Ó¢ÌØ¶ûÈ·ÈÏAlder Lake CPUµÄUEFI BIOSÔ´´úÂë×ß©

Ðû²¼Ê±¼ä 2022-10-10
1¡¢Ó¢ÌضûÈ·ÈÏAlder Lake CPUµÄUEFI BIOSÔ´´úÂë×ß©

      

¾ÝýÌå10ÔÂ9ÈÕ±¨µÀ £¬£¬£¬£¬£¬£¬Ó¢ÌضûÒѾ­Ö¤Êµ £¬£¬£¬£¬£¬£¬Alder Lake cpuµÄUEFI BIOSÔ´´úÂëй¶¡£¡£¡£¡£ ¡£¡£¡£¡£Alder LakeÊǵÚ12´úÓ¢ÌØ¶û¿á¦Öóͷ£Æ÷ £¬£¬£¬£¬£¬£¬ÓÚ2021Äê11ÔÂÐû²¼¡£¡£¡£¡£ ¡£¡£¡£¡£ÉÏÖÜÎå £¬£¬£¬£¬£¬£¬TwitterÓû§freakÐû²¼Á˾ݳÆÊÇAlder LakeµÄUEFI¹Ì¼þÔ´´úÂëµÄÁ´½Ó £¬£¬£¬£¬£¬£¬¸ÃÁ´½ÓÖ¸ÏòGitHub´æ´¢¿âICE_TEA_BIOS £¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨5.97 GBµÄÎļþ¡¢Ô´´úÂ롢˽Կ¡¢¸üËûÈÕÖ¾ºÍ±àÒ빤¾ß¡£¡£¡£¡£ ¡£¡£¡£¡£ÎļþµÄ×îÐÂʱ¼ä´ÁΪ22Äê9ÔÂ30ÈÕ £¬£¬£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎúÔ´´úÂëÊÇÔÚÍøÂç¹¥»÷ʱ´ú±»µÁÕվɱ»ÄÚ²¿Ö°Ô±Ð¹Â¶¡£¡£¡£¡£ ¡£¡£¡£¡£²»¹ý £¬£¬£¬£¬£¬£¬Ó¢ÌضûÒÑÈ·ÈÏÔ´´úÂëÊÇÕæÊµµÄ £¬£¬£¬£¬£¬£¬ÊÇËüµÄרÓÐUEFI´úÂë¡£¡£¡£¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/intel-confirms-leaked-alder-lake-bios-source-code-is-authentic/


2¡¢Ó¢¹úEasylifeÎ¥·´Êý¾Ý±£»£»£»£»¤ºÍÓªÏú·¨±»·£¿£¿£¿ £¿£¿£¿î150ÍòÓ¢°÷

      

10ÔÂ6ÈÕ±¨µÀ³Æ £¬£¬£¬£¬£¬£¬Ó¢¹úÁãÊÛÉÌEasylifeÒòÎ¥·´Êý¾Ý±£»£»£»£»¤ºÍÓªÏú·¨¶ø±»¸Ã¹úµÄÐÅÏ¢î¿Ïµ»ú¹¹·£¿£¿£¿ £¿£¿£¿î½ü150ÍòÓ¢°÷¡£¡£¡£¡£ ¡£¡£¡£¡£ÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©ÌåÏÖ £¬£¬£¬£¬£¬£¬EasylifeÔÚδ¾­¿Í»§Ô޳ɵÄÇéÐÎÏÂʹÓÃÆäСÎÒ˽¼ÒÐÅÏ¢ÏòËûÃÇÍÆÏú¿µ½¡Ïà¹Ø²úÆ· £¬£¬£¬£¬£¬£¬¶øÕâÖÖ¡°ÒþÐΡ±Êý¾Ý´¦Öóͷ£ÊDz»·¨µÄ¡£¡£¡£¡£ ¡£¡£¡£¡£î¿Ïµ»ú¹¹µÄÁíÒ»ÏîÊӲ췢Ã÷ £¬£¬£¬£¬£¬£¬ÔÚ2019Äê8ÔÂÖÁ2020Äê8ÔÂʱ´ú £¬£¬£¬£¬£¬£¬EasylifeÏòÔڵ绰ƫºÃЧÀÍ(TPS)×¢²áµÄÈ˲¦´òÁËÁè¼Ý130Íò´ÎÀ¬»øÓªÏúµç»°¡£¡£¡£¡£ ¡£¡£¡£¡£ICOÒòÎ¥·´Êý¾Ý±£»£»£»£»¤·¨¶ÔEasylife·£¿£¿£¿ £¿£¿£¿î135ÍòÓ¢°÷ £¬£¬£¬£¬£¬£¬ÒòÓªÏúµç»°·£¿£¿£¿ £¿£¿£¿î13ÍòÓ¢°÷¡£¡£¡£¡£ ¡£¡£¡£¡£


