OpenSSLÏîÄ¿ÐÞ¸´Æä¿ªÔ´ÃÜÂë¿âÖÐÁ½¸öÑÏÖØµÄÎó²î

Ðû²¼Ê±¼ä 2022-11-02
1¡¢OpenSSLÏîÄ¿ÐÞ¸´Æä¿ªÔ´ÃÜÂë¿âÖÐÁ½¸öÑÏÖØµÄÎó²î

      

¾ÝýÌå11ÔÂ1ÈÕ±¨µÀ£¬£¬ £¬£¬£¬£¬£¬OpenSSLÏîÄ¿ÐÞ¸´ÁËÆäÓÃÓÚ¼ÓÃÜͨѶͨµÀºÍHTTPSÅþÁ¬µÄ¿ªÔ´ÃÜÂë¿âÖÐÁ½¸öÑÏÖØµÄÎó²î¡£¡£¡£¡£¡£ÆäÖУ¬£¬ £¬£¬£¬£¬£¬CVE-2022-3602ÊÇí§Òâ4×Ö½Ú¿ÍÕ»»º³åÇøÒç³öÎó²î£¬£¬ £¬£¬£¬£¬£¬¿ÉÄÜ´¥·¢±ÀÀ£»£»£»£»£»£»£»£»òµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ(RCE)¡£¡£¡£¡£¡£CVE-2022-3786¿É±»¹¥»÷Õßͨ¹ý¶ñÒâÓʼþµØµãʹÓ㬣¬ £¬£¬£¬£¬£¬Í¨¹ý»º³åÇøÒç³öÀ´´¥·¢¾Ü¾øÐ§ÀÍ״̬¡£¡£¡£¡£¡£ËäÈ»×î³õµÄ¾¯±¨±Þ²ßÖÎÀíÔ±Á¬Ã¦½ÓÄÉÐж¯À´»º½âÎó²î£¬£¬ £¬£¬£¬£¬£¬µ«ÏÖʵӰÏìÒªÓÐÏ޵ö࣬£¬ £¬£¬£¬£¬£¬ÓÉÓÚCVE-2022-3602(×î³õ±»ÆÀ¼¶ÎªCritical)Òѱ»½µ¼¶ÎªHigh£¬£¬ £¬£¬£¬£¬£¬²¢ÇÒËüÖ»Ó°ÏìOpenSSL 3.0¼°¸ü¸ß°æ±¾¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/openssl-fixes-two-high-severity-vulnerabilities-what-you-need-to-know/


2¡¢SnatchÉù³ÆÒÑÈëÇÖ¾ü¹¤ÆóÒµ¹©Ó¦ÉÌHENSOLDT France

      

ýÌå10ÔÂ31Èճƣ¬£¬ £¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïSnatch¹¥»÷ÁË·¨¹ú¹«Ë¾HENSOLDT France¡£¡£¡£¡£¡£HENSOLDTÊÇÒ»¼ÒרÃÅ´Óʾüʺ͹ú·Àµç×Ó²úÆ·µÄ¹«Ë¾£¬£¬ £¬£¬£¬£¬£¬Ö÷ҪΪ·¨¹úºÍÍâÑóµÄº½¿Õ¡¢¹ú·À¡¢ÄÜÔ´ºÍÔËÊ䲿·ÖÌṩµç×Ó½â¾ö¼Æ»®¡¢²úÆ·ºÍЧÀÍ¡£¡£¡£¡£¡£SnatchÒѽ«¸Ã¹«Ë¾Ìí¼Óµ½ÆäTorÍøÕ¾ÉÏ£¬£¬ £¬£¬£¬£¬£¬²¢Ðû²¼ÁËÒ»·Ý±»µÁÊý¾ÝµÄÑù±¾(94 MB)×÷Ϊ¹¥»÷»î¶¯µÄÖ¤¾Ý¡£¡£¡£¡£¡£SnatchÓÚ2019Äêµ×Ê״α»·¢Ã÷£¬£¬ £¬£¬£¬£¬£¬Ëü¿É½«±»Ñ¬È¾µÄÅÌËã»úÖØÆôµ½Ç徲ģʽÒÔÈÆ¹ýÇå¾²½â¾ö¼Æ»®¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/137886/cyber-crime/snatch-hensoldt-france-ransomware.html


