Ñо¿Ö°Ô±Åû¶SQLiteÊý¾Ý¿âÖÐÒѱ£´æ22ÄêµÄÇå¾²Îó²î

Ðû²¼Ê±¼ä 2022-10-27
1¡¢Ñо¿Ö°Ô±Åû¶SQLiteÊý¾Ý¿âÖÐÒѱ£´æ22ÄêµÄÇå¾²Îó²î

      

¾ÝýÌå10ÔÂ25ÈÕ±¨µÀ£¬ £¬ £¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±Åû¶ÁËSQLiteÊý¾Ý¿â¿âÖÐÕûÊýÒç³öÎó²î£¨CVE-2022-35737£©¡£¡£ ¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇ2000Äê10ÔµĴúÂë¸ü¸ÄʱÒýÈëµÄ£¬ £¬ £¬£¬£¬£¬£¬£¬Õâ¸öÒѱ£´æ22ÄêµÄÎó²îÓ°ÏìÁËSQLite°æ±¾1.0.12µ½3.39.1¡£¡£ ¡£¡£¡£¡£¡£¡£ÈôÊÇÔÚC APIµÄ×Ö·û´®²ÎÊýÖÐʹÓÃÊýÊ®ÒÚ×Ö½Ú¿ÉÄܵ¼ÖÂÊý×é½çÏßÒç³ö£¬ £¬ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀÖ³ÉʹÓøÃÎó²î¿ÉÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬ £¬ £¬£¬£¬£¬£¬£¬ÔÚ±àдËüµÄʱ¼ä£¨2000ÄêµÄSQLiteÔ´´úÂëÖУ©£¬ £¬ £¬£¬£¬£¬£¬£¬ÆäʱϵͳÖ÷ÒªÊÇ32λ¼Ü¹¹£¬ £¬ £¬£¬£¬£¬£¬£¬Õâ¿ÉÄܲ¢²»ÊÇÒ»¸öÎó²î¡£¡£ ¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬ £¬£¬£¬£¬£¬£¬Îó²îÒÑÔÚ2022Äê7ÔÂ21ÈÕÐû²¼µÄ°æ±¾3.39.2ÖÐÐÞ¸´¡£¡£ ¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/137629/hacking/cve-2022-35737-sqlite-bug.html


2¡¢VMwareÐÞ¸´Cloud Foundation²úÆ·ÖеÄRCEÎó²î

      

ÔÚ10ÔÂ25ÈÕÐû²¼Çå¾²¸üУ¬ £¬ £¬£¬£¬£¬£¬£¬ÐÞ¸´Cloud FoundationÖеÄÎó²î(CVE-2021-39144)¡£¡£ ¡£¡£¡£¡£¡£¡£¸ÃÎó²îCVSSv3ÆÀ·Ö9.8£¬ £¬ £¬£¬£¬£¬£¬£¬Î»ÓÚCloud FoundationʹÓõÄXStream¿ªÔ´¿âÖУ¬ £¬ £¬£¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÔÚ²»ÐèÒªÓû§½»»¥µÄ¹¥»÷ÖÐÔ¶³ÌʹÓÃËü¡£¡£ ¡£¡£¡£¡£¡£¡£VMware»¹ÎªÎÞ·¨Á¬Ã¦×°Öò¹¶¡µÄÓû§ÌṩÁËÒ»¸öÔÝʱ½â¾ö¼Æ»®¡£¡£ ¡£¡£¡£¡£¡£¡£ÓÉÓÚÎó²îµÄÑÏÖØÐÔ£¬ £¬ £¬£¬£¬£¬£¬£¬VMwareҲΪÒÑÍ£²ú²úÆ·ÌṩÁ˲¹¶¡¡£¡£ ¡£¡£¡£¡£¡£¡£±ðµÄ£¬ £¬ £¬£¬£¬£¬£¬£¬´Ë´Î¸üл¹ÐÞ¸´ÁËXMLÍⲿʵÌåÎó²î(CVE-2022-31678)£¬ £¬ £¬£¬£¬£¬£¬£¬¿Éµ¼Ö¾ܾøÐ§ÀÍ»òÐÅϢй¶¡£¡£ ¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/10/vmware-releases-patch-for-critical-rce.html


3¡¢ºÚ¿ÍʹÓÃPoS¶ñÒâÈí¼þÇÔÈ¡Áè¼Ý16ÍòÕÅÐÅÓÿ¨µÄÐÅÏ¢

      

