Ñо¿ÈËÔ±Åû¶AWSÖÐÀûÓÃAppSyncµÄ¿ç×⻧©¶´µÄÏêÇé

Ðû²¼Ê±¼ä 2022-11-30
1¡¢Ñо¿ÈËÔ±Åû¶AWSÖÐÀûÓÃAppSyncµÄ¿ç×⻧©¶´µÄÏêÇé

¾Ý11ÔÂ28ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±Åû¶ÁËAmazon Web ServicesÖеĿç×⻧©¶´£¬¹¥»÷Õß¿ÉÒÔÀûÓøÃ©¶´»ñµÃ¶Ô×ÊԴδ¾­ÊÚȨµÄ·ÃÎÊ¡£¸Ã©¶´Óë»ìÏýÊðÀíÎÊÌâÓйØ£¬ÊÇÒ»ÖÖÌáȨ©¶´¡£ÕâÖÖ¹¥»÷ÀûÓÃÁËAppSync·þÎñÀ´¸ºµ£ÆäËûAWSÕË»§ÖеÄIAM½ÇÉ«£¬ÕâʹµÃ¹¥»÷ÕßÄܹ»½øÈ뵽Ŀ±ê×éÖ¯Öв¢·ÃÎÊÕâЩÕË»§ÖеÄ×ÊÔ´¡£Ñо¿ÈËÔ±ÓÚ2022Äê9ÔÂ1ÈÕ³ÂËßÁ˸ÃÎÊÌ⣬AWSÓÚ9ÔÂ6ÈÕÐÞ¸´Á˸é¶´¡£

https://thehackernews.com/2022/11/researchers-detail-appsync-cross-tenant.html

2¡¢Checkmarx·¢ÏÖÀûÓÃTikTokÌôÕ½À´·Ö·¢¶ñÒâÈí¼þµÄ»î¶¯

CheckmarxÔÚ11ÔÂ28ÈÕ³ÆÆä·¢ÏÖÁËÀûÓÃTikTok¡°ÒþÐÎÌôÕ½¡±·Ö·¢¶ñÒâÈí¼þµÄ»î¶¯¡£¸ÃÌôÕ½ÒªÇóÓû§Ê¹ÓÃTikTokµÄ¡°ÉíÌåÒþÐΡ±Â˾µÅÄÉãÂãÌ壬¸ÃÂ˾µ»á´ÓÊÓÆµÖÐÒÆ³ýÉíÌ岿ÃŲ¢ÓÃÄ£ºýÅä¾°È¡´ú¡£¹¥»÷ÕßÖÆ×÷ÁËTikTokÊÓÆµ£¬Éù³Æ¿ÉÒÔÌṩһÖÖÌØÊâµÄ¹ýÂËÆ÷£¬Ïû³ýTikTokµÄ¡°ÉíÌåÒþÐΡ±Ð§¹û¡£È»¶ø£¬¸ÃÈí¼þ»á°²×°WASP Stealer£¬ËüÄܹ»ÇÔÈ¡´æ´¢ÔÚä¯ÀÀÆ÷¡¢¼ÓÃÜ»õ±ÒÇ®°üÖеÄDiscordÕÊ»§¡¢ÃÜÂëºÍÐÅÓÿ¨£¬ÉõÖÁÊÇÄ¿±ê¼ÆËã»úÖеÄÎļþ¡£

https://checkmarx.com/blog/attacker-uses-a-popular-tiktok-challenge-to-lure-users-into-installing-malicious-package/

3¡¢BianLianÍÅ»ïÐû²¼´Ó¼ÓÄôóHarry RosenÇÔÈ¡µÄ1GBÊý¾Ý

¾ÝýÌå11ÔÂ25ÈÕ±¨µÀ£¬¼ÓÄôóÄÐ×°Á¬ËøµêHarry RosenÔâµ½ÁËÍøÂç¹¥»÷¡£¸Ã¹«Ë¾ÉÐδ͸¶¹¥»÷ÀàÐÍ£¬ÒÔ¼°ÊÇ·ñÓ°ÏìÁ˹«Ë¾µÄÔËÓª¡£BianLianÉù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦£¬²¢Ðû²¼ÁËÒ»¸ö1 GBµÄÎļþ×÷Ϊ¹¥»÷µÄÖ¤¾Ý£¬ÆäÖаüÂÞHarry RosenµÄGold+¿Í»§ÁÐ±í¡¢ÏúÊÛÐÅÏ¢ºÍÖÖÖÖÆäËüÀàÐ͵ÄÎļþ¡£BianLianÓÚ8Ô·ÝÊ״α»·¢ÏÖ£¬ÀÕË÷Èí¼þÊÇÓÃGoÓïÑÔΪWindowsϵͳ¿ª·¢µÄ£¬Æä³õʼ·ÃÎÊ¿ÉÄÜÊÇͨ¹ýWindows ProxyShell©¶´»òSonicWall VPN¹Ì¼þ©¶´»ñµÃµÄ¡£

https://www.itworldcanada.com/article/canadian-menswear-chain-harry-rosen-confirms-cyber-attack/515325

