÔâµ½¹¥»÷ºóÔ±¹¤µÄÐÅϢй¶
¾ÝýÌå9ÔÂ12ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬Ó¢¹úPVCÖÆÔìÉÌEurocell֪ͨÆäÏÖÔ±¹¤ºÍǰԱ¹¤¹ØÓÚËûÃǵÄСÎÒ˽¼ÒÐÅϢй¶µÄÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ú¹Êͳƣ¬£¬£¬£¬£¬£¬£¬£¬Î´¾ÊÚȨµÄµÚÈý·½»á¼ûÁËÆäϵͳ£¬£¬£¬£¬£¬£¬£¬£¬±»Ð¹Â¶µÄÊý¾Ý°üÀ¨£º¹ÍÓ¶Ìõ¿îºÍÌõ¼þ¡¢³öÉúÈÕÆÚ¡¢Ö§Êô¡¢ÒøÐÐÕË»§¡¢NIºÍ˰Îñ²Î¿¼ºÅ¡¢¿µ½¡ºÍ¸£ÀûÎļþµÈ¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÐÅÏ¢ºóÐø¿ÉÄܱ»´¹ÂÚ¹¥»÷»òÕßÀÕË÷ÀÕË÷ʹÓ㬣¬£¬£¬£¬£¬£¬£¬EurocellÌåÏÖÏÖÔÚÉÐÎÞÖ¤¾ÝÅú×¢Êý¾Ý±»ÀÄÓᣡ£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÏÖÓÐÁè¼Ý2000¸öÔ±¹¤£¬£¬£¬£¬£¬£¬£¬£¬µ«¼øÓÚй¶ÐÅÏ¢µÄÀàÐÍ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜÉÐÓиü¶àµÄǰԱ¹¤ÃæÁÙΣº¦¡£¡£¡£¡£¡£¡£¡£¡£
https://www.infosecurity-magazine.com/news/hackers-employee-data-pvcmaker/
6¡¢KasperskyÐû²¼2022ÄêH1¹¤Òµ×Ô¶¯»¯ÏµÍ³ÍþÐ²Ì¬ÊÆµÄÆÊÎö
9ÔÂ8ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬KasperskyÐû²¼ÁË2022ÄêÉϰëÄ깤ҵ×Ô¶¯»¯ÏµÍ³ÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬£¬×éÖ¯µÄÔËÓªÊÖÒÕ»ù´¡ÉèÊ©ÖÐÅÌËã»úÃæÁÙµÄÖ÷ÒªÍþвȪԴÊÇ»¥ÁªÍø16.5%£©¡¢¿ÉÒÆ¶¯Ã½Ì壨3.5%£©ºÍµç×ÓÓʼþ£¨7.0%£©¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÂ¥Óî×Ô¶¯»¯ÐÐÒµ£¬£¬£¬£¬£¬£¬£¬£¬×èÖ¹µÄ¶ñÒ⸽¼þºÍ´¹ÂÚÁ´½ÓµÄICSµÄÕ¼±È(14.4%)ÊÇÈ«Çòƽ¾ùÖµ(7%)µÄÁ½±¶¡£¡£¡£¡£¡£¡£¡£¡£2022ÄêÉϰëÄ꣬£¬£¬£¬£¬£¬£¬£¬ICS×èÖ¹ÁËÀ´×Ô7219¸öϵÁеĶñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÀÕË÷Èí¼þ¡¢¶ñÒâÎļþ¡¢ÓÃÓÚÒþ²Ø¼ÓÃÜÇ®±ÒÍÚ¾òµÄ¶ñÒâÈí¼þºÍÌØ¹¤Èí¼þµÈ¡£¡£¡£¡£¡£¡£¡£¡£
https://securelist.com/threat-landscape-for-industrial-automation-systems-for-h1-2022/107373/


¾©¹«Íø°²±¸11010802024551ºÅ