OpenSSLÏîÄ¿ÐÞ¸´Æä¿ªÔ´ÃÜÂë¿âÖÐÁ½¸öÑÏÖØµÄ©¶´
Ðû²¼Ê±¼ä 2022-11-02
¾ÝýÌå11ÔÂ1ÈÕ±¨µÀ£¬OpenSSLÏîÄ¿ÐÞ¸´ÁËÆäÓÃÓÚ¼ÓÃÜͨÐÅͨµÀºÍHTTPSÁ¬½ÓµÄ¿ªÔ´ÃÜÂë¿âÖÐÁ½¸öÑÏÖØµÄ©¶´¡£ÆäÖУ¬CVE-2022-3602ÊÇÈÎÒâ4×Ö½Ú¶ÑÕ»»º³åÇøÒç³ö©¶´£¬¿ÉÄÜ´¥·¢±ÀÀ£»òµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ(RCE)¡£CVE-2022-3786¿É±»¹¥»÷Õßͨ¹ý¶ñÒâÓʼþµØÖ·ÀûÓã¬Í¨¹ý»º³åÇøÒç³öÀ´´¥·¢¾Ü¾ø·þÎñ״̬¡£ËäÈ»×î³õµÄ¾¯±¨¶Ø´Ù¹ÜÀíÔ±Á¢¼´½ÓÄÉÐж¯À´»º½â©¶´£¬µ«Êµ¼ÊÓ°ÏìÒªÓÐÏ޵ö࣬ÒòΪCVE-2022-3602(×î³õ±»ÆÀ¼¶ÎªCritical)Òѱ»½µ¼¶ÎªHigh£¬¶øÇÒËüÖ»Ó°ÏìOpenSSL 3.0¼°¸ü¸ß°æ±¾¡£
https://www.bleepingcomputer.com/news/security/openssl-fixes-two-high-severity-vulnerabilities-what-you-need-to-know/
2¡¢SnatchÉù³ÆÒÑÈëÇÖ¾ü¹¤ÆóÒµ¹©Ó¦ÉÌHENSOLDT France
ýÌå10ÔÂ31Èճƣ¬ÀÕË÷ÍÅ»ïSnatch¹¥»÷ÁË·¨¹ú¹«Ë¾HENSOLDT France¡£HENSOLDTÊÇÒ»¼ÒרÃÅ´Óʾüʺ͹ú·Àµç×Ó²úÎïµÄ¹«Ë¾£¬Ö÷ҪΪ·¨¹úºÍ¹úÍâµÄº½¿Õ¡¢¹ú·À¡¢ÄÜÔ´ºÍÔËÊ䲿ÃÅÌṩµç×Ó½â¾ö·½°¸¡¢²úÎïºÍ·þÎñ¡£SnatchÒѽ«¸Ã¹«Ë¾Ìí¼Óµ½ÆäTorÍøÕ¾ÉÏ£¬²¢Ðû²¼ÁËÒ»·Ý±»µÁÊý¾ÝµÄÑù±¾(94 MB)×÷Ϊ¹¥»÷»î¶¯µÄÖ¤¾Ý¡£SnatchÓÚ2019Äêµ×Ê״α»·¢ÏÖ£¬Ëü¿É½«±»Ñ¬È¾µÄ¼ÆËã»úÖØÆôµ½Äþ¾²Ä£Ê½ÒÔÈÆ¹ýÄþ¾²½â¾ö·½°¸¡£
https://securityaffairs.co/wordpress/137886/cyber-crime/snatch-hensoldt-france-ransomware.html
3¡¢ÐÂÎ÷À¼º½¿Õ¹«Ë¾Í¸Â¶Æä²¿Ãſͻ§Ô⵽ƾ֤Ìî³ä¹¥»÷
¾Ý10ÔÂ30ÈÕ±¨µÀ£¬ÐÂÎ÷À¼º½¿Õ¹«Ë¾Í¸Â¶ºÚ¿ÍÊÔͼͨ¹ýƾ֤Ìî³ä¹¥»÷À´·ÃÎÊÆä¿Í»§µÄÕË»§¡£¸Ã¹«Ë¾Ö¸³ö£¬¹¥»÷ÕßûÓÐÈëÇÖ¹«Ë¾µÄÈκÎϵͳ£¬½ö¸öÈ˵ÄÕË»§Êܵ½Ó°Ïì¡£Ö»ÓÐÉÙÊý¿Í»§Ôâµ½Á˹¥»÷£¬ÇÒ¹¥»÷ÕßûÓзÃÎÊÈÎºÎÆÛÕ©ÐÔ½»Ò×ÐÅÏ¢»òÃô¸ÐÐÅÏ¢¡£ÐÂÎ÷À¼º½¿Õ¹«Ë¾Ä¿Ç°ÒÑËø¶¨ÕË»§£¬²¢Í¨Öª¿Í»§ÔÚÏ´ÎʹÓÃAirpointsϵͳ֮ǰ¸ü¸ÄËûÃǵĵǼÐÅÏ¢¡£
https://securityaffairs.co/wordpress/137793/cyber-crime/air-new-zealand-breach.html
