GoogleÐÞ¸´ChromeÖÐÒѱ»ÀûÓõÄ©¶´CVE-2022-3723

Ðû²¼Ê±¼ä 2022-10-31
1¡¢GoogleÐÞ¸´ChromeÖÐÒѱ»ÀûÓõÄ©¶´CVE-2022-3723

      

¾Ý10ÔÂ28ÈÕ±¨µÀ£¬GoogleÐû²¼ÁËChromeµÄ½ô¼±Äþ¾²¸üУ¬ÐÞ¸´×Ô2022Äê³õÒÔÀ´µÄµÚÆ߸öÁãÈÕ©¶´ ¡£¸Ã©¶´(CVE-2022-3723)ÊÇChrome V8 JavascriptÒýÇæÖеÄÒ»¸öÀàÐÍ»ìÏý©¶´£¬ÓÉAvastµÄÑо¿ÈËÔ±ÓÚ½ñÄê10ÔÂ25ÈÕ³ÂËß ¡£³öÓÚÄþ¾²Ô­Òò£¬¸Ã¹«Ë¾Ã»ÓÐÌṩÓйØ©¶´µÄÏêϸÐÅÏ¢£¬Ò²Ã»ÓÐ˵Ã÷Éæ¼°¸Ã©¶´µÄ¹¥»÷»î¶¯Ë®Æ½µÄÐÔÖÊ ¡£Ñо¿ÈËԱǿÁÒ½¨ÒéChromeÓû§¾¡¿ì¸üÐÂÆää¯ÀÀÆ÷ÒÔ×èÖ¹´ËÀ๥»÷ ¡£


https://www.bleepingcomputer.com/news/security/google-fixes-seventh-chrome-zero-day-exploited-in-attacks-this-year/


2¡¢Ë¹Âå·¥¿ËºÍ²¨À¼Òé»áµÄITϵͳÔâµ½´ó¹æÄ£ÍøÂç¹¥»÷

      

ýÌå10ÔÂ29Èճƣ¬Ë¹Âå·¥¿ËºÍ²¨À¼Òé»áÔâµ½´ó¹æÄ£ÍøÂç¹¥»÷ ¡£²¨À¼Õþ¸®³Æ£¬Õâ´Î¹¥»÷¿ÉÄÜÓë²ÎÒéÔºµÄͶƱÓйØ£¬¹¥»÷ÍêÈ«ÖжÏÁËÒé»áµÄIT»ù´¡ÉèÊ© ¡£²¢Í¸Â¶Õâ´Î¹¥»÷ÊǶàÆ«ÏòµÄ£¬°üÂÞÀ´×ÔÂÞ˹Áª°îÄÚ²¿µÄ¹¥»÷ ¡£Ë¹Âå·¥¿ËÒé»á¸±Ò鳤ÌåÏÖ£¬¹¥»÷µ¼ÖÂ˹Âå·¥¿ËÒé»áµÄITϵͳºÍµç»°Ïß·̱»¾£¬¼¸Ïî·¨°¸µÄͶƱ±»ÖжÏ ¡£ËûÃÇÄ¿Ç°ÉÐδȷ¶¨¸ÃʼþµÄÀ´Ô´£¬Æä¼¼ÊõÈËÔ±ÕýÔÚ½â¾ö¸ÃÎÊÌâ ¡£


https://securityaffairs.co/wordpress/137777/hacking/slovak-polish-parliaments-cyberattacks.html


3¡¢Å·ÖÞ×î´óµÄÍ­Éú²úÉÌAurubisÔÚ±»¹¥»÷ºóϵͳ¹Ø±Õ

      

10ÔÂ28ÈÕ±¨µÀ£¬Aurubis³ÆÆäÔâµ½¹¥»÷£¬±»ÆȹرÕITϵͳÒÔ·ÀÖ¹¹¥»÷ÂûÑÓ ¡£AurubisÊÇÅ·ÖÞ×î´óºÍÊÀ½çµÚ¶þ´óµÄÍ­Éú²úÉÌ£¬Ã¿ÄêÉú²ú100Íò¶ÖÒõ¼«Í­ ¡£Aurubisͨ¸æÏÔʾ£¬ËûÃǹرÕÁËÆäËùÔڵصÄÖÖÖÖϵͳ£¬µ«²¢Î´Ó°ÏìÉú²ú ¡£Ò±Á¶³§µÄÉú²úºÍ»·±£ÉèÊ©Õý³£ÔËÐУ¬½ø³ö»õÎïÒ²ÔÚÈ˹¤Î¬»¤ ¡£Ä¿Ç°£¬¸Ã¹«Ë¾ÈÔÕýÔÚÆÀ¹ÀÍøÂç¹¥»÷µÄÓ°Ï죬ÎÞ·¨Ô¤¼Æϵͳ»Ö¸´ÐèÒª¶à³¤Ê±¼ä ¡£ÏÖÔڵĵ±ÎñÖ®¼±ÊDZ£³Ö²úÁ¿ÔÚÕý³£Ë®Æ½£¬³öÓÚÕâ¸öÔ­Òò£¬Ò»Ð©²Ù×÷ÒÑתÏòÊÖ¶¯Ä£Ê½£¬Ö±µ½ÈÛÁ¶³§»Ö¸´¼ÆËã»ú¸¨ÖúµÄ×Ô¶¯»¯ ¡£


https://www.bleepingcomputer.com/news/security/largest-eu-copper-producer-aurubis-suffers-cyberattack-it-outage/


