΢Èí11Ô·ݵÄÖܶþ²¹¶¡µ¼ÖÂODBCÊý¾Ý¿âÁ¬½Ó´æÔÚBug
Ðû²¼Ê±¼ä 2022-12-09¾ÝýÌå12ÔÂ7ÈÕ±¨µÀ£¬Î¢ÈíÕýÔÚŬÁ¦½â¾ö2022Äê11ÔÂÖܶþ²¹¶¡µ¼ÖµÄODBCÊý¾Ý¿âÁ¬½ÓÎÊÌâ¡£°²×°´Ë¸üкó£¬Í¨¹ý΢ÈíODBC SQL ServerÇý¶¯·¨Ê½£¨sqlsrv32.dll£©Ê¹ÓÃODBCÁ¬½ÓÀ´·ÃÎÊÊý¾Ý¿âµÄÓ¦ÓÿÉÄÜ»áÎÞ·¨Á¬½Ó¡£´ËÍ⣬Óû§¿ÉÄÜÔÚÓ¦ÓÃÖÐÊÕµ½Ò»¸ö´íÎ󣬻òÕßÔÚSQL·þÎñÆ÷ÊÕµ½Ò»¸ö´íÎó¡£Î¢ÈíÌåÏÖ£¬ÆäĿǰÕýÔÚÖÆ¶¨½â¾ö·½°¸£¬ÓйشËÎÊÌâµÄ¸ü¶àÏêϸÐÅÏ¢½«ÔÚδÀ´µÄ¸üÐÂÖÐÐû²¼¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-november-updates-break-odbc-database-connections/
2¡¢ÐÂÎ÷À¼¶à¸öÕþ¸®»ú¹¹µÄMSP Mercury ITÔâµ½ÀÕË÷¹¥»÷
¾ÝýÌå12ÔÂ7Èճƣ¬ÍйܷþÎñÌṩÉÌ(MSP)Mercury ITÔâµ½¹¥»÷£¬Ó°ÏìÁ˸ùúµÄÊýÊ®¸ö¹«Ë¾ºÍÕþ¸®»ú¹¹¡£Ë¾·¨²¿ºÍÐÂÎ÷À¼ÎÀÉú²¿Í¸Â¶ÒòΪ´Ë´Î¹¥»÷£¬ËûÃǵIJ¿ÃÅÎļþÎÞ·¨·ÃÎÊ¡£ÎÀÉú²¿»¹³ÆÏÖ½×¶ÎÕâЩÎļþ²¢Î´Êܵ½Î´¾ÊÚȨµÄ·ÃÎÊ»òÏÂÔØ£¬ÇÒÎÀÉú·þÎñҲûÓÐÖжϡ£·ÇÓªÀûÐÔ½¡¿µ±£ÏÕÌṩÉÌBusinessNZÒ²Ðû²¼ÆäÈÕ³£ÔËÓªºÍ¿Í»§·þÎñÊܵ½Ó°Ï졣Ŀǰ£¬ÐÂÎ÷À¼Ïà¹Ø²¿ÃÅÕýÔÚ¿ªÕ¹½ô¼±ÊÂÇ飬ÒÔÁ˽âÊÜÓ°ÏìµÄ×éÖ¯ÊýÁ¿¡¢ËùÉæ¼°ÐÅÏ¢µÄÐÔÖÊÒÔ¼°ÐÅϢй¶ˮƽ¡£
https://therecord.media/multiple-government-departments-in-new-zealand-affected-by-ransomware-attack-on-it-provider/
3¡¢SophosÐû²¼¸üУ¬ÐÞ¸´ÆäFirewall 19.5ÖеÄ7¸ö©¶´
¾Ý12ÔÂ7ÈÕ±¨µÀ£¬SophosÐû²¼ÁËÄþ¾²¸üÐÂÒÔÐÞ¸´ÆäFirewall°æ±¾19.5ÖеÄ7¸ö©¶´¡£ÆäÖУ¬×îÑÏÖØµÄÊÇÓû§ÃÅ»§ºÍWebadminÖеĴúÂë×¢Èë©¶´£¨CVE-2022-3236£©£¬¿ÉÓÃÀ´Ô¶³ÌÖ´ÐдúÂë¡£SophosÒÑÊӲ쵽´Ë©¶´ÔÚÒ°Íâ±»ÀûÓõÄÇé¿ö£¬Ö÷ҪλÓÚÄÏÑǵØÓò¡£Æä´ÎΪÃüÁî×¢Èë©¶´£¨CVE-2022-3226£©¡¢´úÂë×¢Èë©¶´£¨CVE-2022-3713£©ÒÔ¼°´úÂë×¢Èë©¶´£¨CVE-2022-3696£©µÈ¡£
https://securityaffairs.co/wordpress/139362/security/sophos-firewall-critical-flaw.html
4¡¢APT 37ÀûÓÃIEÖеÄÁãÈÕ©¶´CVE-2022-41128¹¥»÷º«¹ú
