GoogleÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ChromeÖеĶà¸öÎó²î

Ðû²¼Ê±¼ä 2022-12-01
1¡¢GoogleÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ChromeÖеĶà¸öÎó²î

11ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬GoogleÐû²¼ChromeÇå¾²¸üУ¬£¬£¬£¬£¬£¬×ܼÆÐÞ¸´ÁË28¸öÎó²î¡£¡£¡£¡£ ¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇV8ÖеÄÀàÐÍ»ìÏýÎó²î£¨CVE-2022-4174£©¡¢Camera CaptureÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2022-4175£©¡¢Lacros GraphicsÖеÄÔ½½çдÈëÎó²î£¨CVE-2022-4176£©¡¢À©Õ¹ÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2022-4177£©ÒÔ¼°MojoÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2022-4178£©µÈ¡£¡£¡£¡£ ¡£¡£GoogleÌåÏÖ£¬£¬£¬£¬£¬£¬ÏÖÔÚûÓйØÓÚÕâЩÎó²îÔÚÒ°ÍⱻʹÓõı¨¸æ¡£¡£¡£¡£ ¡£¡£

https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_29.html

2¡¢Lastpass͸¶ÆäÔÆ´æ´¢Ð§ÀÍÖеĿͻ§Êý¾ÝÒѾ­Ð¹Â¶

LastPassÔÚ11ÔÂ30ÈÕÐû²¼ÉùÃ÷³Æ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÔÚ2022Äê8ÔµĹ¥»÷ÊÂÎñÖÐÇÔÈ¡µÄÐÅÏ¢ÈëÇÖÁËÆäÔÆ´æ´¢Ð§ÀÍ¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾ÔÚÆäµÚÈý·½Ôƴ洢ЧÀÍÖмì²âµ½Òì³£»£»£»£»£»£»î¶¯£¬£¬£¬£¬£¬£¬Ò»µ©ÀֳɽøÈë¹¥»÷Õß»¹Ïë·¨»á¼û´æ´¢Ôڴ洢ЧÀÍÖеĿͻ§Êý¾Ý¡£¡£¡£¡£ ¡£¡£LastpassÔö²¹ÌåÏÖ£¬£¬£¬£¬£¬£¬ËûÃÇÕýÔÚÆð¾¢Ïàʶ¸ÃÊÂÎñµÄÓ°Ïì¹æÄ££¬£¬£¬£¬£¬£¬²¢È·¶¨ºÚ¿Í»á¼ûÁËÄÄЩÐÅÏ¢¡£¡£¡£¡£ ¡£¡£ÕâÊÇLastpassÔÚ½ñÄêÅû¶µÄµÚ¶þÆðÇå¾²ÊÂÎñ£¬£¬£¬£¬£¬£¬´Ëǰ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ8ÔÂÈ·ÈÏÆä¿ª·¢ÕßÇéÐÎÒò¿ª·¢ÕßÕË»§±»µÁ¶øÔâµ½ÈëÇÖ¡£¡£¡£¡£ ¡£¡£

https://www.bleepingcomputer.com/news/security/lastpass-says-hackers-accessed-customer-data-in-new-breach/

3¡¢Mandiant·¢Ã÷ʹÓÃUSB×°±¸¹¥»÷·ÆÂɱö×éÖ¯µÄ»î¶¯

¾ÝMandiant 11ÔÂ28ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬½üÆÚ·¢Ã÷ÁËʹÓÃUSB×°±¸×÷Ϊ³õʼѬȾǰÑÔµÄÌØ¹¤»î¶¯£¬£¬£¬£¬£¬£¬²¢¼¯ÖÐÔÚ·ÆÂɱö¡£¡£¡£¡£ ¡£¡£Mandiant½«´Ë»î¶¯¸ú×ÙΪUNC4191£¬£¬£¬£¬£¬£¬×îÔç¿É×·Ëݵ½2021Äê9Ô£¬£¬£¬£¬£¬£¬¸Ã»î¶¯Ö÷ÒªÓ°ÏìÁ˶«ÄÏÑǵÄ×éÖ¯£¬£¬£¬£¬£¬£¬²¢ÑÓÉìµ½ÁËÃÀ¹ú¡¢Å·ÖÞºÍÑÇÌ«µØÇø¡£¡£¡£¡£ ¡£¡£×ÝȻĿµÄ×é֯λÓÚÆäËûλÖ㬣¬£¬£¬£¬£¬UNC4191ËùÕë¶ÔµÄϵͳÏÖʵλÓÚ·ÆÂɱö¡£¡£¡£¡£ ¡£¡£ÔÚͨ¹ýUSB×°±¸¾ÙÐгõʼѬȾºó£¬£¬£¬£¬£¬£¬¹¥»÷Õß»áʹÓÃÕýµ±Ç©ÊðµÄ¶þ½øÖÆÎļþÀ´²à¼ÓÔØ3¸öеĶñÒâÈí¼þϵÁУ¬£¬£¬£¬£¬£¬MISTCLOAK¡¢DARKDEWºÍBLUEHAZE¡£¡£¡£¡£ ¡£¡£ÀÖ³ÉÈëÇÖºó»á×°ÖÃÖØÃüÃûµÄNCAT¶þ½øÖÆÎļþ²¢ÔÚÄ¿µÄϵͳÉÏÖ´Ðз´Ïòshell£¬£¬£¬£¬£¬£¬´Ó¶øÎª¹¥»÷ÕßÌṩºóÃÅ»á¼û¡£¡£¡£¡£ ¡£¡£