4¡¢¼ÙðµÄSMSÓ¦ÓÃSymoo³äµ±ÕÊ»§´´½¨·þÎñµÄSMSÖмÌ

ýÌå11ÔÂ28Èճƣ¬ÔÚGoogle PlayÉ̵êÖÐ100000´ÎÏÂÔØÁ¿µÄ¼ÙðAndroid SMSÓ¦Óã¬ÃØÃܵس䵱Microsoft¡¢Google¡¢Instagram¡¢TelegramºÍFacebookµÈÍøÕ¾µÄÕÊ»§´´½¨·þÎñµÄSMSÖмÌ¡£Ñо¿ÈËÔ±ÌåÏÖ£¬±»Ñ¬È¾µÄÉè±¸Ëæºó»á×÷Ϊ¡°ÐéÄâºÅÂ롱³ö×⣬ÓÃÓÚÔÚ´´½¨ÐÂÕË»§Ê±×ª·¢ÑéÖ¤Óû§µÄÒ»´ÎÐÔÃÜÂë¡£ËäȻδ¾­Ö¤Êµ£¬µ«¾ÝÐÅSymooÓ¦ÓÃÓÃÓÚ½ÓÊÕºÍת·¢Ê¹ÓÃActivationPW´´½¨ÕÊ»§Ê±Éú³ÉµÄOTPÑéÖ¤Â롣Ŀǰ£¬¸ÃÓ¦ÓÃÈÔÔÚGoogle PlayÉÏ¿ÉÓá£

https://www.bleepingcomputer.com/news/security/malicious-android-app-found-powering-account-creation-service/

5¡¢Group-IB·¢ÏÖ¶àÆðÕë¶Ô2022ÄêFIFAÊÀ½ç±­µÄµöÓã»î¶¯

11ÔÂ29ÈÕ£¬Group-IB͸¶Æä·¢ÏÖ¶àÆðÕë¶Ô¿¨Ëþ¶û2022ÄêFIFAÊÀ½ç±­ÃÅÆ±¡¢¹Ù·½ÉÌÆ·ºÍÊÂÇéµÄÕ©Æ­ºÍµöÓã¹¥»÷¡£Ñо¿ÈËÔ±ÔÚ¿¨Ëþ¶û2022Äê¹Ù·½ÇòÃÔIDÃÅ»§ÍøÕ¾HayyaÉÏ·¢ÏÖÁË90¶à¸ö¿ÉÄÜÔâµ½ÈëÇÖµÄÕË»§£¬ÕâÊÇΪÊÀ½ç±­¹ÛÖÚ½¨Á¢µÄÇ¿ÖÆÐÔϵͳ£¬¿ÉÒÔ½øÈ뿨Ëþ¶û²¢»ñµÃÃÅÆ±ºÍ½»Í¨µÈ·þÎñ¡£¾ÝÊӲ죬¹¥»÷ÕßÀûÓÃRedLineºÍErbiumµÈÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ»ñµÃÁËÕâЩÕË»§µÄÃÜÂë¡£´ËÍ⣬Group-IB»¹È·¶¨ÁË4ÖÖ²îÒìµÄÕ©Æ­ºÍµöÓã¹¥»÷À˳±£¬ÒÔ¼°´óÁ¿¿É´ÓGoogle PlayÉ̵êÏÂÔØµÄÐé¼ÙÓ¦Óá£

https://www.group-ib.com/media-center/press-releases/scammers-on-the-pitch/

6¡¢KasperskyÐû²¼2023Äê¹ØÓÚÏû·ÑÕßµÄÍþвµÄÔ¤²â³ÂËß

11ÔÂ28ÈÕ£¬KasperskyÐû²¼ÁË2023Äê¹ØÓÚÏû·ÑÕßµÄÍþвµÄÔ¤²â³ÂËß¡£³ÂËßÖ¸³ö£¬ÔÚÓÎÏ·ºÍÁ÷ýÌå·þÎñ·½Ã棬Óû§½«ÃæÁÙ¸ü¶àµÄÓÎÏ·¶©ÔÄÆÛÕ©¡¢ÓÎÏ·»úµÄ¶Ìȱ½«±»ÀûÓᢹ¥»÷Õß½«ÐèÒªÓÎÏ·ÖеÄÐéÄâ»õ±Ò¡¢¹¥»÷Õß»áÀûÓÃÆÚ´ýÒѾõÄÓÎÏ·£¬ÒÔ¼°Á÷ýÌåÈÔ½«Êǹ¥»÷Õßȡ֮²»¾¡µÄÊÕÈëÀ´Ô´ £»ÔÚÉ罻ýÌåºÍÔªÓîÖæ·½Ã棬еÄÉ罻ýÌ彫´øÀ´¸ü¶àµÄÒþ˽·çÏÕºÍÔªÓîÖæµÄ¿ª·¢´øÀ´µÄ·çÏÕ £»À´×ÔÐÄÀí½¡¿µÓ¦Ó÷¨Ê½µÄÊý¾Ý½«ÓÃÓÚ¾«È·¶¨Î»µÄÉç»á¹¤³Ì¹¥»÷ £»ÒÔ¼°£¬ÔÚÏß½ÌÓýƽ̨½«ÎüÒý¸ü¶à·¸×ï»î¶¯µÈ¡£

https://securelist.com/consumer-threats-2023/108112/