GoogleÐû²¼12Ô·ݵÄAndroid¸üÐÂ×ܼÆÐÞ¸´81¸öÎó²î

Ðû²¼Ê±¼ä 2022-12-08
1¡¢GoogleÐû²¼12Ô·ݵÄAndroid¸üÐÂ×ܼÆÐÞ¸´81¸öÎó²î

12ÔÂ5ÈÕ£¬£¬£¬ £¬£¬£¬GoogleÐû²¼ÁËAndroid 12Ô·ݵÄÇå¾²¸üУ¬£¬£¬ £¬£¬£¬×ܼÆÐÞ¸´81¸öÎó²î¡£¡£¡£¡£¡£¡£ ¡£ÆäÖнÏΪÑÏÖØµÄÊÇAndroid FrameworkÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2022-20472ºÍCVE-2022-20473£©¡¢Android ϵͳÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2022-20411£©ºÍAndroid ϵͳÖеÄÐÅϢй¶Îó²î£¨CVE-2022-20498£©¡£¡£¡£¡£¡£¡£ ¡£ÆäÓàÒÑÐÞ¸´µÄÎó²îÉæ¼°È¨ÏÞÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐС¢ÐÅϢй¶ºÍ¾Ü¾øÐ§À͵ÈÎÊÌâ¡£¡£¡£¡£¡£¡£ ¡£

https://source.android.com/docs/security/bulletin/2022-12-01

2¡¢Ó¡¶ÈÇå¾²¹«Ë¾CloudSEK³ÆÔâµ½ÁíÒ»¼ÒÇå¾²¹«Ë¾µÄ¹¥»÷

¾ÝýÌå12ÔÂ7ÈÕ±¨µÀ£¬£¬£¬ £¬£¬£¬Ó¡¶ÈÍøÂçÇå¾²¹«Ë¾CloudSEK³Æ£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßʹÓÃÆäÔ±¹¤JiraÕË»§µÄ±»µÁƾ֤»á¼ûÁËÆäConfluenceЧÀÍÆ÷£¬£¬£¬ £¬£¬£¬²¿·ÖÐÅϢй¶¡£¡£¡£¡£¡£¡£ ¡£ºÚ¿ÍsedutÏÖÕýÔÚ¶à¸öÂÛ̳ÉϳöÊÛ¶ÔCloudSekÍøÂç¡¢Xvigil¡¢´úÂë¿â¡¢µç×ÓÓʼþ¡¢JIRAºÍÉ罻ýÌåÕË»§µÄ»á¼ûȨÏÞ£¬£¬£¬ £¬£¬£¬²¢ÒÔ10000ÃÀÔª¼ÛÇ®³öÊÛCloudSEKÊý¾Ý¿â£¬£¬£¬ £¬£¬£¬ÒÔÿ¸ö8000ÃÀÔªµÄ¼ÛÇ®³öÊÛ´úÂë¿â¡¢Ô±¹¤ºÍ¹¤³Ì²úÆ·Îĵµ¡£¡£¡£¡£¡£¡£ ¡£CloudSEKÒÑËø¶¨ÏÓÒÉÈ˹æÄ££¬£¬£¬ £¬£¬£¬Æ¾Ö¤SasiÐû²¼µÄÎÄÕ£¬£¬£¬ £¬£¬£¬ËûÃÇÏÓÒÉÒ»¼Ò¾ÙÐаµÍø¼à¿ØµÄÇå¾²¹«Ë¾ÊÇÄ»ºóºÚÊÖ£¬£¬£¬ £¬£¬£¬µ«¾Ü¾øÌṩÓйظù«Ë¾µÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£

https://www.bleepingcomputer.com/news/security/cloudsek-claims-it-was-hacked-by-another-cybersecurity-firm/