https://www.infosecurity-magazine.com/news/retailer-easylife-fined-15m-data/


3¡¢SynopsysÑо¿Ö°Ô±Åû¶Ò˼ÒÖÇÄÜÕÕÃ÷ϵͳÖеÄ2¸öÎó²î

      

ýÌå10ÔÂ7ÈÕ±¨µÀ³Æ £¬£¬£¬£¬£¬£¬SynopsysÑо¿Ö°Ô±·¢Ã÷Ò˼ÒÖÇÄÜÕÕÃ÷ϵͳÖб£´æ2¸öÎó²î¡£¡£¡£¡£ ¡£¡£¡£¡£ÆäÖÐÒ»¸öÎó²î×·×ÙΪCVE-2022-39064 £¬£¬£¬£¬£¬£¬¿É±»¹¥»÷ÕßÓÃÀ´Í¨¹ýЭÒé·¢ËͶñÒâ֡ʹÒ˼ҵÄTR?DFRIµÆµ¨ÉÁׯ £¬£¬£¬£¬£¬£¬ÈôÊǶà´ÎÖØ¸´·¢ËͶñÒâÐÂÎÅ £¬£¬£¬£¬£¬£¬µÆµ¨»áÖ´Ðгö³§ÖØÖà £¬£¬£¬£¬£¬£¬Ö®ºóÓû§ÎÞ·¨Í¨¹ýÒ˼ÒÖÇÄܼҾÓÓ¦ÓûòTR?DFRIÒ£¿£¿£¿ £¿£¿£¿ØÆ÷¿ØÖƵƵ¨¡£¡£¡£¡£ ¡£¡£¡£¡£ÁíÒ»¸öÎó²îΪCVE-2022-39065 £¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂTR?DFRI¶Ô×°±¸Ò£¿£¿£¿ £¿£¿£¿ØÆ÷ºÍÒ˼ÒÖÇÄܼҾÓÓ¦ÓÃûÓÐÏìÓ¦¡£¡£¡£¡£ ¡£¡£¡£¡£ 


https://therecord.media/researchers-find-bugs-in-ikea-smart-lighting-system/


4¡¢Ó¢¹ú°ü¹ÜÉúÒâËùÀͺÏÉç½«ÖØÆôϵͳÒÔÓ¦¶Ô½üÆÚµÄ¹¥»÷ÊÂÎñ

      

¾Ý10ÔÂ7ÈÕ±¨µÀ £¬£¬£¬£¬£¬£¬Ó¢¹ú°ü¹ÜÉúÒâËùÀͺÏÉ磨Lloyd¡¯s of London£©Í¨¹ýÖØÆôÆäϵͳÀ´Ó¦¶Ô¿ÉÄܵÄÍøÂç¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£¡£Lloyd'sÔÚÆäÍøÂçÉϼì²âµ½ÁËÒì³£»£»£»£»î¶¯ £¬£¬£¬£¬£¬£¬²¢ÕýÔÚÊÓ²ì¸ÃÎÊÌâ¡£¡£¡£¡£ ¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬Ëü»¹ÖØÖÃÁËÍøÂçºÍϵͳ £¬£¬£¬£¬£¬£¬²¢¹Ø±ÕÁËÍⲿÅþÁ¬ £¬£¬£¬£¬£¬£¬°üÀ¨LloydµÄÊÚȨƽ̨¡£¡£¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ £¬£¬£¬£¬£¬£¬ËûÃÇÒÑ֪ͨÊг¡¼ÓÈëÕߺÍÏà¹Ø¸÷·½ £¬£¬£¬£¬£¬£¬Ò»µ©ÊӲ쿢Ê £¬£¬£¬£¬£¬£¬½«»áÌṩ¸ü¶àÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾²¢Î´¹ûÕæ¹¥»÷ϸ½Ú £¬£¬£¬£¬£¬£¬µ«Õë¶Ô¸ÃÊÂÎñ½ÓÄɵIJ½·¥Åú×¢Õâ¿ÉÄÜÊÇÀÕË÷¹¥»÷¡£¡£¡£¡£ ¡£¡£¡£¡£