ýÌå10ÔÂ25Èճƣ¬ £¬ £¬£¬£¬£¬£¬£¬Group-IB·¢Ã÷ÁËÁ½¸öPoS¶ñÒâÈí¼þ£¬ £¬ £¬£¬£¬£¬£¬£¬ÓÃÓÚ´ÓPoSÖ§¸¶ÖÕ¶ËÇÔÈ¡167000¶àÕÅÐÅÓÿ¨µÄÊý¾Ý¡£¡£ ¡£¡£¡£¡£¡£¡£¾ÝϤ£¬ £¬ £¬£¬£¬£¬£¬£¬±»µÁµÄÊý¾Ýת´¢¿ÉÒÔͨ¹ýÔÚºÚ¿ÍÂÛ̳ÉϳöÊÛ¸øÔËÓªÍÅ»ï´øÀ´¸ß´ï334ÍòÃÀÔªµÄ¾»ÊÕÈë¡£¡£ ¡£¡£¡£¡£¡£¡£Group-IBÈ·ÈÏÁËÓëÁ½¸öPoS¶ñÒâÈí¼þÏà¹ØµÄC2ЧÀÍÆ÷£¬ £¬ £¬£¬£¬£¬£¬£¬³ÆÔÚ2022Äê2ÔÂÖÁ9ÔÂʱ´ú£¬ £¬ £¬£¬£¬£¬£¬£¬MajikPOSºÍTreasure Hunter»®·ÖÇÔÈ¡ÁË77428ºÍ900024ÌõÖ§¸¶¼Í¼¡£¡£ ¡£¡£¡£¡£¡£¡£´ó²¿·Ö±»µÁÐÅÓÿ¨ÊÇÓÉÃÀ¹ú¡¢²¨¶àÀè¸÷¡¢ÃØÂ³¡¢°ÍÄÃÂí¡¢Ó¢¹ú¡¢¼ÓÄô󡢷¨¹ú¡¢²¨À¼¡¢Å²ÍþºÍ¸ç˹´ïÀè¼ÓµÄÒøÐп¯Ðеġ£¡£ ¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬ £¬£¬£¬£¬£¬£¬Éв»ÇåÎú¹¥»÷ÕßÉí·Ý£¬ £¬ £¬£¬£¬£¬£¬£¬ÒÔ¼°Êý¾ÝÊÇ·ñÒѱ»³öÊÛ¡£¡£ ¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/10/cybercriminals-used-two-pos-malware-to.html


4¡¢¹ú¼ÊƱÎñ¹«Ë¾See Tickets³ÆÆä¿Í»§µÄÖ§¸¶ÐÅϢй¶

      

¾Ý10ÔÂ25ÈÕ±¨µÀ£¬ £¬ £¬£¬£¬£¬£¬£¬Æ±ÎñЧÀÍÌṩÉÌSee TicketsÅû¶ÁËÒ»ÆðÊý¾Ýй¶ÊÂÎñ£¬ £¬ £¬£¬£¬£¬£¬£¬Í¨Öª¿Í»§¹¥»÷Õß¿ÉÄÜʹÓÃÆäÍøÕ¾ÉϵÄskimmer»á¼ûÁËËûÃǵÄÖ§¸¶¿¨ÏêϸÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¡£¡£See TicketsÓÚ2021Äê4Ô·¢Ã÷ÁËÕâһй¶ÊÂÎñ£¬ £¬ £¬£¬£¬£¬£¬£¬Ö±µ½2022Äê1ÔÂ8ÈÕ£¬ £¬ £¬£¬£¬£¬£¬£¬²ÅÔÚÆäÍøÕ¾ÉÏÍêȫɾ³ýÁ˶ñÒâ´úÂë¡£¡£ ¡£¡£¡£¡£¡£¡£½øÒ»³ÌÐò²éºó£¬ £¬ £¬£¬£¬£¬£¬£¬See TicketsÓÚ2022Äê9ÔÂ12Èյóö½áÂÛ£¬ £¬ £¬£¬£¬£¬£¬£¬Î´¾­ÊÚȨµÄ¸÷·½¿ÉÄÜÒѾ­ÇÔÈ¡Á˿ͻ§µÄÖ§¸¶¿¨ÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¡£¡£Ñ¬È¾±¬·¢ÔÚ2019Äê6ÔÂ25ÈÕ£¬ £¬ £¬£¬£¬£¬£¬£¬Òò´ËÊý¾Ýй¶ÊÂÎñµÄÒ»Á¬Ê±¼ä³¤´ï2.5Äê¡£¡£ ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/see-tickets-discloses-25-years-long-credit-card-theft-breach/ 


