OpenSSLÏîÄ¿ÐÞ¸´Æä¿ªÔ´ÃÜÂë¿âÖÐÁ½¸öÑÏÖØµÄÎó²î
Ðû²¼Ê±¼ä 2022-11-02
¾ÝýÌå11ÔÂ1ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬OpenSSLÏîÄ¿ÐÞ¸´ÁËÆäÓÃÓÚ¼ÓÃÜͨѶͨµÀºÍHTTPSÅþÁ¬µÄ¿ªÔ´ÃÜÂë¿âÖÐÁ½¸öÑÏÖØµÄÎó²î¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬CVE-2022-3602ÊÇí§Òâ4×Ö½Ú¿ÍÕ»»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜ´¥·¢±ÀÀ£»£»£»£»£»£»£»£»òµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ(RCE)¡£¡£¡£¡£¡£CVE-2022-3786¿É±»¹¥»÷Õßͨ¹ý¶ñÒâÓʼþµØµãʹÓ㬣¬£¬£¬£¬£¬£¬Í¨¹ý»º³åÇøÒç³öÀ´´¥·¢¾Ü¾øÐ§ÀÍ״̬¡£¡£¡£¡£¡£ËäÈ»×î³õµÄ¾¯±¨±Þ²ßÖÎÀíÔ±Á¬Ã¦½ÓÄÉÐж¯À´»º½âÎó²î£¬£¬£¬£¬£¬£¬£¬µ«ÏÖʵӰÏìÒªÓÐÏ޵ö࣬£¬£¬£¬£¬£¬£¬ÓÉÓÚCVE-2022-3602(×î³õ±»ÆÀ¼¶ÎªCritical)Òѱ»½µ¼¶ÎªHigh£¬£¬£¬£¬£¬£¬£¬²¢ÇÒËüÖ»Ó°ÏìOpenSSL 3.0¼°¸ü¸ß°æ±¾¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/openssl-fixes-two-high-severity-vulnerabilities-what-you-need-to-know/
2¡¢SnatchÉù³ÆÒÑÈëÇÖ¾ü¹¤ÆóÒµ¹©Ó¦ÉÌHENSOLDT France
ýÌå10ÔÂ31Èճƣ¬£¬£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïSnatch¹¥»÷ÁË·¨¹ú¹«Ë¾HENSOLDT France¡£¡£¡£¡£¡£HENSOLDTÊÇÒ»¼ÒרÃÅ´Óʾüʺ͹ú·Àµç×Ó²úÆ·µÄ¹«Ë¾£¬£¬£¬£¬£¬£¬£¬Ö÷ҪΪ·¨¹úºÍÍâÑóµÄº½¿Õ¡¢¹ú·À¡¢ÄÜÔ´ºÍÔËÊ䲿·ÖÌṩµç×Ó½â¾ö¼Æ»®¡¢²úÆ·ºÍЧÀÍ¡£¡£¡£¡£¡£SnatchÒѽ«¸Ã¹«Ë¾Ìí¼Óµ½ÆäTorÍøÕ¾ÉÏ£¬£¬£¬£¬£¬£¬£¬²¢Ðû²¼ÁËÒ»·Ý±»µÁÊý¾ÝµÄÑù±¾(94 MB)×÷Ϊ¹¥»÷»î¶¯µÄÖ¤¾Ý¡£¡£¡£¡£¡£SnatchÓÚ2019Äêµ×Ê״α»·¢Ã÷£¬£¬£¬£¬£¬£¬£¬Ëü¿É½«±»Ñ¬È¾µÄÅÌËã»úÖØÆôµ½Ç徲ģʽÒÔÈÆ¹ýÇå¾²½â¾ö¼Æ»®¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/137886/cyber-crime/snatch-hensoldt-france-ransomware.html
3¡¢ÐÂÎ÷À¼º½¿Õ¹«Ë¾Í¸Â¶Æä²¿·Ö¿Í»§Ô⵽ƾ֤Ìî³ä¹¥»÷
¾Ý10ÔÂ30ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬ÐÂÎ÷À¼º½¿Õ¹«Ë¾Í¸Â¶ºÚ¿ÍÊÔͼͨ¹ýƾ֤Ìî³ä¹¥»÷À´»á¼ûÆä¿Í»§µÄÕË»§¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ö¸³ö£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßûÓÐÈëÇÖ¹«Ë¾µÄÈκÎϵͳ£¬£¬£¬£¬£¬£¬£¬½öСÎÒ˽¼ÒµÄÕË»§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£Ö»ÓÐÉÙÊý¿Í»§Ôâµ½Á˹¥»÷£¬£¬£¬£¬£¬£¬£¬ÇÒ¹¥»÷ÕßûÓлá¼ûÈκÎÚ²ÆÐÔÉúÒâÐÅÏ¢»òÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£ÐÂÎ÷À¼º½¿Õ¹«Ë¾ÏÖÔÚÒÑËø¶¨ÕË»§£¬£¬£¬£¬£¬£¬£¬²¢Í¨Öª¿Í»§ÔÚÏ´ÎʹÓÃAirpointsϵͳ֮ǰ¸ü¸ÄËûÃǵĵǼÐÅÏ¢¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/137793/cyber-crime/air-new-zealand-breach.html
