΢ÈíÐû²¼·ÇÄþ¾²¸üÐÂÐÞ¸´µ¼ÖÂSSL/TLSÎÕÊÖʧ°ÜµÄÎÊÌâ

Ðû²¼Ê±¼ä 2022-10-19

1¡¢Î¢ÈíÐû²¼·ÇÄþ¾²¸üÐÂÐÞ¸´µ¼ÖÂSSL/TLSÎÕÊÖʧ°ÜµÄÎÊÌâ

      

¾Ý10ÔÂ17ÈÕ±¨µÀ£¬Î¢ÈíÒÑÐû²¼´øÍâ(OOB)·ÇÄþ¾²¸üУ¬ÐÞ¸´ÓÉ2022Äê10ÔÂWindowsÄþ¾²¸üÐÂÒýÆðµÄÔÚ¿Í»§¶ËºÍ·þÎñÆ÷ƽ̨ÉÏ´¥·¢SSL/TLSÎÕÊÖʧ°ÜµÄÎÊÌâ¡£ÔÚ±»Ó°ÏìµÄÉ豸ÉÏ£¬µ±Óë·þÎñÆ÷µÄÁ¬½Ó·ºÆðÎÊÌâʱ£¬»áÏÔʾSEC_E_ILLEGAL_MESSAGE´íÎó¡£Î¢ÈíÌáÐÑ£¬ÎÞ·¨Í¨¹ýWindows Update°²×°¸üеÄÓû§£¬¿Éͨ¹ýMicrosoft Update Catalog ²¢ÊÖ¶¯½«ËüÃǵ¼ÈëWSUSºÍMicrosoft Endpoint Configuration ManagerÀ´°²×°¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-tls-handshake-failures-in-out-of-band-updates/


2¡¢HelpSystems´øÍâ¸üÐÂÐÞ¸´Cobalt StrikeÖеÄRCE©¶´

      

ýÌå10ÔÂ18ÈÕ±¨µÀ£¬HelpSystemsÐû²¼ÁËÒ»¸ö´øÍâÄþ¾²¸üУ¬ÒÔÐÞ¸´ÆäCobalt StrikeÖеÄRCE©¶´¡£Â©¶´×·×ÙΪCVE-2022-42948£¬Ó°ÏìÁËCobalt Strike°æ±¾4.7.1¡£ÆäÔ´ÓÚ2022Äê9ÔÂ20ÈÕÐû²¼µÄÒ»¸ö²»ÍêÕûµÄ²¹¶¡£¬¸Ã²¹¶¡ÓÃÓÚÐÞ¸´XSS©¶´(CVE-2022-39197)¡£¹¥»÷Õß¿ÉÒÔͨ¹ý²Ù¿Ø¿Í»§¶ËUIÊäÈë×ֶΡ¢Ä£ÄâCSÖ²È뷨ʽǩÈë»òͨ¹ýhookÔÚÖ÷»úÉÏÔËÐеÄCSÖ²È뷨ʽÀ´ÀûÓøÃXSS©¶´¡£HelpSystems³Æ£¬ÔÚÌØ¶¨Çé¿öÏ£¬¿ÉÒÔÀûÓÃJava Swing¿ò¼ÜÀ´´¥·¢Ô¶³Ì´úÂëÖ´ÐУ¬Cobalt Strike 4.7.2ÐÞ¸´Á˸é¶´¡£


https://thehackernews.com/2022/10/critical-rce-vulnerability-discovered.html


3¡¢¶à¹úÖ´·¨²¿Ãŵ·»ÙרÃÅÈëÇÖÎÞÔ¿³×ϵͳµÄ³µÁ¾µÄ·¸×ïÍÅ»ï

      

¾ÝýÌå10ÔÂ17Èճƣ¬·¨¹ú¡¢À­ÍÑάÑǺÍÎ÷°àÑÀÖ´·¨²¿Ãŵ·»ÙÁËÒ»¸öÀûÓúڿ͹¤¾ßÇÔÈ¡Æû³µµÄÍøÂç·¸×ïÍŻ²¢´þ²¶ÁË31ÃûÏÓÒÉÈË¡£¹¥»÷ÕßÖ»Õë¶ÔʹÓÃÎÞÔ¿³×½øÈëºÍÆô¶¯ÏµÍ³µÄÆû³µ£¬»áÔÚÀûÓÃËûÃǵÄÎÞÔ¿³×¼¼Êõ½âËø³µÃŲ¢Æô¶¯·¢¶¯»úºóµÁ×߯û³µ¡£´Ë´ÎÖ´·¨Ðж¯ÓÚ10ÔÂ10ÈÕ¿ªÊ¼£¬´þ²¶ÁËÀ´×ÔÈý¸ö¹ú¼Ò22¸öËùÔÚµÄ31ÃûÏÓÒÉÈË£¬ÆäÖаüÂÞÈí¼þ¿ª·¢ÉÌ¡¢¾­ÏúÉÌÒÔ¼°Ê¹Óøù¤¾ßÈëÇÖÆû³µµÄ͵³µÔô£¬»¹Ã»ÊÕÁ˼ÛÖµ1098500Å·ÔªµÄ·¸×ï×ʲú¡£


https://www.bleepingcomputer.com/news/security/police-dismantles-criminal-ring-that-hacked-keyless-cars/


4¡¢µÂ¹úHeilbronn StimmeÔâµ½ÀÕË÷¹¥»÷Ó°Ï챨ֽµÄ¿¯ÐÐ

      