GoogleÓÚ12ÔÂ7ÈÕÅû¶Á˳¯ÏÊÍÅ»ïAPT 37Õë¶Ôº«¹úµÄ¹¥»÷»î¶¯¡£¹¥»÷ÕßÊ×ÏÈÒÔÊ×¶ûÀæÌ©ÔºÊ¹ÊΪÓÕ¶ü£¬·Ö·¢°üÂÞ¶ñÒâÈí¼þµÄMicrosoft OfficeÎĵµ£¬¸ÃÎĵµ»áÏÂÔØÒ»¸ö¸»Îı¾Îļþ(RTF)Ô¶³ÌÄ£°å£¬È»ºó»ñȡԶ³ÌHTMLÄÚÈÝ¡£¼ÓÔØÔ¶³ÌHTMLÄÚÈÝÔÊÐí¹¥»÷ÕßÀûÓÃIEÁãÈÕ©¶´£¨CVE-2022-41128£©£¬¼´Ê¹Ä¿±êûÓн«Æä×÷ΪĬÈÏä¯ÀÀÆ÷¡£ÕâÊÇIEµÄJavaScriptÒýÇæµÄÒ»¸ö©¶´£¬ÀÖ³ÉÀûÓÃËüµÄ¹¥»÷ÕßÔÚ·ºÆð¶ñÒâÍøÕ¾Ê±¿ÉÖ´ÐÐÈÎÒâ´úÂ룬ÒÑÓÚ11ÔÂ8ÈÕÔÚ΢ÈíÐû²¼µÄÖܶþ²¹¶¡ÖÐÐÞ¸´¡£
https://blog.google/threat-analysis-group/internet-explorer-0-day-exploited-by-north-korean-actor-apt37/
5¡¢ÔÚÏßÁãÊÛÆ½Ì¨Vevor·þÎñÆ÷ÅäÖôíÎóй¶Áè¼Ý1ÒÚÌõ¼Ç¼
ýÌå12ÔÂ8ÈÕ͸¶£¬Ñо¿ÍŶӷ¢ÏÖÁËÒ»¸öÎÞÃÜÂë±£»¤µÄÊý¾Ý¿â£¬ÆäÖÐÊý¾Ý¼¯×ܾÞϸΪ601.84 GB£¬Îĵµ×ÜÊýÁè¼Ý1.16ÒÚ¡£¾ÊӲ죬ÕâЩÊý¾ÝÊôÓÚ¼ÓÀû¸£ÄáÑǵÄÔÚÏßÁãÊÛÉÌVevor£¬Ò»¸öרעÓÚÉ豸ºÍ¹¤¾ßµÄÆ·ÅÆ¡£¸Ã·þÎñÆ÷ÊÇÔÚ2022Äê4ÔÂÊ״α»·¢ÏÖ£¬È»ºóÑо¿ÈËÔ±ÔÚ2022Äê7ÔÂÔٴη¢ÏÖ²»Äþ¾²µÄAWS·þÎñÆ÷£¬±»ÍйÜÔÚ²îÒìµÄIPµØÖ·ÉÏ¡£2022Äê4ÔµÄʼþй¶ÁË406.79 GBÊý¾Ý£¬°üÂÞ706206770¸öÎļþ£»2022Äê7ÔÂй¶ÁË601.84 GBÊý¾Ý£¬1166293742¸öÎĵµ¡£¾ÝϤ£¬ÕâÊÇÓÉÓÚ·þÎñÆ÷ËùÓÐÕßÅäÖôíÎóµ¼Öµġ£
https://www.websiteplanet.com/blog/vevor-breach-report/
6¡¢ESET·¢ÏÖÒÁÀÊAgriusʹÓÃÐÂFantasyµÄ¹©Ó¦Á´¹¥»÷»î¶¯¡£
12ÔÂ7ÈÕ£¬ESET³ÆÆä·¢ÏÖÁËÒÁÀÊAgriusµÄ¹©Ó¦Á´¹¥»÷»î¶¯¡£¸Ã»î¶¯ÓÚ½ñÄê2Ô¿ªÊ¼£¬ÓÚ3ÔÂÈ«ÃæÕ¹¿ª£¬ÒÑÈëÇÖÒ»¼ÒITÖ§³Ö·þÎñ¹«Ë¾¡¢Ò»¼Ò×êʯÅú·¢ÉÌ¡¢Ò»¼ÒÖ鱦É̺ÍÒ»¼ÒÈËÁ¦×ÊÔ´×Éѯ¹«Ë¾¡£¸Ã»î¶¯ÀûÓÃÁËÒ»¸öеÄFantasy Wiper£¬ËüµÄ´ó²¿ÃÅ´úÂë¿âÀ´×ÔAgriusÔÚ֮ǰµÄ¹¥»÷ÖÐʹÓõÄApostle Wiper¡£Fantasy»áÓÃËæ»úÊý¾ÝÁýÕÖÿ¸öÎļþµÄÄÚÈÝ£¬½«Ê±¼ä´ÁÉèÖÃΪ2037ÄêÎçÒ¹²¢É¾³ý£¬´Ë¾ÙÊÇΪÁË·ÀÖ¹Îļþ±»Êý¾Ý»Ö¸´¹¤¾ß»Ö¸´¡£³ýÁËFantasy£¬Agrius»¹·Ö·¢ÁËÒ»ÖÖеÄÓÃÓÚºáÏòÒÆ¶¯ºÍÖ´ÐÐFantasyµÄ¹¤¾ßSandals¡£
https://www.welivesecurity.com/2022/12/07/fantasy-new-agrius-wiper-supply-chain-attack/