Verizon͸¶²¿ÃÅÓû§µÄÐÅϢй¶²¢Ôâµ½SIM¿¨½»»»¹¥»÷

Ðû²¼Ê±¼ä 2022-10-20
1¡¢Verizon͸¶²¿ÃÅÓû§µÄÐÅϢй¶²¢Ôâµ½SIM¿¨½»»»¹¥»÷

      

¾Ý10ÔÂ18ÈÕ±¨µÀ£¬Verizon²¿ÃÅÔ¤¸¶·Ñ¿Í»§µÄÐÅϢй¶ ¡£Verizon³Æ£¬ÔÚ2022Äê10ÔÂ6ÈÕÖÁ10ÔÂ10ÈÕÆÚ¼ä£¬Î´¾­ÊÚȨµÄµÚÈý·½·ÃÎÊÁËÓû§ÓÃÓÚ×Ô¶¯¸¶¿îµÄÐÅÓÿ¨µÄ×îºóËÄλÊý×Ö£¬²¢ÔÚSIM¿¨½»»»¹¥»÷ÖÐʹÓÃÁËй¶µÄÐÅÓÿ¨ÐÅÏ¢ ¡£VerizonÌåÏÖ£¬ËûÃÇ×î½ü·¢ÏÖÁËÉæ¼°Ô¼250¸öÔ¤¸¶·ÑÎÞÏßÕË»§µÄδ¾­ÊÚȨµÄ»î¶¯£¬¸Ã¹«Ë¾ÒѾ­½ÓÄÉÁËÌØ±ðµÄ´ëÊ©£¬ÒÔ±£»¤Æä¿Í»§ÃâÊÜδ¾­ÊÚȨµÄ·ÃÎÊ»òÆÛÕ©¹¥»÷ ¡£


https://www.bleepingcomputer.com/news/security/verizon-notifies-prepaid-customers-their-accounts-were-breached/


2¡¢OracleÐû²¼2022Äê10Ô·ÝÄþ¾²¸üÐÂÐÞ¸´366¸ö©¶´     

      

OracleÔÚ10ÔÂ18ÈÕÐû²¼ÁË2022Äê10Ô·ݵÄÖØÒª¸üУ¬ÐÞ¸´Á˶à¸ö²úÎïÖеÄ366¸ö©¶´ ¡£´Ë´ÎÐÞ¸´µÄ½ÏΪÑÏÖØµÄ©¶´°üÂÞOracleÄþ¾²±¸·Ý(Apache HTTP·þÎñÆ÷)ÖеÄ©¶´CVE-2022-31813¡¢OracleÉÌÎñƽ̨DynamoÓ¦Ó÷¨Ê½¿ò¼Ü(dom4j)ÖеÄ©¶´CVE-2020-10683ºÍOracleͨÐÅÔÆÔ­ÉúºËÐÄÄþ¾²±ßÔµ±£»¤ÊðÀíÖеÄ©¶´CVE-2022-1292 ¡£ÆäÖв¿ÃÅ©¶´¿É±»Ô¶³Ì¹¥»÷ÕßÓÃÀ´¿ØÖÆÊÜÓ°ÏìµÄϵͳ£¬Ñо¿ÈËÔ±½¨ÒéÓû§Á¢¼´¼ì²ì¸üв¢Ó¦ÓÃÐëÒªµÄ»º½â´ëÊ© ¡£


https://www.oracle.com/security-alerts/cpuoct2022.html


3¡¢ÃÀ¹úKeystone HealthÊý¾Ýй¶Ê¼þÓ°ÏìÔ¼23Íò»¼Õß

      

ýÌå10ÔÂ18Èճƣ¬±öϦ·¨ÄáÑÇÖÝÒ½ÁƱ£½¡ÌṩÉÌKeystone HealthµÄÊý¾Ýй¶Ê¼þÓ°Ïì235237¸ö»¼Õß ¡£KeystoneÔÚ8ÔÂ19ÈÕ·¢ÏÖÒ»ÆðÍøÂçÄþ¾²Ê¼þµ¼ÖÂÆäijЩϵͳÖÐ¶Ï ¡£¾­ÊӲ췢ÏÖ£¬Î´¾­ÊÚȨµÄµÚÈý·½ÔÚ2022Äê7ÔÂ28ÈÕÖÁ8ÔÂ19ÈÕÆÚ¼ä·ÃÎÊÁËÆäϵͳÄÚµÄÎļþ£¬°üÂÞ»¼ÕßÐÕÃû¡¢Éç»áÄþ¾²ºÅÂëºÍÁÙ´²ÐÅÏ¢µÈ ¡£¸Ã»ú¹¹ÌåÏÖ£¬ËüÒѾ­Í¨ÖªÊÜÓ°Ï컼Õߣ¬²¢½«ÎªËûÃÇÌṩÐÅÓüà²â·þÎñ ¡£


https://www.securityweek.com/keystone-health-data-breach-impacts-235000-patients


4¡¢KasperskyÅû¶DiceyFÕë¶Ô¶«ÄÏÑÇÔÚÏ߶ij¡µÄ¹¥»÷»î¶¯

      

