OpenSSL¼´½«ÐÞ¸´¼ÌHeartbleedÒÔÀ´ÓÖÒ»ÑÏÖØÂ©¶´

Ðû²¼Ê±¼ä 2022-10-28
1¡¢OpenSSL¼´½«ÐÞ¸´¼ÌHeartbleedÒÔÀ´ÓÖÒ»ÑÏÖØÂ©¶´

      

¾Ý10ÔÂ26ÈÕ±¨µÀ£¬OpenSSLÏîÄ¿Ðû²¼½«Ðû²¼¸üÐÂÒÔÐÞ¸´¿ªÔ´¹¤¾ß°üÖеÄÒ»¸öÒªº¦Â©¶´¡£Ñо¿ÈËÔ±Ö¸³ö£¬ÕâÊÇ×Ô2016Äê9ÔÂÒÔÀ´ÔÚ¹¤¾ß°üÖÐÐÞ¸´µÄµÚÒ»¸öÒªº¦Â©¶´¡£Í¨¸æ±íÃ÷£¬OpenSSL 3.0.7ÊÇÒ»¸öÄþ¾²ÐÞ¸´°æ±¾£¬½«ÓÚ2022Äê11ÔÂ1ÈÕ13:00-17:00 UTCÐû²¼¡£¸ÃÑÏÖØÂ©¶´½öÓ°Ïì3.0¼°¸ü¸ß°æ±¾£¬ÊǼÌ2014ÄêHeartbleed©¶´(CVE-2014-0160)Ö®ºó£¬OpenSSLÐÞ¸´µÄµÚ¶þ¸öÑÏÖØµÄ©¶´¡£OpenSSL»¹Ðû²¼Á˼´½«ÔÚͬһÌìÐû²¼µÄbugÐÞ¸´°æ±¾1.1.1¡£


https://securityaffairs.co/wordpress/137689/security/openssl-second-critical-flaw-ever.html


2¡¢Î¢Èí³ÆÊ¹ÓÃServer ManagerÖØÖôÅÅ̿ɵ¼ÖÂÊý¾Ý¶ªÊ§

      

10ÔÂ26ÈÕ±¨µÀ£¬Î¢Èí³ÆÊ¹ÓÃServer Manager¹ÜÀí¿ØÖÆÌ¨ÖØÖÃÐéÄâ´ÅÅÌʱ£¬¿ÉÄܻᵼÖÂÊý¾Ý¶ªÊ§¡£ÓÉÓÚ´ËÎÊÌ⣬ʵÑéÖØÖûòÇå³ýÐéÄâ´ÅÅ̵ĹÜÀíÔ±¿ÉÄÜ»áÒâÍâµØÖØÖÃÆäËüµÄ´ÅÅÌ¡£ËûÃÇ»¹½«ÔÚÈÎÎñ½ø¶È¶Ô»°¿ò´°¿ÚÖп´µ½¡°ÖØÖôÅÅÌʧ°Ü¡±µÄ´íÎó£¬ÒÔ¼°¡°ÕÒµ½¶à¸ö¾ßÓÐÏàͬIDµÄ´ÅÅÌ£¬Çë¸üÐÂÄúµÄ´æ´¢Çý¶¯·¨Ê½£¬È»ºóÖØÊÔ¡£¡±Îª´Ë£¬Î¢ÈíÌṩÁËÒ»ÖÖ½â¾öÒªÁ죬ʹÓÃPowerShellÃüÁîÔÚ¿ÉÓõĴ洢¹ÜÀíÌṩ·¨Ê½ÖмìË÷´ÅÅ̵ÄDeviceID£¬²¢Í¨¹ýɾ³ýËùÓзÖÇøÐÅÏ¢²¢È¡Ïû³õʼ»¯À´Çå³ý´ÅÅÌ£¬À´Çå³ý²Á³ý´ÅÅÌÉϵÄËùÓÐÊý¾Ý¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-server-manager-disk-resets-can-lead-to-data-loss/


3¡¢Ã½Ì幫˾ÌÀɭ·͸Êý¾Ý¿âÅäÖôíÎóй¶Áè¼Ý3TBµÄÊý¾Ý

      

ýÌå10ÔÂ27Èճƣ¬¿ç¹úýÌ幫˾Thomson Reuters£¨ÌÀɭ·͸£©Ð¹Â¶ÁËÖÁÉÙ3 TBµÄÃô¸ÐÊý¾Ý¡£¸ÃElasticSearchµÄË÷ÒýÃüÃû±íÃ÷Ëü±»ÓÃ×÷ÈÕÖ¾·þÎñÆ÷£¬ÒÔÊÕ¼¯Í¨¹ýÓû§-¿Í»§¶Ë½»»¥»ñµÃµÄ´óÁ¿Êý¾Ý¡£Êý¾ÝÑù±¾µÄʱ¼ä´Á±íÃ÷ÕâЩÊý¾ÝÊÇ×î½ü¼Ç¼µÄ£¬ÆäÖÐһЩÊý¾ÝÊÇ10ÔÂ26ÈÕµÄ×îÐÂÊý¾Ý¡£¸ÃÊý¾Ý¿â°üÂÞÒÔ´¿Îı¾¸ñʽÉú´æµÄµÚÈý·½·þÎñÆ÷µÄ·ÃÎÊÆ¾Ö¤¡¢µÇ¼ºÍÃÜÂëÖØÖÃÈÕÖ¾¡¢SQLÈÕÖ¾£¬ÒÔ¼°Ïà¹Ø¹«Ë¾ºÍÖ´·¨ÎļþµÈ¡£Ä¿Ç°£¬¸Ã¹«Ë¾Òѹرտª·ÅµÄÊý¾Ý¿â¡£


https://securityaffairs.co/wordpress/137718/data-breach/thomson-reuters-database-exposed.html


