°Ä´óÀûÑǵڶþ´óµçÐŹ«Ë¾Optus½üǧÍòÓû§µÄÐÅϢй¶
°ä²¼¹¦·ò 2022-09-261¡¢°Ä´óÀûÑǵڶþ´óµçÐŹ«Ë¾Optus½üǧÍòÓû§µÄÐÅϢй¶
¾Ý9ÔÂ23ÈÕ±¨Â·£¬°Ä´óÀûÑǵڶþ´óµçÐŹ«Ë¾OptusÔâµ½¹¥»÷£¬¿ÉÄÜÓ°Ïì¶à´ï900Íò¸öÓû§µÄÊý¾Ý¡£Optus³Æ£¬¹¥»÷ÕßÉè·¨½øÈëÁ˿ͻ§Éí·ÝÊý¾Ý¿â£¬²¢Í¨¹ýÀûÓ÷¨Ê½½Ó¿Ú£¨API£©½«ÆäÊ¢¿ª¸øÆäËûϵͳ¡£ÊÂÎñÈÔÔÚµ÷²éÖУ¬OptusÒÔΪÆäÖÐÒ»¸öÍøÂ类¶³öÔÚÁËÒ»¸öÓл¥ÁªÍø½ÓÈëµÄ²âÊÔÍøÂçÖС£¸Ã¹«Ë¾Òɻ󹥻÷ÕßÒѾÇÔÈ¡ÁËÏû·ÑÕßµÄÊý¾Ý¿â£¬²¢¿ÉÄܸ´ÔìÁËÆäÖеÄÈý·ÖÖ®Ò»¡£Optus°µÊ¾ËüÔÚ·¢ÏÖ¹¥»÷ºóµ±¼´²ÉÈ¡ÁË´ëÊ©£¬µ«ÊÇûÓÐй©¹ØÓÚ¹¥»÷µÄ¾ßÌåÄÚÈÝ¡£
https://www.hackread.com/optus-data-breach-australia-telecom-firm/
2¡¢Sophos½¨¸´Òѱ»ÀûÓõĴúÂë×¢Èë·ì϶CVE-2022-3236
SophosÔÚ9ÔÂ23ÈÕ½¨¸´ÁËÆä·À»ðǽÖдúÂë×¢Èë·ì϶£¨CVE-2022-3236£©¡£¸Ã·ì϶CVSSÆÀ·ÖΪ9.8£¬Éæ¼°Óû§ÃÅ»§ºÍWebÖÎÀí×é¼þ£¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¸Ã¹«Ë¾°µÊ¾£¬ËüÒѾ¹Û²ìµ½ÀûÓø÷ì϶µÄ¹¥»÷»î¶¯£¬ÖØÒªÊÇÔÚÄÏÑǵØÓò£¬²¢²¹³ä˵ËüÖ±½Ó֪ͨÁËÕâЩ×éÖ¯¡£ÆôÓÃÁËÔÊÐí×Ô¶¯×°Öý¨²¹·¨Ê½Ö°ÄܵÄSophos FirewallÓû§ÎÞÐèÖ´ÐÐÈκβÙ×÷£¬ÇÒÆôÓÃÊÇĬÈÏÉèÖá£SophosÔÚ½ñÄê3Ô»¹½¨¸´ÁËÒ»¸öÀàËÆµÄFirewall·ì϶(CVE-2022-1040)£¬¸Ã·ì϶ҲÔÚÕë¶ÔÄÏÑÇ×éÖ¯µÄ¹¥»÷Öб»ÀûÓá£
https://www.bleepingcomputer.com/news/security/sophos-warns-of-new-firewall-rce-bug-exploited-in-attacks/
3¡¢YouTubeÈ«ÇòÁìÓòÄÚ·þÎñÖжÏÇÒÉв»Ã÷ÏÔÊÂÎñÔÒò
ýÌå9ÔÂ23Èճƣ¬YouTubeÔÚÈ«ÇòÁìÓòÄÚ·þÎñÖжϣ¬³ÉǧÉÏÍòµÄÓû§»ã±¨ËûÃÇÎÞ·¨½Ó¼ûÖ±²¥¡£ÔÚ³¢ÊÔ½Ó¼ûYouTubeʱ£¬Óû§»á¿´µ½´øÓмÓÔØ¶¯»µÄºÚÆÁºÍ¡°ÇëÉÔºóÔÙÊÔ¡±µÄÃýÎóÐÂÎÅ¡£ÄÇЩÉè·¨¼ÓÔØÖ±²¥µÄÓû§³ÆÊÓÆµÖͺó£¬Ì¸ÌìÐÂÎÅÒ²Öͺó»òµ××Ó²»ÏÔʾ¡£»¥ÁªÍø¼à¿Ø×éÖ¯NetBlocksҲ֤ʵ£¬YouTubeÕý¾ÀúÒ»³¡Ó°ÏìÖ±²¥µÄÈ«ÇòÐÔÖжϣ¬´ËÊÂÎñÓë¹ú¶È¼¶»¥ÁªÍøÖжϻò¹ýÂËÎ޹ء£Ä¿Ç°£¬Éв»Ã÷ÏÔÕâÊÇ´òËãÖеÄÊØ»¤»î¶¯¡¢YouTube·þÎñÆ÷µÄÎÊÌ⻹ÊÇÓë¶ñÒâ¹¥»÷Óйء£
