ArubaÐÞ¸´EdgeConnectÖÐRCEºÍÉí·ÝÑéÖ¤ÈÆ¹ýµÈÎó²î

Ðû²¼Ê±¼ä 2022-10-14
1¡¢ArubaÐÞ¸´EdgeConnectÖÐRCEºÍÉí·ÝÑéÖ¤ÈÆ¹ýµÈÎó²î

      

ýÌå10ÔÂ12ÈÕ±¨µÀ£¬ £¬£¬ArubaÐû²¼ÁËEdgeConnect Enterprise OrchestratorµÄÇå¾²¸üУ¬ £¬£¬ÐÞ¸´Á˶à¸öÑÏÖØµÄÎó²î¡£¡£¡£ÆäÖаüÀ¨»ùÓÚWebµÄÖÎÀí½çÃæÖеÄÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2022-37913ºÍCVE-2022-37914£©£¬ £¬£¬CVSSÆÀ·ÖΪ9.8£»£»£»£»£»£»£»ÒÔ¼°»ùÓÚWebµÄÖÎÀí½çÃæÖÐδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2022-37915£©£¬ £¬£¬CVSSÆÀ·ÖҲΪ9.8¡£¡£¡£ÎªÁË×î´óÏ޶ȵØïÔ̭ʹÓÃÉÏÊöÎó²îµÄ¿ÉÄÜÐÔ£¬ £¬£¬¹©Ó¦É̽¨ÒéÓû§½«CLIºÍ»ùÓÚWebµÄÖÎÀí½çÃæÏÞÖÆÔÚרÓõĵÚ2²ãÍø¶Î/VLAN£¬ £¬£¬»ò½«·À»ðǽսÂÔÉèÖÃΪµÚ3²ã¼°ÒÔÉÏ¡£¡£¡£


https://securityaffairs.co/wordpress/137000/security/aruba-edgeconnect-flaws.html


2¡¢MinecraftµÄЧÀÍÆ÷Wynncraft½üÆÚÔâµ½DDoS¹¥»÷

      

ýÌå10ÔÂ13Èճƣ¬ £¬£¬MinecraftµÄЧÀÍÆ÷Wynncraft×î½üÔâµ½ÁË2.5 TbpsµÄDDoS¹¥»÷¡£¡£¡£CloudflareÌåÏÖ£¬ £¬£¬ÕâÊÇÒ»ÆðÒ»Á¬Ô¼Á½·ÖÖӵĶàÏòÁ¿¹¥»÷£¬ £¬£¬ÓÉUDPºÍTCPºé·ºÊý¾Ý°ü×é³É£¬ £¬£¬ÊÇËûÃǼͼºÍ´¦Öóͷ£¹ý×î´ó±ÈÌØÂʵĹ¥»÷¡£¡£¡£±ðµÄ£¬ £¬£¬¸ÃÇå¾²¹«Ë¾Ö¸³ö£¬ £¬£¬ËûÃÇÔÚ½ñÄêµÄµÚÈý¼¾¶È×èÖ¹Á˱ÈÈ¥Äê¸ü¶àµÄDDoS¹¥»÷£¬ £¬£¬ÆäÖлùÓÚHTTPµÄ¹¥»÷ÔöÌíÁË111%£¬ £¬£¬µÚ3²ãºÍµÚ4²ã(L3/4)DDoS¹¥»÷Ò²ÏÕЩͬ±È·­ÁËÒ»·¬£¬ £¬£¬ÔöÌíÁË97%¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cloudflare-mitigated-record-ddos-attack-against-minecraft-server/


3¡¢Mango Marketsƽ̨Ôâµ½ÉÁµç´û¹¥»÷Ëðʧ³¬1ÒÚÃÀÔª

      

¾Ý10ÔÂ12ÈÕ±¨µÀ£¬ £¬£¬¼ÓÃÜÇ®±ÒÉúÒâÆ½Ì¨Mango MarketsÔâµ½ÉÁµç´û¹¥»÷£¬ £¬£¬Ëðʧ³¬1ÒÚÃÀÔª¡£¡£¡£¸Ãƽ̨ÖܶþÍíÉÏÔÚTwitterÉϸæËßÓû§£¬ £¬£¬ËüÕýÔÚÊÓ²ìÒ»ÆðÇå¾²ÊÂÎñ¡£¡£¡£¼¸¸öСʱºó£¬ £¬£¬¸Ã¹«Ë¾Ö¤Êµ£¬ £¬£¬ºÚ¿ÍʹÓÃÁ½¸öÕË»§Ôڶ̶̼¸·ÖÖÓÄÚÈËΪ½«MNGO±ÒÔÚ¸÷ÉúÒâËùµÄ¼ÛÇ®Ìá¸ßÁËÔ­¼ÛµÄ5µ½10±¶£¬ £¬£¬Æäʱ¸ÃÕË»§ÌáÈ¡µÄ¾»ÖµÔ¼Îª1ÒÚÃÀÔª¡£¡£¡£ÏÖÔÚÆ½Ì¨ÉϵĿͻ§ÎÞ·¨ÌáÈ¡ÈκÎ×ʲú£¬ £¬£¬ÓÉÓںڿͺľ¡ÁËËùÓпÉÓÃ×ʲú£¬ £¬£¬Ê¹Æ½Ì¨×ʲ»µÖÕ®¡£¡£¡£¾ÝϤ£¬ £¬£¬ºÚ¿ÍÁªÏµÁËMango Markets²¢ÌåÏÖÔ¸Òâ̸ÅС£¡£¡£

 

https://therecord.media/crypto-trading-platform-mango-markets-drained-of-more-than-100-million-in-flash-loan-attack/


