°Ä´óÀûÑǵڶþ´óµçÐŹ«Ë¾Optus½üǧÍòÓû§µÄÐÅϢй¶

Ðû²¼Ê±¼ä 2022-09-26

1¡¢°Ä´óÀûÑǵڶþ´óµçÐŹ«Ë¾Optus½üǧÍòÓû§µÄÐÅϢй¶

      

¾Ý9ÔÂ23ÈÕ±¨µÀ£¬°Ä´óÀûÑǵڶþ´óµçÐŹ«Ë¾OptusÔâµ½¹¥»÷£¬¿ÉÄÜÓ°Ïì¶à´ï900Íò¸öÓû§µÄÊý¾Ý¡£Optus³Æ£¬¹¥»÷ÕßÉè·¨½øÈëÁ˿ͻ§Éí·ÝÊý¾Ý¿â£¬²¢Í¨¹ýÓ¦Ó÷¨Ê½½Ó¿Ú£¨API£©½«Æä¿ª·Å¸øÆäËûϵͳ¡£Ê¼þÈÔÔÚÊÓ²ìÖУ¬OptusÈÏΪÆäÖÐÒ»¸öÍøÂ类̻¶ÔÚÁËÒ»¸öÓл¥ÁªÍø½ÓÈëµÄ²âÊÔÍøÂçÖС£¸Ã¹«Ë¾»³Òɹ¥»÷ÕßÒѾ­ÇÔÈ¡ÁËÏû·ÑÕßµÄÊý¾Ý¿â£¬²¢¿ÉÄܸ´ÖÆÁËÆäÖеÄÈý·ÖÖ®Ò»¡£OptusÌåÏÖËüÔÚ·¢ÏÖ¹¥»÷ºóÁ¢¼´½ÓÄÉÁË´ëÊ©£¬µ«ÊÇûÓÐ͸¶¹ØÓÚ¹¥»÷µÄÏêϸÄÚÈÝ¡£


https://www.hackread.com/optus-data-breach-australia-telecom-firm/


2¡¢SophosÐÞ¸´Òѱ»ÀûÓõĴúÂë×¢Èë©¶´CVE-2022-3236

      

SophosÔÚ9ÔÂ23ÈÕÐÞ¸´ÁËÆä·À»ðǽÖдúÂë×¢Èë©¶´£¨CVE-2022-3236£©¡£¸Ã©¶´CVSSÆÀ·ÖΪ9.8£¬Éæ¼°Óû§ÃÅ»§ºÍWeb¹ÜÀí×é¼þ£¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¸Ã¹«Ë¾ÌåÏÖ£¬ËüÒѾ­ÊӲ쵽ÀûÓøÃ©¶´µÄ¹¥»÷»î¶¯£¬Ö÷ÒªÊÇÔÚÄÏÑǵØÓò£¬²¢Ôö²¹ËµËüÖ±½Ó֪ͨÁËÕâЩ×éÖ¯¡£ÆôÓÃÁËÔÊÐí×Ô¶¯°²×°ÐÞ²¹·¨Ê½¹¦Ð§µÄSophos FirewallÓû§ÎÞÐèÖ´ÐÐÈκβÙ×÷£¬ÇÒÆôÓÃÊÇĬÈÏÉèÖá£SophosÔÚ½ñÄê3Ô»¹ÐÞ¸´ÁËÒ»¸öÀàËÆµÄFirewall©¶´(CVE-2022-1040)£¬¸Ã©¶´Ò²ÔÚÕë¶ÔÄÏÑÇ×éÖ¯µÄ¹¥»÷Öб»ÀûÓá£


https://www.bleepingcomputer.com/news/security/sophos-warns-of-new-firewall-rce-bug-exploited-in-attacks/


3¡¢YouTubeÈ«Çò·¶Î§ÄÚ·þÎñÖжÏÇÒÉв»Çå³þʼþÔ­Òò

      

ýÌå9ÔÂ23Èճƣ¬YouTubeÔÚÈ«Çò·¶Î§ÄÚ·þÎñÖжÏ£¬³ÉǧÉÏÍòµÄÓû§³ÂËßËûÃÇÎÞ·¨·ÃÎÊÖ±²¥¡£ÔÚʵÑé·ÃÎÊYouTubeʱ£¬Óû§»á¿´µ½´øÓмÓÔØ¶¯»­µÄºÚÆÁºÍ¡°ÇëÉÔºóÔÙÊÔ¡±µÄ´íÎóÏûÏ¢¡£ÄÇЩÉè·¨¼ÓÔØÖ±²¥µÄÓû§³ÆÊÓÆµÖͺó£¬ÁÄÌìÏûÏ¢Ò²Öͺó»ò»ù´¡²»ÏÔʾ¡£»¥ÁªÍø¼à¿Ø×éÖ¯NetBlocksҲ֤ʵ£¬YouTubeÕý¾­ÀúÒ»³¡Ó°ÏìÖ±²¥µÄÈ«ÇòÐÔÖжÏ£¬´ËʼþÓë¹ú¼Ò¼¶»¥ÁªÍøÖжϻò¹ýÂËÎ޹ء£Ä¿Ç°£¬Éв»Çå³þÕâÊǼƻ®ÖеÄά»¤»î¶¯¡¢YouTube·þÎñÆ÷µÄÎÊÌ⻹ÊÇÓë¶ñÒâ¹¥»÷ÓйØ¡£


https://www.bleepingcomputer.com/news/technology/youtube-down-live-streams-hit-by-worldwide-outage/