10ÔÂ17ÈÕ±¨µÀ£¬µÂ¹ú±¨ÉçHeilbronn StimmeÔÚÔâµ½ÀÕË÷¹¥»÷ºó´òӡϵͳ̱»¾£¬±»ÆÈÒÔµç×ÓÐÎʽ³öÊéеÄÒ»ÆÚ¡£¹¥»÷·¢ÉúÔÚÉÏÖÜÎ壬Æäµç»°ºÍµç×ÓÓʼþϵͳÔÚÕû¸öÖÜÄ©ÆÚ¼äÒ»Ö±´¦ÓڹرÕ״̬¡£Ö÷±àUwe Ralf HeerÌåÏÖ£¬´Ë´Î¹¥»÷Ó°ÏìÁËÕû¸öStimme MediengruppeýÌ弯ÍÅ£¬ÆäÖаüÂÞPressedruck¡¢EchoºÍRegioMail¹«Ë¾¡£Heer»¹ÌåÏÖ£¬½ØÖÁÖÜÁùÏÂÎ磬ºÚ¿Í¶¼Î´Ìá³ö¾ßÌåµÄÊê½ðÒªÇó¡£¹«Ë¾ÊÂÇéÈËÔ±±»ÆÈÔÚ¼ÒÖÐʹÓøöÈ˵çÄÔÊÂÇ飬¸Ã¹«Ë¾ÕýÔÚÊÓ²ì´ËÊ£¬²¢Ñ°Çó½â¾ö¼¼ÊõÎÊÌâµÄÒªÁì¡£


https://www.bleepingcomputer.com/news/security/ransomware-attack-halts-circulation-of-some-german-newspapers/


5¡¢ÈÕ±¾¿Æ¼¼¹«Ë¾OomiyaµÄIT»ù´¡ÉèʩѬȾLockBit 3.0

      

¾ÝýÌå10ÔÂ17ÈÕ±¨µÀ£¬ÈÕ±¾¿Æ¼¼¹«Ë¾OomiyaÔâµ½ÁËLockBit 3.0µÄ¹¥»÷¡£OomiyaרעÓÚÉè¼ÆºÍÖÆÔì΢µç×ÓºÍÉèʩϵͳÉ豸£¬ÆäÒµÎñ·ÖΪËÄ´óÁìÓò£ºÄ³Î´¾­ÊÚȨµÄµÚÈý·½·Ç·¨·ÃÎÊÁËËûÃÇÔÚÒ»¸ö²âÊÔÆ½Ì¨ÉϵÄÊý¾Ý¿â»¯Ñ§ºÍ¹¤Òµ²úÎïµÄÖÆÔìºÍÉè¼Æ¡¢µç×ÓÖÊÁϵÄÉè¼Æ¡¢Ò©Î↑·¢ºÍ¹¤³§ÖÆÔì¡£Lockbit 3.0ÔËÓªÍÅ»ïÉù³ÆÒÑÇÔÈ¡¸Ã¹«Ë¾µÄÊý¾Ý£¬²¢ÍþвÈç¹û¹«Ë¾²»¸¶Êê½ð½«ÔÚ10ÔÂ20ÈÕ֮ǰй¶±»µÁÊý¾Ý¡£ÒòΪOomiyaλÓÚÈ«Çò¶à¸öÐÐÒµµÄÖ÷Òª×éÖ¯µÄ¹©Ó¦Á´ÖУ¬ËùÒÔ´Ëʼþ¿ÉÄÜ»á¶ÔµÚÈý·½×éÖ¯Ôì³ÉÖØ´óÓ°Ïì¡£


https://securityaffairs.co/wordpress/137243/cyber-crime/oomiya-lockbit-3-0-ransomware.html


6¡¢°Ä´óÀûÑÇÆÏÌѾÆÁãÊÛÉÌVinomofoÔ¼50Íò¿Í»§µÄÐÅϢй¶

      

ýÌå10ÔÂ18Èճƣ¬°Ä´óÀûÑÇµÄÆÏÌѾÆÁãÊÛÉÌVinomofoÔâµ½ºÚ¿Í¹¥»÷£¬¶à´ï50Íò¿Í»§µÄÐÅÏ¢¿ÉÄÜÒѾ­Ì»Â¶¡£¸Ã¹«Ë¾³Æ£¬Î´¾­ÊÚȨµÄµÚÈý·½ÔÚ²âÊÔÆ½Ì¨ÉÏ·Ç·¨·ÃÎÊÁËËûÃǵÄÊý¾Ý¿â£¬Éæ¼°¿Í»§µÄÐÕÃû¡¢ÐԱ𡢳öÉúÈÕÆÚ¡¢µØÖ·¡¢ÓʼþµØÖ·ºÍµç»°ºÅÂëµÈÐÅÏ¢¡£Ä¿Ç°Éв»Çå³þÓм¸¶àÈËÊܵ½¸ÃʼþµÄÓ°Ï죬µ«Óб¨µÀ³ÆVinomofoÓµÓÐÔ¼500000¸ö¿Í»§¡£²»¾Ãǰ£¬°Ä´óÀûÑǵçÐÅÔËÓªÉÌOptusÔøÐ¹Â¶Áè¼Ý200Íò¿Í»§µÄÊý¾Ý¡£


https://www.infosecurity-magazine.com/news/breaches-expose-millions-at-aussie/