4¡¢°Ä´óÀûÑÇÁÙ´²ÊµÑéÊÒ³ÆÀÕË÷¹¥»÷µ¼ÖÂ22ÍòÈËÐÅϢй¶

      

¾ÝýÌå10ÔÂ27Èճƣ¬°Ä´óÀûÑÇÁÙ´²ÊµÑéÊÒ(ACL)͸¶ÆäMedlab PathologyÒµÎñ·¢ÉúÁËÊý¾Ýй¶£¬Ó°ÏìÔ¼223000Ãû»¼ÕߺÍÔ±¹¤ ¡£ÀÕË÷ÍÅ»ïQuantumÓÚ2022Äê6ÔÂ14ÈÕÔÚÆäTorÍøÕ¾ÉÏ´«ÁËËùÓб»µÁÎļþ£¬¹²86 GBµÄÊý¾Ý£¬°üÂÞ»¼ÕߺÍÔ±¹¤µÄÏêϸÐÅÏ¢¡¢²ÆÕþ³ÂËß¡¢·¢Æ±¡¢ºÏͬ¡¢±í¸ñ¡¢´«Æ±ºÍÆäËû˽ÈËÎļþµÈ ¡£Æ¾¾ÝÍøÕ¾Êý¾Ý£¬MedLabµÄй¶ҳÃæÒѱ»·ÃÎÊ130000´Î ¡£¹¥»÷·¢ÉúÓÚ2022Äê2Ô·Ý£¬µ«¸ÃÄþ¾²Ê¼þÔÚ·¢Éú9¸öÔºó²Å±»Åû¶£¬ACLµÄͨ¸æÊÔͼΪÕâÖÖÍÏÑÓÌṩÀíÓÉ ¡£


https://www.databreaches.net/australian-clinical-labs-says-data-of-223000-people-hacked/


5¡¢iOSºÍmacOSÖеÄSiriSpy©¶´¿ÉÇÔÌýÓû§ÓëSiriµÄ¶Ô»°

      

ýÌåÓÚ10ÔÂ27ÈÕ±¨µÀ³Æ£¬Ó°ÏìÁËApple iOSºÍmacOSµÄSiriSpy©¶´£¨CVE-2022-32946£©£¬¿ÉÒÔ±»ÈκοɷÃÎÊÀ¶ÑÀµÄÓ¦Ó÷¨Ê½ÓÃÀ´ÇÔÌýÓû§ÓëSiriµÄ¶Ô»° ¡£ÔÚ²âÊÔAirBuddyµÄ¹¦Ð§Ê±£¬Ñо¿ÈËÔ±×¢Òâµ½AirPods°üÂÞÒ»¸ö´øÓÐUUIDµÄ·þÎñ£¬¶øÇÒ¾ßÓÐÖ§³Ö֪ͨµÄ¹¦Ð§ ¡£½øÒ»·¨Ê½²é½«ÉÏÊöUUIDÓëÓÃÓÚSiriºÍÌýд֧³ÖµÄDoAP·þÎñÏà¹ØÁª£¬¹¥»÷Õß¿ÉÒÔ´´½¨Ò»¸ö¶ñÒâÓ¦Ó㬸ÃÓ¦ÓÿÉÒÔͨ¹ýÀ¶ÑÀÁ¬½Óµ½AirPods²¢ÔÚºǫ́¼ÖÆÒôƵ ¡£Ä¿Ç°£¬¸Ã©¶´Òѱ»ÐÞ¸´ ¡£


https://securityaffairs.co/wordpress/137710/security/sirispy-apple-flaw-spy-conversations.html


6¡¢SymantecÐû²¼CraneflyÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß

      

10ÔÂ28ÈÕ£¬SymantecÐû²¼Á˹ØÓÚCraneflyÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß ¡£³ÂËßÖ¸³ö£¬Cranefly£¨ÓÖÃûUNC3524£©ÕýÔÚʹÓÃÐÂdropper(Trojan.Geppei)À´°²×°ÁíÒ»¸öеĶñÒâÈí¼þ(Trojan.Danfuan)ºÍÆäËü¹¤¾ß£¨Hacktool.Regeorg£© ¡£Geppei´ÓºÏ·¨µÄIISÈÕÖ¾ÖжÁÈ¡ÃüÁî ¡£¶ÁÈ¡µÄÃüÁî°üÂÞ¶ñÒâ±àÂëµÄ.ashxÎļþ£¬ÕâЩÎļþ±»Éú´æµ½ÓÉÃüÁî²ÎÊýÈ·¶¨µÄÈÎÒâÎļþ¼ÐÖУ¬ËüÃÇ×÷ΪºóÃÅÔËÐÐ ¡£¾¡¹ÜÒÑÔÚÄ¿±êµÄÍøÂçÉÏDZ·üÁË18¸öÔ£¬µ«Ñо¿ÈËÔ±ÉÐδÊӲ쵽¹¥»÷Õß´ÓÄ¿±êÖÐÇÔÈ¡Êý¾ÝµÄ»î¶¯ ¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/cranefly-new-tools-technique-geppei-danfuan