4¡¢Anonymous³ÆÒÑÈëÇÖ¶íÂÞ˹¹ú·À²¿ÍøÕ¾²¢¹ûÈ»30ÍòÈËÊý¾Ý

      

AnonymousÓÚ9ÔÂ23ÈÕÔÚÆäTwitterÕË»§ÉÏÐû²¼ÏûÏ¢£¬³ÆÒѾ­ÈëÇÖÁ˶íÂÞ˹¹ú·À²¿µÄÍøÕ¾¡£¸ÃÍŻﻹй¶ÁË305925È˵ÄÊý¾Ý£¬ÕâЩÈË¿ÉÄÜÊÇÆÕ¾©×ÜͳÐû²¼µÄÈý²¨¾üÊ»·¢¶¯ÖеĵÚÒ»²¨Ô¤±¸ÒÛ¾üÈË¡£¹¥»÷Õßͨ¹ýProtonDrive¹ûÈ»ÁËÒ»¸ö90MB¾ÞϸµÄTXTÎļþ£¬ÆäÖаüÂÞÁè¼Ý30ÍòÈ˵ÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µØÓòºÍµØÓò¡£Ä¿Ç°ÎÞ·¨ÑéÖ¤ÕâЩµµ°¸¼òÖ±ÇÐÀ´Ô´¡£


https://www.infosecurity-magazine.com/news/russian-reservists-leaked-anonymous/


5¡¢GitHub·¢ÏÖð³äCircleCIƽ̨ÈëÇÖÆäÓû§ÕË»§µÄ¹¥»÷»î¶¯

      

¾ÝýÌå9ÔÂ25ÈÕ±¨µÀ£¬GitHubÌáÐÑÕë¶ÔÆäÓû§µÄµöÓã¹¥»÷»î¶¯£¬Í¨¹ýð³äCircleCI DevOpsƽ̨À´ÇÔȡƾ¾ÝºÍË«ÖØÉí·ÝÑéÖ¤(2FA)´úÂë¡£¸Ã¹«Ë¾ÓÚ9ÔÂ16ÈÕ»ñϤ´Ë´Î¹¥»÷£¬²¢Ö¸³ö³ýGitHubÍ⣬µöÓã»î¶¯ÒÑÓ°Ïìµ½Ðí¶à×éÖ¯¡£µöÓãÐÅÏ¢Éù³ÆÓû§µÄCircleCI»á»°ÒѹýÆÚ£¬²¢ÊÔͼÓÕʹÊÕ¼þÈËʹÓÃGitHubƾ¾ÝµÇ¼¡£ÊÕ¼þÈ˱»Öض¨Ïòµ½Î±ÔìµÄGitHubµÇÂ¼Ò³Ãæºó£¬»á±»ÇÔÈ¡ÊäÈëµÄƾ¾ÝºÍ2FA´úÂë¡£¸Ã¹«Ë¾ÌåÏÖ£¬ÊÜÓ²¼þÄþ¾²ÃÜÔ¿±£»¤µÄÕË»§²»Ò×Ôâµ½µ½ÕâÖÖ¹¥»÷¡£


https://securityaffairs.co/wordpress/136211/hacking/phishing-circleci-github-accounts.html


6¡¢AhnLabÐû²¼FARGO¹¥»÷MS-SQL·þÎñÆ÷µÄ·ÖÎö³ÂËß

      

9ÔÂ23ÈÕ£¬AhnLabÐû²¼³ÂËß³ÆÒ×Êܹ¥»÷µÄMicrosoft SQL·þÎñÆ÷Ôâµ½ÁËFARGOµÄÐÂÒ»ÂÖ¹¥»÷¡£FARGOÓëGlobeImposterÒ»Ñù£¬ÊÇÖ÷ÒªÕë¶ÔMS-SQL·þÎñÆ÷µÄÀÕË÷Èí¼þÖ®Ò»£¬ÔÚ¹ýÈ¥Ò²±»³ÆÎªMallox¡£Ñ¬È¾Ê¼ÓÚÄ¿±êÉè±¹ØÁ¬ÄMS-SQL½ø³ÌʹÓÃcmd.exeºÍpowershell.exeÏÂÔØ.NETÎļþ¡£Payload»á»ñÈ¡ÆäËû¶ñÒâÈí¼þ£¬Éú³É²¢ÔËÐÐÖÕÖ¹ÌØ¶¨½ø³ÌºÍ·þÎñµÄBATÎļþ¡£È»ºó£¬½«ÀÕË÷Èí¼þpayload×¢Èëµ½ºÏ·¨µÄWindows½ø³ÌAppLaunch.exeÖС£


https://asec.ahnlab.com/en/39152/