4¡¢Ñо¿ÍŶӷ¢Ã÷Ò»ÖÖеÄnpm׼ʱ¹¥»÷¿Éµ¼Ö¹©Ó¦Á´¹¥»÷ 

      

¾ÝýÌå10ÔÂ12ÈÕ±¨µÀ£¬ £¬£¬Aqua SecurityÍŶӷ¢Ã÷Ò»ÖÖеÄnpm׼ʱ¹¥»÷¡£¡£¡£Ëü¿ÉÒÔ͸¶˽ÓÐÈí¼þ°üµÄÃû³Æ£¬ £¬£¬Òò´Ë¹¥»÷Õß¿ÉÒÔ¹ûÕæÐû²¼¶ñÒâ¿Ë¡£¬ £¬£¬²¢ÓÕʹ¿ª·¢Ö°Ô±Ê¹ÓÃËüÃÇ¡£¡£¡£ÕâÖÖ¹¥»÷ÒÀÀµÓÚÔÚËÑË÷Ò»¸ö˽Óаüʱ£¬ £¬£¬Óë¿âÖв»±£´æµÄ°üÏà±È£¬ £¬£¬·µ»Ø404 Not Found¹ýʧµÄϸСʱ¼ä²î¡£¡£¡£ËäÈ»ÏìӦʱ¼ä²îÖ»Óм¸°ÙºÁÃ룬 £¬£¬µ«Ëü×ãÒÔÈ·¶¨Õâ¸ö˽ÓаüÊÇ·ñ±£´æ£¬ £¬£¬´Ó¶ø¾ÙÐÐð³ä¹¥»÷¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬ £¬£¬ÕâÖÖеÄÊÖÒÕ¿ÉÄܵ¼Ö¹©Ó¦Á´¹¥»÷£¬ £¬£¬¶øGitHubÌåÏÖ²»»á½â¾öÕâ¸öÎÊÌâ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-npm-timing-attack-could-lead-to-supply-chain-attacks/


5¡¢INKY³ÆÒÔCOVID-19ΪÖ÷ÌâµÄ´¹ÂÚ¹¥»÷»î¶¯ÔÚÃÀ¹ú¼¤Ôö

      

10ÔÂ12ÈÕ±¨µÀ£¬ £¬£¬ÓʼþÇå¾²¹«Ë¾INKYÖ¸³ö£¬ £¬£¬ÒÔCOVID-19ΪÖ÷ÌâµÄ´¹ÂڻÔÚÃÀ¹ú¼¤Ôö¡£¡£¡£ÔÚ×î½üµÄ¹¥»÷ÖУ¬ £¬£¬´¹ÂÚÓʼþð³äÃÀ¹úСÆóÒµÖÎÀí¾Ö(SBA)²¢ÀÄÓÃGoogle±íµ¥À´ÍйÜÓÃÓÚÇÔÈ¡ÆóÒµÖ÷СÎÒ˽¼ÒÐÅÏ¢µÄ´¹ÂÚÒ³Ãæ¡£¡£¡£¸Ã»î¶¯Ê¹ÓõÄÓÕ¶üÊÇÕë¶ÔCOVID-19µÄ½ðÈÚÖ§³ÖÍýÏ룬 £¬£¬Ö¼ÔÚÇÔȡĿµÄµÄGoogleÕÊ»§Æ¾Ö¤¡¢SSN¡¢EIN¡¢State ID¡¢¼ÝʻִÕÕÐÅÏ¢ÒÔ¼°ÒøÐÐÕʺ𣡣¡£INKY»¹Í¸Â¶£¬ £¬£¬ÓëǰÈý¸öÔÂÏà±È£¬ £¬£¬9Ô·ݵÄÀ¬»øÓʼþÊýÄ¿·­ÁËÒ»·¬£¬ £¬£¬Ô¤¼Æ»¹»á½øÒ»²½ÉÏÉý¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-npm-timing-attack-could-lead-to-supply-chain-attacks/


6¡¢KasperskyÐû²¼¹ØÓÚ¶ñÒâWhatsApp modµÄÆÊÎö±¨¸æ

      

10ÔÂ12ÈÕ£¬ £¬£¬KasperskyÐû²¼ÁËͨ¹ýÕýµ±Ó¦Ó÷ַ¢µÄ¶ñÒâWhatsApp modµÄÆÊÎö±¨¸æ¡£¡£¡£Ñо¿Ö°Ô±ÔÚYoWhatsApp°æ±¾2.22.11.75Öз¢Ã÷ÁËÒ»¸ö¶ñÒâÄ£¿£¿£¿£¿£¿ £¿£¿é£¬ £¬£¬¸ÃÄ£¿£¿£¿£¿£¿ £¿£¿é½âÃܲ¢Æô¶¯ÁËTrojan.AndroidOS.Triada.efµÄÖ÷Òªpayload¡£¡£¡£±ðµÄ£¬ £¬£¬¸Ã¶ñÒâÄ£¿£¿£¿£¿£¿ £¿£¿é»¹ÇÔÈ¡ÁËÕýµ±WhatsAppÊÂÇéËùÐèµÄÖÖÖÖÃÜÔ¿¡£¡£¡£¸ÃÓ¦ÓÃͨ³£Í¨¹ýSnaptubeºÍVidmateÉϵÄڲƭ¹ã¸æÈö²¥£¬ £¬£¬×°Öúó»áÇëÇóÓëWhatsAppÏàͬµÄȨÏÞ¡£¡£¡£


https://securelist.com/malicious-whatsapp-mod-distributed-through-legitimate-apps/107690/