3¡¢Òò¹©Ó¦É̱»¹¥»÷±ÈÀûʱ°²ÌØÎÀÆÕÊеÄÊÐÕþϵͳ̱»¾

ýÌå12ÔÂ6Èճƣ¬£¬£¬ £¬£¬£¬Îª±ÈÀûʱ°²ÌØÎÀÆÕÊÐÌṩÖÎÀíÈí¼þµÄÏàÖúͬ°éDigipolisÔâµ½¹¥»÷£¬£¬£¬ £¬£¬£¬¸ÃÊеÄÊÐÕþϵͳ̱»¾¡£¡£¡£¡£¡£¡£ ¡£¾ÝϤ£¬£¬£¬ £¬£¬£¬²¿·Öµç»°Ð§ÀÍÎÞ·¨Ê¹Ó㬣¬£¬ £¬£¬£¬µç×ÓÓʼþЧÀÍÒ²·ºÆð¹ÊÕÏ£¬£¬£¬ £¬£¬£¬Ô¤¶©ÏµÍ³Ò²±»¹Ø±Õµ¼ÖÂסÃñÎÞ·¨ÁìÈ¡Éí·ÝÖ¤£¬£¬£¬ £¬£¬£¬¾¯Ô±ºÍÏû·À²¿·ÖÒ²Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£ ¡£ÊÓ²ìÕýÔÚ¾ÙÐÐÖУ¬£¬£¬ £¬£¬£¬ÉÙÁ¿¿ÉÓõÄÐÅÏ¢Åú×¢ÕâÊÇÒ»´ÎÀÕË÷¹¥»÷£¬£¬£¬ £¬£¬£¬µ«¹¥»÷ÕßÉí·ÝÉÐδÅû¶¡£¡£¡£¡£¡£¡£ ¡£ÏÖÔÚ»¹²»ÇåÎú°²ÌØÎÀÆÕµÄϵͳºÎʱ²Å»ª»Ö¸´Õý³£ÔËÐУ¬£¬£¬ £¬£¬£¬¸ÃÊÐÊг¤ÌåÏÖ£¬£¬£¬ £¬£¬£¬Ó°Ïì¿ÉÄÜ»áÒ»Á¬µ½12ÔÂβ¡£¡£¡£¡£¡£¡£ ¡£

https://www.bleepingcomputer.com/news/security/antwerps-city-services-down-after-hackers-attack-digital-partner/

4¡¢Î¢ÈíÅû¶DEV-0139Õë¶Ô¼ÓÃÜÇ®±ÒµÄ¹¥»÷»î¶¯ÏêÇé


΢ÈíÔÚ12ÔÂ6ÈÕÅû¶ÁËDEV-0139ʹÓÃTelegram̸Ìì×éÕë¶Ô¼ÓÃÜÇ®±ÒͶ×ʹ«Ë¾µÄÏêÇé¡£¡£¡£¡£¡£¡£ ¡£¹¥»÷ÕßÊ×ÏȼÓÈëÁËÔö½øVIP¿Í»§ºÍ¼ÓÃÜÇ®±ÒÉúÒâÆ½Ì¨Ö®¼ä½»Á÷µÄTelegramȺ£¬£¬£¬ £¬£¬£¬²¢´Ó³ÉÔ±ÖÐÈ·¶¨¹¥»÷µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£ ¡£È»ºóð³äÁíÒ»¼Ò¼ÓÃÜÇ®±ÒͶ×ʹ«Ë¾£¬£¬£¬ £¬£¬£¬ÓÚ2022Äê10ÔÂÔ¼ÇëÄ¿µÄ¼ÓÈëÁíÒ»¸ö̸Ìì×飬£¬£¬ £¬£¬£¬ÒªÇóËûÃǼÓÃÜÇ®±ÒÉúÒâÆ½Ì¨µÄÓöȽṹÌṩ·´Ïì¡£¡£¡£¡£¡£¡£ ¡£ÔÚ»ñµÃÄ¿µÄµÄÐÅÈκ󣬣¬£¬ £¬£¬£¬¹¥»÷Õ߻ᷢËͶñÒâExcel±í¸ñ¡£¡£¡£¡£¡£¡£ ¡£Ä¿µÄ·­¿ªÎĵµ²¢ÆôÓúêºó£¬£¬£¬ £¬£¬£¬»á×°ÖÃÒ»¸ö¶ñÒâDLL¡¢XOR±àÂëºóÃż°ÓÃÓÚ²à¼ÓÔØDLLµÄWindows¿ÉÖ´ÐÐÎļþ¡£¡£¡£¡£¡£¡£ ¡£


https://www.microsoft.com/en-us/security/blog/2022/12/06/dev-0139-launches-targeted-attacks-against-the-cryptocurrency-industry/

