¹È¸è½«Ö§¸¶3.91ÒÚÃÀÔª½â¾ö¹ØÓÚAndroidλÖøú×ÙµÄËßËÏ

Ðû²¼Ê±¼ä 2022-11-16
1¡¢¹È¸è½«Ö§¸¶3.91ÒÚÃÀÔª½â¾ö¹ØÓÚAndroidλÖøú×ÙµÄËßËÏ

¾ÝýÌå11ÔÂ14ÈÕ±¨µÀ £¬¹È¸èÒÑͬÒâÖ§¸¶3.915ÒÚÃÀÔª £¬À´½â¾öÃÀ¹ú40¸öÖÝÌáÆðµÄ¹ØÓÚÒþ˽µÄËßËÏ¡£¶íÀÕ¸ÔÖÝ×ܼì²ì³¤³Æ £¬¹È¸èÎóµ¼Óû§ÒÔΪ×Ô¼ºÔÚÕË»§ÉèÖÃÖйرÕÁËλÖøú×Ù £¬¶øÊÂʵÉÏËüÈÔÔÚÊÕ¼¯ËûÃǵÄλÖÃÐÅÏ¢¡£´Ë´ÎºÍ½â»¹ÒªÇó¹È¸èÒýÈë¸ü¶àÓû§ÓѺÃÐ͵ÄÕË»§¿ØÖÆ £¬²¢ÏÞÖƹ«Ë¾¶ÔijЩÀàÐÍλÖÃÊý¾ÝµÄʹÓúʹ洢¡£°Ä´óÀûÑÇACCCÔøÔÚ8Ô¶Թȸ账ÒÔ6000ÍòÃÀÔªµÄ·£¿î £¬Ô­ÒòÊÇËüʹÓÃÏàͬµÄÒªÁìÊÕ¼¯°Ä´óÀûÑÇÓû§µÄλÖÃÊý¾Ý½üÁ½Äê¡£

https://www.bleepingcomputer.com/news/google/google-will-pay-391m-to-settle-android-location-tracking-lawsuit/


2¡¢OxeyeÅû¶Spotify BackstageÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´

OxeyeÓÚ11ÔÂ15ÈÕ³ÆÆäÔÚSpotify Backstage·¢ÏÖÁËÒ»¸öÑÏÖصÄÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVSSÆÀ·ÖΪ9.8£©¡£BackstageÊÇSpotifyÓÃÓÚ¹¹½¨¿ª·¢ÕßÃÅ»§µÄ¿ªÔ´Æ½Ì¨ £¬Ëü±»°üÂÞÃÀ¹úº½¿Õ¹«Ë¾ºÍNetflixµÈ¶à¼Ò×é֯ʹÓá£Ñо¿ÈËÔ±³Æ £¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÀûÓÃScaffolderºËÐIJå¼þÖеÄvm2ɳÏäÌÓÒÝ©¶´£¨CVE-2022-36067ÓÖÃûSandbreak£©ÔÚBackstageÓ¦Ó÷¨Ê½ÉÏÖ´ÐÐÈÎÒâϵͳÃüÁî¡£OxeyeÓÚ2022Äê8ÔÂ18ÈÕÏòSpotify³ÂËßÁ˸鶴 £¬ºóÕßÔÚ8ÔÂ29ÈÕÐû²¼µÄ¸üÐÂ(v 1.5.1)Öнâ¾öÁËÕâ¸öÎÊÌâ¡£

https://www.oxeye.io/blog/remote-code-execution-in-spotifys-backstage

3¡¢Î¢Èí11Ô·ÝÄþ¾²¸üпɵ¼ÖÂKerberosÉí·ÝÑéÖ¤·ºÆðÎÊÌâ

¾Ý11ÔÂ14ÈÕ±¨µÀ £¬Î¢ÈíÄ¿Ç°ÔÚÊӲ쵼ÖÂÆóÒµÓò¿ØÖÆÆ÷ÔÚ°²×°±¾ÔÂÄþ¾²¸üкó·ºÆðKerberosµÇ¼ʧ°ÜµÈ´íÎóµÄÎÊÌâ¡£KerberosÒѾ­È¡´úNTLMЭÒé³ÉΪWindows 2000ÒÔÉÏËùÓа汾ÖÐÓòÁ¬½ÓÉ豸µÄĬÈÏÈÏ֤ЭÒé¡£Óöµ½´ËÎÊÌâµÄÓû§¿ÉÄÜ»áÔÚÓò¿ØÖÆÆ÷ÉϵÄʼþÈÕÖ¾µÄSystem²¿ÃÅÊÕµ½Microsoft-Windows-Kerberos-Key-Distribution-CenterʼþID 14µÄ´íÎóʼþ¡£Î¢ÈíÌåÏÖÕýÔÚŬÁ¦ÐÞ¸´´ËÎÊÌâ £¬²¢Ô¤¼Æ½«ÔÚδÀ´¼¸ÖÜÄÚÌṩ½â¾ö·½°¸¡£

https://www.bleepingcomputer.com/news/microsoft/windows-kerberos-authentication-breaks-after-november-updates/