https://www.bleepingcomputer.com/news/technology/youtube-down-live-streams-hit-by-worldwide-outage/
4¡¢Anonymous³ÆÒÑÈëÇÖ¶íÂÞ˹¹ú·À²¿ÍøÕ¾²¢¹«¿ª30ÍòÈËÊý¾Ý
AnonymousÓÚ9ÔÂ23ÈÕÔÚÆäTwitterÕË»§Éϰ䲼ÐÂÎÅ£¬³ÆÒѾÈëÇÖÁ˶íÂÞ˹¹ú·À²¿µÄÍøÕ¾¡£¸ÃÍŻﻹй¶ÁË305925È˵ÄÊý¾Ý£¬ÕâЩÈË¿ÉÄÜÊÇÆÕ¾©×Üͳ°ä·¢µÄÈý²¨¾üÊ»´øÍ·ÖеĵÚÒ»²¨Ô¤±¸ÒÛÎäÊ¿¡£¹¥»÷Õßͨ¹ýProtonDrive¹«¿ªÁËÒ»¸ö90MB´óÓ×µÄTXTÎļþ£¬ÆäÖÐÔ̺¬³¬¹ý30ÍòÈ˵ÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µØÓòºÍµØÓò¡£Ä¿Ç°ÎÞ·¨ÑéÖ¤ÕâЩµµ°¸¼òÖ±ÇÐÆðÔ´¡£
https://www.infosecurity-magazine.com/news/russian-reservists-leaked-anonymous/
5¡¢GitHub·¢ÏÖ¼ÙÒâCircleCIƽ̨ÈëÇÔìäÓû§ÕË»§µÄ¹¥»÷»î¶¯
¾ÝýÌå9ÔÂ25ÈÕ±¨Â·£¬GitHubÌáÐÑÕë¶ÔÆäÓû§µÄ´¹µö¹¥»÷»î¶¯£¬Í¨¹ý¼ÙÒâCircleCI DevOpsƽ̨À´ÇÔȡʹ´¦ºÍË«³ÁÉí·ÝÑéÖ¤(2FA)´úÂë¡£¸Ã¹«Ë¾ÓÚ9ÔÂ16ÈÕ»ñϤÕâ´Î¹¥»÷£¬²¢Ö¸³ö³ýGitHub±í£¬´¹µö»î¶¯ÒÑÓ°Ïìµ½ºÜ¶à×éÖ¯¡£´¹µöÐÅÏ¢Ðû³ÆÓû§µÄCircleCI»á»°ÒѹýÆÚ£¬²¢ÊÔͼÓÕʹÊÕ¼þÈËʹÓÃGitHubÍ´´¦µÇ¼¡£ÊÕ¼þÈ˱»³Á¶¨Ïòµ½Î±ÔìµÄGitHubµÇÂ¼Ò³Ãæºó£¬»á±»ÇÔÈ¡ÊäÈëµÄÍ´´¦ºÍ2FA´úÂë¡£¸Ã¹«Ë¾°µÊ¾£¬ÊÜÓ²¼þ°²È«ÃÜÔ¿±£»¤µÄÕË»§²»Ò×Ôâµ½µ½ÕâÖÖ¹¥»÷¡£
https://securityaffairs.co/wordpress/136211/hacking/phishing-circleci-github-accounts.html
6¡¢AhnLab°ä²¼FARGO¹¥»÷MS-SQL·þÎñÆ÷µÄ·ÖÎö»ã±¨
9ÔÂ23ÈÕ£¬AhnLab°ä²¼»ã±¨³ÆÒ×Êܹ¥»÷µÄMicrosoft SQL·þÎñÆ÷Ôâµ½ÁËFARGOµÄÐÂÒ»ÂÖ¹¥»÷¡£FARGOÓëGlobeImposterÒ»Ñù£¬ÊÇÖØÒªÕë¶ÔMS-SQL·þÎñÆ÷µÄÀÕË÷Èí¼þÖ®Ò»£¬ÔÚ´ÓǰҲ±»³ÆÎªMallox¡£Ï°È¾Ê¼ÓÚÖ¸±êÉ豸ÉϵÄMS-SQL¹ý³ÌʹÓÃcmd.exeºÍpowershell.exeÏÂÔØ.NETÎļþ¡£Payload»á»ñÈ¡ÆäËû¶ñÒâÈí¼þ£¬ÌìÉú²¢ÔËÐÐÖÕÖ¹ÌØ¶¨¹ý³ÌºÍ·þÎñµÄBATÎļþ¡£¶øºó£¬½«ÀÕË÷Èí¼þpayload×¢Èëµ½ºÏ·¨µÄWindows¹ý³ÌAppLaunch.exeÖС£
https://asec.ahnlab.com/en/39152/


¾©¹«Íø°²±¸11010802024551ºÅ