3¡¢ÐÂÎ÷À¼º½¿Õ¹«Ë¾Í¸Â¶Æä²¿·Ö¿Í»§Ô⵽ƾ֤Ìî³ä¹¥»÷

      

¾Ý10ÔÂ30ÈÕ±¨µÀ£¬£¬ £¬£¬£¬£¬£¬ÐÂÎ÷À¼º½¿Õ¹«Ë¾Í¸Â¶ºÚ¿ÍÊÔͼͨ¹ýƾ֤Ìî³ä¹¥»÷À´»á¼ûÆä¿Í»§µÄÕË»§¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ö¸³ö£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßûÓÐÈëÇÖ¹«Ë¾µÄÈκÎϵͳ£¬£¬ £¬£¬£¬£¬£¬½öСÎÒ˽¼ÒµÄÕË»§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£Ö»ÓÐÉÙÊý¿Í»§Ôâµ½Á˹¥»÷£¬£¬ £¬£¬£¬£¬£¬ÇÒ¹¥»÷ÕßûÓлá¼ûÈκÎڲƭÐÔÉúÒâÐÅÏ¢»òÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£ÐÂÎ÷À¼º½¿Õ¹«Ë¾ÏÖÔÚÒÑËø¶¨ÕË»§£¬£¬ £¬£¬£¬£¬£¬²¢Í¨Öª¿Í»§ÔÚÏ´ÎʹÓÃAirpointsϵͳ֮ǰ¸ü¸ÄËûÃǵĵǼÐÅÏ¢¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/137793/cyber-crime/air-new-zealand-breach.html


4¡¢APT 10ʹÓÃɱ¶¾Èí¼þÏòÈÕ±¾µÄ×éÖ¯·Ö·¢LODEINFO 

      

KasperskyÓÚ10ÔÂ31ÈÕÅû¶ÁËAPT 10ʹÓÃÇå¾²Èí¼þ·Ö·¢×Ô½ç˵ºóÃÅLODEINFOµÄ¹¥»÷»î¶¯£¬£¬ £¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÈÕ±¾µÄýÌ弯ÍÅ¡¢Íâ½»»ú¹¹¡¢Õþ¸®ºÍ¹«¹²²¿·Ö×éÖ¯ÒÔ¼°Öǿ⡣¡£¡£¡£¡£´Ó½ñÄê3Ô·Ý×îÏÈ£¬£¬ £¬£¬£¬£¬£¬Ñо¿Ö°Ô±×¢Öص½Õë¶ÔAPT10¹¥»÷ʹÓÃÁËеÄѬȾǰÑÔ£¬£¬ £¬£¬£¬£¬£¬°üÀ¨Óã²æÊ½´¹ÂÚÓʼþ¡¢×Ô½âѹ(SFX)RARÎļþÒÔ¼°ÀÄÓÃÇå¾²Èí¼þÖеÄDLL²à¼ÓÔØÎó²î¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬£¬¶ñÒâÈí¼þ¿ª·¢ÕßÔÚ2022ÄêÐû²¼ÁË6¸ö°æ±¾µÄLODEINFO£¬£¬ £¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹ÆÊÎöÁ˸úóÃÅÔÚÕâÒ»ÄêÖеÄÑݱ䡣¡£¡£¡£¡£


https://securelist.com/apt10-tracking-down-lodeinfo-2022-part-i/107742/


5¡¢½ÌÓýÊÖÒÕ¹«Ë¾CheggÒò3ÄêÄÚµÄ4´ÎÊý¾Ýй¶±»FTCÆðËß

      