4¡¢KimsukyÍÅ»ïÀûÓÃ3¸öAndroid¶ñÒâÈí¼þ¹¥»÷º«¹úµÄ×éÖ¯

      

Äþ¾²¹«Ë¾S2WÓÚ10ÔÂ24ÈÕÅû¶ÁËKimsukyÀûÓÃ3¸öAndroid¶ñÒâÈí¼þÕë¶Ôº«¹ú×éÖ¯µÄ¹¥»÷»î¶¯¡£S2W͸¶ËüÃÇÔÚ¸ú×ÙKimsuky×éÖ¯µÄ¹ý³ÌÖз¢ÏÖÁË3ÖÖеĶñÒâÈí¼þ£ºKimsukyĿǰÕýÔÚ¿ª·¢µÄ¶ñÒâAPK FastFire£¬Ëüαװ³É¹È¸èÄþ¾²²å¼þ£»FastViewer£¬Î±×°³É¿ÉÒÔ¶ÁÈ¡º«ÎÄÎļþ(.hwp)µÄÒÆ¶¯¼ì²ì·¨Ê½Hancom Viewer£»»ùÓÚAndroidÉ豸µÄÔ¶³Ì¿ØÖƹ¤¾ßAndroSpyµÄÔ´´úÂ뿪·¢µÄFastSpy¡£Ñо¿ÈËÔ±³Æ£¬KimsukyµÄ¹¥»÷¼ÆÄ±Ô½À´Ô½ÏȽø£¬Òò´ËҪעÒâÕë¶ÔAndroidÉ豸µÄ¹¥»÷¡£


https://thehackernews.com/2022/10/kimsuky-hackers-spotted-using-3-new.html


5¡¢Unit 42Ðû²¼2022ÄêµÚ¶þ¼¾¶ÈWebÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß

      

10ÔÂ26ÈÕ£¬Unit 42Ðû²¼ÁË2022ÄêµÚ¶þ¼¾¶ÈWebÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬µÚ¶þ¼¾¶È·¢ÏÖÁËԼĪ751000¸ö°üÂÞ²îÒìÀàÐÍWebÍþвµÄ¶ñÒâµÇ½URLʼþ£¬ÆäÖÐ253000¸öÊÇΨһURL£»¼ì²âµ½Ô¼Äª1740000¸ö¶ñÒâÖ÷»úURL£¬ÆäÖÐ256000¸öÊÇΨһµÄ£»ÕâЩÓòÃûÖеĴó¶àÊýËÆºõÀ´×ÔÃÀ¹ú£»Top 5µÄÍþвÊǼÓÃܿ󹤡¢JavaScriptÏÂÔØÆ÷¡¢ web skimmer¡¢web scamºÍJavaScriptÖØ¶¨Ïò¹¤¾ß¡£


https://unit42.paloaltonetworks.com/web-threats-malicious-javascript-downloader/


6¡¢Check PointÐû²¼¹ØÓÚ2022ÄêQ3È«ÇòÍøÂç¹¥»÷µÄ³ÂËß

      

Check PointÔÚ10ÔÂ26ÈÕÐû²¼Á˹ØÓÚ2022ÄêQ3È«ÇòÍøÂç¹¥»÷µÄ³ÂËß¡£Óë2021ÄêͬÆÚÏà±È£¬2022ÄêµÚÈý¼¾¶ÈÈ«ÇòµÄÍøÂç¹¥»÷Ôö¼ÓÁË28%£¬È«Çòÿ¸ö×é֯ƽ¾ùÿÖܱ»¹¥»÷¶à´ï1130´Î¡£ÕâÒ»¼¾¶È±»¹¥»÷×î¶àµÄÐÐÒµÊǽÌÓýºÍÑо¿²¿ÃÅ£¬Æ½¾ùÿ¸ö×é֯ÿÖܱ»¹¥»÷2148´Î£¬Óë2021ÄêQ3Ïà±ÈÔö³¤ÁË18%¡£Ò½ÁƱ£½¡ÐÐÒµÊÇ2022ÄêQ3Ôâµ½ÀÕË÷¹¥»÷×î¶àµÄÐÐÒµ£¬Ã¿42¸ö×éÖ¯ÖоÍÓÐÒ»¸öѬȾÀÕË÷Èí¼þ£¬Í¬±ÈÔö³¤5%¡£


https://blog.checkpoint.com/2022/10/26/third-quarter-of-2022-reveals-increase-in-cyberattacks/