5¡¢MicrosoftÐû²¼¹ØÓÚVice Society¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ

      

10ÔÂ25ÈÕ£¬ £¬ £¬£¬£¬£¬£¬£¬MicrosoftÐû²¼Á˹ØÓÚVice Society£¨DEV-0832£©Õë¶ÔÈ«Çò½ÌÓýÐÐÒµµÄ¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ¡£¡£ ¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÔÚÒÑÍùÒ»ÄêʹÓÃÁ˶àÖÖÉÌÆ·ÀÕË÷Èí¼þµÄ±äÌ壬 £¬ £¬£¬£¬£¬£¬£¬°üÀ¨BlackCat¡¢QuantumLocker¡¢Zeppelin£¬ £¬ £¬£¬£¬£¬£¬£¬ÒÔ¼°×î½üµÄZeppelinµÄVice Society±äÌå¡£¡£ ¡£¡£¡£¡£¡£¡£×î½üÒ»´Î¹¥»÷±¬·¢ÔÚ2022Äê9ÔÂÏÂÑ®£¬ £¬ £¬£¬£¬£¬£¬£¬DEV-0832ÔÙ´ÎʹÓÃÁË.lockedÎļþÀ©Õ¹Ãû²¢½«ÀÕË÷Èí¼þpayload¸ÄΪRedAlert±äÌå¡£¡£ ¡£¡£¡£¡£¡£¡£ÔÚ½ñÄê7ÔµÄÒ»´Î¹¥»÷ÖУ¬ £¬ £¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïʵÑé×°ÖÃQuantumLocker¶þ½øÖÆÎļþ²¢ÔÚÎå¸öСʱÄÚ×°ÖÃZeppelin¶þ½øÖÆÎļþ¡£¡£ ¡£¡£¡£¡£¡£¡£ÕâÅú×¢¸ÃÍÅ»ï¿ÉÄÜά»¤×Ŷà¸öÀÕË÷Èí¼þpayload²¢Æ¾Ö¤Ä¿µÄ·ÀÓù¾ÙÐÐÇл»¡£¡£ ¡£¡£¡£¡£¡£¡£


https://www.microsoft.com/en-us/security/blog/2022/10/25/dev-0832-vice-society-opportunistic-ransomware-campaigns-impacting-us-education-sector/


6¡¢SurfsharkÐû²¼2022ÄêQ3È«ÇòÊý¾Ýй¶ÊÂÎñµÄ±¨¸æ

      

ýÌå10ÔÂ25ÈÕ±¨µÀ£¬ £¬ £¬£¬£¬£¬£¬£¬SurfsharkÐû²¼Á˹ØÓÚ2022ÄêQ3È«ÇòÊý¾Ýй¶ÊÂÎñµÄ±¨¸æ¡£¡£ ¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬ £¬ £¬£¬£¬£¬£¬£¬2022ÄêµÚÈý¼¾¶È¹²ÓÐ1.089ÒÚ¸öÕË»§±»µÁ£¬ £¬ £¬£¬£¬£¬£¬£¬±ÈÉÏÒ»¼¾¶Èºá¿ç70% £»£»£»£»£»£»£»Q3ÊÜÊý¾Ýй¶ӰÏì×î´óµÄ5¸ö¹ú¼ÒºÍµØÇøÊǶíÂÞ˹¡¢·¨¹ú¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢ÃÀ¹úºÍÎ÷°àÑÀ £»£»£»£»£»£»£»ËäÈ»¶íÂÞ˹µÄй¶×ÜÊý×î¶à£¨2230Íò£©£¬ £¬ £¬£¬£¬£¬£¬£¬µ«·¨¹úµÄÊý¾Ýй¶ÃܶÈ×î¸ß£¬ £¬ £¬£¬£¬£¬£¬£¬Æ½¾ùÿ1000È˾ÍÓÐ212¸öй¶ÕË»§ £»£»£»£»£»£»£»ÔÚÒÑÍùÊ®ÄêÖУ¬ £¬ £¬£¬£¬£¬£¬£¬ÃÀ¹úÈÔÈ»ÊDZ»¹¥»÷×î¶àµÄ¹ú¼Ò¡£¡£ ¡£¡£¡£¡£¡£¡£


https://www.infosecurity-magazine.com/news/data-breaches-rise-by-70-q3-2022/