ýÌå10ÔÂ31ÈÕ±¨µÀ£¬£¬ £¬£¬£¬£¬£¬½ÌÓýÊÖÒÕ¹«Ë¾Chegg±»FTCÆðËߣ¬£¬ £¬£¬£¬£¬£¬ÒòÆäÔÚ2017ÄêÒÔÀ´µÄ4´ÎÊý¾Ýй¶ÊÂÎñÖÐй¶ÁËÊýÍòÍò¿Í»§ºÍÔ±¹¤µÄÐÅÏ¢¡£¡£¡£¡£¡£CheggÔÚ2017Äê9ÔÂÊ×´ÎÔâµ½ÈëÇÖ£¬£¬ £¬£¬£¬£¬£¬Ô´ÓÚÕë¶Ô¶àÃûÔ±¹¤µÄ´¹ÂÚ¹¥»÷£»£»£»£»£»£»£»£»2018Äê4Ô£¬£¬ £¬£¬£¬£¬£¬Ä³Ç°³Ð°üÉÌʹÓõǼÐÅÏ¢»á¼ûÁ˰üÀ¨Êý°ÙÍòÓû§Êý¾ÝµÄ´æ´¢Í°£»£»£»£»£»£»£»£»Ò»Äêºó£¬£¬ £¬£¬£¬£¬£¬Cheggij¸ß¹ÜµÄƾ֤ÔÚÒ»´Î´¹ÂÚ¹¥»÷Öб»µÁµ¼ÖÂÊý¾Ýй¶£»£»£»£»£»£»£»£»ÓÖ¹ýÁË12¸öÔ£¬£¬ £¬£¬£¬£¬£¬ÁíÒ»ÃûCheggÔ±¹¤Ôâµ½´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£FTCͶË߳ƣ¬£¬ £¬£¬£¬£¬£¬ÕâЩй¶ÊÂÎñ¶¼ÊÇÈô¸É²»Á¼µÄÊý¾ÝÇ徲ʵ¼ùµÄЧ¹û¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/chegg-sued-by-ftc-after-suffering-four-data-breaches-within-3-years/


6¡¢Unit42Ðû²¼¹ØÓÚ¶à¸öÒøÐÐľÂíʹÓõÄÊÖÒյįÊÎö±¨¸æ

      

Unit42ÔÚ10ÔÂ31ÈÕÐû²¼Á˹ØÓÚÒøÐÐľÂíÊÖÒյįÊÎö±¨¸æ¡£¡£¡£¡£¡£ÓÉÓÚ¹¥»÷ÕßһֱʹÓÃеÄÊÖÒÕÀ´Èƹý¼ì²âºÍÖ´Ðй¥»÷£¬£¬ £¬£¬£¬£¬£¬Ñо¿³öÓÚ¾­¼ÃÄ¿µÄµÄ¶ñÒâÈí¼þ¿ÉÒÔ×ÊÖú·ÀÓùÕ߸üÓÐÓõر£»£»£»£»£»£»£»£»¤×éÖ¯¡£¡£¡£¡£¡£¸Ã±¨¸æÆÊÎöÁËÖøÃûµÄÒøÐÐľÂíÓÃÀ´Èƹý¼ì²â¡¢ÇÔÈ¡Ãô¸ÐÊý¾ÝºÍÐÞ¸ÄÊý¾ÝµÄÊÖÒÕ£¬£¬ £¬£¬£¬£¬£¬»¹½«ÐÎòÔõÑù·ÀÓùÕâЩÊÖÒÕ£¬£¬ £¬£¬£¬£¬£¬Éæ¼°Zeus¡¢Kronos¡¢Trickbot¡¢IcedID¡¢EmotetºÍDridex¡£¡£¡£¡£¡£ÒøÐÐľÂíʹÓõÄÊÖÒÕ°üÀ¨Webinject¡¢Named Pipe¡¢Heaven's Gate¡¢AtomBombing¡¢HookingºÍPE InjectionµÈ¡£¡£¡£¡£¡£     


https://unit42.paloaltonetworks.com/banking-trojan-techniques/