https://www.databreaches.net/lloyds-of-london-reboots-its-network/


5¡¢BlackByteʹÓÃWindowsÇý¶¯³ÌÐòÖеÄÎó²îÈÆ¹ý¼ì²â

      

SophosÔÚ10ÔÂ4ÈÕ³ÆÆä·¢Ã÷ÁËBlackByteÔËÓªÍÅ»ïÕýÔÚʹÓõÄ×Ô´øÒ×Êܹ¥»÷µÄÇý¶¯³ÌÐò(BYOVD)¹¥»÷À´ÈƹýÇå¾²²úÆ·¡£¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÁËÕýµ±µÄÇý¶¯³ÌÐòRTCore64.sysÖеÄÎó²î£¨CVE-2019-16098£© £¬£¬£¬£¬£¬£¬¸ÃÎó²î¿É±»¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÃÓÚ¶ÁÈ¡ºÍдÈëí§ÒâÄÚ´æ £¬£¬£¬£¬£¬£¬²¢µ¼ÖÂȨÏÞÌáÉý¡¢´úÂëÖ´ÐлòÐÅϢй¶¡£¡£¡£¡£ ¡£¡£¡£¡£¸ÃÈÆ¹ýÊÖÒտɽûÓÃÁè¼Ý1000¸öÇý¶¯³ÌÐò £¬£¬£¬£¬£¬£¬Çå¾²²úÆ·ÒÀÀµÕâЩÇý¶¯³ÌÐòÀ´Ìṩ±£»£»£»£»¤¡£¡£¡£¡£ ¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬¶ÔÀÕË÷Èí¼þÑù±¾µÄÆÊÎö·¢Ã÷ËüÓ뿪Դ¹¤¾ßEDRSandblastʹÓõÄEDRÈÆ¹ýʵÏÖÓÐÐí¶àÏàËÆÖ®´¦¡£¡£¡£¡£ ¡£¡£¡£¡£


https://news.sophos.com/en-us/2022/10/04/blackbyte-ransomware-returns/


6¡¢Zscaler³ÆÐ¶ñÒâÈí¼þLilithBotÓëEternityÍÅ»ïÓйØ

      

10ÔÂ5ÈÕ £¬£¬£¬£¬£¬£¬ZscalerÅû¶ÁËжñÒâÈí¼þLilithBotÓëEternityÍÅ»ïÖ®¼äµÄ¹ØÏµ¡£¡£¡£¡£ ¡£¡£¡£¡£EternityÔËÓª×ÅÒ»¸öͬÃûµÄ¶ñÒâÈí¼þ¼´Ð§ÀÍ(MaaS) £¬£¬£¬£¬£¬£¬Óë¶íÂÞ˹Jester GroupÓйØ¡£¡£¡£¡£ ¡£¡£¡£¡£LilithBotÓÉEternityͨ¹ýרÓõÄTelegram channel·Ö·¢ £¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýTor¾ÙÐйºÖᣡ£¡£¡£ ¡£¡£¡£¡£Ëü¾ßÓи߼¶¹¦Ð§ £¬£¬£¬£¬£¬£¬¿ÉÓÃ×÷miner¡¢stealerºÍclipper¡£¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÌí¼Óй¦Ð§£¨°üÀ¨·´µ÷ÊÔ¹¦Ð§ºÍ·´ÐéÄâ»ú¼ì²é£©À´Ò»Ö±ÔöÇ¿¶ñÒâÈí¼þ¡£¡£¡£¡£ ¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹ÌṩÁ˹¥»÷Ïà¹ØµÄIOCÒÔ¼°MITRE ATT&CKÊÖÒÕϸ½Ú¡£¡£¡£¡£ ¡£¡£¡£¡£


https://www.zscaler.com/blogs/security-research/analysis-lilithbot-malware-and-eternity-threat-group