4¡¢APT 10ʹÓÃɱ¶¾Èí¼þÏòÈÕ±¾µÄ×éÖ¯·Ö·¢LODEINFO
KasperskyÓÚ10ÔÂ31ÈÕÅû¶ÁËAPT 10ʹÓÃÇå¾²Èí¼þ·Ö·¢×Ô½ç˵ºóÃÅLODEINFOµÄ¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÈÕ±¾µÄýÌ弯ÍÅ¡¢Íâ½»»ú¹¹¡¢Õþ¸®ºÍ¹«¹²²¿·Ö×éÖ¯ÒÔ¼°Öǿ⡣¡£¡£¡£¡£´Ó½ñÄê3Ô·Ý×îÏÈ£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±×¢Öص½Õë¶ÔAPT10¹¥»÷ʹÓÃÁËеÄѬȾǰÑÔ£¬£¬£¬£¬£¬£¬£¬°üÀ¨Óã²æÊ½´¹ÂÚÓʼþ¡¢×Ô½âѹ(SFX)RARÎļþÒÔ¼°ÀÄÓÃÇå¾²Èí¼þÖеÄDLL²à¼ÓÔØÎó²î¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ¿ª·¢ÕßÔÚ2022ÄêÐû²¼ÁË6¸ö°æ±¾µÄLODEINFO£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹ÆÊÎöÁ˸úóÃÅÔÚÕâÒ»ÄêÖеÄÑݱ䡣¡£¡£¡£¡£
https://securelist.com/apt10-tracking-down-lodeinfo-2022-part-i/107742/
5¡¢½ÌÓýÊÖÒÕ¹«Ë¾CheggÒò3ÄêÄÚµÄ4´ÎÊý¾Ýй¶±»FTCÆðËß
ýÌå10ÔÂ31ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬½ÌÓýÊÖÒÕ¹«Ë¾Chegg±»FTCÆðËߣ¬£¬£¬£¬£¬£¬£¬ÒòÆäÔÚ2017ÄêÒÔÀ´µÄ4´ÎÊý¾Ýй¶ÊÂÎñÖÐй¶ÁËÊýÍòÍò¿Í»§ºÍÔ±¹¤µÄÐÅÏ¢¡£¡£¡£¡£¡£CheggÔÚ2017Äê9ÔÂÊ×´ÎÔâµ½ÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Ô´ÓÚÕë¶Ô¶àÃûÔ±¹¤µÄ´¹ÂÚ¹¥»÷£»£»£»£»£»£»£»£»2018Äê4Ô£¬£¬£¬£¬£¬£¬£¬Ä³Ç°³Ð°üÉÌʹÓõǼÐÅÏ¢»á¼ûÁ˰üÀ¨Êý°ÙÍòÓû§Êý¾ÝµÄ´æ´¢Í°£»£»£»£»£»£»£»£»Ò»Äêºó£¬£¬£¬£¬£¬£¬£¬Cheggij¸ß¹ÜµÄƾ֤ÔÚÒ»´Î´¹ÂÚ¹¥»÷Öб»µÁµ¼ÖÂÊý¾Ýй¶£»£»£»£»£»£»£»£»ÓÖ¹ýÁË12¸öÔ£¬£¬£¬£¬£¬£¬£¬ÁíÒ»ÃûCheggÔ±¹¤Ôâµ½´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£FTCͶË߳ƣ¬£¬£¬£¬£¬£¬£¬ÕâЩй¶ÊÂÎñ¶¼ÊÇÈô¸É²»Á¼µÄÊý¾ÝÇ徲ʵ¼ùµÄЧ¹û¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/chegg-sued-by-ftc-after-suffering-four-data-breaches-within-3-years/
6¡¢Unit42Ðû²¼¹ØÓÚ¶à¸öÒøÐÐľÂíʹÓõÄÊÖÒյįÊÎö±¨¸æ
Unit42ÔÚ10ÔÂ31ÈÕÐû²¼Á˹ØÓÚÒøÐÐľÂíÊÖÒյįÊÎö±¨¸æ¡£¡£¡£¡£¡£ÓÉÓÚ¹¥»÷ÕßһֱʹÓÃеÄÊÖÒÕÀ´Èƹý¼ì²âºÍÖ´Ðй¥»÷£¬£¬£¬£¬£¬£¬£¬Ñо¿³öÓÚ¾¼ÃÄ¿µÄµÄ¶ñÒâÈí¼þ¿ÉÒÔ×ÊÖú·ÀÓùÕ߸üÓÐÓõر£»£»£»£»£»£»£»£»¤×éÖ¯¡£¡£¡£¡£¡£¸Ã±¨¸æÆÊÎöÁËÖøÃûµÄÒøÐÐľÂíÓÃÀ´Èƹý¼ì²â¡¢ÇÔÈ¡Ãô¸ÐÊý¾ÝºÍÐÞ¸ÄÊý¾ÝµÄÊÖÒÕ£¬£¬£¬£¬£¬£¬£¬»¹½«ÐÎòÔõÑù·ÀÓùÕâЩÊÖÒÕ£¬£¬£¬£¬£¬£¬£¬Éæ¼°Zeus¡¢Kronos¡¢Trickbot¡¢IcedID¡¢EmotetºÍDridex¡£¡£¡£¡£¡£ÒøÐÐľÂíʹÓõÄÊÖÒÕ°üÀ¨Webinject¡¢Named Pipe¡¢Heaven's Gate¡¢AtomBombing¡¢HookingºÍPE InjectionµÈ¡£¡£¡£¡£¡£
https://unit42.paloaltonetworks.com/banking-trojan-techniques/


¾©¹«Íø°²±¸11010802024551ºÅ