5¡¢Unit 42Ðû²¼Vice SocietyÖ÷ÒªÕë¶Ô½ÌÓýÐÐÒµµÄÆÊÎö±¨¸æ

Unit 42ÔÚ12ÔÂ6ÈÕÐû²¼Á˹ØÓÚVice SocietyÖ÷ÒªÕë¶Ô½ÌÓýÐÐÒµµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£ ¡£×Ô2021Äê×îÏÈÔËÓªÒÔÀ´£¬£¬£¬ £¬£¬£¬Vice Society×ܹ²Ó°ÏìÁË100¶à¸ö×éÖ¯¡£¡£¡£¡£¡£¡£ ¡£Êý¾ÝÅú×¢£¬£¬£¬ £¬£¬£¬½ñÄêVice Society¶Ô½ÌÓýÐÐÒµ×éÖ¯µÄÓ°Ïì×î´ó£¬£¬£¬ £¬£¬£¬ÆäÍøÕ¾ÉÏÁгöÁËÖÁÉÙ33¼Ò±»Ñ¬È¾µÄ½ÌÓý»ú¹¹¡£¡£¡£¡£¡£¡£ ¡£¿ÉÊdzýÁ˽ÌÓý×éÖ¯£¬£¬£¬ £¬£¬£¬¹¥»÷ÍÅ»ïÒ²Õë¶ÔÒªº¦µÄ»ù´¡ÉèÊ©ÐÐÒµ£¬£¬£¬ £¬£¬£¬ÈçÒ½ÁƱ£½¡¡¢Õþ¸®»ú¹¹ºÍÖÆÔìÐÐÒµµÈ¡£¡£¡£¡£¡£¡£ ¡£¸ÃÍÅ»ïѬȾµÄ×éÖ¯±é²¼¸÷¸öµØÇø£¬£¬£¬ £¬£¬£¬ÆäÖÐÃÀ¹úѬȾÈËÊý×î¶à£¬£¬£¬ £¬£¬£¬Æä´ÎÊÇÓ¢¹ú¡¢Î÷°àÑÀºÍ·¨¹úµÈ¡£¡£¡£¡£¡£¡£ ¡£

https://unit42.paloaltonetworks.com/vice-society-targets-education-sector/

6¡¢FortinetÐû²¼¹ØÓÚн©Ê¬ÍøÂçZerobotµÄÆÊÎö±¨¸æ

12ÔÂ6ÈÕ£¬£¬£¬ £¬£¬£¬FortinetÐû²¼ÁËÐÂÐÍ»ùÓÚGoµÄ½©Ê¬ÍøÂçZerobotµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£ ¡£Zerobot¿ÉÒÔɨÃèÍøÂç²¢×ÔÎÒÈö²¥µ½ÏàÁÚ×°±¸£¬£¬£¬ £¬£¬£¬ÒÔ¼°ÔÚWindows(CMD)»òLinux(Bash)ÉÏÔËÐÐÏÂÁî¡£¡£¡£¡£¡£¡£ ¡£ËüÕûºÏÁË21¸öÎó²î£¬£¬£¬ £¬£¬£¬ÆäÖÐÉæ¼°F5 BIG-IP¡¢Zyxel·À»ðǽ¡¢Totolink·ÓÉÆ÷¡¢D-Link·ÓÉÆ÷ÒÔ¼°HikvisionÉãÏñÍ·µÈ£¬£¬£¬ £¬£¬£¬À´»ñȡװ±¸µÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£ ¡£ÔÚÄ¿µÄÖÐפ×ãºó£¬£¬£¬ £¬£¬£¬Zerobot»áÉèÖõ½C2ЧÀÍÆ÷µÄWebSocketÅþÁ¬£¬£¬£¬ £¬£¬£¬²¢·¢ËÍÓйØÄ¿µÄµÄ»ù±¾ÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£ÏÖÔÚ£¬£¬£¬ £¬£¬£¬ZerobotÖ÷ÒªÓÃÓÚÖ´ÐÐDDoS¹¥»÷£¬£¬£¬ £¬£¬£¬¿ÉÊÇËüÒ²¿ÉÒÔÓÃ×÷³õʼ»á¼û¡£¡£¡£¡£¡£¡£ ¡£

https://www.fortinet.com/blog/threat-research/zerobot-new-go-based-botnet-campaign-targets-multiple-vulnerabilities