4¡¢APT 10ÀûÓÃɱ¶¾Èí¼þÏòÈÕ±¾µÄ×éÖ¯·Ö·¢LODEINFO
KasperskyÓÚ10ÔÂ31ÈÕÅû¶ÁËAPT 10ÀûÓÃÄþ¾²Èí¼þ·Ö·¢×Ô½ç˵ºóÃÅLODEINFOµÄ¹¥»÷»î¶¯£¬Ö÷ÒªÕë¶ÔÈÕ±¾µÄýÌ弯ÍÅ¡¢Íâ½»»ú¹¹¡¢Õþ¸®ºÍ¹«¹²²¿ÃÅ×éÖ¯ÒÔ¼°Öǿ⡣´Ó½ñÄê3Ô·ݿªÊ¼£¬Ñо¿ÈËÔ±×¢Òâµ½Õë¶ÔAPT10¹¥»÷ʹÓÃÁËеÄѬȾý½é£¬°üÂÞÓã²æÊ½µöÓãÓʼþ¡¢×Ô½âѹ(SFX)RARÎļþÒÔ¼°ÀÄÓÃÄþ¾²Èí¼þÖеÄDLL²à¼ÓÔØÂ©¶´¡£´ËÍ⣬¶ñÒâÈí¼þ¿ª·¢ÕßÔÚ2022ÄêÐû²¼ÁË6¸ö°æ±¾µÄLODEINFO£¬Ñо¿ÈËÔ±»¹·ÖÎöÁ˸úóÃÅÔÚÕâÒ»ÄêÖеÄÑݱ䡣
https://securelist.com/apt10-tracking-down-lodeinfo-2022-part-i/107742/
5¡¢½ÌÓý¼¼Êõ¹«Ë¾CheggÒò3ÄêÄÚµÄ4´ÎÊý¾Ýй¶±»FTCÆðËß
ýÌå10ÔÂ31ÈÕ±¨µÀ£¬½ÌÓý¼¼Êõ¹«Ë¾Chegg±»FTCÆðËߣ¬ÒòÆäÔÚ2017ÄêÒÔÀ´µÄ4´ÎÊý¾Ýй¶Ê¼þÖÐй¶ÁËÊýǧÍò¿Í»§ºÍÔ±¹¤µÄÐÅÏ¢¡£CheggÔÚ2017Äê9ÔÂÊ×´ÎÔâµ½ÈëÇÖ£¬Ô´ÓÚÕë¶Ô¶àÃûÔ±¹¤µÄµöÓã¹¥»÷£»2018Äê4Ô£¬Ä³Ç°³Ð°üÉÌʹÓõǼÐÅÏ¢·ÃÎÊÁ˰üÂÞÊý°ÙÍòÓû§Êý¾ÝµÄ´æ´¢Í°£»Ò»Äêºó£¬Cheggij¸ß¹ÜµÄƾ¾ÝÔÚÒ»´ÎµöÓã¹¥»÷Öб»µÁµ¼ÖÂÊý¾Ýй¶£»ÓÖ¹ýÁË12¸öÔ£¬ÁíÒ»ÃûCheggÔ±¹¤Ôâµ½µöÓã¹¥»÷¡£FTCͶË߳ƣ¬ÕâЩй¶Ê¼þ¶¼ÊÇÈô¸É²»Á¼µÄÊý¾ÝÄþ¾²Êµ¼ùµÄ½á¹û¡£
https://www.bleepingcomputer.com/news/security/chegg-sued-by-ftc-after-suffering-four-data-breaches-within-3-years/
6¡¢Unit42Ðû²¼¹ØÓÚ¶à¸öÒøÐÐľÂíʹÓõļ¼ÊõµÄ·ÖÎö³ÂËß
Unit42ÔÚ10ÔÂ31ÈÕÐû²¼Á˹ØÓÚÒøÐÐľÂí¼¼ÊõµÄ·ÖÎö³ÂËß¡£ÓÉÓÚ¹¥»÷Õß²»Í£Ê¹ÓÃеļ¼ÊõÀ´Èƹý¼ì²âºÍÖ´Ðй¥»÷£¬Ñо¿³öÓÚ¾¼ÃÄ¿µÄµÄ¶ñÒâÈí¼þ¿ÉÒÔ×ÊÖú·ÀÓùÕ߸üÓÐЧµØ±£»¤×éÖ¯¡£¸Ã³ÂËß·ÖÎöÁËÖøÃûµÄÒøÐÐľÂíÓÃÀ´Èƹý¼ì²â¡¢ÇÔÈ¡Ãô¸ÐÊý¾ÝºÍÐÞ¸ÄÊý¾ÝµÄ¼¼Êõ£¬»¹½«ÃèÊöÈçºÎ·ÀÓùÕâЩ¼¼Êõ£¬Éæ¼°Zeus¡¢Kronos¡¢Trickbot¡¢IcedID¡¢EmotetºÍDridex¡£ÒøÐÐľÂíʹÓõļ¼Êõ°üÂÞWebinject¡¢Named Pipe¡¢Heaven's Gate¡¢AtomBombing¡¢HookingºÍPE InjectionµÈ¡£
https://unit42.paloaltonetworks.com/banking-trojan-techniques/