https://www.mandiant.com/resources/blog/china-nexus-espionage-southeast-asia

4¡¢Ò˼ÒÕýÔÚÊÓ²ìÕë¶ÔÆä¿ÆÍþÌØºÍĦÂå¸çÃŵêµÄÍøÂç¹¥»÷

¾Ý11ÔÂ29ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬Ò˼ÒÕýÔÚÊÓ²ìÕë¶ÔÆä¿ÆÍþÌØºÍĦÂå¸çÃŵêµÄ¹¥»÷ÊÂÎñ¡£¡£¡£¡£ ¡£¡£ÖÜÒ»£¬£¬£¬£¬£¬£¬¿ÆÍþÌØºÍĦÂå¸çµÄÍøµã±»Ìí¼Óµ½Vice SocietyÀÕË÷Èí¼þµÄÍøÕ¾£¬£¬£¬£¬£¬£¬ÍøÕ¾ÉϹûÕæµÄÎļþÃûÅú×¢¹¥»÷ÕßÒÑÇÔȡӪҵºÍÔ±¹¤µÄÊý¾Ý£¬£¬£¬£¬£¬£¬²¢¿ÉÄÜ»¹´ÓÔ¼µ©µÄÒ˼ÒÃŵêÇÔÈ¡ÁËÆäËüÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¹«Ë¾½²»°ÈËÌåÏÖËûÃÇÕýÔÚÓëÏà¹ØÕþ¸®ºÍÍøÂçÇå¾²ÏàÖúͬ°éÒ»ÆðÊÓ²ì´ËÊÂÎñ¡£¡£¡£¡£ ¡£¡£²îδ¼¸Ò»Äêǰ£¬£¬£¬£¬£¬£¬Ò˼ÒÔøÃæÁÙÕë¶ÔÔ±¹¤ÄÚ²¿ÓÊÏäµÄ´¹ÂÚ¹¥»÷»î¶¯¡£¡£¡£¡£ ¡£¡£

https://therecord.media/ikea-investigating-cyberattacks-on-outlets-in-kuwait-morocco/

5¡¢ÐÂÀÕË÷Èí¼þPunisherαװ³ÉCOVID-19¸ú×ÙÓ¦Ó÷ַ¢

¾ÝýÌå11ÔÂ29ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖÐÂÀÕË÷Èí¼þPunisher±äÌ壬£¬£¬£¬£¬£¬Í¨¹ýÍйÜÔÚcovid19[.]digitalhealthconsulting[.]clÉϵĻùÓÚCOVID-19Ö÷ÌâµÄ´¹ÂÚÍøÕ¾¾ÙÐÐÈö²¥¡£¡£¡£¡£ ¡£¡£Õâ¸öÍøÕ¾ÌṩαÔìµÄCOVID-19¸ú×ÙÓ¦Ó㬣¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÖÇÀû¡£¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±ÒÔΪ£¬£¬£¬£¬£¬£¬´Ë´Î»î¶¯Õë¶ÔµÄÊÇСÎÒ˽¼Ò¶ø·ÇÆóÒµ£¬£¬£¬£¬£¬£¬ËüÀÕË÷¼ÛÖµ1000ÃÀÔªµÄ±ÈÌØ±ÒÀ´½âÃÜÎļþ¡£¡£¡£¡£ ¡£¡£±»ÕâÖÖÀÕË÷Èí¼þ¼ÓÃܵÄÎļþÒ²ºÜÈÝÒ×±»½âÃÜ£¬£¬£¬£¬£¬£¬ÓÉÓÚËüʹÓÃAES-128¶Ô³ÆËã·¨¾ÙÐмÓÃÜ¡£¡£¡£¡£ ¡£¡£

https://www.hackread.com/covid-19-app-punisher-ransomware/

6¡¢È«Ó¡¶Èҽѧ¿ÆÑ§Ñо¿ËùAIIMS±»¹¥»÷ϵͳ崻ú6Ìì

ýÌå11ÔÂ29Èճƣ¬£¬£¬£¬£¬£¬Î»ÓÚµÂÀïµÄȫӡ¶Èҽѧ¿ÆÑ§Ñо¿Ëù(AIIMS) Ôâµ½¹¥»÷ºó£¬£¬£¬£¬£¬£¬ÆäϵͳÒÑÒ»Á¬å´»ú6Ìì¡£¡£¡£¡£ ¡£¡£¾Ý³Æ£¬£¬£¬£¬£¬£¬ºÚ¿ÍÀÕË÷ԼĪ20ÒÚ¬±ÈµÄ¼ÓÃÜÇ®±Ò£¬£¬£¬£¬£¬£¬µ«µÂÀᆵ·½·ñ¶¨AIIMS±¨¸æÊÕµ½¹ýÈκδËÀàÒªÇ󡣡£¡£¡£ ¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬¿ÉÄÜÒѾ­Ð¹Â¶ÁË3-4ÍòÍò»¼ÕßµÄÊý¾Ý¡£¡£¡£¡£ ¡£¡£ÓÉÓÚЧÀÍÆ÷´¦ÓÚÍ£»£»£»£»£»£»ú״̬£¬£¬£¬£¬£¬£¬¼±Õï¡¢ÃÅÕסԺºÍ»¯ÑéÊҵϼÕßÕչ˻¤Ê¿Ð§À;ùÓÉÈ˹¤ÖÎÀí¡£¡£¡£¡£ ¡£¡£µÂÀᆵ·½¡¢ÄÚÕþ²¿ºÍÓ¡¶ÈÅÌËã»úÓ¦¼±ÏìӦС×é(CERT-IN)ÕýÔÚÊÓ²ì´ËÀÕË÷¹¥»÷ÊÂÎñ¡£¡£¡£¡£ ¡£¡£

https://www.businesstoday.in/latest/in-focus/story/cyber-attack-at-aiims-delhi-hackers-demand-rs-200-cr-in-crypto-says-report-354475-2022-11-28