10ÔÂ17ÈÕ£¬KasperskyÅû¶ÁËDiceyFÕë¶Ô¶«ÄÏÑÇÔÚÏ߶ij¡µÄ¹¥»÷»î¶¯ ¡£¸Ã»î¶¯ÖÁÉÙ×Ô2021Äê11ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬ÆäËÆºõ²»ÊdzöÓÚ¾­¼ÃÄ¿µÄ£¬¶øÊǽøÐÐÒþ±ÎµÄ¼äµý»î¶¯ºÍ֪ʶ²úȨÇÔÈ¡ ¡£¸ÃAPTÍÅ»ïʹÓõĹ¥»÷¿ò¼ÜÃûΪGamePlayerFramework£¬ÕâÊǶÔC++¶ñÒâÈí¼þPuppetLoaderµÄC#ÖØÐ´ ¡£DiceyF»¹Ê¹ÓÃÒ»¸öÄ£·ÂMango Employee Data SynchronizerµÄGUIÓ¦Ó㬸ÃÓ¦Óý«YunaÏÂÔØ·¨Ê½°²×°µ½Ä¿±êµÄÍøÂçÖÐ ¡£


https://securelist.com/diceyf-deploys-gameplayerframework-in-online-casino-development-studio/107723/


5¡¢SafeBreach³Æ¼ì²âµ½Ò»ÖÖеÄFUD powershellºóÃÅ

      

SafeBreachÔÚ10ÔÂ18ÈÕ³ÆÆä½üÆÚ¼ì²âµ½Ò»ÖÖеÄÍêÈ«²»Ðмì²â(FUD)powershellºóÃÅ ¡£¹¥»÷ʼÓÚ´øÓжñÒâÎĵµApply Form.docmµÄµç×ÓÓʼþ ¡£¸Ã¶ñÒâÎĵµÓÚ2022Äê8ÔÂ25ÈÕ´ÓÔ¼µ©ÉÏ´«£¬¿É°²×°²¢Ö´ÐÐupdater.vbs½Å±¾£¬À´´´½¨Ò»¸ö¼Æ»®ÈÎÎñð³äͨÀýµÄWindows¸üР¡£VBS½Å±¾Ö´ÐÐÁ½¸öPowerShell½Å±¾Script.ps1ºÍTemp.ps1£¬ËüÃÇÔÚVirusTotalÉϾùδ±»¼ì²âΪ¶ñÒâ½Å±¾ ¡£Script.ps1»áÁ¬½Óµ½¹¥»÷ÕßC2£¬Temp.ps1½âÂëÏìÓ¦ÖеÄÃüÁî ¡£


https://www.safebreach.com/resources/blog/safebreach-labs-researchers-uncover-new-fully-undetectable-powershell-backdoor/


6¡¢ZoomÐÞ¸´ÊÊÓÃÓÚmacOSµÄ²úÎïÖеÄ©¶´CVE-2022-28762

      

¾Ý10ÔÂ18ÈÕ±¨µÀ£¬ZoomÐÞ¸´ÁËÊÊÓÃÓÚmacOSµÄZoom Client for MeetingsÖеÄ©¶´£¨CVE-2022-28762£© ¡£¸Ã©¶´µÄCVSSÆÀ·ÖΪ7.3£¬µ±Í¨¹ýÔËÐÐÌØ¶¨µÄZoomÓ¦ÓÃÆôÓÃÏà»úģʽÅä¾°×÷ΪZoomÓ¦ÓòãAPIµÄÒ»²¿ÃÅʱ£¬¿Í»§¶Ë»á´ò¿ªÒ»¸öµ±µØµ÷ÊÔ¶Ë¿Ú ¡£µ±µØ¶ñÒâÓû§¿ÉÒÔÀûÓõ÷ÊÔ¶Ë¿ÚÁ¬½Ó²¢¿ØÖÆÔÚZoom¿Í»§¶ËÖÐÔËÐеÄÓ¦Óà ¡£´ËÍ⣬¸Ã¹«Ë¾»¹ÐÞ¸´ÁËÁíÒ»¸ö©¶´CVE-2022-28761£¬ËüÓ°ÏìÁËZoom On-Premise Meeting Connector¶àýÌå·ÓÉÆ÷(MMR) ¡£ 


https://securityaffairs.co/wordpress/137266/security/zoom-macos-cve-2022-28762.html