4¡¢AkamaiÅû¶ÓÃÓÚÍÚ¿óºÍDDoS¹¥»÷µÄжñÒâÈí¼þKmsdBot

AkamaiÓÚ11ÔÂ10ÈÕÅû¶ÁËÒ»¸öÓÉGolang¿ª·¢µÄжñÒâÈí¼þKmsdBot¡£¸Ã¶ñÒâÈí¼þÀûÓÃSSH¼ÓÃÜЭÒé½øÈëÄ¿±êϵͳ £¬Ê¹ÓÃUDP¡¢TCP¡¢HTTP POSTºÍGETÒÔ¼°Í¨¹ýTCPͨÐŵÄC2½øÐй¥»÷ £¬Ä¿µÄÊÇÍÚ¾ò¼ÓÃÜ»õ±Ò²¢Ö´ÐÐDDoS¹¥»÷¡£ËüÒѱ»·¢ÏÖÕë¶ÔÓÎÏ·ÐÐÒµ¡¢¿Æ¼¼ÐÐÒµºÍºÀ»ªÆû³µÖÆÔìÉ̵ȶà¸öÐÐÒµ £¬²¢Ö§³Ö¶àÖּܹ¹ £¬ÀýÈçWinx86¡¢Arm64ºÍmips64¡¢x86_64¡£´ËÍâ £¬ÎªÁËÈƹý¼ì²â £¬KmsdBot²»»áÔÚ±»Ñ¬È¾µÄϵͳÉϳ־ôæÔÚ¡£

https://www.akamai.com/blog/security-research/kmdsbot-the-attack-and-mine-malware

5¡¢Cyjax·¢ÏÖFangxiaoÔÚÈ«Çò·¶Î§ÄڵĴó¹æÄ£µöÓã»î¶¯

11ÔÂ14ÈÕ £¬Cyjax³ÆÆä½üÆÚÊÓ²ìÁËÒ»ÆðÅÓ´óµÄ´ó¹æÄ£µöÓã»î¶¯ £¬¸Ã»î¶¯Õë¶Ô¶à¸ö´¹Ö±ÐÐÒµµÄÆóÒµ £¬°üÂÞÁãÊÛ¡¢ÒøÐС¢ÂÃÓΡ¢ÖÆÒ©¡¢ÂÃÓκÍÄÜÔ´µÄ400¶à¸öÖªÃûÆ·ÅÆ¡£¸Ã»î¶¯±³ºóµÄ¹¥»÷ÕßΪFangxiao £¬×Ô2019ÄêÒÔÀ´Ê¹ÓÃÁËÁè¼Ý42000¸öÓò¡£Í¨³£ £¬Ä¿±ê»á±»Öض¨Ïòµ½ÓõöÓãÍøÕ¾²¢ÏÂÔØTriadaľÂíµÈ¶ñÒâÈí¼þ¡£´ËÍâ £¬Fanxgiaoͨ¹ý¶àÖÖ¼ÆıÀ´±£³ÖÄäÃû £¬Æä´ó²¿ÃÅ»ù´¡ÉèÊ©¶¼Êܵ½CloudFlareµÄ±£»¤ £¬¶øÇÒÓòÃû»á¶¨ÆÚ¸üР£¬½öÔÚ2022Äê10ÔµÄÒ»Ìì¾ÍʹÓÃÁË300¶à¸öеÄÓòÃû¡£

https://www.cyjax.com/2022/11/14/fangxiao-a-chinese-threat-actor/

6¡¢ESETÐû²¼¹ØÓÚ2022ÄêµÚ¶þ¼¾¶ÈAPT¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß

11ÔÂ14ÈÕ £¬ESETÐû²¼Á˹ØÓÚ2022ÄêµÚ¶þ¼¾¶ÈAPT¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß £¬×ܽáÁË´Ó2022Äê5ÔÂÖÁ8Ôµ×ÊӲ졢ÊÓ²ìºÍ·ÖÎöµÄAPT×éÖ¯µÄ»î¶¯¡£ÔÚµÚ¶þ¼¾¶È £¬Óë¶íÂÞ˹¡¢ÒÁÀʺͳ¯ÏʵÈÏà¹ØµÄAPT»î¶¯Ã»ÓÐϽµ¡£ÎÚ¿ËÀ¼ÈÔÈ»ÊDz¿ÃÅAPTÍÅ»ïµÄÖ÷ҪĿ±ê £¬ÀýÈçSandworm¡¢Gamaredon¡¢InvisiMole¡¢CallistoºÍTurla¡£³¯ÏÊÏà¹ØµÄ¹¥»÷ÍÅ»ï¶Ôº½¿Õº½Ìì¡¢¹ú·À¹¤ÒµÒÔ¼°½ðÈںͼÓÃÜ»õ±ÒÏà¹Ø×éÖ¯¸ÐÐËȤ£»ÔÚÖж« £¬AgriusÖ÷ÒªÕë¶Ô×êʯÐÐÒµµÄÏà¹Ø×éÖ¯¡£

https://www.welivesecurity.com/wp-content/uploads/2022/11/eset_apt_activity_report_t22022.pdf